Skip to content

About

♻️ Ansible inventory with bunch of dockerized services

Resources

Stars

1 star

Watchers

1 watching

Forks

Repository files navigation

Ansible playbook for provisioning my servers

Linters

Requirements

On VPS - Debian 12+. On VPS provider - opened ports: SSH (server_ssh_port), 80/tcp, 443/tcp, 443/udp, and role-specific public ports such as 3x-ui Hysteria2 UDP. On Cloudflare - token (DNS propagated during setup) On PC - just ansible. For MacOS also passlib because of some crypto module.

Instructions

Initial setup

git clone https://github.com/Mayurifag/mayurifag.ru.git
cd mayurifag.ru
cp -rfp inventories/sample inventories/my-provision # and change it directly
ansible-galaxy install -r requirements.yml

Production deployment

TL;DR

make bootstrap HOST=hostname # run once, its cleaning known_hosts and makes ssh configuration
make deploy hostname "traefik,mus" # or make deploy-all if you are sure

Optional steps

  • Make new ssh config section for convenience and using tssh' udp by default
# ~/.ssh/config
Host change_that_provider change_that_website.com
    HostName change.that
    User admin_user # Change user
    Port 2222 # change port
    #!! UdpMode KCP
    #!! TsshdPort 12345 # change this

Applications List

This list changed a lot through years, I'm trying to remove things I do not use.

Name Subdomain Auth Watchtower UFW ports
3x-ui 3x app + 36500/udp (hysteria2)
BentoPDF pdf ldap +
Beszel beszel app +
ConvertX convert ldap +
EchoIP ip none +
Dynacat rss ldap +
Excalidraw draw none
Mini-QR qr ldap +
mayurifag.github.io none +
mus mus ldap +
Navidrome navidrome app +
lldap ldap ldap +
MailFlow mail app
NetBird netbird OIDC 3478/udp (STUN)
OpenCloud cloud ldap
Portainer portainer app +
SnapOtter images ldap +
TG AI Manager tg ldap +
Traefik / Crowdsec traefik ldap 80/tcp, 443/tcp, 443/udp (http3)
Tinyauth auth OIDC +
Watchtower HTTP API watchtower app +

Refer to POST_INSTALL.md for after deployment info.

Notes:

  • ufw also allows ssh tcp port
  • traefik is not autoupdated because they add breaking changes on patch versions
  • opencloud is not autoupdated because requires running migration scripts

TODO

  • Move proxmox folder here.
    • Have a HOMELAB.md file. Also maybe split provisioning? think about it.
    • Wildcard DNS *.home.mayurifag.ru or something
    • Reverse proxy for homelab?
    • Move all settings
    • Automatical netbird setup or something
    • What roles might be reused? Which docker roles are applicable fine?

On hold

  • https://github.com/pranshuparmar/witr - wait debian 14 update
  • Bandwhich - will require downloading binary to root - wait for deb repo
  • When Tinyauth will be an OIDC provider
    • make it work for opencloud
    • Portainer - setup automatic LDAP
  • zerobyte - webapp for restic backups - wait until developed stable version

Thinking if I need it / probably wont do - ideas / notes

About

♻️ Ansible inventory with bunch of dockerized services

Resources

Stars

1 star

Watchers

1 watching

Forks

Used by

Contributors

Languages