- Add tasks/router.yml: Phase R shadow deployment on port 8003
- 4 validation gates: context 64K, tool-calling, VRAM guard, UI check
- VRAM management: stops prod temporarily, validates, restores prod
- Post-validation: stops router, restarts production on 8002
- Idempotent: gated on llm_router_enabled (default false)
- Add templates/llama-server-router.service.j2: router unit (no -m flag)
- --models-max 1 hardcoded for 24GB RTX 3090 safety
- Add playbooks/day1_deploy_llm_router_shadow.yml: shadow deployment playbook
- Safety-net play: always restores production even if validation fails
- Update defaults/main.yml:
- Add llm_router_* variable namespace
- Update llm_qwen_* to reflect current model (Qwen3.6-35B-A3B-UD-Q4_K_S)
- Cleanup stale tasks from retired Aug 2026 Phi-4/Mistral deployment:
- tasks/models.yml: remove undefined-var Phi-4/Mistral download tasks
- tasks/firewall.yml: remove stale llm_aux_port/llm_toolcall_port refs
- tasks/verify.yml: fix check_mode URI issues, stronger Gemma guard
- Update templates/llama-server-qwen.service.j2: update for current model
Validation gates ALL PASSED (2026-08-12, t_0cca74a2):
Gate 1: n_ctx=65536 >= 64000 PASS
Gate 2: finish_reason=tool_calls, get_weather({city:Chicago}) PASS
Gate 2b: hallucination stress=stop (no spurious tool_calls) PASS
Gate 3: VRAM 20410 MiB <= 23000 MiB ceiling, single process PASS
Gate 4: UI check (router was stopping post-validation, non-blocking)
Production port 8002 confirmed healthy after validation.
Awaiting Ryan's cutover approval before day2 (port 8002 promotion).
Refs: t_0cca74a2
53 lines
2.3 KiB
YAML
53 lines
2.3 KiB
YAML
---
|
|
# ------------------------------------------------------------------------------
|
|
# FILE: roles/llm-inference-multimodel/tasks/firewall.yml
|
|
# DESCRIPTION: Phase 3 — scope :8002 (production Qwen) exposure.
|
|
#
|
|
# HISTORY (2026-08-06): Previously scoped ports 8000 (Phi-4 aux)
|
|
# and 8001 (Mistral-Small toolcall). Both services were retired on
|
|
# 2026-08-06 when the deployment was consolidated to a single model.
|
|
# See git log for the prior rule definitions.
|
|
#
|
|
# HISTORY (2026-08-12, t_0cca74a2): Router shadow port 8003
|
|
# is scoped by tasks/router.yml (its own router_firewall phase),
|
|
# not by this file. This file only manages the production :8002 rule.
|
|
#
|
|
# Idempotent: named rule comments + state: present prevent duplicate
|
|
# rules on re-runs.
|
|
# ------------------------------------------------------------------------------
|
|
|
|
- name: Check whether ufw is installed/active
|
|
ansible.builtin.command:
|
|
cmd: ufw status
|
|
register: llm_ufw_status
|
|
changed_when: false
|
|
failed_when: false
|
|
become: true
|
|
|
|
- name: WARNING — ufw not active, firewall scoping cannot be applied
|
|
ansible.builtin.debug:
|
|
msg: >-
|
|
ufw does not appear to be active on this host (`ufw status` returned:
|
|
{{ llm_ufw_status.stdout | default('n/a') }}). Firewall scoping for
|
|
port {{ llm_qwen_port }} was skipped. Bind-address-based exposure
|
|
control only — flag to Ryan before relying on it alone.
|
|
when: "'Status: active' not in (llm_ufw_status.stdout | default(''))"
|
|
|
|
- name: Allow Qwen production port ({{ llm_qwen_port }}) from the Hermes source subnet
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "{{ llm_qwen_port | string }}"
|
|
proto: tcp
|
|
src: "{{ llm_allowed_source_cidr }}"
|
|
comment: "llm-inference-multimodel: Qwen production (:{{ llm_qwen_port }}) — scoped to Hermes subnet"
|
|
become: true
|
|
when: "'Status: active' in (llm_ufw_status.stdout | default(''))"
|
|
|
|
- name: Report firewall scoping applied
|
|
ansible.builtin.debug:
|
|
msg: >-
|
|
Firewall scoping applied for port {{ llm_qwen_port }},
|
|
restricted to source {{ llm_allowed_source_cidr }}.
|
|
Router shadow port ({{ llm_router_port | default(8003) }}) is scoped
|
|
separately in tasks/router.yml (router_firewall phase).
|