- ansible_become: true as a group_vars connection variable silently took
precedence over every task-level `become: false` in this repo, so
every "unprivileged" task (pipx installs, user script deploys,
legacy .env.local writes) was actually running as root the whole
time. Move become to a play-level keyword in site.yml instead, which
correctly loses to a task's own become: false. Also stop relying on
ansible_env.HOME (which reflected root's home once facts were
gathered under the old broken setup) and use /home/{{ remote_user }}
directly, with explicit owner/group so ownership self-heals.
- meshcore_capture: 99-user.toml.j2 now defines every broker
(including letsmesh-us/eu) fully rather than assuming
config.d/10-letsmesh.toml was auto-installed — that preset only gets
created on some install paths (fresh install) and not others
(migrate), so the old partial-override form silently dropped
brokers on migrated nodes.
- base: install libffi-dev/pkg-config on armv6 (Pi Zero W) — cffi has
no prebuilt wheel for that architecture and fails to compile
without the headers.
- dm-ashwell: migrated off the legacy layout to the current
installer's system-service layout; drop its layout override now
that it matches the group default.
- meshcore-capture-update.sh: fix a YAML folded scalar (>-) collapsing
the shebang and command onto one line, corrupting the script.
Co-Authored-By: Claude Sonnet 5 <[email protected]>
25 lines
475 B
YAML
25 lines
475 B
YAML
---
|
|
- name: Deploy MeshCore monitoring nodes
|
|
hosts: meshcore
|
|
become: true
|
|
vars_prompt:
|
|
- name: tailscale_auth_key
|
|
prompt: "Tailscale auth key (leave blank to skip)"
|
|
private: true
|
|
default: ""
|
|
|
|
pre_tasks:
|
|
- name: Update apt cache and upgrade packages
|
|
apt:
|
|
update_cache: true
|
|
upgrade: dist
|
|
autoremove: true
|
|
become: true
|
|
|
|
roles:
|
|
- wifi
|
|
- base
|
|
- meshcore_cli
|
|
- meshcore_capture
|
|
- scripts
|