Compare commits

...

8 Commits

14 changed files with 181 additions and 6 deletions

2
.gitignore vendored
View File

@@ -5,6 +5,8 @@
.ansible_cache .ansible_cache
.ansible_check_mode .ansible_check_mode
fact_cache/ fact_cache/
*galaxy_cache/
*galaxy_token
# --- ROLES & COLLECTIONS --- # --- ROLES & COLLECTIONS ---
# On ignore les rôles téléchargés depuis Galaxy (ils sont définis dans requirements.yml) # On ignore les rôles téléchargés depuis Galaxy (ils sont définis dans requirements.yml)

View File

@@ -31,3 +31,8 @@ Use "ansible-vault view" to read the decrypted content of vault file without mod
> ansible-vault edit ansible/vars/vault.yml > ansible-vault edit ansible/vars/vault.yml
## Ansible Galaxy Collections
- lucasheld.uptime_kuma [https://galaxy.ansible.com/ui/repo/published/lucasheld/uptime_kuma/]

View File

@@ -10,27 +10,38 @@ pve1 ansible_host=192.168.1.251
pve2 ansible_host=192.168.1.253 pve2 ansible_host=192.168.1.253
pve3 ansible_host=192.168.1.252 pve3 ansible_host=192.168.1.252
[pve-tools] [pve_tools]
pdm ansible_host=192.168.1.189 pdm ansible_host=192.168.1.189
pbs ansible_host=192.168.1.91 pbs ansible_host=192.168.1.91
[dns-server] [dns_server]
pihole ansible_host=192.168.1.9 pihole ansible_host=192.168.1.9
ns1 ansible_host=192.168.1.8 ns1 ansible_host=192.168.1.8
ns2 ansible_host=192.168.1.7 ns2 ansible_host=192.168.1.7
[dhcp-server] [dhcp_server]
dhcp ansible_host=192.168.1.5 dhcp ansible_host=192.168.1.5
[web-service] [web_service]
observatoire ansible_host=192.168.1.61 observatoire ansible_host=192.168.1.61
nginx ansible_host=192.168.1.201 nginx ansible_host=192.168.1.201
ncloud ansible_host=192.168.1.239 ncloud ansible_host=192.168.1.239
futursenuage ansible_host=192.168.1.168
[matrix_server]
matrix ansible_host=192.168.1.87
synapse-admin ansible_host=synapse-admin.teyssier.lan
[vpn] [vpn]
vypyhaine ansible_host=192.168.1.97 vypyhaine ansible_host=192.168.1.97
[automatisation]
ansible ansible_host=192.168.1.66 ansible_user=riesjack
[kubernetes] [kubernetes]
k3s-master ansible_host=192.168.1.10 k3s-master ansible_host=192.168.1.10
k3s-worker-1 ansible_host=192.168.1.11 k3s-worker-1 ansible_host=192.168.1.11
k3s-worker-2 ansible_host=192.168.1.12 k3s-worker-2 ansible_host=192.168.1.12
[testing]
test ansible_host=test.teyssier.lan

13
playbook/deploy_nvim.yml Normal file
View File

@@ -0,0 +1,13 @@
---
- name: Deploy and config
gather_facts: true
hosts: all
roles:
- deploy_nvim
vars:
nvim_config_repo: "https://versionning.teyssier.lan/mteyssier/nvim.git"
nvim_version: "v0.11.6" # Ou "nightly"
user_name: "{{ ansible_user_id }}"
user_home: "{{ ansible_env.HOME }}"

View File

@@ -0,0 +1,6 @@
---
- name: Deploy and config
gather_facts: true
hosts: all
roles:
- deploy_root_ca

8
playbook/new_server.yml Normal file
View File

@@ -0,0 +1,8 @@
---
- name: Deploy necessary personal tools
hosts: all
roles:
- deploy_ssh_key
- deploy_root_ca
- deploy_nvim
- prometheus-agent

