Martin Bauer 37b75ecf81 Fix remaining ansible-lint violations: file permissions, var-naming, package pinning
- risky-file-permissions (32): add explicit mode: to copy/template/file tasks,
  matching the umask-derived permissions they already had (0644 for configs
  and systemd units, 0755 for created directories) — no functional change.
- var-naming (28): prefix role-scoped vars with their role name across
  pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite,
  pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's
  sysdweb_name (shared by 9 consuming roles). Updated every dependent
  template, task reference, and matching inventory.yml override, and
  verified resolved values with ansible-inventory before/after.
- Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change
  WiFi country" tasks reused the name wifi_country for both the role default
  and a register, so the register silently clobbered the default before
  do_wifi_country ever read it. Split into distinct names so the intended
  default value is used.
- package-latest (2): pin docker-ce/docker-compose-plugin installs in
  server_debian_docker to state: present.
- no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a
  proper handler notified by the boot-overlay task.

ansible-lint now passes clean at the production profile.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 17:28:12 +02:00
2024-07-28 08:45:01 +02:00
2026-09-08 16:52:46 +02:00
2026-09-08 16:52:46 +02:00

ansible

Personal Ansible setup for provisioning and maintaining a fleet of Raspberry Pis (audio players, sensors, music mouse, etc.) plus one home server.

Layout

  • inventory.yml — hosts and group vars (Pis under iot, plus server).
  • full.yml, working.yml, server.yml, newrpi-provisioning.yml, octopisetup.yml — top-level playbooks. full.yml is the closest thing to a canonical "apply everything" playbook; the others are narrower/ad-hoc runs kept around for specific hosts or one-off tasks.
  • roles/ — one role per piece of functionality (audio backends, sensors, bluetooth monitoring, server basics, etc.). Each has a short README.md.
  • lookup_plugins/keepass.py — custom lookup plugin that fetches secrets (device passwords, wifi passphrase) from a running KeePassXC instance via its browser-integration protocol, instead of storing them in the repo.
  • pis/ — loose config files/scripts used when provisioning Pis by hand.
  • scripts/ — standalone helper scripts (Raspbian image creation, a network logger) that aren't Ansible roles.
  • archive/ — retired setups kept for reference (not actively maintained).

Setup

python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt

Secrets are pulled from KeePassXC at run time via the keepass lookup plugin — see the header of lookup_plugins/keepass.py for how to enable Browser Integration in KeePassXC. Freshly-flashed Raspberry Pis are reached first with the OS-default pi/raspberry credentials (see roles/pi_standard_setup), which the role then rotates to a KeePassXC-managed password.

Running a playbook

ansible-playbook full.yml --limit <host>

ansible.cfg points Ansible at inventory.yml and roles/ by default, so no extra flags are needed for those.

Description
No description provided
Readme 85 MiB
Languages
Jupyter Notebook 79.8%
Python 13.3%
Jinja 3.2%
C++ 1.7%
Shell 1.3%
Other 0.6%