Compare commits

...

15 Commits

Author SHA1 Message Date
max cc68a1f863 fix (roles): ssh config to be placed in ~/.shh 2026-09-02 19:08:46 +05:00
max 4897cdadbd feat (roles): copies a config with hosts rules in human admin ~/.ssh 2026-09-01 10:18:30 +05:00
max e0571783ba fix (docs): a typ in README.md 2026-09-01 09:31:48 +05:00
max c633ead7cc CHANGE: updates README.md 2026-08-24 15:28:22 +05:00
max db217f4ce2 Merge pull request 'feat(maintenance): new checks added, existing improved' (#6) from dev into main
Reviewed-on: #6
2026-08-24 13:32:09 +04:00
max cdfcc844e0 FIX: encloses the variable name with brackets and double quotes
Deploy new config to the Ansible server / trigger-webhook (pull_request) Successful in 26s
2026-08-24 14:20:24 +05:00
max 71a98b34ca FEATURE: replaces hardcoded ip of proxmox with a variable 2026-08-24 14:11:42 +05:00
max d2ee60c0fb FIX: become password added to drive resize task 2026-08-24 12:49:18 +04:00
max baab14c3fc FIX: adds 'children' directive in inventory/hosts.yaml 2026-08-23 17:05:57 +05:00
max 5e253db9c7 FEATURE: resizes rootfs if a host is LXC and its rootfs is almost full 2026-08-23 17:02:01 +05:00
max 54ec2bdbee FEATURE: adds proxmox host to inventory, but excludes it from playbooks/maintain.yaml 2026-08-23 17:00:23 +05:00
max 43ce6a94c0 Merge pull request 'CHANGE: ensures pulls and updates before running jobs' (#4) from dev into main
Reviewed-on: #4
2026-08-18 21:24:44 +04:00
max 1ecc1775ef Merge pull request 'FIX: file extensions in update_modules.sh' (#3) from dev into main
Reviewed-on: #3
2026-08-18 15:54:22 +04:00
max 1ed42f148c Merge pull request 'feat(all): updates some configs' (#2) from dev into main
Reviewed-on: #2
2026-08-18 15:41:32 +04:00
max 0b286b5496 Merge pull request 'Dev to main' (#1) from dev into main
Reviewed-on: #1
2026-08-17 12:15:02 +00:00
12 changed files with 123 additions and 48 deletions
+18 -1
View File
@@ -1,3 +1,20 @@
# ansible_home # ansible_home
My own home services automation repository ## How to use it?
It's better to use a virtual environment to avoid incompatibility issues
```bash
git clone https://git.vmn.su/max/vmn-ansible
cd vmn-ansible
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
ansible-galaxy collection install -r requirements.yaml
ansible-galaxy role install -r requirements.yaml
ansible-playbook playbooks/deploy_and_set_up_lxc_on_proxmox.yaml --vault-pass-file $VAULT_PASS_PATH -i inventory/localhost.yaml --private-key $SSH_KEY
```
**deploy** playbooks must be used with `inventory/localhost.yaml`, they need access to proxmox host only
There are also a systemd service and timer under `systemd` directory
+1
View File
@@ -2,3 +2,4 @@
ansible_become_passwd: "{{ ansible_password }}" ansible_become_passwd: "{{ ansible_password }}"
human_admin_user: max human_admin_user: max
proxmox_1_host: 192.168.0.2
+40 -33
View File
@@ -1,34 +1,41 @@
--- ---
physical: all:
hosts: children:
localhost: physical:
ansible_become_password: "{{ ansible_become_passwd }}" proxmox_1:
ansible_connection: local ansible_host: "{{ proxmox_1_host }}"
ansible_python_interpreter: "{{ ansible_playbook_python }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: [] services_to_run: []
nfs-server: virtual:
ansible_host: 192.168.0.6 hosts:
ansible_become_password: "{{ ansible_become_passwd }}" localhost:
services_to_run: [] ansible_become_password: "{{ ansible_become_passwd }}"
jellyfin: ansible_connection: local
ansible_host: 192.168.0.8 ansible_python_interpreter: "{{ ansible_playbook_python }}"
ansible_become_password: "{{ ansible_become_passwd }}" services_to_run:
services_to_run: [] - webhook
frigate: nfs-server:
ansible_host: 192.168.0.12 ansible_host: 192.168.0.6
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: [] services_to_run: []
vs-code: jellyfin:
ansible_host: 192.168.0.16 ansible_host: 192.168.0.8
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: [] services_to_run: []
gitea-server: frigate:
ansible_host: 192.168.0.39 ansible_host: 192.168.0.12
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: [] services_to_run: []
ai-host: vs-code:
