- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Pangolin
Install and configure Pangolin - a tunneled reverse proxy for homelabs. The role runs
Pangolin and a Traefik instance (with the Pangolin badger plugin and a TransIP DNS challenge for Let's Encrypt)
as Docker containers on a shared pangolin Docker network.
Dependencies
dockerrole (installs Docker; run before this role byplaybook.yaml).
Both roles are fetched from roles/requirements.yml.
Variables
This role has no defaults/main.yaml. The following variables are used by the templates and tasks and must be set
in the inventory or group_vars.
| Variable | Required | Default | Description |
|---|---|---|---|
pangolin_domain |
Yes | none | Public FQDN of the dashboard (dashboard URL, CORS, Gerbil) |
pangolin_server_secret |
Yes | none | Pangolin server secret |
transip_account_name |
Yes | none | TransIP account name, passed to Traefik for the DNS challenge |
transip_private_key_path |
Yes | none | Path to the TransIP private key as seen inside the Traefik container |
Secrets (pangolin_server_secret, the TransIP key) belong in sops-encrypted inventory vars, never in plain text.
Example
pangolin_domain: "pangolin.example.com"
pangolin_server_secret: "CHANGE-ME-long-random-string"
transip_account_name: "example-account"
transip_private_key_path: "/path/to/transip.key"
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml on localhost, then executes the docker and pangolin roles.
What the role does
- Creates the Docker network
pangolin. - Creates
/mnt/pangolin/config,/mnt/pangolin/config/traefikand/mnt/pangolin/config/letsencrypt. - Templates
/mnt/pangolin/config/config.yml(Pangolin) and/mnt/pangolin/config/traefik/traefik_config.yml; a change restarts the matching container. - Runs container
pangolin(fosrl/pangolin, image pinned in the task) with a health check on port 3001. - Runs container
traefik(image pinned in the task) publishing ports 80, 443 and 8006 (TCP). - Prunes unused Docker containers, images, networks and volumes (
docker system prune --all --force --volumes).
Note that the base domains (simoncor.net, mirahsimon.us), the ACME e-mail address and the Pangolin flags are
hardcoded in the templates under templates/.