Skip to content

Repository files navigation

Infra

Infrastructure blueprints for workstations, home network, edge Kubernetes lab, and self-hosted services, provisioned with Ansible and Terraform under GitOps.

Blueprints

Blueprint Scope Status
PC Workstations, laptops, gaming desktop, peripherals Planned
home-net Routers, APs, switches, UPS, cabling Planned
home-lab Bare-metal servers, storage, Kubernetes Planned
home-services Self-hosted services and their backups Planned
home-web Edge static hosting, CDN, domains Planned

Provisioning

Fresh-system prerequisites and Ansible (bruzit.ansible requires ansible-core 2.20 or newer, which apt provides on Ubuntu 26.04 and newer; on 24.04 use pipx install ansible instead):

sudo apt install -y git ansible

Clone this repo (HTTPS, a fresh machine has no SSH key or GitHub CLI yet):

git clone https://github.com/bruzit/infra.git
cd infra

Add the machine to inventory.yaml under workstations or wsl if it is not there yet.

Install collections:

ansible-galaxy collection install -r requirements.yaml

Accounts are defined once in group_vars/all/accounts.yaml and passed to the users, git, gh and docker roles; each account's repositories are cloned into ~/Projects.

Hosts are grouped in inventory.yaml: every host gets apt, users, git, claude, direnv, starship, gh, bitwarden_cli, terraform, docker, jq, pwgen and yq; workstations additionally get snap, obsidian and widelands; wsl hosts additionally get wsl (no systemd, snapd purged, Windows browser for gh and xdg-open; run wsl --shutdown from Windows after the first run), and the Docker daemon is started by hand with sudo service docker start. All hosts connect locally, so always limit the run to the current machine with -l; -K prompts for the sudo password:

ansible-playbook -K -l <inventory-hostname> playbook.yaml

Without a TTY, point Ansible at a password file instead (there is no environment variable for the password itself):

ANSIBLE_BECOME_PASSWORD_FILE=~/.ansible_become ansible-playbook -l <inventory-hostname> playbook.yaml

inventory.yaml connects locally, so ansible.builtin.reboot refuses to run — keep system_reboot_when_needed false and reboot by hand after kernel upgrades.

Copyright and Licensing

MIT License
Copyright © 2026 Martin Bružina

About

Infrastructure blueprints for workstations, home network, edge Kubernetes lab, and self-hosted services, provisioned with Ansible and Terraform under GitOps.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors