ansible-nas/group_vars/all.yml.dist

508 lines
13 KiB
Text
Raw Normal View History

2017-08-28 15:31:54 +00:00
###
### Ansible NAS Features
###
# Set these options to true or false to toggle specific features
2018-11-28 23:22:36 +00:00
# External Access
# Traefik will allow access to certain applications externally. To enable this you'll either; a domain name that points to your
# home static IP address, the cloudflare with the cloudflare_ddns dynamic DNS container enabled, or use a dynamic DNS provider like no-ip.
# You'll also need to map ports 80 and 443 from your router to your ansible-nas server, then enable the per-app "availble_externally"
# settings.
traefik_enabled: false
2018-11-28 23:22:36 +00:00
2017-08-28 15:31:54 +00:00
# BitTorrent
# If you plan to use Transmission with OpenVPN, you'll need to copy group_vars/vpn_credentials.yml.dist
# to group_vars/vpn_credentials.yml, then update it with your own settings.
transmission_with_openvpn_enabled: false
2018-09-21 22:42:16 +00:00
transmission_enabled: false
2017-08-28 15:31:54 +00:00
2018-09-22 23:58:59 +00:00
# Plex
plex_enabled: false
2018-09-23 19:20:10 +00:00
tautulli_enabled: false
2018-09-22 23:58:59 +00:00
# Emby
emby_enabled: false
2018-09-22 23:58:59 +00:00
2019-03-01 23:13:11 +00:00
# minidlna
minidlna_enabled: false
2017-08-28 15:31:54 +00:00
# Media Sourcing
2018-09-21 22:42:16 +00:00
sonarr_enabled: false
sickchill_enabled: false
2017-08-28 15:31:54 +00:00
couchpotato_enabled: false
2018-09-21 22:42:16 +00:00
radarr_enabled: false
2019-03-01 20:59:43 +00:00
get_iplayer_enabled: false
2019-03-22 18:46:38 +00:00
jackett_enabled: false
2017-08-28 15:31:54 +00:00
2019-01-03 15:10:39 +00:00
# Music
airsonic_enabled: false
2019-03-01 23:05:33 +00:00
mymediaforalexa_enabled: false
2019-01-03 15:10:39 +00:00
2018-12-31 00:08:25 +00:00
# News
miniflux_enabled: false
2017-08-28 15:31:54 +00:00
# System Management
2019-01-05 13:16:11 +00:00
heimdall_enabled: true
2017-08-28 15:31:54 +00:00
portainer_enabled: true
2019-04-13 15:13:20 +00:00
glances_enabled: false
2018-09-21 22:42:16 +00:00
stats_enabled: false
guacamole_enabled: false
netdata_enabled: false
watchtower_enabled: false
2019-01-15 23:24:18 +00:00
cloudflare_ddns_enabled: false
2017-08-28 15:31:54 +00:00
# Backup & Restore
duplicati_enabled: false
2018-09-21 22:37:53 +00:00
nextcloud_enabled: false
2018-11-14 10:13:52 +00:00
gitea_enabled: false
2018-12-28 01:00:51 +00:00
timemachine_enabled: false
2017-08-28 15:31:54 +00:00
2019-04-12 22:31:27 +00:00
# IRC
2018-04-10 21:57:28 +00:00
znc_enabled: false
2019-04-12 22:31:27 +00:00
thelounge_enabled: false
2017-11-21 22:18:35 +00:00
# Password Management
bitwarden_enabled: false
2017-11-21 22:18:35 +00:00
2017-08-28 15:31:54 +00:00
###
### General
###
# Sets the hostname of your Ansible NAS
2018-11-28 23:22:36 +00:00
ansible_nas_hostname: ansible-nas
2017-08-28 15:31:54 +00:00
# Sets the timezone for your Ansible NAS
# You can find a list here https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
ansible_nas_timezone: Etc/UTC
2017-08-28 15:31:54 +00:00
# Update all apt packages when playbook is run
keep_packages_updated: false
2017-08-28 15:31:54 +00:00
# Will be added to the docker group to give user command line access to docker
ansible_nas_user: david
2018-11-28 23:22:36 +00:00
# Your email and domain, used for LetsEncrypt SSL certs
ansible_nas_email: me@example.com
2018-11-25 15:27:50 +00:00
2018-11-28 23:22:36 +00:00
# Applications will have subdomain SSL certificates created, eg ansible-nas.<your-domain>, nextcloud.<your-domain>
ansible_nas_domain: example.com
###
### Docker
###
# Where you want Docker to store images
docker_image_directory: "{{ docker_home }}/data"
