| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
This a basic playbook and roles collection.
Ansible control node:
Ansible managed nodes:
Debian-like managed node:
# Performed by root user
# Install prereqs
apt-get update
apt-get install -y openssh-server python3 sudo
# Ensure ssh server running
systemctl enable --now sshd
# Create ansible user, replace USERNAME
useradd -m USERNAME
passwd USERNAME
# Make ansible user sudoer
usermod -aG sudo USERNAMEAlpine managed node:
# Performed by root user
# Install prereqs
apk add --update --no-cache openssh-server python3 sudo shadow
# Ensure ssh server running
rc-update add sshd
rc-service sshd start
# Create ansible user, replace USERNAME
useradd -m USERNAME
passwd USERNAME
# Make ansible user sudoer
echo '%wheel ALL=(ALL) ALL' > /etc/sudoers.d/wheel
usermod -aG wheel USERNAME├── .dev # <- Development convenience scripts
├── ansible.cfg
├── bin # <- Playbook convenience scripts
├── playbook.yaml
├── requirements.yaml # <- Required roles and collections declaretions
├── roles # <- Categorized roles
├── sample # <- Configuration samples
├── vaulted.txt # <- (optional) Create this empty file to trigger vault pass prompt
└── vendor # <- Vendor directoryCopy configurations from sample directory and edit them:
cp -rp ./sample/* ./Use ansible-playbook wrapper scripts from bin directory to deploy
In order to provoke vault password prompt by bin scripts create vaulted.txt file in the project root directory
touch ./vaulted.txtSome services have capability to be proxied via tailscale. Mostly these are traffic intensive ones, and they gain in afficiency when routed via tailnet (vs subnet routing).
Tailscale is just my personal preference. I don't get payed from them (wouldn't mind though 😏)
base/snapd role is not supported by Alpine. In LXC context for non-Ubuntu-like systems installation of snaps fails with error:
error: system does not fully support snapd: cannot mount squashfs image using "squashfs" ...
So I limited it in all contexts to Ubuntu-like only
base/tmuxp role is not supported by Alpine
desktop/* roles are mostly oriented to Debian-based (sometimes narrowed to Ubuntu-based) distros
service/* roles are primarely deployed with docker
The goal of all these *_done variables is to reduce noise in the ansible-playbook log when roles are played more than once.
A lot of roles depend on data collected by factum, so it's better to be the first role in the playbook. It provides the following:
ansible_facts.getent_passwd:
root:
- ... # <- Useless
- UID # [1]
- GID # [2]
- ... # <- Useless
- HOME # [4]
- SHELL # [5]
# ... # <- Other users
factum_os_family: # <- Lowercase ansible_facts.os_family
factum_os_like: # <- More prioritized OS like
factum_ubuntu_codename: # <- Ubuntu code name for Ubuntu-like distrosPerforms all necessary initialization tasks (factum included), so it basically must be the first role in the playbook.
- name: 'MyBook'
hosts: all
roles:
- { role: init, tags: [always] } # <- Required initial tasks
# ... more rolesTesting environment LXC containers in PVE deployment scripts is available in ./tools/test-env. It works in conjunction with devenv.sh script.
In order to create a project cloned from this one, issue
curl -fsSL https://github.com/spaghetti-coder/ansible-bookshelf/raw/master/.dev/remote-proj.sh | bash -s -- install \
path/to/new/project \
master `# <- Optional tree-ish`To sync libraries and tools in the new project with the upstream issue:
# Alway `git commit` before this action
.dev/remote-proj.sh pull-upstreamsudo mkdir -p /etc/tmux
sudo curl -o /etc/tmux/default.conf CONFI_FILE_URL
echo 'source-file /etc/tmux/default.conf' >> ~/.tmux.conf| Back | FazBrowse Home | New Git URL |