Fix ansible-lint violations: FQCN, formatting, bugs, role renames

- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
  syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
  (bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
  were re-cased, which would have silently broken reboot/restart
  handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
  pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
  (apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
  and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
  ansible-lint's role-name rule, updating every playbook/meta reference

Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.
This commit is contained in:
2026-09-08 17:13:00 +02:00
parent f79c106437
commit ab9763ec49
158 changed files with 775 additions and 660 deletions

View File

@@ -0,0 +1,10 @@
# pi_standard_setup
Baseline provisioning applied to every Pi: apt update/upgrade, detects the
Pi model, adds a root SSH key, disables the SSH locale-forwarding warning,
optionally configures wifi and the hostname, and rotates the default
`pi`/`raspberry` credentials via the `keepass` lookup plugin.
**Key vars:** `wifi_ssid`, `new_hostname`, `timezone`, `wifi_country`,
`ansible_ssh_pass` (the OS-default password, used only to reach a
freshly-flashed Pi for the first time before its password is rotated)

View File

@@ -0,0 +1,11 @@
---
wifi_ssid: "" # put SSID here to configure wifi
ansible_user: "root" # "User to connect with, put in 'pi' here if you connect the first time, else leave empty"
new_hostname: "" # set this to change the hostname
timezone: "Europe/Berlin"
wifi_country: "DE"
wifi_pass_url: "bauer_wifi" # has to be in keepass with url "wifi_pass_url"
ansible_ssh_pass: "raspberry"
ansible_become_password: "raspberry"
ansible_become: true

View File

@@ -0,0 +1,7 @@
[user]
name = Martin Bauer
email = bauer_martin@gmx.de
[alias]
sf = submodule foreach
[core]
autocrlf = input

View File

@@ -0,0 +1,14 @@
WELCOME IN THE BEDROOM
!__________!
|____ ____|
_____ {____}{____} _____
__|_*_|__%%%%%%%%%%%%__|_*_|
| | %%%%%%%%%%%%%% | |
%%%%%%%%%%%%%%%%
%%%%%%%%%%%%%%%%%%
%%%%%%%%%%%%%%%%%%%%
/||||||||||||||||||||\
||||||||||||||||||||||

View File

@@ -0,0 +1,12 @@
EsszimmerRadio Eltern
________
/______ |
| | | _
| ===== | | | |
| ===== | | o o
| | | |~
| .-. | | o o o
| ' . ' | | |~ |_|
..'| '._.' | | o
.' |_______|/

View File

@@ -0,0 +1,18 @@
WELCOME IN THE KITCHEN
___
.' _ '.
/ /` `\ \
| | [__]
| | {{
| | }}
_ | | _ {{
___________<_>_| |_<_>}}________
.=======^=(___)=^={{====.
/ .----------------}}---. \
/ / {{ \ \
/ / }} \ \
( '=========================' )
'-----------------------------'

View File

@@ -0,0 +1,7 @@
Music Mouse
___
_ _ .-' '-.
(.)(.)/ \
/@@ ;
o_\\-mm-......-mm`~~~~~~~~~~~~~~~~`

View File

@@ -0,0 +1,10 @@
Musik Server Wohnzimmer oben
|~~~~~~~~~~~~~~~|
|~~~~~~~~~~~~~~~|
| |
/~~\| /~~\|
\__/ \__/

View File

@@ -0,0 +1,4 @@
THIS IS A NEW RASPI - CONFIGURE IT!

View File

@@ -0,0 +1,3 @@
=================
WELCOME TO OCTOPI
=================

View File

@@ -0,0 +1,8 @@
[Unit]
Description=Turn Raspi LEDs off at boot
[Service]
ExecStart=/usr/sbin/raspi-leds-off.sh
[Install]
WantedBy=multi-user.target

View File

@@ -0,0 +1,7 @@
#!/bin/bash
echo none > /sys/class/leds/led0/trigger
echo none > /sys/class/leds/led1/trigger
echo 0 >/sys/class/leds/led0/brightness
echo 0 >/sys/class/leds/led1/brightness

View File

@@ -0,0 +1,2 @@
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCu66CgHoF+v1z5ydpu0SJzPuAa0eARLLggMAJY4vWcLfLTTlFjwPpO9kjkr4acUL5uLHZkAFqXQZC91io80bIfyBiM1i1yBq290x8sETgoNHrNzvcCQUBAeCxhcogi68F14BbpwBbejDTPKKybpuuAnVPj9YiHVFEDbqjLwoEY+HH7SkCsrK8qTyp9rHzwPGk0xPBwTnCPXqzvUCr/4H+m/5lamVIOW6XYoqnvAp5jP0mbadrmB0PwvK8cfgwPJWQeLJcqwl87mwHjjlrCinkpQbd2D8mR798bGmW/iTZ7GLCkyBNE34qKg24CzE0scWjqyWICXOrTYUXLORDt99/F martin@Laptop

