Ansible role for starting a (RustFS) S3 storage server
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: RustFS
Installs and runs RustFS, an S3 compatible object storage server, as a Docker
container. The repository is named s3, the role is installed as rustfs.
Requirements
- A Docker host. The role uses the
community.dockercollection. - Access to the registry mirror
cr.simoncor.net(the image is pulled fromcr.simoncor.net/dockerhub).
Dependencies
The playbook runs these roles first, as listed in roles/requirements.yml:
docker(https://git.simoncor.net/ansible/docker.git)traefik(https://git.simoncor.net/ansible/traefik.git)rustfs(this repository,https://git.simoncor.net/ansible/s3.git)
Variables
The role has no defaults/ and defines no variables of its own. It uses one variable that must come from the
inventory or from one of the dependencies:
| Variable | Required | Default | Description |
|---|---|---|---|
timezone |
Yes | Timezone, passed to the container as TZ |
Variables of the docker and traefik roles apply as documented in those repositories.
Example
timezone: "Europe/Amsterdam"
Usage
Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml
on localhost, then runs the docker, traefik and rustfs roles in that order.
Operational notes
- The data directory
/mnt/rustfs/datais created with owner and group10001and mounted at/datain the container. The mount must exist and be persistent. - The container is called
rustfs, uses imagecr.simoncor.net/dockerhub/rustfs/rustfs:1.0.0-beta.3(pinned beta), runs with host networking, restart policyunless-stoppedand is pulled on every run (pull: always). - Ports:
9000/tcp(S3 API) and9001/tcp(console) are published. The container sets no Traefik labels, so routing through Traefik has to be configured on the Traefik side. - No credentials are configured by the role: the only environment variable is
TZ. - After starting the container, the role runs a Docker cleanup (
tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runsdocker system prune --all --force --volumes. This removes everything unused on the host, including images and volumes of stopped containers. - There are no tags.