- Jinja 71.2%
- Just 28.8%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
All checks were successful
CI / lint (push) Successful in 1m19s
Commented-out example, consistent with the Traefik ACME entries above it. See roles/galaxy/systemd_docker_base/defaults/main.yml for the rollout caveat (existing container networks aren't retroactively upgraded). |
||
| .forgejo/workflows | ||
| docs | ||
| examples | ||
| group_vars/slovo_servers | ||
| roles | ||
| .ansible-lint | ||
| .gitignore | ||
| .yamllint | ||
| ansible.cfg | ||
| justfile | ||
| README.md | ||
| renovate.json | ||
| requirements.yml | ||
| setup.yml | ||
slovo-propovedi-playbook
Ansible playbook for deploying the slovo-propovedi infrastructure services (PostgreSQL, PgBouncer, MinIO, Adminer, Traefik).
This playbook follows the matrix-docker-ansible-deploy pattern: every service runs in a Docker container managed by systemd, with Traefik as the reverse proxy in front of everything.
It provisions shared infrastructure only. The applications (backend API, admin SPA, docs site, landing site) deploy themselves from their own repositories via scripts/vps-deploy.sh on a v* tag, and expect this playbook to have run against the host first. See Deploying the applications.
Features
- PostgreSQL 18.4 — primary database
- PgBouncer — connection pooling in front of PostgreSQL
- MinIO — S3-compatible object storage
- Adminer — web-based database administration
- Traefik — reverse proxy with automatic Let's Encrypt certificates
- systemd-managed containers — each service runs as its own systemd unit
Prerequisites
- Ansible 2.16+ on the control machine
- just — the command runner used by the
justfile(see just). If you don't have it, you can run the rawansible-playbookcommands instead (see the note in the quick start below) - Docker on the target host
- Python 3 with the
bcryptmodule on the target host (required for admin user seeding)
Quick start
-
Clone this repository:
git clone <your-repo-url> slovo-propovedi-playbook cd slovo-propovedi-playbook -
Install the Galaxy roles:
just roles -
Create your configuration file:
mkdir -p inventory/host_vars/<your-host> cp examples/vars.yml inventory/host_vars/<your-host>/vars.ymlThen open
inventory/host_vars/<your-host>/vars.ymland fill in your domain names and secrets. -
Create your inventory file:
cp examples/hosts inventory/hostsThen edit
inventory/hostsand add your server to the[slovo_servers]group. -
Run the playbook to set everything up and start the services:
just setup-all -
Create the admin user (run separately, after the services are up):
just ensure-admin-user
Note
All commands above use
just(see thejustfile— runjustto list the available recipes). If you don't havejustinstalled, you can run the same steps with Ansible directly:ansible-galaxy role install -r requirements.yml -p roles/galaxy ansible-galaxy collection install -r requirements.yml ansible-playbook -i inventory/hosts setup.yml --tags=setup-all,start ansible-playbook -i inventory/hosts setup.yml --tags=ensure-slovo-users-created
Documentation
- Configuring the playbook
- Configuring Traefik
- Configuring backups — PostgreSQL dumps + NAS pull
- Deploying the applications — how the app repos deploy on top of this playbook
- VPS migration runbook — August 2026
License
AGPL-3.0