servers/roles/alpine/tasks/main.yml

107 lines
2.1 KiB
YAML
Raw Normal View History

- name: Tell ifupdown to rename network interfaces
copy:
dest: /etc/network/if-pre-up.d/nameif
content: |
#!/bin/sh
nameif -s
mode: 0755
notify: restart networking
- name: Configure interface names
template:
dest: /etc/mactab
src: mactab.j2
mode: 0644
notify: restart networking
2024-06-24 22:40:13 +00:00
- name: Set up network interfaces
template:
dest: /etc/network/interfaces
src: interfaces.j2
notify: restart networking
2024-07-04 12:55:09 +00:00
- meta: flush_handlers
- name: Set hostname
hostname:
name: '{{ dns_name }}'
- name: Configure hosts
template:
dest: /etc/hosts
src: hosts.j2
- name: Enable community package repo
lineinfile:
path: /etc/apk/repositories
regexp: '^# *(http.*/v[^/]*/community)'
line: '\1'
backrefs: yes
notify: update package cache
- meta: flush_handlers
- name: Install base packages
package:
name:
2024-06-24 22:40:13 +00:00
- acl
- git
- iproute2
2024-06-17 07:52:56 +00:00
- logrotate
2024-05-28 10:52:59 +00:00
- nftables
- procps
- rsync
- tmux
- vim
- name: Disable SSH password authentication
lineinfile:
path: /etc/ssh/sshd_config
regexp: '^#?{{ item.key }}'
line: '{{ item.key }} {{ item.value }}'
loop:
- key: PasswordAuthentication
value: 'no'
- key: PermitRootLogin
value: 'prohibit-password'
notify: reload sshd
- name: Set up firewall
template:
dest: /etc/nftables.d/local.nft
src: local.nft.j2
notify: reload nftables
- name: Enable firewall
service:
name: nftables
enabled: yes
state: started
2024-07-04 12:55:09 +00:00
- meta: flush_handlers
- name: Enable QEMU guest agent
when: is_virtual
block:
- name: Install QEMU guest agent package
package:
name: qemu-guest-agent
- name: Enable QEMU guest agent service
service:
name: qemu-guest-agent
enabled: yes
state: started
2024-06-17 07:52:56 +00:00
- name: Install automatic upgrade script
copy:
dest: /etc/periodic/weekly/
src: unattended-upgrade
mode: 0755
- name: Configure log rotation for automatic upgrades
copy:
dest: /etc/logrotate.d/unattended-upgrade
src: unattended-upgrade.logrotate
mode: 0644