Syncthing With Nothing That Phones Home
Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-syncthing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Syncthing With Nothing That Phones Home](https://www.iac-bazaar.com/catalog/ansible-syncthing?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Syncthing With Nothing That Phones Home: https://www.iac-bazaar.com/catalog/ansible-syncthing (download from your IaC Bazaar account)
```Preview:
Documentation
syncthing
Syncthing from the upstream release (sha256-verified against the vendor's signed checksum file), as a hardened system service with its GUI and REST API on loopback behind a key that never appears in the unit file, and every phone-home default switched off. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
syncthing; Syncthing ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by syncthing_version.
A service account, a hardened unit, a loopback listener. syncthing
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:8384 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
Nothing phones home. Syncthing's defaults announce the device to a global discovery server and broadcast it on the local network, use public relays, open NAT mappings, send crash reports and replace their own binary every 12 hours. The role turns each off through the REST API - only when it differs, and without a restart, which Syncthing confirms - and leaves usage reporting declined rather than unanswered. Peers are configured by address; turn discovery or relays back on with the variables when you want them.
A key that is not in the unit. The API key reaches the process from a
root-owned 0640 environment file (STGUIAPIKEY), not an Environment= line
anybody can read with systemctl cat. The live test sees no key and a wrong
key refused (403), reads the options back, checks that neither the unit file nor
anything systemd applies from it holds the key and that the file holding it
is root's at 0640, shares a folder
through the API and watches the scan index its file. The sync listener is on every interface
by design: the protocol authenticates each peer by device ID over TLS.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-garage
Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.
ansible-kopia
kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-samba-share
Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.
ansible-seaweedfs
SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.
ansible-rclone
rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-rest-server
restic's REST backend server from the upstream release (sha256-verified) as a hardened system service on loopback, append-only and private repositories a variable away. No client is installed, so the live test speaks the protocol: creates a repository, writes its config object, reads it back, deletes it and sees it gone. Original role, live-tested on Rocky Linux 10.