refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
+1
View File
@@ -0,0 +1 @@
ansible_python_interpreter: /usr/bin/python3
+25
View File
@@ -0,0 +1,25 @@
zfs:
- name: rpool/data/pgsql
extra_zfs_properties:
quota: "21474836480"
- name: rpool/data/vaultwarden
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/gitea
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/slskd
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/rtorrent
extra_zfs_properties:
quota: "1073741824"
- name: rpool/data/jellfin
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/prosody
extra_zfs_properties:
quota: "10737418240"
- name: rpool/data/steamcmd
extra_zfs_properties:
quota: "21474836480"
+3
View File
@@ -35,6 +35,9 @@ nft_to:
- to: bylampa
proto: tcp
port: 80
- to: ps3
proto: tcp
port: 80
- to: firebat
proto: tcp
port: 8006
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+20 -1
View File
@@ -1,4 +1,7 @@
nft_to:
- to: nginx
proto: tcp
port: [80,443]
- to: nfs
proto: [tcp,udp]
port: [2049,111,32765,32767]
@@ -9,7 +12,23 @@ nft_to:
proto: tcp
port: 22
nft_dst:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
nft_from:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
- proxy: all
-6
View File
@@ -1,6 +0,0 @@
ansible_host: 10.1.0.1
ansible_connection: ssh
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
zone_iface: eth0
container_ip: 10.1.0.1
+37
View File
@@ -0,0 +1,37 @@
ifupdown2:
- iface: lo
method: loopback
routing:
- "post-up ip rule add fwmark 0x1 lookup 100 2>/dev/null || true"
- "post-up ip route add local 0.0.0.0/0 dev lo table 100 2>/dev/null || true"
- "pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true"
- "pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true"
- iface: eth0
method: static
address: 10.1.0.1/24
- iface: eth0.2
method: static
address: 10.2.0.1/24
vlan-raw-device: eth0
- iface: eth0.3
method: static
address: 10.3.0.1/24
vlan-raw-device: eth0
- iface: eth0.4
method: static
address: 10.4.0.1/24
vlan-raw-device: eth0
- iface: eth0.10
method: static
address: 10.10.0.1/24
vlan-raw-device: eth0
- iface: eth0.11
method: static
address: 10.11.0.1/24
vlan-raw-device: eth0
- iface: eth0.12
method: static
address: 10.12.0.1/24
vlan-raw-device: eth0
- iface: eth1
method: dhcp
+13
View File
@@ -0,0 +1,13 @@
logrotate:
- name: xray-core
paths:
- /var/log/xray-core/access.log
- /var/log/xray-core/error.log
options:
- daily
- rotate 4
- compress
- delaycompress
- missingok
- notifempty
- copytruncate
+2
View File
@@ -0,0 +1,2 @@
zone_iface: "eth0"
container_ip: "10.1.0.1"
@@ -0,0 +1,3 @@
nft_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}"
dnsmasq_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}"
xray_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}"
+5
View File
@@ -0,0 +1,5 @@
sysctl:
net.ipv4.ip_forward: 1
net.ipv4.conf.lo.rp_filter: 0
net.ipv4.conf.all.rp_filter: 0
net.ipv4.conf.wg0.rp_filter: 0
+62
View File
@@ -0,0 +1,62 @@
xray_ip_sets:
refilter:
urls:
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
cdn:
urls:
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
telegram:
urls:
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
russian_whitelist:
urls:
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
cloudflare:
static:
- 1.1.1.1
- 1.0.0.1
google:
urls:
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
xray_domain_sets:
v2ray:
urls:
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
torrent:
static:
- bt.t-ru.org
- bt2.t-ru.org
- bt3.t-ru.org
- bt4.t-ru.org
- rutracker.org
- rutracker.net
- tapochek.net
- bt.tapochek.net
- nnmclub.to
- rutor.info
- bigfangroup.org
vps:
static:
- dev.oyacoi.ru
- vector.oyacoi.ru
terraform:
static:
- terraform.io
- hashicorp.com
output_rules:
- cloudflare
xray_static_sets:
- private
xray_lists_global:
cache_dir: /var/lib/xray-lists/cache
output_dir: /var/lib/xray-lists/generated
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
proxy: "socks5h://127.0.0.1:1080"
http_timeout: 20
xray_tproxy_port: 61219
xray_fwmark: "0x00000001"
@@ -0,0 +1,7 @@
$ANSIBLE_VAULT;1.1;AES256
30313538656633333565613030356534313035646337323763663565326431323437623636656365
3139663263383363626438396133623639636565386230640a333166373634343630663566396264
64613435643864373264323061336438396339326466663637363536663165373231333738313466
6532343566653238620a336633376336303439656163393165323364663033663432643034396262
61383431663836613335623761366433366364363938643935636634313631653935306230346234
3934303233633837356437636639353563376563613237646133
+3
View File
@@ -1,4 +1,7 @@
nft_to:
- to: [zone:eth0.12]
proto: tcp
port: 22
- to: firebat
proto: tcp
port: [22, 8006]
-9
View File
@@ -1,9 +0,0 @@
nft_dst:
- iface: eth0
proto: udp
port: 2456
nft_from:
- iface: [eth0,wg0]
proto: udp
port: [2456,2457]
+15
View File
@@ -0,0 +1,15 @@
nft_dst:
- iface: eth1
proto: udp
port: [2456,2457]
nft_from:
- iface: [eth0,wg0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
- iface: [eth0,wg0]
proto: udp
port: [2302,2304,2456,2457,27016]
- iface: eth1
proto: udp
port: [2456,2457]
+6
View File
@@ -0,0 +1,6 @@
user:
- name: steamcmd
create_home: true
home: /var/lib/steamcmd
shell: /bin/bash
system: true
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all