summaryrefslogtreecommitdiffstats
path: root/roles
AgeCommit message (Collapse)AuthorFilesLines
2025-09-15Add prometheus role (with node exporter)Ahmed Abdelhalim6-0/+126
2025-09-15Fix uv idempotent install for the tool versionsAhmed Abdelhalim1-8/+38
2025-09-15Fix idempotent testing for python roleAhmed Abdelhalim1-1/+1
2025-09-15Refactor python and ansible roles to use uv package managerAhmed Abdelhalim7-138/+30
2025-09-15Refactor go role to simplify version managementAhmed Abdelhalim3-64/+23
2025-09-15Update network role to remove dhcpcd dependencyAhmed Abdelhalim6-6/+15
Fix install on ubuntu not having networking service stated by default on ubuntu
2025-09-14Fix linting issues in nginx roleAhmed Abdelhalim1-5/+5
2025-09-14Fix wireguard stopping vpn when it's not necessaryAhmed Abdelhalim1-1/+1
It's only necessary to stop the VPN to set another one running instead (as the configurations are not built to stack VPN although possible)
2025-09-14Put back the idempotent ignore testAhmed Abdelhalim2-0/+4
The idempotent test is only failing on the second run, the reason is, on the first run the wireguard files are created with default permissions, then the wg_portal role update the ACL. On the second run, the wireguard role recognizes the difference in the permissions, and update the files (expectedly), the default ACL then takes place and set the permissions correctly with ACLs On any successive run, the role is idempotent and doesn't update the files again.
2025-09-14nginx serves .local domain over http otherwise redirects http to httpsAhmed Abdelhalim1-0/+12
2025-09-13Remove the idempotence ignore test in wireguardAhmed Abdelhalim1-2/+0
Since the ACL fix probably fixed this one too
2025-09-13Add pihole port configurations and integration with nginxAhmed Abdelhalim4-0/+43
2025-09-13Add wg_portal nginx integration (enabled by flag, default false)Ahmed Abdelhalim4-0/+37
2025-09-13Add nginx roleAhmed Abdelhalim8-0/+250
2025-09-13Add logrotate role (dependency for nginx)Ahmed Abdelhalim3-0/+30
2025-09-13Add openssl role (dependency for nginx)Ahmed Abdelhalim3-0/+30
2025-09-12Fix idempotence for wg-portal roleAhmed Abdelhalim1-9/+2
Delegate the /etc/wireguard directory creation to the package, this way, if later the wg-portal role was to be installed and update that directory ACL, it won't fail idempotent test. Ignore the wireguard configuration creation, for some reason the usage of dictionary is not preventing the detection of when items change!
2025-09-12Fix the testing of gateway role in containers/CIAhmed Abdelhalim2-2/+3
2025-09-12Fix testing ansible role on 2.19.2Ahmed Abdelhalim1-1/+1
The issue is that regex_match either returns a string or none which was implicitly converted to a boolean, this breaks on 2.19.2+ This ensure compatibility with newer versions.
2025-09-12Fix looping over wireguard connection dictAhmed Abdelhalim1-1/+1
2025-09-12Fix linting issuesAhmed Abdelhalim1-1/+1
2025-09-12Implement the gateway role (replacing old wireguard-gateway)Ahmed Abdelhalim11-0/+364
2025-09-11Fix the wg-portal role to be idempotent and withstand install/uninsallAhmed Abdelhalim1-5/+42
2025-09-10Refactor site playbooks to be more host orientedAhmed Abdelhalim3-0/+32
This also improves the dependency management, making the roles less repeating when not needing to execute multiple times
2025-09-10Add recommended argument_specsAhmed Abdelhalim23-3/+91
2025-09-10Follow the ansible recommendation of using systemd_serviceAhmed Abdelhalim7-14/+14
2025-09-10Remove wireguard_gatewayAhmed Abdelhalim6-233/+0
This implementation doesn't work properly after testing. The iptable configuration didn't allow for changing the VPN state without running into networking issues. Either have to change the VPN by running the role, which is inconvenient or reimplement the role differently to allow for control over network/interfaces
2025-09-10Refactor role dependencies to be more module modularAhmed Abdelhalim22-49/+157
This modularity means that each role can be installed in a playbook by itself as long as the other roles exist around it. This also straps the ensure dependency packages exist in any of the roles tasks, they should be moved to their own roles and configured properly if needed.
2025-09-10Add wg_portal role to install vpn web interface managerAhmed Abdelhalim4-0/+70
2025-09-10Fix password policy on debian don't have gnome installed by defaultAhmed Abdelhalim1-0/+2
2025-09-09Remove old pihole 5 related pathsAhmed Abdelhalim1-3/+0
2025-09-04[skip-ci] fix typo in notesAhmed Abdelhalim1-2/+2
2025-09-04Skip idempotence test because the ipv6 default isn't set on CIAhmed Abdelhalim1-10/+6
2025-09-04Fix CIAhmed Abdelhalim7-3/+29
2025-09-04Refactor molecule testing to run a scenario per distro and fix ipv6Ahmed Abdelhalim1-0/+3
2025-09-03Fix archlinux failureAhmed Abdelhalim1-0/+1
The root causes why the idempotence test to fail is that Docker bridge creation sends netlink events to socket Socket activation starts systemd-networkd.service despite disabled state Idempotence test finds service running when expecting stopped
2025-09-03Add ansible roleAhmed Abdelhalim6-0/+221
2025-09-03Revert "Fix networking issue"Ahmed Abdelhalim1-24/+0
This reverts commit 06e686bc12ee10697431f056efbaecdcba1681d2.
2025-09-03Revert "Refactor: rename wireguard_gateway to gateway"Ahmed Abdelhalim7-22/+22
This reverts commit fdd0b5b58f0ebd39ad05e2dcb17faa6603145f97.
2025-09-03Revert "Experimental: adding iptables persistence through reboots"Ahmed Abdelhalim2-48/+1
This reverts commit 025abf3ce9497f51d21b14aa31907c0c3bd75ecf.
2025-09-03Experimental: adding iptables persistence through rebootsAhmed Abdelhalim2-1/+48
2025-09-03Refactor: rename wireguard_gateway to gatewayAhmed Abdelhalim7-22/+22
As the role now functions as a gateway and not just a wireguard gateway it's better name for clarity
2025-09-03Fix networking issueAhmed Abdelhalim1-0/+24
This allows forwarding the traffic through the pi (similar to how the VPN is routing all the traffic using it's iptables) This means that the role is more of a general gateway When the vpn is activated it handles routing all the traffic through it This commits provide the same functionality when the VPN isn't active
2025-09-03Add podman role with configuration to work over ssh with cgroupfsAhmed Abdelhalim2-0/+66
2025-09-03Fix the user groups to be appendedAhmed Abdelhalim1-1/+1
It's more modular and each role can manage its own group memberships
2025-09-03Revert back to using brew module as it has better idempotency handlingAhmed Abdelhalim2-24/+23
2025-09-03Add docker roleAhmed Abdelhalim2-0/+38
2025-09-02Revert the pyenv full path changeAhmed Abdelhalim1-4/+12
It should be cosmetic, but apparently failing on debian
2025-09-02Add bash as a role and use it in role dependencies when bash is neededAhmed Abdelhalim8-15/+32
2025-09-02Fix CI failures and ignore intentionally changing tasks for idem testAhmed Abdelhalim3-2/+27