Merge branch 'new-infra' of gitea.auro.re:aurore/ansible into new-infra
This commit is contained in:
commit
13f22bc7b8
4 changed files with 50 additions and 0 deletions
|
@ -5,4 +5,5 @@
|
|||
- vm_network
|
||||
roles:
|
||||
- base_utils
|
||||
- unattended_upgrades
|
||||
...
|
||||
|
|
16
roles/unattended_upgrades/tasks/main.yml
Normal file
16
roles/unattended_upgrades/tasks/main.yml
Normal file
|
@ -0,0 +1,16 @@
|
|||
---
|
||||
- name: Install unattended-upgrades
|
||||
apt:
|
||||
name: unattended-upgrades
|
||||
|
||||
- name: Configure unattended-upgrades
|
||||
template:
|
||||
src: "{{ item }}.j2"
|
||||
dest: "/etc/apt/apt.conf.d/{{ item }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: "u=rw,g=r,o=r"
|
||||
loop:
|
||||
- 20auto-upgrades
|
||||
- 50unattended-upgrades
|
||||
...
|
4
roles/unattended_upgrades/templates/20auto-upgrades.j2
Normal file
4
roles/unattended_upgrades/templates/20auto-upgrades.j2
Normal file
|
@ -0,0 +1,4 @@
|
|||
{{ ansible_managed | comment }}
|
||||
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "1";
|
29
roles/unattended_upgrades/templates/50unattended-upgrades.j2
Normal file
29
roles/unattended_upgrades/templates/50unattended-upgrades.j2
Normal file
|
@ -0,0 +1,29 @@
|
|||
{{ ansible_managed | comment }}
|
||||
|
||||
Unattended-Upgrade::Origins-Pattern {
|
||||
"origin=Debian,label=Debian-Security";
|
||||
};
|
||||
|
||||
Unattended-Upgrade::Package-Blacklist {};
|
||||
Unattended-Upgrade::Package-Whitelist {};
|
||||
|
||||
Unattended-Upgrade::Automatic-Reboot "false";
|
||||
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
|
||||
Unattended-Upgrade::IgnoreAppsRequireRestart "false";
|
||||
Unattended-Upgrade::InstallOnShutdown "false";
|
||||
Unattended-Upgrade::MinimalSteps "true";
|
||||
|
||||
Unattended-Upgrade::Mail "{{ monitoring_mail }}";
|
||||
Unattended-Upgrade::MailOnlyOnError "true";
|
||||
|
||||
Unattended-Upgrade::Keep-Debs-After-Install "false";
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "false";
|
||||
|
||||
Unattended-Upgrade::SyslogEnable "true";
|
||||
Unattended-Upgrade::SyslogFacility "daemon";
|
||||
|
||||
Unattended-Upgrade::OnlyOnACPower "false";
|
||||
|
||||
# https://bugs.launchpad.net/ubuntu/+source/pygobject/+bug/1859080
|
||||
Unattended-Upgrade::Skip-Updates-On-Metered-Connections "false";
|
Loading…
Reference in a new issue