{"id":16342783,"url":"https://github.com/budimanjojo/ansible-playbooks","last_synced_at":"2026-05-09T00:04:13.608Z","repository":{"id":104049113,"uuid":"389000737","full_name":"budimanjojo/ansible-playbooks","owner":"budimanjojo","description":"My Ansible playbooks repository","archived":false,"fork":false,"pushed_at":"2022-02-20T15:50:41.000Z","size":136,"stargazers_count":3,"open_issues_count":0,"forks_count":0,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-12-27T13:43:42.072Z","etag":null,"topics":["ansible","ansible-playbook","ansible-role","cluster","kubernetes","kubespray"],"latest_commit_sha":null,"homepage":"","language":"Jinja","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/budimanjojo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-07-24T04:36:33.000Z","updated_at":"2023-06-24T09:52:05.000Z","dependencies_parsed_at":"2023-06-29T11:30:26.675Z","dependency_job_id":null,"html_url":"https://github.com/budimanjojo/ansible-playbooks","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/budimanjojo%2Fansible-playbooks","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/budimanjojo%2Fansible-playbooks/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/budimanjojo%2Fansible-playbooks/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/budimanjojo%2Fansible-playbooks/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/budimanjojo","download_url":"https://codeload.github.com/budimanjojo/ansible-playbooks/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":239461562,"owners_count":19642595,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","ansible-playbook","ansible-role","cluster","kubernetes","kubespray"],"created_at":"2024-10-11T00:05:09.469Z","updated_at":"2025-11-05T14:30:30.775Z","avatar_url":"https://github.com/budimanjojo.png","language":"Jinja","funding_links":[],"categories":[],"sub_categories":[],"readme":"# ansible-playbooks\n\nThis repository contains my Ansible playbooks.\nMost of the roles used in the playbooks are my own roles.\nThe goal of me making these roles instead of using the available ones in the Galaxy is to simplify everything and use the best practices of current Ansible version.\nMost of these roles are not features heavy, but fit my needs as a regular user.\n\nYou can find all the playbooks in the [playbooks directory](./playbooks/). The `*.yml` files starting with `k3s-` are k3s related playbooks.\nExample inventory file and all the variables are inside [playbooks/inventory](./playbooks/inventory/example/).\nI'm using [ansible-role-k3s](https://github.com/PyratLabs/ansible-role-k3s) to deploy my k3s cluster.\n\nI provision my [kubernetes cluster](https://github.com/budimanjojo/home-cluster) using [ansible-role-k3s](https://github.com/PyratLabs/ansible-role-k3s).\n\n## Available roles\n\nHere are the list of roles from me used in this repository. Each role has its own README file explaining how to use it:\n- [users](https://galaxy.ansible.com/budimanjojo/users): This role lets you create and remove users and groups\n- [sudo](https://galaxy.ansible.com/budimanjojo/sudo): This role lets you configure sudoers file\n- [ssh](https://galaxy.ansible.com/budimanjojo/ssh): This role lets you configure ssh\n- [packages](https://galaxy.ansible.com/budimanjojo/packages): This role lets you install and uninstall packages\n- [dotfiles](https://galaxy.ansible.com/budimanjojo/dotfiles): This role lets you clone and link your dotfiles from remote repository\n- [gitclone](https://galaxy.ansible.com/budimanjojo/gitclone): This role lets you clone repositories to your machine\n- [download](https://galaxy.ansible.com/budimanjojo/download): This role lets you download files or archive files to your machine\n- [zinit](https://galaxy.ansible.com/budimanjojo/zinit): This role lets you install [zinit](https://github.com/zdharma/zinit)\n- [vimplug](https://galaxy.ansible.com/budimanjojo/vimplug): This role lets you install [vim-plug](https://github.com/junegunn/vim-plug) and configure vim plugins\n- [nodejs](https://galaxy.ansible.com/budimanjojo/nodejs): This role lets you install nodejs and npm from NodeSource\n- [haproxy](https://galaxy.ansible.com/budimanjojo/haproxy): This role lets you install and configure HAProxy\n\n## Secret variables management\n\nI personally use [sops](https://github.com/mozilla/sops) to manage my secrets. This require `sops` and your preferred encryption tool to be installed in the ansible host machine. I use [age](https://github.com/FiloSottile/age) as my preferred sops companion. The example secret group_vars is available in [inventory/example/group_vars/all.sops.yml](./plabooks/inventory/example/group_vars/all.sops.yml). This is possible by the [community.sops ansible plugin](https://github.com/ansible-collections/community.sops). The provided [ansible.cfg](./playbooks/ansible.cfg) file is configured to load the plugin by default. Public key to encrypt the secret file is in [.sops.yaml](./.sops.yaml) file.