| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2025-11-26 | Add firefox user.js preference as a code | Ahmed AbdelHalim | 5 | -8/+106 | |
| And fix the role ideompotent testing | |||||
| 2025-11-25 | Fix the testing of passff (requires pass to be installed) | Ahmed AbdelHalim | 7 | -5/+22 | |
| Update the firefox role dependencies and added notes about using passff and it's required dependencies | |||||
| 2025-11-25 | Rename the firefox created profile to ansible-profile to avoid conflict | Ahmed AbdelHalim | 1 | -2/+2 | |
| To avoid potential conflict when a user already have a profile named and configured for them, it's simpler to use a defined ansible profile that also indicates that the profile is automated | |||||
| 2025-11-25 | Fix role to use ansible_user_id special variable instead of USER env | Ahmed AbdelHalim | 1 | -2/+2 | |
| The USER env is failing on CI, so reverting back to using ansible_user_id special variable, the ansible_user also failed as the CI doesn't have ssh connection (at least not during the tests, and therefore the ansible_user is undefined) | |||||
| 2025-11-24 | Add initial firefox role implementation with only GNOME support for pass | Ahmed AbdelHalim | 15 | -0/+456 | |
| 2025-11-24 | Add the sed role dependency for completeness | Ahmed AbdelHalim | 4 | -0/+31 | |
| 2025-11-19 | Update docs about the usage of gateway-init service | Ahmed AbdelHalim | 1 | -0/+4 | |
| 2025-11-19 | Fix gateway direct-mode not triggering on VPN disconnect | Ahmed AbdelHalim | 1 | -1/+1 | |
| The gateway-direct-mode.service was never triggering when WireGuard interfaces were removed, leaving VPN iptables rules active even when VPN was disconnected. This caused internet connectivity to fail in direct mode. Root cause: SYSTEMD_WANTS in udev rules only works for ACTION=="add" events. When a device is removed, the device unit is already gone before systemd can process the SYSTEMD_WANTS dependency, so the service never starts. This is a documented systemd limitation. Fix: Replace SYSTEMD_WANTS with RUN+ for the remove action, which executes systemctl directly during udev event processing without requiring a device unit to exist. References: - https://stackoverflow.com/questions/72208534/why-does-systemd-wants-not-pass-a-parameter-to-a-service-file-from-a-udev-remov - https://stackoverflow.com/questions/73148448/how-to-start-systemd-user-service-when-device-is-removed-and-stop-it-when-devic - https://bugzilla.redhat.com/show_bug.cgi?id=871074https://bugzilla.redhat.com/show_bug.cgi?id=871074 - https://unix.stackexchange.com/questions/528803/systemd-doesnt-stop-the-service-when-the-device-is-removed The VPN mode (ACTION=="add") continues to use SYSTEMD_WANTS as it works correctly for device addition events. | |||||
| 2025-11-14 | Fix example config, and ignore rpi idempotent test failure | Ahmed AbdelHalim | 2 | -1/+7 | |
| The reason the idempotent test fails is the following: - 1st run: wireguard role deploys all the configured VPN connections - 1st run: wg_portal updates the file permissions /etc/wireguard (ACLs) - 2nd run: wireguard sees the file changed, deploys again (idempotent failure) | |||||
| 2025-11-13 | Minor fixes to autostart connection validation/service logic | Ahmed AbdelHalim | 1 | -6/+15 | |
| 2025-11-13 | Add mechanism to clean up wireguard configurations | Ahmed AbdelHalim | 4 | -10/+34 | |
| When a wireguard configuration gets removed from the group/host variables, the role now removes them and make sure only the files found in the vars are the ones to be configured on the hosts | |||||
| 2025-11-11 | Add neomutt email client role w/testing | Ahmed AbdelHalim | 8 | -0/+37 | |
| 2025-11-11 | Fix dotfile setup of gpg | Ahmed AbdelHalim | 2 | -0/+2 | |
| 2025-11-10 | Add vim role python dependency (as some plugins need python support) | Ahmed AbdelHalim | 1 | -0/+1 | |
| 2025-11-10 | Enable lingering for user | Ahmed AbdelHalim | 1 | -0/+7 | |
| This allows the creation and persisting of the /run/user/UID/ directories required for gpg smart-card forwarding agent. | |||||
