Initial commit with not yet working docker networking
Signed-off-by: TuDatTr <tuan-dat.tran@tudattr.dev>
This commit is contained in:
13
roles/common/tasks/essential.yml
Normal file
13
roles/common/tasks/essential.yml
Normal file
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: Update and upgrade packages
|
||||
apt:
|
||||
update_cache: yes
|
||||
upgrade: yes
|
||||
autoremove: yes
|
||||
become: yes
|
||||
|
||||
- name: Install extra packages
|
||||
apt:
|
||||
name: "{{ common_packages }}"
|
||||
state: present
|
||||
become: yes
|
||||
3
roles/common/tasks/main.yml
Normal file
3
roles/common/tasks/main.yml
Normal file
@@ -0,0 +1,3 @@
|
||||
---
|
||||
- include_tasks: time.yml
|
||||
- include_tasks: essential.yml
|
||||
4
roles/common/tasks/time.yml
Normal file
4
roles/common/tasks/time.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
- name: Set timezone to "{{ timezone }}"
|
||||
community.general.timezone:
|
||||
name: "{{ timezone }}"
|
||||
54
roles/docker/tasks/compose.yml
Normal file
54
roles/docker/tasks/compose.yml
Normal file
@@ -0,0 +1,54 @@
|
||||
---
|
||||
- name: Create ddns-config directory
|
||||
file:
|
||||
path: "{{ docker_dir }}/ddns-updater/data/"
|
||||
owner: 1000
|
||||
mode: '700'
|
||||
state: directory
|
||||
|
||||
- name: Copy ddns-config
|
||||
template:
|
||||
owner: 1000
|
||||
src: "templates/ddns-updater/data/config.json"
|
||||
dest: "{{ docker_dir }}/ddns-updater/data/config.json"
|
||||
mode: '400'
|
||||
|
||||
- name: Create traefik-config directory
|
||||
file:
|
||||
path: "{{ docker_dir }}/traefik/"
|
||||
owner: 1000
|
||||
mode: '700'
|
||||
state: directory
|
||||
|
||||
- name: Create pihole-config directory
|
||||
file:
|
||||
path: "{{ item }}"
|
||||
owner: 1000
|
||||
mode: '777'
|
||||
state: directory
|
||||
loop:
|
||||
- "{{ docker_dir }}/pihole/etc-pihole/"
|
||||
- "{{ docker_dir }}/pihole/etc-dnsmasq.d/"
|
||||
become: yes
|
||||
|
||||
- name: Copy traefik-config
|
||||
template:
|
||||
owner: 1000
|
||||
src: "templates/traefik/traefik.yml"
|
||||
dest: "{{ docker_dir }}/traefik/traefik.yml"
|
||||
mode: '400'
|
||||
|
||||
- name: Shut down docker
|
||||
shell:
|
||||
cmd: "docker compose down --remove-orphans"
|
||||
chdir: "{{ docker_compose_dir }}"
|
||||
|
||||
- name: Copy the compose file
|
||||
template:
|
||||
src: templates/compose.yaml
|
||||
dest: "{{ docker_compose_dir }}/compose.yaml"
|
||||
|
||||
- name: Run docker compose
|
||||
shell:
|
||||
cmd: "docker compose up -d"
|
||||
chdir: "{{ docker_compose_dir }}"
|
||||
67
roles/docker/tasks/install.yml
Normal file
67
roles/docker/tasks/install.yml
Normal file
@@ -0,0 +1,67 @@
|
||||
---
|
||||
- name: Uninstall old versions
|
||||
apt:
|
||||
name: "{{ item }}"
|
||||
state: absent
|
||||
purge: true
|
||||
loop:
|
||||
- docker
|
||||
- docker-engine
|
||||
- docker.io
|
||||
- containerd
|
||||
- runc
|
||||
become: true
|
||||
|
||||
- name: Update cache
|
||||
apt:
|
||||
update_cache: true
|
||||
become: true
|
||||
|
||||
- name: Install dependencies for apt to use repositories over HTTPS
|
||||
apt:
|
||||
name: "{{ item }}"
|
||||
state: present
|
||||
loop:
|
||||
- ca-certificates
|
||||
- curl
|
||||
- gnupg
|
||||
- lsb-release
|
||||
become: true
|
||||
|
||||
- name: Create keyrings direcoty
|
||||
ansible.builtin.file:
|
||||
path: /etc/apt/keyrings
|
||||
state: directory
|
||||
mode: '0755'
|
||||
become: true
|
||||
|
||||
- name: Add Docker apt key.
