Changelog¶
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
Unreleased¶
Highlights: Apache no longer loads mod_info, which served the complete configuration including other modules' credentials. A broken PHP-FPM configuration aborts the run instead of taking the service down on the restart. Sudo rules deployed by freeipa_server can carry their commands again. The Bitwarden lookup can be told to abort instead of silently generating a new password, for runs against hosts whose credentials must already exist. The Grafana graph configuration for the Monitoring Plugins is no longer deployed on every ordinary run and has to be requested explicitly by its tag.
Breaking Changes¶
- role:collabora:
collabora__coolwsd_ssl_settings_ssl_verificationandcollabora__coolwsd_welcome_enablereach the deployedcoolwsd.xmlagain, and SSL verification of the WOPI host now defaults to strict. Both variables were only wired into a few old templates, so on newer versions the value came from the package instead of from the inventory, and most packages ship verification off. A host whose WOPI host presents a self-signed or otherwise untrusted certificate needscollabora__coolwsd_ssl_settings_ssl_verification: false, otherwise its documents stop loading. - role:apache_httpd:
mod_infois no longer enabled, so/server-infostops serving the complete Apache configuration, including the credentials of other modules. Hosts that need the endpoint re-enable theinfomodule in their inventory viaapache_httpd__mods__group_var/apache_httpd__mods__host_var. - role:monitoring_plugins: A source install now places the notification plugins in
/usr/lib64/nagios/plugins, next to the check plugins, and removes the/usr/lib64/nagios/plugins/notificationsdirectory it used before. This is where the shipped Icinga command definitions and the rpm/deb packages have always expected them. Adjust any command definition of your own that points into thenotificationssubdirectory. - role:collabora: Drop support for EOL Collabora 23.05. Upgrade to 24.04 or newer.
- role:icingaweb2_module_grafana: The graph configuration for the Linuxfabrik Monitoring Plugins is only deployed when the role is called with
--tags icingaweb2_module_grafana:monitoring_plugins_graphs, matching theicingaweb2_module_director:baskettag. Run the role with that tag to update/etc/icingaweb2/modules/grafana/graphs.ini. Theicingaweb2_module_grafana__skip_monitoring_plugins_graphs_configvariable is gone; remove it from your inventory.
Added¶
- role:files: A file can opt out of the backup copy that is written before it is overwritten, via the
backupsubkey offiles__files__*_var. - role:collabora: The
collabora:configuretag deployscoolwsd.xmland the logrotate configuration without touching the packages. - role:docker: The address pools docker assigns container network subnets from (
default-address-pools) can be configured. - role:collabora: Add support for Collabora Online CODE 26.04.1, 26.04.2 and 26.04.3, and Collabora Enterprise 24.04.18, 25.04.12 and 26.04.2.
- role:monitoring_plugins: Deploy the bash completion file for source installs.
- role:kvm_vm: VMs can now also be installed from an ISO or install tree instead of a prepared cloud image.
- role:files: The
files:directories,files:filesandfiles:symlinkstags manage one kind of file system entity each, so a single directory or symlink can be deployed without touching the rest. - plugin:bitwarden_item: The lookup can be told not to create secrets, so a lookup that finds no matching item aborts the run instead of silently generating a new password. Set
LFOPS_BITWARDEN_LOOKUP_ITEM_CREATE=false, orcreate = falsein the[bitwarden_item_lookup]section of youransible.cfg; the default is the previous behaviour.
Changed¶
- role:collabora: A host running a Collabora version the role has no configuration template for aborts with that version and the list of supported ones, instead of failing on a missing file.
- role:collabora: The
localhostWOPI host is an ordinary entry ofcollabora__coolwsd_storage_wopi__*instead of being hard-coded in the template, so it can be dropped withstate: 'absent'like any other host. - role:php: The PHP-FPM configuration is checked with
php-fpm --testbefore the service is restarted, so a broken pool or ini aborts the run with the error message instead of taking PHP-FPM down on the restart.
Fixed¶
- playbook:icingaweb2, playbook:setup_icinga2_master, role:icingaweb2 update
icingaweb2dependent vars to ensure php.ini valuepost_max_size>upload_max_filesizeby default. - role:monitoring_plugins: A source install installs the dependencies of the Linuxfabrik library, so checks that speak HTTP, MySQL, SMB or WinRM no longer report
Python module "httpx" is not installedand its equivalents. - role:monitoring_plugins: A source install deploys the event plugins, which only the rpm/deb package used to ship.
- role:monitoring_plugins: A source install completes on a minimal installation, which has neither the Python module
ansible.builtin.pipneeds nor an/etc/bash_completion.ddirectory. - role:monitoring_plugins: A source install leaves the plugins, the library and the virtual environment readable and executable for the monitoring user, even when the Ansible controller runs with a hardened umask.
- role:monitoring_plugins: A second source install run against an unchanged host no longer reports changes.
- role:login: Removing a user that had lingering enabled no longer aborts the run.
- role:example: The config-validation handler of the reference role triggers the restart handler it notifies; only the template new roles are copied from was affected, not any role that manages an application.
- role:freeipa_server: Commands and command groups can be assigned to a sudo rule, through the
allow_sudocmdsandallow_sudocmdgroupssubkeys offreeipa_server__sudorules; the formercmdsandcmdgroupsnames never reached FreeIPA and aborted the run withUnsupported parameters. - role:apache_solr:
__apache_solr__java_packagecovers the Java package required by Solr 10. - role:collabora: The WOPI hosts from
collabora__coolwsd_storage_wopi__*reach coolwsd again. Every entry was discarded on load, and access only kept working because coolwsd trusted the first host that happened to connect. Collabora 26.04 drops that fallback, where the result would have been that no document loads at all.
v8.0.0 - 2026-07-31¶
Highlights: Host reboots move to one configurable maintenance window managed by the new schedule_reboot role, so system_update__update_time and the reboot-downtime settings have to be moved in the inventory. dnf_versionlock changes its variable format and no longer unlocks packages that are simply dropped from the inventory. PHP on Debian can be pinned to a declared version instead of drifting with whatever sury promotes, and a fresh installation no longer bounces its services right after starting them. Review the Breaking Changes before updating: php, mariadb_server, apache_httpd and repo_baseos all change defaults.
Breaking Changes¶
- role:dnf_versionlock: Rename
dnf_versionlock__versionlockstodnf_versionlock__versionlocks__group_var/__host_varand change it from a list of strings to a list of dictionaries (name, plus the optionalrawandstatesubkeys). The role no longer rewrites the whole lock list, so locks set elsewhere (for example bymonitoring_plugins) survive, but removing an entry from the inventory no longer unlocks the package: setstate: 'absent'instead. - role:apache_httpd: Role-internal variables are now
__-prefixed. If you copied the SSL/TLS snippet fromEXAMPLES.mdinto a vHostrawblock, renameapache_httpd__openssl_certificate_path,apache_httpd__openssl_privatekey_pathandapache_httpd__openssl_chain_pathto their__-prefixed form, otherwise the vHost fails to render. - role:system_update: Host reboots are now performed at one configurable maintenance window by the new
schedule_rebootrole (see Added). Adjust in your inventory:system_update__update_timetoschedule_reboot__reboot_time__group_var(now a plain time of day, e.g.'04:00'), and anysystem_update__icinga2_*reboot-downtime settings toschedule_reboot__icinga2_*. Also, in most casessystem_update__update_dayshould be used instead ofsystem_update__notify_and_schedule_on_calendar. - role:php: In preparation for the upcoming PHP 8.6,
php__ini_session_cookie_httponlynow defaults toOn, so session cookies are marked HttpOnly and are no longer accessible to JavaScript viadocument.cookie. This matches the hardened session defaults PHP 8.6 ships. Applications that must read the session cookie from JavaScript have to setphp__ini_session_cookie_httponly__group_var: 'Off'(or the__host_var) to restore the previous behaviour. - role:php: The default
php__ini_opcache_blacklist_filenamenow points to the distribution-neutral/etc/opcache.blacklistinstead of/etc/php-zts.d/opcache*.blacklist. The old default pointed at the thread-safe (ZTS) config directory, which the non-ZTS PHP-FPM this role deploys never reads. No file exists at the new path by default, so no scripts are excluded from OPcache unless an admin creates one. - role:apache_httpd: The Matomo log-analytics import script (
import_logs.py) and theapache_httpd:matomotag have been removed and moved to the newmatomo_import_logsrole. Hosts that import their access logs into Matomo, or that pipe their access logs to/usr/local/sbin/import_logs.pyfor realtime tracking, must now also run thematomo_import_logsrole, which deploys the script. ThematomoLogFormat itself stays inapache_httpd. - role:repo_baseos: The Rocky Linux
securityrepository now always points at the upstream mirrorlist, even when a customrepo_baseos__mirror_urlis set, so critical CVE fixes keep coming straight from upstream instead of a potentially lagging mirror. Hosts that previously pulled thesecurityrepository from their custom mirror now reach upstream directly. Setrepo_baseos__security_repo_use_upstream: falseto restore the previous behaviour and have thesecurityrepository followrepo_baseos__mirror_urlagain. - role:mariadb_server: The default for
skip_name_resolveis nowOFFinstead ofON. Hosts that relied on the previous default and grant access by hostname keep working, but connections are now resolved via DNS again. Setmariadb_server__cnf_skip_name_resolve__group_var: 'ON'(or the__host_var) to restore the previous behaviour.
Added¶
- role:glpi_agent: Add optional scheduled database inventory via
glpi_agent__database_inventory_enabledandglpi_agent__database_inventory_login, which runsglpi-agent --partial=databaseas a dedicated read-only database user on a systemd timer instead of letting the always-on daemon connect as root on every cycle.glpi_agent__conf_no_categorydisables arbitrary inventory categories andglpi_agent__database_inventory_on_calendarsets the schedule. - role:php: Add
php__versionto declare which PHP version a Debian host runs, for example'8.4', so an ordinaryapt upgradeno longer migrates the host to a new major PHP version on its own. With the sury repo enabled, the unversioned metapackages follow whatever sury currently declares as its default; declaring a version makes the role install the versioned packages, pin thephp,pharandphar.pharalternatives to it, and purge the stacks of all other versions onphp:update. Leave it empty to keep the previous behaviour. Has no effect on RedHat, where the module stream pins the version at repo level. - playbook:php: Now runs the
repo_suryrole on Debian (skip withphp__skip_repo_sury), since sury is what makes any PHP version other than the distribution's own available in the first place. - role:fail2ban: Add
fail2ban__filters__*_var(combined-var pattern,unique_key="filename") so custom filter definitions can be deployed from the inventory in the same generic shape asfail2ban__jails__*_var. The built-inapache-dosandportscanfilters move intofail2ban__filters__role_varwith no behaviour change, and can now be opted out viastate: 'absent'. - role:postfix: Add
postfix__recipient_canonicals__group_var/__host_varto rewrite recipient addresses via Postfix'srecipient_canonical_maps, mirroring the existing sender canonical rewriting, which is useful for redirecting all mail addressed to a host to a central team mailbox. - all roles: Add
lfops__skip_restart_handlersto deploy configuration changes without restarting the affected services, for example when a bounce has to wait for a maintenance window. Reload handlers still run, since a reload applies the configuration without an outage. Note that the skipped restart is not remembered: a later ordinary run finds the configuration already correct and does not restart either, so the service has to be restarted explicitly (--tags <role>:state --extra-vars '<role>__service_state=restarted'). See the README. - Add a service state variable (for example
chrony__service_state,clamav__clamd_service_stateorphp__fpm_service_state) to start, stop, restart or reload the managed service independently of whether it is enabled at boot; it defaults tostartedwhen the role's matching*_service_enabledistrueand tostoppedotherwise, so existing inventories keep their current behaviour (apache_solr, bind, blocky, chrony, clamav, collabora, coturn, fail2ban, glpi_agent, grafana, graylog_datanode, graylog_server, icinga2_master, icinga_kubernetes, icingadb, influxdb, keepalived, opensearch, php, redis, snmp, squid, vsftpd). - role:duplicity: Add Debian and Ubuntu support (proven on Debian 12, Debian 13, Ubuntu 22.04, Ubuntu 24.04 and Ubuntu 26.04), and install the
gnupgpackage itself so backups also work on minimal installs that ship withoutgpg. - role:python_venv: Add an optional per-venv
pip_constraintskey that pins transitive dependencies through a pip constraints file, without having to list them as direct packages. - role:opensearch: Add
opensearch__path_repoto register file system paths aspath.repoinopensearch.yml, required for file system based snapshot repositories. - role:nextcloud: Add
nextcloud__jobs_timeout_start_secto configure the start-up timeout of thenextcloud-jobs.service, defaulting to10m, for instances where background jobs regularly need longer. - role:icinga2_agent, role:icinga2_master: Deploy a systemd drop-in override ensuring the Icinga 2 service starts after SSSD on hosts where SSSD is installed.
