FEATURE: basic maintanance routines added: internet connection, disk space

This commit is contained in:
2026-07-07 09:07:03 +00:00
parent e4089273ca
commit d6cddf13eb
6 changed files with 118 additions and 22 deletions
@@ -5,3 +5,9 @@ ansible_become_password: p@a$$word
ansible_ssh_key: $$h_key
# Password for the default unprivileged user
user_password: p@a$$word
# ntfy topic
ntfy_topic: https://x.y.z/topic
# ntfy topic token
ntfy_topic_token: t0ken
# Home Assistant Webhook token
ha_webhook_token: h@_t0ken
+29 -20
View File
@@ -1,21 +1,30 @@
$ANSIBLE_VAULT;1.1;AES256
37386438323934313261326132383539643062353335333661326131643032316239326161373930
3264633766303937353938343565326562626535343830370a303632386666613033323132616561
33353565616333346663396535613738343439323535663932633134663139623032353764633333
6533366164393164300a303963343863323133303565323635313030396532336237313837633231
35653733306565386665333739323433646238343961396234666232666238363264333639346265
31323037356665366138663365653666623066393661353035636239656136323466633461323765
34323836623766643562363035313465343863633534646466376437633761373665636233646532
39616362353930376464626136336133333639636638623138313065383934666237383738396334
34323930306536663131333639373764393135653161663431373563323837313964333736643238
61353861656431396366616534633935636332323665336536353337646133653333663436623633
34616333393666356632656238333935636562366237393162653864306462316231376666653932
32373336373231306134343337373736656638343439373564343464653030623034333734656462
63633634396631333233323939663763313163373863326634306663656638373239306634643337
32343262393761643237653538376163633066376538616537653139376637663339646234383535
62396663396161396130303135396330303530333533363533366330303831326661653138333336
37386436373337613064343138373433393435653066303364326461303565336539396362373135
31663538383030326566303166353934626639653432356562613938646364666337383835353234
62383838346339653766393233383563356363383039303862393564353464343534373666376434
33323136613337366566393535633730643064353664393436363830333561643265623163386165
62323337363238643166
38616132653531633164316632376332616261393136373235356332646132663735646563653033
3835343662356664633163366638383534383238623561350a313862376637383731663636663962
36326233376135623338383631636364353864663965336335303632363263323733333238363436
3939343938366361660a313933326563363638356531323162613039363662376537396631346230
37666639323638613063646434663135373332316165336662396632363439363737383434383035
39626232613439366166646465346231393330383266386234313633643132643530323361653735
35326230396136616339376339636233336231316231303536666638623130323030616535646461
61626466343136343532616261613635366534373138343333353732646664313864613732376562
30376366613165336135313264373934313334316130613038393963653061343561383931343736
34383739623831636539353165323062336365356633366131323236636434326666666238333962
38643436386633353261373964633361316432633066323837383563383431633034663135366363
38373463306565656164653134643232643532626661633263386436333134626435623563633933
64343666363930333232353836666464656137666534643038343933366336393036656433336237
63653933666566376462353132393337303064353361316434353466333239386634623063313836
63363039376335306266666236626530346335353537626533326437336663633530396139323235
33643331366330303862313864653566323430623866353434623735346135616165643535363662
32633434386237336132663731353233663834616138353363343632613234643835386464376639
36366433363766396361306261386439336561396633663630663764386565306531643664663239
37373431656337346363333639333734623231393865613762666339356537313563333465626536
34333535376362633235313535373331663961376365356661336635396239636461383663356361
31353731356135396365663536336133303731653437623435666230386534373237323731316336
37656261323530623564316438613735313138336236356630393737393663626461653936306564
63626133343339343837626133343833323264633634623461366335336232316439613762366162
64316638366434313636373265343230373934373034366130333737626137613935386637633832
64616161633965373661626165393136323039383064383539613335363264613664346533346430
