Compare commits
8 Commits
7913e36080
...
main
| Author | SHA256 | Date | |
|---|---|---|---|
| 012f6c8a95 | |||
| b5ad4b21cb | |||
| d00679880b | |||
| 449af922ee | |||
| c7c567c9b3 | |||
| 98fed16975 | |||
| 3a6ee4d705 | |||
| bb175dc5fd |
2
.gitignore
vendored
2
.gitignore
vendored
@@ -5,6 +5,8 @@
|
|||||||
.ansible_cache
|
.ansible_cache
|
||||||
.ansible_check_mode
|
.ansible_check_mode
|
||||||
fact_cache/
|
fact_cache/
|
||||||
|
*galaxy_cache/
|
||||||
|
*galaxy_token
|
||||||
|
|
||||||
# --- ROLES & COLLECTIONS ---
|
# --- ROLES & COLLECTIONS ---
|
||||||
# On ignore les rôles téléchargés depuis Galaxy (ils sont définis dans requirements.yml)
|
# On ignore les rôles téléchargés depuis Galaxy (ils sont définis dans requirements.yml)
|
||||||
|
|||||||
@@ -31,3 +31,8 @@ Use "ansible-vault view" to read the decrypted content of vault file without mod
|
|||||||
> ansible-vault edit ansible/vars/vault.yml
|
> ansible-vault edit ansible/vars/vault.yml
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Ansible Galaxy Collections
|
||||||
|
|
||||||
|
- lucasheld.uptime_kuma [https://galaxy.ansible.com/ui/repo/published/lucasheld/uptime_kuma/]
|
||||||
@@ -10,27 +10,38 @@ pve1 ansible_host=192.168.1.251
|
|||||||
pve2 ansible_host=192.168.1.253
|
pve2 ansible_host=192.168.1.253
|
||||||
pve3 ansible_host=192.168.1.252
|
pve3 ansible_host=192.168.1.252
|
||||||
|
|
||||||
[pve-tools]
|
[pve_tools]
|
||||||
pdm ansible_host=192.168.1.189
|
pdm ansible_host=192.168.1.189
|
||||||
pbs ansible_host=192.168.1.91
|
pbs ansible_host=192.168.1.91
|
||||||
|
|
||||||
[dns-server]
|
[dns_server]
|
||||||
pihole ansible_host=192.168.1.9
|
pihole ansible_host=192.168.1.9
|
||||||
ns1 ansible_host=192.168.1.8
|
ns1 ansible_host=192.168.1.8
|
||||||
ns2 ansible_host=192.168.1.7
|
ns2 ansible_host=192.168.1.7
|
||||||
|
|
||||||
[dhcp-server]
|
[dhcp_server]
|
||||||
dhcp ansible_host=192.168.1.5
|
dhcp ansible_host=192.168.1.5
|
||||||
|
|
||||||
[web-service]
|
[web_service]
|
||||||
observatoire ansible_host=192.168.1.61
|
observatoire ansible_host=192.168.1.61
|
||||||
nginx ansible_host=192.168.1.201
|
nginx ansible_host=192.168.1.201
|
||||||
ncloud ansible_host=192.168.1.239
|
ncloud ansible_host=192.168.1.239
|
||||||
|
futursenuage ansible_host=192.168.1.168
|
||||||
|
|
||||||
|
[matrix_server]
|
||||||
|
matrix ansible_host=192.168.1.87
|
||||||
|
synapse-admin ansible_host=synapse-admin.teyssier.lan
|
||||||
|
|
||||||
[vpn]
|
[vpn]
|
||||||
vypyhaine ansible_host=192.168.1.97
|
vypyhaine ansible_host=192.168.1.97
|
||||||
|
|
||||||
|
[automatisation]
|
||||||
|
ansible ansible_host=192.168.1.66 ansible_user=riesjack
|
||||||
|
|
||||||
[kubernetes]
|
[kubernetes]
|
||||||
k3s-master ansible_host=192.168.1.10
|
k3s-master ansible_host=192.168.1.10
|
||||||
k3s-worker-1 ansible_host=192.168.1.11
|
k3s-worker-1 ansible_host=192.168.1.11
|
||||||
k3s-worker-2 ansible_host=192.168.1.12
|
k3s-worker-2 ansible_host=192.168.1.12
|
||||||
|
|
||||||
|
[testing]
|
||||||
|
test ansible_host=test.teyssier.lan
|
||||||
|
|||||||
13
playbook/deploy_nvim.yml
Normal file
13
playbook/deploy_nvim.yml
Normal file
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
- name: Deploy and config
|
||||||
|
gather_facts: true
|
||||||
|
hosts: all
|
||||||
|
roles:
|
||||||
|
- deploy_nvim
|
||||||
|
vars:
|
||||||
|
nvim_config_repo: "https://versionning.teyssier.lan/mteyssier/nvim.git"
|
||||||
|
nvim_version: "v0.11.6" # Ou "nightly"
