<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/dendrite/server/tasks/main.yaml, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-04-06T02:19:55+00:00</updated>
<entry>
<title>Harden role security: file permissions, service binding, no_log, strict defaults</title>
<updated>2026-04-06T02:19:55+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-04-06T02:19:55+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=06b69bd8def0aae07d3fb565d19193be1a8dfe20'/>
<id>urn:sha1:06b69bd8def0aae07d3fb565d19193be1a8dfe20</id>
<content type='text'>
- Add no_log: true to tasks that handle passwords/secrets
- Tighten config file permissions (0644 -&gt; 0600/0640 where appropriate)
- Bind pleroma to 127.0.0.1 instead of 0.0.0.0
- Tighten ergo unix socket mode 0777 -&gt; 0770
- Remove weak defaults; roles now fail explicitly if required vars not set
</content>
</entry>
<entry>
<title>Added soju role.</title>
<updated>2026-03-28T18:42:08+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-28T18:42:08+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=45da5bca82200af63b0ee16479b267eb209386f3'/>
<id>urn:sha1:45da5bca82200af63b0ee16479b267eb209386f3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Cleaned up always-changed status tasks.</title>
<updated>2024-07-29T17:41:57+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-07-29T17:41:57+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=874be10f6646a66cd0e994963b2746ad48f5b73e'/>
<id>urn:sha1:874be10f6646a66cd0e994963b2746ad48f5b73e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Dendrite tweaks.</title>
<updated>2024-02-10T21:40:36+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-02-10T21:40:36+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=de23e66fdded8d2884de32267e09b128d2680bfa'/>
<id>urn:sha1:de23e66fdded8d2884de32267e09b128d2680bfa</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Tons of updates to fix migration to new server.</title>
<updated>2024-02-05T02:27:19+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-02-05T02:27:19+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=04edbf561c44e28753cbbaa3870b23b220cc644c'/>
<id>urn:sha1:04edbf561c44e28753cbbaa3870b23b220cc644c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Finished up dendrite build server role.</title>
<updated>2023-07-22T20:50:07+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-07-22T20:50:07+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=d6454704216bfa4b4f6e8a250f057f2b0d543fa1'/>
<id>urn:sha1:d6454704216bfa4b4f6e8a250f057f2b0d543fa1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Split dendrite build out of install role.</title>
<updated>2023-07-21T20:14:24+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-07-21T20:14:24+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=8b9372c76e66c892741335566d1a63c29cc18ba3'/>
<id>urn:sha1:8b9372c76e66c892741335566d1a63c29cc18ba3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version updates.</title>
<updated>2023-07-19T18:54:22+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-07-19T18:54:22+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=d5c5467d4d2a6090d75436f07ef2eac6945dfa1b'/>
<id>urn:sha1:d5c5467d4d2a6090d75436f07ef2eac6945dfa1b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version update</title>
<updated>2023-04-03T18:20:18+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-04-03T18:20:18+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=fecba00f69bf8577d7abe67dcb81a612b3c547e5'/>
<id>urn:sha1:fecba00f69bf8577d7abe67dcb81a612b3c547e5</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Minor version updates and bug fixes.</title>
<updated>2022-09-05T16:14:48+00:00</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2022-09-05T16:14:48+00:00</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=7d2ffb19545a7888c23851b73dbd577cd98ef655'/>
<id>urn:sha1:7d2ffb19545a7888c23851b73dbd577cd98ef655</id>
<content type='text'>
</content>
</entry>
</feed>
