Commit graph

133 commits

Author SHA1 Message Date
7eabd88e2c
unbound(role): update readme and move task block to top level and remove unused 2026-08-07 22:55:57 +02:00
32caa40f77
unbound(role): fix some unbound setup stuff 2026-08-07 22:55:55 +02:00
8d9cb0007c
kea_dhcp(role): update to newest fux noc version 2026-08-07 22:55:55 +02:00
9271cbda97
unbound(role): fix systemd unit of prometheus exporter 2026-08-07 22:55:34 +02:00
83f654037a
unbound(role): fix unbound prometheus exporter install on debian
- download debian image from github und verify checksum
- setup systemd service unit
2026-08-07 22:55:33 +02:00
6b05c4b05a
unbound(role): fix unbound config template
- fix some indentation problems
- fix access control
- fix remote control unix socket and thrust anchor file (because debain
appamour ist annoying)
  - add unbound-anchor package
2026-08-07 22:55:33 +02:00
db6ef3fcb2
kea_dhcp(role): fix include wars check 2026-08-07 22:55:33 +02:00
a0b0e8188f
unbound(role): move resolvd vars to task 2026-08-07 22:55:33 +02:00
5423558ab4
unbound(role): make unbound thread number configurable 2026-08-07 22:55:32 +02:00
bb141ddab3
unbound(role): reformat config template and use all vcpus 2026-08-07 22:55:32 +02:00
9a5dafb2bc
unbound(role): remove tags inside role 2026-08-07 22:55:32 +02:00
a4bb9a82d2
unbound(role): add FIXME note to unbound prometheus exporter install 2026-08-07 22:55:32 +02:00
1a0ac38861
unbound(role): use existing deploy_systemd_resolved_config role and some reordering 2026-08-07 22:55:32 +02:00
613e0528d7
kea_dhcp(role): make stork-agent.env smaller and add link to documentation 2026-08-07 22:55:32 +02:00
6734843e8a
kea_dhcp(role): fix indentation in template 2026-08-07 22:55:32 +02:00
c803b1fc67
kea_dhcp(role): add README.md 2026-08-07 22:55:31 +02:00
7440e8fd15
kea_dhcp(role): some fixes and removing arch part
- remove tags from tasks
- remove archlinux part
- use debian default package for kea
2026-08-07 22:55:31 +02:00
010b8d1224
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-08-07 22:55:31 +02:00
9a78164b7b
roles(dooris): remove blank line to make ansible-lint happy
All checks were successful
/ build (push) Successful in 30s
/ Ansible Lint (push) Successful in 2m28s
2026-08-03 00:06:44 +02:00
de8daaf56c
add dooris role for setup of dooris interaction on the node itself
Some checks failed
/ build (pull_request) Successful in 28s
/ Ansible Lint (pull_request) Failing after 3m49s
/ cleanup-staging (pull_request) Successful in 6s
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m35s
2026-07-29 14:16:04 +02:00
699a2bcfff
specify that docker_compose role may not be included twice
Our docker compose role is configured via ansible variables in a way
that overwrites each other if it is activated twice with different
variable assignments (unless e.g. a role that just installs more
packages).
To prevent misuse of the role, the allow_duplicates key of the role
meta is set to false. This should make ansible complain if the role
is included twice for a single host.
2026-07-29 14:16:04 +02:00
4218b59d3b
fix: alloy role the suites for deb repo must be stable
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 2m27s
2026-07-23 22:08:58 +02:00
900971ebe9 alloy(role): pull in alloy role that works from fux (#112)
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m39s
Reviewed-on: #112
Reviewed-by: June <june@noreply.git.hamburg.ccc.de>
2026-07-23 20:34:02 +02:00
a35326a065
transmission(role): running the handler should always report changed
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 2m42s
Make ansible-lint happy by specifying that.
2026-07-08 00:59:02 +02:00
81b16a04cb Explain why this is necessary
Some checks failed
/ build (push) Successful in 48s
/ Ansible Lint (push) Failing after 2m42s
2026-07-05 10:40:29 +02:00
0acc56b238
docker(role): document gVisor issue with user-def. br. and provide help
Document issue with containers on user-defined bridges and using the
gVisor runsc runtime. Also provide a helper resolv.conf as a workaround.
