Fix ansible-lint violations: FQCN, formatting, bugs, role renames
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module syntax via ansible-lint --fix - Fix comments misplaced inside module args by the auto-fixer (bluetooth-monitor, pi_standard_setup, pi_musicmouse) - Fix notify: references left stale (lowercase) after handler names were re-cased, which would have silently broken reboot/restart handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp, pi_squeezelite, pi_standard_setup) - Fix a task in pis/debmatic-install.yml missing its module name (apt_repository), which caused a real syntax-check failure - Add missing play names, fix comment spacing, literal-compare idiom, and no-changed-when annotations - Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML) - Rename all hyphenated role directories to underscore form to satisfy ansible-lint's role-name rule, updating every playbook/meta reference Remaining lint findings (var-naming, package-latest, risky-file-permissions, no-handler) intentionally left for follow-up per user decision.
This commit is contained in:
10
roles/pi_standard_setup/README.md
Normal file
10
roles/pi_standard_setup/README.md
Normal file
@@ -0,0 +1,10 @@
|
||||
# pi_standard_setup
|
||||
|
||||
Baseline provisioning applied to every Pi: apt update/upgrade, detects the
|
||||
Pi model, adds a root SSH key, disables the SSH locale-forwarding warning,
|
||||
optionally configures wifi and the hostname, and rotates the default
|
||||
`pi`/`raspberry` credentials via the `keepass` lookup plugin.
|
||||
|
||||
**Key vars:** `wifi_ssid`, `new_hostname`, `timezone`, `wifi_country`,
|
||||
`ansible_ssh_pass` (the OS-default password, used only to reach a
|
||||
freshly-flashed Pi for the first time before its password is rotated)
|
||||
11
roles/pi_standard_setup/defaults/main.yml
Normal file
11
roles/pi_standard_setup/defaults/main.yml
Normal file
@@ -0,0 +1,11 @@
|
||||
---
|
||||
wifi_ssid: "" # put SSID here to configure wifi
|
||||
ansible_user: "root" # "User to connect with, put in 'pi' here if you connect the first time, else leave empty"
|
||||
new_hostname: "" # set this to change the hostname
|
||||
|
||||
timezone: "Europe/Berlin"
|
||||
wifi_country: "DE"
|
||||
wifi_pass_url: "bauer_wifi" # has to be in keepass with url "wifi_pass_url"
|
||||
ansible_ssh_pass: "raspberry"
|
||||
ansible_become_password: "raspberry"
|
||||
ansible_become: true
|
||||
7
roles/pi_standard_setup/files/gitconfig
Normal file
7
roles/pi_standard_setup/files/gitconfig
Normal file
@@ -0,0 +1,7 @@
|
||||
[user]
|
||||
name = Martin Bauer
|
||||
email = bauer_martin@gmx.de
|
||||
[alias]
|
||||
sf = submodule foreach
|
||||
[core]
|
||||
autocrlf = input
|
||||
14
roles/pi_standard_setup/files/motd/bedroompi
Normal file
14
roles/pi_standard_setup/files/motd/bedroompi
Normal file
@@ -0,0 +1,14 @@
|
||||
|
||||
WELCOME IN THE BEDROOM
|
||||
|
||||
!__________!
|
||||
|____ ____|
|
||||
_____ {____}{____} _____
|
||||
__|_*_|__%%%%%%%%%%%%__|_*_|
|
||||
| | %%%%%%%%%%%%%% | |
|
||||
%%%%%%%%%%%%%%%%
|
||||
%%%%%%%%%%%%%%%%%%
|
||||
%%%%%%%%%%%%%%%%%%%%
|
||||
/||||||||||||||||||||\
|
||||
||||||||||||||||||||||
|
||||
|
||||
12
roles/pi_standard_setup/files/motd/esszimmerradio
Normal file
12
roles/pi_standard_setup/files/motd/esszimmerradio
Normal file
@@ -0,0 +1,12 @@
|
||||
EsszimmerRadio Eltern
|
||||
|
||||
________
|
||||
/______ |
|
||||
| | | _
|
||||
| ===== | | | |
|
||||
| ===== | | o o
|
||||
| | | |~
|
||||
| .-. | | o o o
|
||||
| ' . ' | | |~ |_|
|
||||
..'| '._.' | | o
|
||||
.' |_______|/
|
||||
18
roles/pi_standard_setup/files/motd/kitchenpi
Normal file
18
roles/pi_standard_setup/files/motd/kitchenpi
Normal file
@@ -0,0 +1,18 @@
|
||||
|
||||
WELCOME IN THE KITCHEN
|
||||
|
||||
___
|
||||
.' _ '.
