Ansible role to setup a Zabbix Server
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet ec75cd3e37
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:25 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:52:09 +00:00
defaults feat(zabbix-server): import database schema into an empty database 2026-10-01 10:17:02 +02:00
handlers feat: initial commit 2025-06-06 17:53:55 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles feat(zabbix-server): run the postgresql role when the database is local 2026-10-01 12:47:44 +02:00
tasks fix(zabbix-server): run read-only lookups in check mode 2026-10-01 10:23:18 +02:00
templates/zabbix feat(zabbix-server): use pgsql 2026-09-30 10:33:47 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:05 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:11 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:11 +02:00
.gitignore feat: initial commit 2025-06-06 17:53:55 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:44:04 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:11 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:48 +02:00
AGENTS.md feat(zabbix-server): import database schema into an empty database 2026-10-01 10:17:02 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml feat(zabbix-server): run the postgresql role when the database is local 2026-10-01 12:47:44 +02:00
readme.md docs: improve readme 2026-10-05 17:28:25 +02:00
renovate.json fix(ci): use central config 2025-06-17 17:58:38 +02:00

Ansible Role: Zabbix Server

This role installs and configures a Zabbix Server with a PostgreSQL backend (TimescaleDB optional). It imports the Zabbix database schema into an empty database.

Requirements

Operating System Version
Debian 13 and newer

The role does not manage the database itself. You need:

  • A reachable PostgreSQL server (TimescaleDB is optional).
  • A database and user matching zabbix_server_db_name and zabbix_server_db_user (with the timescaledb extension when zabbix_server_db_timescaledb is true).

Dependencies

  • zabbix_prereq: installs the Zabbix package repository.
  • postgresql: provides the database. The included playbook.yaml runs it only when zabbix_server_db_host is localhost or 127.0.0.1. Configure the database and user through its own variables (postgresql_users, postgresql_databases, postgresql_timescaledb_enabled), see the readme of that role.

Variables

Variable Required Default Description
zabbix_major_version No "7.4" Zabbix major version to install (upgrades on mismatch)
zabbix_server_db_host No "localhost" Database host
zabbix_server_db_port No "5432" Database port
zabbix_server_db_name No "zabbix" Database name
zabbix_server_db_user No "zabbix" Database user
zabbix_server_db_pass Yes Database password (the role fails when it is empty)
zabbix_server_db_timescaledb No false Also import the TimescaleDB schema when importing the schema

The database password is a secret and belongs in sops-encrypted inventory variables.

Example

zabbix_server_db_name: "zabbix"
zabbix_server_db_user: "zabbix"
zabbix_server_db_pass: "replace-with-sops-encrypted-password"
zabbix_server_db_timescaledb: true

# settings for the postgresql role (same host)
postgresql_timescaledb_enabled: true
postgresql_users:
  - name: "zabbix"
    password: "replace-with-sops-encrypted-password"
postgresql_databases:
  - name: "zabbix"
    owner: "zabbix"
    extensions:
      - "timescaledb"

What the role does

  • Installs zabbix-server-pgsql, zabbix-sql-scripts, postgresql-client and fping. When the installed major version differs from zabbix_major_version the packages are upgraded to the latest version.
  • Imports server.sql.gz (and the TimescaleDB schema.sql when enabled), only into a database without a dbversion table. An existing schema is never touched.
  • Writes /etc/zabbix/zabbix_server.conf (mode 0640, owner root:zabbix), which contains the database password.
  • Enables and starts the zabbix-server service, restarting it when configuration changes.

The server listens on TCP 10051. Poller counts and caches are fixed in the template.

Tags

If you call the role without tags, it will execute all of the stages below.

Tags Purpose
zabbix_server_install Only manage Zabbix Server install
zabbix_server_schema Only manage the database schema
zabbix_server_config Only manage Zabbix Server config

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq, postgresql and zabbix_server roles, then executes them on all hosts.