- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| meta | ||
| roles | ||
| tasks | ||
| templates/semaphore | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Semaphore
Installs and runs Semaphore UI, a web UI for Ansible, as a Docker container with a SQLite database. The role also checks out Mitogen for use by playbooks run from Semaphore and provides the SSH key and SSH client config used to reach managed hosts.
Requirements
- A Docker host. The role uses the
community.dockercollection and theansible.builtin.gitmodule. - Access to the registry mirror
cr.simoncor.net(the image is pulled fromcr.simoncor.net/dockerhub). - Outbound access to
https://github.com/mitogen-hq/mitogen(git certificate verification is disabled for this checkout).
Dependencies
The playbook runs the docker role (https://git.simoncor.net/ansible/docker.git) before this role. Note that
roles/requirements.yml only lists the semaphore role itself.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
mitogen_version |
No | 0.3.53 |
Mitogen release (git tag v<version>) |
semaphore_admin_username |
No | admin |
Admin username (see note below) |
semaphore_admin_password |
Yes | admin |
Admin password, must be overridden |
semaphore_admin_name |
No | Administrator |
Admin display name (see note below) |
semaphore_ansible_ssh_key |
Yes | supersecure |
Private SSH key for managed hosts |
semaphore_ssh_config |
No | SSH config, see below | Content of ~/.ssh/config |
timezone |
Yes | Container timezone (TZ), not set here |
The defaults for semaphore_admin_password and semaphore_ansible_ssh_key are placeholders. Always override them,
and keep real values in sops-encrypted inventory variables.
The semaphore_admin_* variables are defined in defaults/main.yaml, but no task or template in this role uses them:
the container is not given an admin account through its environment. Create the admin user with Semaphore itself.
The default semaphore_ssh_config is:
host *
user ansible
identityfile /home/semaphore/.ssh/ansible.key
addressfamily inet
stricthostkeychecking no
userknownhostsfile /dev/null
Example
timezone: "Europe/Amsterdam"
mitogen_version: "0.3.53"
# keep real values in sops-encrypted inventory vars
semaphore_admin_password: "CHANGE-ME"
semaphore_ansible_ssh_key: "{{ vault_ansible_ssh_key }}"
Usage
Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml
on localhost, then runs the docker and semaphore roles in that order.
Operational notes
- Directories
/mnt/mitogenand/mnt/semaphore/{config,data,ssh,tmp}are created with owner and group1001. - The SSH config is written to
/mnt/semaphore/ssh/config(mode0640), the key to/mnt/semaphore/ssh/ansible.key(mode0400). Both are mounted into/home/semaphore/.ssh/in the container. - Mitogen is cloned to
/mnt/mitogen(mounted at/tmp/mitogen) and its ownership is set to1001on every run. - The container is called
semaphore-app, uses imagecr.simoncor.net/dockerhub/semaphoreui/semaphore:v2.19.14, host networking, restart policyunless-stoppedand is pulled on every run. The web UI listens on3000/tcp. - The container environment sets
SEMAPHORE_DB_DIALECT=sqlite,SEMAPHORE_TOTP_ENABLED=True,SEMAPHORE_TOTP_ALLOW_RECOVERY=True,SEMAPHORE_SCHEDULE_TIMEZONE=Europe/Amsterdam(hardcoded) andTZ. Data lives in/mnt/semaphore/dataand/mnt/semaphore/config. - After starting the container, the role runs a Docker cleanup (
tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runsdocker system prune --all --force --volumes. This removes everything unused on the host. - There are no tags.