- role:librenms: Add
librenms__config_app_trusted_proxiesandlibrenms__config_app_urlto set theAPP_TRUSTED_PROXIESandAPP_URLvariables in/opt/librenms/.env, needed when running LibreNMS behind a reverse proxy. - role:mariadb_server: Add
mariadb_server__cnf_innodb_flush_neighbors__group_var/__host_varto configure theinnodb_flush_neighborsInnoDB system variable, defaulting to0, which is the recommended value for SSD and NVMe storage. - role:freeipa_server: Add
freeipa_server__limit_groups,freeipa_server__limit_hbacrules,freeipa_server__limit_hostgroups,freeipa_server__limit_pwpolicies,freeipa_server__limit_sudocmdgroups,freeipa_server__limit_sudocmds,freeipa_server__limit_sudorulesandfreeipa_server__limit_usersto manage only specific resources via--extra-vars, which speeds up deployments on servers with many FreeIPA resources. - role:vsftpd: Add
vsftpd__pam_use_userdbto authenticate virtual users viapam_userdbagainst/etc/vsftpd/login.db, so virtual-user logins work instead of failing against the local-user PAM stack the role always rendered. - role:opensearch: Add
opensearch__heapto set the JVM heap size via a drop-in at/etc/opensearch/jvm.options.d/heap.options, defaulting to 50% of system memory capped at 31 GB. - role:trend_micro_v1es: Add a role to install and activate the Trend Vision One Endpoint Security agent (Endpoint Sensor and Server & Workload Protection).
- role:matomo_import_logs: New role that imports Apache access logs into Matomo on a schedule, one systemd timer per site, and ships the Matomo log-analytics import script (
import_logs.py). Thetoken_authis provided via a per-site auth file instead of the command line, since--token-auth,--loginand--passwordare visible in the process list and now log a deprecation warning. The script also supports the Traefik access-log format. - role:glances: Add RHEL 10 / Rocky 10 / Alma 10 support by installing glances into a Python venv via the
python_venvrole, since the package is not available in EPEL 10. RHEL 10 is now marked proven (x) in COMPATIBILITY. - role:graylog_datanode: Add
graylog_datanode__http_publish_urito set the REST API URI the DataNode advertises, needed when the bind address is not directly reachable (multiple interfaces, a NAT gateway, or a0.0.0.0bind address).
Changed¶
- role:php: The
php:updatetag also deploys the PHP-FPM pools and enables and starts the FPM service, because both live under version-specific paths on Debian, so a host that changedphp__versionwould otherwise run the new version with none of its pools and a unit that was never enabled. - role:fail2ban: README documents the
statesubkey of the filter and jail entries as optional (defaults topresent), notes thatrawonly applies to entries using therawtemplate, and states up front that filters and jails are defined in the inventory. - role:nextcloud: Adds Debian and Ubuntu support alongside Red Hat-family systems, marked
(x)inCOMPATIBILITY.mdsince package names are verified on Debian 13 but the role is not yet proven end to end. SELinux relabeling is skipped automatically on hosts where SELinux is disabled. - role:apache_solr, role:blocky, role:fail2ban, role:rsyslog: The service is started after its configuration has been deployed, not before, so on a fresh installation it comes up with the configuration the role just wrote instead of starting on the package defaults and being restarted afterwards.
- role:duplicity: Validate the role variables at start, and align the task tags with the LFOps vocabulary: the
duplicity:scripttag is gone (thedubascript now deploys underduplicity:configure), and the newduplicity:dumptag manages the backup schedule. - role:schedule_reboot: Hosts without an explicit reboot window are assigned a deterministic minute within the 04:00-04:59 window, staggered by hostname, so a fleet no longer reboots in lockstep at exactly 04:00. Pin
schedule_reboot__reboot_time__group_var(or the__host_var) to keep a specific window. - role:monitoring_plugins: A source install deploys the plugins into a self-contained Python virtual environment and provisions a suitable Python by itself, so it works on RHEL 8 where the system Python 3.6 is too old. The Linuxfabrik library is deployed newest straight from GitHub and the third-party dependencies are installed unpinned, so a source install always tracks the newest code for the selected
monitoring_plugins__version. The dependencies the former source install placed into the home directories of root and the icinga user are cleaned up on the next run. - role:icinga2_agent: The
icinga2_agent:updatetag refreshes the apt cache before the upgrade on Debian-family hosts, so it reliably installs the latest package instead of running against a stale cache. - role:mariadb_server: Databases created via
mariadb_server__databaseswithout an explicitcollationorencodinginherit the server default character set and collation (utf8mb4) instead of being pinned to the legacyutf8/utf8_general_ci. Existing databases are unaffected; setcollation/encodingper database to override. - role:collabora: Support Collabora Online CODE 25.04.10, which had no
coolwsd.xmltemplate and therefore aborted the deploy on hosts that had updated to it. - role:clamav: Send notification mails through
sendmail(provided by postfix) instead of themailcommand (mailx), so one invocation works across distributions and delivery no longer depends on mailx being installed. - role:icingadb, role:icingaweb2, role:icingaweb2_module_reporting, role:icingaweb2_module_x509, role:mariadb_server: Move the MariaDB tasks from the deprecated
community.mysqlcollection to its replacementansible.mysql, so the deprecation warnings printed on every run are gone and the roles keep working oncecommunity.mysqlis removed upstream.
Fixed¶
- A configuration change no longer restarts or reloads a service that the very same run had just started, so a fresh installation no longer bounces the service right after starting it, and no longer starts a service that is configured to stay stopped (apache_httpd, apache_solr, apache_tomcat, bind, blocky, chrony, clamav, collabora, coturn, docker, elasticsearch, fail2ban, glpi_agent, grafana, graylog_datanode, graylog_server, icinga2_master, icinga_kubernetes, icingadb, influxdb, keepalived, kibana, logstash, mariadb_server, mongodb, opensearch, php, postfix, postgresql_server, redis, rocketchat, rsyslog, snmp, squid, sshd, systemd_journald, telegraf, vsftpd).
- role:mariadb_server, role:monitoring_plugins, role:php: The update tags refresh the apt cache before upgrading on Debian-family hosts, so they reliably install the latest packages instead of running against a stale cache. RHEL-family hosts are unaffected, since dnf refreshes its metadata on its own.
- role:mastodon: Modules set via
apache_httpd__mods__host_varin the inventory are no longer discarded, because the role used the wrong dependent variable name. - role:postgresql_server: The
grant_optionsubkey ofpostgresql_server__privstakes effect, and the entry'srolesandstatesubkeys are documented. - playbook:php, playbook:redis, playbook:setup_grav, playbook:setup_moodle: These playbooks enable EPEL (and CRB on Rocky 9 and newer) before installing packages from Remi's repository, which depend on it; on RedHat 8 the run previously aborted with
nothing provides libcapstone.so.4 needed by php-opcache. Skippable via<prefix>__skip_repo_epeland<prefix>__skip_repo_baseos. - role:php: A dry run (
--check) against a host that does not have PHP-FPM installed yet no longer aborts, so the role can be previewed before the first real run. - role:icingaweb2, role:icingaweb2_module_fileshipper, role:icingaweb2_module_vspheredb, role:icingaweb2_module_x509, role:nextcloud: On Debian and Ubuntu, PHP extension names are built from the PHP version the
phprole manages, so the unversionedphp-<module>metapackages can no longer pull a second, undeclared PHP runtime onto the host whenever sury promotes a new default. RedHat is unaffected. - role:nextcloud: The IMAP PHP extension installs on PHP 8.4 and newer, where IMAP was removed from PHP core, by installing it from the PECL package instead of the no-longer-existing
php-imap. - role:php: Running the role with a specific tag such as
--tags php:stateon Debian and Ubuntu no longer fails with an undefined PHP version, so roles that build on php and only restart php-fpm work when run with their own tags. - role:nextcloud: The
nextcloud-ldap-show-remnantsscript no longer aborts thenextcloud:crondeploy with'setup_basic__skip_mailto_root' is undefinedwhen the role runs outside thesetup_basicplaybook; report recipients come fromnextcloud__mail_recipients, defaulting to the globalmailto_root__to. - role:nextcloud: Replace ws.linuxfabrik.io with www.linuxfabrik.ch, since ws.linuxfabrik.io is decommissioned.
- role:icingaweb2_module_grafana:
icingaweb2_module_grafana__auth_jwthonours a quoted'false', which previously enabled JWT authentication and deployed the private key anyway; unquotedtrue/falsebehaved correctly before and are unaffected. - role:shared:
lfops__remove_rpmnew_rpmsavehonours an explicit opt-out, so--extra-vars='lfops__remove_rpmnew_rpmsave=false'keeps the.rpmnew,.rpmsave,.dpkg-distand.ucf-distfiles instead of removing them. Leaving the variable unset was, and still is, safe. - role:apache_tomcat:
apache_tomcat__service_statetakes effect instead of being silently ignored in favour ofapache_tomcat__service_enabled; its default isstartedifapache_tomcat__service_enabledistrueandstoppedotherwise, so hosts that never set it are unaffected. - role:freeipa_server: The
pki-tomcatdstart-up timeout configured viafreeipa_server__systemd_timeoutstartsecis in effect, because the role now applies the same value to systemd and to FreeIPA and reloads systemd. On slow machinesipactl start, server upgrades and CA certificate renewals previously failed with a timeout even though the CA was still coming up. - role:duplicity: Swift backups work out of the box on Python 3.10 and newer, since the role pins a modern
oslo.*stack in the venv, which fixes thecollections.Mappingcrash and drops the deprecatednetifacesdependency. As a result the role no longer installs a C compiler or development headers on backup hosts, which removes the build toolchain from production machines. - role:keycloak: Keycloak is no longer restarted a second time right after it was started on a fresh install, and a configuration change no longer starts the service on hosts that pin
keycloak__statetostopped. - role:nextcloud: Set the
text workspace_availableapp config key asbooleaninstead ofstring, since newer Nextcloud enforces the config lexicon and the text app declares the key asValueType::BOOL. - role:system_update: The update and security-update jobs no longer send a failure mail when a mirror hiccups briefly, because repository metadata is refreshed with a few retries before updates are applied.
