| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2025-12-13 | Fix dotfiles error on debian with missing envsubst | Ahmed Abdelhalim | 6 | -0/+38 | |
| 2025-12-12 | Add initial (basic) hyprland role configurations | Ahmed Abdelhalim | 12 | -0/+385 | |
| 2025-12-12 | Fix the dotfiles setup to be more generic and not requiring sudo | Ahmed Abdelhalim | 2 | -4/+10 | |
| The sude was used to link the pinentry-wrapper into the /usr/local/bin dir | |||||
| 2025-12-12 | Update user role to allow configure a password instead of default | Ahmed Abdelhalim | 5 | -6/+33 | |
| If no user_password is provided, the behavior remains the same, it uses the default changeme password and requires to be changed for using sudo If a user_password is provided, this hashed password will be used instead of the default and doesn't require changing on first usage of sudo | |||||
| 2025-12-12 | Add greetd role (dependency of hyprland) | Ahmed Abdelhalim | 4 | -0/+37 | |
| 2025-12-12 | Add uwsm role (dependency of hyprland) | Ahmed Abdelhalim | 3 | -0/+24 | |
| 2025-12-12 | Fix warning in ideompotence testing about pihole_install.stdout missing | Ahmed Abdelhalim | 2 | -4/+5 | |
| 2025-12-12 | Fix testing wrong chroot detection for configure playbook | Ahmed Abdelhalim | 4 | -0/+4 | |
| Theory is that when running a normal user on a docker container that is running root user, something triggers that gather_facts thinks that ansible is running in a chroot (while in fact it's just running in a container mimicking a real system that has multiple users) This is a side effect of fixing the issue that caused the splitting of the bootstrap/configure testing. While some roles can't run root and needs to run some user and not root, setting that in the test isn't possible (AFAIK) and therefore we just override the variable | |||||
| 2025-12-11 | Add the nautilus role (dependency of hyprland) | Ahmed Abdelhalim | 4 | -0/+86 | |
| 2025-12-11 | Remove duplicate role testing in raspberry testing | Ahmed Abdelhalim | 1 | -5/+0 | |
| 2025-12-11 | Fix the test_group passwordless permission for testing | Ahmed Abdelhalim | 8 | -20/+32 | |
| 2025-12-11 | Update the testing to match real scenario (with passwordless test_group) | Ahmed Abdelhalim | 8 | -0/+20 | |
| The passwordless test_group is required to allow switching users without needing to add the password | |||||
| 2025-12-11 | Restructure the molecule testing to match the playbook structure | Ahmed Abdelhalim | 4 | -23/+69 | |
| 2025-12-11 | Add cage on archlinux (dependency of hyprland role) | Ahmed Abdelhalim | 4 | -0/+25 | |
| 2025-12-11 | Add no_logs to semi-sensitive tasks to follow best practices | Ahmed Abdelhalim | 5 | -0/+5 | |
| 2025-12-10 | Add jq CLI to all installs | Ahmed Abdelhalim | 8 | -0/+37 | |
| 2025-12-09 | Fix rustup ideompotent exec by removing the default bashrc conf | Ahmed Abdelhalim | 1 | -0/+6 | |
| 2025-12-02 | Add yay role on arch w/testing | Ahmed Abdelhalim | 5 | -0/+58 | |
| 2025-12-02 | Add rust role w/testing | Ahmed Abdelhalim | 8 | -0/+82 | |
| 2025-12-02 | Add archlinux ghostty install role | Ahmed Abdelhalim | 4 | -0/+25 | |
| 2025-12-02 | Add alactritty terminal emulator on different distros | Ahmed Abdelhalim | 7 | -0/+34 | |
| 2025-12-01 | Add font configurations in a role | Ahmed Abdelhalim | 13 | -0/+64 | |
| 2025-11-30 | Fix dotfiles_setup_script to be idempotent | Ahmed Abdelhalim | 2 | -0/+1 | |
| 2025-11-30 | Fix git log not showing properly on archlinux | Ahmed Abdelhalim | 4 | -1/+32 | |
| 2025-11-29 | Add the minimal role to ensure which util/bin is installed on boot | Ahmed Abdelhalim | 8 | -0/+35 | |
| 2025-11-27 | Update archlinux firefox plugins/pass integrations | Ahmed Abdelhalim | 1 | -0/+0 | |
| 2025-11-26 | Replace the package_cache role with pre-task since it wasn't reused | Ahmed Abdelhalim | 4 | -33/+8 | |
| It was expected to have the package_cache role reused or added as dependency for other roles, but it turned out it's not used that way, therefore removing it to a more simpler approach | |||||
| 2025-11-26 | Revert adding user.js config | Ahmed Abdelhalim | 4 | -100/+2 | |
| Since the configs were mainly to control UI pref (which is not usable with user.js, as it will always override manual customization) The rest of the features provided by user.js isn't necessary and are already covered by policies. So for now, I'm removing this user.js integration, maybe revisit it later if it's proven to be useful, ATM, it complicates and brittles the setup without providing any additional value. | |||||
| 2025-11-26 | Fix firefox installation on debian (not using snaps) | Ahmed Abdelhalim | 3 | -3/+10 | |
| 2025-11-26 | Add firefox user.js preference as a code | Ahmed Abdelhalim | 5 | -8/+106 | |
