Compare commits
1
Commits
main
..
6d7779af3f
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6d7779af3f |
@@ -1 +0,0 @@
|
|||||||
.vault_pass
|
|
||||||
@@ -3,7 +3,6 @@ inventory = inventory/
|
|||||||
roles_path = roles/
|
roles_path = roles/
|
||||||
host_key_checking = False
|
host_key_checking = False
|
||||||
forks = 8
|
forks = 8
|
||||||
vault_password_file = .vault_pass
|
|
||||||
|
|
||||||
[inventory]
|
[inventory]
|
||||||
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
|
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
locale_default: en_US.UTF-8
|
|
||||||
locales_list:
|
|
||||||
- en_US.UTF-8
|
|
||||||
- ru_RU.UTF-8
|
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
nft_managed_group: all
|
||||||
|
dnsmasq_managed_group: all
|
||||||
|
xray_managed_group: all
|
||||||
@@ -1 +0,0 @@
|
|||||||
timezone_name: Europe/Samara
|
|
||||||
@@ -4,29 +4,36 @@ xray_ip_sets:
|
|||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
|
||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
|
||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
|
||||||
|
|
||||||
cdn:
|
cdn:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
|
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
|
||||||
|
|
||||||
telegram:
|
telegram:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
|
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
|
||||||
|
|
||||||
russian_whitelist:
|
russian_whitelist:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
|
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
|
||||||
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
|
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
|
||||||
|
|
||||||
cloudflare:
|
cloudflare:
|
||||||
static:
|
static:
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
- 1.0.0.1
|
- 1.0.0.1
|
||||||
|
|
||||||
google:
|
google:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
|
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
|
||||||
|
|
||||||
xray_domain_sets:
|
xray_domain_sets:
|
||||||
v2ray:
|
v2ray:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
|
||||||
|
|
||||||
torrent:
|
torrent:
|
||||||
static:
|
static:
|
||||||
- bt.t-ru.org
|
- bt.t-ru.org
|
||||||
@@ -40,23 +47,28 @@ xray_domain_sets:
|
|||||||
- nnmclub.to
|
- nnmclub.to
|
||||||
- rutor.info
|
- rutor.info
|
||||||
- bigfangroup.org
|
- bigfangroup.org
|
||||||
|
|
||||||
vps:
|
vps:
|
||||||
static:
|
static:
|
||||||
- dev.oyacoi.ru
|
- dev.oyacoi.ru
|
||||||
- vector.oyacoi.ru
|
- vector.oyacoi.ru
|
||||||
|
|
||||||
terraform:
|
terraform:
|
||||||
static:
|
static:
|
||||||
- terraform.io
|
- terraform.io
|
||||||
- hashicorp.com
|
- hashicorp.com
|
||||||
output_rules:
|
|
||||||
- cloudflare
|
|
||||||
xray_static_sets:
|
xray_static_sets:
|
||||||
- private
|
- private
|
||||||
|
|
||||||
xray_lists_global:
|
xray_lists_global:
|
||||||
cache_dir: /var/lib/xray-lists/cache
|
cache_dir: /var/lib/xray-lists/cache
|
||||||
output_dir: /var/lib/xray-lists/generated
|
output_dir: /var/lib/xray-lists/generated
|
||||||
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
|
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
|
||||||
proxy: "socks5h://127.0.0.1:1080"
|
proxy: "socks5h://127.0.0.1:1080"
|
||||||
|
proxy_user: "{{ lookup('env', 'SOCKS5_USERNAME') }}"
|
||||||
|
proxy_pass: "{{ lookup('env', 'SOCKS5_PASSWORD') }}"
|
||||||
http_timeout: 20
|
http_timeout: 20
|
||||||
|
|
||||||
xray_tproxy_port: 61219
|
xray_tproxy_port: 61219
|
||||||
xray_fwmark: "0x00000001"
|
xray_fwmark: "0x00000001"
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
|
||||||
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
|
||||||
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
|
||||||
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
|
||||||
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
|
||||||
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
|
||||||
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
|
||||||
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
|
||||||
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
|
||||||
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
|
||||||
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
|
||||||
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
|
||||||
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
|
||||||
6163656436303665346232643162383338326333386465303564
|
|
||||||
@@ -1,15 +1,5 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
ansible_connection: community.proxmox.proxmox_pct_remote
|
||||||
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
ansible_host: 10.1.0.4
|
||||||
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
ansible_user: root
|
||||||
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||||
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
ansible_python_interpreter: /usr/bin/python3
|
||||||
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
|
||||||
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
|
||||||
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
|
||||||
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
|
||||||
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
|
||||||
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
|
||||||
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
|
||||||
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
|
||||||
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
|
||||||
6163656436303665346232643162383338326333386465303564
|
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
ansible_connection: ssh
|
|
||||||
ansible_user: root
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
|
||||||
@@ -1,2 +1,4 @@
|
|||||||
dhcp-host:
|
nft_from:
|
||||||
- mac: "b8:88:80:92:b5:4c"
|
- iface: [eth1,eth0.2]
|
||||||
|
to: camera0
|
||||||
|
proto: [tcp,udp]
|
||||||
|
|||||||
@@ -1,12 +1,12 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [br-eth0,eth0.2]
|
- iface: [eth0,eth0.2]
|
||||||
proto: [tcp,udp]
|
proto: [tcp,udp]
|
||||||
port: [3478,5349]
|
port: [3478,5349]
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
||||||
proto: [tcp,udp]
|
proto: [tcp,udp]
|
||||||
port: [3478,5349]
|
port: [3478,5349]
|
||||||
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
||||||
proto: udp
|
proto: udp
|
||||||
port: ["49152-65535"]
|
port: ["49152-65535"]
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
ansible_python_interpreter: /usr/bin/python3
|
|
||||||
@@ -1,25 +0,0 @@
|
|||||||
zfs:
|
|
||||||
- name: rpool/data/pgsql
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "21474836480"
|
|
||||||
- name: rpool/data/vaultwarden
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "5368709120"
|
|
||||||
- name: rpool/data/gitea
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "5368709120"
|
|
||||||
- name: rpool/data/slskd
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "5368709120"
|
|
||||||
- name: rpool/data/rtorrent
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "1073741824"
|
|
||||||
- name: rpool/data/jellfin
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "5368709120"
|
|
||||||
- name: rpool/data/prosody
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "10737418240"
|
|
||||||
- name: rpool/data/steamcmd
|
|
||||||
extra_zfs_properties:
|
|
||||||
quota: "21474836480"
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
dhcp-host:
|
|
||||||
- mac: "d4:f0:ea:78:ec:a0"
|
|
||||||
@@ -1,10 +1,5 @@
|
|||||||
nft_to:
|
|
||||||
- to: pgsql
|
|
||||||
proto: tcp
|
|
||||||
port: 5432
|
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: tun0
|
- iface: wg0
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
certbot_certs:
|
|
||||||
- domains:
|
|
||||||
- liqueur.oyacoi.ru
|
|
||||||
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
|
||||||
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
|
||||||
- domains:
|
|
||||||
- absinthe.oyacoi.ru
|
|
||||||
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
|
||||||
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
ansible_python_interpreter: /usr/bin/python3
|
|
||||||
ansible_password: "{{ ssh_password }}"
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
openvpn_role: server
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
37353538363139326635383437313831346265623562383533386261623437366462343663363261
|
|
||||||
3264363465656165343038656631373436613235343232620a663633636264383736303030323938
|
|
||||||
30336565383337613637613963343132646665613932393237323437373434646335383531303461
|
|
||||||
6134393232336132350a393333613362306462613839333732343963363961653561666437383037
|
|
||||||
35366561393537643463396462356464663162316632613331316230643932666233
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
openvpn_client_bundle_dir: /etc/easy-rsa/ovpn
|
|
||||||
openvpn_instances:
|
|
||||||
- name: tun0
|
|
||||||
pki_dir: /etc/easy-rsa/pki/tun0
|
|
||||||
clients:
|
|
||||||
- name: mur89
|
|
||||||
- name: matr10
|
|
||||||
- name: tap0
|
|
||||||
pki_dir: /etc/easy-rsa/pki/tap0
|
|
||||||
clients:
|
|
||||||
- name: ltrefilov
|
|
||||||
- name: lnosov
|
|
||||||
ip: 10.1.0.220
|
|
||||||
route_metric: 50
|
|
||||||
- name: aborovlev
|
|
||||||
ip: 10.1.0.221
|
|
||||||
route_metric: 50
|
|
||||||
- name: dperesypkin
|
|
||||||
ip: 10.1.0.222
|
|
||||||
route_metric: 50
|
|
||||||
- name: dkarpcov
|
|
||||||
ip: 10.1.0.223
|
|
||||||
route_metric: 50
|
|
||||||
@@ -1,10 +1,10 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [br-eth0,eth0.2]
|
- iface: [eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 25565
|
port: 25565
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [br-eth0,tun0]
|
- iface: [eth0,wg0]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 25565
|
port: 25565
|
||||||
|
|
||||||
|
|||||||
@@ -35,17 +35,11 @@ nft_to:
|
|||||||
- to: bylampa
|
- to: bylampa
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 80
|
port: 80
|
||||||
- to: ps3
|
|
||||||
proto: tcp
|
|
||||||
port: 80
|
|
||||||
- to: firebat
|
|
||||||
proto: tcp
|
|
||||||
port: 8006
|
|
||||||
- to: mcsmanager
|
- to: mcsmanager
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [23333,24444]
|
port: [23333,24444]
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [br-eth0,eth0.2]
|
- iface: [eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [80,443,24444]
|
port: [80,443,24444]
|
||||||
|
|||||||
@@ -1,4 +0,0 @@
|
|||||||
xray_policy:
|
|
||||||
- bypass: private
|
|
||||||
- bypass: russian_whitelist
|
|
||||||
- proxy: all
|
|
||||||
@@ -1,7 +1,4 @@
|
|||||||
nft_to:
|
nft_to:
|
||||||
- to: nginx
|
|
||||||
proto: tcp
|
|
||||||
port: [80,443]
|
|
||||||
- to: nfs
|
- to: nfs
|
||||||
proto: [tcp, udp]
|
proto: [tcp, udp]
|
||||||
port: [2049, 111, 32765, 32767]
|
port: [2049, 111, 32765, 32767]
|
||||||
@@ -12,22 +9,6 @@ nft_to:
|
|||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
nft_dst:
|
|
||||||
- iface: eth1
|
|
||||||
proto: tcp
|
|
||||||
port: [3783,4321,28900,29900,29901]
|
|
||||||
- iface: eth1
|
|
||||||
proto: udp
|
|
||||||
port: [6500,6515,13139,27900]
|
|
||||||
|
|
||||||
nft_from:
|
|
||||||
- iface: eth1
|
|
||||||
proto: tcp
|
|
||||||
port: [3783,4321,28900,29900,29901]
|
|
||||||
- iface: eth1
|
|
||||||
proto: udp
|
|
||||||
port: [6500,6515,13139,27900]
|
|
||||||
|
|
||||||
xray_policy:
|
xray_policy:
|
||||||
- bypass: private
|
- bypass: private
|
||||||
- bypass: russian_whitelist
|
- bypass: russian_whitelist
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [br-eth0,eth0.2]
|
- iface: [eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [5000,5222,5223,5280,5270,5269]
|
port: [5000,5222,5223,5280,5270,5269]
|
||||||
|
|
||||||
@@ -9,7 +9,7 @@ nft_to:
|
|||||||
port: 5432
|
port: 5432
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [br-eth0,eth0.2,tun0]
|
- iface: [eth0,eth0.2,wg0]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [5000,5222,5223,5269,5270,5280]
|
port: [5000,5222,5223,5269,5270,5280]
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,3 @@
|
|||||||
dnsmasq:
|
dnsmasq:
|
||||||
- name: rustdesk.dttx.ru
|
- name: rustdesk.dttx.ru
|
||||||
ip_from: liqueur
|
ip: 176.119.157.97
|
||||||
- name: fs.dttx.ru
|
|
||||||
ip_from: liqueur
|
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
ansible_host: 10.1.0.1
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
zone_iface: eth0
|
||||||
|
container_ip: 10.1.0.1
|
||||||
@@ -1 +0,0 @@
|
|||||||
ifupdown2_manage_prerequisites: true
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
zone_iface: "eth0"
|
|
||||||
container_ip: "10.1.0.1"
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
nft_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
|
||||||
dnsmasq_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
|
||||||
xray_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
nftables_bootstrap_files: true
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
openvpn_role: client
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
user:
|
|
||||||
- name: steamcmd
|
|
||||||
create_home: true
|
|
||||||
home: /var/lib/steamcmd
|
|
||||||
shell: /bin/bash
|
|
||||||
system: true
|
|
||||||
@@ -1,100 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
65616666356261363366373733653631636132613931366637383432656566366636313864666230
|
|
||||||
6136653839653366336561613365383535616231613064660a343139643135653933343731363038
|
|
||||||
36396436353033396265646338666537623237323166373664626633366432373037613631636236
|
|
||||||
6134633533636361310a663966353432366436383333666266666238636239666136316665353665
|
|
||||||
33353161626637353063613738376130333533393565383065613732663637653334636130383663
|
|
||||||
65376666373861326639343362353136303038396535303234326135633665366164393239376430
|
|
||||||
38343932613935343930376131373837376235633432373535356162616333653432666131333261
|
|
||||||
30313436613465626330393936613166663563636435356136613930303933323238336565663232
|
|
||||||
35616665333339313365323837383832393563353238326234643934393234323462336363303232
|
|
||||||
30383863366331656331336135313362303235396266613661356562333064653736396531323463
|
|
||||||
63353736633139353764356634376531613738393965393264623462333232366233396233643533
|
|
||||||
65653364643235373837303731363565656265616633336236313266373635646233623362636161
|
|
||||||
61346432336636633030616232343738666136366666353135656237653437663565643032663562
|
|
||||||
31633764343537666633386237633662306362303732353761353937323039623238353439383336
|
|
||||||
39356236646333666535326337616337313233646365333830343637376533373661636364313362
|
|
||||||
35333132353364343836366639356465323636313564636433393361636536323432363232376337
|
|
||||||
37653835666664386437316163323261336135613330636537633934633839633538343238323035
|
|
||||||
38653163626266316137383433656630313234326530313533376337393865643162613532326463
|
|
||||||
38613533373263303138333237303739393261396364646330646334386338636538343265393238
|
|
||||||
64653036366237396233323064323732393831343563643238363964333633636362303866373530
|
|
||||||
35383433643163366534613931666563376133336663393332666465616436343562613833653766
|
|
||||||
32663237383466356433383065336664393664326536346364313536656565613635666665643133
|
|
||||||
35366165643163636166613735313036326232656330313637353133323265646162333565643930
|
|
||||||
38643666396431316165626433383236653663376263663736323838343435396639636162663738
|
|
||||||
64366238363532363433313336393937353561643635343466393761623161643235663366633932
|
|
||||||
30303339306333643331323962333035393933653431383139653531626533396131663564353237
|
|
||||||
65346637383133626630376639663630333265346434656361386463343162393131393631396638
|
|
||||||
64353931643733356362376139633037363434316366396266363665613563663565366466616336
|
|
||||||
65663561666163613639643136613132303662396661653830363862346535656436613739376363
|
|
||||||
61633562346331333566313165373133633137663831313534323737623564306437346562356362
|
|
||||||
66363965313337303265343966656330356361326666353134636465613833356134383833323537
|
|
||||||
63353965346666656364633230333539383464613637333131356637326535333733356139396363
|
|
||||||
64393938366533346165386165333336333638316166663236373131366334363037626662323737
|
|
||||||
39376162616333623638383038396465356130353261303730613632623265333764633330303238
|
|
||||||
34653338346430636231376339306632376236613865383737663530353465366536313864636639
|
|
||||||
39663237383564363063663266396537393536353466643564613432646663373263306164646336
|
|
||||||
38626334373138376436336130386266343766363636636437363862303635356231323336306135
|
|
||||||
61353561643761336133623565306233383333363963393765363163323139373935313636663065
|
|
||||||
30333237313738633338663630363430373232343939303134363436653563393231656262333033
|
|
||||||
38323837646131626162383237373736306634386631613864623338303235666132353837626665
|
|
||||||
35303533623533366437656133653239613563363232343535363234346466343936393132376332
|
|
||||||
64626137363564656661653466396631346364356561313562373965623539616362383835383234
|
|
||||||
30323262353833336332623863626465376238383133633462303465393463663337356464613236
|
|
||||||
31313232383738313136303439623563393861623039393536373539303838623832323238336432
|
|
||||||
39633661626364313034623832363763313031333565373363323636393265333530633837623934
|
|
||||||
64626535646661333266303461633664346461396237333633613736303239336530616236336561
|
|
||||||
65626532303063396131376335663738393362633937393131396134316235376338623165643233
|
|
||||||
39373533373033633838626239343232323733336633333837383834666661383162366337303435
|
|
||||||
61666638393938653666643834313831613134633731353665366133633334356535343464373461
|
|
||||||
