Add Atlas media and storage services

This commit is contained in:
Fabio Scotto di Santolo
2026-09-10 22:27:33 +02:00
parent 569e6ef24e
commit 64aebe8c34
34 changed files with 1127 additions and 209 deletions

View File

@@ -6,6 +6,29 @@ effective_username: "{{ server_username }}"
effective_user_group: "{{ server_user_group }}"
effective_user_home: "{{ server_user_home }}"
server_container_stack_dir: /opt/docker/server
server_atlas_music_enabled: false
server_atlas_sftp_remote_name: atlas
server_atlas_sftp_host: CHANGEME_ATLAS_WIREGUARD_IP
server_atlas_sftp_port: 22
server_atlas_sftp_username: admin
server_atlas_sftp_remote_path: /pool/media/music
server_atlas_sftp_private_key: "{{ vault_prometheus_atlas_sftp_private_key | default('') }}"
server_atlas_sftp_private_key_file: /etc/rclone/atlas_ed25519
server_atlas_sftp_known_host: ""
server_atlas_sftp_known_hosts_file: /etc/rclone/known_hosts
server_atlas_wireguard_unit: ""
server_rclone_config_dir: /etc/rclone
server_rclone_config_file: /etc/rclone/rclone.conf
server_rclone_music_service: rclone-music.service
server_rclone_music_mountpoint: /mnt/music_atlas
server_rclone_music_cache_dir: /var/cache/rclone-music
server_navidrome_data_dir: /opt/navidrome/data
server_navidrome_quadlet_dir: "{{ server_user_home }}/.config/containers/systemd"
server_navidrome_env_dir: "{{ server_user_home }}/.config/navidrome"
server_navidrome_env_file: "{{ server_navidrome_env_dir }}/navidrome.env"
server_navidrome_image: docker.io/deluan/navidrome:latest
server_navidrome_port: 4533
server_navidrome_db_password: "{{ vault_navidrome_db_password | default('') }}"
ai_agents: {}
vim_plugins_enabled: false
@@ -62,11 +85,7 @@ server_directories:
owner: root
group: root
mode: "0755"
- path: /opt/navidrome/data
owner: "{{ server_username }}"
group: "{{ server_user_group }}"
mode: "0755"
- path: /opt/music
- path: "{{ server_navidrome_data_dir }}"
owner: "{{ server_username }}"
group: "{{ server_user_group }}"
mode: "0755"

View File

@@ -1,10 +1,10 @@
---
# Replace every CHANGEME value before enabling Atlas storage management.
# Keep Atlas management gates disabled until the NAS and required Vault inputs are ready.
hostname: atlas
ansible_host: CHANGEME_ATLAS_HOST
ansible_host: 192.168.178.55
ansible_user: "{{ atlas_connection_username }}"
ansible_port: 22
ansible_ssh_private_key_file: CHANGEME_ATLAS_SSH_PRIVATE_KEY_PATH
ansible_ssh_private_key_file: /home/fscotto/.ssh/id_ed25519
atlas_admin_username: admin
atlas_connection_username: "{{ atlas_admin_username }}"
@@ -15,46 +15,67 @@ atlas_admin_gid: 1000
atlas_admin_ssh_keys: "{{ vault_atlas_authorized_ssh_keys | default([]) }}"
atlas_admin_password_hash: "{{ vault_atlas_admin_password_hash | default('!') }}"
atlas_lan_subnet: CHANGEME_LAN_SUBNET
atlas_lan_subnet: 192.168.178.0/24
atlas_aegis_ip: 192.168.178.54
atlas_manage_firewall: false
atlas_firewalld_zone: public
atlas_zfs_pool: CHANGEME_ZFS_POOL
atlas_zfs_pool: zpool
atlas_zfs_dataset_work: work
atlas_zfs_dataset_archive: archive
atlas_zfs_dataset_music: media/music
atlas_zfs_dataset_syncthing: syncthing
atlas_zfs_dataset_backup_prometheus: backup_prometheus
atlas_zfs_dataset_icloud_photos: icloud_photos
atlas_mount_root: /CHANGEME_ATLAS_MOUNT_ROOT
atlas_zfs_dataset_icloud_photos: media/icloud_photos
atlas_zfs_dataset_service_backups: backups/services
atlas_mount_root: /zpool
atlas_manage_storage: false
atlas_manage_media_stack: false
rocky_manage_openzfs_repo: true
rocky_manage_syncthing_binary: true
rocky_manage_podman: true
rocky_podman_packages:
- podman
host_packages:
- cockpit
- nfs-utils
- policycoreutils-python-utils
- samba
- samba-client
- samba-common-tools
- zfs
atlas_nfs_exports:
- path: "{{ atlas_work_mountpoint }}"
clients: "{{ atlas_lan_subnet }}(rw,sync,no_subtree_check,root_squash)"
- path: "{{ atlas_icloud_photos_mountpoint }}"
client: "{{ atlas_aegis_ip }}"
options:
- rw
- sync
- no_subtree_check
- all_squash
- "anonuid={{ atlas_immich_uid }}"
- "anongid={{ atlas_immich_gid }}"
atlas_samba_share_name: work
atlas_samba_share_name: Archive
atlas_samba_workgroup: WORKGROUP
atlas_samba_valid_users:
- "{{ atlas_admin_username }}"
atlas_samba_password: "{{ vault_atlas_samba_password | default('') }}"
# Append any pre-existing laptop Unix account here and keep its Samba password in Vault.
atlas_samba_accounts:
- username: "{{ atlas_admin_username }}"
password: "{{ vault_atlas_samba_password | default('') }}"
atlas_samba_valid_users: "{{ atlas_samba_accounts | map(attribute='username') | list }}"
atlas_immich_db_password: "{{ vault_atlas_immich_db_password | default('') }}"
atlas_firewalld_rich_rules:
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" service name="ssh" accept'
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" service name="cockpit" accept'
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" port port="2049" protocol="tcp" accept'
- 'rule family="ipv4" source address="{{ atlas_aegis_ip }}" service name="nfs" accept'
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" service name="samba" accept'
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" service name="http" accept'
- 'rule family="ipv4" source address="{{ atlas_lan_subnet }}" service name="https" accept'
host_enabled_services:
- sshd
- cockpit.socket
- nfs-server
- smb
- zfs.target

View File

@@ -7,11 +7,19 @@ ansible_ssh_private_key_file: /home/fscotto/.ssh/id_ed25519
server_username: rocky
server_duckdns_domain: fscotto
server_atlas_music_enabled: false
server_atlas_sftp_host: CHANGEME_ATLAS_WIREGUARD_IP
server_atlas_sftp_username: admin
server_atlas_sftp_known_host: CHANGEME_ATLAS_SSH_HOST_KEY
server_atlas_wireguard_unit: wg-quick@wg0.service
server_atlas_sftp_private_key: "{{ vault_prometheus_atlas_sftp_private_key | default('') }}"
host_packages:
- cockpit
- cockpit-navigator
- cockpit-podman
- fuse3
- rclone
host_enabled_services:
- cockpit.socket