The *-update.yml playbooks hard-coded the pre-migration VMIDs, so after cutover the "safety backup" ran against the stopped OLD container. Now the VMID comes from homelab_services['<svc>'].vmid. Also removes `--prune-backups keep-all=1` from the vzdump calls: retention is PBS's job (prune-pbs), and the client-side flag needed Datastore.Modify/Prune the ansible@pve token does not have, which made vzdump print "Backup ... failed" and exit non-zero after a successful upload. gitea-update.yml additionally splits the offsite backup (hosts: gitea) from its audit (hosts: cloud-pc), matching the profile move into the container. pve-*.yml imports pass pve_provisioning_enabled: false so the runtime update path never re-enters container creation. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012uoq5AVK8mkBgg83Mq6o5V
110 lines
3.2 KiB
YAML
110 lines
3.2 KiB
YAML
---
|
|
- name: Create and verify Grimmory backup before update
|
|
hosts: grimmory
|
|
gather_facts: false
|
|
tasks:
|
|
- name: Create a fresh Grimmory offsite backup
|
|
ansible.builtin.command:
|
|
argv:
|
|
- systemctl
|
|
- start
|
|
- --wait
|
|
- homelab-restic-offsite-grimmory.service
|
|
changed_when: true
|
|
|
|
- name: Run Grimmory offsite backup audit
|
|
ansible.builtin.command:
|
|
argv:
|
|
- systemctl
|
|
- start
|
|
- --wait
|
|
- homelab-backup-audit-grimmory.service
|
|
changed_when: true
|
|
|
|
- name: Create a fresh Grimmory PBS backup
|
|
hosts: cloud-pc
|
|
gather_facts: false
|
|
vars:
|
|
grimmory_vmid: "{{ homelab_services['grimmory'].vmid }}"
|
|
tasks:
|
|
- name: Read Grimmory LXC config
|
|
ansible.builtin.command:
|
|
argv:
|
|
- pct
|
|
- config
|
|
- "{{ grimmory_vmid }}"
|
|
register: grimmory_pct_config
|
|
changed_when: false
|
|
|
|
- name: Assert registry VMID belongs to Grimmory
|
|
ansible.builtin.assert:
|
|
that:
|
|
- grimmory_pct_hostname_line != ""
|
|
- grimmory_pct_hostname == "grimmory"
|
|
fail_msg: >-
|
|
Refusing to run vzdump {{ grimmory_vmid }} because pct config
|
|
hostname is not grimmory:
|
|
{{ grimmory_pct_hostname_line | default('missing hostname line') }}
|
|
vars:
|
|
grimmory_pct_hostname_line: >-
|
|
{{ (grimmory_pct_config.stdout_lines | select('match', '^hostname:\\s+') | list | first | default('')) }}
|
|
grimmory_pct_hostname: >-
|
|
{{ grimmory_pct_hostname_line | regex_replace('^hostname:\\s*', '') }}
|
|
|
|
- name: Check for active Proxmox backup before Grimmory PBS backup
|
|
ansible.builtin.command: pgrep -x vzdump
|
|
register: grimmory_vzdump_preflight
|
|
changed_when: false
|
|
failed_when: false
|
|
|
|
- name: Require no active Proxmox backup before Grimmory PBS backup
|
|
ansible.builtin.assert:
|
|
that:
|
|
- grimmory_vzdump_preflight.rc != 0
|
|
fail_msg: >-
|
|
A Proxmox backup is already running on cloud-pc.
|
|
Retry after the existing backup completes.
|
|
|
|
- name: Create a fresh Grimmory PBS backup
|
|
ansible.builtin.command:
|
|
argv:
|
|
- vzdump
|
|
- "{{ grimmory_vmid }}"
|
|
- --storage
|
|
- pbs
|
|
- --mode
|
|
- snapshot
|
|
- --exclude-path
|
|
- /var/lib/docker/fuse-overlayfs/*/merged
|
|
|
|
- name: Run PBS backup audit on mini-pc
|
|
hosts: mini-pc
|
|
gather_facts: false
|
|
tasks:
|
|
- name: Run current PBS backup audit on mini-pc
|
|
ansible.builtin.command:
|
|
argv:
|
|
- systemctl
|
|
- start
|
|
- --wait
|
|
- homelab-backup-audit-pbs.service
|
|
changed_when: true
|
|
|
|
- import_playbook: pve-grimmory.yml
|
|
vars:
|
|
pve_provisioning_enabled: false
|
|
|
|
- name: Verify Grimmory public endpoint after update
|
|
hosts: ru-vps
|
|
gather_facts: false
|
|
tasks:
|
|
- name: Check Grimmory public health endpoint
|
|
ansible.builtin.uri:
|
|
url: https://books.ada-dev.ru/api/v1/healthcheck
|
|
status_code: 200
|
|
return_content: false
|
|
register: grimmory_public_health
|
|
retries: 24
|
|
delay: 5
|
|
until: grimmory_public_health.status == 200
|