Ansible role with usefull tools to execute based on tags
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet fd74e9a3b3
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:29:31 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:51:32 +00:00
meta feat: initial commit 2025-10-23 10:08:46 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:44:20 +02:00
tasks feat: add upgrade to alpine v3.24 2026-06-10 08:04:24 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:59 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:05 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:05 +02:00
.gitignore feat: initial commit 2025-10-23 10:08:46 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:44:20 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:06 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:42 +02:00
AGENTS.md style: align markdown table formatting for MD060 compliance 2026-05-18 18:26:21 +02:00
alpine-upgrade.yaml feat: enable alpine upgrade playbook 2026-06-10 08:05:16 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml fix: import_tasks to make tags work 2025-11-10 15:25:48 +01:00
readme.md docs: improve readme 2026-10-05 17:29:31 +02:00
renovate.json feat: initial commit 2025-10-23 10:08:46 +02:00
update-all-hosts.yaml feat: ignore single host failures 2026-05-01 15:41:43 +02:00

Ansible Playbook: Toolbox

A set of operational playbooks and tasks for system maintenance: forcing a time sync, installing OS updates, rebooting, updating a whole fleet and upgrading Alpine Linux releases. It is not a role with variables; each playbook is run on demand (for example from Semaphore).

Requirements

  • Update tasks support the OS families Alpine (apk), Debian (apt), RedHat (dnf) and Suse (zypper).
  • Alpine release upgrades are available for Alpine 3.22 to 3.23 and 3.23 to 3.24.
  • Collection community.general (apk and zypper modules).

Dependencies

None (dependencies: []). roles/requirements.yml only lists this repository itself (https://git.simoncor.net/ansible/toolbox.git) and none of the playbooks runs ansible-galaxy.

Variables

There is no defaults/ directory and the playbooks define no variables.

Playbooks

All playbooks run on hosts: "all" with become: true and serial: 1 (one host at a time), so limit them to the hosts you want to touch.

Playbook Purpose
playbook.yaml Force a time sync, install updates, reboot; selected with tags
update-all-hosts.yaml Install updates and reboot all hosts except proxmox and semaphore01
alpine-upgrade.yaml Upgrade Alpine to the next release (3.22 to 3.23, or 3.23 to 3.24)

playbook.yaml

Tag Tasks file Description
chrony tasks/chrony.yaml Run chronyc makestep if chrony is installed (never fails)
update tasks/update.yaml Install updates and clean the package cache (apk, apt, dnf or zypper)
reboot tasks/reboot.yaml Reboot the host (reboot timeout 120 seconds)

The update and reboot tasks are additionally tagged never, so they only run when you select their tag explicitly. The chrony task has no never tag and also runs when no tags are given.

On Debian the update is a safe upgrade with autoremove and cache clean; on Alpine it is apk upgrade plus apk clean cache; on RedHat it is dnf update, autoremove and clean; on Suse a zypper update and clean.

update-all-hosts.yaml

Updates and reboots every host in the inventory except the group proxmox and semaphore01.siempie.internal (max_fail_percentage: 100, so a failing host does not stop the run). A second play on localhost prints a reminder that the Proxmox hosts and semaphore01.siempie.internal need manual attention.

Because of the never tags inside the tasks, run it with the update and reboot tags, otherwise no task runs:

--tags update,reboot

alpine-upgrade.yaml

Upgrades Alpine one release at a time. The play picks tasks/alpine323.yaml on Alpine 3.22 hosts and tasks/alpine324.yaml on Alpine 3.23 hosts. Each file does the following:

  • rewrites the release in /etc/apk/repositories
  • updates the apk cache, upgrades apk-tools and then all packages
  • reboots the host
  • removes /etc/motd, cleans the apk cache and runs fstrim / when the host is a KVM guest

To go from 3.22 to 3.24, run the playbook twice.

Example

Run from Semaphore with the playbook, a limit and tags, for example:

playbook:  playbook.yaml
limit:     myhost.example.com
--tags:    chrony,update,reboot

Usage

Create a Semaphore task template per playbook and set the tags (CLI args --tags ...) as needed.