summaryrefslogtreecommitdiff
path: root/tasks
diff options
context:
space:
mode:
authorMatthew Fennell <matthew@fennell.dev>2026-09-09 21:48:42 +0100
committerMatthew Fennell <matthew@fennell.dev>2026-09-09 21:50:33 +0100
commit25db56f6241ae50feb54232e25f8203c1a450c7c (patch)
tree076e0e4dfc7f14f96377fbeebe475e30bafe61e3 /tasks
parentafa36d11a380f924588d67172ecf02275461f386 (diff)
Move bootstrap sources to their own subdirectory
Since much of the setup (e.g. linter, hook, Makefile configuration) is consistent between ansible roles, instead of having a separate repo per role (as I initially planned), I'd prefer to have a single repo with all of the roles that the playbooks can then pull from. This is in preparation of adding a new munin-node role, following a similar process to bootstrap.
Diffstat (limited to 'tasks')
-rw-r--r--tasks/main.yml153
1 files changed, 0 insertions, 153 deletions
diff --git a/tasks/main.yml b/tasks/main.yml
deleted file mode 100644
index 4512804..0000000
--- a/tasks/main.yml
+++ /dev/null
@@ -1,153 +0,0 @@
-# SPDX-FileCopyrightText: 2026 Matthew Fennell <matthew@fennell.dev>
-#
-# SPDX-License-Identifier: AGPL-3.0-or-later
-
----
-
-- name: Ensure all authorized keys are copied to root account
- remote_user: root
- ansible.posix.authorized_key:
- key: |
- {% for key in authorized_key_files %}
- {{ lookup('file', key) }}
- {% endfor %}
- user: root
- exclusive: true
-
-# Now, we create a non-root user with sudo privileges
-- name: Ensure wheel group exists
- remote_user: root
- ansible.builtin.group:
- name: wheel
- state: present
-
-- name: Ensure wheel group allows passwordless sudo
- remote_user: root
- ansible.builtin.lineinfile:
- dest: /etc/sudoers
- state: present
- regexp: "^%wheel"
- line: "%wheel ALL=(ALL) NOPASSWD: ALL"
- validate: visudo -cf %s
-
-- name: Ensure non-root admin account is created in wheel group
- remote_user: root
- ansible.builtin.user:
- name: admin
- groups: wheel
- append: true
-
-- name: Ensure admin ssh directory exists
- remote_user: root
- ansible.builtin.file:
- path: /home/admin/.ssh
- state: directory
- owner: admin
- group: admin
- mode: "0700"
-
-- name: Copy authorised keys to admin account
- remote_user: root
- ansible.builtin.copy:
- src: /root/.ssh/authorized_keys
- dest: /home/admin/.ssh/authorized_keys
- remote_src: true
- owner: admin
- group: admin
- mode: preserve
-
-- name: Ensure cloud-init is disabled
- ansible.builtin.copy:
- content: ""
- dest: /etc/cloud/cloud-init.disabled
- force: false
- owner: root
- group: root
- mode: "0644"
- become: true
-
-- name: Ensure hostname is set
- ansible.builtin.hostname:
- name: "{{ hostname }}"
- become: true
-
-- name: Ensure hostname is configured in /etc/hosts
- ansible.builtin.template:
- src: hosts.j2
- dest: /etc/hosts
- owner: root
- group: root
- mode: "0644"
- become: true
-
-# This is needed by ansible.builtin.deb822_repository to interact with the
-# sources lists. In ansible-core 2.20 and above, there is a builtin
-# install_python_debian parameter that handles that without this extra step,
-# but we are currently running 2.19.
-# TODO(debian-forky) use deb822_repository's install_python_debian parameter
-- name: Ensure python3-debian is installed
- ansible.builtin.apt:
- name:
- - python3-debian
- state: present
- update_cache: true
- become: true
-
-- name: Ensure debian apt repositories are configured
- ansible.builtin.deb822_repository:
- name: debian
- uris: "{{ debian_uri }}"
- suites:
- - "{{ debian_version }}"
- - "{{ debian_version }}-updates"
- components: main
- signed_by: /usr/share/keyrings/debian-archive-keyring.gpg
- become: true
-
-- name: Ensure debian-security apt repositories are configured
- ansible.builtin.deb822_repository:
- name: debian-security
- uris: "{{ debian_security_uri }}"
- suites: "{{ debian_version }}-security"
- components: main
- signed_by: /usr/share/keyrings/debian-archive-keyring.gpg
- become: true
-
-- name: Ensure required packages are installed
- ansible.builtin.apt:
- name:
- - rsync # Backups
- - systemd-timesyncd # Used to make sure the date is correct
- - ufw # Firewall
- - unattended-upgrades # Not every hosting provider installs by default
- state: present
- update_cache: true
- become: true
-
-# Vultr adds a custom sshd_config file that enabled password authentication.
-# I don't want this to be enabled, since I'm already copying the public key.
-- name: Ensure password authentication is not explicitly enabled
- ansible.builtin.file:
- path: "/etc/ssh/sshd_config.d/50-cloud-init.conf"
- state: absent
- become: true
- notify: Restart sshd
-
-- name: Ensure password based authentication is disabled
- ansible.builtin.copy:
- src: 50-disable-password-auth.conf
- dest: "/etc/ssh/sshd_config.d/50-disable-password-auth.conf"
- owner: root
- group: root
- mode: "0644"
- become: true
- notify: Restart sshd
-
-- name: Ensure unattended upgrades config is installed
- ansible.builtin.copy:
- src: 50unattended-upgrades
- dest: "/etc/apt/apt.conf.d/50unattended-upgrades"
- owner: root
- group: root
- mode: "0644"
- become: true