commit 0bf75c93d7374db9fc375c7c5414b9d46d5409c4
parent b72685b3847e228ac5463ca1b1880cc423123694
Author: Chris Roberts <chris.roberts@learningunix.net>
Date: Mon, 22 Jun 2026 12:38:03 -0500
added readme html
Diffstat:
| A | README.html | | | 365 | +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ |
1 file changed, 365 insertions(+), 0 deletions(-)
diff --git a/README.html b/README.html
@@ -0,0 +1,365 @@
+<!DOCTYPE html>
+<html xmlns="http://www.w3.org/1999/xhtml" lang="" xml:lang="">
+<head>
+ <meta charset="utf-8" />
+ <meta name="generator" content="pandoc" />
+ <meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=yes" />
+ <title>README</title>
+ <style>
+ html {
+ color: #1a1a1a;
+ background-color: #fdfdfd;
+ }
+ body {
+ margin: 0 auto;
+ max-width: 36em;
+ padding-left: 50px;
+ padding-right: 50px;
+ padding-top: 50px;
+ padding-bottom: 50px;
+ hyphens: auto;
+ overflow-wrap: break-word;
+ text-rendering: optimizeLegibility;
+ font-kerning: normal;
+ }
+ @media (max-width: 600px) {
+ body {
+ font-size: 0.9em;
+ padding: 12px;
+ }
+ h1 {
+ font-size: 1.8em;
+ }
+ }
+ @media print {
+ html {
+ background-color: white;
+ }
+ body {
+ background-color: transparent;
+ color: black;
+ font-size: 12pt;
+ }
+ p, h2, h3 {
+ orphans: 3;
+ widows: 3;
+ }
+ h2, h3, h4 {
+ page-break-after: avoid;
+ }
+ }
+ p {
+ margin: 1em 0;
+ }
+ a {
+ color: #1a1a1a;
+ }
+ a:visited {
+ color: #1a1a1a;
+ }
+ img {
+ max-width: 100%;
+ }
+ svg {
+ height: auto;
+ max-width: 100%;
+ }
+ h1, h2, h3, h4, h5, h6 {
+ margin-top: 1.4em;
+ }
+ h5, h6 {
+ font-size: 1em;
+ font-style: italic;
+ }
+ h6 {
+ font-weight: normal;
+ }
+ ol, ul {
+ padding-left: 1.7em;
+ margin-top: 1em;
+ }
+ li > ol, li > ul {
+ margin-top: 0;
+ }
+ blockquote {
+ margin: 1em 0 1em 1.7em;
+ padding-left: 1em;
+ border-left: 2px solid #e6e6e6;
+ color: #606060;
+ }
+ code {
+ font-family: Menlo, Monaco, Consolas, 'Lucida Console', monospace;
+ font-size: 85%;
+ margin: 0;
+ hyphens: manual;
+ }
+ pre {
+ margin: 1em 0;
+ overflow: auto;
+ }
+ pre code {
+ padding: 0;
+ overflow: visible;
+ overflow-wrap: normal;
+ }
+ .sourceCode {
+ background-color: transparent;
+ overflow: visible;
+ }
+ hr {
+ background-color: #1a1a1a;
+ border: none;
+ height: 1px;
+ margin: 1em 0;
+ }
+ table {
+ margin: 1em 0;
+ border-collapse: collapse;
+ width: 100%;
+ overflow-x: auto;
+ display: block;
+ font-variant-numeric: lining-nums tabular-nums;
+ }
+ table caption {
+ margin-bottom: 0.75em;
+ }
+ tbody {
+ margin-top: 0.5em;
+ border-top: 1px solid #1a1a1a;
+ border-bottom: 1px solid #1a1a1a;
+ }
+ th {
+ border-top: 1px solid #1a1a1a;
+ padding: 0.25em 0.5em 0.25em 0.5em;
+ }
+ td {
+ padding: 0.125em 0.5em 0.25em 0.5em;
+ }
+ header {
+ margin-bottom: 4em;
+ text-align: center;
+ }
+ #TOC li {
+ list-style: none;
+ }
+ #TOC ul {
+ padding-left: 1.3em;
+ }
+ #TOC > ul {
+ padding-left: 0;
+ }
+ #TOC a:not(:hover) {
+ text-decoration: none;
+ }
+ code{white-space: pre-wrap;}
+ span.smallcaps{font-variant: small-caps;}
+ div.columns{display: flex; gap: min(4vw, 1.5em);}
+ div.column{flex: auto; overflow-x: auto;}
+ div.hanging-indent{margin-left: 1.5em; text-indent: -1.5em;}
+ /* The extra [class] is a hack that increases specificity enough to
+ override a similar rule in reveal.js */
+ ul.task-list[class]{list-style: none;}
+ ul.task-list li input[type="checkbox"] {
+ font-size: inherit;
+ width: 0.8em;
+ margin: 0 0.8em 0.2em -1.6em;
+ vertical-align: middle;
+ }
+ .display.math{display: block; text-align: center; margin: 0.5rem auto;}
+ /* CSS for syntax highlighting */
+ html { -webkit-text-size-adjust: 100%; }
+ pre > code.sourceCode { white-space: pre; position: relative; }
