netz39-infra-ansible/host-tau.yml

199 lines
5.9 KiB
YAML
Raw Permalink Normal View History

2020-12-28 22:53:53 +01:00
---
2020-12-10 22:11:37 +01:00
- hosts: tau.netz39.de
become: true
vars:
ansible_python_interpreter: /usr/bin/python3
data_dir: "/srv/data"
docker_registry_port: 5000 # this is the reg standard port
docker_registry_domain: "docker.netz39.de"
2022-01-20 10:03:24 +01:00
2022-06-25 20:31:20 +02:00
dokuwiki_domain: "wiki.netz39.de"
dokuwiki_port: 9005
# This container is pinned, because there are issues
# with backwards compatibility within the same tag!
dokuwiki_image: bitnami/dokuwiki:20230404@sha256:5869cd296e2afd9d4be196911c471701309cfd08590dfa3a76d56ec25ba2aa39
2022-06-25 20:31:20 +02:00
discord_invite_domain: discord.netz39.de
2020-12-10 22:11:37 +01:00
roles:
# role 'docker_setup' applied through group 'docker_host'
2020-12-28 22:53:53 +01:00
- role: apache
- role: penguineer.dehydrated_cron
2020-12-10 22:11:37 +01:00
tasks:
- name: Setup docker network
docker_network:
name: dockernet
driver: bridge
ipam_config:
- subnet: 192.168.0.0/24
gateway: 192.168.0.1
state: present
2021-03-10 10:54:44 +01:00
- name: Setup Dehydrated
include_role:
name: ansible-role-dehydrated
vars:
dehydrated_contact_email: "{{ server_admin }}"
dehydrated_domains:
- name: "testredmine.netz39.de"
deploy_challenge_hook: "/bin/systemctl restart apache2"
- name: "mysql.adm.netz39.de"
deploy_challenge_hook: "/bin/systemctl restart apache2"
2022-01-20 10:03:24 +01:00
- name: "{{ docker_registry_domain }}"
deploy_challenge_hook: "/bin/systemctl restart apache2"
2022-06-25 20:31:20 +02:00
- name: "{{ dokuwiki_domain }}"
deploy_challenge_hook: "/bin/systemctl restart apache2"
- name: "{{ discord_invite_domain }}"
deploy_challenge_hook: "/bin/systemctl restart apache2"
2021-03-10 10:54:44 +01:00
2020-12-10 22:11:37 +01:00
- name: Setup proxy site testredmine.netz39.de
include_role:
name: setup_http_site_proxy
2020-12-10 22:11:37 +01:00
vars:
site_name: testredmine.netz39.de
proxy_port: 9004
- name: Setup phpmyadmin
docker_container:
name: phpmyadmin
state: started
image: phpmyadmin:5.2
2020-12-10 22:11:37 +01:00
networks_cli_compatible: true
networks:
- name: dockernet
restart_policy: always
env:
TZ: "{{ timezone }}"
2020-12-10 22:11:37 +01:00
PMA_HOST: 192.168.0.1
MYSQL_ROOT_PASSWORD: "{{ mysql_root_pw }}"
PMA_ABSOLUTE_URI: "https://mysql.adm.netz39.de"
published_ports:
- 9001:80
- name: Setup proxy site mysql.adm.netz39.de
include_role:
name: setup_http_site_proxy
2020-12-10 22:11:37 +01:00
vars:
site_name: mysql.adm.netz39.de
proxy_port: 9001
2022-01-20 10:03:24 +01:00
- name: Check if Docker Registry auth dir exists
ansible.builtin.stat:
path: "{{ data_dir }}/registry/auth"
2022-01-20 10:03:24 +01:00
register: docker_dir
- name: Fail if docker registry data dir does not exist
ansible.builtin.fail:
msg: "Docker Registry auth dir is missing, please restore from the backup!"
when: not docker_dir.stat.exists
- name: Ensure the Docker Registry data directory exists
# This may not be part of the backup
file:
path: "{{ data_dir }}/registry/data"
state: directory
mode: "0755"
2022-01-20 10:03:24 +01:00
- name: Setup Docker Registry Container
docker_container:
name: registry
image: registry:2
2022-01-20 10:03:24 +01:00
pull: true
state: started
restart_policy: unless-stopped
detach: yes
ports:
- 127.0.0.1:{{ docker_registry_port }}:{{ docker_registry_port }}
2022-01-20 10:03:24 +01:00
env:
TZ: "{{ timezone }}"
2022-01-20 10:03:24 +01:00
REGISTRY_HTTP_HOST: "https://{{ docker_registry_domain }}"
REGISTRY_AUTH_HTPASSWD_REALM: "Netz39 Docker Registry"
REGISTRY_AUTH_HTPASSWD_PATH: "/auth/htpasswd"
volumes:
- "{{ data_dir }}/registry/data:/var/lib/registry:rw"
- "{{ data_dir }}/registry/auth:/auth:rw"
2022-01-20 10:03:24 +01:00
- name: Setup proxy site for the Docker Registry
include_role:
name: setup_http_site_proxy
2022-01-20 10:03:24 +01:00
vars:
site_name: "{{ docker_registry_domain }}"
proxy_port: "{{ docker_registry_port }}"
2022-06-25 20:31:20 +02:00
- name: Check if Dokuwiki data dir exists
ansible.builtin.stat:
path: "{{ data_dir }}/dokuwiki"
2022-06-25 20:31:20 +02:00
register: dokuwiki_dir
tags:
- dokuwiki
2022-06-25 20:31:20 +02:00
- name: Fail if Dokuwiki data dir does not exist
ansible.builtin.fail:
msg: "Dokuwiki data dir is missing, please restore from the backup!"
when: not dokuwiki_dir.stat.exists
tags:
- dokuwiki
2022-06-25 20:31:20 +02:00
- name: Set correct user for Dokuwiki data
ansible.builtin.file:
path: "{{ data_dir }}/dokuwiki"
2022-06-25 20:31:20 +02:00
owner: "1001" # According to container config
recurse: yes
tags:
- dokuwiki
2022-06-25 20:31:20 +02:00
- name: Setup Dokuwiki Container
docker_container:
name: dokuwiki
image: "{{ dokuwiki_image }}"
pull: true
state: started
restart_policy: unless-stopped
detach: yes
ports:
- 127.0.0.1:{{ dokuwiki_port }}:{{ 8080 }}
2022-06-25 20:31:20 +02:00
# env: No env here, because we copy the data
# and the container will never be created from scratch.
volumes:
- "{{ data_dir }}/dokuwiki:/bitnami/dokuwiki:rw"
env:
TZ: "{{ timezone }}"
tags:
- dokuwiki
2022-06-25 20:31:20 +02:00
- name: Setup proxy site for Dokuwiki
include_role:
name: setup_http_site_proxy
2022-06-25 20:31:20 +02:00
vars:
site_name: "{{ dokuwiki_domain }}"
proxy_port: "{{ dokuwiki_port }}"
tags:
- dokuwiki
- name: Setup container for secondary FFMD DNS
docker_container:
name: bind9-md-freifunk-net
image: ffmd/bind9-md-freifunk-net:v2022122301
pull: true
state: started
restart_policy: unless-stopped
detach: yes
ports:
- "53:53/udp"
env:
TZ: "{{ timezone }}"
2023-08-25 20:03:16 +02:00
tags:
- ffmd-dns
- name: Setup forwarding for Discord invite
include_role:
name: setup-http-site-forward
vars:
site_name: "{{ discord_invite_domain }}"
# forward_to: "https://discord.com/invite/8FcDvAf"
forward_to: "https://sl.n39.eu/discord"