| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: phpIPAM
Install and configure phpIPAM - an open-source IP address management tool using Docker.
The role runs three containers on a dedicated phpipam Docker network: MariaDB (phpipam-db), the web application
(phpipam-app) and the scanning cron container (phpipam-cron).
Dependencies
dockerrole (installs Docker).traefikrole (reverse proxy in front of the web interface).
Both are executed before this role by playbook.yaml and fetched via roles/requirements.yml.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
mariadb_version |
No | "11.8.6" |
MariaDB image tag (managed by Renovate) |
phpipam_db_root_password |
Yes | "changeme" |
MariaDB root password |
phpipam_db_user |
No | "phpipam" |
phpIPAM database user |
phpipam_db_password |
Yes | "changeme" |
phpIPAM database password |
phpipam_db_name |
No | "phpipam" |
phpIPAM database name |
phpipam_http_port |
No | "8080" |
Host port mapped to port 80 of the web container |
phpipam_scan_interval |
No | "6h" |
Interval for network scanning (SCAN_INTERVAL of the cron container) |
The role also uses the global variable timezone (passed as TZ to all containers), which is not defined in
defaults/main.yaml and must be set in the inventory.
The default values of phpipam_db_root_password and phpipam_db_password are placeholders. Always override them.
Keep the real values in sops-encrypted inventory vars.
Example
timezone: "Europe/Amsterdam"
phpipam_db_root_password: "CHANGE-ME-root-password"
phpipam_db_user: "phpipam"
phpipam_db_password: "CHANGE-ME-db-password"
phpipam_db_name: "phpipam"
phpipam_http_port: "8080"
phpipam_scan_interval: "12h"
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml on localhost, then executes the docker, traefik and
phpipam roles.
Operational notes
- MariaDB data lives in
/mnt/mariadbon the host. - The web interface is published on
phpipam_http_port; the web and cron containers run phpIPAMv1.8.3and get theNET_ADMINandNET_RAWcapabilities for scanning. - The web container has
IPAM_DISABLE_INSTALLERenabled and trustsX-Forwarded-*headers (for use behind Traefik). - After the containers are started the role prunes unused Docker containers, images, networks and volumes.