Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
253 commits
Select commit Hold shift + click to select a range
620d5a1
Fix bad comment
LDiazN Aug 25, 2025
b1ee5cc
fix certificate deadlock issue
LDiazN Aug 28, 2025
3beab5d
Routing test helper traffic with nginx
LDiazN Aug 28, 2025
d0a9298
nginx config for test helpers
LDiazN Aug 28, 2025
4c5fcc6
Creating echo machine
LDiazN Aug 28, 2025
61d705e
Creating host for each th
LDiazN Aug 28, 2025
91bfe43
Fix bad module name
LDiazN Aug 28, 2025
1f08b62
Set up ansible for each test helper
LDiazN Aug 28, 2025
b773393
Run prometheus without dehydrated when no https is required
LDiazN Aug 29, 2025
ed6f3a2
removing unused listen 80 entry in prometheus config
LDiazN Aug 29, 2025
94b24cd
Allow services to run on port 80
LDiazN Aug 29, 2025
393803e
Add port parameters to use a different port for test helpers metrics
LDiazN Aug 29, 2025
f5f5819
Remove unused firewall rules
LDiazN Sep 1, 2025
901639d
Updated comment
LDiazN Sep 1, 2025
e45f173
Add checksum for test helpers tar download
LDiazN Sep 4, 2025
7ca3083
Merge conflict
LDiazN Nov 4, 2025
9f86d7f
Apply stricter constraints on oonimeasurements user queries
hellais Apr 17, 2026
d9addca
Reduce max rows to 50k
hellais Apr 17, 2026
d442c90
raise oonimeasuremenets max memory
aagbsn Apr 27, 2026
7e52d43
Merge remote-tracking branch 'origin/main' into oonimeasurements-limits
aagbsn Apr 29, 2026
a5fd688
Merge remote-tracking branch 'origin/raise_oonimeasurements_max_memor…
aagbsn Apr 29, 2026
b7a4246
enable clickhouse_role_manage_settings_profiles and clickhouse_role_m…
aagbsn Apr 29, 2026
798b0c2
fix user password misconfiguration
aagbsn Apr 30, 2026
3773e15
sql managed users does NOT read var password_sha256_hex nor hash pass…
aagbsn Apr 30, 2026
b7baff6
add clickhouse users for each ooniapi service, fastpath, and testlists
aagbsn May 1, 2026
ea6e883
add clickhouse secrets, clickhouse_url to prod environment
aagbsn May 1, 2026
7520f88
remove clickhouse settings for oonifindings: uses psgql
aagbsn May 1, 2026
993f920
Merge remote-tracking branch 'origin/main' into add_ooni_clickhouse_u…
aagbsn May 5, 2026
b6a1673
Merge remote-tracking branch 'origin/main' into add_ooni_clickhouse_u…
aagbsn May 26, 2026
065b076
Add reuploader builder task to dev
aagbsn Jun 8, 2026
ccda78d
fix trigger path
aagbsn Jun 8, 2026
01ab568
Extend ooniapi_service to provide scheduled run
aagbsn Jun 8, 2026
e8e191e
add scheduled_service module
aagbsn Jun 9, 2026
1d82bdb
add reuploader scheduled service (hourly)
aagbsn Jun 9, 2026
d245b73
set failed reports bucket
aagbsn Jun 9, 2026
4dd954e
reuploader: set DRY_RUN=true
aagbsn Jun 11, 2026
b6e2ba7
reuploader: set BATCH_SIZE=10
aagbsn Jun 11, 2026
0b94e88
reuploader: set AWS_SECRET_ACCESS_KEY from module
aagbsn Jun 11, 2026
22f35d5
reuploader: set scheduled_task_cluster
aagbsn Jun 11, 2026
3a0b895
reuploader: remove unused outputs
aagbsn Jun 11, 2026
d171d28
reuploader: add first_run to create container definition
aagbsn Jun 11, 2026
c2ffbf1
reuploader: pin to tagged container
aagbsn Jun 11, 2026
6964ab5
Merge remote-tracking branch 'origin/main' into add_reuploader_builder
aagbsn Jun 11, 2026
d55b502
remove redundant count
aagbsn Jun 11, 2026
d9361d9
Merge remote-tracking branch 'origin/main' into add_reuploader_builder
aagbsn Jun 11, 2026
dbe872f
singleton requires no index
aagbsn Jun 11, 2026
27f9c59
FIXME: try to add events:PutRule et al to profile
aagbsn Jun 11, 2026
093c98f
Add permission to the ooni_devops role to modify events
LDiazN Jun 11, 2026
94f3638
unmix environment from secrets
aagbsn Jun 11, 2026
92fb38a
use bucket from https://github.com/ooni/devops/issues/398
aagbsn Jun 11, 2026
