diff --git a/devserver/ansible/deploy-svc-events.yaml b/devserver/ansible/deploy-svc-events.yaml index 1f27b96..ca402ee 100644 --- a/devserver/ansible/deploy-svc-events.yaml +++ b/devserver/ansible/deploy-svc-events.yaml @@ -2,10 +2,11 @@ # Lightweight deploy: pull the latest events image and restart the # svc-events systemd service — without re-applying the whole playbook. # -# The svc-events run.sh already runs `docker compose up --pull=always`, so -# a plain `systemctl restart` would pull too. We pull explicitly first so -# that a registry/network failure surfaces *before* we take the running -# container down. +# Pull goes through run.sh so it runs in the same infisical context as +# the service: the events compose.yaml interpolates ${...} secrets that +# only infisical can provide. A bare `docker compose pull` would fail on +# those missing vars. We pull explicitly first so that a registry/network +# failure surfaces *before* we take the running container down. # # Run from devserver/ansible/: # ansible-playbook deploy-svc-events.yaml @@ -19,7 +20,7 @@ tasks: - name: Pull latest events image ansible.builtin.command: - cmd: docker compose pull + cmd: "{{ svc_events_deploy_dir }}/run.sh pull" chdir: "{{ svc_events_deploy_dir }}" changed_when: true register: _svc_events_pull diff --git a/devserver/ansible/roles/svc-events/templates/run.sh.j2 b/devserver/ansible/roles/svc-events/templates/run.sh.j2 index 4534d81..bd01bbd 100644 --- a/devserver/ansible/roles/svc-events/templates/run.sh.j2 +++ b/devserver/ansible/roles/svc-events/templates/run.sh.j2 @@ -1,8 +1,18 @@ #!/usr/bin/env bash # Runs the events compose stack with secrets injected at runtime by the -# infisical CLI. Invoked by svc-events.service. +# infisical CLI. Invoked by svc-events.service (and the deploy playbook). +# +# run.sh -> docker compose up +# run.sh pull -> docker compose pull +# run.sh -> docker compose set -euo pipefail +# Infisical machine-identity credentials. Sourced here (not via systemd +# EnvironmentFile=) so the script is self-contained when called outside +# systemd — e.g. by deploy-svc-events.yaml. +# shellcheck source=/dev/null +source {{ svc_events_env_file }} + # Exchange the machine-identity credentials for a short-lived access # token. We export into the environment rather than pass --token= so the # token never appears on a command line (visible via ps). @@ -12,14 +22,14 @@ export INFISICAL_TOKEN="$(infisical login \ --client-id="$SVC_EVENTS_INFISICAL_CLIENT_ID" \ --client-secret="$SVC_EVENTS_INFISICAL_CLIENT_SECRET")" -# infisical run injects the project's secrets into the environment of the -# process it spawns (the `docker compose` CLI), which (a) resolves ${VAR} -# interpolation in compose.yaml and (b) lets `environment: [VAR]` copy -# values into the container. See compose.yaml.j2 for the var list. +# infisical run injects the project's secrets into the environment of +# the process it spawns (the `docker compose` CLI), which (a) resolves +# ${VAR} interpolation in compose.yaml and (b) lets `environment: [VAR]` +# copy values into the container. See compose.yaml.j2 for the var list. # -# Note: `docker compose up` runs in the foreground so systemd (Type=simple) +# `docker compose up` runs in the foreground so systemd (Type=simple) # supervises it directly. exec infisical run \ --env=prod \ --projectId={{ svc_events_infisical_project_id }} \ - -- docker compose up + -- docker compose "${@:-up}" diff --git a/devserver/ansible/roles/svc-events/templates/svc-events.service.j2 b/devserver/ansible/roles/svc-events/templates/svc-events.service.j2 index e0e0a83..381f3b6 100644 --- a/devserver/ansible/roles/svc-events/templates/svc-events.service.j2 +++ b/devserver/ansible/roles/svc-events/templates/svc-events.service.j2 @@ -7,7 +7,6 @@ Wants=network-online.target [Service] Type=simple WorkingDirectory={{ svc_events_deploy_dir }} -EnvironmentFile={{ svc_events_env_file }} ExecStart={{ svc_events_deploy_dir }}/run.sh Restart=on-failure RestartSec=5