From ca1eea8f56607b19259aef681c8597817e9d866f Mon Sep 17 00:00:00 2001 From: Matthew McKinnon Date: Mon, 9 Sep 2024 22:37:51 +1000 Subject: [PATCH] Initial Commit --- .gitea/ISSUE_TEMPLATE/adding.yml | 74 +++++++++ .gitea/ISSUE_TEMPLATE/feature-request.yml | 50 ++++++ .gitea/workflows/deploy-containers.yml | 39 +++++ .gitea/workflows/deploy.sh | 14 ++ README.md | 175 +++++++++++++++++++++ ansible.cfg | 6 + build-debian-promox-template.yml | 77 ++++++++++ group_vars/all.yml | 100 ++++++++++++ hosts | 9 ++ main.yml | 132 ++++++++++++++++ renovate.json | 22 +++ roles/docker/defaults/main.yml | 2 + roles/docker/meta/main.yml | 52 +++++++ roles/docker/tasks/main.yml | 48 ++++++ roles/docker/vars/main.yml | 51 +++++++ roles/nfs/defaults/main.yml | 8 + roles/nfs/meta/main.yml | 52 +++++++ roles/nfs/tasks/main.yml | 20 +++ roles/portainer/defaults/main.yml | 2 + roles/portainer/meta/main.yml | 52 +++++++ roles/portainer/tasks/main.yml | 29 ++++ roles/portainer/vars/main.yml | 14 ++ roles/traefik/defaults/main.yml | 2 + roles/traefik/meta/main.yml | 52 +++++++ roles/traefik/tasks/main.yml | 86 +++++++++++ roles/traefik/templates/traefik.yml.j2 | 42 ++++++ roles/traefik/vars/main.yml | 14 ++ scripts/backupvpsdocker | 30 ++++ scripts/rclone.conf | 176 ++++++++++++++++++++++ tasks/base.yml | 119 +++++++++++++++ tasks/dozzle.yml | 29 ++++ tasks/homepage.yml | 40 +++++ tasks/idrac.yml | 15 ++ tasks/invoiceninja.yml | 95 ++++++++++++ tasks/jellyseerr.yml | 29 ++++ tasks/lidarr.yml | 36 +++++ tasks/mariadb.yml | 29 ++++ tasks/mealie.yml | 36 +++++ tasks/osticket.yml | 61 ++++++++ tasks/postgres.yml | 22 +++ tasks/prowlarr.yml | 31 ++++ tasks/pykms.yml | 28 ++++ tasks/radarr.yml | 31 ++++ tasks/readarr.yml | 31 ++++ tasks/sabnzbd.yml | 32 ++++ tasks/sonarr.yml | 31 ++++ tasks/speedtest.yml | 41 +++++ tasks/vaultwarden.yml | 64 ++++++++ vault.sh | 41 +++++ 49 files changed, 2271 insertions(+) create mode 100644 .gitea/ISSUE_TEMPLATE/adding.yml create mode 100644 .gitea/ISSUE_TEMPLATE/feature-request.yml create mode 100644 .gitea/workflows/deploy-containers.yml create mode 100755 .gitea/workflows/deploy.sh create mode 100644 README.md create mode 100644 ansible.cfg create mode 100644 build-debian-promox-template.yml create mode 100644 group_vars/all.yml create mode 100644 hosts create mode 100644 main.yml create mode 100644 renovate.json create mode 100644 roles/docker/defaults/main.yml create mode 100644 roles/docker/meta/main.yml create mode 100644 roles/docker/tasks/main.yml create mode 100644 roles/docker/vars/main.yml create mode 100644 roles/nfs/defaults/main.yml create mode 100644 roles/nfs/meta/main.yml create mode 100644 roles/nfs/tasks/main.yml create mode 100644 roles/portainer/defaults/main.yml create mode 100644 roles/portainer/meta/main.yml create mode 100644 roles/portainer/tasks/main.yml create mode 100644 roles/portainer/vars/main.yml create mode 100644 roles/traefik/defaults/main.yml create mode 100644 roles/traefik/meta/main.yml create mode 100644 roles/traefik/tasks/main.yml create mode 100644 roles/traefik/templates/traefik.yml.j2 create mode 100644 roles/traefik/vars/main.yml create mode 100644 scripts/backupvpsdocker create mode 100644 scripts/rclone.conf create mode 100644 tasks/base.yml create mode 100644 tasks/dozzle.yml create mode 100644 tasks/homepage.yml create mode 100644 tasks/idrac.yml create mode 100644 tasks/invoiceninja.yml create mode 100644 tasks/jellyseerr.yml create mode 100644 tasks/lidarr.yml create mode 100644 tasks/mariadb.yml create mode 100644 tasks/mealie.yml create mode 100644 tasks/osticket.yml create mode 100644 tasks/postgres.yml create mode 100644 tasks/prowlarr.yml create mode 100644 tasks/pykms.yml create mode 100644 tasks/radarr.yml create mode 100644 tasks/readarr.yml create mode 100644 tasks/sabnzbd.yml create mode 100644 tasks/sonarr.yml create mode 100644 tasks/speedtest.yml create mode 100644 tasks/vaultwarden.yml create mode 100755 vault.sh diff --git a/.gitea/ISSUE_TEMPLATE/adding.yml b/.gitea/ISSUE_TEMPLATE/adding.yml new file mode 100644 index 0000000..c234d44 --- /dev/null +++ b/.gitea/ISSUE_TEMPLATE/adding.yml @@ -0,0 +1,74 @@ +name: 'Add Application' +description: 'Track the process of adding a new application' +title: 'Add Application: [Application Name]' +labels: + - addition +assignees: '' + +body: + - type: markdown + attributes: + value: | + ## Application Details + + - type: input + id: application-name + attributes: + label: Application Name + description: Name of the application to be added + placeholder: Name of the application + + - type: textarea + id: application-description + attributes: + label: Application Description + description: Provide a brief description of the application and its purpose + placeholder: Description of the application + + - type: checkboxes + id: application-reason + attributes: + label: Reason for Addition + description: Please select one or more reasons for adding the application + options: + - label: New functionality + - label: Performance improvement + - label: Security enhancement + - label: Replacing another application + description: Provide the name of the application being replaced, if applicable + - label: Other (please specify) + description: Provide additional details + + - type: markdown + attributes: + value: | + ## Steps to Add + + - type: checkboxes + id: steps-to-add + attributes: + label: Steps to Add + description: Please check off each step as it is completed + options: + - label: Add Configuration Files + description: Create and add configuration files for the new application + - label: Update Wiki + description: Create or update the Wiki page for the new application and update any relevant architecture diagrams or flowcharts + - label: Update README(s) + description: Add the new application to the main table and any other relevant sections + - label: Add to CD Platform Logic + description: Add necessary logic to the CD platform for the new application + - label: Testing and Validation + description: Ensure the application is tested and validated in the environment + + - type: markdown + attributes: + value: | + ## Commit IDs for Completed Steps + + - type: textarea + id: commit-ids + attributes: + label: Commit IDs + description: Enter the commit IDs for the completed steps above + placeholder: Enter commit IDs separated by commas diff --git a/.gitea/ISSUE_TEMPLATE/feature-request.yml b/.gitea/ISSUE_TEMPLATE/feature-request.yml new file mode 100644 index 0000000..52a17b9 --- /dev/null +++ b/.gitea/ISSUE_TEMPLATE/feature-request.yml @@ -0,0 +1,50 @@ +name: 'Feature Request' +description: 'Suggest a new feature for the project' +title: 'Feature Request: [Summary]' +labels: + - enhancement +assignees: '' + +body: + - type: markdown + attributes: + value: | + ## Feature Request + + **Please fill out this template with the requested information.** + + - type: input + id: summary + attributes: + label: Summary + description: A concise description of the feature you'd like to see added. + placeholder: Brief summary of the feature request + + - type: textarea + id: motivation + attributes: + label: Motivation + description: Explain why this feature would be beneficial to the project. What problem does it solve or what value does it bring? + placeholder: Describe the motivation behind the feature request + + - type: textarea + id: detailed-description + attributes: + label: Detailed Description + description: | + Provide a detailed explanation of the proposed feature. Include: + - How would this feature be used? + - What are the expected benefits of this feature? + - Are there any potential drawbacks or limitations to consider? + placeholder: Provide a detailed description of the feature + + - type: textarea + id: additional-context + attributes: + label: Additional Context + description: | + Include any relevant information such as: + - Links to external resources (e.g., documentation, articles) + - Screenshots or mockups to illustrate the feature + - Use cases and examples of how the feature would be used + placeholder: Add any other context or screenshots