# Where you want Docker to store its container data.
2017-08-28 15:31:54 +00:00
docker_home: /mnt/Volume2/docker
# Docker storage driver, see https://docs.docker.com/storage/storagedriver/select-storage-driver/#supported-backing-filesystems
# You might want to change this to ZFS, depending on your underlying filesystem.
docker_storage_driver: overlay2
2017-08-28 15:31:54 +00:00
###
### Samba
###
# The location where all shares will be created by default. Can be overridden on a per-share basis.
2018-04-08 23:01:59 +00:00
# This path will be mounted to backup containers, Duplicati
2017-08-28 15:31:54 +00:00
samba_shares_root: /mnt/Volume3
2017-08-28 21:10:19 +00:00
# Where stuff downloaded will be stored
downloads_root: "{{ samba_shares_root }}/downloads"
# Where your movies are stored
movies_root: "{{ samba_shares_root }}/movies"
# Where your TV episodes are stored
tv_root: "{{ samba_shares_root }}/tv"
# Where torrent files are stored (picked up by Transmission for downloading)
torrents_root: "{{ samba_shares_root }}/torrents"
2019-01-03 15:10:39 +00:00
# Where music is stored
music_root: "{{ samba_shares_root }}/music"
# Where podcasts are stored
podcasts_root: "{{ samba_shares_root }}/podcasts"
# The description that'll appear next to your Ansible-NAS box when browsing your network
samba_server_string: Ansible NAS
2017-08-28 15:31:54 +00:00
# Shares you want published over Samba.
2017-08-28 21:10:19 +00:00
samba_shares:
2017-08-28 15:31:54 +00:00
- name: downloads
comment: 'Stuff downloaded'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 21:10:19 +00:00
path: "{{ downloads_root }}"
2017-08-28 15:31:54 +00:00
- name: movies
comment: 'Movies'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 21:10:19 +00:00
path: "{{ movies_root }}"
2017-08-28 15:31:54 +00:00
- name: tv
comment: 'TV Episodes'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 21:10:19 +00:00
path: "{{ tv_root }}"
2017-08-28 15:31:54 +00:00
2019-01-03 15:10:39 +00:00
- name: music
comment: 'Music'
guest_ok: yes
public: yes
writable: yes
browsable: yes
path: "{{ samba_shares_root }}/music"
- name: podcasts
comment: 'Podcasts'
guest_ok: yes
public: yes
writable: yes
browsable: yes
path: "{{ samba_shares_root }}/podcasts"
2017-08-28 15:31:54 +00:00
- name: dump
comment: 'File dump'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 15:31:54 +00:00
path: "{{ samba_shares_root }}/dump"
- name: games
comment: 'Games'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 15:31:54 +00:00
path: "{{ samba_shares_root }}/games"
- name: photos
comment: 'Pictures'
guest_ok: yes
public: yes
writable: yes
browsable: yes
2017-08-28 15:31:54 +00:00
path: "{{ samba_shares_root }}/photos"
