37b75ecf81c832141c02dc338f39abef4d0e131d
- risky-file-permissions (32): add explicit mode: to copy/template/file tasks, matching the umask-derived permissions they already had (0644 for configs and systemd units, 0755 for created directories) — no functional change. - var-naming (28): prefix role-scoped vars with their role name across pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite, pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's sysdweb_name (shared by 9 consuming roles). Updated every dependent template, task reference, and matching inventory.yml override, and verified resolved values with ansible-inventory before/after. - Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change WiFi country" tasks reused the name wifi_country for both the role default and a register, so the register silently clobbered the default before do_wifi_country ever read it. Split into distinct names so the intended default value is used. - package-latest (2): pin docker-ce/docker-compose-plugin installs in server_debian_docker to state: present. - no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a proper handler notified by the boot-overlay task. ansible-lint now passes clean at the production profile. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
ansible
Personal Ansible setup for provisioning and maintaining a fleet of Raspberry Pis (audio players, sensors, music mouse, etc.) plus one home server.
Layout
inventory.yml— hosts and group vars (Pis underiot, plusserver).full.yml,working.yml,server.yml,newrpi-provisioning.yml,octopisetup.yml— top-level playbooks.full.ymlis the closest thing to a canonical "apply everything" playbook; the others are narrower/ad-hoc runs kept around for specific hosts or one-off tasks.roles/— one role per piece of functionality (audio backends, sensors, bluetooth monitoring, server basics, etc.). Each has a shortREADME.md.lookup_plugins/keepass.py— custom lookup plugin that fetches secrets (device passwords, wifi passphrase) from a running KeePassXC instance via its browser-integration protocol, instead of storing them in the repo.pis/— loose config files/scripts used when provisioning Pis by hand.scripts/— standalone helper scripts (Raspbian image creation, a network logger) that aren't Ansible roles.archive/— retired setups kept for reference (not actively maintained).
Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
Secrets are pulled from KeePassXC at run time via the keepass lookup
plugin — see the header of lookup_plugins/keepass.py for how to enable
Browser Integration in KeePassXC. Freshly-flashed Raspberry Pis are reached
first with the OS-default pi/raspberry credentials (see
roles/pi_standard_setup), which the role then rotates to a KeePassXC-managed
password.
Running a playbook
ansible-playbook full.yml --limit <host>
ansible.cfg points Ansible at inventory.yml and roles/ by default, so
no extra flags are needed for those.
Languages
Jupyter Notebook
79.8%
Python
13.3%
Jinja
3.2%
C++
1.7%
Shell
1.3%
Other
0.6%