ansible/site.yml

58 lines
1.7 KiB
YAML
Raw Normal View History

2020-10-17 00:21:57 -05:00
#!/usr/bin/env ansible-playbook
# vim:ft=ansible:
2020-10-17 01:00:06 -05:00
---
2020-10-17 18:06:35 -05:00
# Preambulatory system configuration
2020-10-17 00:21:57 -05:00
- hosts: all
tasks:
- name: collect service facts
service_facts:
tags: [ always ]
2020-10-17 00:21:57 -05:00
roles:
- role: common
2020-10-17 01:00:06 -05:00
tags: [ common ]
2021-02-26 10:07:57 -06:00
- role: adminuser
tags: [ adminuser, common ]
2021-08-07 16:55:28 -05:00
- role: docker
tags: [ docker, common, skip-pull ]
2021-08-07 16:52:19 -05:00
- role: motd
vars:
motd_watch_services_extra:
- apache2
- docker
- kubelet
- php7.4-fpm
- postgresql
tags: [ motd, common ]
2021-03-11 08:04:57 -06:00
- role: sshd
vars:
sshd:
AcceptEnv: "LANG LC_*"
ChallengeResponseAuthentication: no
Compression: yes
PasswordAuthentication: no
PermitRootLogin: no
PrintMotd: no
PubkeyAuthentication: yes
Subsystem: "sftp /usr/lib/openssh/sftp-server"
UsePAM: yes
X11Forwarding: no
tags: [ sshd, common ]
2021-08-23 20:28:18 -05:00
# Manufacturer configuration
- import_playbook: playbooks/manufacturers_raspi.yml
# Tags for fundamental services
- import_playbook: playbooks/tags_zerotier.yml
- import_playbook: playbooks/tags_snmp.yml
- import_playbook: playbooks/tags_nagios-nrpe.yml
# Device roles
- import_playbook: playbooks/device_roles_pik8s-storage.yml
- import_playbook: playbooks/device_roles_pik8s.yml
- import_playbook: playbooks/device_roles_workstation.yml
# Production configuration
- import_playbook: playbooks/prod_db.yml
- import_playbook: playbooks/prod_web.yml
- import_playbook: playbooks/prod_game.yml
# Supplementary tags
- import_playbook: playbooks/tags_ansible-pull.yml
2021-08-23 20:28:18 -05:00
# Housekeeping tags for one-off tasks
- import_playbook: playbooks/tags_docker-prune.yml