summaryrefslogtreecommitdiffstats
path: root/roles
AgeCommit message (Collapse)AuthorFilesLines
2025-11-26Replace the package_cache role with pre-task since it wasn't reusedAhmed Abdelhalim3-32/+0
It was expected to have the package_cache role reused or added as dependency for other roles, but it turned out it's not used that way, therefore removing it to a more simpler approach
2025-11-26Revert adding user.js configAhmed Abdelhalim4-100/+2
Since the configs were mainly to control UI pref (which is not usable with user.js, as it will always override manual customization) The rest of the features provided by user.js isn't necessary and are already covered by policies. So for now, I'm removing this user.js integration, maybe revisit it later if it's proven to be useful, ATM, it complicates and brittles the setup without providing any additional value.
2025-11-26Fix firefox installation on debian (not using snaps)Ahmed Abdelhalim3-3/+10
2025-11-26Add firefox user.js preference as a codeAhmed Abdelhalim5-8/+106
And fix the role ideompotent testing
2025-11-25Fix the testing of passff (requires pass to be installed)Ahmed Abdelhalim3-5/+14
Update the firefox role dependencies and added notes about using passff and it's required dependencies
2025-11-25Rename the firefox created profile to ansible-profile to avoid conflictAhmed Abdelhalim1-2/+2
To avoid potential conflict when a user already have a profile named and configured for them, it's simpler to use a defined ansible profile that also indicates that the profile is automated
2025-11-25Fix role to use ansible_user_id special variable instead of USER envAhmed Abdelhalim1-2/+2
The USER env is failing on CI, so reverting back to using ansible_user_id special variable, the ansible_user also failed as the CI doesn't have ssh connection (at least not during the tests, and therefore the ansible_user is undefined)
2025-11-24Add initial firefox role implementation with only GNOME support for passAhmed Abdelhalim8-0/+431
2025-11-24Add the sed role dependency for completenessAhmed Abdelhalim4-0/+31
2025-11-19Update docs about the usage of gateway-init serviceAhmed Abdelhalim1-0/+4
2025-11-19Fix gateway direct-mode not triggering on VPN disconnectAhmed Abdelhalim1-1/+1
The gateway-direct-mode.service was never triggering when WireGuard interfaces were removed, leaving VPN iptables rules active even when VPN was disconnected. This caused internet connectivity to fail in direct mode. Root cause: SYSTEMD_WANTS in udev rules only works for ACTION=="add" events. When a device is removed, the device unit is already gone before systemd can process the SYSTEMD_WANTS dependency, so the service never starts. This is a documented systemd limitation. Fix: Replace SYSTEMD_WANTS with RUN+ for the remove action, which executes systemctl directly during udev event processing without requiring a device unit to exist. References: - https://stackoverflow.com/questions/72208534/why-does-systemd-wants-not-pass-a-parameter-to-a-service-file-from-a-udev-remov - https://stackoverflow.com/questions/73148448/how-to-start-systemd-user-service-when-device-is-removed-and-stop-it-when-devic - https://bugzilla.redhat.com/show_bug.cgi?id=871074https://bugzilla.redhat.com/show_bug.cgi?id=871074 - https://unix.stackexchange.com/questions/528803/systemd-doesnt-stop-the-service-when-the-device-is-removed The VPN mode (ACTION=="add") continues to use SYSTEMD_WANTS as it works correctly for device addition events.
2025-11-14Fix example config, and ignore rpi idempotent test failureAhmed Abdelhalim1-0/+6
The reason the idempotent test fails is the following: - 1st run: wireguard role deploys all the configured VPN connections - 1st run: wg_portal updates the file permissions /etc/wireguard (ACLs) - 2nd run: wireguard sees the file changed, deploys again (idempotent failure)
2025-11-13Minor fixes to autostart connection validation/service logicAhmed Abdelhalim1-6/+15
2025-11-13Add mechanism to clean up wireguard configurationsAhmed Abdelhalim1-7/+27
When a wireguard configuration gets removed from the group/host variables, the role now removes them and make sure only the files found in the vars are the ones to be configured on the hosts
2025-11-11Add neomutt email client role w/testingAhmed Abdelhalim3-0/+30
2025-11-10Add vim role python dependency (as some plugins need python support)Ahmed Abdelhalim1-0/+1
2025-11-10Enable lingering for userAhmed Abdelhalim1-0/+7
This allows the creation and persisting of the /run/user/UID/ directories required for gpg smart-card forwarding agent.
2025-11-10Fix running rpi configuration as root alwaysAhmed Abdelhalim2-0/+10
The dotfile/vim/password_store required to run as user with root permissions, that's why reverting these changes on rpi and resolving to using a more normal role (in pihole where it was broken)
2025-11-10Refactor vimrc to accept custom setup scriptAhmed Abdelhalim3-10/+12
2025-11-09Add vim role w/testingAhmed Abdelhalim3-0/+61
2025-11-09Refactor scattered known_hosts to be part of the ssh roleAhmed Abdelhalim5-14/+17
2025-11-09Add password_store roleAhmed Abdelhalim5-0/+62
2025-11-09Add gpg public key import to gpg roleAhmed Abdelhalim2-1/+18
2025-11-09Fix git clone by adding ssh keys to known_hostsAhmed Abdelhalim1-0/+7
2025-11-09Fix clean up forwarded socketsAhmed Abdelhalim2-16/+1
2025-11-09Update ansible/molecule versionsAhmed Abdelhalim1-2/+2
2025-11-08Fix python role meta dataAhmed Abdelhalim1-2/+2
2025-11-08Update gpg role to include smart gpg keys dependenciesAhmed Abdelhalim2-0/+19
2025-11-03Add dotfiles setup role w/testingAhmed Abdelhalim6-0/+79
2025-11-03Fix python install not to always report changedAhmed Abdelhalim1-2/+2
2025-11-03Remove unneeded backup of files in wireguardAhmed Abdelhalim1-1/+0
2025-10-24Fix removing the packages the breaks ubuntu DNSAhmed Abdelhalim3-13/+35
This disables install_recommends and revert to using specific gnome packages that are needed/necessary for functioning
2025-10-22Refactor naming of packages and services to follow same conventionsAhmed Abdelhalim17-24/+24
2025-10-22Add gpg role w/testingAhmed Abdelhalim5-0/+41
2025-10-20Ignore failing idempotence test for get_url with note in codeAhmed Abdelhalim1-0/+10
2025-10-20Implement a better download/install for python, pihole and go roleAhmed Abdelhalim3-1/+15
2025-10-20Fix archlinux setupAhmed Abdelhalim1-0/+11
2025-10-20Refactor python role to remove homebrew dependencyAhmed Abdelhalim4-38/+16
2025-10-20Refactor go role to install 1 version and remove homebrew dependencyAhmed Abdelhalim4-35/+36
2025-10-20Remove homebrew for linux as it's not that usefulAhmed Abdelhalim4-77/+0
The roles sometimes fail to install, and on linux it cannot be used with casks which is defeating the purpose of having it to manage apps and packages
2025-09-23Remove SSL directory management from nginxAhmed Abdelhalim1-10/+0
Let the linux distros manage the ssl directories and it's permissions instead of introducing complex logic to match the original created permissions by the distro install
2025-09-23Fix installing gnome on debianAhmed Abdelhalim3-3/+9
2025-09-23Use static values for defaults instead of ansible varsAhmed Abdelhalim5-10/+15
The ansible vars fail on CI because the validate arguments task runs way before the setting of the variables, which causes the ansible undefined vars on CI to cause errors. This is a way better approach of having the static values as defaults and allowing setting the variables to ansible vars in the host/group vars
2025-09-23Update debian gnome packages for better experienceAhmed Abdelhalim1-1/+3
2025-09-23Fix gnome role idempotency testAhmed Abdelhalim4-15/+14
Gnome installs avahi-daemon, and keeps reinstalling it Remove the ubuntu specific tasks and install the packages with recommendations (as we are removing the avahi-daemon afterwords to make the network manager stable and idempotent)
2025-09-22Add simple rsync role used to sync between hostsAhmed Abdelhalim3-0/+30
2025-09-22Refactor gnome not to pull unnecessary deps (like avahi)Ahmed Abdelhalim4-4/+17
The recommended debian/ubuntu install of gnome pulls avahi-daemon and that could potentially conflicts with NetworkManager. Therefore resorting to more restrictive approach for installing gnome
2025-09-22Attempt fixing avahi test by pinning versionsAhmed Abdelhalim1-8/+0
2025-09-22Linting: update the code to use latest sytnax recommendationAhmed Abdelhalim3-4/+4
2025-09-22Ignore gnome debian package install idempotency failureAhmed Abdelhalim1-0/+2
It seems that the gnome packages are complicated and might have postinst scripts that causes the system state to change/correct... For this, we just ignore it from the idempotent test