prole/infrastructure/playbooks/disable_pi_k3s.yml
chrisfu eb9430df9d fix(gitlab,infra): ARM64 RPi service cluster – GitLab deploy in gitlab ns on gandalf
Namespace & routing
- milestones.py: GitOpsMilestone now resolves namespace from
  gitops.gitlab_namespace (new) → Global.GITLAB_NAMESPACE → 'gitlab'
  hardcoded; never falls through to gitops.namespace (was 'gitea')
- prole.cfg: add gitops.gitlab_namespace=gitlab + GITLAB_NAMESPACE=gitlab
- init_gitlab.sh: NAMESPACE defaults to gitlab, NODE_SELECTOR blanked so
  only gitaly+minio are node-pinned; GITOPS_NAMESPACE fallback removed

GitLab on ARM64 RPi (16 KB kernel pages)
- init_gitlab.sh: DaemonSet compiles jemalloc-5.3.0 with --with-lg-page=14
  (glibc/Ubuntu) on every node; LD_PRELOAD injected per Ruby component
- Minio: quay.io 2022 image (ARM64); configure init container replaced
  with ARM64 alpine that writes credential files; MINIO_ROOT_USER/PASSWORD
  injected directly into main container env via secretKeyRef
- Minio buckets auto-created post-deploy (registry, lfs, artifacts, etc.)
- webservice/sidekiq: replicaCount=1, reduced memory (1500M/800M),
  liveness probe initialDelaySeconds=3600 (Rails loads 25-40min on RPi)
- allowedHosts set as flat string list (chart 9.x default is list-of-maps
  which breaks URI initializer in 7_gitlab_http.rb)
- gitaly+minio always pinned to gandalf (local PV); other workloads spread

Storage
- Static PVs created for gitaly (50Gi) + minio (10Gi) on synology d005
- Synology dirs created before PVs; bucket creation idempotent

Redis (shared for GitLab KAS)
- init_redis.sh: persistence disabled (no dynamic provisioner); Redis used
  as pub/sub broker only

Infrastructure / pi.prole.org
- Removed pi.prole.org from [k3s_agents] – dedicated pihole node, OOM
- host_vars: k3s_enabled=false, k3s_state=absent (storage preserved)
- New playbook: infrastructure/playbooks/disable_pi_k3s.yml (drain + disable)
- monitoring.py: node-exporter DaemonSet excludes pi.prole.org
- init_monitoring.sh: pi.prole.org excluded from node-exporter affinity
- kong-deployment.yaml: affinity rule prevents scheduling on pi (pihole owns 80/443)

Co-authored-by: Junie <junie@jetbrains.com>
2026-04-02 20:15:11 -07:00

87 lines
2.6 KiB
YAML

---
# Disable k3s-agent on pi.prole.org and remove it from the cluster.
# Safe to run against a live cluster — only touches pi.prole.org.
# Storage (iSCSI) and pihole configuration are intentionally preserved.
#
# Usage:
# ansible-playbook -i inventory/hosts.ini playbooks/disable_pi_k3s.yml
# ansible-playbook -i inventory/hosts.ini playbooks/disable_pi_k3s.yml --check
- name: Drain and delete pi node from k3s control-plane
hosts: k3s_servers
gather_facts: false
become: true
tasks:
- name: Drain pi.prole.org (evict pods, ignore DaemonSets)
ansible.builtin.command:
cmd: kubectl drain pi.prole.org
--ignore-daemonsets
--delete-emptydir-data
--force
--timeout=120s
environment:
KUBECONFIG: /etc/rancher/k3s/k3s.yaml
register: _drain
changed_when: _drain.rc == 0
failed_when: false
- name: Delete pi node from cluster
ansible.builtin.command:
cmd: kubectl delete node pi.prole.org --ignore-not-found
environment:
KUBECONFIG: /etc/rancher/k3s/k3s.yaml
register: _delete_node
changed_when: "'deleted' in _delete_node.stdout"
failed_when: false
- name: Stop and disable k3s-agent on pi.prole.org
hosts: pi.prole.org
gather_facts: false
become: true
tasks:
- name: Gather minimal facts
ansible.builtin.setup:
gather_subset:
- min
- name: Check for k3s-agent systemd unit
ansible.builtin.stat:
path: /etc/systemd/system/k3s-agent.service
register: _agent_unit
- name: Stop k3s-agent service
ansible.builtin.systemd:
name: k3s-agent
state: stopped
enabled: false
when:
- _agent_unit.stat.exists | default(false)
- not ansible_check_mode
- name: Check for generic k3s systemd unit (agent variant)
ansible.builtin.stat:
path: /etc/systemd/system/k3s.service
register: _k3s_unit
- name: Stop k3s service if present (some installs use k3s not k3s-agent)
ansible.builtin.systemd:
name: k3s
state: stopped
enabled: false
when:
- _k3s_unit.stat.exists | default(false)
- not ansible_check_mode
failed_when: false
- name: Confirm k3s processes are not running
ansible.builtin.command: pgrep -c k3s
register: _k3s_procs
changed_when: false
failed_when: false
- name: Report k3s process status
ansible.builtin.debug:
msg: >-
k3s processes on pi.prole.org:
{{ 'NONE (clean)' if _k3s_procs.rc != 0 else _k3s_procs.stdout + ' process(es) still running' }}