2abcdd7c58b607b1d089342fc574452987bde9f5
Sync runner checkout / sync (push) Successful in 6s
## Summary - Closes [#27](#27). - Register `print_forge` in `app_catalog` (`type: django`, repo `ai_ml_operations/print_forge`, default branch `master`). - Add `host_apps` prod `:8007` / beta `:8019` on **adama**, **roslin**, **starbuck**, **apollo**, and **ai-server-4080**. - dj-queue **worker singleton on adama** only (`compose_profiles: [worker]`); other hosts web-only. - Document ports, NPM hosts, Postgres DBs, secrets, Nominatim (`10.0.0.128:8089`), and the app-repo companion ([print_forge#1](ai_ml_operations/print_forge#1)). - Update `scripts/deploy.sh` `--app` help. - Move unused `abc_be` prod port reserve **8007 → 8009** so it does not collide with `print_forge`. ## Test plan - [ ] Confirm `print_forge` appears in `app_catalog` and `--app print_forge` is listed in `deploy.sh --help` - [ ] Confirm beta `host_apps` on all five hosts (port **8019**); adama has `compose_profiles: [worker]` - [ ] Confirm prod port **8007** reserved on those hosts (no NPM until launch) - [ ] After merge (ops, not this PR): create Postgres DBs `print_forge_beta` + `print_forge` on `10.0.0.230`, grant `westfarn` - [ ] After merge (ops): write `~/Documents/secrets/print_forge/print_forge_{beta,prod}.env` from app `.env.prod.example`; add `print_forge:<token>` to `SHORTENER_API_TOKENS` (beta first) - [ ] After merge (ops): NPM `print-forge-preview.aimloperations.com` → `:8019` active/active; do **not** NPM-route `printforgeprints.com` until launch - [ ] After secrets + DBs: `~/Documents/repos/server-infra/scripts/deploy.sh --app print_forge --env beta --ref master` and hit `/healthz/` Reviewed-on: #28
server-infra
Ansible provisioning and deployment for homelab web servers.
Quick Start
# Install collections (once)
ansible-galaxy collection install -r requirements.yml
# Bootstrap SSH key to each host (one-time, before Ansible)
ssh-copy-id westfarn@10.0.0.77
ssh-copy-id westfarn@10.0.0.176
ssh-copy-id westfarn@10.0.0.44
ssh-copy-id westfarn@10.0.0.7
# First-time only: passwordless sudo on each new host (before first provision)
ssh -t westfarn@10.0.0.176 # repeat for each host IP
# on the host:
echo 'westfarn ALL=(ALL) NOPASSWD:ALL' | sudo tee /etc/sudoers.d/westfarn
sudo chmod 440 /etc/sudoers.d/westfarn
exit
# Test connectivity to one host
ansible adama -m ping
# Provision one host (dry run first) — includes Alloy log/metrics agent
./scripts/provision.sh adama --check
./scripts/provision.sh adama
# Control node: Alloy + Loki + Prometheus + Grafana
./scripts/provision.sh ai-server-4080
# Provision all hosts
./scripts/provision.sh
See IMPLEMENTATION.md for full architecture, CI/CD plan, and phase breakdown.
Observability (Alloy → Loki / Prometheus → Grafana): docs/OBSERVABILITY.md · docs/GRAFANA_USAGE.md
Provision installs Alloy on every host. On ai-server-4080 it also starts
the central Loki / Prometheus / Grafana stack (observability_stack: true).
Servers
| Host | IP | Role |
|---|---|---|
| adama | 10.0.0.77 | app host |
| roslin | 10.0.0.176 | app host |
| starbuck | 10.0.0.44 | app host |
| apollo | 10.0.0.7 | app host |
| ai-server-4080 | 10.0.0.128 | control node + act runner |
Languages
Jinja
63.3%
Shell
36.7%