+ pre > code.sourceCode > span { display: inline-block; line-height: 1.25; }
+ pre > code.sourceCode > span:empty { height: 1.2em; }
+ .sourceCode { overflow: visible; }
+ code.sourceCode > span { color: inherit; text-decoration: inherit; }
+ div.sourceCode { margin: 1em 0; }
+ pre.sourceCode { margin: 0; }
+ @media screen {
+ div.sourceCode { overflow: auto; }
+ }
+ @media print {
+ pre > code.sourceCode { white-space: pre-wrap; }
+ pre > code.sourceCode > span { text-indent: -5em; padding-left: 5em; }
+ }
+ pre.numberSource code
+ { counter-reset: source-line 0; }
+ pre.numberSource code > span
+ { position: relative; left: -4em; counter-increment: source-line; }
+ pre.numberSource code > span > a:first-child::before
+ { content: counter(source-line);
+ position: relative; left: -1em; text-align: right; vertical-align: baseline;
+ border: none; display: inline-block;
+ -webkit-touch-callout: none; -webkit-user-select: none;
+ -khtml-user-select: none; -moz-user-select: none;
+ -ms-user-select: none; user-select: none;
+ padding: 0 4px; width: 4em;
+ color: #aaaaaa;
+ }
+ pre.numberSource { margin-left: 3em; border-left: 1px solid #aaaaaa; padding-left: 4px; }
+ div.sourceCode
+ { }
+ @media screen {
+ pre > code.sourceCode > span > a:first-child::before { text-decoration: underline; }
+ }
+ code span.al { color: #ff0000; font-weight: bold; } /* Alert */
+ code span.an { color: #60a0b0; font-weight: bold; font-style: italic; } /* Annotation */
+ code span.at { color: #7d9029; } /* Attribute */
+ code span.bn { color: #40a070; } /* BaseN */
+ code span.bu { color: #008000; } /* BuiltIn */
+ code span.cf { color: #007020; font-weight: bold; } /* ControlFlow */
+ code span.ch { color: #4070a0; } /* Char */
+ code span.cn { color: #880000; } /* Constant */
+ code span.co { color: #60a0b0; font-style: italic; } /* Comment */
+ code span.cv { color: #60a0b0; font-weight: bold; font-style: italic; } /* CommentVar */
+ code span.do { color: #ba2121; font-style: italic; } /* Documentation */
+ code span.dt { color: #902000; } /* DataType */
+ code span.dv { color: #40a070; } /* DecVal */
+ code span.er { color: #ff0000; font-weight: bold; } /* Error */
+ code span.ex { } /* Extension */
+ code span.fl { color: #40a070; } /* Float */
+ code span.fu { color: #06287e; } /* Function */
+ code span.im { color: #008000; font-weight: bold; } /* Import */
+ code span.in { color: #60a0b0; font-weight: bold; font-style: italic; } /* Information */
+ code span.kw { color: #007020; font-weight: bold; } /* Keyword */
+ code span.op { color: #666666; } /* Operator */
+ code span.ot { color: #007020; } /* Other */
+ code span.pp { color: #bc7a00; } /* Preprocessor */
+ code span.sc { color: #4070a0; } /* SpecialChar */
+ code span.ss { color: #bb6688; } /* SpecialString */
+ code span.st { color: #4070a0; } /* String */
+ code span.va { color: #19177c; } /* Variable */
+ code span.vs { color: #4070a0; } /* VerbatimString */
+ code span.wa { color: #60a0b0; font-weight: bold; font-style: italic; } /* Warning */
+ </style>
+</head>
+<body>
+<h1 id="cachy-workstation">Cachy-workstation</h1>
+<p>Infrastructure-as-Code for a CachyOS Linux workstation, managed with
+Ansible.</p>
+<h2 id="goals">Goals</h2>
+<ul>
+<li>Describe and reproduce the workstation configuration
+declaratively</li>
+<li>Learn Ansible patterns: site-based playbooks, roles, and tags</li>
+</ul>
+<h2 id="design">Design</h2>
+<ul>
+<li><strong>Tool:</strong> Ansible</li>
+<li><strong>Target:</strong> <code>localhost</code> only</li>
+<li><strong>Entry point:</strong> <code>site.yml</code></li>
+<li><strong>Structure:</strong> Roles with tags for selective
+execution</li>
+</ul>
+<h2 id="new-machine-bootstrap">New Machine Bootstrap</h2>
