Files
ansible/roles/pi_standard_setup/tasks/main.yml
Martin Bauer f043606466 Add deliberate update playbook and unattended-upgrades role
Regular playbooks now use state: present, so they no longer upgrade
packages as a side effect. This adds two separate, explicit mechanisms
to keep the fleet patched instead:

- update-packages.yml: ad hoc / to-be-scheduled fleet-wide upgrade
  (safe by default, dist available via -e), plus
  update-packages-pinned-example.yml as a template for pinning or
  bumping a single package outside that.
- roles/unattended_upgrades: automatic security-only patching via
  unattended-upgrades, with a scheduled reboot window and mail
  left disabled pending a configured MTA. Applied to every host in
  full.yml and server.yml.

Also removes a leftover `upgrade: yes` apt task from pi_standard_setup
and server_basic_environment that was still doing a full upgrade on
every routine run, defeating the point of the state: present switch.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 18:02:41 +02:00

139 lines
4.4 KiB
YAML

---
- name: Refresh apt cache
ansible.builtin.apt:
update_cache: "yes"
cache_valid_time: "7200"
- name: Detect Raspi Model
ansible.builtin.slurp:
src: /sys/firmware/devicetree/base/model
register: pi_standard_setup_raspberry_model
- name: Show Raspi Model
ansible.builtin.debug:
msg: "{{ pi_standard_setup_raspberry_model.content | b64decode }}"
- name: Add authorized SSH key to root account
ansible.posix.authorized_key:
user: root
key: "{{ lookup('file', 'sshkey.pub') }}"
state: present
- name: Activate root login with key
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "^#?PermitRootLogin"
line: "PermitRootLogin prohibit-password"
notify: Restart sshd
- name: Deactive SSH accepting locale vars (leads to warnings)
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "^#?AcceptEnv LANG LC_*"
line: "#AcceptEnv LANG LC_*"
notify: Restart sshd
- name: Get hostname
ansible.builtin.command: "raspi-config nonint get_hostname"
register: pi_standard_setup_pi_hostname
changed_when: false
- name: Change hostname {{ pi_standard_setup_new_hostname }}
ansible.builtin.command: "raspi-config nonint do_hostname {{ pi_standard_setup_new_hostname }}"
when: pi_standard_setup_new_hostname | bool and pi_standard_setup_pi_hostname.stdout != pi_standard_setup_new_hostname
register: pi_standard_setup_set_hostname
changed_when: true
notify: Reboot
- name: Get hostname
ansible.builtin.command: "raspi-config nonint get_hostname"
register: pi_standard_setup_pi_hostname
changed_when: false
- name: Set boot mode to CLI
ansible.builtin.command: "raspi-config nonint do_boot_behaviour B1"
changed_when: true
# I2 Change Timezone
- name: Change timezone
ansible.builtin.command: "raspi-config nonint do_change_timezone {{ pi_standard_setup_timezone }}"
changed_when: true
- name: Change locale
ansible.builtin.command: "raspi-config nonint do_change_locale en_US.UTF-8"
changed_when: true
- name: Change password of default pi account
ansible.builtin.user:
name: pi
update_password: always
password: "{{ lookup('keepass', 'ansible://default_rpi_password') | password_hash('sha512') }}"
- name: Install Packages (vim, git, basic python stuff)
ansible.builtin.apt:
name:
- vim
- git
- python3
- python3-pip
- python3-wheel
- telnet
cache_valid_time: 7200
state: present
- name: Copy vim config
ansible.builtin.copy:
src: vimrc
dest: /root/.vimrc
mode: "0644"
- name: Copy git config
ansible.builtin.copy:
src: gitconfig
dest: /root/.gitconfig
mode: "0644"
# Wifi
- name: Get WiFi country
ansible.builtin.command: "raspi-config nonint get_wifi_country"
register: pi_standard_setup_current_wifi_country
changed_when: false
ignore_errors: true # to avoid error when WiFi is not present
- name: Change WiFi country
ansible.builtin.command: "raspi-config nonint do_wifi_country {{ pi_standard_setup_wifi_country }}"
when: configure_wifi
changed_when: true
- name: Set WiFi credentials
ansible.builtin.command: "raspi-config nonint do_wifi_ssid_passphrase {{ pi_standard_setup_wifi_ssid }} {{ lookup('keepass', 'bauer_wifi') }}"
when: configure_wifi
changed_when: true
- name: Install watchdog
ansible.builtin.apt:
name: watchdog
cache_valid_time: "7200"
state: present
when: not pi_standard_setup_wifi_ssid is defined
- name: Configure watchdog
ansible.builtin.blockinfile:
path: /etc/watchdog.conf
block: |
interface = wlan0
retry-timeout = 90
ping = {{ router_ip }}
interval = 15
when: configure_wifi
- name: Start watchdog
ansible.builtin.systemd: # state=restarted not working, also not manually
name: watchdog
state: started
enabled: "yes"
daemon_reload: "yes"
when: configure_wifi
# Message of the day
- name: Set Message of the day
ansible.builtin.copy:
src: motd/{{ pi_standard_setup_pi_hostname.stdout }}
dest: /etc/motd
mode: "0644"
# LED off script
- name: Copy led off script
ansible.builtin.copy:
src: raspi-leds-off.sh
dest: /usr/sbin/raspi-leds-off.sh
mode: "u+rwx"
- name: Copy led off service
ansible.builtin.copy:
src: raspi-leds-off.service
dest: /lib/systemd/system/
mode: "0644"
- name: Activate led off servic
ansible.builtin.systemd:
name: raspi-leds-off
state: restarted
enabled: "yes"
daemon_reload: "yes"