|
||||
ansible.builtin.get_url:
|
||||
url: "{{ docker_apt_gpg_key }}"
|
||||
dest: /etc/apt/trusted.gpg.d/docker.asc
|
||||
mode: '0644'
|
||||
force: true
|
||||
become: true
|
||||
|
||||
- name: Add Docker repository.
|
||||
apt_repository:
|
||||
repo: "{{ docker_apt_repository }}"
|
||||
state: present
|
||||
become: true
|
||||
|
||||
- name: Update cache
|
||||
apt:
|
||||
update_cache: true
|
||||
become: true
|
||||
|
||||
- name: Install Docker Engine, containerd, and Docker Compose.
|
||||
apt:
|
||||
name: "{{ item }}"
|
||||
state: present
|
||||
loop:
|
||||
- docker-ce
|
||||
- docker-ce-cli
|
||||
- docker-compose-plugin
|
||||
- containerd.io
|
||||
become: true
|
||||
|
||||
5
roles/docker/tasks/main.yml
Normal file
5
roles/docker/tasks/main.yml
Normal file
@@ -0,0 +1,5 @@
|
||||
---
|
||||
- include_tasks: install.yml
|
||||
- include_tasks: user_group_setup.yml
|
||||
- include_tasks: compose.yml
|
||||
|
||||
25
roles/docker/tasks/user_group_setup.yml
Normal file
25
roles/docker/tasks/user_group_setup.yml
Normal file
@@ -0,0 +1,25 @@
|
||||
---
|
||||
- name: Ensure group "docker" exists
|
||||
group:
|
||||
name: docker
|
||||
state: present
|
||||
become: yes
|
||||
|
||||
- name: Append the group "docker" to "{{ user }}" groups
|
||||
ansible.builtin.user:
|
||||
name: "{{ user }}"
|
||||
shell: /bin/bash
|
||||
groups: docker
|
||||
append: yes
|
||||
become: yes
|
||||
|
||||
- name: Make sure that the docker folders exists
|
||||
ansible.builtin.file:
|
||||
path: "{{ item }}"
|
||||
owner: "{{ user }}"
|
||||
group: "{{ user }}"
|
||||
state: directory
|
||||
loop:
|
||||
- "{{docker_compose_dir}}"
|
||||
- "{{docker_dir}}"
|
||||
become: yes
|
||||
85
roles/docker/templates/compose.yaml
Normal file
85
roles/docker/templates/compose.yaml
Normal file
@@ -0,0 +1,85 @@
|
||||
version: '3'
|
||||
services:
|
||||
traefik:
|
||||
container_name: traefik
|
||||
image: traefik:v2.5
|
||||
networks:
|
||||
- compose_net
|
||||
volumes:
|
||||
- "/etc/localtime:/etc/localtime:ro"
|
||||
- "/var/run/docker.sock:/var/run/docker.sock:ro"
|
||||
- {{ docker_dir }}/traefik/traefik.yml:/etc/traefik/traefik.yml
|
||||
ports:
|
||||
- 80:80
|
||||
- 8080:8080
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.traefik.rule=Host(`traefik.{{local_domain}}`)"
|
||||
- "traefik.http.routers.traefik.entrypoints=web"
|
||||
- "traefik.http.services.traefik.loadbalancer.server.port=80"
|
||||
ddns-updater:
|
||||
container_name: ddns-updater
|
||||
image: "ghcr.io/qdm12/ddns-updater"
|
||||
networks:
|
||||
- compose_net
|
||||
volumes:
|
||||
- {{ docker_dir }}/ddns-updater/data/:/updater/data/
|
||||
ports:
|
||||
- 8000:8000/tcp
|
||||
restart: unless-stopped
|
||||
homeassistant:
|
||||
container_name: homeassistant
|
||||
image: "ghcr.io/home-assistant/home-assistant:stable"
|
||||
networks:
|
||||
- compose_net
|
||||
volumes:
|
||||
- /etc/localtime:/etc/localtime:ro
|
||||
- {{ docker_dir }}/home-assistant/config/:/config/
|
||||
restart: unless-stopped
|
||||
privileged: true
|
||||
network_mode: host
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.homeassistant.rule=Host(`hass.{{local_domain}}`)"
|
||||
- "traefik.http.routers.homeassistant.entrypoints=web"
|
||||
- "traefik.http.services.homeassistant.loadbalancer.server.port=8123"
|
||||
pihole:
|
||||
container_name: pihole
|
||||
image: pihole/pihole:latest
|
||||
networks:
|
||||
- compose_net
|
||||
ports:
|
||||
- "53:53/tcp"
|
||||
- "53:53/udp"
|
||||
- "67:67/udp"
|
||||
- "8089:80/tcp"
|
||||
environment:
|
||||
- "TZ=Europe/Berlin"
|
||||
- "WEBPASSWORD=a"
|
||||
- "ServerIP=192.168.20.11"
|
||||
- "INTERFACE=eth0"
|
||||
- "DNS1=1.1.1.1"
|
||||
- "DNS1=1.0.0.1"
|
||||
volumes:
|
||||
- "{{ docker_dir }}/pihole/etc-pihole/:/etc/pihole/"
|
||||
- "{{ docker_dir }}/pihole/etc-dnsmasq.d/:/etc/dnsmasq.d/"
|
||||
dns:
|
||||
- 127.0.0.1
|
||||
- 1.1.1.1
|
||||
cap_add:
|
||||
- NET_ADMIN
|
||||
restart: unless-stopped
|
||||
labels:
|
||||
- "traefik.enable=true"
|
||||
- "traefik.http.routers.pihole.rule=Host(`pihole.{{local_domain}}`)"
|
||||
- "traefik.http.routers.pihole.entrypoints=web"
|
||||
- "traefik.http.services.pihole.loadbalancer.server.port=8089"
|
||||
|
||||
networks:
|
||||
compose_net:
|
||||
driver: bridge
|
||||
ipam:
|
||||
driver: default
|
||||
config:
|
||||
- subnet: 172.16.69.0/24
|
||||
gateway: 172.16.69.1
|
||||
31
roles/docker/templates/ddns-updater/data/config.json
Normal file
31
roles/docker/templates/ddns-updater/data/config.json
Normal file
@@ -0,0 +1,31 @@
|
||||
{
|
||||
"settings": [
|
||||
{
|
||||
"provider": "namecheap",
|
||||
"domain": "tudattr.dev",
|
||||
"host": "@",
|
||||
"password": "f12ffc0d94dd4bbdb862fcf2c0bed864",
|
||||
"provider_ip": true
|
||||
}, {
|
||||
"provider": "namecheap",
|
||||
"domain": "tudattr.dev",
|
||||
"host": "www",
|
||||
"password": "f12ffc0d94dd4bbdb862fcf2c0bed864",
|
||||
"provider_ip": true
|
||||
},
|
||||
{
|
||||
"provider": "namecheap",
|
||||
"domain": "tudattr.dev",
|
||||
"host": "plex",
|
||||
"password": "f12ffc0d94dd4bbdb862fcf2c0bed864",
|
||||
"provider_ip": true
|
||||
},
|
||||
{
|
||||
"provider": "namecheap",
|
||||
"domain": "borg.land",
|
||||
"host": "@",
|
||||
"password": "aae80116bf684d4abbadbbb37b36d391",
|
||||
"provider_ip": true
|
||||
}
|
||||
]
|
||||
}
|
||||
16
roles/docker/templates/traefik/traefik.yml
Normal file
16
roles/docker/templates/traefik/traefik.yml
Normal file
@@ -0,0 +1,16 @@
|
||||
## traefik.yml
|
||||
# Entry Points
|
||||
entryPoints:
|
||||
web:
|
||||
address: ":80"
|
||||
websecure:
|
||||
address: ":443"
|
||||
|
||||
# Docker configuration backend
|
||||
providers:
|
||||
docker:
|
||||
defaultRule: "Host(`{{ '{{' }} trimPrefix `/` .Name {{ '}}' }}.{{ local_domain }}`)"
|
||||
|
||||
# API and dashboard configuration
|
||||
api:
|
||||
insecure: true
|
||||
24
roles/power_management/tasks/configure.yml
Normal file
24
roles/power_management/tasks/configure.yml
Normal file
@@ -0,0 +1,24 @@
|
||||
---
|
||||
- name: Copy powertop service
|
||||
template:
|
||||
src: templates/powertop.service
|
||||
dest: /etc/systemd/system/powertop.service
|
||||
become: true
|
||||
|
||||
- name: Reload all services
|
||||
ansible.builtin.systemd:
|
||||
daemon_reload: yes
|
||||
become: true
|
||||
|
||||
- name: Start and enable the new powertop service
|
||||
ansible.builtin.systemd:
|
||||
state: started
|
||||
enabled: true
|
||||
name: powertop
|
||||
become: true
|
||||
|
||||
- name: Copy hdparm.conf
|
||||
template:
|
||||
src: templates/hdparm.conf
|
||||
dest: /etc/hdparm.conf
|
||||
become: true
|
||||
15
roles/power_management/tasks/install.yml
Normal file
15
roles/power_management/tasks/install.yml
Normal file
@@ -0,0 +1,15 @@
|
||||
---
|
||||
- name: Update cache
|
||||
apt:
|
||||
update_cache: true
|
||||
become: true
|
||||
|
||||
- name: Install packages
|
||||
apt:
|
||||
name: "{{ item }}"
|
||||
state: present
|
||||
loop:
|
||||
- powertop
|
||||
- hdparm
|
||||
become: true
|
||||
|
||||
3
roles/power_management/tasks/main.yml
Normal file
3
roles/power_management/tasks/main.yml
Normal file
@@ -0,0 +1,3 @@
|
||||
---
|
||||
- include_tasks: install.yml
|
||||
- include_tasks: configure.yml
|
||||
18
roles/power_management/templates/hdparm.conf
Normal file
18
roles/power_management/templates/hdparm.conf
Normal file
@@ -0,0 +1,18 @@
|
||||
quiet
|
||||
/dev/sda {
|
||||
apm = 128
|
||||
spindown_time = 240
|
||||
}
|
||||
|
||||
/dev/sdb {
|
||||
apm = 128
|
||||
spindown_time = 240
|
||||
}
|
||||
/dev/sdc {
|
||||
apm = 128
|
||||
spindown_time = 240
|
||||
}
|
||||
/dev/sdd {
|
||||
apm = 128
|
||||
spindown_time = 240
|
||||
}
|
||||
11
roles/power_management/templates/powertop.service
Normal file
11
roles/power_management/templates/powertop.service
Normal file
@@ -0,0 +1,11 @@
|
||||
[Unit]
|
||||
Description=PowerTOP auto tune
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
Environment="TERM=dumb"
|
||||
RemainAfterExit=true
|
||||
ExecStart=/usr/sbin/powertop --auto-tune
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user