Commit Graph
159 Commits
Author SHA1 Message Date
DmitryandClaude Opus 5 9725d3ea7c Add service registry, shared roles and unified reverse proxy
Collect the facts about all 14 services -- VMID, node, address, ports,
domain, pinned images, resources, backup and monitoring participation --
into group_vars/all/services.yml. Values are taken from the existing
playbooks; gaps are marked null rather than invented.

Replace reverse-proxy-{gitea,vaultwarden,grimmory}.yml with a single
playbook iterating over registry entries that declare a domain. It keeps
every check the three had, preserves grimmory's richer Caddy block
byte-for-byte, and restarts Caddy once when any site changed instead of
up to three times. Verified with --check --diff against ru-vps: ok=6
changed=0, so it reproduces the current Caddyfile exactly.

Add two roles factoring out the skeleton duplicated across the pve-*
playbooks: lxc_docker_host (packages, /dev/fuse assertion, fuse-overlayfs
storage driver, UFW baseline) and compose_service (compose file, systemd
unit, config validation, health check). They are not wired into any
playbook yet -- migrating a live service is a separate, per-service step;
compose_service/README.md shows the Gitea example and spells out what
actually changes on the host.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:10:16 +03:00
DmitryandClaude Opus 5 ec3b736250 Move SSH transport to ssh_config and shared group_vars
hosts.yml repeated the same authentication block for 13 LXC hosts and
carried 13 byte-identical copies of the ru-vps ProxyCommand. Describe the
transport once in ansible/ssh_config instead: jump host, per-host users,
keys, and the fact that pbs and ovpn-mini are reached directly rather
than through ru-vps.

Ansible loads that file through ansible_ssh_common_args in
group_vars/all/main.yml, where the path is derived from inventory_dir so
it depends on neither the current directory nor the clone location.
The same file makes `ssh gitea` work from a plain terminal once
~/.ssh/config includes it.

hosts.yml drops from 209 to 137 lines and now holds only addresses and
per-host facts. Verified equivalent: ansible-inventory --list before and
after differ only by the removed ansible_ssh_common_args, with group
membership and ordering byte-identical.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:10:16 +03:00
DmitryandClaude Opus 5 a7b0635830 Add lint configuration and Gitea Actions CI
Configure yamllint and ansible-lint, plus a workflow running yamllint,
ansible-lint and ansible-playbook --syntax-check over every playbook.

ansible-lint uses the moderate profile: on the current code it reports
exactly the same violations as basic, so it costs nothing today while
holding a higher bar for new code. skip_list is empty; noisy legacy
rules go to warn_list with a comment on why and when to restore them.
Correctness and safety rules stay fatal.

Two constraints are encoded in the workflow: syntax-check must run from
ansible/ because roles_path is relative, and ansible-lint needs absolute
ANSIBLE_ROLES_PATH/ANSIBLE_COLLECTIONS_PATH when run from the root.

The runner is not registered yet; registration notes are in the workflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:09:59 +03:00
DmitryandClaude Opus 5 b953909e0a Add reproducible Nix dev environment
Replace the Python venv with a Nix devshell pinning ansible-core 2.21.3,
ansible-lint, yamllint and a Python with proxmoxer/requests. The Python
dependencies share the interpreter that runs ansible, so pve-*.yml plays
on implicit localhost can import proxmoxer without inventory changes.

The shellHook exports absolute ANSIBLE_CONFIG, ANSIBLE_INVENTORY,
ANSIBLE_ROLES_PATH and ANSIBLE_COLLECTIONS_PATH, so commands work from
the repository root as well as from ansible/.

Also un-ignore .envrc, which the global gitignore hides, and ignore the
stray .ansible/ runtime directory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:09:59 +03:00
DmitryandClaude Opus 5 c676be81ec Capture current Ansible control plane state
Commit the accumulated infrastructure work that was living only in the
working tree: monitoring stack, emergency access/bot, gyro allocator,
grimmory, adguard, backup audit and the OpenCode agent definitions.

