├── .gitignore ├── LICENSE ├── README.md ├── ec2-setup.yml ├── group_vars └── all ├── hosts.example ├── roles ├── common │ ├── handlers │ │ └── main.yml │ ├── tasks │ │ └── main.yml │ └── templates │ │ ├── 10periodic.j2 │ │ ├── 50unattended-upgrades.j2 │ │ ├── env.sh.j2 │ │ └── timezone.j2 ├── monit │ ├── handlers │ │ └── main.yml │ ├── tasks │ │ └── main.yml │ └── templates │ │ ├── monitapp.conf.j2 │ │ └── monitrc.j2 ├── nginx │ ├── handlers │ │ └── main.yml │ ├── tasks │ │ └── main.yml │ └── templates │ │ ├── default.conf.j2 │ │ └── nginx.conf.j2 ├── postgresql │ ├── handlers │ │ └── main.yml │ ├── tasks │ │ └── main.yml │ └── templates │ │ └── postgresql.conf.j2 ├── ruby │ └── tasks │ │ └── main.yml ├── ufw │ └── tasks │ │ └── main.yml ├── unicorn │ ├── tasks │ │ └── main.yml │ └── templates │ │ └── unicorn.conf.j2 └── upstart │ ├── tasks │ └── main.yml │ └── templates │ └── upstart.conf.j2 └── server.yml /.gitignore: -------------------------------------------------------------------------------- 1 | hosts 2 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | Copyright (c) 2014 Daniel Romero 2 | 3 | MIT License 4 | 5 | Permission is hereby granted, free of charge, to any person obtaining 6 | a copy of this software and associated documentation files (the 7 | "Software"), to deal in the Software without restriction, including 8 | without limitation the rights to use, copy, modify, merge, publish, 9 | distribute, sublicense, and/or sell copies of the Software, and to 10 | permit persons to whom the Software is furnished to do so, subject to 11 | the following conditions: 12 | 13 | The above copyright notice and this permission notice shall be 14 | included in all copies or substantial portions of the Software. 15 | 16 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, 17 | EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF 18 | MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND 19 | NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE 20 | LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 21 | OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION 22 | WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 23 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Simple Ansible 2 | 3 | - Requires Ansible 1.6.1 or newer 4 | - Expects Ubuntu 14.04 LTS (64 bit) 5 | 6 | ## Info 7 | 8 | - This ROR stack can be on a single node or multiple nodes. 9 | The inventory file `hosts` defines the nodes in wich the stacks 10 | should be configured. 11 | 12 | ## Setup and use 13 | 14 | $ git clone https://github.com/infoslack/simple-ansible.git 15 | $ cd simple-ansible 16 | $ cp hosts.example hosts 17 | 18 | - Change the **app_name** variable located in `group_vars/all` to the name of your application. 19 | - Edit `hosts` and include the name servers `123.456.789.10` or `example.org`. 20 | - You can change the rules or the order of execution in `server.yml` 21 | 22 | Run the playbook: 23 | 24 | $ ansible-playbook -i hosts server.yml 25 | 26 | ## Contributing 27 | 28 | 1. Fork it ( https://github.com/[my-github-username]/versioning/fork ) 29 | 2. Create your feature branch (`git checkout -b my-new-feature`) 30 | 3. Commit your changes (`git commit -am 'Add some feature'`) 31 | 4. Push to the branch (`git push origin my-new-feature`) 32 | 5. Create a new Pull Request 33 | 34 | ## License 35 | 36 | simple-ansible is released under the [MIT license](https://github.com/infoslack/simple-ansible/blob/master/LICENSE) 37 | -------------------------------------------------------------------------------- /ec2-setup.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - hosts: local 3 | connection: local 4 | gather_facts: False 5 | 6 | tasks: 7 | - name: Provision an EC2 node 8 | ec2: 9 | key_name: infoslack 10 | group: ansible 11 | instance_type: t2.micro 12 | image: ami-d05e75b8 13 | ec2_url: ec2.us-east-1.amazonaws.com 14 | region: us-east-1 15 | vpc_subnet_id: subnet-5f698206 16 | wait: yes 17 | count: 1 18 | assign_public_ip: yes 19 | register: ec2 20 | 21 | # http://docs.ansible.com/ec2_module.html 22 | # Requirements: boto 23 | # Configure boto or set export: 24 | # 25 | # aws_access_key_id = somekeyid 26 | # aws_secret_access_key = someaccesskey 27 | -------------------------------------------------------------------------------- /group_vars/all: -------------------------------------------------------------------------------- 1 | --- 2 | # Setup: set according to your application needs 3 | 4 | # application name 5 | app_name: demo 6 | 7 | # RAILS_ENV 8 | rails_env: production 9 | 10 | # config timezone 11 | time_zone: 'America/Brasilia' 12 | 13 | # ruby select version to install 14 | ruby_version: ruby-2.2 15 | ruby_repo_install: 'deb [arch=amd64] http://apt.hellobits.com/ trusty main' 16 | ruby_url: http://apt.hellobits.com/hellobits.key 17 | 18 | # nginx installation 19 | nginx_url: http://nginx.org/keys/nginx_signing.key 20 | nginx_repo_install: 'deb http://nginx.org/packages/ubuntu/ trusty nginx' 21 | 22 | # nginx configure 23 | nginx_user: www-data 24 | nginx_group: www-data 25 | nginx_workers: 2 26 | nginx_connections: 1024 27 | nginx_port: 80 28 | nginx_hostname: localhost 29 | nginx_frame_opt: DENY #(DENY | SAMEORIGIN | ALLOW-FROM) 30 | nginx_accept_mutex: 'on' # if worker_processes > 1 change to on 31 | 32 | # unicorn config 33 | unicorn_workers: 2 34 | unicorn_timeout: 15 35 | 36 | # monit time config 37 | monit_time: 60 38 | 39 | # postgres installation 40 | psql_version: 9.4 41 | psql_repo: 'deb http://apt.postgresql.org/pub/repos/apt/ trusty-pgdg main' 42 | psql_url: https://www.postgresql.org/media/keys/ACCC4CF8.asc 43 | 44 | # postgres set configs 45 | dbname: demodb 46 | dbuser: demouser 47 | dbpassword: demopass 48 | -------------------------------------------------------------------------------- /hosts.example: -------------------------------------------------------------------------------- 