fabbr@site:~/projects/ansible-infra$

ansible-infra

# ~/projects/ansible-infra.yml
ansible-infra:
  status: active
  started: 2026-08-04
  tags: [ansible, collection]
  repo: https://github.com/fabbrito/ansible-infra

fabbrito.infra is an Ansible collection that provisions long-lived Debian-family hosts, cloud VMs and single-board computers alike, on x86 and ARM, and keeps them converged.

How it works

It manages:

  • OS settings and unattended upgrades;
  • SSH hardening, a deny-by-default firewall and fail2ban;
  • Docker, with a pruning timer;
  • rclone to Cloudflare R2;
  • Caddy as the TLS edge;
  • a metrics and logs stack bound to loopback;
  • on boards, a cloud-init seed for first boot, a fixed LAN address and a journal that survives a reboot.

Before it changes anything, a preflight check refuses any platform it doesn’t support.

Why

It covers the part of a host that no host is interesting for, once. Service roles stay in the repository that owns the service, along with the inventory, the secrets and the converge itself.

Where it stands

At v2.3.0. Tested on Ubuntu 24.04 and later, Debian 13 on amd64, and Raspberry Pi OS trixie on armhf. Other ARM targets are expected to work but aren’t tested yet.