--- - name: set the hostname become: true ansible.builtin.hostname: name: "{{ labelprint_hostname }}" tags: [labelprint, base] # The hostname is also the mDNS name, and avahi publishes whatever is in # /etc/hosts for 127.0.1.1. cloud-init writes this line on first boot from the # image's own hostname, so it has to be corrected here too or the Pi answers to # the wrong .local name. - name: point 127.0.1.1 at the hostname become: true ansible.builtin.lineinfile: path: /etc/hosts regexp: '^127\.0\.1\.1\s' line: "127.0.1.1\t{{ labelprint_hostname }}" owner: root group: root mode: "0644" tags: [labelprint, base] - name: install the print proxy packages become: true ansible.builtin.apt: name: "{{ labelprint_deps }}" state: present update_cache: true cache_valid_time: 3600 tags: [labelprint, base] - name: publish the host over mDNS become: true ansible.builtin.systemd: name: avahi-daemon.service enabled: true state: started tags: [labelprint, base] # --------------------------------------------------------------------------- # Unattended security updates # --------------------------------------------------------------------------- # This box sits on the LAN with an open IPP port and is not something anyone # logs into for months at a time, so it patches itself. - name: enable unattended upgrades become: true ansible.builtin.copy: dest: /etc/apt/apt.conf.d/20auto-upgrades content: | APT::Periodic::Update-Package-Lists "1"; APT::Periodic::Unattended-Upgrade "1"; APT::Periodic::AutocleanInterval "7"; owner: root group: root mode: "0644" tags: [labelprint, base, updates] # Debian's stock 50unattended-upgrades allowlists the Debian security origin # only. Raspberry Pi OS serves its own kernel, firmware and userland from the # Raspberry Pi archives, so without these two extra origins the packages most # specific to this hardware are exactly the ones that never get patched. - name: allow the Raspberry Pi origins and reboot for kernel updates become: true ansible.builtin.copy: dest: /etc/apt/apt.conf.d/52unattended-upgrades-labelprint content: | Unattended-Upgrade::Origins-Pattern { "origin=Raspbian,codename=${distro_codename},label=Raspbian"; "origin=Raspberry Pi Foundation,codename=${distro_codename},label=Raspberry Pi Foundation"; }; Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; Unattended-Upgrade::Remove-Unused-Dependencies "true"; // Nothing here holds state across a reboot -- a queued job is spooled on // disk and resumes -- so take the kernel update at 04:00 rather than // leaving the Pi running an unpatched kernel until someone notices. Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot-Time "04:00"; owner: root group: root mode: "0644" tags: [labelprint, base, updates] - name: enable the unattended-upgrades timers become: true ansible.builtin.systemd: name: "{{ item }}" enabled: true state: started loop: - apt-daily.timer - apt-daily-upgrade.timer tags: [labelprint, base, updates]