Stage 4 of REFACTOR_PLAN.md. - Merge ansible/ansible.cfg into root ansible.cfg (single source of truth); the dual-config setup silently broke documented commands and lost host_key_checking=False when run from the ansible/ directory. - Add ansible/requirements.yml pinning community.general, ansible.posix, community.docker -- previously undocumented deps of the glances/watch-party roles that would fail a fresh bootstrap. - Align K3s version to v1.32.4+k3s1 across roles/k3s-server, roles/k3s-agent, and host_vars/gpu-node.yaml defaults (was skewed: .2 vs .4). This only changes what a *future* provision installs -- minisforum/debian are still live on v1.32.2+k3s1 until separately upgraded. - Fix kubeconfig fetch/replace path mismatch in k3s-server role: the `fetch` task (flat: true) writes to ~/.kube/config, but `replace` was targeting a /tmp/k3s-minisforum.yaml nothing creates -- would break a fresh rebuild. - gitea-runner: only remove /run/docker.sock when it's actually a directory (task name implied a check that wasn't there); tighten registration-token systemd unit from 0644 to 0600. - nvidia: stop unconditionally reporting `changed` (and restarting Docker) on every run for an idempotent runtime-configure command. - Gate the K3s join-token debug print and WireGuard client-config/QR display behind opt-in vars (k3s_show_token, wireguard_show_client_configs), default off -- both were printing real secrets to console on every run. - Parameterize the docker role for Debian and Ubuntu; homeassistant now depends on it (meta/main.yaml) instead of duplicating a Debian-only Docker install inline. - FQCN cleanup across wireguard, homeassistant, and ollama roles/handlers (bare module names -> ansible.builtin.*/community.general.*/ansible.posix.*), plus a few ansible-lint name-casing/idiom fixes. Handler renames verified against their `notify:` call sites so notifications still fire. - Update ansible/README.md and root README.md: add gpu-node/gpu_workstation (4th host, previously undocumented), docker/nvidia roles, setup-gpu-node.yaml, homeassistant.yaml, requirements.yml install step; correct the "Legacy" homeassistant label (it's the only thing serving ha.home.arpa); correct the Gitea ingress/backup-storage doc-drift; flag the Grafana/Loki static-PV binding drift discovered via live cluster check. Verified: all playbooks pass `ansible-playbook --syntax-check`, yamllint clean. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
54 lines
2.2 KiB
YAML
54 lines
2.2 KiB
YAML
# Host vars for: gpu-node (GPU workstation — spot K3s agent)
|
|
ansible_python_interpreter: /usr/bin/python3.12
|
|
|
|
# ── common ─────────────────────────────────────────────────────────────────────
|
|
timezone: Asia/Tokyo
|
|
username: nik
|
|
|
|
base_packages:
|
|
- curl
|
|
- git
|
|
- htop
|
|
- vim
|
|
- wget
|
|
- ca-certificates
|
|
- gnupg
|
|
- lsb-release
|
|
- build-essential
|
|
|
|
ufw_allowed_ports:
|
|
- { port: "430", proto: tcp, comment: "SSH" }
|
|
- { port: "11434", proto: tcp, comment: "Ollama API" }
|
|
- { port: "61208", proto: tcp, comment: "Glances web UI" }
|
|
|
|
data_dirs: []
|
|
|
|
# ── nvidia ─────────────────────────────────────────────────────────────────────
|
|
nvidia_driver_version: "570"
|
|
cuda_version: "12-8"
|
|
|
|
# ── k3s-agent ──────────────────────────────────────────────────────────────────
|
|
k3s_server_url: "https://192.168.7.77:6443"
|
|
k3s_node_token: "{{ vault_k3s_node_token }}"
|
|
|
|
# Check current cluster version with: k3s --version on minisforum
|
|
# Kept in sync with roles/k3s-server and roles/k3s-agent defaults — all three
|
|
# must match; see ansible/README.md "K3s version" note.
|
|
k3s_version: "v1.32.4+k3s1"
|
|
|
|
k3s_node_labels:
|
|
node-role: gpu
|
|
nik4nao.com/node-type: spot
|
|
nik4nao.com/gpu: "true"
|
|
|
|
k3s_node_taints:
|
|
- "spot=true:NoSchedule"
|
|
|
|
# ── ollama ─────────────────────────────────────────────────────────────────────
|
|
ollama_port: 11434
|
|
ollama_models:
|
|
- qwen3:4b
|
|
ollama_models_dir: /usr/share/ollama/.ollama/models
|
|
|
|
# ── glances ────────────────────────────────────────────────────────────────────
|
|
# no extra vars — uses role defaults |