2019-01-15 23:24:18 +00:00
###
### Cloudflare
###
# Cloudflare is a great free DNS option for domains. If you use the cloudflare_ddns container then you'll need to
# set the options below.
# Your domain name
cloudflare_zone: "{{ ansible_nas_domain }}"
2019-01-15 23:24:18 +00:00
# The hostname you want the container to update. You shouldn't need to change this.
cloudflare_host: "*.{{ cloudflare_zone }}"
# Email address used to register for Cloudflare
cloudflare_email: "{{ ansible_nas_email }}"
2019-01-15 23:24:18 +00:00
# Cloudflare 'Global API Key', can be found on the 'My Profile' page
cloudflare_api_key: abcdeabcdeabcdeabcde1234512345
2017-08-28 15:31:54 +00:00
##################################################################
###### You shouldn't need to edit anything below this point ######
##################################################################
###
### General
###
# Extra packages to install
2018-12-31 00:08:25 +00:00
ansible_nas_extra_packages:
- smartmontools
- htop
- zfsutils-linux
- bonnie++
- unzip
- lm-sensors
ansible_python_interpreter: /usr/bin/python3
###
### Samba
###
# Seems to break browsing of the \\server-name shares root when enabled
samba_mitigate_cve_2017_7494: false
# The account used when Samba shares are accessed. Shouldn't need to change this unless you want to
# mess with Samba user permissions.
samba_guest_account: ansible-nas
# How Samba behaves when an unknown user connects, see Samba docs for more info
samba_map_to_guest: Bad Password
# The Netbios hostname used by Samba on your network
samba_netbios_name: "{{ ansible_nas_hostname }}"
2018-11-28 23:22:36 +00:00
###
### Traefik
###
traefik_docker_image: traefik:latest
2018-11-28 23:22:36 +00:00
traefik_data_directory: "{{ docker_home }}/traefik"
traefik_debug: "false"
2018-11-28 23:22:36 +00:00
###
### Heimdall
###
heimdall_available_externally: "false"
2018-11-28 23:22:36 +00:00
heimdall_docker_image: linuxserver/heimdall:latest
heimdall_data_directory: "{{ docker_home }}/heimdall"
2017-08-28 15:31:54 +00:00
###
### Transmission
###
transmission_available_externally: "false"
transmission_with_openvpn_available_externally: "false"
2017-08-28 15:31:54 +00:00
transmission_config_directory: "{{ docker_home }}/transmission/config"
2017-08-28 21:10:19 +00:00
transmission_download_directory: "{{ downloads_root }}"
transmission_watch_directory: "{{ torrents_root }}"
2017-08-28 15:31:54 +00:00
transmission_user_id: 0
transmission_group_id: 0
transmission_local_network: "192.168.1.0/24"
2018-09-23 19:20:10 +00:00
###
### Plex
###
plex_available_externally: "false"
2018-09-23 19:20:10 +00:00
plex_config_directory: "{{ docker_home }}/plex/config"
plex_movies_directory: "{{ movies_root }}"
plex_tv_directory: "{{ tv_root }}"
plex_user_id: 0
plex_group_id: 0
###
### Emby
###
emby_available_externally: "false"
emby_config_directory: "{{ docker_home }}/emby/config"
emby_movies_directory: "{{ movies_root }}"
emby_tv_directory: "{{ tv_root }}"
emby_user_id: 0
emby_group_id: 0
2018-09-23 19:20:10 +00:00
###
### Tautulli
###
tautulli_available_externally: "false"
2018-09-23 19:20:10 +00:00
tautulli_config_directory: "{{ docker_home }}/tautulli/config"
tautulli_user_id: 0
tautulli_group_id: 0
2017-08-28 15:31:54 +00:00
###
### Duplicati
###
duplicati_available_externally: "false"
2017-08-28 15:31:54 +00:00
duplicati_data_directory: "{{ docker_home }}/duplicati/config"
