generated from GamingChaos/ansible-repository-template
Compare commits
12
Commits
36fa894031
...
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
39f65a88b1 | ||
|
|
2882f28443 | ||
|
|
a88df82e45 | ||
|
|
21b3b528cf | ||
|
|
e35c1cbf3c | ||
|
|
ce33e8a689 | ||
|
|
79c3952e64 | ||
|
|
d7b53b1cf5 | ||
|
|
5b4f9f2942 | ||
|
|
57fef3ca81 | ||
|
|
42ebc08206 | ||
|
|
dee62d3d8a |
+1
-3
@@ -1,3 +1 @@
|
||||
# ---> Ansible
|
||||
*.retry
|
||||
|
||||
venv/
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
#!/bin/bash
|
||||
|
||||
groupadd -g 3003 ansible
|
||||
useradd -g 3003 -u 994 -m -r ansible
|
||||
usermod -aG ansible vst
|
||||
|
||||
mkdir /home/ansible/.ssh
|
||||
cat << EOL > /home/ansible/.ssh/authorized_keys
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMuxBznuFNFztZt1MbuDRdww7LdmWq0dpK7F3Is/gMPO ansible@semaphore
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMqPCol1eSm4vrAYK0XEaq05n6BAQqQVJOAWhRItfZRS vst@yuuki
|
||||
EOL
|
||||
|
||||
chown -R ansible: /home/ansible/.ssh
|
||||
chmod 400 /home/ansible/.ssh/authorized_keys
|
||||
|
||||
cat << EOL > /etc/sudoers.d/ansible
|
||||
%ansible ALL = (ALL) NOPASSWD: ALL
|
||||
EOL
|
||||
@@ -0,0 +1,8 @@
|
||||
|
||||
# initialize venv
|
||||
python3 -m venv venv
|
||||
. ./venv/bin/activate
|
||||
|
||||
pip install -r requirements.txt
|
||||
|
||||
ansible-galaxy collection install -r requirements.yml
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
proxmox_api_host: rimeru.stuyckv.local
|
||||
proxmox_api_user: ansible@pve
|
||||
proxmox_api_token_id: ansible
|
||||
@@ -0,0 +1,9 @@
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
66393831316666346565393032333961373365346633643730386661616332356431653331396334
|
||||
3633373066646165636639646462376338366665376561650a643530306339666436323130383737
|
||||
36373532623435336466386433326664356537326137363537343133323739343732383565346336
|
||||
6630636236363261610a646336613436323462663339313364393833653539653238666437623261
|
||||
65383864346165623730363136353838396131643962393134366362393266356365396231633064
|
||||
65366631653437626666343465383338383637373139353130623961316662353431313037303834
|
||||
36356131323233613461333163303537306635343065663435333961376264316235643335323661
|
||||
36336331336537343432
|
||||
@@ -0,0 +1,24 @@
|
||||
[ubuntu]
|
||||
shion.stuyckv.local
|
||||
charybdis.stuyckv.local
|
||||
ramiris.stuyckv.local
|
||||
millim.stuyckv.local
|
||||
guy.stuyckv.local
|
||||
claymen.stuyckv.local
|
||||
leon.stuyckv.local
|
||||
|
||||
[docker]
|
||||
charybdis.stuyckv.local
|
||||
ramiris.stuyckv.local
|
||||
millim.stuyckv.local
|
||||
|
||||
[kubernetes]
|
||||
guy.stuyckv.local
|
||||
claymen.stuyckv.local
|
||||
leon.stuyckv.local
|
||||
|
||||
[proxmox]
|
||||
rimeru.stuyckv.local
|
||||
|
||||
[truenas]
|
||||
veldora.stuyckv.local
|
||||
@@ -0,0 +1,5 @@
|
||||
checkmk_sites:
|
||||
- local
|
||||
- dev
|
||||
|
||||
vmid: 101
|
||||
@@ -1,11 +1,12 @@
|
||||
[ubuntu]
|
||||
charybdis.stuyckv.local
|
||||
millim.stuyckv.local
|
||||
ramiris.stuyckv.local
|
||||
[sites]
|
||||
shion.stuyckv.local
|
||||
|
||||
[proxmox]
|
||||
[agents]
|
||||
rimeru.stuyckv.local
|
||||
|
||||
[truenas]
|
||||
veldora.stuyckv.local
|
||||
shion.stuyckv.local
|
||||
charybdis.stuyckv.local
|
||||
ramiris.stuyckv.local
|
||||
millim.stuyckv.local
|
||||
guy.stuyckv.local
|
||||
claymen.stuyckv.local
|
||||
leon.stuyckv.local
|
||||
@@ -0,0 +1,132 @@
|
||||
- name: Install Kubernetes
|
||||
hosts: kubernetes
|
||||
become: true
|
||||
|
||||
tasks:
|
||||
- name: Disable swap
|
||||
command: swapoff -a
