Skip to content

Repository files navigation

Ansible Collection - bcduggan.qubes

Opinionated Qubes OS automation

Nutshell

This collection contains roles and playbooks you can include in your own Ansible playbook project for Qubes OS. But you can get started with just an inventory and run the playbooks directly:

user@dom0:~/qubes-playbooks$ ansible-playbook bcduggan.qubes.site

Quick start from scratch

An Ansible playbook project includes an inventory and playbooks. You can define your own custom roles and playbooks in the project that use the qubes-ansible modules and plugins. Your project can also use roles, modules, plugins, and playbooks from collections, lke this one.

If you don't already have a playbook project for Qubes OS, you can create one that can directly use this collection's playbooks with just a few short files.

Create a virtual machine with network access to develop your Ansible project and name it playbook-dev. Install any editors, linters, LSPs, or other development tools in playbook-dev.

Create a directory for your playbook project called qubes-playbooks. After these setup steps, it will contain these files:

user@playbook-dev:~qubes-playbooks$ tree
.
├── ansible.cfg
├── gnupg
│   └── pubring.kbx
├── inventory
│   └── hosts.yml
├── requirements.yml

ansible.cfg

ansible.cfg must define collections_path so that ansible-galaxy installs collections in the project directory:

# ansible.cfg
[defaults]
strategy=qubes_proxy
collecions_path=./

When you define your own ansible.cfg, you may also set strategy=qubes_proxy to ensure Ansible uses the qubes_proxy plugin for VM connections.

requirements.yml

Add this collection and my signature to requirements.yml:

---
collections:
- name: bcduggan.qubes
  version: "<bcduggan.qubes-version>"
  signatures:
    - "https://github.com/bcduggan/bcduggan.qubes/releases/download/<bcduggan.qubes-version>/bcduggan-qubes.sig"
Placeholder Substitution
<bcduggan.qubes-version> Version of bcduggan.qubes collection, like 0.1.0

inventory/hosts.yml

adminvm:
  hosts:
    localhost:
      ansible_connection: local
      ansible_host: dom0

Install

Download my public key. And add it to a GPG keyring:

user@playbook-dev:~qubes-playbooks$ mkdir --mode=0700 gnupg
user@playbook-dev:~qubes-playbooks$ GNUPGHOME=gnupg gpg --keyserver keys.openpgp.org --recv-key 5EEBC6DAB95FF8610CBF401156A1C2EEA520ECEB

Install this collection in your Ansible project. This will create an ansible_collections directory in your project directory that contains your project's external collection dependencies:

user@playbook-dev:~qubes-playbooks$ ansible-galaxy collection install --keyring gnupg/pubring.kbx --requirements-file requirements.yml

Synchronize to dom0

qubes-ansible only works when you run Ansible directly on dom0 (for now). A copy of your Ansible project and all of its dependencies (like this collection) must exist in dom0 for this to work.

The Qubes OS documention describes how to copy a single file from a VM to dom0. You need to copy the Ansible project directory from your development VM to dom0. You will probably need to do this many times as you develop playbooks, roles, and update dependencies in your Ansible project. You should entirely overwrite the Ansible project on dom0 each time you copy it from from the VM where you develop your Ansible project.

The qvm-sync-dom0 script in this collection synchronizes directories from Qubes VMs to dom0. After you install this collection, copy qvm-sync-dom0 from your Ansible project to dom0:

root@dom0:~$ qvm-run --pass-io playbook-dev 'cat /home/user/qubes-playbooks/ansible_collections/bcduggan/qubes/qvm-sync-dom0' > /usr/local/bin/qvm-sync-dom0

Now you can use qvm-sync-dom0 to synchronize your Ansible project to dom0:

user@dom0:~$ qvm-sync-dom0 playbook-dev qubes-playbooks

Development

Clone the git repository to the same VM where you develop your playbook project. Install in your playbook project from the bcduggan.qubes clone:

user@playbook-dev:~qubes-playbooks$ ansible-galaxy collection install --force ~/bcduggan.qubes

It is only possible to verify signatures for collections installed from Ansible Galaxy.

Roles

qvm_sync_dom0

Playbooks

site.yml

About

Helper modules and roles for qubes-ansible

Resources

Stars

1 star

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages