- risky-file-permissions (32): add explicit mode: to copy/template/file tasks, matching the umask-derived permissions they already had (0644 for configs and systemd units, 0755 for created directories) — no functional change. - var-naming (28): prefix role-scoped vars with their role name across pi_dhtsensor, pi_dhtsensor_circuitpython, pi_shairport, pi_squeezelite, pi_squeezelite_custom, pi_sispmctl, pi_standard_setup, and pi_sysdweb's sysdweb_name (shared by 9 consuming roles). Updated every dependent template, task reference, and matching inventory.yml override, and verified resolved values with ansible-inventory before/after. - Fixes a latent bug found while renaming: pi_standard_setup's "Get/Change WiFi country" tasks reused the name wifi_country for both the role default and a register, so the register silently clobbered the default before do_wifi_country ever read it. Split into distinct names so the intended default value is used. - package-latest (2): pin docker-ce/docker-compose-plugin installs in server_debian_docker to state: present. - no-handler (1): move pi_lirc's "Reboot if boot overlay changed" into a proper handler notified by the boot-overlay task. ansible-lint now passes clean at the production profile. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
12 lines
582 B
Markdown
12 lines
582 B
Markdown
# pi_standard_setup
|
|
|
|
Baseline provisioning applied to every Pi: apt update/upgrade, detects the
|
|
Pi model, adds a root SSH key, disables the SSH locale-forwarding warning,
|
|
optionally configures wifi and the hostname, and rotates the default
|
|
`pi`/`raspberry` credentials via the `keepass` lookup plugin.
|
|
|
|
**Key vars:** `pi_standard_setup_wifi_ssid`, `pi_standard_setup_new_hostname`,
|
|
`pi_standard_setup_timezone`, `pi_standard_setup_wifi_country`,
|
|
`ansible_ssh_pass` (the OS-default password, used only to reach a
|
|
freshly-flashed Pi for the first time before its password is rotated)
|