Ansible role for common server configuration
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 92f85faf45
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:45 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:47:05 +00:00
defaults feat: add zram by default 2026-06-18 14:40:37 +02:00
handlers feat: add zram by default 2026-06-18 14:40:37 +02:00
meta feat(meta): compress galaxy_info 2025-05-28 07:24:52 +02:00
roles fix: update requirements to forgejo repo locations 2026-05-15 13:51:05 +02:00
tasks fix: include network and virtual fact subsets 2026-08-12 15:14:41 +02:00
templates fix: deprication warning 2026-08-12 14:02:50 +02:00
vars feat: add boto3 to default packages 2026-05-19 10:21:03 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:37 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:41 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:41 +02:00
.gitignore feat: add gitigore file 2025-03-31 11:34:22 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:43:59 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:44 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:20 +02:00
AGENTS.md style: align markdown table formatting for MD060 compliance 2026-05-18 18:26:21 +02:00
ansible.cfg perf: set forks to 7 2026-08-12 15:27:18 +02:00
playbook.yaml fix: attempt 2 on making ansible-galaxy run once 2026-08-12 14:48:44 +02:00
readme.md docs: improve readme 2026-10-05 17:28:45 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:57:50 +02:00
requirements.yml chore(package): update dependency community.sops to v2.5.0 2026-10-04 14:31:24 +00:00

Ansible Role: Common

Manage core Operating System components and system defaults: hostname and locale, APT sources and unattended upgrades, default packages, DNS, NTP (chrony), firewall (ufw), syslog, journald, SSH daemon, users, swap, zram, sysctl and the message of the day. This is the foundational role for all Debian, Ubuntu and Alpine hosts.

Requirements

Operating System Version
Debian 12, 13
Ubuntu 22.04, 24.04
Alpine 3.23

Many tasks are limited to Debian-family hosts, and some only run on specific virtualization types (kvm, lxc or none). Hosts that are a member of the proxmox inventory group are skipped entirely.

The collections in requirements.yml are needed: ansible.posix, community.general and community.sops.

Dependencies

None (dependencies: []). The playbook only runs the common role.

Variables

APT

Variable Required Default Description
apt_automatic_reboot No true Reboot automatically after unattended upgrades
apt_automatic_reboot_time No 03:45 Time of the automatic reboot
apt_enable_multiverse No false Enable the Ubuntu multiverse component
apt_enable_universe No true Enable the Ubuntu universe component
apt_repository No https://archive.ubuntu.com/ubuntu Ubuntu repository URL (legacy sources.list)
apt_repository_main No https://archive.ubuntu.com/ubuntu Ubuntu main repository URL (deb822, 24.04+)
apt_repository_security No https://archive.ubuntu.com/ubuntu Ubuntu security repository URL (deb822, 24.04+)
debian_repo_url_security No http://security.debian.org/debian-security Debian security repository URL
debian_repo_url_update No http://deb.debian.org/debian Debian repository URL

DNS

Variable Required Default Description
dns_servers No ["192.168.10.1"] List of nameservers for /etc/resolv.conf
dns_search No example.internal Search domain (string). Not written while it contains example
dns_options No [] List of resolver options

Firewall

Variable Required Default Description
firewall_enable No true Install and enable ufw (false removes it)
firewall_basic_rules No allow SSH from 192.168.10.55 Rules applied on every host
firewall_host_rules No [] Extra rules for a single host or group
firewall_portless_protocols No ah, esp, gre, igmp, vrrp Protocols for which to_port is omitted

Each rule has the keys name, from_ip, to_port and optionally proto (default tcp). Incoming traffic is denied by default and logging is enabled.

Time

Variable Required Default Description
ntp_server No time.cloudflare.com NTP server (see the note below)
timezone No Europe/Amsterdam System timezone

The chrony template iterates over ntp_servers (a list) and not over ntp_server. Define ntp_servers in the inventory to configure chrony. The hosts ntp01, ntp02 and ntp03 (.siempie.internal) are skipped.

Other

Variable Required Default Description
syslog_enable No true Install and configure rsyslog (busybox syslog on Alpine)
swap No false Create a swap file (true) or remove it (false), KVM only
zram No true Defined for zram, see the note below

The zram variable is defined but not referenced by the tasks. On Debian-family KVM guests the role always installs systemd-zram-generator and writes a zram0 device with half of the RAM and zstd compression.

Optional variables without a default

These are only used when set in the inventory.

Variable Description
swap_file_size Size of the swap file (for example 2G), required when swap is true
swap_file_location Path of the swap file (default /swapfile)
users_global List of users created on all hosts
users_host List of users created on one host or group
service List of services with name, enabled and state
sysctl List of kernel parameters with name and value
systemctl List of fstrim.timer settings with description and optional oncalendar (weekly)
snapd_service Install and enable snapd (default false, which purges it)
snap_package List of snaps with name and optional channel (default stable)
rsyslog_destination Remote syslog host, used by the remote logging templates
rsyslog_port Remote syslog port, used by the remote logging templates

Users have the keys username, name, optionally password (hash), publickey, shell (/bin/bash), state (present or absent), sudo, sudo_passwordless and hosts. Keep password hashes and keys in the sops-encrypted inventory variables.

Example

apt_automatic_reboot: true
apt_automatic_reboot_time: "03:00"
timezone: "UTC"
ntp_servers:
  - "time.cloudflare.com"

firewall_host_rules:
  - name: "allow https from the lan"
    from_ip: "192.168.10.0/24"
    to_port: "443"

users_global:
  - username: "alice"
    name: "Alice Example"
    publickey: "ssh-ed25519 AAAA... alice@example"
    sudo: true

Tags

If you call the role without tags, it will execute all of the stages below.

Tag Purpose
apk Alpine packages
apt APT sources, packages and configuration
apt-update APT upgrade, reboot handling
apt-cleanup APT cleanup
cron Cron jobs
environment-file /etc/environment
firewall ufw firewall
fstab fstab entries (Alpine)
hostname Hostname
journald journald configuration
locale System locale
lxd Remove LXD
motd Message of the day
ntp chrony
profile System-wide shell prompt (Alpine)
service Services from service
snap snapd and snap packages
sshd SSH daemon
swap Swap file
sysctl Kernel parameters
systemctl systemd units (fstrim.timer)
syslog rsyslog
telemetry Remove Ubuntu telemetry
timezone Timezone
usermanagement Users, keys and sudoers files
zram zram compressed swap

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml to refresh the role, then imports the common role with the free strategy.

ansible-playbook playbook.yaml --tags "apt,sshd"

Notes

  • The apt upgrade task reboots the host when /var/run/reboot-required exists. On semaphore01.siempie.internal a reboot is scheduled in 15 minutes instead.
  • The sshd configuration restricts ciphers, MACs and key exchange algorithms. On Ubuntu 24.04 the post-quantum key exchange is left out.
  • The sudoers template contains host specific rules for the drone user.