Stage 4 of REFACTOR_PLAN.md. - Merge ansible/ansible.cfg into root ansible.cfg (single source of truth); the dual-config setup silently broke documented commands and lost host_key_checking=False when run from the ansible/ directory. - Add ansible/requirements.yml pinning community.general, ansible.posix, community.docker -- previously undocumented deps of the glances/watch-party roles that would fail a fresh bootstrap. - Align K3s version to v1.32.4+k3s1 across roles/k3s-server, roles/k3s-agent, and host_vars/gpu-node.yaml defaults (was skewed: .2 vs .4). This only changes what a *future* provision installs -- minisforum/debian are still live on v1.32.2+k3s1 until separately upgraded. - Fix kubeconfig fetch/replace path mismatch in k3s-server role: the `fetch` task (flat: true) writes to ~/.kube/config, but `replace` was targeting a /tmp/k3s-minisforum.yaml nothing creates -- would break a fresh rebuild. - gitea-runner: only remove /run/docker.sock when it's actually a directory (task name implied a check that wasn't there); tighten registration-token systemd unit from 0644 to 0600. - nvidia: stop unconditionally reporting `changed` (and restarting Docker) on every run for an idempotent runtime-configure command. - Gate the K3s join-token debug print and WireGuard client-config/QR display behind opt-in vars (k3s_show_token, wireguard_show_client_configs), default off -- both were printing real secrets to console on every run. - Parameterize the docker role for Debian and Ubuntu; homeassistant now depends on it (meta/main.yaml) instead of duplicating a Debian-only Docker install inline. - FQCN cleanup across wireguard, homeassistant, and ollama roles/handlers (bare module names -> ansible.builtin.*/community.general.*/ansible.posix.*), plus a few ansible-lint name-casing/idiom fixes. Handler renames verified against their `notify:` call sites so notifications still fire. - Update ansible/README.md and root README.md: add gpu-node/gpu_workstation (4th host, previously undocumented), docker/nvidia roles, setup-gpu-node.yaml, homeassistant.yaml, requirements.yml install step; correct the "Legacy" homeassistant label (it's the only thing serving ha.home.arpa); correct the Gitea ingress/backup-storage doc-drift; flag the Grafana/Loki static-PV binding drift discovered via live cluster check. Verified: all playbooks pass `ansible-playbook --syntax-check`, yamllint clean. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
92 lines
3.2 KiB
YAML
92 lines
3.2 KiB
YAML
---
|
|
# Part of role: ollama
|
|
# Called by: ansible/playbooks/setup-ollama.yaml
|
|
# ansible/playbooks/setup-gpu-node.yaml
|
|
# Description: Installs Ollama, configures it to bind to all interfaces, and pulls models.
|
|
# Supports macOS (Homebrew + launchd) and Linux (install script + systemd).
|
|
|
|
# ── macOS ──────────────────────────────────────────────────────────────────────
|
|
- name: Install ollama via Homebrew
|
|
community.general.homebrew:
|
|
name: ollama
|
|
state: present
|
|
when: ansible_facts['system'] == 'Darwin'
|
|
|
|
- name: Deploy ollama launchd plist
|
|
ansible.builtin.template:
|
|
src: ollama.plist.j2
|
|
dest: /Library/LaunchDaemons/com.ollama.ollama.plist
|
|
owner: root
|
|
group: wheel
|
|
mode: "0644"
|
|
become: true
|
|
notify: Restart ollama
|
|
when: ansible_facts['system'] == 'Darwin'
|
|
|
|
- name: Load ollama launchd service
|
|
become: true
|
|
ansible.builtin.command: launchctl load -w /Library/LaunchDaemons/com.ollama.ollama.plist
|
|
args:
|
|
creates: /var/run/ollama.pid
|
|
ignore_errors: true
|
|
when: ansible_facts['system'] == 'Darwin'
|
|
|
|
# ── Linux ──────────────────────────────────────────────────────────────────────
|
|
- name: Install ollama via install script
|
|
ansible.builtin.shell:
|
|
cmd: curl -fsSL https://ollama.com/install.sh | sh
|
|
creates: /etc/systemd/system/ollama.service
|
|
when: ansible_facts['system'] == 'Linux'
|
|
|
|
- name: Create ollama systemd override directory
|
|
ansible.builtin.file:
|
|
path: /etc/systemd/system/ollama.service.d
|
|
state: directory
|
|
mode: "0755"
|
|
become: true
|
|
when: ansible_facts['system'] == 'Linux'
|
|
|
|
- name: Deploy ollama systemd override
|
|
ansible.builtin.template:
|
|
src: ollama-override.conf.j2
|
|
dest: /etc/systemd/system/ollama.service.d/override.conf
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
become: true
|
|
notify: Restart ollama linux
|
|
when: ansible_facts['system'] == 'Linux'
|
|
|
|
- name: Enable and start ollama service
|
|
ansible.builtin.systemd:
|
|
name: ollama
|
|
state: started
|
|
enabled: true
|
|
daemon_reload: true
|
|
become: true
|
|
when: ansible_facts['system'] == 'Linux'
|
|
|
|
# ── shared ─────────────────────────────────────────────────────────────────────
|
|
- name: Wait for ollama to be ready
|
|
ansible.builtin.uri:
|
|
url: "http://localhost:{{ ollama_port }}"
|
|
status_code: 200
|
|
register: result
|
|
until: result.status == 200
|
|
retries: 10
|
|
delay: 3
|
|
|
|
- name: Check installed ollama models
|
|
ansible.builtin.uri:
|
|
url: "http://localhost:{{ ollama_port }}/api/tags"
|
|
return_content: true
|
|
register: ollama_tags
|
|
|
|
- name: Pull ollama models
|
|
ansible.builtin.command: >
|
|
{{ '/opt/homebrew/bin/ollama' if ansible_facts['system'] == 'Darwin' else '/usr/local/bin/ollama' }}
|
|
pull {{ item }}
|
|
loop: "{{ ollama_models }}"
|
|
when: item not in (ollama_tags.json.models | map(attribute='name') | list)
|
|
environment:
|
|
OLLAMA_HOST: "http://localhost:{{ ollama_port }}" |