Commit Graph
160 Commits
Author SHA1 Message Date
DmitryandClaude Opus 5 d535ef2d32 Add read-only infrastructure status playbook
One command to see the state of everything: reachability, uptime, disk
usage, service unit states, failed units, pct list on the Proxmox nodes,
OpenVPN transport health, and the last run of each backup job.

An unreachable host is reported as data, not as a run failure, so a
single host being down still produces a full summary. Every command is
changed_when: false with check_mode: false, so the playbook is read-only
and works under --check. Backup freshness is read from what systemd
already recorded rather than by invoking the audit scripts, which would
hit PBS and Yandex Disk and take locks.

Service units are derived from inventory groups where possible; only
app-specific units need the per-host map, and each was taken from the
playbook or role that installs it.

Verified against live infrastructure: 15 hosts, changed=0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:10:29 +03:00
DmitryandClaude Opus 5 9725d3ea7c Add service registry, shared roles and unified reverse proxy
Collect the facts about all 14 services -- VMID, node, address, ports,
domain, pinned images, resources, backup and monitoring participation --
into group_vars/all/services.yml. Values are taken from the existing
playbooks; gaps are marked null rather than invented.

Replace reverse-proxy-{gitea,vaultwarden,grimmory}.yml with a single
playbook iterating over registry entries that declare a domain. It keeps
every check the three had, preserves grimmory's richer Caddy block
byte-for-byte, and restarts Caddy once when any site changed instead of
up to three times. Verified with --check --diff against ru-vps: ok=6
changed=0, so it reproduces the current Caddyfile exactly.

Add two roles factoring out the skeleton duplicated across the pve-*
playbooks: lxc_docker_host (packages, /dev/fuse assertion, fuse-overlayfs
storage driver, UFW baseline) and compose_service (compose file, systemd
unit, config validation, health check). They are not wired into any
playbook yet -- migrating a live service is a separate, per-service step;
compose_service/README.md shows the Gitea example and spells out what
actually changes on the host.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:10:16 +03:00
DmitryandClaude Opus 5 ec3b736250 Move SSH transport to ssh_config and shared group_vars
hosts.yml repeated the same authentication block for 13 LXC hosts and
carried 13 byte-identical copies of the ru-vps ProxyCommand. Describe the
transport once in ansible/ssh_config instead: jump host, per-host users,
keys, and the fact that pbs and ovpn-mini are reached directly rather
than through ru-vps.

Ansible loads that file through ansible_ssh_common_args in
group_vars/all/main.yml, where the path is derived from inventory_dir so
it depends on neither the current directory nor the clone location.
The same file makes `ssh gitea` work from a plain terminal once
~/.ssh/config includes it.

hosts.yml drops from 209 to 137 lines and now holds only addresses and
per-host facts. Verified equivalent: ansible-inventory --list before and
after differ only by the removed ansible_ssh_common_args, with group
membership and ordering byte-identical.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:10:16 +03:00
DmitryandClaude Opus 5 a7b0635830 Add lint configuration and Gitea Actions CI
Configure yamllint and ansible-lint, plus a workflow running yamllint,
ansible-lint and ansible-playbook --syntax-check over every playbook.

ansible-lint uses the moderate profile: on the current code it reports
exactly the same violations as basic, so it costs nothing today while
holding a higher bar for new code. skip_list is empty; noisy legacy
rules go to warn_list with a comment on why and when to restore them.
Correctness and safety rules stay fatal.

Two constraints are encoded in the workflow: syntax-check must run from
ansible/ because roles_path is relative, and ansible-lint needs absolute
ANSIBLE_ROLES_PATH/ANSIBLE_COLLECTIONS_PATH when run from the root.

The runner is not registered yet; registration notes are in the workflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:09:59 +03:00
DmitryandClaude Opus 5 b953909e0a Add reproducible Nix dev environment
Replace the Python venv with a Nix devshell pinning ansible-core 2.21.3,
ansible-lint, yamllint and a Python with proxmoxer/requests. The Python
dependencies share the interpreter that runs ansible, so pve-*.yml plays
on implicit localhost can import proxmoxer without inventory changes.

The shellHook exports absolute ANSIBLE_CONFIG, ANSIBLE_INVENTORY,
ANSIBLE_ROLES_PATH and ANSIBLE_COLLECTIONS_PATH, so commands work from
the repository root as well as from ansible/.

Also un-ignore .envrc, which the global gitignore hides, and ignore the
stray .ansible/ runtime directory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 22:09:59 +03:00
DmitryandClaude Opus 5 c676be81ec Capture current Ansible control plane state
Commit the accumulated infrastructure work that was living only in the
working tree: monitoring stack, emergency access/bot, gyro allocator,
grimmory, adguard, backup audit and the OpenCode agent definitions.

