# Ansible Guides

# Installing the Semaphore UI

[![Semaphore UI](https://img.shields.io/badge/Semaphore_UI-0288D1?style=flat)](https://semaphoreui.com/)
[![Documentation](https://img.shields.io/badge/Documentation-077b70?style=flat)](https://semaphoreui.com/docs)
[![semaphoreui/semaphore](https://img.shields.io/badge/semaphoreui/semaphore-555555?style=flat&logo=github&logoColor=white)](https://github.com/semaphoreui/semaphore)

Installation
-------------

[![GitHub Releases](https://img.shields.io/badge/GitHub_Releases-0f7d15?style=flat&logo=github&logoColor=white)](https://github.com/semaphoreui/semaphore/releases)

```shell
sudo apt install ansible python3-jmespath yq
```

```shell
sudo wget "https://github.com/semaphoreui/semaphore/releases/download/v2.19.12/semaphore_2.19.12_linux_amd64.deb" -O "/usr/local/src/semaphore_2.19.12_linux_amd64.deb"
sudo apt install "/usr/local/src/semaphore_2.19.12_linux_amd64.deb"
```

```shell
sudo useradd --create-home -d "/var/lib/semaphoreui" --shell "/usr/sbin/nologin" --system semaphoreui
sudo chmod 0750 "/var/lib/semaphoreui"
```

```shell
sudo -u semaphoreui semaphore setup
```

```shell
sudo chmod 0640 "/var/lib/semaphoreui/config.json"
sudo chmod 0600 "/var/lib/semaphoreui/database.sqlite"
```

```shell
sudo tee "/etc/systemd/system/semaphoreui.service" >/dev/null <<'EOF'
[Unit]
Description=Semaphore UI
Documentation=https://semaphoreui.com/docs
Wants=network-online.target
After=network-online.target
ConditionPathExists=/usr/bin/semaphoreui
ConditionPathExists=/var/lib/semaphoreui/config.json

[Service]
ExecStart=/usr/bin/semaphore server --config=/var/lib/semaphoreui/config.json
ExecReload=/bin/kill -HUP $MAINPID
Restart=always
RestartSec=10s
User=semaphore
Group=semaphore
SyslogIdentifier=semaphoreui

[Install]
WantedBy=multi-user.target
EOF
```

```shell
sudo systemctl daemon-reload
sudo systemctl enable --now semaphoreui
```

Configure a NGINX Reverse-Proxy
--------------------------------

```nginx
server {
    listen 443 ssl;
    http2 on;

    add_header Strict-Transport-Security "max-age=63072000" always;
    add_header X-Content-Type-Options "nosniff";
    add_header X-Frame-Options "SAMEORIGIN";

    # Required to avoid HTTP 411: see Issue #1486.
    # (https://github.com/docker/docker/issues/1486)
    chunked_transfer_encoding on;

    location / {
        proxy_pass http://127.0.0.1:3000/;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;

        proxy_buffering off;
        proxy_request_buffering off;
    }

    location /api/ws {
        proxy_pass http://127.0.0.1:3000/api/ws;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Origin "";
    }
}
```

Create GitLab Acecss Token
---------------------------

`read_api` `read_repository`

# Setup Agent on Client Node

```shell
groupadd -g 2042 ansible-agent
useradd --create-home --home /var/lib/ansible --shell /bin/bash -u 2042 -g 2042 ansible-agent
passwd -l ansible-agent
mkdir -p /var/lib/ansible/.ssh
touch /var/lib/ansible/.ssh/authorized_keys
chown ansible-agent /var/lib/ansible/.ssh/authorized_keys
chmod 0600 /var/lib/ansible/.ssh/authorized_keys
mkdir -p /var/lib/ansible/.ansible
chown ansible-agent /var/lib/ansible/.ansible
```

```shell
sudo touch /etc/sudoers.d/ansible-agent
sudo chmod 0440 /etc/sudoers.d/ansible-agent
sudo cat > /etc/sudoers.d/ansible-agent <<'EOF'
ansible-agent ALL=(ALL) NOPASSWD: ALL
EOF
```

# Ansible Authoring Guide

EditorConfig Code Style 
-----------------------

[![EditorConfig Guide](https://img.shields.io/badge/EditorConfig_Guide-7b2c2c?style=flat-square)](/books/code-style-guides/page/editorconfig-guide)

```ini
[{*.yml,*.yaml}]
indent_size = 2
#indent_style = space
```