--- - name: Do apt update/upgrade ansible.builtin.apt: upgrade: "yes" update_cache: "yes" cache_valid_time: "7200" - name: Detect Raspi Model ansible.builtin.slurp: src: /sys/firmware/devicetree/base/model register: pi_standard_setup_raspberry_model - name: Show Raspi Model ansible.builtin.debug: msg: "{{ pi_standard_setup_raspberry_model.content | b64decode }}" - name: Add authorized SSH key to root account ansible.posix.authorized_key: user: root key: "{{ lookup('file', 'sshkey.pub') }}" state: present - name: Activate root login with key ansible.builtin.lineinfile: path: /etc/ssh/sshd_config regexp: "^#?PermitRootLogin" line: "PermitRootLogin prohibit-password" notify: Restart sshd - name: Deactive SSH accepting locale vars (leads to warnings) ansible.builtin.lineinfile: path: /etc/ssh/sshd_config regexp: "^#?AcceptEnv LANG LC_*" line: "#AcceptEnv LANG LC_*" notify: Restart sshd - name: Get hostname ansible.builtin.command: "raspi-config nonint get_hostname" register: pi_standard_setup_pi_hostname changed_when: false - name: Change hostname {{ pi_standard_setup_new_hostname }} ansible.builtin.command: "raspi-config nonint do_hostname {{ pi_standard_setup_new_hostname }}" when: pi_standard_setup_new_hostname | bool and pi_standard_setup_pi_hostname.stdout != pi_standard_setup_new_hostname register: pi_standard_setup_set_hostname changed_when: true notify: Reboot - name: Get hostname ansible.builtin.command: "raspi-config nonint get_hostname" register: pi_standard_setup_pi_hostname changed_when: false - name: Set boot mode to CLI ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1" changed_when: true # I2 Change Timezone - name: Change timezone ansible.builtin.command: "raspi-config nonint do_change_timezone {{ pi_standard_setup_timezone }}" changed_when: true - name: Change locale ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8" changed_when: true - name: Change password of default pi account ansible.builtin.user: name: pi update_password: always password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}" - name: Install Packages (vim, git, basic python stuff) ansible.builtin.apt: name: - vim - git - python3 - python3-pip - python3-wheel - telnet cache_valid_time: 7200 state: present - name: Copy vim config ansible.builtin.copy: src: vimrc dest: /root/.vimrc mode: "0644" - name: Copy git config ansible.builtin.copy: src: gitconfig dest: /root/.gitconfig mode: "0644" # Wifi - name: Get WiFi country ansible.builtin.command: "raspi-config nonint get_wifi_country" register: pi_standard_setup_current_wifi_country changed_when: false ignore_errors: true # to avoid error when WiFi is not present - name: Change WiFi country ansible.builtin.command: "raspi-config nonint do_wifi_country {{ pi_standard_setup_wifi_country }}" when: configure_wifi changed_when: true - name: Set WiFi credentials ansible.builtin.command: "raspi-config nonint do_wifi_ssid_passphrase {{ pi_standard_setup_wifi_ssid }} {{ lookup('keepass', 'bauer_wifi') }}" when: configure_wifi changed_when: true - name: Install watchdog ansible.builtin.apt: name: watchdog cache_valid_time: "7200" state: present when: not pi_standard_setup_wifi_ssid is defined - name: Configure watchdog ansible.builtin.blockinfile: path: /etc/watchdog.conf block: | interface = wlan0 retry-timeout = 90 ping = {{ router_ip }} interval = 15 when: configure_wifi - name: Start watchdog ansible.builtin.systemd: # state=restarted not working, also not manually name: watchdog state: started enabled: "yes" daemon_reload: "yes" when: configure_wifi # Message of the day - name: Set Message of the day ansible.builtin.copy: src: motd/{{ pi_standard_setup_pi_hostname.stdout }} dest: /etc/motd mode: "0644" # LED off script - name: Copy led off script ansible.builtin.copy: src: raspi-leds-off.sh dest: /usr/sbin/raspi-leds-off.sh mode: "u+rwx" - name: Copy led off service ansible.builtin.copy: src: raspi-leds-off.service dest: /lib/systemd/system/ mode: "0644" - name: Activate led off servic ansible.builtin.systemd: name: raspi-leds-off state: restarted enabled: "yes" daemon_reload: "yes"