bafa175
update reuploader, fix env
aagbsn Jun 11, 2026
ed341e5
add AWS_REGION to task_environment
aagbsn Jun 11, 2026
bb5a163
set S3_BUCKET_NAME env
aagbsn Jun 11, 2026
bea658f
test reading primary failed reports bucket
aagbsn Jun 16, 2026
a5fdbc1
add iam_role_policy for reuploader task
aagbsn Jun 16, 2026
e9ebb3f
remove task secrets from reuploader; container uses ecs task role
aagbsn Jun 16, 2026
1e6802e
output scheduled_service_task.arn as task_role_arn
aagbsn Jun 17, 2026
8a603fa
set task_role_arn = scheduled_service_task.arn
aagbsn Jun 17, 2026
20b309a
WIP: use the bucket from ticket https://github.com/ooni/devops/issues…
aagbsn Jun 17, 2026
0334a52
Merge remote-tracking branch 'origin/main' into add_reuploader_builder
aagbsn Jun 23, 2026
73d4580
move reuploader scheduled service to prod environment
aagbsn Jun 23, 2026
6b941c7
use reuploader fastpath instance
aagbsn Jun 23, 2026
9fd3ddc
moved ref to failed_reports_2026_04_10 to prod
aagbsn Jun 23, 2026
d58bca7
set LOG_LEVEL to DEBUG
aagbsn Jun 23, 2026
7e362e7
add reuploaderfastpath to clickhouse nft rules
aagbsn Jun 23, 2026
f4d0868
revert changes to ooniapi_service
aagbsn Jun 23, 2026
1b58303
fastpath: switch to ooni.io domains
aagbsn Jun 23, 2026
406f350
also update reuploaderfastpath clickhouse_url
aagbsn Jun 23, 2026
3fc321f
change BATCH_SIZE; allow deleteobject on failed-reports
aagbsn Jun 29, 2026
67d0763
Add new notebook user
LDiazN Jul 10, 2026
989170d
remove willshersystems.sshd
aagbsn Jul 10, 2026
3cb3fba
Set sshd Ciphers and KexAlgorithms
aagbsn Jul 10, 2026
5d9cf21
Merge pull request #452 from ooni/ansible_role_cleanup
aagbsn Jul 10, 2026
421f2cb
remove tailscale from requirements/ansible-galaxy.yml
aagbsn Jul 10, 2026
c0d9888
remove unused role tailnet
aagbsn Jul 10, 2026
060cab1
Merge pull request #421 from ooni/add_ooni_clickhouse_users
LDiazN Jul 13, 2026
f4207d6
run reuploader daily, limit the batch size
aagbsn Jul 13, 2026
cf97658
Merge remote-tracking branch 'origin/main' into update_fastpath_click…
aagbsn Jul 13, 2026
5fd5578
Merge pull request #446 from ooni/update_fastpath_clickhouse_url
aagbsn Jul 13, 2026
96151ee
Merge pull request #440 from ooni/add_reuploader_builder
aagbsn Jul 13, 2026
da0f139
chore(terraform): auto-format on merge to main
actions-user Jul 13, 2026
76cfb48
change reuploader branch_name to master
aagbsn Jul 13, 2026
759d72d
remove group_vars related to tailscale
aagbsn Jul 13, 2026
e73e2dd
Use notebook.ooni.org domain
LDiazN Jul 15, 2026
3c45384
Replace old .nu domain with .org domain for notebook
LDiazN Jul 15, 2026
bb61817
Remove breaking algorithm from ssh steps
LDiazN Jul 15, 2026
812a3a4
remove mlkem768x25519-sha256 from KexAlgorithms
aagbsn Jul 15, 2026
3dd791b
Merge pull request #459 from ooni/remove_kex_mlkem768
aagbsn Jul 15, 2026
390587a
Remove redundant hostname for notebook server
LDiazN Jul 15, 2026
74a89eb
Merge branch 'main' into 458-fix-notebook-certs
LDiazN Jul 16, 2026
ddfef87
Use old server name for notebooks
LDiazN Jul 16, 2026
4dee89e
Roll back hostname for notebook server
LDiazN Jul 16, 2026
aa764a3
Merge pull request #460 from ooni/458-fix-notebook-certs
LDiazN Jul 16, 2026
03a5090
Change service count for ooniprobe
LDiazN Jul 17, 2026
ee69d6d
Fix broken ooniprobe clickhouse url
LDiazN Jul 17, 2026
7952ba3
Delete deb-ci.ooni.org dns record
LDiazN Jul 22, 2026
ed030a9
Merge pull request #455 from ooni/remove_tailscale_ansible_role
aagbsn Jul 27, 2026
4fa4ab3
add grants to oonitest db, #462
aagbsn Jul 28, 2026
6c49d08
remove notebook as keeper, re-add clickhouse2 as keeper
aagbsn Jul 28, 2026
845dde8
Merge pull request #457 from ooni/change_reuploader_deployer_target_b…
aagbsn Jul 29, 2026
