Infrastructure blueprints for workstations, home network, edge Kubernetes lab, and self-hosted services, provisioned with Ansible and Terraform under GitOps.
| Blueprint | Scope | Status |
|---|---|---|
PC |
Workstations, laptops, gaming desktop, peripherals | Planned |
home-net |
Routers, APs, switches, UPS, cabling | Planned |
home-lab |
Bare-metal servers, storage, Kubernetes | Planned |
home-services |
Self-hosted services and their backups | Planned |
home-web |
Edge static hosting, CDN, domains | Planned |
Fresh-system prerequisites and Ansible (bruzit.ansible requires ansible-core 2.20 or newer, which apt provides on Ubuntu 26.04 and newer; on 24.04 use pipx install ansible instead):
sudo apt install -y git ansibleClone this repo (HTTPS, a fresh machine has no SSH key or GitHub CLI yet):
git clone https://github.com/bruzit/infra.git
cd infraAdd the machine to inventory.yaml under workstations or wsl if it is not there yet.
Install collections:
ansible-galaxy collection install -r requirements.yamlAccounts are defined once in group_vars/all/accounts.yaml and passed to the users, git, gh and docker roles; each account's repositories are cloned into ~/Projects.
Hosts are grouped in inventory.yaml: every host gets apt, users, git, claude, direnv, starship, gh, bitwarden_cli, terraform, docker, jq, pwgen and yq; workstations additionally get snap, obsidian and widelands; wsl hosts additionally get wsl (no systemd, snapd purged, Windows browser for gh and xdg-open; run wsl --shutdown from Windows after the first run), and the Docker daemon is started by hand with sudo service docker start. All hosts connect locally, so always limit the run to the current machine with -l; -K prompts for the sudo password:
ansible-playbook -K -l <inventory-hostname> playbook.yamlWithout a TTY, point Ansible at a password file instead (there is no environment variable for the password itself):
ANSIBLE_BECOME_PASSWORD_FILE=~/.ansible_become ansible-playbook -l <inventory-hostname> playbook.yamlinventory.yaml connects locally, so ansible.builtin.reboot refuses to run — keep system_reboot_when_needed false and reboot by hand after kernel upgrades.
MIT License
Copyright © 2026 Martin Bružina