Also ignore Python bytecode, local archives and Nix/direnv artifacts.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
2026-08-26 21:39:28 +03:00
Dmitry 4bafa7d09e Archive Legacy Setup And Add Ansible Control Plane 2026-07-08 12:47:37 +03:00
Dmitry 841d56380b Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 11:05:53 +03:00
Dmitry 827f8de6d3 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 10:56:33 +03:00
Dmitry 1a0b38d066 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 2s
2026-07-04 10:51:47 +03:00
Dmitry 046d3bc236 Update docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 2s
2026-07-04 10:51:08 +03:00
Dmitry b2d6c9a436 Create docker-compose.yml
Deploy mini-pc / deploy (push) Failing after 3s
2026-07-04 10:49:36 +03:00
Dmitry f8ccc7ec35 Update Caddyfile
Deploy mini-pc / deploy (push) Successful in 32s
2026-06-10 21:10:44 +03:00
Dmitry c935564ed8 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 23s
2026-06-09 06:32:49 +03:00
Dmitry 59a7749b18 Убрать всё, кроме mihomo
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 23:05:05 +03:00
Dmitry 74c3c54feb Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 23:02:45 +03:00
Dmitry e3d7c8ccbf Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:53:09 +03:00
Dmitry f153bcdbd1 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 32s
2026-06-08 22:52:23 +03:00
Dmitry 6529b49e1f Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:51:41 +03:00
Dmitry 638f043a49 Update mtg-config.toml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 22:46:30 +03:00
Dmitry 928878e057 dfddd
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 22:37:16 +03:00
Dmitry 92ce67732c Update mtg-config.toml
Deploy ru-vps / deploy (push) Failing after 24s
2026-06-08 22:33:36 +03:00
Dmitry 41404085f5 mtg
Deploy ru-vps / deploy (push) Failing after 24s
2026-06-08 22:27:13 +03:00
Dmitry 0e96d60ece Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 21:59:29 +03:00
Dmitry 2e829d9380 fff
Deploy ru-vps / deploy (push) Failing after 1s
2026-06-08 20:46:26 +03:00
Dmitry 2cd106b84c Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 31s
2026-06-08 20:44:28 +03:00
Dmitry 46824776ef Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 9s
2026-06-08 20:43:16 +03:00
Dmitry d5b56f1a20 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 20:39:22 +03:00
Dmitry 65ef3341a4 Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 59s
2026-06-08 20:35:57 +03:00
Dmitry db7c95845b Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 21s
2026-06-08 20:34:33 +03:00
Dmitry 5cf7f11b88 ыыы
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 20:28:10 +03:00
Dmitry 857e63ca68 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 9s
2026-06-08 20:21:06 +03:00
Dmitry 9c7ef29a43 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 20:19:40 +03:00
Dmitry 81174047bd Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 56s
2026-06-08 20:09:56 +03:00
Dmitry 17f91d833e Update config.yaml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:54:39 +03:00
Dmitry 32428d0156 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:49:37 +03:00
Dmitry e49cf515e9 Убрать squid
Deploy ru-vps / deploy (push) Successful in 34s
2026-06-08 19:46:52 +03:00
Dmitry eb9c8767b0 Update config.yaml
Deploy ru-vps / deploy (push) Successful in 22s
2026-06-08 19:41:25 +03:00
Dmitry f61ad5763e Update config.yaml
Deploy ru-vps / deploy (push) Failing after 33s
2026-06-08 19:40:16 +03:00
Dmitry 3cca8246db Update docker-compose.yml
Deploy ru-vps / deploy (push) Successful in 33s
2026-06-08 19:33:57 +03:00
Dmitry 573590ef45 Опять прокси новый
Deploy ru-vps / deploy (push) Successful in 24s
2026-06-08 19:31:18 +03:00
Dmitry 4a80762cbc Переосмысление сервисов
Deploy ru-vps / deploy (push) Successful in 29s
2026-06-08 19:22:42 +03:00
Dmitry f98b83514f Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 29s
2026-06-08 19:21:12 +03:00
Dmitry 055bb45be4 Sss
Deploy ru-vps / deploy (push) Failing after 1s
2026-06-08 19:18:03 +03:00
Dmitry 40a499decf Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 30s
2026-06-08 19:13:07 +03:00
Dmitry 14bf5c9e63 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 43s
2026-06-08 19:08:15 +03:00
Dmitry ab9d07c379 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 29s
2026-06-08 19:06:50 +03:00
Dmitry 39bdb810a2 Update docker-compose.yml
Deploy ru-vps / deploy (push) Failing after 27s
2026-06-08 18:58:46 +03:00
Dmitry b3a17ab5e4 Update entrypoint.sh
Deploy ru-vps / deploy (push) Failing after 16s
2026-06-08 18:57:08 +03:00
Dmitry 322bfa9513 Добавить 3proxy к squid
Deploy ru-vps / deploy (push) Failing after 20s
2026-06-08 18:55:05 +03:00