ae4e729
prometheus_node_exporter: don't override host_vars ssl_domains
aagbsn Jul 29, 2026
5f503bd
Merge pull request #465 from ooni/fix_464_clickhouse_keeper_config
aagbsn Jul 29, 2026
b32069c
Merge remote-tracking branch 'origin/main' into fix_466_override_defa…
aagbsn Jul 29, 2026
b6e7a36
add per-role tags to roles in deploy-clickhouse playbook
aagbsn Jul 29, 2026
9efb956
do not self-reference ssl_domains in expression
aagbsn Jul 29, 2026
1c2c066
Merge pull request #467 from ooni/fix_466_override_default_ssl_domains
aagbsn Jul 29, 2026
fdd7c17
override clickhouse_role_manage_grants on notebook
aagbsn Jul 29, 2026
b752f9f
Merge pull request #468 from ooni/fix_notebook_clickhouse_vars
aagbsn Jul 29, 2026
f3fb7b4
Point oonimeasurements in dev to prod db
LDiazN Jul 31, 2026
309e274
Merge branch 'main' of https://github.com/ooni/devops
LDiazN Jul 31, 2026
ebfce37
Remove anonc ec2 instance
LDiazN Jul 31, 2026
61fdd14
Point dev env to labeling branch of oonimeasurements
hellais Jul 31, 2026
ce371e4
Create new domain name for airflow
LDiazN Aug 3, 2026
34d6b74
Add nginx rules to direct traffic to panel
LDiazN Aug 3, 2026
60dd019
Add basic http auth
LDiazN Aug 3, 2026
73416ae
Add password file for detector panel
LDiazN Aug 3, 2026
c098480
Add detector panel service unit
LDiazN Aug 4, 2026
bfc3625
Install oonipipeline with the analysis profile
LDiazN Aug 4, 2026
5bcc21c
Add event-detector panel systemd unit
LDiazN Aug 4, 2026
f654db1
Fix wrong register type for detector domain
LDiazN Aug 4, 2026
49730e0
Use inventory hostname for the certificate file
LDiazN Aug 4, 2026
f005f02
Set username to admin
LDiazN Aug 4, 2026
d3065fe
Notify nginx on detector panel changes
LDiazN Aug 4, 2026
668ffce
dehydrated: place each domain on a separate line
aagbsn Aug 5, 2026
c3cfe1e
Merge remote-tracking branch 'origin/fix_474_dehydrated_domains' into…
LDiazN Aug 5, 2026
550866b
Merge pull request #475 from ooni/fix_474_dehydrated_domains
aagbsn Aug 5, 2026
48bc0f6
Use the right certificate for detector panel
LDiazN Aug 6, 2026
c421c38
Merge pull request #473 from ooni/472-deploy-events-panel
LDiazN Aug 6, 2026
1ef7431
update with main
LDiazN Aug 11, 2026
335152a
Add test helpers machines; build th from scratch since we don't have …
LDiazN Aug 11, 2026
61c8f79
Fix edge case where service won't be properly restarted if a new vers…
LDiazN Aug 11, 2026
42cafb5
point oonimeasurements to master
LDiazN Aug 12, 2026
9e27329
Merge branch 'main' into test-helpers-machine
LDiazN Aug 12, 2026
824a2bf
Point oonimeasurements to the temp branch
LDiazN Aug 12, 2026
7d85944
remove test helpers from dev env; point ooniprobe to dev branch
LDiazN Aug 12, 2026
41a344c
Pull binaries from ooniprobe-rs repo
LDiazN Aug 12, 2026
2958a9e
Point oonimeasurements to test db
LDiazN Aug 12, 2026
a3547ca
chore: change deployer branch to enable webconnectivity_0.5
DecFox Aug 13, 2026
8f74d5d
Merge branch 'main' into test-helpers-machine
LDiazN Aug 13, 2026
be60cd7
Merge pull request #478 from ooni/feat/webconnectivity-lte
DecFox Aug 13, 2026
abf93a2
Get monitoring ip by digging it
LDiazN Aug 13, 2026
e4dc574
Pull out nginx and dehydrated roles
hellais Aug 13, 2026
d32df96
Apply tags and suggest a tagging convention
hellais Aug 13, 2026
cd7d168
Add oonidevops ssh key to digitalocean hosts
LDiazN Aug 14, 2026
b8b458b
Fix small issues on playbooks for debian
LDiazN Aug 14, 2026
a40258f
Add simpler test helper module
LDiazN Aug 14, 2026
f88a07f
Fix test helper restart
LDiazN Aug 14, 2026
0e057b4
merge conflict
LDiazN Aug 14, 2026
01214d6
rename binaries; do checksum on download
LDiazN Aug 14, 2026
a88a725
Update github actions script
hellais Aug 14, 2026
