{"id":13550296,"url":"https://github.com/ironicbadger/infra","last_synced_at":"2026-01-12T15:40:53.443Z","repository":{"id":50085056,"uuid":"234387745","full_name":"ironicbadger/infra","owner":"ironicbadger","description":"99.7% less leaked credentials","archived":false,"fork":false,"pushed_at":"2026-01-11T04:49:04.000Z","size":2040,"stargazers_count":798,"open_issues_count":11,"forks_count":47,"subscribers_count":20,"default_branch":"main","last_synced_at":"2026-01-11T12:11:36.384Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"HCL","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ironicbadger.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-01-16T18:44:34.000Z","updated_at":"2026-01-11T00:52:47.000Z","dependencies_parsed_at":"2023-10-20T17:24:55.237Z","dependency_job_id":"51b91eaa-1107-400a-bc1e-41b91005f1c9","html_url":"https://github.com/ironicbadger/infra","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ironicbadger/infra","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ironicbadger%2Finfra","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ironicbadger%2Finfra/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ironicbadger%2Finfra/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ironicbadger%2Finfra/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ironicbadger","download_url":"https://codeload.github.com/ironicbadger/infra/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ironicbadger%2Finfra/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28341269,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-12T12:22:26.515Z","status":"ssl_error","status_checked_at":"2026-01-12T12:22:10.856Z","response_time":98,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T12:01:31.243Z","updated_at":"2026-01-12T15:40:53.434Z","avatar_url":"https://github.com/ironicbadger.png","language":"HCL","funding_links":[],"categories":["HCL","Jinja","others","Python"],"sub_categories":[],"readme":"# ironicbadger/infra\n\nWe started at 100% no leaked credentials. Each time a leak has occurred the counter gets decremented by one. Oops.\n\nThis repo is the living, breathing source of truth for my self-hosted infrastructure. I run everything in the open because open source matters.\n\n## Architecture\n\n```mermaid\n%%{init: {\"theme\": \"base\", \"themeVariables\": {\n    \"fontFamily\": \"monospace\",\n    \"primaryColor\": \"#5a5a5a\",\n    \"primaryTextColor\": \"#e8e8e8\",\n    \"primaryBorderColor\": \"#707070\",\n    \"lineColor\": \"#d4782c\",\n    \"secondaryColor\": \"#4a4a4a\",\n    \"tertiaryColor\": \"#3a3a3a\",\n    \"background\": \"#3a3a3a\",\n    \"mainBkg\": \"#4a4a4a\",\n    \"secondBkg\": \"#5a5a5a\",\n    \"textColor\": \"#e8e8e8\"\n}, \"flowchart\": {\"curve\": \"basis\"}, \"themeCSS\": \".edge-pattern-dotted { stroke-width: 2px !important; } .flowchart-link { stroke-width: 2px !important; } .edgeLabel { font-size: 14px; background: #2a2a2a; }\"}}%%\nflowchart LR\n    subgraph home[\"Home 🇺🇸\"]\n        direction TB\n        c137[\"c137\u003cbr/\u003emedia/storage server\u003cbr/\u003ezpool: rust (164TB)\"]\n        ms01[\"ms01\u003cbr/\u003eapp Server\u003cbr/\u003eCaddy, DNS, Home Assistant\"]\n    end\n\n    subgraph offsite[\"Off-site\"]\n        direction TB\n        ktz-cloud[\"ktz-cloud\u003cbr/\u003eVPS 🇺🇸\"]\n        igloo[\"igloo - Canada 🇨🇦\u003cbr/\u003ezpool: tank (62TB)\"]\n        snowball[\"snowball - UK 🇬🇧\"]\n    end\n\n    c137 -.-\u003e|\"zrepl via tailscale\"| igloo\n    c137 -.-\u003e|\"zrepl via tailscale\"| snowball\n    c137 \u003c-.-\u003e|\"zrepl via tailscale\"| ktz-cloud\n```\n\n## Technologies\n\n- **Ansible** - Configuration management\n- **Docker Compose** - Container orchestration (via `docker-compose-generator`)\n- **SOPS + age** - Secret encryption\n- **Tailscale** - Mesh VPN\n- **ZFS + zrepl** - Storage and replication\n- **Just** - Task runner\n\n## Roles Philosophy\n\nRoles are sourced three ways:\n\n| Type | Location | Purpose |\n|------|----------|---------|\n| **Submodules** | `roles/ironicbadger.*` | Reusable roles maintained in separate repos. Pinned to specific commits. |\n| **Galaxy** | `requirements.yaml` | Community roles (e.g., `geerlingguy.docker`). Installed via `just reqs`. |\n| **Local** | `roles/\u003cname\u003e` | Project-specific roles not useful elsewhere (e.g., `zrepl`, `ktz-server-welcome`). |\n\n## Prerequisites\n\n- Ansible\n- SOPS with age keyfile at `~/.config/sops/age/keys.txt`\n- SSH access to target hosts\n\n## Usage\n\n```bash\njust reqs              # Install galaxy dependencies\njust run \u003chost\u003e \u003ctags\u003e # Run playbook on host\njust compose \u003chost\u003e    # Deploy docker-compose services\njust sops \u003cfile\u003e       # Edit encrypted secrets\njust sub-update        # Update git submodules\n```\n\n## Structure\n\n```\n├── run.yaml              # Main playbook\n├── hosts.ini             # Inventory\n├── justfile              # Task automation\n├── group_vars/           # Variables (some SOPS encrypted)\n├── roles/                # Ansible roles\n└── services/             # Docker Compose configs per host\n    └── \u003chostname\u003e/\n        └── \u003c##-category\u003e/\n            ├── compose.yaml\n            └── config-\u003capp\u003e/\n```\n\nServices are organized under `services/\u003chostname\u003e/\u003c##-category\u003e/`. The `docker-compose-generator` role merges these into a single compose file on deployment.\n\n\n## Core Edge Nodes (VIP)\n\nCaddy and AdGuardHome are configured to run using keepalived and a floating VIP.\n\n| Host | IP | Role | Hardware |\n|------|-----|------|----------|\n| core-pi5 | 10.42.0.5 | Primary | Raspberry Pi 5 |\n| core-zima | 10.42.0.6 | Backup | ZimaBlade |\n| **VIP** | **10.42.0.53** | Floating | - |\n\n### Services\n\n- **AdGuard Home** - Local DNS resolution (port 53, web UI on 3000)\n- **Caddy** - Reverse proxy with automatic TLS\n- **Keepalived** - VRRP failover for VIP\n- **Chrony** - NTP time synchronization\n- **AdGuard Home Sync** - Config replication from primary to backup\n\n### Usage\n\n```bash\njust core                 # Run full core playbook\njust core --tags caddy    # Run only caddy role\njust core --tags network  # Run only network role\njust core --tags adguard  # Run only adguard role\n```\n\n### Network Backend\n\nThe `core-network` role supports two backends configured via `network_backend`:\n\n- `networkd` - systemd-networkd (Debian)\n- `networkmanager` - NetworkManager (Raspberry Pi OS)\n\nThe role removes dhcpcd packages and writes a static `/etc/resolv.conf`.","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fironicbadger%2Finfra","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fironicbadger%2Finfra","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fironicbadger%2Finfra/lists"}