- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module syntax via ansible-lint --fix - Fix comments misplaced inside module args by the auto-fixer (bluetooth-monitor, pi_standard_setup, pi_musicmouse) - Fix notify: references left stale (lowercase) after handler names were re-cased, which would have silently broken reboot/restart handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp, pi_squeezelite, pi_standard_setup) - Fix a task in pis/debmatic-install.yml missing its module name (apt_repository), which caused a real syntax-check failure - Add missing play names, fix comment spacing, literal-compare idiom, and no-changed-when annotations - Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML) - Rename all hyphenated role directories to underscore form to satisfy ansible-lint's role-name rule, updating every playbook/meta reference Remaining lint findings (var-naming, package-latest, risky-file-permissions, no-handler) intentionally left for follow-up per user decision.
1.8 KiB
1.8 KiB
ansible
Personal Ansible setup for provisioning and maintaining a fleet of Raspberry Pis (audio players, sensors, music mouse, etc.) plus one home server.
Layout
inventory.yml— hosts and group vars (Pis underiot, plusserver).full.yml,working.yml,server.yml,newrpi-provisioning.yml,octopisetup.yml— top-level playbooks.full.ymlis the closest thing to a canonical "apply everything" playbook; the others are narrower/ad-hoc runs kept around for specific hosts or one-off tasks.roles/— one role per piece of functionality (audio backends, sensors, bluetooth monitoring, server basics, etc.). Each has a shortREADME.md.lookup_plugins/keepass.py— custom lookup plugin that fetches secrets (device passwords, wifi passphrase) from a running KeePassXC instance via its browser-integration protocol, instead of storing them in the repo.pis/— loose config files/scripts used when provisioning Pis by hand.scripts/— standalone helper scripts (Raspbian image creation, a network logger) that aren't Ansible roles.archive/— retired setups kept for reference (not actively maintained).
Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
Secrets are pulled from KeePassXC at run time via the keepass lookup
plugin — see the header of lookup_plugins/keepass.py for how to enable
Browser Integration in KeePassXC. Freshly-flashed Raspberry Pis are reached
first with the OS-default pi/raspberry credentials (see
roles/pi_standard_setup), which the role then rotates to a KeePassXC-managed
password.
Running a playbook
ansible-playbook full.yml --limit <host>
ansible.cfg points Ansible at inventory.yml and roles/ by default, so
no extra flags are needed for those.