Ansible role for installing and configuring Pangolin
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet e698891aa7
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:36 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:49:44 +00:00
handlers fix: add missing traefik handler 2026-07-21 13:53:29 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:27 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:00 +02:00
tasks chore(package): update cr.simoncor.net/dockerhub/fosrl/pangolin docker tag to v1.24.0 2026-10-01 05:48:14 +00:00
templates feat: initial commit 2025-09-22 10:53:02 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:50 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:55 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:55 +02:00
.gitignore feat: initial commit 2025-09-22 10:53:02 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:00 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:57 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:34 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:27:02 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:31 +02:00
readme.md docs: improve readme 2026-10-05 17:28:36 +02:00
renovate.json feat: initial commit 2025-09-22 10:53:02 +02:00

Ansible Role: Pangolin

Install and configure Pangolin - a tunneled reverse proxy for homelabs. The role runs Pangolin and a Traefik instance (with the Pangolin badger plugin and a TransIP DNS challenge for Let's Encrypt) as Docker containers on a shared pangolin Docker network.

Dependencies

  • docker role (installs Docker; run before this role by playbook.yaml).

Both roles are fetched from roles/requirements.yml.

Variables

This role has no defaults/main.yaml. The following variables are used by the templates and tasks and must be set in the inventory or group_vars.

Variable Required Default Description
pangolin_domain Yes none Public FQDN of the dashboard (dashboard URL, CORS, Gerbil)
pangolin_server_secret Yes none Pangolin server secret
transip_account_name Yes none TransIP account name, passed to Traefik for the DNS challenge
transip_private_key_path Yes none Path to the TransIP private key as seen inside the Traefik container

Secrets (pangolin_server_secret, the TransIP key) belong in sops-encrypted inventory vars, never in plain text.

Example

pangolin_domain: "pangolin.example.com"
pangolin_server_secret: "CHANGE-ME-long-random-string"
transip_account_name: "example-account"
transip_private_key_path: "/path/to/transip.key"

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on localhost, then executes the docker and pangolin roles.

What the role does

  • Creates the Docker network pangolin.
  • Creates /mnt/pangolin/config, /mnt/pangolin/config/traefik and /mnt/pangolin/config/letsencrypt.
  • Templates /mnt/pangolin/config/config.yml (Pangolin) and /mnt/pangolin/config/traefik/traefik_config.yml; a change restarts the matching container.
  • Runs container pangolin (fosrl/pangolin, image pinned in the task) with a health check on port 3001.
  • Runs container traefik (image pinned in the task) publishing ports 80, 443 and 8006 (TCP).
  • Prunes unused Docker containers, images, networks and volumes (docker system prune --all --force --volumes).

Note that the base domains (simoncor.net, mirahsimon.us), the ACME e-mail address and the Pangolin flags are hardcoded in the templates under templates/.