diff --git a/ansible/roles/podman/tasks/container-awsddns.yml b/ansible/roles/podman/tasks/container-awsddns.yml index e87cf08..6d01267 100644 --- a/ansible/roles/podman/tasks/container-awsddns.yml +++ b/ansible/roles/podman/tasks/container-awsddns.yml @@ -5,7 +5,7 @@ diff: false containers.podman.podman_container: name: awsddns - image: docker.io/bdebyl/awsddns + image: docker.io/bdebyl/awsddns:1.0.10 recreate: false restart: true restart_policy: on-failure diff --git a/ansible/roles/podman/tasks/container-drone.yml b/ansible/roles/podman/tasks/container-drone.yml index f720d38..5aa306d 100644 --- a/ansible/roles/podman/tasks/container-drone.yml +++ b/ansible/roles/podman/tasks/container-drone.yml @@ -27,11 +27,10 @@ restart_policy: on-failure log_driver: journald env: - DRONE_LOGS_DEBUG: "true" - DRONE_RPC_DEBUG: "true" + DRONE_LOGS_DEBUG: "false" + DRONE_RPC_DEBUG: "false" DRONE_GITHUB_CLIENT_ID: "{{ drone_gh_client_id }}" DRONE_GITHUB_CLIENT_SECRET: "{{ drone_gh_client_sec }}" - DRONE_GIT_ALWAYS_AUTH: "true" DRONE_RPC_SECRET: "{{ drone_rpc_secret }}" DRONE_SERVER_HOST: "{{ ci_server_name }}" DRONE_SERVER_PROTO: "{{ drone_server_proto }}" diff --git a/ansible/roles/podman/tasks/container-graylog.yml b/ansible/roles/podman/tasks/container-graylog.yml index ce61dd1..78a44ba 100644 --- a/ansible/roles/podman/tasks/container-graylog.yml +++ b/ansible/roles/podman/tasks/container-graylog.yml @@ -96,8 +96,8 @@ become_user: "{{ podman_user }}" containers.podman.podman_container: name: graylog - image: docker.io/graylog/graylog:4.2 - recreate: false + image: docker.io/graylog/graylog:4.2.9 + recreate: true restart: true restart_policy: on-failure sysctl: diff --git a/ansible/roles/podman/tasks/container-partkeepr.yml b/ansible/roles/podman/tasks/container-partkeepr.yml index ac92349..11f9c02 100644 --- a/ansible/roles/podman/tasks/container-partkeepr.yml +++ b/ansible/roles/podman/tasks/container-partkeepr.yml @@ -4,7 +4,7 @@ ansible.builtin.file: path: "{{ item }}" state: directory - owner: "{{ podman_user }}" + owner: "{{ podman_subuid.stdout }}" group: "{{ podman_user }}" mode: 0755 notify: restorecon podman diff --git a/ansible/roles/podman/tasks/container-pihole.yml b/ansible/roles/podman/tasks/container-pihole.yml index e4f338d..27163f1 100644 --- a/ansible/roles/podman/tasks/container-pihole.yml +++ b/ansible/roles/podman/tasks/container-pihole.yml @@ -70,3 +70,12 @@ tags: - pihole - firewall + +- name: Save state of iptables for IPv4 + become: true + community.general.iptables_state: + state: saved + path: /etc/sysconfig/iptables + tags: + - pihole + - firewall diff --git a/ansible/roles/podman/templates/nginx/sites/home.bdebyl.net.conf.j2 b/ansible/roles/podman/templates/nginx/sites/home.bdebyl.net.conf.j2 index 513fee4..3c431a2 100644 --- a/ansible/roles/podman/templates/nginx/sites/home.bdebyl.net.conf.j2 +++ b/ansible/roles/podman/templates/nginx/sites/home.bdebyl.net.conf.j2 @@ -10,7 +10,7 @@ server { listen 80 default_server; server_name {{ home_server_name }}; if ($whitelisted = 1) { - return 302 http://{{ ansible_default_ipv4.address }}; + return 302 http://pi.bdebyl.net; } if ($whitelisted = 0) {