Add the playbook: container metrics on the Flatcar Docker hosts #1

Merged
mgbruin merged 2 commits from add-container-metrics into main 2026-09-22 18:02:17 +00:00
Owner

Second half of the deployment side of DWA-65. Deploys container_metrics (cAdvisor) to bix, inara and mara, pinned by tag at v0.1.0.

Why a separate repository

baseline installs and removes packages on every host it touches, and these hosts have no package manager at all — which is why baseline.yml already documents excluding them. Adding a play for them to that file would mean every run of one carrying the risk of the other.

fennec01 is deliberately absent

It is Flatcar too, but it is the Kubernetes node: kubespray owns its configuration, and its containers are already reported through kubelet's own cAdvisor. The flatcar group is the three Docker hosts only.

No collections

The playbook uses ansible.builtin only. A pinned-but-unused collection is one more copy to keep in step across playbook repositories for no benefit.

Verified

  • ansible-lint at the production profile: passed
  • yamllint: clean
  • the role installs from its tag: container_metrics (v0.1.0) was installed successfully
  • ansible-inventory --graph flatcar resolves to exactly bix, inara, mara
  • ansible-playbook --syntax-check passes with the role in place

⚠️ As with the role PR: river's pinned ansible-lint, yamllint and ansible-core shims are all broken (ModuleNotFoundError from the pipx installs), so mise run lint / setup / validate cannot currently run there. I used the same pinned versions through uvx. That is worth fixing on its own — right now no playbook or role repository can be linted on river through its own tooling.

Running it

mise run setup
mise run check    # dry run first
mise run ping     # reachability

The role pulls the cAdvisor image on first start, so the initial run takes a little longer than later ones; the task waits for /metrics to answer rather than declaring success when systemd reports active.

After this

The fennec side: scrape config for :9101 on the three hosts, alerts, and a dashboard. Worth holding until this has actually run, or the new targets simply alert as down.

Second half of the deployment side of DWA-65. Deploys `container_metrics` (cAdvisor) to bix, inara and mara, pinned by tag at **v0.1.0**. ## Why a separate repository `baseline` installs *and removes* packages on every host it touches, and these hosts have no package manager at all — which is why `baseline.yml` already documents excluding them. Adding a play for them to that file would mean every run of one carrying the risk of the other. ## fennec01 is deliberately absent It is Flatcar too, but it is the Kubernetes node: kubespray owns its configuration, and its containers are already reported through kubelet's own cAdvisor. The `flatcar` group is the three Docker hosts only. ## No collections The playbook uses `ansible.builtin` only. A pinned-but-unused collection is one more copy to keep in step across playbook repositories for no benefit. ## Verified - `ansible-lint` at the **production** profile: passed - `yamllint`: clean - the role installs from its tag: `container_metrics (v0.1.0) was installed successfully` - `ansible-inventory --graph flatcar` resolves to exactly `bix`, `inara`, `mara` - `ansible-playbook --syntax-check` passes with the role in place ⚠️ As with the role PR: river's pinned `ansible-lint`, `yamllint` and `ansible-core` shims are all broken (`ModuleNotFoundError` from the pipx installs), so `mise run lint` / `setup` / `validate` cannot currently run there. I used the same pinned versions through `uvx`. That is worth fixing on its own — right now no playbook or role repository can be linted on river through its own tooling. ## Running it ```bash mise run setup mise run check # dry run first mise run ping # reachability ``` The role pulls the cAdvisor image on first start, so the initial run takes a little longer than later ones; the task waits for `/metrics` to answer rather than declaring success when systemd reports active. ## After this The fennec side: scrape config for `:9101` on the three hosts, alerts, and a dashboard. Worth holding until this has actually run, or the new targets simply alert as down.
bix, inara and mara run Docker outside Kubernetes and exported nothing
about it. This deploys container_metrics (cAdvisor) to them, pinned by
tag at v0.1.0 (DWA-65).

A separate repository rather than a play inside baseline, because
baseline installs and removes packages on every host it touches and
these hosts have no package manager at all. That exclusion is already
stated in baseline.yml; sharing a file would mean every run of one
carrying the risk of the other.

fennec01 is Flatcar too and is deliberately absent: kubespray owns its
configuration, and its containers are already reported through kubelet's
own cAdvisor.

No collections pinned. This playbook uses ansible.builtin only, and a
pinned-but-unused collection is another copy to keep in step for nothing.

Verified: ansible-lint at the production profile and yamllint both clean,
the role installs from its tag, `ansible-inventory --graph flatcar`
resolves to the three hosts, and --syntax-check passes with the role in
place.
Same fix as the other repositories (DWA-71), folded into this PR because
this repository's mise.toml arrives with it -- a separate PR would have
to wait for this one to merge before it had a file to change.
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
mgbruin/ansible_playbook_flatcar!1
No description provided.