Initial VPS operations handbook
This commit is contained in:
@@ -0,0 +1,50 @@
|
||||
---
|
||||
# The health-check service owns the sole dispatcher hook. This role only
|
||||
# installs/removes that dispatcher according to the explicit opt-in below.
|
||||
- name: Require explicit non-secret alert recipient when email is enabled
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- email_alert_recipient | length > 0
|
||||
fail_msg: Set email_alert_recipient outside version control before enabling alerts.
|
||||
when: email_alert_enabled | bool
|
||||
|
||||
- name: Install alert integration when explicitly enabled
|
||||
when: email_alert_enabled | bool
|
||||
block:
|
||||
- name: Install alert state directory
|
||||
ansible.builtin.file:
|
||||
path: "{{ email_alert_state_path | dirname }}"
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0750"
|
||||
|
||||
- name: Install secret-free alert dispatcher
|
||||
ansible.builtin.template:
|
||||
src: alert-dispatch.sh.j2
|
||||
dest: /usr/local/lib/vps-health/alert-dispatch
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0750"
|
||||
|
||||
- name: Remove alert integration when disabled
|
||||
when: not (email_alert_enabled | bool)
|
||||
block:
|
||||
- name: Remove alert dispatcher
|
||||
ansible.builtin.file:
|
||||
path: /usr/local/lib/vps-health/alert-dispatch
|
||||
state: absent
|
||||
|
||||
- name: Remove legacy alert service drop-in
|
||||
ansible.builtin.file:
|
||||
path: /etc/systemd/system/vps-healthcheck.service.d/alerting.conf
|
||||
state: absent
|
||||
notify: Reload systemd
|
||||
|
||||
- name: Report required server-side alert configuration
|
||||
ansible.builtin.debug:
|
||||
msg: >-
|
||||
Email alerts are {{ 'enabled' if email_alert_enabled | bool else 'disabled' }}.
|
||||
When enabled, the root-owned {{ email_alert_config_path }} must be provisioned
|
||||
directly on the host and must contain SMTP settings and recipient; it is never
|
||||
created or populated by this repository.
|
||||
Reference in New Issue
Block a user