Ansible Playbooks, Roles etc for a home Proxmox host and its guest VMs.
Install external role dependencies before running any playbook:
ansible-galaxy install -r requirements.yml
Provisions the Proxmox host itself:
- Unattended-upgrades
- dropbear-luks: unlock the encrypted root over SSH at boot
- Installs Proxmox VE (
lae.proxmox) - Network bridge setup
- Host-level GPU passthrough prep
Runs against the Proxmox host to build/clone guest VMs:
- Downloads a Debian cloud image and builds a VM template (cloud-init, qemu-guest-agent)
- Clones the template to
vmdeb3(docker services VM), passing through GPU + scratch NVMe - Clones the template to
vmdeb-nas(NAS VM), passing through the NAS HDD - Applies VM perf tuning (virtio-scsi-single, iothread, multiqueue net) to both clones
- Lowers host
vm.swappinessto 10 for the VM-hosting workload
Provisions vmdeb3:
- Unattended-upgrades, i915 firmware, qemu-guest-agent, Docker
- 4G swapfile on
/scratch - Mounts the NAS share, and re-exports
/scratchback over NFS to the workstation - Generates an SSH key and checks out the docker-stuff config repo from git
- Runs the
cinemagedarrcompose stack via adocker compose upsystemd timer
Provisions vmdeb-nas:
- Unattended-upgrades, qemu-guest-agent
- 4G swapfile on root
- Unlocks the LUKS+LVM data volume, mounts
/data - Exports
/dataover NFS to the workstation andvmdeb3
Runs against localhost:
- Unattended-upgrades (Pop!_OS/System76 repos wildcarded, same as dietpi)
- autofs NFS automounts
- Flatpak, pyenv, and pip updaters
Provisions a DietPi host: bootstraps Python, unattended-upgrades, and unmasks the
apt-daily services/timers DietPi disables by default (breaks unattended-upgrades otherwise).
docker-backup: stops running containers and tars up docker-stuff onvmdeb3snapshot-vmdeb3: runs the same backup, then detachesvmdeb3's GPU/disk passthrough and takes a Proxmox snapshot (passthrough devices can't be snapshotted live)