7 Commits

Author SHA1 Message Date
605525c7ba Merge pull request #27 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner4
feat: Add traefik configuration for consensus TCP port, open it in firewall
2024-08-13 13:36:58 +02:00
5bdeb0fcfa feat: Add traefik configuration for consensus TCP port, open it in
firewall
2024-08-13 13:32:10 +02:00
bf186104d4 Merge pull request #26 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner3
fix: Correct path and file names for consensus
2024-08-12 17:33:38 +02:00
493e5ceffc fix: Correct path and file names for consensus 2024-08-12 17:31:25 +02:00
7a77daacf3 Merge pull request #25 from matter-labs/ya-zkd-1817-upgrade-external-nodes-on-hetzner2
fix: Correct task names
2024-08-12 17:10:16 +02:00
8290a1cd9b Yaml lint 2024-08-12 15:32:48 +02:00
191ebeced5 fix: Correct task names 2024-08-12 14:55:50 +02:00
3 changed files with 26 additions and 10 deletions

View File

@ -49,6 +49,14 @@
source: "{{ loadbalancer_ip | mandatory }}" source: "{{ loadbalancer_ip | mandatory }}"
jump: ACCEPT jump: ACCEPT
- name: Allow consensus port traffic from any IP
when: enable_consensus
ansible.builtin.iptables:
chain: INPUT
protocol: tcp
destination_port: "{{ consensus_port }}"
jump: ACCEPT
- name: Set default policy to DROP - name: Set default policy to DROP
ansible.builtin.iptables: ansible.builtin.iptables:
chain: INPUT chain: INPUT

View File

@ -38,7 +38,7 @@
when: vars[item] == "" when: vars[item] == ""
with_items: "{{ en_required_variables }}" with_items: "{{ en_required_variables }}"
- name: Copy main configs - name: Create main configs
ansible.builtin.template: ansible.builtin.template:
src: '{{ item.src }}' src: '{{ item.src }}'
dest: '{{ item.dest }}' dest: '{{ item.dest }}'
@ -51,7 +51,7 @@
- src: "templates/postgres.env.j2" - src: "templates/postgres.env.j2"
dest: "{{ configuration_directory }}/postgres.env" dest: "{{ configuration_directory }}/postgres.env"
- name: Copy restore script - name: Create restore script
register: restore_dump_script register: restore_dump_script
ansible.builtin.template: ansible.builtin.template:
src: 'templates/restore_dump.sh.j2' src: 'templates/restore_dump.sh.j2'
@ -64,7 +64,7 @@
when: enable_monitoring and ( vars[item] == "" ) when: enable_monitoring and ( vars[item] == "" )
with_items: "{{ monitoring_required_variables }}" with_items: "{{ monitoring_required_variables }}"
- name: Copy monitoring configs - name: Create monitoring configs
when: enable_monitoring when: enable_monitoring
ansible.builtin.template: ansible.builtin.template:
src: '{{ item.src }}' src: '{{ item.src }}'
@ -76,7 +76,7 @@
- src: "templates/vmagent-config.yml.j2" - src: "templates/vmagent-config.yml.j2"
dest: "{{ configuration_directory }}/vmagent-config.yml" dest: "{{ configuration_directory }}/vmagent-config.yml"
- name: Copy main configs - name: Create consensus config
when: enable_consensus when: enable_consensus
ansible.builtin.template: ansible.builtin.template:
src: "templates/consensus_config.yaml.j2" src: "templates/consensus_config.yaml.j2"
@ -88,7 +88,7 @@
ansible.builtin.copy: ansible.builtin.copy:
src: "{{ consensus_secrets_file }}" src: "{{ consensus_secrets_file }}"
dest: "{{ configuration_directory }}/consensus_secrets.yaml" dest: "{{ configuration_directory }}/consensus_secrets.yaml"
decrypt: yes decrypt: true
mode: '0600' mode: '0600'
- name: Run docker-compose without monitoring - name: Run docker-compose without monitoring

View File

@ -8,10 +8,13 @@ services:
- "--log.level=INFO" - "--log.level=INFO"
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80" - "--entryPoints.web.address=:80"
- "--entrypoints.external_node_health.address=:3080" - "--entryPoints.external_node_health.address=:3080"
{% if enable_consensus %}
- "--entryPoints.external_node_consensus.address=:{{ consensus_port }}"
{% endif %}
{% if enable_tls %} {% if enable_tls %}
- "--entrypoints.websecure.address=:443" - "--entryPoints.websecure.address=:443"
- "--certificatesresolvers.en_resolver.acme.tlschallenge=true" - "--certificatesresolvers.en_resolver.acme.tlschallenge=true"
- "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json" - "--certificatesresolvers.en_resolver.acme.storage=/letsencrypt/acme.json"
- "--certificatesresolvers.myresolver.acme.email={{ acme_email }}" - "--certificatesresolvers.myresolver.acme.email={{ acme_email }}"
@ -76,6 +79,11 @@ services:
{% if enable_basic_auth %} {% if enable_basic_auth %}
- "traefik.http.routers.external_node_main.middlewares=external_node_auth" - "traefik.http.routers.external_node_main.middlewares=external_node_auth"
- "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}" - "traefik.http.middlewares.external_node_auth.basicauth.users={{ basic_auth_secret }}"
{% endif %}
{% if enable_consensus %}
- "traefik.tcp.services.external_node_consensus.loadbalancer.server.port={{ consensus_port }}"
- "traefik.tcp.routers.external_node_consensus.entrypoints=external_node_consensus"
- "traefik.tcp.routers.external_node_consensus.service=external_node_consensus"
{% endif %} {% endif %}
expose: expose:
- {{ rpc_http_port }} - {{ rpc_http_port }}
@ -101,7 +109,7 @@ services:
RUST_LOG: {{ rust_log }} RUST_LOG: {{ rust_log }}
{% if enable_consensus %} {% if enable_consensus %}
EN_CONSENSUS_CONFIG_PATH: /etc/consensus_config.yaml EN_CONSENSUS_CONFIG_PATH: /etc/consensus_config.yaml
EN_CONSENSUS_SECRETS_PATH: /run/secrets/consensus_secrets.yaml EN_CONSENSUS_SECRETS_PATH: /run/secrets/consensus_secrets
{% endif %} {% endif %}
healthcheck: healthcheck:
test: [ "CMD", "curl", "-f", "http://localhost:{{ healthcheck_port }}/health" ] test: [ "CMD", "curl", "-f", "http://localhost:{{ healthcheck_port }}/health" ]
@ -112,7 +120,7 @@ services:
volumes: volumes:
- "{{ storage_directory }}/db:/db" - "{{ storage_directory }}/db:/db"
{% if enable_consensus %} {% if enable_consensus %}
- "consensus_config.yaml:/etc/consensus_config.yaml" - "{{ configuration_directory }}/consensus_config.yaml:/etc/consensus_config.yaml"
{% endif %} {% endif %}
env_file: env_file:
- "external_node.env" - "external_node.env"