- role:mod_maxminddb, role:monitoring_plugins: The role no longer aborts at start demanding a variable that has an OS-specific default (
monitoring_plugins__icinga_userrespectivelymod_maxminddb__apache_conf_modules_d), so there is no need to set it in the inventory. - role:monitoring_plugins: A source install no longer aborts on RHEL 8, where the system Python 3.6 is older than the required 3.9; the role installs and uses Python 3.9 automatically.
- role:python_venv: Install
python3-packagingon EL10, which ships Python 3.12 without the stdlibdistutils, so Ansible'spipmodule can create a venv again. - role:icingaweb2_module_vspheredb: Download the module tarball from the canonical
archive/refs/tags/<version>.tar.gzURL, so the pinned release tag is fetched reliably. - role:monitoring_plugins: A source install deploys the sudoers drop-in as
/etc/sudoers.d/linuxfabrik-monitoring-plugins, the same file name the packages use, and both install methods remove the drop-in under the former name, so sudo no longer warns about a duplicateCmnd_Alias. - role:collect_rpmnew_rpmsave: Stop emitting an Ansible deprecation warning on every run, which keeps the role working on Ansible 2.19 and later.
- role:kvm_vm: Use
kvm_vm__connect_urlfor every libvirt operation, so disk resizes (virsh blockresize) and a few other steps no longer ignore the configured connection URL and act on the wrong libvirt.
Security¶
- role:opensearch: The OpenSearch data directory is no longer readable by other local users; its root uses mode
0750instead of2755, matching the OpenSearch package default. - role:monitoring_plugins: A source install leaves the plugins, the bundled library and the dependency venv owned by root instead of the monitoring user, closing a local privilege escalation in which that account could edit a plugin, a library module or the venv interpreter that runs as root via sudo.
v7.0.0 - 2026-06-11¶
Highlights: setup_basic gains three CIS-oriented hardening roles (core_dumps, kernel_modules, login) and the sshd defaults are tightened, which stops sessions that rely on X11 or agent forwarding and can lock out clients offering more than three keys. Reboots move to one windowed mechanism in the new schedule_reboot role. Tags were renamed across a dozen roles and the MinIO roles were removed, so review your --tags invocations and any object-store backup first. RHEL 10 is now proven for the roles setup_basic runs.
Breaking Changes¶
- Internal OS-specific variables are
__-prefixed to mark them as not overridable from inventory. Rename any inventory override ofdnf_versionlock__list_path,dnf_versionlock__packagesor a role's*__icingaweb2_ownervariable to the__-prefixed form; the values are unchanged (dnf_versionlock, icingaweb2_module_businessprocess, icingaweb2_module_company, icingaweb2_module_cube, icingaweb2_module_fileshipper, icingaweb2_module_generictts, icingaweb2_module_incubator, icingaweb2_module_pdfexport, icingaweb2_theme_linuxfabrik). - plugin:combine_lod, role:apache_httpd, role:mariadb_server, role:proxysql, role:selinux: A composite
unique_key(a list of keys) now requires every component to be set on each item, instead of letting one be filled by a downstream default. Set the previously optional component explicitly:virtualhost_porton everyapache_httpdvHost,hoston everymariadb_serveruser/role,porton everyproxysqlserver, andprotoon everyselinuxport. Otherwise the play fails with a clear error. - role:apache_httpd, role:apache_tomcat, role:mastodon, role:postgresql_server: Rename tags to the project-wide naming scheme.
apache_httpd:configbecomesapache_httpd:configure, andapache_tomcat:users,mastodon:users,postgresql_server:usersandpostgresql_server:databaseslose their trailings(...:user,...:database). Adjust any--tags/--skip-tagsinvocations and automation that reference the old tag names. - role:sshd: Ship hardened SSH defaults that change the behaviour of existing installations on the next run: X11 forwarding, agent forwarding and TCP keepalives are now off,
MaxAuthTriesis lowered to3,ClientAliveCountMaxto2, andLogLevelis raised toVERBOSE. Sessions relying on X11 or agent forwarding stop working, and a client offering more than three keys from its SSH agent can be locked out. Restore the previous behaviour where needed via the new variables:sshd__x11_forwarding: true,sshd__allow_agent_forwarding: true,sshd__tcp_keep_alive: true,sshd__max_auth_tries: 6,sshd__client_alive_count_max: 3,sshd__log_level: 'INFO'. Additionally configurable aresshd__allow_tcp_forwardingandsshd__max_sessions. - role:apache_httpd, role:apache_solr, role:freeipa_server, role:grav, role:icingaweb2, role:influxdb, role:mariadb_server, role:mongodb, role:nextcloud, role:opensearch: Align section tags to the controlled vocabulary, which uses plural names for sections that manage multiple objects. The
:usertags become:users, the:databasetags become:databases, andapache_httpd:configbecomesapache_httpd:configure. Adjust any--tags/--skip-tagsinvocations and automation that reference the old tag names. - role:minio_client, role:objectstore_backup: Both roles and their playbooks (
playbooks/minio_client.yml,playbooks/objectstore_backup.yml) have been removed, along with the corresponding role blocks inplaybooks/setup_nextcloud.ymland thesetup_nextcloud__skip_minio_client/setup_nextcloud__skip_objectstore_backupvariables. MinIO Server has been archived as no-longer-maintained since February 2026, and we are moving away from using object storage for critical data. Users relying on these roles must replace the MinIO-based object-store backup with their own solution (e.g.rclone); themcbinary, its config under/etc/mc/, theobjectstore-backupsystemd timer/service, and/usr/local/bin/mc-mirror.share no longer managed by lfops and will remain on existing hosts until removed manually (#241). - role:infomaniak_vm: Always create a managed port for every entry in
infomaniak_vm__networks, even when nofixed_ipis set. Previously only networks with afixed_ipgot a managed port; networks without one relied on OpenStack's auto-created port. To avoid creating unused (but billed) managed ports on VMs provisioned under the old behavior, make sure to manually rename the existing port in OpenStack to match theport_name. Note that this port will not survive VM deletion / detachment, since it was automatically created and therefore is owned by OpenStack, not the user. - role:shared: The Apache httpd user and group are defined once as
__shared__apache_httpd_user/__shared__apache_httpd_groupand loaded into every playbook through a newglobal-variables.ymltask inpre_tasks, instead of being repeated in thevars/of around 20 roles. Running one of those roles ad-hoc outside the bundled playbooks now requires importingshared'sglobal-variables.ymlfirst. On Suse, themonitoring_pluginsweb files use the correct apache groupwwwinstead ofwwwrun. - role:crypto_policy, role:duplicity, role:icingaweb2, role:icingaweb2_module_x509, role:mariadb_server, role:php: The internal package-selection dicts behind the OS-keyed default lookups are no longer overridable from inventory; they were never meant to be. Behaviour is unchanged on supported platforms.
Added¶
- all roles: Role variables are validated at role entry through
meta/argument_specs.yml, so a type mismatch or a missing mandatory variable in the inventory fails immediately with a clear message instead of an obscure error later in the run. - role:schedule_reboot: New role providing a single, windowed reboot mechanism: a request spool (
/run/schedule-reboot/), an ad-hocschedule-rebootcommand, and one actor that performs a single reboot for all pending requests at a configurable window (schedule_reboot__reboot_time__*), setting an Icinga downtime around it. Other roles request a reboot instead of rebooting themselves;system_updateuses it. - role:core_dumps: New role that disables core dumps, which can leak sensitive process memory to disk, following the CIS Benchmark recommendations. Runs as part of
setup_basic. - role:kernel_modules: New role that hardens a host by blocking rarely used or risky kernel modules (FireWire, legacy filesystems, uncommon network protocols) following the CIS Benchmark recommendations, and runs as part of
setup_basic. The defaults stay clear of modules that would break common workloads such as containers, snap and USB storage. - role:login: New role that sets a password-aging policy and a stricter default umask in
/etc/login.defs, applying to newly created accounts and password changes rather than retroactively. - role:chromium_headless: New role providing a hardened, socket-activated headless Chromium backend for tools such as the Icinga Web 2 PDF Export Module, started on the first request and stopped again after an idle timeout so it uses no RAM while unused. Installs
chromium-headlessfrom EPEL instead of Google's proprietary repository. - role:tmux: New role that installs tmux and deploys a system-wide
/etc/tmux.confwith a larger scrollback buffer and mouse support. Selections are copied to the local clipboard over SSH via OSC 52 where the terminal supports it, andprefix + Pdumps a pane's whole scrollback buffer to a file. - role:hostname: Maintains an
/etc/hostsentry mapping the FQDN and short name to the host's primary IPv4 address, configurable viahostname__etc_hosts_ipand disablable withhostname__manage_etc_hosts: false. - role:uptimerobot, plugins/modules/uptimerobot_*: New role and nine custom modules to manage UptimeRobot resources from a playbook:
uptimerobot_monitor,uptimerobot_mwindowanduptimerobot_pspfor CRUD,uptimerobot_alert_contactfor deletion only (UptimeRobot API v2 does not expose creating contacts), plus five read-only info modules. All CRUD modules support--checkand--diffand are idempotent on re-run. Configured viauptimerobot__monitors,uptimerobot__mwindows,uptimerobot__pspsanduptimerobot__alert_contacts; the API key comes from theapi_keyparameter,api_key_file(default~/.uptimerobot) orUPTIMEROBOT_API_KEY. - plugin:platform_select: New filter plugin for selecting a value from a platform-keyed dictionary by OS family, distribution or version.
- role:system_update: Add a security lane for Rocky Linux: a daily timer installs only Rocky Linux security hot-fixes from the dedicated
securityrepository and requests a reboot if needed, performed at the host's maintenance window. Enabled by default, a no-op where thesecurityrepository is not enabled, and turned off withsystem_update__security_enabled: false. - role:repo_baseos: Add the Rocky Linux
securityrepository for critical CVE fixes, enabled by default. Opt out per host or group viarepo_baseos__security_repo_enabled__host_var/__group_var. - role:sshd: Add Debian 13 and Ubuntu 22.04 / 24.04 / 26.04 support and run on Fedora. On Debian and Ubuntu the role manages the correct service unit (
ssh.service) and disables OpenSSH socket activation (ssh.socket), and Red Hat-family releases without a version-specific template fall back to a genericRedHatsshd_configtemplate instead of failing. - role:icinga2_master, role:icingadb, role:icingaweb2, role:icingaweb2_module_reporting, role:icingaweb2_module_x509: Add explicit Ubuntu variable files, making Ubuntu support visible alongside Debian. The Icinga repository, GPG key and package names were verified on Debian 13 and Ubuntu 24.04.
- role:libmaxminddb, role:mod_maxminddb: Run on Debian and Ubuntu in addition to Red Hat-family systems, with the Apache module enabled automatically on Debian and Ubuntu.
