Commit graph

92 commits

Author SHA1 Message Date
FluxCD
e6a4b27737 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771097039-30e0322 2026-02-14 19:26:34 +00:00
FluxCD
30e032207f chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771096857-26dc35f 2026-02-14 19:23:35 +00:00
FluxCD
26dc35f58a chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771096678-7c9d014 2026-02-14 19:20:33 +00:00
FluxCD
7c9d014c6b chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771096497-ecfa150 2026-02-14 19:17:35 +00:00
FluxCD
ecfa1500ec chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771096328-99da7e0 2026-02-14 19:14:33 +00:00
FluxCD
99da7e0299 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771096058-5df5c97 2026-02-14 19:11:33 +00:00
FluxCD
933cb7fc5f chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771095731-cb0c6e7 2026-02-14 19:08:24 +00:00
FluxCD
cb0c6e79fb chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771095546-66ea0e2 2026-02-14 19:01:44 +00:00
FluxCD
66ea0e256b chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771095367-61dfe82 2026-02-14 18:58:42 +00:00
FluxCD
61dfe82ca9 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771095194-d26a070 2026-02-14 18:55:44 +00:00
FluxCD
d26a0701cb chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771094551-f837178 2026-02-14 18:52:49 +00:00
FluxCD
f8371783cf chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771094368-530bf01 2026-02-14 18:42:07 +00:00
FluxCD
530bf01bba chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771094191-9f0211f 2026-02-14 18:39:04 +00:00
FluxCD
9f0211f140 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771094000-c59a852 2026-02-14 18:36:07 +00:00
FluxCD
ed7542b94a chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771090131-e9e1a29 2026-02-14 17:31:28 +00:00
FluxCD
e9e1a29684 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089953-61cfd3c 2026-02-14 17:28:25 +00:00
FluxCD
61cfd3c0d3 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089769-d9de116 2026-02-14 17:25:29 +00:00
FluxCD
d9de116a7e chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089591-661ed97 2026-02-14 17:22:27 +00:00
FluxCD
661ed97622 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089406-67a0b10 2026-02-14 17:19:27 +00:00
FluxCD
67a0b10ea5 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089224-e8449f6 2026-02-14 17:16:24 +00:00
FluxCD
e8449f67e5 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771089049-3e5dce3 2026-02-14 17:13:23 +00:00
FluxCD
3e5dce35a0 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771088871-4e2910a 2026-02-14 17:10:24 +00:00
FluxCD
4e2910a1b2 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771088688-dd25098 2026-02-14 17:07:23 +00:00
b47b00d9e0
fix: exclude cert-manager and traefik resources from FluxCD kustomization
These CRDs are not available for FluxCD dry-run validation, causing the
kustomization to fail. Apply certificate.yaml and ingressroute.yaml
manually instead.
2026-02-14 11:05:20 -06:00
FluxCD
dd250980ea chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771088502-3a9fffe 2026-02-14 17:04:25 +00:00
FluxCD
3a9fffe147 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771088322-7464376 2026-02-14 17:01:20 +00:00
FluxCD
746437644b chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771088140-0c99535 2026-02-14 16:58:16 +00:00
FluxCD
0c99535682 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771087964-d16bee5 2026-02-14 16:55:16 +00:00
FluxCD
d16bee59d8 chore: update towerops image to git.mcintire.me/graham/towerops-web:main-1771086677-8d00a04 2026-02-14 16:52:18 +00:00
8d00a04187
feat: add FluxCD image automation, fix Preseem duplicate AP crash
Switch deployment pipeline from GitLab Agent kubectl to FluxCD image
automation. CI now only builds and pushes tagged images to Forgejo
registry; FluxCD detects new tags and updates the deployment manifest.

Fix Ecto.MultipleResultsError on /dashboard when a device has multiple
Preseem access point records by using limit(1) instead of Repo.get_by.
2026-02-14 10:30:12 -06:00
17c5b681a3
back up to 2 replicas 2026-02-11 16:04:47 -06:00
92b4f0081a
reduce to one replica in prod for now 2026-02-11 15:38:07 -06:00
a97ae5ad09
Speed up Kubernetes rollouts
Changes:
- maxSurge: 1 → 100% (start all new pods simultaneously)
- minReadySeconds: 30 → 10 (faster promotion)
- readinessProbe successThreshold: 2 → 1 (faster health checks)

