8 Commits

8 changed files with 50 additions and 6 deletions

2
.gitignore vendored
View File

@@ -1 +1,3 @@
ansible-navigator.log
collections/
backups/

View File

@@ -29,6 +29,7 @@
path: "~/.config/systemd/user/"
label:
traefik.enable: "true"
traefik.http.routers.gitea.entrypoints: "http"
traefik.http.routers.gitea.rule: "Host(`git.wtf.lt`)"
traefik.http.middlewares.gitea-https-redirect.redirectscheme.scheme: "https"
traefik.http.routers.gitea.middlewares: "gitea-https-redirect"

View File

@@ -9,7 +9,7 @@ Restart=always
[Container]
ContainerName=traefik
Image=docker.io/library/traefik:latest
Exec=--api.dashboard=true --api.insecure=true --certificatesresolvers.lets-encrypt.acme.email={{ infra_acme.email }} --certificatesresolvers.lets-encrypt.acme.storage=/{{ infra_acme.storage }} --certificatesresolvers.lets-encrypt.acme.tlschallenge=true --entrypoints.http --entrypoints.http.http.redirections.entryPoint.to=https --entrypoints.http.http.redirections.entryPoint.scheme=https --entrypoints.https --providers.docker=true
Exec=--api.dashboard=true --api.insecure=true --certificatesresolvers.lets-encrypt.acme.email={{ infra_acme.email }} --certificatesresolvers.lets-encrypt.acme.storage=/{{ infra_acme.storage }} --certificatesresolvers.lets-encrypt.acme.tlschallenge=true --entrypoints.http --entrypoints.http.address=:80 --entrypoints.http.http.redirections.entryPoint.to=:443 --entrypoints.http.http.redirections.entryPoint.scheme=https --entrypoints.https --providers.docker=true --providers.docker.network=podman
Network=podman
Notify=true
PublishPort=8080:8080

View File

@@ -71,6 +71,47 @@
- name: Install database quadlet
ansible.builtin.include_tasks: db.yml
- name: Schedule postgres database backup
ansible.builtin.cron:
name: "Backup mastodon postgres database"
minute: "0"
hour: "3"
job: >-
podman exec database pg_dump -U {{ mastodon_database.username }} mastodon
| gzip > ~/backups/mastodon-$(date +\%Y\%m\%d\%H\%M\%S).sql.gz &&
find ~/backups/ -type f -mtime 7 -delete
- name: Find backup files
ansible.builtin.find:
paths: "~/backups"
patterns: "mastodon-*.sql.gz"
register: mastodon_backup_files
tags:
- backup
- name: Identify latest backup file
ansible.builtin.set_fact:
mastodon_latest_backup: "{{ (mastodon_backup_files.files | sort(attribute='mtime') | last).path }}"
tags:
- backup
- name: Ensure local backup directory exists
ansible.builtin.file:
path: "{{ mastodon_local_backup_dir }}"
state: directory
delegate_to: localhost
become: false
tags:
- backup
- name: Download latest backup file to local machine
ansible.builtin.fetch:
src: "{{ mastodon_latest_backup }}"
dest: "{{ mastodon_local_backup_dir }}/{{ mastodon_latest_backup | basename }}"
flat: true
tags:
- backup
- name: Install redis quadlet
ansible.builtin.include_tasks: redis.yml

View File

@@ -5,7 +5,6 @@ Description=Mastodon Elasticsearch
ContainerName=elasticsearch
Image=docker.elastic.co/elasticsearch/elasticsearch:7.17.29
Network=mastodon_internal.network
Network=mastodon_external.network
Environment=ES_JAVA_OPTS=-Xms512m -Xmx512m -Des.enforce.bootstrap.checks=true
Environment=xpack.license.self_generated.type=basic
Environment=xpack.security.enabled=false

View File

@@ -5,10 +5,9 @@ Requires=database.service redis.service elasticsearch.service
[Container]
ContainerName=mastodon
Image=ghcr.io/mastodon/mastodon:v4.5.5
Image=ghcr.io/mastodon/mastodon:v4.6.4
Exec=bundle exec puma -C config/puma.rb
Network=mastodon_internal.network
Network=mastodon_external.network
Network=podman
Environment=LOCAL_DOMAIN=wtf.lt
Environment=REDIS_HOST=redis

View File

@@ -5,10 +5,9 @@ Requires=database.service redis.service elasticsearch.service
[Container]
ContainerName=sidekiq
Image=ghcr.io/mastodon/mastodon:v4.5.5
Image=ghcr.io/mastodon/mastodon:v4.6.4
Exec=bundle exec sidekiq
Network=mastodon_internal.network
Network=mastodon_external.network
Environment=LOCAL_DOMAIN=wtf.lt
Environment=REDIS_HOST=redis
Environment=REDIS_PORT=6379

View File

@@ -7,3 +7,6 @@ mastodon_local_dirs:
- "~/mastodon/redis"
- "~/mastodon/elasticsearch"
- "~/mastodon/system"
- "~/backups"
mastodon_local_backup_dir: "{{ playbook_dir }}/backups"