Ansible role to setup a Zabbix Proxy
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 63a5243603
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:33 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:52:04 +00:00
defaults feat: upgrade zabbix to version 7.4 2025-07-17 11:18:34 +02:00
handlers feat: initial commit 2025-06-06 18:08:13 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles fix: update requirements to forgejo repo locations 2026-05-15 13:51:08 +02:00
tasks chore: migrate bare ansible_* facts to ansible_facts[] syntax 2026-05-19 09:19:09 +02:00
templates/zabbix feat: initial commit 2025-06-06 18:08:13 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:04 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:10 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:10 +02:00
.gitignore feat: initial commit 2025-06-06 18:08:13 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:44:05 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:10 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:47 +02:00
AGENTS.md style: align markdown table formatting for MD060 compliance 2026-05-18 18:26:21 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:28:33 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:58:34 +02:00

Ansible Role: Zabbix Proxy

This role installs and configures a Zabbix Proxy (active mode, SQLite database) that reports to a Zabbix server and encrypts the connection with a pre-shared key (PSK).

Requirements

Operating System Version
Debian 13

Dependencies

The role zabbix_prereq must run first. It installs the Zabbix package repository. The included playbook.yaml does this for you.

Variables

Variable Required Default Description
zabbix_major_version No "7.4" Zabbix major version to install
zabbix_server_host No "zabbix.siempie.internal" Zabbix server the proxy reports to
zabbix_proxy_psk_id Yes PSK identity (TLSPSKIdentity)
zabbix_proxy_psk Yes PSK value, written to /etc/zabbix/zabbix_proxy.psk

The PSK is a secret and belongs in sops-encrypted inventory variables. The role does not validate that the PSK variables are set.

Example

zabbix_server_host: "zabbix.siempie.internal"
zabbix_proxy_psk_id: "proxy-siempie"
zabbix_proxy_psk: "replace-with-sops-encrypted-psk"

What the role does

  • Installs zabbix-proxy-sqlite3 when the installed major version differs from zabbix_major_version. The old zabbix-proxy package is removed first.
  • Creates /usr/lib/zabbix/proxy/ for the SQLite database (zabbix.db).
  • Writes /etc/zabbix/zabbix_proxy.conf and the PSK file /etc/zabbix/zabbix_proxy.psk.
  • Restarts and enables the zabbix-proxy service when configuration changes.

The proxy runs in active mode (ProxyMode=0), listens on TCP 10051, uses inventory_hostname as its Hostname and has EnableRemoteCommands=1. Poller counts, caches and timeouts are fixed in the template.

Tags

If you call the role without tags, it will execute all of the stages below.

Tags Purpose
zabbix_proxy_install Only manage Zabbix Proxy install
zabbix_proxy_config Only manage Zabbix Proxy config

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq and zabbix_proxy roles, then executes both on all hosts.