- role:monitoring_plugins, role:repo_monitoring_plugins: Add SLES 15 and SLES 16 support, installing the Linuxfabrik Monitoring Plugins from the SUSE channel of
repo.linuxfabrik.chand applying the SUSE-specific package version lock (#245). - role:repo_remi: Add RHEL 10 / Rocky 10 support with a new GPG key, repo templates and module-stream tasks for EL 10.
- role:repo_monitoring_plugins: Add
repo_monitoring_plugins__testing(defaultfalse) to switch from thereleaseto thetestingchannel. On Red Hat-family systems a single/etc/yum.repos.d/linuxfabrik-monitoring-plugins.repois deployed containing both channel sections withenabled=toggled by the variable, so DNF metadata for both can stay cached across switches; on Debian and Ubuntu the-releasesuffix in the apt sources file is replaced with-testing. - role:graylog_server: Make more HTTP, Elasticsearch, processing/output buffer and message journal settings configurable via
graylog_server__http_external_uri,graylog_server__http_enable_cors,graylog_server__elasticsearch_max_total_connections,graylog_server__elasticsearch_max_total_connections_per_route,graylog_server__output_batch_size,graylog_server__processbuffer_processors,graylog_server__outputbuffer_processors,graylog_server__ring_size,graylog_server__inputbuffer_ring_size,graylog_server__message_journal_max_ageandgraylog_server__message_journal_max_size. - role:graylog_datanode: Add
graylog_datanode__raw, plusgraylog_datanode__path_reposandgraylog_datanode__node_search_cache_sizeto configure searchable snapshot locations and the size of the disk-based searchable snapshot cache. - role:graylog_datanode, role:graylog_server: Add template for Graylog 7.1.
- role:mariadb_server: Make
aria_pagecache_buffer_size,key_buffer_sizeandsort_buffer_sizeconfigurable via the correspondingmariadb_server__cnf_*variables, and addmariadb_server__cnf_innodb_snapshot_isolation(MariaDB 10.6+), defaulting to'ON'. - role:elasticsearch: Add optional variables
elasticsearch__cluster_routing_allocation_disk_watermark_flood_stage_frozenand the four corresponding*_max_headroomvariables. - role:kibana: Add
kibana__loggingto make thelogging:block inkibana.ymlfully user-configurable (appenders, loggers, root, rotation). The default preserves the previous behaviour: JSON logs at/var/log/kibana/kibana.log, rotated daily, 14 rotations kept. - role:logstash: Add optional variables
logstash__monitoring_cluster_uuidandlogstash__monitoring_enabled. - role:alternatives: Support managing
subcommands(slaves/followers) and the Red Hat-onlyfamilygrouping, ensure the alternatives tooling is installed, and allow the role to be included without variables as a no-op. - role:at, role:dnf_makecache, role:open_vm_tools, role:qemu_guest_agent: Add service state variables (
at__service_state,dnf_makecache__service_stateand__timer_state,open_vm_tools__service_enabledand__service_state,qemu_guest_agent__service_state) to control the running state independently from boot autostart. Default behaviour is unchanged. - role:infomaniak_vm: Add the
keep_port_on_absentsubkey oninfomaniak_vm__networksentries to preserve the port and its fixed IP when the VM is set toabsent, so the same IP can be re-used, andport_nameto override the managed port's name. - role:mirror: Document the per-repository
newest_onlysubkey onmirror__reposync_reposentries, defaulting totrue. Set it tofalsefor repositories that publish multiple versions in parallel, such as Icinga. - role:redis: Add template for version 8.8.
- playbooks/setup_basic: Add
setup_basic__skip_policycoreutilsto skip thepolicycoreutilsrole, matching the pattern used by the other roles in the playbook.
Changed¶
- all roles: The role READMEs follow one standard format and explain what the underlying software actually is and when an admin would want it, instead of only naming it. Install behaviour, upgrade paths, role scope and previously undocumented variables are spelled out, and tags and variables are bullet lists instead of markdown tables.
- COMPATIBILITY: RHEL 10 is promoted to proven (
x) for the 23 roles thatsetup_basicexercises, Ubuntu 26.04 is added, the EOL Debian 11 and Ubuntu 20.04 columns are dropped, and roles that are expected to work but are untested are marked(x).glancesstays at(x)because the package is missing in EPEL 10. - role:nextcloud: Automatic app updates are enabled by default (
nextcloud__timer_app_update_enabled), and the scheduled update only switches Nextcloud into maintenance mode when an app update is actually pending, so an instance that is already up to date keeps serving requests. The recommended database migrations are applied afterwards, and a failed run no longer leaves the instance stuck in maintenance mode. - role:keycloak: The bootstrap admin credentials no longer stay in
/etc/sysconfig/keycloakafter the first run. The role writes them, waits for Keycloak to consume them on startup, re-renders the sysconfig file without them, and stores a state marker so subsequent runs skip the credential render;keycloak__admin_logincan then be removed from the inventory. For disaster recovery, delete the marker file, re-add the variable and re-run. A-tempsuffix on the initial admin username is recommended so it is obvious which account must be deleted once a permanent admin exists. - role:icinga2_master, role:icingadb: Validate the Icinga 2 configuration before restarting the service, so a faulty config fails the playbook run loudly instead of bouncing the daemon into a broken state and leaving Icinga 2 down.
- role:clamav: Runs on Debian and Ubuntu in addition to Red Hat-family systems, and works on RHEL 10. The role seeds the signature database on first install so the scanner starts reliably, and runs an EICAR self-test (also available via the
clamav:testtag) that confirms detection actually works. - role:acme_sh: Issue ECDSA P-256 certificates by default instead of RSA-4096, for faster TLS handshakes at equivalent security. Certificates previously issued as RSA are reissued as ECDSA on the next run and the superseded RSA certificate is dropped from renewal; set
acme_sh__key_lengthto an RSA value such as4096to keep RSA. - role:mailto_root: Send the verification mails via
sendmail(provided bypostfix) instead of themail(mailx) command, completing the move offmailx, so the role no longer needs themailxpackage installed. - playbooks: Roles that target the whole RHEL family run on any enterprise distribution that is not Fedora, instead of an explicit list of major versions, which adds support for RHEL 10 and future releases without further changes. The CRB repository is now also enabled on Rocky 10, which previously left dependencies such as
python3-virtualenvuninstallable. - role:grafana: Apply the systemd/chkconfig workaround on RHEL 10 as well, not just RHEL 9.
- role:tools: Install the German locale package (
glibc-langpack-de) on RHEL 10 as well, and no longer install tmux; use the dedicatedtmuxrole instead, which ships a configuration with sensible defaults. - role:repo_baseos: The Rocky 8
securityrepository matches Rocky 9 and 10: it adds the disabledsecurity-debuginfoandsecurity-sourcesub-repositories, a 6-hour metadata expiry so emergency hot-fixes are noticed quickly, and the$rltypemirrorlist variable. - role:redis: Bump the default for
net.core.somaxconnfrom1024to4096to match the RHEL 9 and RHEL 10 kernel default and the current Redis upstream recommendation. RHEL 9 and 10 hosts see no effective change; RHEL 8 hosts now get4096. - role:monitoring_plugins:
install_method: 'source'reads the per-Python-LTS lockfile underlockfiles/pyXX/requirements.txtfrom both themonitoring-pluginsandlibrepos, picking the directory that matches the target host's Python, since the previous root-levelrequirements.txtno longer exists upstream. - role:system_update: Change the default of
system_update__update_timeso updates are spread deterministically across 04:00-04:59, with the minute derived frominventory_hostname, instead of all hosts firing at 04:00 sharp. - role:apache_httpd: Bump the Core Rule Set to 4.27.0, and update the two reverse-proxy snippets in
EXAMPLES.mdto useProxyPassinstead ofRewriteRule, which%-decodes the URI pattern and breaks WebDAV apps such as Nextcloud on rename. See the blog post. - role:firewall: Install
nftablestogether withiptablesforfirewall__firewall == "fwbuilder"on all distros, instead of only on Fedora and RHEL 8/9. - role:graylog_server: Update the
server.conftemplates to includetelemetry_enabled = false. - role:network: Scope the
hc-utilsremoval task to Red Hat-family hosts, since Hetzner shipshc-utilsas RPMs only. No behaviour change on either family. - plugin:gpg_key: Refresh the bundled GPG helper library so the module keeps working on current Python and GnuPG releases, and make the
gnupghomeparameter expand~and resolve relative paths as documented. Existing playbooks are unaffected. - role:motd: Update the default value of
motd__legal_notice.
Removed¶
- role:repo_remi: Drop support for RHEL 7 and Fedora 35, both EOL, along with their per-platform task, vars and template trees.
- role:freeipa_client: Remove the dead-code defaults
freeipa_server__config_default_shell,freeipa_server__config_password_expiration_notification,freeipa_server__domainandfreeipa_server__realmfromdefaults/main.yml; they were never read by the role.
Fixed¶
- role:repo_elasticsearch, role:repo_grafana, role:repo_graylog, role:repo_icinga, role:repo_influxdb, role:repo_mariadb, role:repo_mongodb, role:repo_monitoring_plugins, role:repo_mydumper, role:repo_opensearch, role:repo_proxysql, role:repo_redis, role:repo_sury: Refreshing the apt cache is no longer reported as a change on every run.
- roles: Controller-side downloads and git clones delegated to localhost are no longer skipped when the first targeted host happens not to need them, which previously risked leaving later hosts without the downloaded artifact.
- roles: Set
become: falseon tasks delegated to localhost across the collection, so they no longer try to callsudoon the Ansible controller and fail withsudo: a password is requiredwhere passwordless sudo is not set up (#242). - role:repo_remi: Enabling the php, composer and Redis module streams is idempotent, so repeated runs no longer report a change or briefly disable and re-enable the stream.
- role:proxysql:
mysql_serversentries are deduplicated by their actualaddressfield; the merge key referenced a non-existenthostnamefield, so multiple backends sharing a host group and port were silently collapsed into one. - role:repo_influxdb: Prevent the
influxdata-archive-keyringpackage from being installed on both Enterprise Linux and Debian, since it drops a second repo file pointing at upstream that is not managed by LFOps. - role:php: php-fpm workers run with a defined
PATH, which previously was empty and broke PHP code that shells out to system binaries and tripped Nextcloud's "PHP getenv" setup warning. - role:redis: The Redis configuration file is no longer world-readable; it is deployed as
root:rediswith mode0640, so a configured password can no longer be read by other local users. - role:acme_sh: No longer reinstalls every certificate and reloads the web server on every run; certificates are only reinstalled when they were just (re)issued or when the installed file is missing.
- role:keycloak: The role prints a clear instruction when a re-run can no longer obtain a token because the bootstrap admin was manually switched over to a permanent account and the bootstrap marker went missing.
