summaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)AuthorFilesLines
2025-12-12Add greetd role (dependency of hyprland)Ahmed Abdelhalim4-0/+37
2025-12-12Add uwsm role (dependency of hyprland)Ahmed Abdelhalim3-0/+24
2025-12-12Fix warning in ideompotence testing about pihole_install.stdout missingAhmed Abdelhalim2-4/+5
2025-12-12Fix testing wrong chroot detection for configure playbookAhmed Abdelhalim4-0/+4
Theory is that when running a normal user on a docker container that is running root user, something triggers that gather_facts thinks that ansible is running in a chroot (while in fact it's just running in a container mimicking a real system that has multiple users) This is a side effect of fixing the issue that caused the splitting of the bootstrap/configure testing. While some roles can't run root and needs to run some user and not root, setting that in the test isn't possible (AFAIK) and therefore we just override the variable
2025-12-11Add the nautilus role (dependency of hyprland)Ahmed Abdelhalim4-0/+86
2025-12-11Remove duplicate role testing in raspberry testingAhmed Abdelhalim1-5/+0
2025-12-11Fix the test_group passwordless permission for testingAhmed Abdelhalim8-20/+32
2025-12-11Update the testing to match real scenario (with passwordless test_group)Ahmed Abdelhalim8-0/+20
The passwordless test_group is required to allow switching users without needing to add the password
2025-12-11Restructure the molecule testing to match the playbook structureAhmed Abdelhalim4-23/+69
2025-12-11Add cage on archlinux (dependency of hyprland role)Ahmed Abdelhalim4-0/+25
2025-12-11Add no_logs to semi-sensitive tasks to follow best practicesAhmed Abdelhalim5-0/+5
2025-12-10Add jq CLI to all installsAhmed Abdelhalim8-0/+37
2025-12-09Fix rustup ideompotent exec by removing the default bashrc confAhmed Abdelhalim1-0/+6
2025-12-02Add yay role on arch w/testingAhmed Abdelhalim5-0/+58
2025-12-02Add rust role w/testingAhmed Abdelhalim8-0/+82
2025-12-02Add archlinux ghostty install roleAhmed Abdelhalim4-0/+25
2025-12-02Add alactritty terminal emulator on different distrosAhmed Abdelhalim7-0/+34
2025-12-01Add font configurations in a roleAhmed Abdelhalim13-0/+64
2025-11-30Fix dotfiles_setup_script to be idempotentAhmed Abdelhalim2-0/+1
2025-11-30Fix git log not showing properly on archlinuxAhmed Abdelhalim4-1/+32
2025-11-29Add the minimal role to ensure which util/bin is installed on bootAhmed Abdelhalim8-0/+35
2025-11-27Update archlinux firefox plugins/pass integrationsAhmed Abdelhalim1-0/+0
2025-11-26Replace the package_cache role with pre-task since it wasn't reusedAhmed Abdelhalim4-33/+8
It was expected to have the package_cache role reused or added as dependency for other roles, but it turned out it's not used that way, therefore removing it to a more simpler approach
2025-11-26Revert adding user.js configAhmed Abdelhalim4-100/+2
Since the configs were mainly to control UI pref (which is not usable with user.js, as it will always override manual customization) The rest of the features provided by user.js isn't necessary and are already covered by policies. So for now, I'm removing this user.js integration, maybe revisit it later if it's proven to be useful, ATM, it complicates and brittles the setup without providing any additional value.