2da3b0c
Bump github actions script to v9
hellais Aug 14, 2026
40c0cfc
Comment out the ansible comment step
hellais Aug 14, 2026
599b667
Merge pull request #267 from ooni/test-helpers-machine
LDiazN Aug 14, 2026
e530d22
Merge remote-tracking branch 'origin/main' into nginx-fix
hellais Aug 14, 2026
930d705
Add web_connectivity test helper dev instance
hellais Aug 14, 2026
c9e58ab
Add deploy-wc-test-helper playbook
hellais Aug 14, 2026
806abc0
Fix resolved check command
hellais Aug 14, 2026
a557e88
Fix updating of locales
hellais Aug 14, 2026
7ceafd7
Enable post quantum sshd algorithms
hellais Aug 14, 2026
2d06d40
Exclude mlkem768x25519-sha256 since it's not in bookworm
hellais Aug 14, 2026
41b5b55
Enable TLSv1.3
hellais Aug 14, 2026
3d7e2fa
Point echo and json test helpers to DO hosts
LDiazN Aug 19, 2026
98fb44d
Merge pull request #479 from ooni/nginx-fix
hellais Aug 19, 2026
1291da9
Add support for setting custom https port in node_exporter config
hellais Aug 19, 2026
f57b9e9
Add oohelpderd role
hellais Aug 19, 2026
8b4b4ff
Update deploy script
hellais Aug 19, 2026
9c09988
Add support for deploying prod test helpers
hellais Aug 19, 2026
babb26e
Remove duplcate key definition
hellais Aug 19, 2026
ed2e4bb
terraform fmt
hellais Aug 19, 2026
790faf5
Add wcth[0-2] to inventory
hellais Aug 19, 2026
244830d
Fix inventory lines
hellais Aug 19, 2026
e761528
Add prod test helpers to deployment
hellais Aug 19, 2026
0414ed1
Put flush all handlers sooner in the dehydrated role
hellais Aug 19, 2026
4066883
Remove monitoring of old test helpers
LDiazN Aug 19, 2026
b477e78
Set instance name in terraform config
hellais Aug 19, 2026
1435e1d
More debugging of dehydrated role
hellais Aug 19, 2026
b8e5956
Add new test helpers to monitoring
hellais Aug 19, 2026
8009f9d
Add test helpers to monitoring
hellais Aug 19, 2026
9d91700
Merge pull request #484 from ooni/th-wc
hellais Aug 19, 2026
085b0f8
Fix pointers for notebook server
hellais Aug 19, 2026
f289d46
Add new test helpers checks
LDiazN Aug 20, 2026
340f77a
Merge branch 'main' into 485-remove-stale-hosts
LDiazN Aug 20, 2026
49bc1d9
Lookup ip of test helper instead of hardcoding it
LDiazN Aug 20, 2026
8c1e490
Merge pull request #486 from ooni/485-remove-stale-hosts
LDiazN Aug 20, 2026
1794519
Add public fqdn for test helper addresses
hellais Aug 20, 2026
084d6c1
Merge branch 'main' of github.com:ooni/devops
hellais Aug 20, 2026
c864901
Pass ssl_domains from host_vars
hellais Aug 20, 2026
c868a42
Build nginx config from ssl_domains
hellais Aug 20, 2026
9b42b29
Fix ssl_domains host var precedence
hellais Aug 20, 2026
bc4453c
Write ssl_domains on the same line in dehydrated
hellais Aug 20, 2026
fbd7c8a
Revert change to domains.txt
hellais Aug 20, 2026
b9e9b76
Fix server_name mappings and dehydrated setup for alternate hostnames
hellais Aug 20, 2026
6cadabd
Fix jinja template for loop
hellais Aug 20, 2026
25847f2
Setup load balancer rules to map to the legacy ooniprobe based on header
LDiazN Sep 2, 2026
22b14b9
Add ooniprobe-legacy service to prod as well
LDiazN Sep 2, 2026
d8d8d3c
Set first run to true for these services
LDiazN Sep 3, 2026
bab971d
Fix trying to create the service
LDiazN Sep 3, 2026
8cd00e5
feat: point fastpath dev builder to feat/wc-x-flags
DecFox Sep 3, 2026
7b6d5da
Merge pull request #489 from ooni/feat/wc-fastpath
DecFox Sep 3, 2026
731f80c
feat: make fastpath image as env var for ansible role
DecFox Sep 7, 2026
c691fe6
chore: explicitly pass in fastpath image tags for prod env
DecFox Sep 7, 2026
a54c5bf
Merge pull request #491 from ooni/feat/fastpath-wc
DecFox Sep 7, 2026
96ebe34
chore: point fastpath prod deployments to latest docker image
DecFox Sep 8, 2026
