63 lines
2.0 KiB
YAML
63 lines
2.0 KiB
YAML
---
|
|||
|
|
#- name: collect xray policy hosts
|
||
|
|
# ansible.builtin.set_fact:
|
||
|
|
# _xray_hosts_with_policy: >-
|
||
|
|
# {{
|
||
|
|
# (_xray_hosts_with_policy | default([]))
|
||
|
|
# + [{'inventory_hostname': item, 'xray_policy': hostvars[item].xray_policy}]
|
||
|
|
# }}
|
||
|
|
# loop: "{{ groups[xray_managed_group] }}"
|
||
|
|
# when: hostvars[item].xray_policy is defined
|
||
|
|
|
||
|
|
#- name: validate xray policy sets
|
||
|
|
# ansible.builtin.assert:
|
||
|
|
# that:
|
||
|
|
# - (item.1.bypass | default(item.1.proxy)) == 'all' or
|
||
|
|
# (item.1.bypass | default(item.1.proxy)) in xray_ip_sets or
|
||
|
|
# (item.1.bypass | default(item.1.proxy)) in xray_domain_sets or
|
||
|
|
# (item.1.bypass | default(item.1.proxy)) in (xray_static_sets | default([]))
|
||
|
|
# fail_msg: "host {{ item.0.inventory_hostname }}: unknown xray set '{{ item.1.bypass | default(item.1.proxy) }}'"
|
||
|
|
# quiet: true
|
||
|
|
# loop: "{{ query('ansible.builtin.subelements', _xray_hosts_with_policy | default([]), 'xray_policy', {'skip_missing': True}) }}"
|
||
|
|
# loop_control:
|
||
|
|
# label: "{{ item.0.inventory_hostname }} -> {{ item.1.bypass | default(item.1.proxy) }}"
|
||
|
|
|
||
|
|
- name: render xray-lists config
|
||
|
|
ansible.builtin.template:
|
||
|
|
src: xray-config.yaml.j2
|
||
|
|
dest: /var/lib/xray-lists/config.yaml
|
||
|
|
mode: "0640"
|
||
|
|
notify: restart xray-lists timer
|
||
|
|
|
||
|
|
- name: bootstrap empty config files
|
||
|
|
ansible.builtin.copy:
|
||
|
|
dest: "/etc/nftables.d/{{ item }}"
|
||
|
|
content: ""
|
||
|
|
force: false
|
||
|
|
mode: "0644"
|
||
|
|
loop:
|
||
|
|
- 90-sets.nft
|
||
|
|
- 90-proxy-prerouting.nft
|
||
|
|
- 90-proxy-output.nft
|
||
|
|
|
||
|
|
- name: render nft sets
|
||
|
|
ansible.builtin.template:
|
||
|
|
src: 90-sets.nft.j2
|
||
|
|
dest: /etc/nftables.d/90-sets.nft
|
||
|
|
mode: "0644"
|
||
|
|
notify: reload nftables
|
||
|
|
|
||
|
|
- name: render proxy prerouting
|
||
|
|
ansible.builtin.template:
|
||
|
|
src: 90-proxy-prerouting.nft.j2
|
||
|
|
dest: /etc/nftables.d/90-proxy-prerouting.nft
|
||
|
|
mode: "0644"
|
||
|
|
notify: reload nftables
|
||
|
|
|
||
|
|
- name: render proxy output
|
||
|
|
ansible.builtin.template:
|
||
|
|
src: 90-proxy-output.nft.j2
|
||
|
|
dest: /etc/nftables.d/90-proxy-output.nft
|
||
|
|
mode: "0644"
|
||
|
|
notify: reload nftables
|