From e681a46b786920db72c87987d6188c65e8335640 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Mon, 14 Sep 2026 14:02:38 -0400 Subject: [PATCH 1/4] SCRUM-196: GA4 analytics config for fulfillr Traffic & funnel tab Render an analytics block (property 353859448 + service-account key) into the fulfillr dev and prod configs once fulfillr_ga4_credentials is in the vault. Without the vault var the block is omitted and the portal reports GA as not connected. Remember to restart the container after deploy. Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/defaults/main.yml | 3 +++ ansible/roles/podman/templates/fulfillr/dev.json.j2 | 8 ++++++++ .../roles/podman/templates/fulfillr/production.json.j2 | 8 ++++++++ 3 files changed, 19 insertions(+) diff --git a/ansible/roles/podman/defaults/main.yml b/ansible/roles/podman/defaults/main.yml index ba18998..87a0773 100644 --- a/ansible/roles/podman/defaults/main.yml +++ b/ansible/roles/podman/defaults/main.yml @@ -326,3 +326,6 @@ cifs_watchdog_mounts: - "{{ photos_path }}/storage" - "{{ photos_path }}/immich" +# GA4 property for the fulfillr portal Traffic & funnel tab (SCRUM-196, non-secret). +# Shared by dev and prod. The service-account key `fulfillr_ga4_credentials` lives in the vault. +fulfillr_ga4_property_id: "353859448" diff --git a/ansible/roles/podman/templates/fulfillr/dev.json.j2 b/ansible/roles/podman/templates/fulfillr/dev.json.j2 index 553c11b..cb5d8fb 100644 --- a/ansible/roles/podman/templates/fulfillr/dev.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/dev.json.j2 @@ -53,5 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-dev", "schedule_group": "default" + }{%- if fulfillr_ga4_credentials is defined %}, + {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the + service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + is in the vault; without it the traffic endpoint reports configured:false. #} + "analytics": { + "ga4_property_id": "{{ fulfillr_ga4_property_id }}", + "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} } +{%- endif %} } diff --git a/ansible/roles/podman/templates/fulfillr/production.json.j2 b/ansible/roles/podman/templates/fulfillr/production.json.j2 index 6f12879..6a315eb 100644 --- a/ansible/roles/podman/templates/fulfillr/production.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/production.json.j2 @@ -53,5 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-prod", "schedule_group": "default" + }{%- if fulfillr_ga4_credentials is defined %}, + {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the + service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + is in the vault; without it the traffic endpoint reports configured:false. #} + "analytics": { + "ga4_property_id": "{{ fulfillr_ga4_property_id }}", + "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} } +{%- endif %} } -- 2.54.0 From e174e259ebad24f2fd6d1dc3ae710ff7b761d9f5 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Mon, 14 Sep 2026 16:21:04 -0400 Subject: [PATCH 2/4] SCRUM-196: Read GA4 key from fulfillr_ga4_credentials_json Match the vault variable name holding the service-account key file. Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/defaults/main.yml | 2 +- ansible/roles/podman/templates/fulfillr/dev.json.j2 | 6 +++--- ansible/roles/podman/templates/fulfillr/production.json.j2 | 6 +++--- 3 files changed, 7 insertions(+), 7 deletions(-) diff --git a/ansible/roles/podman/defaults/main.yml b/ansible/roles/podman/defaults/main.yml index 87a0773..327d6d3 100644 --- a/ansible/roles/podman/defaults/main.yml +++ b/ansible/roles/podman/defaults/main.yml @@ -327,5 +327,5 @@ cifs_watchdog_mounts: - "{{ photos_path }}/immich" # GA4 property for the fulfillr portal Traffic & funnel tab (SCRUM-196, non-secret). -# Shared by dev and prod. The service-account key `fulfillr_ga4_credentials` lives in the vault. +# Shared by dev and prod. The service-account key `fulfillr_ga4_credentials_json` lives in the vault. fulfillr_ga4_property_id: "353859448" diff --git a/ansible/roles/podman/templates/fulfillr/dev.json.j2 b/ansible/roles/podman/templates/fulfillr/dev.json.j2 index cb5d8fb..fedb5ac 100644 --- a/ansible/roles/podman/templates/fulfillr/dev.