Infrastructure/ansible/playbooks/octoprint.yml

63 lines
2 KiB
YAML

# OS-level configuration of the OctoPrint Pi, on top of a stock OctoPi image.
# OctoPrint's own settings/plugins/profiles come from its Backup & Restore zip,
# not from here (OctoPrint rewrites its own config.yaml) — see docs/todo.md.
- name: Configure the OctoPrint Pi
hosts: octoprint
become: true
vars:
timezone: Europe/Vienna
tasks:
- name: Set the timezone
community.general.timezone:
name: "{{ timezone }}"
# ModemManager probes new serial devices for modems — a printer on /dev/ttyACM0
# is one, and the probing can disturb the connection. There's no modem here.
- name: Disable and mask ModemManager
ansible.builtin.systemd_service:
name: ModemManager
state: stopped
enabled: false
masked: true
- name: Disable the Bluetooth services
ansible.builtin.systemd_service:
name: "{{ item }}"
state: stopped
enabled: false
loop:
- bluetooth
- hciuart
- name: Turn off the Bluetooth hardware (applies after reboot)
ansible.builtin.lineinfile:
path: /boot/firmware/config.txt
regexp: '^dtoverlay=disable-bt$'
line: dtoverlay=disable-bt
insertafter: '^\[all\]$'
notify: Reboot
# Key login only. sshd uses the first value it reads, and files in
# sshd_config.d are read (alphabetically) before the main sshd_config.
- name: Disable SSH password login
ansible.builtin.copy:
dest: /etc/ssh/sshd_config.d/10-no-passwords.conf
content: |
# Managed by Ansible (Infrastructure repo) — key login only
PasswordAuthentication no
KbdInteractiveAuthentication no
owner: root
group: root
mode: "0644"
validate: /usr/sbin/sshd -t -f %s
notify: Restart ssh
handlers:
- name: Restart ssh
ansible.builtin.systemd_service:
name: ssh
state: restarted
- name: Reboot
ansible.builtin.reboot: