infra/ansible/README.md
2026-06-22 16:17:33 -05:00

3.1 KiB
Executable file

Ansible Infrastructure Management

This repository contains Ansible playbooks and roles for managing infrastructure across multiple environments.

Directory Structure

├── playbook.yml          # Main playbook (common, firewall, DNS, monitoring, etc.)
├── bootstrap.yml         # Bootstrap playbook for new hosts
├── netbox.yml            # Standalone NetBox deployment playbook
├── hosts                 # Inventory file
├── ansible.cfg           # Ansible configuration
├── requirements.yml      # Collection and role dependencies
├── group_vars/           # Group-specific variables
│   ├── all/              # Global variables
│   └── bind9_servers/    # BIND9 zone configurations
├── host_vars/            # Host-specific variables
├── vars/                 # Legacy base variables
├── roles/                # Ansible roles (26 roles)
│   ├── base/             # Base configuration (users, SSH, system)
│   ├── general/          # General system configurations
│   ├── caddy/            # Caddy web server
│   ├── firewall/         # UFW/firewalld management
│   ├── ns/               # BIND9 nameserver
│   ├── tailscale/        # Tailscale VPN
│   ├── monitor/          # Icinga2 monitoring
│   ├── prometheus/       # Prometheus monitoring stack
│   └── ...               # Other roles (see playbook.yml for all)
├── baseline/             # Proxmox baseline configuration
├── fact_cache/           # Ansible fact cache (gitignored)
└── findings.md           # Audit findings and recommendations

## Quick Start

### Bootstrap a new host
```bash
# For hosts with existing user access
make bootstrap-init HOSTNAME=hostname ANSIBLE_HOST=ip_address

# Full bootstrap with network config and reboot
make bootstrap HOSTNAME=hostname ANSIBLE_HOST=ip_address

Run playbooks

# Run main playbook
./run.sh

# Run on specific host
ansible-playbook -l hostname playbook.yml

# Run with specific tags
ansible-playbook -t caddy playbook.yml

Inventory Groups

  • vntx_servers - VNTX network services (logs, radius, vpn, netbox, unimus, monitor, librenms, uisp)
  • home_servers - Home network services (skippy, mail, dokku, aprs, staging, prom)
  • bind9_servers - BIND9 authoritative nameservers
  • caddy_servers - Servers running Caddy web server
  • monitoring_servers - Icinga2 monitoring master
  • prometheus_servers - Prometheus monitoring stack
  • postgresql_servers - PostgreSQL database servers
  • proxmox_servers - Proxmox virtualization hosts

See hosts file for the full inventory.

Key Features

  • Automated user management with GitHub SSH key integration
  • Base package installation across all systems
  • Role-based configuration management
  • Support for multiple OS families (Debian, Ubuntu, AlmaLinux)
  • Tailscale VPN integration
  • Caddy web server with automatic SSL
  • BIND9 authoritative DNS with DNSSEC
  • Icinga2 monitoring with PagerDuty integration
  • Prometheus/Grafana/Loki monitoring stack
  • NetBox IPAM/DCIM
  • Proxmox VM provisioning
  • LibreNMS network monitoring