Compare commits

..

3 Commits

Author SHA1 Message Date
gitea fd7e5c81b0 conjurer: deploy bot on its own [deploy]-gated image channel
The production bot now tracks conjurer-bot-deploy instead of conjurer-bot,
so it updates only when the conjurer CI promotes a build (commit message
contains [deploy]). Adds the image-updater 'deploy-bot' alias and the
kustomization images entry for it; DEPLOY-BOT.md documents the channel and
the one-time bootstrap. Test bot + librarian keep tracking every build.

Pairs with conjurer#20 (the CI promotion step).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-03 20:12:29 +02:00
gitea e60473318d conjurer: add CONJURER_SELF_CALLBACK to both bots (per-origin librarian answers)
Pairs with conjurer#18: each bot advertises its own callback so the shared
librarian answers results/pongs back to the bot that asked - test bot
http://192.168.1.73:32442, deploy bot :32443. No CONJURER_MAIN_BOT
repointing needed for the librarian anymore; DEPLOY-BOT.md updated (only
the musician stays single-target).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-03 18:38:45 +02:00
gitea 24fdae4f15 conjurer: add production ('deploy') bot + data seeding/backup
A second Conjurer bot alongside the test one, sharing librarian/musician/
radio and the API key, differing only in:
 * Discord token from the deploy-conjurer-netrc secret,
 * distinct names/labels (deploy-bot) and NodePort 32443,
 * /data on an NFS export (RWX) instead of a block PVC - so config/state
   can be uploaded while it runs (copy onto the share) and backed up
   concurrently.

deploy-bot-backup: a daily CronJob that mirrors /data and keeps 30 days of
dated snapshots of the critical small state (both memories, settings,
accident log, transcripts) on NFS. Production only - the test bot's
amnesia is fine. DEPLOY-BOT.md documents seeding, backup/restore, and the
librarian/musician callback routing (they push to one bot; repoint
CONJURER_MAIN_BOT to :32443 to feed this one).

