Add base plays for all hosts, nvidia_gpu role, GPU pre-work items
- run.yml: base plays (geerlingguy.security) for jira and git; gpu01 play with security + docker + nvidia_gpu - roles/nvidia_gpu: driver pinned >=580 (Blackwell), CUDA repo, container toolkit incl. the nvidia-ctk runtime configure step - manuals/20260714-nvidia-driver-install.md: dated per convention, corrected (pinned -server driver instead of autoinstall+cuda-drivers mix, toolkit optional, added missing nvidia-ctk/docker restart step) - gpu01 folder: planning docs under notes/, runbooks under manuals/, scripts/; convention documented in CLAUDE.md - scripts/share-analysis.ps1: read-only SMB share analysis for the Windows server (projektplan §2.1) - TODO.md: Phase-0 pre-work items from the projektplan Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,70 @@
|
||||
---
|
||||
# Automates server/phy-z-srv-gpu01/manuals/20260714-nvidia-driver-install.md
|
||||
# Requires Docker (geerlingguy.docker) for the container toolkit part.
|
||||
|
||||
- name: Check Secure Boot state
|
||||
command: mokutil --sb-state
|
||||
register: nvidia_sb_state
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
|
||||
- name: Fail if Secure Boot is enabled
|
||||
fail:
|
||||
msg: "Secure Boot is enabled — disable it in the BIOS before installing the NVIDIA driver."
|
||||
when: "'SecureBoot enabled' in nvidia_sb_state.stdout"
|
||||
|
||||
- name: Install NVIDIA driver
|
||||
apt:
|
||||
name: "{{ nvidia_driver_package }}"
|
||||
state: present
|
||||
register: nvidia_driver_install
|
||||
|
||||
- name: Reboot after fresh driver install
|
||||
reboot:
|
||||
reboot_timeout: 600
|
||||
when: nvidia_driver_install.changed
|
||||
|
||||
- name: Install NVIDIA CUDA repository keyring
|
||||
apt:
|
||||
deb: "{{ nvidia_cuda_keyring_url }}"
|
||||
|
||||
- name: Install CUDA toolkit (optional, see defaults)
|
||||
apt:
|
||||
name: "{{ nvidia_cuda_toolkit_package }}"
|
||||
state: present
|
||||
update_cache: true
|
||||
when: nvidia_install_cuda_toolkit
|
||||
|
||||
- name: Add NVIDIA container toolkit repository key
|
||||
shell: >
|
||||
curl -fsSL https://nvidia.github.io/libnvidia-container/gpgkey
|
||||
| gpg --dearmor -o /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg
|
||||
args:
|
||||
creates: /usr/share/keyrings/nvidia-container-toolkit-keyring.gpg
|
||||
|
||||
- name: Add NVIDIA container toolkit repository
|
||||
copy:
|
||||
dest: /etc/apt/sources.list.d/nvidia-container-toolkit.list
|
||||
content: "deb [signed-by=/usr/share/keyrings/nvidia-container-toolkit-keyring.gpg] https://nvidia.github.io/libnvidia-container/stable/deb/$(ARCH) /\n"
|
||||
mode: "0644"
|
||||
|
||||
- name: Install NVIDIA container toolkit
|
||||
apt:
|
||||
name: nvidia-container-toolkit
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Check whether Docker already uses the NVIDIA runtime
|
||||
command: grep -q nvidia /etc/docker/daemon.json
|
||||
register: nvidia_docker_runtime
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
|
||||
- name: Configure Docker to use the NVIDIA runtime
|
||||
command: nvidia-ctk runtime configure --runtime=docker
|
||||
when: nvidia_docker_runtime.rc != 0
|
||||
notify: restart docker
|
||||
|
||||
- name: Verify the driver works
|
||||
command: nvidia-smi
|
||||
changed_when: false
|
||||
Reference in New Issue
Block a user