Compare commits
16
Commits
6d7779af3f
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c640406c10 | ||
|
|
ba9e1a664f | ||
|
|
33ddc88ee9 | ||
|
|
6e248bb709 | ||
|
|
4e6aace464 | ||
|
|
d5762dfc07 | ||
|
|
fa6a65aed2 | ||
|
|
47e6340bf0 | ||
|
|
681f384810 | ||
|
|
66062e6122 | ||
|
|
271c290498 | ||
|
|
abeb2e0eb9 | ||
|
|
98873cb5eb | ||
|
|
a928e0ec70 | ||
|
|
7ce01c7173 | ||
|
|
3020de7dc1 |
@@ -0,0 +1 @@
|
|||||||
|
.vault_pass
|
||||||
@@ -3,6 +3,7 @@ inventory = inventory/
|
|||||||
roles_path = roles/
|
roles_path = roles/
|
||||||
host_key_checking = False
|
host_key_checking = False
|
||||||
forks = 8
|
forks = 8
|
||||||
|
vault_password_file = .vault_pass
|
||||||
|
|
||||||
[inventory]
|
[inventory]
|
||||||
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
|
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
locale_default: en_US.UTF-8
|
||||||
|
locales_list:
|
||||||
|
- en_US.UTF-8
|
||||||
|
- ru_RU.UTF-8
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
nft_managed_group: all
|
|
||||||
dnsmasq_managed_group: all
|
|
||||||
xray_managed_group: all
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
timezone_name: Europe/Samara
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
||||||
|
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
||||||
|
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
||||||
|
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
||||||
|
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
||||||
|
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
||||||
|
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
||||||
|
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
||||||
|
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
||||||
|
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
||||||
|
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
||||||
|
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
||||||
|
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
||||||
|
6163656436303665346232643162383338326333386465303564
|
||||||
@@ -1,5 +1,15 @@
|
|||||||
ansible_connection: community.proxmox.proxmox_pct_remote
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
ansible_host: 10.1.0.4
|
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
||||||
ansible_user: root
|
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
||||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
||||||
ansible_python_interpreter: /usr/bin/python3
|
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
||||||
|
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
||||||
|
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
||||||
|
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
||||||
|
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
||||||
|
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
||||||
|
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
||||||
|
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
||||||
|
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
||||||
|
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
||||||
|
6163656436303665346232643162383338326333386465303564
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
ansible_connection: ssh
|
||||||
|
ansible_user: root
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||||
@@ -1,4 +1,2 @@
|
|||||||
nft_from:
|
dhcp-host:
|
||||||
- iface: [eth1,eth0.2]
|
- mac: "b8:88:80:92:b5:4c"
|
||||||
to: camera0
|
|
||||||
proto: [tcp,udp]
|
|
||||||
|
|||||||
@@ -1,12 +1,12 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [eth0,eth0.2]
|
- iface: [br-eth0,eth0.2]
|
||||||
proto: [tcp,udp]
|
proto: [tcp,udp]
|
||||||
port: [3478,5349]
|
port: [3478,5349]
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
||||||
proto: [tcp,udp]
|
proto: [tcp,udp]
|
||||||
port: [3478,5349]
|
port: [3478,5349]
|
||||||
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
||||||
proto: udp
|
proto: udp
|
||||||
port: ["49152-65535"]
|
port: ["49152-65535"]
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
ansible_python_interpreter: /usr/bin/python3
|
||||||
@@ -0,0 +1,25 @@
|
|||||||
|
zfs:
|
||||||
|
- name: rpool/data/pgsql
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "21474836480"
|
||||||
|
- name: rpool/data/vaultwarden
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "5368709120"
|
||||||
|
- name: rpool/data/gitea
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "5368709120"
|
||||||
|
- name: rpool/data/slskd
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "5368709120"
|
||||||
|
- name: rpool/data/rtorrent
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "1073741824"
|
||||||
|
- name: rpool/data/jellfin
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "5368709120"
|
||||||
|
- name: rpool/data/prosody
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "10737418240"
|
||||||
|
- name: rpool/data/steamcmd
|
||||||
|
extra_zfs_properties:
|
||||||
|
quota: "21474836480"
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
dhcp-host:
|
||||||
|
- mac: "d4:f0:ea:78:ec:a0"
|
||||||
@@ -1,5 +1,10 @@
|
|||||||
|
nft_to:
|
||||||
|
- to: pgsql
|
||||||
|
proto: tcp
|
||||||
|
port: 5432
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: wg0
|
- iface: tun0
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
certbot_certs:
|
||||||
|
- domains:
|
||||||
|
- liqueur.oyacoi.ru
|
||||||
|
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
||||||
|
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
||||||
|
- domains:
|
||||||
|
- absinthe.oyacoi.ru
|
||||||
|
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
||||||
|
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
ansible_python_interpreter: /usr/bin/python3
|
||||||
|
ansible_password: "{{ ssh_password }}"
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
openvpn_role: server
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
37353538363139326635383437313831346265623562383533386261623437366462343663363261
|
||||||
|
3264363465656165343038656631373436613235343232620a663633636264383736303030323938
|
||||||
|
30336565383337613637613963343132646665613932393237323437373434646335383531303461
|
||||||
|
6134393232336132350a393333613362306462613839333732343963363961653561666437383037
|
||||||
|
35366561393537643463396462356464663162316632613331316230643932666233
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
openvpn_client_bundle_dir: /etc/easy-rsa/ovpn
|
||||||
|
openvpn_instances:
|
||||||
|
- name: tun0
|
||||||
|
pki_dir: /etc/easy-rsa/pki/tun0
|
||||||
|
clients:
|
||||||
|
- name: mur89
|
||||||
|
- name: matr10
|
||||||
|
- name: tap0
|
||||||
|
pki_dir: /etc/easy-rsa/pki/tap0
|
||||||
|
clients:
|
||||||
|
- name: ltrefilov
|
||||||
|
- name: lnosov
|
||||||
|
ip: 10.1.0.220
|
||||||
|
route_metric: 50
|
||||||
|
- name: aborovlev
|
||||||
|
ip: 10.1.0.221
|
||||||
|
route_metric: 50
|
||||||
|
- name: dperesypkin
|
||||||
|
ip: 10.1.0.222
|
||||||
|
route_metric: 50
|
||||||
|
- name: dkarpcov
|
||||||
|
ip: 10.1.0.223
|
||||||
|
route_metric: 50
|
||||||
@@ -1,10 +1,10 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [eth0,eth0.2]
|
- iface: [br-eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 25565
|
port: 25565