|
||||
|
||||
- name: Comment out swap entries in /etc/fstab
|
||||
replace:
|
||||
path: /etc/fstab
|
||||
regexp: '^([^#].*\sswap\s.*)$'
|
||||
replace: '#\1'
|
||||
|
||||
- name: Remove conflicting packages
|
||||
apt:
|
||||
name:
|
||||
- docker.io
|
||||
- docker-compose
|
||||
- docker-compose-v2
|
||||
- docker-doc
|
||||
- podman-docker
|
||||
- containerd
|
||||
- runc
|
||||
state: absent
|
||||
purge: true
|
||||
autoremove: true
|
||||
|
||||
- name: Update and upgrade apt packages
|
||||
apt:
|
||||
update_cache: true
|
||||
upgrade: dist
|
||||
|
||||
- name: Install prerequisites
|
||||
apt:
|
||||
name:
|
||||
- ca-certificates
|
||||
- curl
|
||||
- apt-transport-https
|
||||
- gpg
|
||||
state: present
|
||||
|
||||
- name: Create /etc/apt/keyrings directory
|
||||
file:
|
||||
path: /etc/apt/keyrings
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Download Docker GPG key
|
||||
get_url:
|
||||
url: https://download.docker.com/linux/ubuntu/gpg
|
||||
dest: /etc/apt/keyrings/docker.asc
|
||||
mode: '0644'
|
||||
|
||||
- name: Get Ubuntu codename
|
||||
shell: ". /etc/os-release && echo \"${UBUNTU_CODENAME:-$VERSION_CODENAME}\""
|
||||
register: ubuntu_codename
|
||||
changed_when: false
|
||||
|
||||
- name: Add Docker apt repository
|
||||
copy:
|
||||
dest: /etc/apt/sources.list.d/docker.sources
|
||||
content: |
|
||||
Types: deb
|
||||
URIs: https://download.docker.com/linux/ubuntu
|
||||
Suites: {{ ubuntu_codename.stdout }}
|
||||
Components: stable
|
||||
Signed-By: /etc/apt/keyrings/docker.asc
|
||||
|
||||
- name: Download Kubernetes GPG key
|
||||
shell: >
|
||||
curl -fsSL https://pkgs.k8s.io/core:/stable:/v1.35/deb/Release.key |
|
||||
gpg --dearmor -o /etc/apt/keyrings/kubernetes-apt-keyring.gpg
|
||||
args:
|
||||
creates: /etc/apt/keyrings/kubernetes-apt-keyring.gpg
|
||||
|
||||
- name: Add Kubernetes apt repository
|
||||
copy:
|
||||
dest: /etc/apt/sources.list.d/kubernetes.list
|
||||
content: "deb [signed-by=/etc/apt/keyrings/kubernetes-apt-keyring.gpg] https://pkgs.k8s.io/core:/stable:/v1.35/deb/ /\n"
|
||||
|
||||
- name: Update apt cache
|
||||
apt:
|
||||
update_cache: true
|
||||
|
||||
- name: Install Docker and Kubernetes packages
|
||||
apt:
|
||||
name:
|
||||
- docker-ce
|
||||
- docker-ce-cli
|
||||
- containerd.io
|
||||
- docker-buildx-plugin
|
||||
- docker-compose-plugin
|
||||
- kubelet
|
||||
- kubeadm
|
||||
- kubectl
|
||||
state: present
|
||||
|
||||
- name: Hold kubelet, kubeadm, kubectl at current version
|
||||
dpkg_selections:
|
||||
name: "{{ item }}"
|
||||
selection: hold
|
||||
loop:
|
||||
- kubelet
|
||||
- kubeadm
|
||||
- kubectl
|
||||
|
||||
- name: Generate default containerd config
|
||||
shell: containerd config default > /etc/containerd/config.toml
|
||||
args:
|
||||
creates: /etc/containerd/config.toml
|
||||
|
||||
- name: Restart containerd
|
||||
systemd:
|
||||
name: containerd
|
||||
state: restarted
|
||||
|
||||
- name: Enable and start Docker
|
||||
systemd:
|
||||
name: docker
|
||||
enabled: true
|
||||
state: started
|
||||
|
||||
- name: Enable and start kubelet
|
||||
systemd:
|
||||
name: kubelet
|
||||
enabled: true
|
||||
state: started
|
||||
|
||||
- name: Run hello-world Docker test
|
||||
command: docker run hello-world
|
||||
changed_when: false
|
||||
@@ -0,0 +1,88 @@
|
||||
- name: Gather latest checkmk version
|
||||
hosts: all
|
||||
|
||||
tasks:
|
||||
# cannot be done with git module. It has no method to query the tags of a repo
|
||||
- name: Get latest checkmk version # noqa: run-once[task] command-instead-of-module
