Files
server-infra/roles/app-deploy/tasks/django.yml
T
westfarn 2e3fe13b39
Sync runner checkout / sync (push) Successful in 7s
Build profile-gated services so workers do not run stale images (#19)
## Summary

The django deploy sets `COMPOSE_PROFILES` on the **start** step but not on the **build** step, so `docker compose build` skips profile-gated services. `up -d` then reuses whatever image already exists and the container silently keeps running old code.

This adds `COMPOSE_PROFILES` to the build step so it matches the start step. Only affects hosts that set `host_apps.compose_profiles` (today: the `monica_site` dj-queue worker on adama).

## Symptom this fixes

On adama the beta worker image was 20 hours stale while web was current:

| Image | Built | Postgres driver |
|---|---|---|
| `monica_site_beta-web` | today | psycopg 3.3.4 |
| `monica_site_beta-worker` | Aug 8 | psycopg2 2.9.12 |

So the worker crash-looped on LISTEN/NOTIFY (`TypeError: 'list' object is not callable` in `dj_queue/runtime/notify.py`) long after `monica_site` had moved to psycopg3, because its image was never rebuilt.

Branch is merged up with `master`, which already carries the worker auto-start from [#18](#18); the diff here is just the build step.

## Test plan

- [x] Manual `COMPOSE_PROFILES=worker docker compose build worker` on adama produced an image with psycopg 3.3.4 and the notify errors stopped.
- [ ] Beta deploy from this branch recreates the worker with a fresh image, no manual rebuild.
- [ ] Hosts without `compose_profiles` (roslin, ai-server-4080) still build/start web only.Reviewed-on: #19
2026-08-09 04:36:51 -07:00

120 lines
4.1 KiB
YAML

---
# Deploy one Django app+env as its own docker compose project.
# Called per item with loop_var app_item = { name, env, port }.
- name: "django[{{ app_item.name }}/{{ app_item.env }}] locals"
ansible.builtin.set_fact:
_spec: "{{ app_catalog[app_item.name] }}"
_src: "{{ apps_src_dir }}/{{ app_item.name }}_{{ app_item.env }}"
_envfile: "{{ apps_env_dir }}/{{ app_item.name }}_{{ app_item.env }}.env"
_secret_src: "{{ secrets_dir }}/{{ app_item.name }}/{{ app_item.name }}_{{ app_item.env }}.env"
_project: "{{ app_item.name }}_{{ app_item.env }}"
_ref: "{{ app_ref | default(app_catalog[app_item.name].default_branch) }}"
- name: "django[{{ _project }}] ensure base dirs"
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: "{{ admin_user }}"
group: "{{ admin_user }}"
mode: "0750"
loop:
- "{{ apps_src_dir }}"
- "{{ apps_env_dir }}"
- name: "django[{{ _project }}] check local secret exists"
ansible.builtin.stat:
path: "{{ _secret_src }}"
register: _secret_stat
delegate_to: localhost
become: false
- name: "django[{{ _project }}] fail when local secret missing"
ansible.builtin.fail:
msg: >-
Missing local secret {{ _secret_src }} on the control node.
Create it (DATABASE_URL to the shared external Postgres, DJANGO_SECRET_KEY,
WEB_PORT={{ app_item.port }}, etc.) before deploying. It is never committed
to git.
when: not _secret_stat.stat.exists
- name: "django[{{ _project }}] push secret to {{ _envfile }}"
ansible.builtin.copy:
src: "{{ _secret_src }}"
dest: "{{ _envfile }}"
owner: "{{ admin_user }}"
group: "{{ admin_user }}"
mode: "0600"
- name: "django[{{ _project }}] checkout {{ _ref }}"
ansible.builtin.git:
repo: "{{ _spec.repo }}"
dest: "{{ _src }}"
version: "{{ _ref }}"
force: true
accept_hostkey: true
become: true
become_user: "{{ admin_user }}"
- name: "django[{{ _project }}] install .env into checkout"
ansible.builtin.copy:
src: "{{ _envfile }}"
dest: "{{ _src }}/.env"
remote_src: true
owner: "{{ admin_user }}"
group: "{{ admin_user }}"
mode: "0600"
# COMPOSE_PROFILES must match the start step below: without it, profile-gated
# services (e.g. the dj-queue worker) are skipped here and keep a stale image.
- name: "django[{{ _project }}] build images"
ansible.builtin.command:
cmd: "docker compose -f {{ _spec.compose_file }} --env-file .env build"
chdir: "{{ _src }}"
environment:
COMPOSE_PROJECT_NAME: "{{ _project }}"
WEB_PORT: "{{ app_item.port }}"
COMPOSE_PROFILES: "{{ (app_item.compose_profiles | default([])) | join(',') }}"
become: true
become_user: "{{ admin_user }}"
changed_when: true
- name: "django[{{ _project }}] legacy systemd unit"
ansible.builtin.set_fact:
_legacy_systemd: "{{ _spec.legacy_systemd_units[app_item.env] | default('') }}"
when: _spec.legacy_systemd_units is defined
- name: "django[{{ _project }}] probe legacy systemd unit"
ansible.builtin.command:
cmd: systemctl list-unit-files {{ _legacy_systemd }}.service --no-legend
register: _legacy_systemd_probe
changed_when: false
failed_when: false
become: true
when: _legacy_systemd | default('') | length > 0
- name: "django[{{ _project }}] stop legacy systemd unit"
ansible.builtin.systemd:
name: "{{ _legacy_systemd }}"
state: stopped
enabled: false
become: true
when:
- _legacy_systemd | default('') | length > 0
- _legacy_systemd_probe.stdout | default('') | length > 0
# Optional host_apps.compose_profiles (e.g. [worker]) activates compose profiles
# on this host only. Used for monica_site dj-queue singleton on adama — without
# it, plain up --remove-orphans can drop a manually started worker.
- name: "django[{{ _project }}] start containers"
ansible.builtin.command:
cmd: "docker compose -f {{ _spec.compose_file }} --env-file .env up -d --remove-orphans"
chdir: "{{ _src }}"
environment:
COMPOSE_PROJECT_NAME: "{{ _project }}"
WEB_PORT: "{{ app_item.port }}"
COMPOSE_PROFILES: "{{ (app_item.compose_profiles | default([])) | join(',') }}"
become: true
become_user: "{{ admin_user }}"
changed_when: true