<feed xmlns='http://www.w3.org/2005/Atom'>
<title>luke/ansible-roles/soju, branch main</title>
<subtitle>Ansible roles for nth.io infrastructure
</subtitle>
<id>https://src.nth.io/luke/ansible-roles/atom?h=main</id>
<link rel='self' href='https://src.nth.io/luke/ansible-roles/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/'/>
<updated>2026-08-01T14:53:44Z</updated>
<entry>
<title>soju: pass passwords via stdin, restart after sojudb writes</title>
<updated>2026-08-01T14:53:44Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-08-01T14:53:44Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=3bf3b8424de4ccabd0a97faa6d6a99b1ffb558f8'/>
<id>urn:sha1:3bf3b8424de4ccabd0a97faa6d6a99b1ffb558f8</id>
<content type='text'>
dash echo mangles backslash escapes, and soju authenticates against its
in-memory copy so sojudb changes need a restart to take effect.
</content>
</entry>
<entry>
<title>soju: gate the admin password reset behind soju_reset_password</title>
<updated>2026-07-31T19:31:51Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-07-31T19:31:51Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=a9a87f70f787fbc0d47d7138996e31294f172bea'/>
<id>urn:sha1:a9a87f70f787fbc0d47d7138996e31294f172bea</id>
<content type='text'>
The unconditional change-password re-keyed the account on every run,
clobbering any password changed in-band and locking out clients.
</content>
</entry>
<entry>
<title>relayer, soju: order services after postgresql at boot</title>
<updated>2026-07-30T23:19:08Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-07-30T23:19:08Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=6f573b9d12e6fa2f6a7dbebb41ccfbbd966c82e7'/>
<id>urn:sha1:6f573b9d12e6fa2f6a7dbebb41ccfbbd966c82e7</id>
<content type='text'>
relayer had Requires= without After=, which does not order startup;
soju's packaged unit has no postgres ordering at all, so both raced
the postgres socket at boot and stayed failed. Adds After= to the
relayer unit and a systemd drop-in for soju.
</content>
</entry>
<entry>
<title>Add re-key support for soju and postgresql</title>
<updated>2026-04-06T01:15:02Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-04-06T01:15:02Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=0b402a7a0a773dfa40e5549235941cd1217617d3'/>
<id>urn:sha1:0b402a7a0a773dfa40e5549235941cd1217617d3</id>
<content type='text'>
- soju: add change-password task so admin password updates on every
  playbook run via sojudb change-password
- postgresql: remove superuser password task — postgres uses peer auth
  (Unix socket), no password needed or desired
</content>
</entry>
<entry>
<title>Removed sojuctl ansible commands. configure via client.</title>
<updated>2026-03-29T01:09:33Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-29T01:09:33Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=55e55db9154e80aec134eef17d9d883d0213d4c4'/>
<id>urn:sha1:55e55db9154e80aec134eef17d9d883d0213d4c4</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Added soju role.</title>
<updated>2026-03-28T18:42:08Z</updated>
<author>
<name>Luke Hoersten</name>
<email>luke@hoersten.org</email>
</author>
<published>2026-03-28T18:42:08Z</published>
<link rel='alternate' type='text/html' href='https://src.nth.io/luke/ansible-roles/commit/?id=45da5bca82200af63b0ee16479b267eb209386f3'/>
<id>urn:sha1:45da5bca82200af63b0ee16479b267eb209386f3</id>
<content type='text'>
</content>
</entry>
</feed>
