feat(maintenance): new checks added, existing improved #6

Merged
max merged 10 commits from dev into main 2026-08-24 13:32:09 +04:00
11 changed files with 95 additions and 30 deletions
+1
View File
@@ -2,3 +2,4 @@
ansible_become_passwd: "{{ ansible_password }}" ansible_become_passwd: "{{ ansible_password }}"
human_admin_user: max human_admin_user: max
proxmox_1_host: 192.168.0.2
+30 -6
View File
@@ -1,17 +1,41 @@
--- ---
physical: all:
children:
physical:
proxmox_1:
ansible_host: "{{ proxmox_1_host }}"
ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: []
virtual:
hosts: hosts:
localhost: localhost:
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
ansible_connection: local ansible_connection: local
ansible_python_interpreter: "{{ ansible_playbook_python }}" ansible_python_interpreter: "{{ ansible_playbook_python }}"
192.168.0.6: services_to_run:
- webhook
nfs-server:
ansible_host: 192.168.0.6
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
192.168.0.8: services_to_run: []
jellyfin:
ansible_host: 192.168.0.8
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
192.168.0.12: services_to_run: []
frigate:
ansible_host: 192.168.0.12
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
192.168.0.16: services_to_run: []
vs-code:
ansible_host: 192.168.0.16
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
192.168.0.39: services_to_run: []
gitea-server:
ansible_host: 192.168.0.39
ansible_become_password: "{{ ansible_become_passwd }}" ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run: []
ai-host:
ansible_host: 192.168.0.50
ansible_become_password: "{{ ansible_become_passwd }}"
services_to_run:
- coder_ai
@@ -25,6 +25,10 @@
prompt: "IP address for the container (in x.x.x.x/x formant)" prompt: "IP address for the container (in x.x.x.x/x formant)"
private: false private: false
- name: lxc_is_privileged
prompt: "Unprivileged LXC (true/false)?"
private: false
pre_tasks: pre_tasks:
- name: Validate hostname - name: Validate hostname
ansible.builtin.fail: ansible.builtin.fail:
+3 -1
View File
@@ -1,6 +1,6 @@
--- ---
- name: Deploy and set up an LXC container in Proxmox - name: Deploy and set up an LXC container in Proxmox
hosts: all hosts: virtual
remote_user: ansible remote_user: ansible
vars_files: vars_files:
@@ -18,3 +18,5 @@
- ../roles/harden_ssh - ../roles/harden_ssh
# Update configs - omz, nvim, ranger and so on. Distribute the last version of those configs # Update configs - omz, nvim, ranger and so on. Distribute the last version of those configs
- ../roles/update_configs - ../roles/update_configs
# Make sure that the services that are supposed to run are running
- ../roles/check_services
+7
View File
@@ -0,0 +1,7 @@
---
- name: Make sure required services are running
ansible.builtin.service:
name: "{{ item }}"
state: started
loop: "{{ services_to_run }}"
+7 -3
View File
@@ -23,8 +23,8 @@
become: false become: false
# We have to use this complicated pipeline because of Alpine and its wierd df implementation # We have to use this complicated pipeline because of Alpine and its wierd df implementation
ansible.builtin.shell: set -o pipefail && df -h / | tail -1 | awk '{gsub(/%/, "", $5); print $5}' ansible.builtin.shell: set -o pipefail && df -h / | tail -1 | awk '{gsub(/%/, "", $5); print $5}'
register: free_disk_space_result register: common_healthcheck_space_left_result
failed_when: free_disk_space_result.stdout | int > 85 failed_when: common_healthcheck_space_left_result.stdout | int > 85
changed_when: false # This task does not change the system changed_when: false # This task does not change the system
rescue: rescue:
@@ -41,5 +41,9 @@
body: body:
- "{{ ansible_facts['hostname'] }}: Disk space is low" - "{{ ansible_facts['hostname'] }}: Disk space is low"
delegate_to: 127.0.0.1 delegate_to: 127.0.0.1
failed_when: false failed_when: false # It's OK if it fails, not critical
changed_when: false # This task does not change the system changed_when: false # This task does not change the system
- name: Resize rootfs if it's an LXC
ansible.builtin.include_tasks: resize_lxc_rootfs.yaml
when: ansible_virtualization_type == 'lxc'
@@ -0,0 +1,24 @@
---
- name: Get container info by name
delegate_to: localhost
become: false
community.general.proxmox_vm_info:
validate_certs: false
node: proxmox-server
api_user: root@pam
api_host: 192.168.0.2
api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}"
name: "{{ inventory_hostname }}"
type: lxc
register: common_healthcheck_vmid
- name: Resize LXC's rootfs
become: true
ansible.builtin.command:
cmd: pct resize {{ common_healthcheck_vmid.proxmox_vms[0].vmid }} rootfs +5G
delegate_to: 192.168.0.2
changed_when: true
vars:
ansible_become_password: "{{ ansible_become_passwd }}"
+3 -2
View File
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -14,6 +14,7 @@
password: "{{ lxc_root_password }}" password: "{{ lxc_root_password }}"
hostname: "{{ lxc_hostname }}" hostname: "{{ lxc_hostname }}"
ostemplate: 'main:vztmpl/debian-13-golden-image.tar.gz' ostemplate: 'main:vztmpl/debian-13-golden-image.tar.gz'
unprivileged: "{{ lxc_is_privileged }}"
memory: 2048 memory: 2048
cores: 2 cores: 2
state: present state: present
@@ -33,7 +34,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -29,7 +29,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -49,7 +49,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -64,10 +64,9 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
name: "{{ vm_hostname }}" name: "{{ vm_hostname }}"
state: started state: started
+1 -1
View File
@@ -5,7 +5,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -6,7 +6,7 @@
validate_certs: false validate_certs: false
node: proxmox-server node: proxmox-server
api_user: root@pam api_user: root@pam
api_host: 192.168.0.2 api_host: "{{ proxmox_1_host }}"
api_token_id: ansible api_token_id: ansible
api_token_secret: "{{ proxmox_token_secret }}" api_token_secret: "{{ proxmox_token_secret }}"
@@ -19,4 +19,3 @@
timeout: 120 timeout: 120
delegate_to: localhost delegate_to: localhost
changed_when: false changed_when: false