|
||||
/ /` `\ \
|
||||
| | [__]
|
||||
| | {{
|
||||
| | }}
|
||||
_ | | _ {{
|
||||
___________<_>_| |_<_>}}________
|
||||
.=======^=(___)=^={{====.
|
||||
/ .----------------}}---. \
|
||||
/ / {{ \ \
|
||||
/ / }} \ \
|
||||
( '=========================' )
|
||||
'-----------------------------'
|
||||
|
||||
7
roles/pi_standard_setup/files/motd/musicmouse
Normal file
7
roles/pi_standard_setup/files/motd/musicmouse
Normal file
@@ -0,0 +1,7 @@
|
||||
Music Mouse
|
||||
|
||||
___
|
||||
_ _ .-' '-.
|
||||
(.)(.)/ \
|
||||
/@@ ;
|
||||
o_\\-mm-......-mm`~~~~~~~~~~~~~~~~`
|
||||
10
roles/pi_standard_setup/files/motd/musikserverwohnzimmeroben
Normal file
10
roles/pi_standard_setup/files/motd/musikserverwohnzimmeroben
Normal file
@@ -0,0 +1,10 @@
|
||||
|
||||
Musik Server Wohnzimmer oben
|
||||
|
||||
|~~~~~~~~~~~~~~~|
|
||||
|~~~~~~~~~~~~~~~|
|
||||
| |
|
||||
/~~\| /~~\|
|
||||
\__/ \__/
|
||||
|
||||
|
||||
4
roles/pi_standard_setup/files/motd/newrpi
Normal file
4
roles/pi_standard_setup/files/motd/newrpi
Normal file
@@ -0,0 +1,4 @@
|
||||
|
||||
THIS IS A NEW RASPI - CONFIGURE IT!
|
||||
|
||||
|
||||
3
roles/pi_standard_setup/files/motd/octopi
Normal file
3
roles/pi_standard_setup/files/motd/octopi
Normal file
@@ -0,0 +1,3 @@
|
||||
=================
|
||||
WELCOME TO OCTOPI
|
||||
=================
|
||||
8
roles/pi_standard_setup/files/raspi-leds-off.service
Normal file
8
roles/pi_standard_setup/files/raspi-leds-off.service
Normal file
@@ -0,0 +1,8 @@
|
||||
[Unit]
|
||||
Description=Turn Raspi LEDs off at boot
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/sbin/raspi-leds-off.sh
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
7
roles/pi_standard_setup/files/raspi-leds-off.sh
Normal file
7
roles/pi_standard_setup/files/raspi-leds-off.sh
Normal file
@@ -0,0 +1,7 @@
|
||||
#!/bin/bash
|
||||
|
||||
echo none > /sys/class/leds/led0/trigger
|
||||
echo none > /sys/class/leds/led1/trigger
|
||||
|
||||
echo 0 >/sys/class/leds/led0/brightness
|
||||
echo 0 >/sys/class/leds/led1/brightness
|
||||
2
roles/pi_standard_setup/files/sshkey.pub
Normal file
2
roles/pi_standard_setup/files/sshkey.pub
Normal file
@@ -0,0 +1,2 @@
|
||||
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCu66CgHoF+v1z5ydpu0SJzPuAa0eARLLggMAJY4vWcLfLTTlFjwPpO9kjkr4acUL5uLHZkAFqXQZC91io80bIfyBiM1i1yBq290x8sETgoNHrNzvcCQUBAeCxhcogi68F14BbpwBbejDTPKKybpuuAnVPj9YiHVFEDbqjLwoEY+HH7SkCsrK8qTyp9rHzwPGk0xPBwTnCPXqzvUCr/4H+m/5lamVIOW6XYoqnvAp5jP0mbadrmB0PwvK8cfgwPJWQeLJcqwl87mwHjjlrCinkpQbd2D8mR798bGmW/iTZ7GLCkyBNE34qKg24CzE0scWjqyWICXOrTYUXLORDt99/F martin@Laptop
|
||||
|
||||
14
roles/pi_standard_setup/files/vimrc
Normal file
14
roles/pi_standard_setup/files/vimrc
Normal file
@@ -0,0 +1,14 @@
|
||||
:colorscheme elflord
|
||||
:set tabstop=4
|
||||
:set shiftwidth=4
|
||||
:set expandtab
|
||||
|
||||
"other key mappings
|
||||
inoremap jk <Esc>
|
||||
|
