Graylog was the worst cost/benefit tenant on this 4-core box: two JVMs plus
MongoDB holding ~1.6 GB resident and ~3% CPU around the clock to store ~3k
messages a day -- about 28 MB across its four live indices. journald already
retains ~25 days of the same logs at its 500M cap, so this costs searchability,
not the logs.
The switch is `graylog_enabled` in inventory rather than a role default,
because three roles read it (common, podman, graylog-config). The disabled
path is an active teardown, not a skipped create: the containers already on
the host keep running and their systemd user units keep restarting them at
boot unless something stops and removes them. fluent-bit follows the same
flag -- with the GELF sink down it would spin retrying a dead 127.0.0.1:12202
and fill the journal it exists to drain -- but only the service state follows,
so re-enabling is a restart rather than a reinstall.
Caddy reloads were silently no-ops. The handler read /etc/caddy/Caddyfile,
which is a single-file bind mount, and podman binds those by inode; the
template module writes a temp file and renames it into place, so every deploy
gave the host file a new inode while the container kept seeing the one it was
created with. Config changes only ever landed when something recreated the
container. {{ caddy_path }}/config is also mounted, as a *directory*, and
directory mounts resolve names at open() time -- so /config/Caddyfile is
always the file Ansible just wrote.
awsddns and its four siblings had accumulated 12 zombies over 30 days of
uptime. The image's PID 1 is busybox crond, which only waitpid()s the job PIDs
it tracks and does no generic orphan reaping, so whenever the run-parts/sh
layer exited before the script it left a permanent <defunct>. init: true puts
catatonit at PID 1 to reap them, and the recreation clears the existing ones.
Also bumps fulfillr and greg-time-bot images.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
64 lines
1.7 KiB
YAML
64 lines
1.7 KiB
YAML
---
|
|
- name: restorecon podman
|
|
become: true
|
|
ansible.builtin.command: |
|
|
restorecon -Frv {{ podman_home }}/.local/share/volumes
|
|
tags:
|
|
- podman
|
|
- selinux
|
|
|
|
# nginx handler removed - nginx infrastructure decommissioned
|
|
|
|
- name: restart firewalld
|
|
become: true
|
|
ansible.builtin.service:
|
|
name: firewalld
|
|
state: restarted
|
|
tags:
|
|
- firewall
|
|
|
|
- name: restart caddy
|
|
become: true
|
|
become_user: "{{ podman_user }}"
|
|
ansible.builtin.command: |
|
|
podman restart caddy
|
|
tags:
|
|
- caddy
|
|
|
|
# Reads /config/Caddyfile, NOT the /etc/caddy/Caddyfile the container starts
|
|
# from, even though both are the same host file. /etc/caddy/Caddyfile is a
|
|
# single-file bind mount, which podman binds by inode; the template module
|
|
# writes a temp file and renames it into place, so every deploy gives the host
|
|
# file a new inode and the container keeps seeing the one it was created with.
|
|
# Reloading from that path silently re-applied the old config -- the change only
|
|
# ever landed when something recreated the container. {{ caddy_path }}/config is
|
|
# also bind-mounted as a *directory* at /config, and a directory mount resolves
|
|
# names at open() time, so /config/Caddyfile is always the file Ansible just
|
|
# wrote.
|
|
- name: reload caddy
|
|
become: true
|
|
become_user: "{{ podman_user }}"
|
|
ansible.builtin.command: |
|
|
podman exec caddy caddy reload --config /config/Caddyfile --adapter caddyfile
|
|
tags:
|
|
- caddy
|
|
- caddy-config
|
|
|
|
- name: reload zomboid systemd
|
|
become: true
|
|
become_user: "{{ podman_user }}"
|
|
ansible.builtin.systemd:
|
|
daemon_reload: true
|
|
scope: user
|
|
tags:
|
|
- zomboid
|
|
|
|
- name: reload podman systemd
|
|
become: true
|
|
become_user: "{{ podman_user }}"
|
|
ansible.builtin.systemd:
|
|
daemon_reload: true
|
|
scope: user
|
|
tags:
|
|
- podman
|