- role:keycloak: Fix ownership under
/opt/keycloak/data/, which the post-install build step left owned byroot:rootso thekeycloakservice user could not write into it; the build now runs as the service user and existing installations are corrected on the next run. - role:keycloak: Fix the transaction timeout silently dropping from 3600s to 300s on Keycloak 26.6.0 and newer, and the MariaDB database encoding defaulting to the deprecated
utf8(utf8mb3) instead ofutf8mb4. - role:mongodb: The role aborts early with a clear message when users are defined while
mongodb__conf_security_authorizationis disabled, instead of failing with a confusing authentication error, and the dump config no longer writes login credentials in that case. - role:kernel_settings: The
systemd_cpu_affinitysetting is actually applied; the value was computed and shown in the debug output but never passed to the underlying system role. - role:icingaweb2_module_pdfexport: PDF export works out of the box, because the headless browser backend the module needs is installed and configured automatically via the new
chromium_headlessrole instead of having to be set up by hand. - role:nextcloud: The
nextcloud-updatescript owns the maintenance mode lifecycle itself instead of expecting callers to enable it beforehand, which disabled the LDAP user provider and made thebefore-updateexport silently omit LDAP users. Callers must drop the manualmaintenance:mode --onstep from their pre-script workflow and rely on--single-transactionfor the DB dump instead. - role:nextcloud: Ensure that the Nextcloud OCC is executable.
- role:graylog_server: Fix the
graylog_server:configure_defaultsrun aborting on Graylog 7.0 and newer withUnable to map property can_be_defaultwhile creating the default index set, by removing the property; Graylog 7.x dropped it and 6.x ignored it. - role:graylog_server: Validate that each
graylog_server__system_inputsentry setsglobal: trueor assigns anode, which was marked mandatory but never enforced. - role:graylog_datanode, role:graylog_server: Validate that the
password_secretis at least 16 characters long. - role:graylog_datanode: Fix the
Conditional result ... was of type 'str'deprecation warning. - role:nodejs: Fix
@nodejs:<stream>install failing withbroken groups or modules, by resetting the module first whennodejs__dnf_module_streamis set and installing the explicit/commonprofile. - role:blocky: The
validate config & restart blocky.servicehandler is notified when the blocky binary changes, so the service is restarted after an update. - role:mariadb_server: Stop writing the deprecated
innodb_buffer_pool_chunk_sizesetting for MariaDB 10.11, 11.4 and 11.8, which ignore it and derive the chunk size frominnodb_buffer_pool_size. The role aborts at the start of the run with a clear error ifinnodb_buffer_pool_chunk_size(on MariaDB 10.11+) orinnodb_file_per_table(on MariaDB 11.0+) is still set in inventory, so an upgrade from 10.6 to 11.x does not silently keep a stale override. - role:mariadb_server: Fix MariaDB starting in the
unconfined_service_tSELinux domain on RHEL 10, which mislabels/var/lib/mysql/mysql.sockand breaksphp-fpmandhttpd_tclients such as Icinga Web 2 login. The role sets themysqld_exec_tfile context persistently viasemanage fcontextandrestorecon, since the previouschconworkaround cannot relabel the binary under EL10's read-only/usrservice sandbox. - role:icinga2_master: Fix the
selinuxrole failing on RHEL 10 withSELinux boolean icinga2_can_connect_all is not defined in persistent policy, by installingnagios-selinuxfrom EPEL first so its%postregisters the types thaticinga2-selinuxreferences. - role:redis: Fix
No package redis available.on RHEL 10, where Red Hat replaced Redis with the compatible Valkey in AppStream and Remi no longer ships Redis for EL10. The role installsvalkeyon EL10 and guards the Redis Stackloadmoduledirectives that do not exist on Valkey; EL8 and EL9 keep installing Redis unchanged and the user-facingredis__conf_*variables stay backwards-compatible. - role:openvpn_server: Fix
invalid selinux contexton RHEL 10 when deployingserver.p12andcrl.pem, by usingetc_tthere since theopenvpn_etc_ttype no longer exists in the RHEL 10 core policy. - role:repo_epel: Fix a malformed RHEL 10
epel.repo, where a missing newline renderedenabled=0username=<login>whenrepo_epel__basic_auth_loginwas set and dnf rejected the file. - role:repo_mariadb: Fix
dnf -y module disable mariadbfailing on RHEL 10, where modularity was removed, by scoping the task and themodule_hotfixesdirective to RHEL 8 and 9. - role:infomaniak_vm: Apply the VM's security group on the
ext-net1port instead of only on the server, since Neutron enforces the port's security groups when a VM boots against a pre-created port, and stop passingsecurity_groupstoopenstack.cloud.server, which failed on internal-network ports withport_security_enabledset tofalse. - role:haveged: Setting
haveged__service_state: 'stopped'no longer produces the invalid systemctl commandstopp, so all four valid values work as expected. - role:influxdb: Always install
curl, which is required to start influxdb but missing as a package dependency. - role:redis: Add the missing paths for running against Debian.
- role:logstash: The default
logstash__java_optssets the JVM heap size to 60% of total memory, capped at 8g. - role:mount: Fix the
whencondition for NFS/CIFS client package installation failing with multiple mounts and when thestatekey is undefined. - execution-environment: Add the missing
sshpasssystem package, required for SSH password-based connections such as--ask-pass. - plugin:nextcloud_occ_app_config: An
arrayconfig value is compared as JSON, so a key whose stored value already matches no longer reports a change and re-runsocc config:app:seton every run. - plugin:bitwarden_item: The module no longer writes to the Bitwarden vault in check mode (
--check), and a run withoutpasswordno longer overwrites an existing item's password. - plugin:sqlite_query: A failed query fails the task instead of reporting success with the error text in
query_result, and aREGEXPquery against a column containing NULL values no longer fails. - plugin:uptimerobot_*: The modules no longer crash when the UptimeRobot API returns a non-list response for a list endpoint.
- plugin:bitwarden_item, plugin:combine_lod, plugin:gpg_key, plugin:nextcloud_occ_app_config, plugin:nextcloud_occ_system_config, plugin:uptimerobot_monitor, plugin:uptimerobot_psp: Fixed the plugin documentation so
ansible-docrenders it again, and corrected thegpg_keydocs, which claimed a separatepython-gnupginstall is required and named the returned key field wrongly. - playbooks/clamav, playbooks/duplicity, playbooks/fangfrisch, playbooks/influxdb, playbooks/mongodb, playbooks/python_venv: Enable
repo_baseos(CRB) andrepo_epelon Rocky 9 and newer before thepython_venvrole, to fixNo match for argument: python3-virtualenv. - playbooks/setup_graylog_datanode, playbooks/setup_graylog_server, playbooks/setup_icinga2_master, playbooks/setup_rocketchat: Extend the
repo_baseosandrepo_epelconditions to Rocky and RHEL 10. - playbooks/freeipa_client, playbooks/freeipa_server: Set
strategy: 'linear'explicitly, so the playbooks work even when the user'sansible.cfgdefaults to a strategy that reuses the target Python interpreter, which otherwise fails withAPI.bootstrap() already called. - role:repo_monitoring_plugins: Add the missing
run_once: trueon the local repo-key download task on Red Hat platforms, so the key is downloaded once per run instead of once per host.
Security¶
- plugin:gpg_key: The cleartext passphrase is no longer included in the module's failure output when key generation fails.
- role:repo_*: HTTP basic auth credentials are only written to the repository config files when a custom mirror URL is set. Previously, setting
lfops__repo_basic_auth_loginwithoutlfops__repo_mirror_urlwrote the credentials into repo files that still pointed at the public vendor mirrors, so the package manager sent them to servers that do not use basic auth. The Icinga repo is intentionally unchanged, since its subscription URL legitimately requires basic auth.
v6.0.1 - 2026-04-07¶
Fixed¶
- ci: Strip badges from README.md before publishing to Galaxy, as external images are not rendered
v6.0.0 - 2026-04-07¶
Breaking Changes¶
- role:nfs_server: Rework
nfs_server__exportsfrom a list of strings to a list of dictionaries with newpath,clients,owner,group, andmodesubkeys - role:kvm_host: Change NAT to be explicitly activated for virtual nets
- role:apache_httpd: Change the default to not install/enable mod_qos by default (it is no longer shipped in EPEL 10)
Added¶
- Add MkDocs-based documentation site, deployed automatically to GitHub Pages via
tools/build-docsand a GitHub Actions workflow - CONTRIBUTING: Document semantic parameter ordering for Ansible modules
- playbooks: Add
example.ymlandsetup_example.ymlplaybooks as development references - role:example: Add complete example role with defaults, handlers, tasks, templates, and vars as a reference for consistent role development
- role:icingaweb2_module_grafana: Add JWT support
- role:grafana: Add JWT support
- Add
playbooks/README.mddocumenting all playbooks with their roles in execution order and available skip variables - role:apache_httpd: Add platform-specific behavior section, wsgi example, and document localhost endpoints in README
- role:apache_httpd: Add skip variables section to README linking to relevant playbooks
- role:mailx: Add skip variables section to README linking to relevant playbooks
- role:policycoreutils: Add skip variables section to README linking to relevant playbooks
- role:yum_utils: Add skip variables section to README linking to relevant playbooks
- plugin:bitwarden_item: Add file-based item cache to reduce
bw serveAPI calls, preventing crashes under load. Cache is stored in$XDG_RUNTIME_DIR(RAM-backed tmpfs) with/tmpfallback. After create/edit operations, the cache is updated inline to avoid expensive full re-syncs, with a 1-second sleep as rate limit to prevent Bitwarden API errors. Convertis_unlockedto a property to fix it never being called. - role:freeipa_server: Add
--diffsupport for all FreeIPA modules and addfreeipa_server:configuretag - role:mariadb_server: Add
mariadb_server__cnf_wsrep_log_conflictsandmariadb_server__cnf_wsrep_retry_autocommitvariables - role:mariadb_server: Add
mariadb_server__cnf_wsrep_gtid_modevariable to configurewsrep_gtid_modefor Galera - role:openvpn_server: Add
openvpn_server:crltag to allow deploying the certificate revocation list independently - role:nextcloud: Add Icinga2 set / unset downtime functionality to
nextcloud-update.j2 - execution-environment: Add mitogen
- role:nfs_client: Add optional
owner,groupandmodesubkeys for mount point directories - role:logstash: Add support for deploying custom grok pattern files to
/etc/logstash/patterns/ - role:mount: Add optional
ownerandgroupsubkeys for mount point directories - role:elasticsearch: Add logrotate config for daily rotation
- role:freeipa_server: Add the ability to specify the systemd unit start timeout
- role:postfix: Add RHEL 10 support
- role:kvm_vm: Add the ability to resize disks
- role:infomaniak_vm: Add the ability to choose the deployment region/datacenter
- role:crypto_policy: Add RHEL 10 support
- role:elastic_agent: Add new role
- role:elastic_agent_fleet_server: Add new role
- role:fail2ban: Make
bantimeconfigurable for the sshd and portscan jails - role:duplicity: Add support for RHEL 10
- role:php: Make
