63 lines
2 KiB
YAML
63 lines
2 KiB
YAML
# OS-level configuration of the OctoPrint Pi, on top of a stock OctoPi image.
|
|
# OctoPrint's own settings/plugins/profiles come from its Backup & Restore zip,
|
|
# not from here (OctoPrint rewrites its own config.yaml) — see docs/todo.md.
|
|
- name: Configure the OctoPrint Pi
|
|
hosts: octoprint
|
|
become: true
|
|
vars:
|
|
timezone: Europe/Vienna
|
|
|
|
tasks:
|
|
- name: Set the timezone
|
|
community.general.timezone:
|
|
name: "{{ timezone }}"
|
|
|
|
# ModemManager probes new serial devices for modems — a printer on /dev/ttyACM0
|
|
# is one, and the probing can disturb the connection. There's no modem here.
|
|
- name: Disable and mask ModemManager
|
|
ansible.builtin.systemd_service:
|
|
name: ModemManager
|
|
state: stopped
|
|
enabled: false
|
|
masked: true
|
|
|
|
- name: Disable the Bluetooth services
|
|
ansible.builtin.systemd_service:
|
|
name: "{{ item }}"
|
|
state: stopped
|
|
enabled: false
|
|
loop:
|
|
- bluetooth
|
|
- hciuart
|
|
|
|
- name: Turn off the Bluetooth hardware (applies after reboot)
|
|
ansible.builtin.lineinfile:
|
|
path: /boot/firmware/config.txt
|
|
regexp: '^dtoverlay=disable-bt$'
|
|
line: dtoverlay=disable-bt
|
|
insertafter: '^\[all\]$'
|
|
notify: Reboot
|
|
|
|
# Key login only. sshd uses the first value it reads, and files in
|
|
# sshd_config.d are read (alphabetically) before the main sshd_config.
|
|
- name: Disable SSH password login
|
|
ansible.builtin.copy:
|
|
dest: /etc/ssh/sshd_config.d/10-no-passwords.conf
|
|
content: |
|
|
# Managed by Ansible (Infrastructure repo) — key login only
|
|
PasswordAuthentication no
|
|
KbdInteractiveAuthentication no
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
validate: /usr/sbin/sshd -t -f %s
|
|
notify: Restart ssh
|
|
|
|
handlers:
|
|
- name: Restart ssh
|
|
ansible.builtin.systemd_service:
|
|
name: ssh
|
|
state: restarted
|
|
|
|
- name: Reboot
|
|
ansible.builtin.reboot:
|