From 79af417b4f99330f101aa4789a4e1fa23ddd2ff4 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:02:01 +0200 Subject: [PATCH 01/13] homeassistant: Create empty role for further development --- roles/homeassistant/meta/main.yml | 11 +++++++++++ roles/homeassistant/tasks/main.yml | 1 + site.yml | 5 +++++ 3 files changed, 17 insertions(+) create mode 100644 roles/homeassistant/meta/main.yml create mode 100644 roles/homeassistant/tasks/main.yml diff --git a/roles/homeassistant/meta/main.yml b/roles/homeassistant/meta/main.yml new file mode 100644 index 0000000..eb29279 --- /dev/null +++ b/roles/homeassistant/meta/main.yml @@ -0,0 +1,11 @@ +--- + +galaxy_info: + author: Thomas Basler + description: Install HomeAssistant environment + license: None + platforms: + - name: Debian + min_ansible_version: "2.4" + +dependencies: [] diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml new file mode 100644 index 0000000..ed97d53 --- /dev/null +++ b/roles/homeassistant/tasks/main.yml @@ -0,0 +1 @@ +--- diff --git a/site.yml b/site.yml index fe1f123..25493a8 100644 --- a/site.yml +++ b/site.yml @@ -172,3 +172,8 @@ hosts: barium.binary-kitchen.net roles: - workadventure + +- name: Setup HomeAssistant server + hosts: lasagne.binary.kitchen + roles: + - homeassistant \ No newline at end of file -- 2.39.5 From 42538dc0190ffea5e74bd5adbec739bb1b7953f1 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:09:02 +0200 Subject: [PATCH 02/13] mosquitto: Add role to install and configure mosquitto --- roles/mosquitto/README.md | 4 ++ roles/mosquitto/defaults/main.yml | 46 +++++++++++++++++++ .../filter_plugins/mosquitto_passwd.py | 34 ++++++++++++++ roles/mosquitto/handlers/main.yml | 6 +++ roles/mosquitto/meta/main.yml | 11 +++++ roles/mosquitto/tasks/main.yml | 35 ++++++++++++++ roles/mosquitto/templates/acl.j2 | 28 +++++++++++ roles/mosquitto/templates/mosquitto.conf.j2 | 36 +++++++++++++++ roles/mosquitto/templates/users.j2 | 5 ++ 9 files changed, 205 insertions(+) create mode 100644 roles/mosquitto/README.md create mode 100644 roles/mosquitto/defaults/main.yml create mode 100644 roles/mosquitto/filter_plugins/mosquitto_passwd.py create mode 100644 roles/mosquitto/handlers/main.yml create mode 100644 roles/mosquitto/meta/main.yml create mode 100644 roles/mosquitto/tasks/main.yml create mode 100644 roles/mosquitto/templates/acl.j2 create mode 100644 roles/mosquitto/templates/mosquitto.conf.j2 create mode 100644 roles/mosquitto/templates/users.j2 diff --git a/roles/mosquitto/README.md b/roles/mosquitto/README.md new file mode 100644 index 0000000..ce8e5a4 --- /dev/null +++ b/roles/mosquitto/README.md @@ -0,0 +1,4 @@ +Ansible Role: Mosquitto +========= + +Install and configure [Mosquitto](https://mosquitto.org/) MQTT message broker. diff --git a/roles/mosquitto/defaults/main.yml b/roles/mosquitto/defaults/main.yml new file mode 100644 index 0000000..c833435 --- /dev/null +++ b/roles/mosquitto/defaults/main.yml @@ -0,0 +1,46 @@ +--- + +mosquitto_packages: + - mosquitto + - mosquitto-clients + +mosquitto_listeners: + # Listeners for Mosquitto MQTT Broker + - name: "default" + listener: "1883 localhost" + protocol: "mqtt" + use_username_as_clientid: "true" + allow_zero_length_clientid: "true" + allow_anonymous: "false" + users: [] + # Users for Mosquitto MQTT Broker + # Type: Arrays of Objects with following parameters defined: + # - username: + # password: + # acl: of Objects as follows: + # - permissions: Acceptable Value: either `read`, `readwrite`, `write`, `deny` + # - topic: Acceptable Value: your/mqtt/topic (wildcards `+`, and `*` allowed) + auth_anonymous: [] + # Topics which are accessable with anonymous access + # Example + # - "topic read topic_name" + auth_patterns: [] + # %c to match the client id of the client + # %u to match the username of the client + # Example + # - "pattern write $SYS/broker/connection/%c/state" + +mosquitto_bridges: [] + # Bridges for Mosquitto MQTT Broker + # Type: Arrays of Objects with following parameters defined: + # - connection: + # address: + # bridge_insecure: + # bridge_capath: + # remote_password: + # remote_username: + # remote_clientid: + # try_private: + # topics: + # - topic: # in 0 down/ to-level/02/line/ + # - topic: # out 0 up/ from-level/02/line/ diff --git a/roles/mosquitto/filter_plugins/mosquitto_passwd.py b/roles/mosquitto/filter_plugins/mosquitto_passwd.py new file mode 100644 index 0000000..3b2b8aa --- /dev/null +++ b/roles/mosquitto/filter_plugins/mosquitto_passwd.py @@ -0,0 +1,34 @@ +# mosquitto_passwd.py: Custom Jinja2 filter plugin to generate valid PBKDF2_SHA512 +# hash digests for plain-text passwords in `users` file for +# Eclipse Mosquitto Broker + + +from ansible.errors import AnsibleError + + +def mosquitto_passwd(passwd): + try: + import passlib.hash + except Exception as e: + raise AnsibleError( + 'mosquitto_passlib custom filter requires the passlib pip package installed') + + SALT_SIZE = 12 + ITERATIONS = 101 + salt = passwd[:SALT_SIZE] + salt = bytes(salt, 'utf-8') + salt += b"0" * (SALT_SIZE - len(salt)) + + digest = passlib.hash.pbkdf2_sha512.using(salt_size=SALT_SIZE, rounds=ITERATIONS, salt=salt) \ + .hash(passwd) \ + .replace("pbkdf2-sha512", "7") \ + .replace(".", "+") + + return digest + "==" + + +class FilterModule(object): + def filters(self): + return { + 'mosquitto_passwd': mosquitto_passwd, + } diff --git a/roles/mosquitto/handlers/main.yml b/roles/mosquitto/handlers/main.yml new file mode 100644 index 0000000..03a1edb --- /dev/null +++ b/roles/mosquitto/handlers/main.yml @@ -0,0 +1,6 @@ +--- + +- name: Restart Mosquitto + ansible.builtin.service: + name: mosquitto + state: restarted diff --git a/roles/mosquitto/meta/main.yml b/roles/mosquitto/meta/main.yml new file mode 100644 index 0000000..90e4265 --- /dev/null +++ b/roles/mosquitto/meta/main.yml @@ -0,0 +1,11 @@ +--- + +galaxy_info: + author: Thomas Basler + description: Install Mosquitto + license: None + platforms: + - name: Debian + min_ansible_version: "2.4" + +dependencies: [] diff --git a/roles/mosquitto/tasks/main.yml b/roles/mosquitto/tasks/main.yml new file mode 100644 index 0000000..822e560 --- /dev/null +++ b/roles/mosquitto/tasks/main.yml @@ -0,0 +1,35 @@ +--- + +- name: Mosquitto | Install Mosquitto packages + ansible.builtin.apt: + name: "{{ item }}" + state: present + with_items: "{{ mosquitto_packages }}" + notify: Restart Mosquitto + +- name: Mosquitto | Generating Configuration File + ansible.builtin.template: + src: mosquitto.conf.j2 + dest: /etc/mosquitto/conf.d/mosquitto.conf + mode: "0755" + notify: Restart Mosquitto + +- name: Mosquitto | Generating Authentication Users File + ansible.builtin.template: + src: users.j2 + dest: "/etc/mosquitto/users_{{ item.name }}" + mode: "0755" + vars: + mosquitto_users: "{{ item.users }}" + with_items: "{{ mosquitto_listeners }}" + notify: Restart Mosquitto + +- name: Mosquitto | Generating Access Control List File + ansible.builtin.template: + src: acl.j2 + dest: "/etc/mosquitto/acl_{{ item.name }}" + mode: "0755" + vars: + listener: "{{ item }}" + with_items: "{{ mosquitto_listeners }}" + notify: Restart Mosquitto diff --git a/roles/mosquitto/templates/acl.j2 b/roles/mosquitto/templates/acl.j2 new file mode 100644 index 0000000..a6a9293 --- /dev/null +++ b/roles/mosquitto/templates/acl.j2 @@ -0,0 +1,28 @@ +{{ ansible_managed | comment }} + +{% for entry in listener.auth_anonymous | default([]) %} +{% if loop.first %} +# Anonymous access +{% endif %} +{{ entry }} +{% endfor %} + +{% for user in listener.users %} +{% if loop.first %} +# User access +{% endif %} +user {{ user.username }} +{% for access_list in user.acl | default([]) %} +topic {{ access_list.permissions }} {{ access_list.topic }} +{% if loop.last %} + +{% endif %} +{% endfor %} +{% endfor %} + +{% for entry in listener.auth_patterns | default([]) %} +{% if loop.first %} +# Global patterns +{% endif %} +{{ entry }} +{% endfor %} diff --git a/roles/mosquitto/templates/mosquitto.conf.j2 b/roles/mosquitto/templates/mosquitto.conf.j2 new file mode 100644 index 0000000..c96c10a --- /dev/null +++ b/roles/mosquitto/templates/mosquitto.conf.j2 @@ -0,0 +1,36 @@ +{{ ansible_managed | comment }} + +# Logging Configuration +log_timestamp true +log_type all + +# Listener +per_listener_settings true + +{% for elem in mosquitto_listeners %} +### Listener '{{ elem.name }}' +listener {{ elem.listener }} +{% for key, value in elem | dictsort %} +{% if key not in ["listener", "name", "users", "auth_anonymous", "auth_patterns"] %} +{{ key }} {{ value }} +{% endif %} +{% endfor %} +password_file /etc/mosquitto/users_{{ elem.name }} +acl_file /etc/mosquitto/acl_{{ elem.name }} + +{% endfor %} + +{% for elem in mosquitto_bridges %} +{% if loop.first %} +# Bridges +{% endif %} +connection {{ elem.connection }} +{% for key, value in elem | dictsort %} +{% if key not in ["connection", "topics"] %} +{{ key }} {{ value }} +{% endif %} +{% endfor %} +{% for topic in elem.topics %} +topic {{ topic.topic }} +{% endfor %} +{% endfor %} diff --git a/roles/mosquitto/templates/users.j2 b/roles/mosquitto/templates/users.j2 new file mode 100644 index 0000000..d1107d0 --- /dev/null +++ b/roles/mosquitto/templates/users.j2 @@ -0,0 +1,5 @@ +{{ ansible_managed | comment }} + +{% for user in mosquitto_users %} +{{ user.username }}:{{ user.password | mosquitto_passwd }} +{% endfor %} -- 2.39.5 From a9c66ab0e3eb6f6a60fb89a6e025caccab5f9115 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:13:55 +0200 Subject: [PATCH 03/13] homeassistant: Install basic mosquitto instance --- host_vars/lasagne.binary.kitchen | 21 +++++++++++++++++++++ roles/homeassistant/meta/main.yml | 3 ++- 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/host_vars/lasagne.binary.kitchen b/host_vars/lasagne.binary.kitchen index b480848..b49b471 100644 --- a/host_vars/lasagne.binary.kitchen +++ b/host_vars/lasagne.binary.kitchen @@ -9,3 +9,24 @@ root_keys_host: - "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC0Wq37DP89UO6MiJvvRbsXEcEV9d5/JJb7K2R0WHsHa sct39667@m-mob-062" uau_reboot: "false" + +mosquitto_listeners: + # Listeners for Mosquitto MQTT Broker + - name: "default" + listener: "1883" + protocol: "mqtt" + use_username_as_clientid: "false" + allow_zero_length_clientid: "true" + allow_anonymous: "false" + users: + - username: admin + password: "{{ vault_mosquitto_arwen_admin_passwd }}" + acl: + - permissions: readwrite + topic: "#" + + - username: homeassistant + password: "{{ vault_mosquitto_arwen_homeassistant_passwd }}" + acl: + - permissions: readwrite + topic: "#" diff --git a/roles/homeassistant/meta/main.yml b/roles/homeassistant/meta/main.yml index eb29279..9a715bd 100644 --- a/roles/homeassistant/meta/main.yml +++ b/roles/homeassistant/meta/main.yml @@ -8,4 +8,5 @@ galaxy_info: - name: Debian min_ansible_version: "2.4" -dependencies: [] +dependencies: + - { role: mosquitto } -- 2.39.5 From c7c56f212e43919fad28f406eed0ea4329043f5b Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:19:28 +0200 Subject: [PATCH 04/13] homeassistant: Add MQTT bridge to pizza --- host_vars/lasagne.binary.kitchen | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/host_vars/lasagne.binary.kitchen b/host_vars/lasagne.binary.kitchen index b49b471..05ac66c 100644 --- a/host_vars/lasagne.binary.kitchen +++ b/host_vars/lasagne.binary.kitchen @@ -30,3 +30,10 @@ mosquitto_listeners: acl: - permissions: readwrite topic: "#" + +mosquitto_bridges: + - connection: pizza + address: 172.23.4.6:1883 + topics: + - topic: "# out 0" + - topic: "# in 0" \ No newline at end of file -- 2.39.5 From 389331e59a541731c9cdcb0a4a8718ccf1bd559a Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:20:39 +0200 Subject: [PATCH 05/13] Add .pyc files to .gitignore --- .gitignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.gitignore b/.gitignore index 83cf9dd..3392089 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,4 @@ site.retry ansible.log *.swp +*.pyc -- 2.39.5 From b629b62974481f76ef4067b8281064d8516cfa19 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 21:59:04 +0200 Subject: [PATCH 06/13] homeassistant: Install newer python version if required --- roles/homeassistant/defaults/main.yml | 3 +++ roles/homeassistant/tasks/main.yml | 4 ++++ roles/homeassistant/tasks/python_312.yml | 26 ++++++++++++++++++++++++ roles/homeassistant/vars/main.yml | 6 ++++++ 4 files changed, 39 insertions(+) create mode 100644 roles/homeassistant/defaults/main.yml create mode 100644 roles/homeassistant/tasks/python_312.yml create mode 100644 roles/homeassistant/vars/main.yml diff --git a/roles/homeassistant/defaults/main.yml b/roles/homeassistant/defaults/main.yml new file mode 100644 index 0000000..11d0f72 --- /dev/null +++ b/roles/homeassistant/defaults/main.yml @@ -0,0 +1,3 @@ +--- + +ha_python_version: '3.12' diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml index ed97d53..87982b2 100644 --- a/roles/homeassistant/tasks/main.yml +++ b/roles/homeassistant/tasks/main.yml @@ -1 +1,5 @@ --- + +- name: Install python if required + ansible.builtin.include_tasks: python_312.yml + when: ha_python_version == '3.12' diff --git a/roles/homeassistant/tasks/python_312.yml b/roles/homeassistant/tasks/python_312.yml new file mode 100644 index 0000000..cb9cfc2 --- /dev/null +++ b/roles/homeassistant/tasks/python_312.yml @@ -0,0 +1,26 @@ +--- + +- name: Python 3.12 | add GPG signing key + become: true + ansible.builtin.apt_key: + url: "https://pascalroeleven.nl/deb-pascalroeleven.gpg" + state: present + validate_certs: true + tags: install + +- name: Python 3.12 | add official repository + become: true + ansible.builtin.apt_repository: + repo: "deb http://deb.pascalroeleven.nl/python3.12 bookworm-backports main" + state: present + filename: python312 + update_cache: true + tags: install + +- name: Python 3.12 | establish dependencies + become: true + ansible.builtin.apt: + name: "{{ item }}" + state: present + loop: "{{ python312_dependencies }}" + tags: install diff --git a/roles/homeassistant/vars/main.yml b/roles/homeassistant/vars/main.yml new file mode 100644 index 0000000..7209b3e --- /dev/null +++ b/roles/homeassistant/vars/main.yml @@ -0,0 +1,6 @@ +--- + +python312_dependencies: + - python3.12 + - python3.12-venv + - python3.12-dev -- 2.39.5 From 3b8cc7d1ea5b122b850d4f9942e542a40cf3643a Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 22:09:54 +0200 Subject: [PATCH 07/13] homeassistant: Prepare system for installation (install packages, create directories) --- roles/homeassistant/defaults/main.yml | 10 ++++++ roles/homeassistant/tasks/main.yml | 5 +++ roles/homeassistant/tasks/preparation.yml | 41 +++++++++++++++++++++++ 3 files changed, 56 insertions(+) create mode 100644 roles/homeassistant/tasks/preparation.yml diff --git a/roles/homeassistant/defaults/main.yml b/roles/homeassistant/defaults/main.yml index 11d0f72..8565fda 100644 --- a/roles/homeassistant/defaults/main.yml +++ b/roles/homeassistant/defaults/main.yml @@ -1,3 +1,13 @@ --- +# Python version required for home assistant ha_python_version: '3.12' + +# The location of the config directory +ha_conf_dir: /etc/homeassistant + +# The location of the installatin directory +ha_venv_dir: "/opt/homeassistant" + +# The default user +ha_user: homeassistant diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml index 87982b2..bd2e656 100644 --- a/roles/homeassistant/tasks/main.yml +++ b/roles/homeassistant/tasks/main.yml @@ -3,3 +3,8 @@ - name: Install python if required ansible.builtin.include_tasks: python_312.yml when: ha_python_version == '3.12' + +- name: Include sub-tasks + ansible.builtin.include_tasks: '{{ item }}' + loop: + - preparation.yml diff --git a/roles/homeassistant/tasks/preparation.yml b/roles/homeassistant/tasks/preparation.yml new file mode 100644 index 0000000..1c74213 --- /dev/null +++ b/roles/homeassistant/tasks/preparation.yml @@ -0,0 +1,41 @@ +--- + +- name: Install commonly-named packages + ansible.builtin.package: + name: "{{ item }}" + state: present + loop: + - python3 + - python3-dev + - python3-venv + - python3-pip + - libffi-dev + - libssl-dev + - libjpeg-dev + - zlib1g-dev + - autoconf + - build-essential + - libopenjp2-7 + - libtiff6 + - libturbojpeg0 + - tzdata + - git + - ffmpeg + +- name: Create user + ansible.builtin.user: + name: "{{ ha_user }}" + comment: "Home Assistant" + system: true + shell: "/sbin/nologin" + +- name: Create directory + ansible.builtin.file: + path: "{{ item }}" + state: directory + mode: "02775" + owner: "{{ ha_user }}" + group: "{{ ha_user }}" + loop: + - "{{ ha_conf_dir }}" + - "{{ ha_venv_dir }}" -- 2.39.5 From 552c9d71b36a03dcb2bb03928fd195ae4328553d Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 22:26:46 +0200 Subject: [PATCH 08/13] homeassistant: Added install procedure for postgres database --- host_vars/lasagne.binary.kitchen | 4 +- roles/homeassistant/defaults/main.yml | 5 +++ roles/homeassistant/handlers/main.yml | 6 +++ roles/homeassistant/tasks/main.yml | 1 + roles/homeassistant/tasks/postgres.yml | 54 ++++++++++++++++++++++++++ 5 files changed, 69 insertions(+), 1 deletion(-) create mode 100644 roles/homeassistant/handlers/main.yml create mode 100644 roles/homeassistant/tasks/postgres.yml diff --git a/host_vars/lasagne.binary.kitchen b/host_vars/lasagne.binary.kitchen index 05ac66c..4871259 100644 --- a/host_vars/lasagne.binary.kitchen +++ b/host_vars/lasagne.binary.kitchen @@ -36,4 +36,6 @@ mosquitto_bridges: address: 172.23.4.6:1883 topics: - topic: "# out 0" - - topic: "# in 0" \ No newline at end of file + - topic: "# in 0" + +ha_pg_db_pass: "{{ vault_ha_pg_db_pass }}" \ No newline at end of file diff --git a/roles/homeassistant/defaults/main.yml b/roles/homeassistant/defaults/main.yml index 8565fda..b7a786f 100644 --- a/roles/homeassistant/defaults/main.yml +++ b/roles/homeassistant/defaults/main.yml @@ -11,3 +11,8 @@ ha_venv_dir: "/opt/homeassistant" # The default user ha_user: homeassistant + +ha_pg_db_version: 15 +ha_pg_db_name: homeassistant +ha_pg_db_user: homeassistant +ha_pg_db_pass: xxxxx diff --git a/roles/homeassistant/handlers/main.yml b/roles/homeassistant/handlers/main.yml new file mode 100644 index 0000000..8cb9a93 --- /dev/null +++ b/roles/homeassistant/handlers/main.yml @@ -0,0 +1,6 @@ +--- + +- name: Restart postgresql + ansible.builtin.service: + name: postgresql + state: restarted diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml index bd2e656..ee248b2 100644 --- a/roles/homeassistant/tasks/main.yml +++ b/roles/homeassistant/tasks/main.yml @@ -8,3 +8,4 @@ ansible.builtin.include_tasks: '{{ item }}' loop: - preparation.yml + - postgres.yml diff --git a/roles/homeassistant/tasks/postgres.yml b/roles/homeassistant/tasks/postgres.yml new file mode 100644 index 0000000..eee0f56 --- /dev/null +++ b/roles/homeassistant/tasks/postgres.yml @@ -0,0 +1,54 @@ +--- + +- name: Postgres | establish dependencies + ansible.builtin.package: + name: "{{ item }}" + state: present + loop: + - postgresql-{{ ha_pg_db_version }} + - libpq-dev + - python3-psycopg2 + +- name: Postgres | Configure PostgreSQL database + community.general.postgresql_db: + name: "{{ ha_pg_db_name }}" + template: template0 + encoding: utf8 + become: true + become_user: postgres + +- name: Postgres | Configure PostgreSQL user + community.general.postgresql_user: + db: "{{ ha_pg_db_name }}" + name: "{{ ha_pg_db_user }}" + password: "{{ ha_pg_db_pass }}" + become: true + become_user: postgres + +- name: Postgres | GRANT ALL PRIVILEGES ON SCHEMA public TO {{ ha_pg_db_user }} + community.postgresql.postgresql_privs: + db: "{{ ha_pg_db_user }}" + privs: ALL + type: schema + objs: public + role: "{{ ha_pg_db_user }}" + become: true + become_user: postgres + +- name: Postgres | Grant all users access to all dbs + community.general.postgresql_pg_hba: + dest: /etc/postgresql/{{ ha_pg_db_version }}/main/pg_hba.conf + contype: host + users: all + databases: all + method: scram-sha-256 + source: 0.0.0.0/0 + notify: Restart postgresql + +- name: Postgres | Listen to external interfaces + community.general.postgresql_set: + name: listen_addresses + value: "*" + become: true + become_user: postgres + notify: Restart postgresql -- 2.39.5 From 6bfff16a4b2094699ff840fbe132b35660c8b5d7 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 23:07:09 +0200 Subject: [PATCH 09/13] homeassistant: Add installation procedures for homeassistant --- roles/homeassistant/handlers/main.yml | 5 +++ roles/homeassistant/tasks/installation.yml | 33 +++++++++++++++++++ roles/homeassistant/tasks/main.yml | 2 ++ roles/homeassistant/tasks/systemd.yml | 17 ++++++++++ .../templates/home-assistant.service.j2 | 14 ++++++++ 5 files changed, 71 insertions(+) create mode 100644 roles/homeassistant/tasks/installation.yml create mode 100644 roles/homeassistant/tasks/systemd.yml create mode 100644 roles/homeassistant/templates/home-assistant.service.j2 diff --git a/roles/homeassistant/handlers/main.yml b/roles/homeassistant/handlers/main.yml index 8cb9a93..69cfebc 100644 --- a/roles/homeassistant/handlers/main.yml +++ b/roles/homeassistant/handlers/main.yml @@ -4,3 +4,8 @@ ansible.builtin.service: name: postgresql state: restarted + +- name: Restart homeassistant + ansible.builtin.service: + name: home-assistant + state: restarted diff --git a/roles/homeassistant/tasks/installation.yml b/roles/homeassistant/tasks/installation.yml new file mode 100644 index 0000000..64d88af --- /dev/null +++ b/roles/homeassistant/tasks/installation.yml @@ -0,0 +1,33 @@ +--- + +- name: Install defined version of Home Assistant + ansible.builtin.pip: + name: + - wheel + - psycopg2 + - packaging + - uv + - netifaces + - homeassistant=={{ ha_version }} + virtualenv: '{{ ha_venv_dir }}' + virtualenv_command: 'python{{ ha_python_version }} -m venv' + when: ha_version is defined + become: true + become_user: "{{ ha_user }}" + notify: Restart homeassistant + +- name: Install latest version of Home Assistant + ansible.builtin.pip: + name: + - wheel + - psycopg2 + - packaging + - uv + - homeassistant + extra_args: "--upgrade" + virtualenv: "{{ ha_venv_dir }}" + virtualenv_command: 'python{{ ha_python_version }} -m venv' + when: ha_version is undefined + become: true + become_user: "{{ ha_user }}" + notify: Restart homeassistant diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml index ee248b2..b200556 100644 --- a/roles/homeassistant/tasks/main.yml +++ b/roles/homeassistant/tasks/main.yml @@ -9,3 +9,5 @@ loop: - preparation.yml - postgres.yml + - systemd.yml + - installation.yml diff --git a/roles/homeassistant/tasks/systemd.yml b/roles/homeassistant/tasks/systemd.yml new file mode 100644 index 0000000..2c6c63f --- /dev/null +++ b/roles/homeassistant/tasks/systemd.yml @@ -0,0 +1,17 @@ +--- + +- name: Install systemd unit file + ansible.builtin.template: + src: home-assistant.service.j2 + dest: "/etc/systemd/system/home-assistant.service" + owner: root + group: root + mode: "0644" + notify: Restart homeassistant + +- name: Enable home assistant service + ansible.builtin.systemd: + name: home-assistant + daemon_reload: true + enabled: true + notify: Restart homeassistant \ No newline at end of file diff --git a/roles/homeassistant/templates/home-assistant.service.j2 b/roles/homeassistant/templates/home-assistant.service.j2 new file mode 100644 index 0000000..fc6caff --- /dev/null +++ b/roles/homeassistant/templates/home-assistant.service.j2 @@ -0,0 +1,14 @@ +[Unit] +Description=Home Assistant +After=network.target postgresql.service + +[Service] +Type=simple +User={{ ha_user }} +Environment="PATH=/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:{{ ha_venv_dir }}/bin" +ExecStart={{ ha_venv_dir }}/bin/hass --config {{ ha_conf_dir }} +Restart=always +RestartSec=3 + +[Install] +WantedBy=multi-user.target -- 2.39.5 From 838d881480f76a79f52cb40449d63a0a6f0f0543 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 23:19:54 +0200 Subject: [PATCH 10/13] pgadmin4: Add role to install and configure pgadmin4 --- roles/pgadmin4/defaults/main.yml | 10 ++ roles/pgadmin4/handlers/main.yml | 6 + roles/pgadmin4/meta/main.yml | 11 ++ roles/pgadmin4/tasks/main.yml | 119 +++++++++++++++++++ roles/pgadmin4/templates/config_system.py.j2 | 4 + roles/pgadmin4/templates/pgadmin4.service.j2 | 29 +++++ 6 files changed, 179 insertions(+) create mode 100644 roles/pgadmin4/defaults/main.yml create mode 100644 roles/pgadmin4/handlers/main.yml create mode 100644 roles/pgadmin4/meta/main.yml create mode 100644 roles/pgadmin4/tasks/main.yml create mode 100644 roles/pgadmin4/templates/config_system.py.j2 create mode 100644 roles/pgadmin4/templates/pgadmin4.service.j2 diff --git a/roles/pgadmin4/defaults/main.yml b/roles/pgadmin4/defaults/main.yml new file mode 100644 index 0000000..7da5e34 --- /dev/null +++ b/roles/pgadmin4/defaults/main.yml @@ -0,0 +1,10 @@ +--- + +pgadmin4_user: pgadmin4 +pgadmin4_db_database: pgadmin4 +pgadmin4_db_user: pgadmin4 +pgadmin4_db_password: xxxxx +pgadmin4_conf_dir: /etc/pgadmin + +pgadmin4_initial_user_email: admin@admin.com +pgadmin4_initial_user_password: admin42 diff --git a/roles/pgadmin4/handlers/main.yml b/roles/pgadmin4/handlers/main.yml new file mode 100644 index 0000000..c0bf955 --- /dev/null +++ b/roles/pgadmin4/handlers/main.yml @@ -0,0 +1,6 @@ +--- + +- name: Restart pgadmin4 + ansible.builtin.service: + name: pgadmin4 + state: restarted diff --git a/roles/pgadmin4/meta/main.yml b/roles/pgadmin4/meta/main.yml new file mode 100644 index 0000000..1cf895d --- /dev/null +++ b/roles/pgadmin4/meta/main.yml @@ -0,0 +1,11 @@ +--- + +galaxy_info: + author: Thomas Basler + description: Install PgAdmin4 + license: None + platforms: + - name: Debian + min_ansible_version: "2.4" + +dependencies: [] diff --git a/roles/pgadmin4/tasks/main.yml b/roles/pgadmin4/tasks/main.yml new file mode 100644 index 0000000..3a6355e --- /dev/null +++ b/roles/pgadmin4/tasks/main.yml @@ -0,0 +1,119 @@ +--- + +- name: PgAdmin 4 | add GPG signing key + become: true + ansible.builtin.apt_key: + url: "https://www.pgadmin.org/static/packages_pgadmin_org.pub" + state: present + validate_certs: true + tags: install + +- name: PgAdmin 4 | add official repository + become: true + ansible.builtin.apt_repository: + repo: "deb https://ftp.postgresql.org/pub/pgadmin/pgadmin4/apt/bookworm pgadmin4 main" + state: present + filename: pgadmin4 + update_cache: true + tags: install + +- name: PgAdmin 4 | establish dependencies + become: true + ansible.builtin.apt: + name: "{{ item }}" + state: present + tags: install + loop: ["pgadmin4-server", "uwsgi-core", "uwsgi-plugin-python3", "python3-pexpect"] + +- name: PgAdmin 4 | Configure PostgreSQL database + community.general.postgresql_db: + name: "{{ pgadmin4_db_database }}" + template: template0 + encoding: utf8 + become: true + become_user: postgres + register: pgadmin4_db + +- name: PgAdmin 4 | Configure PostgreSQL user + community.general.postgresql_user: + db: "{{ pgadmin4_db_database }}" + name: "{{ pgadmin4_db_user }}" + password: "{{ pgadmin4_db_password }}" + become: true + become_user: postgres + +- name: PgAdmin 4 | Configure PostgreSQL user privileges + community.postgresql.postgresql_privs: + database: "{{ pgadmin4_db_database }}" + state: present + privs: ALL + type: database + role: "{{ pgadmin4_db_user }}" + become: true + become_user: postgres + +- name: PgAdmin 4 | GRANT ALL PRIVILEGES ON SCHEMA public TO {{ pgadmin4_db_user }} + community.postgresql.postgresql_privs: + db: "{{ pgadmin4_db_database }}" + privs: ALL + type: schema + objs: public + role: "{{ pgadmin4_db_user }}" + become: true + become_user: postgres + +- name: Create user + ansible.builtin.user: + name: "{{ pgadmin4_user }}" + comment: "pgAdmin 4" + createhome: false + system: true + shell: "/sbin/nologin" + +- name: PgAdmin 4 | create config directory + ansible.builtin.file: + path: "{{ item }}" + state: directory + mode: "02775" + owner: "root" + group: "root" + with_items: + - "{{ pgadmin4_conf_dir }}" + +- name: PgAdmin 4 | install config file + ansible.builtin.template: + src: config_system.py.j2 + dest: "{{ pgadmin4_conf_dir }}/config_system.py" + owner: root + group: root + mode: "0644" + notify: Restart pgadmin4 + +- name: PgAdmin 4 | install systemd unit file + ansible.builtin.template: + src: pgadmin4.service.j2 + dest: "/etc/systemd/system/pgadmin4.service" + owner: root + group: root + mode: "0644" + notify: Restart pgadmin4 + +- name: PgAdmin 4 | enable service + ansible.builtin.service: + name: pgadmin4 + enabled: true + +- name: PgAdmin 4 | setup pgadmin # noqa: no-handler + ansible.builtin.expect: + command: /bin/bash -c "/usr/pgadmin4/venv/bin/python3 /usr/pgadmin4/web/setup.py setup-db" + chdir: /usr/pgadmin4/web/ + echo: true + timeout: 300 + responses: + 'Email\ address:': "{{ pgadmin4_initial_user_email | trim }}" + 'Password:': "{{ pgadmin4_initial_user_password | trim }}" + 'Retype\ password:': "{{ pgadmin4_initial_user_password | trim }}" + 'Do\ you\ wish\ to\ continue\ \(y/n\)\?': "y" + 'Would\ you\ like\ to\ continue\ \(y/n\)\?': "y" + when: pgadmin4_db.changed + notify: Restart pgadmin4 diff --git a/roles/pgadmin4/templates/config_system.py.j2 b/roles/pgadmin4/templates/config_system.py.j2 new file mode 100644 index 0000000..5a56136 --- /dev/null +++ b/roles/pgadmin4/templates/config_system.py.j2 @@ -0,0 +1,4 @@ +LOG_FILE = '/var/log/pgadmin/pgadmin4.log' +CONFIG_DATABASE_URI = 'postgresql://{{ pgadmin4_db_user }}:{{ pgadmin4_db_password }}@localhost:5432/{{ pgadmin4_db_database }}' +SESSION_DB_PATH = '/var/lib/pgadmin/sessions' +STORAGE_DIR = '/var/lib/pgadmin/storage' \ No newline at end of file diff --git a/roles/pgadmin4/templates/pgadmin4.service.j2 b/roles/pgadmin4/templates/pgadmin4.service.j2 new file mode 100644 index 0000000..cfa45aa --- /dev/null +++ b/roles/pgadmin4/templates/pgadmin4.service.j2 @@ -0,0 +1,29 @@ +[Unit] +Description = PgAdmin4 uwsgi Service +After = network.target network-online.target +Wants = network-online.target + +[Service] +User={{ pgadmin4_user }} +StateDirectory=pgadmin +RuntimeDirectory=pgadmin4 +LogsDirectory=pgadmin +ExecStart=uwsgi \ + --socket /run/pgadmin4/pgadmin4.sock --chmod-socket=666 \ + --plugin python3 \ + -H /usr/pgadmin4/venv \ + --processes 1 \ + --threads 25 \ + --chdir /usr/pgadmin4/web/ \ + --manage-script-name \ + --mount /pgadmin4=pgAdmin4:app +ExecReload=/bin/kill -HUP $MAINPID +ExecStop=/bin/kill -INT $MAINPID +Restart=always +Type=notify +StandardError=syslog +NotifyAccess=all +KillSignal=SIGQUIT + +[Install] +WantedBy = multi-user.target \ No newline at end of file -- 2.39.5 From 3e87601013fd64a53e5e022bab7b3ac21f934d54 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Wed, 2 Oct 2024 23:20:43 +0200 Subject: [PATCH 11/13] homeassistant: Install pgadmin4 --- host_vars/lasagne.binary.kitchen | 5 ++++- roles/homeassistant/meta/main.yml | 1 + 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/host_vars/lasagne.binary.kitchen b/host_vars/lasagne.binary.kitchen index 4871259..aecfaff 100644 --- a/host_vars/lasagne.binary.kitchen +++ b/host_vars/lasagne.binary.kitchen @@ -38,4 +38,7 @@ mosquitto_bridges: - topic: "# out 0" - topic: "# in 0" -ha_pg_db_pass: "{{ vault_ha_pg_db_pass }}" \ No newline at end of file +ha_pg_db_pass: "{{ vault_ha_pg_db_pass }}" +pgadmin4_db_password: "{{ vault_pgadmin4_db_password }}" +pgadmin4_initial_user_email: noby@binary-kitchen.de +pgadmin4_initial_user_password: "{{ vault_pgadmin4_initial_user_password }}" \ No newline at end of file diff --git a/roles/homeassistant/meta/main.yml b/roles/homeassistant/meta/main.yml index 9a715bd..9b650cd 100644 --- a/roles/homeassistant/meta/main.yml +++ b/roles/homeassistant/meta/main.yml @@ -10,3 +10,4 @@ galaxy_info: dependencies: - { role: mosquitto } + - { role: pgadmin4 } -- 2.39.5 From 6e55e4ff7824a2ed9b753886805256a2ca68f420 Mon Sep 17 00:00:00 2001 From: Thomas Basler Date: Thu, 3 Oct 2024 00:48:58 +0200 Subject: [PATCH 12/13] homeassistant: Add installation procedures for grafana --- host_vars/lasagne.binary.kitchen | 3 +- roles/homeassistant/defaults/main.yml | 4 + roles/homeassistant/handlers/main.yml | 5 + roles/homeassistant/tasks/grafana.yml | 77 ++ roles/homeassistant/tasks/main.yml | 1 + roles/homeassistant/templates/grafana.ini.j2 | 1082 ++++++++++++++++++ 6 files changed, 1171 insertions(+), 1 deletion(-) create mode 100644 roles/homeassistant/tasks/grafana.yml create mode 100644 roles/homeassistant/templates/grafana.ini.j2 diff --git a/host_vars/lasagne.binary.kitchen b/host_vars/lasagne.binary.kitchen index aecfaff..52b25cf 100644 --- a/host_vars/lasagne.binary.kitchen +++ b/host_vars/lasagne.binary.kitchen @@ -41,4 +41,5 @@ mosquitto_bridges: ha_pg_db_pass: "{{ vault_ha_pg_db_pass }}" pgadmin4_db_password: "{{ vault_pgadmin4_db_password }}" pgadmin4_initial_user_email: noby@binary-kitchen.de -pgadmin4_initial_user_password: "{{ vault_pgadmin4_initial_user_password }}" \ No newline at end of file +pgadmin4_initial_user_password: "{{ vault_pgadmin4_initial_user_password }}" +ha_pg_grafana_db_pass: "{{ vault_ha_pg_grafana_db_pass }}" diff --git a/roles/homeassistant/defaults/main.yml b/roles/homeassistant/defaults/main.yml index b7a786f..099a1c2 100644 --- a/roles/homeassistant/defaults/main.yml +++ b/roles/homeassistant/defaults/main.yml @@ -16,3 +16,7 @@ ha_pg_db_version: 15 ha_pg_db_name: homeassistant ha_pg_db_user: homeassistant ha_pg_db_pass: xxxxx + +ha_pg_grafana_db_name: grafana +ha_pg_grafana_db_user: grafana +ha_pg_grafana_db_pass: xxxxx diff --git a/roles/homeassistant/handlers/main.yml b/roles/homeassistant/handlers/main.yml index 69cfebc..6728c1d 100644 --- a/roles/homeassistant/handlers/main.yml +++ b/roles/homeassistant/handlers/main.yml @@ -9,3 +9,8 @@ ansible.builtin.service: name: home-assistant state: restarted + +- name: Restart grafana + ansible.builtin.service: + name: grafana-server + state: restarted diff --git a/roles/homeassistant/tasks/grafana.yml b/roles/homeassistant/tasks/grafana.yml new file mode 100644 index 0000000..819a5e9 --- /dev/null +++ b/roles/homeassistant/tasks/grafana.yml @@ -0,0 +1,77 @@ +--- + +- name: Grafana | add GPG signing key + become: true + ansible.builtin.apt_key: + url: "https://apt.grafana.com/gpg.key" + state: present + validate_certs: true + +- name: Grafana | add official repository + become: true + ansible.builtin.apt_repository: + repo: "deb https://apt.grafana.com stable main" + state: present + filename: grafana + update_cache: true + tags: install + +- name: Grafana | establish dependencies + become: true + ansible.builtin.apt: + name: "{{ item }}" + state: present + loop: ["grafana"] + tags: install + +- name: Grafana | Configure PostgreSQL database + community.general.postgresql_db: + name: "{{ ha_pg_grafana_db_name }}" + template: template0 + encoding: utf8 + become: true + become_user: postgres + +- name: Grafana | Configure PostgreSQL user + community.general.postgresql_user: + db: "{{ ha_pg_grafana_db_name }}" + name: "{{ ha_pg_grafana_db_user }}" + password: "{{ ha_pg_grafana_db_pass }}" + become: true + become_user: postgres + +- name: Grafana | GRANT ALL PRIVILEGES ON SCHEMA public TO {{ pgadmin4_db_user }} + community.postgresql.postgresql_privs: + db: "{{ ha_pg_grafana_db_name }}" + privs: ALL + type: schema + objs: public + role: "{{ ha_pg_grafana_db_user }}" + become: true + become_user: postgres + +- name: GRANT SELECT PRIVILEGES ON DATABASE {{ ha_pg_db_name }} TO {{ ha_pg_grafana_db_user }} + community.general.postgresql_privs: + db: "{{ ha_pg_db_name }}" + privs: SELECT + type: table + objs: statistics,statistics_meta + role: "{{ ha_pg_grafana_db_user }}" + become: true + become_user: postgres + ignore_errors: true + +- name: Grafana | install config file + ansible.builtin.template: + src: grafana.ini.j2 + dest: "/etc/grafana/grafana.ini" + owner: root + group: root + mode: "0644" + notify: Restart grafana + +- name: Grafana | Start service + ansible.builtin.service: + name: grafana-server + state: started + enabled: true diff --git a/roles/homeassistant/tasks/main.yml b/roles/homeassistant/tasks/main.yml index b200556..7259630 100644 --- a/roles/homeassistant/tasks/main.yml +++ b/roles/homeassistant/tasks/main.yml @@ -11,3 +11,4 @@ - postgres.yml - systemd.yml - installation.yml + - grafana.yml diff --git a/roles/homeassistant/templates/grafana.ini.j2 b/roles/homeassistant/templates/grafana.ini.j2 new file mode 100644 index 0000000..9ab8426 --- /dev/null +++ b/roles/homeassistant/templates/grafana.ini.j2 @@ -0,0 +1,1082 @@ +{{ ansible_managed | comment }} + +##################### Grafana Configuration Example ##################### +# +# Everything has defaults so you only need to uncomment things you want to +# change + +# possible values : production, development +;app_mode = production + +# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty +;instance_name = ${HOSTNAME} + +#################################### Paths #################################### +[paths] +# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used) +;data = /var/lib/grafana + +# Temporary files in `data` directory older than given duration will be removed +;temp_data_lifetime = 24h + +# Directory where grafana can store logs +;logs = /var/log/grafana + +# Directory where grafana will automatically scan and look for plugins +;plugins = /var/lib/grafana/plugins + +# folder that contains provisioning config files that grafana will apply on startup and while running. +;provisioning = conf/provisioning + +#################################### Server #################################### +[server] +# Protocol (http, https, h2, socket) +;protocol = http + +# The ip address to bind to, empty will bind to all interfaces +;http_addr = + +# The http port to use +;http_port = 3000 + +# The public facing domain name used to access grafana from a browser +;domain = localhost + +# Redirect to correct domain if host header does not match domain +# Prevents DNS rebinding attacks +;enforce_domain = false + +# The full public facing url you use in browser, used for redirects and emails +# If you use reverse proxy and sub path specify full url (with sub path) +root_url = %(protocol)s://%(domain)s:%(http_port)s/grafana/ + +# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. +serve_from_sub_path = true + +# Log web requests +;router_logging = false + +# the path relative working path +;static_root_path = public + +# enable gzip +;enable_gzip = false + +# https certs & key file +;cert_file = +;cert_key = + +# Unix socket path +;socket = + +# CDN Url +;cdn_url = + +# Sets the maximum time using a duration format (5s/5m/5ms) before timing out read of an incoming request and closing idle connections. +# `0` means there is no timeout for reading the request. +;read_timeout = 0 + +#################################### Database #################################### +[database] +# You can configure the database connection by specifying type, host, name, user and password +# as separate properties or as on string using the url properties. + +# Either "mysql", "postgres" or "sqlite3", it's your choice +;type = sqlite3 +;host = 127.0.0.1:3306 +;name = grafana +;user = root +# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;""" +;password = + +# Use either URL or the previous fields to configure the database +# Example: mysql://user:secret@host:port/database +url = postgres://{{ ha_pg_grafana_db_user }}:{{ ha_pg_grafana_db_pass }}@/{{ ha_pg_grafana_db_name }} + +# For "postgres" only, either "disable", "require" or "verify-full" +;ssl_mode = disable + +# Database drivers may support different transaction isolation levels. +# Currently, only "mysql" driver supports isolation levels. +# If the value