mirror of
https://github.com/fscotto/infra.git
synced 2026-09-27 19:03:47 +00:00
* Add Atlas media and storage services * Document Atlas backend phase one and WireGuard deployment * Enable Atlas NAS management and document bootstrap workflow * Harden Atlas network, SSH, firewall, and sharing * Rotate Ansible Vault secrets * Allow configurable Aegis SSH users and authorized keys * Manage Aegis SSH authorized key fragments * Manage SSH authorized key fragments for infrastructure hosts * Harden Rocky storage and sharing configuration * Verify WireGuard handshakes and restore Podman networking
139 lines
3.2 KiB
YAML
139 lines
3.2 KiB
YAML
---
|
|
- name: Configure common user environment
|
|
hosts: all
|
|
become: true
|
|
pre_tasks:
|
|
- name: Load local vault variables when available
|
|
tags: [always]
|
|
ansible.builtin.include_vars:
|
|
file: "{{ playbook_dir }}/../secrets/vault.yml"
|
|
no_log: true
|
|
when: >-
|
|
lookup('ansible.builtin.fileglob', playbook_dir + '/../secrets/vault.yml',
|
|
errors='ignore', wantlist=True) | length > 0
|
|
|
|
- name: Load machine-local vault variables when available
|
|
tags: [always]
|
|
ansible.builtin.include_vars:
|
|
file: "{{ playbook_dir }}/../secrets/vault.local.yml"
|
|
no_log: true
|
|
when: >-
|
|
lookup('ansible.builtin.fileglob', playbook_dir + '/../secrets/vault.local.yml',
|
|
errors='ignore', wantlist=True) | length > 0
|
|
|
|
- name: Reject conflicting AI coding-agent lifecycle flags
|
|
tags: [always, ai_agents]
|
|
ansible.builtin.assert:
|
|
that:
|
|
- not (item.value.install_enabled | bool and item.value.uninstall_enabled | bool)
|
|
fail_msg: >-
|
|
{{ item.key }} has both install_enabled and uninstall_enabled set to true.
|
|
Choose either installation or removal before running the playbook.
|
|
loop: "{{ ai_agents | dict2items }}"
|
|
loop_control:
|
|
label: "{{ item.key }}"
|
|
|
|
roles:
|
|
- role: dotfiles_common
|
|
when:
|
|
- "'platform_rocky' not in group_names"
|
|
- "'platform_fedora_iot' not in group_names"
|
|
|
|
- name: Configure Void platform
|
|
hosts: platform_void
|
|
become: true
|
|
|
|
roles:
|
|
- packages_void
|
|
- services_runit
|
|
|
|
- name: Configure Void graphical desktop
|
|
hosts: platform_void:&graphical_desktop
|
|
become: true
|
|
|
|
roles:
|
|
- profile_desktop_common
|
|
- profile_desktop_sway
|
|
- profile_desktop_niri
|
|
- profile_desktop_host
|
|
|
|
- name: Configure Fedora platform
|
|
hosts: platform_fedora
|
|
become: true
|
|
|
|
roles:
|
|
- packages_fedora
|
|
- services_systemd
|
|
|
|
- name: Configure Rocky Linux platform
|
|
hosts: platform_rocky
|
|
become: true
|
|
|
|
roles:
|
|
- packages_rocky
|
|
- services_systemd
|
|
|
|
- name: Configure WireGuard overlay
|
|
hosts: wireguard_overlay
|
|
become: true
|
|
|
|
roles:
|
|
- wireguard_overlay
|
|
|
|
- name: Configure Aegis Fedora IoT profile
|
|
hosts: role_aegis
|
|
become: true
|
|
|
|
roles:
|
|
- profile_aegis
|
|
|
|
- name: Configure Atlas NAS profile
|
|
hosts: atlas
|
|
become: true
|
|
|
|
roles:
|
|
- profile_atlas
|
|
|
|
- name: Configure Atlas phase-one backend services
|
|
hosts: role_backend_phase1
|
|
become: true
|
|
|
|
roles:
|
|
- profile_backend_phase1
|
|
|
|
- name: Configure Rocky Linux server
|
|
hosts: rocky_server
|
|
become: true
|
|
|
|
roles:
|
|
- dotfiles_common
|
|
- profile_server
|
|
|
|
- name: Configure personal workstation role on Fedora
|
|
hosts: platform_fedora:&role_personal_workstation
|
|
become: true
|
|
|
|
roles:
|
|
- profile_personal_workstation
|
|
|
|
- name: Configure Fedora GNOME desktop
|
|
hosts: platform_fedora:&desktop_gnome
|
|
become: true
|
|
|
|
roles:
|
|
- profile_desktop_gnome
|
|
|
|
- name: Configure Fedora workstation development layer
|
|
hosts: workstation_dev_fedora
|
|
become: true
|
|
|
|
roles:
|
|
- profile_workstation_dev_common
|
|
|
|
- name: Configure Fedora WSL workstation development layer
|
|
hosts: workstation_dev_wsl
|
|
become: true
|
|
|
|
roles:
|
|
- profile_workstation_dev_wsl
|