Ansible role to setup a Zabbix Server
- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates/zabbix | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Zabbix Server
This role installs and configures a Zabbix Server with a PostgreSQL backend (TimescaleDB optional). It imports the Zabbix database schema into an empty database.
Requirements
| Operating System | Version |
|---|---|
| Debian | 13 and newer |
The role does not manage the database itself. You need:
- A reachable PostgreSQL server (TimescaleDB is optional).
- A database and user matching
zabbix_server_db_nameandzabbix_server_db_user(with thetimescaledbextension whenzabbix_server_db_timescaledbistrue).
Dependencies
zabbix_prereq: installs the Zabbix package repository.postgresql: provides the database. The includedplaybook.yamlruns it only whenzabbix_server_db_hostislocalhostor127.0.0.1. Configure the database and user through its own variables (postgresql_users,postgresql_databases,postgresql_timescaledb_enabled), see the readme of that role.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
| zabbix_major_version | No | "7.4" |
Zabbix major version to install (upgrades on mismatch) |
| zabbix_server_db_host | No | "localhost" |
Database host |
| zabbix_server_db_port | No | "5432" |
Database port |
| zabbix_server_db_name | No | "zabbix" |
Database name |
| zabbix_server_db_user | No | "zabbix" |
Database user |
| zabbix_server_db_pass | Yes | Database password (the role fails when it is empty) | |
| zabbix_server_db_timescaledb | No | false |
Also import the TimescaleDB schema when importing the schema |
The database password is a secret and belongs in sops-encrypted inventory variables.
Example
zabbix_server_db_name: "zabbix"
zabbix_server_db_user: "zabbix"
zabbix_server_db_pass: "replace-with-sops-encrypted-password"
zabbix_server_db_timescaledb: true
# settings for the postgresql role (same host)
postgresql_timescaledb_enabled: true
postgresql_users:
- name: "zabbix"
password: "replace-with-sops-encrypted-password"
postgresql_databases:
- name: "zabbix"
owner: "zabbix"
extensions:
- "timescaledb"
What the role does
- Installs
zabbix-server-pgsql,zabbix-sql-scripts,postgresql-clientandfping. When the installed major version differs fromzabbix_major_versionthe packages are upgraded to the latest version. - Imports
server.sql.gz(and the TimescaleDBschema.sqlwhen enabled), only into a database without adbversiontable. An existing schema is never touched. - Writes
/etc/zabbix/zabbix_server.conf(mode 0640, ownerroot:zabbix), which contains the database password. - Enables and starts the
zabbix-serverservice, restarting it when configuration changes.
The server listens on TCP 10051. Poller counts and caches are fixed in the template.
Tags
If you call the role without tags, it will execute all of the stages below.
| Tags | Purpose |
|---|---|
| zabbix_server_install | Only manage Zabbix Server install |
| zabbix_server_schema | Only manage the database schema |
| zabbix_server_config | Only manage Zabbix Server config |
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq,
postgresql and zabbix_server roles, then executes them on all hosts.