|
||||||
|
user_name: "{{ ansible_user_id }}"
|
||||||
|
user_home: "{{ ansible_env.HOME }}"
|
||||||
|
|
||||||
|
|
||||||
6
playbook/deploy_root_ca.yml
Normal file
6
playbook/deploy_root_ca.yml
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: Deploy and config
|
||||||
|
gather_facts: true
|
||||||
|
hosts: all
|
||||||
|
roles:
|
||||||
|
- deploy_root_ca
|
||||||
8
playbook/new_server.yml
Normal file
8
playbook/new_server.yml
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
- name: Deploy necessary personal tools
|
||||||
|
hosts: all
|
||||||
|
roles:
|
||||||
|
- deploy_ssh_key
|
||||||
|
- deploy_root_ca
|
||||||
|
- deploy_nvim
|
||||||
|
- prometheus-agent
|
||||||
5
playbook/uptime-kuma.yml
Normal file
5
playbook/uptime-kuma.yml
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
- name: uptime_kuma playbook
|
||||||
|
hosts: all
|
||||||
|
roles:
|
||||||
|
- uptime-kuma
|
||||||
62
roles/deploy_nvim/tasks/main.yml
Normal file
62
roles/deploy_nvim/tasks/main.yml
Normal file
@@ -0,0 +1,62 @@
|
|||||||
|
---
|
||||||
|
- name: Install system dependencies (Ubuntu/Debian)
|
||||||
|
become: true
|
||||||
|
apt:
|
||||||
|
name:
|
||||||
|
- git
|
||||||
|
- curl
|
||||||
|
- build-essential # Pour Treesitter (gcc/make)
|
||||||
|
- unzip
|
||||||
|
- python3-pip
|
||||||
|
- nodejs # Pour certains serveurs LSP (Pyright, etc.)
|
||||||
|
- npm
|
||||||
|
- ripgrep # Pour Telescope
|
||||||
|
- fd-find # Pour Telescope
|
||||||
|
state: present
|
||||||
|
update_cache: yes
|
||||||
|
|
||||||
|
- name: Download Neovim Binary via Curl (Bypass get_url SSL bug)
|
||||||
|
become: true
|
||||||
|
command: >
|
||||||
|
curl -L -o /tmp/nvim.tar.gz
|
||||||
|
https://github.com/neovim/neovim/releases/download/{{ nvim_version }}/nvim-linux-x86_64.tar.gz
|
||||||
|
args:
|
||||||
|
creates: "/tmp/nvim.tar.gz" # Ne télécharge pas si déjà présent
|
||||||
|
|
||||||
|
|
||||||
|
- name: Extract Neovim
|
||||||
|
become: true
|
||||||
|
unarchive:
|
||||||
|
src: "/tmp/nvim.tar.gz"
|
||||||
|
dest: "/opt"
|
||||||
|
remote_src: yes
|
||||||
|
|
||||||
|
- name: Create symbolic link to /usr/local/bin
|
||||||
|
become: true
|
||||||
|
file:
|
||||||
|
src: "/opt/nvim-linux-x86_64/bin/nvim"
|
||||||
|
dest: "/usr/local/bin/nvim"
|
||||||
|
state: link
|
||||||
|
|
||||||
|
- name: Ensure .config directory exists
|
||||||
|
file:
|
||||||
|
path: "{{ user_home }}/.config/nvim"
|
||||||
|
state: directory
|
||||||
|
owner: "{{ user_name }}"
|
||||||
|
mode: '0755'
|
||||||
|
become: no
|
||||||
|
|
||||||
|
- name: Clone Neovim Configuration from Git
|
||||||
|
git:
|
||||||
|
repo: "{{ nvim_config_repo }}"
|
||||||
|
dest: "{{ user_home }}/.config/nvim"
|
||||||
|
force: yes
|
||||||
|
become: no
|
||||||
|
|
||||||
|
- name: Final check - Neovim version
|
||||||
|
command: nvim --version
|
||||||
|
register: nvim_check
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- debug:
|
||||||
|
msg: "Neovim installé avec succès : {{ nvim_check.stdout_lines[0] }}"
|
||||||
6
roles/deploy_nvim/vars/main.yml
Normal file
6
roles/deploy_nvim/vars/main.yml
Normal file
@@ -0,0 +1,6 @@
|
|||||||
|
nvim_config_repo: "https://versionning.teyssier.lan/mteyssier/nvim.git"
|
||||||
|
nvim_version: "v0.11.6" # Ou "nightly"
|
||||||
|
user_name: "{{ ansible_user_id }}"
|
||||||
|
user_home: "{{ ansible_env.HOME }}"
|
||||||
|
|
||||||
|
|
||||||
15
roles/deploy_root_ca/tasks/main.yml
Normal file
15
