A Pi 3B+ (stickah.local) shares a Phomemo PM246 to the LAN as a plain CUPS queue, so any machine can print 4x6 labels -- fulfillr-site's shipping labels in particular -- without installing the vendor driver, which is x86-64 only. The role builds the TSPL CUPS driver from source instead. It is Debian, not Fedora, so it lives in its own inventory and playbook (make deploy-labelprint / check-labelprint) and the home.debyl.io roles can never run against it. make bootfs renders its cloud-init first-boot files onto a freshly imaged SD card from the same templates the role uses. The Wi-Fi credentials for the home and rescue networks are in the vault. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
93 lines
3.2 KiB
YAML
93 lines
3.2 KiB
YAML
---
|
|
- name: set the hostname
|
|
become: true
|
|
ansible.builtin.hostname:
|
|
name: "{{ labelprint_hostname }}"
|
|
tags: [labelprint, base]
|
|
|
|
# The hostname is also the mDNS name, and avahi publishes whatever is in
|
|
# /etc/hosts for 127.0.1.1. cloud-init writes this line on first boot from the
|
|
# image's own hostname, so it has to be corrected here too or the Pi answers to
|
|
# the wrong .local name.
|
|
- name: point 127.0.1.1 at the hostname
|
|
become: true
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/hosts
|
|
regexp: '^127\.0\.1\.1\s'
|
|
line: "127.0.1.1\t{{ labelprint_hostname }}"
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
tags: [labelprint, base]
|
|
|
|
- name: install the print proxy packages
|
|
become: true
|
|
ansible.builtin.apt:
|
|
name: "{{ labelprint_deps }}"
|
|
state: present
|
|
update_cache: true
|
|
cache_valid_time: 3600
|
|
tags: [labelprint, base]
|
|
|
|
- name: publish the host over mDNS
|
|
become: true
|
|
ansible.builtin.systemd:
|
|
name: avahi-daemon.service
|
|
enabled: true
|
|
state: started
|
|
tags: [labelprint, base]
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Unattended security updates
|
|
# ---------------------------------------------------------------------------
|
|
# This box sits on the LAN with an open IPP port and is not something anyone
|
|
# logs into for months at a time, so it patches itself.
|
|
- name: enable unattended upgrades
|
|
become: true
|
|
ansible.builtin.copy:
|
|
dest: /etc/apt/apt.conf.d/20auto-upgrades
|
|
content: |
|
|
APT::Periodic::Update-Package-Lists "1";
|
|
APT::Periodic::Unattended-Upgrade "1";
|
|
APT::Periodic::AutocleanInterval "7";
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
tags: [labelprint, base, updates]
|
|
|
|
# Debian's stock 50unattended-upgrades allowlists the Debian security origin
|
|
# only. Raspberry Pi OS serves its own kernel, firmware and userland from the
|
|
# Raspberry Pi archives, so without these two extra origins the packages most
|
|
# specific to this hardware are exactly the ones that never get patched.
|
|
- name: allow the Raspberry Pi origins and reboot for kernel updates
|
|
become: true
|
|
ansible.builtin.copy:
|
|
dest: /etc/apt/apt.conf.d/52unattended-upgrades-labelprint
|
|
content: |
|
|
Unattended-Upgrade::Origins-Pattern {
|
|
"origin=Raspbian,codename=${distro_codename},label=Raspbian";
|
|
"origin=Raspberry Pi Foundation,codename=${distro_codename},label=Raspberry Pi Foundation";
|
|
};
|
|
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
|
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
|
// Nothing here holds state across a reboot -- a queued job is spooled on
|
|
// disk and resumes -- so take the kernel update at 04:00 rather than
|
|
// leaving the Pi running an unpatched kernel until someone notices.
|
|
Unattended-Upgrade::Automatic-Reboot "true";
|
|
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
tags: [labelprint, base, updates]
|
|
|
|
- name: enable the unattended-upgrades timers
|
|
become: true
|
|
ansible.builtin.systemd:
|
|
name: "{{ item }}"
|
|
enabled: true
|
|
state: started
|
|
loop:
|
|
- apt-daily.timer
|
|
- apt-daily-upgrade.timer
|
|
tags: [labelprint, base, updates]
|