1 | [web] 2 | server01 3 | -------------------------------------------------------------------------------- /roles/common/handlers/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: restart ntp 3 | service: name=ntp state=restarted 4 | 5 | - name: reload ntp 6 | service: name=ntp state=reloaded 7 | -------------------------------------------------------------------------------- /roles/common/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Set Rails Environment 3 | template: > 4 | src=env.sh.j2 5 | dest=/etc/profile.d/env.sh 6 | tags: setup 7 | 8 | - name: Install extra packages 9 | apt: "pkg={{item}} state=latest force=yes update_cache=yes" 10 | with_items: 11 | - build-essential 12 | - unattended-upgrades 13 | - git 14 | - ufw 15 | - ntp 16 | tags: setup 17 | 18 | - name: Copy config file NTP (Network Time Protocol) 19 | template: > 20 | src=timezone.j2 21 | dest=/etc/timezone 22 | tags: setup 23 | 24 | - name: Configure NTP 25 | command: dpkg-reconfigure --frontend noninteractive tzdata 26 | notify: restart ntp 27 | tags: setup 28 | 29 | - name: Create user for deploy 30 | user: > 31 | name=deploy 32 | group=www-data 33 | comment="Deploy user" 34 | state=present 35 | tags: setup 36 | 37 | - name: Add public key to authorized_keys 38 | authorized_key: > 39 | user=deploy 40 | state=present 41 | key="{{lookup('file', '~/.ssh/id_rsa.pub')}}" 42 | tags: pubkey 43 | 44 | # Add the public keys of the allowed list 45 | # Set up authorized_keys for the deploy user 46 | # 47 | #- name: Add authorized_keys for the deploy user 48 | # authorized_key: > 49 | # user=deploy 50 | # key="{{item}}" 51 | # 52 | # with_items: 53 | # - https://github.com/infoslack.keys 54 | # - https://github.com/example.keys 55 | # 56 | # or 57 | # 58 | # with_file: 59 | # - public_keys/infoslack 60 | # - public_keys/example 61 | 62 | - name: Configure unattended upgrades 63 | template: > 64 | src=50unattended-upgrades.j2 65 | dest=/etc/apt/apt.conf.d/50unattended-upgrades 66 | tags: setup 67 | 68 | - name: Configure time for unattended upgrades 69 | template: > 70 | src=10periodic.j2 71 | dest=/etc/apt/apt.conf.d/10periodic 72 | tags: setup 73 | -------------------------------------------------------------------------------- /roles/common/templates/10periodic.j2: -------------------------------------------------------------------------------- 1 | APT::Periodic::Update-Package-Lists "1"; 2 | APT::Periodic::Download-Upgradeable-Packages "1"; 3 | APT::Periodic::AutocleanInterval "7"; 4 | APT::Periodic::Unattended-Upgrade "1"; 5 | -------------------------------------------------------------------------------- /roles/common/templates/50unattended-upgrades.j2: -------------------------------------------------------------------------------- 1 | // Automatically upgrade packages from these (origin:archive) pairs 2 | Unattended-Upgrade::Allowed-Origins { 3 | "${distro_id}:${distro_codename}-security"; 4 | "${distro_id}:${distro_codename}-updates"; 5 | //"${distro_id}:${distro_codename}-proposed"; 6 | //"${distro_id}:${distro_codename}-backports"; 7 | }; 8 | 9 | // List of packages to not update (regexp are supported) 10 | Unattended-Upgrade::Package-Blacklist { 11 | //"vim"; 12 | //"libc6"; 13 | //"libc6-dev"; 14 | //"Blacklistlibc6-i686"; 15 | }; 16 | 17 | // This option allows you to control if on a unclean dpkg exit 18 | // unattended-upgrades will automatically run 19 | // dpkg --force-confold --configure -a 20 | // The default is true, to ensure updates keep getting installed 21 | //Unattended-Upgrade::AutoFixInterruptedDpkg "false"; 22 | 23 | // Split the upgrade into the smallest possible chunks so that 24 | // they can be interrupted with SIGUSR1. This makes the upgrade 25 | // a bit slower but it has the benefit that shutdown while a upgrade 26 | // is running is possible (with a small delay) 27 | //Unattended-Upgrade::MinimalSteps "true"; 28 | 29 | // Install all unattended-upgrades when the machine is shuting down 30 | // instead of doing it in the background while the machine is running 31 | // This will (obviously) make shutdown slower 32 | //Unattended-Upgrade::InstallOnShutdown "true"; 33 | 34 | // Send email to this address for problems or packages upgrades 35 | // If empty or unset then no email is sent, make sure that you 36 | // have a working mail setup on your system. A package that provides 37 | // 'mailx' must be installed. E.g. "user@example.com" 38 | //Unattended-Upgrade::Mail "root"; 39 | 40 | // Set this value to "true" to get emails only on errors. Default 41 | // is to always send a mail if Unattended-Upgrade::Mail is set 42 | //Unattended-Upgrade::MailOnlyOnError "true"; 43 | 44 | // Do automatic removal of new unused dependencies after the upgrade 45 | // (equivalent to apt-get autoremove) 46 | //Unattended-Upgrade::Remove-Unused-Dependencies "false"; 47 | 48 | // Automatically reboot *WITHOUT CONFIRMATION* 49 | // if the file /var/run/reboot-required is found after the upgrade 50 | //Unattended-Upgrade::Automatic-Reboot "false"; 51 | 52 | // If automatic reboot is enabled and needed, reboot at the specific 53 | // time instead of immediately 54 | // Default: "now" 55 | //Unattended-Upgrade::Automatic-Reboot-Time "02:00"; 56 | 57 | // Use apt bandwidth limit feature, this example limits the download 58 | // speed to 70kb/sec 59 | //Acquire::http::Dl-Limit "70"; 60 | -------------------------------------------------------------------------------- /roles/common/templates/env.sh.j2: -------------------------------------------------------------------------------- 1 | export RAILS_ENV="{{ rails_env }}" 2 | -------------------------------------------------------------------------------- /roles/common/templates/timezone.j2: -------------------------------------------------------------------------------- 1 | {{ time_zone }} 2 | -------------------------------------------------------------------------------- /roles/monit/handlers/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: restart monit 3 | service: name=monit state=restarted 4 | -------------------------------------------------------------------------------- /roles/monit/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Install monit 3 | apt: name=monit update_cache=yes 4 | 5 | - name: Configure monit 6 | template: > 7 | src=monitrc.j2 8 | dest=/etc/monit/monitrc 9 | 10 | - name: Add monit check rails app 11 | template: > 12 | src=monitapp.conf.j2 13 | dest=/etc/monit/conf.d/{{app_name}}.conf 14 | notify: restart monit 15 | -------------------------------------------------------------------------------- /roles/monit/templates/monitapp.conf.j2: -------------------------------------------------------------------------------- 1 | check file restart.txt with path /var/www/{{app_name}}/current/tmp/restart.txt 2 | if changed timestamp then restart 3 | stop program = "/sbin/stop {{app_name}}" 4 | start program = "/sbin/start {{app_name}}" 5 | -------------------------------------------------------------------------------- /roles/monit/templates/monitrc.j2: -------------------------------------------------------------------------------- 1 | set daemon {{monit_time}} 2 | 3 | set logfile /var/log/monit.log 4 | set idfile /var/lib/monit/id 5 | set statefile /var/lib/monit/state 6 | 7 | set eventqueue 8 | basedir /var/lib/monit/events 9 | slots 100 10 | 11 | include /etc/monit/conf.d/* 12 | -------------------------------------------------------------------------------- /roles/nginx/handlers/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: restart nginx 3 | service: name=nginx state=restarted 4 | -------------------------------------------------------------------------------- /roles/nginx/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Add the key used to sign the nginx packages and repository 3 | apt_key: url={{ nginx_url }} 4 | tags: nginx 5 | 6 | - name: Add repository for install nginx 7 | apt_repository: > 8 | repo='{{nginx_repo_install}}' 9 | state=present 10 | tags: nginx 11 | 12 | - name: Install nginx 13 | apt: > 14 | pkg=nginx 15 | update_cache=yes 16 | cache_valid_time=3600 17 | state=latest 18 | force=yes 19 | tags: nginx 20 | 21 | - name: Copy nginx file configuration 22 | template: > 23 | src=nginx.conf.j2 24 | dest=/etc/nginx/nginx.conf 25 | notify: restart nginx 26 | tags: 27 | - nginx 28 | - config 29 | 30 | - name: Copy example config default 31 | template: > 32 | src=default.conf.j2 33 | dest=/etc/nginx/sites/{{app_name}}.conf 34 | notify: restart nginx 35 | tags: 36 | - nginx 37 | - config 38 | 39 | - name: Create /var/www and set permissions 40 | file: > 41 | dest=/var/www 42 | state=directory 43 | recurse=yes 44 | owner=deploy 45 | group=www-data 46 | mode=774 47 | tags: 48 | - nginx 49 | - config 50 | -------------------------------------------------------------------------------- /roles/nginx/templates/default.conf.j2: -------------------------------------------------------------------------------- 1 | upstream {{app_name}} { 2 | server unix://tmp/{{app_name}}.sock fail_timeout=0; 3 | } 4 | 5 | server { 6 | listen {{nginx_port}}; 7 | client_max_body_size 2M; 8 | server_name {{nginx_hostname}}; 9 | keepalive_timeout 5; 10 | root /var/www/{{app_name}}/current/public; 11 | access_log off; 12 | error_log off; 13 | 14 | location ~ ^/(assets)/ { 15 | gzip_static on; 16 | expires max; 17 | add_header Cache-Control public; 18 | } 19 | 20 | location / { 21 | try_files $uri/index.html $uri.html $uri @app; 22 | error_page 404 /404.html; 23 | error_page 422 /422.html; 24 | error_page 500 502 503 504 /500.html; 25 | error_page 403 /403.html; 26 | } 27 | 28 | location @app { 29 | proxy_set_header X-Real-IP $remote_addr; 30 | proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; 31 | proxy_set_header Host $http_host; 32 | proxy_set_header X-Forwarded-Proto $scheme; 33 | proxy_redirect off; 34 | proxy_pass http://{{app_name}}; 35 | } 36 | 37 | location = /favicon.ico { 38 | expires max; 39 | add_header Cache-Control public; 40 | } 41 | 42 | location ~ \.php$ { 43 | deny all; 44 | } 45 | } 46 | -------------------------------------------------------------------------------- /roles/nginx/templates/nginx.conf.j2: -------------------------------------------------------------------------------- 1 | user {{nginx_user}} {{nginx_group}}; 2 | worker_processes {{nginx_workers}}; 3 | pid /var/run/nginx.pid; 4 | 5 | events { 6 | worker_connections {{nginx_connections}}; 7 | accept_mutex {{nginx_accept_mutex}}; 8 | use epoll; 9 | } 10 | 11 | http { 12 | include /etc/nginx/mime.types; 13 | default_type application/octet-stream; 14 | 15 | log_format main '$remote_addr - $remote_user [$time_local] ' 16 | '"$request" $status $body_bytes_sent "$http_referer" ' 17 | '"$http_user_agent" "$http_x_forwarded_for"'; 18 | 19 | sendfile on; 20 | keepalive_requests 10; 21 | keepalive_timeout 30; 22 | tcp_nodelay off; 23 | tcp_nopush on; 24 | 25 | add_header X-Content-Type-Options nosniff; 26 | add_header X-Frame-Options {{nginx_frame_opt}}; 27 | add_header X-XSS-Protection "1; mode=block"; 28 | add_header Strict-Transport-Security max-age=31536000; 29 | 30 | server_tokens off; 31 | client_header_timeout 60; 32 | client_body_timeout 60; 33 | ignore_invalid_headers on; 34 | send_timeout 60; 35 | server_name_in_redirect off; 36 | large_client_header_buffers 2 2k; 37 | server_names_hash_max_size 4096; 38 | types_hash_max_size 4096; 39 | 40 | gzip on; 41 | gzip_http_version 1.1; 42 | gzip_comp_level 6; 43 | gzip_min_length 500; 44 | gzip_proxied any; 45 | gzip_disable "MSIE [1-6] \."; 46 | gzip_types text/plain text/css application/x-javascript text/xml 47 | application/xml application/xml+rss text/javascript 48 | image/svg+xml; 49 | 50 | include /etc/nginx/sites/*; 51 | } 52 | -------------------------------------------------------------------------------- /roles/postgresql/handlers/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: restart postgresql 3 | service: name=postgresql state=restarted 4 | -------------------------------------------------------------------------------- /roles/postgresql/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Add GPG Key for PostgreSQL install 3 | apt_key: url={{psql_url}} 4 | tags: postgresql 5 | 6 | - name: Add repository for install PostgreSQL 7 | apt_repository: > 8 | repo='{{psql_repo}}' 9 | state=present 10 | tags: postgresql 11 | 12 | - name: Install PostgreSQL 13 | apt: "pkg={{item}} state=latest force=yes update_cache=yes" 14 | with_items: 15 | - postgresql-{{psql_version}} 16 | - postgresql-contrib-{{psql_version}} 17 | - libpq-dev 18 | - python-psycopg2 19 | tags: postgresql 20 | 21 | - name: Copy custom config and restart 22 | template: > 23 | src=postgresql.conf.j2 24 | dest=/etc/postgresql/{{psql_version}}/main/postgresql.conf 25 | notify: restart postgresql 26 | tags: 27 | - postgresql 28 | - config 29 | 30 | - name: PostgreSQL add extensions 31 | sudo_user: postgres 32 | command: > 33 | psql template1 -c 'CREATE EXTENSION IF NOT EXISTS "{{item}}"' 34 | with_items: 35 | - hstore 36 | - citext 37 | tags: 38 | - postgresql 39 | - config 40 | 41 | - name: Create database 42 | sudo_user: postgres 43 | postgresql_db: > 44 | name={{dbname}} 45 | state=present 46 | encoding='UTF-8' 47 | tags: 48 | - postgresql 49 | - config 50 | - createdb 51 | 52 | - name: Ensure user has access to database 53 | sudo_user: postgres 54 | postgresql_user: > 55 | db={{dbname}} 56 | name={{dbuser}} 57 | password={{dbpassword}} 58 | priv=ALL 59 | tags: 60 | - postgresql 61 | - config 62 | - createuser 63 | 64 | - name: Ensure user does not have unnecessary privilege 65 | sudo_user: postgres 66 | postgresql_user: name={{dbuser}} role_attr_flags=NOSUPERUSER,NOCREATEDB 67 | tags: 68 | - postgresql 69 | - config 70 | - privileges 71 | -------------------------------------------------------------------------------- /roles/postgresql/templates/postgresql.conf.j2: -------------------------------------------------------------------------------- 1 | # ----------------------------- 2 | # PostgreSQL configuration file 3 | # ----------------------------- 4 | # 5 | # This file consists of lines of the form: 6 | # 7 | # name = value 8 | # 9 | # (The "=" is optional.) Whitespace may be used. Comments are introduced with 10 | # "#" anywhere on a line. The complete list of parameter names and allowed 11 | # values can be found in the PostgreSQL documentation. 12 | # 13 | # The commented-out settings shown in this file represent the default values. 14 | # Re-commenting a setting is NOT sufficient to revert it to the default value; 15 | # you need to reload the server. 16 | # 17 | # This file is read on server startup and when the server receives a SIGHUP 18 | # signal. If you edit the file on a running system, you have to SIGHUP the 19 | # server for the changes to take effect, or use "pg_ctl reload". Some 20 | # parameters, which are marked below, require a server shutdown and restart to 21 | # take effect. 22 | # 23 | # Any parameter can also be given as a command-line option to the server, e.g., 24 | # "postgres -c log_connections=on". Some parameters can be changed at run time 25 | # with the "SET" SQL command. 26 | # 27 | # Memory units: kB = kilobytes Time units: ms = milliseconds 28 | # MB = megabytes s = seconds 29 | # GB = gigabytes min = minutes 30 | # h = hours 31 | # d = days 32 | 33 | 34 | #------------------------------------------------------------------------------ 35 | # FILE LOCATIONS 36 | #------------------------------------------------------------------------------ 37 | 38 | # The default values of these variables are driven from the -D command-line 39 | # option or PGDATA environment variable, represented here as ConfigDir. 40 | 41 | data_directory = '/var/lib/postgresql/9.4/main' # use data in another directory 42 | # (change requires restart) 43 | hba_file = '/etc/postgresql/9.4/main/pg_hba.conf' # host-based authentication file 44 | # (change requires restart) 45 | ident_file = '/etc/postgresql/9.4/main/pg_ident.conf' # ident configuration file 46 | # (change requires restart) 47 | 48 | # If external_pid_file is not explicitly set, no extra PID file is written. 49 | external_pid_file = '/var/run/postgresql/9.4-main.pid' # write an extra PID file 50 | # (change requires restart) 51 | 52 | 53 | #------------------------------------------------------------------------------ 54 | # CONNECTIONS AND AUTHENTICATION 55 | #------------------------------------------------------------------------------ 56 | 57 | # - Connection Settings - 58 | 59 | #listen_addresses = 'localhost' # what IP address(es) to listen on; 60 | # comma-separated list of addresses; 61 | # defaults to 'localhost'; use '*' for all 62 | # (change requires restart) 63 | port = 5432 # (change requires restart) 64 | max_connections = 100 # (change requires restart) 65 | # Note: Increasing max_connections costs ~400 bytes of shared memory per 66 | # connection slot, plus lock space (see max_locks_per_transaction). 