roles/deploy_root_ca/tasks/main.yml
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
- name: Make sure the folder exists
|
||||||
|
file:
|
||||||
|
path: /usr/local/share/ca-certificates
|
||||||
|
state: directory
|
||||||
|
|
||||||
|
- name: Copy the certificate (Debian, Ubuntu)
|
||||||
|
copy:
|
||||||
|
src: "/home/riesjack/ansible/roles/deploy_root_ca/template/root_ca_teyssier-lan.crt"
|
||||||
|
dest: "/usr/local/share/ca-certificates/root_ca_teyssier-lan.crt"
|
||||||
|
register: result
|
||||||
|
|
||||||
|
- name: Update CA Trust (Debian, Ubuntu)
|
||||||
|
command: update-ca-certificates
|
||||||
|
when: result is changed
|
||||||
12
roles/deploy_root_ca/template/root_ca_teyssier-lan.crt
Normal file
12
roles/deploy_root_ca/template/root_ca_teyssier-lan.crt
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIBtzCCAV6gAwIBAgIRANuBmXvozSr/3UZhmBRBgb0wCgYIKoZIzj0EAwIwOjEX
|
||||||
|
MBUGA1UEChMOTVRFLUhvbWVMYWItQ0ExHzAdBgNVBAMTFk1URS1Ib21lTGFiLUNB
|
||||||
|
IFJvb3QgQ0EwHhcNMjYwMjE5MjMyOTMwWhcNMzYwMjE3MjMyOTMwWjA6MRcwFQYD
|
||||||
|
VQQKEw5NVEUtSG9tZUxhYi1DQTEfMB0GA1UEAxMWTVRFLUhvbWVMYWItQ0EgUm9v
|
||||||
|
dCBDQTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABFiah3HIaLfJ6Bj/bs4nA21K
|
||||||
|
w0oaNgjaxF0XKvRgNX4nWj7lzWRM5RvqtuZuX4l1KcfFq8GP9MCdKM9qsihe+1qj
|
||||||
|
RTBDMA4GA1UdDwEB/wQEAwIBBjASBgNVHRMBAf8ECDAGAQH/AgEBMB0GA1UdDgQW
|
||||||
|
BBTdprIba2EdXlvq7y0EIcGmBVC7LjAKBggqhkjOPQQDAgNHADBEAiAw1BtCe/Dv
|
||||||
|
73SIhXvDeeDxmLu0VtLSzvEIRLhXW2OgsQIgA0e4OCvHg1m/dqJLEGvkyLezvFRR
|
||||||
|
196Ykc61ugWh6cU=
|
||||||
|
-----END CERTIFICATE-----
|
||||||
14
roles/uptime-kuma/tasks/main.yml
Normal file
14
roles/uptime-kuma/tasks/main.yml
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
- name: Charger les secrets du Vault
|
||||||
|
include_vars:
|
||||||
|
file: vault.yml # Il cherchera par défaut dans le dossier vars/ du rôle
|
||||||
|
|
||||||
|
- name: Login by token and create a monitor
|
||||||
|
lucasheld.uptime_kuma.monitor:
|
||||||
|
api_url: "{{ api_url }}"
|
||||||
|
api_token: "{{ uptime_kuma_api_key }}"
|
||||||
|
name: "{{ host_name }}"
|
||||||
|
type: ping
|
||||||
|
url: "{{ url }}"
|
||||||
|
state: present
|
||||||
|
...
|
||||||
7
roles/uptime-kuma/vars/main.yml
Normal file
7
roles/uptime-kuma/vars/main.yml
Normal file
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
domain_name: teyssier.lan
|
||||||
|
host_name: futurenuage
|
||||||
|
uptime_kuma_host: "uptime-kuma.{{ domain_name }}"
|
||||||
|
url: nc.teyssier.lan
|
||||||
|
api_url: "https://{{ uptime_kuma_host }}"
|
||||||
|
uptime_kuma_api_key: "{{ secret_uptime_kuma_api_key }}"
|
||||||
9
roles/uptime-kuma/vars/vault.yml
Normal file
9
roles/uptime-kuma/vars/vault.yml
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
31646463313736336435343930383232376132366237383439373964353432306234346265646235
|
||||||
|
3131306234316163373663643666636630326565373731330a333562356437613566313562373831
|
||||||
|
63613064303764663833643662653036386530613734316537383638663563633463393164346666
|
||||||
|
6465343462666438350a393433636561623633653761643939306165303930376138643364633565
|
||||||
|
61303137313931356439663232623138396464353434333434343461663238643464633861626634
|
||||||
|
35333161653933643939306265313736616634353562326437663461656232316137623365613761
|
||||||
|
37663035666134646237386134646132663936323130333265643235343531346465306666323762
|
||||||
|
33323362643534323934
|
||||||
Reference in New Issue
Block a user