add nginx, sshd, ssl roles

This commit is contained in:
2026-09-20 22:14:56 +00:00
parent ba9e1a664f
commit c640406c10
131 changed files with 1535 additions and 780 deletions
+50
View File
@@ -0,0 +1,50 @@
auto lo
iface lo inet loopback
post-up ip rule add fwmark 0x1 lookup 100 2>/dev/null || true
post-up ip route add local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
auto br-eth0
iface br-eth0 inet static
address 10.1.0.1/24
bridge_ports eth0 tap0
bridge_stp off
pre-up ip tuntap add dev tap0 mode tap || true
post-down ip tuntap del dev tap0 mode tap || true
auto eth0
iface eth0 inet manual
auto eth0.2
iface eth0.2 inet static
address 10.2.0.1/24
vlan-raw-device eth0
auto eth0.3
iface eth0.3 inet static
address 10.3.0.1/24
vlan-raw-device eth0
auto eth0.4
iface eth0.4 inet static
address 10.4.0.1/24
vlan-raw-device eth0
auto eth0.10
iface eth0.10 inet static
address 10.10.0.1/24
vlan-raw-device eth0
auto eth0.11
iface eth0.11 inet static
address 10.11.0.1/24
vlan-raw-device eth0
auto eth0.12
iface eth0.12 inet static
address 10.12.0.1/24
vlan-raw-device eth0
auto eth1
iface eth1 inet dhcp
@@ -1,7 +1,7 @@
---
- name: deploy ifupdown interfaces config
ansible.builtin.template:
src: interfaces
- name: deploy ifupdown interfaces
ansible.builtin.copy:
src: "{{ inventory_hostname }}/interfaces"
dest: /etc/network/interfaces
owner: root
group: root
+6 -2
View File
@@ -1,3 +1,7 @@
---
- name: include network configuration
include_tasks: network.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
- name: include prerequisites
ansible.builtin.include_tasks: prerequisites.yml
tags: ifupdown2_prereqs
+17
View File
@@ -0,0 +1,17 @@
---
- name: install bridge-utils
ansible.builtin.package:
name: bridge-utils
state: present
register: bridge_utils_install
- name: ensure rt_tables.d directory exists
ansible.builtin.file:
path: /etc/iproute2/rt_tables.d
state: directory
mode: "0755"
register: rt_tables_dir
- name: reload ifupdown2
ansible.builtin.command: ifreload -a
when: bridge_utils_install.changed or rt_tables_dir.changed
-20
View File
@@ -1,20 +0,0 @@
{% for item in ifupdown2 %}
auto {{ item.iface }}
iface {{ item.iface }}{% if item.method is defined %} inet {{ item.method }}
{% endif %}
{% if item.address is defined %}
address {{ item.address }}
{% endif %}
{% if item['vlan-raw-device'] is defined %}
vlan-raw-device {{ item['vlan-raw-device'] }}
{% endif %}
{% if item.routing is defined %}
{% for route in item.routing %}
{{ route }}
{% endfor %}
{% endif %}
{% if not loop.last %}
{% endif %}
{% endfor %}