Upgrade Mastodon from 4.3 to 4.7, deploy on new Ubuntu 24.04 VM #681

Merged
raucao merged 21 commits from chore/upgrade_mastodon into master 2026-10-08 13:02:46 +00:00
21 Commits
Author SHA1 Message Date
raucao 63e4401715 Update Mastodon data bag, nodes 2026-10-08 14:28:16 +02:00
raucao 2bb5b582ec Deploy Mastodon from now on
The mastodon role now always deploys (deploy=true), so a plain converge rebuilds and restarts on new production-4.7 commits.
2026-10-08 12:43:35 +02:00
raucao 8ac0b965b2 Declare the search deploy unit before the migration chain
The migration chain starts mastodon-search-deploy.service immediately, but the systemd_unit resource was declared later in the recipe, so the unit did not exist yet and systemctl failed with 'Unit not found'.
2026-10-08 12:21:24 +02:00
raucao af4983d747 Record revision stamps as the mastodon user
The stamp files' lazy git call ran as root, which git rejects on the mastodon-owned repository (dubious ownership), silently writing an empty stamp. Use execute resources with the mastodon user instead so git works and the revision is recorded.
2026-10-08 11:51:23 +02:00
raucao 1b564c285d Give the mastodon user a /home/mastodon home
The mastodon user's home was /opt/mastodon, i.e. the clone destination, so writing the SSH deploy key into ~/.ssh made the directory non-empty and Chef's git resource silently skipped cloning (it only clones into an empty directory). Use a dedicated /home/mastodon home for the user and keep the clone destination separate. Also clear a non-git (partial) clone destination before cloning.
2026-10-08 11:43:47 +02:00
raucao 0696d03374 Replace the removed bundler --deployment flag
Bundler 4 (shipped with Ruby 4) removed --deployment. Use 'bundle config set --local deployment true' (frozen + vendor/bundle) and the 'without' setting instead, in the Mastodon, akkounts and liquor-cabinet cookbooks.
2026-10-08 11:34:46 +02:00
raucao b0718a5dac Ensure the SSH deploy key ends with a newline
OpenSSH's PEM parser rejects a private key file without a trailing newline ('error in libcrypto').
2026-10-08 11:30:09 +02:00
raucao aeeb900f14 Add repo deploy key 2026-10-08 10:53:51 +02:00
raucao a3877e620e Create the mastodon home directory in the dependencies recipe
The user resource does not manage the home directory, so removing /opt/mastodon broke the build phase when it tried to create /opt/mastodon/.ssh.
2026-10-07 19:49:52 +02:00
raucao abfd654ae5 Clone the private Mastodon repo with an SSH deploy key
The repository is private, so use git@gitea.kosmos.org with a read-only deploy key stored in credentials/mastodon (repo_deploy_key). The pinned gitea host key is an attribute.
2026-10-07 19:41:43 +02:00
raucao d05f00dae2 Pre-stage the Mastodon 4.7 build on mastodon-4 2026-10-07 18:08:30 +02:00
raucao fb0c7b2b1c Add a build phase, make deployment revision-driven
Split the deployment into kosmos-mastodon::build (checkout + bundle/yarn/assets, no database) and kosmos-mastodon::deploy (migrations + services), dispatched by the new 'build' attribute. Both phases are idempotent per checked-out revision via stamps, and the migration/restart/search-index chain is now triggered by the deployed revision instead of the git resource, so it still runs when the build was pre-staged.
2026-10-07 18:08:22 +02:00
raucao 9dfdf6bc9b Remove the backup gem from Mastodon
The shared backup cookbook hardcodes postgresql-client-12, which does not exist on Ubuntu 24.04. Drop the Mastodon backup recipe and its role inclusion; the PostgreSQL standby is the safety net. The backup cookbook itself is still used by other services.
2026-10-07 17:53:57 +02:00
raucao ec2645c5da Install LibreTranslate in a virtualenv
Ubuntu 24.04's system Python is externally managed (PEP 668) and refuses pip installs. Also bump LibreTranslate from 1.3.8 to 1.9.6, since the former pulls ctranslate2 2.24.0 which has no Python 3.12 wheels.
2026-10-07 17:44:16 +02:00
raucao b09808b12e Drop the java cookbook dependency
The java cookbook's openjdk recipe unconditionally adds the dead openjdk-r PPA on Ubuntu and cannot be told not to, which breaks on Ubuntu 24.04. Elasticsearch 7.x ships a bundled JDK and no JAVA_HOME is configured, so no system Java is needed.
2026-10-07 17:26:40 +02:00
raucao 8a11cd88f7 Create search indices during deploy, import in background
Mastodon 4.4+ can create/upgrade the Elasticsearch indices and mappings without importing data. Do that synchronously during the deployment so search does not fail on a missing index, then populate the (potentially very long) import via a systemd unit started with --no-block so the maintenance window is not extended.
2026-10-07 17:17:27 +02:00
raucao 9fe5def5f9 Move Mastodon deploy flag to the mastodon role
Set kosmos-mastodon.deploy to false as a role default, making it overridable per node, and drop the node-level attribute.
2026-10-07 16:51:18 +02:00
raucao fef57f1ee1 Update mastodon-4 node to dependency-only deployment 2026-10-07 16:41:40 +02:00
raucao 591d6dc4ec Split Mastodon runtime deps from deployment, use Redis cluster
Add a kosmos-mastodon::dependencies recipe with everything needed to run Mastodon (Node, Ruby, libvips, Elasticsearch, packages) but without the app deployment. The default recipe includes it and only runs the deployment when node['kosmos-mastodon']['deploy'] is true, so a VM can be prepared ahead of a maintenance window.

Stop using the local redisio instance and connect to the external Redis cluster (redis_server role, db 2, password from the credentials data bag) instead. Remove the redisio service dependencies from the systemd units and drop the redisio cookbook dependency.
2026-10-07 16:41:28 +02:00
raucao 735145f5a9 Add mastodon-4 node and client config 2026-10-07 16:13:53 +02:00
raucao b60ca687ec Upgrade Mastodon to 4.7
Bump the production branch to 4.7 and adjust for the changes between 4.3 and 4.7:

- Node 24.21.0 and Ruby 4.0.7 (via ruby-build v20260924)
- Redis 7.4.11 (Mastodon 4.5 requires >= 7.0)
- Replace ImageMagick with libvips (required since 4.6) and libidn11 with libidn
- Split database migrations into pre-/post-deployment phases and rebuild
  the Elasticsearch accounts index mappings (required since 4.4)
- Remove the OTP_SECRET environment variable (removed in 4.4)
- Disable email subscriptions (new optional feature in 4.6) and force the
  default locale (DEFAULT_LOCALE no longer overrides it since 4.4)
- Add the new fasp Sidekiq queue
- Enable corepack for yarn instead of the removed no-arg 'corepack prepare'
2026-10-07 16:12:48 +02:00