Files
AWatch-rus/ansible/deploy_file_1c_analytics.yml
T

348 lines
12 KiB
YAML

---
- name: Развернуть file-1C analytics backend
hosts: proxmox
become: true
gather_facts: true
vars:
aw_file_1c_repo_root: "{{ playbook_dir | dirname }}"
aw_file_1c_release_root: /opt/activitywatch/releases
aw_file_1c_release_dir: "{{ aw_file_1c_release_root }}/clickhouse-1c"
aw_file_1c_root: /opt/activitywatch/clickhouse-1c
aw_file_1c_clickhouse_db: analytics_1c
aw_file_1c_clickhouse_user: default
aw_file_1c_clickhouse_password: change-me
aw_file_1c_clickhouse_port: 8123
aw_file_1c_clickhouse_native_port: 9000
aw_file_1c_company_api_host: "{{ ansible_host | default('127.0.0.1') }}"
aw_file_1c_company_api_port: 8710
aw_file_1c_manager_brief_grafana_url: "http://10.10.10.11:3000/d/1c-file-mgmt/1c-file-management-board?orgId=1"
aw_file_1c_manager_brief_state_dir: /opt/activitywatch/clickhouse-1c/state/manager-brief
aw_file_1c_manager_brief_model: gpt-5.3-codex
aw_file_1c_manager_brief_codex_user: igor
aw_file_1c_manager_brief_codex_bin: codex
aw_file_1c_manager_brief_workdir: /home/igor
aw_file_1c_manager_brief_top_limit: 5
aw_file_1c_manager_brief_freshness_hours: 8
aw_file_1c_manager_brief_timeout_sec: 300
aw_file_1c_manager_brief_run_after_ingest: false
aw_file_1c_windows_upload_pubkey_path: /tmp/awops_ed25519.pub
tasks:
- name: Установить базовые пакеты file-1C analytics
ansible.builtin.apt:
name:
- docker.io
- docker-compose
- python3-venv
- python3-pip
state: present
update_cache: true
- name: Включить и запустить docker
ansible.builtin.systemd:
name: docker
enabled: true
state: started
- name: Создать release каталоги file-1C analytics
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: igor
group: igor
mode: "0755"
loop:
- "{{ aw_file_1c_release_root }}"
- "{{ aw_file_1c_release_dir }}"
- name: Скопировать верхнеуровневые файлы stack file-1C analytics
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/{{ item.src }}"
dest: "{{ aw_file_1c_release_dir }}/{{ item.dest }}"
owner: igor
group: igor
mode: "{{ item.mode | default('0644') }}"
loop:
- { src: 'README.md', dest: 'README.md' }
- { src: 'docker-compose.yml', dest: 'docker-compose.yml' }
- { src: '.env.example', dest: '.env.example' }
- name: Подготовить каталоги stack file-1C analytics
ansible.builtin.file:
path: "{{ aw_file_1c_release_dir }}/{{ item }}"
state: directory
owner: igor
group: igor
mode: "0755"
loop:
- clickhouse
- detections
- etl
- ai
- grafana
- ops
- sample
- name: Скопировать каталоги stack file-1C analytics
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/{{ item }}/"
dest: "{{ aw_file_1c_release_dir }}/{{ item }}/"
owner: igor
group: igor
mode: preserve
directory_mode: "0755"
loop:
- clickhouse
- detections
- etl
- ai
- grafana
- ops
- sample
- name: Установить права на исполняемые ops scripts
ansible.builtin.file:
path: "{{ aw_file_1c_release_dir }}/ops/{{ item }}"
owner: igor
group: igor
mode: "0755"
state: file
loop:
- bootstrap_runtime.sh
- check_ingest_freshness.sh
- run_company_intelligence_api.sh
- run_company_intelligence_refresh.sh
- run_company_registry_bindings_refresh.sh
- run_manager_brief.sh
- run_ingest_cycle.sh
- name: Создать .env для file-1C analytics
ansible.builtin.copy:
dest: "{{ aw_file_1c_release_dir }}/.env"
owner: igor
group: igor
mode: "0600"
content: |
CLICKHOUSE_DB={{ aw_file_1c_clickhouse_db }}
CLICKHOUSE_USER={{ aw_file_1c_clickhouse_user }}
CLICKHOUSE_PASSWORD={{ aw_file_1c_clickhouse_password }}
CLICKHOUSE_PORT={{ aw_file_1c_clickhouse_port }}
CLICKHOUSE_NATIVE_PORT={{ aw_file_1c_clickhouse_native_port }}
CLICKHOUSE_HOST=clickhouse
AW_1C_COMPANY_API_HOST={{ aw_file_1c_company_api_host }}
AW_1C_COMPANY_API_PORT={{ aw_file_1c_company_api_port }}
AW_1C_MANAGER_BRIEF_GRAFANA_URL={{ aw_file_1c_manager_brief_grafana_url }}
AW_1C_MANAGER_BRIEF_STATE_DIR={{ aw_file_1c_manager_brief_state_dir }}
AW_1C_MANAGER_BRIEF_MODEL={{ aw_file_1c_manager_brief_model }}
AW_1C_MANAGER_BRIEF_CODEX_USER={{ aw_file_1c_manager_brief_codex_user }}
AW_1C_MANAGER_BRIEF_CODEX_BIN={{ aw_file_1c_manager_brief_codex_bin }}
AW_1C_MANAGER_BRIEF_WORKDIR={{ aw_file_1c_manager_brief_workdir }}
AW_1C_MANAGER_BRIEF_TOP_LIMIT={{ aw_file_1c_manager_brief_top_limit }}
AW_1C_MANAGER_BRIEF_FRESHNESS_HOURS={{ aw_file_1c_manager_brief_freshness_hours }}
AW_1C_MANAGER_BRIEF_TIMEOUT_SEC={{ aw_file_1c_manager_brief_timeout_sec }}
AW_1C_MANAGER_BRIEF_RUN_AFTER_INGEST={{ 1 if aw_file_1c_manager_brief_run_after_ingest else 0 }}
- name: Создать etl/config.yml для file-1C analytics
ansible.builtin.copy:
dest: "{{ aw_file_1c_release_dir }}/etl/config.yml"
owner: igor
group: igor
mode: "0644"
content: |
clickhouse:
host: localhost
port: {{ aw_file_1c_clickhouse_port }}