5
playbook/uptime-kuma.yml Normal file
View File

@@ -0,0 +1,5 @@
---
- name: uptime_kuma playbook
hosts: all
roles:
- uptime-kuma

View File

@@ -0,0 +1,62 @@
---
- name: Install system dependencies (Ubuntu/Debian)
become: true
apt:
name:
- git
- curl
- build-essential # Pour Treesitter (gcc/make)
- unzip
- python3-pip
- nodejs # Pour certains serveurs LSP (Pyright, etc.)
- npm
- ripgrep # Pour Telescope
- fd-find # Pour Telescope
state: present
update_cache: yes
- name: Download Neovim Binary via Curl (Bypass get_url SSL bug)
become: true
command: >
curl -L -o /tmp/nvim.tar.gz
https://github.com/neovim/neovim/releases/download/{{ nvim_version }}/nvim-linux-x86_64.tar.gz
args:
creates: "/tmp/nvim.tar.gz" # Ne télécharge pas si déjà présent
- name: Extract Neovim
become: true
unarchive:
src: "/tmp/nvim.tar.gz"
dest: "/opt"
remote_src: yes
- name: Create symbolic link to /usr/local/bin
become: true
file:
src: "/opt/nvim-linux-x86_64/bin/nvim"
dest: "/usr/local/bin/nvim"
state: link
- name: Ensure .config directory exists
file:
path: "{{ user_home }}/.config/nvim"
state: directory
owner: "{{ user_name }}"
mode: '0755'
become: no
- name: Clone Neovim Configuration from Git
git:
repo: "{{ nvim_config_repo }}"
dest: "{{ user_home }}/.config/nvim"
force: yes
become: no
- name: Final check - Neovim version
command: nvim --version
register: nvim_check
changed_when: false
- debug:
msg: "Neovim installé avec succès : {{ nvim_check.stdout_lines[0] }}"

View File

@@ -0,0 +1,6 @@
nvim_config_repo: "https://versionning.teyssier.lan/mteyssier/nvim.git"
nvim_version: "v0.11.6" # Ou "nightly"
user_name: "{{ ansible_user_id }}"
user_home: "{{ ansible_env.HOME }}"

View File

@@ -0,0 +1,15 @@
---
- name: Make sure the folder exists
file:
path: /usr/local/share/ca-certificates
state: directory
- name: Copy the certificate (Debian, Ubuntu)
copy:
src: "/home/riesjack/ansible/roles/deploy_root_ca/template/root_ca_teyssier-lan.crt"
dest: "/usr/local/share/ca-certificates/root_ca_teyssier-lan.crt"
register: result
- name: Update CA Trust (Debian, Ubuntu)
command: update-ca-certificates
when: result is changed

View File

@@ -0,0 +1,12 @@
-----BEGIN CERTIFICATE-----
MIIBtzCCAV6gAwIBAgIRANuBmXvozSr/3UZhmBRBgb0wCgYIKoZIzj0EAwIwOjEX
MBUGA1UEChMOTVRFLUhvbWVMYWItQ0ExHzAdBgNVBAMTFk1URS1Ib21lTGFiLUNB
IFJvb3QgQ0EwHhcNMjYwMjE5MjMyOTMwWhcNMzYwMjE3MjMyOTMwWjA6MRcwFQYD
VQQKEw5NVEUtSG9tZUxhYi1DQTEfMB0GA1UEAxMWTVRFLUhvbWVMYWItQ0EgUm9v
dCBDQTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFiah3HIaLfJ6Bj/bs4nA21K
w0oaNgjaxF0XKvRgNX4nWj7lzWRM5RvqtuZuX4l1KcfFq8GP9MCdKM9qsihe+1qj
RTBDMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQW
BBTdprIba2EdXlvq7y0EIcGmBVC7LjAKBggqhkjOPQQDAgNHADBEAiAw1BtCe/Dv
73SIhXvDeeDxmLu0VtLSzvEIRLhXW2OgsQIgA0e4OCvHg1m/dqJLEGvkyLezvFRR
196Ykc61ugWh6cU=
-----END CERTIFICATE-----

View File

@@ -0,0 +1,14 @@
---
- name: Charger les secrets du Vault
include_vars:
file: vault.yml # Il cherchera par défaut dans le dossier vars/ du rôle
- name: Login by token and create a monitor
lucasheld.uptime_kuma.monitor:
api_url: "{{ api_url }}"
api_token: "{{ uptime_kuma_api_key }}"
name: "{{ host_name }}"
type: ping
url: "{{ url }}"
state: present
...

View File

@@ -0,0 +1,7 @@
---
domain_name: teyssier.lan
host_name: futurenuage
uptime_kuma_host: "uptime-kuma.{{ domain_name }}"
url: nc.teyssier.lan
api_url: "https://{{ uptime_kuma_host }}"
uptime_kuma_api_key: "{{ secret_uptime_kuma_api_key }}"

View File

@@ -0,0 +1,9 @@
$ANSIBLE_VAULT;1.1;AES256
31646463313736336435343930383232376132366237383439373964353432306234346265646235
3131306234316163373663643666636630326565373731330a333562356437613566313562373831
63613064303764663833643662653036386530613734316537383638663563633463393164346666
6465343462666438350a393433636561623633653761643939306165303930376138643364633565
61303137313931356439663232623138396464353434333434343461663238643464633861626634
35333161653933643939306265313736616634353562326437663461656232316137623365613761
37663035666134646237386134646132663936323130333265643235343531346465306666323762
33323362643534323934