--- # Deploy Zot OCI registry via Docker Compose, with htpasswd basic auth # and a simple retention policy. # ponytail: single zot instance, no TLS termination here (assumed behind # plain HTTP for the PoC); add a reverse proxy with TLS before any real use. - name: Create zot directories ansible.builtin.file: path: "{{ item }}" state: directory mode: "0755" loop: - /opt/zot - /opt/zot/data - /opt/zot/auth - name: Ensure apache2-utils (htpasswd) is installed ansible.builtin.apt: name: apache2-utils state: present - name: Check if htpasswd file already exists ansible.builtin.stat: path: /opt/zot/auth/htpasswd register: zot_htpasswd_stat - name: Generate htpasswd file for zot user ansible.builtin.command: cmd: >- htpasswd -cbB /opt/zot/auth/htpasswd {{ zot_admin_user }} {{ zot_admin_password }} when: not zot_htpasswd_stat.stat.exists changed_when: true - name: Deploy zot configuration ansible.builtin.template: src: config.json.j2 dest: /opt/zot/config.json mode: "0644" notify: Restart zot - name: Deploy zot compose file ansible.builtin.template: src: compose.yaml.j2 dest: /opt/zot/compose.yaml mode: "0644" - name: Start zot via docker compose ansible.builtin.command: cmd: docker compose up -d chdir: /opt/zot changed_when: true