- Auto-fix FQCN, YAML formatting, jinja spacing, and free-form module syntax via ansible-lint --fix - Fix comments misplaced inside module args by the auto-fixer (bluetooth-monitor, pi_standard_setup, pi_musicmouse) - Fix notify: references left stale (lowercase) after handler names were re-cased, which would have silently broken reboot/restart handlers (pi_disable_onboard_bluetooth, pi_hifiberry_amp, pi_squeezelite, pi_standard_setup) - Fix a task in pis/debmatic-install.yml missing its module name (apt_repository), which caused a real syntax-check failure - Add missing play names, fix comment spacing, literal-compare idiom, and no-changed-when annotations - Delete unused/broken roles/better-shell-env (unreferenced, invalid YAML) - Rename all hyphenated role directories to underscore form to satisfy ansible-lint's role-name rule, updating every playbook/meta reference Remaining lint findings (var-naming, package-latest, risky-file-permissions, no-handler) intentionally left for follow-up per user decision.
136 lines
4.1 KiB
YAML
136 lines
4.1 KiB
YAML
---
|
|
- name: Do apt update/upgrade
|
|
ansible.builtin.apt:
|
|
upgrade: "yes"
|
|
update_cache: "yes"
|
|
cache_valid_time: "7200"
|
|
- name: Detect Raspi Model
|
|
ansible.builtin.slurp:
|
|
src: /sys/firmware/devicetree/base/model
|
|
register: raspberry_model
|
|
- name: Show Raspi Model
|
|
ansible.builtin.debug:
|
|
msg: "{{ raspberry_model.content | b64decode }}"
|
|
- name: Add authorized SSH key to root account
|
|
ansible.posix.authorized_key:
|
|
user: root
|
|
key: "{{ lookup('file', 'sshkey.pub') }}"
|
|
state: present
|
|
- name: Activate root login with key
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/ssh/sshd_config
|
|
regexp: "^#?PermitRootLogin"
|
|
line: "PermitRootLogin prohibit-password"
|
|
notify: Restart sshd
|
|
- name: Deactive SSH accepting locale vars (leads to warnings)
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/ssh/sshd_config
|
|
regexp: "^#?AcceptEnv LANG LC_*"
|
|
line: "#AcceptEnv LANG LC_*"
|
|
notify: Restart sshd
|
|
- name: Get hostname
|
|
ansible.builtin.command: "raspi-config nonint get_hostname"
|
|
register: pi_hostname
|
|
changed_when: false
|
|
- name: Change hostname {{ new_hostname }}
|
|
ansible.builtin.command: "raspi-config nonint do_hostname {{ new_hostname }}"
|
|
when: new_hostname | bool and pi_hostname.stdout != new_hostname
|
|
register: set_hostname
|
|
changed_when: true
|
|
notify: Reboot
|
|
- name: Get hostname
|
|
ansible.builtin.command: "raspi-config nonint get_hostname"
|
|
register: pi_hostname
|
|
changed_when: false
|
|
- name: Set boot mode to CLI
|
|
ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1"
|
|
changed_when: true
|
|
# I2 Change Timezone
|
|
- name: Change timezone
|
|
ansible.builtin.command: "raspi-config nonint do_change_timezone {{ timezone }}"
|
|
changed_when: true
|
|
- name: Change locale
|
|
ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8"
|
|
changed_when: true
|
|
- name: Change password of default pi account
|
|
ansible.builtin.user:
|
|
name: pi
|
|
update_password: always
|
|
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}"
|
|
- name: Install Packages (vim, git, basic python stuff)
|
|
ansible.builtin.apt:
|
|
name:
|
|
- vim
|
|
- git
|
|
- python3
|
|
- python3-pip
|
|
- python3-wheel
|
|
- telnet
|
|
cache_valid_time: 7200
|
|
state: present
|
|
- name: Copy vim config
|
|
ansible.builtin.copy:
|
|
src: vimrc
|
|
dest: /root/.vimrc
|
|
- name: Copy git config
|
|
ansible.builtin.copy:
|
|
src: gitconfig
|
|
dest: /root/.gitconfig
|
|
# Wifi
|
|
- name: Get WiFi country
|
|
ansible.builtin.command: "raspi-config nonint get_wifi_country"
|
|
register: wifi_country
|
|
changed_when: false
|
|
ignore_errors: true # to avoid error when WiFi is not present
|
|
- name: Change WiFi country
|
|
ansible.builtin.command: "raspi-config nonint do_wifi_country {{ wifi_country }}"
|
|
when: configure_wifi
|
|
changed_when: true
|
|
- name: Set WiFi credentials
|
|
ansible.builtin.command: "raspi-config nonint do_wifi_ssid_passphrase {{ wifi_ssid }} {{ lookup('keepass', 'bauer_wifi') }}"
|
|
when: configure_wifi
|
|
changed_when: true
|
|
- name: Install watchdog
|
|
ansible.builtin.apt:
|
|
name: watchdog
|
|
cache_valid_time: "7200"
|
|
state: present
|
|
when: not wifi_ssid is defined
|
|
- name: Configure watchdog
|
|
ansible.builtin.blockinfile:
|
|
path: /etc/watchdog.conf
|
|
block: |
|
|
interface = wlan0
|
|
retry-timeout = 90
|
|
ping = {{ router_ip }}
|
|
interval = 15
|
|
when: configure_wifi
|
|
- name: Start watchdog
|
|
ansible.builtin.systemd: # state=restarted not working, also not manually
|
|
name: watchdog
|
|
state: started
|
|
enabled: "yes"
|
|
daemon_reload: "yes"
|
|
when: configure_wifi
|
|
# Message of the day
|
|
- name: Set Message of the day
|
|
ansible.builtin.copy:
|
|
src: motd/{{ pi_hostname.stdout }}
|
|
dest: /etc/motd
|
|
# LED off script
|
|
- name: Copy led off script
|
|
ansible.builtin.copy:
|
|
src: raspi-leds-off.sh
|
|
dest: /usr/sbin/raspi-leds-off.sh
|
|
mode: "u+rwx"
|
|
- name: Copy led off service
|
|
ansible.builtin.copy:
|
|
src: raspi-leds-off.service
|
|
dest: /lib/systemd/system/
|
|
- name: Activate led off servic
|
|
ansible.builtin.systemd:
|
|
name: raspi-leds-off
|
|
state: restarted
|
|
enabled: "yes"
|
|
daemon_reload: "yes"
|