Ansible provisioning and deployment for Wudele (a fork of Pollaris with timezone-aware slots), running on a Wikimedia Cloud VPS instance at wudele.wmcloud.org.
This replaces the Framadate-based wudele-toolforge.
One Debian 13 instance (wudele.globaleducation.eqiad1.wikimedia.cloud) runs the
whole stack:
- nginx serving
/srv/wudele/app/public, behind the shared Cloud VPS web proxy (which terminates TLS for wudele.wmcloud.org) - PHP 8.4 FPM with a dedicated
wudelepool running as thewudeleuser - PostgreSQL 17 (local), database and role
wudele - wudele-worker systemd service running the Symfony Messenger worker (async jobs and scheduled tasks such as poll expiration)
- Email features disabled entirely (
APP_EMAILS_ENABLED=falseand a null mailer transport), like the original wudele.toolforge.org - Nightly
pg_dumpbackups to/srv/backups/wudele(14 days retention)
Secrets (Symfony APP_SECRET, database password) are generated on the host on
first provisioning and stored under /srv/wudele/secrets/; nothing secret
lives in this repository.
Production assets are pre-built and committed in the application repository (upstream Pollaris convention), so the instance does not need Node.js. When changing JS/CSS, rebuild and commit before deploying:
$ docker compose -f docker/development/docker-compose.yml run --rm bundler npm run build- Create the instance (Debian 13, g4.cores1.ram2.disk20 or larger) — done.
- Create a web proxy
wudele.wmcloud.org→ the instance, port 80. - Make sure the project security groups allow HTTP (port 80) from the web proxy to the instance (the default security group usually does).
Requirements: ansible-core, plus SSH access to the instance through the
Cloud VPS bastion (see hosts; set bastion_user to your own shell
username).
Full provisioning (idempotent):
$ ansible-playbook main.ymlDeploy the latest code from the wudele branch:
$ ansible-playbook main.yml --tags applicationOther tags: system, database, webserver, worker, backups.