- Jinja 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| templates/zabbix | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Zabbix Web
This role installs and configures the Zabbix web frontend (nginx, PHP-FPM) with a PostgreSQL backend.
Requirements
| Operating System | Version |
|---|---|
| Debian | 13 and newer |
The Zabbix database must already exist and be reachable, for example created by the zabbix_server role.
Dependencies
The role zabbix_prereq must run first. It installs the Zabbix package repository. The included playbook.yaml
does this for you.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
| zabbix_major_version | No | "7.4" |
Zabbix major version to install (upgrades on mismatch) |
| zabbix_web_name | No | "Siempie Monitoring" |
Name shown in the frontend ($ZBX_SERVER_NAME) |
| zabbix_web_php_version | No | "8.4" |
PHP version, selects the php<version>-fpm service |
| zabbix_server_db_host | No | "localhost" |
Database host |
| zabbix_server_db_port | No | "5432" |
Database port |
| zabbix_server_db_name | No | "zabbix" |
Database name |
| zabbix_server_db_user | No | "zabbix" |
Database user |
| zabbix_server_db_pass | Yes | Database password (the role fails when it is empty) |
zabbix_web_php_version must match the PHP version that Debian installs with zabbix-frontend-php. The database
password is a secret and belongs in sops-encrypted inventory variables.
Example
zabbix_web_name: "Zabbix Monitoring"
zabbix_server_db_name: "zabbix"
zabbix_server_db_user: "zabbix"
zabbix_server_db_pass: "replace-with-sops-encrypted-password"
What the role does
- Installs
zabbix-frontend-php,zabbix-nginx-confandphp-pgsql. When the installed major version differs fromzabbix_major_versionthe packages are upgraded to the latest version. - Writes
/etc/zabbix/web/zabbix.conf.php(mode 0600, ownerwww-data) with the database settings. Database TLS is disabled. - Enables and starts
nginxandphp<zabbix_web_php_version>-fpm, restarting them after a package change.
The nginx virtual host is the one shipped by the zabbix-nginx-conf package; this role does not change it.
Tags
If you call the role without tags, it will execute all of the stages below.
| Tags | Purpose |
|---|---|
| zabbix_web_install | Only manage Zabbix Web install |
| zabbix_web_config | Only manage Zabbix Web config |
Usage
Run the role through Semaphore using playbook.yaml. The playbook first runs
ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zabbix_prereq and
zabbix_web roles, then executes both on all hosts.