Compare commits

...

6 Commits

Author SHA1 Message Date
Fabio Sinibaldi acec737b01 Selective become 2026-07-29 18:27:20 +02:00
Fabio Sinibaldi f5db60a0b7 Pangolin Enterprise 2026-07-29 18:27:10 +02:00
Fabio Sinibaldi 2f10f3b5d7 Become method by host group 2026-07-29 18:26:51 +02:00
Fabio Sinibaldi 54026f7a21 Install forgejo 2026-07-29 17:38:31 +02:00
Fabio Sinibaldi bd299333b8 fixing newt configuration 2026-07-29 17:38:16 +02:00
Fabio Sinibaldi c503d49904 Refactor inventory vars 2026-07-29 17:37:39 +02:00
21 changed files with 192 additions and 57 deletions

View File

@ -444,7 +444,7 @@ interpreter_python=auto_silent
;become_ask_pass=False
# (string) executable to use for privilege escalation, otherwise Ansible will depend on PATH.
become_exe=sudo.ws
;become_exe=sudo.ws
# (string) Flags to pass to the privilege escalation executable.
;become_flags=

View File

@ -1,4 +1,12 @@
---
new_sudo:
hosts:
hserve1:
hserve2:
mini1:
distributed:
children:
pangolin:
@ -17,4 +25,7 @@ distributed:
hosts:
hserve1:
ansible_host: 192.168.1.142
forgejo:
hosts:
hserve1:

View File

@ -1,5 +1,8 @@
---
ansible_user: ansible
ansible_group: ansible
ansible_user_uid: 1100
ansible_group_uid: 1100
to_set_authorized_keys:
- label: hassallah
key: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEArNhKFcJ6T08sn7kTTLf+rO9HEvgOvqfhv5HQ2sRf2tFYfjfCb0zHKnMkgW+sy5gMU10Lyx1r7juXCvqRC955uIM97m1B1Xc6sVqASVKuGPhCKfhxEaMAyBcWFdE+HYbCOPYVN+JMrcwWfbblwiZTtK1OCqaEUvDDI7cFeU68noXwggEp46T48eqMUdi541D9Y+BVx9HYAo6OCQz0+6eXwxJL+tpRcAAXIMMWv362CYHoOgIU45R7xVSMLY1k/HLrcEAblwxEaSpduCH5cWUXZE/56IyxpvP44BxZkVhNdqJLmg4hxBQWhoMNYiTZxbLay3W2TwBCM111cAtUx4M/jQ=="

View File

@ -0,0 +1,3 @@
---
docker_users:
- "{{ ansible_user }}"