c95110c
Merge pull request #492 from ooni/feat/fastpath-wc-prod
DecFox Sep 8, 2026
7078aa8
Merge branch 'main' into redirect-on-header
LDiazN Sep 14, 2026
ec62b76
debug: point dev ooniprobe deployer to feat/experiment-versions
DecFox Sep 21, 2026
7fa8041
Merge pull request #493 from ooni/feat/check-in-version-deploy
DecFox Sep 21, 2026
1eccb2b
Increase quota for default in notebook for in-host operations
LDiazN Sep 22, 2026
d758d05
Increase quota for the default user overall
LDiazN Sep 22, 2026
ce27740
Add nginx rules for downloading the data dump
LDiazN Sep 23, 2026
1b21bab
Point oonirun dev to master
LDiazN Sep 23, 2026
f4f0ed2
Update fastpath_image to latest tag
aagbsn Sep 24, 2026
425247d
clean up old nginx apt sources
aagbsn Sep 24, 2026
8fd1280
fix repo path for ubuntu host compatibility
aagbsn Sep 24, 2026
43b2167
match nginx.org/packages in sources.list.d files
aagbsn Sep 24, 2026
114ccbb
Merge pull request #494 from ooni/update_fastpath_image
aagbsn Sep 24, 2026
72f66f1
Update from main
LDiazN Sep 25, 2026
0a5d9f6
Remove intersection dump from notebook server
LDiazN Sep 28, 2026
b3b8716
Merge branch 'main' into redirect-on-header
LDiazN Sep 28, 2026
7dfda84
Update docker tag in legacy
LDiazN Sep 28, 2026
eeff8dd
Already deployed; first_run no longer needed
LDiazN Sep 28, 2026
0e2a6c9
Merge pull request #490 from ooni/redirect-on-header
LDiazN Sep 28, 2026
4a7907c
Add wcth to the metrics scraping
hellais Sep 29, 2026
5da15b9
Add dev test helper to monitoring
hellais Sep 29, 2026
56e8345
Fix node_exporter path
hellais Sep 29, 2026
a7f1d8b
Fix monitoring address
hellais Sep 29, 2026
ee8d3ec
Fix url
hellais Sep 29, 2026
848df1f
Fix oohelperd nginx config
hellais Sep 29, 2026
9ccfa83
Drop legacy droplet test helpers from digital ocean
hellais Sep 29, 2026
addf016
Drop digital ocean test helpers from monitoring
hellais Sep 29, 2026
67369d2
Merge pull request #499 from ooni/drop-th
hellais Sep 30, 2026
8d929ce
add private api targets as blackbox job with interval
aagbsn Sep 30, 2026
55e622e
add api.oonio.io targets
aagbsn Sep 30, 2026
fdc716b
Merge pull request #500 from ooni/add_privapi_blackbox_jobs
aagbsn Oct 2, 2026
5392bc6
Drop countly host from monitoring
hellais Oct 2, 2026
f62b6e0
Merge pull request #502 from ooni/deprecate-countly
hellais Oct 2, 2026
ea669d3
testing pagination PR on dev
LDiazN Oct 2, 2026
aa5e8f9
Merge branch 'main' of https://github.com/ooni/devops
LDiazN Oct 2, 2026
9f478be
Merge remote-tracking branch 'origin/main' into blue-green-podman
aagbsn Oct 3, 2026
124a863
Use per-service ClickHouse URLs in blue/green service secrets
aagbsn Oct 3, 2026
1a7bdd6
deploy.py: log every command it runs
aagbsn Oct 3, 2026
ab09641
deploy.py: give a new slot as long as ECS gives a new task
aagbsn Oct 3, 2026
0e20528
deploy.py: restore the live upstream when nginx -t fails
aagbsn Oct 3, 2026
608d3f0
Bound how long a slot taken out of rotation drains
aagbsn Oct 3, 2026
16aa56b
Declare the ooniapi ALB routes in routes.yaml
aagbsn Oct 3, 2026
fbb91b8
Generate the gateway's nginx locations from routes.yaml
aagbsn Oct 3, 2026
e8a184e
ooniapi_gateway: use a syslog tag nginx accepts
aagbsn Oct 3, 2026
ac8df6d
ooniapi_gateway: cache responses of the read heavy routes
aagbsn Oct 3, 2026
525c657
Invalidate a service's gateway cache when it is deployed
aagbsn Oct 3, 2026
d20cc6f
ooniapi_service_deployer: add deploy_mode "both"
aagbsn Oct 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
60 changes: 30 additions & 30 deletions .github/workflows/check_ansible.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,41 +58,41 @@ jobs:
#- name: Setup tmate session
# uses: mxschmitt/action-tmate@v3

- uses: actions/github-script@v6
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const commentTitle = "Ansible Run Output";
const ansiblePlaybookOutput = `${{ steps.playbook.outputs.ansible_playbook}}`;
const parts = ansiblePlaybookOutput.split(/PLAY RECAP \*+/);
const ansiblePlaybookRecap = parts.length > 1 ? parts[1].trim() : '';
#- uses: actions/github-script@v9
# with:
# github-token: ${{ secrets.GITHUB_TOKEN }}
# script: |
# const commentTitle = "Ansible Run Output";
# const ansiblePlaybookOutput = `${{ steps.playbook.outputs.ansible_playbook}}`;
# const parts = ansiblePlaybookOutput.split(/PLAY RECAP \*+/);
# const ansiblePlaybookRecap = parts.length > 1 ? parts[1].trim() : '';

const commentBody = `
#### Ansible Playbook Recap 🔍
# const commentBody = `
# #### Ansible Playbook Recap 🔍

\`\`\`\n
${ansiblePlaybookRecap}
\`\`\`
# \`\`\`\n
# ${ansiblePlaybookRecap}
# \`\`\`

#### Ansible playbook output 📖\`${{ steps.playbook.outcome }}\`
# #### Ansible playbook output 📖\`${{ steps.playbook.outcome }}\`