| And fix the role ideompotent testing | |||||
| 2025-11-25 | Fix the testing of passff (requires pass to be installed) | Ahmed Abdelhalim | 7 | -5/+22 | |
| Update the firefox role dependencies and added notes about using passff and it's required dependencies | |||||
| 2025-11-25 | Rename the firefox created profile to ansible-profile to avoid conflict | Ahmed Abdelhalim | 1 | -2/+2 | |
| To avoid potential conflict when a user already have a profile named and configured for them, it's simpler to use a defined ansible profile that also indicates that the profile is automated | |||||
| 2025-11-25 | Fix role to use ansible_user_id special variable instead of USER env | Ahmed Abdelhalim | 1 | -2/+2 | |
| The USER env is failing on CI, so reverting back to using ansible_user_id special variable, the ansible_user also failed as the CI doesn't have ssh connection (at least not during the tests, and therefore the ansible_user is undefined) | |||||
| 2025-11-24 | Add initial firefox role implementation with only GNOME support for pass | Ahmed Abdelhalim | 15 | -0/+456 | |
| 2025-11-24 | Add the sed role dependency for completeness | Ahmed Abdelhalim | 4 | -0/+31 | |
| 2025-11-19 | Update docs about the usage of gateway-init service | Ahmed Abdelhalim | 1 | -0/+4 | |
| 2025-11-19 | Fix gateway direct-mode not triggering on VPN disconnect | Ahmed Abdelhalim | 1 | -1/+1 | |
| The gateway-direct-mode.service was never triggering when WireGuard interfaces were removed, leaving VPN iptables rules active even when VPN was disconnected. This caused internet connectivity to fail in direct mode. Root cause: SYSTEMD_WANTS in udev rules only works for ACTION=="add" events. When a device is removed, the device unit is already gone before systemd can process the SYSTEMD_WANTS dependency, so the service never starts. This is a documented systemd limitation. Fix: Replace SYSTEMD_WANTS with RUN+ for the remove action, which executes systemctl directly during udev event processing without requiring a device unit to exist. References: - https://stackoverflow.com/questions/72208534/why-does-systemd-wants-not-pass-a-parameter-to-a-service-file-from-a-udev-remov - https://stackoverflow.com/questions/73148448/how-to-start-systemd-user-service-when-device-is-removed-and-stop-it-when-devic - https://bugzilla.redhat.com/show_bug.cgi?id=871074https://bugzilla.redhat.com/show_bug.cgi?id=871074 - https://unix.stackexchange.com/questions/528803/systemd-doesnt-stop-the-service-when-the-device-is-removed The VPN mode (ACTION=="add") continues to use SYSTEMD_WANTS as it works correctly for device addition events. | |||||
| 2025-11-14 | Fix example config, and ignore rpi idempotent test failure | Ahmed Abdelhalim | 2 | -1/+7 | |
| The reason the idempotent test fails is the following: - 1st run: wireguard role deploys all the configured VPN connections - 1st run: wg_portal updates the file permissions /etc/wireguard (ACLs) - 2nd run: wireguard sees the file changed, deploys again (idempotent failure) | |||||
| 2025-11-13 | Minor fixes to autostart connection validation/service logic | Ahmed Abdelhalim | 1 | -6/+15 | |
| 2025-11-13 | Add mechanism to clean up wireguard configurations | Ahmed Abdelhalim | 4 | -10/+34 | |
| When a wireguard configuration gets removed from the group/host variables, the role now removes them and make sure only the files found in the vars are the ones to be configured on the hosts | |||||
| 2025-11-11 | Add neomutt email client role w/testing | Ahmed Abdelhalim | 8 | -0/+37 | |
| 2025-11-11 | Fix dotfile setup of gpg | Ahmed Abdelhalim | 2 | -0/+2 | |
| 2025-11-10 | Add vim role python dependency (as some plugins need python support) | Ahmed Abdelhalim | 1 | -0/+1 | |
| 2025-11-10 | Enable lingering for user | Ahmed Abdelhalim | 1 | -0/+7 | |
| This allows the creation and persisting of the /run/user/UID/ directories required for gpg smart-card forwarding agent. | |||||
| 2025-11-10 | Fix running rpi configuration as root always | Ahmed Abdelhalim | 3 | -1/+10 | |
| The dotfile/vim/password_store required to run as user with root permissions, that's why reverting these changes on rpi and resolving to using a more normal role (in pihole where it was broken) | |||||
| 2025-11-10 | Refactor vimrc to accept custom setup script | Ahmed Abdelhalim | 5 | -10/+15 | |
| 2025-11-09 | Re-enable ipv6 back again | Ahmed Abdelhalim | 3 | -0/+0 | |
| 2025-11-09 | Fix testing by adding a small testing gpg key | Ahmed Abdelhalim | 1 | -5/+7 | |
| 2025-11-09 | Add vim role w/testing | Ahmed Abdelhalim | 10 | -0/+73 | |
| 2025-11-09 | Refactor scattered known_hosts to be part of the ssh role | Ahmed Abdelhalim | 5 | -14/+17 | |
