Ansible role to setup a Zabbix Web Server
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet dea949c24c
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:25 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:52:13 +00:00
defaults feat: various fixes 2026-09-30 10:34:40 +02:00
handlers feat: various fixes 2026-09-30 10:34:40 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:27 +02:00
roles fix(zabbix-web): install zabbix_prereq role from requirements 2026-10-01 12:42:34 +02:00
tasks fix(zabbix-web): run version lookup in check mode 2026-10-01 10:23:18 +02:00
templates/zabbix feat: various fixes 2026-09-30 10:34:40 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:05 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:12 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:12 +02:00
.gitignore feat: initial commit 2025-06-06 18:23:44 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:44:04 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:12 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:48 +02:00
AGENTS.md feat: various fixes 2026-09-30 10:34:40 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:04 +02:00
readme.md docs: improve readme 2026-10-05 17:28:25 +02:00
renovate.json feat: play with extends 2025-06-17 17:49:43 +02:00

Ansible Role: Zabbix Web

This role installs and configures the Zabbix web frontend (nginx, PHP-FPM) with a PostgreSQL backend.

Requirements

Operating System Version
Debian 13 and newer

The Zabbix database must already exist and be reachable, for example created by the zabbix_server role.

Dependencies

The role zabbix_prereq must run first. It installs the Zabbix package repository. The included playbook.yaml does this for you.

Variables

Variable Required Default Description
zabbix_major_version No "7.4" Zabbix major version to install (upgrades on mismatch)
zabbix_web_name No "Siempie Monitoring" Name shown in the frontend ($ZBX_SERVER_NAME)
zabbix_web_php_version No "8.4" PHP version, selects the php<version>-fpm service
zabbix_server_db_host No "localhost" Database host
zabbix_server_db_port No "5432" Database port
zabbix_server_db_name No "zabbix" Database name
zabbix_server_db_user No "zabbix" Database user
zabbix_server_db_pass Yes Database password (the role fails when it is empty)

zabbix_web_php_version must match the PHP version that Debian installs with zabbix-frontend-php. The database password is a secret and belongs in sops-encrypted inventory variables.

Example

zabbix_web_name: "Zabbix Monitoring"
zabbix_server_db_name: "zabbix"
zabbix_server_db_user: "zabbix"
zabbix_server_db_pass: "replace-with-sops-encrypted-password"

What the role does

  • Installs zabbix-frontend-php, zabbix-nginx-conf and php-pgsql. When the installed major version differs from zabbix_major_version the packages are upgraded to the latest version.
  • Writes /etc/zabbix/web/zabbix.conf.php (mode 0600, owner www-data) with the database settings. Database TLS is disabled.
  • Enables and starts nginx and php<zabbix_web_php_version>-fpm, restarting them after a package change.

The nginx virtual host is the one shipped by the zabbix-nginx-conf package; this role does not change it.

Tags

If you call the role without tags, it will execute all of the stages below.

Tags Purpose
zabbix_web_install Only manage Zabbix Web install
zabbix_web_config Only manage Zabbix Web config

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq and zabbix_web roles, then executes both on all hosts.