Installation
Overview
The MiniPaaS role provisions servers so they are ready to run a Docker Swarm cluster.
The role installs:
- Docker
- Swarm cluster (init on the primary manager, join on workers)
- nftables firewall
- syslog-ng
- Fail2Ban
- Telegram monitoring and log alerts
swarm-cronjobon the primary manager
Requirements
You need:
- Linux hosts with SSH access
- Python 3 and Ansible installed locally
- An inventory file defining
managersandworkers - (Optional) tokens/IDs for monitoring and alerting
Supported operating systems:
- Debian / Ubuntu family with systemd
Install the Role Locally
Clone the repository:
git clone https://github.com/yunier-rojas/minipaas.git
cd minipaasInstall the Galaxy dependencies used by the role:
ansible-galaxy install -r minipaas-role/requirements.yml
ansible-galaxy role install geerlingguy.dockerPrepare an Inventory
Create an inventory.ini in the repository root listing your hosts:
[managers]
manager1 ansible_host=1.2.3.4
[workers]
worker1 ansible_host=1.2.3.5The role automatically:
- initializes Swarm on the manager node
- joins workers through the primary manager’s worker join token
More details: Inventory
Create a Playbook
Ansible applies the role through a playbook. Create playbook.yml in the repository root:
- name: Install and Configure MiniPaaS
hosts: all
become: true
roles:
- ./minipaas-roleThe ./minipaas-role path is resolved relative to the playbook.
Remote Access
The role binds Docker to the local Unix socket (unix:///var/run/docker.sock). The MiniPaaS CLI reaches a remote manager over SSH.
Point ssh at a manager host and use an ssh:// target in minipaas.yaml:
docker:
host: ssh://deploy@manager.example.comDeploying Applications
After provisioning, the MiniPaaS CLI builds images, rolls out the stack, and authorizes Caddy routes. The Caddy service runs as part of the environment’s stack.
See Commands for the deploy and code commands.
Run the Role
Provision the entire cluster:
ansible-playbook -i inventory.ini playbook.ymlThe role performs:
- Docker installation
- Swarm init on the primary manager
- Swarm join on workers
- nftables firewall configuration
- syslog-ng configuration
- Fail2Ban installation
- Telegram monitoring and log alerts (when credentials are set)
swarm-cronjobinstallation on the primary manager
Re-running the playbook converges the nodes to the declared configuration.
Verifying Installation
Check Docker
docker infoCheck that Swarm is active
docker node lsCheck that swarm-cronjob is running on the primary manager
systemctl status swarm-cronjobCheck remote SSH access
From your workstation:
docker -H ssh://deploy@<manager-ip> infoWhat Happens Next?
Once the role finishes:
- Machines are hardened and configured
- The Swarm cluster is ready
- The CLI can build and roll out the stack
To proceed:
- Use the MiniPaaS CLI → MiniPaaS CLI Overview
Summary
Use the MiniPaaS Ansible role to:
- prepare machines
- bootstrap Swarm
- secure the environment
- install host-level cron orchestration
- standardize logs and firewall