Ansible role for installing and configuring a WoodpeckerCI server
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 4d49568f6c
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:29:32 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:51:51 +00:00
meta feat: initial woodpecker ci server role setup 2026-05-10 14:13:09 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:49 +02:00
tasks feat: set woodpecker agent healthcheck to port 3001 2026-09-16 13:51:46 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:01 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:08 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:08 +02:00
.gitignore feat: initial woodpecker ci server role setup 2026-05-10 14:13:09 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:13:49 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:08 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:45 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:29:32 +02:00
renovate.json feat: initial woodpecker ci server role setup 2026-05-10 14:13:09 +02:00

Ansible Role: Woodpecker CI

Installs and runs Woodpecker CI as two Docker containers on one host: a server (web UI and API, SQLite database) and an agent that runs the pipelines through the Docker socket. Logins use OAuth2 with a Forgejo instance.

Requirements

  • A Docker host. The role uses the community.docker collection.
  • Access to the registry mirror cr.simoncor.net (images are pulled from cr.simoncor.net/dockerhub).
  • A Forgejo OAuth2 application for Woodpecker.

Dependencies

The playbook runs these roles first, as listed in roles/requirements.yml:

  • docker (https://git.simoncor.net/ansible/docker.git)
  • traefik (https://git.simoncor.net/ansible/traefik.git), which publishes the server on its public host name
  • woodpecker (this repository, https://git.simoncor.net/ansible/woodpecker.git)

Variables

The role has no defaults/ directory; all variables must be set in the inventory.

Variable Required Default Description
woodpecker_forgejo_client Yes Forgejo OAuth2 client ID
woodpecker_forgejo_secret Yes Forgejo OAuth2 client secret
woodpecker_agent_secret Yes Shared secret for agent authentication
timezone Yes Timezone for the containers (TZ)

Keep the secrets in sops-encrypted inventory variables.

Example

timezone: "Europe/Amsterdam"

# keep real values in sops-encrypted inventory vars
woodpecker_forgejo_client: "your-oauth2-client-id"
woodpecker_forgejo_secret: "CHANGE-ME"
woodpecker_agent_secret: "CHANGE-ME"

Usage

Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on localhost, then runs the docker, traefik and woodpecker roles in that order.

Operational notes

  • The data directory /mnt/woodpecker/data is created with owner and group 1000 and mounted at /data in the server container. It holds the SQLite database (woodpecker.db, WAL mode).
  • Containers woodpecker-server and woodpecker-agent use the images woodpeckerci/woodpecker-server and woodpecker-agent, both tag v3.18.1, from cr.simoncor.net/dockerhub. They use host networking, restart policy unless-stopped, are pulled on every run and have a healthcheck every 30 seconds.
  • The server listens on 8000/tcp. The agent mounts /var/run/docker.sock, runs at most 3 workflows at the same time and serves its healthcheck on :3001.
  • Several settings are hardcoded in tasks/woodpecker.yaml: the public URL https://ci.simoncor.net, the Forgejo URL https://git.simoncor.net, the admin users forgejo_admin,simon and closed registration (WOODPECKER_OPEN=false). Edit the tasks to change them. A matching Traefik route for the server has to be defined in the traefik role.
  • After starting the containers, the role runs a Docker cleanup (tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runs docker system prune --all --force --volumes. This removes everything unused on the host.
  • There are no tags.