-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathconfigure-ubuntu.yml
253 lines (221 loc) · 6.82 KB
/
configure-ubuntu.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
- name: Configure Ubuntu
hosts: localhost
connection: local
gather_facts: true
tasks:
- name: Update apt repo and cache
apt:
update_cache: yes
force_apt_get: yes
- name: Upgrade all packages
apt:
upgrade: 'yes'
force_apt_get: yes
- name: Gather hostname
shell: hostname
register: hostname
- name: Gather current username
user:
name: "{{ ansible_facts['env']['SUDO_USER'] }}"
register: username
changed_when: False
- name: Update sudo config
lineinfile:
path: "/etc/sudoers.d/{{ username.name }}"
regexp: "^{{ username.name }}"
line: "{{ username.name }} ALL=(ALL:ALL) NOPASSWD:ALL"
create: true
- name: Install required packages
apt:
name:
- apt-transport-https
- jq
- bash
- ca-certificates
- curl
- gnupg-agent
- software-properties-common
- chrony
- zip
- unzip
- openssl
- net-tools
- tcpdump
- telnet
- nano
- gnupg
- lsb-release
- sshfs
- wget
- tar
- rsync
- rename
- bridge-utils
- nfs-common
state: present
force_apt_get: yes
- name: Remove unnecessary packages
apt:
name:
- ufw
- mdadm
- open-iscsi
- lxd
- lxd-client
- lxcfs
- liblxc-common
- popularity-contest
- ubuntu-standard
- ubuntu-advantage-tools
- landscape-common
state: absent
autoremove: yes
force_apt_get: yes
- name: Create NFS mount point
file:
path: /mnt/cluster-backup
state: directory
mode: '0755'
- name: Check if fstab entry exists for NFS mount
lineinfile:
path: /etc/fstab
regexp: '^192.168.10.40:/volume1/cluster-backup'
line: '192.168.10.40:/volume1/cluster-backup /mnt/cluster-backup nfs auto,defaults,nofail 0 0'
create: yes
- name: Mount the NFS share
shell: mount -a
register: mount_result
- name: Verify NFS mount
shell: df -h | grep "/mnt/cluster-backup"
register: nfs_mount_check
changed_when: nfs_mount_check.stdout == ""
failed_when: nfs_mount_check.stdout == ""
- name: Check for docker gpg key
stat:
path: /usr/share/keyrings/docker-archive-keyring.gpg
register: docker_gpg_key
- name: Install docker gpg key
shell: curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
when: not docker_gpg_key.stat.exists
args:
warn: false
- name: Check for docker repo source definition
stat:
path: /etc/apt/sources.list.d/docker.list
register: docker_src_list
- name: Add Docker Repository
shell: echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
when: not docker_src_list.stat.exists
args:
warn: false
- name: Update apt and install docker-ce
apt:
update_cache: yes
name:
- docker-ce
- docker-ce-cli
- containerd.io
state: present
force_apt_get: yes
- name: Create '/etc/docker'
ansible.builtin.file:
path: /etc/docker
state: directory
mode: '0755'
- name: Configure Docker logging limits
copy:
dest: /etc/docker/daemon.json
content: |
{
"log-driver": "json-file",
"log-opts": {
"max-size": "10m",
"max-file": "10"
}
}
register: docker_daemon_json
- name: Restart Docker to apply new config
shell: systemctl restart docker
when: docker_daemon_json.changed
args:
warn: false
- name: Get Docker compose version (latest release)
uri:
url: https://github.com/docker/compose/releases/latest
register: latest_compose
- name: Download Docker compose module (latest release)
get_url:
url: "{{ latest_compose.url | replace('/tag/','/download/') }}/docker-compose-linux-x86_64"
dest: /usr/libexec/docker/cli-plugins/docker-compose
mode: '755'
- name: Create /docker
file:
path: /docker
state: directory
mode: '0755'
- name: Create /docker/services
file:
path: /docker/services
state: directory
mode: '0755'
- name: Write Dozzle Docker Compose service file
copy:
dest: /docker/services/dozzle.yml
content: |
version: '3.9'
services:
dozzle:
container_name: dozzle
image: amir20/dozzle:latest
volumes:
- /var/run/docker.sock:/var/run/docker.sock
ports:
- 8080:8080
restart: unless-stopped
mode: '0644'
- name: Write top-level Docker Compose file
copy:
dest: /docker/docker-compose.yaml
content: |
services:
dozzle:
extends:
file: ./services/dozzle.yml
service: dozzle
mode: '0644'
- name: Enable separate cron logging
lineinfile:
path: /etc/rsyslog.d/50-default.conf
regexp: '^#cron.*'
line: 'cron.* /var/log/cron.log'
register: cron_log_config
- name: Reload rsyslog daemon configurations
shell: systemctl restart rsyslog.service
when: cron_log_config.changed
- name: Create app interface systemd unit file
copy:
dest: /etc/systemd/system/appif.service
content: |
[Unit]
Description=Service to bring up/down app interface
After=network.target
[Service]
Type=oneshot
RemainAfterExit=yes
ExecStart=/bin/sh -c "/sbin/ip link add name app type dummy 2> /dev/null || true; \
/sbin/ip addr add 169.254.254.254/24 dev app; \
/sbin/ip link set app up 2> /dev/null || true"
ExecStop=/sbin/ip link set app down
[Install]
WantedBy=multi-user.target
mode: '0444'
register: appif_service
- name: Reload system daemon configurations
shell: systemctl daemon-reload
when: appif_service.changed
- name: Enable app interface service
shell: systemctl enable appif
when: appif_service.changed
- name: Enable app interface service
shell: systemctl start appif
when: appif_service.changed