diff --git a/ansible/roles/podman/tasks/containers/home/zomboid.yml b/ansible/roles/podman/tasks/containers/home/zomboid.yml index bdb90aa..d6e9c01 100644 --- a/ansible/roles/podman/tasks/containers/home/zomboid.yml +++ b/ansible/roles/podman/tasks/containers/home/zomboid.yml @@ -271,14 +271,41 @@ vars: container_name: zomboid -# Ensure zomboid restarts on any exit (including admin-triggered restarts) -- name: configure zomboid systemd to always restart +# Make systemd actually supervise the container, so it restarts on any exit -- +# including the clean one that `@bot restart` produces via RCON quit. +# +# `podman generate systemd` emits Type=forking with ExecStart=podman start and +# a PIDFile pointing at conmon. podman start returns immediately, so the process +# systemd is told to watch was never its child; it says so itself in the journal +# ("Supervising process N which is not our child. We'll most likely not notice +# when it exits") and it does not notice. The unit sat at active/running with +# NRestarts=0 while the container was exited(0) and the server was down. The +# PIDFile is worse than useless here: it embeds the container ID, so it goes +# stale every time a deploy recreates the container. +# +# Type=simple with `podman start -a` keeps podman in the foreground as systemd's +# own child, so the exit is seen and Restart=always fires. +# +# stdout/stderr are discarded on purpose. Attaching re-emits the container's +# output on podman's stdout, which systemd would capture straight back into the +# journal -- exactly the flood the k8s-file log driver exists to avoid. Nothing +# is lost: `podman logs` still serves it from the container's own log. +- name: configure zomboid systemd supervision become: true become_user: "{{ podman_user }}" ansible.builtin.lineinfile: path: "{{ podman_home }}/.config/systemd/user/zomboid.service" - regexp: "^Restart=" - line: "Restart=always" + regexp: "{{ item.regexp }}" + line: "{{ item.line }}" + state: "{{ item.state | default('present') }}" + insertafter: '^\[Service\]' + loop: + - { regexp: '^Restart=', line: 'Restart=always' } + - { regexp: '^Type=', line: 'Type=simple' } + - { regexp: '^ExecStart=', line: 'ExecStart=/usr/bin/podman start -a zomboid' } + - { regexp: '^StandardOutput=', line: 'StandardOutput=null' } + - { regexp: '^StandardError=', line: 'StandardError=null' } + - { regexp: '^PIDFile=', line: '', state: absent } notify: reload zomboid systemd # Firewall logging for player IP correlation