Skip to content

feat(ansible): prepare the launch fleet (private overlay, catalogue sizing, runbook) - #67

Merged
thiras merged 2 commits into
mainfrom
feat/launch-fleet-readiness
Sep 22, 2026
Merged

thiras merged 2 commits into
mainfrom
feat/launch-fleet-readiness

Conversation

@thiras

@thiras thiras commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Devops side of the 2026-09-28 testnet launch (decdn/internal Launch/fleet-plan.md).

Why

  • Blob cap was a launch blocker. decdn origin import stores each file as one whole-file blob (--optimize only adds chunk hints to the manifest), and the node rejects anything over max_blob_size_mb with BlobTooLarge. The role default is 1 GiB. Measured from the HF trees of the seed-model.sh set: the largest file is 13.5 GiB (Mistral v0.3 consolidated.safetensors, the hero model), and the whole set is about 352 GiB.
  • Public repo, real IPs. hosts.yml could be committed, and the release checklist forbids private host IPs in public repos. Moving the fleet to a private overlay (-i) would also have silently dropped the udp/4433 firewall hole, which lived in inventory-adjacent group_vars.

What

  • inventory/hosts.yml is now git-ignored. make check|deploy INVENTORY=<path> has the same env/empty guards as LIMIT.
  • The QUIC hole moved to playbooks/group_vars/decdn_nodes.yml, which loads for every inventory.
  • inventory/fleet.example/: launch overlay template. Role groups: decdn_seed (fs origin at /var/lib/decdn/origin, where seed-model.sh writes) and decdn_edge (pull-through). Billing groups: decdn_metered (egress budget) and decdn_unmetered. It sets max_blob_size_mb: 16384 and a 400 GiB cache, and makes decdn_region per host.
  • ansible/docs/launch-runbook.md: deploy → stake/register → seed → pin → verify → flip to release at v0.1.0.
  • SECURITY.md with the pinned release-key fingerprint. The org has no default one.

Not in this PR: the flip to install_method: release. It waits for the v0.1.0 tag, and upstream has none yet.

Tested

  • make lint and make lint-ansible (production profile): pass
  • ansible-playbook --syntax-check with both the CI dummy inventory and fleet.example: pass
  • make molecule (all scenarios): exit 0
  • A throwaway play confirmed baseline_extra_inbound resolves to udp/4433 under both inventory/hosts.yml and the overlay
  • make -n confirmed the INVENTORY guards (empty value and env-set value both refused)

🤖 Generated with Claude Code

…izing, runbook)

Readies the devops side of the 2026-09-28 testnet launch (decdn/internal
Launch/fleet-plan.md):

- Keep real inventory out of this public repo: git-ignore inventory/hosts.yml,
  add INVENTORY=<path> to check/deploy (with the same env/empty guards as
  LIMIT), and move the udp/4433 firewall hole to playbooks/group_vars so a
  private overlay passed with -i cannot deploy nodes with QUIC firewalled off.
- inventory/fleet.example/: launch-fleet overlay template grouped by role
  (seed = fs origin for seed-model.sh, edge = pull-through) and billing
  (metered = egress budget). It sizes max_blob_size_mb to 16 GiB, because
  origin import stores each file as one blob and the catalogue's largest file
  is 13.5 GiB (measured from HF). The 1 GiB default would BlobTooLarge every
  model.
- docs/launch-runbook.md: deploy -> stake/register -> seed -> pin -> verify.
- SECURITY.md with the pinned release-key fingerprint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 22, 2026 17:55

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved moderate issues remain in deployment safety, secret-file protection, and storage sizing.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Prepares Ansible for the 2026-09-28 testnet launch with private fleet overlays, large-model storage sizing, firewall preservation, and operational documentation.