||||
|
||||
syntax on
|
||||
|
||||
" Treat long lines as break lines (useful when moving around in them)
|
||||
map j gj
|
||||
map k gk
|
||||
10
roles/pi_standard_setup/files/wifi-watchdog.sh
Normal file
10
roles/pi_standard_setup/files/wifi-watchdog.sh
Normal file
@@ -0,0 +1,10 @@
|
||||
#!/bin/bash
|
||||
|
||||
if /sbin/ifconfig wlan0 | /bin/grep -q "inet addr:" ; then
|
||||
logger "Tested Inet connection - everything ok"
|
||||
echo "Tested Inet connection - everything ok"
|
||||
else
|
||||
logger "Network connection down! Attempting reconnection."
|
||||
echo "Network connection down! Attempting reconnection."
|
||||
/sbin/ifup --force wlan0
|
||||
fi
|
||||
7
roles/pi_standard_setup/handlers/main.yml
Normal file
7
roles/pi_standard_setup/handlers/main.yml
Normal file
@@ -0,0 +1,7 @@
|
||||
---
|
||||
- name: Restart sshd
|
||||
ansible.builtin.service:
|
||||
name: sshd
|
||||
state: restarted
|
||||
- name: Reboot
|
||||
ansible.builtin.reboot:
|
||||
135
roles/pi_standard_setup/tasks/main.yml
Normal file
135
roles/pi_standard_setup/tasks/main.yml
Normal file
@@ -0,0 +1,135 @@
|
||||
---
|
||||
- name: Do apt update/upgrade
|
||||
ansible.builtin.apt:
|
||||
upgrade: "yes"
|
||||
update_cache: "yes"
|
||||
cache_valid_time: "7200"
|
||||
- name: Detect Raspi Model
|
||||
ansible.builtin.slurp:
|
||||
src: /sys/firmware/devicetree/base/model
|
||||
register: raspberry_model
|
||||
- name: Show Raspi Model
|
||||
ansible.builtin.debug:
|
||||
msg: "{{ raspberry_model.content | b64decode }}"
|
||||
- name: Add authorized SSH key to root account
|
||||
ansible.posix.authorized_key:
|
||||
user: root
|
||||
key: "{{ lookup('file', 'sshkey.pub') }}"
|
||||
state: present
|
||||
- name: Activate root login with key
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: "^#?PermitRootLogin"
|
||||
line: "PermitRootLogin prohibit-password"
|
||||
notify: Restart sshd
|
||||
- name: Deactive SSH accepting locale vars (leads to warnings)
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: "^#?AcceptEnv LANG LC_*"
|
||||
line: "#AcceptEnv LANG LC_*"
|
||||
notify: Restart sshd
|
||||
- name: Get hostname
|
||||
ansible.builtin.command: "raspi-config nonint get_hostname"
|
||||
register: pi_hostname
|
||||
changed_when: false
|
||||
- name: Change hostname {{ new_hostname }}
|
||||
ansible.builtin.command: "raspi-config nonint do_hostname {{ new_hostname }}"
|
||||
when: new_hostname | bool and pi_hostname.stdout != new_hostname
|
||||
register: set_hostname
|
||||
changed_when: true
|
||||
notify: Reboot
|
||||
- name: Get hostname
|
||||
ansible.builtin.command: "raspi-config nonint get_hostname"
|
||||
register: pi_hostname
|
||||
changed_when: false
|
||||
- name: Set boot mode to CLI
|
||||
ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1"
|
||||
changed_when: true
|
||||
# I2 Change Timezone
|
||||
- name: Change timezone
|
