Commit Graph

19 Commits

Author SHA1 Message Date
f043606466 Add deliberate update playbook and unattended-upgrades role
Regular playbooks now use state: present, so they no longer upgrade
packages as a side effect. This adds two separate, explicit mechanisms
to keep the fleet patched instead:

- update-packages.yml: ad hoc / to-be-scheduled fleet-wide upgrade
  (safe by default, dist available via -e), plus
  update-packages-pinned-example.yml as a template for pinning or
  bumping a single package outside that.
- roles/unattended_upgrades: automatic security-only patching via
  unattended-upgrades, with a scheduled reboot window and mail
  left disabled pending a configured MTA. Applied to every host in
  full.yml and server.yml.

Also removes a leftover `upgrade: yes` apt task from pi_standard_setup
and server_basic_environment that was still doing a full upgrade on
every routine run, defeating the point of the state: present switch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 18:02:41 +02:00
37b75ecf81 Fix remaining ansible-lint violations: file permissions, var-naming, package pinning
- risky-file-permissions (32): add explicit mode: to copy/template/file tasks,
  matching the umask-derived permissions they already had (0644 for configs
  and systemd units, 0755 for created directories) — no functional change.
- var-naming (28): prefix role-scoped vars with their role name across
  pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite,
  pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's
  sysdweb_name (shared by 9 consuming roles). Updated every dependent
  template, task reference, and matching inventory.yml override, and
  verified resolved values with ansible-inventory before/after.
- Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change
  WiFi country" tasks reused the name wifi_country for both the role default
  and a register, so the register silently clobbered the default before
  do_wifi_country ever read it. Split into distinct names so the intended
  default value is used.
- package-latest (2): pin docker-ce/docker-compose-plugin installs in
  server_debian_docker to state: present.
- no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a
  proper handler notified by the boot-overlay task.

ansible-lint now passes clean at the production profile.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 17:28:12 +02:00
ab9763ec49 Fix ansible-lint violations: FQCN, formatting, bugs, role renames
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
  syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
  (bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
  were re-cased, which would have silently broken reboot/restart
  handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
  pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
  (apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
  and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
  ansible-lint's role-name rule, updating every playbook/meta reference

Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.
2026-09-08 17:13:00 +02:00
f79c106437 Automated repo cleanup with claude 2026-09-08 16:52:46 +02:00
5642424697 before cleanup 2026-09-08 16:32:02 +02:00
7c70221723 IR stuff update 2025-01-06 18:01:18 +01:00
Martin Bauer
9092f08481 Bt monitor 2024-07-28 08:45:01 +02:00
Martin Bauer
e9ec94a5f8 Bluetooth Monitor WIP 2024-03-29 09:32:59 +01:00
Martin Bauer
fe744b2285 bt monitor 2024-03-08 13:02:55 +01:00
Martin Bauer
ffeee72652 music mouse setup 2024-03-08 13:02:43 +01:00
Martin Bauer
fb6f10891d Bluetooth monitor and more 2024-03-01 15:01:08 +01:00
Martin Bauer
7501ef18a4 updates raspis to new os based on bookworm 2024-02-19 08:10:58 +01:00
Martin Bauer
7776095180 New server setup based on ubuntu 2023-09-19 10:55:47 +02:00
Martin Bauer
578be1a1cf updates 2023-01-03 20:07:56 +01:00
Martin Bauer
f1d104a224 Updates & fixes 2021-07-20 15:35:12 +02:00
Martin Bauer
23a2c1fb50 added ir server, squeeze server, ... 2020-05-16 18:35:44 +02:00
Martin Bauer
93034dd0ec Update dht22 sensing code + sispmctl fixes 2020-05-12 20:51:04 +02:00
Martin Bauer
d8c9a491d1 Working sound setup for raspis 2020-05-10 15:25:38 +02:00
Martin Bauer
caf6232dfb Added sysdweb 2020-05-02 11:21:52 +02:00