View File

@ -1,26 +1,29 @@
$ANSIBLE_VAULT;1.1;AES256
34303734613430353163313633353035646165656434326438646437303736383834646165336532
3662363136306137386136613762663235323737306436350a303430616636383733646163393933
38313266376538343963666562333134666237653964303966323762396437643235633236333231
6438333637633833380a343638363338363665363231653534333761343833343136663164373131
35346561313539653636356637326165336438646435363537613331333565333635626139323563
62323331356463623965326264643061386431373561343537633733323137646661383462626331
63646631616565323338356565373639616637323936346164643032383730646265333830656239
37613364666262353537386433366365623265373364303530313364393937336337323936663231
38643932663461346137393161343536303838393964633365323236663363366432356530303864
30343239336436313535376331666431323865643436323431666261633137623432303439383235
35656535323335636338636539353064613638323538633232653634643962316235666662623932
33663430623633363432643766396563646233396635663431343166343431663266663930356432
31636632326234666464633331643262653833396531646330323764313638663963343263316238
37633837313665323639363666633764323062386165323238326365623338346434306564616335
31626234303437646636363933366262646639326232303432653337636363376134616238336538
63653734636166623034376430626232613132313532323163393466613936363033396235643433
35383037626233633735306164366136616532316434363034623239306230326635623563366434
36393432386330363837633763663933623165333534323363323433306265666635663737653066
63653739613738643430643466393335353262346432643333333862393563393133396133373662
36373537393061363936663632383731646234353866356236306265656264333232343634353365
33643134313962653264326133343065333731613736653663386666653433633965373734363238
31306634623962656431386662376130343262666236353337613661613935653862396338363865
35623963653761396363336632633831383462346538396635393436633637383434343531316232
61373137633838393137363636356566346433636239323432336138633635643833363061323632
36383130376365336564633234363433393439353434616331306561623363613263
38356639333633663161333637663539623835623666653738333235336563373030653036393837
3235613032363938623938303463333562656561316636660a626532363638396138613637323265
66663562366431333139616134333039323737356437393031643463363362363335636464333162
3430353964646133660a666234613262396464363134313935383661393438616237633961643233
31646435326336353130323139323961343561646137636332333139643033303664333035663538
30346138613061616432656431613437306462666432646239373236323633346131663431366564
66663031353366663766663330346633306233653033626134343738303937393934393936646533
63613338323631366537353531356538643738393562346161666566393639363138663832306639
32336433643134323433633433376137363834353763643834393530356536316565653831616165
32306661353761643139343838313535333365646265613537626533346338333239626137363533
39323930636336396134313561346463313662333734643536366433663030393130646366396564
66656335353138376638353939316263306633613563663465636366353437333536353731326562
66313862373830383736323330616236643066393032353961643166663935333966386562646335
62616634363964333062306637656331396339643662663132623533636663313962376266353137
30663131326365613635616234616138366236303938386536346633393839393732653964316636
36626262663463306434386332353166313162356365643866393638663564343161643430373937
37336233396632316537626465323866373463306565633835363263616362653266303364373835
30386163626239356333353232343662643438353965346335613937346366386331343965343738
32633732366161653834663766326536343065613463643263333065396532356635376362336335
36386339343832623664323732363638616632363964373732336565636161396237333934353931
66656339653731343534666635663331336238646561353664323438356339343164353531303362
38333535333064386562346234656232653938316337343163616361633834656234333036393932
37303539663032363134613335663937363165636135663338656434633031336631613236346663
31376535353235636362346462333530633334313266613433396361333331363936643863323261
61653564393238323935373935653662636363353063613432653531393337613664336433663337
34383533376362303439303132363665313437363134333432643566636335393739616639613961
32626163333961343331323364636238353137613835363363613538333231303031323033383634
65643735636133313964

View File

@ -0,0 +1,2 @@
---
become_exe: sudo.ws

View File

@ -1,3 +0,0 @@
---
pangolin_site_id: 7drc3dz2bg5gbq5
newt_secret: "{{ test_nginx_newt_secret }}"

View File

@ -0,0 +1,6 @@
---
pangolin_site_id: 7drc3dz2bg5gbq5
newt_secret: "{{ test_nginx_newt_secret }}"
forgejo_db_password : "{{ forgejo_db_crypted_password }}"

View File

@ -0,0 +1,5 @@
---
- name : Install Forgejo
hosts: forgejo
roles:
- forgejo

View File

@ -0,0 +1,34 @@
---
- name: Create docker compose directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/compose_projects/forgejo"
state: directory
mode: '0755'
register: compose_dir
- name: Create data directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/forgejo/data"
state: directory
mode: '0755'
register: forgejo_data_dir
- name: Create DB data directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/forgejo/db"
state: directory
mode: '0755'
register: forgejo_db_dir
- name: Copy compose file
ansible.builtin.template:
src: templates/forgejo_compose.yaml.j2
dest: "{{ compose_dir.path }}/compose.yaml"
- name: Starting forgejo compose project
community.docker.docker_compose_v2:
project_src: "{{ compose_dir.path }}"

View File

@ -0,0 +1,6 @@
---
- include_role:
name: geerlingguy.docker
apply:
become: true
- include_tasks: forgejo_docker.yaml

