add nginx, sshd, ssl roles

This commit is contained in:
2026-09-20 22:14:56 +00:00
parent ba9e1a664f
commit c640406c10
131 changed files with 1535 additions and 780 deletions
+14
View File
@@ -0,0 +1,14 @@
# handlers/main.yml
---
- name: validate nginx config
ansible.builtin.command: nginx -t
changed_when: false
listen: restart nginx
- name: restart nginx systemd service unit
ansible.builtin.systemd_service:
name: nginx
daemon_reload: true
state: restarted
enabled: true
listen: restart nginx
+10
View File
@@ -0,0 +1,10 @@
---
- name: deploy nginx config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/nginx/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
notify: restart nginx
+81
View File
@@ -0,0 +1,81 @@
---
- name: install prerequisites for nginx repository
ansible.builtin.apt:
name:
- curl
- gnupg2
- ca-certificates
- lsb-release
- debian-archive-keyring
state: present
update_cache: true
- name: check if nginx keyring already exists
ansible.builtin.stat:
path: /usr/share/keyrings/nginx-archive-keyring.gpg
register: nginx_keyring
- name: download nginx gpg key
ansible.builtin.get_url:
url: https://nginx.org/keys/nginx_signing.key
dest: /tmp/nginx_signing.key
mode: '0644'
when: not nginx_keyring.stat.exists
- name: dearmor nginx gpg key
ansible.builtin.command:
cmd: gpg --dearmor --yes -o /usr/share/keyrings/nginx-archive-keyring.gpg /tmp/nginx_signing.key
when: not nginx_keyring.stat.exists
- name: ensure /root/.gnupg exists
ansible.builtin.file:
path: /root/.gnupg
state: directory
mode: '0700'
owner: root
group: root
- name: verify nginx signing key fingerprint
ansible.builtin.command:
cmd: gpg --dry-run --quiet --no-keyring --import --import-options import-show /usr/share/keyrings/nginx-archive-keyring.gpg
register: nginx_key_check
changed_when: false
- name: check nginx signing key fingerprint
ansible.builtin.fail:
msg: "nginx signing key fingerprint mismatch! Got: {{ nginx_key_check.stdout }}"
when: "'573BFD6B3D8FBC641079A6ABABF5BD827BD9BF62' not in nginx_key_check.stdout"
- name: add nginx apt repository
ansible.builtin.copy:
dest: /etc/apt/sources.list.d/nginx.list
content: >-
deb [signed-by=/usr/share/keyrings/nginx-archive-keyring.gpg]
https://nginx.org/packages/{{ 'mainline/' if (nginx_use_mainline | default(false)) else '' }}debian
{{ ansible_facts['distribution_release'] }} nginx
owner: root
group: root
mode: '0644'
register: nginx_repo_file
- name: set up repository pinning for nginx
ansible.builtin.copy:
dest: /etc/apt/preferences.d/99nginx
content: |
Package: *
Pin: origin nginx.org
Pin: release o=nginx
Pin-Priority: 900
owner: root
group: root
mode: '0644'
- name: update apt cache
ansible.builtin.apt:
update_cache: true
when: nginx_repo_file.changed
- name: install nginx
ansible.builtin.apt:
name: nginx
state: present
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,37 @@
user www-data;
worker_processes auto;
worker_cpu_affinity auto;
pid /run/nginx.pid;
error_log /var/log/nginx/error.log;
include /etc/nginx/modules-enabled/*.conf;
events {
worker_connections 768;
}
stream {
upstream haproxy_http {
server 127.0.0.1:10080;
}
upstream haproxy_backend {
server 127.0.0.1:10443;
}
upstream stunnel_tun0_backend {
server 127.0.0.1:8443;
}
upstream stunnel_tap0_backend {
server 127.0.0.1:8444;
}
map $ssl_preread_server_name $backend {
liqueur.oyacoi.ru stunnel_tun0_backend;
absinthe.oyacoi.ru stunnel_tap0_backend;
default haproxy_backend;
}
server {
listen {{ container_ip }}:80;
proxy_pass haproxy_http;
}
server {
listen {{ container_ip }}:443;
proxy_pass $backend;
ssl_preread on;
}
}