<details><summary>Show Execution</summary>
# <details><summary>Show Execution</summary>

\`\`\`\n
${ansiblePlaybookOutput}
\`\`\`
# \`\`\`\n
# ${ansiblePlaybookOutput}
# \`\`\`

</details>
# </details>

| | |
|-------------------|------------------------------------|
| Pusher | @${{ github.actor }} |
| Action | ${{ github.event_name }} |
| Working Directory | ${{ env.tf_actions_working_dir }} |
| Workflow | ${{ github.workflow }} |
| Last updated | ${(new Date()).toUTCString()} |
`;
# | | |
# |-------------------|------------------------------------|
# | Pusher | @${{ github.actor }} |
# | Action | ${{ github.event_name }} |
# | Working Directory | ${{ env.tf_actions_working_dir }} |
# | Workflow | ${{ github.workflow }} |
# | Last updated | ${(new Date()).toUTCString()} |
# `;

// Call the script to write the comment
const script = require('./scripts/ghactions/comment-on-pr.js');
await script({github, context, core, commentTitle, commentBody});
# // Call the script to write the comment
# const script = require('./scripts/ghactions/comment-on-pr.js');
# await script({github, context, core, commentTitle, commentBody});
35 changes: 35 additions & 0 deletions ansible/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -191,6 +191,41 @@ When deploying files or updating files already existing on the hosts it can be u
This helps track down how files on the host were modified and why.
:::

#### Tagging convention

Tasks are tagged along two independent axes, so that `--tags`/`--skip-tags` can be used to run (or skip) a
meaningful slice of a playbook without guessing what else might be silently pulled in or left out:

* **Component tag** — matches the role name (`nginx`, `dehydrated`, `nftables`, `prometheus_node_exporter`,
`docker`, `ooniapi_gateway`, ...). Selects everything belonging to that role.
* **Phase tag** — a small, fixed vocabulary describing *what kind* of operation the task performs, independent of
which role it lives in:

| Tag | Meaning |
|--------------|----------------------------------------------------------------------------------------------------------------------|
| `packages` | apt/package installs — slow, safe to skip when nothing package-level changed |
| `config` | template/config file rendering — fast, safe to run often |
| `certs` | dehydrated cert issuance/renewal — rate-limited by Let's Encrypt, must be independently skippable (e.g. before DNS is cut over to a new host) |
| `network` | nftables rules and docker network setup |
| `service` | service enable/start/restart/reload operations |
| `monitoring` | prometheus/node_exporter wiring and health checks |
| `secrets` | sudoers rules and deploy-credential/password setup |

Most tasks should carry exactly one component tag and one phase tag.

Examples:
```
./play -i inventory deploy-monitoring-proxy.yml -l monitoringproxy.prod.ooni.io --tags config
./play -i inventory deploy-ooni-backend.yml -l backend-hel.ooni.org --skip-tags certs
./play -i inventory deploy-clickhouse-proxy.yml -l clickhouseproxy.prod.ooni.io --tags monitoring
```

:::note
This taxonomy is applied incrementally as roles are touched, not retrofitted across the whole codebase in one go
— currently `nginx`, `dehydrated`, and `prometheus_node_exporter` follow it. Don't assume every task elsewhere
already does.
:::

### Platform specific known bugs

On macOS you might run into this issue: https://github.com/ansible/ansible/issues/76322
Expand Down
3 changes: 3 additions & 0 deletions ansible/deploy-airflow.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,9 @@
vars:
airflow_public_fqdn: "airflow.prod.ooni.io"
tls_cert_dir: /var/lib/dehydrated/certs
event_detector_panel_domain: detector-panel.prod.ooni.io
ssl_domains:
- "data1.htz-fsn.prod.ooni.nu"
- "airflow.prod.ooni.io"
- "{{event_detector_panel_domain}}"
detector_panel_passwd: "{{ lookup('amazon.aws.aws_ssm', '/oonidevops/secrets/detector_panel_passwd', profile='oonidevops_user_prod') }}"
5 changes: 3 additions & 2 deletions ansible/deploy-clickhouse-proxy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,10 @@
become: true
roles:
- role: bootstrap
- role: nginx
- role: dehydrated
vars:
ssl_domains:
vars:
ssl_domains:
- "{{ inventory_hostname }}"
tls_cert_dir: /var/lib/dehydrated/certs
- role: clickhouse_proxy
Expand Down
10 changes: 5 additions & 5 deletions ansible/deploy-clickhouse.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
---
- name: Deploy oonidata clickhouse hosts
hosts:
- notebook1.htz-fsn.prod.ooni.nu
- notebook.ooni.org
- data1.htz-fsn.prod.ooni.nu
- data2.htz-fsn.prod.ooni.nu
- data3.htz-fsn.prod.ooni.nu
become: true
tags:
- clickhouse
roles:
- prometheus_node_exporter
- oonidata_clickhouse
- role: prometheus_node_exporter
tags: [node_exporter]
- role: oonidata_clickhouse
tags: [clickhouse]
23 changes: 23 additions & 0 deletions ansible/deploy-echo-test-helper.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
- name: Deploy test helpers
hosts:
- echo.th.dev.ooni.io
- echo.th.prod.ooni.io
become: true
roles:
- role: bootstrap
- role: prometheus_node_exporter
vars:
node_exporter_port: 9100
node_exporter_host: "0.0.0.0"
prometheus_nginx_proxy_config:
- location: /metrics/node_exporter
proxy_pass: http://127.0.0.1:9100/metrics
use_https: false
http_port: 8080 # if we leave port 80, it's taken by nginx
- role: test_helpers
vars:
helper: ooechohelpd
# sha256 of https://github.com/ooni/ooniprobe-rs/releases/download/v0.1.6/ooechohelpd
test_helpers_checksum: 10511a8b918c2244eba9e17c32f3cec9efbc5ffa51d6ad7f59fe648cd0986615
port: 80
22 changes: 22 additions & 0 deletions ansible/deploy-fastpath.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,28 @@
- fastpath2.prod.ooni.io
- reuploaderfastpath.prod.ooni.io
become: true
vars:
nginx_install_method: official_repo
pre_tasks:
- name: Find any nginx.org apt source files left over from a previous nginxinc.nginx install
ansible.builtin.find:
paths: /etc/apt/sources.list.d
patterns: "*.list"
contains: "nginx\\.org/packages"
read_whole_file: true
register: _stale_nginx_apt_sources
tags:
- nginx
- packages

