David Kilias
fa7f16f814
- resolves https://redmine.n39.eu/issues/722 - role https://github.com/jnv/ansible-role-unattended-upgrades is deprecated - replacement is https://github.com/hifis-net/ansible-role-unattended-upgrades
38 lines
844 B
YAML
38 lines
844 B
YAML
---
|
|
# tasks for all hosts
|
|
|
|
- hosts: all
|
|
become: true
|
|
|
|
vars:
|
|
ansible_python_interpreter: /usr/bin/python3
|
|
|
|
roles:
|
|
- role: ansible.timezone
|
|
|
|
tasks:
|
|
- name: Update and clean package cache
|
|
apt:
|
|
update_cache: true
|
|
cache_valid_time: 3600
|
|
autoclean: true
|
|
changed_when: false
|
|
|
|
- name: Ensure unattended-upgrades is installed and up to date
|
|
apt:
|
|
name: unattended-upgrades
|
|
state: present
|
|
|
|
- name: Setup unattended-upgrades
|
|
include_role:
|
|
name: hifis.unattended-upgrades
|
|
vars:
|
|
unattended_origins_patterns:
|
|
- "origin=Debian,archive=buster-security"
|
|
- "o=Debian,a=buster-updates"
|
|
unattended_package_blacklist: [cowsay]
|
|
unattended_mail: "root"
|
|
|
|
- name: Setup users
|
|
include_role:
|
|
name: users
|