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [eth0,wg0]
|
- iface: [br-eth0,tun0]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 25565
|
port: 25565
|
||||||
|
|
||||||
|
|||||||
@@ -35,11 +35,17 @@ nft_to:
|
|||||||
- to: bylampa
|
- to: bylampa
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 80
|
port: 80
|
||||||
|
- to: ps3
|
||||||
|
proto: tcp
|
||||||
|
port: 80
|
||||||
|
- to: firebat
|
||||||
|
proto: tcp
|
||||||
|
port: 8006
|
||||||
- to: mcsmanager
|
- to: mcsmanager
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [23333,24444]
|
port: [23333,24444]
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [eth0,eth0.2]
|
- iface: [br-eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [80,443,24444]
|
port: [80,443,24444]
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
xray_policy:
|
||||||
|
- bypass: private
|
||||||
|
- bypass: russian_whitelist
|
||||||
|
- proxy: all
|
||||||
@@ -1,7 +1,10 @@
|
|||||||
nft_to:
|
nft_to:
|
||||||
|
- to: nginx
|
||||||
|
proto: tcp
|
||||||
|
port: [80,443]
|
||||||
- to: nfs
|
- to: nfs
|
||||||
proto: [tcp, udp]
|
proto: [tcp,udp]
|
||||||
port: [2049, 111, 32765, 32767]
|
port: [2049,111,32765,32767]
|
||||||
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
|
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
@@ -9,7 +12,23 @@ nft_to:
|
|||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
|
nft_dst:
|
||||||
|
- iface: eth1
|
||||||
|
proto: tcp
|
||||||
|
port: [3783,4321,28900,29900,29901]
|
||||||
|
- iface: eth1
|
||||||
|
proto: udp
|
||||||
|
port: [6500,6515,13139,27900]
|
||||||
|
|
||||||
|
nft_from:
|
||||||
|
- iface: eth1
|
||||||
|
proto: tcp
|
||||||
|
port: [3783,4321,28900,29900,29901]
|
||||||
|
- iface: eth1
|
||||||
|
proto: udp
|
||||||
|
port: [6500,6515,13139,27900]
|
||||||
|
|
||||||
xray_policy:
|
xray_policy:
|
||||||
- bypass: private
|
- bypass: private
|
||||||
- bypass: russian_whitelist
|
- bypass: russian_whitelist
|
||||||
- proxy: all
|
- proxy: all
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
nft_dst:
|
nft_dst:
|
||||||
- iface: [eth0,eth0.2]
|
- iface: [br-eth0,eth0.2]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [5000,5222,5223,5280,5270,5269]
|
port: [5000,5222,5223,5280,5270,5269]
|
||||||
|
|
||||||
@@ -9,7 +9,7 @@ nft_to:
|
|||||||
port: 5432
|
port: 5432
|
||||||
|
|
||||||
nft_from:
|
nft_from:
|
||||||
- iface: [eth0,eth0.2,wg0]
|
- iface: [br-eth0,eth0.2,tun0]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [5000,5222,5223,5269,5270,5280]
|
port: [5000,5222,5223,5269,5270,5280]
|
||||||
|
|
||||||
|
|||||||
@@ -1,3 +1,5 @@
|
|||||||
dnsmasq:
|
dnsmasq:
|
||||||
- name: rustdesk.dttx.ru
|
- name: rustdesk.dttx.ru
|
||||||
ip: 176.119.157.97
|
ip_from: liqueur
|
||||||
|
- name: fs.dttx.ru
|
||||||
|
ip_from: liqueur
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
ansible_host: 10.1.0.1
|
|
||||||
ansible_connection: ssh
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
|
||||||
zone_iface: eth0
|
|
||||||
container_ip: 10.1.0.1
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ifupdown2_manage_prerequisites: true
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
zone_iface: "eth0"
|
||||||
|
container_ip: "10.1.0.1"
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
nft_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||||
|
dnsmasq_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||||
|
xray_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
nftables_bootstrap_files: true
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
openvpn_role: client
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
user:
|
||||||
|
- name: steamcmd
|
||||||
|
create_home: true
|
||||||
|
home: /var/lib/steamcmd
|
||||||
|
shell: /bin/bash
|
||||||
|
system: true
|
||||||
@@ -0,0 +1,100 @@
|
|||||||
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
|
65616666356261363366373733653631636132613931366637383432656566366636313864666230
|
||||||
|
6136653839653366336561613365383535616231613064660a343139643135653933343731363038
|
||||||
|
36396436353033396265646338666537623237323166373664626633366432373037613631636236
|
||||||
|
6134633533636361310a663966353432366436383333666266666238636239666136316665353665
|
||||||
|
33353161626637353063613738376130333533393565383065613732663637653334636130383663
|
||||||
|
65376666373861326639343362353136303038396535303234326135633665366164393239376430
|
||||||
|
38343932613935343930376131373837376235633432373535356162616333653432666131333261
|
||||||
|
30313436613465626330393936613166663563636435356136613930303933323238336565663232
|
||||||
|
35616665333339313365323837383832393563353238326234643934393234323462336363303232
|
||||||
|
30383863366331656331336135313362303235396266613661356562333064653736396531323463
|
||||||
|
63353736633139353764356634376531613738393965393264623462333232366233396233643533
|
||||||
|
65653364643235373837303731363565656265616633336236313266373635646233623362636161
|
||||||
|
61346432336636633030616232343738666136366666353135656237653437663565643032663562
|
||||||
|
31633764343537666633386237633662306362303732353761353937323039623238353439383336
|
||||||
|
39356236646333666535326337616337313233646365333830343637376533373661636364313362
|
||||||
|
35333132353364343836366639356465323636313564636433393361636536323432363232376337
|
||||||
|
37653835666664386437316163323261336135613330636537633934633839633538343238323035
|
||||||
|
38653163626266316137383433656630313234326530313533376337393865643162613532326463
|
||||||
|
38613533373263303138333237303739393261396364646330646334386338636538343265393238
|
||||||
|
64653036366237396233323064323732393831343563643238363964333633636362303866373530
|
||||||
|
35383433643163366534613931666563376133336663393332666465616436343562613833653766
|
||||||
|
32663237383466356433383065336664393664326536346364313536656565613635666665643133
|
||||||
|
35366165643163636166613735313036326232656330313637353133323265646162333565643930
|
||||||
|
38643666396431316165626433383236653663376263663736323838343435396639636162663738
|
||||||
|
64366238363532363433313336393937353561643635343466393761623161643235663366633932
|
||||||
|
30303339306333643331323962333035393933653431383139653531626533396131663564353237
|
||||||
|
65346637383133626630376639663630333265346434656361386463343162393131393631396638
|
||||||
|
64353931643733356362376139633037363434316366396266363665613563663565366466616336
|
||||||
|
65663561666163613639643136613132303662396661653830363862346535656436613739376363
|
||||||
|
61633562346331333566313165373133633137663831313534323737623564306437346562356362
|
||||||
|
66363965313337303265343966656330356361326666353134636465613833356134383833323537
|
||||||
|
63353965346666656364633230333539383464613637333131356637326535333733356139396363
|
||||||
|
64393938366533346165386165333336333638316166663236373131366334363037626662323737
|
||||||
|
39376162616333623638383038396465356130353261303730613632623265333764633330303238
|
||||||
|
34653338346430636231376339306632376236613865383737663530353465366536313864636639
|
||||||
|
39663237383564363063663266396537393536353466643564613432646663373263306164646336
|
||||||
|
38626334373138376436336130386266343766363636636437363862303635356231323336306135
|