about the feature request here \ No newline at end of file diff --git a/.gitea/workflows/deploy-containers.yml b/.gitea/workflows/deploy-containers.yml new file mode 100644 index 0000000..fd1a936 --- /dev/null +++ b/.gitea/workflows/deploy-containers.yml @@ -0,0 +1,39 @@ +name: Deploy + +on: + push: + branches: + - master + +jobs: + deploy: + name: Prepare Build + runs-on: alpine-latest + container: alpine:latest + steps: + - name: Install dependencies + run: | + apk update + apk add --no-cache nodejs npm git bash openssh python3 py3-pip py3-passlib + python3 -m pip install --user ansible --break-system-packages + export PATH="/root/.local/bin:$PATH" + + - name: Checkout code + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Deploy containers + run: | + mkdir -p ~/.ssh + echo "${{ secrets.SSH_KNOWN_HOSTS }}" >> ~/.ssh/known_hosts + chmod 644 ~/.ssh/known_hosts + eval $(ssh-agent -s) + ssh-add <(echo "${{ secrets.SSH_PRIVATE_KEY }}") + echo "HOST *" > ~/.ssh/config + echo "StrictHostKeyChecking no" >> ~/.ssh/config + echo "${{ secrets.ANSIBLE_VAULT_PASSWORD }}" > ~/.vault_password.txt + echo "nameserver 10.10.10.1" > /etc/resolv.conf + ./.gitea/workflows/deploy.sh "${{ github.event.before }}" "${{ github.sha }}" + + \ No newline at end of file diff --git a/.gitea/workflows/deploy.sh b/.gitea/workflows/deploy.sh new file mode 100755 index 0000000..0bf6124 --- /dev/null +++ b/.gitea/workflows/deploy.sh @@ -0,0 +1,14 @@ +#!/bin/bash + +changed_tasks=($(git diff --name-only $1 $2 | grep '\.yml$')) +if [ ! -z "$changed_tasks" ]; then + for task in "${changed_tasks[@]}"; do + tag=$(echo "$task" | awk -F/ '{print $2}') + if [[ "$tag" != "deploy-homelab.yml" && "$tag" != "main.yml" && "$tag" != "all.yml" && "$tag" != "all.example.yml" && "$tag" != "ISSUE_TEMPLATE" && "$tag" != "workflows" ]] ; then + tag=${tag%.*}_install + /root/.local/bin/ansible-playbook main.yml --tags "$tag" --vault-password-file ~/.vault_password.txt + fi + done +else + echo "No changes detected in task files. Skipping Ansible playbook execution." +fi \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..036d517 --- /dev/null +++ b/README.md @@ -0,0 +1,175 @@ +![Header Image](https://miro.medium.com/v2/resize:fit:4000/1*16DgdobhWUUXKzF4fwjOdw.png) + +
+ +# Homelab + +Homelab deployed as Infrastructure as Code (IaC) using ansible and terraform. Using Gitea Actions and Renovate bot for CI/CD to keep containers updated. +
+ + + +
+ + + +| Provider | OS | Tools +|---|---|---| +| [![BinaryLane](https://img.shields.io/badge/BinaryLane-8A2BE2)](https://binarylane.com.au) | [![Debian](https://img.shields.io/badge/Debian-%23c9d1d9?&logo=Debian&logoColor=red)](https://www.debian.org/releases/stable/) | [![Gitea](https://img.shields.io/badge/gitea-%23c9d1d9?logo=gitea&logoColor=green)](https://about.gitea.com/) [![Docker](https://img.shields.io/badge/-Docker-%23c9d1d9?logo=docker)](https://www.docker.com/) + +
+ +This VPS contains containers and services that need to be always online as part of the HomeLab setup. + + \ No newline at end of file diff --git a/ansible.cfg b/ansible.cfg new file mode 100644 index 0000000..f96f6fb --- /dev/null +++ b/ansible.cfg @@ -0,0 +1,6 @@ +[defaults] +inventory=hosts +deprecation_warnings=False +host_key_checking=False +interpreter_python=auto_silent + diff --git a/build-debian-promox-template.yml b/build-debian-promox-template.yml new file mode 100644 index 0000000..18ec15f --- /dev/null +++ b/build-debian-promox-template.yml @@ -0,0 +1,77 @@ +--- +- hosts: proxmox + become: yes + + tasks: + # - name: Delete existing template + # community.general.proxmox_kvm: + # api_host: "{{ api_host }}" + # api_user: "{{ api_user }}" + # api_password: "{{ api_password }}" + # node: "{{ node_target }}" + # name: "debian-12-generic-amd64" + # state: absent + + # - name: Download cloud-init image + # register: image + # ansible.builtin.get_url: + # url: "https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-generic-amd64.qcow2" + # dest: /tmp + # mode: '0644' + # force: true + + # - name: Install Tools + # ansible.builtin.apt: + # name: + # - libguestfs-tools + # - python3 + # - python3-pip + # - python3-proxmoxer + # update_cache: true + # install_recommends: false + # state: present + + # - name: Install Tools to cloud-init image + # ansible.builtin.shell: | + # virt-customize -a {{ image.dest }} --install qemu-guest-agent + # virt-customize -a {{ image.dest }} --install vim + # virt-customize -a {{ image.dest }} --install git + + - name: Create new VM template from cloud-init image + community.general.proxmox_kvm: + api_host: "{{ api_host }}" + api_user: "{{ api_user }}" + # api_password: "{{ api_password }}" + api_token_id: "{{ api_token_id }}" + api_token_secret: "{{ api_token_secret }}" + api_port: "8006" + node: "{{ node_target }}" + name: "debian-12-generic-amd64" + agent: "enabled=1" + bios: ovmf + boot: 'order=scsi0' + cores: 4 + sockets: 1 + machine: q35 + memory: 4096 + ostype: "l26" + vga: std + scsihw: 'virtio-scsi-single' + #scsi: + #scsi0: "{{ storage_target }}:0,iothread=1,discard=on,import-from={{ image.dest }},format=raw" + #scsi0: "{{ storage_target }}:0,import-from=/tmp/debian-12-generic-amd64.qcow2,format=raw" + net: + net0: 'virtio,bridge=vmbr0,firewall=1,tag=10' + ipconfig: + ipconfig0: 'ip=dhcp' + template: true + timeout: 600 + vmid: 10000 + + # - name: Pause for 5 seconds while template imported + # ansible.builtin.pause: + # seconds: 10 + + - name: Import HDD to Template + command: + cmd: "qm set 10000 --scsi0 {{ storage_target }}:0,iothread=1,discard=on,import-from=/tmp/debian-12-generic-amd64.qcow2,format=raw" diff --git a/group_vars/all.yml b/group_vars/all.yml new file mode 100644 index 0000000..4572d1c --- /dev/null +++ b/group_vars/all.yml @@ -0,0 +1,100 @@ +$ANSIBLE_VAULT;1.1;AES256 +32656263363465383531613338653130323635653238383232646265326433616462363464656539 +3162306463653134666135376366643861353862663765630a343165613030633661353463316463 +30633162376563663166616366643836316363663065333366643338383939636531323538616536 +3136383363636131360adiff --git a/hosts b/hosts new file mode 100644 index 0000000..45198d2 --- /dev/null +++ b/hosts @@ -0,0 +1,9 @@ +[cloud] +vps02.comprofix.com + +# [docker] +# docker.comprofix.xyz + + + + diff --git a/main.yml b/main.yml new file mode 100644 index 0000000..a4c7351 --- /dev/null +++ b/main.yml @@ -0,0 +1,132 @@ +--- + +- hosts: all + name: Configure all servers + tasks: + - name: Gather facts if run with tags + ansible.builtin.setup: + when: ansible_run_tags | length + tags: always + +- hosts: all + become: yes + tasks: + - include_tasks: tasks/base.yml + tags: base_install + +- hosts: cloud + become: yes + roles: + - role: docker + tags: docker_install + + - name: traefik + vars: + traefik_host: traefik01.comprofix.com + tags: traefik_install + + tasks: + # - name: Deploy Homepage + # import_tasks: tasks/homepage.yml + # tags: homepage_install + + - name: Deploy Vaultwarden + import_tasks: tasks/vaultwarden.yml + tags: vaultwarden_install + + - name: Deploy gitea + import_tasks: tasks/gitea.yml + tags: gitea_install + tags: cloud_install + +# - hosts: docker +# become: yes +# roles: +# - role: docker +# tags: docker_install +# - role: nfs +# mounts: +# - name: Docker share +# path: /mnt/nfs/docker +# src: truenas.comprofix.xyz:/mnt/datapool/docker +# - name: Data share +# path: /mnt/nfs/data +# src: truenas.comprofix.xyz:/mnt/datapool/data +# tags: nfs_install +# - role: traefik +# vars: +# traefik_host: traefik02.comprofix.xyz +# data_folder: "/mnt/nfs/docker" +# tags: traefik_install +# tasks: +# - name: Deploy iDrac Fan Controller +# import_tasks: tasks/idrac.yml +# tags: idrac_install + +# - name: Deploy MariaDB +# import_tasks: tasks/mariadb.yml +# tags: mariadb_install + +# - name: Deploy InvoiceNinja +# import_tasks: tasks/invoiceninja.yml +# tags: invoiceninja_install + +# - name: Deploy osTicket +# import_tasks: tasks/osticket.yml +# tags: osticket_install + +# - name: Deploy speedtest-tracker +# import_tasks: tasks/speedtest.yml +# tags: speedtest_install + +# - name: Deploy dozzle +# import_tasks: tasks/dozzle.yml +# tags: dozzle_install + +# - name: Deploy jellyseerr +# import_tasks: tasks/jellyseerr.yml +# tags: jellyseerr_install + +# - name: Deploy lidarr +# import_tasks: tasks/lidarr.yml +# tags: lidarr_install + +# - name: Deploy prowlarr +# import_tasks: tasks/prowlarr.yml +# tags: prowlarr_install + +# - name: Deploy radarr +# import_tasks: tasks/radarr.yml +# tags: radarr_install + +# - name: Deploy readarr +# import_tasks: tasks/readarr.yml +# tags: readarr_install + +# - name: Deploy sonarr +# import_tasks: tasks/sonarr.yml +# tags: sonarr_install + +# - name: Deploy sabnzbd +# import_tasks: tasks/sabnzbd.yml +# tags: sabnzbd_install + +# - name: Deploy mealie +# import_tasks: tasks/mealie.yml +# tags: mealie_install + +# - name: Deploy pyKMS +# import_tasks: tasks/pykms.yml +# tags: pykms_install +# tags: dockerserver_install + + + + + + + + + + + diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..03177d3 --- /dev/null +++ b/renovate.json @@ -0,0 +1,22 @@ +{ + "$schema": "https://docs.renovatebot.com/renovate-schema.json", + "extends": [ + "config:base", + "renovatebot/renovate-config", + ":semanticCommitTypeAll(chore)" + ], + // "automerge": true, + // "automergeType": "branch", + // "automergeStrategy": "rebase", + // "commitBodyTable": true, + // "ignoreTests": true, + // "major": { + // "automerge": false, + // "dependencyDashboardApproval": true, + // "commitMessagePrefix": "chore(deps-major): ", + // "labels": ["dependencies", "breaking"] + // }, + // "ignorePaths": [ + // "terraform/" + // ] + } \ No newline at end of file diff --git a/roles/docker/defaults/main.yml b/roles/docker/defaults/main.yml new file mode 100644 index 0000000..f0327f6 --- /dev/null +++ b/roles/docker/defaults/main.yml @@ -0,0 +1,2 @@ +--- +# defaults file for docker diff --git a/roles/docker/meta/main.yml b/roles/docker/meta/main.yml new file mode 100644 index 0000000..37aea76 --- /dev/null +++ b/roles/docker/meta/main.yml @@ -0,0 +1,52 @@ +galaxy_info: + author: Matthew McKinnon + description: Mounting NFS filesystem + company: support@comprofix.com + + # If the issue tracker for your role is not on github, uncomment the + # next line and provide a value + # issue_tracker_url: http://example.com/issue/tracker + + # Choose a valid license ID from https://spdx.org - some suggested licenses: + # - BSD-3-Clause (default) + # - MIT + # - GPL-2.0-or-later + # - GPL-3.0-only + # - Apache-2.0 + # - CC-BY-4.0 + license: license (GPL-2.0-or-later, MIT, etc) + + min_ansible_version: 2.1 + + # If this a Container Enabled role, provide the minimum Ansible Container version. + # min_ansible_container_version: + + # + # Provide a list of supported platforms, and for each platform a list of versions. + # If you don't wish to enumerate all versions for a particular platform, use 'all'. + # To view available platforms and versions (or releases), visit: + # https://galaxy.ansible.com/api/v1/platforms/ + # + # platforms: + # - name: Fedora + # versions: + # - all + # - 25 + # - name: SomePlatform + # versions: + # - all + # - 1.0 + # - 7 + # - 99.99 + + galaxy_tags: [] + # List tags for your role here, one per line. A tag is a keyword that describes + # and categorizes the role. Users find roles by searching for tags. Be sure to + # remove the '[]' above, if you add tags to this list. + # + # NOTE: A tag is limited to a single word comprised of alphanumeric characters. + # Maximum 20 tags per role. + +dependencies: [] + # List your role dependencies here, one per line. Be sure to remove the '[]' above, + # if you add dependencies to this list. diff --git a/roles/docker/tasks/main.yml b/roles/docker/tasks/main.yml new file mode 100644 index 0000000..784bcf2 --- /dev/null +++ b/roles/docker/tasks/main.yml @@ -0,0 +1,48 @@ +--- +- name: Add Docker apt key. + ansible.builtin.get_url: + url: "{{ docker_apt_gpg_key }}" + dest: /etc/apt/trusted.gpg.d/docker.asc + mode: '0644' + force: false + checksum: "{{ docker_apt_gpg_key_checksum | default(omit) }}" + ignore_errors: true + +- name: Add Docker repository. + apt_repository: + repo: "{{ docker_apt_repository }}" + state: present + filename: "{{ docker_apt_filename }}" + update_cache: true + +- name: Install Docker packages. + package: + name: "{{ docker_packages }}" + state: "present" + +- name: Install Docker Module for Python + pip: + name: + - PyYAML==5.3.1 + - docker + - docker-compose + - pymysql + - passlib + state: "present" + +- name: Ensure docker users are added to the docker group. + user: + name: "{{ item }}" + groups: docker + append: true + with_items: "{{ docker_users }}" + +- name: Reset ssh connection to apply user changes. + meta: reset_connection + +- name: Setup cron job for backup + cron: + name: Docker Prune + minute: 0 + hour: 5 + job: "docker system prune -af && docker image prune -af && docker system prune -af --volumes" \ No newline at end of file diff --git a/roles/docker/vars/main.yml b/roles/docker/vars/main.yml new file mode 100644 index 0000000..94f11dc --- /dev/null +++ b/roles/docker/vars/main.yml @@ -0,0 +1,51 @@ +$ANSIBLE_VAULT;1.1;AES256 +36326633353666613166393030633363373435666230663138303735323132663930663663383138 +3131616265626633663430353835663866356436373533390a623564333539306162613532393661 +61326437363033383862343034356639316162363364356135616132396136383962333062653566 +3966323033663162640a323461656637633062373134656237323339346638663338353266386164 +30653839343165663937653534313335316336356262303331643839643733663264643265633337 +62633265656330353536663762643130636466353165336535393033663937396364373064363133 +66323931663164313235316638393838326532643233636663333635656162343333643233646131 +33336239393035613839646434643633313239393764613836343039383361613437626334643534 +33373461336363636162646631323266353235326361393338366563653663343537633765653261 +30393863323134376466346663376432623938376638393135356439326562656534376233646364 +31353336396362323363323964383635303264646661626662333161303961383333636437393264 +61623638303066343832303034633736343031333732633437356134393837663637653738303837 +65643264663564643432363830373861323062393561386261323638353339663835663830653633 +35373865383832656665333263323463303631343239346632336565393032333865353364386431 +34633064356233626337646439623665613039666632366162346534656438393965623836366230 +38323765633333663266656161376233343131646165343538653335653061363435316536313339 +65366539313338623030663233633766373865653938616437323664633537306162353438373564 +30383831353563663834373731356330393535613162313461303265353461643434613833376330 +39653063363666353261373161636434366464306539306538623533373764666466383766646166 +63313263626539316163656431393534393266666632366430323439373931636235663137393363 +66323338643835356338646565653235333762343162636434653561626630333233343232633365 +64353139376236363039343432636563316562383263336434376236613734396564393137366531 +35613232646638313435326234366335356538393331363862353232353961373734646332646635 +37323930623932326164323831393462653331373562336264613635396339653161303863623739 +34303532376335623533373466366464666662653533363963326536633938333833376432616330 +62326261366463323934663939316338306535323935623935323337333866353539336132326564 +64623739623064333932386363353235356431656339663039643631353264376234316430356235 +33326233356638646163633333613736343732626263333631336333343434353164333436653331 +64376539336562393538613134633933373339363737363364623066383130653033633966316665 +36323361656131623435346565323638313030343762313765646264396461616165393762366436 +65363563313439376437626533386262323036346436663030303736363061396639633338386337 +65623534393561643662653538633630363663326430383030393062323934326465313533303662 +30323861613333353465396536653632373934363162393465373466636132383064663063383834 +66653938346463663335333737386339666430643034386335353938633232323333633238643035 +37643239383936393233353735333164663566663833383763306635646666666365336161316437 +64343032376139373036366433376263376565656435336662656661336530323130356266353265 +32316361623238386530303533343763646533653631613965386639386237303965636634353366 +31363137376633376532383361376631663734653262616237373933363330323337386434623261 +63656364653162323463626361633533353132666563393538383332306263316639396530323131 +63646566623064393930343137623564323234383430363365313834336464333432623466646139 +33343833353339633236613439623735316538373962663365623963663639663264396238363465 +61313338343435313035643163316631303433383738393162633032613830663264386538343763 +30363434653461396239306334333366333232373732353362666538323063313934346433666334 +35363236333038333363653737656362653362376338653364636566346637376566306632326438 +32663930613066343361616665396334393863643963316239313735363539333263656133356665 +62663236366665373637373436656630336630393333393164343265306533666366333964333338 +36376337376366333835326565323735613961323264663466356635653763343331373561666632 +61343466643661636335373663386466333232393064623538666636653439363639386462373238 +38613862656363373434353037613135363464313864386361323136613762306632653838616463 +3438636539363664613934313333336535623165306438353130 diff --git a/roles/nfs/defaults/main.yml b/roles/nfs/defaults/main.yml new file mode 100644 index 0000000..abd341c --- /dev/null +++ b/roles/nfs/defaults/main.yml @@ -0,0 +1,8 @@ +--- +# defaults file for roles/nfs-mount + +# List of NFS shares +nfs_share_mounts: [] + +# Default NFS4 mount options +nfs_mount_opts: "rw,sync,hard" \ No newline at end of file diff --git a/roles/nfs/meta/main.yml b/roles/nfs/meta/main.yml new file mode 100644 index 0000000..37aea76 --- /dev/null +++ b/roles/nfs/meta/main.yml @@ -0,0 +1,52 @@ +galaxy_info: + author: Matthew McKinnon + description: Mounting NFS filesystem + company: support@comprofix.com + + # If the issue tracker for your role is not on github, uncomment the + # next line and provide a value + # issue_tracker_url: http://example.com/issue/tracker + + # Choose a valid license ID from https://spdx.org - some suggested licenses: + # - BSD-3-Clause (default) + # - MIT + # - GPL-2.0-or-later + # - GPL-3.0-only + # - Apache-2.0 + # - CC-BY-4.0 + license: license (GPL-2.0-or-later, MIT, etc) + + min_ansible_version: 2.1 + + # If this a Container Enabled role, provide the minimum Ansible Container version. + # min_ansible_container_version: + + # + # Provide a list of supported platforms, and for each platform a list of versions. + # If you don't wish to enumerate all versions for a particular platform, use 'all'. + # To view available platforms and versions (or releases), visit: + # https://galaxy.ansible.com/api/v1/platforms/ + # + # platforms: + # - name: Fedora + # versions: + # - all + # - 25 + # - name: SomePlatform + # versions: + # - all + # - 1.0 + # - 7 + # - 99.99 + + galaxy_tags: [] + # List tags for your role here, one per line. A tag is a keyword that describes + # and categorizes the role. Users find roles by searching for tags. Be sure to + # remove the '[]' above, if you add tags to this list. + # + # NOTE: A tag is limited to a single word comprised of alphanumeric characters. + # Maximum 20 tags per role. + +dependencies: [] + # List your role dependencies here, one per line. Be sure to remove the '[]' above, + # if you add dependencies to this list. diff --git a/roles/nfs/tasks/main.yml b/roles/nfs/tasks/main.yml new file mode 100644 index 0000000..27a5cf2 --- /dev/null +++ b/roles/nfs/tasks/main.yml @@ -0,0 +1,20 @@ +--- + +- name: Install NFS mount utility + ansible.builtin.apt: + update_cache: true + pkg: nfs-common + state: present + when: ansible_os_family == "Debian" + +- name: Mount an NFS volume + ansible.posix.mount: + src: "{{ item.src }}" + path: "{{ item.path }}" + opts: "{{ item.opts | default(nfs_mount_opts) }}" + state: "{{ item.state | default( 'mounted' ) }}" + fstype: nfs + with_items: "{{ mounts }}" + + + diff --git a/roles/portainer/defaults/main.yml b/roles/portainer/defaults/main.yml new file mode 100644 index 0000000..205c4a1 --- /dev/null +++ b/roles/portainer/defaults/main.yml @@ -0,0 +1,2 @@ +--- +# defaults file for common diff --git a/roles/portainer/meta/main.yml b/roles/portainer/meta/main.yml new file mode 100644 index 0000000..a0e6573 --- /dev/null +++ b/roles/portainer/meta/main.yml @@ -0,0 +1,52 @@ +galaxy_info: + author: Matthew McKinnon + description: Portainer CE + company: support@comprofix.com + + # If the issue tracker for your role is not on github, uncomment the + # next line and provide a value + # issue_tracker_url: http://example.com/issue/tracker + + # Choose a valid license ID from https://spdx.org - some suggested licenses: + # - BSD-3-Clause (default) + # - MIT + # - GPL-2.0-or-later + # - GPL-3.0-only + # - Apache-2.0 + # - CC-BY-4.0 + license: license (GPL-2.0-or-later, MIT, etc) + + min_ansible_version: 2.1 + + # If this a Container Enabled role, provide the minimum Ansible Container version. + # min_ansible_container_version: + + # + # Provide a list of supported platforms, and for each platform a list of versions. + # If you don't wish to enumerate all versions for a particular platform, use 'all'. + # To view available platforms and versions (or releases), visit: + # https://galaxy.ansible.com/api/v1/platforms/ + # + # platforms: + # - name: Fedora + # versions: + # - all + # - 25 + # - name: SomePlatform + # versions: + # - all + # - 1.0 + # - 7 + # - 99.99 + + galaxy_tags: [] + # List tags for your role here, one per line. A tag is a keyword that describes + # and categorizes the role. Users find roles by searching for tags. Be sure to + # remove the '[]' above, if you add tags to this list. + # + # NOTE: A tag is limited to a single word comprised of alphanumeric characters. + # Maximum 20 tags per role. + +dependencies: [] + # List your role dependencies here, one per line. Be sure to remove the '[]' above, + # if you add dependencies to this list. diff --git a/roles/portainer/tasks/main.yml b/roles/portainer/tasks/main.yml new file mode 100644 index 0000000..556b848 --- /dev/null +++ b/roles/portainer/tasks/main.yml @@ -0,0 +1,29 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "{{ data_folder }}/portainer" + +- name: Create Portainer Container + docker_container: + name: portainer + image: portainer/portainer-ce:2.21.0 + command: --admin-password "{{PORTAINER_ADMIN_PASSWORD}}" + restart_policy: unless-stopped + volumes: + - "{{ data_folder }}/portainer/data:/data" + - '/var/run/docker.sock:/var/run/docker.sock' + networks: + - name: proxy + labels: + traefik.enable: "true" + traefik.http.routers.portainer-secure.rule: "Host(`{{portainer_host}}`)" + traefik.http.routers.portainer-secure.entrypoints: "https" + traefik.http.routers.portainer-secure.tls: "true" + traefik.http.routers.portainer-secure.service: "portainer" + traefik.http.services.portainer.loadbalancer.server.port: "9443" + traefik.http.services.portainer.loadbalancer.server.scheme: "https" + register: container_portainer + diff --git a/roles/portainer/vars/main.yml b/roles/portainer/vars/main.yml new file mode 100644 index 0000000..99186d1 --- /dev/null +++ b/roles/portainer/vars/main.yml @@ -0,0 +1,14 @@ +$ANSIBLE_VAULT;1.1;AES256 +66663364383263343838636561393437373730633165306539633566356166313664656166633537 +6333663336336463613565666465663430303665323766300a393063366230643139363061633636 +65303631383230396461303836386335306261613664393762393266636437333634663464353137 +6563366664663331380a346534323264633738663063356565643137323964663964656137633363 +33333264383830666637376337633432353732353630333134353638653234333730636166356164 +33363433343432623762393834336637626562613633393963323963623661643862636362313930 +37346233373231663762346633323634666436323364653136656630636462333638316632626435 +30336433353961333334386134383032356633643261656639623237386439653739363133633836 +65333065336464386164363037363766353066396163386561323338326439376138316131306636 +65376230383666393762393938313535386131313134613033393936633139363366373065623033 +33353733613439383366393864623130396231323433393732653966653132313262346538646334 +63303831333465613962653661656237326364396465366234383663333431366233363133623936 +62663632356361323930326230326565366366663733633137633938643564373766 diff --git a/roles/traefik/defaults/main.yml b/roles/traefik/defaults/main.yml new file mode 100644 index 0000000..205c4a1 --- /dev/null +++ b/roles/traefik/defaults/main.yml @@ -0,0 +1,2 @@ +--- +# defaults file for common diff --git a/roles/traefik/meta/main.yml b/roles/traefik/meta/main.yml new file mode 100644 index 0000000..17d2a6b --- /dev/null +++ b/roles/traefik/meta/main.yml @@ -0,0 +1,52 @@ +galaxy_info: + author: Matthew McKinnon + description: Traefik Proxy + company: support@comprofix.com + + # If the issue tracker for your role is not on github, uncomment the + # next line and provide a value + # issue_tracker_url: http://example.com/issue/tracker + + # Choose a valid license ID from https://spdx.org - some suggested licenses: + # - BSD-3-Clause (default) + # - MIT + # - GPL-2.0-or-later + # - GPL-3.0-only + # - Apache-2.0 + # - CC-BY-4.0 + license: license (GPL-2.0-or-later, MIT, etc) + + min_ansible_version: 2.1 + + # If this a Container Enabled role, provide the minimum Ansible Container version. + # min_ansible_container_version: + + # + # Provide a list of supported platforms, and for each platform a list of versions. + # If you don't wish to enumerate all versions for a particular platform, use 'all'. + # To view available platforms and versions (or releases), visit: + # https://galaxy.ansible.com/api/v1/platforms/ + # + # platforms: + # - name: Fedora + # versions: + # - all + # - 25 + # - name: SomePlatform + # versions: + # - all + # - 1.0 + # - 7 + # - 99.99 + + galaxy_tags: [] + # List tags for your role here, one per line. A tag is a keyword that describes + # and categorizes the role. Users find roles by searching for tags. Be sure to + # remove the '[]' above, if you add tags to this list. + # + # NOTE: A tag is limited to a single word comprised of alphanumeric characters. + # Maximum 20 tags per role. + +dependencies: [] + # List your role dependencies here, one per line. Be sure to remove the '[]' above, + # if you add dependencies to this list. diff --git a/roles/traefik/tasks/main.yml b/roles/traefik/tasks/main.yml new file mode 100644 index 0000000..32849b0 --- /dev/null +++ b/roles/traefik/tasks/main.yml @@ -0,0 +1,86 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "{{ data_folder }}/traefik" + - "{{ data_folder }}/traefik/data" + +- name: Create a network + docker_network: + name: proxy + register: network + +- name: Copy Traefik config + template: + src: templates/traefik.yml.j2 + dest: "{{ data_folder }}/traefik/data/traefik.yml" + mode: '0600' + +- name: Check if {{ data_folder }}/traefik/data/acme.json exists + ansible.builtin.stat: + path: "{{ data_folder }}/traefik/data/acme.json" + register: file_status + +- name: Creates {{ data_folder }}/traefik/data/acme.json if it doesn't exists + ansible.builtin.file: + path: "{{ data_folder }}/traefik/data/acme.json" + state: touch + owner: root + group: root + mode: '0600' + when: not file_status.stat.exists + +- name: Check if {{ data_folder }}/traefik/data/traefik.json.log exists + ansible.builtin.stat: + path: "{{ data_folder }}/traefik/data/traefik.json.log" + register: file_status + +- name: Creates {{ data_folder }}/traefik/data/traefik.json.log if it doesn't exists + ansible.builtin.file: + path: "{{ data_folder }}/traefik/data/traefik.json.log" + state: touch + owner: root + group: root + mode: '0600' + when: not file_status.stat.exists + +- name: Create traefik Container + docker_container: + name: traefik + image: traefik:v3.1 + restart_policy: unless-stopped + networks: + - name: "proxy" + ports: + - 80:80 + - 443:443 + env: + CF_API_EMAIL: "{{ CF_API_EMAIL }}" + CF_DNS_API_TOKEN: "{{CF_DNS_API_TOKEN}}" + volumes: + - /etc/localtime:/etc/localtime:ro + - /var/run/docker.sock:/var/run/docker.sock:ro + - "{{ data_folder }}/traefik/data/traefik.yml:/traefik.yml:ro" + - "{{ data_folder }}/traefik/data/acme.json:/acme.json" + - "{{ data_folder }}/traefik/data/traefik.json.log:/traefik.json.log" + # - ./data/config.yml:/config.yml:ro + labels: + traefik.enable: "true" + traefik.http.routers.traefik.entrypoints: "http" + traefik.http.routers.traefik.rule: "Host(`{{traefik_host}}`)" + traefik.http.middlewares.traefik-auth.basicauth.users: "{{ traefik_api_user }}:{{ traefik_api_password | password_hash('blowfish','1234567890123456789012') }}" + traefik.http.middlewares.traefik-https-redirect.redirectscheme.scheme: "https" + traefik.http.middlewares.sslheader.headers.customrequestheaders.X-Forwarded-Proto: "https" + traefik.http.routers.traefik.middlewares: "traefik-https-redirect" + traefik.http.routers.traefik-secure.entrypoints: "https" + traefik.http.routers.traefik-secure.rule: "Host(`{{traefik_host}}`)" + traefik.http.routers.traefik-secure.middlewares: "traefik-auth" + traefik.http.routers.traefik-secure.tls: "true" + traefik.http.routers.traefik-secure.tls.certresolver: "cloudflare" + traefik.http.routers.traefik-secure.tls.domains[0].main: "comprofix.com" + traefik.http.routers.traefik-secure.tls.domains[0].sans: "*.comprofix.com" + traefik.http.routers.traefik-secure.tls.domains[1].main: "comprofix.xyz" + traefik.http.routers.traefik-secure.tls.domains[1].sans: "*.comprofix.xyz" + traefik.http.routers.traefik-secure.service: "api@internal" \ No newline at end of file diff --git a/roles/traefik/templates/traefik.yml.j2 b/roles/traefik/templates/traefik.yml.j2 new file mode 100644 index 0000000..420d325 --- /dev/null +++ b/roles/traefik/templates/traefik.yml.j2 @@ -0,0 +1,42 @@ +api: + dashboard: true + debug: true + +entryPoints: + http: + address: ":80" + http: + redirections: + entryPoint: + to: https + scheme: https + https: + address: ":443" + +serversTransport: + insecureSkipVerify: true + +log: + level: DEBUG + filePath: /traefik.json.log + format: json + +providers: + docker: + endpoint: "unix:///var/run/docker.sock" + exposedByDefault: false + file: + filename: /config.yml + +certificatesResolvers: + cloudflare: + acme: + email: {{ CF_API_EMAIL }} + storage: acme.json + dnsChallenge: + provider: cloudflare + #disablePropagationCheck: true # uncomment this if you have issues pulling certificates through cloudflare, By setting this flag to true disables the need to wait for the propagation of the TXT record to all authoritative name servers. + resolvers: + - "1.1.1.1:53" + - "1.0.0.1:53" + \ No newline at end of file diff --git a/roles/traefik/vars/main.yml b/roles/traefik/vars/main.yml new file mode 100644 index 0000000..3653604 --- /dev/null +++ b/roles/traefik/vars/main.yml @@ -0,0 +1,14 @@ +$ANSIBLE_VAULT;1.1;AES256 +65353236643865303034613264613133353338613962646164333936353761336231643332303164 +3834613038663965376661373336646433353437373132300a353663633034643265653937396238 +66326632323432646239663762626230326338666138653330323566633864623734396639323062 +3735326666306239370a383439646335343965316464386265613437646163636335393139316232 +61396631356263333933626334313438633132663764326539393663636631303538636131303830 +31633037376231326436306463376134633031666431303133383237316530646261383733313132 +62343261303266613764633861393939343937343038383231353137333337383936623338313561 +64633330356639643863336437653137393364653833653934633762333461393035393963313432 +39633563636164363461326231306237343265626533366562626136643561636464663866303434 +64363663396334623738316238316135616162393566613631396163666134663765343230656135 +35646364666531303361623833643136663832363737623161386562393234393533306636363265 +37343438386439303931633434303939393062363138353732373163663761366337326437316537 +6137 diff --git a/scripts/backupvpsdocker b/scripts/backupvpsdocker new file mode 100644 index 0000000..648e2ad --- /dev/null +++ b/scripts/backupvpsdocker @@ -0,0 +1,30 @@ +#!/bin/bash +# +# +# Backup vps02 docker data + + +#Stop all containers +docker stop $(docker ps -a -q) + +date=$(date +%F) + +cd /data +for dir in */; do + dir=${dir%*/} + backupfile="$dir-$date.tar.gz" + #echo "backup $dir" + tar -zcf /tmp/$backupfile $dir + + if [ $dir == "vaultwarden" ]; then + #echo "rclone vaultwarden" + rclone copy /tmp/$backupfile BitwardenBackup:BitwardenBackup + else + #echo "scp $backupfile" + #scp /tmp/$backupfile mmckinnon@truenas.comprofix.xyz:/mnt/datapool/data/backup/docker/ + fi + rm /tmp/$backupfile +done + +#Start all containers +docker start $(docker ps -a -q) diff --git a/scripts/rclone.conf b/scripts/rclone.conf new file mode 100644 index 0000000..5e128dd --- /dev/null +++ b/scripts/rclone.conf @@ -0,0 +1,176 @@ +$ANSIBLE_VAULT;1.1;AES256 +31393237373262646664663739633130643562326538336561353265633064383466363532366332 +3966346334336430633238376438353961393936393037340a666263623538653061646366653831 +65363535646434393035626435353630626133643634373961393063343361646561643233633733 +3263323166336638380adiff --git a/tasks/base.yml b/tasks/base.yml new file mode 100644 index 0000000..1b0bea1 --- /dev/null +++ b/tasks/base.yml @@ -0,0 +1,119 @@ +--- +- name: Update cache + apt: + force_apt_get: yes + update_cache: yes + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + +- name: Update all packages to their latest version + apt: + name: "*" + force_apt_get: yes + state: latest + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + +- name: Upgrade all packages on servers + apt: + upgrade: dist + force_apt_get: yes + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + +- name: Install required packages + package: + name: "{{ install_packages }}" + state: present + become: yes + tags: + - install_packages + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + +- name: Remove /usr/lib/python3.11/EXTERNALLY-MANAGED + file: + path: /usr/lib/python3.11/EXTERNALLY-MANAGED + state: absent + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + +# - name: Download Oh My Zsh installation script +# get_url: +# url: https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh +# dest: /tmp/install_ohmyzsh.sh + +# - name: Run Oh My Zsh installation script +# become: no +# command: sh /tmp/install_ohmyzsh.sh --unattended +# register: ohmyzsh_result +# failed_when: "'FAILED' in ohmyzsh_result.stderr" + +# - name: Download zsh Dracula Theme +# become: no +# unarchive: +# src: https://github.com/dracula/zsh/archive/refs/heads/master.zip +# dest: "/tmp" +# remote_src: yes + +# - name: Download moe theme for zsh +# become: no +# get_url: +# url: https://git.comprofix.com/mmckinnon/dotfiles/raw/branch/master/oh-my-zsh/moe.zsh-theme +# dest: "/home/{{ ansible_user }}/.oh-my-zsh/themes" +# force: true + +# - name: Move zsh theme to correct folder +# become: no +# copy: +# src: /tmp/zsh-master/ +# dest: /home/{{ ansible_user }}/.oh-my-zsh/themes +# remote_src: yes + +# - name: Create vim config paths +# become: no +# file: +# path: "/home/{{ ansible_user }}/.vim/pack/themes/start/dracula" +# state: directory + +# - name: Download vim Dracula Theme +# become: no +# unarchive: +# src: https://github.com/dracula/vim/archive/refs/heads/master.zip +# dest: "/tmp" +# remote_src: yes + +# - name: Move vim theme to correct folder +# become: no +# copy: +# src: /tmp/vim-master/ +# dest: /home/{{ ansible_user }}/.vim/pack/themes/start/dracula +# remote_src: yes + +# - name: Get zsh config +# become: no +# get_url: +# url: https://git.comprofix.com/mmckinnon/dotfiles/raw/branch/master/zsh/zshrc +# dest: "/home/{{ ansible_user }}/.zshrc" +# force: true + +# - name: Get vim config +# become: no +# get_url: +# url: https://git.comprofix.com/mmckinnon/dotfiles/raw/branch/master/vim/vimrc +# dest: "/home/{{ ansible_user }}/.vimrc" +# force: true + +# - name: Set shell zsh +# user: +# name: "{{ ansible_user }}" +# shell: /bin/zsh + +# - name: Set moe theme for zsh +# become: no +# ansible.builtin.lineinfile: +# path: "/home/{{ansible_user}}/.zshrc" +# regexp: '^ZSH_THEME="dracula"' +# line: 'ZSH_THEME="moe"' + + + + + + + diff --git a/tasks/dozzle.yml b/tasks/dozzle.yml new file mode 100644 index 0000000..a7c7c38 --- /dev/null +++ b/tasks/dozzle.yml @@ -0,0 +1,29 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/dozzle" + - "/mnt/nfs/docker/dozzle/config" + +- name: Create the dozzle container + docker_container: + name: dozzle + image: amir20/dozzle:v8.4.1 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + volumes: + - /var/run/docker.sock:/var/run/docker.sock + env: + DOZZLE_LEVEL: "trace" + DOZZLE_REMOTE_HOST: "tcp://omada.comprofix.xyz:2375,tcp://vps02.comprofix.com:2375" + labels: + traefik.enable: "true" + traefik.http.routers.dozzle.rule: "Host(`dozzle.comprofix.xyz`)" + traefik.http.routers.dozzle.entrypoints: "https" + traefik.http.routers.dozzle.tls: "true" + traefik.http.services.dozzle.loadbalancer.server.port: "8080" + traefik.http.services.dozzle.loadbalancer.server.scheme: "http" \ No newline at end of file diff --git a/tasks/homepage.yml b/tasks/homepage.yml new file mode 100644 index 0000000..0c4fb73 --- /dev/null +++ b/tasks/homepage.yml @@ -0,0 +1,40 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "{{ data_folder }}/homepage" + - "{{ data_folder }}/homepage/config" + +- name: Get dashboard-icons + git: + repo: https://github.com/walkxcode/dashboard-icons.git + dest: /data/dashboard-icons + update: yes + +- name: Create the homepage container + docker_container: + name: homepage + image: ghcr.io/gethomepage/homepage:v0.9.6 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + dns_servers: + - 10.10.10.1 + env: + LOG_LEVEL: debug + volumes: + - "{{ data_folder }}/homepage/config:/app/config" + - "{{ data_folder }}/dashboard-icons:/app/public/icons" + - /var/run/docker.sock:/var/run/docker.sock + labels: + traefik.enable: "true" + traefik.http.routers.homepage.rule: "Host(`homepage.comprofix.xyz`)" + traefik.http.routers.homepage.entrypoints: "https" + traefik.http.routers.homepage.tls: "true" + traefik.http.routers.homepage.service: "homepage" + traefik.http.services.homepage.loadbalancer.server.port: "3000" + register: container_homepage + diff --git a/tasks/idrac.yml b/tasks/idrac.yml new file mode 100644 index 0000000..ee50d0e --- /dev/null +++ b/tasks/idrac.yml @@ -0,0 +1,15 @@ +--- +- name: Create the Dell_R730xd Fan Contoller container + docker_container: + name: Dell_R730xd + image: tigerblue77/dell_idrac_fan_controller:latest@sha256:5184af88c6c03204611d40d4b1c6bc36202762592d16a97236bb4254951d23b0 + restart_policy: unless-stopped + recreate: true + env: + IDRAC_HOST: "10.10.10.138" + IDRAC_USERNAME: "root" + IDRAC_PASSWORD: "calvin" + FAN_SPEED: "35" + CPU_TEMPERATURE_THRESHOLD: "80" + CHECK_INTERVAL: "60" + DISABLE_THIRD_PARTY_PCIE_CARD_DELL_DEFAULT_COOLING_RESPONSE: "true" \ No newline at end of file diff --git a/tasks/invoiceninja.yml b/tasks/invoiceninja.yml new file mode 100644 index 0000000..2d1c63c --- /dev/null +++ b/tasks/invoiceninja.yml @@ -0,0 +1,95 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/invoiceninja/" + - "/mnt/nfs/docker/invoiceninja/config" + - "/mnt/nfs/docker/invoiceninja/db" + +- name: "create stack.env" + copy: + dest: "/mnt/nfs/docker/invoiceninja/stack.env" + content: | + APP_NAME="Invoice Ninja" + APP_ENV=production + APP_KEY="{{ IN_APP_KEY }}" + APP_DEBUG=false + APP_URL="{{ IN_APP_URL }}" + REQUIRE_HTTPS=true + TRUSTED_PROXIES='*' + SESSION_ENCRYPT=false + SESSION_SECURE=false + DB_CONNECTION="mysql" + MULTI_DB_ENABLED=false + DB_HOST="{{MYSQL_HOST}}" + DB_DATABASE="{{IN_DB_DATABASE}}" + DB_USERNAME="{{IN_DB_USERNAME}}" + DB_PASSWORD="{{IN_DB_PASSWORD}}" + DB_PORT="3306" + DEMO_MODE=false + BROADCAST_DRIVER=log + LOG_CHANNEL=stack + CACHE_DRIVER=file + #QUEUE_CONNECTION=sync + QUEUE_CONNECTION=database + SESSION_DRIVER=file + SESSION_LIFETIME=120 + REDIS_HOST=127.0.0.1 + REDIS_PASSWORD=null + REDIS_PORT=6379 + MAIL_MAILER="smtp" + MAIL_HOST="{{MAIL_HOST}}" + MAIL_PORT="{{MAIL_PORT}}" + MAIL_ENCRYPTION="tls" + MAIL_FROM_ADDRESS="{{MAIL_FROM}}" + MAIL_FROM_NAME="{{MAIL_FROM_NAME}}" + POSTMARK_API_TOKEN= + GOOGLE_MAPS_API_KEY= + ERROR_EMAIL= + NINJA_ENVIRONMENT="selfhost" + #options - snappdf / phantom / hosted_ninja + PDF_GENERATOR=hosted_ninja + PHANTOMJS_KEY='a-demo-key-with-low-quota-per-ip-address' + PHANTOMJS_SECRET=secret + UPDATE_SECRET=secret + SENTRY_LARAVEL_DSN=https://32f01ea994744fa08a0f688769cef78a@sentry.invoicing.co/ + +- name: Create the invoiceninja-app container + docker_container: + name: invoiceninja-app + image: invoiceninja/invoiceninja:5 + env_file: /mnt/nfs/docker/invoiceninja/stack.env + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + volumes: + - /mnt/nfs/docker/invoiceninja/config/hosts:/etc/hosts + - /mnt/nfs/docker/invoiceninja/docker/app/public:/var/www/app/public + - /mnt/nfs/docker/invoiceninja/docker/app/storage:/var/www/app/storage + +- name: Create the invoiceninja-nginx container + docker_container: + name: invoiceninja-nginx + image: nginx:1.27.1 + env_file: /mnt/nfs/docker/invoiceninja/stack.env + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + volumes: + - /mnt/nfs/docker/invoiceninja/config/nginx/in-vhost.conf:/etc/nginx/conf.d/in-vhost.conf + - /mnt/nfs/docker/invoiceninja/docker/app/public:/var/www/app/public + - /mnt/nfs/docker/invoiceninja/docker/app/storage:/var/www/app/storage + labels: + traefik.enable: "true" + traefik.http.routers.invoiceninja.rule: "Host(`invoice.comprofix.com`)" + traefik.http.routers.invoiceninja.entrypoints: "https" + traefik.http.routers.invoiceninja.tls: "true" + traefik.http.services.invoiceninja.loadbalancer.server.port: "80" + traefik.http.services.invoiceninja.loadbalancer.server.scheme: "http" + + + diff --git a/tasks/jellyseerr.yml b/tasks/jellyseerr.yml new file mode 100644 index 0000000..393c5d1 --- /dev/null +++ b/tasks/jellyseerr.yml @@ -0,0 +1,29 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/jellyseerr" + - "/mnt/nfs/docker/jellyseerr/config" + +- name: Create the jellyseerr container + docker_container: + name: jellyseerr + image: fallenbagel/jellyseerr:1.9.2 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + volumes: + - /mnt/nfs/docker/jellyseerr/config:/app/config + labels: + traefik.enable: "true" + traefik.http.routers.jellyseerr.rule: "Host(`jellyseerr.comprofix.xyz`)" + traefik.http.routers.jellyseerr.entrypoints: "https" + traefik.http.routers.jellyseerr.tls: "true" + traefik.http.services.jellyseerr.loadbalancer.server.port: "5055" \ No newline at end of file diff --git a/tasks/lidarr.yml b/tasks/lidarr.yml new file mode 100644 index 0000000..2ad5754 --- /dev/null +++ b/tasks/lidarr.yml @@ -0,0 +1,36 @@ +--- +- name: Set Facts + set_fact: + container_name: 'lidarr' + +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/lidarr" + - "/mnt/nfs/docker/lidarr/config" + +- name: Create the lidarr container + docker_container: + name: lidarr + image: ghcr.io/linuxserver/lidarr:latest@sha256:a77af413426b8509fad2d02f5b89104a5766ee6ebb13497d73993e74f6cfa0a8 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + AUTO_UPDATE: "true" #optional + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:lidarr" + volumes: + - /mnt/nfs/docker/lidarr/config:/config + - /mnt/nfs/data:/data + labels: + traefik.enable: "true" + traefik.http.routers.lidarr.rule: "Host(`lidarr.comprofix.xyz`)" + traefik.http.routers.lidarr.entrypoints: "https" + traefik.http.routers.lidarr.tls: "true" + traefik.http.services.lidarr.loadbalancer.server.port: "8686" diff --git a/tasks/mariadb.yml b/tasks/mariadb.yml new file mode 100644 index 0000000..5ebf058 --- /dev/null +++ b/tasks/mariadb.yml @@ -0,0 +1,29 @@ +--- +- name: Set Facts + set_fact: + container_name: 'mariadb' + +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/mariadb" + - "/mnt/nfs/docker/mariadb/config" + +- name: Create the mariadb container + docker_container: + name: "mariadb" + image: ghcr.io/linuxserver/mariadb:10.11.8 + restart_policy: unless-stopped + recreate: true + ports: + - 3306:3306 + env: + PUID: "0" + PGID: "0" + MYSQL_ROOT_PASSWORD: "{{MYSQL_ROOT_PASSWORD}}" + TZ: "Australia/Brisbane" + volumes: + - "/mnt/nfs/docker/mariadb/config:/config" + \ No newline at end of file diff --git a/tasks/mealie.yml b/tasks/mealie.yml new file mode 100644 index 0000000..e1712a9 --- /dev/null +++ b/tasks/mealie.yml @@ -0,0 +1,36 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/mealie" + - "/mnt/nfs/docker/mealie/config" + +- name: Create the mealie container + docker_container: + name: mealie + image: ghcr.io/mealie-recipes/mealie:v1.12.0 + restart_policy: unless-stopped + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + RECIPE_PUBLIC: "true" + RECIPE_SHOW_NUTRITION: "false" + RECIPE_SHOW_ASSETS: "true" + RECIPE_LANDSCAPE_VIEW: "true" + RECIPE_DISABLE_COMMENTS: "true" + RECIPE_DISABLE_AMOUNT: "true" + BASE_URL: "mealie.comprofix.xyz" + SMTP_HOST: "{{MAIL_HOST}}" + volumes: + - /mnt/nfs/docker/mealie/data/:/app/data + labels: + traefik.enable: "true" + traefik.http.routers.mealie.rule: "Host(`mealie.comprofix.xyz`)" + traefik.http.routers.mealie.entrypoints: "https" + traefik.http.routers.mealie.tls: "true" + traefik.http.services.mealie.loadbalancer.server.port: "9000" \ No newline at end of file diff --git a/tasks/osticket.yml b/tasks/osticket.yml new file mode 100644 index 0000000..340d9e8 --- /dev/null +++ b/tasks/osticket.yml @@ -0,0 +1,61 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/osticket" + - "/mnt/nfs/docker/osticket/config" + +- name: Create the osticket container + docker_container: + name: osticket + image: devinsolutions/osticket:1.17.5 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + SMTP_HOST: "{{MAIL_HOST}}" + MYSQL_HOST: "{{MYSQL_HOST}}" + MYSQL_DATABASE: "{{OST_DATABASE}}" + MYSQL_USER: "{{OST_DB_USER}}" + MYSQL_PASSWORD: "{{OST_DB_PASSWORD}}" + INSTALL_SECRET: "{{OST_SIRI}}" + labels: + traefik.enable: "true" + traefik.http.routers.osticket.rule: "Host(`helpdesk.comprofix.com`)" + traefik.http.routers.osticket.entrypoints: "https" + traefik.http.routers.osticket.tls: "true" + traefik.http.services.osticket.loadbalancer.server.port: "80" + traefik.http.services.osticket.loadbalancer.server.scheme: "http" + +- name: Add tzdata to osTicket container + community.docker.docker_container_exec: + container: osticket + command: apk add tzdata + +- name: Set container Timezone + community.docker.docker_container_exec: + container: osticket + command: "ln -s /usr/share/zoneinfo/Australia/Brisbane /etc/localtime" + +- name: Set PHP Timezone + community.docker.docker_container_exec: + container: osticket + command: "sed -i 's|UTC|Australia/Brisbane|g' /usr/local/etc/php/conf.d/php-osticket.ini" + +- name: Patch mysqli.php for timezone + community.docker.docker_container_exec: + container: osticket + command: "sed -i 's|system_time_zone|time_zone|g' /var/www/html/include/mysqli.php" + +- name: Clear ost_sessions table + mysql_query: + login_host: "{{MYSQL_HOST}}" + login_user: "{{OST_DB_USER}}" + login_password: "{{OST_DB_PASSWORD}}" + login_db: "{{OST_DATABASE}}" + query: + - USE comprofix_ost; + - TRUNCATE TABLE ost_session; diff --git a/tasks/postgres.yml b/tasks/postgres.yml new file mode 100644 index 0000000..a44e739 --- /dev/null +++ b/tasks/postgres.yml @@ -0,0 +1,22 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/postgres" + - "/mnt/nfs/docker/postgres/config" + +- name: Create the postgres container + docker_container: + name: postgres + image: postgres:16-alpine + restart_policy: unless-stopped + recreate: true + ports: + - 5432:5432 + env: + POSTGRES_PASSWORD: "{{POSTGRES_PASSWORD}}" + volumes: + - /mnt/nfs/docker/postgres/db-data:/var/lib/postgresql/data + diff --git a/tasks/prowlarr.yml b/tasks/prowlarr.yml new file mode 100644 index 0000000..960dbc4 --- /dev/null +++ b/tasks/prowlarr.yml @@ -0,0 +1,31 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/prowlarr" + - "/mnt/nfs/docker/prowlarr/config" + +- name: Create the prowlarr container + docker_container: + name: prowlarr + image: linuxserver/prowlarr:1.23.1 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + AUTO_UPDATE: "true" #optional + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:prowlarr" + volumes: + - /mnt/nfs/docker/prowlarr/config:/config + labels: + traefik.enable: "true" + traefik.http.routers.prowlarr.rule: "Host(`prowlarr.comprofix.xyz`)" + traefik.http.routers.prowlarr.entrypoints: "https" + traefik.http.routers.prowlarr.tls: "true" + traefik.http.services.prowlarr.loadbalancer.server.port: "9696" diff --git a/tasks/pykms.yml b/tasks/pykms.yml new file mode 100644 index 0000000..7cc247a --- /dev/null +++ b/tasks/pykms.yml @@ -0,0 +1,28 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/pykms" + - "/mnt/nfs/docker/pykms/config" + +- name: Create the pykms container + docker_container: + name: pykms + image: ghcr.io/py-kms-organization/py-kms:latest + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy_network + ports: + - "1688:1688" + env: + IP: "0.0.0.0" + SQLITE: "true" + HWID: "RANDOM" + LOGLEVEL: "INFO" + volumes: + - /mnt/nfs/docker/pykms/db:/home/py-kms/db + - /etc/localtime:/etc/localtime:ro + diff --git a/tasks/radarr.yml b/tasks/radarr.yml new file mode 100644 index 0000000..fd5acfc --- /dev/null +++ b/tasks/radarr.yml @@ -0,0 +1,31 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/radarr" + - "/mnt/nfs/docker/radarr/config" + +- name: Create the radarr container + docker_container: + name: radarr + image: linuxserver/radarr:5.9.1 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:radarr" + volumes: + - /mnt/nfs/docker/radarr/config:/config + - /mnt/nfs/data:/data + labels: + traefik.enable: "true" + traefik.http.routers.radarr.rule: "Host(`radarr.comprofix.xyz`)" + traefik.http.routers.radarr.entrypoints: "https" + traefik.http.routers.radarr.tls: "true" + traefik.http.services.radarr.loadbalancer.server.port: "7878" \ No newline at end of file diff --git a/tasks/readarr.yml b/tasks/readarr.yml new file mode 100644 index 0000000..899eda8 --- /dev/null +++ b/tasks/readarr.yml @@ -0,0 +1,31 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/readarr" + - "/mnt/nfs/docker/readarr/config" + +- name: Create the readarr container + docker_container: + name: readarr + image: ghcr.io/linuxserver/readarr:develop@sha256:dbca70a2dedff17b12698f55c02a49e3ec37e8ce884c5352b54264f9a3979aae + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:readarr" + volumes: + - /mnt/nfs/docker/readarr/config/:/config + - /mnt/nfs/data/:/data + labels: + traefik.enable: "true" + traefik.http.routers.readarr.rule: "Host(`readarr.comprofix.xyz`)" + traefik.http.routers.readarr.entrypoints: "https" + traefik.http.routers.readarr.tls: "true" + traefik.http.services.readarr.loadbalancer.server.port: "8787" diff --git a/tasks/sabnzbd.yml b/tasks/sabnzbd.yml new file mode 100644 index 0000000..cd77eac --- /dev/null +++ b/tasks/sabnzbd.yml @@ -0,0 +1,32 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/sabnzbd" + - "/mnt/nfs/docker/sabnzbd/config" + +- name: Create the sabnzbd container + docker_container: + name: sabnzbd + image: linuxserver/sabnzbd:4.3.3 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + HOSTNAME: "sabnzbd.comprofix.xyz" + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:sabnzbd" + volumes: + - /mnt/nfs/docker/sabnzbd/config:/config + - /mnt/nfs/data:/data + labels: + traefik.enable: "true" + traefik.http.routers.sabnzbd.rule: "Host(`sabnzbd.comprofix.xyz`)" + traefik.http.routers.sabnzbd.entrypoints: "https" + traefik.http.routers.sabnzbd.tls: "true" + traefik.http.services.sabnzbd.loadbalancer.server.port: "8080" diff --git a/tasks/sonarr.yml b/tasks/sonarr.yml new file mode 100644 index 0000000..6af9a5f --- /dev/null +++ b/tasks/sonarr.yml @@ -0,0 +1,31 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/sonarr" + - "/mnt/nfs/docker/sonarr/config" + +- name: Create the sonarr container + docker_container: + name: sonarr + image: linuxserver/sonarr:4.0.9 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + DOCKER_MODS: "ghcr.io/themepark-dev/theme.park:sonarr" + volumes: + - /mnt/nfs/docker/sonarr/config/:/config + - /mnt/nfs/data:/data + labels: + traefik.enable: "true" + traefik.http.routers.sonarr.rule: "Host(`sonarr.comprofix.xyz`)" + traefik.http.routers.sonarr.entrypoints: "https" + traefik.http.routers.sonarr.tls: "true" + traefik.http.services.sonarr.loadbalancer.server.port: "8989" diff --git a/tasks/speedtest.yml b/tasks/speedtest.yml new file mode 100644 index 0000000..2b62767 --- /dev/null +++ b/tasks/speedtest.yml @@ -0,0 +1,41 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "/mnt/nfs/docker/speedtest" + - "/mnt/nfs/docker/speedtest/config" + +- name: Create the speedtest container + docker_container: + name: speedtest + image: lscr.io/linuxserver/speedtest-tracker:0.21.2 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + APP_KEY: "base64:ViJcK7rSIwGC+TAW7pRWnczB43zPPVHH2Hx80t7eVm0=" + PUID: "1000" + PGID: "1000" + DB_CONNECTION: "mysql" + DB_HOST: "{{ MYSQL_HOST }}" + DB_PORT: "3306" + DB_DATABASE: "{{ST_DATABASE}}" + DB_USERNAME: "{{ST_DB_USERNAME}}" + DB_PASSWORD: "{{ST_DB_PASSWORD}}" + TZ: "Australia/Brisbane" + SPEEDTEST_SCHEDULE: "0 * * * *" + DISPLAY_TIMEZONE: "Australia/Brisbane" + + volumes: + - /mnt/nfs/docker/speedtest/config:/config + - /mnt/nfs/docker/speedtest/web:/etc/ssl/web + labels: + traefik.enable: "true" + traefik.http.routers.speedtest.rule: "Host(`speedtest.comprofix.xyz`)" + traefik.http.routers.speedtest.entrypoints: "https" + traefik.http.routers.speedtest.tls: "true" + traefik.http.services.speedtest.loadbalancer.server.port: "80" + traefik.http.services.speedtest.loadbalancer.server.scheme: "http" diff --git a/tasks/vaultwarden.yml b/tasks/vaultwarden.yml new file mode 100644 index 0000000..19b7f01 --- /dev/null +++ b/tasks/vaultwarden.yml @@ -0,0 +1,64 @@ +--- +- name: Create directories + file: + path: "{{ item }}" + state: directory + with_items: + - "{{ data_folder }}/vaultwarden" + - "{{ data_folder }}/vaultwarden/config" + +- name: Create the vaultwarden container + docker_container: + name: vaultwarden + image: vaultwarden/server:1.32.0 + restart_policy: unless-stopped + recreate: true + networks: + - name: proxy + env: + PUID: "1000" + PGID: "1000" + TZ: "Australia/Brisbane" + volumes: + - "{{ data_folder }}/vaultwarden/data:/data" + labels: + traefik.enable: "true" + traefik.http.routers.vaultwarden.rule: "Host(`vault.comprofix.com`)" + traefik.http.routers.vaultwarden.entrypoints: "https" + traefik.http.routers.vaultwarden.tls: "true" + traefik.http.routers.vaultwarden.service: "vaultwarden" + traefik.http.services.vaultwarden.loadbalancer.server.port: "80" + register: container + +- name: Create rclone config folder + file: + path: "/root/.config/rclone" + state: directory + +- name: Copy rclone config + copy: + src: scripts/rclone.conf + dest: /root/.config/rclone/rclone.conf + decrypt: yes + mode: "0600" + +- name: copy backup script + copy: + src: scripts/backupvpsdocker + dest: /usr/local/sbin/backupvpsdocker + mode: 0755 + +- name: Setup cron job for backup + cron: + name: backup backupvpsdocker + minute: 0 + hour: 4 + job: "/usr/local/sbin/backupvpsdocker >/dev/null 2>&1" + + + + + + + + diff --git a/vault.sh b/vault.sh new file mode 100755 index 0000000..fd2b9c6 --- /dev/null +++ b/vault.sh @@ -0,0 +1,41 @@ +#!/bin/bash + +# If number of arguments is 0 +if [ $# -eq 0 ] + then + echo "This script will encrypt of decrypt all files containing secrets." + echo "There are all files in vars as well as all secrets.yaml files under each service." + echo "Specify 'decrypt' or 'encrypt' as argument" + echo "If you put the vault password in a password file named .vault_password, the script will not ask for a password." + exit 1 +fi + +files=`find . \( -type d -name 'group_vars' -o -name 'vars' \) -exec find {} -type f \;` + +# password_type=--ask-vault-password +# if [ -f "~/.vault_password.txt" ] +# then +# if [ `stat -c %a ~/.vault_password.txt` != "600" ] +# then +# echo "~/.vault_password.txt file has bad permissions; fixing this to 600" +# chmod 600 ~/.vault_password.txt +# fi +# password_type="--vault-password-file=~/.vault_password.txt" +# fi + +if [ $1 == "encrypt" ] + then + ansible-vault encrypt --vault-password-file=~/.vault_password.txt $files + for value in $files; do + echo $value; + done + +elif [ $1 == "decrypt" ] + then + ansible-vault decrypt --vault-password-file=~/.vault_password.txt $files + for value in $files; do + echo $value; + done +else + echo "Wrong argument supplied. Run without arguments to see allowed ones." +fi