Repository navigation
feat(ansible): prepare the launch fleet (private overlay, catalogue sizing, runbook) - #67
Merged
Merged
Conversation
…izing, runbook) Readies the devops side of the 2026-09-28 testnet launch (decdn/internal Launch/fleet-plan.md): - Keep real inventory out of this public repo: git-ignore inventory/hosts.yml, add INVENTORY=<path> to check/deploy (with the same env/empty guards as LIMIT), and move the udp/4433 firewall hole to playbooks/group_vars so a private overlay passed with -i cannot deploy nodes with QUIC firewalled off. - inventory/fleet.example/: launch-fleet overlay template grouped by role (seed = fs origin for seed-model.sh, edge = pull-through) and billing (metered = egress budget). It sizes max_blob_size_mb to 16 GiB, because origin import stores each file as one blob and the catalogue's largest file is 13.5 GiB (measured from HF). The 1 GiB default would BlobTooLarge every model. - docs/launch-runbook.md: deploy -> stake/register -> seed -> pin -> verify. - SECURITY.md with the pinned release-key fingerprint. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved moderate issues remain in deployment safety, secret-file protection, and storage sizing.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Prepares Ansible for the 2026-09-28 testnet launch with private fleet overlays, large-model storage sizing, firewall preservation, and operational documentation.
Changes:
- Adds guarded private inventory selection and secret protection.
- Adds seed/edge fleet templates with cache and blob sizing.
- Documents deployment, verification, release signing, and launch operations.
| File | Summary | Review notes |
|---|---|---|
SECURITY.md |
Adds vulnerability reporting and release-key guidance. | Nit (1 vote): Qualify release guarantees when signature verification is disabled. |
ansible/README.md |
Documents private fleet overlays and deployment usage. | Moderate (1 vote): Protect copied overlays from accidentally tracking secret.yml. |
ansible/playbooks/group_vars/decdn_nodes.yml |
Makes the QUIC firewall rule inventory-independent. | — |
ansible/Makefile |
Adds guarded inventory selection. | Moderate (2 votes): Validate that the default inventory exists or require an explicit overlay. |
ansible/inventory/hosts.yml.example |
Updates public inventory guidance. | — |
ansible/inventory/group_vars/decdn_nodes.yml |
Documents firewall-rule relocation. | — |
ansible/inventory/fleet.example/hosts.yml |
Defines launch fleet topology and regions. | — |
ansible/inventory/fleet.example/host_vars/fsn1-a/secret.yml.example |
Provides an optional RPC secret template. | — |
ansible/inventory/fleet.example/group_vars/decdn_unmetered.yml |
Documents unmetered billing behavior. | — |
ansible/inventory/fleet.example/group_vars/decdn_seed.yml |
Configures filesystem origins. | — |
ansible/inventory/fleet.example/group_vars/decdn_nodes.yml |
Configures binaries, contracts, cache sizing, and pins. | Nit (1 vote): Add the authoritative ADR reference for protocol values here and in the runbook. |
ansible/inventory/fleet.example/group_vars/decdn_metered.yml |
Configures metered egress budgeting. | — |
ansible/inventory/fleet.example/group_vars/decdn_edge.yml |
Documents edge pull-through behavior. | — |
ansible/docs/launch-runbook.md |
Documents deployment and launch operations. | Moderate (1 vote): State the roughly 760 GiB storage requirement. Nit (1 vote): Provide the complete decdn setup dry-run and execution commands. |
ansible/.gitignore |
Ignores real inventories and nested secrets. | — |
AGENTS.md |
Updates inventory and deployment conventions. | — |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…, setup) - check/deploy now fail on a missing or unparseable inventory (ANSIBLE_INVENTORY_UNPARSED_FAILED on those recipes). Without it a mistyped INVENTORY= warned, skipped the play, and exited 0. It isn't set in ansible.cfg because ansible-lint's syntax checks run with no inventory and would break. - fleet.example/.gitignore travels with `cp -r`, so the private overlay ignores host_vars/*/secret.* too. - Runbook: seeds need origin + cache + headroom (about 760 GiB with template values), plus hf staging while seeding; exact `decdn setup` command via systemd-run with the unit's EnvironmentFile (the RPC key stays out of argv), with ADR 019/026/030 citations. - SECURITY.md: the tarball guarantee holds only with signature verification on in release mode; manual mode verifies nothing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Replies to the notes in the review overview table (fixes in ace223a):
Re-run after the fixes: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Devops side of the 2026-09-28 testnet launch (
decdn/internalLaunch/fleet-plan.md).Why
decdn origin importstores each file as one whole-file blob (--optimizeonly adds chunk hints to the manifest), and the node rejects anything overmax_blob_size_mbwithBlobTooLarge. The role default is 1 GiB. Measured from the HF trees of theseed-model.shset: the largest file is 13.5 GiB (Mistral v0.3consolidated.safetensors, the hero model), and the whole set is about 352 GiB.hosts.ymlcould be committed, and the release checklist forbids private host IPs in public repos. Moving the fleet to a private overlay (-i) would also have silently dropped the udp/4433 firewall hole, which lived in inventory-adjacent group_vars.What
inventory/hosts.ymlis now git-ignored.make check|deploy INVENTORY=<path>has the same env/empty guards asLIMIT.playbooks/group_vars/decdn_nodes.yml, which loads for every inventory.inventory/fleet.example/: launch overlay template. Role groups:decdn_seed(fs origin at/var/lib/decdn/origin, whereseed-model.shwrites) anddecdn_edge(pull-through). Billing groups:decdn_metered(egress budget) anddecdn_unmetered. It setsmax_blob_size_mb: 16384and a 400 GiB cache, and makesdecdn_regionper host.ansible/docs/launch-runbook.md: deploy → stake/register → seed → pin → verify → flip to release at v0.1.0.SECURITY.mdwith the pinned release-key fingerprint. The org has no default one.Not in this PR: the flip to
install_method: release. It waits for thev0.1.0tag, and upstream has none yet.Tested
make lintandmake lint-ansible(production profile): passansible-playbook --syntax-checkwith both the CI dummy inventory andfleet.example: passmake molecule(all scenarios): exit 0baseline_extra_inboundresolves to udp/4433 under bothinventory/hosts.ymland the overlaymake -nconfirmed theINVENTORYguards (empty value and env-set value both refused)🤖 Generated with Claude Code