||||||
|
61353561643761336133623565306233383333363963393765363163323139373935313636663065
|
||||||
|
30333237313738633338663630363430373232343939303134363436653563393231656262333033
|
||||||
|
38323837646131626162383237373736306634386631613864623338303235666132353837626665
|
||||||
|
35303533623533366437656133653239613563363232343535363234346466343936393132376332
|
||||||
|
64626137363564656661653466396631346364356561313562373965623539616362383835383234
|
||||||
|
30323262353833336332623863626465376238383133633462303465393463663337356464613236
|
||||||
|
31313232383738313136303439623563393861623039393536373539303838623832323238336432
|
||||||
|
39633661626364313034623832363763313031333565373363323636393265333530633837623934
|
||||||
|
64626535646661333266303461633664346461396237333633613736303239336530616236336561
|
||||||
|
65626532303063396131376335663738393362633937393131396134316235376338623165643233
|
||||||
|
39373533373033633838626239343232323733336633333837383834666661383162366337303435
|
||||||
|
61666638393938653666643834313831613134633731353665366133633334356535343464373461
|
||||||
|
61303632663936363866353764653130386233326362343466623338326234386363653432303437
|
||||||
|
30333361653662633863323731383438373764653834363062613665613862623338336233663263
|
||||||
|
37353738373131333333353662636561323234393634643734376539383965346530386265323063
|
||||||
|
32636364653365656236396665623735656630393632333330653738643736383664396230663033
|
||||||
|
64303763336339623638653831653039353731356430626530636335623235366635313339386137
|
||||||
|
64613239653538653262393265356463643739383634663432393231636561376139653834646664
|
||||||
|
65356534336264643039303762623533616431353130353332663230336133383461386161333737
|
||||||
|
33316438303935663937373335323339656535393163616166346535313830343462303738313133
|
||||||
|
36653038343639373336663961396137366632653138396139346431363431336331376339333135
|
||||||
|
30343331626636323332393337626231326463316665373734653934653531663663393937333838
|
||||||
|
37656534626639343639366366653131313137633534316137333730346531326232353137633332
|
||||||
|
34303236386138623038303263613966346532323637303665353931333930613339626362666433
|
||||||
|
36666335356464373962376335653266663138373130303639633661393036663663323538343837
|
||||||
|
32613837636166646634626137346532656364343730616663646130356631333634353766623938
|
||||||
|
32366431623032353937363462633661396365353962393931623538366365353761353365643231
|
||||||
|
35656361393162663066393539363262663966653032356465326534616230313438323437346638
|
||||||
|
37356661376361396164646135666161373732393830343932626565663535346437346236343361
|
||||||
|
34346134343438643338636437613733323065646638646364663930353062653233353066383530
|
||||||
|
33633731396562663338393838376639363034373965353465643263613632646135346432323235
|
||||||
|
64353435363032343537633035613739336637356339373164383964313062313932653336616366
|
||||||
|
30666465613263373561373366326630366636643639616138366363346561346363646139333838
|
||||||
|
30316266376330393861666137356263336638323939666431336131383339306437333832306235
|
||||||
|
37366135613230666165396136343030643630356462333830623230613133356563666533373763
|
||||||
|
66353637393430306465373465316433386131373431343436663533663264333662333865616139
|
||||||
|
65643738656666333830383833346334383430666537313733613833356239383730666437326532
|
||||||
|
38393061326136333533653565343962333336616665633034356334653366313435383630623537
|
||||||
|
32323065363137656336626130633361353763653664303636373736326363306439346263383437
|
||||||
|
33636139656437303965353362313865333535366337666466366430353837353930656638393334
|
||||||
|
32313561306132386331383633333931353336313639366434313931333733663630386436336230
|
||||||
|
32376365613061383636326366326265623038373766316561643163646564396638336537303131
|
||||||
|
39383163323337336561616666336637316435323534353961623834656664316262623834346336
|
||||||
|
36343536336439363762333538376261663934636566323962313565303137653036653434376434
|
||||||
|
61623732613936393838386163366561373539393635303664333931396565633437393931353965
|
||||||
|
62313838636461343037626332613530663336353562656563323939323636373164363930616265
|
||||||
|
62656465366330363466386261323039323766376237303263666634653561643439323630666431
|
||||||
|
62316162366436383065623961323062353034653935626638393862366535616330356135303761
|
||||||
|
34613438393730663562633239373935383264366361376536633331323062343535626262326133
|
||||||
|
63383731613664663339613830353231643866326362663336653336666530343633376465376161
|
||||||
|
37313666346261313137363864396531643765363166663931633338383037363933646436323863
|
||||||
|
34333862613730326630356437373531373838383265383238383863373339326439643035626431
|
||||||
|
63313537623339343564326534636234646635653434356161303530393236663832316233306261
|
||||||
|
63663864383862393634656630393533326438396164623037623961363833616664666437626563
|
||||||
|
63363334323930363930326231363339363233646263643861393034656562363434383034633961
|
||||||
|
36663865393430333964626231396431663634623536656237326430356334653739333339336337
|
||||||
|
36306663316638376631323165383963636562336438383639333632316133323933653539336664
|
||||||
|
38636531326230333665653937303639616338303063666561353435353764373431643234623338
|
||||||
|
66313963373964613237346238303566316138383364666238616333663437323135376466366166
|
||||||
|
39376130336635646131653237363461663664633336663837356265616133653031613662323861
|
||||||
|
38303266613934376136366430313934373462363630633037323461306134653637623035383936
|
||||||
|
343164306335323561333737633538633333
|
||||||
@@ -4,36 +4,29 @@ xray_ip_sets:
|
|||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
|
||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
|
||||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
|
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
|
||||||
|
|
||||||
cdn:
|
cdn:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
|
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
|
||||||
|
|
||||||
telegram:
|
telegram:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
|
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
|
||||||
|
|
||||||
russian_whitelist:
|
russian_whitelist:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
|
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
|
||||||
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
|
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
|
||||||
|
|
||||||
cloudflare:
|
cloudflare:
|
||||||
static:
|
static:
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
- 1.0.0.1
|
- 1.0.0.1
|
||||||
|
|
||||||
google:
|
google:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
|
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
|
||||||
|
|
||||||
xray_domain_sets:
|
xray_domain_sets:
|
||||||
v2ray:
|
v2ray:
|
||||||
urls:
|
urls:
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
|
||||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
|
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
|
||||||
|
|
||||||
torrent:
|
torrent:
|
||||||
static:
|
static:
|
||||||
- bt.t-ru.org
|
- bt.t-ru.org
|
||||||
@@ -47,28 +40,23 @@ xray_domain_sets:
|
|||||||
- nnmclub.to
|
- nnmclub.to
