- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates | ||
| vars | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
| requirements.yml | ||
Ansible Role: Common
Manage core Operating System components and system defaults: hostname and locale, APT sources and unattended upgrades, default packages, DNS, NTP (chrony), firewall (ufw), syslog, journald, SSH daemon, users, swap, zram, sysctl and the message of the day. This is the foundational role for all Debian, Ubuntu and Alpine hosts.
Requirements
| Operating System | Version |
|---|---|
| Debian | 12, 13 |
| Ubuntu | 22.04, 24.04 |
| Alpine | 3.23 |
Many tasks are limited to Debian-family hosts, and some only run on specific virtualization types (kvm, lxc or
none). Hosts that are a member of the proxmox inventory group are skipped entirely.
The collections in requirements.yml are needed: ansible.posix, community.general and community.sops.
Dependencies
None (dependencies: []). The playbook only runs the common role.
Variables
APT
| Variable | Required | Default | Description |
|---|---|---|---|
apt_automatic_reboot |
No | true |
Reboot automatically after unattended upgrades |
apt_automatic_reboot_time |
No | 03:45 |
Time of the automatic reboot |
apt_enable_multiverse |
No | false |
Enable the Ubuntu multiverse component |
apt_enable_universe |
No | true |
Enable the Ubuntu universe component |
apt_repository |
No | https://archive.ubuntu.com/ubuntu |
Ubuntu repository URL (legacy sources.list) |
apt_repository_main |
No | https://archive.ubuntu.com/ubuntu |
Ubuntu main repository URL (deb822, 24.04+) |
apt_repository_security |
No | https://archive.ubuntu.com/ubuntu |
Ubuntu security repository URL (deb822, 24.04+) |
debian_repo_url_security |
No | http://security.debian.org/debian-security |
Debian security repository URL |
debian_repo_url_update |
No | http://deb.debian.org/debian |
Debian repository URL |
DNS
| Variable | Required | Default | Description |
|---|---|---|---|
dns_servers |
No | ["192.168.10.1"] |
List of nameservers for /etc/resolv.conf |
dns_search |
No | example.internal |
Search domain (string). Not written while it contains example |
dns_options |
No | [] |
List of resolver options |
Firewall
| Variable | Required | Default | Description |
|---|---|---|---|
firewall_enable |
No | true |
Install and enable ufw (false removes it) |
firewall_basic_rules |
No | allow SSH from 192.168.10.55 |
Rules applied on every host |
firewall_host_rules |
No | [] |
Extra rules for a single host or group |
firewall_portless_protocols |
No | ah, esp, gre, igmp, vrrp |
Protocols for which to_port is omitted |
Each rule has the keys name, from_ip, to_port and optionally proto (default tcp). Incoming traffic is
denied by default and logging is enabled.
Time
| Variable | Required | Default | Description |
|---|---|---|---|
ntp_server |
No | time.cloudflare.com |
NTP server (see the note below) |
timezone |
No | Europe/Amsterdam |
System timezone |
The chrony template iterates over ntp_servers (a list) and not over ntp_server. Define ntp_servers in the
inventory to configure chrony. The hosts ntp01, ntp02 and ntp03 (.siempie.internal) are skipped.
Other
| Variable | Required | Default | Description |
|---|---|---|---|
syslog_enable |
No | true |
Install and configure rsyslog (busybox syslog on Alpine) |
swap |
No | false |
Create a swap file (true) or remove it (false), KVM only |
zram |
No | true |
Defined for zram, see the note below |
The zram variable is defined but not referenced by the tasks. On Debian-family KVM guests the role always installs
systemd-zram-generator and writes a zram0 device with half of the RAM and zstd compression.
Optional variables without a default
These are only used when set in the inventory.
| Variable | Description |
|---|---|
swap_file_size |
Size of the swap file (for example 2G), required when swap is true |
swap_file_location |
Path of the swap file (default /swapfile) |
users_global |
List of users created on all hosts |
users_host |
List of users created on one host or group |
service |
List of services with name, enabled and state |
sysctl |
List of kernel parameters with name and value |
systemctl |
List of fstrim.timer settings with description and optional oncalendar (weekly) |
snapd_service |
Install and enable snapd (default false, which purges it) |
snap_package |
List of snaps with name and optional channel (default stable) |
rsyslog_destination |
Remote syslog host, used by the remote logging templates |
rsyslog_port |
Remote syslog port, used by the remote logging templates |
Users have the keys username, name, optionally password (hash), publickey, shell (/bin/bash), state
(present or absent), sudo, sudo_passwordless and hosts. Keep password hashes and keys in the
sops-encrypted inventory variables.
Example
apt_automatic_reboot: true
apt_automatic_reboot_time: "03:00"
timezone: "UTC"
ntp_servers:
- "time.cloudflare.com"
firewall_host_rules:
- name: "allow https from the lan"
from_ip: "192.168.10.0/24"
to_port: "443"
users_global:
- username: "alice"
name: "Alice Example"
publickey: "ssh-ed25519 AAAA... alice@example"
sudo: true
Tags
If you call the role without tags, it will execute all of the stages below.
| Tag | Purpose |
|---|---|
apk |
Alpine packages |
apt |
APT sources, packages and configuration |
apt-update |
APT upgrade, reboot handling |
apt-cleanup |
APT cleanup |
cron |
Cron jobs |
environment-file |
/etc/environment |
firewall |
ufw firewall |
fstab |
fstab entries (Alpine) |
hostname |
Hostname |
journald |
journald configuration |
locale |
System locale |
lxd |
Remove LXD |
motd |
Message of the day |
ntp |
chrony |
profile |
System-wide shell prompt (Alpine) |
service |
Services from service |
snap |
snapd and snap packages |
sshd |
SSH daemon |
swap |
Swap file |
sysctl |
Kernel parameters |
systemctl |
systemd units (fstrim.timer) |
syslog |
rsyslog |
telemetry |
Remove Ubuntu telemetry |
timezone |
Timezone |
usermanagement |
Users, keys and sudoers files |
zram |
zram compressed swap |
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml to refresh the role, then imports the common role with the
free strategy.
ansible-playbook playbook.yaml --tags "apt,sshd"
Notes
- The apt upgrade task reboots the host when
/var/run/reboot-requiredexists. Onsemaphore01.siempie.internala reboot is scheduled in 15 minutes instead. - The sshd configuration restricts ciphers, MACs and key exchange algorithms. On Ubuntu 24.04 the post-quantum key exchange is left out.
- The sudoers template contains host specific rules for the
droneuser.