<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/miniflux, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-07-31T19:31:51Z</updated>
<entry>
<title>install from the 26.04 archive instead of third-party sources</title>
<updated>2026-07-31T19:31:51Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-07-31T19:31:51Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=846782c44c1c65e7b755de76fd50d86fc7c9636e'/>
<id>urn:sha1:846782c44c1c65e7b755de76fd50d86fc7c9636e</id>
<content type='text'>
- rpi-base: log2ram from the archive, drop the azlux repo (which still
  pointed at debian buster)
- aws-s3-backup: apt awscli (v2) instead of pip v1; drop boto3, nothing
  used it
- scrypted, koreader-sync: docker.io and docker-compose-v2 instead of
  the docker.com repo pinned to noble; the docker-ce removal lives in
  cleanup-third-party.yaml since the packages collide on files
- miniflux: the archive package with a dbconfig preseed; drops the
  github binary download and the bundled unit
- prometheus/client: note the nginx and postgres exporters are in apt
- dendrite/build, nostr/build: unversioned golang-go instead of pinned
  golang-1.21-go and a hand symlink that shadowed the real go
</content>
</entry>
<entry>
<title>Harden role security: file permissions, service binding, no_log, strict defaults</title>
<updated>2026-04-06T02:19:55Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-04-06T02:19:55Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=06b69bd8def0aae07d3fb565d19193be1a8dfe20'/>
<id>urn:sha1:06b69bd8def0aae07d3fb565d19193be1a8dfe20</id>
<content type='text'>
- Add no_log: true to tasks that handle passwords/secrets
- Tighten config file permissions (0644 -&gt; 0600/0640 where appropriate)
- Bind pleroma to 127.0.0.1 instead of 0.0.0.0
- Tighten ergo unix socket mode 0777 -&gt; 0770
- Remove weak defaults; roles now fail explicitly if required vars not set
</content>
</entry>
<entry>
<title>Update versions and fix nginx logging.</title>
<updated>2026-03-26T02:42:49Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-26T02:42:49Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=58d4444b06de49587417791bb06a4fe1aeda571d'/>
<id>urn:sha1:58d4444b06de49587417791bb06a4fe1aeda571d</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Updated versions.</title>
<updated>2025-05-29T00:24:44Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2025-05-29T00:24:44Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=cb74bdc5ae5194ceeda48aa92ca26ca685c737f9'/>
<id>urn:sha1:cb74bdc5ae5194ceeda48aa92ca26ca685c737f9</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version updates and fixed excessive logging on web server.</title>
<updated>2025-01-04T01:36:28Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2025-01-04T01:36:28Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=b180fe427c44da015874dbf86c326f6e6bcd0aa8'/>
<id>urn:sha1:b180fe427c44da015874dbf86c326f6e6bcd0aa8</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Lots of updates and fixes for Ubuntu 24.04 Noble.</title>
<updated>2024-10-07T20:25:37Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-10-07T20:25:37Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=27739609362360b2bf533f5a59106ce52c8d4b9f'/>
<id>urn:sha1:27739609362360b2bf533f5a59106ce52c8d4b9f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version updates.</title>
<updated>2024-07-20T15:22:38Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-07-20T15:22:38Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=77c421bdee5279551abbfeea8a97fdf5ba8edc61'/>
<id>urn:sha1:77c421bdee5279551abbfeea8a97fdf5ba8edc61</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Tons of updates to fix migration to new server.</title>
<updated>2024-02-05T02:27:19Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-02-05T02:27:19Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=04edbf561c44e28753cbbaa3870b23b220cc644c'/>
<id>urn:sha1:04edbf561c44e28753cbbaa3870b23b220cc644c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version updates.</title>
<updated>2024-01-16T06:04:53Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2024-01-16T06:04:53Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=312bf5e6094a496eafbfaed53d972c7d21d0b6d2'/>
<id>urn:sha1:312bf5e6094a496eafbfaed53d972c7d21d0b6d2</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Version updates.</title>
<updated>2023-09-16T03:46:19Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2023-09-16T03:46:19Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=12c9a85cbc9f4c218dd09f226c235e9376b45c85'/>
<id>urn:sha1:12c9a85cbc9f4c218dd09f226c235e9376b45c85</id>
<content type='text'>
</content>
</entry>
</feed>