|
||||||
- rutor.info
|
- rutor.info
|
||||||
- bigfangroup.org
|
- bigfangroup.org
|
||||||
|
|
||||||
vps:
|
vps:
|
||||||
static:
|
static:
|
||||||
- dev.oyacoi.ru
|
- dev.oyacoi.ru
|
||||||
- vector.oyacoi.ru
|
- vector.oyacoi.ru
|
||||||
|
|
||||||
terraform:
|
terraform:
|
||||||
static:
|
static:
|
||||||
- terraform.io
|
- terraform.io
|
||||||
- hashicorp.com
|
- hashicorp.com
|
||||||
|
output_rules:
|
||||||
|
- cloudflare
|
||||||
xray_static_sets:
|
xray_static_sets:
|
||||||
- private
|
- private
|
||||||
|
|
||||||
xray_lists_global:
|
xray_lists_global:
|
||||||
cache_dir: /var/lib/xray-lists/cache
|
cache_dir: /var/lib/xray-lists/cache
|
||||||
output_dir: /var/lib/xray-lists/generated
|
output_dir: /var/lib/xray-lists/generated
|
||||||
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
|
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
|
||||||
proxy: "socks5h://127.0.0.1:1080"
|
proxy: "socks5h://127.0.0.1:1080"
|
||||||
proxy_user: "{{ lookup('env', 'SOCKS5_USERNAME') }}"
|
|
||||||
proxy_pass: "{{ lookup('env', 'SOCKS5_PASSWORD') }}"
|
|
||||||
http_timeout: 20
|
http_timeout: 20
|
||||||
|
|
||||||
xray_tproxy_port: 61219
|
xray_tproxy_port: 61219
|
||||||
xray_fwmark: "0x00000001"
|
xray_fwmark: "0x00000001"
|
||||||
@@ -1,4 +1,7 @@
|
|||||||
nft_to:
|
nft_to:
|
||||||
|
- to: [zone:eth0.12]
|
||||||
|
proto: tcp
|
||||||
|
port: 22
|
||||||
- to: firebat
|
- to: firebat
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: [22, 8006]
|
port: [22, 8006]
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
nft_dst:
|
|
||||||
- iface: eth0
|
|
||||||
proto: udp
|
|
||||||
port: 2456
|
|
||||||
|
|
||||||
nft_from:
|
|
||||||
- iface: [eth0,wg0]
|
|
||||||
proto: udp
|
|
||||||
port: [2456,2457]
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
nft_dst:
|
||||||
|
- iface: eth1
|
||||||
|
proto: udp
|
||||||
|
port: [2456,2457]
|
||||||
|
|
||||||
|
nft_from:
|
||||||
|
- iface: [br-eth0,tun0]
|
||||||
|
proto: tcp
|
||||||
|
port: [5000,5222,5223,5269,5270,5280]
|
||||||
|
- iface: [br-eth0,tun0]
|
||||||
|
proto: udp
|
||||||
|
port: [2302,2304,2456,2457,27016]
|
||||||
|
- iface: eth1
|
||||||
|
proto: udp
|
||||||
|
port: [2456,2457]
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
user:
|
||||||
|
- name: steamcmd
|
||||||
|
create_home: true
|
||||||
|
home: /var/lib/steamcmd
|
||||||
|
shell: /bin/bash
|
||||||
|
system: true
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
xray_policy:
|
||||||
|
- bypass: private
|
||||||
|
- bypass: russian_whitelist
|
||||||
|
- proxy: all
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
dhcp-host:
|
||||||
|
- mac: "c8:5c:cc:91:71:58"
|
||||||
@@ -8,3 +8,8 @@ nft_to:
|
|||||||
- to: [xiawrt,rbpi4]
|
- to: [xiawrt,rbpi4]
|
||||||
proto: tcp
|
proto: tcp
|
||||||
port: 22
|
port: 22
|
||||||
|
|
||||||
|
xray_policy:
|
||||||
|
- bypass: private
|
||||||
|
- bypass: russian_whitelist
|
||||||
|
- proxy: all
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
dhcp-host:
|
||||||
|
- mac: "ac:ba:c0:9c:1e:4c"
|
||||||
+20
-13
@@ -1,13 +1,20 @@
|
|||||||
plugin: community.proxmox.proxmox
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
url: https://10.1.0.4:8006
|
37386530393166613762313561626462336132393166653364343962396164323734313165383763
|
||||||
user: root@pam
|
6234663630386531323464643538353865613334656264620a316630336537396363303333343637
|
||||||
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
|
38636437633264373866616366666337366362306438306430633566316234323935363237343762
|
||||||
validate_certs: false
|
3533393634633733330a626139316231383738626465373566303565633135646164323535326635
|
||||||
want_facts: true
|
38313138383063646237303634376237623661633830363531323563613131613530663730653533
|
||||||
|
36643330623366636363613437313030303463613163323333663865633538343266353134386631
|
||||||
filter_by_types:
|
36663530376238656262346662383532613631636234323431303935323138306163323839636338
|
||||||
- lxc
|
61373735366332356138313762663633393165663732653565663066613636366538376263366337
|
||||||
|
31386337623562313731386563313736346139353961663231353862636138303938323235633038
|
||||||
compose:
|
38636562646533633261346264373466373536376530623639366262613365366437373334396665
|
||||||
zone_iface: "'eth0.' ~ proxmox_net0.tag"
|
30653037366339383538313965663865636462633139616332386165663564616263666533363034
|
||||||
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
|
38643065303832666335623035326566653437393638373261343138636530373839646231643665
|
||||||
|
33323338333231643435663336653232373732636335656238376563666632313131656432336233
|
||||||
|
63636437643838316166666137386361386233346633316166333662323838313565653233346537
|
||||||
|
61383966343434323539326364646230336339353337326539333031376464353732326331333864
|
||||||
|
34303431363632386562616131306436373464393165396437613535323230353862346662346265
|
||||||
|
33303137383033313534393438343934653037643936633361343638616461643935386430616133
|
||||||
|
62633262306538663961646263613239313261633764663532616138313663343863643965613730
|
||||||
|
396266656366353238353038333832336234
|
||||||
|
|||||||
+48
-25
@@ -1,37 +1,34 @@
|
|||||||
all:
|
all:
|
||||||
children:
|
children:
|
||||||
static:
|
internal:
|
||||||
hosts:
|
hosts:
|
||||||
workuter:
|
workuter:
|
||||||
container_ip: "10.1.0.2"
|
container_ip: "10.1.0.2"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
oyacoi-odcm:
|
oyacoi-odcm:
|
||||||
container_ip: "10.1.0.3"
|
container_ip: "10.1.0.3"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
firebat:
|
firebat:
|
||||||
container_ip: "10.1.0.4"
|
container_ip: "10.1.0.4"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
ansible_host: 10.1.0.4
|
|
||||||
ansible_user: root
|
|
||||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
|
||||||
|
|
||||||
ps2:
|
ps2:
|
||||||
container_ip: "10.1.0.5"
|
container_ip: "10.1.0.5"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
ps3:
|
ps3:
|
||||||
container_ip: "10.1.0.6"
|
container_ip: "10.1.0.6"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
tanix:
|
tanix:
|
||||||
container_ip: "10.1.0.8"
|
container_ip: "10.1.0.8"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
bananawrt:
|
bananawrt:
|
||||||
container_ip: "10.1.0.100"
|
container_ip: "10.1.0.100"
|
||||||
zone_iface: "eth0"
|
zone_iface: "br-eth0"
|
||||||
|
|
||||||
ps4:
|
ps4:
|
||||||
container_ip: "10.2.0.2"
|
container_ip: "10.2.0.2"
|
||||||
@@ -57,30 +54,56 @@ all:
|
|||||||
container_ip: "10.2.0.7"
|
container_ip: "10.2.0.7"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
psp:
|
3ds:
|
||||||
container_ip: "10.2.0.8"
|
container_ip: "10.2.0.8"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.2"
|
||||||
|
|
||||||
dsi:
|
yandex-lite-2:
|
||||||
container_ip: "10.2.0.9"
|
container_ip: "10.3.0.2"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.3"
|
||||||
|
|
||||||
3ds:
|
fryer:
|
||||||
container_ip: "10.2.0.10"
|
container_ip: "10.3.0.3"
|
||||||
zone_iface: "eth0.2"
|
zone_iface: "eth0.3"
|
||||||
|
|
||||||
|
vacuum:
|
||||||
|
container_ip: "10.3.0.4"
|
||||||
|
zone_iface: "eth0.3"
|
||||||
|
|
||||||
camera0:
|
camera0:
|
||||||
container_ip: "10.3.0.5"
|
container_ip: "10.3.0.5"
|
||||||
zone_iface: "eth0.3"
|
zone_iface: "eth0.3"
|
||||||
|
|
||||||
haproxy:
|
psp:
|
||||||
container_ip: "10.255.255.100"
|
container_ip: "10.4.0.2"
|
||||||
zone_iface: "wg0"
|
zone_iface: "eth0.4"
|
||||||
|
|
||||||
|
dsi:
|
||||||
|
container_ip: "10.4.0.3"
|
||||||
|
zone_iface: "eth0.4"
|
||||||
|
|
||||||
xiawrt:
|
xiawrt:
|
||||||
container_ip: "10.250.250.1"
|
container_ip: "192.168.1.1"
|
||||||
zone_iface: "wg0"
|
zone_iface: "tun0"
|
||||||
|
|
||||||
rbpi4:
|
rbpi4:
|
||||||
container_ip: "10.250.250.5"
|
container_ip: "192.168.1.5"
|
||||||
zone_iface: "wg0"
|
zone_iface: "tun0"
|
||||||
|
|
||||||
|
haproxy:
|
||||||
|
container_ip: "172.168.0.1"
|
||||||
|
zone_iface: "tun0"
|
||||||
|
|
||||||
|
external:
|
||||||
|
hosts:
|
||||||
|
liqueur:
|
||||||
|
container_ip: "130.49.213.132"
|
||||||
|
zone_iface: "eht1"
|
||||||
|
|
||||||
|
vector:
|
||||||
|
container_ip: "144.31.155.100"
|
||||||
|
zone_iface: "eht1"
|
||||||
|
|
||||||
|
dev:
|
||||||
|
container_ip: "178.173.249.148"
|
||||||
|
zone_iface: "eht1"
|
||||||
|
|||||||
@@ -1,5 +0,0 @@
|
|||||||
---
|
|
||||||
- hosts: router
|
|
||||||
become: true
|
|
||||||
roles:
|
|
||||||
- dnsmasq
|
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
---
|
||||||
|
- name: deploy rasy-rsa
|
||||||
|
hosts: localhost
|
||||||
|
connection: local
|
||||||
|
become: true
|
||||||
|
roles:
|
||||||
|
- easy-rsa
|
||||||
|
|
||||||
|
- name: configure liqueur openvpn
|
||||||
|
hosts: liqueur
|
||||||
|
vars:
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||||
|
roles:
|
||||||
|
- openvpn
|
||||||
|
|
||||||
|
- name: configure router openvpn
|
||||||
|
hosts: router
|
||||||
|
vars:
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||||
|
roles:
|
||||||
|
- openvpn
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
- name: configure over ssh
|
||||||
|
hosts: firebat
|
||||||
|
vars:
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||||
|
roles:
|
||||||
|
- zfs
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
- name: configure over ssh
|
||||||
|
hosts: liqueur
|
||||||
|
vars:
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: >-
|
||||||
|
-o UserKnownHostsFile=/dev/null
|
||||||
|
-o StrictHostKeyChecking=no
|
||||||
|
-o PreferredAuthentications=publickey,password
|
||||||
|
-o PubkeyAuthentication=yes
|
||||||
|
roles:
|
||||||
|
- authorized_key
|
||||||
|
- sshd
|
||||||
|
- certbot
|
||||||
|
- sysctl
|
||||||
|
- nginx
|
||||||
|
- nftables
|
||||||
|
- stunnel4
|
||||||
|
- openvpn
|
||||||
|
- haproxy
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
---
|
|
||||||
- hosts: router
|
|
||||||
become: true
|
|
||||||
roles:
|
|
||||||
- xray-lists
|
|
||||||
- dnsmasq
|
|
||||||
- nftables
|
|
||||||
|
|
||||||
tasks:
|
|
||||||
- name: enable update timer
|
|
||||||
systemd:
|
|
||||||
name: xray-lists.timer
|
|
||||||
enabled: yes
|
|
||||||
state: started
|
|
||||||
+25
-12
@@ -1,15 +1,28 @@
|
|||||||
---
|
---
|
||||||
- hosts: router
|
- name: configure over pct
|
||||||
become: yes
|
hosts: router
|
||||||
|
gather_facts: false
|
||||||
roles:
|
roles:
|
||||||
- router
|
- authorized_key
|
||||||
- xray-lists
|
- ifupdown2
|
||||||
- dnsmasq
|
|
||||||
- nftables
|
|
||||||
|
|
||||||
tasks:
|
- name: configure over ssh
|
||||||
- name: enable update timer
|
hosts: router
|
||||||
systemd:
|
vars:
|
||||||
name: xray-lists.timer
|
ansible_connection: ssh
|
||||||
enabled: yes
|
ansible_host: "{{ container_ip }}"
|
||||||
state: started
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||||
|
roles:
|
||||||
|
- timezone
|
||||||
|
- locales
|
||||||
|
- sysctl
|
||||||
|
- stunnel4
|
||||||
|
- openvpn
|
||||||
|
- xray-core
|
||||||
|
- logrotate
|
||||||
|
- dnsmasq
|
||||||
|
- xray-lists
|
||||||
|
- unbound
|
||||||
|
- nftables
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
- name: configure over pct
|
||||||
|
hosts: steamcmd
|
||||||
|
gather_facts: false
|
||||||
|
roles:
|
||||||
|
- authorized_key
|
||||||
|
|
||||||
|
- name: configure over ssh
|
||||||
|
hosts: steamcmd
|
||||||
|
vars:
|
||||||
|
ansible_connection: ssh
|
||||||
|
ansible_host: "{{ container_ip }}"
|
||||||
|
ansible_user: root
|
||||||
|
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||||
|
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||||
|
roles:
|
||||||
|
- timezone
|
||||||
|
- locales
|
||||||
|
- user
|
||||||
|
- steamcmd
|
||||||
@@ -1,5 +0,0 @@
|
|||||||
---
|
|
||||||
- hosts: router
|
|
||||||
become: true
|
|
||||||
roles:
|
|
||||||
- xray-lists
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
- name: ensure .ssh exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /root/.ssh
|
||||||
|
state: directory
|
||||||
|
mode: '0700'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
|
||||||
|
- name: set authorized key
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: root
|
||||||
|
state: present
|
||||||
|
key: "{{ item }}"
|
||||||
|
loop: "{{ ssh_keys }}"
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
- name: install certbot
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: certbot
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: issue certificate if missing
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: >
|
||||||
|
certbot certonly --standalone
|
||||||
|
--non-interactive --agree-tos
|
||||||
|
--register-unsafely-without-email
|
||||||
|
--pre-hook "{{ item.pre_hook }}"
|
||||||
|
--post-hook "{{ item.post_hook }}"
|
||||||
|
{{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }}
|
||||||
|
creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem"
|
||||||
|
loop: "{{ certbot_certs }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.domains | join(',') }}"
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: install certbot
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: certbot
|
||||||
|
state: latest
|
||||||
|
update_cache: true
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: include certbot install
|
||||||
|
ansible.builtin.include_tasks: install.yml
|
||||||
|
|
||||||
|
- name: include certbot configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
interface=lo
|
||||||
|
interface=br-eth0
|
||||||
|
interface=eth0.2
|
||||||
|
interface=eth0.3
|
||||||
|
interface=eth0.4
|
||||||
|
interface=eth0.10
|
||||||
|
interface=eth0.11
|
||||||
|
interface=eth0.12
|
||||||
|
bind-dynamic
|
||||||
|
no-resolv
|
||||||
|
server=127.0.0.1#5353
|
||||||
|
#server=1.1.1.1
|
||||||
|
domain=lan
|
||||||
|
local=/lan/
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
server=/dev.oyacoi.ru/9.9.9.9
|
||||||
|
server=/vector.oyacoi.ru/9.9.9.9
|
||||||
|
server=/.themoviedb.org/9.9.9.9
|
||||||
|
server=/.tmdb.org/9.9.9.9
|
||||||
|
server=/tmdb-image-prod.b-cdn.net/9.9.9.9
|
||||||
|
server=/infolada.ru/217.113.115.150
|
||||||
|
server=/infolada.ru/217.113.114.100
|
||||||
|
server=/start.infolada.ru/217.113.115.150
|
||||||
|
server=/start.infolada.ru/217.113.114.100
|
||||||
|
conf-file=/var/lib/xray-lists/generated/nftsets.conf
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
dhcp-range=interface:eth0.3,10.3.0.200,10.3.0.254,255.255.255.0,2h
|
||||||
|
dhcp-option=interface:eth0.3,option:router,10.3.0.1
|
||||||
|
