No description
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| defaults | ||
| meta | ||
| tasks | ||
| .gitignore | ||
| LICENSE | ||
| README.md | ||
ansible-role-vikunja
Deploys Vikunja with rootless Podman.
References:
Example
- name: Setup Vikunja
hosts: vikunja
become: true
roles:
- role: vikunja
vikunja_public_url: https://tasks.example.com
vikunja_service_secret: "{{ vault_vikunja_service_secret }}"
vikunja_database_password: "{{ vault_vikunja_database_password }}"
By default this role creates a pod with:
vikunja-database, unlessvikunja_database_disabled: truevikunja, listening on127.0.0.1:3456
For an external PostgreSQL database, set:
vikunja_database_disabled: true
vikunja_database_host: db.example.com
vikunja_database_password: "{{ vault_vikunja_database_password }}"
Secrets
vikunja_service_secret is used by Vikunja to sign JWT tokens and for other
cryptographic operations. Keep it persistent across restarts; rotating it will
invalidate existing sessions. A good default format is 48 random bytes encoded
as Base64:
openssl rand -base64 48
The Vikunja container writes attachments and related files to
/app/vikunja/files. The upstream container runs as UID 1000 by default, but
the role runs the app container with the deployment user's rootless Podman user
mapping unless vikunja_container_user is explicitly set.