cachy-workstation

Log | Files | Refs | README

commit 0bf75c93d7374db9fc375c7c5414b9d46d5409c4
parent b72685b3847e228ac5463ca1b1880cc423123694
Author: Chris Roberts <chris.roberts@learningunix.net>
Date:   Mon, 22 Jun 2026 12:38:03 -0500

added readme html

Diffstat:
AREADME.html | 365+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 365 insertions(+), 0 deletions(-)

diff --git a/README.html b/README.html @@ -0,0 +1,365 @@ +<!DOCTYPE html> +<html xmlns="http://www.w3.org/1999/xhtml" lang="" xml:lang=""> +<head> + <meta charset="utf-8" /> + <meta name="generator" content="pandoc" /> + <meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=yes" /> + <title>README</title> + <style> + html { + color: #1a1a1a; + background-color: #fdfdfd; + } + body { + margin: 0 auto; + max-width: 36em; + padding-left: 50px; + padding-right: 50px; + padding-top: 50px; + padding-bottom: 50px; + hyphens: auto; + overflow-wrap: break-word; + text-rendering: optimizeLegibility; + font-kerning: normal; + } + @media (max-width: 600px) { + body { + font-size: 0.9em; + padding: 12px; + } + h1 { + font-size: 1.8em; + } + } + @media print { + html { + background-color: white; + } + body { + background-color: transparent; + color: black; + font-size: 12pt; + } + p, h2, h3 { + orphans: 3; + widows: 3; + } + h2, h3, h4 { + page-break-after: avoid; + } + } + p { + margin: 1em 0; + } + a { + color: #1a1a1a; + } + a:visited { + color: #1a1a1a; + } + img { + max-width: 100%; + } + svg { + height: auto; + max-width: 100%; + } + h1, h2, h3, h4, h5, h6 { + margin-top: 1.4em; + } + h5, h6 { + font-size: 1em; + font-style: italic; + } + h6 { + font-weight: normal; + } + ol, ul { + padding-left: 1.7em; + margin-top: 1em; + } + li > ol, li > ul { + margin-top: 0; + } + blockquote { + margin: 1em 0 1em 1.7em; + padding-left: 1em; + border-left: 2px solid #e6e6e6; + color: #606060; + } + code { + font-family: Menlo, Monaco, Consolas, 'Lucida Console', monospace; + font-size: 85%; + margin: 0; + hyphens: manual; + } + pre { + margin: 1em 0; + overflow: auto; + } + pre code { + padding: 0; + overflow: visible; + overflow-wrap: normal; + } + .sourceCode { + background-color: transparent; + overflow: visible; + } + hr { + background-color: #1a1a1a; + border: none; + height: 1px; + margin: 1em 0; + } + table { + margin: 1em 0; + border-collapse: collapse; + width: 100%; + overflow-x: auto; + display: block; + font-variant-numeric: lining-nums tabular-nums; + } + table caption { + margin-bottom: 0.75em; + } + tbody { + margin-top: 0.5em; + border-top: 1px solid #1a1a1a; + border-bottom: 1px solid #1a1a1a; + } + th { + border-top: 1px solid #1a1a1a; + padding: 0.25em 0.5em 0.25em 0.5em; + } + td { + padding: 0.125em 0.5em 0.25em 0.5em; + } + header { + margin-bottom: 4em; + text-align: center; + } + #TOC li { + list-style: none; + } + #TOC ul { + padding-left: 1.3em; + } + #TOC > ul { + padding-left: 0; + } + #TOC a:not(:hover) { + text-decoration: none; + } + code{white-space: pre-wrap;} + span.smallcaps{font-variant: small-caps;} + div.columns{display: flex; gap: min(4vw, 1.5em);} + div.column{flex: auto; overflow-x: auto;} + div.hanging-indent{margin-left: 1.5em; text-indent: -1.5em;} + /* The extra [class] is a hack that increases specificity enough to + override a similar rule in reveal.js */ + ul.task-list[class]{list-style: none;} + ul.task-list li input[type="checkbox"] { + font-size: inherit; + width: 0.8em; + margin: 0 0.8em 0.2em -1.6em; + vertical-align: middle; + } + .display.math{display: block; text-align: center; margin: 0.5rem auto;} + /* CSS for syntax highlighting */ + html { -webkit-text-size-adjust: 100%; } + pre > code.sourceCode { white-space: pre; position: relative; } + pre > code.sourceCode > span { display: inline-block; line-height: 1.25; } + pre > code.sourceCode > span:empty { height: 1.2em; } + .sourceCode { overflow: visible; } + code.sourceCode > span { color: inherit; text-decoration: inherit; } + div.sourceCode { margin: 1em 0; } + pre.sourceCode { margin: 0; } + @media screen { + div.sourceCode { overflow: auto; } + } + @media print { + pre > code.sourceCode { white-space: pre-wrap; } + pre > code.sourceCode > span { text-indent: -5em; padding-left: 5em; } + } + pre.numberSource code + { counter-reset: source-line 0; } + pre.numberSource code > span + { position: relative; left: -4em; counter-increment: source-line; } + pre.numberSource code > span > a:first-child::before + { content: counter(source-line); + position: relative; left: -1em; text-align: right; vertical-align: baseline; + border: none; display: inline-block; + -webkit-touch-callout: none; -webkit-user-select: none; + -khtml-user-select: none; -moz-user-select: none; + -ms-user-select: none; user-select: none; + padding: 0 4px; width: 4em; + color: #aaaaaa; + } + pre.numberSource { margin-left: 3em; border-left: 1px solid #aaaaaa; padding-left: 4px; } + div.sourceCode + { } + @media screen { + pre > code.sourceCode > span > a:first-child::before { text-decoration: underline; } + } + code span.al { color: #ff0000; font-weight: bold; } /* Alert */ + code span.an { color: #60a0b0; font-weight: bold; font-style: italic; } /* Annotation */ + code span.at { color: #7d9029; } /* Attribute */ + code span.bn { color: #40a070; } /* BaseN */ + code span.bu { color: #008000; } /* BuiltIn */ + code span.cf { color: #007020; font-weight: bold; } /* ControlFlow */ + code span.ch { color: #4070a0; } /* Char */ + code span.cn { color: #880000; } /* Constant */ + code span.co { color: #60a0b0; font-style: italic; } /* Comment */ + code span.cv { color: #60a0b0; font-weight: bold; font-style: italic; } /* CommentVar */ + code span.do { color: #ba2121; font-style: italic; } /* Documentation */ + code span.dt { color: #902000; } /* DataType */ + code span.dv { color: #40a070; } /* DecVal */ + code span.er { color: #ff0000; font-weight: bold; } /* Error */ + code span.ex { } /* Extension */ + code span.fl { color: #40a070; } /* Float */ + code span.fu { color: #06287e; } /* Function */ + code span.im { color: #008000; font-weight: bold; } /* Import */ + code span.in { color: #60a0b0; font-weight: bold; font-style: italic; } /* Information */ + code span.kw { color: #007020; font-weight: bold; } /* Keyword */ + code span.op { color: #666666; } /* Operator */ + code span.ot { color: #007020; } /* Other */ + code span.pp { color: #bc7a00; } /* Preprocessor */ + code span.sc { color: #4070a0; } /* SpecialChar */ + code span.ss { color: #bb6688; } /* SpecialString */ + code span.st { color: #4070a0; } /* String */ + code span.va { color: #19177c; } /* Variable */ + code span.vs { color: #4070a0; } /* VerbatimString */ + code span.wa { color: #60a0b0; font-weight: bold; font-style: italic; } /* Warning */ + </style> +</head> +<body> +<h1 id="cachy-workstation">Cachy-workstation</h1> +<p>Infrastructure-as-Code for a CachyOS Linux workstation, managed with +Ansible.</p> +<h2 id="goals">Goals</h2> +<ul> +<li>Describe and reproduce the workstation configuration +declaratively</li> +<li>Learn Ansible patterns: site-based playbooks, roles, and tags</li> +</ul> +<h2 id="design">Design</h2> +<ul> +<li><strong>Tool:</strong> Ansible</li> +<li><strong>Target:</strong> <code>localhost</code> only</li> +<li><strong>Entry point:</strong> <code>site.yml</code></li> +<li><strong>Structure:</strong> Roles with tags for selective +execution</li> +</ul> +<h2 id="new-machine-bootstrap">New Machine Bootstrap</h2> +<p>On a fresh machine, run <code>bootstrap.yml</code> first. It handles +the prerequisites that <code>site.yml</code> depends on:</p> +<ol type="1"> +<li>Installs and authenticates Tailscale</li> +<li>Imports GPG keys from the local git server</li> +<li>Clones the pass password store</li> +</ol> +<p>Prerequisites before running bootstrap:</p> +<div class="sourceCode" id="cb1"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb1-1"><a href="#cb1-1" aria-hidden="true" tabindex="-1"></a><span class="fu">sudo</span> pacman <span class="at">-S</span> ansible git</span></code></pre></div> +<p>Run bootstrap:</p> +<div class="sourceCode" id="cb2"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb2-1"><a href="#cb2-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml bootstrap.yml</span></code></pre></div> +<p>Then run the full site playbook:</p> +<div class="sourceCode" id="cb3"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb3-1"><a href="#cb3-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml</span></code></pre></div> +<h2 id="usage">Usage</h2> +<p>Run the full site playbook:</p> +<div class="sourceCode" id="cb4"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb4-1"><a href="#cb4-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml</span></code></pre></div> +<p>Run only tasks matching a specific tag:</p> +<div class="sourceCode" id="cb5"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb5-1"><a href="#cb5-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml <span class="at">--tags</span> <span class="op">&lt;</span>tagname<span class="op">&gt;</span></span></code></pre></div> +<p>Skip tasks matching a tag:</p> +<div class="sourceCode" id="cb6"><pre +class="sourceCode bash"><code class="sourceCode bash"><span id="cb6-1"><a href="#cb6-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml <span class="at">--skip-tags</span> <span class="op">&lt;</span>tagname<span class="op">&gt;</span></span></code></pre></div> +<h2 id="roles">Roles</h2> +<table> +<colgroup> +<col style="width: 24%" /> +<col style="width: 24%" /> +<col style="width: 52%" /> +</colgroup> +<thead> +<tr> +<th>Role</th> +<th>Play</th> +<th>Description</th> +</tr> +</thead> +<tbody> +<tr> +<td>firewall</td> +<td>system</td> +<td>ufw, default deny incoming, allow port 22</td> +</tr> +<tr> +<td>packages</td> +<td>system</td> +<td>General packages via pacman</td> +</tr> +<tr> +<td>docker</td> +<td>system</td> +<td>Docker, enables service, adds user to docker group</td> +</tr> +<tr> +<td>virtualization</td> +<td>system</td> +<td>qemu-full, virt-manager, libvirtd</td> +</tr> +<tr> +<td>web</td> +<td>system</td> +<td>hcloud, hugo, tea</td> +</tr> +<tr> +<td>flatpak</td> +<td>system</td> +<td>Flatpak and apps, MakeMKV device permissions</td> +</tr> +<tr> +<td>gpg</td> +<td>user</td> +<td>Import GPG keys from private git repo</td> +</tr> +<tr> +<td>ssh</td> +<td>user</td> +<td>Deploy SSH keys and config from pass</td> +</tr> +<tr> +<td>pass</td> +<td>user</td> +<td>Clone pass password store</td> +</tr> +<tr> +<td>dotfiles</td> +<td>user</td> +<td>Clone dotfiles and nvim repos, symlink configs</td> +</tr> +<tr> +<td>scripts</td> +<td>user</td> +<td>Clone scripts repo, add to PATH, deploy Pushover credentials</td> +</tr> +<tr> +<td>hotkeys</td> +<td>user</td> +<td>Deploy .desktop files, set Plasma 6 global shortcuts</td> +</tr> +</tbody> +</table> +<h2 id="structure">Structure</h2> +<pre><code>. +├── bootstrap.yml # New machine bootstrap +├── site.yml # Main entry point +├── inventory/ # Inventory files +└── roles/ # Ansible roles</code></pre> +</body> +</html>