| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Omni
Installs and configures Omni, the Sidero Labs management platform for Talos Linux and Kubernetes, as a Docker container using host networking.
Requirements
Docker must be present on the host, the community.docker collection must be available, and the TLS certificate
must already exist as an acme.sh certificate for simoncor.net under /root/.acme.sh/simoncor.net_ecc/
(the role only links it). The role needs root.
Dependencies
The omni role itself declares none (dependencies: []). The playbook runs the docker role first. Note that
roles/requirements.yml only lists omni, so the docker role has to be available to the playbook some other way.
Variables
The role has no defaults/main.yaml. All variables below must be provided from the inventory.
| Variable | Required | Default | Description |
|---|---|---|---|
omni_etcd_priv_key |
Yes | none | Private (GPG) key content written to /mnt/omni/omni.asc |
omni_account_uuid |
Yes | none | Omni account ID (--account-id) |
omni_domain |
Yes | none | Base domain, used for api.<domain>, kube.<domain> and <domain> |
omni_ip |
Yes | none | Advertised IP for the SideroLink WireGuard endpoint (port 50180) |
omni_sso_user |
Yes | none | Initial user (--initial-users) |
auth0_client_id |
Yes | none | Auth0 client ID |
auth0_domain |
Yes | none | Auth0 domain |
Example
Secrets such as the etcd private key belong in sops-encrypted inventory vars.
omni_account_uuid: "00000000-0000-0000-0000-000000000000"
omni_domain: "omni.example.com"
omni_ip: "192.0.2.10"
omni_sso_user: "admin@example.com"
auth0_client_id: "changeme"
auth0_domain: "example.eu.auth0.com"
omni_etcd_priv_key: "<sops-encrypted gpg private key>"
Usage
Run playbook.yaml via Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on
the controller, then includes the docker role and the omni role on all hosts.
Operational notes
- Image:
ghcr.io/siderolabs/omni:v1.12.0(always pulled), containeromni,network_mode: host, restart policyunless-stopped, withNET_ADMINand/dev/net/tun. - Data lives in
/mnt/omni(data,etcd-vol). Omni stores its state in SQLite at/data/omni-sqlite.db. /mnt/omni/omni.keyand/mnt/omni/omni.pemare symlinks to the acme.sh key and full chain forsimoncor.net.- Ports: 443 (API), 8090 (machine API), 8091 (event sink), 8100 (Kubernetes proxy), 50180 (WireGuard).
- Auth is through Auth0 (
--auth-auth0-enabled=true). - Changing the etcd key restarts the container through the
restart omnihandler. - After the install the role runs a Docker prune of all unused containers, images, networks and volumes on the host,
and then repeats it with
docker system prune --all --force --volumes.