dhcp-option=interface:eth0.3,option:dns-server,10.3.0.1
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
filterwin2k
|
||||||
|
domain-needed
|
||||||
|
bogus-priv
|
||||||
|
cache-size=0
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
---
|
||||||
|
- name: ensure /etc/dnsmasq.d exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/dnsmasq.d
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
|
||||||
|
- name: deploy dnsmasq rule
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/dnsmasq.d/{{ item }}"
|
||||||
|
mode: "0644"
|
||||||
|
loop:
|
||||||
|
- 10-upstream.conf
|
||||||
|
- 20-custom-domains.conf
|
||||||
|
- 20-dhcp.conf
|
||||||
|
- 20-dns-optimizations.conf
|
||||||
|
notify: restart dnsmasq
|
||||||
|
|
||||||
|
- name: render local
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-local.conf.j2
|
||||||
|
dest: /etc/dnsmasq.d/90-local.conf
|
||||||
|
mode: "0644"
|
||||||
|
notify: restart dnsmasq
|
||||||
|
|
||||||
|
- name: render dhcp-host
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-dhcp-host.conf.j2
|
||||||
|
dest: /etc/dnsmasq.d/90-dhcp-host.conf
|
||||||
|
mode: "0644"
|
||||||
|
notify: restart dnsmasq
|
||||||
|
|
||||||
|
- name: render domain
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 90-domains.conf.j2
|
||||||
|
dest: /etc/dnsmasq.d/90-domains.conf
|
||||||
|
mode: "0644"
|
||||||
|
notify: restart dnsmasq
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: install dnsmasq
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: dnsmasq
|
||||||
|
state: latest
|
||||||
|
update_cache: true
|
||||||
@@ -1,20 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: ensure /etc/dnsmasq.d exists
|
- name: include dnsmasq install
|
||||||
ansible.builtin.file:
|
ansible.builtin.include_tasks: install.yml
|
||||||
path: /etc/dnsmasq.d
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
- name: render local
|
- name: include dnsmasq configurure
|
||||||
ansible.builtin.template:
|
ansible.builtin.include_tasks: configure.yml
|
||||||
src: 90-local.conf.j2
|
|
||||||
dest: /etc/dnsmasq.d/90-local.conf
|
|
||||||
mode: "0644"
|
|
||||||
notify: restart dnsmasq
|
|
||||||
|
|
||||||
- name: render domain
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-domains.conf.j2
|
|
||||||
dest: /etc/dnsmasq.d/90-domains.conf
|
|
||||||
mode: "0644"
|
|
||||||
notify: restart dnsmasq
|
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
|
{% for item in dnsmasq_managed_group | sort %}
|
||||||
|
{% set client = hostvars[item] %}
|
||||||
|
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||||
|
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
|
||||||
|
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
|
||||||
|
{% for entry in entries %}
|
||||||
|
{% if entry.mac %}
|
||||||
|
dhcp-host={{ entry.mac }},{{ ip }},{{ item }}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
|
{% endif %}
|
||||||
|
{% endfor %}
|
||||||
@@ -1,15 +1,9 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
{% for item in groups[dnsmasq_managed_group] | sort %}
|
{% for item in dnsmasq_managed_group | sort %}
|
||||||
{% set client = hostvars[item] %}
|
{% for entry in hostvars[item].dnsmasq | default([]) %}
|
||||||
{% if 'dnsmasq' in client and client.dnsmasq %}
|
{% set ip = entry.ip | default(hostvars[entry.ip_from].container_ip if entry.ip_from is defined else none) %}
|
||||||
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
{% if ip %}
|
||||||
{% set domains = client.dnsmasq if (client.dnsmasq is iterable and client.dnsmasq is not string) else [client.dnsmasq] %}
|
|
||||||
{% for d in domains %}
|
|
||||||
{% set entry = d if (d is mapping) else {'name': d} %}
|
|
||||||
{% set ip = entry.ip | default(default_ip) %}
|
|
||||||
{% if ip %}
|
|
||||||
host-record={{ entry.name }},{{ ip }}
|
host-record={{ entry.name }},{{ ip }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||||
{% for item in groups[dnsmasq_managed_group] | sort %}
|
{% for item in dnsmasq_managed_group | sort %}
|
||||||
{% set client = hostvars[item] %}
|
{% set client = hostvars[item] %}
|
||||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||||
{% if ip %}
|
{% if ip %}
|
||||||
host-record={{ item }},{{ item }}.lan,{{ ip }}
|
host-record={{ item }},{{ item }}.lan,{{ ip }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
{% endfor %}
|
{% endfor %}
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: ensure local output directory exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}"
|
||||||
|
state: directory
|
||||||
|
mode: '0700'
|
||||||
|
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||||
|
delegate_to: localhost
|
||||||
|
become: false
|
||||||
|
|
||||||
|
- name: render standalone client bundles
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: "{{ role_path }}/templates/client-certs/{{ item.0.name }}.conf.j2"
|
||||||
|
dest: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}/{{ item.1.name }}.ovpn"
|
||||||
|
mode: '0600'
|
||||||
|
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||||
|
delegate_to: localhost
|
||||||
|
become: false
|
||||||
@@ -0,0 +1,82 @@
|
|||||||
|
---
|
||||||
|
- name: prepare list of client certificates
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
cert_list: "{{ cert_list | default([]) + [ {'instance': item.0.name, 'pki_dir': item.0.pki_dir, 'client': item.1} ] }}"
|
||||||
|
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||||
|
|
||||||
|
- name: ensure local PKI directories exist
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ item.pki_dir }}"
|
||||||
|
state: directory
|
||||||
|
mode: '0700'
|
||||||
|
loop: "{{ openvpn_instances }}"
|
||||||
|
|
||||||
|
- name: init pki if missing
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: /opt/easy-rsa/easyrsa --batch init-pki
|
||||||
|
creates: "{{ item.pki_dir }}/private"
|
||||||
|
environment:
|
||||||
|
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||||
|
loop: "{{ openvpn_instances }}"
|
||||||
|
|
||||||
|
- name: build ca if missing
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: /opt/easy-rsa/easyrsa --batch build-ca nopass
|
||||||
|
creates: "{{ item.pki_dir }}/ca.crt"
|
||||||
|
environment:
|
||||||
|
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||||
|
EASYRSA_REQ_CN: "CA-{{ item.name }}"
|
||||||
|
loop: "{{ openvpn_instances }}"
|
||||||
|
|
||||||
|
- name: build server cert if missing
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: /opt/easy-rsa/easyrsa --batch build-server-full server nopass
|
||||||
|
creates: "{{ item.pki_dir }}/issued/server.crt"
|
||||||
|
environment:
|
||||||
|
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||||
|
loop: "{{ openvpn_instances }}"
|
||||||
|
|
||||||
|
- name: generate dh params if missing
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: /opt/easy-rsa/easyrsa gen-dh
|
||||||
|
creates: "{{ item.pki_dir }}/dh.pem"
|
||||||
|
environment:
|
||||||
|
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||||
|
loop: "{{ openvpn_instances }}"
|
||||||
|
|
||||||
|
- name: check client certificates validity
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: "openssl x509 -checkend 2592000 -in {{ item.pki_dir }}/issued/{{ item.client.name }}.crt"
|
||||||
|
register: cert_check
