No description
  • Jinja 71.2%
  • Just 28.8%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
egoreast c0932400d7
All checks were successful
CI / lint (push) Successful in 1m19s
docs(vars): document devture_systemd_docker_base_ipv6_enabled
Commented-out example, consistent with the Traefik ACME entries above
it. See roles/galaxy/systemd_docker_base/defaults/main.yml for the
rollout caveat (existing container networks aren't retroactively
upgraded).
2026-09-15 22:46:12 +03:00
.forgejo/workflows ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
docs ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
examples docs(vars): document devture_systemd_docker_base_ipv6_enabled 2026-09-15 22:46:12 +03:00
group_vars/slovo_servers ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
roles ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
.ansible-lint ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
.gitignore ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
.yamllint ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
ansible.cfg add: ansible.cfg with sensible defaults for the playbook 2026-08-03 17:16:35 +03:00
justfile ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
README.md ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
renovate.json chore(renovate): use forgejo platform, drop redundant requirements.yml manager 2026-09-08 13:39:49 +03:00
requirements.yml ci: add lint/dry-run workflow and declare missing collections 2026-09-15 16:33:42 +03:00
setup.yml feat: automated postgres and minio backups to NAS 2026-09-10 12:24:54 +03:00

slovo-propovedi-playbook

Ansible playbook for deploying the slovo-propovedi infrastructure services (PostgreSQL, PgBouncer, MinIO, Adminer, Traefik).

This playbook follows the matrix-docker-ansible-deploy pattern: every service runs in a Docker container managed by systemd, with Traefik as the reverse proxy in front of everything.

It provisions shared infrastructure only. The applications (backend API, admin SPA, docs site, landing site) deploy themselves from their own repositories via scripts/vps-deploy.sh on a v* tag, and expect this playbook to have run against the host first. See Deploying the applications.

Features

  • PostgreSQL 18.4 — primary database
  • PgBouncer — connection pooling in front of PostgreSQL
  • MinIO — S3-compatible object storage
  • Adminer — web-based database administration
  • Traefik — reverse proxy with automatic Let's Encrypt certificates
  • systemd-managed containers — each service runs as its own systemd unit

Prerequisites

  • Ansible 2.16+ on the control machine
  • just — the command runner used by the justfile (see just). If you don't have it, you can run the raw ansible-playbook commands instead (see the note in the quick start below)
  • Docker on the target host
  • Python 3 with the bcrypt module on the target host (required for admin user seeding)

Quick start

  1. Clone this repository:

    git clone <your-repo-url> slovo-propovedi-playbook
    cd slovo-propovedi-playbook
    
  2. Install the Galaxy roles:

    just roles
    
  3. Create your configuration file:

    mkdir -p inventory/host_vars/<your-host>
    cp examples/vars.yml inventory/host_vars/<your-host>/vars.yml
    

    Then open inventory/host_vars/<your-host>/vars.yml and fill in your domain names and secrets.

  4. Create your inventory file:

    cp examples/hosts inventory/hosts
    

    Then edit inventory/hosts and add your server to the [slovo_servers] group.

  5. Run the playbook to set everything up and start the services:

    just setup-all
    
  6. Create the admin user (run separately, after the services are up):

    just ensure-admin-user
    

Note

All commands above use just (see the justfile — run just to list the available recipes). If you don't have just installed, you can run the same steps with Ansible directly:

ansible-galaxy role install -r requirements.yml -p roles/galaxy
ansible-galaxy collection install -r requirements.yml
ansible-playbook -i inventory/hosts setup.yml --tags=setup-all,start
ansible-playbook -i inventory/hosts setup.yml --tags=ensure-slovo-users-created

Documentation

License

AGPL-3.0