{"id":18722401,"url":"https://github.com/nleiva/ansible-home","last_synced_at":"2025-08-31T20:31:15.709Z","repository":{"id":87030906,"uuid":"325457399","full_name":"nleiva/ansible-home","owner":"nleiva","description":"Collection of playbooks I run in my personal home-lab.","archived":false,"fork":false,"pushed_at":"2023-04-05T19:56:20.000Z","size":6865,"stargazers_count":9,"open_issues_count":0,"forks_count":1,"subscribers_count":3,"default_branch":"main","last_synced_at":"2024-11-07T13:52:20.021Z","etag":null,"topics":["ansible","grafana","playbook","raspberry-pi","raspbian"],"latest_commit_sha":null,"homepage":"","language":"Jinja","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/nleiva.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-12-30T04:49:21.000Z","updated_at":"2024-09-14T22:27:59.000Z","dependencies_parsed_at":null,"dependency_job_id":"98d35d16-ba16-4d01-8ba4-c66294cafb24","html_url":"https://github.com/nleiva/ansible-home","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nleiva%2Fansible-home","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nleiva%2Fansible-home/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nleiva%2Fansible-home/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/nleiva%2Fansible-home/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/nleiva","download_url":"https://codeload.github.com/nleiva/ansible-home/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":231622025,"owners_count":18401831,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","grafana","playbook","raspberry-pi","raspbian"],"created_at":"2024-11-07T13:41:19.273Z","updated_at":"2024-12-28T12:15:52.610Z","avatar_url":"https://github.com/nleiva.png","language":"Jinja","funding_links":[],"categories":[],"sub_categories":[],"readme":"# My Home Lab\n\n![Ansible Lint](https://github.com/nleiva/ansible-home/workflows/Ansible%20Lint/badge.svg)\n\nThese are the playbooks I run in my personal lab.\n\n\u003cp align=\"center\"\u003e\n  \u003cimg width=\"454\" height=\"605\" title=\"My Home Lab\" src=\"static/home-lab.jpeg\"\u003e\u003cbr\u003e\n  \u003cb\u003eEarly setup of my lab\u003c/b\u003e\u003cbr\u003e\n\u003c/p\u003e\n\n## Requirements\n\n`ssh-copy-id` to every host before running these playbooks. \n\n## Playbooks\n\n### 1. Setup Lab instances\n\nTo perform some basic management tasks such as upgrading packages or updating Firewall rules:\n\n```bash\nansible-playbook setup.yml --ask-become-pass -v\n```\n\n#### Dependencies\n\nThe role names will be according to the [requirements.yml](roles/requirements.yml) file definition.\n\n```bash\nansible-galaxy role install -r roles/requirements.yml\n```\n\n### 2. Install Pi-hole\n\nTo install Pi-hole:\n\n```bash\nansible-playbook pi-hole.yml --ask-become-pass -v\n```\n\nTo update the list of whitelisted websites per [WHITELIST](https://github.com/anudeepND/whitelist):\n\n```bash\nansible-playbook pi-hole.yml --ask-become-pass -v --tags whitelist\n```\n\n[Block lists](https://firebog.net/) can be added via the [GUI](https://docs.pi-hole.net/database/gravity/example/).\n\n### 3. Cloud monitoring with Grafana Agent\n\nInstall [Grafana Cloud Agent](https://github.com/grafana/agent) in a RHEL/Debian host using [grafana_agent](https://galaxy.ansible.com/nleiva/grafana_agent)'s role.\n\n```bash\nansible-playbook grafana-cloud.yml --ask-become-pass -v\n```\n\n### 4. Initial setup for a new machine\n\nCreates my user (assuming I can ssh as root) and adds my SSH public key to the authorized users (instead of `ssh-copy-id`). \nRegisters the system if it's RHEL.\n\n\n```bash\nansible-playbook initial-setup.yml --ask-become-pass --ask-vault-pass\n```\n\n### 5. Install RH Satellite (WIP)\n\nInstalls RH Satellite 6.7 (Work in Progress) in RHEL 7.\n\n\n```bash\nansible-playbook install-satellite.yml --ask-become-pass --ask-vault-pass\n```\n\n### 6. Run OpenSCAP\n\nPerform compliance and vulnerability scanning on RHEL 8 with OpenSCAP.\n\n- [ ] TODO: Profile selection: STIG, PCI-DSS, or HIPAA\n\n\n```bash\nansible-playbook openscap.yml --ask-become-pass\n```\n\n## HW details\n\n### 2nd generation\n\u003cp align=\"center\"\u003e\n  \u003cimg width=\"605\" height=\"454\" title=\"My Home Lab v2\" src=\"static/lab_rack.jpeg\"\u003e\u003cbr\u003e\n  \u003cb\u003eSecond iteration of my lab\u003c/b\u003e\u003cbr\u003e\n\u003c/p\u003e\n\n\n- [6U Wall Mount Rack Cabinet Enclosure](https://smile.amazon.com/gp/product/B01K1JJHTO)\n- [Cantilever Server Shelf Rack Mount 19 Inch 1U](https://smile.amazon.com/gp/product/B008LUW3ZG)\n- [Intel® NUC Kit NUC8i5BEH](https://www.intel.com/content/www/us/en/products/boards-kits/nuc/kits/nuc8i5beh.html)\n- [Raspberry Pi 4 Model B](https://www.raspberrypi.org/products/raspberry-pi-4-model-b/)\n- [Raspberry Pi 3 Model B](https://www.raspberrypi.org/products/raspberry-pi-3-model-b/)\n- [Raspberry Pi Cluster Case 6-Layers](https://smile.amazon.com/gp/product/B07K72STFB)\n- [5-Pack Snagless Short Cat6 Ethernet Cable](https://smile.amazon.com/gp/product/B00C2DZ85U)\n- [TP-Link Litewave 8 Port Gigabit Ethernet Switch](https://smile.amazon.com/gp/product/B086384H7C)\n- [CyberPower LE850G UPS Battery Backup](https://www.costco.com/cyberpower-le850g-ups-battery-backup-with-surge-protection.product.100519070.html)\n\n### 3rd generation\n\u003cp align=\"center\"\u003e\n  \u003cimg width=\"605\" height=\"454\" title=\"My Home Lab v3\" src=\"static/lab3.jpg\"\u003e\u003cbr\u003e\n  \u003cb\u003eThird iteration of my lab\u003c/b\u003e\u003cbr\u003e\n\u003c/p\u003e\n\n- [Lenovo ThinkCentre M910Q Tiny Desktop Computer](https://www.amazon.com/gp/product/B08MMQH98H): Intel Core i7-6700T Upto 3.6GHz, 32GB RAM, 1TB NVMe SSD.\n- [Dell OptiPlex 3060 MFF](https://www.dellrefurbished.com/category/store-dt-ultra/desktops/ultra-small/1.html?model_f[]=OptiPlex%203060): Intel Core i5-8500T 2.10 GHz, 16GB RAM, 500GB HDD.\n- [Switch 8 PoE (60W)](https://store.ui.com/collections/unifi-network-switching/products/unifi-switch-8-60w)\n- [Switch Flex Mini](https://store.ui.com/collections/unifi-network-switching/products/usw-flex-mini)\n- [AC Infinity MULTIFAN S1](https://www.amazon.com/gp/product/B00G059G86)\n- [APC® 8-Outlet Uninterruptible Power Supply, 1000VA/600 Watts, BX1000M-LM60](https://www.officedepot.com/a/products/5182451/APC-8-Outlet-Uninterruptible-Power-Supply/)","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnleiva%2Fansible-home","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fnleiva%2Fansible-home","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fnleiva%2Fansible-home/lists"}