Skip to content

fix(decdn_node): create the fs cache-origin directory for kind: fs - #31

Merged
thiras merged 2 commits into
mainfrom
fix/issue-28-fs-cache-origin-dir
Jul 12, 2026
Merged

thiras merged 2 commits into
mainfrom
fix/issue-28-fs-cache-origin-dir

Conversation

@thiras

@thiras thiras commented Jul 12, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes #28. When decdn_cache_origin_kind: fs, the decdn_node role rendered [cache.origin] path = … into node.toml but never created that directory. The daemon's FilesystemOrigin::new fails fast on a missing/non-directory base path, and the unit is Restart=always/RestartSec=5 — so a kind: fs deploy that didn't pre-create the dir out-of-band crash-looped on every (re)start until an operator made it by hand.

Changes

  • roles/decdn_node/tasks/main.yml — new when: decdn_cache_origin_kind == "fs" task creating decdn_cache_origin_path (owner decdn:decdn, mode 0755, per the issue), placed after the existing data/cache/config dir task so the dir exists before install + systemd … started. Idempotent and check-mode safe. Only the base dir is role-managed; the sharded blobs ({path}/{hex[0..2]}/{hex}) remain an operator concern.
  • molecule/default/converge.yml — switched the default scenario's origin from http to fs (/var/lib/decdn/origin) so the new task actually runs in CI. prepare.yml deliberately does not pre-create that dir, so the assertion is non-vacuous. http-origin template coverage is retained by the generate-keystore and slow-readiness scenarios.
  • molecule/default/verify.yml — assert the dir exists as decdn:decdn/0755/directory, and extend the node.toml content check to the nested [cache.origin] table.

Verification

  • yamllint -c .yamllint and ansible-lint (production profile): clean.
  • molecule test --all: exit 0 — all three scenarios pass converge → idempotence → verify. The new task shows changed on converge and ok on idempotence (idempotent); the verify assertions pass.

Note: the molecule daemon is a stub, so this verifies the role's dir-creation contract (dir created with correct owner/group/mode), not the daemon crash-loop itself (that behavior lives in decdn/decdn).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added support for filesystem-based cache origins.
    • Automatically creates the configured cache origin directory with the expected ownership and permissions.
  • Bug Fixes

    • Improved deployment validation to confirm filesystem cache origin settings and directory readiness.

When `decdn_cache_origin_kind: fs`, the role rendered
`[cache.origin] path = {{ decdn_cache_origin_path }}` into node.toml but
never created that directory. The daemon's `FilesystemOrigin::new` fails
fast if the base path is missing or is not a directory, and the unit is
`Restart=always`/`RestartSec=5`, so a `kind: fs` deploy that didn't
pre-create the dir out-of-band crash-looped on every (re)start.

Add a `when: kind == fs` task that creates `decdn_cache_origin_path`
(owner decdn:decdn, mode 0755) right after the existing data/cache/config
dir task, making a `kind: fs` deploy self-contained. The sharded blob
files under it ({path}/{hex[0..2]}/{hex}) are content, not config, and
stay an operator concern — only the base dir is role-managed.

Test coverage: switch the molecule `default` scenario from an http origin
to an fs origin so the new task actually runs, and assert in verify.yml
that the dir exists as decdn:decdn/0755 plus a node.toml [cache.origin]
content check. http-origin template coverage is retained by the
generate-keystore and slow-readiness scenarios.

Closes #28

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 12, 2026 16:29
@coderabbitai

coderabbitai Bot commented Jul 12, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@thiras, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 52 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 50685c20-d927-4c91-b64d-1fd413d93ba3

📥 Commits

Reviewing files that changed from the base of the PR and between 599f034 and e3766b8.

📒 Files selected for processing (2)
  • ansible/molecule/default/verify.yml
  • ansible/roles/decdn_node/tasks/main.yml
📝 Walkthrough

Walkthrough

The role now provisions a filesystem cache-origin directory when configured for fs. Molecule uses this configuration and verifies the rendered origin settings and directory ownership, type, and permissions.

Changes

Filesystem cache origin

Layer / File(s) Summary
Provision filesystem cache origin
ansible/roles/decdn_node/tasks/main.yml
Creates the configured cache-origin path as a decdn:decdn directory with mode 0755 when fs is selected.
Molecule configuration and verification
ansible/molecule/default/converge.yml, ansible/molecule/default/verify.yml
Configures an fs origin at /var/lib/decdn/origin and verifies the rendered TOML values and directory properties.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related issues

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: creating the fs cache-origin directory in the decdn_node role.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/issue-28-fs-cache-origin-dir

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request configures and tests a filesystem pull-through origin (kind: fs) for the decdn_node role, ensuring that the base directory is automatically created with the correct ownership and permissions. Feedback on the changes suggests combining the Ansible assertion conditions in verify.yml into a single short-circuiting expression to prevent AnsibleUndefinedVariable errors if the directory does not exist.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread ansible/molecule/default/verify.yml Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes a deployment gap in the decdn_node Ansible role: when decdn_cache_origin_kind: fs, the role rendered an on-disk cache origin path into node.toml but didn’t create the corresponding directory, leading to daemon crash-loops on startup. It also updates the default Molecule scenario to exercise and verify this behavior in CI.

Changes:

  • Add a conditional Ansible task to create decdn_cache_origin_path when decdn_cache_origin_kind == "fs".
  • Switch Molecule default converge to use an fs origin and set a concrete origin path.
  • Extend Molecule verification to assert [cache.origin] content in node.toml and that the origin directory exists with correct ownership/mode.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 1 comment.

File Description
ansible/roles/decdn_node/tasks/main.yml Create the filesystem cache-origin base directory when kind: fs before install/service start.
ansible/molecule/default/converge.yml Configure the default Molecule scenario to use an fs origin so the new task runs in CI.
ansible/molecule/default/verify.yml Verify [cache.origin] TOML output and assert the origin directory exists with expected owner/group/mode.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread ansible/roles/decdn_node/tasks/main.yml Outdated
…t 0755 rationale

- verify.yml: combine the fs cache-origin dir assertions into one
  short-circuiting expression (file convention) so a missing dir routes to
  fail_msg instead of raising AnsibleUndefinedVariable on the absent
  pw_name/gr_name/mode — the regression this assert is meant to catch.
- tasks/main.yml: reword the 0755 rationale — 0755 grants no write, so drop
  the misleading "populate as a different user" claim; state that the blobs
  are public content and 0755 only widens read access if the path is
  relocated outside the 0700 parent.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@thiras
thiras merged commit 05d923a into main Jul 12, 2026
9 checks passed
@thiras
thiras deleted the fix/issue-28-fs-cache-origin-dir branch July 12, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

decdn_node role: create the fs cache-origin directory for kind: fs (daemon crash-loops otherwise)

2 participants