- docker: install Docker Engine from official apt repo, configure log rotation, create shared traefik_public network - traefik: reverse proxy with automatic Let's Encrypt TLS, dashboard on cloud.ladkau.de behind basic auth - gitea: self-hosted Git with PostgreSQL, Git-over-SSH on port 2222 - sso: Keycloak with PostgreSQL for OIDC/OAuth2 single sign-on - nextcloud: file storage with PostgreSQL, Redis, cron sidecar, CalDAV/CardDAV well-known redirects - mail: Roundcube webmail client with PostgreSQL - registry: Docker Registry v2 with htpasswd auth, no upload size limit - k8s: placeholder nginx page All secrets documented in vault.yml; runbook updated with per-service first-run notes.
Info:
Server: Strato STRATO VPS Linux VC4-8 Order Number: 9478462
Customer Number: 73171334
Customer Login: https://www.strato.de/apps/CustomerService
Cores: 4 Cores
RAM: 8 GB RAM
Storage: 240 HDD
IPv4: 217.154.207.148
IPv6: 2a01:239:35b:c400::1
OS: Ubuntu 24.04 LTS
DNS Names: cloud.ladkau.de gitea.ladkau.de nextcloud.ladkau.de sso.ladkau.de mail.ladkau.de cr.ladkau.de k8s.ladkau.de
Purpose:
This repository tracks the complete server configuration so the server can be fully reinstalled from scratch using only this repo. Every configuration change must be committed here. The git history serves as the change log.
Architecture:
Provisioning: Ansible Ansible playbooks configure the OS and deploy all services. Roles are idempotent — re-running them brings the server back to the desired state without side effects. The master playbook is ansible/site.yml.
Service runtime: Docker Compose Each service runs as a Docker Compose stack. Compose files live inside their respective Ansible roles (roles//files/docker-compose.yml). This keeps service definition and deployment config together.
Reverse proxy / TLS: Traefik Traefik is the single entry point for all HTTP/HTTPS traffic. It runs as a Docker Compose service and routes to other containers via Docker labels. TLS certificates are issued automatically via Let's Encrypt (ACME).
Repo layout:
ansible/
inventory.ini # host address and connection vars
site.yml # master playbook — runs all roles in order
group_vars/all.yml # shared variables (domains, image versions, ...)
roles/
base/ # OS hardening, non-root user, SSH, ufw firewall
docker/ # Docker Engine + Compose plugin install
traefik/ # reverse proxy, TLS termination
gitea/ # self-hosted Git
nextcloud/ # file storage and collaboration
sso/ # Single Sign-On
mail/ # mail server
registry/ # container registry (cr.ladkau.de)
k8s/ # k3s Kubernetes node
docs/
runbook.md # step-by-step reinstall instructions
keys/
*.pub # public SSH keys (private keys are gitignored)
SSH keys:
root_cloud_ladkau_de — root access (initial setup only)
notroot_cloud_ladkau_de — non-root deploy user (used by Ansible)