2025-11-26Fix firefox installation on debian (not using snaps)Ahmed Abdelhalim3-3/+10
2025-11-26Add firefox user.js preference as a codeAhmed Abdelhalim5-8/+106
And fix the role ideompotent testing
2025-11-25Fix the testing of passff (requires pass to be installed)Ahmed Abdelhalim7-5/+22
Update the firefox role dependencies and added notes about using passff and it's required dependencies
2025-11-25Rename the firefox created profile to ansible-profile to avoid conflictAhmed Abdelhalim1-2/+2
To avoid potential conflict when a user already have a profile named and configured for them, it's simpler to use a defined ansible profile that also indicates that the profile is automated
2025-11-25Fix role to use ansible_user_id special variable instead of USER envAhmed Abdelhalim1-2/+2
The USER env is failing on CI, so reverting back to using ansible_user_id special variable, the ansible_user also failed as the CI doesn't have ssh connection (at least not during the tests, and therefore the ansible_user is undefined)
2025-11-24Add initial firefox role implementation with only GNOME support for passAhmed Abdelhalim15-0/+456
2025-11-24Add the sed role dependency for completenessAhmed Abdelhalim4-0/+31
2025-11-19Update docs about the usage of gateway-init serviceAhmed Abdelhalim1-0/+4
2025-11-19Fix gateway direct-mode not triggering on VPN disconnectAhmed Abdelhalim1-1/+1
The gateway-direct-mode.service was never triggering when WireGuard interfaces were removed, leaving VPN iptables rules active even when VPN was disconnected. This caused internet connectivity to fail in direct mode. Root cause: SYSTEMD_WANTS in udev rules only works for ACTION=="add" events. When a device is removed, the device unit is already gone before systemd can process the SYSTEMD_WANTS dependency, so the service never starts. This is a documented systemd limitation. Fix: Replace SYSTEMD_WANTS with RUN+ for the remove action, which executes systemctl directly during udev event processing without requiring a device unit to exist. References: - https://stackoverflow.com/questions/72208534/why-does-systemd-wants-not-pass-a-parameter-to-a-service-file-from-a-udev-remov - https://stackoverflow.com/questions/73148448/how-to-start-systemd-user-service-when-device-is-removed-and-stop-it-when-devic - https://bugzilla.redhat.com/show_bug.cgi?id=871074https://bugzilla.redhat.com/show_bug.cgi?id=871074 - https://unix.stackexchange.com/questions/528803/systemd-doesnt-stop-the-service-when-the-device-is-removed The VPN mode (ACTION=="add") continues to use SYSTEMD_WANTS as it works correctly for device addition events.
2025-11-14Fix example config, and ignore rpi idempotent test failureAhmed Abdelhalim2-1/+7
The reason the idempotent test fails is the following: - 1st run: wireguard role deploys all the configured VPN connections - 1st run: wg_portal updates the file permissions /etc/wireguard (ACLs) - 2nd run: wireguard sees the file changed, deploys again (idempotent failure)
2025-11-13Minor fixes to autostart connection validation/service logicAhmed Abdelhalim1-6/+15
2025-11-13Add mechanism to clean up wireguard configurationsAhmed Abdelhalim4-10/+34
When a wireguard configuration gets removed from the group/host variables, the role now removes them and make sure only the files found in the vars are the ones to be configured on the hosts
2025-11-11Add neomutt email client role w/testingAhmed Abdelhalim8-0/+37
2025-11-11Fix dotfile setup of gpgAhmed Abdelhalim2-0/+2
2025-11-10Add vim role python dependency (as some plugins need python support)Ahmed Abdelhalim1-0/+1
2025-11-10Enable lingering for userAhmed Abdelhalim1-0/+7
This allows the creation and persisting of the /run/user/UID/ directories required for gpg smart-card forwarding agent.
2025-11-10Fix running rpi configuration as root alwaysAhmed Abdelhalim3-1/+10
The dotfile/vim/password_store required to run as user with root permissions, that's why reverting these changes on rpi and resolving to using a more normal role (in pihole where it was broken)
2025-11-10Refactor vimrc to accept custom setup scriptAhmed Abdelhalim5-10/+15
2025-11-09Re-enable ipv6 back againAhmed Abdelhalim3-0/+0
2025-11-09Fix testing by adding a small testing gpg keyAhmed Abdelhalim1-5/+7
2025-11-09Add vim role w/testingAhmed Abdelhalim10-0/+73
2025-11-09Refactor scattered known_hosts to be part of the ssh roleAhmed Abdelhalim5-14/+17
2025-11-09Add password_store roleAhmed Abdelhalim8-0/+67
2025-11-09Fix install dotfiles script to correct gpg folder permissionsAhmed Abdelhalim2-1/+6
2025-11-09Add gpg public key import to gpg roleAhmed Abdelhalim3-1/+24
2025-11-09Fix git clone by adding ssh keys to known_hostsAhmed Abdelhalim1-0/+7