ansible_host: 192.168.0.50 ansible_host: 192.168.0.16
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: services_to_run: []
- coder_ai gitea-server:
ansible_host: 192.168.0.39
ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: []
ai-host:
ansible_host: 192.168.0.50
ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run:
- coder_ai
+1 -1
View File
@@ -1,6 +1,6 @@
--- ---
- name: Deploy and set up an LXC container in Proxmox - name: Deploy and set up an LXC container in Proxmox
hosts: all hosts: virtual
remote_user: ansible remote_user: ansible
vars_files: vars_files:
+7 -3
View File
@@ -23,8 +23,8 @@
become: false become: false
# We have to use this complicated pipeline because of Alpine and its wierd df implementation # We have to use this complicated pipeline because of Alpine and its wierd df implementation
ansible.builtin.shell: set -o pipefail && df -h / | tail -1 | awk '{gsub(/%/, "", $5); print $5}' ansible.builtin.shell: set -o pipefail && df -h / | tail -1 | awk '{gsub(/%/, "", $5); print $5}'
register: free_disk_space_result register: common_healthcheck_space_left_result
failed_when: free_disk_space_result.stdout | int > 85 failed_when: common_healthcheck_space_left_result.stdout | int > 85
changed_when: false # This task does not change the system changed_when: false # This task does not change the system
rescue: rescue:
@@ -41,5 +41,9 @@
body: body:
- "{{ ansible_facts['hostname'] }}: Disk space is low" - "{{ ansible_facts['hostname'] }}: Disk space is low"
delegate_to: 127.0.0.1 delegate_to: 127.0.0.1
failed_when: false failed_when: false # It's OK if it fails, not critical
changed_when: false # This task does not change the system changed_when: false # This task does not change the system
- name: Resize rootfs if it's an LXC
ansible.builtin.include_tasks: resize_lxc_rootfs.yaml
when: ansible_virtualization_type == 'lxc'
@@ -0,0 +1,24 @@
---
- name: Get container info by name
delegate_to: localhost
become: false
community.general.proxmox_vm_info:
validate_certs: false
node: proxmox-server
api_user: root@pam
api_host: 192.168.0.2
api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}"
name: "{{ inventory_hostname }}"
type: lxc
register: common_healthcheck_vmid
- name: Resize LXC's rootfs
become: true
ansible.builtin.command:
cmd: pct resize {{ common_healthcheck_vmid.proxmox_vms[0].vmid }} rootfs +5G
delegate_to: 192.168.0.2
changed_when: true
vars:
ansible_become_password: "{{ ansible_become_passwd }}"
+2 -2
View File
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -34,7 +34,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -29,7 +29,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -49,7 +49,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -64,10 +64,9 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
name: "{{ vm_hostname }}" name: "{{ vm_hostname }}"
state: started state: started
+1 -1
View File
@@ -5,7 +5,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -19,4 +19,3 @@
timeout: 120 timeout: 120
delegate_to: localhost delegate_to: localhost
changed_when: false changed_when: false
+15
View File
@@ -0,0 +1,15 @@
# PUT NEW BLOCKS STRICTLY BEFORE ANY MATCH BLOCK
# Private keys are NOT distributed via Ansible
# They must to be copied manually ONLY to those hosts that need access to others
# Most of the home major LAN hosts should be accessible with this key
Match Host 192.168.0.?
User max
IdentityFile ~/.ssh/max_regular_key
# This virtual network has the same hosts range
Match Host 10.9.2.?
User max
IdentityFile ~/.ssh/max_regular_key
+9
View File
@@ -48,6 +48,15 @@
group: "{{ human_admin_user }}" group: "{{ human_admin_user }}"
mode: u=rw,g=r,o-rwx mode: u=rw,g=r,o-rwx
- name: Configure ssh client, by pushing the config
remote_user: ansible
ansible.builtin.copy:
src: "{{ role_path }}/files/ssh_config"
dest: "/home/{{ human_admin_user }}/.ssh/config"
owner: "{{ human_admin_user }}"
group: "{{ human_admin_user }}"
mode: u=rw,g=r,o-rwx
# WARNING: we've finished with the initial setup, drop ansible key # WARNING: we've finished with the initial setup, drop ansible key
# Push regular user key # Push regular user key