summaryrefslogtreecommitdiffstats
path: root/molecule/debian/converge.yml
blob: 4e08cac7569a14aec7bbe58e6214243bc72feffe (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
---
- name: "Bootstrap"
  hosts: "debian"
  gather_facts: true
  environment:
    PATH: "{{ ansible_env.HOME }}/.local/bin:{{ ansible_env.PATH }}"
  vars:
    ansible_become_method: su
    user_public_keys:
      - "ssh-ed25519 AAAA...fMo"
      - "ssh-rsa AAAA...4I3"
    user_groups: ["wheel", "test_group"]
  roles:
    - role: "hostname"
    - role: "network"
    - role: "user"
    - role: "ssh"
    - role: "password_policy"
  tasks:
    - name: "Configure passwordless sudo for testing"
      ansible.builtin.copy:
        content: "%test_group ALL=(ALL) NOPASSWD: ALL\n"
        dest: "/etc/sudoers.d/test_group"
        mode: "0440"
        validate: 'visudo -cf %s'

- name: "Configure"
  hosts: "debian"
  gather_facts: true
  remote_user: "{{ username }}"
  environment:
    PATH: "{{ ansible_env.HOME }}/.local/bin:{{ ansible_env.PATH }}"
  vars:
    ansible_become_method: sudo
    locales:
      - "en_US.UTF-8 UTF-8"
    timezone: "GMT"
    wireguard_autostart_connection: ""
    gateway_enabled: false
    gateway_local_ipv4_subnet: "10.0.0.0/24"
    python_global_version: "3.13"
    python_versions:
      - "3.13"
    prometheus_host: "localhost"
    prometheus_port: 9090
    prometheus_node_exporter_port: 9100
    grafana_port: 3000
    grafana_dashboards:
      - id: 1860
        revision: 37
        name: "node-exporter-full"
        datasource_mappings:
          - key: "000000001"
            value: "prometheus"
    vimrc_repo_url: "https://git.sr.ht/~a14m/.vim"
    password_store_repo_url: "https://github.com/octocat/Spoon-Knife"
    firefox_install_browserpass: true
    firefox_install_passff: true
  pre_tasks:
    - name: "Override is_chroot fact for container environment"
      ansible.builtin.set_fact:
        ansible_facts: "{{ ansible_facts | combine({'is_chroot': false}) }}"
  roles:
    - role: "locales"
    - role: "timezone"
    - role: "bash"
    - role: "man"
    - role: "jq"
    - role: "ag"
    - role: "tmux"
    - role: "wireguard"
    - role: "gateway"
    - role: "python"
    - role: "go"
    - role: "rust"
    - role: "docker"
    - role: "podman"
    - role: "ansible"
    - role: "nginx"
    - role: "prometheus"
    - role: "grafana"
    - role: "gnome"
    - role: "rsync"
    - role: "gpg"
    - role: "dotfiles"
    - role: "vim"
    - role: "neomutt"
    - role: "password_store"
    - role: "which"
    - role: "firefox"
    - role: "font"
    - role: "alacritty"
    - role: "btop"
    - role: "pipewire"