| Age | Commit message (Collapse) | Author |
|
Colliding with the nightly generation CronJob's flock at the top of
some hours caused an intermittent EBADF failure. Move sync to two
fixed daytime ticks (10:00/18:00 Europe/Sofia) clear of the 04:00
generation run, and replace the mtime-based "did a generation
complete" check with a per-site content diff (image_count/
total_size_bytes vs a backed-up status.json from the last publish),
so a tick with no real content change is a no-op instead of an
unconditional publish.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
|
|
|
Track the shuriken.sh 0.14.0 release: Chart appVersion, generation +
sync CronJob image, docker-image/Justfile TAG, and README references.
|
|
Per feedback: the shuriken-sync CronJob now uses the rsync daemon
protocol (rsync://) instead of SSH -- no key/Secret needed. The
frontends run rsyncd via inetd with hosts allow *.wg0; k3s pods run on
r-nodes with .wg0 (WireGuard) connectivity, so they're authorized to
push over the mesh. Add writable irregular-ninja and alt-irregular-ninja
modules to frontends/etc/rsyncd.conf.tpl (deploy with rex rsync).
It only publishes when a generation has COMPLETED since the last sync:
shuriken now deletes dist/status.json at the start of a run and writes
it last on success, so status.json presence+freshness vs a .last-sync
marker on NFS is the completed/not-yet-published signal. Most ticks
skip; a publish fires once after each daily generation. hostAliases pin
the .wg0 frontend names to mesh IPs (cluster DNS doesn't resolve *.wg0).
The nfs-check initContainer stays so rsync --delete can't wipe the live
site if NFS is down. shuriken --sync over SSH stays as a manual option.
|
|
Per request, decouple publishing from generation: add a second
shuriken-sync CronJob that rsyncs /data/shuriken.sh/<site>/dist to
admin@fishfinger.buetow.org and admin@blowfish.buetow.org (with
--delete) every 4h -- far more often than the daily generate. rsync
is incremental, so post-generation publishes are cheap and a failed
publish retries on the next tick without re-running generation.
Reuses the shuriken image (now with openssh-client). Requires a
shuriken-rsync-ssh-key Secret holding the admin key authorized on
fishfinger/blowfish; until it exists the publish pods fail to mount
the key and publish nothing (safe by design -- no live publish
without the key). README documents the one-time Secret creation and
the image rebuild/push for openssh.
|
|
ArgoCD-managed CronJob that regenerates the irregular.ninja and
alt.irregular.ninja photo albums with the shuriken.sh Docker image,
writing them to /data/nfs/k3svolumes/shuriken.sh/<site>/dist on the
shared NFS export. Single image job by default (passively cooled N100
hosts). 04:00 Europe/Sofia daily, Forbid stacking, 6h deadline.
|