Changes:

  • Adds guarded private inventory selection and secret protection.
  • Adds seed/edge fleet templates with cache and blob sizing.
  • Documents deployment, verification, release signing, and launch operations.
File Summary Review notes
SECURITY.md Adds vulnerability reporting and release-key guidance. Nit (1 vote): Qualify release guarantees when signature verification is disabled.
ansible/​README.md Documents private fleet overlays and deployment usage. Moderate (1 vote): Protect copied overlays from accidentally tracking secret.yml.
ansible/​playbooks/​group_vars/​decdn_nodes.yml Makes the QUIC firewall rule inventory-independent. —
ansible/​Makefile Adds guarded inventory selection. Moderate (2 votes): Validate that the default inventory exists or require an explicit overlay.
ansible/​inventory/​hosts.yml.example Updates public inventory guidance. —
ansible/​inventory/​group_vars/​decdn_nodes.yml Documents firewall-rule relocation. —
ansible/​inventory/​fleet.example/​hosts.yml Defines launch fleet topology and regions. —
ansible/​inventory/​fleet.example/​host_vars/​fsn1-a/​secret.yml.example Provides an optional RPC secret template. —
ansible/​inventory/​fleet.example/​group_vars/​decdn_unmetered.yml Documents unmetered billing behavior. —
ansible/​inventory/​fleet.example/​group_vars/​decdn_seed.yml Configures filesystem origins. —
ansible/​inventory/​fleet.example/​group_vars/​decdn_nodes.yml Configures binaries, contracts, cache sizing, and pins. Nit (1 vote): Add the authoritative ADR reference for protocol values here and in the runbook.
ansible/​inventory/​fleet.example/​group_vars/​decdn_metered.yml Configures metered egress budgeting. —
ansible/​inventory/​fleet.example/​group_vars/​decdn_edge.yml Documents edge pull-through behavior. —
ansible/​docs/​launch-runbook.md Documents deployment and launch operations. Moderate (1 vote): State the roughly 760 GiB storage requirement. Nit (1 vote): Provide the complete decdn setup dry-run and execution commands.
ansible/​.gitignore Ignores real inventories and nested secrets. —
AGENTS.md Updates inventory and deployment conventions. —

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread ansible/Makefile
…, setup)

- check/deploy now fail on a missing or unparseable inventory
  (ANSIBLE_INVENTORY_UNPARSED_FAILED on those recipes). Without it a mistyped
  INVENTORY= warned, skipped the play, and exited 0. It isn't set in ansible.cfg
  because ansible-lint's syntax checks run with no inventory and would break.
- fleet.example/.gitignore travels with `cp -r`, so the private overlay
  ignores host_vars/*/secret.* too.
- Runbook: seeds need origin + cache + headroom (about 760 GiB with template
  values), plus hf staging while seeding; exact `decdn setup` command via
  systemd-run with the unit's EnvironmentFile (the RPC key stays out of argv),
  with ADR 019/026/030 citations.
- SECURITY.md: the tarball guarantee holds only with signature verification on
  in release mode; manual mode verifies nothing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@thiras

thiras commented Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

Replies to the notes in the review overview table (fixes in ace223a):

  • Copied overlays tracking secret.yml: fixed. inventory/fleet.example/.gitignore now travels with cp -r. In a fresh git init of a copied overlay, host_vars/fsn1-a/secret.yml is ignored and the .example is not.
  • ~760 GiB storage: correct for seeds, which hold the fs origin (~352 GiB) plus the 400 GiB cache plus 8 GiB headroom on one volume. The runbook §3 and group_vars/decdn_seed.yml now say so. They also cover the extra hf download staging space while seeding, or shrinking the seeds' cache instead.
  • Complete decdn setup commands: added. The runbook gives the exact --dry-run command and then the real one. It runs through systemd-run -p EnvironmentFile=/etc/decdn/decdn.env, so DECDN_RPC_URL is loaded by the same parser as the unit and never lands in argv. Flags checked against upstream SetupArgs / CommonChainArgs.
  • SECURITY.md guarantee: qualified. The guarantee holds only in release mode with decdn_verify_release_signature: true. Turning verification off prints a warning, and manual mode verifies nothing. I checked install.yml: manual mode has no warning, so the doc doesn't claim one.
  • ADR references: added to the runbook for onboarding (ADR 019), region (ADR 030) and bond sizing (ADR 026). Not added for the contract addresses in fleet.example/group_vars/decdn_nodes.yml. No ADR carries addresses; their source is the deployment manifest decdn/contracts/deployments/421614.json, which that file already cites. An ADR link there would point at the wrong source.

Re-run after the fixes: make lint and make lint-ansible (0 failures, production profile); make molecule (all scenarios, exit 0); CI and overlay --syntax-check.

@thiras
thiras merged commit a314689 into main Sep 22, 2026
11 checks passed
@thiras
thiras deleted the feat/launch-fleet-readiness branch September 22, 2026 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants