Set up repo structure and implement base role
- Document architecture decisions in README (Ansible + Docker Compose + Traefik) - Scaffold Ansible layout: inventory, site.yml, group_vars, 9 service roles - Implement base role: package install, deploy user, SSH hardening, UFW firewall (22/80/443), fail2ban, unattended-upgrades - Add reinstall runbook in docs/runbook.md - Add ansible/requirements.yml for community.general and ansible.posix
This commit is contained in:
@@ -0,0 +1,75 @@
|
||||
Info:
|
||||
--
|
||||
Server:
|
||||
Strato STRATO VPS Linux VC4-8
|
||||
Order Number: 9478462
|
||||
|
||||
Customer Number: 73171334
|
||||
Customer Login: https://www.strato.de/apps/CustomerService
|
||||
|
||||
Cores: 4 Cores
|
||||
RAM: 8 GB RAM
|
||||
Storage: 240 HDD
|
||||
|
||||
IPv4: 217.154.207.148
|
||||
IPv6: 2a01:239:35b:c400::1
|
||||
|
||||
OS: Ubuntu 24.04 LTS
|
||||
|
||||
DNS Names:
|
||||
cloud.ladkau.de
|
||||
gitea.ladkau.de
|
||||
nextcloud.ladkau.de
|
||||
sso.ladkau.de
|
||||
mail.ladkau.de
|
||||
cr.ladkau.de
|
||||
k8s.ladkau.de
|
||||
|
||||
Purpose:
|
||||
--
|
||||
This repository tracks the complete server configuration so the server can be
|
||||
fully reinstalled from scratch using only this repo. Every configuration change
|
||||
must be committed here. The git history serves as the change log.
|
||||
|
||||
Architecture:
|
||||
--
|
||||
Provisioning: Ansible
|
||||
Ansible playbooks configure the OS and deploy all services. Roles are
|
||||
idempotent — re-running them brings the server back to the desired state
|
||||
without side effects. The master playbook is ansible/site.yml.
|
||||
|
||||
Service runtime: Docker Compose
|
||||
Each service runs as a Docker Compose stack. Compose files live inside
|
||||
their respective Ansible roles (roles/<service>/files/docker-compose.yml).
|
||||
This keeps service definition and deployment config together.
|
||||
|
||||
Reverse proxy / TLS: Traefik
|
||||
Traefik is the single entry point for all HTTP/HTTPS traffic. It runs as
|
||||
a Docker Compose service and routes to other containers via Docker labels.
|
||||
TLS certificates are issued automatically via Let's Encrypt (ACME).
|
||||
|
||||
Repo layout:
|
||||
--
|
||||
ansible/
|
||||
inventory.ini # host address and connection vars
|
||||
site.yml # master playbook — runs all roles in order
|
||||
group_vars/all.yml # shared variables (domains, image versions, ...)
|
||||
roles/
|
||||
base/ # OS hardening, non-root user, SSH, ufw firewall
|
||||
docker/ # Docker Engine + Compose plugin install
|
||||
traefik/ # reverse proxy, TLS termination
|
||||
gitea/ # self-hosted Git
|
||||
nextcloud/ # file storage and collaboration
|
||||
sso/ # Single Sign-On
|
||||
mail/ # mail server
|
||||
registry/ # container registry (cr.ladkau.de)
|
||||
k8s/ # k3s Kubernetes node
|
||||
docs/
|
||||
runbook.md # step-by-step reinstall instructions
|
||||
keys/
|
||||
*.pub # public SSH keys (private keys are gitignored)
|
||||
|
||||
SSH keys:
|
||||
--
|
||||
root_cloud_ladkau_de — root access (initial setup only)
|
||||
notroot_cloud_ladkau_de — non-root deploy user (used by Ansible)
|
||||
Reference in New Issue
Block a user