Minimal Ansible project for provisioning and maintaining an Oracle Linux instance (OCI).
Designed to be:
- reproducible
- easy to understand
- easy to tear down and rebuild
This repo contains:
-
site.yml – main playbook (base + dotfiles + hardening)
-
fail2ban-setup.yml – standalone Fail2ban install/config
-
roles/
base– core system setup (firewalld, chrony, timezone)dotfiles– user environment (vim, tmux, git, symlinks)hardening– security-related tasks (in progress)
- Control node: Linux / WSL with Python 3
- Target: Oracle Linux (OCI)
- SSH key access to target host
Install Ansible (recommended via venv):
python3 -m venv .venv
source .venv/bin/activate
pip install ansibleCopy the template and edit:
cp inventory.ini.tmplt inventory.iniExample:
[oci]
YOUR_HOSTNAME ansible_host=YOUR_IP ansible_user=YOUR_USER ansible_ssh_private_key_file=~/.ssh/id_rsaRun full setup:
ansible-playbook site.ymlRun specific components:
ansible-playbook site.yml --tags base
ansible-playbook site.yml --tags dotfiles
ansible-playbook site.yml --tags "base,hardening"Run standalone Fail2ban setup:
ansible-playbook fail2ban-setup.yml.
├── ansible.cfg
├── inventory.ini.tmplt
├── inventory.ini (local, not committed)
├── site.yml
├── fail2ban-setup.yml
├── roles/
│ ├── base/
│ ├── dotfiles/
│ └── hardening/
└── .venv/ (ignored)
.venv/is not committed (reproducible via pip)inventory.iniis not committed (contains host-specific info)- Dotfiles are symlinked from
~/dotfilesrepo on the target host - Tasks are idempotent where possible
- No secrets are stored in this repo
- SSH keys are referenced, not included
- Add your IP to Fail2ban
ignoreipto avoid lockout
Check connectivity:
ansible oci -m pingVerbose output:
ansible-playbook site.yml -vvv- Expand hardening role (SSH config, audit rules)
- Template-based configs instead of inline content
- Multi-host inventory support
Keep it simple:
- small roles
- readable tasks
- minimal magic
If it can’t be understood in a few minutes, it’s too complicated.