46 lines
1.3 KiB
YAML
46 lines
1.3 KiB
YAML
---
|
|
# Site playbook. Apply with:
|
|
#
|
|
# ansible-galaxy install -r requirements.yml
|
|
# ansible-playbook -i inventory/disposable.yml playbook.yml \
|
|
# --extra-vars "caddy_image=$(cd ../pulumi && pulumi stack output imageRepo):latest"
|
|
#
|
|
# The controller (operator laptop OR Cloud Build) must be authed to GCP via
|
|
# ADC — `gcloud auth application-default login` locally, or the Cloud Build
|
|
# SA identity when running under cloudbuild.yaml. The secrets role uses
|
|
# `gcloud secrets versions access` to pull from Google Cloud Secret Manager.
|
|
|
|
- name: Vaultwarden host configuration
|
|
hosts: all
|
|
become: true
|
|
gather_facts: true
|
|
|
|
pre_tasks:
|
|
- name: Verify SELinux is enforcing
|
|
ansible.builtin.command: getenforce
|
|
changed_when: false
|
|
register: selinux_status
|
|
failed_when: "'Enforcing' not in selinux_status.stdout"
|
|
|
|
roles:
|
|
- role: base
|
|
tags: [base]
|
|
- role: podman
|
|
tags: [podman]
|
|
- role: mail
|
|
tags: [mail]
|
|
- role: wireguard
|
|
tags: [wireguard, network]
|
|
- role: nftables
|
|
tags: [nftables, network]
|
|
- role: fail2ban
|
|
tags: [fail2ban]
|
|
- role: dnf_automatic
|
|
tags: [dnf_automatic, updates]
|
|
- role: secrets
|
|
tags: [secrets]
|
|
- role: quadlets
|
|
tags: [quadlets]
|
|
- role: backup
|
|
tags: [backup]
|