is empty - driver's default isolation level is applied. +# For "mysql" use "READ-UNCOMMITTED", "READ-COMMITTED", "REPEATABLE-READ" or "SERIALIZABLE". +;isolation_level = + +;ca_cert_path = +;client_key_path = +;client_cert_path = +;server_cert_name = + +# For "sqlite3" only, path relative to data_path setting +;path = grafana.db + +# Max idle conn setting default is 2 +;max_idle_conn = 2 + +# Max conn setting default is 0 (mean not set) +;max_open_conn = + +# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours) +;conn_max_lifetime = 14400 + +# Set to true to log the sql calls and execution times. +;log_queries = + +# For "sqlite3" only. cache mode setting used for connecting to the database. (private, shared) +;cache_mode = private + +################################### Data sources ######################### +[datasources] +# Upper limit of data sources that Grafana will return. This limit is a temporary configuration and it will be deprecated when pagination will be introduced on the list data sources API. +;datasource_limit = 5000 + +#################################### Cache server ############################# +[remote_cache] +# Either "redis", "memcached" or "database" default is "database" +;type = database + +# cache connectionstring options +# database: will use Grafana primary database. +# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'. +# memcache: 127.0.0.1:11211 +;connstr = + +#################################### Data proxy ########################### +[dataproxy] + +# This enables data proxy logging, default is false +;logging = false + +# How long the data proxy waits to read the headers of the response before timing out, default is 30 seconds. +# This setting also applies to core backend HTTP data sources where query requests use an HTTP client with timeout set. +;timeout = 30 + +# How long the data proxy waits to establish a TCP connection before timing out, default is 10 seconds. +;dialTimeout = 10 + +# How many seconds the data proxy waits before sending a keepalive probe request. +;keep_alive_seconds = 30 + +# How many seconds the data proxy waits for a successful TLS Handshake before timing out. +;tls_handshake_timeout_seconds = 10 + +# How many seconds the data proxy will wait for a server's first response headers after +# fully writing the request headers if the request has an "Expect: 100-continue" +# header. A value of 0 will result in the body being sent immediately, without +# waiting for the server to approve. +;expect_continue_timeout_seconds = 1 + +# Optionally limits the total number of connections per host, including connections in the dialing, +# active, and idle states. On limit violation, dials will block. +# A value of zero (0) means no limit. +;max_conns_per_host = 0 + +# The maximum number of idle connections that Grafana will keep alive. +;max_idle_connections = 100 + +# How many seconds the data proxy keeps an idle connection open before timing out. +;idle_conn_timeout_seconds = 90 + +# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request, default is false. +;send_user_header = false + +# Limit the amount of bytes that will be read/accepted from responses of outgoing HTTP requests. +;response_limit = 0 + +# Limits the number of rows that Grafana will process from SQL data sources. +;row_limit = 1000000 + +#################################### Analytics #################################### +[analytics] +# Server reporting, sends usage counters to stats.grafana.org every 24 hours. +# No ip addresses are being tracked, only simple counters to track +# running instances, dashboard and error counts. It is very helpful to us. +# Change this option to false to disable reporting. +;reporting_enabled = true + +# The name of the distributor of the Grafana instance. Ex hosted-grafana, grafana-labs +;reporting_distributor = grafana-labs + +# Set to false to disable all checks to https://grafana.net +# for new versions (grafana itself and plugins), check is used +# in some UI views to notify that grafana or plugin update exists +# This option does not cause any auto updates, nor send any information +# only a GET request to http://grafana.com to get latest versions +;check_for_updates = true + +# Google Analytics universal tracking code, only enabled if you specify an id here +;google_analytics_ua_id = + +# Google Tag Manager ID, only enabled if you specify an id here +;google_tag_manager_id = + +#################################### Security #################################### +[security] +# disable creation of admin user on first start of grafana +;disable_initial_admin_creation = false + +# default admin user, created on startup +;admin_user = admin + +# default admin password, can be changed before first start of grafana, or in profile settings +;admin_password = admin + +# used for signing +;secret_key = SW2YcwTIb9zpOOhoPsMm + +# current key provider used for envelope encryption, default to static value specified by secret_key +;encryption_provider = secretKey + +# list of configured key providers, space separated (Enterprise only): e.g., awskms.v1 azurekv.v1 +;available_encryption_providers = + +# disable gravatar profile images +;disable_gravatar = false + +# data source proxy whitelist (ip_or_domain:port separated by spaces) +;data_source_proxy_whitelist = + +# disable protection against brute force login attempts +;disable_brute_force_login_protection = false + +# set to true if you host Grafana behind HTTPS. default is false. +;cookie_secure = false + +# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled" +;cookie_samesite = lax + +# set to true if you want to allow browsers to render Grafana in a ,