feat: provision ansible user with terraform #1
@@ -1,5 +1,5 @@
|
|||||||
---
|
---
|
||||||
ansible_user: "ansible"
|
ansible_user: "root"
|
||||||
|
|
||||||
sysadmin_user: "alessandrovitali"
|
sysadmin_user: "alessandrovitali"
|
||||||
sysadmin_public_ssh_key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAm/J+9YG+odym9In9C4iLcrfXlrlPK2TygtI7lBNNpl"
|
sysadmin_public_ssh_key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAm/J+9YG+odym9In9C4iLcrfXlrlPK2TygtI7lBNNpl"
|
||||||
|
|||||||
@@ -6,3 +6,4 @@
|
|||||||
- role: studio.ansible.base
|
- role: studio.ansible.base
|
||||||
- role: studio.ansible.users
|
- role: studio.ansible.users
|
||||||
- role: studio.ansible.security
|
- role: studio.ansible.security
|
||||||
|
- role: dokploy
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
# Official Dokploy installer
|
||||||
|
dokploy_installer_url: "https://dokploy.com/install.sh"
|
||||||
|
dokploy_installer_path: "/usr/local/bin/dokploy-install.sh"
|
||||||
|
|
||||||
|
# Pin to a specific release tag for reproducible installs
|
||||||
|
dokploy_version: "latest"
|
||||||
|
|
||||||
|
# Packages the installer expects on a minimal Debian image
|
||||||
|
# dokploy_prerequisites:
|
||||||
|
# - ca-certificates
|
||||||
|
# - curl
|
||||||
|
# - openssl
|
||||||
|
# - iproute2
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
---
|
||||||
|
# - name: Install Dokploy prerequisites
|
||||||
|
# ansible.builtin.apt:
|
||||||
|
# name: "{{ dokploy_prerequisites }}"
|
||||||
|
# state: present
|
||||||
|
# update_cache: true
|
||||||
|
|
||||||
|
- name: Download Dokploy installer
|
||||||
|
ansible.builtin.get_url:
|
||||||
|
url: "{{ dokploy_installer_url }}"
|
||||||
|
dest: "{{ dokploy_installer_path }}"
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
|
# The upstream installer is not idempotent & exits non-zero if the swarm is already initialized. Guard on the presence of the dokploy swarm service
|
||||||
|
- name: Check if Dokploy is already installed
|
||||||
|
ansible.builtin.command: docker service inspect dokploy
|
||||||
|
register: dokploy_installed
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: Install Dokploy
|
||||||
|
ansible.builtin.command: "{{ dokploy_installer_path }}"
|
||||||
|
environment:
|
||||||
|
DOKPLOY_VERSION: "{{ dokploy_version }}"
|
||||||
|
changed_when: true
|
||||||
|
when: dokploy_installed.rc != 0
|
||||||
|
|
||||||
|
# - name: Update Dokploy (opt-in)
|
||||||
|
# ansible.builtin.command: "{{ dokploy_installer_path }} update"
|
||||||
|
# environment:
|
||||||
|
# DOKPLOY_VERSION: "{{ dokploy_version }}"
|
||||||
|
# changed_when: true
|
||||||
|
# when: dokploy_installed.rc == 0
|
||||||
+11
-2
@@ -58,9 +58,18 @@ locals {
|
|||||||
}
|
}
|
||||||
|
|
||||||
# Publish the VPS IP as a Cloudflare A record
|
# Publish the VPS IP as a Cloudflare A record
|
||||||
resource "cloudflare_dns_record" "a" {
|
resource "cloudflare_dns_record" "domain" {
|
||||||
zone_id = data.cloudflare_zone.zone.id
|
zone_id = data.cloudflare_zone.zone.id
|
||||||
name = var.record_name
|
name = "@"
|
||||||
|
type = "A"
|
||||||
|
content = local.public_ip
|
||||||
|
proxied = var.cloudflare_proxied
|
||||||
|
ttl = var.cloudflare_proxied ? 1 : 3600
|
||||||
|
}
|
||||||
|
|
||||||
|
resource "cloudflare_dns_record" "subdomain" {
|
||||||
|
zone_id = data.cloudflare_zone.zone.id
|
||||||
|
name = "*"
|
||||||
type = "A"
|
type = "A"
|
||||||
content = local.public_ip
|
content = local.public_ip
|
||||||
proxied = var.cloudflare_proxied
|
proxied = var.cloudflare_proxied
|
||||||
|
|||||||
@@ -4,7 +4,6 @@ hcloud_server_type = "cx23"
|
|||||||
hcloud_image = "debian-13"
|
hcloud_image = "debian-13"
|
||||||
hcloud_location = "nbg1"
|
hcloud_location = "nbg1"
|
||||||
|
|
||||||
record_name = "dokploy"
|
|
||||||
cloudflare_proxied = true
|
cloudflare_proxied = true
|
||||||
|
|
||||||
# Note: Use file() to easily read your local SSH public key
|
# Note: Use file() to easily read your local SSH public key
|
||||||
|
|||||||
@@ -45,12 +45,6 @@ variable "domain_name" {
|
|||||||
description = "Cloudflare zone (apex domain) in which to create the A record"
|
description = "Cloudflare zone (apex domain) in which to create the A record"
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "record_name" {
|
|
||||||
type = string
|
|
||||||
description = "DNS record name relative to the zone; use \"@\" for the apex"
|
|
||||||
default = "dokploy"
|
|
||||||
}
|
|
||||||
|
|
||||||
variable "cloudflare_proxied" {
|
variable "cloudflare_proxied" {
|
||||||
type = bool
|
type = bool
|
||||||
description = "Whether Cloudflare should proxy (orange-cloud) the A record"
|
description = "Whether Cloudflare should proxy (orange-cloud) the A record"
|
||||||
|
|||||||
Reference in New Issue
Block a user