View File

@ -0,0 +1,52 @@
networks:
forgejo:
external: false
newt:
name: newt_compose_default
external: true
services:
server:
image: codeberg.org/forgejo/forgejo:16.0.1
container_name: forgejo
restart: always
environment:
- USER_UID={{ ansible_user_uid }}
- USER_GID={{ ansible_group_uid }}
- FORGEJO__database__DB_TYPE=postgres
- FORGEJO__database__HOST=db:5432
- FORGEJO__database__NAME=forgejo
- FORGEJO__database__USER=forgejo
- FORGEJO__database__PASSWD={{ forgejo_db_password }}
networks:
- forgejo
- newt
volumes:
- {{ forgejo_data_dir.path }}:/data
- /etc/localtime:/etc/localtime:ro
ports:
- '3000:3000'
- '222:22'
depends_on:
- db
db:
image: postgres:14
restart: always
environment:
- POSTGRES_USER=forgejo
- POSTGRES_PASSWORD={{ forgejo_db_password }}
- POSTGRES_DB=forgejo
networks:
- forgejo
volumes:
- {{ forgejo_db_dir.path }}:/var/lib/postgresql/data

View File

@ -17,15 +17,7 @@
src: templates/newt-config.secret.j2
dest: "{{ compose_dir.path }}/newt-config.secret"
- name: Defining network
community.docker.docker_network:
name: "newt-network"
state: present
- name: Starting newt project
community.docker.docker_compose_v2:
project_src: "{{ compose_dir.path }}"

View File

@ -2,5 +2,9 @@
"id": "{{ pangolin_site_id }}",
"secret": "{{ newt_secret }}",
"endpoint": "https://pangolin.{{ base_domain }}",
"dockerSocket": "unix:///var/run/docker.sock",
"dockerEnforceNetworkValidation": true,
"tlsClientCert": ""
}

View File

@ -4,20 +4,13 @@ services:
image: fosrl/newt
container_name: newt
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
- CONFIG_FILE=/run/secrets/newt-config
secrets:
- newt-config
networks:
- newt-network
networks:
newt-network:
external: true
secrets:
newt-config:
file: ./newt-config.secret

View File

@ -30,6 +30,13 @@
dest: "{{ nginx_conf_dir.path }}/nginx.conf"
- name: Create nginx logs dir
file:
path: "/home/{{ ansible_user }}/nginx/logs"
state: directory
register: nginx_logs_dir
- name: Create container
docker_container:
name: nginx-static
@ -39,5 +46,10 @@
volumes:
- "{{ site_dir.path }}:/usr/share/nginx/html"
- "{{ nginx_conf_dir.path }}:/etc/nginx/conf.d"
- "{{ nginx_logs_dir.path }}:/var/log/nginx"
restart_policy : "unless-stopped"
init : true
networks:
- name: "newt_compose_default"
init : true
recreate: true
state: started

View File

@ -1,8 +1,13 @@
server {
listen 80;
listen [::]:80;
root /var/www/html;
index index.html;
}
listen 80;
root /usr/share/nginx/html;
index index.html index.htm;
server_name static1;
client_max_body_size 32m;
access_log /var/log/nginx/static1.access.log;
error_log /var/log/nginx/static1.error.log debug;
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /var/lib/nginx/html;
}
}

View File

@ -1,3 +1,10 @@
---
- ansible.builtin.include_tasks: prepare_node.yaml
- ansible.builtin.include_tasks: docker_pangolin.yaml
- include_role:
name: geerlingguy.docker
apply:
become: true
- ansible.builtin.include_tasks:
file: docker_pangolin.yaml
apply:
become: true

View File

@ -1,6 +1,6 @@
services:
pangolin:
image: fosrl/pangolin:latest
image: fosrl/pangolin:ee-latest
container_name: pangolin
restart: unless-stopped
volumes: