Compare commits

..
16 Commits
Author SHA1 Message Date
pyrschtjag c640406c10 add nginx, sshd, ssl roles 2026-09-20 22:14:56 +00:00
pyrschtjag ba9e1a664f refactor: restructure inventory, split roles and add new services 2026-09-07 19:50:34 +00:00
pyrschtjag 33ddc88ee9 added xray-core role 2026-08-28 11:11:43 +00:00
pyrschtjag 6e248bb709 change router role 2026-08-28 11:11:42 +00:00
pyrschtjag 4e6aace464 change router playbook 2026-08-28 11:11:22 +00:00
pyrschtjag d5762dfc07 remove unused playbooks 2026-08-28 11:11:13 +00:00
pyrschtjag fa6a65aed2 change static inventory 2026-08-28 11:11:09 +00:00
pyrschtjag 47e6340bf0 init empty unbound role 2026-08-28 11:11:03 +00:00
pyrschtjag 681f384810 add dnsmasq role 2026-08-28 11:10:57 +00:00
pyrschtjag 66062e6122 change group_vars 2026-08-28 11:10:55 +00:00
pyrschtjag 271c290498 change nftables role 2026-08-28 11:10:51 +00:00
pyrschtjag abeb2e0eb9 add xray-lists role 2026-08-28 11:10:47 +00:00
pyrschtjag 98873cb5eb change host_inventory 2026-08-28 11:10:44 +00:00
pyrschtjag a928e0ec70 add .gitignore 2026-08-28 11:10:40 +00:00
pyrschtjag 7ce01c7173 add vault 2026-08-28 11:10:34 +00:00
pyrschtjag 3020de7dc1 change host_vars 2026-08-28 11:10:12 +00:00
191 changed files with 2630 additions and 694 deletions
+1
View File
@@ -0,0 +1 @@
.vault_pass
+1
View File
@@ -3,6 +3,7 @@ inventory = inventory/
roles_path = roles/
host_key_checking = False
forks = 8
vault_password_file = .vault_pass
[inventory]
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
+4
View File
@@ -0,0 +1,4 @@
locale_default: en_US.UTF-8
locales_list:
- en_US.UTF-8
- ru_RU.UTF-8
-3
View File
@@ -1,3 +0,0 @@
nft_managed_group: all
dnsmasq_managed_group: all
xray_managed_group: all
+1
View File
@@ -0,0 +1 @@
timezone_name: Europe/Samara
+15
View File
@@ -0,0 +1,15 @@
$ANSIBLE_VAULT;1.1;AES256
37633533653037393835663435613364366430616366386631383963363265643963626232666132
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
62303435393932303333666434373764366463633838636533363532363732333739313437376566
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
32316330363134383761373966636464336532373863643666336363376230366237373636323234
34623265306362343765643435356236326363393431313832623937323239613834636434303938
34353763373761373739366431326162636134636135633735643930346565623430323931386239
31353762646435343639616138303130663735373932386631643834633864366638613431643966
33643833313331373735393864333665376663316534316638656363376365383834313566613037
64373764363634326463303631643231616435383738353032323537633230633063653331633734
39336265326138636232323762633936383864303565376361663664316364343039623730376234
30396435396433613532623332663335633132356662336239653536383638376435393738643439
39663537343231343734656265383762623731383336663234636638373962363535656539343765
6163656436303665346232643162383338326333386465303564
+15 -5
View File
@@ -1,5 +1,15 @@
ansible_connection: community.proxmox.proxmox_pct_remote
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
ansible_python_interpreter: /usr/bin/python3
$ANSIBLE_VAULT;1.1;AES256
37633533653037393835663435613364366430616366386631383963363265643963626232666132
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
62303435393932303333666434373764366463633838636533363532363732333739313437376566
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
32316330363134383761373966636464336532373863643666336363376230366237373636323234
34623265306362343765643435356236326363393431313832623937323239613834636434303938
34353763373761373739366431326162636134636135633735643930346565623430323931386239
31353762646435343639616138303130663735373932386631643834633864366638613431643966
33643833313331373735393864333665376663316534316638656363376365383834313566613037
64373764363634326463303631643231616435383738353032323537633230633063653331633734
39336265326138636232323762633936383864303565376361663664316364343039623730376234
30396435396433613532623332663335633132356662336239653536383638376435393738643439
39663537343231343734656265383762623731383336663234636638373962363535656539343765
6163656436303665346232643162383338326333386465303564
+4
View File
@@ -0,0 +1,4 @@
ansible_connection: ssh
ansible_user: root
ansible_host: "{{ container_ip }}"
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
+2 -4
View File
@@ -1,4 +1,2 @@
nft_from:
- iface: [eth1,eth0.2]
to: camera0
proto: [tcp,udp]
dhcp-host:
- mac: "b8:88:80:92:b5:4c"
+3 -3
View File
@@ -1,12 +1,12 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: [tcp,udp]
port: [3478,5349]
nft_from:
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
proto: [tcp,udp]
port: [3478,5349]
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
proto: udp
port: ["49152-65535"]
+1
View File
@@ -0,0 +1 @@
ansible_python_interpreter: /usr/bin/python3
+25
View File
@@ -0,0 +1,25 @@
zfs:
- name: rpool/data/pgsql
extra_zfs_properties:
quota: "21474836480"
- name: rpool/data/vaultwarden
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/gitea
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/slskd
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/rtorrent
extra_zfs_properties:
quota: "1073741824"
- name: rpool/data/jellfin
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/prosody
extra_zfs_properties:
quota: "10737418240"
- name: rpool/data/steamcmd
extra_zfs_properties:
quota: "21474836480"
+2
View File
@@ -0,0 +1,2 @@
dhcp-host:
- mac: "d4:f0:ea:78:ec:a0"
+6 -1
View File
@@ -1,5 +1,10 @@
nft_to:
- to: pgsql
proto: tcp
port: 5432
nft_from:
- iface: wg0
- iface: tun0
proto: tcp
port: 22
+9
View File
@@ -0,0 +1,9 @@
certbot_certs:
- domains:
- liqueur.oyacoi.ru
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
post_hook: "systemctl start nginx && systemctl start stunnel4"
- domains:
- absinthe.oyacoi.ru
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
post_hook: "systemctl start nginx && systemctl start stunnel4"
+2
View File
@@ -0,0 +1,2 @@
ansible_python_interpreter: /usr/bin/python3
ansible_password: "{{ ssh_password }}"
+1
View File
@@ -0,0 +1 @@
openvpn_role: server
+6
View File
@@ -0,0 +1,6 @@
$ANSIBLE_VAULT;1.1;AES256
37353538363139326635383437313831346265623562383533386261623437366462343663363261
3264363465656165343038656631373436613235343232620a663633636264383736303030323938
30336565383337613637613963343132646665613932393237323437373434646335383531303461
6134393232336132350a393333613362306462613839333732343963363961653561666437383037
35366561393537643463396462356464663162316632613331316230643932666233
+23
View File
@@ -0,0 +1,23 @@
openvpn_client_bundle_dir: /etc/easy-rsa/ovpn
openvpn_instances:
- name: tun0
pki_dir: /etc/easy-rsa/pki/tun0
clients:
- name: mur89
- name: matr10
- name: tap0
pki_dir: /etc/easy-rsa/pki/tap0
clients:
- name: ltrefilov
- name: lnosov
ip: 10.1.0.220
route_metric: 50
- name: aborovlev
ip: 10.1.0.221
route_metric: 50
- name: dperesypkin
ip: 10.1.0.222
route_metric: 50
- name: dkarpcov
ip: 10.1.0.223
route_metric: 50
+2 -2
View File
@@ -1,10 +1,10 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: 25565
nft_from:
- iface: [eth0,wg0]
- iface: [br-eth0,tun0]
proto: tcp
port: 25565
+7 -1
View File
@@ -35,11 +35,17 @@ nft_to:
- to: bylampa
proto: tcp
port: 80
- to: ps3
proto: tcp
port: 80
- to: firebat
proto: tcp
port: 8006
- to: mcsmanager
proto: tcp
port: [23333,24444]
nft_from:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: [80,443,24444]
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+22 -3
View File
@@ -1,7 +1,10 @@
nft_to:
- to: nginx
proto: tcp
port: [80,443]
- to: nfs
proto: [tcp, udp]
port: [2049, 111, 32765, 32767]
proto: [tcp,udp]
port: [2049,111,32765,32767]
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
proto: tcp
port: 22
@@ -9,7 +12,23 @@ nft_to:
proto: tcp
port: 22
nft_dst:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
nft_from:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
- proxy: all
+2 -2
View File
@@ -1,5 +1,5 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: [5000,5222,5223,5280,5270,5269]
@@ -9,7 +9,7 @@ nft_to:
port: 5432
nft_from:
- iface: [eth0,eth0.2,wg0]
- iface: [br-eth0,eth0.2,tun0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
+3 -1
View File
@@ -1,3 +1,5 @@
dnsmasq:
- name: rustdesk.dttx.ru
ip: 176.119.157.97
ip_from: liqueur
- name: fs.dttx.ru
ip_from: liqueur
-6
View File
@@ -1,6 +0,0 @@
ansible_host: 10.1.0.1
ansible_connection: ssh
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
zone_iface: eth0
container_ip: 10.1.0.1
+1
View File
@@ -0,0 +1 @@
ifupdown2_manage_prerequisites: true
+2
View File
@@ -0,0 +1,2 @@
zone_iface: "eth0"
container_ip: "10.1.0.1"
@@ -0,0 +1,3 @@
nft_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
dnsmasq_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
xray_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
+1
View File
@@ -0,0 +1 @@
nftables_bootstrap_files: true
+1
View File
@@ -0,0 +1 @@
openvpn_role: client
+6
View File
@@ -0,0 +1,6 @@
user:
- name: steamcmd
create_home: true
home: /var/lib/steamcmd
shell: /bin/bash
system: true
+100
View File
@@ -0,0 +1,100 @@
$ANSIBLE_VAULT;1.1;AES256
65616666356261363366373733653631636132613931366637383432656566366636313864666230
6136653839653366336561613365383535616231613064660a343139643135653933343731363038
36396436353033396265646338666537623237323166373664626633366432373037613631636236
6134633533636361310a663966353432366436383333666266666238636239666136316665353665
33353161626637353063613738376130333533393565383065613732663637653334636130383663
65376666373861326639343362353136303038396535303234326135633665366164393239376430
38343932613935343930376131373837376235633432373535356162616333653432666131333261
30313436613465626330393936613166663563636435356136613930303933323238336565663232
35616665333339313365323837383832393563353238326234643934393234323462336363303232
30383863366331656331336135313362303235396266613661356562333064653736396531323463
63353736633139353764356634376531613738393965393264623462333232366233396233643533
65653364643235373837303731363565656265616633336236313266373635646233623362636161
61346432336636633030616232343738666136366666353135656237653437663565643032663562
31633764343537666633386237633662306362303732353761353937323039623238353439383336
39356236646333666535326337616337313233646365333830343637376533373661636364313362
35333132353364343836366639356465323636313564636433393361636536323432363232376337
37653835666664386437316163323261336135613330636537633934633839633538343238323035
38653163626266316137383433656630313234326530313533376337393865643162613532326463
38613533373263303138333237303739393261396364646330646334386338636538343265393238
64653036366237396233323064323732393831343563643238363964333633636362303866373530
35383433643163366534613931666563376133336663393332666465616436343562613833653766
32663237383466356433383065336664393664326536346364313536656565613635666665643133
35366165643163636166613735313036326232656330313637353133323265646162333565643930
38643666396431316165626433383236653663376263663736323838343435396639636162663738
64366238363532363433313336393937353561643635343466393761623161643235663366633932
30303339306333643331323962333035393933653431383139653531626533396131663564353237
65346637383133626630376639663630333265346434656361386463343162393131393631396638
64353931643733356362376139633037363434316366396266363665613563663565366466616336
65663561666163613639643136613132303662396661653830363862346535656436613739376363
61633562346331333566313165373133633137663831313534323737623564306437346562356362
66363965313337303265343966656330356361326666353134636465613833356134383833323537
63353965346666656364633230333539383464613637333131356637326535333733356139396363
64393938366533346165386165333336333638316166663236373131366334363037626662323737
39376162616333623638383038396465356130353261303730613632623265333764633330303238
34653338346430636231376339306632376236613865383737663530353465366536313864636639
39663237383564363063663266396537393536353466643564613432646663373263306164646336
38626334373138376436336130386266343766363636636437363862303635356231323336306135
61353561643761336133623565306233383333363963393765363163323139373935313636663065
30333237313738633338663630363430373232343939303134363436653563393231656262333033
38323837646131626162383237373736306634386631613864623338303235666132353837626665
35303533623533366437656133653239613563363232343535363234346466343936393132376332
64626137363564656661653466396631346364356561313562373965623539616362383835383234
30323262353833336332623863626465376238383133633462303465393463663337356464613236
31313232383738313136303439623563393861623039393536373539303838623832323238336432
39633661626364313034623832363763313031333565373363323636393265333530633837623934
64626535646661333266303461633664346461396237333633613736303239336530616236336561
65626532303063396131376335663738393362633937393131396134316235376338623165643233
39373533373033633838626239343232323733336633333837383834666661383162366337303435
61666638393938653666643834313831613134633731353665366133633334356535343464373461
61303632663936363866353764653130386233326362343466623338326234386363653432303437
30333361653662633863323731383438373764653834363062613665613862623338336233663263
37353738373131333333353662636561323234393634643734376539383965346530386265323063
32636364653365656236396665623735656630393632333330653738643736383664396230663033
64303763336339623638653831653039353731356430626530636335623235366635313339386137
64613239653538653262393265356463643739383634663432393231636561376139653834646664
65356534336264643039303762623533616431353130353332663230336133383461386161333737
33316438303935663937373335323339656535393163616166346535313830343462303738313133
36653038343639373336663961396137366632653138396139346431363431336331376339333135
30343331626636323332393337626231326463316665373734653934653531663663393937333838
37656534626639343639366366653131313137633534316137333730346531326232353137633332
34303236386138623038303263613966346532323637303665353931333930613339626362666433
36666335356464373962376335653266663138373130303639633661393036663663323538343837
32613837636166646634626137346532656364343730616663646130356631333634353766623938
32366431623032353937363462633661396365353962393931623538366365353761353365643231
35656361393162663066393539363262663966653032356465326534616230313438323437346638
37356661376361396164646135666161373732393830343932626565663535346437346236343361
34346134343438643338636437613733323065646638646364663930353062653233353066383530
33633731396562663338393838376639363034373965353465643263613632646135346432323235
64353435363032343537633035613739336637356339373164383964313062313932653336616366
30666465613263373561373366326630366636643639616138366363346561346363646139333838
30316266376330393861666137356263336638323939666431336131383339306437333832306235
37366135613230666165396136343030643630356462333830623230613133356563666533373763
66353637393430306465373465316433386131373431343436663533663264333662333865616139
65643738656666333830383833346334383430666537313733613833356239383730666437326532
38393061326136333533653565343962333336616665633034356334653366313435383630623537
32323065363137656336626130633361353763653664303636373736326363306439346263383437
33636139656437303965353362313865333535366337666466366430353837353930656638393334
32313561306132386331383633333931353336313639366434313931333733663630386436336230
32376365613061383636326366326265623038373766316561643163646564396638336537303131
39383163323337336561616666336637316435323534353961623834656664316262623834346336
36343536336439363762333538376261663934636566323962313565303137653036653434376434
61623732613936393838386163366561373539393635303664333931396565633437393931353965
62313838636461343037626332613530663336353562656563323939323636373164363930616265
62656465366330363466386261323039323766376237303263666634653561643439323630666431
62316162366436383065623961323062353034653935626638393862366535616330356135303761
34613438393730663562633239373935383264366361376536633331323062343535626262326133
63383731613664663339613830353231643866326362663336653336666530343633376465376161
37313666346261313137363864396531643765363166663931633338383037363933646436323863
34333862613730326630356437373531373838383265383238383863373339326439643035626431
63313537623339343564326534636234646635653434356161303530393236663832316233306261
63663864383862393634656630393533326438396164623037623961363833616664666437626563
63363334323930363930326231363339363233646263643861393034656562363434383034633961
36663865393430333964626231396431663634623536656237326430356334653739333339336337
36306663316638376631323165383963636562336438383639333632316133323933653539336664
38636531326230333665653937303639616338303063666561353435353764373431643234623338
66313963373964613237346238303566316138383364666238616333663437323135376466366166
39376130336635646131653237363461663664633336663837356265616133653031613662323861
38303266613934376136366430313934373462363630633037323461306134653637623035383936
343164306335323561333737633538633333
@@ -4,36 +4,29 @@ xray_ip_sets:
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
cdn:
urls:
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
telegram:
urls:
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
russian_whitelist:
urls:
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
cloudflare:
static:
- 1.1.1.1
- 1.0.0.1
google:
urls:
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
xray_domain_sets:
v2ray:
urls:
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
torrent:
static:
- bt.t-ru.org
@@ -47,28 +40,23 @@ xray_domain_sets:
- nnmclub.to
- rutor.info
- bigfangroup.org
vps:
static:
- dev.oyacoi.ru
- vector.oyacoi.ru
terraform:
static:
- terraform.io
- hashicorp.com
output_rules:
- cloudflare
xray_static_sets:
- private
xray_lists_global:
cache_dir: /var/lib/xray-lists/cache
output_dir: /var/lib/xray-lists/generated
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
proxy: "socks5h://127.0.0.1:1080"
proxy_user: "{{ lookup('env', 'SOCKS5_USERNAME') }}"
proxy_pass: "{{ lookup('env', 'SOCKS5_PASSWORD') }}"
http_timeout: 20
xray_tproxy_port: 61219
xray_fwmark: "0x00000001"
+3
View File
@@ -1,4 +1,7 @@
nft_to:
- to: [zone:eth0.12]
proto: tcp
port: 22
- to: firebat
proto: tcp
port: [22, 8006]
-9
View File
@@ -1,9 +0,0 @@
nft_dst:
- iface: eth0
proto: udp
port: 2456
nft_from:
- iface: [eth0,wg0]
proto: udp
port: [2456,2457]
+15
View File
@@ -0,0 +1,15 @@
nft_dst:
- iface: eth1
proto: udp
port: [2456,2457]
nft_from:
- iface: [br-eth0,tun0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
- iface: [br-eth0,tun0]
proto: udp
port: [2302,2304,2456,2457,27016]
- iface: eth1
proto: udp
port: [2456,2457]
+6
View File
@@ -0,0 +1,6 @@
user:
- name: steamcmd
create_home: true
home: /var/lib/steamcmd
shell: /bin/bash
system: true
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+2
View File
@@ -0,0 +1,2 @@
dhcp-host:
- mac: "c8:5c:cc:91:71:58"
+5
View File
@@ -8,3 +8,8 @@ nft_to:
- to: [xiawrt,rbpi4]
proto: tcp
port: 22
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+2
View File
@@ -0,0 +1,2 @@
dhcp-host:
- mac: "ac:ba:c0:9c:1e:4c"
+20 -13
View File
@@ -1,13 +1,20 @@
plugin: community.proxmox.proxmox
url: https://10.1.0.4:8006
user: root@pam
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
validate_certs: false
want_facts: true
filter_by_types:
- lxc
compose:
zone_iface: "'eth0.' ~ proxmox_net0.tag"
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
$ANSIBLE_VAULT;1.1;AES256
37386530393166613762313561626462336132393166653364343962396164323734313165383763
6234663630386531323464643538353865613334656264620a316630336537396363303333343637
38636437633264373866616366666337366362306438306430633566316234323935363237343762
3533393634633733330a626139316231383738626465373566303565633135646164323535326635
38313138383063646237303634376237623661633830363531323563613131613530663730653533
36643330623366636363613437313030303463613163323333663865633538343266353134386631
36663530376238656262346662383532613631636234323431303935323138306163323839636338
61373735366332356138313762663633393165663732653565663066613636366538376263366337
31386337623562313731386563313736346139353961663231353862636138303938323235633038
38636562646533633261346264373466373536376530623639366262613365366437373334396665
30653037366339383538313965663865636462633139616332386165663564616263666533363034
38643065303832666335623035326566653437393638373261343138636530373839646231643665
33323338333231643435663336653232373732636335656238376563666632313131656432336233
63636437643838316166666137386361386233346633316166333662323838313565653233346537
61383966343434323539326364646230336339353337326539333031376464353732326331333864
34303431363632386562616131306436373464393165396437613535323230353862346662346265
33303137383033313534393438343934653037643936633361343638616461643935386430616133
62633262306538663961646263613239313261633764663532616138313663343863643965613730
396266656366353238353038333832336234
+48 -25
View File
@@ -1,37 +1,34 @@
all:
children:
static:
internal:
hosts:
workuter:
container_ip: "10.1.0.2"
zone_iface: "eth0"
zone_iface: "br-eth0"
oyacoi-odcm:
container_ip: "10.1.0.3"
zone_iface: "eth0"
zone_iface: "br-eth0"
firebat:
container_ip: "10.1.0.4"
zone_iface: "eth0"
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
zone_iface: "br-eth0"
ps2:
container_ip: "10.1.0.5"
zone_iface: "eth0"
zone_iface: "br-eth0"
ps3:
container_ip: "10.1.0.6"
zone_iface: "eth0"
zone_iface: "br-eth0"
tanix:
container_ip: "10.1.0.8"
zone_iface: "eth0"
zone_iface: "br-eth0"
bananawrt:
container_ip: "10.1.0.100"
zone_iface: "eth0"
zone_iface: "br-eth0"
ps4:
container_ip: "10.2.0.2"
@@ -57,30 +54,56 @@ all:
container_ip: "10.2.0.7"
zone_iface: "eth0.2"
psp:
3ds:
container_ip: "10.2.0.8"
zone_iface: "eth0.2"
dsi:
container_ip: "10.2.0.9"
zone_iface: "eth0.2"
yandex-lite-2:
container_ip: "10.3.0.2"
zone_iface: "eth0.3"
3ds:
container_ip: "10.2.0.10"
zone_iface: "eth0.2"
fryer:
container_ip: "10.3.0.3"
zone_iface: "eth0.3"
vacuum:
container_ip: "10.3.0.4"
zone_iface: "eth0.3"
camera0:
container_ip: "10.3.0.5"
zone_iface: "eth0.3"
haproxy:
container_ip: "10.255.255.100"
zone_iface: "wg0"
psp:
container_ip: "10.4.0.2"
zone_iface: "eth0.4"
dsi:
container_ip: "10.4.0.3"
zone_iface: "eth0.4"
xiawrt:
container_ip: "10.250.250.1"
zone_iface: "wg0"
container_ip: "192.168.1.1"
zone_iface: "tun0"
rbpi4:
container_ip: "10.250.250.5"
zone_iface: "wg0"
container_ip: "192.168.1.5"
zone_iface: "tun0"
haproxy:
container_ip: "172.168.0.1"
zone_iface: "tun0"
external:
hosts:
liqueur:
container_ip: "130.49.213.132"
zone_iface: "eht1"
vector:
container_ip: "144.31.155.100"
zone_iface: "eht1"
dev:
container_ip: "178.173.249.148"
zone_iface: "eht1"
-5
View File
@@ -1,5 +0,0 @@
---
- hosts: router
become: true
roles:
- dnsmasq
+29
View File
@@ -0,0 +1,29 @@
---
- name: deploy rasy-rsa
hosts: localhost
connection: local
become: true
roles:
- easy-rsa
- name: configure liqueur openvpn
hosts: liqueur
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- openvpn
- name: configure router openvpn
hosts: router
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- openvpn
+11
View File
@@ -0,0 +1,11 @@
---
- name: configure over ssh
hosts: firebat
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- zfs