Result: Rollout time reduced from 6+ minutes to ~90 seconds while
maintaining zero downtime (maxUnavailable: 0 unchanged).
2026-02-04 15:16:16 -06:00
6b63dc9295
encryption updates 2026-02-01 17:05:55 -06:00
b709ae9fbe fix prod crash with yaml parsing 2026-01-31 08:25:07 -06:00
ef8d9199ba fix: add C NIF compilation to k8s Dockerfile
Match the root Dockerfile changes:
- Add libsnmp-dev build dependency
- Add libsnmp40 runtime dependency
- Copy c_src and compile C NIF before Elixir compilation
- Add TERM=dumb for cross-architecture builds
2026-01-30 13:06:18 -06:00
d29fb8cfd7 totp fixes 2026-01-28 16:16:59 -06:00
c694d452de
fix: add vendor directory and snmp package to k8s Dockerfile 2026-01-27 09:21:55 -06:00
7b6298f5dc
ecto ssl tweaks 2026-01-25 16:00:48 -06:00
76854479c9
update deployment 2026-01-25 15:29:38 -06:00
81f13f789b
revert: remove custom base image dependency from main Dockerfile
Reverted k8s/Dockerfile back to using official hexpm/elixir and debian
images directly instead of custom gmcintire/towerops-base images.

This restores the original Dockerfile behavior where all dependencies
are installed during each build. The base image work in k8s/base-image/
remains available but is not used by the main application build.
2026-01-25 11:12:37 -06:00
564caed3e5
refactor: rename base images to gmcintire/towerops-base
Changed image naming scheme from separate builder/runtime images to a
single image name with different tags:

- docker.io/gmcintire/towerops-base:builder
- docker.io/gmcintire/towerops-base:runtime
- docker.io/gmcintire/towerops-base:latest (alias for runtime)

This simplifies the naming and makes it clearer that both images are
part of the same towerops-base image family.

Changes:
- build.sh: Use IMAGE_NAME with BUILDER_TAG/RUNTIME_TAG
- Makefile: Update all targets to use new naming
- k8s/Dockerfile: Point to gmcintire/towerops-base:builder and :runtime
2026-01-25 09:33:42 -06:00
edd64479df
feat: create builder and runtime base images for faster deploys
Instead of installing system packages and tools on every deploy, we now
have two base images that pre-bake all the slow setup steps.

Base Images Created:
1. elixir-builder:latest - Builder stage base
   - hexpm/elixir with build-essential and git pre-installed
   - hex and rebar pre-installed
   - Saves ~40 seconds per deploy

2. debian-runtime:latest - Runtime stage base
   - Debian with all runtime packages pre-installed
   - Locale pre-configured (en_US.UTF-8)
   - /app directory pre-created
   - Saves ~60 seconds per deploy

Main Dockerfile Changes:
- Use elixir-builder:latest instead of hexpm/elixir
- Use debian-runtime:latest instead of debian:trixie-slim
- Remove apt-get install steps (now in base images)
- Remove hex/rebar install (now in builder base)
- Remove locale setup (now in runtime base)

Build System:
- build.sh builds both images with podman/docker auto-detect
- Pushes to both GitLab registry and Docker Hub
- Makefile targets for build/test/push/clean

Total Time Saved Per Deploy: ~100 seconds (1m40s)

Benefits:
- Faster CI/CD builds (no repeated apt-get install)
- Faster local development builds
- Consistent build environment across all deploys
- Security updates centralized in base image rebuilds
2026-01-25 09:29:22 -06:00
26a3b39edd
fix: correct paths for hexpm/elixir image structure
The hexpm images install Erlang and Elixir in /usr/local instead of /usr/lib.

Changes:
- Copy from /usr/local/lib/erlang instead of /usr/lib/erlang
- Copy all Erlang/Elixir binaries from /usr/local/bin
- Remove manual symlink creation (binaries already exist)
- Binaries are symlinks to ../lib/erlang/bin and ../lib/elixir/bin
2026-01-25 09:22:45 -06:00
7685fa53d1
fix: use official hexpm/elixir images instead of erlang-solutions repo
The Erlang Solutions APT repository was experiencing 504 Gateway Timeout
errors during builds, making the image build process unreliable.