request_slowlog_timeoutandrequest_terminate_timeoutconfigurable - role:graylog_server: Make
http_publish_uriconfigurable; maketrusted_proxiesconfigurable - role:graylog_datanode: Add template for 7.0
- role:graylog_server: Add template for 7.0
- role:lvm: Add new role
- role:logrotate: Add support for RHEL 10
- role:sshd: Add support for RHEL 10
- role:yum_utils: Add support for RHEL 10
- role:repo_epel: Add support for RHEL 10
- role:repo_baseos: Add support for RHEL 10
- role:policycoreutils: Add support for RHEL 10
- role:mailx: Add support for RHEL 10
- role:graylog_server: Make
message_journal_dirconfigurable - playbook:setup_basic: Add lvm role
Changed¶
- ci: Publish pre-releases directly to prod Ansible Galaxy instead of galaxy-dev, since it is unreliable and pulp-ansible excludes pre-release versions from "latest"
- Update pre-commit hooks to latest versions
- Unify CONTRIBUTING and convert from reStructuredText to Markdown
- roles: Add
backup: trueto allansible.builtin.templatetasks to ensure config file backups before overwriting - role:nextcloud: Refactor
nextcloud-update.j2 - role:keycloak: Rework
keycloak.conftemplate to match Keycloak's default config structure - role:apache_httpd: bump Core Rule Set to 4.24.1
- role:repo_remi: Install Composer from
remi-modularrepository - role:icingadb: Enhance
config.ymltemplate - role:apache_httpd: Improve output; bump Core Rule Set to 4.24.0
Fixed¶
- role:apache_httpd: Fix
apache_httpd__mod_security_coreruleset_versiondefault value in README (4.4.0 -> 4.24.1), fix prefork variable names in README (spare_threads->spare_servers), fix various typos ("best practise", "Tipp") - role:mailx: Fix grammar in task name ("make" -> "makes"), sort template module parameters alphabetically
- role:policycoreutils: Fix grammar in task name ("are" -> "is")
- plugin:bitwarden_item: Fix missing
raisein multipart error handling,breakinstead ofcontinuein multi-term lookup,folder_idwrongly typed aslistinstead ofstrin module, notes default mismatch between documentation and code, and wrong "lookup plugin" wording in module documentation - role:mirror: Fix missing
0440permissions on sudoers file - role:login: Rename sudoers file from
lfops_logintolinuxfabrikto match the kickstart configuration; remove the old file automatically - roles: Fix Ansible 2.19 deprecation warning for conditional results of type
intby using| length > 0instead of| length - role:firewall: Fix fwbuilder repo clone being skipped when
run_oncepicks a host withoutfirewall__fwbuilder_repo_url - role:sshd: Validate sshd config with
sshd -tbefore reloading the service - role:nfs_client: Fix systemd not being aware of new or removed NFS mount units
- role:keycloak: Fix issues preventing Keycloak from starting
- role:systemd_unit: Correct the removal of units
- role:bind: Fix incorrect distribution version comparison in named.conf
- role:python_venv: Fix venv path in remove venv task
- role:apache_httpd: Prevent deployment of mods that should be disabled
- role:repo_postgresql: Remove EOL versions, adjust for RHEL 9 & 10
- role:mariadb_server: Fix the root cause of
/run/mariadb/wsrep-start-position: No such file or directoryafter update of MariaDB (10.11.14 -> 10.11.15 or 11.4.8 -> 11.4.9) - role:ansible_init: Install Ansible Collections from requirements.txt since that file contains the correct versions for running against RHEL 8
- role:kibana: Enable log rotation
- role:kibana: Fix
whenstatement - playbook:setup_icinga2_master: Fix syntax; add missing
kernel_settingsfor MariaDB - lookup_plugin:bitwarden: Make it more robust
- role:monitoring_plugins: Fix installation of package against non-RHEL hosts
- role:rocketchat: Fix typo and order of calls in playbook
v5.1.0 - 2026-01-06¶
Added¶
- role:kibana: Add
kibana__rawvariable - role:elasticsearch: Add
elasticsearch__rawvariable - role:apache_httpd: Add nice ErrorDocuments
- role:kibana: Make SSL settings configurable
v5.0.0 - 2025-11-14¶
Breaking Changes¶
- role:elasticsearch_oss: Rename to
elasticsearch, as both the free and subscription versions are now in the same package - role:repo_elasticsearch_oss: Remove, as both the free and subscription versions are now in the same package
Added¶
- role:acme_sh: Add
acme_sh__reload_cmdto allow setting the local reload command globally for all certificates - role:collabora: Add new template versions
- role:elasticsearch:
- Make
node.rolesconfigurable - Add variables for allocation awareness
- Add
elasticsearch__path_datavariable to configure custom data directory - Improve handling of TLS certificates
- Allow creation of clusters
- role:gitlab_ce: Make the
gitlab.rboptions for default project features, email reply-to address, LDAP integration and the upload path configurable - role:graylog_server: Re-add
graylog_server__elasticsearch_hoststo allow setups without Graylog Data Node - role:kibana: Add new role
- role:mariadb_server:
- Add support for version 11.8 (LTS)
- Make
log_slave_updatesconfigurable - Add
mariadb_server__cnf_server_rawvariable - role:podman_containers: Add option to enable the
podman-auto-update.timer - role:postfix: Add
postfix__lookup_tables__*_varto allow easy deployment of lookup tables - role:redis: Add template for version 8.2
- role:selinux:
- Add handling of SELinux modules
- Add capability to run
restorecon - Add
selinux__policyvariable - role:shell: Add
shell__limit_cmdsto limit executed shell commands - playbook:selinux: Add
selinux__skip_policycoreutilsvariable
Fixed¶
- role:acme_sh: Fix certificate paths for Ubuntu and Debian
- role:apache_solr: Automatically install the correct Java version
- role:elasticsearch:
- Prevent undefined variable error
- Fix default of
elasticsearch__path_data - Set
vm.swappinessto 1 - role:firewall: Ensure
firewalldis installed if chosen - role:icinga2_agent: Deploy logrotate config as hotfix for upstream issue (#188)
- role:icinga2_master: Deploy logrotate config as hotfix for upstream issue (#189)
- role:icingaweb2: Fix Icinga username for Debian
- role:keycloak: Install correct Java version, removing the
keycloak__java_package_namevariable - role:kvm_vm: Fix path
- role:mariadb_server: Fix
/run/mariadb/wsrep-start-position: No such file or directoryafter update - role:mastodon: Adjust to breaking changes in
elasticsearchrole - role:monitoring_plugins:
- Also install
libvia source ifmonitoring_plugins__install_method: 'source'is set - Add workaround for pip on Debian & Ubuntu
- role:openvpn_server: Actually remove CCD with
state: 'absent' - role:repo_mariadb: Fix handling of GPG key for Debian & Ubuntu
- role:repo_opensearch: Deploy correct GPG key for selected OpenSearch version
- role:rocketchat: Fix syntax of HealthCmd
- playbook:opensearch: Prevent the whole cluster from restarting at once
- playbook:setup_icinga2_master:
- Fix order
- Add missing injection for MariaDB Python modules
v4.0.0 - 2025-10-03¶
Breaking Changes¶
- role:icinga2_master: Remove support for IDO, as it is deprecated in favor of IcingaDB. The following variables can be removed from the inventory:
icinga2_master__database_enable_haicinga2_master__database_hosticinga2_master__database_loginicinga2_master__database_name- role:icingaweb2_module_monitoring: Remove, as it is deprecated in favor of IcingaDB. All variables starting with
icingaweb2_module_monitoring__can be removed from the inventory. - role:mariadb_server:
- Remove support for EOL version 10.5
- Remove
mariadb_server__cnf_expire_logs_days__group_var/mariadb_server__cnf_expire_logs_days__host_var, usemariadb_server__cnf_binlog_expire_logs_seconds__group_var/mariadb_server__cnf_binlog_expire_logs_seconds__host_varinstead
Added¶
- role:acme_sh: Add support for Debian/Ubuntu
- role:apache_httpd: Add support for Debian/Ubuntu
- role:elasticsearch_oss: Add
elasticsearch_oss__discovery_type,elasticsearch_oss__network_hostvariables; reset JVM tmp directory - role:icingaweb2_module_pdfexport: Add new role
- role:kvm_host: Add support for Ubuntu 24.04
- role:mastodon: Add new role
- role:mongodb: Add RedHat config template for v8.0
- role:moodle: Add
moodle__versionvariable to select the major and minor version - role:postgresql_server: Add
postgresql_server__login_passwordvariable - role:repo_mydumper: Add official repos for Debian-based systems
- role:system_update: Add
metadata_timer_syncoption for cache-only installations - tool:particle: Add new tool
Changed¶
- role:gitlab_ce: Update template to v18.4.0
- role:mariadb_server:
- Create a backup file of the most important config files before applying new versions
- Make ownership of SSL certificate CIS-conform
- role:monitoring_plugins: Remove
monitoring_plugins__skip_notification_plugins__*_varvariables as they are now always installed - role:systemd_journald: Move config file to
/etc/systemd/journald.conf.d/z00-linuxfabrik.conf, improve calculations and default values
Fixed¶
- role:apache_httpd:
- Use platform-specific group for htpasswd files
- Allow unsetting the
CustomLogdirective - role:apache_tomcat: Adjust logrotate config for multiple Tomcat instances
- role:bind:
- Do not run
named-checkzoneagainst forward zones - Remove obsolete options for RHEL 9
- role:duplicity: Use python3.11 to prevent errors when installing latest duplicity
- role:elasticsearch_oss: Move tmpdir to a location with exec permissions specified by CIS hardening
- role:keycloak: Set
keycloak__proxy_trusted_addressesto'127.0.0.1'due to FD leak if using'127.0.0.1,::1' - role:mariadb_server:
- Correct mydumper dependency packages for Debian-based systems
- Fix failing dumps after mydumper update to v0.20.1
- Adjust SELinux settings after upgrades
- Grant
binlog monitorprivilege formariadb-backupuser - role:monitoring_plugins:
- Fix path to old sudoers file
- Fix script execution in CIS-hardened
/tmp - Improve versionlock and install SELinux package on RHEL
- role:nextcloud: Add missing
envmodule - role:repo_opensearch: Fix GPG key
v3.0.0 - 2025-06-13¶
Breaking Changes¶
- role:apache_httpd:
- Change
conf_server_aliasfrom a string to a list - Change default of the
authz_document_rootvHost variable fromRequire localtoRequire all granted. This is a more sensible default, asallowed_file_extensionsis used to restrict the access. - Remove the
authz_file_extensionsvHost variable. Access to listed file extensions is now always allowed. - Fix a bug that allowed access to dotfiles which had extensions listed in
allowed_file_extensions. Make sure this does not break your application, or setallow_accessing_dotfiles: true. - Change default of
apache_httpd__skip_mod_security_corerulesetfromfalsetotrue - role:apache_tomcat:
- Rename
apache_tomcat__skip_managertoapache_tomcat__skip_admin_webapps - Change
apache_tomcat__users__*_varfrom a simple list to a list of dictionaries - role:borg_local: Add new mandatory variable
borg_local__passphrase - role:collabora:
- Change
collabora__coolwsd_storage_wopi__*_varto a list of dictionaries from a list of strings - Change
collabora__language_packages__*_varto a list of dictionaries from a list of strings - Rename
collabora__coolwsd_allowed_languagestocollabora__coolwsd_allowed_languages__*_varand change it to a list of dictionaries from a list of strings - role:fangfrisch: Remove malwarepatrol as it is discontinued (see https://malwareblocklist.org/)
- role:grafana: Change default value for
grafana__serve_from_sub_pathfromtruetofalse - role:graylog_server:
- Remove support for Graylog < 5.0
- Only support Graylog 6.1+ (Graylog Data Node based installations). Currently no more support for dedicated OpenSearch or Elasticsearch.
