# ansible Personal Ansible setup for provisioning and maintaining a fleet of Raspberry Pis (audio players, sensors, music mouse, etc.) plus one home server. ## Layout - `inventory.yml` — hosts and group vars (Pis under `iot`, plus `server`). - `full.yml`, `working.yml`, `server.yml`, `newrpi-provisioning.yml`, `octopisetup.yml` — top-level playbooks. `full.yml` is the closest thing to a canonical "apply everything" playbook; the others are narrower/ad-hoc runs kept around for specific hosts or one-off tasks. - `roles/` — one role per piece of functionality (audio backends, sensors, bluetooth monitoring, server basics, etc.). Each has a short `README.md`. - `lookup_plugins/keepass.py` — custom lookup plugin that fetches secrets (device passwords, wifi passphrase) from a running KeePassXC instance via its browser-integration protocol, instead of storing them in the repo. - `pis/` — loose config files/scripts used when provisioning Pis by hand. - `scripts/` — standalone helper scripts (Raspbian image creation, a network logger) that aren't Ansible roles. - `archive/` — retired setups kept for reference (not actively maintained). ## Setup ``` python3 -m venv venv source venv/bin/activate pip install -r requirements.txt ``` Secrets are pulled from KeePassXC at run time via the `keepass` lookup plugin — see the header of `lookup_plugins/keepass.py` for how to enable Browser Integration in KeePassXC. Freshly-flashed Raspberry Pis are reached first with the OS-default `pi`/`raspberry` credentials (see `roles/pi-standard-setup`), which the role then rotates to a KeePassXC-managed password. ## Running a playbook ``` ansible-playbook full.yml --limit ``` `ansible.cfg` points Ansible at `inventory.yml` and `roles/` by default, so no extra flags are needed for those.