- name: Install Forgejo on Debian 12 with Caddy reverse proxy hosts: vipy become: yes vars_files: - ../../infra_vars.yml - ../../services_config.yml - ../../infra_secrets.yml - ./forgejo_vars.yml vars: forgejo_subdomain: "{{ subdomains.forgejo }}" caddy_sites_dir: "{{ caddy_sites_dir }}" forgejo_domain: "{{ forgejo_subdomain }}.{{ root_domain }}" uptime_kuma_api_url: "https://{{ subdomains.uptime_kuma }}.{{ root_domain }}" tasks: - name: Ensure required packages are installed apt: name: - git - git-lfs - wget state: present update_cache: true - name: Download Forgejo binary get_url: url: "{{ forgejo_url }}" dest: "/tmp/forgejo" mode: '0755' - name: Move Forgejo binary to /usr/local/bin copy: src: "/tmp/forgejo" dest: "{{ forgejo_bin_path }}" remote_src: yes mode: '0755' - name: Create git system user user: name: "{{ forgejo_user }}" system: yes shell: /bin/bash home: "/home/{{ forgejo_user }}" create_home: yes comment: 'Git Version Control' - name: Create Forgejo data directory file: path: "{{ forgejo_data_dir }}" state: directory owner: "{{ forgejo_user }}" group: "{{ forgejo_user }}" mode: '0750' - name: Create Forgejo config directory file: path: "{{ forgejo_config_dir }}" state: directory owner: "{{ forgejo_user }}" group: "{{ forgejo_user }}" mode: '0770' - name: Create Forgejo config file ansible.builtin.copy: dest: "{{ forgejo_config_dir }}/app.ini" content: | APP_NAME = ; Countergit [server] HTTP_PORT = {{ forgejo_port }} owner: "{{ forgejo_user }}" group: "{{ forgejo_user }}" mode: '0644' - name: Download Forgejo systemd service file get_url: url: "{{ forgejo_service_url }}" dest: "/etc/systemd/system/forgejo.service" mode: '0644' - name: Reload systemd systemd: daemon_reload: yes - name: Enable and start Forgejo service systemd: name: forgejo enabled: yes state: started - name: Ensure Caddy sites-enabled directory exists file: path: "{{ caddy_sites_dir }}" state: directory owner: root group: root mode: '0755' - name: Ensure Caddyfile includes import directive for sites-enabled lineinfile: path: /etc/caddy/Caddyfile line: 'import sites-enabled/*' insertafter: EOF state: present backup: yes - name: Create Caddy reverse proxy configuration for forgejo copy: dest: "{{ caddy_sites_dir }}/forgejo.conf" content: | {{ forgejo_domain }} { reverse_proxy localhost:{{ forgejo_port }} } owner: root group: root mode: '0644' - name: Reload Caddy to apply new config command: systemctl reload caddy - name: Create Uptime Kuma monitor setup script for Forgejo delegate_to: localhost become: no copy: dest: /tmp/setup_forgejo_monitor.py content: | #!/usr/bin/env python3 import sys import yaml from uptime_kuma_api import UptimeKumaApi, MonitorType try: with open('/tmp/ansible_config.yml', 'r') as f: config = yaml.safe_load(f) url = config['uptime_kuma_url'] username = config['username'] password = config['password'] monitor_url = config['monitor_url'] monitor_name = config['monitor_name'] api = UptimeKumaApi(url, timeout=30) api.login(username, password) # Get all monitors monitors = api.get_monitors() # Find or create "services" group group = next((m for m in monitors if m.get('name') == 'services' and m.get('type') == 'group'), None) if not group: group_result = api.add_monitor(type='group', name='services') # Refresh to get the group with id monitors = api.get_monitors() group = next((m for m in monitors if m.get('name') == 'services' and m.get('type') == 'group'), None) # Check if monitor already exists existing_monitor = None for monitor in monitors: if monitor.get('name') == monitor_name: existing_monitor = monitor break # Get ntfy notification ID notifications = api.get_notifications() ntfy_notification_id = None for notif in notifications: if notif.get('type') == 'ntfy': ntfy_notification_id = notif.get('id') break if existing_monitor: print(f"Monitor '{monitor_name}' already exists (ID: {existing_monitor['id']})") print("Skipping - monitor already configured") else: print(f"Creating monitor '{monitor_name}'...") api.add_monitor( type=MonitorType.HTTP, name=monitor_name, url=monitor_url, parent=group['id'], interval=60, maxretries=3, retryInterval=60, notificationIDList={ntfy_notification_id: True} if ntfy_notification_id else {} ) api.disconnect() print("SUCCESS") except Exception as e: print(f"ERROR: {str(e)}", file=sys.stderr) sys.exit(1) mode: '0755' - name: Create temporary config for monitor setup delegate_to: localhost become: no copy: dest: /tmp/ansible_config.yml content: | uptime_kuma_url: "{{ uptime_kuma_api_url }}" username: "{{ uptime_kuma_username }}" password: "{{ uptime_kuma_password }}" monitor_url: "https://{{ forgejo_domain }}/api/healthz" monitor_name: "Forgejo" mode: '0644' - name: Run Uptime Kuma monitor setup command: python3 /tmp/setup_forgejo_monitor.py delegate_to: localhost become: no register: monitor_setup changed_when: "'SUCCESS' in monitor_setup.stdout" ignore_errors: yes - name: Clean up temporary files delegate_to: localhost become: no file: path: "{{ item }}" state: absent loop: - /tmp/setup_forgejo_monitor.py - /tmp/ansible_config.yml