Compare commits

..

4 Commits

2 changed files with 34 additions and 6 deletions

View File

@ -2,6 +2,11 @@
allow_reboot: false allow_reboot: false
manage_network: false manage_network: false
# Import my GPG key for git signature verification
root_gpgkeys:
- name: kris@lamoureux.io
id: FBF673CEEC030F8AECA814E73EDA9C3441EDA925
# docker # docker
docker_users: docker_users:
- vagrant - vagrant
@ -10,6 +15,7 @@ docker_users:
#docker_login_user: myuser #docker_login_user: myuser
#docker_login_pass: YOUR_PASSWD #docker_login_pass: YOUR_PASSWD
docker_compose_env_nolog: false # dev only setting
docker_compose_deploy: docker_compose_deploy:
# Traefik # Traefik
- name: traefik - name: traefik
@ -17,9 +23,8 @@ docker_compose_deploy:
version: 31ee724feebc1d5f91cb17ffd6892c352537f194 version: 31ee724feebc1d5f91cb17ffd6892c352537f194
enabled: true enabled: true
accept_newhostkey: true # Consider verifying manually instead accept_newhostkey: true # Consider verifying manually instead
# Must manually add my public GPG key to root's keyring trusted_keys:
#trusted_keys: - FBF673CEEC030F8AECA814E73EDA9C3441EDA925
# - FBF673CEEC030F8AECA814E73EDA9C3441EDA925
env: env:
ENABLE: true ENABLE: true
@ -29,9 +34,8 @@ docker_compose_deploy:
version: 31ee724feebc1d5f91cb17ffd6892c352537f194 version: 31ee724feebc1d5f91cb17ffd6892c352537f194
enabled: true enabled: true
accept_newhostkey: true # Consider verifying manually instead accept_newhostkey: true # Consider verifying manually instead
# Must manually add my public GPG key to root's keyring trusted_keys:
#trusted_keys: - FBF673CEEC030F8AECA814E73EDA9C3441EDA925
# - FBF673CEEC030F8AECA814E73EDA9C3441EDA925
env: env:
ENABLE: true ENABLE: true
VERSION: "2.10" VERSION: "2.10"

View File

@ -9,6 +9,30 @@
name: gpg name: gpg
state: present state: present
- name: Check for existing GPG keys
command: "gpg --list-keys {{ item.id }} 2>/dev/null"
register: gpg_check
loop: "{{ root_gpgkeys }}"
failed_when: false
changed_when: false
when: root_gpgkeys is defined
- name: Import GPG keys
command: "gpg --keyserver {{ item.item.server | default('keys.openpgp.org') }} --recv-key {{ item.item.id }}"
register: gpg_check_import
loop: "{{ gpg_check.results }}"
loop_control:
label: "{{ item.item }}"
when: root_gpgkeys is defined and item.rc != 0
- name: Check GPG key imports
fail:
msg: "{{ item.stderr }}"
loop: "{{ gpg_check_import.results }}"
loop_control:
label: "{{ item.item.item }}"
when: (item.skipped | default(false) == false) and ('imported' not in item.stderr)
- name: Install NTPsec - name: Install NTPsec
ansible.builtin.apt: ansible.builtin.apt:
name: ntpsec name: ntpsec