67 | #superuser_reserved_connections = 3 # (change requires restart) 68 | unix_socket_directories = '/var/run/postgresql' # comma-separated list of directories 69 | # (change requires restart) 70 | #unix_socket_group = '' # (change requires restart) 71 | #unix_socket_permissions = 0777 # begin with 0 to use octal notation 72 | # (change requires restart) 73 | #bonjour = off # advertise server via Bonjour 74 | # (change requires restart) 75 | #bonjour_name = '' # defaults to the computer name 76 | # (change requires restart) 77 | 78 | # - Security and Authentication - 79 | 80 | #authentication_timeout = 1min # 1s-600s 81 | ssl = true # (change requires restart) 82 | #ssl_ciphers = 'DEFAULT:!LOW:!EXP:!MD5:@STRENGTH' # allowed SSL ciphers 83 | # (change requires restart) 84 | #ssl_renegotiation_limit = 512MB # amount of data between renegotiations 85 | ssl_cert_file = '/etc/ssl/certs/ssl-cert-snakeoil.pem' # (change requires restart) 86 | ssl_key_file = '/etc/ssl/private/ssl-cert-snakeoil.key' # (change requires restart) 87 | #ssl_ca_file = '' # (change requires restart) 88 | #ssl_crl_file = '' # (change requires restart) 89 | #password_encryption = on 90 | #db_user_namespace = off 91 | 92 | # Kerberos and GSSAPI 93 | #krb_server_keyfile = '' 94 | #krb_srvname = 'postgres' # (Kerberos only) 95 | #krb_caseins_users = off 96 | 97 | # - TCP Keepalives - 98 | # see "man 7 tcp" for details 99 | 100 | #tcp_keepalives_idle = 0 # TCP_KEEPIDLE, in seconds; 101 | # 0 selects the system default 102 | #tcp_keepalives_interval = 0 # TCP_KEEPINTVL, in seconds; 103 | # 0 selects the system default 104 | #tcp_keepalives_count = 0 # TCP_KEEPCNT; 105 | # 0 selects the system default 106 | 107 | 108 | #------------------------------------------------------------------------------ 109 | # RESOURCE USAGE (except WAL) 110 | #------------------------------------------------------------------------------ 111 | 112 | # - Memory - 113 | 114 | shared_buffers = 128MB # min 128kB 115 | # (change requires restart) 116 | #temp_buffers = 8MB # min 800kB 117 | #max_prepared_transactions = 0 # zero disables the feature 118 | # (change requires restart) 119 | # Note: Increasing max_prepared_transactions costs ~600 bytes of shared memory 120 | # per transaction slot, plus lock space (see max_locks_per_transaction). 121 | # It is not advisable to set max_prepared_transactions nonzero unless you 122 | # actively intend to use prepared transactions. 123 | #work_mem = 1MB # min 64kB 124 | #maintenance_work_mem = 16MB # min 1MB 125 | #max_stack_depth = 2MB # min 100kB 126 | 127 | # - Disk - 128 | 129 | #temp_file_limit = -1 # limits per-session temp file space 130 | # in kB, or -1 for no limit 131 | 132 | # - Kernel Resource Usage - 133 | 134 | #max_files_per_process = 1000 # min 25 135 | # (change requires restart) 136 | #shared_preload_libraries = '' # (change requires restart) 137 | 138 | # - Cost-Based Vacuum Delay - 139 | 140 | #vacuum_cost_delay = 0 # 0-100 milliseconds 141 | #vacuum_cost_page_hit = 1 # 0-10000 credits 142 | #vacuum_cost_page_miss = 10 # 0-10000 credits 143 | #vacuum_cost_page_dirty = 20 # 0-10000 credits 144 | #vacuum_cost_limit = 200 # 1-10000 credits 145 | 146 | # - Background Writer - 147 | 148 | #bgwriter_delay = 200ms # 10-10000ms between rounds 149 | #bgwriter_lru_maxpages = 100 # 0-1000 max buffers written/round 150 | #bgwriter_lru_multiplier = 2.0 # 0-10.0 multipler on buffers scanned/round 151 | 152 | # - Asynchronous Behavior - 153 | 154 | #effective_io_concurrency = 1 # 1-1000; 0 disables prefetching 155 | 156 | 157 | #------------------------------------------------------------------------------ 158 | # WRITE AHEAD LOG 159 | #------------------------------------------------------------------------------ 160 | 161 | # - Settings - 162 | 163 | #wal_level = minimal # minimal, archive, or hot_standby 164 | # (change requires restart) 165 | #fsync = on # turns forced synchronization on or off 166 | #synchronous_commit = on # synchronization level; 167 | # off, local, remote_write, or on 168 | #wal_sync_method = fsync # the default is the first option 169 | # supported by the operating system: 170 | # open_datasync 171 | # fdatasync (default on Linux) 172 | # fsync 173 | # fsync_writethrough 174 | # open_sync 175 | #full_page_writes = on # recover from partial page writes 176 | #wal_buffers = -1 # min 32kB, -1 sets based on shared_buffers 177 | # (change requires restart) 178 | #wal_writer_delay = 200ms # 1-10000 milliseconds 179 | 180 | #commit_delay = 0 # range 0-100000, in microseconds 181 | #commit_siblings = 5 # range 1-1000 182 | 183 | # - Checkpoints - 184 | 185 | #checkpoint_segments = 3 # in logfile segments, min 1, 16MB each 186 | #checkpoint_timeout = 5min # range 30s-1h 187 | #checkpoint_completion_target = 0.5 # checkpoint target duration, 0.0 - 1.0 188 | #checkpoint_warning = 30s # 0 disables 189 | 190 | # - Archiving - 191 | 192 | #archive_mode = off # allows archiving to be done 193 | # (change requires restart) 194 | #archive_command = '' # command to use to archive a logfile segment 195 | # placeholders: %p = path of file to archive 196 | # %f = file name only 197 | # e.g. 'test ! -f /mnt/server/archivedir/%f && cp %p /mnt/server/archivedir/%f' 198 | #archive_timeout = 0 # force a logfile segment switch after this 199 | # number of seconds; 0 disables 200 | 201 | 202 | #------------------------------------------------------------------------------ 203 | # REPLICATION 204 | #------------------------------------------------------------------------------ 205 | 206 | # - Sending Server(s) - 207 | 208 | # Set these on the master and on any standby that will send replication data. 209 | 210 | #max_wal_senders = 0 # max number of walsender processes 211 | # (change requires restart) 212 | #wal_keep_segments = 0 # in logfile segments, 16MB each; 0 disables 213 | #wal_sender_timeout = 60s # in milliseconds; 0 disables 214 | 215 | # - Master Server - 216 | 217 | # These settings are ignored on a standby server. 218 | 219 | #synchronous_standby_names = '' # standby servers that provide sync rep 220 | # comma-separated list of application_name 221 | # from standby(s); '*' = all 222 | #vacuum_defer_cleanup_age = 0 # number of xacts by which cleanup is delayed 223 | 224 | # - Standby Servers - 225 | 226 | # These settings are ignored on a master server. 227 | 228 | #hot_standby = off # "on" allows queries during recovery 229 | # (change requires restart) 230 | #max_standby_archive_delay = 30s # max delay before canceling queries 231 | # when reading WAL from archive; 232 | # -1 allows indefinite delay 233 | #max_standby_streaming_delay = 30s # max delay before canceling queries 234 | # when reading streaming WAL; 235 | # -1 allows indefinite delay 236 | #wal_receiver_status_interval = 10s # send replies at least this often 237 | # 0 disables 238 | #hot_standby_feedback = off # send info from standby to prevent 239 | # query conflicts 240 | #wal_receiver_timeout = 60s # time that receiver waits for 241 | # communication from master 242 | # in milliseconds; 0 disables 243 | 244 | 245 | #------------------------------------------------------------------------------ 246 | # QUERY TUNING 247 | #------------------------------------------------------------------------------ 248 | 249 | # - Planner Method Configuration - 250 | 251 | #enable_bitmapscan = on 252 | #enable_hashagg = on 253 | #enable_hashjoin = on 254 | #enable_indexscan = on 255 | #enable_indexonlyscan = on 256 | #enable_material = on 257 | #enable_mergejoin = on 258 | #enable_nestloop = on 259 | #enable_seqscan = on 260 | #enable_sort = on 261 | #enable_tidscan = on 262 | 263 | # - Planner Cost Constants - 264 | 265 | #seq_page_cost = 1.0 # measured on an arbitrary scale 266 | #random_page_cost = 4.0 # same scale as above 267 | #cpu_tuple_cost = 0.01 # same scale as above 268 | #cpu_index_tuple_cost = 0.005 # same scale as above 269 | #cpu_operator_cost = 0.0025 # same scale as above 270 | #effective_cache_size = 128MB 271 | 272 | # - Genetic Query Optimizer - 273 | 274 | #geqo = on 275 | #geqo_threshold = 12 276 | #geqo_effort = 5 # range 1-10 277 | #geqo_pool_size = 0 # selects default based on effort 278 | #geqo_generations = 0 # selects default based on effort 279 | #geqo_selection_bias = 2.0 # range 1.5-2.0 280 | #geqo_seed = 0.0 # range 0.0-1.0 281 | 282 | # - Other Planner Options - 283 | 284 | #default_statistics_target = 100 # range 1-10000 285 | #constraint_exclusion = partition # on, off, or partition 286 | #cursor_tuple_fraction = 0.1 # range 0.0-1.0 287 | #from_collapse_limit = 8 288 | #join_collapse_limit = 8 # 1 disables collapsing of explicit 289 | # JOIN clauses 290 | 291 | 292 | #------------------------------------------------------------------------------ 293 | # ERROR REPORTING AND LOGGING 294 | #------------------------------------------------------------------------------ 295 | 296 | # - Where to Log - 297 | 298 | #log_destination = 'stderr' # Valid values are combinations of 299 | # stderr, csvlog, syslog, and eventlog, 300 | # depending on platform. csvlog 301 | # requires logging_collector to be on. 302 | 303 | # This is used when logging to stderr: 304 | #logging_collector = off # Enable capturing of stderr and csvlog 305 | # into log files. Required to be on for 306 | # csvlogs. 307 | # (change requires restart) 308 | 309 | # These are only used if logging_collector is on: 310 | #log_directory = 'pg_log' # directory where log files are written, 311 | # can be absolute or relative to PGDATA 312 | #log_filename = 'postgresql-%Y-%m-%d_%H%M%S.log' # log file name pattern, 313 | # can include strftime() escapes 314 | #log_file_mode = 0600 # creation mode for log files, 315 | # begin with 0 to use octal notation 316 | #log_truncate_on_rotation = off # If on, an existing log file with the 317 | # same name as the new log file will be 318 | # truncated rather than appended to. 319 | # But such truncation only occurs on 320 | # time-driven rotation, not on restarts 321 | # or size-driven rotation. Default is 322 | # off, meaning append to existing files 323 | # in all cases. 324 | #log_rotation_age = 1d # Automatic rotation of logfiles will 325 | # happen after that time. 0 disables. 326 | #log_rotation_size = 10MB # Automatic rotation of logfiles will 327 | # happen after that much log output. 328 | # 0 disables. 329 | 330 | # These are relevant when logging to syslog: 331 | #syslog_facility = 'LOCAL0' 332 | #syslog_ident = 'postgres' 333 | 334 | # This is only relevant when logging to eventlog (win32): 335 | #event_source = 'PostgreSQL' 336 | 337 | # - When to Log - 338 | 339 | #client_min_messages = notice # values in order of decreasing detail: 340 | # debug5 341 | # debug4 342 | # debug3 343 | # debug2 344 | # debug1 345 | # log 346 | # notice 347 | # warning 348 | # error 349 | 350 | #log_min_messages = warning # values in order of decreasing detail: 351 | # debug5 352 | # debug4 353 | # debug3 354 | # debug2 355 | # debug1 356 | # info 357 | # notice 358 | # warning 359 | # error 360 | # log 361 | # fatal 362 | # panic 363 | 364 | #log_min_error_statement = error # values in order of decreasing detail: 365 | # debug5 366 | # debug4 367 | # debug3 368 | # debug2 369 | # debug1 370 | # info 371 | # notice 372 | # warning 373 | # error 374 | # log 375 | # fatal 376 | # panic (effectively off) 377 | 378 | #log_min_duration_statement = -1 # -1 is disabled, 0 logs all statements 379 | # and their durations, > 0 logs only 380 | # statements running at least this number 381 | # of milliseconds 382 | 383 | 384 | # - What to Log - 385 | 386 | #debug_print_parse = off 387 | #debug_print_rewritten = off 388 | #debug_print_plan = off 389 | #debug_pretty_print = on 390 | #log_checkpoints = off 391 | #log_connections = off 392 | #log_disconnections = off 393 | #log_duration = off 394 | #log_error_verbosity = default # terse, default, or verbose messages 395 | #log_hostname = off 396 | log_line_prefix = '%t ' # special values: 397 | # %a = application name 398 | # %u = user name 399 | # %d = database name 400 | # %r = remote host and port 401 | # %h = remote host 402 | # %p = process ID 403 | # %t = timestamp without milliseconds 404 | # %m = timestamp with milliseconds 405 | # %i = command tag 406 | # %e = SQL state 407 | # %c = session ID 408 | # %l = session line number 409 | # %s = session start timestamp 410 | # %v = virtual transaction ID 411 | # %x = transaction ID (0 if none) 412 | # %q = stop here in non-session 413 | # processes 414 | # %% = '%' 415 | # e.g. '<%u%%%d> ' 416 | #log_lock_waits = off # log lock waits >= deadlock_timeout 417 | #log_statement = 'none' # none, ddl, mod, all 418 | #log_temp_files = -1 # log temporary files equal or larger 419 | # than the specified size in kilobytes; 420 | # -1 disables, 0 logs all temp files 421 | log_timezone = 'localtime' 422 | 423 | 424 | #------------------------------------------------------------------------------ 425 | # RUNTIME STATISTICS 426 | #------------------------------------------------------------------------------ 427 | 428 | # - Query/Index Statistics Collector - 429 | 430 | #track_activities = on 431 | #track_counts = on 432 | #track_io_timing = off 433 | #track_functions = none # none, pl, all 434 | #track_activity_query_size = 1024 # (change requires restart) 435 | #update_process_title = on 436 | #stats_temp_directory = 'pg_stat_tmp' 437 | 438 | 439 | # - Statistics Monitoring - 440 | 441 | #log_parser_stats = off 442 | #log_planner_stats = off 443 | #log_executor_stats = off 444 | #log_statement_stats = off 445 | 446 | 447 | #------------------------------------------------------------------------------ 448 | # AUTOVACUUM PARAMETERS 449 | #------------------------------------------------------------------------------ 450 | 451 | #autovacuum = on # Enable autovacuum subprocess? 'on' 452 | # requires track_counts to also be on. 453 | #log_autovacuum_min_duration = -1 # -1 disables, 0 logs all actions and 454 | # their durations, > 0 logs only 455 | # actions running at least this number 456 | # of milliseconds. 457 | #autovacuum_max_workers = 3 # max number of autovacuum subprocesses 458 | # (change requires restart) 459 | #autovacuum_naptime = 1min # time between autovacuum runs 460 | #autovacuum_vacuum_threshold = 50 # min number of row updates before 461 | # vacuum 462 | #autovacuum_analyze_threshold = 50 # min number of row updates before 463 | # analyze 464 | #autovacuum_vacuum_scale_factor = 0.2 # fraction of table size before vacuum 465 | #autovacuum_analyze_scale_factor = 0.1 # fraction of table size before analyze 466 | #autovacuum_freeze_max_age = 200000000 # maximum XID age before forced vacuum 467 | # (change requires restart) 468 | #autovacuum_multixact_freeze_max_age = 400000000 # maximum Multixact age 469 | # before forced vacuum 470 | # (change requires restart) 471 | #autovacuum_vacuum_cost_delay = 20ms # default vacuum cost delay for 472 | # autovacuum, in milliseconds; 473 | # -1 means use vacuum_cost_delay 474 | #autovacuum_vacuum_cost_limit = -1 # default vacuum cost limit for 475 | # autovacuum, -1 means use 476 | # vacuum_cost_limit 477 | 478 | 479 | #------------------------------------------------------------------------------ 480 | # CLIENT CONNECTION DEFAULTS 481 | #------------------------------------------------------------------------------ 482 | 483 | # - Statement Behavior - 484 | 485 | #search_path = '"$user",public' # schema names 486 | #default_tablespace = '' # a tablespace name, '' uses the default 487 | #temp_tablespaces = '' # a list of tablespace names, '' uses 488 | # only default tablespace 489 | #check_function_bodies = on 490 | #default_transaction_isolation = 'read committed' 491 | #default_transaction_read_only = off 492 | #default_transaction_deferrable = off 493 | #session_replication_role = 'origin' 494 | #statement_timeout = 0 # in milliseconds, 0 is disabled 495 | #lock_timeout = 0 # in milliseconds, 0 is disabled 496 | #vacuum_freeze_min_age = 50000000 497 | #vacuum_freeze_table_age = 150000000 498 | #vacuum_multixact_freeze_min_age = 5000000 499 | #vacuum_multixact_freeze_table_age = 150000000 500 | #bytea_output = 'hex' # hex, escape 501 | #xmlbinary = 'base64' 502 | #xmloption = 'content' 503 | 504 | # - Locale and Formatting - 505 | 506 | datestyle = 'iso, mdy' 507 | #intervalstyle = 'postgres' 508 | timezone = 'localtime' 509 | #timezone_abbreviations = 'Default' # Select the set of available time zone 510 | # abbreviations. Currently, there are 511 | # Default 512 | # Australia 513 | # India 514 | # You can create your own file in 515 | # share/timezonesets/. 516 | #extra_float_digits = 0 # min -15, max 3 517 | #client_encoding = sql_ascii # actually, defaults to database 518 | # encoding 519 | 520 | # These settings are initialized by initdb, but they can be changed. 521 | lc_messages = 'en_US.UTF-8' # locale for system error message 522 | # strings 523 | lc_monetary = 'en_US.UTF-8' # locale for monetary formatting 524 | lc_numeric = 'en_US.UTF-8' # locale for number formatting 525 | lc_time = 'en_US.UTF-8' # locale for time formatting 526 | 527 | # default configuration for text search 528 | default_text_search_config = 'pg_catalog.english' 529 | 530 | # - Other Defaults - 531 | 532 | #dynamic_library_path = '$libdir' 533 | #local_preload_libraries = '' 534 | 535 | 536 | #------------------------------------------------------------------------------ 537 | # LOCK MANAGEMENT 538 | #------------------------------------------------------------------------------ 539 | 540 | #deadlock_timeout = 1s 541 | #max_locks_per_transaction = 64 # min 10 542 | # (change requires restart) 543 | # Note: Each lock table slot uses ~270 bytes of shared memory, and there are 544 | # max_locks_per_transaction * (max_connections + max_prepared_transactions) 545 | # lock table slots. 546 | #max_pred_locks_per_transaction = 64 # min 10 547 | # (change requires restart) 548 | 549 | 550 | #------------------------------------------------------------------------------ 551 | # VERSION/PLATFORM COMPATIBILITY 552 | #------------------------------------------------------------------------------ 553 | 554 | # - Previous PostgreSQL Versions - 555 | 556 | #array_nulls = on 557 | #backslash_quote = safe_encoding # on, off, or safe_encoding 558 | #default_with_oids = off 559 | #escape_string_warning = on 560 | #lo_compat_privileges = off 561 | #quote_all_identifiers = off 562 | #sql_inheritance = on 563 | #standard_conforming_strings = on 564 | #synchronize_seqscans = on 565 | 566 | # - Other Platforms and Clients - 567 | 568 | #transform_null_equals = off 569 | 570 | 571 | #------------------------------------------------------------------------------ 572 | # ERROR HANDLING 573 | #------------------------------------------------------------------------------ 574 | 575 | #exit_on_error = off # terminate session on any error? 