###
### Sonarr
###
sonarr_available_externally: "false"
2017-08-28 15:31:54 +00:00
sonarr_data_directory: "{{ docker_home }}/sonarr/config"
2017-08-28 21:10:19 +00:00
sonarr_tv_directory: "{{ tv_root }}"
sonarr_download_directory: "{{ downloads_root }}"
2017-08-28 15:31:54 +00:00
sonarr_user_id: 0
sonarr_group_id: 0
2018-04-10 21:57:28 +00:00
###
### Radarr
###
radarr_available_externally: "false"
2018-04-10 21:57:28 +00:00
radarr_movies_directory: "{{ movies_root }}"
radarr_download_directory: "{{ downloads_root }}"
radarr_data_directory: "{{ docker_home }}/radarr"
radarr_user_id: 0
radarr_group_id: 0
2017-08-28 21:10:19 +00:00
###
### Couchpotato
###
couchpotato_available_externally: "false"
2017-08-28 21:10:19 +00:00
couchpotato_config_directory: "{{ docker_home }}/couchpotato/config"
couchpotato_movies_directory: "{{ movies_root }}"
couchpotato_downloads_directory: "{{ downloads_root }}"
couchpotato_torrents_directory: "{{ torrents_root }}"
couchpotato_user_id: 0
couchpotato_group_id: 0
2017-11-21 22:18:35 +00:00
###
### Sickchill
2017-11-21 22:18:35 +00:00
###
sickchill_available_externally: "false"
sickchill_config_directory: "{{ docker_home }}/sickchill/config"
sickchill_tv_directory: "{{ tv_root }}"
sickchill_downloads_directory: "{{ downloads_root }}"
sickchill_user_id: 0
sickchill_group_id: 0
2017-11-21 22:18:35 +00:00
###
### Netdata
###
netdata_available_externally: "false"
2017-11-21 22:18:35 +00:00
2017-08-28 15:31:54 +00:00
###
### OpenVPN
###
openvpn_config_directory: "{{ docker_home }}/openvpn"
###
### Portainer
###
portainer_available_externally: "false"
2017-08-28 15:31:54 +00:00
portainer_data_directory: "{{ docker_home }}/portainer/config"
2017-11-21 22:18:35 +00:00
###
### ZNC
###
znc_available_externally: "false"
2017-11-21 22:18:35 +00:00
znc_data_directory: "{{ docker_home }}/znc"
znc_user_id: 0
znc_group_id: 0
2018-04-07 10:29:22 +00:00
###
2018-09-23 19:20:10 +00:00
### Stats
2018-04-07 10:29:22 +00:00
###
grafana_available_externally: "false"
telegraf_data_directory: "{{ docker_home }}/telegraf"
2018-04-07 10:29:22 +00:00
influxdb_data_directory: "{{ docker_home }}/influxdb"
grafana_data_directory: "{{ docker_home }}/grafana"
2018-04-10 21:57:28 +00:00
stat_collection_interval: 15s
2018-09-21 22:37:53 +00:00
2018-11-14 10:13:52 +00:00
###
### Gitea
###
gitea_available_externally: "false"
2018-11-14 10:13:52 +00:00
gitea_data_directory: "{{ docker_home }}/gitea"
###
### Glances
###
glances_available_externally: "false"
2018-09-21 22:37:53 +00:00
###
### Nextcloud
###
nextcloud_available_externally: "false"
2018-09-21 22:37:53 +00:00
nextcloud_data_directory: "{{ docker_home }}/nextcloud"
###
### nginx
###
nginx_data_directory: "{{ docker_home }}/nginx"
###
### Guacamole
###
guacamole_available_externally: "false"
guacamole_docker_image: guacamole/guacamole:0.9.14
guacamole_guacd_docker_image: guacamole/guacd:0.9.14
guacamole_data_directory: "{{ docker_home }}/guacamole"
2018-12-31 00:08:25 +00:00
###
### Miniflux
###
miniflux_available_externally: "false"
2018-12-31 00:08:25 +00:00
miniflux_data_directory: "{{ docker_home }}/miniflux"
miniflux_admin_username: admin
miniflux_admin_password: supersecure
2019-01-03 15:10:39 +00:00
###
### Airsonic
###
airsonic_available_externally: "false"
2019-01-03 15:10:39 +00:00
airsonic_data_directory: "{{ docker_home }}/airsonic"
