Ansible role for installing and configuring a WoodpeckerCI server
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Woodpecker CI
Installs and runs Woodpecker CI as two Docker containers on one host: a server (web UI and API, SQLite database) and an agent that runs the pipelines through the Docker socket. Logins use OAuth2 with a Forgejo instance.
Requirements
- A Docker host. The role uses the
community.dockercollection. - Access to the registry mirror
cr.simoncor.net(images are pulled fromcr.simoncor.net/dockerhub). - A Forgejo OAuth2 application for Woodpecker.
Dependencies
The playbook runs these roles first, as listed in roles/requirements.yml:
docker(https://git.simoncor.net/ansible/docker.git)traefik(https://git.simoncor.net/ansible/traefik.git), which publishes the server on its public host namewoodpecker(this repository,https://git.simoncor.net/ansible/woodpecker.git)
Variables
The role has no defaults/ directory; all variables must be set in the inventory.
| Variable | Required | Default | Description |
|---|---|---|---|
woodpecker_forgejo_client |
Yes | Forgejo OAuth2 client ID | |
woodpecker_forgejo_secret |
Yes | Forgejo OAuth2 client secret | |
woodpecker_agent_secret |
Yes | Shared secret for agent authentication | |
timezone |
Yes | Timezone for the containers (TZ) |
Keep the secrets in sops-encrypted inventory variables.
Example
timezone: "Europe/Amsterdam"
# keep real values in sops-encrypted inventory vars
woodpecker_forgejo_client: "your-oauth2-client-id"
woodpecker_forgejo_secret: "CHANGE-ME"
woodpecker_agent_secret: "CHANGE-ME"
Usage
Run playbook.yaml through Semaphore. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml
on localhost, then runs the docker, traefik and woodpecker roles in that order.
Operational notes
- The data directory
/mnt/woodpecker/datais created with owner and group1000and mounted at/datain the server container. It holds the SQLite database (woodpecker.db, WAL mode). - Containers
woodpecker-serverandwoodpecker-agentuse the imageswoodpeckerci/woodpecker-serverandwoodpecker-agent, both tagv3.18.1, fromcr.simoncor.net/dockerhub. They use host networking, restart policyunless-stopped, are pulled on every run and have a healthcheck every 30 seconds. - The server listens on
8000/tcp. The agent mounts/var/run/docker.sock, runs at most 3 workflows at the same time and serves its healthcheck on:3001. - Several settings are hardcoded in
tasks/woodpecker.yaml: the public URLhttps://ci.simoncor.net, the Forgejo URLhttps://git.simoncor.net, the admin usersforgejo_admin,simonand closed registration (WOODPECKER_OPEN=false). Edit the tasks to change them. A matching Traefik route for the server has to be defined in thetraefikrole. - After starting the containers, the role runs a Docker cleanup (
tasks/cleanup.yaml): it prunes containers, images, networks, volumes and the builder cache and then runsdocker system prune --all --force --volumes. This removes everything unused on the host. - There are no tags.