Ansible role for updating a Promxox Cluster
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 0942a85181
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:37 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:50:05 +00:00
meta feat: initial commit 2025-05-30 15:04:18 +02:00
playbooks feat: unifi tasks and playbooks 2026-08-06 07:44:56 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:53 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:58 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:58 +02:00
.gitignore feat: initial commit 2025-05-30 15:04:18 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:53 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:00 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:36 +02:00
AGENTS.md style: align markdown table formatting for MD060 compliance 2026-05-18 18:26:21 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
readme.md docs: improve readme 2026-10-05 17:28:37 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:58:02 +02:00

Ansible Playbook: Proxmox

Playbooks to maintain a Proxmox VE cluster: put a node into maintenance, update it, take it out of maintenance and set or unset the Ceph maintenance flags. This repository only contains playbooks (no role tasks, defaults or requirements.yml) and defines no variables. All playbooks target hosts: all with become: true, so limit them to the node you want to work on.

Requirements

  • Proxmox VE nodes (Debian based) reachable over SSH, with a user that can become root.
  • ha-manager and pvesh (Proxmox VE) on the nodes, ceph for the Ceph playbooks and fwupdmgr for firmware updates.
  • The inventory hostname must start with the Proxmox node name, because inventory_hostname_short is used as node name.

Playbooks

Playbook Description
playbooks/pve-enter-maintenance.yaml Enable HA maintenance mode on the node, then wait until it is empty
playbooks/pve-update-node.yaml Run a dist-upgrade, install firmware updates and reboot the node
playbooks/pve-exit-maintenance.yaml Disable HA maintenance mode on the node, then wait 60 seconds
playbooks/ceph-enter-maintenance.yaml Set the Ceph OSD flags nodeep-scrub, noout, norebalance, noscrub
playbooks/ceph-exit-maintenance.yaml Unset the same Ceph OSD flags

Details

  • Enter maintenance runs ha-manager crm-command node-maintenance enable <node> and then polls pvesh get /cluster/resources (every 10 seconds, up to 60 retries) until no guests remain on the node. Resources matching node/pve, storage/pve, sdn/pve, template, network, ocp or test are ignored.
  • Update runs apt with dist upgrade (keeping existing config files), then fwupdmgr upgrade (failures are ignored) and finally reboots the node, waiting up to 600 seconds for it to return.
  • Exit maintenance runs ha-manager crm-command node-maintenance disable <node> (3 retries) and waits 60 seconds so the cluster can settle.

Tags

None of the playbooks define tags.

Usage

Run the playbooks through Semaphore, one task template per playbook, limited to a single node. A typical node update runs the playbooks in this order:

  1. ceph-enter-maintenance.yaml (only when the cluster uses Ceph)
  2. pve-enter-maintenance.yaml
  3. pve-update-node.yaml
  4. pve-exit-maintenance.yaml
  5. ceph-exit-maintenance.yaml (only when the cluster uses Ceph)

Run it manually with, for example:

ansible-playbook -i inventory playbooks/pve-update-node.yaml --limit pve01