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/dev.json.j2 @@ -53,13 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-dev", "schedule_group": "default" - }{%- if fulfillr_ga4_credentials is defined %}, + }{%- if fulfillr_ga4_credentials_json is defined %}, {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the - service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + service-account key `fulfillr_ga4_credentials_json` (the key JSON, as a mapping or string) is in the vault; without it the traffic endpoint reports configured:false. #} "analytics": { "ga4_property_id": "{{ fulfillr_ga4_property_id }}", - "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} + "ga4_credentials": {{ (fulfillr_ga4_credentials_json if fulfillr_ga4_credentials_json is mapping else (fulfillr_ga4_credentials_json | from_json)) | to_json }} } {%- endif %} } diff --git a/ansible/roles/podman/templates/fulfillr/production.json.j2 b/ansible/roles/podman/templates/fulfillr/production.json.j2 index 6a315eb..8619764 100644 --- a/ansible/roles/podman/templates/fulfillr/production.json.j2 +++ b/ansible/roles/podman/templates/fulfillr/production.json.j2 @@ -53,13 +53,13 @@ "recovery": { "schedule_name": "cart-recovery-prod", "schedule_group": "default" - }{%- if fulfillr_ga4_credentials is defined %}, + }{%- if fulfillr_ga4_credentials_json is defined %}, {# GA4 Data API for the portal Traffic & funnel tab (SCRUM-196). Renders only once the - service-account key `fulfillr_ga4_credentials` (the key JSON, as a mapping or string) + service-account key `fulfillr_ga4_credentials_json` (the key JSON, as a mapping or string) is in the vault; without it the traffic endpoint reports configured:false. #} "analytics": { "ga4_property_id": "{{ fulfillr_ga4_property_id }}", - "ga4_credentials": {{ (fulfillr_ga4_credentials if fulfillr_ga4_credentials is mapping else (fulfillr_ga4_credentials | from_json)) | to_json }} + "ga4_credentials": {{ (fulfillr_ga4_credentials_json if fulfillr_ga4_credentials_json is mapping else (fulfillr_ga4_credentials_json | from_json)) | to_json }} } {%- endif %} } -- 2.54.0 From 80edc8458687a2e5b3b88c7c5c5571d7f089e5b1 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Mon, 14 Sep 2026 17:10:08 -0400 Subject: [PATCH 3/4] SCRUM-196: fulfillr 20260914.2103 (funnel + GA4 traffic endpoints) Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/tasks/main.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ansible/roles/podman/tasks/main.yml b/ansible/roles/podman/tasks/main.yml index 125aeba..db0563c 100644 --- a/ansible/roles/podman/tasks/main.yml +++ b/ansible/roles/podman/tasks/main.yml @@ -81,13 +81,13 @@ - import_tasks: containers/debyltech/fulfillr.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260827.2009 + image: git.debyl.io/debyltech/fulfillr:20260914.2103 tags: debyltech, fulfillr # Staging back-office (fulfillr-dev.debyltech.com) — same image, staging Turso config. - import_tasks: containers/debyltech/fulfillr-dev.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260827.2009 + image: git.debyl.io/debyltech/fulfillr:20260914.2103 tags: debyltech, fulfillr-dev - import_tasks: containers/debyltech/uptime-kuma.yml -- 2.54.0 From 75e257077e70af18f18d093ec38fd4a4a474ddb5 Mon Sep 17 00:00:00 2001 From: Bastian de Byl Date: Mon, 14 Sep 2026 17:55:15 -0400 Subject: [PATCH 4/4] SCRUM-196: fulfillr 20260914.2149 (embedded tzdata for GA4) Co-Authored-By: Claude Opus 5 --- ansible/roles/podman/tasks/main.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/ansible/roles/podman/tasks/main.yml b/ansible/roles/podman/tasks/main.yml index db0563c..20665e8 100644 --- a/ansible/roles/podman/tasks/main.yml +++ b/ansible/roles/podman/tasks/main.yml @@ -81,13 +81,13 @@ - import_tasks: containers/debyltech/fulfillr.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260914.2103 + image: git.debyl.io/debyltech/fulfillr:20260914.2149 tags: debyltech, fulfillr # Staging back-office (fulfillr-dev.debyltech.com) — same image, staging Turso config. - import_tasks: containers/debyltech/fulfillr-dev.yml vars: - image: git.debyl.io/debyltech/fulfillr:20260914.2103 + image: git.debyl.io/debyltech/fulfillr:20260914.2149 tags: debyltech, fulfillr-dev - import_tasks: containers/debyltech/uptime-kuma.yml -- 2.54.0