mirror of
https://github.com/kevinveenbirkenbach/computer-playbook.git
synced 2025-09-24 11:06:24 +02:00
- Remove stray spaces after include_role: across many roles to ensure clean YAML and consistent linting/formatting. - Listmonk: - Introduce LISTMONK_CONFIG_HOST = [ docker_compose.directories.config, 'config.toml' ] | path_join - Use that var in the template task (dest) and the docker-compose volume mount - Matrix: - Build MATRIX_SYNAPSE_CONFIG_PATH_HOST, MATRIX_SYNAPSE_LOG_PATH_HOST, and MATRIX_ELEMENT_CONFIG_PATH_HOST via path_join - Mobilizon: - Build mobilizon_host_conf_exs_file via path_join - Keep get_app_conf strictness unchanged (defaults to True in our filter), so behavior remains strict even though the explicit third arg was dropped - Simpleicons: - Build server.js and package.json host paths via path_join - Numerous web-app roles (Confluence, Discourse, EspoCRM, Friendica, Funkwhale, Gitea, GitLab, Jenkins, Joomla, Listmonk, Mailu, Mastodon, Matomo, Matrix, MediaWiki, Mobilizon, Moodle, Nextcloud, OpenProject, Peertube, Pixelfed, Pretix, Roulette Wheel, Snipe-IT, Syncope, Taiga, WordPress, XWiki, Yourls) and web-svc roles (coturn, libretranslate, simpleicons) updated for consistent include_role formatting Why: - path_join avoids double slashes and missing separators across different config roots - Consistent include_role: formatting improves readability and prevents linter noise Ref: - Conversation: https://chatgpt.com/share/68d14711-727c-800f-b454-7dc4c3c1f4cb
86 lines
2.7 KiB
YAML
86 lines
2.7 KiB
YAML
---
|
|
- name: "load docker, db and proxy for {{ application_id }}"
|
|
include_role:
|
|
name: sys-stk-full-stateful
|
|
vars:
|
|
docker_compose_flush_handlers: false
|
|
proxy_extra_configuration: >-
|
|
{% if not LISTMONK_PUBLIC_API_ENABLED | bool %}
|
|
{{ lookup('file', '{{ playbook_dir }}/roles/web-app-listmonk/files/deactivate-public-api.conf') }}
|
|
{% else %}
|
|
""
|
|
{% endif %}
|
|
|
|
- name: add config.toml
|
|
template:
|
|
src: "config.toml.j2"
|
|
dest: "{{ LISTMONK_CONFIG_HOST }}"
|
|
notify: docker compose up
|
|
|
|
- meta: flush_handlers
|
|
|
|
- name: Check if listmonk database is already initialized
|
|
command: docker compose exec -T {{ database_host }} psql -U {{ database_username }} -d {{ database_name }} -c "\dt"
|
|
register: db_tables
|
|
changed_when: false
|
|
failed_when: false
|
|
|
|
- name: Run Listmonk setup only if DB is empty
|
|
command:
|
|
cmd: docker compose run -T --rm application sh -c "yes | ./listmonk --install"
|
|
chdir: "{{ docker_compose.directories.instance }}"
|
|
when: "'No relations found.' in db_tables.stdout"
|
|
|
|
- name: "Listmonk | run DB/schema upgrade (non-interactive)"
|
|
ansible.builtin.shell: |
|
|
set -o pipefail
|
|
echo "y" | docker compose run -T application ./listmonk --upgrade
|
|
args:
|
|
chdir: "{{ docker_compose.directories.instance }}"
|
|
when: MODE_UPDATE | bool
|
|
|
|
- name: Build OIDC settings JSON
|
|
set_fact:
|
|
oidc_settings_json: >-
|
|
{{ {
|
|
"enabled": True,
|
|
"client_id": OIDC.CLIENT.ID,
|
|
"provider_url": OIDC.CLIENT.ISSUER_URL,
|
|
"client_secret": OIDC.CLIENT.SECRET
|
|
} | to_json }}
|
|
|
|
- name: Update administrator email and password login in Listmonk (as superuser)
|
|
shell: |
|
|
docker exec -i {{ database_host }} psql \
|
|
-U {{ database_username }} \
|
|
-v ON_ERROR_STOP=1 \
|
|
-d {{ database_name }} << 'EOSQL'
|
|
UPDATE users
|
|
SET email = '{{ users.administrator.email }}',
|
|
password_login = {{ 'false' if applications | get_app_conf(application_id, 'features.oidc', True) else 'true' }}
|
|
WHERE username = 'administrator';
|
|
EOSQL
|
|
args:
|
|
executable: /bin/bash
|
|
|
|
- name: Apply all Listmonk settings
|
|
shell: |
|
|
docker exec -i {{ database_host }} psql \
|
|
-U {{ database_username }} \
|
|
-v ON_ERROR_STOP=1 \
|
|
-d {{ database_name }} << 'EOSQL'
|
|
UPDATE settings
|
|
SET value = '{{ item.value }}'::jsonb
|
|
WHERE key = '{{ item.key }}';
|
|
EOSQL
|
|
args:
|
|
executable: /bin/bash
|
|
loop: "{{ LISTMONK_SETTINGS }}"
|
|
loop_control:
|
|
label: "{{ item.key }}"
|
|
when: item.when is not defined or item.when
|
|
no_log: "{{ MASK_CREDENTIALS_IN_LOGS | bool }}"
|
|
async: "{{ ASYNC_TIME if ASYNC_ENABLED | bool else omit }}"
|
|
poll: "{{ ASYNC_POLL if ASYNC_ENABLED | bool else omit }}"
|
|
|