Changes:
- Use official hexpm/elixir Docker image as builder stage
- More reliable (official Docker Hub images)
- Faster builds (pre-built binaries, no package installation)
- Still produces minimal runtime-only final image
- Updated documentation to reflect new approach

Benefits:
- No dependency on erlang-solutions CDN availability
- Faster build times (no apt-get install of large packages)
- Same minimal final image size (~150-200 MB)
- Easier to specify exact Erlang/Elixir versions
2026-01-25 09:21:42 -06:00
d92443d91b
feat: add podman support and Docker Hub push to base image builder
Enhanced base image build system with:

Container Engine Support:
- Auto-detect podman or docker (prefers podman if both installed)
- All scripts work with either engine seamlessly
- No configuration needed

Docker Hub Integration:
- Push to both GitLab and Docker Hub registries
- GitLab: registry.gitlab.com/towerops/towerops/elixir-runtime
- Docker Hub: docker.io/gmcintire/elixir-runtime
- Both versioned and :latest tags pushed to each

Build Script:
- Detect and use $CONTAINER_CMD for all operations
- Show which container engine is being used in output
- Tag and push to both registries automatically

Makefile:
- Add CONTAINER_CMD variable with auto-detection
- Add DOCKERHUB_REGISTRY configuration
- Update all targets to use detected container engine
- Add login-dockerhub target for Docker Hub authentication
- Update push target to push to both registries

Documentation:
- Document podman/docker auto-detection
- Update login instructions for both registries
- Update troubleshooting with examples for both engines

This makes the build system more flexible and accessible to users
who prefer podman over docker, while also publishing to the public
Docker Hub registry for easier access.
2026-01-25 09:18:03 -06:00
8f87d4bbab
feat: add custom minimal Debian base image build system
Created build system for minimal Debian 13 (Trixie) image with Erlang/OTP
and Elixir runtime pre-installed. This will speed up CI/CD builds by caching
the runtime environment.

Features:
- Multi-stage Dockerfile for minimal final image (~150-200 MB)
- Build script with automatic tagging (versioned, latest, dated)
- Update script for easy security patch rebuilds
- Makefile for common operations
- Comprehensive documentation (README + QUICKSTART)

Benefits:
- Faster CI/CD: Saves 30-60s per build (no apt-get install runtime deps)
- Smaller images: Only essential runtime packages included
- Security: Easy to rebuild weekly/monthly with latest patches
- Consistency: Same runtime across all environments

Usage:
  cd k8s/base-image
  make build    # Build the image
  make test     # Verify it works
  make push     # Push to registry

Then update k8s/Dockerfile to use the custom base image.

This replaces the previous Dockerfile.base approach with a more
comprehensive and maintainable build system.
2026-01-25 09:07:55 -06:00
29593ac734
refactor: migrate from etcd to Oban for distributed job coordination
Replaces etcd-based distributed locking with Oban's PostgreSQL-backed job queue.
This simplifies the architecture by eliminating the need for a separate etcd cluster
while providing better reliability and observability.

Changes:
- Add Oban dependency and migration (oban_jobs table)
- Create DevicePollerCoordinator and DeviceMonitorCoordinator Oban workers
- Remove EtcdCoordinator and EtcdLock modules
- Update application supervisor to start Oban
- Configure Oban with pollers (50 workers) and monitors (50 workers) queues
- Remove etcd StatefulSet from Kubernetes manifests
- Update monitoring supervisor documentation

Benefits:
- Simpler architecture (no etcd cluster to manage)
- PostgreSQL-based (uses existing database)
- Built-in uniqueness prevents duplicate jobs cluster-wide
- Better observability with Oban Web UI
- Automatic job rescue on node crashes
- Easier local development (no etcd required)

What was removed:
- etcd StatefulSet (3 pods)
- EtcdCoordinator module (320 lines)
- EtcdLock module (158 lines)
- eetcd dependency

All 3,686 tests passing.
2026-01-24 16:12:27 -06:00
979d246160
reduce replicas 2026-01-24 15:59:52 -06:00
be818b49b8
refactor: remove Valkey from K8s, move to Proxmox hosts
Removing all Valkey (Redis) resources from Kubernetes due to instability
caused by Flannel CNI networking issues. Redis will now run on Proxmox
hosts for better stability and performance.

Changes:
- Delete Valkey StatefulSet (master + 2 replicas)
- Delete Valkey Sentinel StatefulSet (3 instances)
- Delete Valkey services (headless and sentinel)
- Delete Valkey ConfigMap
- Remove Valkey resources from kustomization.yaml
- Update deployment to use towerops-redis secret for connection

Next Steps:
- Set up Redis Sentinel on 3 Proxmox hosts/LXC containers
- Create towerops-redis secret with REDIS_HOST and REDIS_PORT
- Test failover and application connectivity

Benefits:
- Not affected by K8s networking issues (Flannel failures)
- More stable (no restarts from node issues)
- Better performance (no K8s overhead)
- Independent lifecycle from K8s cluster
2026-01-24 14:12:02 -06:00