\n\n## Example playbook\n```\n- hosts: all\n  become: true\n\n  vars:\n    users_add:\n    - username: admin\n      password: $6$secretsalt$rhg1DOUiEqjMGlpDXDdS8wXQfgM2WXxnbvNFNCdSp4wjwGOGpOC5lkuHPDHe7NraAc9oLq5yFqz0tbgfUbSy/0\n      groups:\n      - group1\n      - group2\n    - username: admin2\n      password: $6$secretsalt$rhg1DOUiEqjMGlpDXDdS8wXQfgM2WXxnbvNFNCdSp4wjwGOGpOC5lkuHPDHe7NraAc9oLq5yFqz0tbgfUbSy/0\n      generate_ssh_key: true\n      shell: /bin/zsh\n      authorized_keys:\n      - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIgzLDHHRtLD9DLfNTX8Te9zBcDmEF33UPJ5HngP6aJAhdQln7ebSOzQoehxN0th644G9csnujxjNAStIEUjzeXO1NQQfEYGqDVxDL0jE4hXr1WVg+6GxQnV1nWP5Sd2i24+ElygCdw3KuteeNlfGZ7BKs91zySb03DICXPNcgXj6ZR9INalabFhbjeVG5MRH38KRR9cxZKbgW+eQZZwVtDRPzL7rAfaeeJPg7ZQ3Iu0SC3q5SskGQD5XfqCwPDx9n0GWva36jwNneifv5WFDh0U+xKaoVT4HJTWyV/vf3+fTji1yEsGMBbPexuD5aHvmun9SdgIlGw65GJB7Ibz47Bq/jVfnTV6o5BVDhEfwayHZgahODl5Uyc3VqkKoJh9IWivoBr/bLHXepiJGUReEw61nBc3JL9QC4J5ngterLXP/iapl185+JSvUzDjbtFDHLiXCqa8X17Cm9LSIKik/W7gM2tU63QcQd/p8H55he/Kgm94vWJlq98rjLCtBYTNQDSNAU6AFQqk2c3x23L09wSRIQJ1aUEq6aPx3yfbiRHyTslTyP4tg0I1U1o+jjh9tZV/+JpRcwg9xi9YLoGMAv9aUVGHodjehZw1wHnuql3ALiy/Nnm2LANDh4vhJ2fKsrBqhk8dyDdqFHFsLyTSXUAE4NKGG1AUV3fgMjvRRZZQ==\n      - ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDJVJ+gHYFCoyd1WG8uJ2d0ErwmyASjhqv8ZXblNBHMjTSNXtqxTZ/MIIAPkxi3XSSFIcAGO7nr5myKyQVfiFlPAQMDR64iTfL6N/peMi25xE5+MhQKTIcJBSlRYx3RjJmx9JwmDuT8aXlPqL16QWk8WVe5XErNAXrsj+PrTISlS9O8wbqKExcC2jTzieg4L3II4cBv+M7QySt8ApzLJ5geYniO4mc5Jqor1hBZakQDw8vJdohOgnjVK+MIvVFm97iVmhNXUCgqFn3EGXVGLAB8J8h2aix8WvkP85WmvJ4nZ9k22QvijBr3WHQdwU/VoZ7xWpXVcGsXwnlD9tpGUotx\nssh-rsa\n    users_remove:\n    - username: trash\n      remove_dir: true\n    groups_remove:\n    - disk\n    - adm\n    sudo_admin_group_nopasswd: true\n    sudo_users:\n    - username: somebody\n      commands:\n      - /usr/bin/cp\n      - /usr/bin/mv\n      - /usr/bin/touch\n    ssh_packages:\n    - openssh-server\n    - openssh-client\n    ssh_sshd_config_options:\n      ChallengeResponseAuthentication: \"no\"\n      Port: 22\n    ssh_ssh_config_options:\n    - hostnames: [\"*\"]\n      options:\n        Port: 22\n\tIdentityFile:\n\t- ~/.ssh/id_rsa\n\t- ~/.ssh/id_dca\n\t- ~/.ssh/id_ecdsa\n\t- ~/.ssh/id_ed25519\n    packages_install:\n      all:\n      - neovim\n      archlinux:\n      - python-pynvim\n      debian:\n      - python3-neovim\n      redhat:\n      - python36-neovim\n    dotfiles_repo_url: https://github.com/budimanjojo/dotfiles.git\n    dotfiles_repo_local_path: ~/dotfiles\n    dotfiles_files:\n    - .zshrc\n    - .tmux.conf\n    gitclone_repo_add:\n    - repo_url: https://github.com/budimanjojo/ansible-playbooks.git\n      repo_local_path: ~/ansible-playbooks\n    download_geturl_options:\n    - url: https://raw.githubusercontent.com/username/repo/master/file.txt\n      dest_file: ~/Downloads/file.txt\n      checksum: sha256:123584564yda2fas5df31fad23afa532\n    - url: https://raw.githubusercontent.com/username/repo/master/file2.txt\n      dest_file: ~/Documents/file2.txt\n      checksum: sha256:http://example.com/path/sha256sum.txt\n      owner: somebody\n      group: somebody\n      backup: yes\n    download_geturl_archive_options:\n    - url: https://raw.githubusercontent.com/username/repo/master/file.zip\n      dest_folder: ~/Downloads\n      checksum: sha256:123584564yda2fas5df31fad23afa532\n    haproxy_frontend_options:\n    - name: apiserver\n      options:\n        bind: \"*:6443\n\tmode: tcp\n\tdefault_backend: apiserver\n    haproxy_backend_options:\n    - name: apiserver\n      options:\n        mode: tcp\n\toption httpchk: GET /healthz\n\toption ssl-hello-chk: true\n\tserver:\n\t- node1 10.10.10.10:8443 check\n\t- node2 10.10.10.20:8443 check\n\t- node3 10.10.10.30:8443 check\n\n  roles:\n  - budimanjojo.users\n  - budimanjojo.sudo\n  - budimanjojo.ssh\n  - budimanjojo.packages\n  - budimanjojo.dotfiles\n  - budimanjojo.gitclone\n  - budimanjojo.download\n  - budimanjojo.zinit\n  - budimanjojo.vimplug\n  - budimanjojo.nodejs\n  - budimanjojo.haproxy\n```\n\n## License\n\nMIT License\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbudimanjojo%2Fansible-playbooks","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fbudimanjojo%2Fansible-playbooks","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fbudimanjojo%2Fansible-playbooks/lists"}