61303632663936363866353764653130386233326362343466623338326234386363653432303437
|
|
||||||
30333361653662633863323731383438373764653834363062613665613862623338336233663263
|
|
||||||
37353738373131333333353662636561323234393634643734376539383965346530386265323063
|
|
||||||
32636364653365656236396665623735656630393632333330653738643736383664396230663033
|
|
||||||
64303763336339623638653831653039353731356430626530636335623235366635313339386137
|
|
||||||
64613239653538653262393265356463643739383634663432393231636561376139653834646664
|
|
||||||
65356534336264643039303762623533616431353130353332663230336133383461386161333737
|
|
||||||
33316438303935663937373335323339656535393163616166346535313830343462303738313133
|
|
||||||
36653038343639373336663961396137366632653138396139346431363431336331376339333135
|
|
||||||
30343331626636323332393337626231326463316665373734653934653531663663393937333838
|
|
||||||
37656534626639343639366366653131313137633534316137333730346531326232353137633332
|
|
||||||
34303236386138623038303263613966346532323637303665353931333930613339626362666433
|
|
||||||
36666335356464373962376335653266663138373130303639633661393036663663323538343837
|
|
||||||
32613837636166646634626137346532656364343730616663646130356631333634353766623938
|
|
||||||
32366431623032353937363462633661396365353962393931623538366365353761353365643231
|
|
||||||
35656361393162663066393539363262663966653032356465326534616230313438323437346638
|
|
||||||
37356661376361396164646135666161373732393830343932626565663535346437346236343361
|
|
||||||
34346134343438643338636437613733323065646638646364663930353062653233353066383530
|
|
||||||
33633731396562663338393838376639363034373965353465643263613632646135346432323235
|
|
||||||
64353435363032343537633035613739336637356339373164383964313062313932653336616366
|
|
||||||
30666465613263373561373366326630366636643639616138366363346561346363646139333838
|
|
||||||
30316266376330393861666137356263336638323939666431336131383339306437333832306235
|
|
||||||
37366135613230666165396136343030643630356462333830623230613133356563666533373763
|
|
||||||
66353637393430306465373465316433386131373431343436663533663264333662333865616139
|
|
||||||
65643738656666333830383833346334383430666537313733613833356239383730666437326532
|
|
||||||
38393061326136333533653565343962333336616665633034356334653366313435383630623537
|
|
||||||
32323065363137656336626130633361353763653664303636373736326363306439346263383437
|
|
||||||
33636139656437303965353362313865333535366337666466366430353837353930656638393334
|
|
||||||
32313561306132386331383633333931353336313639366434313931333733663630386436336230
|
|
||||||
32376365613061383636326366326265623038373766316561643163646564396638336537303131
|
|
||||||
39383163323337336561616666336637316435323534353961623834656664316262623834346336
|
|
||||||
36343536336439363762333538376261663934636566323962313565303137653036653434376434
|
|
||||||
61623732613936393838386163366561373539393635303664333931396565633437393931353965
|
|
||||||
62313838636461343037626332613530663336353562656563323939323636373164363930616265
|
|
||||||
62656465366330363466386261323039323766376237303263666634653561643439323630666431
|
|
||||||
62316162366436383065623961323062353034653935626638393862366535616330356135303761
|
|
||||||
34613438393730663562633239373935383264366361376536633331323062343535626262326133
|
|
||||||
63383731613664663339613830353231643866326362663336653336666530343633376465376161
|
|
||||||
37313666346261313137363864396531643765363166663931633338383037363933646436323863
|
|
||||||
34333862613730326630356437373531373838383265383238383863373339326439643035626431
|
|
||||||
63313537623339343564326534636234646635653434356161303530393236663832316233306261
|
|
||||||
63663864383862393634656630393533326438396164623037623961363833616664666437626563
|
|
||||||
63363334323930363930326231363339363233646263643861393034656562363434383034633961
|
|
||||||
36663865393430333964626231396431663634623536656237326430356334653739333339336337
|
|
||||||
36306663316638376631323165383963636562336438383639333632316133323933653539336664
|
|
||||||
38636531326230333665653937303639616338303063666561353435353764373431643234623338
|
|
||||||
66313963373964613237346238303566316138383364666238616333663437323135376466366166
|
|
||||||
39376130336635646131653237363461663664633336663837356265616133653031613662323861
|
|
||||||
38303266613934376136366430313934373462363630633037323461306134653637623035383936
|
|
||||||
343164306335323561333737633538633333
|
|
||||||
@@ -1,7 +1,4 @@
|
|||||||
nft_to:
|
nft_to:
|
||||||
- to: [zone:eth0.12]
|
|
||||||
proto: tcp
|
|
||||||
port: 22
|
|
||||||
- to: firebat
|
- to: firebat
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [22, 8006]
|
port: [22, 8006]
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
nft_dst:
|
||||||
|
- iface: eth0
|
||||||
|
proto: udp
|
||||||
|
port: 2456
|
||||||
|
|
||||||
|
nft_from:
|
||||||
|
- iface: [eth0,wg0]
|
||||||
|
proto: udp
|
||||||
|
port: [2456,2457]
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
nft_dst:
|
|
||||||
- iface: eth1
|
|
||||||
proto: udp
|
|
||||||
port: [2456,2457]
|
|
||||||
|
|
||||||
nft_from:
|
|
||||||
- iface: [br-eth0,tun0]
|
|
||||||
proto: tcp
|
|
||||||
port: [5000,5222,5223,5269,5270,5280]
|
|
||||||
- iface: [br-eth0,tun0]
|
|
||||||
proto: udp
|
|
||||||
port: [2302,2304,2456,2457,27016]
|
|
||||||
- iface: eth1
|
|
||||||
proto: udp
|
|
||||||
port: [2456,2457]
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
user:
|
|
||||||
- name: steamcmd
|
|
||||||
create_home: true
|
|
||||||
home: /var/lib/steamcmd
|
|
||||||
shell: /bin/bash
|
|
||||||
system: true
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
xray_policy:
|
|
||||||
- bypass: private
|
|
||||||
- bypass: russian_whitelist
|
|
||||||
- proxy: all
|
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
dhcp-host:
|
|
||||||
- mac: "c8:5c:cc:91:71:58"
|
|
||||||
@@ -8,8 +8,3 @@ nft_to:
|
|||||||
- to: [xiawrt,rbpi4]
|
- to: [xiawrt,rbpi4]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
xray_policy:
|
|
||||||
- bypass: private
|
|
||||||
- bypass: russian_whitelist
|
|
||||||
- proxy: all
|
|
||||||
|
|||||||
@@ -1,2 +0,0 @@
|
|||||||
dhcp-host:
|
|
||||||
- mac: "ac:ba:c0:9c:1e:4c"
|
|
||||||
+13
-20
@@ -1,20 +1,13 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
plugin: community.proxmox.proxmox
|
||||||
37386530393166613762313561626462336132393166653364343962396164323734313165383763
|
url: https://10.1.0.4:8006
|
||||||
6234663630386531323464643538353865613334656264620a316630336537396363303333343637
|
user: root@pam
|
||||||
38636437633264373866616366666337366362306438306430633566316234323935363237343762
|
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
|
||||||
3533393634633733330a626139316231383738626465373566303565633135646164323535326635
|
validate_certs: false
|
||||||
38313138383063646237303634376237623661633830363531323563613131613530663730653533
|
want_facts: true
|
||||||
36643330623366636363613437313030303463613163323333663865633538343266353134386631
|
|
||||||
36663530376238656262346662383532613631636234323431303935323138306163323839636338
|
filter_by_types:
|
||||||
61373735366332356138313762663633393165663732653565663066613636366538376263366337
|
- lxc
|
||||||
31386337623562313731386563313736346139353961663231353862636138303938323235633038
|
|
||||||
38636562646533633261346264373466373536376530623639366262613365366437373334396665
|
compose:
|
||||||
30653037366339383538313965663865636462633139616332386165663564616263666533363034
|
zone_iface: "'eth0.' ~ proxmox_net0.tag"
|
||||||
38643065303832666335623035326566653437393638373261343138636530373839646231643665
|
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
|
||||||
33323338333231643435663336653232373732636335656238376563666632313131656432336233
|
|
||||||
63636437643838316166666137386361386233346633316166333662323838313565653233346537
|
|
||||||
61383966343434323539326364646230336339353337326539333031376464353732326331333864
|
|
||||||
34303431363632386562616131306436373464393165396437613535323230353862346662346265
|
|
||||||
33303137383033313534393438343934653037643936633361343638616461643935386430616133
|
|
||||||
62633262306538663961646263613239313261633764663532616138313663343863643965613730
|
|
||||||
396266656366353238353038333832336234
|
|
||||||
|
|||||||
+25
-48
@@ -1,34 +1,37 @@
|
|||||||
all:
|
all:
|
||||||
children:
|
children:
|
||||||
internal:
|
static:
|
||||||
hosts:
|
hosts:
|
||||||
workuter:
|
workuter:
|
||||||
container_ip: "10.1.0.2"
|
container_ip: "10.1.0.2"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
oyacoi-odcm:
|
oyacoi-odcm:
|
||||||
container_ip: "10.1.0.3"
|
container_ip: "10.1.0.3"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
firebat:
|
firebat:
|
||||||
container_ip: "10.1.0.4"
|
container_ip: "10.1.0.4"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
ansible_host: 10.1.0.4
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||||
|
|
||||||
ps2:
|
ps2:
|
||||||
container_ip: "10.1.0.5"
|
container_ip: "10.1.0.5"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
ps3:
|
ps3:
|
||||||
container_ip: "10.1.0.6"
|
container_ip: "10.1.0.6"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
tanix:
|
tanix:
|
||||||
container_ip: "10.1.0.8"
|
container_ip: "10.1.0.8"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
bananawrt:
|
bananawrt:
|
||||||
container_ip: "10.1.0.100"
|
container_ip: "10.1.0.100"
|
||||||
zone_iface: "br-eth0"
|
zone_iface: "eth0"
|
||||||
|
|
||||||
ps4:
|
ps4:
|
||||||
container_ip: "10.2.0.2"
|
container_ip: "10.2.0.2"
|
||||||
@@ -54,56 +57,30 @@ all:
|
|||||||
container_ip: "10.2.0.7"
|
container_ip: "10.2.0.7"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
3ds:
|
psp:
|
||||||
container_ip: "10.2.0.8"
|
container_ip: "10.2.0.8"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
yandex-lite-2:
|
dsi:
|
||||||
container_ip: "10.3.0.2"
|
container_ip: "10.2.0.9"
|
||||||
zone_iface: "eth0.3"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
fryer:
|
3ds:
|
||||||
container_ip: "10.3.0.3"
|
container_ip: "10.2.0.10"
|
||||||
zone_iface: "eth0.3"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
vacuum:
|
|
||||||
container_ip: "10.3.0.4"
|
|
||||||
zone_iface: "eth0.3"
|
|
||||||
|
|
||||||
camera0:
|
camera0:
|
||||||
container_ip: "10.3.0.5"
|
container_ip: "10.3.0.5"
|
||||||
zone_iface: "eth0.3"
|
zone_iface: "eth0.3"
|
||||||
|
|
||||||
psp:
|
haproxy:
|
||||||
container_ip: "10.4.0.2"
|
container_ip: "10.255.255.100"
|
||||||
zone_iface: "eth0.4"
|
zone_iface: "wg0"
|
||||||
|
|
||||||
dsi:
|
|
||||||
container_ip: "10.4.0.3"
|
|
||||||
zone_iface: "eth0.4"
|
|
||||||
|
|
||||||
xiawrt:
|
xiawrt:
|
||||||
container_ip: "192.168.1.1"
|
container_ip: "10.250.250.1"
|
||||||
zone_iface: "tun0"
|
zone_iface: "wg0"
|
||||||
|
|
||||||
rbpi4:
|
rbpi4:
|
||||||
container_ip: "192.168.1.5"
|
container_ip: "10.250.250.5"
|
||||||
zone_iface: "tun0"
|
zone_iface: "wg0"
|
||||||
|
|
||||||
haproxy:
|
|
||||||
container_ip: "172.168.0.1"
|
|
||||||
zone_iface: "tun0"
|
|
||||||
|
|
||||||
external:
|
|
||||||
hosts:
|
|
||||||
liqueur:
|
|
||||||
container_ip: "130.49.213.132"
|
|
||||||
zone_iface: "eht1"
|
|
||||||
|
|
||||||
vector:
|
|
||||||
container_ip: "144.31.155.100"
|
|
||||||
zone_iface: "eht1"
|
|
||||||
|
|
||||||
dev:
|
|
||||||
container_ip: "178.173.249.148"
|
|
||||||
zone_iface: "eht1"
|
|
||||||
|
|||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
- hosts: router
|
||||||
|
become: true
|
||||||
|
roles:
|
||||||
|
- dnsmasq
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
---
|
|
||||||
- name: deploy rasy-rsa
|
|
||||||
hosts: localhost
|
|
||||||
connection: local
|
|
||||||
become: true
|
|
||||||
roles:
|
|
||||||
- easy-rsa
|
|
||||||
|
|
||||||
- name: configure liqueur openvpn
|
|
||||||
hosts: liqueur
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
|
||||||
roles:
|
|
||||||
- openvpn
|
|
||||||
|
|
||||||
- name: configure router openvpn
|
|
||||||
hosts: router
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
|
||||||
roles:
|
|
||||||
- openvpn
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
---
|
|
||||||
- name: configure over ssh
|
|
||||||
hosts: firebat
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
|
||||||
roles:
|
|
||||||
- zfs
|
|
||||||
@@ -1,23 +0,0 @@
|
|||||||
---
|
|
||||||
- name: configure over ssh
|
|
||||||
hosts: liqueur
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: >-
|
|
||||||
-o UserKnownHostsFile=/dev/null
|
|
||||||
-o StrictHostKeyChecking=no
|
|
||||||
-o PreferredAuthentications=publickey,password
|
|
||||||
-o PubkeyAuthentication=yes
|
|
||||||
roles:
|
|
||||||
- authorized_key
|
|
||||||
- sshd
|
|
||||||
- certbot
|
|
||||||
- sysctl
|
|
||||||
- nginx
|
|
||||||
- nftables
|
|
||||||
- stunnel4
|
|
||||||
- openvpn
|
|
||||||
- haproxy
|
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
- hosts: router
|
||||||
|
become: true
|
||||||
|
roles:
|
||||||
|
- xray-lists
|
||||||
|
- dnsmasq
|
||||||
|
- nftables
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: enable update timer
|
||||||
|
systemd:
|
||||||
|
name: xray-lists.timer
|
||||||
|
enabled: yes
|
||||||
|
state: started
|
||||||
+11
-24
@@ -1,28 +1,15 @@
|
|||||||
---
|
---
|
||||||
- name: configure over pct
|
- hosts: router
|
||||||
hosts: router
|
become: yes
|
||||||
gather_facts: false
|
|
||||||
roles:
|
roles:
|
||||||
- authorized_key
|
- router
|
||||||
- ifupdown2
|
|
||||||
|
|
||||||
- name: configure over ssh
|
|
||||||
hosts: router
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
|
||||||
roles:
|
|
||||||
- timezone
|
|
||||||
- locales
|
|
||||||
- sysctl
|
|
||||||
- stunnel4
|
|
||||||
- openvpn
|
|
||||||
- xray-core
|
|
||||||
- logrotate
|
|
||||||
- dnsmasq
|
|
||||||
- xray-lists
|
- xray-lists
|
||||||
- unbound
|
- dnsmasq
|
||||||
- nftables
|
- nftables
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
- name: enable update timer
|
||||||
|
systemd:
|
||||||
|
name: xray-lists.timer
|
||||||
|
enabled: yes
|
||||||
|
state: started
|
||||||
|
|||||||
@@ -1,20 +0,0 @@
|
|||||||
---
|
|
||||||
- name: configure over pct
|
|
||||||
hosts: steamcmd
|
|
||||||
gather_facts: false
|
|
||||||
roles:
|
|
||||||
- authorized_key
|
|
||||||
|
|
||||||
- name: configure over ssh
|
|
||||||
hosts: steamcmd
|
|
||||||
vars:
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_host: "{{ container_ip }}"
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
|
||||||
roles:
|
|
||||||
- timezone
|
|
||||||
- locales
|
|
||||||
- user
|
|
||||||
- steamcmd
|
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
- hosts: router
|
||||||
|
become: true
|
||||||
|
roles:
|
||||||
|
- xray-lists
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
- name: ensure .ssh exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /root/.ssh
|
|
||||||
state: directory
|
|
||||||
mode: '0700'
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
|
|
||||||
- name: set authorized key
|
|
||||||
ansible.posix.authorized_key:
|
|
||||||
user: root
|
|
||||||
state: present
|
|
||||||
key: "{{ item }}"
|
|
||||||
loop: "{{ ssh_keys }}"
|
|
||||||
@@ -1,20 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install certbot
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: certbot
|
|
||||||
state: present
|
|
||||||
update_cache: true
|
|
||||||
|
|
||||||
- name: issue certificate if missing
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: >
|
|
||||||
certbot certonly --standalone
|
|
||||||
--non-interactive --agree-tos
|
|
||||||
--register-unsafely-without-email
|
|
||||||
--pre-hook "{{ item.pre_hook }}"
|
|
||||||
--post-hook "{{ item.post_hook }}"
|
|
||||||
{{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }}
|
|
||||||
creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem"
|
|
||||||
loop: "{{ certbot_certs }}"
|
|
||||||
loop_control:
|
|
||||||
label: "{{ item.domains | join(',') }}"
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install certbot
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: certbot
|
|
||||||
state: latest
|
|
||||||
update_cache: true
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include certbot install
|
|
||||||
ansible.builtin.include_tasks: install.yml
|
|
||||||
|
|
||||||
- name: include certbot configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
interface=lo
|
|
||||||
interface=br-eth0
|
|
||||||
interface=eth0.2
|
|
||||||
interface=eth0.3
|
|
||||||
interface=eth0.4
|
|
||||||
interface=eth0.10
|
|
||||||
interface=eth0.11
|
|
||||||
interface=eth0.12
|
|
||||||
bind-dynamic
|
|
||||||
no-resolv
|
|
||||||
server=127.0.0.1#5353
|
|
||||||
#server=1.1.1.1
|
|
||||||
domain=lan
|
|
||||||
local=/lan/
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
server=/dev.oyacoi.ru/9.9.9.9
|
|
||||||
server=/vector.oyacoi.ru/9.9.9.9
|
|
||||||
server=/.themoviedb.org/9.9.9.9
|
|
||||||
server=/.tmdb.org/9.9.9.9
|
|
||||||
server=/tmdb-image-prod.b-cdn.net/9.9.9.9
|
|
||||||
server=/infolada.ru/217.113.115.150
|
|
||||||
server=/infolada.ru/217.113.114.100
|
|
||||||
server=/start.infolada.ru/217.113.115.150
|
|
||||||
server=/start.infolada.ru/217.113.114.100
|
|
||||||
conf-file=/var/lib/xray-lists/generated/nftsets.conf
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
dhcp-range=interface:eth0.3,10.3.0.200,10.3.0.254,255.255.255.0,2h
|
|
||||||
dhcp-option=interface:eth0.3,option:router,10.3.0.1
|
|
||||||
dhcp-option=interface:eth0.3,option:dns-server,10.3.0.1
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
filterwin2k
|
|
||||||
domain-needed
|
|
||||||
bogus-priv
|
|
||||||
cache-size=0
|
|
||||||
@@ -1,39 +0,0 @@
|
|||||||
---
|
|
||||||
- name: ensure /etc/dnsmasq.d exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/dnsmasq.d
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
- name: deploy dnsmasq rule
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/dnsmasq.d/{{ item }}"
|
|
||||||
mode: "0644"
|
|
||||||
loop:
|
|
||||||
- 10-upstream.conf
|
|
||||||
- 20-custom-domains.conf
|
|
||||||
- 20-dhcp.conf
|
|
||||||
- 20-dns-optimizations.conf
|
|
||||||
notify: restart dnsmasq
|
|
||||||
|
|
||||||
- name: render local
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-local.conf.j2
|
|
||||||
dest: /etc/dnsmasq.d/90-local.conf
|
|
||||||
mode: "0644"
|
|
||||||
notify: restart dnsmasq
|
|
||||||
|
|
||||||
- name: render dhcp-host
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-dhcp-host.conf.j2
|
|
||||||
dest: /etc/dnsmasq.d/90-dhcp-host.conf
|
|
||||||
mode: "0644"
|
|
||||||
notify: restart dnsmasq
|
|
||||||
|
|
||||||
- name: render domain
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-domains.conf.j2
|
|
||||||
dest: /etc/dnsmasq.d/90-domains.conf
|
|
||||||
mode: "0644"
|
|
||||||
notify: restart dnsmasq
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install dnsmasq
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: dnsmasq
|
|
||||||
state: latest
|
|
||||||
update_cache: true
|
|
||||||
@@ -1,6 +1,20 @@
|
|||||||
---
|
---
|
||||||
- name: include dnsmasq install
|
- name: ensure /etc/dnsmasq.d exists
|
||||||
ansible.builtin.include_tasks: install.yml
|
ansible.builtin.file:
|
||||||
|
path: /etc/dnsmasq.d
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
- name: include dnsmasq configurure
|
- name: render local
|
||||||
ansible.builtin.include_tasks: configure.yml
|
ansible.builtin.template:
|
||||||
|
src: 90-local.conf.j2
|
||||||
|
dest: /etc/dnsmasq.d/90-local.conf
|
||||||
|
mode: "0644"
|
||||||
|
notify: restart dnsmasq
|
||||||
|
|
||||||
|
- name: render domain
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-domains.conf.j2
|
||||||
|
dest: /etc/dnsmasq.d/90-domains.conf
|
||||||
|
mode: "0644"
|
||||||
|
notify: restart dnsmasq
|
||||||
|
|||||||
@@ -1,13 +0,0 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
|
||||||
{% for item in dnsmasq_managed_group | sort %}
|
|
||||||
{% set client = hostvars[item] %}
|
|
||||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
|
||||||
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
|
|
||||||
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
|
|
||||||
{% for entry in entries %}
|
|
||||||
{% if entry.mac %}
|
|
||||||
dhcp-host={{ entry.mac }},{{ ip }},{{ item }}
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
@@ -1,9 +1,15 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
{% for item in dnsmasq_managed_group | sort %}
|
{% for item in groups[dnsmasq_managed_group] | sort %}
|
||||||
{% for entry in hostvars[item].dnsmasq | default([]) %}
|
{% set client = hostvars[item] %}
|
||||||
{% set ip = entry.ip | default(hostvars[entry.ip_from].container_ip if entry.ip_from is defined else none) %}
|
{% if 'dnsmasq' in client and client.dnsmasq %}
|
||||||
|
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||||
|
{% set domains = client.dnsmasq if (client.dnsmasq is iterable and client.dnsmasq is not string) else [client.dnsmasq] %}
|
||||||
|
{% for d in domains %}
|
||||||
|
{% set entry = d if (d is mapping) else {'name': d} %}
|
||||||
|
{% set ip = entry.ip | default(default_ip) %}
|
||||||
{% if ip %}
|
{% if ip %}
|
||||||
host-record={{ entry.name }},{{ ip }}
|
host-record={{ entry.name }},{{ ip }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
{% for item in dnsmasq_managed_group | sort %}
|
{% for item in groups[dnsmasq_managed_group] | sort %}
|
||||||
{% set client = hostvars[item] %}
|
{% set client = hostvars[item] %}
|
||||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||||
{% if ip %}
|
{% if ip %}
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
---
|
|
||||||
- name: ensure local output directory exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}"
|
|
||||||
state: directory
|
|
||||||
mode: '0700'
|
|
||||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
|
||||||
delegate_to: localhost
|
|
||||||
become: false
|
|
||||||
|
|
||||||
- name: render standalone client bundles
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: "{{ role_path }}/templates/client-certs/{{ item.0.name }}.conf.j2"
|
|
||||||
dest: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}/{{ item.1.name }}.ovpn"
|
|
||||||
mode: '0600'
|
|
||||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
|
||||||
delegate_to: localhost
|
|
||||||
become: false
|
|
||||||
@@ -1,82 +0,0 @@
|
|||||||
---
|
|
||||||
- name: prepare list of client certificates
|
|
||||||
ansible.builtin.set_fact:
|
|
||||||
cert_list: "{{ cert_list | default([]) + [ {'instance': item.0.name, 'pki_dir': item.0.pki_dir, 'client': item.1} ] }}"
|
|
||||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
|
||||||
|
|
||||||
- name: ensure local PKI directories exist
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item.pki_dir }}"
|
|
||||||
state: directory
|
|
||||||
mode: '0700'
|
|
||||||
loop: "{{ openvpn_instances }}"
|
|
||||||
|
|
||||||
- name: init pki if missing
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: /opt/easy-rsa/easyrsa --batch init-pki
|
|
||||||
creates: "{{ item.pki_dir }}/private"
|
|
||||||
environment:
|
|
||||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
|
||||||
loop: "{{ openvpn_instances }}"
|
|
||||||
|
|
||||||
- name: build ca if missing
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: /opt/easy-rsa/easyrsa --batch build-ca nopass
|
|
||||||
creates: "{{ item.pki_dir }}/ca.crt"
|
|
||||||
environment:
|
|
||||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
|
||||||
EASYRSA_REQ_CN: "CA-{{ item.name }}"
|
|
||||||
loop: "{{ openvpn_instances }}"
|
|
||||||
|
|
||||||
- name: build server cert if missing
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: /opt/easy-rsa/easyrsa --batch build-server-full server nopass
|
|
||||||
creates: "{{ item.pki_dir }}/issued/server.crt"
|
|
||||||
environment:
|
|
||||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
|
||||||
loop: "{{ openvpn_instances }}"
|
|
||||||
|
|
||||||
- name: generate dh params if missing
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: /opt/easy-rsa/easyrsa gen-dh
|
|
||||||
creates: "{{ item.pki_dir }}/dh.pem"
|
|
||||||
environment:
|
|
||||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
|
||||||
loop: "{{ openvpn_instances }}"
|
|
||||||
|
|
||||||
- name: check client certificates validity
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: "openssl x509 -checkend 2592000 -in {{ item.pki_dir }}/issued/{{ item.client.name }}.crt"
|
|
||||||
register: cert_check
|
|
||||||
failed_when: false
|
|
||||||
changed_when: false
|
|
||||||
loop: "{{ cert_list }}"
|
|
||||||
|
|
||||||
- name: remove old cert file before reissue
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item.item.pki_dir }}/issued/{{ item.item.client.name }}.crt"
|
|
||||||
state: absent
|
|
||||||
loop: "{{ cert_check.results }}"
|
|
||||||
when: item.rc != 0
|
|
||||||
|
|
||||||
- name: remove old req file before reissue
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item.item.pki_dir }}/reqs/{{ item.item.client.name }}.req"
|
|
||||||
state: absent
|
|
||||||
loop: "{{ cert_check.results }}"
|
|
||||||
when: item.rc != 0
|
|
||||||
|
|
||||||
- name: remove old key file before reissue
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ item.item.pki_dir }}/private/{{ item.item.client.name }}.key"
|
|
||||||
state: absent
|
|
||||||
loop: "{{ cert_check.results }}"
|
|
||||||
when: item.rc != 0
|
|
||||||
|
|
||||||
- name: issue or renew client certificates
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: /opt/easy-rsa/easyrsa --batch build-client-full "{{ item.item.client.name }}" nopass
|
|
||||||
environment:
|
|
||||||
EASYRSA_PKI: "{{ item.item.pki_dir }}"
|
|
||||||
when: item.rc != 0
|
|
||||||
loop: "{{ cert_check.results }}"
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
---
|
|
||||||
- name: get latest easy-rsa release info
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: https://api.github.com/repos/OpenVPN/easy-rsa/releases/latest
|
|
||||||
return_content: true
|
|
||||||
register: easyrsa_release
|
|
||||||
run_once: true
|
|
||||||
check_mode: false
|
|
||||||
|
|
||||||
- name: set current easy-rsa version
|
|
||||||
ansible.builtin.set_fact:
|
|
||||||
easyrsa_version: "{{ easyrsa_release.json.tag_name | replace('v', '') }}"
|
|
||||||
easyrsa_asset_url: "{{ easyrsa_release.json.assets | selectattr('name', 'search', 'EasyRSA.*\\.tgz') | map(attribute='browser_download_url') | first }}"
|
|
||||||
|
|
||||||
- name: check easy-rsa installed version
|
|
||||||
ansible.builtin.command: /opt/easy-rsa/easyrsa version
|
|
||||||
register: easyrsa_current_version
|
|
||||||
changed_when: false
|
|
||||||
failed_when: false
|
|
||||||
|
|
||||||
- name: ensure easy-rsa directory exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /opt/easy-rsa
|
|
||||||
state: directory
|
|
||||||
mode: '0755'
|
|
||||||
check_mode: false
|
|
||||||
|
|
||||||
- name: update easy-rsa
|
|
||||||
ansible.builtin.unarchive:
|
|
||||||
src: "{{ easyrsa_asset_url }}"
|
|
||||||
dest: /opt/easy-rsa
|
|
||||||
remote_src: true
|
|
||||||
extra_opts:
|
|
||||||
- --strip-components=1
|
|
||||||
when: easyrsa_version not in (easyrsa_current_version.stdout | default(''))
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include install
|
|
||||||
ansible.builtin.include_tasks: install.yml
|
|
||||||
|
|
||||||
- name: include configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
|
|
||||||
- name: include client-certs.yml
|
|
||||||
ansible.builtin.include_tasks: client-certs.yml
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
client
|
|
||||||
dev tap0
|
|
||||||
proto tcp
|
|
||||||
remote 127.0.0.1 1195
|
|
||||||
resolv-retry infinite
|
|
||||||
nobind
|
|
||||||
persist-key
|
|
||||||
persist-tun
|
|
||||||
remote-cert-tls server
|
|
||||||
auth SHA256
|
|
||||||
cipher AES-256-GCM
|
|
||||||
verb 3
|
|
||||||
{% if item.1.ip is defined %}
|
|
||||||
route-metric {{ item.1.route_metric | default(50) }}
|
|
||||||
script-security 2
|
|
||||||
up "C:\\Windows\\System32\\netsh.exe interface ip set address name="OpenVPN TAP-Windows6" static {{ item.1.ip }} 255.255.255.0"
|
|
||||||
{% endif %}
|
|
||||||
<ca>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
|
||||||
</ca>
|
|
||||||
<cert>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
|
||||||
</cert>
|
|
||||||
<key>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
|
||||||
</key>
|
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
client
|
|
||||||
dev tun0
|
|
||||||
proto tcp
|
|
||||||
remote 127.0.0.1 1194
|
|
||||||
resolv-retry infinite
|
|
||||||
nobind
|
|
||||||
persist-key
|
|
||||||
persist-tun
|
|
||||||
remote-cert-tls server
|
|
||||||
auth SHA256
|
|
||||||
cipher AES-256-GCM
|
|
||||||
verb 3
|
|
||||||
<ca>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
|
||||||
</ca>
|
|
||||||
<cert>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
|
||||||
</cert>
|
|
||||||
<key>
|
|
||||||
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
|
||||||
</key>
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
---
|
|
||||||
- name: validate haproxy config
|
|
||||||
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
|
|
||||||
changed_when: false
|
|
||||||
listen: restart haproxy
|
|
||||||
|
|
||||||
- name: restart haproxy systemd service unit
|
|
||||||
ansible.builtin.systemd_service:
|
|
||||||
name: haproxy
|
|
||||||
daemon_reload: true
|
|
||||||
state: restarted
|
|
||||||
enabled: true
|
|
||||||
listen: restart haproxy
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
---
|
|
||||||
- name: render haproxy config
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
|
|
||||||
notify: restart haproxy
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install haproxy
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: haproxy
|
|
||||||
state: latest
|
|
||||||
update_cache: true
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include install
|
|
||||||
ansible.builtin.include_tasks: install.yml
|
|
||||||
|
|
||||||
- name: include configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
@@ -1,90 +0,0 @@
|
|||||||
global
|
|
||||||
log /dev/log local2
|
|
||||||
chroot /var/lib/haproxy
|
|
||||||
maxconn 4000
|
|
||||||
user haproxy
|
|
||||||
group haproxy
|
|
||||||
daemon
|
|
||||||
stats socket /var/lib/haproxy/stats mode 660 level admin
|
|
||||||
|
|
||||||
defaults
|
|
||||||
log global
|
|
||||||
mode tcp
|
|
||||||
option tcplog
|
|
||||||
option dontlognull
|
|
||||||
retries 3
|
|
||||||
timeout connect 5s
|
|
||||||
timeout client 1h
|
|
||||||
timeout server 1h
|
|
||||||
timeout check 10s
|
|
||||||
|
|
||||||
frontend http_frontend
|
|
||||||
bind 127.0.0.1:10080
|
|
||||||
mode http
|
|
||||||
option httplog
|
|
||||||
acl host_dttx hdr_end(host) -m end dttx.ru
|
|
||||||
use_backend dttx_http_srv if host_dttx
|
|
||||||
default_backend oyacoi_http_srv
|
|
||||||
|
|
||||||
backend oyacoi_http_srv
|
|
||||||
mode http
|
|
||||||
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
|
|
||||||
|
|
||||||
backend dttx_http_srv
|
|
||||||
mode http
|
|
||||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
|
|
||||||
|
|
||||||
frontend https_frontend
|
|
||||||
bind 127.0.0.1:10443
|
|
||||||
mode tcp
|
|
||||||
option tcplog
|
|
||||||
tcp-request inspect-delay 5s
|
|
||||||
tcp-request content accept if { req_ssl_hello_type 1 }
|
|
||||||
acl host_dttx req_ssl_sni -m end dttx.ru
|
|
||||||
acl host_telemt req_ssl_sni -m end regionculture.ru
|
|
||||||
use_backend dttx_https_srv if host_dttx
|
|
||||||
use_backend telemt_https_srv if host_telemt
|
|
||||||
default_backend oyacoi_https_srv
|
|
||||||
|
|
||||||
backend oyacoi_https_srv
|
|
||||||
mode tcp
|
|
||||||
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
|
|
||||||
|
|
||||||
backend dttx_https_srv
|
|
||||||
mode tcp
|
|
||||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
|
|
||||||
|
|
||||||
backend telemt_https_srv
|
|
||||||
mode tcp
|
|
||||||
option tcp-check
|
|
||||||
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
|
|
||||||
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
|
|
||||||
|
|
||||||
listen mcsmanager_service
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:24444
|
|
||||||
mode tcp
|
|
||||||
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
|
|
||||||
|
|
||||||
listen xmpp_c2s
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5222
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
|
|
||||||
|
|
||||||
listen xmpp_legacy_ssl
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5223
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
|
|
||||||
|
|
||||||
listen xmpp_s2s
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5269
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
|
|
||||||
|
|
||||||
listen prosody_proxy65
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5000
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
|
|
||||||
|
|
||||||
listen prosody_components
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5270
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
|
|
||||||
|
|
||||||
listen prosody_bosh_http
|
|
||||||
bind {{ hostvars['liqueur']['container_ip'] }}:5280
|
|
||||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
---
|
|
||||||
- name: deploy ifupdown interfaces
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: "{{ inventory_hostname }}/interfaces"
|
|
||||||
dest: /etc/network/interfaces
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
register: interfaces_conf
|
|
||||||
|
|
||||||
- name: reload ifupdown2
|
|
||||||
command: ifreload -a
|
|
||||||
when: interfaces_conf.changed
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
|
|
||||||
- name: include prerequisites
|
|
||||||
ansible.builtin.include_tasks: prerequisites.yml
|
|
||||||
tags: ifupdown2_prereqs
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install bridge-utils
|
|
||||||
ansible.builtin.package:
|
|
||||||
name: bridge-utils
|
|
||||||
state: present
|
|
||||||
register: bridge_utils_install
|
|
||||||
|
|
||||||
- name: ensure rt_tables.d directory exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/iproute2/rt_tables.d
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
register: rt_tables_dir
|
|
||||||
|
|
||||||
- name: reload ifupdown2
|
|
||||||
ansible.builtin.command: ifreload -a
|
|
||||||
when: bridge_utils_install.changed or rt_tables_dir.changed
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
---
|
|
||||||
- name: set required locales
|
|
||||||
community.general.locale_gen:
|
|
||||||
name: "{{ item }}"
|
|
||||||
state: present
|
|
||||||
loop: "{{ locales_list }}"
|
|
||||||
|
|
||||||
- name: configure /etc/locale.conf
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: /etc/locale.conf
|
|
||||||
content: LANG={{ locale_default }}
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include locales configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
/var/log/xray-core/*.log {
|
|
||||||
daily
|
|
||||||
rotate 4
|
|
||||||
compress
|
|
||||||
delaycompress
|
|
||||||
missingok
|
|
||||||
notifempty
|
|
||||||
copytruncate
|
|
||||||
}
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
---
|
|
||||||
- name: deploy logrotate config
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: "{{ inventory_hostname }}/"
|
|
||||||
dest: "/etc/logrotate.d/"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
- name: include logrotate configure
|
|
||||||
ansible.builtin.include_tasks: configure.yml
|
|
||||||
@@ -0,0 +1,49 @@
|
|||||||
|
flowtable ft {
|
||||||
|
hook ingress priority filter
|
||||||
|
devices = { eth0, eth1 }
|
||||||
|
}
|
||||||
|
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority filter; policy drop;
|
||||||
|
|
||||||
|
ct state established,related accept
|
||||||
|
ct state invalid drop
|
||||||
|
|
||||||
|
iif lo accept
|
||||||
|
ip protocol icmp accept
|
||||||
|
ip6 nexthdr icmpv6 accept
|
||||||
|
|
||||||
|
meta mark 0x00000001 accept
|
||||||
|
|
||||||
|
iifname eth0 tcp dport 22 accept
|
||||||
|
iifname eth0.11 tcp dport 22 accept
|
||||||
|
|
||||||
|
iifname eth1 udp dport 51820 accept
|
||||||
|
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
||||||
|
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
||||||
|
|
||||||
|
iifname eth0.3 udp dport 67 accept
|
||||||
|
iifname eth1 udp dport 68 accept
|
||||||
|
|
||||||
|
#include "/etc/nftables.d/90-input.nft"
|
||||||
|
}
|
||||||
|
|
||||||
|
chain forward {
|
||||||
|
type filter hook forward priority filter; policy drop;
|
||||||
|
|
||||||
|
ct state established,related accept
|
||||||
|
ct state invalid drop
|
||||||
|
|
||||||
|
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||||
|
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||||
|
|
||||||
|
tcp flags syn tcp option maxseg size set rt mtu
|
||||||
|
|
||||||
|
include "/etc/nftables.d/90-forward.nft"
|
||||||
|
}
|
||||||
|
|
||||||
|
chain output {
|
||||||
|
type route hook output priority filter; policy accept;
|
||||||
|
|
||||||
|
#include "/etc/nftables.d/90-output.nft"
|
||||||
|
}
|
||||||
@@ -2,6 +2,7 @@ chain postrouting {
|
|||||||
type nat hook postrouting priority srcnat; policy accept;
|
type nat hook postrouting priority srcnat; policy accept;
|
||||||
oifname eth1 masquerade
|
oifname eth1 masquerade
|
||||||
}
|
}
|
||||||
|
|
||||||
chain prerouting {
|
chain prerouting {
|
||||||
type nat hook prerouting priority dstnat; policy accept;
|
type nat hook prerouting priority dstnat; policy accept;
|
||||||
include "/etc/nftables.d/90-dstnat.nft"
|
include "/etc/nftables.d/90-dstnat.nft"
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
chain vpn_prerouting_dnat {
|
||||||
|
type nat hook prerouting priority dstnat - 5; policy accept;
|
||||||
|
|
||||||
|
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
|
||||||
|
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
|
||||||
|
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
|
||||||
|
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
|
||||||
|
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
|
||||||
|
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
|
||||||
|
}
|
||||||
|
|
||||||
|
chain vpn_postrouting_snat {
|
||||||
|
type nat hook postrouting priority srcnat; policy accept;
|
||||||
|
|
||||||
|
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
|
||||||
|
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
|
||||||
|
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
|
||||||
|
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
|
||||||
|
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
|
||||||
|
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
|
||||||
|
}
|
||||||
|
|
||||||
|
chain vpn_prerouting_pbr {
|
||||||
|
type filter hook prerouting priority mangle - 10; policy accept;
|
||||||
|
|
||||||
|
iifname wg0 ct state new counter ct mark set 0x000000c7
|
||||||
|
ip daddr 10.0.0.0/8 return
|
||||||
|
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
|
||||||
|
}
|
||||||
|
|
||||||
|
chain vpn_output_pbr {
|
||||||
|
type route hook output priority mangle - 10; policy accept;
|
||||||
|
|
||||||
|
ct mark 0x000000c7 counter meta mark set 0x000000c7
|
||||||
|
}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
chain proxy_prerouting {
|
||||||
|
type filter hook prerouting priority filter - 50; policy accept;
|
||||||
|
|
||||||
|
fib daddr type local accept
|
||||||
|
|
||||||
|
include "/etc/nftables.d/90-proxy.nft"
|
||||||
|
}
|
||||||
|
|
||||||
|
chain proxy_output {
|
||||||
|
type route hook output priority mangle; policy accept;
|
||||||
|
|
||||||
|
#meta mark 0x000000ff return
|
||||||
|
|
||||||
|
#meta l4proto { tcp, udp } ip daddr @cloudflare_ip meta mark set 0x00000001 accept
|
||||||
|
}
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
#!/usr/sbin/nft -f
|
||||||
|
|
||||||
|
flush ruleset
|
||||||
|
|
||||||
|
table inet filter {
|
||||||
|
include "/etc/nftables.d/40-sets.nft"
|
||||||
|
include "/etc/nftables.d/90-sets.nft"
|
||||||
|
include "/etc/nftables.d/10-filter.nft"
|
||||||
|
include "/etc/nftables.d/20-vpn.nft"
|
||||||
|
include "/etc/nftables.d/30-proxy.nft"
|
||||||
|
}
|
||||||
|
|
||||||
|
table ip nat {
|
||||||
|
include "/etc/nftables.d/10-nat.nft"
|
||||||
|
}
|
||||||
@@ -1,34 +0,0 @@
|
|||||||
flowtable ft {
|
|
||||||
hook ingress priority filter
|
|
||||||
devices = { eth0, eth1 }
|
|
||||||
}
|
|
||||||
chain input {
|
|
||||||
type filter hook input priority filter; policy drop;
|
|
||||||
ct state established,related accept
|
|
||||||
ct state invalid drop
|
|
||||||
iif lo accept
|
|
||||||
meta mark 0x00000001 accept
|
|
||||||
iifname br-eth0 tcp dport 22 accept
|
|
||||||
iifname eth0.11 tcp dport 22 accept
|
|
||||||
iifname tun0 tcp dport 22 accept
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
|
||||||
iifname eth0.3 udp dport 67 accept
|
|
||||||
iifname eth1 udp dport 68 accept
|
|
||||||
include "/etc/nftables.d/90-input.nft"
|
|
||||||
}
|
|
||||||
chain forward {
|
|
||||||
type filter hook forward priority filter; policy drop;
|
|
||||||
ct state established,related accept
|
|
||||||
ct state invalid drop
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
|
||||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
|
||||||
tcp flags syn tcp option maxseg size set rt mtu
|
|
||||||
include "/etc/nftables.d/90-forward.nft"
|
|
||||||
}
|
|
||||||
chain output {
|
|
||||||
type route hook output priority filter; policy accept;
|
|
||||||
include "/etc/nftables.d/90-output.nft"
|
|
||||||
}
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
chain proxy_prerouting {
|
|
||||||
type filter hook prerouting priority filter - 50; policy accept;
|
|
||||||
fib daddr type local accept
|
|
||||||
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
|
|
||||||
include "/etc/nftables.d/90-proxy-prerouting.nft"
|
|
||||||
}
|
|
||||||
chain proxy_output {
|
|
||||||
type route hook output priority mangle; policy accept;
|
|
||||||
meta mark != 0 return
|
|
||||||
include "/etc/nftables.d/90-proxy-output.nft"
|
|
||||||
}
|
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: restart nftables
|
- name: reload nftables
|
||||||
ansible.builtin.command: nft -f /etc/nftables.conf
|
ansible.builtin.command: nft -f /etc/nftables.conf
|
||||||
listen: restart nftables
|
listen: reload nftables
|
||||||
|
|||||||
@@ -1,58 +0,0 @@
|
|||||||
---
|
|
||||||
- name: ensure /etc/nftables.d exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/nftables.d
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
when: nftables_bootstrap_files | default(false)
|
|
||||||
|
|
||||||
- name: bootstrap empty config files
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: "/etc/nftables.d/{{ item }}"
|
|
||||||
content: ""
|
|
||||||
force: false
|
|
||||||
mode: "0644"
|
|
||||||
loop:
|
|
||||||
- 10-sets.nft
|
|
||||||
- 20-sets.nft
|
|
||||||
- 30-nat.nft
|
|
||||||
- 40-filter.nft
|
|
||||||
- 50-proxy.nft
|
|
||||||
- 90-dstnat.nft
|
|
||||||
- 90-forward.nft
|
|
||||||
- 90-input.nft
|
|
||||||
- 90-output.nft
|
|
||||||
- 90-proxy-output.nft
|
|
||||||
- 90-proxy-prerouting.nft
|
|
||||||
when: nftables_bootstrap_files | default(false)
|
|
||||||
|
|
||||||
- name: deploy nftables rules
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/nftables.d/{{ item | basename }}"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.nft') }}"
|
|
||||||
notify: restart nftables
|
|
||||||
|
|
||||||
- name: render nftable rules
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/nftables.d/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0644'
|
|
||||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.nft.j2') }}"
|
|
||||||
notify: restart nftables
|
|
||||||
|
|
||||||
- name: deploy nftables.conf
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: "0644"
|
|
||||||
validate: "nft -c -f %s"
|
|
||||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
|
|
||||||
notify: restart nftables
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
---
|
|
||||||
- name: install nftables
|
|
||||||
ansible.builtin.apt:
|
|
||||||
name: nftables
|
|
||||||
state: latest
|
|
||||||
update_cache: true
|
|
||||||
@@ -1,6 +1,41 @@
|
|||||||
---
|
---
|
||||||
- name: include nftables install
|
- name: ensure /etc/nftables.d exists
|
||||||
ansible.builtin.include_tasks: install.yml
|
ansible.builtin.file:
|
||||||
|
path: /etc/nftables.d
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
- name: include nftables configure
|
- name: deploy nftables rule
|
||||||
ansible.builtin.include_tasks: configure.yml
|
ansible.builtin.copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/nftables.d/{{ item }}"
|
||||||
|
mode: "0644"
|
||||||
|
loop:
|
||||||
|
- 10-filter.nft
|
||||||
|
- 10-nat.nft
|
||||||
|
- 20-vpn.nft
|
||||||
|
- 30-proxy.nft
|
||||||
|
- 40-sets.nft
|
||||||
|
notify: reload nftables
|
||||||
|
|
||||||
|
- name: render forward
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-forward.nft.j2
|
||||||
|
dest: /etc/nftables.d/90-forward.nft
|
||||||
|
mode: "0644"
|
||||||
|
notify: reload nftables
|
||||||
|
|
||||||
|
- name: render dstnat
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-dstnat.nft.j2
|
||||||
|
dest: /etc/nftables.d/90-dstnat.nft
|
||||||
|
mode: "0644"
|
||||||
|
notify: reload nftables
|
||||||
|
|
||||||
|
- name: deploy nftables.conf
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: nftables.conf
|
||||||
|
dest: /etc/nftables.conf
|
||||||
|
mode: "0644"
|
||||||
|
validate: "nft -c -f %s"
|
||||||
|
notify: reload nftables
|
||||||
|
|||||||
@@ -0,0 +1,31 @@
|
|||||||
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
|
{% macro render_dstnat_rule(ifaces, proto, port, target_ip, item_name) %}
|
||||||
|
{% set lines = [] %}
|
||||||
|
{% set active_ifaces = ifaces if (ifaces is iterable and ifaces is not string) else [ifaces] %}
|
||||||
|
{% for current_iface in active_ifaces %}
|
||||||
|
{% set comment_str = ' comment "' ~ current_iface ~ ' -> ' ~ item_name ~ '"' %}
|
||||||
|
{% set rule_line = 'iifname "' ~ current_iface ~ '" ' ~ proto ~ ' dport ' ~ port ~ ' counter dnat ip to ' ~ target_ip ~ ':' ~ port ~ comment_str %}
|
||||||
|
{% set _ = lines.append(rule_line) %}
|
||||||
|
{% endfor %}
|
||||||
|
{{ lines | join('\n') }}
|
||||||
|
{% endmacro %}
|
||||||
|
{% filter regex_replace('\n[ \t]*\n+', '\n') %}
|
||||||
|
{% for item in groups[nft_managed_group] | sort %}
|
||||||
|
{% set client = hostvars[item] %}
|
||||||
|
{% if 'nft_dst' in client and client.nft_dst is not none %}
|
||||||
|
{% set target_ip = client.container_ip | default(client.ansible_host | default(item)) %}
|
||||||
|
{% set raw_expose = client.nft_dst %}
|
||||||
|
{% set exposes = raw_expose if (raw_expose is iterable and raw_expose is not string and raw_expose is not mapping) else [raw_expose] %}
|
||||||
|
{% for expose in exposes %}
|
||||||
|
{% set protos = expose.proto if (expose.proto is defined and expose.proto is iterable and expose.proto is not string) else [expose.proto | default('tcp')] %}
|
||||||
|
{% set ports = expose.port if (expose.port is defined and expose.port is iterable and expose.port is not string) else [expose.port] %}
|
||||||
|
{% set ifaces = expose.iface %}
|
||||||
|
{% for p in protos | sort %}
|
||||||
|
{% for port in ports | sort %}
|
||||||
|
{{ render_dstnat_rule(ifaces, p, port, target_ip, item) }}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfilter %}
|
||||||
@@ -0,0 +1,95 @@
|
|||||||
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
|
{% set ip_to_host = {} %}
|
||||||
|
{% for host in groups['all'] | default([]) %}
|
||||||
|
{% set hv = hostvars[host] | default({}) %}
|
||||||
|
{% if hv.ansible_host is defined and (hv.ansible_connection | default('')) != 'community.proxmox.proxmox_pct_remote' %}
|
||||||
|
{% set _ = ip_to_host.update({(hv.ansible_host | string): host}) %}
|
||||||
|
{% endif %}
|
||||||
|
{% if hv.container_ip is defined and hv.container_ip %}
|
||||||
|
{% set _ = ip_to_host.update({(hv.container_ip | string): host}) %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% macro render_rule(service_name, iif, saddr, oif, daddr, protos, ports, dest_name) %}
|
||||||
|
{% set lines = [] %}
|
||||||
|
{% set iifs = iif if (iif is iterable and iif is not string) else [iif] %}
|
||||||
|
{% set oifs = oif if (oif is iterable and oif is not string) else [oif] %}
|
||||||
|
{% set active_protos = protos | sort if protos | length > 0 else [none] %}
|
||||||
|
{% set active_ports = ports if ports | length > 0 else [none] %}
|
||||||
|
{% for current_iif in iifs %}
|
||||||
|
{% for current_oif in oifs %}
|
||||||
|
{% for p in active_protos %}
|
||||||
|
{% for port in active_ports %}
|
||||||
|
{% set proto_rule = '' %}
|
||||||
|
{% if p and port %}
|
||||||
|
{% set proto_rule = p ~ ' dport ' ~ port %}
|
||||||
|
{% elif p %}
|
||||||
|
{% set proto_rule = 'meta l4proto ' ~ p %}
|
||||||
|
{% endif %}
|
||||||
|
{# Resolve source name: prefer an explicit host resolved via saddr, otherwise fall back
|
||||||
|
to the current interface for this specific line (not the whole iif list/service_name) #}
|
||||||
|
{% set resolved_service_name = service_name if service_name else current_iif %}
|
||||||
|
{% if saddr and ip_to_host[saddr | string] is defined %}
|
||||||
|
{% set resolved_service_name = ip_to_host[saddr | string] %}
|
||||||
|
{% endif %}
|
||||||
|
{# Resolve destination IP to inventory hostname only for comment #}
|
||||||
|
{% set resolved_dest_name = dest_name %}
|
||||||
|
{% if daddr and ip_to_host[daddr | string] is defined %}
|
||||||
|
{% set resolved_dest_name = ip_to_host[daddr | string] %}
|
||||||
|
{% endif %}
|
||||||
|
{% set comment_text = resolved_service_name ~ ' -> ' ~ resolved_dest_name %}
|
||||||
|
{% set comment_str = ' comment "' ~ comment_text ~ '"' %}
|
||||||
|
{% set parts = ['iifname "' ~ current_iif ~ '"'] %}
|
||||||
|
{% if saddr %}
|
||||||
|
{% set _ = parts.append('ip saddr ' ~ saddr) %}
|
||||||
|
{% endif %}
|
||||||
|
{% if current_oif %}
|
||||||
|
{% set _ = parts.append('oifname "' ~ current_oif ~ '"') %}
|
||||||
|
{% endif %}
|
||||||
|
{% if daddr %}
|
||||||
|
{% set _ = parts.append('ip daddr ' ~ daddr) %}
|
||||||
|
{% endif %}
|
||||||
|
{% if proto_rule %}
|
||||||
|
{% set _ = parts.append(proto_rule) %}
|
||||||
|
{% endif %}
|
||||||
|
{% set _ = parts.append('counter accept' ~ comment_str) %}
|
||||||
|
{% set _ = lines.append(parts | join(' ')) %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{{ lines | join('\n') }}
|
||||||
|
{% endmacro %}
|
||||||
|
{% filter regex_replace('\n[ \t]*\n+', '\n') %}
|
||||||
|
{# === Managed Hosts Forward Rules === #}
|
||||||
|
{% for item in groups[nft_managed_group] | sort %}
|
||||||
|
{% set client = hostvars[item] %}
|
||||||
|
{% if client.nft_to is defined and client.nft_to is not none %}
|
||||||
|
{% set raw_rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string and client.nft_to is not mapping) else [client.nft_to] %}
|
||||||
|
{% for r in raw_rules %}
|
||||||
|
{% set rule_dict = r if (r is mapping) else {'to': r} %}
|
||||||
|
{% set raw_dests = rule_dict.to if (rule_dict.to is iterable and rule_dict.to is not string) else [rule_dict.to] %}
|
||||||
|
{% set protos = rule_dict.proto if (rule_dict.proto is defined and rule_dict.proto is iterable and rule_dict.proto is not string) else ([rule_dict.proto] if rule_dict.proto is defined else []) %}
|
||||||
|
{% set ports = rule_dict.port if (rule_dict.port is defined and rule_dict.port is iterable and rule_dict.port is not string) else ([rule_dict.port] if rule_dict.port is defined else []) %}
|
||||||
|
{% for dest in raw_dests %}
|
||||||
|
{% set dest_name = dest | regex_replace('^zone:', '') %}
|
||||||
|
{% if dest.startswith('zone:') %}
|
||||||
|
{{ render_rule(item, client.zone_iface, client.container_ip, dest.split(':')[1], none, protos, ports, dest_name) }}
|
||||||
|
{% else %}
|
||||||
|
{{ render_rule(item, client.zone_iface, client.container_ip, hostvars[dest].zone_iface, hostvars[dest].container_ip, protos, ports, dest_name) }}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% for item in groups[nft_managed_group] | sort %}
|
||||||
|
{% set client = hostvars[item] %}
|
||||||
|
{% if client.nft_from is defined and client.nft_from is not none %}
|
||||||
|
{% set raw_from_rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string and client.nft_from is not mapping) else [client.nft_from] %}
|
||||||
|
{% for r in raw_from_rules %}
|
||||||
|
{% set protos = r.proto if (r.proto is defined and r.proto is iterable and r.proto is not string) else ([r.proto] if r.proto is defined else []) %}
|
||||||
|
{% set ports = r.port if (r.port is defined and r.port is iterable and r.port is not string) else ([r.port] if r.port is defined else []) %}
|
||||||
|
{{ render_rule(none, r.iface, none, client.zone_iface, client.container_ip, protos, ports, item) }}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endfilter %}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user