The previous role was netbox-community/netbox-docker (compose-based) but the live host runs the upstream tarball install directly: system Postgres 17, system Redis 8, gunicorn under systemd, and Caddy reverse-proxy. Re-running the old role would have torn the working install down. This rewrite mirrors what's actually deployed: - defaults: NetBox 4.6.0, /opt/netbox layout, gunicorn 5w/3t/120s, all configuration.py knobs exposed as ansible vars. - tasks: install OS deps, ensure netbox user, create Postgres role + db, download + extract release tarball, run upgrade.sh, render configuration.py / gunicorn.py / systemd units, enable services. - templates: configuration.py.j2 covers the same keys the live file sets; netbox.service / netbox-rq.service are byte-equivalent to the live units (modulo paths driven by the install-dir var). - caddy role gets a per-host Caddyfile-netbox.vntx.net.j2 mirroring the live vhost (25MB body limit, /static/* file_server, reverse_proxy to 127.0.0.1:8001). - inventory: new netbox_servers group; netbox.vntx.net added to caddy_servers so the per-host Caddyfile is wired up. - host_vars/netbox.vntx.net.yml: secrets reference vault_* vars; role refuses to render config.py until they're set. Operator action: create host_vars/netbox.vntx.net/vault.yml with netbox_secret_key, netbox_db_password, and netbox_api_token_peppers (value visible via `sudo cat /opt/netbox/netbox/netbox/configuration.py` on the live host). See roles/netbox/README.md.
21 lines
724 B
Django/Jinja
21 lines
724 B
Django/Jinja
{{ netbox_caddy_domain | default(inventory_hostname) }} {
|
|
# Set max request body size
|
|
request_body {
|
|
max_size {{ netbox_caddy_max_body_size | default('25MB') }}
|
|
}
|
|
|
|
# Serve static files
|
|
handle /static/* {
|
|
root * {{ netbox_install_dir | default('/opt/netbox') }}/netbox
|
|
file_server
|
|
}
|
|
|
|
# Proxy to Gunicorn backend
|
|
handle {
|
|
reverse_proxy {{ netbox_listen_addr | default('127.0.0.1:8001') }} {
|
|
header_up X-Forwarded-Host {host}
|
|
header_up X-Real-IP {remote_host}
|
|
header_up X-Forwarded-Proto {scheme}
|
|
}
|
|
}
|
|
}
|