diff --git a/roles/dnsmasq/files/10-upstream.conf b/roles/dnsmasq/files/10-upstream.conf new file mode 100644 index 0000000..49215f2 --- /dev/null +++ b/roles/dnsmasq/files/10-upstream.conf @@ -0,0 +1,14 @@ +interface=lo +interface=eth0 +interface=eth0.2 +interface=eth0.3 +interface=eth0.4 +interface=eth0.10 +interface=eth0.11 +interface=eth0.12 +bind-dynamic +no-resolv +server=127.0.0.1#5353 +#server=1.1.1.1 +domain=lan +local=/lan/ diff --git a/roles/dnsmasq/files/20-custom-domains.conf b/roles/dnsmasq/files/20-custom-domains.conf new file mode 100644 index 0000000..6788c87 --- /dev/null +++ b/roles/dnsmasq/files/20-custom-domains.conf @@ -0,0 +1,10 @@ +server=/dev.oyacoi.ru/9.9.9.9 +server=/vector.oyacoi.ru/9.9.9.9 +server=/.themoviedb.org/9.9.9.9 +server=/.tmdb.org/9.9.9.9 +server=/tmdb-image-prod.b-cdn.net/9.9.9.9 +server=/infolada.ru/217.113.115.150 +server=/infolada.ru/217.113.114.100 +server=/start.infolada.ru/217.113.115.150 +server=/start.infolada.ru/217.113.114.100 +conf-file=/var/lib/xray-lists/generated/nftsets.conf diff --git a/roles/dnsmasq/files/20-dhcp.conf b/roles/dnsmasq/files/20-dhcp.conf new file mode 100644 index 0000000..18712aa --- /dev/null +++ b/roles/dnsmasq/files/20-dhcp.conf @@ -0,0 +1,3 @@ +dhcp-range=interface:eth0.3,10.3.0.200,10.3.0.254,255.255.255.0,2h +dhcp-option=interface:eth0.3,option:router,10.3.0.1 +dhcp-option=interface:eth0.3,option:dns-server,10.3.0.1 diff --git a/roles/dnsmasq/files/20-dns-optimizations.conf b/roles/dnsmasq/files/20-dns-optimizations.conf new file mode 100644 index 0000000..fc6a38f --- /dev/null +++ b/roles/dnsmasq/files/20-dns-optimizations.conf @@ -0,0 +1,4 @@ +filterwin2k +domain-needed +bogus-priv +cache-size=0 diff --git a/roles/dnsmasq/tasks/main.yml b/roles/dnsmasq/tasks/main.yml index 9b84308..08d7a40 100644 --- a/roles/dnsmasq/tasks/main.yml +++ b/roles/dnsmasq/tasks/main.yml @@ -5,6 +5,18 @@ state: directory mode: "0755" +- name: deploy dnsmasq rule + ansible.builtin.copy: + src: "{{ item }}" + dest: "/etc/dnsmasq.d/{{ item }}" + mode: "0644" + loop: + - 10-upstream.conf + - 20-custom-domains.conf + - 20-dhcp.conf + - 20-dns-optimizations.conf + notify: restart dnsmasq + - name: render local ansible.builtin.template: src: 90-local.conf.j2 @@ -12,6 +24,13 @@ mode: "0644" notify: restart dnsmasq +- name: render dhcp-host + ansible.builtin.template: + src: 90-dhcp-host.conf.j2 + dest: /etc/dnsmasq.d/90-dhcp-host.conf + mode: "0644" + notify: restart dnsmasq + - name: render domain ansible.builtin.template: src: 90-domains.conf.j2 diff --git a/roles/dnsmasq/templates/90-dhcp-host.conf.j2 b/roles/dnsmasq/templates/90-dhcp-host.conf.j2 new file mode 100644 index 0000000..d7c4d71 --- /dev/null +++ b/roles/dnsmasq/templates/90-dhcp-host.conf.j2 @@ -0,0 +1,13 @@ +#jinja2: trim_blocks: True, lstrip_blocks: True +{% for item in groups[dnsmasq_managed_group] | sort %} + {% set client = hostvars[item] %} + {% set ip = client.container_ip | default(client.ansible_host | default(none)) %} + {% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %} + {% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %} + {% for entry in entries %} + {% if entry.mac %} +dhcp-host={{ entry.mac }},{{ ip }},{{ item }} + {% endif %} + {% endfor %} + {% endif %} +{% endfor %}