Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1714c0c7c6 |
@@ -6,4 +6,3 @@
|
|||||||
- role: studio.ansible.base
|
- role: studio.ansible.base
|
||||||
- role: studio.ansible.users
|
- role: studio.ansible.users
|
||||||
- role: studio.ansible.security
|
- role: studio.ansible.security
|
||||||
- role: dokploy
|
|
||||||
|
|||||||
@@ -1,14 +0,0 @@
|
|||||||
---
|
|
||||||
# Official Dokploy installer
|
|
||||||
dokploy_installer_url: "https://dokploy.com/install.sh"
|
|
||||||
dokploy_installer_path: "/usr/local/bin/dokploy-install.sh"
|
|
||||||
|
|
||||||
# Pin to a specific release tag for reproducible installs
|
|
||||||
dokploy_version: "latest"
|
|
||||||
|
|
||||||
# Packages the installer expects on a minimal Debian image
|
|
||||||
# dokploy_prerequisites:
|
|
||||||
# - ca-certificates
|
|
||||||
# - curl
|
|
||||||
# - openssl
|
|
||||||
# - iproute2
|
|
||||||
@@ -1,33 +0,0 @@
|
|||||||
---
|
|
||||||
# - name: Install Dokploy prerequisites
|
|
||||||
# ansible.builtin.apt:
|
|
||||||
# name: "{{ dokploy_prerequisites }}"
|
|
||||||
# state: present
|
|
||||||
# update_cache: true
|
|
||||||
|
|
||||||
- name: Download Dokploy installer
|
|
||||||
ansible.builtin.get_url:
|
|
||||||
url: "{{ dokploy_installer_url }}"
|
|
||||||
dest: "{{ dokploy_installer_path }}"
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
# The upstream installer is not idempotent & exits non-zero if the swarm is already initialized. Guard on the presence of the dokploy swarm service
|
|
||||||
- name: Check if Dokploy is already installed
|
|
||||||
ansible.builtin.command: docker service inspect dokploy
|
|
||||||
register: dokploy_installed
|
|
||||||
changed_when: false
|
|
||||||
failed_when: false
|
|
||||||
|
|
||||||
- name: Install Dokploy
|
|
||||||
ansible.builtin.command: "{{ dokploy_installer_path }}"
|
|
||||||
environment:
|
|
||||||
DOKPLOY_VERSION: "{{ dokploy_version }}"
|
|
||||||
changed_when: true
|
|
||||||
when: dokploy_installed.rc != 0
|
|
||||||
|
|
||||||
# - name: Update Dokploy (opt-in)
|
|
||||||
# ansible.builtin.command: "{{ dokploy_installer_path }} update"
|
|
||||||
# environment:
|
|
||||||
# DOKPLOY_VERSION: "{{ dokploy_version }}"
|
|
||||||
# changed_when: true
|
|
||||||
# when: dokploy_installed.rc == 0
|
|
||||||
+2
-4
@@ -10,9 +10,7 @@ resource "hcloud_server" "dokploy" {
|
|||||||
image = var.hcloud_image
|
image = var.hcloud_image
|
||||||
server_type = var.hcloud_server_type
|
server_type = var.hcloud_server_type
|
||||||
location = var.hcloud_location
|
location = var.hcloud_location
|
||||||
user_data = templatefile("${path.module}/templates/user_data.tpl", {
|
ssh_keys = [hcloud_ssh_key.ansible.id]
|
||||||
ssh_public_key = var.ssh_public_key
|
|
||||||
})
|
|
||||||
firewall_ids = [hcloud_firewall.host.id]
|
firewall_ids = [hcloud_firewall.host.id]
|
||||||
|
|
||||||
public_net {
|
public_net {
|
||||||
@@ -78,7 +76,7 @@ resource "cloudflare_dns_record" "subdomain" {
|
|||||||
|
|
||||||
# Write IP to Ansible inventory
|
# Write IP to Ansible inventory
|
||||||
resource "local_file" "ansible_inventory" {
|
resource "local_file" "ansible_inventory" {
|
||||||
content = templatefile("${path.module}/templates/ansible_inventory.tpl", {
|
content = templatefile("${path.module}/../ansible/inventory.tpl", {
|
||||||
public_ip = local.public_ip
|
public_ip = local.public_ip
|
||||||
})
|
})
|
||||||
filename = "${path.module}/../ansible/inventory.ini"
|
filename = "${path.module}/../ansible/inventory.ini"
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
# cloud-config
|
|
||||||
users:
|
|
||||||
- name: ansible
|
|
||||||
sudo: ALL=(ALL) NOPASSWD:ALL
|
|
||||||
shell: /bin/bash
|
|
||||||
ssh_authorized_keys:
|
|
||||||
- ${ssh_public_key}
|
|
||||||
ssh_pwauth: false
|
|
||||||
disable_root: true
|
|
||||||
@@ -4,6 +4,7 @@ hcloud_server_type = "cx23"
|
|||||||
hcloud_image = "debian-13"
|
hcloud_image = "debian-13"
|
||||||
hcloud_location = "nbg1"
|
hcloud_location = "nbg1"
|
||||||
|
|
||||||
|
record_name = "@"
|
||||||
cloudflare_proxied = true
|
cloudflare_proxied = true
|
||||||
|
|
||||||
# Note: Use file() to easily read your local SSH public key
|
# Note: Use file() to easily read your local SSH public key
|
||||||
|
|||||||
@@ -45,6 +45,12 @@ variable "domain_name" {
|
|||||||
description = "Cloudflare zone (apex domain) in which to create the A record"
|
description = "Cloudflare zone (apex domain) in which to create the A record"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
variable "record_name" {
|
||||||
|
type = string
|
||||||
|
description = "DNS record name relative to the zone; use \"@\" for the apex"
|
||||||
|
default = "dokploy"
|
||||||
|
}
|
||||||
|
|
||||||
variable "cloudflare_proxied" {
|
variable "cloudflare_proxied" {
|
||||||
type = bool
|
type = bool
|
||||||
description = "Whether Cloudflare should proxy (orange-cloud) the A record"
|
description = "Whether Cloudflare should proxy (orange-cloud) the A record"
|
||||||
|
|||||||
Reference in New Issue
Block a user