refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
+3
View File
@@ -35,6 +35,9 @@ chain forward {
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
iifname "zt*" oifname "eth0" accept
iifname "eth0" oifname "zt*" accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
+3 -2
View File
@@ -1,5 +1,6 @@
---
- name: install nftables
ansible.builtin.package:
ansible.builtin.apt:
name: nftables
state: present
state: latest
update_cache: true
+1 -1
View File
@@ -2,5 +2,5 @@
- name: include nftables install
ansible.builtin.include_tasks: install.yml
- name: include nftables configurure
- name: include nftables configure
ansible.builtin.include_tasks: configure.yml
+1 -1
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_dst' in client and client.nft_dst is not none %}
{% set target_ip = client.container_ip %}
+2 -2
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_to' in client and client.nft_to is not none %}
{% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %}
@@ -27,7 +27,7 @@ iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{
{% endfor %}
{% endif %}
{% endfor %}
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_from' in client and client.nft_from is not none %}
{% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %}