mirror of
https://github.com/CPunch/openpunk-ansible.git
synced 2024-12-22 14:00:04 +00:00
Ansible project used for my production server for https://openpunk.com
CPunch
abaa4c9639
- all tasks/* have been moved to their own roles in roles/* - each file && template is now oragnized per-role - annotated each task which still isn't idempotent !TODO! |
||
---|---|---|
.github/workflows | ||
group_vars | ||
roles | ||
secrets@585d0fd7dd | ||
.gitignore | ||
.gitmodules | ||
README.md | ||
run.yml |
OpenPunk's Ansible playbook
This is my failsafe (and also my helpful migration tool) for restoring the OpenPunk server. This handles setting everything back up, including:
- gitea
- blog
- tor mirror
- nginx (for the above mentioned)
- my shell theme (zsh + powerlevel10k)
- deadswitch (& the ssh + git config to allow pushes)
This playbook assumes the target VPS is running the latest debian stable release.
Automatic deployment
On new release tags the playbook is automatically ran on the production openpunk vps. For more info checkout the .github/workflows/deploy.yaml
workflow
Notes to my future self
The deadswitch has the deadtrigger setup every run, so you have a 14-day timer to add a one-liner to your crontab to keep that deadtrigger set.
Usage
ansible-playbook -i hosts --ask-vault-pass run.yml
NOTE: The 'secrets' directory has been omitted from this repo (so it's not going to run without the provided files)
Example hosts file
[hosts]
openpunk-vps ansible_host=104.238.138.76 ansible_user=root ansible_connection=ssh