From d68e39127ac91a2c8bd507ac2a99bb093f3249c2 Mon Sep 17 00:00:00 2001 From: Christoph Date: Mon, 13 Jul 2026 21:24:24 +0200 Subject: [PATCH] Add deb822 source templates for Debian backports and security repositories --- roles/common/tasks/apt.yml | 207 +++++++++++++++--- .../etc/apt/deb822/backports.sources.j2 | 12 + .../etc/apt/deb822/debian.sources.j2 | 10 + .../etc/apt/deb822/security.sources.j2 | 10 + 4 files changed, 207 insertions(+), 32 deletions(-) create mode 100644 roles/common/templates/etc/apt/deb822/backports.sources.j2 create mode 100644 roles/common/templates/etc/apt/deb822/debian.sources.j2 create mode 100644 roles/common/templates/etc/apt/deb822/security.sources.j2 diff --git a/roles/common/tasks/apt.yml b/roles/common/tasks/apt.yml index 266609f..01c7b31 100644 --- a/roles/common/tasks/apt.yml +++ b/roles/common/tasks/apt.yml @@ -1,4 +1,13 @@ --- +- name: (apt.yml) Delete Hetzner files 'hetzner-mirror.list' and 'hetzner-security-updates.list' + file: + path: "{{ item }}" + state: absent + with_items: + - /etc/apt/sources.list.d/hetzner-mirror.list + - /etc/apt/sources.list.d/hetzner-security-updates.list + tags: + - apt-configuration - name: (apt.yml) update configuration file - /etc/apt/sources.list template: @@ -15,6 +24,138 @@ tags: - apt-configuration +- name: (apt.yml) Ensure Debian archive keyring is present for deb822 Signed-By (Debian >= 13) + apt: + name: debian-archive-keyring + state: present + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + - apt_deb822_use_signed_by | default(true) | bool + tags: + - apt-configuration + +- name: (apt.yml) backup legacy /etc/apt/sources.list before deb822 migration (Debian >= 13) + copy: + src: /etc/apt/sources.list + dest: /etc/apt/sources.list.before-deb822 + remote_src: true + force: false + owner: root + group: root + mode: "0644" + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + failed_when: + - apt_sources_list_backup.failed + - "'No such file or directory' not in (apt_sources_list_backup.msg | default(''))" + register: apt_sources_list_backup + tags: + - apt-configuration + +- name: (apt.yml) replace /etc/apt/sources.list with deb822 notice (Debian >= 13) + copy: + dest: /etc/apt/sources.list + content: | + # {{ ansible_managed }} + # + # Verwaltet via Ansible. Repositories liegen in /etc/apt/sources.list.d/*.sources (deb822). + # Zielrelease: {{ ansible_facts['distribution_release'] }} + owner: root + group: root + mode: "0644" + register: apt_config_updated_sources_list + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + tags: + - apt-configuration + +- name: (apt.yml) configure deb822 Debian repository (Debian >= 13) + template: + src: "etc/apt/deb822/debian.sources.j2" + dest: /etc/apt/sources.list.d/debian.sources + owner: root + group: root + mode: "0644" + register: apt_config_updated_debian_sources + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + tags: + - apt-configuration + +- name: (apt.yml) configure deb822 security repository (Debian >= 13) + template: + src: "etc/apt/deb822/security.sources.j2" + dest: /etc/apt/sources.list.d/security.sources + owner: root + group: root + mode: "0644" + register: apt_config_updated_security_sources + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + tags: + - apt-configuration + +- name: (apt.yml) configure deb822 backports repository (Debian >= 13) + template: + src: "etc/apt/deb822/backports.sources.j2" + dest: /etc/apt/sources.list.d/backports.sources + owner: root + group: root + mode: "0644" + register: apt_config_updated_backports_sources + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + - apt_backports_enable | default(false) | bool + tags: + - apt-configuration + +# If 'backports' was enabled in a previous run but is now disabled. +# +- name: (apt.yml) remove deb822 backports repository when disabled (Debian >= 13) + file: + path: /etc/apt/sources.list.d/backports.sources + state: absent + register: apt_config_removed_backports_sources + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + - not (apt_backports_enable | default(false) | bool) + tags: + - apt-configuration + +# Collect change states from all Debian >=13 deb822 source tasks so apt update +# can force a fresh cache refresh when repository files changed. +- name: (apt.yml) aggregate deb822 source changes (Debian >= 13) + set_fact: + apt_config_updated: + changed: >- + {{ + (apt_config_updated_sources_list.changed | default(false)) + or (apt_config_updated_debian_sources.changed | default(false)) + or (apt_config_updated_security_sources.changed | default(false)) + or (apt_config_updated_backports_sources.changed | default(false)) + or (apt_config_removed_backports_sources.changed | default(false)) + }} + when: + - apt_manage_sources_list|bool + - ansible_facts['distribution'] == 'Debian' + - (ansible_facts['distribution_major_version'] | int) >= 13 + tags: + - apt-configuration + - name: (apt.yml) apt update apt: update_cache: true @@ -29,7 +170,6 @@ - apt-compiler-pkgs - apt-webserver-pkgs - - name: (apt.yml) Configure any half-installed packages 'dpkg --configure -a' ansible.builtin.command: dpkg --configure -a register: _dpkg_configure @@ -43,7 +183,6 @@ - apt-compiler-pkgs - apt-webserver-pkgs - - name: (apt.yml) apt upgrade apt: upgrade: "{{ apt_upgrade_type }}" @@ -57,7 +196,6 @@ - apt-compiler-pkgs - apt-webserver-pkgs - - name: (apt.yml) Initial install debian packages (stretch) apt: name: "{{ apt_initial_install_stretch }}" @@ -69,11 +207,12 @@ tags: - apt-initial-install - - name: (apt.yml) Initial install debian packages (buster) apt: name: "{{ apt_initial_install_buster }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - apt_initial_install_buster is defined and apt_initial_install_buster|length > 0 - ansible_facts['distribution'] == "Debian" @@ -81,11 +220,12 @@ tags: - apt-initial-install - - name: (apt.yml) Initial install debian packages (bullseye) apt: name: "{{ apt_initial_install_bullseye }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - apt_initial_install_bullseye is defined and apt_initial_install_bullseye|length > 0 - ansible_facts['distribution'] == "Debian" @@ -93,11 +233,12 @@ tags: - apt-initial-install - - name: (apt.yml) Initial install debian packages (bookworm) apt: name: "{{ apt_initial_install_bookworm }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - apt_initial_install_bookworm is defined and apt_initial_install_bookworm|length > 0 - ansible_facts['distribution'] == "Debian" @@ -105,11 +246,12 @@ tags: - apt-initial-install - - name: (apt.yml) Initial install debian packages (trixie) apt: name: "{{ apt_initial_install_trixie }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - apt_initial_install_trixie is defined and apt_initial_install_trixie|length > 0 - ansible_facts['distribution'] == "Debian" @@ -117,11 +259,12 @@ tags: - apt-initial-install - - name: (apt.yml) Initial install ubuntu packages (bionic) apt: name: "{{ apt_initial_install_bionic }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - ansible_facts['distribution'] == "Ubuntu" - ansible_facts['distribution_release'] == "bionic" @@ -132,6 +275,8 @@ apt: name: "{{ apt_initial_install_xenial }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - ansible_facts['distribution'] == "Ubuntu" - ansible_facts['distribution_release'] == "xenial" @@ -142,6 +287,8 @@ apt: name: "{{ apt_initial_install_jammy }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - ansible_facts['distribution'] == "Ubuntu" - ansible_facts['distribution_release'] == "jammy" @@ -152,13 +299,14 @@ apt: name: "{{ apt_initial_install_ubuntu_noble }}" state: "{{ apt_install_state }}" + environment: + DEBIAN_FRONTEND: noninteractive when: - ansible_facts['distribution'] == "Ubuntu" - ansible_facts['distribution_release'] == "noble" tags: - apt-initial-install - # --- # Microcode # --- @@ -176,7 +324,6 @@ - apt-initial-install - apt-microcode - - name: (apt.yml) Install CPU microcode (debian buster/bullseye/bookworm/trixie) apt: name: "{{ microcode_package }}" @@ -190,7 +337,6 @@ - apt-initial-install - apt-microcode - - name: (apt.yml) Install CPU microcode (ubuntu bionic) apt: name: "{{ microcode_package }}" @@ -204,7 +350,6 @@ - apt-initial-install - apt-microcode - - name: (apt.yml) Install CPU microcode (ubuntu xenial) apt: name: "{{ microcode_package }}" @@ -218,7 +363,6 @@ - apt-initial-install - apt-microcode - - name: (apt.yml) Install CPU microcode (ubuntu jammy) apt: name: "{{ microcode_package }}" @@ -236,7 +380,7 @@ apt: name: "{{ apt_lxc_host_pkgs }}" state: "{{ apt_install_state }}" - when: + when: - groups['lxc_host']|string is search(inventory_hostname) tags: - apt-lxc-hosts-pkgs @@ -245,7 +389,7 @@ apt: name: "{{ apt_docker_host_pkgs }}" state: "{{ apt_install_state }}" - when: + when: - groups['docker_host']|string is search(inventory_hostname) tags: - apt-docker-hosts-pkgs @@ -254,7 +398,7 @@ apt: name: "{{ apt_kvm_host_pkgs }}" state: "{{ apt_install_state }}" - when: + when: - groups['kvm_host']|string is search(inventory_hostname) tags: - apt-kvm-hosts-pkgs @@ -263,7 +407,7 @@ apt: name: "{{ apt_kvm_host_buster_pkgs }}" state: "{{ apt_install_state }}" - when: + when: - groups['kvm_host']|string is search(inventory_hostname) - ansible_facts['distribution'] == "Debian" - ansible_facts['distribution_major_version'] == "10" @@ -290,10 +434,10 @@ apt: name: "{{ apt_webserver_pkgs }}" state: "{{ apt_install_state }}" - when: - - install_webserver_pkgs|bool - - ansible_facts['os_family'] == 'Debian' - - ansible_facts['distribution_major_version'] | int <= 12 + when: + - install_webserver_pkgs|bool + - ansible_facts['os_family'] == 'Debian' + - ansible_facts['distribution_major_version'] | int <= 12 tags: - apt-webserver-pkgs @@ -301,16 +445,16 @@ apt: name: "{{ apt_webserver_pkgs_trixie }}" state: "{{ apt_install_state }}" - when: - - install_webserver_pkgs|bool - - ansible_facts['os_family'] == 'Debian' - - ansible_facts['distribution_major_version'] | int >= 13 + when: + - install_webserver_pkgs|bool + - ansible_facts['os_family'] == 'Debian' + - ansible_facts['distribution_major_version'] | int >= 13 tags: - apt-webserver-pkgs - name: (apt.yml) Install samba related packages package: - pkg: '{{ apt_install_server_samba }}' + pkg: "{{ apt_install_server_samba }}" state: present when: - "groups['samba_server']|string is search(inventory_hostname)" @@ -378,9 +522,9 @@ stat: path: /usr/local/mysql/etc/my.cnf register: usr_local_mysql_etc_my_cnf - when: groups['mysql_server']|string is search(inventory_hostname) or - groups['apache2_webserver']|string is search(inventory_hostname) or - groups['nextcloud_server']|string is search(inventory_hostname) + when: groups['mysql_server']|string is search(inventory_hostname) or + groups['apache2_webserver']|string is search(inventory_hostname) or + groups['nextcloud_server']|string is search(inventory_hostname) tags: - apt-webserver-pkgs - apt-mysql-server-pkgs @@ -401,8 +545,8 @@ owner: root group: root state: link - when: - - (groups['mysql_server']|string is search(inventory_hostname) or + when: + - (groups['mysql_server']|string is search(inventory_hostname) or groups['apache2_webserver']|string is search(inventory_hostname) or groups['nextcloud_server']|string is search(inventory_hostname)) - usr_local_mysql_etc_my_cnf.stat.exists @@ -410,4 +554,3 @@ - apt-webserver-pkgs - apt-mysql-server-pkgs - check_mysql_cnf - diff --git a/roles/common/templates/etc/apt/deb822/backports.sources.j2 b/roles/common/templates/etc/apt/deb822/backports.sources.j2 new file mode 100644 index 0000000..b3a1c4b --- /dev/null +++ b/roles/common/templates/etc/apt/deb822/backports.sources.j2 @@ -0,0 +1,12 @@ +# {{ ansible_managed }} +# +# Managed by Ansible: deb822 definition for the Debian backports repository. +# It enables deb-src only when apt_src_enable is true and sets Signed-By only +# when apt_deb822_use_signed_by is enabled. +Types: {{ 'deb deb-src' if apt_src_enable | default(true) | bool else 'deb' }} +URIs: {{ apt_debian_mirror }} +Suites: {{ ansible_facts['distribution_release'] }}-backports +Components: main contrib non-free non-free-firmware +{% if apt_deb822_use_signed_by | default(true) | bool %} +Signed-By: {{ apt_deb822_signed_by_keyring | default('/usr/share/keyrings/debian-archive-keyring.gpg') }} +{% endif %} diff --git a/roles/common/templates/etc/apt/deb822/debian.sources.j2 b/roles/common/templates/etc/apt/deb822/debian.sources.j2 new file mode 100644 index 0000000..fb9fc0e --- /dev/null +++ b/roles/common/templates/etc/apt/deb822/debian.sources.j2 @@ -0,0 +1,10 @@ +# {{ ansible_managed }} +# +# Verwaltet via Ansible - Debian Basis & Updates fuer {{ ansible_facts['distribution_release'] }} +Types: {{ 'deb deb-src' if apt_src_enable | default(true) | bool else 'deb' }} +URIs: {{ apt_debian_mirror }} +Suites: {{ ansible_facts['distribution_release'] }} {{ ansible_facts['distribution_release'] }}-updates +Components: main contrib non-free non-free-firmware +{% if apt_deb822_use_signed_by | default(true) | bool %} +Signed-By: {{ apt_deb822_signed_by_keyring | default('/usr/share/keyrings/debian-archive-keyring.gpg') }} +{% endif %} diff --git a/roles/common/templates/etc/apt/deb822/security.sources.j2 b/roles/common/templates/etc/apt/deb822/security.sources.j2 new file mode 100644 index 0000000..318048d --- /dev/null +++ b/roles/common/templates/etc/apt/deb822/security.sources.j2 @@ -0,0 +1,10 @@ +# {{ ansible_managed }} +# +# Verwaltet via Ansible - Security fuer {{ ansible_facts['distribution_release'] }} +Types: {{ 'deb deb-src' if apt_src_enable | default(true) | bool else 'deb' }} +URIs: http://security.debian.org/debian-security +Suites: {{ ansible_facts['distribution_release'] }}-security +Components: main contrib non-free non-free-firmware +{% if apt_deb822_use_signed_by | default(true) | bool %} +Signed-By: {{ apt_deb822_signed_by_keyring | default('/usr/share/keyrings/debian-archive-keyring.gpg') }} +{% endif %}