2026-07-03 03:42:18 +02:00
2e50226b94
docker(role): provide option to set up gVisor (runsc runtime) 2026-07-03 03:42:18 +02:00
7d7cf455eb
forgejo_runner(role): create role for setting up Forgejo Runner install 2026-07-03 03:42:18 +02:00
3e0fdb6074 Configure transmission 2026-06-28 17:02:05 +02:00
5973de0959
dns: validate zone files before apply in knot role
Some checks failed
/ build (push) Failing after 2m44s
/ Ansible Lint (push) Successful in 3m23s
2026-06-10 16:17:58 +02:00
8ca5d82d39
knot: fix templating inconsistency in netplan config 2026-06-06 15:06:11 +02:00
3a09c107b9
knot: use explicit ansible_facts reference 2026-06-06 14:59:16 +02:00
4574dbf4ba
secrets(role): introduce secrets role for storing secrets
Some checks failed
/ Ansible Lint (push) Successful in 2m18s
/ build (push) Failing after 2m40s
Allows storage of secrets to then be referenced in other places.
The motivation was storing WireGuard secrets for systemd-networkd.
2026-05-23 22:40:17 +02:00
3541c68357
disable dnssec for catalog zones on auth-dns
All checks were successful
/ Ansible Lint (push) Successful in 2m35s
Catalog zones are not real zones in the DNS hierarchy and don't
have a parent zone. Therefore they will never have a valid DNSSEC
delegation so we should skip signing those zones.
2026-05-19 11:01:52 +02:00
73e77bde70
tag plays in playbooks (instead of tasks in roles)
All checks were successful
/ Ansible Lint (pull_request) Successful in 3m18s
/ Ansible Lint (push) Successful in 2m20s
2026-05-19 00:24:10 +02:00
6b19f69135
renovate(role): add cleanup service and timer for renovate volume
All checks were successful
/ Ansible Lint (push) Successful in 2m25s
With time the volume seems to just keeps growing with cache data, so
clean it up once a day.
2026-05-19 00:23:26 +02:00
83e6f76464 deploy_systemd_journal_config(role): Disable ForwardToSyslog
Some checks failed
/ Ansible Lint (pull_request) Failing after 29m12s
/ Ansible Lint (push) Successful in 41m19s
We don't want hour journalctl logs mirrored to /var/log/syslog
2026-05-15 19:25:44 +02:00
637dc6b25a
consider ansible-pull jobs failed after 30 minutes
All checks were successful
/ Ansible Lint (pull_request) Successful in 2m27s
/ Ansible Lint (push) Successful in 2m32s
2026-05-13 16:53:57 +02:00
bc4df9a3f4
fix ansible-lint warnings of knot role
All checks were successful
/ Ansible Lint (push) Successful in 2m31s
2026-05-07 23:45:48 +02:00
50beedbc62
configure metric scraping from knot on auth-dns
Some checks failed
/ Ansible Lint (push) Failing after 6m12s
2026-05-06 15:51:38 +02:00
5283d2da95
improve knot roles reloading behavior
With this change, the nameserver is not restarted on configuration
updates but only reloaded instead.
2026-05-06 14:33:04 +02:00
3aa146d723
nftables(role): reload instead of restart
Some checks failed
/ Ansible Lint (push) Failing after 3m22s
This should make the role more robust against misconfigurations.
2026-05-06 14:19:38 +02:00
fa021fb737
migrate dns zone ccchh.net. to new auth-dns server
All checks were successful
/ Ansible Lint (push) Successful in 2m27s
2026-05-06 12:12:54 +02:00
416ca85b11
rename auth_dns -> knot role
Some checks failed
/ Ansible Lint (pull_request) Successful in 2m37s
/ Ansible Lint (push) Has been cancelled
2026-05-06 11:52:33 +02:00
8c1553c707
fix role name auth-dns -> auth_dns
Some checks failed
/ Ansible Lint (push) Failing after 2m38s
/ Ansible Lint (pull_request) Failing after 2m40s
2026-05-06 11:47:10 +02:00
6fa2d65db2
enable auth-dns role to actually configure useful zones 2026-05-06 11:47:10 +02:00
fa94d59df6
add barebones knot config
This configuration does not yet do much but it provisions a knot
server that runs.
2026-05-06 11:47:10 +02:00
d880eb8677
fix systemd-resolved not being installed
All checks were successful
/ Ansible Lint (pull_request) Successful in 2m27s
/ Ansible Lint (push) Successful in 2m25s
closes #88
2026-05-03 16:50:45 +02:00
c304a1c82a
add README.md to deploy_systemd_resolved_config role
All checks were successful
/ Ansible Lint (pull_request) Successful in 2m31s
/ Ansible Lint (push) Successful in 2m24s
2026-05-02 01:01:23 +02:00
58ced1a85e
add capability to disable systemd-resolved to base_config role
All checks were successful
/ Ansible Lint (push) Successful in 2m28s
/ Ansible Lint (pull_request) Successful in 2m24s
2026-05-01 00:16:43 +02:00