||||
ansible.builtin.command: "raspi-config nonint do_change_timezone {{ timezone }}"
|
||||
changed_when: true
|
||||
- name: Change locale
|
||||
ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8"
|
||||
changed_when: true
|
||||
- name: Change password of default pi account
|
||||
ansible.builtin.user:
|
||||
name: pi
|
||||
update_password: always
|
||||
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}"
|
||||
- name: Install Packages (vim, git, basic python stuff)
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- vim
|
||||
- git
|
||||
- python3
|
||||
- python3-pip
|
||||
- python3-wheel
|
||||
- telnet
|
||||
cache_valid_time: 7200
|
||||
state: present
|
||||
- name: Copy vim config
|
||||
ansible.builtin.copy:
|
||||
src: vimrc
|
||||
dest: /root/.vimrc
|
||||
- name: Copy git config
|
||||
ansible.builtin.copy:
|
||||
src: gitconfig
|
||||
dest: /root/.gitconfig
|
||||
# Wifi
|
||||
- name: Get WiFi country
|
||||
ansible.builtin.command: "raspi-config nonint get_wifi_country"
|
||||
register: wifi_country
|
||||
changed_when: false
|
||||
ignore_errors: true # to avoid error when WiFi is not present
|
||||
- name: Change WiFi country
|
||||
ansible.builtin.command: "raspi-config nonint do_wifi_country {{ wifi_country }}"
|
||||
when: configure_wifi
|
||||
changed_when: true
|
||||
- name: Set WiFi credentials
|
||||
ansible.builtin.command: "raspi-config nonint do_wifi_ssid_passphrase {{ wifi_ssid }} {{ lookup('keepass', 'bauer_wifi') }}"
|
||||
when: configure_wifi
|
||||
changed_when: true
|
||||
- name: Install watchdog
|
||||
ansible.builtin.apt:
|
||||
name: watchdog
|
||||
cache_valid_time: "7200"
|
||||
state: present
|
||||
when: not wifi_ssid is defined
|
||||
- name: Configure watchdog
|
||||
ansible.builtin.blockinfile:
|
||||
path: /etc/watchdog.conf
|
||||
block: |
|
||||
interface = wlan0
|
||||
retry-timeout = 90
|
||||
ping = {{ router_ip }}
|
||||
interval = 15
|
||||
when: configure_wifi
|
||||
- name: Start watchdog
|
||||
ansible.builtin.systemd: # state=restarted not working, also not manually
|
||||
name: watchdog
|
||||
state: started
|
||||
enabled: "yes"
|
||||
daemon_reload: "yes"
|
||||
when: configure_wifi
|
||||
# Message of the day
|
||||
- name: Set Message of the day
|
||||
ansible.builtin.copy:
|
||||
src: motd/{{ pi_hostname.stdout }}
|
||||
dest: /etc/motd
|
||||
# LED off script
|
||||
- name: Copy led off script
|
||||
ansible.builtin.copy:
|
||||
src: raspi-leds-off.sh
|
||||
dest: /usr/sbin/raspi-leds-off.sh
|
||||
mode: "u+rwx"
|
||||
- name: Copy led off service
|
||||
ansible.builtin.copy:
|
||||
src: raspi-leds-off.service
|
||||
dest: /lib/systemd/system/
|
||||
- name: Activate led off servic
|
||||
ansible.builtin.systemd:
|
||||
name: raspi-leds-off
|
||||
state: restarted
|
||||
enabled: "yes"
|
||||
daemon_reload: "yes"
|
||||
Reference in New Issue
Block a user