Also ignore Python bytecode, local archives and Nix/direnv artifacts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 21:39:28 +03:00
Dmitry 4bafa7d09e Archive Legacy Setup And Add Ansible Control Plane 2026-07-08 12:47:37 +03:00
Dmitry 841d56380b Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 11:05:53 +03:00
Dmitry 827f8de6d3 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 10:56:33 +03:00
Dmitry 1a0b38d066 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 2s
2026-07-04 10:51:47 +03:00
Dmitry 046d3bc236 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 2s
2026-07-04 10:51:08 +03:00
Dmitry b2d6c9a436 Create docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 10:49:36 +03:00
Dmitry f8ccc7ec35 Update Caddyfile
Deploy mini-pc / deploy (push) Successful in 32s
2026-06-10 21:10:44 +03:00
Dmitry c935564ed8 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 23s
2026-06-09 06:32:49 +03:00
Dmitry 59a7749b18 Убрать всё, кроме mihomo
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 23:05:05 +03:00
Dmitry 74c3c54feb Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 23:02:45 +03:00
Dmitry e3d7c8ccbf Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:53:09 +03:00
Dmitry f153bcdbd1 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 32s
2026-06-08 22:52:23 +03:00
Dmitry 6529b49e1f Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:51:41 +03:00
Dmitry 638f043a49 Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:46:30 +03:00
Dmitry 928878e057 dfddd
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 22:37:16 +03:00
Dmitry 92ce67732c Update mtg-config.toml
Deploy ru-vps / deploy (push) Failing after 24s
2026-06-08 22:33:36 +03:00
Dmitry 41404085f5 mtg
Deploy ru-vps / deploy (push) Failing after 24s
2026-06-08 22:27:13 +03:00
Dmitry 0e96d60ece Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 21:59:29 +03:00
Dmitry 2e829d9380 fff
Deploy ru-vps / deploy (push) Failing after 1s
2026-06-08 20:46:26 +03:00
Dmitry 2cd106b84c Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 31s
2026-06-08 20:44:28 +03:00
Dmitry 46824776ef Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 9s
2026-06-08 20:43:16 +03:00
Dmitry d5b56f1a20 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 20:39:22 +03:00
Dmitry 65ef3341a4 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 59s
2026-06-08 20:35:57 +03:00
Dmitry db7c95845b Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 21s
2026-06-08 20:34:33 +03:00
Dmitry 5cf7f11b88 ыыы
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 20:28:10 +03:00
Dmitry 857e63ca68 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 9s
2026-06-08 20:21:06 +03:00
Dmitry 9c7ef29a43 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 20:19:40 +03:00
Dmitry 81174047bd Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 56s
2026-06-08 20:09:56 +03:00
Dmitry 17f91d833e Update config.yaml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:54:39 +03:00
Dmitry 32428d0156 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:49:37 +03:00
Dmitry e49cf515e9 Убрать squid
Deploy ru-vps / deploy (push) Successful in 34s
2026-06-08 19:46:52 +03:00
Dmitry eb9c8767b0 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 19:41:25 +03:00
Dmitry f61ad5763e Update config.yaml
Deploy ru-vps / deploy (push) Failing after 33s
2026-06-08 19:40:16 +03:00
Dmitry 3cca8246db Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 19:33:57 +03:00
Dmitry 573590ef45 Опять прокси новый
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:31:18 +03:00
Dmitry 4a80762cbc Переосмысление сервисов
Deploy ru-vps / deploy (push) Successful in 29s
2026-06-08 19:22:42 +03:00
Dmitry f98b83514f Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 29s
2026-06-08 19:21:12 +03:00
Dmitry 055bb45be4 Sss
Deploy ru-vps / deploy (push) Failing after 1s
2026-06-08 19:18:03 +03:00
Dmitry 40a499decf Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 30s
2026-06-08 19:13:07 +03:00
Dmitry 14bf5c9e63 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 43s
2026-06-08 19:08:15 +03:00
Dmitry ab9d07c379 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 29s
2026-06-08 19:06:50 +03:00
Dmitry 39bdb810a2 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 27s
2026-06-08 18:58:46 +03:00
Dmitry b3a17ab5e4 Update entrypoint.sh
Deploy ru-vps / deploy (push) Failing after 16s
2026-06-08 18:57:08 +03:00
Dmitry 322bfa9513 Добавить 3proxy к squid
Deploy ru-vps / deploy (push) Failing after 20s
2026-06-08 18:55:05 +03:00
Dmitry c0cd22a73a Update squid.conf
Deploy ru-vps / deploy (push) Successful in 43s
2026-06-08 18:50:54 +03:00