158 lines
3.7 KiB
YAML
Raw Permalink Normal View History

2021-07-14 17:38:28 +02:00
---
- name: Create group
group: name={{ netbox_group }}
- name: Create user
user: name={{ netbox_user }} home=/home/{{ netbox_user }} group={{ netbox_group }}
- name: Install dependencies
apt:
name:
- build-essential
- libffi-dev
- libpq-dev
- libssl-dev
- libxml2-dev
- libxslt1-dev
- python3-setuptools
- python3-dev
- python3-pip
- python3-venv
- zlib1g-dev
- name: Install PostgreSQL
apt:
name:
- postgresql
- python3-psycopg2
- name: Configure PostgreSQL user
postgresql_user:
2021-11-03 18:25:33 +01:00
name: "{{ netbox_dbuser }}"
password: "{{ netbox_dbpass }}"
become: true
become_user: postgres
- name: Configure PostgreSQL database
postgresql_db:
name: "{{ netbox_dbname }}"
owner: "{{ netbox_dbuser }}"
2021-07-14 17:38:28 +02:00
become: true
become_user: postgres
- name: Install redis
apt: name=redis-server
- name: Unpack netbox
unarchive:
2021-11-03 18:25:33 +01:00
src: "https://github.com/netbox-community/netbox/archive/v{{ netbox_version }}.tar.gz"
2021-07-14 17:38:28 +02:00
dest: /opt
remote_src: yes
2021-11-03 18:25:33 +01:00
creates: "/opt/netbox-{{ netbox_version }}"
2021-07-14 17:38:28 +02:00
register: netbox_unarchive
- name: Configure netbox
template:
src: configuration.py.j2
2021-11-03 18:25:33 +01:00
dest: "/opt/netbox-{{ netbox_version }}/netbox/netbox/configuration.py"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
2021-12-19 10:11:01 +01:00
notify: Restart netbox
2021-07-14 17:38:28 +02:00
- name: Configure gunicorn
template:
src: gunicorn.py.j2
2021-11-03 18:25:33 +01:00
dest: "/opt/netbox-{{ netbox_version }}/gunicorn.py"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
2021-07-14 17:38:28 +02:00
- name: Netbox file permissions
file:
2021-11-03 18:25:33 +01:00
path: "/opt/netbox-{{ netbox_version }}"
owner: "{{ netbox_user }}"
group: "{{ netbox_group }}"
2021-07-14 17:38:28 +02:00
recurse: yes
- name: Fix psycopg variant
lineinfile:
path: "/opt/netbox-{{ netbox_version }}/requirements.txt"
regexp: '^psycopg\[.*,pool\]==(.*)$'
line: 'psycopg[binary,pool]==\1'
backrefs: yes
register: netbox_psycopg_fix
2021-07-14 17:38:28 +02:00
- name: Run upgrade script
command:
cmd: ./upgrade.sh
2021-11-03 18:25:33 +01:00
chdir: "/opt/netbox-{{ netbox_version }}"
2021-07-14 17:38:28 +02:00
become: true
2021-11-03 18:25:33 +01:00
become_user: "{{ netbox_user }}"
when: netbox_unarchive.changed or netbox_psycopg_fix.changed
2021-07-14 17:38:28 +02:00
# TODO - still manual work
# * Create a super user
# * Migrate media files
2021-08-31 19:02:20 +02:00
- name: Install netbox housekeeping cronjob
template:
src: netbox-housekeeping.sh.j2
dest: /etc/cron.daily/netbox-housekeeping.sh
mode: 0755
2021-07-14 17:38:28 +02:00
- name: Ensure certificates are available
command:
cmd: >
openssl req -x509 -nodes -newkey rsa:2048
-keyout /etc/nginx/ssl/{{ netbox_domain }}.key -out /etc/nginx/ssl/{{ netbox_domain }}.crt
-days 730 -subj "/CN={{ netbox_domain }}"
2021-11-03 18:25:33 +01:00
creates: "/etc/nginx/ssl/{{ netbox_domain }}.crt"
2021-07-14 17:38:28 +02:00
notify: Restart nginx
- name: Request nsupdate key for certificate
include_role: name=acme-dnskey-generate
vars:
acme_dnskey_san_domains:
- "{{ netbox_domain }}"
when: "'kitchen' in group_names"
- name: Configure certificate manager for netbox
template: src=certs.j2 dest=/etc/acertmgr/{{ netbox_domain }}.conf
notify: Run acertmgr
- name: Configure vhost
template:
src: vhost.j2
dest: /etc/nginx/sites-available/netbox
owner: root
2021-11-03 18:25:33 +01:00
mode: "0644"
2021-07-14 17:38:28 +02:00
notify: Restart nginx
- name: Enable vhost
file:
src: /etc/nginx/sites-available/netbox
dest: /etc/nginx/sites-enabled/netbox
state: link
notify: Restart nginx
- name: Install systemd units
template: src={{ item }}.service.j2 dest=/lib/systemd/system/{{ item }}.service
with_items:
- netbox
- netbox-rq
notify:
- Reload systemd
- Restart netbox
- Restart netbox-rq
- name: Enable services
service: name={{ item }} state=started enabled=yes
with_items:
- netbox
- netbox-rq
2022-06-06 21:06:07 +02:00
- name: Enable monitoring
include_role: name=icinga-monitor tasks_from=http
vars:
vhost: "{{ netbox_domain }}"