Ansible role for installing and configuring SideroLab's Omni
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet fa3a6157f9
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:30 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:49:30 +00:00
handlers feat: initial commit 2025-09-25 14:54:09 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:00 +02:00
tasks chore(package): update ghcr.io/siderolabs/omni docker tag to v1.12.3 2026-09-30 08:32:38 +00:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:49 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:54 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:54 +02:00
.gitignore feat: initial commit 2025-09-25 14:54:09 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:00 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:56 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:32 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:27:00 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:30 +02:00
readme.md docs: improve readme 2026-10-05 17:28:30 +02:00
renovate.json feat: initial commit 2025-09-25 14:54:09 +02:00

Ansible Role: Omni

Installs and configures Omni, the Sidero Labs management platform for Talos Linux and Kubernetes, as a Docker container using host networking.

Requirements

Docker must be present on the host, the community.docker collection must be available, and the TLS certificate must already exist as an acme.sh certificate for simoncor.net under /root/.acme.sh/simoncor.net_ecc/ (the role only links it). The role needs root.

Dependencies

The omni role itself declares none (dependencies: []). The playbook runs the docker role first. Note that roles/requirements.yml only lists omni, so the docker role has to be available to the playbook some other way.

Variables

The role has no defaults/main.yaml. All variables below must be provided from the inventory.

Variable Required Default Description
omni_etcd_priv_key Yes none Private (GPG) key content written to /mnt/omni/omni.asc
omni_account_uuid Yes none Omni account ID (--account-id)
omni_domain Yes none Base domain, used for api.<domain>, kube.<domain> and <domain>
omni_ip Yes none Advertised IP for the SideroLink WireGuard endpoint (port 50180)
omni_sso_user Yes none Initial user (--initial-users)
auth0_client_id Yes none Auth0 client ID
auth0_domain Yes none Auth0 domain

Example

Secrets such as the etcd private key belong in sops-encrypted inventory vars.

omni_account_uuid: "00000000-0000-0000-0000-000000000000"
omni_domain: "omni.example.com"
omni_ip: "192.0.2.10"
omni_sso_user: "admin@example.com"
auth0_client_id: "changeme"
auth0_domain: "example.eu.auth0.com"
omni_etcd_priv_key: "<sops-encrypted gpg private key>"

Usage

Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller, then includes the docker role and the omni role on all hosts.

Operational notes

  • Image: ghcr.io/siderolabs/omni:v1.12.0 (always pulled), container omni, network_mode: host, restart policy unless-stopped, with NET_ADMIN and /dev/net/tun.
  • Data lives in /mnt/omni (data, etcd-vol). Omni stores its state in SQLite at /data/omni-sqlite.db.
  • /mnt/omni/omni.key and /mnt/omni/omni.pem are symlinks to the acme.sh key and full chain for simoncor.net.
  • Ports: 443 (API), 8090 (machine API), 8091 (event sink), 8100 (Kubernetes proxy), 50180 (WireGuard).
  • Auth is through Auth0 (--auth-auth0-enabled=true).
  • Changing the etcd key restarts the container through the restart omni handler.
  • After the install the role runs a Docker prune of all unused containers, images, networks and volumes on the host, and then repeats it with docker system prune --all --force --volumes.