username: {{ aw_file_1c_clickhouse_user }}
password: {{ aw_file_1c_clickhouse_password }}
database: {{ aw_file_1c_clickhouse_db }}
landing:
documents: {{ aw_file_1c_root }}/landing/documents
postings: {{ aw_file_1c_root }}/landing/postings
business_events: {{ aw_file_1c_root }}/landing/business_events
document_changes: {{ aw_file_1c_root }}/landing/document_changes
companies: {{ aw_file_1c_root }}/landing/companies
reglog: {{ aw_file_1c_root }}/landing/reglog
audit: {{ aw_file_1c_root }}/landing/audit
host: {{ aw_file_1c_root }}/landing/host
formats:
default: jsonl
documents: jsonl
postings: jsonl
business_events: jsonl
document_changes: jsonl
companies: jsonl
reglog: jsonl
audit: jsonl
host: jsonl
archive_dir: {{ aw_file_1c_root }}/archive
delete_after_load: false
min_file_age_seconds: 180
- name: Создать symlink на активный root file-1C analytics
ansible.builtin.file:
src: "{{ aw_file_1c_release_dir }}"
dest: "{{ aw_file_1c_root }}"
state: link
force: true
- name: Bootstrap runtime file-1C analytics
ansible.builtin.command:
cmd: "{{ aw_file_1c_root }}/ops/bootstrap_runtime.sh"
environment:
AW_1C_ROOT: "{{ aw_file_1c_root }}"
- name: Сделать landing/archive writable для igor upload path
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: igor
group: igor
mode: "0755"
recurse: true
loop:
- "{{ aw_file_1c_root }}/landing"
- "{{ aw_file_1c_root }}/archive"
- name: Поднять ClickHouse для file-1C analytics
ansible.builtin.command:
cmd: docker compose up -d clickhouse
args:
chdir: "{{ aw_file_1c_root }}"
- name: Переапплиить ClickHouse schema и views для file-1C analytics
ansible.builtin.shell: |
set -eu
docker exec -i aw-rus-1c-clickhouse clickhouse-client \
--user {{ aw_file_1c_clickhouse_user }} \
--password {{ aw_file_1c_clickhouse_password }} \
--multiquery < "{{ aw_file_1c_root }}/clickhouse/init/{{ item }}"
args:
executable: /bin/bash
loop:
- 00_database.sql
- 01_raw_tables.sql
- 02_core_tables.sql
- 03_views.sql
- 04_company_intelligence.sql
- 05_financial_reporting.sql
- name: Установить systemd unit aw-1c-ingest.service
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-ingest.service"
dest: /etc/systemd/system/aw-1c-ingest.service
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-ingest.timer
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-ingest.timer"
dest: /etc/systemd/system/aw-1c-ingest.timer
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-proofcheck.service
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-proofcheck.service"
dest: /etc/systemd/system/aw-1c-proofcheck.service
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-proofcheck.timer
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-proofcheck.timer"
dest: /etc/systemd/system/aw-1c-proofcheck.timer
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-company-api.service
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-company-api.service"
dest: /etc/systemd/system/aw-1c-company-api.service
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-manager-brief.service
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-manager-brief.service"
dest: /etc/systemd/system/aw-1c-manager-brief.service
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Установить systemd unit aw-1c-manager-brief.timer
ansible.builtin.copy:
src: "{{ aw_file_1c_repo_root }}/clickhouse-1c/ops/aw-1c-manager-brief.timer"
dest: /etc/systemd/system/aw-1c-manager-brief.timer
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Разрешить Windows upload key для igor
ansible.builtin.lineinfile:
path: /home/igor/.ssh/authorized_keys
line: "{{ lookup('file', aw_file_1c_windows_upload_pubkey_path) }}"
create: true
owner: igor
group: igor
mode: "0600"
- name: Включить и запустить aw-1c-ingest.timer
ansible.builtin.systemd:
name: aw-1c-ingest.timer
enabled: true
state: started
daemon_reload: true
- name: Включить и запустить aw-1c-proofcheck.timer
ansible.builtin.systemd:
name: aw-1c-proofcheck.timer
enabled: true
state: started
daemon_reload: true
- name: Включить и запустить aw-1c-company-api.service
ansible.builtin.systemd:
name: aw-1c-company-api.service
enabled: true
state: started
daemon_reload: true
- name: Включить и запустить aw-1c-manager-brief.timer
ansible.builtin.systemd:
name: aw-1c-manager-brief.timer
enabled: true
state: started
daemon_reload: true
- name: Проверить доступность ClickHouse ping
ansible.builtin.uri:
url: "http://127.0.0.1:{{ aw_file_1c_clickhouse_port }}/ping"
return_content: true
register: aw_file_1c_ping
changed_when: false
- name: Показать ping ClickHouse
ansible.builtin.debug:
msg: "{{ aw_file_1c_ping.content }}"
handlers:
- name: Перезагрузить systemd
ansible.builtin.systemd:
daemon_reload: true