|
||||||
|
failed_when: false
|
||||||
|
changed_when: false
|
||||||
|
loop: "{{ cert_list }}"
|
||||||
|
|
||||||
|
- name: remove old cert file before reissue
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ item.item.pki_dir }}/issued/{{ item.item.client.name }}.crt"
|
||||||
|
state: absent
|
||||||
|
loop: "{{ cert_check.results }}"
|
||||||
|
when: item.rc != 0
|
||||||
|
|
||||||
|
- name: remove old req file before reissue
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ item.item.pki_dir }}/reqs/{{ item.item.client.name }}.req"
|
||||||
|
state: absent
|
||||||
|
loop: "{{ cert_check.results }}"
|
||||||
|
when: item.rc != 0
|
||||||
|
|
||||||
|
- name: remove old key file before reissue
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ item.item.pki_dir }}/private/{{ item.item.client.name }}.key"
|
||||||
|
state: absent
|
||||||
|
loop: "{{ cert_check.results }}"
|
||||||
|
when: item.rc != 0
|
||||||
|
|
||||||
|
- name: issue or renew client certificates
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: /opt/easy-rsa/easyrsa --batch build-client-full "{{ item.item.client.name }}" nopass
|
||||||
|
environment:
|
||||||
|
EASYRSA_PKI: "{{ item.item.pki_dir }}"
|
||||||
|
when: item.rc != 0
|
||||||
|
loop: "{{ cert_check.results }}"
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
- name: get latest easy-rsa release info
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: https://api.github.com/repos/OpenVPN/easy-rsa/releases/latest
|
||||||
|
return_content: true
|
||||||
|
register: easyrsa_release
|
||||||
|
run_once: true
|
||||||
|
check_mode: false
|
||||||
|
|
||||||
|
- name: set current easy-rsa version
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
easyrsa_version: "{{ easyrsa_release.json.tag_name | replace('v', '') }}"
|
||||||
|
easyrsa_asset_url: "{{ easyrsa_release.json.assets | selectattr('name', 'search', 'EasyRSA.*\\.tgz') | map(attribute='browser_download_url') | first }}"
|
||||||
|
|
||||||
|
- name: check easy-rsa installed version
|
||||||
|
ansible.builtin.command: /opt/easy-rsa/easyrsa version
|
||||||
|
register: easyrsa_current_version
|
||||||
|
changed_when: false
|
||||||
|
failed_when: false
|
||||||
|
|
||||||
|
- name: ensure easy-rsa directory exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /opt/easy-rsa
|
||||||
|
state: directory
|
||||||
|
mode: '0755'
|
||||||
|
check_mode: false
|
||||||
|
|
||||||
|
- name: update easy-rsa
|
||||||
|
ansible.builtin.unarchive:
|
||||||
|
src: "{{ easyrsa_asset_url }}"
|
||||||
|
dest: /opt/easy-rsa
|
||||||
|
remote_src: true
|
||||||
|
extra_opts:
|
||||||
|
- --strip-components=1
|
||||||
|
when: easyrsa_version not in (easyrsa_current_version.stdout | default(''))
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
- name: include install
|
||||||
|
ansible.builtin.include_tasks: install.yml
|
||||||
|
|
||||||
|
- name: include configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
|
|
||||||
|
- name: include client-certs.yml
|
||||||
|
ansible.builtin.include_tasks: client-certs.yml
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
client
|
||||||
|
dev tap0
|
||||||
|
proto tcp
|
||||||
|
remote 127.0.0.1 1195
|
||||||
|
resolv-retry infinite
|
||||||
|
nobind
|
||||||
|
persist-key
|
||||||
|
persist-tun
|
||||||
|
remote-cert-tls server
|
||||||
|
auth SHA256
|
||||||
|
cipher AES-256-GCM
|
||||||
|
verb 3
|
||||||
|
{% if item.1.ip is defined %}
|
||||||
|
route-metric {{ item.1.route_metric | default(50) }}
|
||||||
|
script-security 2
|
||||||
|
up "C:\\Windows\\System32\\netsh.exe interface ip set address name="OpenVPN TAP-Windows6" static {{ item.1.ip }} 255.255.255.0"
|
||||||
|
{% endif %}
|
||||||
|
<ca>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
||||||
|
</ca>
|
||||||
|
<cert>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
||||||
|
</cert>
|
||||||
|
<key>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
||||||
|
</key>
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
client
|
||||||
|
dev tun0
|
||||||
|
proto tcp
|
||||||
|
remote 127.0.0.1 1194
|
||||||
|
resolv-retry infinite
|
||||||
|
nobind
|
||||||
|
persist-key
|
||||||
|
persist-tun
|
||||||
|
remote-cert-tls server
|
||||||
|
auth SHA256
|
||||||
|
cipher AES-256-GCM
|
||||||
|
verb 3
|
||||||
|
<ca>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
||||||
|
</ca>
|
||||||
|
<cert>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
||||||
|
</cert>
|
||||||
|
<key>
|
||||||
|
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
||||||
|
</key>
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
- name: validate haproxy config
|
||||||
|
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
|
||||||
|
changed_when: false
|
||||||
|
listen: restart haproxy
|
||||||
|
|
||||||
|
- name: restart haproxy systemd service unit
|
||||||
|
ansible.builtin.systemd_service:
|
||||||
|
name: haproxy
|
||||||
|
daemon_reload: true
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
listen: restart haproxy
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
- name: render haproxy config
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
|
||||||
|
notify: restart haproxy
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: install haproxy
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: haproxy
|
||||||
|
state: latest
|
||||||
|
update_cache: true
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: include install
|
||||||
|
ansible.builtin.include_tasks: install.yml
|
||||||
|
|
||||||
|
- name: include configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
@@ -0,0 +1,90 @@
|
|||||||
|
global
|
||||||
|
log /dev/log local2
|
||||||
|
chroot /var/lib/haproxy
|
||||||
|
maxconn 4000
|
||||||
|
user haproxy
|
||||||
|
group haproxy
|
||||||
|
daemon
|
||||||
|
stats socket /var/lib/haproxy/stats mode 660 level admin
|
||||||
|
|
||||||
|
defaults
|
||||||
|
log global
|
||||||
|
mode tcp
|
||||||
|
option tcplog
|
||||||
|
option dontlognull
|
||||||
|
retries 3
|
||||||
|
timeout connect 5s
|
||||||
|
timeout client 1h
|
||||||
|
timeout server 1h
|
||||||
|
timeout check 10s
|
||||||
|
|
||||||
|
frontend http_frontend
|
||||||
|
bind 127.0.0.1:10080
|
||||||
|
mode http
|
||||||
|
option httplog
|
||||||
|
acl host_dttx hdr_end(host) -m end dttx.ru
|
||||||
|
use_backend dttx_http_srv if host_dttx
|
||||||
|
default_backend oyacoi_http_srv
|
||||||
|
|
||||||
|
backend oyacoi_http_srv
|
||||||
|
mode http
|
||||||
|
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
|
||||||
|
|
||||||
|
backend dttx_http_srv
|
||||||
|
mode http
|
||||||
|
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
|
||||||
|
|
||||||
|
frontend https_frontend
|
||||||
|
bind 127.0.0.1:10443
|
||||||
|
mode tcp
|
||||||
|
option tcplog
|
||||||
|
tcp-request inspect-delay 5s
|
||||||
|
tcp-request content accept if { req_ssl_hello_type 1 }
|
||||||
|
acl host_dttx req_ssl_sni -m end dttx.ru
|
||||||
|
acl host_telemt req_ssl_sni -m end regionculture.ru
|
||||||
|
use_backend dttx_https_srv if host_dttx
|
||||||
|
use_backend telemt_https_srv if host_telemt
|
||||||
|
default_backend oyacoi_https_srv
|
||||||
|
|
||||||
|
backend oyacoi_https_srv
|
||||||
|
mode tcp
|
||||||
|
