Repository navigation
Conversation
- Deployment Lambda picks the newest gold master of the instance type's architecture, so x86_64 and Graviton instance types both work; cloning refuses to cross architectures since it copies the root volume. - setup.sh installs bestool (bes-tools apt repo) and Munin into the AMI. The Image Builder pipelines now live in the `tupaia` Pulumi stack in ops, which replaces setupGoldMaster.sh. - setupObservability.sh, run at boot: restores Munin history from S3 by deployment name and serves it on the tailnet (node:4950 and svc:munin-tupaia-<deployment>), and for deployments with a Canopy registration in Parameter Store imports it and starts alertd. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
…4950 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
…AMIs Drops libappindicator3-1 (gone since 24.04), uses libgcc-s1, installs cloud-utils and the AWS CLI when missing, and keeps Munin's RRDs in a nodatacow btrfs subvolume like the Tamanu servers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
flushToS3.sh uploads Munin history and logs (deployment, pm2, nginx, cloud-init) to the server bucket. It runs hourly, at shutdown or termination through tupaia-flush.service, and from the deployment Lambda, which asks the old instance through SSM Run Command before launching its replacement so that one restores the latest Munin data. The flush is best effort and never blocks a redeploy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
Replaces zipping and uploading by hand through the console. The function's configuration is in the tupaia Pulumi stack in ops; this only updates its code, including startupTupaia.sh. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
… flush The Lambda's pre-replacement flush passes --final, which marks the server superseded once the upload succeeds. Its later hourly and termination flushes then upload logs only, so they can't overwrite the replacement's newer Munin history. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
…uild in startup.sh The Lambda (and its deploy workflow) now lives in the tupaia Pulumi stack in beyondessential/ops. What a new server does once it has checked out its branch moves into deployment-aws/startup.sh, versioned with the branch: prompt, preaggregation, Tailscale, build, pm2, nginx and observability. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
…yment infrastructure Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
Member
Author
|
The Generated by Claude Code |
…oyment>/registration Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
…ment The final flush before a redeploy uploads the node's state, then rejoins the tailnet as an ephemeral <name>-retiring node: reachable if the swap goes wrong, gone once terminated. It never logs out, which would invalidate the identity. The replacement takes the node over (same name, address and Canopy binding) only when the deployment Lambda tagged it TailscaleIdentity=handed-over, which it does only after a successful handover; otherwise it joins as a new node, as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue #:
None yet.
Changes:
pulumi/tupaia/infra/lambda, in thetupaia-infrastack), because one Lambda serves every deployment.deployment-aws/startup.sh: what a new server does once the Lambda's boot script has checked out its branch: prompt, preaggregation, Tailscale, build, pm2, nginx and observability. It's versioned with the branch. Branches without it fall back to the old steps.flushToS3.sh --finaluploads the node's state and rejoins as an ephemeral<name>-retiringnode. It never runstailscale logout, which would invalidate the uploaded identity.connectTailscale.shrestores that state only when the Lambda tagged the new instanceTailscaleIdentity=handed-over, which it does only after a successful handover. The deployment then keeps the same node: same name, address and Canopy binding.setup.sh:libappindicator3-1and useslibgcc-s1;cloud-utilsand the AWS CLI;setupObservability.sh:flushToS3.sh:setupGoldMaster.sh, both now in the ops stack.Related: beyondessential/ops#332, beyondessential/bestool#954, beyondessential/tailscale#39.
Still to do or verify:
-retiring;Screenshots:
N/A
🦸 Review Hero
🤖 Generated with Claude Code
https://claude.ai/code/session_01Tzq5SfWsJpLpoBxsSG6MVg