+<p>On a fresh machine, run <code>bootstrap.yml</code> first. It handles
+the prerequisites that <code>site.yml</code> depends on:</p>
+<ol type="1">
+<li>Installs and authenticates Tailscale</li>
+<li>Imports GPG keys from the local git server</li>
+<li>Clones the pass password store</li>
+</ol>
+<p>Prerequisites before running bootstrap:</p>
+<div class="sourceCode" id="cb1"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb1-1"><a href="#cb1-1" aria-hidden="true" tabindex="-1"></a><span class="fu">sudo</span> pacman <span class="at">-S</span> ansible git</span></code></pre></div>
+<p>Run bootstrap:</p>
+<div class="sourceCode" id="cb2"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb2-1"><a href="#cb2-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml bootstrap.yml</span></code></pre></div>
+<p>Then run the full site playbook:</p>
+<div class="sourceCode" id="cb3"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb3-1"><a href="#cb3-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml</span></code></pre></div>
+<h2 id="usage">Usage</h2>
+<p>Run the full site playbook:</p>
+<div class="sourceCode" id="cb4"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb4-1"><a href="#cb4-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml</span></code></pre></div>
+<p>Run only tasks matching a specific tag:</p>
+<div class="sourceCode" id="cb5"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb5-1"><a href="#cb5-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml <span class="at">--tags</span> <span class="op"><</span>tagname<span class="op">></span></span></code></pre></div>
+<p>Skip tasks matching a tag:</p>
+<div class="sourceCode" id="cb6"><pre
+class="sourceCode bash"><code class="sourceCode bash"><span id="cb6-1"><a href="#cb6-1" aria-hidden="true" tabindex="-1"></a><span class="ex">ansible-playbook</span> <span class="at">-K</span> <span class="at">-i</span> inventory/hosts.yml site.yml <span class="at">--skip-tags</span> <span class="op"><</span>tagname<span class="op">></span></span></code></pre></div>
+<h2 id="roles">Roles</h2>
+<table>
+<colgroup>
+<col style="width: 24%" />
+<col style="width: 24%" />
+<col style="width: 52%" />
+</colgroup>
+<thead>
+<tr>
+<th>Role</th>
+<th>Play</th>
+<th>Description</th>
+</tr>
+</thead>
+<tbody>
+<tr>
+<td>firewall</td>
+<td>system</td>
+<td>ufw, default deny incoming, allow port 22</td>
+</tr>
+<tr>
+<td>packages</td>
+<td>system</td>
+<td>General packages via pacman</td>
+</tr>
+<tr>
+<td>docker</td>
+<td>system</td>
+<td>Docker, enables service, adds user to docker group</td>
+</tr>
+<tr>
+<td>virtualization</td>
+<td>system</td>
+<td>qemu-full, virt-manager, libvirtd</td>
+</tr>
+<tr>
+<td>web</td>
+<td>system</td>
+<td>hcloud, hugo, tea</td>
+</tr>
+<tr>
+<td>flatpak</td>
+<td>system</td>
+<td>Flatpak and apps, MakeMKV device permissions</td>
+</tr>
+<tr>
+<td>gpg</td>
+<td>user</td>
+<td>Import GPG keys from private git repo</td>
+</tr>
+<tr>
+<td>ssh</td>
+<td>user</td>
+<td>Deploy SSH keys and config from pass</td>
+</tr>
+<tr>
+<td>pass</td>
+<td>user</td>
+<td>Clone pass password store</td>
+</tr>
+<tr>
+<td>dotfiles</td>
+<td>user</td>
+<td>Clone dotfiles and nvim repos, symlink configs</td>
+</tr>
+<tr>
+<td>scripts</td>
+<td>user</td>
+<td>Clone scripts repo, add to PATH, deploy Pushover credentials</td>
+</tr>
+<tr>
+<td>hotkeys</td>
+<td>user</td>
+<td>Deploy .desktop files, set Plasma 6 global shortcuts</td>
+</tr>
+</tbody>
+</table>
+<h2 id="structure">Structure</h2>
+<pre><code>.
+├── bootstrap.yml # New machine bootstrap
+├── site.yml # Main entry point
+├── inventory/ # Inventory files
+└── roles/ # Ansible roles</code></pre>
+</body>
+</html>