576 | #restart_after_crash = on # reinitialize after backend crash? 577 | 578 | 579 | #------------------------------------------------------------------------------ 580 | # CONFIG FILE INCLUDES 581 | #------------------------------------------------------------------------------ 582 | 583 | # These options allow settings to be loaded from files other than the 584 | # default postgresql.conf. 585 | 586 | #include_dir = 'conf.d' # include files ending in '.conf' from 587 | # directory 'conf.d' 588 | #include_if_exists = 'exists.conf' # include file only if it exists 589 | #include = 'special.conf' # include file 590 | 591 | 592 | #------------------------------------------------------------------------------ 593 | # CUSTOMIZED OPTIONS 594 | #------------------------------------------------------------------------------ 595 | 596 | # Add settings for extensions here 597 | -------------------------------------------------------------------------------- /roles/ruby/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Add GPG Key hellobits.com for ruby install 3 | apt_key: url={{ ruby_url }} 4 | tags: ruby 5 | 6 | - name: Add repository for ruby install 7 | apt_repository: > 8 | repo='{{ruby_repo_install}}' 9 | state=present 10 | tags: ruby 11 | 12 | - name: Install Ruby 13 | apt: > 14 | pkg={{ ruby_version }} 15 | update_cache=yes 16 | cache_valid_time=3600 17 | state=latest 18 | force=yes 19 | tags: ruby 20 | 21 | - name: Gem install bundler 22 | gem: > 23 | name=bundler 24 | user_install=no 25 | state=latest 26 | tags: ruby 27 | -------------------------------------------------------------------------------- /roles/ufw/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: UFW - set default policy 3 | ufw: policy=deny 4 | 5 | - name: UFW - enable logging 6 | ufw: logging=on 7 | 8 | - name: UFW - allow services 9 | ufw: rule=allow port={{ item }} 10 | with_items: 11 | - 80 12 | - 22 13 | #enable vagrant - 2222 14 | 15 | - name: UFW - enabled 16 | ufw: state=enabled 17 | -------------------------------------------------------------------------------- /roles/unicorn/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Create dir unicorn config 3 | command: mkdir -p /etc/unicorn 4 | 5 | - name: Configure unicorn for project 6 | template: > 7 | src=unicorn.conf.j2 8 | dest=/etc/unicorn/{{app_name}}.rb 9 | -------------------------------------------------------------------------------- /roles/unicorn/templates/unicorn.conf.j2: -------------------------------------------------------------------------------- 1 | worker_processes Integer(ENV["WEB_CONCURRENCY"] || {{ unicorn_workers }}) 2 | timeout {{ unicorn_timeout }} 3 | preload_app true 4 | listen "/tmp/{{ app_name }}.sock" 5 | 6 | pid "/var/run/unicorn/{{ app_name }}.pid" 7 | stdout_path "/var/log/unicorn/{{ app_name }}.log" 8 | stderr_path "/var/log/unicorn/{{ app_name }}-errors.log" 9 | working_directory "/var/www/{{ app_name }}/current" 10 | 11 | before_fork do |server, worker| 12 | Signal.trap 'TERM' do 13 | puts 'Unicorn master intercepting TERM and sending myself QUIT instead' 14 | Process.kill 'QUIT', Process.pid 15 | end 16 | 17 | defined?(ActiveRecord::Base) and ActiveRecord::Base.connection.disconnect! 18 | end 19 | 20 | after_fork do |server, worker| 21 | Signal.trap 'TERM' do 22 | puts 'Unicorn worker intercepting TERM and doing nothing. Wait for master to send QUIT' 23 | end 24 | 25 | defined?(ActiveRecord::Base) and ActiveRecord::Base.establish_connection 26 | end 27 | -------------------------------------------------------------------------------- /roles/upstart/tasks/main.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: Configure upstart for app 3 | template: > 4 | src=upstart.conf.j2 5 | dest=/etc/init/{{app_name}}.conf 6 | tags: upstart 7 | -------------------------------------------------------------------------------- /roles/upstart/templates/upstart.conf.j2: -------------------------------------------------------------------------------- 1 | description "{{app_name}} server config" 2 | 3 | start on started {{app_name}} 4 | stop on stopped {{app_name}} 5 | 6 | pre-start script 7 | mkdir -p /var/log/unicorn 8 | chown www-data. /var/log/unicorn 9 | 10 | mkdir -p /var/run/unicorn 11 | chown www-data. /var/run/unicorn 12 | end script 13 | 14 | chdir /var/www/{{app_name}}/current/ 15 | respawn 16 | 17 | exec sudo -u www-data sh -c "bundle exec unicorn -c /etc/unicorn/{{app_name}}.rb -E production" 18 | -------------------------------------------------------------------------------- /server.yml: -------------------------------------------------------------------------------- 1 | --- 2 | - name: App Server 3 | hosts: web 4 | sudo: yes 5 | user: ubuntu 6 | gather_facts: False 7 | 8 | roles: 9 | - common 10 | - ufw 11 | - ruby 12 | - nginx 13 | - unicorn 14 | - upstart 15 | - monit 16 | - postgresql 17 | 18 | # Use this block to send a message to an IRC channel 19 | #- name: Alert we are done 20 | # hosts: notify 21 | # tasks: 22 | # - irc: > 23 | # server=irc.freenode.net 24 | # channel="#channel" 25 | # msg="All finished ." 26 | # color=red 27 | # nick=ansibleAlert 28 | 29 | # Use this block to a different node 30 | #- name: Database Server 31 | # hosts: db 32 | # sudo: yes 33 | # user: root 34 | # 35 | # roles: 36 | # - common 37 | # - postgresql 38 | --------------------------------------------------------------------------------