- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates/zabbix | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Zabbix Proxy
This role installs and configures a Zabbix Proxy (active mode, SQLite database) that reports to a Zabbix server and encrypts the connection with a pre-shared key (PSK).
Requirements
| Operating System | Version |
|---|---|
| Debian | 13 |
Dependencies
The role zabbix_prereq must run first. It installs the Zabbix package repository. The included playbook.yaml
does this for you.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
| zabbix_major_version | No | "7.4" |
Zabbix major version to install |
| zabbix_server_host | No | "zabbix.siempie.internal" |
Zabbix server the proxy reports to |
| zabbix_proxy_psk_id | Yes | PSK identity (TLSPSKIdentity) | |
| zabbix_proxy_psk | Yes | PSK value, written to /etc/zabbix/zabbix_proxy.psk |
The PSK is a secret and belongs in sops-encrypted inventory variables. The role does not validate that the PSK variables are set.
Example
zabbix_server_host: "zabbix.siempie.internal"
zabbix_proxy_psk_id: "proxy-siempie"
zabbix_proxy_psk: "replace-with-sops-encrypted-psk"
What the role does
- Installs
zabbix-proxy-sqlite3when the installed major version differs fromzabbix_major_version. The oldzabbix-proxypackage is removed first. - Creates
/usr/lib/zabbix/proxy/for the SQLite database (zabbix.db). - Writes
/etc/zabbix/zabbix_proxy.confand the PSK file/etc/zabbix/zabbix_proxy.psk. - Restarts and enables the
zabbix-proxyservice when configuration changes.
The proxy runs in active mode (ProxyMode=0), listens on TCP 10051, uses inventory_hostname as its Hostname and
has EnableRemoteCommands=1. Poller counts, caches and timeouts are fixed in the template.
Tags
If you call the role without tags, it will execute all of the stages below.
| Tags | Purpose |
|---|---|
| zabbix_proxy_install | Only manage Zabbix Proxy install |
| zabbix_proxy_config | Only manage Zabbix Proxy config |
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq and
zabbix_proxy roles, then executes both on all hosts.