add nginx, sshd, ssl roles
This commit is contained in:
@@ -0,0 +1,9 @@
|
||||
setuid = stunnel4
|
||||
setgid = stunnel4
|
||||
pid = /var/run/stunnel4/absinthe.pid
|
||||
output = /var/log/stunnel4/absinthe.log
|
||||
[openvpn]
|
||||
cert = /etc/letsencrypt/live/absinthe.oyacoi.ru/fullchain.pem
|
||||
key = /etc/letsencrypt/live/absinthe.oyacoi.ru/privkey.pem
|
||||
accept = 127.0.0.1:8444
|
||||
connect = 127.0.0.1:1195
|
||||
@@ -0,0 +1,9 @@
|
||||
setuid = stunnel4
|
||||
setgid = stunnel4
|
||||
pid = /var/run/stunnel4/liqueur.pid
|
||||
output = /var/log/stunnel4/liqueur.log
|
||||
[openvpn]
|
||||
cert = /etc/letsencrypt/live/liqueur.oyacoi.ru/fullchain.pem
|
||||
key = /etc/letsencrypt/live/liqueur.oyacoi.ru/privkey.pem
|
||||
accept = 127.0.0.1:8443
|
||||
connect = 127.0.0.1:1194
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: restart stunnel4
|
||||
ansible.builtin.service:
|
||||
name: stunnel4
|
||||
state: restarted
|
||||
listen: restart stunnel4
|
||||
@@ -0,0 +1,36 @@
|
||||
---
|
||||
- name: ensure /var/run/stunnel exists
|
||||
ansible.builtin.file:
|
||||
path: /var/run/stunnel
|
||||
owner: stunnel4
|
||||
group: stunnel4
|
||||
state: directory
|
||||
mode: "0755"
|
||||
|
||||
- name: ensure /var/log/stunnel exists
|
||||
ansible.builtin.file:
|
||||
path: /var/log/stunnel
|
||||
state: directory
|
||||
owner: stunnel4
|
||||
group: stunnel4
|
||||
mode: "0755"
|
||||
|
||||
- name: deploy stunnel config
|
||||
ansible.builtin.copy:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/stunnel/{{ item | basename }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('fileglob', role_path + '/files/' + inventory_hostname + '/*.conf') }}"
|
||||
notify: restart stunnel4
|
||||
|
||||
- name: render stunnel config
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/stunnel/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
|
||||
notify: restart stunnel4
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install stunnel4
|
||||
ansible.builtin.apt:
|
||||
name: stunnel4
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,9 @@
|
||||
setuid = stunnel4
|
||||
setgid = stunnel4
|
||||
pid = /var/run/stunnel/absinthe.pid
|
||||
output = /var/log/stunnel/absinthe.log
|
||||
client = yes
|
||||
[openvpn]
|
||||
sni = absinthe.oyacoi.ru
|
||||
accept = 127.0.0.1:1195
|
||||
connect = {{ hostvars['liqueur'].container_ip }}:443
|
||||
@@ -0,0 +1,9 @@
|
||||
setuid = stunnel4
|
||||
setgid = stunnel4
|
||||
pid = /var/run/stunnel/liqueur.pid
|
||||
output = /var/log/stunnel/liqueur.log
|
||||
client = yes
|
||||
[openvpn]
|
||||
sni = liqueur.oyacoi.ru
|
||||
accept = 127.0.0.1:1194
|
||||
connect = {{ hostvars['liqueur'].container_ip }}:443
|
||||
Reference in New Issue
Block a user