| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| alpine-upgrade.yaml | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
| update-all-hosts.yaml | ||
Ansible Playbook: Toolbox
A set of operational playbooks and tasks for system maintenance: forcing a time sync, installing OS updates, rebooting, updating a whole fleet and upgrading Alpine Linux releases. It is not a role with variables; each playbook is run on demand (for example from Semaphore).
Requirements
- Update tasks support the OS families Alpine (
apk), Debian (apt), RedHat (dnf) and Suse (zypper). - Alpine release upgrades are available for Alpine 3.22 to 3.23 and 3.23 to 3.24.
- Collection
community.general(apk and zypper modules).
Dependencies
None (dependencies: []). roles/requirements.yml only lists this repository itself
(https://git.simoncor.net/ansible/toolbox.git) and none of the playbooks runs ansible-galaxy.
Variables
There is no defaults/ directory and the playbooks define no variables.
Playbooks
All playbooks run on hosts: "all" with become: true and serial: 1 (one host at a time), so limit them to the
hosts you want to touch.
| Playbook | Purpose |
|---|---|
playbook.yaml |
Force a time sync, install updates, reboot; selected with tags |
update-all-hosts.yaml |
Install updates and reboot all hosts except proxmox and semaphore01 |
alpine-upgrade.yaml |
Upgrade Alpine to the next release (3.22 to 3.23, or 3.23 to 3.24) |
playbook.yaml
| Tag | Tasks file | Description |
|---|---|---|
chrony |
tasks/chrony.yaml |
Run chronyc makestep if chrony is installed (never fails) |
update |
tasks/update.yaml |
Install updates and clean the package cache (apk, apt, dnf or zypper) |
reboot |
tasks/reboot.yaml |
Reboot the host (reboot timeout 120 seconds) |
The update and reboot tasks are additionally tagged never, so they only run when you select their tag
explicitly. The chrony task has no never tag and also runs when no tags are given.
On Debian the update is a safe upgrade with autoremove and cache clean; on Alpine it is apk upgrade plus
apk clean cache; on RedHat it is dnf update, autoremove and clean; on Suse a zypper update and clean.
update-all-hosts.yaml
Updates and reboots every host in the inventory except the group proxmox and semaphore01.siempie.internal
(max_fail_percentage: 100, so a failing host does not stop the run). A second play on localhost prints a reminder
that the Proxmox hosts and semaphore01.siempie.internal need manual attention.
Because of the never tags inside the tasks, run it with the update and reboot tags, otherwise no task runs:
--tags update,reboot
alpine-upgrade.yaml
Upgrades Alpine one release at a time. The play picks tasks/alpine323.yaml on Alpine 3.22 hosts and
tasks/alpine324.yaml on Alpine 3.23 hosts. Each file does the following:
- rewrites the release in
/etc/apk/repositories - updates the apk cache, upgrades
apk-toolsand then all packages - reboots the host
- removes
/etc/motd, cleans the apk cache and runsfstrim /when the host is a KVM guest
To go from 3.22 to 3.24, run the playbook twice.
Example
Run from Semaphore with the playbook, a limit and tags, for example:
playbook: playbook.yaml
limit: myhost.example.com
--tags: chrony,update,reboot
Usage
Create a Semaphore task template per playbook and set the tags (CLI args --tags ...) as needed.