Repository navigation
docs(install): add fleet install guide and Ansible playbook - #373
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces a fleet installation guide and an Ansible playbook to support installing, upgrading, or removing the nudgebee node agent across multiple Linux hosts. The review feedback highlights several key improvements: ensuring the playbook explicitly starts the service to handle cases where no configuration changes are detected, replacing a shell loop anti-pattern in the documentation with a more robust while read loop, warning users about GitHub rate-limiting risks when using the latest version on large fleets, and adding a comment to guide developers on overriding the installer URL for local testing.
aa4fd2e to
19e71ad
Compare
mayankpande88
left a comment
There was a problem hiding this comment.
Requesting changes. Both install paths here download install.sh from the prod branch, and that copy is still the upstream installer, so neither works as written (details inline). A real install on one host would have caught it; the description says that wasn't run. Please do one run against a test host before merge.
Also blocking:
API_KEYends up on the sudo command line on every host (inline oninstall-node-agent.yml:44).- Play-level
vars:silently override inventory/group/host vars. - The service health check passes for an agent that is crash-looping.
Several statements in docs/fleet-install.md don't match main: TRACES_SAMPLING and other flags are dropped by the installer's whitelist, LISTEN can't change the push-mode listen address, --help doesn't list settings, re-runs always restart, and COLLECTOR_ENDPOINT metrics aren't OTLP.
PR/commit hygiene, since this repo is public:
- The description links a private-repo issue and an org discussion. Please remove both.
- Please drop the
Co-Authored-By: Claudetrailer from the commit and the "Generated with" footer from the description. The trailer needs a commit rewrite, not just a description edit.
Minor, not inline: the installer file is left in /var/tmp when the install fails (a block/always would fix that and remove the five repeated when: lines). A typo in node_agent_state runs nothing and reports success. changed_when depends on the exact wording of an installer log line.
19e71ad to
73409fe
Compare
|
Thanks, all addressed in the latest push (single commit, trailer removed, description cleaned up).
Still not done: a real install on a remote host. |
mayankpande88
left a comment
There was a problem hiding this comment.
All review points addressed. I ran the playbook for real on a Debian 12 VM (systemd 252, arm64) against v0.1.9:
- Fresh install: passes.
/etc/default/nudgebee-node-agentis0600 root. AnAPI_KEYcontaining\,"and$reaches the agent's environment unchanged, and it doesn't appear in the journal or the sudo log. The installer's own env file is empty, and the agent listens on127.0.0.1:10300. - Re-run, nothing changed: passes. The settings task reports
ok. TRACES_SAMPLING: "abc": the health check fails onActiveState, and the journal shows theParseFloatexit and the crash-loop.state=absent: the unit, binary and settings file are all removed.- SSH loop from the docs: installs; the settings file is
0600, the service is active.
Follow-up, not blocking: NRestarts == 0 works only because the installer always restarts the agent (systemd resets the counter on a manual start). If the installer's "No change detected" path is ever fixed, a healthy host with an earlier auto-restart (e.g. one OOM kill) would fail every re-run. Comparing NRestarts before and after the pause avoids that. Minor wording: latest is resolved through the github.com/.../releases/latest redirect, not the GitHub API.
What this PR does
Adds a guide and an Ansible playbook for installing the agent on many hosts in one run, instead of running
install.shby hand on each one. Docs and examples only; no agent or installer code changes.Linked issue / context
No public issue. This is the install step of running the agent on standalone VMs.
How to check it
docs/fleet-install.md(linked from the README install section).inventory.ini(copied frominventory.example.ini), copyvars.example.ymltovars.yml, and run:ansible-playbook -i inventory.ini -e @vars.yml install-node-agent.yml --limit <host>Expect the final "Check the agent is up and stayed up" task to pass, and
/etc/default/nudgebee-node-agenton the host to be mode0600and hold your settings.-e node_agent_state=absent: the service, binary and settings file are removed.How was this tested?
yamllintandansible-lint(production profile) pass;--syntax-checkpasses.--checkrun against localhost: host checks pass, install steps are skipped.\and";systemdread every value back unchanged. A value with a single quote is rejected with a clear message.eBPF changes?
No.
Checklist
make lint/make test: not applicable (no Go changes)## [Unreleased]example.com)