+23
View File
@@ -0,0 +1,23 @@
---
- name: configure over ssh
hosts: liqueur
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: >-
-o UserKnownHostsFile=/dev/null
-o StrictHostKeyChecking=no
-o PreferredAuthentications=publickey,password
-o PubkeyAuthentication=yes
roles:
- authorized_key
- sshd
- certbot
- sysctl
- nginx
- nftables
- stunnel4
- openvpn
- haproxy
-14
View File
@@ -1,14 +0,0 @@
---
- hosts: router
become: true
roles:
- xray-lists
- dnsmasq
- nftables
tasks:
- name: enable update timer
systemd:
name: xray-lists.timer
enabled: yes
state: started
+25 -12
View File
@@ -1,15 +1,28 @@
---
- hosts: router
become: yes
- name: configure over pct
hosts: router
gather_facts: false
roles:
- router
- xray-lists
- dnsmasq
- nftables
- authorized_key
- ifupdown2
tasks:
- name: enable update timer
systemd:
name: xray-lists.timer
enabled: yes
state: started
- name: configure over ssh
hosts: router
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- timezone
- locales
- sysctl
- stunnel4
- openvpn
- xray-core
- logrotate
- dnsmasq
- xray-lists
- unbound
- nftables
+20
View File
@@ -0,0 +1,20 @@
---
- name: configure over pct
hosts: steamcmd
gather_facts: false
roles:
- authorized_key
- name: configure over ssh
hosts: steamcmd
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- timezone
- locales
- user
- steamcmd
-5
View File
@@ -1,5 +0,0 @@
---
- hosts: router
become: true
roles:
- xray-lists
+15
View File
@@ -0,0 +1,15 @@
---
- name: ensure .ssh exists
ansible.builtin.file:
path: /root/.ssh
state: directory
mode: '0700'
owner: root
group: root
- name: set authorized key
ansible.posix.authorized_key:
user: root
state: present
key: "{{ item }}"
loop: "{{ ssh_keys }}"
+20
View File
@@ -0,0 +1,20 @@
---
- name: install certbot
ansible.builtin.apt:
name: certbot
state: present
update_cache: true
- name: issue certificate if missing
ansible.builtin.command:
cmd: >
certbot certonly --standalone
--non-interactive --agree-tos
--register-unsafely-without-email
--pre-hook "{{ item.pre_hook }}"
--post-hook "{{ item.post_hook }}"
{{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }}
creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem"
loop: "{{ certbot_certs }}"
loop_control:
label: "{{ item.domains | join(',') }}"
+6
View File
@@ -0,0 +1,6 @@
---
- name: install certbot
ansible.builtin.apt:
name: certbot
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include certbot install
ansible.builtin.include_tasks: install.yml
- name: include certbot configure
ansible.builtin.include_tasks: configure.yml
+14
View File
@@ -0,0 +1,14 @@
interface=lo
interface=br-eth0
interface=eth0.2
interface=eth0.3
interface=eth0.4
interface=eth0.10
interface=eth0.11
interface=eth0.12
bind-dynamic
no-resolv
server=127.0.0.1#5353
#server=1.1.1.1
domain=lan
local=/lan/
@@ -0,0 +1,10 @@
server=/dev.oyacoi.ru/9.9.9.9
server=/vector.oyacoi.ru/9.9.9.9
server=/.themoviedb.org/9.9.9.9
server=/.tmdb.org/9.9.9.9
server=/tmdb-image-prod.b-cdn.net/9.9.9.9
server=/infolada.ru/217.113.115.150
server=/infolada.ru/217.113.114.100
server=/start.infolada.ru/217.113.115.150
server=/start.infolada.ru/217.113.114.100
conf-file=/var/lib/xray-lists/generated/nftsets.conf
+3
View File
@@ -0,0 +1,3 @@
dhcp-range=interface:eth0.3,10.3.0.200,10.3.0.254,255.255.255.0,2h
dhcp-option=interface:eth0.3,option:router,10.3.0.1
dhcp-option=interface:eth0.3,option:dns-server,10.3.0.1
@@ -0,0 +1,4 @@
filterwin2k
domain-needed
bogus-priv
cache-size=0
+39
View File
@@ -0,0 +1,39 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: deploy dnsmasq rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/dnsmasq.d/{{ item }}"
mode: "0644"
loop:
- 10-upstream.conf
- 20-custom-domains.conf
- 20-dhcp.conf
- 20-dns-optimizations.conf
notify: restart dnsmasq
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render dhcp-host
ansible.builtin.template:
src: 90-dhcp-host.conf.j2
dest: /etc/dnsmasq.d/90-dhcp-host.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
+6
View File
@@ -0,0 +1,6 @@
---
- name: install dnsmasq
ansible.builtin.apt:
name: dnsmasq
state: latest
update_cache: true
+4 -18
View File
@@ -1,20 +1,6 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: include dnsmasq install
ansible.builtin.include_tasks: install.yml
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
- name: include dnsmasq configurure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,13 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
{% for entry in entries %}
{% if entry.mac %}
dhcp-host={{ entry.mac }},{{ ip }},{{ item }}
{% endif %}
{% endfor %}
{% endif %}
{% endfor %}
+6 -12
View File
@@ -1,15 +1,9 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'dnsmasq' in client and client.dnsmasq %}
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% set domains = client.dnsmasq if (client.dnsmasq is iterable and client.dnsmasq is not string) else [client.dnsmasq] %}
{% for d in domains %}
{% set entry = d if (d is mapping) else {'name': d} %}
{% set ip = entry.ip | default(default_ip) %}
{% if ip %}
{% for item in dnsmasq_managed_group | sort %}
{% for entry in hostvars[item].dnsmasq | default([]) %}
{% set ip = entry.ip | default(hostvars[entry.ip_from].container_ip if entry.ip_from is defined else none) %}
{% if ip %}
host-record={{ entry.name }},{{ ip }}
{% endif %}
{% endfor %}
{% endif %}
{% endif %}
{% endfor %}
{% endfor %}
+5 -5
View File
@@ -1,8 +1,8 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if ip %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if ip %}
host-record={{ item }},{{ item }}.lan,{{ ip }}
{% endif %}
{% endif %}
{% endfor %}
+18
View File
@@ -0,0 +1,18 @@
---
- name: ensure local output directory exists
ansible.builtin.file:
path: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}"
state: directory
mode: '0700'