- name: Remove stale nginx.org apt source files (avoids "Conflicting values set for option Signed-By")
ansible.builtin.file:
path: "{{ item.path }}"
state: absent
loop: "{{ _stale_nginx_apt_sources.files }}"
tags:
- nginx
- packages
roles:
- role: bootstrap
- role: nginx
Expand Down
23 changes: 23 additions & 0 deletions ansible/deploy-json-test-helper.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
- name: Deploy test helpers
hosts:
- json.th.dev.ooni.io
- json.th.prod.ooni.io
become: true
roles:
- role: bootstrap
- role: prometheus_node_exporter
vars:
node_exporter_port: 9100
node_exporter_host: "0.0.0.0"
prometheus_nginx_proxy_config:
- location: /metrics/node_exporter
proxy_pass: http://127.0.0.1:9100/metrics
use_https: false
http_port: 8080 # if we leave port 80, it's taken by nginx
- role: test_helpers
vars:
helper: oojsonhelpd
# sha256 of https://github.com/ooni/ooniprobe-rs/releases/download/v0.1.6/oojsonhelpd
test_helpers_checksum: 3d977e1418ea398f520dff3de951e36010a294dc3d1b564c961542cc3729a224
port: 80
4 changes: 2 additions & 2 deletions ansible/deploy-monitoring-proxy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,13 @@
become: true
roles:
- role: bootstrap
- role: nginx
tags: nginx
- role: dehydrated
vars:
ssl_domains:
- "{{ inventory_hostname }}"
tls_cert_dir: /var/lib/dehydrated/certs
- role: nginx
tags: nginx
- role: monitoring_proxy
vars:
monitoring_proxy_public_fqdn: "{{ inventory_hostname }}"
Expand Down
5 changes: 3 additions & 2 deletions ansible/deploy-notebook.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,14 @@
---
- name: Deploy notebook host
hosts: notebook1.htz-fsn.prod.ooni.nu
hosts: notebook.ooni.org
become: true
tags:
- notebook
vars:
notebook_domain: "notebook.ooni.org"
ssl_domains:
- "{{ inventory_hostname }}"
- "notebook.ooni.org"
roles:
- nginx
- dehydrated
- notebook
1 change: 1 addition & 0 deletions ansible/deploy-ooni-backend.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@
admin_group_name: adm
- role: base-backend
- role: nftables
- role: nginx
- role: dehydrated
tags: dehydrated
expand: yes
Expand Down
19 changes: 19 additions & 0 deletions ansible/deploy-wc-test-helper.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
- name: Deploy the Web Connectivity test helper
hosts:
- wc.th.dev.ooni.io
- wcth0.fra1.prod.ooni.io
- wcth1.fra1.prod.ooni.io
- wcth2.fra1.prod.ooni.io
become: true
vars:
nginx_install_method: official_repo
roles:
- role: bootstrap
- role: nginx
- role: dehydrated
- role: prometheus_node_exporter
vars:
use_https: true
https_port: 9001
- role: oohelperd
Loading
Loading