Files
deploy_home/ansible/roles/labelprint/defaults/main.yml
T
Bastian de BylandClaude Opus 5 6cd4d56de1 feat(labelprint): 4x6 label print proxy on a Raspberry Pi
A Pi 3B+ (stickah.local) shares a Phomemo PM246 to the LAN as a plain CUPS
queue, so any machine can print 4x6 labels -- fulfillr-site's shipping labels
in particular -- without installing the vendor driver, which is x86-64 only.
The role builds the TSPL CUPS driver from source instead.

It is Debian, not Fedora, so it lives in its own inventory and playbook
(make deploy-labelprint / check-labelprint) and the home.debyl.io roles can
never run against it. make bootfs renders its cloud-init first-boot files onto
a freshly imaged SD card from the same templates the role uses. The Wi-Fi
credentials for the home and rescue networks are in the vault.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 23:14:45 -04:00

119 lines
5.3 KiB
YAML

---
# ---------------------------------------------------------------------------
# Identity
# ---------------------------------------------------------------------------
# Reached as stickah.local. There is no DNS record for it: the UDM Pro passes
# mDNS across the LAN, so avahi on the Pi is the whole of the name service.
labelprint_hostname: stickah
# The login the image creates and Ansible connects as. Password auth stays on
# with a trivial, documented password: this box has to be reachable when the SSH
# key is not an option -- a reflashed card, a different laptop, someone standing
# at the workshop bench -- and it is only reachable from the LAN or from its own
# rescue AP in the first place. The key is what Ansible actually uses.
labelprint_user: stickah
labelprint_user_password: stickah
labelprint_authorized_key_file: ~/.ssh/id_ed25519.pub
# ---------------------------------------------------------------------------
# Printer
# ---------------------------------------------------------------------------
# Phomemo PM246, 4x6 direct thermal, 203 dpi, speaks TSPL over USB.
labelprint_queue: labels
labelprint_queue_info: 4x6 Label Printer (Phomemo PM246)
labelprint_queue_location: stickah
# The tspl backend finds the printer's usblp node by USB id. "auto" matches only
# the ids the driver already knows, and the PM246 is not yet one of them -- so if
# a deploy leaves the queue unable to find the printer, read the id off the Pi:
#
# for n in /dev/usb/lp*; do udevadm info -q property -n "$n" | grep -E 'ID_(VENDOR|MODEL)_ID|ID_SERIAL_SHORT'; done
#
# and pin it here as tspl://<vid>-<pid> (a DASH, not a colon: CUPS parses ":pid"
# as a port number and rejects the URI), or as tspl:///dev/usb/lp0.
labelprint_device_uri: "tspl://auto"
# 203dpi matches the PM246 head. The PPD defaults to 300dpi, which would render
# every label at ~2/3 scale on this printer.
labelprint_resolution: 203dpi
labelprint_media: na_index-4x6_4x6in
# Cut every other media size out of the PPD, so 4x6 is the only paper a client
# can pick. Driverless clients build their own PPD from the IPP media-supported
# list cupsd derives from ours, and there is no lpadmin option that restricts
# that list -- trimming the PPD is the only lever.
#
# The trade is real: the driver's PPD also offers 100x150mm, 4x4, 2.25x1.5, 2x1
# and a custom range, and this takes all of them away. Set false if you ever
# want this queue to run stock other than 4x6; a second queue off the untrimmed
# PPD is the better answer if you want both.
labelprint_media_only_4x6: true
# The PPD page-size keyword kept when the above is on. Pairs with
# labelprint_media, which is the same size under its IPP name.
labelprint_ppd_pagesize: w288h432
# 0-15. 8 is the driver's default and a sane starting point for the cheap
# thermal stock; raise it if barcodes scan poorly, lower it if edges bleed.
labelprint_darkness: 8
# in/sec x10. 40 = 4 in/sec.
labelprint_print_speed: 40
# ---------------------------------------------------------------------------
# Driver: RunTheWall/tspl-cups-driver (MIT)
# ---------------------------------------------------------------------------
# Built from source at a pinned commit rather than installed from the project's
# apt repo: this keeps a third-party signing key and package feed off the Pi,
# and makes the version we run a reviewed, deliberate bump in git history.
#
# The vendor Phomemo driver is not an option here -- its rastertolabeltspl
# filter ships as an x86-64 ELF only, and this host is aarch64.
labelprint_driver_repo: https://github.com/RunTheWall/tspl-cups-driver.git
labelprint_driver_version: f433b7774d80a4f6a901b6b998cb710fd79918a4
labelprint_driver_src: /usr/local/src/tspl-cups-driver
labelprint_ppd_dir: /usr/share/ppd/tspl
# The PPD the queue is actually built from.
labelprint_ppd_active: >-
{{ labelprint_ppd_dir }}/{{
'tspl-label-4x6.ppd' if labelprint_media_only_4x6 else 'tspl-label.ppd'
}}
# ---------------------------------------------------------------------------
# Network
# ---------------------------------------------------------------------------
# The only subnet allowed to reach CUPS. Everything else is dropped at nftables
# and refused again by cupsd's own access rules.
labelprint_lan_cidr: 192.168.1.0/24
# Rescue access point, brought up when the home SSID is unreachable. The Pi 3B+
# has a single radio and cannot hold an AP and a station link at once, so this
# is strictly a fallback -- see templates/wifi-rescue.sh.j2.
labelprint_ap_addr: 192.168.4.1
labelprint_ap_cidr: 192.168.4.0/24
# How often the watchdog checks, and how long the AP stays up before it drops
# for a few seconds to scan for the home SSID again.
labelprint_watchdog_interval_secs: 60
labelprint_ap_rescan_secs: 300
# How long a hand-placed /run/wifi-rescue.hold pins the radio before the
# watchdog ignores it. Bounded so a forgotten hold file cannot strand the Pi.
labelprint_hold_max_age_secs: 1800
# ---------------------------------------------------------------------------
# Packages
# ---------------------------------------------------------------------------
labelprint_deps:
[
avahi-daemon,
build-essential,
cups,
cups-filters,
dnsmasq-base,
git,
libcups2-dev,
network-manager,
nftables,
unattended-upgrades,
]
# Secrets live in ansible/vars/vault.yml (no vault_ prefix, per repo
# convention): stickah_ssid, stickah_psk,
# stickah_ssid_rescue, stickah_psk_rescue