loop: "{{ openvpn_instances | subelements('clients') }}"
delegate_to: localhost
become: false
- name: render standalone client bundles
ansible.builtin.template:
src: "{{ role_path }}/templates/client-certs/{{ item.0.name }}.conf.j2"
dest: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}/{{ item.1.name }}.ovpn"
mode: '0600'
loop: "{{ openvpn_instances | subelements('clients') }}"
delegate_to: localhost
become: false
+82
View File
@@ -0,0 +1,82 @@
---
- name: prepare list of client certificates
ansible.builtin.set_fact:
cert_list: "{{ cert_list | default([]) + [ {'instance': item.0.name, 'pki_dir': item.0.pki_dir, 'client': item.1} ] }}"
loop: "{{ openvpn_instances | subelements('clients') }}"
- name: ensure local PKI directories exist
ansible.builtin.file:
path: "{{ item.pki_dir }}"
state: directory
mode: '0700'
loop: "{{ openvpn_instances }}"
- name: init pki if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch init-pki
creates: "{{ item.pki_dir }}/private"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: build ca if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-ca nopass
creates: "{{ item.pki_dir }}/ca.crt"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
EASYRSA_REQ_CN: "CA-{{ item.name }}"
loop: "{{ openvpn_instances }}"
- name: build server cert if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-server-full server nopass
creates: "{{ item.pki_dir }}/issued/server.crt"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: generate dh params if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa gen-dh
creates: "{{ item.pki_dir }}/dh.pem"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: check client certificates validity
ansible.builtin.command:
cmd: "openssl x509 -checkend 2592000 -in {{ item.pki_dir }}/issued/{{ item.client.name }}.crt"
register: cert_check
failed_when: false
changed_when: false
loop: "{{ cert_list }}"
- name: remove old cert file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/issued/{{ item.item.client.name }}.crt"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: remove old req file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/reqs/{{ item.item.client.name }}.req"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: remove old key file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/private/{{ item.item.client.name }}.key"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: issue or renew client certificates
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-client-full "{{ item.item.client.name }}" nopass
environment:
EASYRSA_PKI: "{{ item.item.pki_dir }}"
when: item.rc != 0
loop: "{{ cert_check.results }}"
+35
View File
@@ -0,0 +1,35 @@
---
- name: get latest easy-rsa release info
ansible.builtin.uri:
url: https://api.github.com/repos/OpenVPN/easy-rsa/releases/latest
return_content: true
register: easyrsa_release
run_once: true
check_mode: false
- name: set current easy-rsa version
ansible.builtin.set_fact:
easyrsa_version: "{{ easyrsa_release.json.tag_name | replace('v', '') }}"
easyrsa_asset_url: "{{ easyrsa_release.json.assets | selectattr('name', 'search', 'EasyRSA.*\\.tgz') | map(attribute='browser_download_url') | first }}"
- name: check easy-rsa installed version
ansible.builtin.command: /opt/easy-rsa/easyrsa version
register: easyrsa_current_version
changed_when: false
failed_when: false
- name: ensure easy-rsa directory exists
ansible.builtin.file:
path: /opt/easy-rsa
state: directory
mode: '0755'
check_mode: false
- name: update easy-rsa
ansible.builtin.unarchive:
src: "{{ easyrsa_asset_url }}"
dest: /opt/easy-rsa
remote_src: true
extra_opts:
- --strip-components=1
when: easyrsa_version not in (easyrsa_current_version.stdout | default(''))
+9
View File
@@ -0,0 +1,9 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
- name: include client-certs.yml
ansible.builtin.include_tasks: client-certs.yml
@@ -0,0 +1,26 @@
client
dev tap0
proto tcp
remote 127.0.0.1 1195
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
auth SHA256
cipher AES-256-GCM
verb 3
{% if item.1.ip is defined %}
route-metric {{ item.1.route_metric | default(50) }}
script-security 2
up "C:\\Windows\\System32\\netsh.exe interface ip set address name="OpenVPN TAP-Windows6" static {{ item.1.ip }} 255.255.255.0"
{% endif %}
<ca>
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
</ca>
<cert>
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
</cert>
<key>
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
</key>
@@ -0,0 +1,21 @@
client
dev tun0
proto tcp
remote 127.0.0.1 1194
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
auth SHA256
cipher AES-256-GCM
verb 3
<ca>
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
</ca>
<cert>
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
</cert>
<key>
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
</key>
+13
View File
@@ -0,0 +1,13 @@
---
- name: validate haproxy config
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
changed_when: false
listen: restart haproxy
- name: restart haproxy systemd service unit
ansible.builtin.systemd_service:
name: haproxy
daemon_reload: true
state: restarted
enabled: true
listen: restart haproxy
+10
View File
@@ -0,0 +1,10 @@
---
- name: render haproxy config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
notify: restart haproxy
+6
View File
@@ -0,0 +1,6 @@
---
- name: install haproxy
ansible.builtin.apt:
name: haproxy
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,90 @@
global
log /dev/log local2
chroot /var/lib/haproxy
maxconn 4000
user haproxy
group haproxy
daemon
stats socket /var/lib/haproxy/stats mode 660 level admin
defaults
log global
mode tcp
option tcplog
option dontlognull
retries 3
timeout connect 5s
timeout client 1h
timeout server 1h
timeout check 10s
frontend http_frontend
bind 127.0.0.1:10080
mode http
option httplog
acl host_dttx hdr_end(host) -m end dttx.ru
use_backend dttx_http_srv if host_dttx
default_backend oyacoi_http_srv
backend oyacoi_http_srv
mode http
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
backend dttx_http_srv
mode http
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
frontend https_frontend
bind 127.0.0.1:10443
mode tcp
option tcplog
tcp-request inspect-delay 5s
tcp-request content accept if { req_ssl_hello_type 1 }
acl host_dttx req_ssl_sni -m end dttx.ru
acl host_telemt req_ssl_sni -m end regionculture.ru
use_backend dttx_https_srv if host_dttx
use_backend telemt_https_srv if host_telemt
default_backend oyacoi_https_srv
backend oyacoi_https_srv
mode tcp
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
backend dttx_https_srv
mode tcp
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
backend telemt_https_srv
mode tcp
option tcp-check
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
listen mcsmanager_service
bind {{ hostvars['liqueur']['container_ip'] }}:24444
mode tcp
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
listen xmpp_c2s
bind {{ hostvars['liqueur']['container_ip'] }}:5222
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
listen xmpp_legacy_ssl
bind {{ hostvars['liqueur']['container_ip'] }}:5223
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
listen xmpp_s2s
bind {{ hostvars['liqueur']['container_ip'] }}:5269
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
listen prosody_proxy65
bind {{ hostvars['liqueur']['container_ip'] }}:5000
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
listen prosody_components
bind {{ hostvars['liqueur']['container_ip'] }}:5270
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
listen prosody_bosh_http
bind {{ hostvars['liqueur']['container_ip'] }}:5280
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
@@ -5,9 +5,16 @@ iface lo inet loopback
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
auto br-eth0
iface br-eth0 inet static
address 10.1.0.1/24
bridge_ports eth0 tap0
bridge_stp off
pre-up ip tuntap add dev tap0 mode tap || true
post-down ip tuntap del dev tap0 mode tap || true
auto eth0
iface eth0 inet manual
address 10.1.0.1/24
auto eth0.2
iface eth0.2 inet static
@@ -41,12 +48,3 @@ iface eth0.12 inet static
auto eth1
iface eth1 inet dhcp
auto wg0
iface wg0 inet manual
post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
post-up ip route add default dev wg0 table 199 2>/dev/null || true
pre-down ip route del default dev wg0 table 199 2>/dev/null || true
pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
+13
View File
@@ -0,0 +1,13 @@
---
- name: deploy ifupdown interfaces
ansible.builtin.copy:
src: "{{ inventory_hostname }}/interfaces"
dest: /etc/network/interfaces
owner: root
group: root
mode: '0644'
register: interfaces_conf
- name: reload ifupdown2
command: ifreload -a
when: interfaces_conf.changed
+7
View File
@@ -0,0 +1,7 @@
---
- name: include configure
ansible.builtin.include_tasks: configure.yml
- name: include prerequisites
ansible.builtin.include_tasks: prerequisites.yml
tags: ifupdown2_prereqs
+17
View File
@@ -0,0 +1,17 @@
---
- name: install bridge-utils
ansible.builtin.package:
name: bridge-utils
state: present
register: bridge_utils_install
- name: ensure rt_tables.d directory exists
ansible.builtin.file:
path: /etc/iproute2/rt_tables.d
state: directory
mode: "0755"
register: rt_tables_dir
- name: reload ifupdown2
ansible.builtin.command: ifreload -a
when: bridge_utils_install.changed or rt_tables_dir.changed
+14
View File
@@ -0,0 +1,14 @@
---
- name: set required locales
community.general.locale_gen:
name: "{{ item }}"
state: present
loop: "{{ locales_list }}"
- name: configure /etc/locale.conf
ansible.builtin.copy:
dest: /etc/locale.conf
content: LANG={{ locale_default }}
owner: root
group: root
mode: '0644'
+3
View File
@@ -0,0 +1,3 @@
---
- name: include locales configure
ansible.builtin.include_tasks: configure.yml
+9
View File
@@ -0,0 +1,9 @@
/var/log/xray-core/*.log {
daily
rotate 4
compress
delaycompress
missingok
notifempty
copytruncate
}
+8
View File
@@ -0,0 +1,8 @@
---
- name: deploy logrotate config
ansible.builtin.copy:
src: "{{ inventory_hostname }}/"
dest: "/etc/logrotate.d/"
owner: root
group: root
mode: '0644'
+3
View File
@@ -0,0 +1,3 @@
---
- name: include logrotate configure
ansible.builtin.include_tasks: configure.yml
-49
View File
@@ -1,49 +0,0 @@
flowtable ft {
hook ingress priority filter
devices = { eth0, eth1 }
}
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iif lo accept
ip protocol icmp accept
ip6 nexthdr icmpv6 accept
meta mark 0x00000001 accept
iifname eth0 tcp dport 22 accept
iifname eth0.11 tcp dport 22 accept
iifname eth1 udp dport 51820 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
iifname eth0.3 udp dport 67 accept
iifname eth1 udp dport 68 accept
#include "/etc/nftables.d/90-input.nft"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
}
chain output {
type route hook output priority filter; policy accept;
#include "/etc/nftables.d/90-output.nft"
}
-35
View File
@@ -1,35 +0,0 @@
chain vpn_prerouting_dnat {
type nat hook prerouting priority dstnat - 5; policy accept;
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
}
chain vpn_postrouting_snat {
type nat hook postrouting priority srcnat; policy accept;
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
}
chain vpn_prerouting_pbr {
type filter hook prerouting priority mangle - 10; policy accept;
iifname wg0 ct state new counter ct mark set 0x000000c7
ip daddr 10.0.0.0/8 return
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
}
chain vpn_output_pbr {
type route hook output priority mangle - 10; policy accept;
ct mark 0x000000c7 counter meta mark set 0x000000c7
}
-15
View File
@@ -1,15 +0,0 @@
chain proxy_prerouting {
type filter hook prerouting priority filter - 50; policy accept;
fib daddr type local accept
include "/etc/nftables.d/90-proxy.nft"
}
chain proxy_output {
type route hook output priority mangle; policy accept;
#meta mark 0x000000ff return
#meta l4proto { tcp, udp } ip daddr @cloudflare_ip meta mark set 0x00000001 accept
}
-15
View File
@@ -1,15 +0,0 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
include "/etc/nftables.d/40-sets.nft"
include "/etc/nftables.d/90-sets.nft"
include "/etc/nftables.d/10-filter.nft"
include "/etc/nftables.d/20-vpn.nft"
include "/etc/nftables.d/30-proxy.nft"
}
table ip nat {
include "/etc/nftables.d/10-nat.nft"
}
@@ -2,7 +2,6 @@ chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
oifname eth1 masquerade
}
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
include "/etc/nftables.d/90-dstnat.nft"
+34
View File
@@ -0,0 +1,34 @@
flowtable ft {
hook ingress priority filter
devices = { eth0, eth1 }
}
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iif lo accept
meta mark 0x00000001 accept
iifname br-eth0 tcp dport 22 accept
iifname eth0.11 tcp dport 22 accept
iifname tun0 tcp dport 22 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
iifname eth0.3 udp dport 67 accept
iifname eth1 udp dport 68 accept
include "/etc/nftables.d/90-input.nft"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
}
chain output {
type route hook output priority filter; policy accept;
include "/etc/nftables.d/90-output.nft"
}
+11
View File
@@ -0,0 +1,11 @@
chain proxy_prerouting {
type filter hook prerouting priority filter - 50; policy accept;
fib daddr type local accept
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
include "/etc/nftables.d/90-proxy-prerouting.nft"
}
chain proxy_output {
type route hook output priority mangle; policy accept;
meta mark != 0 return
include "/etc/nftables.d/90-proxy-output.nft"
}
+2 -2
View File
@@ -1,4 +1,4 @@
---
- name: reload nftables
- name: restart nftables
ansible.builtin.command: nft -f /etc/nftables.conf
listen: reload nftables
listen: restart nftables
+58
View File
@@ -0,0 +1,58 @@
---
- name: ensure /etc/nftables.d exists
ansible.builtin.file:
path: /etc/nftables.d
state: directory
mode: "0755"
when: nftables_bootstrap_files | default(false)
- name: bootstrap empty config files
ansible.builtin.copy:
dest: "/etc/nftables.d/{{ item }}"
content: ""
force: false
mode: "0644"
loop:
- 10-sets.nft
- 20-sets.nft
- 30-nat.nft
- 40-filter.nft
- 50-proxy.nft
- 90-dstnat.nft
- 90-forward.nft
- 90-input.nft
- 90-output.nft
- 90-proxy-output.nft
- 90-proxy-prerouting.nft
when: nftables_bootstrap_files | default(false)
- name: deploy nftables rules
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item | basename }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.nft') }}"
notify: restart nftables
- name: render nftable rules
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.nft.j2') }}"
notify: restart nftables
- name: deploy nftables.conf
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: "0644"
validate: "nft -c -f %s"
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
notify: restart nftables
+6
View File
@@ -0,0 +1,6 @@
---
- name: install nftables
ansible.builtin.apt:
name: nftables
state: latest
update_cache: true
+4 -39
View File
@@ -1,41 +1,6 @@
---
- name: ensure /etc/nftables.d exists
ansible.builtin.file:
path: /etc/nftables.d
state: directory
mode: "0755"
- name: include nftables install
ansible.builtin.include_tasks: install.yml
- name: deploy nftables rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item }}"
mode: "0644"
loop:
- 10-filter.nft
- 10-nat.nft
- 20-vpn.nft
- 30-proxy.nft
- 40-sets.nft
notify: reload nftables
- name: render forward
ansible.builtin.template:
src: 90-forward.nft.j2
dest: /etc/nftables.d/90-forward.nft
mode: "0644"
notify: reload nftables
- name: render dstnat
ansible.builtin.template:
src: 90-dstnat.nft.j2
dest: /etc/nftables.d/90-dstnat.nft
mode: "0644"
notify: reload nftables
- name: deploy nftables.conf
ansible.builtin.copy:
src: nftables.conf
dest: /etc/nftables.conf
mode: "0644"
validate: "nft -c -f %s"
notify: reload nftables
- name: include nftables configure
ansible.builtin.include_tasks: configure.yml
-31
View File
@@ -1,31 +0,0 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% macro render_dstnat_rule(ifaces, proto, port, target_ip, item_name) %}
{% set lines = [] %}
{% set active_ifaces = ifaces if (ifaces is iterable and ifaces is not string) else [ifaces] %}
{% for current_iface in active_ifaces %}
{% set comment_str = ' comment "' ~ current_iface ~ ' -> ' ~ item_name ~ '"' %}
{% set rule_line = 'iifname "' ~ current_iface ~ '" ' ~ proto ~ ' dport ' ~ port ~ ' counter dnat ip to ' ~ target_ip ~ ':' ~ port ~ comment_str %}
{% set _ = lines.append(rule_line) %}
{% endfor %}
{{ lines | join('\n') }}
{% endmacro %}
{% filter regex_replace('\n[ \t]*\n+', '\n') %}
{% for item in groups[nft_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'nft_dst' in client and client.nft_dst is not none %}
{% set target_ip = client.container_ip | default(client.ansible_host | default(item)) %}
{% set raw_expose = client.nft_dst %}
{% set exposes = raw_expose if (raw_expose is iterable and raw_expose is not string and raw_expose is not mapping) else [raw_expose] %}
{% for expose in exposes %}
{% set protos = expose.proto if (expose.proto is defined and expose.proto is iterable and expose.proto is not string) else [expose.proto | default('tcp')] %}
{% set ports = expose.port if (expose.port is defined and expose.port is iterable and expose.port is not string) else [expose.port] %}
{% set ifaces = expose.iface %}
{% for p in protos | sort %}
{% for port in ports | sort %}
{{ render_dstnat_rule(ifaces, p, port, target_ip, item) }}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
{% endfilter %}

Some files were not shown because too many files have changed in this diff Show More