{"id":13583837,"url":"https://github.com/weareinteractive/ansible-apt","last_synced_at":"2025-03-20T18:17:03.373Z","repository":{"id":19232335,"uuid":"22466957","full_name":"weareinteractive/ansible-apt","owner":"weareinteractive","description":"Ansible role that configures apt \u0026 installs/updates packages.","archived":false,"fork":false,"pushed_at":"2022-06-01T13:44:17.000Z","size":124,"stargazers_count":29,"open_issues_count":1,"forks_count":20,"subscribers_count":5,"default_branch":"master","last_synced_at":"2025-01-25T16:42:00.296Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Jinja","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/weareinteractive.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2014-07-31T11:30:39.000Z","updated_at":"2024-02-05T10:42:14.000Z","dependencies_parsed_at":"2022-07-10T07:46:11.342Z","dependency_job_id":null,"html_url":"https://github.com/weareinteractive/ansible-apt","commit_stats":null,"previous_names":[],"tags_count":37,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weareinteractive%2Fansible-apt","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weareinteractive%2Fansible-apt/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weareinteractive%2Fansible-apt/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/weareinteractive%2Fansible-apt/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/weareinteractive","download_url":"https://codeload.github.com/weareinteractive/ansible-apt/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":244666591,"owners_count":20490287,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:03:50.440Z","updated_at":"2025-03-20T18:17:03.354Z","avatar_url":"https://github.com/weareinteractive.png","language":"Jinja","funding_links":[],"categories":["Jinja"],"sub_categories":[],"readme":"# Ansible weareinteractive.apt role\n\n[![Build Status](https://img.shields.io/travis/weareinteractive/ansible-apt.svg)](https://travis-ci.com/weareinteractive/ansible-apt)\n[![Galaxy](http://img.shields.io/badge/galaxy-weareinteractive.apt-blue.svg)](https://galaxy.ansible.com/weareinteractive/apt)\n[![GitHub Tags](https://img.shields.io/github/tag/weareinteractive/ansible-apt.svg)](https://github.com/weareinteractive/ansible-apt)\n[![GitHub Stars](https://img.shields.io/github/stars/weareinteractive/ansible-apt.svg)](https://github.com/weareinteractive/ansible-apt)\n\n\u003e `weareinteractive.apt` is an [Ansible](http://www.ansible.com) role which:\n\u003e\n\u003e * updates apt\n\u003e * cleans up apt\n\u003e * configures apt\n\u003e * ensures packages\n\u003e * add repositories\n\u003e * add keys\n\u003e * apt pinning\n\u003e * manages unattended upgrades\n\u003e * optionally alters solution cost\n\u003e * optionally allows filesystems to be remounted\n\n**Note:**\n\n\u003e Since Ansible Galaxy supports [organization](https://www.ansible.com/blog/ansible-galaxy-2-release) now, this role has moved from `franklinkim.apt` to `weareinteractive.apt`!\n\n## Installation\n\nUsing `ansible-galaxy`:\n\n```shell\n$ ansible-galaxy install weareinteractive.apt\n```\n\nUsing `requirements.yml`:\n\n```yaml\n- src: weareinteractive.apt\n```\n\nUsing `git`:\n\n```shell\n$ git clone https://github.com/weareinteractive/ansible-apt.git weareinteractive.apt\n```\n\n## Dependencies\n\n* Ansible \u003e= 2.4\n\n## Variables\n\nHere is a list of all the default variables for this role, which are also available in `defaults/main.yml`.\n\n```yaml\n---\n# apt_unattended_upgrades_blacklist:\n#   - vim\n#   - libc6\n# apt_mails:\n#   - root\n#   - foo@dev.null\n# apt_keys:\n#   - id: 473041FA\n#     file: /tmp/apt.gpg\n#     data: \"{{ lookup('file', 'apt.asc') }}\"\n#     keyring: /etc/apt/trusted.gpg.d/debian.gpg\n#     keyserver: keyserver.ubuntu.com\n#     url: https://ftp-master.debian.org/keys/archive-key-6.0.asc\n#     validate_certs: yes\n#     state: present\n# apt_repositories:\n#   - codename: trusty\n#     filename: google-chrome\n#     mode: 0644\n#     repo: 'ppa:nginx/stable'\n#     state: present\n#     update_cache: yes\n\n# depenencies packages\napt_dependencies:\n  - aptitude\n  - python3-apt\n  - python3-pycurl\n# sets the amount of time the cache is valid\napt_cache_valid_time: 3600\n# upgrade system: safe | full | dist\napt_upgrade: no\n# packages to ensure\napt_packages: []\n# purge configuration when removing packages\napt_remove_purge: no\n# default package state\napt_package_state: 'present'\n# remove packages that are no longer needed for dependencies\napt_autoremove: yes\n# remove .deb files for packages no longer on your system\napt_autoclean: yes\n# .deb packages to install.\napt_deb_packages: []\n\n# https://people.debian.org/~hmh/invokerc.d-policyrc.d-specification.txt\napt_policy: 101\n# whether or not suggested packages should be installed.\napt_install_suggests: no\n# do not install Recommended packages by default\napt_install_recommends: no\n# allow 'apt-get autoremove' to remove suggested packages\napt_remove_suggests: no\n# allow 'apt-get autoremove' to remove recommended packages\napt_remove_recommends: no\n# Enable the update/upgrade script\napt_periodic: yes\n# Do “apt-get update” automatically every n-days (0=disable)\napt_update_package_lists: 1\n# Do “apt-get upgrade –download-only” every n-days (0=disable)\napt_download_upgradeable_packages: 0\n# Do “apt-get autoclean” every n-days (0=disable)\napt_auto_clean_interval: 0\n\n# enable unattended-upgrades\napt_unattended_upgrades: yes\n# list of origins patterns to control which packages are upgraded\n# replaces allowed-origins, kept for compatibility\napt_unattended_upgrades_origins: []\n# List of allowed-origins, default value kept for compatibility\n# set to null to use origins-pattern\napt_unattended_upgrades_allowed:\n- ${distro_id}:${distro_codename}-security\n# list of packages to not update (regexp are supported)\napt_unattended_upgrades_blacklist: []\n# Split the upgrade into the smallest possible chunks so that\n# they can be interrupted with SIGUSR1. This makes the upgrade\n# a bit slower but it has the benefit that shutdown while a upgrade\n# is running is possible (with a small delay)\napt_unattended_upgrades_minimal_steps: no\n# Send email to this address for problems or packages upgrades\n# If empty or unset then no email is sent, make sure that you\n# have a working mail setup on your system. A package that provides\n# 'mailx' must be installed. E.g. \"user@example.com\"\napt_mails: []\n# Set this value to \"true\" to get emails only on errors. Default\n# is to always send a mail if Unattended-Upgrade::Mail is set\napt_unattended_upgrades_notify_error_only: yes\n# Do automatic removal of new unused dependencies after the upgrade\n# (equivalent to apt-get autoremove)\napt_unattended_upgrades_autoremove: yes\n# Automatically reboot *WITHOUT CONFIRMATION*\n# if the file /var/run/reboot-required is found after the upgrade\napt_unattended_upgrades_automatic_reboot: no\n# Automatically reboot even if there are users currently logged in.\napt_unattended_upgrades_automatic_reboot_with_users: no\n# If automatic reboot is enabled and needed, reboot at the specific\n# time instead of immediately\n# Values: now | 02:00 | ...\napt_unattended_upgrades_automatic_reboot_time: now\n# Enable logging to syslog.\napt_unattended_upgrades_syslog_enable: no\n# Specify syslog facility.\napt_unattended_upgrades_syslog_facility: daemon\n\n# Override download timer ? Default no\napt_unattended_upgrades_download_timer_override: null\n# In case of override :\n# apt_unattended_upgrades_download_timer_override:\n#   on_calendar_replace: (true|false) If true, delete default system schedule. If not, default and new schedules will be merged\n#   on_calendar: new schedule, see man systemd.time.7, example : 'Mon..Fri *-*-* 6:00'\n#   randomized_delay_sec: random delay in sec\n#   persistent: (true|false)\n# See systemd.time.5 for random delay and persistent\n\n# Override upgrade timer the same way\napt_unattended_upgrades_upgrade_timer_override: null\n# apt_unattended_upgrades_upgrade_timer_override:\n#   on_calendar_replace:\n#   on_calendar:\n#   randomized_delay_sec:\n#   persistent:\n\n# remount file system: currently supported options are rootfs and tmpfs\n#   tmpfs:  remount tmp before running if mounted noexec\n#   rootfs: remount root filesystem r/w before running if mounted r/o\napt_remount_filesystems: []\n\n# repositories to register\napt_repositories: []\n# gpg keys for external repositories\napt_keys: []\n# HTTP proxy server (optional)\n# apt_http_proxy_address:\n# HTTP pipeline depth (optional)\n# apt_http_pipeline_depth: 5\n\n# Change Aptitudes solution costs, default is not to change anything\n# Mirror https://lists.debian.org/543FF3BD.1020609@zen.co.uk\n# apt_aptitude_solution_cost:\n#   - priority\n#   - removals\n#   - canceled-actions\napt_aptitude_solution_cost: []\n\n# List of preferences options.\n# apt_preferences:\n#   - file: perl\n#     package: perl\n#     pin: \"version 5.20*\"\n#     priority: 1001\napt_preferences: []\n\n```\n\n## Handlers\n\nThese are the handlers that are defined in `handlers/main.yml`.\n\n```yaml\n---\n\n- name: reload systemd\n  systemd:\n    daemon_reload: true\n\n```\n\n\n## Usage\n\nThis is an example playbook:\n\n```yaml\n---\n\n- hosts: all\n  become: yes\n  roles:\n    - weareinteractive.apt\n  vars:\n    apt_cache_valid_time: 7200\n    apt_packages:\n      - vim\n      - tree\n      - name: ca-certificates\n        state: latest\n        hold: true\n      - name: zsh\n        state: absent\n        purge: true\n    apt_deb_packages:\n      - \"https://releases.hashicorp.com/vagrant/2.1.5/vagrant_2.1.5_x86_64.deb\"\n    apt_mails:\n      - root\n    apt_preferences:\n      - file: perl\n        package: perl\n        pin: \"version 5.20*\"\n        priority: 1001\n    apt_unattended_upgrades_notify_error_only: no\n    apt_remove_recommends: yes\n    apt_remove_suggests: yes\n    apt_remove_purge: yes\n\n```\n\n\n## Testing\n\n```shell\n$ git clone https://github.com/weareinteractive/ansible-apt.git\n$ cd ansible-apt\n$ make test\n```\n\n## Contributing\nIn lieu of a formal style guide, take care to maintain the existing coding style. Add unit tests and examples for any new or changed functionality.\n\n1. Fork it\n2. Create your feature branch (`git checkout -b my-new-feature`)\n3. Commit your changes (`git commit -am 'Add some feature'`)\n4. Push to the branch (`git push origin my-new-feature`)\n5. Create new Pull Request\n\n*Note: To update the `README.md` file please install and run `ansible-role`:*\n\n```shell\n$ gem install ansible-role\n$ ansible-role docgen\n```\n\n## License\nCopyright (c) We Are Interactive under the MIT license.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fweareinteractive%2Fansible-apt","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fweareinteractive%2Fansible-apt","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fweareinteractive%2Fansible-apt/lists"}