Files
ansible/README.md
Martin Bauer ab9763ec49 Fix ansible-lint violations: FQCN, formatting, bugs, role renames
- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module
  syntax via ansible-lint --fix
- Fix comments misplaced inside module args by the auto-fixer
  (bluetooth-monitor, pi_standard_setup, pi_musicmouse)
- Fix notify: references left stale (lowercase) after handler names
  were re-cased, which would have silently broken reboot/restart
  handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp,
  pi_squeezelite, pi_standard_setup)
- Fix a task in pis/debmatic-install.yml missing its module name
  (apt_repository), which caused a real syntax-check failure
- Add missing play names, fix comment spacing, literal-compare idiom,
  and no-changed-when annotations
- Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML)
- Rename all hyphenated role directories to underscore form to satisfy
  ansible-lint's role-name rule, updating every playbook/meta reference

Remaining lint findings (var-naming, package-latest, risky-file-permissions,
no-handler) intentionally left for follow-up per user decision.
2026-09-08 17:13:00 +02:00

46 lines
1.8 KiB
Markdown

# ansible
Personal Ansible setup for provisioning and maintaining a fleet of Raspberry
Pis (audio players, sensors, music mouse, etc.) plus one home server.
## Layout
- `inventory.yml` — hosts and group vars (Pis under `iot`, plus `server`).
- `full.yml`, `working.yml`, `server.yml`, `newrpi-provisioning.yml`,
`octopisetup.yml` — top-level playbooks. `full.yml` is the closest thing to
a canonical "apply everything" playbook; the others are narrower/ad-hoc
runs kept around for specific hosts or one-off tasks.
- `roles/` — one role per piece of functionality (audio backends, sensors,
bluetooth monitoring, server basics, etc.). Each has a short `README.md`.
- `lookup_plugins/keepass.py` — custom lookup plugin that fetches secrets
(device passwords, wifi passphrase) from a running KeePassXC instance via
its browser-integration protocol, instead of storing them in the repo.
- `pis/` — loose config files/scripts used when provisioning Pis by hand.
- `scripts/` — standalone helper scripts (Raspbian image creation, a network
logger) that aren't Ansible roles.
- `archive/` — retired setups kept for reference (not actively maintained).
## Setup
```
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
```
Secrets are pulled from KeePassXC at run time via the `keepass` lookup
plugin — see the header of `lookup_plugins/keepass.py` for how to enable
Browser Integration in KeePassXC. Freshly-flashed Raspberry Pis are reached
first with the OS-default `pi`/`raspberry` credentials (see
`roles/pi_standard_setup`), which the role then rotates to a KeePassXC-managed
password.
## Running a playbook
```
ansible-playbook full.yml --limit <host>
```
`ansible.cfg` points Ansible at `inventory.yml` and `roles/` by default, so
no extra flags are needed for those.