No restore procedure existed anywhere in this repo. The backup pipeline is well commented but nothing described how to get data back, and the README the backup script already referenced was missing. Covers the shared backup engine and its stage ordering, a restore procedure for both MariaDB and Postgres with the rootless-podman command form, data-tree restore including the uid 33 chown, and the maintenance-mode/files:scan reconcile. Two things worth stating plainly: - Untested backups are not a control. No rehearsal has been recorded. - Do not blindly re-run libresign:configure:openssl on a restored instance -- it mints a new root CA and invalidates the trust chain on every document already signed under the old one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Deploy Home
There's no place like home!
Just as Dorothy managed the simple task of clicking her heels together, the desire for an equally simple one-button push deployment was in my heart. Thus, this repository was made.
Ansible
Ansible, along with double encrypted secrets, deploys the necessary configurations to make the home fit for certain needs and desires. Namely, having access to my home from anywhere, securely, and a self-hosted CI server that easily ties into existing workflows.
Makefile
The makefile is primarily used as a wrapper script to ensure that necessary
files, such as the secret vault password file, are provisioned as part of this.
One such addition to the task is utilizing dependency pinning through the
utilization of Python's virtualenv to lock down the specific dependency
versions within the requirements.txt file. This, ideally, prevents any
deployment issues with dependency version woes (e.g. version conflicts, major
updates in newest versions, etc.)
| Target Name | Description |
|---|---|
lint |
(default) Runs yamllint and ansible-lint on all YAML files in ansible/ |
deploy |
Deploys everything, or only tasks specified in TAGS= environment variable |
check |
Runs deploy in a "dry-run", showing diff-style outputs on tasks indicating changes |
vault |
Opens the Ansible vault file for editing |