Commit graph

815 commits

Author SHA1 Message Date
c3a88dc03e
z9-router(host): nftables conf fix indent and allow dhcpv6 2026-07-31 18:25:47 +02:00
937ddaf788
unbound(role): fix systemd unit of prometheus exporter 2026-07-31 18:25:47 +02:00
dbf163ef3f
z9-router(host): fix systemd-networkd configs 2026-07-31 18:25:47 +02:00
1f6d38aeb4
unbound(role): fix unbound prometheus exporter install on debian
- download debian image from github und verify checksum
- setup systemd service unit
2026-07-31 18:25:46 +02:00
d6c6139be7
unbound(role): fix unbound config template
- fix some indentation problems
- fix access control
- fix remote control unix socket and thrust anchor file (because debain
appamour ist annoying)
  - add unbound-anchor package
2026-07-31 18:25:46 +02:00
4e932fc8d1
kea_dhcp(role): fix include wars check 2026-07-31 18:25:46 +02:00
34ebd20656
z9(pve01): change thinkcccore0 to pve01 2026-07-31 18:25:46 +02:00
b0abae6036
z9(group): remove all old ip references and change them to new ones 2026-07-31 18:25:46 +02:00
6481ff2d14
z9(group): remove all z9 references as subdomain 2026-07-31 18:19:14 +02:00
bacd27bea9
unbound(role): move resolvd vars to task 2026-07-31 18:19:14 +02:00
3c667414f4
unbound(role): make unbound thread number configurable 2026-07-31 18:19:14 +02:00
affe5cd92d
unbound(role): reformat config template and use all vcpus 2026-07-31 18:19:13 +02:00
c972189007
unbound(role): remove tags inside role 2026-07-31 18:19:13 +02:00
c50f3f0c38
unbound(role): add FIXME note to unbound prometheus exporter install 2026-07-31 18:19:13 +02:00
8414c49a63
unbound(role): use existing deploy_systemd_resolved_config role and some reordering 2026-07-31 18:19:13 +02:00
8358678771
kea_dhcp(role): make stork-agent.env smaller and add link to documentation 2026-07-31 18:19:13 +02:00
03039282b1
kea_dhcp(role): fix indentation in template 2026-07-31 18:19:13 +02:00
b8d03e7a56
kea_dhcp(role): add README.md 2026-07-31 18:19:13 +02:00
7e65e54676
kea_dhcp(role): some fixes and removing arch part
- remove tags from tasks
- remove archlinux part
- use debian default package for kea
2026-07-31 18:19:12 +02:00
13973a23b8
z9-router(host): fix some spelling and a wireguard peer address 2026-07-31 18:19:12 +02:00
fe12b4da2b
z9-router(host): add ansible pull 2026-07-31 18:19:12 +02:00
0a5dfe1b8d
z9-router(host): rename rt1 to z9-router 2026-07-31 18:19:12 +02:00
d03a39e67a
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-07-31 18:17:55 +02:00
7602190aaf
rt1(z9 host): create host and configure networkd and nftables 2026-07-31 18:17:55 +02:00
6eafc47773 jitsi dazu
Some checks failed
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 2m28s
Erstmal nur der Host, die eigentliche Config muss später passieren
2026-07-29 22:52:13 +02:00
de8daaf56c
add dooris role for setup of dooris interaction on the node itself
Some checks failed
/ build (pull_request) Successful in 28s
/ Ansible Lint (pull_request) Failing after 3m49s
/ cleanup-staging (pull_request) Successful in 6s
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m35s
2026-07-29 14:16:04 +02:00
699a2bcfff
specify that docker_compose role may not be included twice
Our docker compose role is configured via ansible variables in a way
that overwrites each other if it is activated twice with different
variable assignments (unless e.g. a role that just installs more
packages).
To prevent misuse of the role, the allow_duplicates key of the role
meta is set to false. This should make ansible complain if the role
is included twice for a single host.
2026-07-29 14:16:04 +02:00
685646c697 Set up Keycloak to Mailman sync for chaos@
All checks were successful
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m23s
DRY_RUN=true, so no changes to Mailman are performed yet.
2026-07-26 16:19:41 +02:00
647058f6ad ccchoir: stick to major version and cronjob update
All checks were successful
/ build (push) Successful in 48s
/ Ansible Lint (push) Successful in 2m46s
2026-07-26 13:21:41 +02:00
283bc80b41 Update wordpress image
All checks were successful
/ build (push) Successful in 50s
/ Ansible Lint (push) Successful in 2m53s
2026-07-26 00:47:54 +02:00
70b1039f95 Upgrade Hedgdedoc to 1.11.1
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m38s
Closes #130

Also add appropriate config for renovate to upgrade Hedgedoc.
2026-07-24 23:26:23 +02:00
374e8f981a Update git.hamburg.ccc.de/ccchh/oci-images/nextcloud Docker tag to v34
All checks were successful
/ build (pull_request) Successful in 31s
/ Ansible Lint (pull_request) Successful in 2m54s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m46s
2026-07-23 20:16:22 +00:00
4218b59d3b
fix: alloy role the suites for deb repo must be stable
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 2m27s
2026-07-23 22:08:58 +02:00
900971ebe9 alloy(role): pull in alloy role that works from fux (#112)
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m39s
Reviewed-on: #112
Reviewed-by: June <june@noreply.git.hamburg.ccc.de>
2026-07-23 20:34:02 +02:00
9a876e12a8
fix CNAME for club-assistant acme challenge
All checks were successful
/ build (push) Successful in 47s
/ Ansible Lint (push) Successful in 3m52s
2026-07-23 14:33:19 +02:00
b3fe097421
re-enable club-assistant dns record
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 3m27s
2026-07-22 21:44:03 +02:00
28a22e4476 pad: disable external link warning
All checks were successful
/ build (pull_request) Successful in 29s
/ Ansible Lint (pull_request) Successful in 3m10s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 4m20s
closes #130
2026-07-22 00:04:05 +02:00
60a407a406
add prusa-mk4.ccchh.net DNS entry
All checks were successful
/ build (push) Successful in 43s
/ Ansible Lint (push) Successful in 2m58s
2026-07-18 20:13:00 +02:00
Max
2a576495da
separate multiple major release upgrades
All checks were successful
/ build (pull_request) Successful in 30s
/ Ansible Lint (pull_request) Successful in 2m31s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m47s
2026-07-11 21:57:34 +02:00
580b5bdb1f
auth-dns(host): add acme cnames back
All checks were successful
/ build (pull_request) Successful in 46s
/ Ansible Lint (pull_request) Successful in 2m27s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 29s
/ Ansible Lint (push) Successful in 2m33s
for:
- club-assistant
- light
- light-werkstatt
- dooris
2026-07-11 21:29:47 +02:00
14d2d002f7 Update docker.io/prom/prometheus Docker tag to v3.13.1
All checks were successful
/ build (pull_request) Successful in 50s
/ Ansible Lint (pull_request) Successful in 3m17s
/ cleanup-staging (pull_request) Successful in 7s
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 3m14s
2026-07-10 09:15:50 +00:00
25bab80c58
status(host): add monitoring for didays.de and staging
All checks were successful
/ build (pull_request) Successful in 30s
/ Ansible Lint (pull_request) Successful in 2m31s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m35s
2026-07-09 22:20:11 +02:00
56392b776a
public-reverse-proxy(host): add config for didays.de and staging 2026-07-09 22:20:11 +02:00
50cca22cfe Update docker.io/binwiederhier/ntfy Docker tag to v2.26.0
All checks were successful
/ build (pull_request) Successful in 30s
/ Ansible Lint (pull_request) Successful in 3m28s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m42s
2026-07-09 19:00:56 +00:00
1ae4a39f57 Update all stable non-major dependencies
All checks were successful
/ build (pull_request) Successful in 33s
/ Ansible Lint (pull_request) Successful in 3m19s
/ cleanup-staging (pull_request) Successful in 8s
/ build (push) Successful in 45s
/ Ansible Lint (push) Successful in 2m51s
2026-07-08 00:16:11 +00:00
a35326a065
transmission(role): running the handler should always report changed
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 2m42s
Make ansible-lint happy by specifying that.
2026-07-08 00:59:02 +02:00
9ae16363c5
forgejo-runner-external(host): configure forgejo-runner setup
Some checks failed
/ build (push) Successful in 48s
/ Ansible Lint (push) Failing after 2m57s
Configure connection for the DI-Day/website repo.
2026-07-08 00:42:50 +02:00
dd1cd6f529
forgejo-runner-external(host): basic setup 2026-07-08 00:20:02 +02:00
81b16a04cb Explain why this is necessary
Some checks failed
/ build (push) Successful in 48s
/ Ansible Lint (push) Failing after 2m42s
2026-07-05 10:40:29 +02:00
b9a5fa3ce5
forgejo-runner(host): configure some more labels for more images
Some checks failed
/ build (pull_request) Successful in 29s
/ cleanup-staging (pull_request) Successful in 9s
/ build (push) Successful in 26s
/ Ansible Lint (pull_request) Failing after 2m33s
/ Ansible Lint (push) Failing after 2m25s
Provide the ubuntu labels similar to the images running at Codeberg
using the catthehacker/ubuntu:act-* images.
See:
https://github.com/catthehacker/docker_images
https://codeberg.org/actions/meta

Also provide convenience labels for Alpine and Debian.
2026-07-03 03:42:18 +02:00