summaryrefslogtreecommitdiffstats
path: root/roles
AgeCommit message (Collapse)AuthorFilesLines
2025-09-21Disable connectivity detectionAhmed Abdelhalim1-1/+1
2025-09-20Move gcc to it's own role and add it as homebrew dependencyAhmed Abdelhalim9-20/+40
2025-09-20Fix homebrew role dependencies on ubuntuAhmed Abdelhalim4-1/+33
2025-09-20Fix ansible install on ubuntu when there is another version installedAhmed Abdelhalim1-2/+2
2025-09-20Migrate to the new loop syntaxAhmed Abdelhalim9-17/+17
2025-09-20Ignore failing idempotent test (as it can't be idempotent)Ahmed Abdelhalim1-0/+5
2025-09-20Fix include vars using os_family (not distribution)Ahmed Abdelhalim2-3/+3
2025-09-20Update the prometheus/grafana role varsAhmed Abdelhalim1-19/+1
2025-09-20Fix installing grafana on raspberry piAhmed Abdelhalim4-1/+9
2025-09-19Add Grafana roleAhmed Abdelhalim12-0/+315
2025-09-19Fix env files paths on different distrosAhmed Abdelhalim3-2/+11
2025-09-19Enable systemd monitoring via prometheus node exporterAhmed Abdelhalim1-1/+4
2025-09-18Allow configuring multiple targets for prometheusAhmed Abdelhalim4-4/+21
The default are localhost, but it can be overridden to allow scrapping localhost and or remote hosts (for both prometheus job and node exporter jobs)
2025-09-17Restrict prometheus/node-exporter access to only local networkAhmed Abdelhalim3-4/+9
2025-09-17Clean up argument_specsAhmed Abdelhalim1-7/+3
2025-09-17Fix prometheus/node-exporter starting on configured portAhmed Abdelhalim3-1/+27
2025-09-15Add prometheus role (with node exporter)Ahmed Abdelhalim6-0/+126
2025-09-15Fix uv idempotent install for the tool versionsAhmed Abdelhalim1-8/+38
2025-09-15Fix idempotent testing for python roleAhmed Abdelhalim1-1/+1
2025-09-15Refactor python and ansible roles to use uv package managerAhmed Abdelhalim7-138/+30
2025-09-15Refactor go role to simplify version managementAhmed Abdelhalim3-64/+23
2025-09-15Update network role to remove dhcpcd dependencyAhmed Abdelhalim6-6/+15
Fix install on ubuntu not having networking service stated by default on ubuntu
2025-09-14Fix linting issues in nginx roleAhmed Abdelhalim1-5/+5
2025-09-14Fix wireguard stopping vpn when it's not necessaryAhmed Abdelhalim1-1/+1
It's only necessary to stop the VPN to set another one running instead (as the configurations are not built to stack VPN although possible)
2025-09-14Put back the idempotent ignore testAhmed Abdelhalim2-0/+4
The idempotent test is only failing on the second run, the reason is, on the first run the wireguard files are created with default permissions, then the wg_portal role update the ACL. On the second run, the wireguard role recognizes the difference in the permissions, and update the files (expectedly), the default ACL then takes place and set the permissions correctly with ACLs On any successive run, the role is idempotent and doesn't update the files again.
2025-09-14nginx serves .local domain over http otherwise redirects http to httpsAhmed Abdelhalim1-0/+12
2025-09-13Remove the idempotence ignore test in wireguardAhmed Abdelhalim1-2/+0
Since the ACL fix probably fixed this one too
2025-09-13Add pihole port configurations and integration with nginxAhmed Abdelhalim4-0/+43
2025-09-13Add wg_portal nginx integration (enabled by flag, default false)Ahmed Abdelhalim4-0/+37
2025-09-13Add nginx roleAhmed Abdelhalim8-0/+250
2025-09-13Add logrotate role (dependency for nginx)Ahmed Abdelhalim3-0/+30
2025-09-13Add openssl role (dependency for nginx)Ahmed Abdelhalim3-0/+30
2025-09-12Fix idempotence for wg-portal roleAhmed Abdelhalim1-9/+2
Delegate the /etc/wireguard directory creation to the package, this way, if later the wg-portal role was to be installed and update that directory ACL, it won't fail idempotent test. Ignore the wireguard configuration creation, for some reason the usage of dictionary is not preventing the detection of when items change!
2025-09-12Fix the testing of gateway role in containers/CIAhmed Abdelhalim2-2/+3
2025-09-12Fix testing ansible role on 2.19.2Ahmed Abdelhalim1-1/+1
The issue is that regex_match either returns a string or none which was implicitly converted to a boolean, this breaks on 2.19.2+ This ensure compatibility with newer versions.
2025-09-12Fix looping over wireguard connection dictAhmed Abdelhalim1-1/+1
2025-09-12Fix linting issuesAhmed Abdelhalim1-1/+1
2025-09-12Implement the gateway role (replacing old wireguard-gateway)Ahmed Abdelhalim11-0/+364
2025-09-11Fix the wg-portal role to be idempotent and withstand install/uninsallAhmed Abdelhalim1-5/+42
2025-09-10Refactor site playbooks to be more host orientedAhmed Abdelhalim3-0/+32
This also improves the dependency management, making the roles less repeating when not needing to execute multiple times
2025-09-10Add recommended argument_specsAhmed Abdelhalim23-3/+91
2025-09-10Follow the ansible recommendation of using systemd_serviceAhmed Abdelhalim7-14/+14
2025-09-10Remove wireguard_gatewayAhmed Abdelhalim6-233/+0
This implementation doesn't work properly after testing. The iptable configuration didn't allow for changing the VPN state without running into networking issues. Either have to change the VPN by running the role, which is inconvenient or reimplement the role differently to allow for control over network/interfaces
2025-09-10Refactor role dependencies to be more module modularAhmed Abdelhalim22-49/+157
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-10Add wg_portal role to install vpn web interface managerAhmed Abdelhalim4-0/+70
2025-09-10Fix password policy on debian don't have gnome installed by defaultAhmed Abdelhalim1-0/+2
2025-09-09Remove old pihole 5 related pathsAhmed Abdelhalim1-3/+0
2025-09-04[skip-ci] fix typo in notesAhmed Abdelhalim1-2/+2
2025-09-04Skip idempotence test because the ipv6 default isn't set on CIAhmed Abdelhalim1-10/+6
2025-09-04Fix CIAhmed Abdelhalim7-3/+29