Cutover mx99 and decommission Ansible
closedFinish the migration and delete the Ansible stack.
Sketch:
- mx99 is a smoke-test box with no production data. Rebuild it on NixOS from scratch (optionally through the restore path, as a rehearsal of the recovery issue).
- Justfile: replace bootstrap, update, update-slice, _precheck, recovery-*, build-stalwart, build-zds, persist-bootstrap-secrets and provision-*-secrets with thin wrappers: colmena apply --on <host>, nixos-anywhere ..., colmena build.
- Delete:
- deployment/ (roles, playbooks, inventory, ansible.cfg, scripts)
- nix/pkgs/stalwart.nix + stalwart-Cargo.lock
- bootstrap-stalwart.sh
- the ansible package in devenv
- CI: nix flake check (plan --dry-run) + colmena build instead of the hour-long Stalwart build.
- Docs: rewrite docs/deployment.md and the runbooks.
Done when no Ansible remains in the repo and every box is deployed by Colmena.
2 Comments
Update (2026-10-06): hosts are deployed from
~/projects/servers(shared Colmena fleet), so this issue changes: - Justfile host recipes don’t becomecolmena applywrappers here; they become stubs pointing at the fleet (just -f ../servers/Justfile …). Dev/test/build recipes stay. - CI staging (test, then deploy mx99) runs from the fleet: bump the sovrn input, run sovrn’s checks, deploy. - Also deletenix/hosts.nix,nix/hosts.json,nix/modules/{base,hetzner}.nix(the fleet owns them). - Prerequisites before deleting Ansible: relay, telemetry edge, backups, mx99 rebuilt by the fleet, and 1badc33 recovery (the playbooks are the only restore path today), unless we decide explicitly to go without it while there’s no production data. Plan:~/projects/servers/docs/fleet-migration-plan.md, Phase 11.Done (2026-10-08): no Ansible remains in the repo (deployment/ and the Ansible-era host machinery removed in sovrn 6f3bdcf; Justfile.nix folded into Justfile, host recipes forward to the fleet; docs and runbooks rewritten for the fleet), and every box is deployed by Colmena from ~/projects/servers: infra.mymood.at (metrics + relay) and mx99.eu.sovrn.at (staging cell). No CI for now: deploys run from the operator’s machine. Note: the old Ansible vaults (keys rotated in Phase 4) remain in repo history.