|
||||
register: checkmk_version
|
||||
delegate_to: localhost
|
||||
changed_when: false
|
||||
ansible.builtin.shell:
|
||||
executable: /bin/bash
|
||||
cmd: |
|
||||
set -o pipefail
|
||||
git -c 'versionsort.suffix=-' \
|
||||
ls-remote --tags --sort='v:refname' \
|
||||
https://github.com/Checkmk/checkmk.git |\
|
||||
grep -v '\-rc.' | tail --lines=1 |\
|
||||
cut --delimiter='/' --fields=3 | tr -d "v^{}"
|
||||
|
||||
- name: Output checkmk version # noqa: run-once[task]
|
||||
run_once: true
|
||||
ansible.builtin.debug:
|
||||
var: checkmk_version.stdout
|
||||
|
||||
- name: Set checkmk version fact # noqa: run-once[task]
|
||||
run_once: true
|
||||
ansible.builtin.set_fact:
|
||||
checkmk_version: "{{ checkmk_version.stdout }}"
|
||||
|
||||
- name: Update checkmk on monitoring hosts
|
||||
hosts: sites
|
||||
become: true
|
||||
|
||||
tasks:
|
||||
- name: Snapshot VM before update
|
||||
become: false
|
||||
delegate_to: localhost
|
||||
community.proxmox.proxmox_snap:
|
||||
api_host: "{{ proxmox_api_host }}"
|
||||
api_user: "{{ proxmox_api_user }}"
|
||||
api_token_id: "{{ proxmox_api_token_id }}"
|
||||
api_token_secret: "{{ proxmox_api_token_secret }}"
|
||||
validate_certs: false
|
||||
hostname: "{{ inventory_hostname_short }}"
|
||||
snapname: "checkmk_{{ checkmk_version | replace('.', '_') | replace('-', '_') }}"
|
||||
description: "Pre-update snapshot before checkmk {{ checkmk_version }}"
|
||||
timeout: 120
|
||||
state: present
|
||||
|
||||
- name: Install new checkmk version
|
||||
vars:
|
||||
checkmk_edition: community
|
||||
filename: "check-mk-{{ checkmk_edition }}-{{ checkmk_version }}_0.{{ ansible_facts.lsb.codename }}_amd64.deb"
|
||||
ansible.builtin.apt:
|
||||
deb: "https://download.checkmk.com/checkmk/{{ checkmk_version }}/{{ filename }}"
|
||||
when: ansible_facts.lsb.id == 'Ubuntu'
|
||||
|
||||
- name: Stop omd sites
|
||||
register: stop_cmd
|
||||
changed_when: stop_cmd.rc == 0
|
||||
loop: "{{ checkmk_sites }}"
|
||||
ansible.builtin.command: "omd stop {{ item }}"
|
||||
|
||||
- name: Create Site backups
|
||||
changed_when: true
|
||||
loop: "{{ checkmk_sites }}"
|
||||
ansible.builtin.command: "omd backup {{ item }} /tmp/backup-{{ item }}.tar.gz"
|
||||
|
||||
- name: Update omd site
|
||||
changed_when: true
|
||||
loop: "{{ checkmk_sites }}"
|
||||
ansible.builtin.command: "omd -f update --conflict=keepold {{ item }}"
|
||||
|
||||
- name: Start omd sites
|
||||
register: start_cmd
|
||||
changed_when: start_cmd.rc == 0
|
||||
loop: "{{ checkmk_sites }}"
|
||||
ansible.builtin.command: "omd start {{ item }}"
|
||||
|
||||
- name: Update checkmk agents on monitored hosts
|
||||
hosts: agents
|
||||
become: true
|
||||
|
||||
tasks:
|
||||
- name: Install new checkmk agent
|
||||
ansible.builtin.apt:
|
||||
deb: "https://checkmk.stuyckv.com/local/check_mk/agents/check-mk-agent_{{ checkmk_version }}-1_all.deb"
|
||||
when: ansible_facts.lsb.id == 'Ubuntu'
|
||||
@@ -1,6 +1,6 @@
|
||||
---
|
||||
# source: https://www.jeffgeerling.com/blog/2022/ansible-playbook-upgrade-ubuntudebian-servers-and-reboot-if-needed
|
||||
- hosts: ubuntu:proxmox
|
||||
- hosts: ubuntu
|
||||
gather_facts: yes
|
||||
become: yes
|
||||
|
||||
@@ -22,4 +22,4 @@
|
||||
|
||||
- name: Remove dependencies that are no longer required.
|
||||
ansible.builtin.apt:
|
||||
autoremove: yes
|
||||
autoremove: yes
|
||||
@@ -0,0 +1,2 @@
|
||||
proxmoxer
|
||||
requests
|
||||
@@ -0,0 +1,4 @@
|
||||
---
|
||||
collections:
|
||||
- name: community.proxmox
|
||||
version: "1.6.0"
|
||||
Reference in New Issue
Block a user