33633732363362363563353034616637363962646166353335656265336463323537666665663566
30353264623966373033656364636634643064613331383464643536366234363831366531363138
31303232663633303462373461616662666564376233323637343630646331663465373537376132
62616132363136306334336661656264336131393039346431363661663438396438
+12
View File
@@ -0,0 +1,12 @@
---
- name: Physical machines maintanance play
hosts: all
remote_user: ansible
roles:
- ../roles/1_common_healthcheck
vars_files:
../inventory/group_vars/all/secrets.yaml
vars:
ansible_user_passwd_hash: "{{ ansible_password | password_hash('sha512', 's3edscrj45e6r') }}"
user_passwd_hash: "{{ user_password | password_hash('sha512', 's3ed6123jhgcr') }}"
ha_addr: https://ha.lan
+31
View File
@@ -0,0 +1,31 @@
-----BEGIN CERTIFICATE-----
MIIFRTCCAy2gAwIBAgIUEYfbZs1nFB1sEyTb/W2AcKn9whwwDQYJKoZIhvcNAQEL
BQAwMTEQMA4GA1UEAwwHaG9tZS5jYTELMAkGA1UEBhMCUlUxEDAOBgNVBAcMB25v
d2hlcmUwIBcNMjYwMjAzMTg0NTA3WhgPMjA1MzA2MjAxODQ1MDdaMDExEDAOBgNV
BAMMB2hvbWUuY2ExCzAJBgNVBAYTAlJVMRAwDgYDVQQHDAdub3doZXJlMIICIjAN
BgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAhZJPmln1+iZ5b35U1KBPxGdfd2ra
V55vzjBA+9EeVJ7SgHqwvE6T7uXc/ZOpum/TiGAeU1bBtqilCwxXLLiL4Mkn6p1m
/ePosqE4lb7vMaZmAwxTcjmvekqnrcme+V1DSY5PtQljp+YBn/npOCHWe3WHNppc
3dUW6Y06hWk26C5xq4xdcIbs5LohMcJmMYI1kcaJPtys7RyW13Wy5dH8wF4Efdco
J4CU0yWBhF0Ys56YPbkWu1u2DqrFRiJr53LfJ90P88R4sSeBtLZVvEzWj+kWZEfJ
Oke7B1jXVJ40yBJ+brGQoFsD9o2x9JyNXHOUVcx1XH3a+NUFVKMJRCYPa5uaxq9h
B2gCBD4rBlOADchwSdNk1oGmtDg8xs3fcLxUqsO2jVA2T7w9iP4arvzqHuIWwVss
WdtcyQ/x8tjVC6cp8I8WH5CV8iWptH9exGnKbVjAWEkL6xbT7f09WDAheaXY1b59
Opuw9KAGIvqj4NCPpdd7zwDivNFJWYfz7SkEiM9I6NMDP9BoYBVMIyxJR83NOgl0
0gUPoEFT81k5w8k4S7kqa7YdMj3PLxGowIQb9xoQuXyAFtPhbXbHn/igKx62H/Lq
IOBvm55+GOaSnWAlVoze6rE+qCRWr6fS4bTcGEDb8INHPriwxX+YehqxLdqcGRLG
n8fd6ldOvS/BfXkCAwEAAaNTMFEwHQYDVR0OBBYEFBehubXS/4xlJz1AA6iVi2HA
HPfFMB8GA1UdIwQYMBaAFBehubXS/4xlJz1AA6iVi2HAHPfFMA8GA1UdEwEB/wQF
MAMBAf8wDQYJKoZIhvcNAQELBQADggIBACH/M9xbPuKmluznwtwofLod+4w5nTtU
bFpGmqSRNRjnL4j0aL+Gr/lcD2tGQXf01dOVdSbBjmBmW1p/2trVdVPxTLTaIhCw
Q8QuVmQJUkwnG1uv7W9Of9akJ4TadPKc5GfzYJJ+e71Z8sFXxFqfr0nF1fPdpPp8
xkKsIwZopcjqLEzJydGOcHUbDWvR2fkG01DjgSevP34ZJQBm/bSAwlSs6b1119jw
ofQD462YLtXfavSz/MzRNNgCZlEAGVNt42CDOES6aZvOIt1pCKo8hIhptKgU4GpQ
vTE0kdekJWTUNQzbfWSF42FwllxVa4LJYXzmW7Jf30Q5xCZICH1Ofdk3qLK/B7tf
Fo/bNP3aLU4qBWShmCzYAyW4LPKL6AfODL5X45nESQDoAlfcdfeSXrbdG7P0NAcN
g4nROb5NNy/CgLNq2zDnq/JKdW3xvvNKT2FsNvOf3+9a99gB/L2dt8nX5SSLiWlN
50ynzOK21Z/YHCXutLiK2ugQf9dqj2rw7/C9oktoyvqwoVILhcsA0mhpN4343zI4
PK2/zIjd0nZWaZLpJCj0yREnhhqgV3Par9d5biRfgFUuIoBnXIh4fr75xdkxqECX
pKu2rt3D0YGkPsP5lausvPbUy4nYcT1UkMwtdi0JZLNx04m22ZTzXpATo96LoWob
9eRPR6uW/Kmp
-----END CERTIFICATE-----
+38
View File
@@ -0,0 +1,38 @@
---
- name: Internet connection test block
block:
- name: Test reachability to ya.ru
become: yes # Usually it's not necessary, but sometimes there are some wierd issues with ping, especially on Alpine
shell: ping -c 5 ya.ru > /dev/null
changed_when: false # This task does not change the system
rescue:
# This won't work for now. CA certificate reissuing is required!git
- name: Create a test file
become: no
ansible.builtin.uri:
url: "{{ ha_addr }}/api/webhook/{{ ha_webhook_token }}"
ca_path: ../files/ca.pem
delegate_to: 127.0.0.1
# TODO: REMOVE THIS AFTER REISSUING CA CERTIFICATE!
failed_when: false
- name: Disk free space test block
block:
- name: Test free disk space in root
become: no
shell: df -h / | tail -1 | awk '{gsub(/%/, "", $5); print $5}'
register: result
failed_when: result.stdout | int > 85
changed_when: false # This task does not change the system
rescue:
- name: Notify with ntfy
become: no
ansible.builtin.command: |
curl -H "Authorization: Bearer {{ ntfy_topic_token }}" \
-d "{{ ansible_facts['hostname'] }}: Disk space is low" \
{{ ntfy_topic }}
delegate_to: 127.0.0.1
failed_when: false
changed_when: false # This task does not change the system
+1 -1
View File
@@ -1,4 +1,4 @@
#!/bin/sh
ansible-playbook -i inventory/hosts.yaml playbooks/deploy.yaml \
ansible-playbook -i inventory/hosts.yaml $1 \
--private-key inventory/group_vars/secret/ansible_key \
--vault-password-file inventory/group_vars/secret/.vault_pass