5776dbe1bf
ups role: NUT server on home.debyl.io for the CyberPower PR1500RT2U that backs both it and truenas.localdomain, with staged shutdown (TrueNAS sheds at t+2min, host at 10% charge) and best-effort IPMI power-on when mains returns. The 10% threshold leans on ignorelb + override.battery.charge.low rather than a custom poller, because CyberPower asserts its own low-battery flag far too early. Credentials come from vault vars; nothing sensitive is templated in the clear. Nextcloud background jobs: both instances have backgroundjobs_mode "cron", which expects an external caller every ~5 minutes, and nothing was calling. The personal instance had not run a background job since 2026-05-14 and skudak since 2024-11-20. Consequently trash and file versions never expired, stale chunked uploads accumulated, calendar reminders never fired, and nextcloud.log was never rotated -- which quietly made the existing log_rotate_size cap inert. Added a systemd timer per instance, skipping cleanly when the container is down or in maintenance so deploy windows don't show up as failed units. Trash retention on the personal instance: the default "auto" only expires when disk space demands it, so 66 GB of >30-day deletions sat on a host with 1.3 TB free -- effectively unbounded. "auto, 30" makes the 30-day expiry unconditional while still purging early under pressure. Image bumps: nextcloud 33.0.0 -> 34.0.2 (both cloud and skudak-cloud) greg-time-bot 3.9.25 -> 3.10.0 fulfillr 20260723.2044 -> 20260728.2155 (prod and dev) The fulfillr bump records what is already deployed: both containers were rolled to that image on 2026-07-29 for SCRUM-156 (digital product releases + customer update campaign). Committing it keeps the repo from claiming an older tag than the host is actually running, which would otherwise roll fulfillr backwards on the next clean-checkout deploy. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
41 lines
1.4 KiB
Django/Jinja
41 lines
1.4 KiB
Django/Jinja
# {{ ansible_managed }}
|
|
|
|
MONITOR {{ ups_name }}@localhost 1 upsmon {{ nut_upsmon_password }} master
|
|
|
|
MINSUPPLIES 1
|
|
SHUTDOWNCMD "/usr/bin/systemctl poweroff"
|
|
NOTIFYCMD /usr/bin/upssched
|
|
|
|
# upsmon drops this file before halting; /lib/systemd/system-shutdown/nutshutdown
|
|
# reads it late in shutdown and, if present, tells the UPS to cut its output.
|
|
# That AC drop-and-return is what triggers the R415's always-on restore policy
|
|
# and this host's BIOS "After Power Loss: Power On". upsmon has NO compiled-in
|
|
# default for this - leave it unset and the UPS never powers down.
|
|
# Must be on tmpfs: a persistent path can go stale and make every ordinary
|
|
# reboot look like a forced shutdown.
|
|
POWERDOWNFLAG /run/nut/killpower
|
|
|
|
POLLFREQ 5
|
|
POLLFREQALERT 5
|
|
|
|
# Wait up to 30s for the truenas slave to disconnect before we halt.
|
|
HOSTSYNC 30
|
|
DEADTIME 15
|
|
RBWARNTIME 43200
|
|
NOCOMMWARNTIME 300
|
|
FINALDELAY 5
|
|
|
|
# SYSLOG puts every UPS event in the journal, which fluent-bit already
|
|
# forwards to Graylog (see roles/common/tasks/fluent-bit.yml).
|
|
# EXEC runs NOTIFYCMD, i.e. upssched, which drives the TrueNAS restore.
|
|
NOTIFYFLAG ONLINE SYSLOG+EXEC
|
|
NOTIFYFLAG ONBATT SYSLOG+EXEC
|
|
NOTIFYFLAG LOWBATT SYSLOG+EXEC
|
|
NOTIFYFLAG FSD SYSLOG+EXEC
|
|
NOTIFYFLAG COMMOK SYSLOG+EXEC
|
|
NOTIFYFLAG COMMBAD SYSLOG+EXEC
|
|
NOTIFYFLAG SHUTDOWN SYSLOG+EXEC
|
|
NOTIFYFLAG REPLBATT SYSLOG
|
|
NOTIFYFLAG NOCOMM SYSLOG
|
|
NOTIFYFLAG NOPARENT SYSLOG
|