No description
  • Shell 36%
  • Python 28%
  • Makefile 19.7%
  • Dockerfile 16.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Ymage 47dd24036c
All checks were successful
Build forgejo/ansible / build-images (push) Successful in 17m59s
ci: publish image to git.desord.re registry root
Set the workflow REGISTRY to git.desord.re so the image is pushed as
git.desord.re/forgejo/ansible, and update the README and AGENTS image
references accordingly.
2026-10-07 21:58:59 +02:00
.forgejo/workflows ci: publish image to git.desord.re registry root 2026-10-07 21:58:59 +02:00
build fix(dockerfile): harden production image and patch vendored msgpack CVE 2026-09-15 03:57:11 +02:00
tests chore: drop leftovers of the removed github tooling 2026-10-07 21:32:48 +02:00
.dockerignore chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.editorconfig chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.gitignore chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.gitleaks.toml chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.hadolint.yaml chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.markdownlint.json chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.secretlintrc.json chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.trivyignore chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
.yamllint.yml chore(lint): add lefthook hooks and lint/scan tooling configuration 2026-09-15 03:57:18 +02:00
AGENTS.md ci: publish image to git.desord.re registry root 2026-10-07 21:58:59 +02:00
CHANGELOG.md chore: drop leftovers of the removed github tooling 2026-10-07 21:32:48 +02:00
CLAUDE.md chore(repo): bump license year and add code-review guidelines 2026-09-15 03:57:43 +02:00
Dockerfile chore(deps): bump alpine, ansible-core, python deps and collections 2026-10-07 21:30:10 +02:00
lefthook.yml chore: drop leftovers of the removed github tooling 2026-10-07 21:32:48 +02:00
LICENSE chore(repo): bump license year and add code-review guidelines 2026-09-15 03:57:43 +02:00
Makefile chore: drop leftovers of the removed github tooling 2026-10-07 21:32:48 +02:00
README.md ci: publish image to git.desord.re registry root 2026-10-07 21:58:59 +02:00
requirements.txt chore(deps): bump alpine, ansible-core, python deps and collections 2026-10-07 21:30:10 +02:00
requirements.yml chore(deps): bump alpine, ansible-core, python deps and collections 2026-10-07 21:30:10 +02:00
REVIEW.md chore(repo): bump license year and add code-review guidelines 2026-09-15 03:57:43 +02:00

Ansible Container

Alpine-based Docker container for running Ansible with Mitogen optimization, Kubernetes tools, and multi-platform support.

Quick Start

# Check Ansible version
docker run --rm git.desord.re/forgejo/ansible ansible-playbook --version

# Run a playbook
docker run --rm -v $(pwd):/workspace -w /workspace git.desord.re/forgejo/ansible ansible-playbook playbook.yml

# Interactive shell
docker run --rm -it -v $(pwd):/workspace -w /workspace git.desord.re/forgejo/ansible bash

Environment Variables

The image needs no environment variables to run. The defaults below are baked in; override them with -e NAME=value when needed.

Variable Default Purpose
ANSIBLE_FORCE_COLOR True Colored output even when stdout is not a TTY. Set False to disable.
ANSIBLE_HOST_KEY_CHECKING False (via cfg) Skips SSH host-key verification. Set True for persistent hosts.
ANSIBLE_CONFIG /etc/ansible/ansible.cfg Point to a mounted config to override the baked-in defaults.
PIPX_HOME / PATH /pipx Location of the Ansible virtualenv. Do not change.

Common run-time inputs are passed by mounting, not env vars:

# SSH key and connecting to a remote host with host-key checking enabled
docker run --rm \
  -e ANSIBLE_HOST_KEY_CHECKING=True \
  -v $(pwd):/workspace -w /workspace \
  -v $HOME/.ssh/id_ed25519:/home/ansible/.ssh/id_ed25519:ro \
  git.desord.re/forgejo/ansible ansible-playbook -i inventory.yml playbook.yml

# Vault password via file
docker run --rm \
  -v $(pwd):/workspace -w /workspace \
  -v $(pwd)/.vault_pass:/home/ansible/.vault_pass:ro \
  git.desord.re/forgejo/ansible ansible-playbook --vault-password-file /home/ansible/.vault_pass playbook.yml

Features

  • Mitogen enabled by default (2-7x faster execution)
  • Kubernetes tools (kubectl, helm, kustomize)
  • Multi-platform (amd64, arm64)
  • Non-root user

Registry

docker pull git.desord.re/forgejo/ansible

Build

make ansible-build
make lint
make comprehensive-test

License

MIT License