View File

@@ -0,0 +1,14 @@
:colorscheme elflord
:set tabstop=4
:set shiftwidth=4
:set expandtab
"other key mappings
inoremap jk <Esc>
syntax on
" Treat long lines as break lines (useful when moving around in them)
map j gj
map k gk

View File

@@ -0,0 +1,10 @@
#!/bin/bash
if /sbin/ifconfig wlan0 | /bin/grep -q "inet addr:" ; then
logger "Tested Inet connection - everything ok"
echo "Tested Inet connection - everything ok"
else
logger "Network connection down! Attempting reconnection."
echo "Network connection down! Attempting reconnection."
/sbin/ifup --force wlan0
fi

View File

@@ -0,0 +1,7 @@
---
- name: Restart sshd
ansible.builtin.service:
name: sshd
state: restarted
- name: Reboot
ansible.builtin.reboot:

View File

@@ -0,0 +1,135 @@
---
- name: Do apt update/upgrade
ansible.builtin.apt:
upgrade: "yes"
update_cache: "yes"
cache_valid_time: "7200"
- name: Detect Raspi Model
ansible.builtin.slurp:
src: /sys/firmware/devicetree/base/model
register: raspberry_model
- name: Show Raspi Model
ansible.builtin.debug:
msg: "{{ raspberry_model.content | b64decode }}"
- name: Add authorized SSH key to root account
ansible.posix.authorized_key:
user: root
key: "{{ lookup('file', 'sshkey.pub') }}"
state: present
- name: Activate root login with key
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "^#?PermitRootLogin"
line: "PermitRootLogin prohibit-password"
notify: Restart sshd
- name: Deactive SSH accepting locale vars (leads to warnings)
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "^#?AcceptEnv LANG LC_*"
line: "#AcceptEnv LANG LC_*"
notify: Restart sshd
- name: Get hostname
ansible.builtin.command: "raspi-config nonint get_hostname"
register: pi_hostname
changed_when: false
- name: Change hostname {{ new_hostname }}
ansible.builtin.command: "raspi-config nonint do_hostname {{ new_hostname }}"
when: new_hostname | bool and pi_hostname.stdout != new_hostname
register: set_hostname
changed_when: true
notify: Reboot
- name: Get hostname
ansible.builtin.command: "raspi-config nonint get_hostname"
register: pi_hostname
changed_when: false
- name: Set boot mode to CLI
ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1"
changed_when: true
# I2 Change Timezone
- name: Change timezone
ansible.builtin.command: "raspi-config nonint do_change_timezone {{ timezone }}"
changed_when: true
- name: Change locale
ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8"
changed_when: true
- name: Change password of default pi account
ansible.builtin.user:
name: pi
update_password: always
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}"
- name: Install Packages (vim, git, basic python stuff)
ansible.builtin.apt:
name:
- vim
- git
- python3
- python3-pip
- python3-wheel
- telnet
cache_valid_time: 7200
state: present
- name: Copy vim config
ansible.builtin.copy:
src: vimrc
dest: /root/.vimrc
- name: Copy git config
ansible.builtin.copy:
src: gitconfig
dest: /root/.gitconfig
# Wifi
- name: Get WiFi country
ansible.builtin.command: "raspi-config nonint get_wifi_country"
register: wifi_country
changed_when: false
ignore_errors: true # to avoid error when WiFi is not present
- name: Change WiFi country
ansible.builtin.command: "raspi-config nonint do_wifi_country {{ wifi_country }}"
when: configure_wifi
changed_when: true
- name: Set WiFi credentials
ansible.builtin.command: "raspi-config nonint do_wifi_ssid_passphrase {{ wifi_ssid }} {{ lookup('keepass', 'bauer_wifi') }}"
when: configure_wifi
changed_when: true
- name: Install watchdog
ansible.builtin.apt:
name: watchdog
cache_valid_time: "7200"
state: present
when: not wifi_ssid is defined
- name: Configure watchdog
ansible.builtin.blockinfile:
path: /etc/watchdog.conf
block: |
interface = wlan0
retry-timeout = 90
ping = {{ router_ip }}
interval = 15
when: configure_wifi
- name: Start watchdog
ansible.builtin.systemd: # state=restarted not working, also not manually
name: watchdog
state: started
enabled: "yes"
daemon_reload: "yes"
when: configure_wifi
# Message of the day
- name: Set Message of the day
ansible.builtin.copy:
src: motd/{{ pi_hostname.stdout }}
dest: /etc/motd
# LED off script
- name: Copy led off script
ansible.builtin.copy:
src: raspi-leds-off.sh
dest: /usr/sbin/raspi-leds-off.sh
mode: "u+rwx"
- name: Copy led off service
ansible.builtin.copy:
src: raspi-leds-off.service
dest: /lib/systemd/system/
- name: Activate led off servic
ansible.builtin.systemd:
name: raspi-leds-off
state: restarted
enabled: "yes"
daemon_reload: "yes"