###
### Watchtower
###
2018-12-28 23:28:30 +00:00
# Sets the 6 field cron schedule to use for checks and updates. This will check at 5am daily.
watchtower_cron_schedule: 0 0 5 * * *
# Sets the Watchtower Docker start command. Different options can be supplied based on whether you want to receive
# notifications or not, some examples are provided below. See https://github.com/v2tec/watchtower for more info.
# No notifications
watchtower_command: "--schedule '{{ watchtower_cron_schedule }}' --debug"
# Email notifications
# watchtower_command: "--schedule '{{ watchtower_cron_schedule }}' --notifications 'email' --notification-email-from 'ansible@nas.com' --notification-email-to '{{ ansible_nas_email }}' --notification-email-server 'my.email.server.com' --notification-email-server-port '25' --notification-email-server-user 'email_username' --notification-email-server-password 'top-secret'"
2018-12-28 23:28:30 +00:00
# Slack notifications
2018-12-28 01:00:51 +00:00
# watchtower_command: "--schedule '{{ watchtower_cron_schedule }}' --notifications 'slack' --notification-slack-hook-url 'https://hooks.slack.com/services/xxx/yyyyyyyyyyyyyyy' --notification-slack-identifier 'ansible-nas'"
###
### Time Machine
###
timemachine_data_directory: "{{ docker_home }}/timemachine"
timemachine_volume_size_limit: 0
timemachine_password: timemachine
timemachine_share_name: TimeMachine
timemachine_log_level: error
2019-03-01 23:13:11 +00:00
###
### minidlna
###
minidlna_media_directory1: "{{ movies_root }}"
minidlna_media_directory2: "{{ tv_root }}"
minidlna_friendly_name: "{{ ansible_nas_hostname }}"
2019-03-01 20:59:43 +00:00
###
### get_iplayer
###
get_iplayer_config_directory: "{{ docker_home }}/get_iplayer"
get_iplayer_download_directory: "{{ tv_root }}/iplayer_downloads"
2019-03-01 23:05:33 +00:00
###
### mymediaforalexa
###
2019-03-31 22:34:56 +00:00
mymediaforalexa_media_directory: "{{ music_root }}"
2019-03-01 23:05:33 +00:00
mymediaforalexa_data_directory: "{{ docker_home }}/mymediaforalexa"
2019-03-22 18:46:38 +00:00
###
2019-04-12 22:31:27 +00:00
### Jackett
2019-03-22 18:46:38 +00:00
###
jackett_available_externally: "false"
jackett_data_directory: "{{ docker_home }}/jackett"
2019-04-12 22:31:27 +00:00
###
### The Lounge
###
thelounge_available_externally: "false"
2019-04-14 16:02:55 +00:00
thelounge_data_directory: "{{ docker_home }}/thelounge"
###
### Bitwarden
###
2019-04-14 16:05:21 +00:00
bitwarden_available_externally: "false"
bitwarden_data_directory: "{{ docker_home }}/bitwarden"
2019-04-14 16:02:55 +00:00
# Keep this token secret, this is password to access admin area of your server!
# This token can be anything, but it's recommended to use a long, randomly generated string of characters,
# for example running openssl rand -base64 48
bitwarden_admin_token: qwertyuiop1234567890poiuytrewq0987654321
# To create a user set this to "true", and reprovision the container by re-running the ansible-nas playbook.
# Once you have created your user, set to "false" and run one more time.
# Target just Bitwarden by running: ansible-playbook -i inventory nas.yml -b -K -t bitwarden
bitwarden_allow_signups: false