Ansible Role for installing and configuring SempahoreUI
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 376f7f5c65
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:29:31 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:51:04 +00:00
defaults chore(package): update dependency mitogen-hq/mitogen to v0.3.53 2026-09-02 05:48:36 +00:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:50 +02:00
tasks chore(package): update cr.simoncor.net/dockerhub/semaphoreui/semaphore docker tag to v2.19.14 2026-09-09 10:33:20 +00:00
templates/semaphore feat: simplify semaphore and add ssh config 2025-10-02 14:14:26 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:58 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:04 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:04 +02:00
.gitignore feat: initial commit 2025-09-30 19:45:08 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:50 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:06 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:41 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:27:03 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 12:29:55 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:32 +02:00
readme.md docs: improve readme 2026-10-05 17:29:31 +02:00
renovate.json feat: initial commit 2025-09-30 19:45:08 +02:00

Ansible Role: Semaphore

Installs and runs Semaphore UI, a web UI for Ansible, as a Docker container with a SQLite database. The role also checks out Mitogen for use by playbooks run from Semaphore and provides the SSH key and SSH client config used to reach managed hosts.

Requirements

  • A Docker host. The role uses the community.docker collection and the ansible.builtin.git module.
  • Access to the registry mirror cr.simoncor.net (the image is pulled from cr.simoncor.net/dockerhub).
  • Outbound access to https://github.com/mitogen-hq/mitogen (git certificate verification is disabled for this checkout).

Dependencies

The playbook runs the docker role (https://git.simoncor.net/ansible/docker.git) before this role. Note that roles/requirements.yml only lists the semaphore role itself.

Variables

Variable Required Default Description
mitogen_version No 0.3.53 Mitogen release (git tag v<version>)
semaphore_admin_username No admin Admin username (see note below)
semaphore_admin_password Yes admin Admin password, must be overridden
semaphore_admin_name No Administrator Admin display name (see note below)
semaphore_ansible_ssh_key Yes supersecure Private SSH key for managed hosts
semaphore_ssh_config No SSH config, see below Content of ~/.ssh/config
timezone Yes Container timezone (TZ), not set here

The defaults for semaphore_admin_password and semaphore_ansible_ssh_key are placeholders. Always override them, and keep real values in sops-encrypted inventory variables.

The semaphore_admin_* variables are defined in defaults/main.yaml, but no task or template in this role uses them: the container is not given an admin account through its environment. Create the admin user with Semaphore itself.

The default semaphore_ssh_config is:

host *
  user ansible
  identityfile /home/semaphore/.ssh/ansible.key
  addressfamily inet
  stricthostkeychecking no
  userknownhostsfile /dev/null

Example

timezone: "Europe/Amsterdam"
mitogen_version: "0.3.53"

# keep real values in sops-encrypted inventory vars
semaphore_admin_password: "CHANGE-ME"
semaphore_ansible_ssh_key: "{{ vault_ansible_ssh_key }}"

Usage

Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on localhost, then runs the docker and semaphore roles in that order.

Operational notes

  • Directories /mnt/mitogen and /mnt/semaphore/{config,data,ssh,tmp} are created with owner and group 1001.
  • The SSH config is written to /mnt/semaphore/ssh/config (mode 0640), the key to /mnt/semaphore/ssh/ansible.key (mode 0400). Both are mounted into /home/semaphore/.ssh/ in the container.
  • Mitogen is cloned to /mnt/mitogen (mounted at /tmp/mitogen) and its ownership is set to 1001 on every run.
  • The container is called semaphore-app, uses image cr.simoncor.net/dockerhub/semaphoreui/semaphore:v2.19.14, host networking, restart policy unless-stopped and is pulled on every run. The web UI listens on 3000/tcp.
  • The container environment sets SEMAPHORE_DB_DIALECT=sqlite, SEMAPHORE_TOTP_ENABLED=True, SEMAPHORE_TOTP_ALLOW_RECOVERY=True, SEMAPHORE_SCHEDULE_TIMEZONE=Europe/Amsterdam (hardcoded) and TZ. Data lives in /mnt/semaphore/data and /mnt/semaphore/config.
  • After starting the container, the role runs a Docker cleanup (tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runs docker system prune --all --force --volumes. This removes everything unused on the host.
  • There are no tags.