Files
deploy_home/ansible/roles/podman/tasks/containers/cloud-cron.yml
T
Bastian de Byl 5776dbe1bf UPS monitoring, Nextcloud cron, container image bumps
ups role: NUT server on home.debyl.io for the CyberPower PR1500RT2U that backs
both it and truenas.localdomain, with staged shutdown (TrueNAS sheds at t+2min,
host at 10% charge) and best-effort IPMI power-on when mains returns. The 10%
threshold leans on ignorelb + override.battery.charge.low rather than a custom
poller, because CyberPower asserts its own low-battery flag far too early.
Credentials come from vault vars; nothing sensitive is templated in the clear.

Nextcloud background jobs: both instances have backgroundjobs_mode "cron", which
expects an external caller every ~5 minutes, and nothing was calling. The
personal instance had not run a background job since 2026-05-14 and skudak since
2024-11-20. Consequently trash and file versions never expired, stale chunked
uploads accumulated, calendar reminders never fired, and nextcloud.log was never
rotated -- which quietly made the existing log_rotate_size cap inert. Added a
systemd timer per instance, skipping cleanly when the container is down or in
maintenance so deploy windows don't show up as failed units.

Trash retention on the personal instance: the default "auto" only expires when
disk space demands it, so 66 GB of >30-day deletions sat on a host with 1.3 TB
free -- effectively unbounded. "auto, 30" makes the 30-day expiry unconditional
while still purging early under pressure.

Image bumps:
  nextcloud       33.0.0  -> 34.0.2   (both cloud and skudak-cloud)
  greg-time-bot   3.9.25  -> 3.10.0
  fulfillr        20260723.2044 -> 20260728.2155  (prod and dev)

The fulfillr bump records what is already deployed: both containers were rolled
to that image on 2026-07-29 for SCRUM-156 (digital product releases + customer
update campaign). Committing it keeps the repo from claiming an older tag than
the host is actually running, which would otherwise roll fulfillr backwards on
the next clean-checkout deploy.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-30 13:00:51 -04:00

41 lines
1001 B
YAML

---
- name: template {{ cron_name }} cron script
become: true
ansible.builtin.template:
src: nextcloud/cloud-cron.sh.j2
dest: "{{ cron_script_path }}"
owner: root
group: root
mode: 0755
setype: bin_t
- name: template {{ cron_name }} cron systemd service
become: true
ansible.builtin.template:
src: nextcloud/cloud-cron.service.j2
dest: "/etc/systemd/system/{{ cron_name }}-cron.service"
owner: root
group: root
mode: 0644
vars:
instance_name: "{{ cron_name }}"
- name: template {{ cron_name }} cron systemd timer
become: true
ansible.builtin.template:
src: nextcloud/cloud-cron.timer.j2
dest: "/etc/systemd/system/{{ cron_name }}-cron.timer"
owner: root
group: root
mode: 0644
vars:
instance_name: "{{ cron_name }}"
- name: enable and start {{ cron_name }} cron timer
become: true
ansible.builtin.systemd:
name: "{{ cron_name }}-cron.timer"
enabled: true
state: started
daemon_reload: true