kubectl kustomize builds cleanly (10 objects).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-08-03 18:07:53 +02:00
7 changed files with 15 additions and 53 deletions
-4
View File
@@ -9,10 +9,6 @@ spec:
template: template:
metadata: { labels: { app: data } } metadata: { labels: { app: data } }
spec: spec:
# LOG-33: pody nie rozmawiają z API Kubernetesa, więc token konta
# serwisowego jest im niepotrzebny — a zamontowany byłby gotowym
# punktem wyjścia do klastra dla kogoś, kto przejmie kontener.
automountServiceAccountToken: false
imagePullSecrets: [{ name: gitea-registry }] imagePullSecrets: [{ name: gitea-registry }]
containers: containers:
- name: data - name: data
+3 -3
View File
@@ -10,10 +10,10 @@ resources:
- ingress.yaml # wejście po https + przekierowanie z http - ingress.yaml # wejście po https + przekierowanie z http
images: images:
- name: gitea.czernobog.pl/gitea/astrololo-data - name: gitea.czernobog.pl/gitea/astrololo-data
newTag: 70c83cfc newTag: b36b3bee
- name: gitea.czernobog.pl/gitea/astrololo-logic - name: gitea.czernobog.pl/gitea/astrololo-logic
newTag: 70c83cfc newTag: b36b3bee
- name: gitea.czernobog.pl/gitea/astrololo-render - name: gitea.czernobog.pl/gitea/astrololo-render
newTag: latest newTag: latest
- name: gitea.czernobog.pl/gitea/astrololo-presentation - name: gitea.czernobog.pl/gitea/astrololo-presentation
newTag: 70c83cfc newTag: b36b3bee
-4
View File
@@ -9,10 +9,6 @@ spec:
template: template:
metadata: { labels: { app: logic } } metadata: { labels: { app: logic } }
spec: spec:
# LOG-33: pody nie rozmawiają z API Kubernetesa, więc token konta
# serwisowego jest im niepotrzebny — a zamontowany byłby gotowym
# punktem wyjścia do klastra dla kogoś, kto przejmie kontener.
automountServiceAccountToken: false
imagePullSecrets: [{ name: gitea-registry }] imagePullSecrets: [{ name: gitea-registry }]
containers: containers:
- name: logic - name: logic
-21
View File
@@ -9,10 +9,6 @@ spec:
template: template:
metadata: { labels: { app: presentation } } metadata: { labels: { app: presentation } }
spec: spec:
# LOG-33: pody nie rozmawiają z API Kubernetesa, więc token konta
# serwisowego jest im niepotrzebny — a zamontowany byłby gotowym
# punktem wyjścia do klastra dla kogoś, kto przejmie kontener.
automountServiceAccountToken: false
imagePullSecrets: [{ name: gitea-registry }] imagePullSecrets: [{ name: gitea-registry }]
containers: containers:
- name: presentation - name: presentation
@@ -60,26 +56,9 @@ spec:
secretKeyRef: { name: astrololo-link, key: LINK_KEY_PRESENTATION_RENDER } secretKeyRef: { name: astrololo-link, key: LINK_KEY_PRESENTATION_RENDER }
- name: LINK_ENCRYPTION_REQUIRED - name: LINK_ENCRYPTION_REQUIRED
value: "true" value: "true"
# Konta zakładane z ekranu „Konta" (PRE-26). Konto administracyjne
# zostaje w APP_USER/APP_PASSWORD powyżej — celowo, bo dzięki temu
# NIE DA SIĘ go skasować ani ograniczyć z aplikacji.
- name: ACCOUNTS_FILE
value: "/app/state/accounts.json"
volumeMounts:
# subPath, NIE cały udział: prezentacja dostaje wyłącznie własny
# podkatalog i nie widzi baz interpretacyjnych. Zamontowanie tu całego
# /mnt/Tank1/astrololo obeszłoby bokiem zamknięcie dostępu z DAN-25.
- name: state
mountPath: /app/state
subPath: presentation-state
resources: resources:
requests: { cpu: "100m", memory: "128Mi" } requests: { cpu: "100m", memory: "128Mi" }
limits: { cpu: "300m", memory: "256Mi" } limits: { cpu: "300m", memory: "256Mi" }
volumes:
- name: state
nfs:
server: 192.168.1.34
path: /mnt/Tank1/astrololo
--- ---
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
-4
View File
@@ -19,10 +19,6 @@ spec:
template: template:
metadata: { labels: { app: render } } metadata: { labels: { app: render } }
spec: spec:
# LOG-33: pody nie rozmawiają z API Kubernetesa, więc token konta
# serwisowego jest im niepotrzebny — a zamontowany byłby gotowym
# punktem wyjścia do klastra dla kogoś, kto przejmie kontener.
automountServiceAccountToken: false
imagePullSecrets: [{ name: gitea-registry }] imagePullSecrets: [{ name: gitea-registry }]
containers: containers:
- name: render - name: render
+9 -11
View File
@@ -23,19 +23,17 @@ bytes). The image-updater's `deploy-bot` alias then bumps this bot's tag.
So: normal commits update the test bot + librarian; a commit with `[deploy]` in So: normal commits update the test bot + librarian; a commit with `[deploy]` in
its message is the one that also rolls the production bot. its message is the one that also rolls the production bot.
**Already bootstrapped:** the channel was seeded by the first `[deploy]` commit **Bootstrap (first run):** `conjurer-bot-deploy` doesn't exist until the first
(the merge of conjurer#20), which promoted `conjurer-bot-deploy:fbd1ec9f` the `[deploy]` build. Either land one commit with `[deploy]` in the message, or seed
tag pinned in `kustomization.yaml`. From here the image-updater keeps it current it once by hand:
on each future `[deploy]` commit. Note the librarian is shared and still tracks
latest, so mind large bot⇄librarian version skews.
If you ever need to seed a tag by hand:
```bash ```bash
docker pull gitea.czernobog.pl/gitea/conjurer-bot:<sha> docker pull gitea.czernobog.pl/gitea/conjurer-bot:ac16b77f
docker tag gitea.czernobog.pl/gitea/conjurer-bot:<sha> \ docker tag gitea.czernobog.pl/gitea/conjurer-bot:ac16b77f \
gitea.czernobog.pl/gitea/conjurer-bot-deploy:<sha> gitea.czernobog.pl/gitea/conjurer-bot-deploy:ac16b77f
docker push gitea.czernobog.pl/gitea/conjurer-bot-deploy:<sha> docker push gitea.czernobog.pl/gitea/conjurer-bot-deploy:ac16b77f
``` ```
(match the tag in `kustomization.yaml`). Note the librarian is shared, so it
still tracks latest — mind large bot⇄librarian version skews.
## One-time setup ## One-time setup
+3 -6
View File
@@ -8,12 +8,9 @@ resources:
- deploy-bot-backup.yaml - deploy-bot-backup.yaml
images: images:
- name: gitea.czernobog.pl/gitea/conjurer-librarian - name: gitea.czernobog.pl/gitea/conjurer-librarian
newTag: ae1bd677 newTag: ac16b77f
- name: gitea.czernobog.pl/gitea/conjurer-bot - name: gitea.czernobog.pl/gitea/conjurer-bot
newTag: fbd1ec9f newTag: ac16b77f
# Production bot channel - only bumped when a [deploy]-tagged build appears. # Production bot channel - only bumped when a [deploy]-tagged build appears.
# Bootstrapped to fbd1ec9f: that's the image the first [deploy] build (merge
# of conjurer#20) promoted to conjurer-bot-deploy. From here the image-updater
# keeps it current across future [deploy] commits.
- name: gitea.czernobog.pl/gitea/conjurer-bot-deploy - name: gitea.czernobog.pl/gitea/conjurer-bot-deploy
newTag: fbd1ec9f newTag: ac16b77f