| 2025-11-10 | Fix running rpi configuration as root always | Ahmed AbdelHalim | 3 | -1/+10 | |
| The dotfile/vim/password_store required to run as user with root permissions, that's why reverting these changes on rpi and resolving to using a more normal role (in pihole where it was broken) | |||||
| 2025-11-10 | Refactor vimrc to accept custom setup script | Ahmed AbdelHalim | 5 | -10/+15 | |
| 2025-11-09 | Re-enable ipv6 back again | Ahmed AbdelHalim | 3 | -0/+0 | |
| 2025-11-09 | Fix testing by adding a small testing gpg key | Ahmed AbdelHalim | 1 | -5/+7 | |
| 2025-11-09 | Add vim role w/testing | Ahmed AbdelHalim | 10 | -0/+73 | |
| 2025-11-09 | Refactor scattered known_hosts to be part of the ssh role | Ahmed AbdelHalim | 5 | -14/+17 | |
| 2025-11-09 | Add password_store role | Ahmed AbdelHalim | 8 | -0/+67 | |
| 2025-11-09 | Fix install dotfiles script to correct gpg folder permissions | Ahmed AbdelHalim | 2 | -1/+6 | |
| 2025-11-09 | Add gpg public key import to gpg role | Ahmed AbdelHalim | 3 | -1/+24 | |
| 2025-11-09 | Fix git clone by adding ssh keys to known_hosts | Ahmed AbdelHalim | 1 | -0/+7 | |
| 2025-11-09 | Fix clean up forwarded sockets | Ahmed AbdelHalim | 2 | -16/+1 | |
| 2025-11-09 | Disable ipv6 on machines as not all vpns are ipv6 compatible | Ahmed AbdelHalim | 3 | -0/+0 | |
| 2025-11-09 | Update ansible/molecule versions | Ahmed AbdelHalim | 3 | -2/+2 | |
| 2025-11-08 | Fix python role meta data | Ahmed AbdelHalim | 1 | -2/+2 | |
| 2025-11-08 | Update gpg role to include smart gpg keys dependencies | Ahmed AbdelHalim | 2 | -0/+19 | |
| 2025-11-03 | Add dotfiles setup role w/testing | Ahmed AbdelHalim | 13 | -0/+92 | |
| 2025-11-03 | Fix python install not to always report changed | Ahmed AbdelHalim | 1 | -2/+2 | |
| 2025-11-03 | Remove unneeded backup of files in wireguard | Ahmed AbdelHalim | 1 | -1/+0 | |
| 2025-10-24 | Fix removing the packages the breaks ubuntu DNS | Ahmed AbdelHalim | 3 | -13/+35 | |
| This disables install_recommends and revert to using specific gnome packages that are needed/necessary for functioning | |||||
| 2025-10-22 | Refactor naming of packages and services to follow same conventions | Ahmed AbdelHalim | 17 | -24/+24 | |
| 2025-10-22 | Add gpg role w/testing | Ahmed AbdelHalim | 10 | -0/+48 | |
| 2025-10-20 | Ignore failing idempotence test for get_url with note in code | Ahmed AbdelHalim | 1 | -0/+10 | |
| 2025-10-20 | Implement a better download/install for python, pihole and go role | Ahmed AbdelHalim | 3 | -1/+15 | |
| 2025-10-20 | Fix archlinux setup | Ahmed AbdelHalim | 1 | -0/+11 | |
| 2025-10-20 | Fix testing to install galaxy collections | Ahmed AbdelHalim | 5 | -2/+6 | |
| 2025-10-20 | Pin the python and packages versions | Ahmed AbdelHalim | 1 | -4/+4 | |
| 2025-10-20 | Fix molecule testing after refactoring python/go | Ahmed AbdelHalim | 3 | -0/+6 | |
| 2025-10-20 | Add weekly scheduled test run | Ahmed AbdelHalim | 1 | -1/+5 | |
| 2025-10-20 | Add more vpn configuration | Ahmed AbdelHalim | 1 | -0/+0 | |
| 2025-10-20 | Reorder role execution | Ahmed AbdelHalim | 1 | -2/+2 | |
| 2025-10-20 | Refactor python role to remove homebrew dependency | Ahmed AbdelHalim | 5 | -38/+20 | |
| 2025-10-20 | Refactor go role to install 1 version and remove homebrew dependency | Ahmed AbdelHalim | 4 | -35/+36 | |
| 2025-10-20 | Remove homebrew for linux as it's not that useful | Ahmed AbdelHalim | 8 | -82/+0 | |
| The roles sometimes fail to install, and on linux it cannot be used with casks which is defeating the purpose of having it to manage apps and packages | |||||
| 2025-09-23 | Remove SSL directory management from nginx | Ahmed AbdelHalim | 1 | -10/+0 | |
| Let the linux distros manage the ssl directories and it's permissions instead of introducing complex logic to match the original created permissions by the distro install | |||||
| 2025-09-23 | Update the test scenario removing the unused stps | Ahmed AbdelHalim | 4 | -0/+36 | |
