add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
---
|
||||
- name: deploy rasy-rsa
|
||||
hosts: localhost
|
||||
connection: local
|
||||
become: true
|
||||
roles:
|
||||
- easy-rsa
|
||||
|
||||
- name: configure liqueur openvpn
|
||||
hosts: liqueur
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- openvpn
|
||||
|
||||
- name: configure router openvpn
|
||||
hosts: router
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- openvpn
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
- name: configure over ssh
|
||||
hosts: liqueur
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: >-
|
||||
-o UserKnownHostsFile=/dev/null
|
||||
-o StrictHostKeyChecking=no
|
||||
-o PreferredAuthentications=publickey,password
|
||||
-o PubkeyAuthentication=yes
|
||||
roles:
|
||||
- authorized_key
|
||||
- sshd
|
||||
- certbot
|
||||
- sysctl
|
||||
- nginx
|
||||
- nftables
|
||||
- stunnel4
|
||||
- openvpn
|
||||
- haproxy
|
||||
@@ -18,12 +18,11 @@
|
||||
- timezone
|
||||
- locales
|
||||
- sysctl
|
||||
- stunnel4
|
||||
- openvpn
|
||||
- xray-core
|
||||
- xray-client
|
||||
- logrotate
|
||||
- dnsmasq
|
||||
- xray-lists
|
||||
- unbound
|
||||
- wireguard-tools
|
||||
- zerotier-one
|
||||
- nftables
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
---
|
||||
- hosts: router
|
||||
become: yes
|
||||
roles:
|
||||
- xray-core
|
||||
Reference in New Issue
Block a user