- Rename
graylog_server__admin_usertograylog_server__root_user - role:icinga_kubernetes: Switch config to v0.3.0 multi-cluster format, remove
icinga_kubernetes__kubeconfig_path - role:icingadb: Split into two roles, one for the IcingaDB daemon and one for IcingaDB Web. Have a look at the variables in the READMEs. Generally it is enough to rename
icingadb__api_user_logintoicingadb_web__api_user_login. - role:icingaweb2_module_director: The
icingaweb2_module_director:baskettag only runs if explicitly called to prevent accidental config overwrites - role:icingaweb2_module_vspheredb: Remove the
vprefix from theicingaweb2_module_vspheredb__versionvariable to be consistent with the othericingaweb2_module_*roles - role:kvm_vm: Change
kvm_vm__boot_uefi(bool) tokvm_vm__boot(string) - role:login: Change default of
remove_other_sshd_authorized_keysfromtruetofalse - role:mailto_root:
- Move most functionality to
role:postfix, remove themailto_root:configureandmailto_root:testmailtags - Change
mailto_root__fromfrom optional to mandatory - Testmail to external addresses now uses sender address (
mailto_root__from) - role:mariadb_client: Remove (use the
appsrole instead) - role:mariadb_server:
- Remove support for EOL versions 10.3 and 10.4
- Remove support for non-LTS versions
- Change default of
mariadb_server__cnf_client_ssl_verify_server_cert__*_varfor versions lower than 10.11 fromtruetofalseto prevent errors when SSL is disabled - module:bitwarden_item, lookup_plugin:bitwarden:
- Remove parameters
password_uppercase,password_lowercase,password_numeric,password_special - Add parameter
password_choice - role:mongodb: Change
mongodb__conf_net_bind_ipfrom a string to a list of strings. For example: ```yaml # old mongodb__conf_net_bind_ip: '0.0.0.0'
# new
mongodb__conf_net_bind_ip:
- '0.0.0.0'
* **role:monitoring_plugins**:
* Remove variables:
* `monitoring_plugins__pip_executable`
* `monitoring_plugins__pip_package`
* `monitoring_plugins__python__modules`
* `monitoring_plugins__windows_variant`
* The `lfops__monitoring_plugins_version` variable (and all the `*.monitoring_plugin.*_version` variables) now only accepts a specific release or the value `dev`. `stable` or `latest` are no longer supported.
* The `lfops__monitoring_plugins_version` variable is now mandatory.
* Rename `monitoring_plugins__linux_variant` to `monitoring_plugins__install_method`:
* `monitoring_plugins__linux_variant: 'python'` becomes `monitoring_plugins__install_method: 'source'`
* Rename `monitoring_plugins__repo_version` to `monitoring_plugins__version`:
* `monitoring_plugins__repo_version: 'latest'` becomes `monitoring_plugins__version: 'dev'`
* Remove the tasks for Nuitka compilation, as the compilation is done by the [Monitoring Plugins GitHub Action](https://github.com/Linuxfabrik/monitoring-plugins/actions/workflows/nuitka-compile.yml) now
* Lock the version of the `monitoring-plugins` package after installing it. Updating the plugins should be done manually along with updating the monitoring system configuration.
* **role:monitoring_plugins_grafana_dashboards**: Change from provisioning to grizzly for the deployment of the dashboards
* **role:mount**: Change `mount__mounts` to `mount__mounts__host_var` / `mount__mounts__group_var`
* **role:nextcloud**:
* Rename `nextcloud__apps_config` to `nextcloud__app_configs__*_var`, add `state` subkey, make more use of the `value` subkey. `--value` is no longer required:yaml
# old
nextcloud__apps_config:
- { key: 'core', value: 'shareapi_default_expire_date --value=yes' }
# new
nextcloud__app_configs__host_var:
- key: 'core shareapi_default_expire_date'
value: 'yes'
state: 'present'
* Rename `nextcloud__apps` to `nextcloud__apps__*_var`, add `state` subkey
* Rename `nextcloud__sysconfig` to `nextcloud__sysconfig__*_var`, add `state` subkey, make more use of the `value` subkey (same as `nextcloud__app_configs__*_var`)
* Remove `nextcloud__proxyconfig`. Use `nextcloud__sysconfig__*_var` instead.
* Implement [notify_push](https://github.com/nextcloud/notify_push). Add the following to your Apache HTTPd config:apacheconf
RewriteRule ^\/push\/ws(.) ws://nextcloud-server:7867/ws$1 [proxy,last]
RewriteRule ^\/push\/(.) http://nextcloud-server:7867/$1 [proxy,last]
ProxyPassReverse /push/ http://nextcloud-server:7867/
``
* Change default ofnextcloud__timer_app_update_enabledfromtruetofalse, as this can sometimes lead to Nextcloud ending up in maintenance mode
* Renamenextcloud__apache_httpd__vhosts_virtualhost_iptonextcloud__vhost_virtualhost_ip* Renamenextcloud__apache_httpd__vhosts_virtualhost_porttonextcloud__vhost_virtualhost_port* **role:opensearch**:
* Change default ofopensearch__plugins_security_disabledfromtruetofalse* For new installations of OpenSearch 2.12 and later, you must define a custom admin password inopensearch__opensearch_initial_admin_password* **role:openssl**: Remove (use theappsrole instead)
* **role:perl**: Remove (use theappsrole instead)
* **role:postfix**: Now completely templates the whole config file. Beware when running against existing hosts.
* **role:postgresql_server**: Rename thenamesubkey ofpostgresql_server__users___vartousernamefor consistency and easier integration of the Bitwarden lookup plugin
* **role:python**: Changepython__modules___varto a list of dictionaries from a list of strings
* **role:redis**:
* Drop support for Redis v5 (end of life)
* Drop support for Redis v6
* Change default ofredis__service_timeout_start_secandredis__service_timeout_stop_secfrom5sto90s* **role:repo_icinga**:
* Removerepo_icinga__use_subscription_urlfor RHEL (and compatibles) as the packages without a subscription are outdated. The variable is now only effective for openSUSE and SLES.
* Renamerepo_icinga__subscription_logintorepo_icinga__basic_auth_loginand add a variable to explicitly use the Icinga Repo Subscription URL (repo_icinga__use_subscription_url). If you haverepo_icinga__subscription_loginset in your inventory, rename it torepo_icinga__basic_auth_loginand setrepo_icinga__use_subscription_url: truefor the same effect.
* **role:repo_mydumper**: Adjust to use https://repo.linuxfabrik.ch/mydumper/ by default. Removerepo_mydumper__baseurl, addrepo_mydumper__mirror_urlinstead.
* **role:rocketchat**:
* Switch deployment method from native installation to Podman container
* Removerocketchat__npm_versionvariable
* Rename and alter:
*rocketchat__application_pathtorocketchat__user_home_directory(new default:'/opt/rocketchat')
*rocketchat__service_enabledtorocketchat__container_enabled*rocketchat__service_statetorocketchat__container_state* Change default ofrocketchat__mongodb_hostto'host.containers.internal'* Remove Rocket.Chat notifications from the default banaction
* **role:selinux**: Changeportssubkey ofselinux__ports__*_vartoport, accepting only a single port or port range, not a list
* **role:sshd**:
* Removesshd__ciphers,sshd__kexandsshd__macsvariables, as these settings are managed bycrypto-policyon RHEL
* Now deploy the complete/etc/ssh/sshd_configas a template
* Remove support for RHEL 7
* **role:system_update**: Removesystem_update__icinga2_mastervariable. Usesystem_update__icinga2_api_urlinstead.
* **role:systemd_journald**: The value forsystemd_journald__conf_system_max_useis now interpreted as a size in bytes. It supports the size specifications possible injournald.conf(e.g.4G). If you want to specify a percentage, use'40%'.
* **role:tar**: Remove (use theappsrole instead)
* **playbook:icinga2_agent**: Change to also include the installation of the [Linuxfabrik Monitoring Plugins](https://github.com/Linuxfabrik/monitoring-plugins). This can be skipped by settingicinga2_agent__skip_monitoring_plugins: true.
* **playbook:setup_icinga2_master**:
* Change default ofsetup_icinga2_master__icingaweb2_module_company__skip_rolefromfalsetotrue* Change the format of the role skip-variables fromplaybook_name_skip_role_nametoplaybook_name__role_name__skip_rolefor clarity and consistency. Have a look at the [README.md](./README.md#skipping-roles-in-a-playbook).
* Addplaybook_name__role_name__skip_role_injectionsvariables to disable or re-enable the role's injections
* Change default ofsetup_icinga2_master__skip_icingaweb2_module_monitoringfromfalsetotrue`
Added¶
- role:nextcloud: Add nextcloud_occ_*_config modules with diff and check mode support
- role:alternatives: Add new role
- role:apache_httpd:
- Add some mods
- Add
skip_allowed_file_extensionsvHost variable - Add
skip_allowed_http_methodsvHost variable - role:apache_solr: Add new role
- role:audit: Add more config variables
- role:bind:
- Add multiple new variables, now allowing a primary-secondary setup
- Add
bind__named_conf_rawvariable - role:blocky: Add new role
- role:borg_local: Add new role
- role:clamav: Add new role
- role:cloud_init: Add task to remove
/etc/cloud/cloud.cfg.rpmsave - role:collect_rpmnew_rpmsave: Add new role
- role:dnf_versionlock: Add new role
- role:duplicity: Add
duplicity__backup_full_if_older_thanvariable - role:fangfrisch: Add new role
- role:firewall: Add
firewall__firewalld_ports__*_varandfirewall__firewalld_services__*_varvariables - role:github_project_createrepo: Add new role
- role:glpi_agent: Add new role
- role:grafana: Add creation of service accounts and their tokens
- role:grafana_grizzly: Add new role
- role:graylog_datanode: Add new role
- role:graylog_server: Add variables and documentation for multi-node setup; add Debian support
- role:icinga2_agent: Add
icinga2_agent:updatetag; addicinga2_agent__validate_certsvariable - role:icinga2_master: Add
icinga2_master__bind_hostvariable - role:icinga_kubernetes: Add new role
- role:icinga_kubernetes_web: Add new role
- role:icingadb: Add new role
- role:icingaweb2_module_businessprocess: Add new role
- role:icingaweb2_module_cube: Add new role
- role:icingaweb2_module_fileshipper: Add new role
- role:icingaweb2_module_generictts: Add new role
- role:icingaweb2_module_jira: Add new role
- role:icingaweb2_module_reporting: Add new role
- role:icingaweb2_module_x509: Add
icingaweb2_module_x509__urlvariable - role:kvm_vm: Add the option to boot the VM with UEFI
- role:logrotate: Add compression
- role:mariadb_server:
- Add
mariadb_server__cnf_wsrep_sst_authandmariadb_server__cnf_wsrep_sst_methodvariables - Add
mariadb_server__cnf_extra_max_connections__*_varandmariadb_server__cnf_extra_port__*_varvariables - Add support for client and server TLS
- Add Galera cluster installation
- Make datadir configurable, including copy of old data to the new location
- Make socket configurable
- role:mirror: Add new role
- role:mongodb:
- Add Debian support
- Add keyfile handling
- Adjust for replica set across members
- Implement user management (fix #89)
- role:moodle: Add new role
- role:mount: Add new role
- role:opensearch: Add Debian support; add variables for cluster configuration
- role:php: Add tag
php:fpm - role:podman_containers: Add new role
- role:proxysql: Add new role
- role:python_venv:
- Allow specifying different certificate store
- Allow specifying the Python executable to be used in the venv
- Add Debian support
- role:repo_baseos: Add AlmaLinux 8 support
- role:repo_epel: Add
repo_epel__epel_cisco_openh264_enabledvariable - role:repo_gitlab_runner: Add new role
- role:repo_graylog: Add Debian support
- role:repo_mongodb: Add Debian support
- role:repo_opensearch: Add Debian support
- role:repo_proxysql: Add new role
- role:repo_redis: Add new role
- role:repo_rpmfusion: Add new role
- role:selinux: Add support for SELinux ports
- role:shell: Add new role; add option to ignore errors during command execution
- role:system_update: Add option
-ytoyum check-update - role:systemd_journald: Add variable
systemd_journald__conf_system_keep_free; makeSystemMaxUseconfigurable - role:systemd_unit: Add support for mount units
- role:tools: Add
tools__prompt_use_fqdnvariable - playbook:setup_basic: Add support for AlmaLinux 8
Changed¶
- role:apache_httpd: Change default of the
conf_custom_logvHost variable from unset to'logs/{{ conf_server_name }}-access.log linuxfabrikio' - role:graylog_server: Remove version defaults from the role
- role:icingaweb2_module_grafana: Change GitHub repo from Mikesch-mp to NETWAYS
- role:mariadb_server: mariadb-dump checks for the mydumper version and sets parameters accordingly
- role:open_vm_tools: Start and enable
vmtoolsd - role:opensearch: Make
opensearch__version*optional
Fixed¶
- role:influxdb: Fix wrong systemd service name, which was preventing InfluxDB dumps from being scheduled
- role:mariadb_server:
- Fix handler when
bind_addressis not localhost - Add installation of missing package for mariabackup Galera SST
- Fix clone-datadir against new Galera cluster
- role:redis: Fix various messages from log, fix v7 template settings, fix various comments and README
v2.0.1 - 2023-02-28¶
Changed¶
- Adjustments for the Ansible Galaxy Release
v2.0.0 - 2023-02-28¶
Breaking Changes¶
- All roles: Rename all injectable variables:
rolename__combined_varnametorolename__varname__combined_varrolename__dependent_varnametorolename__varname__dependent_varrolename__group_varnametorolename__varname__group_varrolename__host_varnametorolename__varname__host_varrolename__role_varnametorolename__varname__role_var- role:acme_sh:
- Add
namesubkey toacme_sh__certificates - Move
acme_sh__reload_cmdto a subkey ofacme_sh__certificates - role:chrony: Fix wrong variable prefix: adjust
chrony_server__tochrony__ - role:collabora: Rename rolename and vars from
collabora_codetocollabora - role:duplicity:
- Rename
duplicity__public_master_long_keyidtoduplicity__gpg_encrypt_master_key - Rename
duplicity__public_master_keytoduplicity__gpg_encrypt_master_key_block - Change the format of
duplicity__backup_sources__host_var - role:fail2ban: Adjust subkeys of
fail2ban__jails__group_var/fail2ban__jails__host_var - role:git: Add and later remove in favor of a more general
appsrole - role:hostname:
- Rename
hostname__domain_nametohostname__domain_part - Rename
hostname__hostnametohostname__full_hostname - role:icinga2_agent:
- Add new mandatory variable
icinga2_agent__icinga2_master_cn - Make
icinga2_agent__icinga2_master_hostoptional - Most users can replace all instances of
icinga2_agent__icinga2_master_hostwithicinga2_agent__icinga2_master_cn - role:infomaniak_vm:
- Rename
infomaniak_vm__passwordtoinfomaniak_vm__api_password - Rename
infomaniak_vm__project_idtoinfomaniak_vm__api_project_id - Rename
infomaniak_vm__usernametoinfomaniak_vm__api_username - Rename
infomaniak_vm__volume_sizetoinfomaniak_vm__separate_boot_volume_size - role:java: Remove, better substituted by the
appsrole - role:kernel_settings: Make
kernel_settings__variables injection-capable viakernel_settings__host_*,kernel_settings__group_*andkernel_settings__dependent_* - role:libselinux_python: Rename the role to
policycoreutils - role:login: Change logic and rename
login__usersto two combined variableslogin__users__group_var(define users in group vars) andlogin__users__host_var(define users in host vars) - role:mariadb_server:
- Rename
mariadb_server__admin_logintomariadb_server__admin_user - Move
mariadb_server__admin_hosttomariadb_server__admin_user["host"] - Rename
mariadb_server__dump_logintomariadb_server__dump_user - Move
mariadb_server__dump_user_*to subkeys inmariadb_server__dump_user - role:monitoring_plugins: Rename
monitoring_plugins__deploy_notification_pluginstomonitoring_plugins__skip_notification_pluginsand flip the logic - role:php: Make more variables injectable, therefore the variables have a new name
- role:stig: Move to a new GitHub repo (temporarily)
- role:system_update: Rename variables (note: old and new names appear identical in the original CHANGELOG, likely a documentation error):
system_update__mail_recipients_new_configfiles=>system_update__mail_recipients_new_configfilessystem_update__mail_recipients_updates=>system_update__mail_recipients_updatessystem_update__mail_from=>system_update__mail_fromsystem_update__mail_subject_prefix=>system_update__mail_subject_prefixsystem_update__notify_and_schedule_on_calendar=>system_update__notify_and_schedule_on_calendar- playbook:basic_setup: Rename to
setup_basicto be consistent with the other setup playbooks. Removeauditandcrypto_policyroles for now.
Added¶
- This CHANGELOG
- role:acme_sh: Add new role
- role:ansible_init: Add new role
- role:apache_httpd: Add new role
- role:apache_tomcat: Add new role
- role:apps: Add new role
- role:at: Add new role
- role:audit: Add new role
- role:bind: Add new role
- role:chrony: Add new role
- role:cloud_init: Add new role
- role:cockpit: Add new role
- role:collabora: Add new role
- role:coturn: Add new role
- role:crypto_policy: Add new role
- role:dnf_makecache: Add new role
- role:docker: Add new role
- role:elasticsearch_oss: Add new role
- role:exoscale_vm: Add new role
- role:fail2ban: Add new role
- role:firewall: Add new role
- role:freeipa_client: Add new role
- role:freeipa_server: Add new role
- role:glances: Add new role
- role:grafana: Add new role
- role:grav: Add new role
- role:graylog_server: Add new role
- role:haveged: Add new role
- role:hetzner_vm: Add new role
- role:hostname: Add new role
- role:icinga2_agent: Add new role
- role:icinga2_master: Add new role
- role:icingaweb2: Add new role
- role:icingaweb2_module_company: Add new role
- role:icingaweb2_module_director: Add new role
- role:icingaweb2_module_doc: Add new role
- role:icingaweb2_module_grafana: Add new role
- role:icingaweb2_module_incubator: Add new role
- role:icingaweb2_module_monitoring: Add new role
- role:icingaweb2_module_vspheredb: Add new role
- role:influxdb: Add new role
- role:infomaniak_vm: Add new role
- role:kdump: Add new role
- role:keepalived: Add new role
- role:kernel_settings: Add new role
- role:keycloak: Add new role
- role:kvm_host: Add new role
- role:kvm_vm: Add new role
- role:libmaxminddb: Add new role
- role:librenms: Add new role
- role:libreoffice: Add new role
- role:login: Add new role
- role:mailto_root: Add new role
- role:mariadb_client: Add new role
- role:mariadb_server: Add new role
- role:maxmind_geoip: Add new role
- role:minio_client: Add new role
- role:mod_maxminddb: Add new role
- role:mongodb: Add new role
- role:motd: Add new role
- role:network: Add new role; add functionality to configure network connections
- role:nextcloud: Add new role
- role:nfs_client: Add new role
- role:nfs_server: Add new role
- role:nodejs: Add new role
- role:objectstore_backup: Add new role
- role:open_vm_tools: Add new role
- role:openssl: Add new role
- role:openvpn_server: Add new role
- role:perl: Add new role
- role:php: Add new role
- role:policycoreutils: Add new role
- role:postgresql_server: Add new role
- role:qemu_guest_agent: Add new role
- role:redis: Add new role
- role:repo_baseos: Add new role
- role:repo_collabora: Add new role
- role:repo_collabora_code: Add new role
- role:repo_debian_base: Add new role
- role:repo_docker: Add new role
- role:repo_elasticsearch_oss: Add new role
- role:repo_gitlab_ce: Add new role
- role:repo_grafana: Add new role
- role:repo_icinga: Add new role
- role:repo_influxdb: Add new role
- role:repo_mariadb: Add new role
- role:repo_mongodb: Add new role
- role:repo_monitoring_plugins: Add new role
- role:repo_mydumper: Add new role
- role:repo_postgresql: Add new role
- role:repo_remi: Add new role
- role:repo_sury: Add new role
- role:rocketchat: Add new role
- role:rsyslog: Add new role
- role:snmp: Add new role
- role:sshd: Add new role
- role:stig: Add new role
- role:system_update: Add new role
- role:systemd_journald: Add new role
- role:systemd_unit: Add new role
- role:tar: Add new role
- role:telegraf: Add new role
- role:timezone: Add new role
- role:unattended_upgrades: Add new role
- role:wordpress: Add new role
- role:yum_utils: Add new role
Changed¶
- module_util:bitwarden: Switch to the Bitwarden client API, as it is more reliable than using the command line tool directly
- role:acme_sh: Automatically update acme.sh (fix #74)
- role:apache_tomcat: Use the correct Java version depending on Tomcat version (fix #82)
- role:duplicity: Implement massive-parallel backups
- role:hetzner_vm: Improve handling of IP addresses (new Hetzner features) (fix #72); manage the provider firewall (fix #71)
- role:login: Add a switch to be aggressive or not (fix #65)
- role:mariadb_server: Implement mydumper / adapt to the LFOps standards (fix #56)
- role:mongodb: Implement dumping / user management (fix #78)
- role:python: On RHEL 8+, don't install
python3. Instead installpython38orpython39explicitly (fix #62) - role:tools: Show distro in prompt (fix #47)
Fixed¶
- role:audit: Fix wrong README (fix #51, fix #58)
- role:crypto_policy: Fix wrong README (fix #52, fix #76)
- role:icinga2_agent: On Debian, user
nagiosdoes not exist when certs folder is created (fix #77) - role:icinga2_master: Fix missing option name in
icinga2_master/tasks/main.yml(fix #105) - role:monitoring_plugins: Fix "deploy" vs "skip" logic (fix #103)
- role:repo_graylog: Fix
repo_graylog__mirror_urlnever actually being used (fix #94) - role:sshd: Fix
ModuleNotFoundError: No module named 'seobject'(fix #53) - playbook:basic_setup: Fix
Failed to set locale, defaulting to C.UTF-8(fix #55) - Do not use
become: truein all playbooks (fix #66) - Deploy nft in basic-setup or the fwbuilder role (fix #61)
- role:freeipa_server: Fix
In unattended mode you need to provide at least -r, -p and -a options(fix #83)
v1.0.1 - 2022-03-17¶
Changed¶
- Adjust tags for Ansible Galaxy
v1.0.0 - 2022-03-17¶
Added¶
- role:duplicity: Add new role
- role:monitoring_plugins: Add new role
- role:python_venv: Add new role
- role:repo_epel: Add new role
- module:bitwarden_item: Add new module
- module:gpg_key: Add new module
- lookup_plugin:bitwarden: Add new lookup plugin
- module_util:bitwarden: Add new module util
- module_util:gnupg: Add new module util