Ansible role to run phpIPAM in docker containers.
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 828eb30540
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:36 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:49:50 +00:00
defaults feat: pin mariadb version 2026-05-08 13:59:41 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:54 +02:00
tasks chore(package): update cr.simoncor.net/dockerhub/phpipam/phpipam-www docker tag to v1.8.3 2026-09-10 14:33:41 +00:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:51 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:57 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:57 +02:00
.gitignore feat: add more stuff 2026-02-18 17:20:00 +01:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:54 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:58 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:35 +02:00
AGENTS.md feat: initial commit 2026-02-18 17:08:46 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:28:36 +02:00
renovate.json feat: add more stuff 2026-02-18 17:20:00 +01:00

Ansible Role: phpIPAM

Install and configure phpIPAM - an open-source IP address management tool using Docker. The role runs three containers on a dedicated phpipam Docker network: MariaDB (phpipam-db), the web application (phpipam-app) and the scanning cron container (phpipam-cron).

Dependencies

  • docker role (installs Docker).
  • traefik role (reverse proxy in front of the web interface).

Both are executed before this role by playbook.yaml and fetched via roles/requirements.yml.

Variables

Variable Required Default Description
mariadb_version No "11.8.6" MariaDB image tag (managed by Renovate)
phpipam_db_root_password Yes "changeme" MariaDB root password
phpipam_db_user No "phpipam" phpIPAM database user
phpipam_db_password Yes "changeme" phpIPAM database password
phpipam_db_name No "phpipam" phpIPAM database name
phpipam_http_port No "8080" Host port mapped to port 80 of the web container
phpipam_scan_interval No "6h" Interval for network scanning (SCAN_INTERVAL of the cron container)

The role also uses the global variable timezone (passed as TZ to all containers), which is not defined in defaults/main.yaml and must be set in the inventory.

The default values of phpipam_db_root_password and phpipam_db_password are placeholders. Always override them. Keep the real values in sops-encrypted inventory vars.

Example

timezone: "Europe/Amsterdam"
phpipam_db_root_password: "CHANGE-ME-root-password"
phpipam_db_user: "phpipam"
phpipam_db_password: "CHANGE-ME-db-password"
phpipam_db_name: "phpipam"
phpipam_http_port: "8080"
phpipam_scan_interval: "12h"

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on localhost, then executes the docker, traefik and phpipam roles.

Operational notes

  • MariaDB data lives in /mnt/mariadb on the host.
  • The web interface is published on phpipam_http_port; the web and cron containers run phpIPAM v1.8.3 and get the NET_ADMIN and NET_RAW capabilities for scanning.
  • The web container has IPAM_DISABLE_INSTALLER enabled and trusts X-Forwarded-* headers (for use behind Traefik).
  • After the containers are started the role prunes unused Docker containers, images, networks and volumes.