Ansible role for installing and configuring Zot
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet 70d1305be2
All checks were successful
ci/woodpecker/push/linting Pipeline was successful
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:28:33 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:52:18 +00:00
defaults chore(package): update dependency project-zot/zot to v2.1.21 2026-09-07 05:50:08 +00:00
handlers feat: add handler 2026-05-08 09:12:17 +02:00
meta feat: initial commit 2026-05-08 08:34:04 +02:00
roles fix: update requirements to forgejo repo locations 2026-05-15 13:51:10 +02:00
tasks chore: use ansible_facts 2026-05-19 09:04:26 +02:00
templates/zot feat: added lscr alias 2026-07-13 16:21:42 +02:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:24:06 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:24:13 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:24:13 +02:00
.gitignore feat: initial commit 2026-05-08 08:34:04 +02:00
.markdownlint-cli2.jsonc style: ignore line length for markdown tables 2026-05-15 13:44:03 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:02:12 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:50 +02:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:16 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:34 +02:00
readme.md docs: improve readme 2026-10-05 17:28:33 +02:00
renovate.json feat: initial commit 2026-05-08 08:34:04 +02:00

Ansible Role: Zot

Install and configure Zot - an OCI-native container image registry.

Dependencies

None. The binary is downloaded from the GitHub releases of project-zot/zot at version zot_version (zot-linux-amd64), so the host needs access to github.com and must be amd64.

Variables

Variable Required Default Description
zot_version No 2.1.21 Zot release version to install
zot_cve_scanning No false Enable CVE scanning of images
zot_sync_credentials No undefined List of sync registry credentials to avoid rate limits

Each entry of zot_sync_credentials has the keys registry, username and password. The credentials are written to /etc/zot/sync-credentials.json (mode 0600) and are secrets: keep them in sops-encrypted inventory variables.

Example

zot_version: "2.1.21"
zot_cve_scanning: true
zot_sync_credentials:
  - name: "dockerhub"
    registry: "registry-1.docker.io"
    username: "your-dockerhub-username"
    password: "replace-with-sops-encrypted-password"

Configuration

The role deploys Zot with the following defaults:

  • Bind address: 127.0.0.1:5000 (put a reverse proxy in front of it)
  • Storage: /var/lib/zot, with garbage collection (delay 1h, interval 24h)
  • Retention: untagged images and referrers are deleted, tags not pulled within 1440h (60 days) are removed
  • Config: /etc/zot/config.json
  • Binary: /usr/bin/zot
  • Extensions: UI and search enabled; CVE database updates every 24h when zot_cve_scanning is true
  • Sync: on-demand pull-through mirrors for Docker Hub, GHCR, Codeberg, Quay, GitLab and LSCR, under the prefixes /dockerhub, /ghcr, /codeberg, /quay, /gitlab and /lscr
  • Service: systemd unit zot on Debian-family systems (runs as root, memory capped at 1536M)

The binary is only downloaded again when the installed version does not contain zot_version.

Usage

Run the role through Semaphore using playbook.yaml. The playbook first runs ansible-galaxy install -f -r roles/requirements.yml on the controller to fetch the latest zot role, then executes it on all hosts, one host at a time.