homelab/roles/gitea/tasks/main.yml

112 lines
2.4 KiB
YAML
Raw Permalink Normal View History

- name: Create Gitea directory
file:
path: "{{ gitea_root }}"
state: directory
2020-07-28 03:20:50 +00:00
- name: Create Gitea database
2022-08-12 01:04:07 +00:00
mysql_db:
2020-07-28 03:20:50 +00:00
name: "{{ gitea_dbname }}"
2022-08-12 01:04:07 +00:00
state: present
login_unix_socket: /var/run/mysqld/mysqld.sock
2020-07-28 03:20:50 +00:00
- name: Create Gitea database user
2022-08-12 01:04:07 +00:00
mysql_user:
name: "{{ gitea_dbuser }}"
password: "{{ gitea_dbpass }}"
2022-08-12 01:04:07 +00:00
host: '%'
state: present
priv: "{{ gitea_dbname }}.*:ALL"
login_unix_socket: /var/run/mysqld/mysqld.sock
2022-05-27 06:28:51 +00:00
- name: Create git user
user:
name: git
state: present
- name: Git user uid
getent:
database: passwd
key: git
- name: Git user gid
getent:
database: group
key: git
- name: Create git's .ssh directory
file:
path: /home/git/.ssh
state: directory
- name: Generate git's SSH keys
openssh_keypair:
path: /home/git/.ssh/id_rsa
- name: Find git's public SSH key
slurp:
src: /home/git/.ssh/id_rsa.pub
register: git_rsapub
2022-05-28 03:14:06 +00:00
- name: Get stats on git's authorized_keys file
stat:
path: /home/git/.ssh/authorized_keys
register: git_authkeys
2022-05-27 06:28:51 +00:00
- name: Create git's authorized_keys file
file:
path: /home/git/.ssh/authorized_keys
state: touch
2022-05-28 03:14:06 +00:00
when: not git_authkeys.stat.exists
2022-05-27 06:28:51 +00:00
- name: Add git's public SSH key to authorized_keys
lineinfile:
path: /home/git/.ssh/authorized_keys
2022-05-28 03:14:06 +00:00
regex: "^ssh-rsa"
2022-05-27 06:28:51 +00:00
line: "{{ git_rsapub['content'] | b64decode }}"
- name: Create Gitea host script for SSH
template:
src: gitea.sh.j2
dest: /usr/local/bin/gitea
mode: 0755
- name: Install Gitea's docker-compose file
template:
src: docker-compose.yml.j2
dest: "{{ gitea_root }}/docker-compose.yml"
notify: restart_gitea
- name: Install Gitea's docker-compose variables
template:
src: compose-env.j2
dest: "{{ gitea_root }}/.env"
notify: restart_gitea
2022-05-22 04:19:56 +00:00
2022-06-07 04:25:47 +00:00
- name: Create Gitea's logging directory
file:
name: /var/log/gitea
state: directory
- name: Create Gitea's initial log file
file:
name: /var/log/gitea/gitea.log
state: touch
2022-05-28 06:31:41 +00:00
- name: Install Gitea's Fail2ban filter
template:
src: fail2ban-filter.conf.j2
dest: /etc/fail2ban/filter.d/gitea.conf
notify: restart_fail2ban
- name: Install Gitea's Fail2ban jail
template:
src: fail2ban-jail.conf.j2
dest: /etc/fail2ban/jail.d/gitea.conf
notify: restart_fail2ban
- name: Start and enable Gitea service
service:
name: "{{ docker_compose_service }}@{{ gitea_name }}"
2022-05-22 04:19:56 +00:00
state: started
enabled: true