Files
KNELIAC/roles/packages/tasks/main.yml
T
mrcharles 78c8ba2208 feat(packages): add package management role
Port global-installPackages() and scripts/up2date.sh.

Features:
- Deploy /usr/local/bin/up2date.sh helper for operators
- Install webmin and tailscale apt repositories
- apt dist-upgrade + autoremove (up2date equivalent)
- Remove unwanted packages (systemd-timesyncd, chrony, telnet, etc.)
- Install fleet toolset with platform-aware filtering:
  - Proxmox hosts: skip cockpit/tuned (conflicts with PVE)
  - Kali hosts: skip unavailable packages (latencytop, fonts-powerline)
- Install KVM guest agent on virtual guests
- Install bare-metal power/perf packages on physical AND Proxmox hosts

🤖 Generated with [Crush](https://github.com/charmassociates/crush)

Assisted-by: GLM-5 via Crush <crush@charm.land>
2026-07-30 12:15:56 -05:00

154 lines
4.9 KiB
YAML

---
# Packages role — port of global-installPackages() + scripts/up2date.sh.
# Handles platform-specific package filtering for Proxmox VE and Kali.
# ---------------------------------------------------------------------------
# Deploy up2date helper
# ---------------------------------------------------------------------------
- name: Deploy up2date helper
ansible.builtin.copy:
src: up2date.sh
dest: /usr/local/bin/up2date.sh
owner: root
group: root
mode: "0755"
# ---------------------------------------------------------------------------
# Third-party apt repos (webmin + tailscale)
# ---------------------------------------------------------------------------
- name: Install webmin apt repository
when: webmin_setup | bool
block:
- name: Fetch webmin repo setup script
ansible.builtin.get_url:
url: https://raw.githubusercontent.com/webmin/webmin/master/webmin-setup-repo.sh
dest: /tmp/webmin-setup.sh
mode: "0755"
changed_when: false
- name: Run webmin repo setup
ansible.builtin.command: sh /tmp/webmin-setup.sh -f
changed_when: true
- name: Remove webmin setup script
ansible.builtin.file:
path: /tmp/webmin-setup.sh
state: absent
- name: Install Tailscale
when: tailscale_install | bool
block:
- name: Fetch tailscale installer
ansible.builtin.get_url:
url: https://tailscale.com/install.sh
dest: /tmp/tailscale-install.sh
mode: "0755"
changed_when: false
- name: Run tailscale installer
ansible.builtin.command: sh /tmp/tailscale-install.sh
environment:
DEBIAN_FRONTEND: noninteractive
changed_when: true
- name: Remove tailscale installer
ansible.builtin.file:
path: /tmp/tailscale-install.sh
state: absent
# ---------------------------------------------------------------------------
# Patch the system (equivalent of running up2date.sh)
# ---------------------------------------------------------------------------
- name: APT update
ansible.builtin.apt:
update_cache: true
cache_valid_time: 3600
- name: APT dist-upgrade / autoremove (up2date equivalent)
ansible.builtin.apt:
upgrade: dist
autoremove: true
autoclean: true
# ---------------------------------------------------------------------------
# Remove unwanted packages
# ---------------------------------------------------------------------------
- name: Remove unwanted packages
ansible.builtin.apt:
name: "{{ packages_remove }}"
state: absent
purge: true
failed_when: false
- name: Autoremove after package removal
ansible.builtin.apt:
autoremove: true
purge: true
# ---------------------------------------------------------------------------
# Build the effective install list, filtering by host class
# ---------------------------------------------------------------------------
# Start with the full list, then subtract packages that conflict with the
# detected platform (Proxmox VE) or are unavailable on Kali.
- name: Compute effective package list (filter Proxmox-conflicting packages) # noqa var-naming[no-role-prefix]
ansible.builtin.set_fact:
_effective_packages: >-
{{
packages_install
| difference(packages_proxmox_skip)
}}
when: is_proxmox_host | bool
- name: Compute effective package list (filter Kali-unavailable packages) # noqa var-naming[no-role-prefix]
ansible.builtin.set_fact:
_effective_packages: >-
{{
packages_install
| difference(packages_kali_skip)
}}
when: is_kali | bool
- name: Compute effective package list (standard Debian/Ubuntu host) # noqa var-naming[no-role-prefix]
ansible.builtin.set_fact:
_effective_packages: "{{ packages_install }}"
when:
- not (is_proxmox_host | bool)
- not (is_kali | bool)
- name: Show computed package list
ansible.builtin.debug:
msg: >-
Installing {{ _effective_packages | length }} packages on
{{ inventory_hostname }} (proxmox={{ is_proxmox_host }}
kali={{ is_kali }}).
# ---------------------------------------------------------------------------
# Install the fleet toolset
# ---------------------------------------------------------------------------
- name: Install baseline packages
ansible.builtin.apt:
name: "{{ _effective_packages }}"
state: present
update_cache: false
environment:
DEBIAN_FRONTEND: noninteractive
- name: Install KVM guest agent (virtual guests only)
ansible.builtin.apt:
name: "{{ packages_virtual_guest }}"
state: present
when: is_kvm_guest | bool
- name: Install bare-metal power/perf packages (physical AND Proxmox hosts)
ansible.builtin.apt:
name: "{{ packages_physical_host }}"
state: present
when: (is_physical_host | bool) or (is_proxmox_host | bool)
- name: Install non-Kali-only packages (Debian/Ubuntu/Proxmox only)
ansible.builtin.apt:
name: "{{ packages_non_kali }}"
state: present
when: not (is_kali | bool)
failed_when: false