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
|
||||||
|
|
||||||
|
backend dttx_https_srv
|
||||||
|
mode tcp
|
||||||
|
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
|
||||||
|
|
||||||
|
backend telemt_https_srv
|
||||||
|
mode tcp
|
||||||
|
option tcp-check
|
||||||
|
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
|
||||||
|
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
|
||||||
|
|
||||||
|
listen mcsmanager_service
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:24444
|
||||||
|
mode tcp
|
||||||
|
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
|
||||||
|
|
||||||
|
listen xmpp_c2s
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5222
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
|
||||||
|
|
||||||
|
listen xmpp_legacy_ssl
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5223
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
|
||||||
|
|
||||||
|
listen xmpp_s2s
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5269
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
|
||||||
|
|
||||||
|
listen prosody_proxy65
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5000
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
|
||||||
|
|
||||||
|
listen prosody_components
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5270
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
|
||||||
|
|
||||||
|
listen prosody_bosh_http
|
||||||
|
bind {{ hostvars['liqueur']['container_ip'] }}:5280
|
||||||
|
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
|
||||||
@@ -5,9 +5,16 @@ iface lo inet loopback
|
|||||||
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
|
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
|
||||||
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
|
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
|
||||||
|
|
||||||
|
auto br-eth0
|
||||||
|
iface br-eth0 inet static
|
||||||
|
address 10.1.0.1/24
|
||||||
|
bridge_ports eth0 tap0
|
||||||
|
bridge_stp off
|
||||||
|
pre-up ip tuntap add dev tap0 mode tap || true
|
||||||
|
post-down ip tuntap del dev tap0 mode tap || true
|
||||||
|
|
||||||
auto eth0
|
auto eth0
|
||||||
iface eth0 inet manual
|
iface eth0 inet manual
|
||||||
address 10.1.0.1/24
|
|
||||||
|
|
||||||
auto eth0.2
|
auto eth0.2
|
||||||
iface eth0.2 inet static
|
iface eth0.2 inet static
|
||||||
@@ -41,12 +48,3 @@ iface eth0.12 inet static
|
|||||||
|
|
||||||
auto eth1
|
auto eth1
|
||||||
iface eth1 inet dhcp
|
iface eth1 inet dhcp
|
||||||
|
|
||||||
auto wg0
|
|
||||||
iface wg0 inet manual
|
|
||||||
post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
|
|
||||||
post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
|
|
||||||
post-up ip route add default dev wg0 table 199 2>/dev/null || true
|
|
||||||
pre-down ip route del default dev wg0 table 199 2>/dev/null || true
|
|
||||||
pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
|
|
||||||
pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
|
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
- name: deploy ifupdown interfaces
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "{{ inventory_hostname }}/interfaces"
|
||||||
|
dest: /etc/network/interfaces
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
register: interfaces_conf
|
||||||
|
|
||||||
|
- name: reload ifupdown2
|
||||||
|
command: ifreload -a
|
||||||
|
when: interfaces_conf.changed
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
- name: include configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
|
|
||||||
|
- name: include prerequisites
|
||||||
|
ansible.builtin.include_tasks: prerequisites.yml
|
||||||
|
tags: ifupdown2_prereqs
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
- name: install bridge-utils
|
||||||
|
ansible.builtin.package:
|
||||||
|
name: bridge-utils
|
||||||
|
state: present
|
||||||
|
register: bridge_utils_install
|
||||||
|
|
||||||
|
- name: ensure rt_tables.d directory exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/iproute2/rt_tables.d
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
register: rt_tables_dir
|
||||||
|
|
||||||
|
- name: reload ifupdown2
|
||||||
|
ansible.builtin.command: ifreload -a
|
||||||
|
when: bridge_utils_install.changed or rt_tables_dir.changed
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
- name: set required locales
|
||||||
|
community.general.locale_gen:
|
||||||
|
name: "{{ item }}"
|
||||||
|
state: present
|
||||||
|
loop: "{{ locales_list }}"
|
||||||
|
|
||||||
|
- name: configure /etc/locale.conf
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /etc/locale.conf
|
||||||
|
content: LANG={{ locale_default }}
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
- name: include locales configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
/var/log/xray-core/*.log {
|
||||||
|
daily
|
||||||
|
rotate 4
|
||||||
|
compress
|
||||||
|
delaycompress
|
||||||
|
missingok
|
||||||
|
notifempty
|
||||||
|
copytruncate
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
- name: deploy logrotate config
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "{{ inventory_hostname }}/"
|
||||||
|
dest: "/etc/logrotate.d/"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
- name: include logrotate configure
|
||||||
|
ansible.builtin.include_tasks: configure.yml
|
||||||
@@ -1,49 +0,0 @@
|
|||||||
flowtable ft {
|
|
||||||
hook ingress priority filter
|
|
||||||
devices = { eth0, eth1 }
|
|
||||||
}
|
|
||||||
|
|
||||||
chain input {
|
|
||||||
type filter hook input priority filter; policy drop;
|
|
||||||
|
|
||||||
ct state established,related accept
|
|
||||||
ct state invalid drop
|
|
||||||
|
|
||||||
iif lo accept
|
|
||||||
ip protocol icmp accept
|
|
||||||
ip6 nexthdr icmpv6 accept
|
|
||||||
|
|
||||||
meta mark 0x00000001 accept
|
|
||||||
|
|
||||||
iifname eth0 tcp dport 22 accept
|
|
||||||
iifname eth0.11 tcp dport 22 accept
|
|
||||||
|
|
||||||
iifname eth1 udp dport 51820 accept
|
|
||||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
|
||||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
|
||||||
|
|
||||||
iifname eth0.3 udp dport 67 accept
|
|
||||||
iifname eth1 udp dport 68 accept
|
|
||||||
|
|
||||||
#include "/etc/nftables.d/90-input.nft"
|
|
||||||
}
|
|
||||||
|
|
||||||
chain forward {
|
|
||||||
type filter hook forward priority filter; policy drop;
|
|
||||||
|
|
||||||
ct state established,related accept
|
|
||||||
ct state invalid drop
|
|
||||||
|
|
||||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
|
||||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
|
||||||
|
|
||||||
tcp flags syn tcp option maxseg size set rt mtu
|
|
||||||
|
|
||||||
include "/etc/nftables.d/90-forward.nft"
|
|
||||||
}
|
|
||||||
|
|
||||||
chain output {
|
|
||||||
type route hook output priority filter; policy accept;
|
|
||||||
|
|
||||||
#include "/etc/nftables.d/90-output.nft"
|
|
||||||
}
|
|
||||||
@@ -1,35 +0,0 @@
|
|||||||
chain vpn_prerouting_dnat {
|
|
||||||
type nat hook prerouting priority dstnat - 5; policy accept;
|
|
||||||
|
|
||||||
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
|
|
||||||
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
|
|
||||||
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
|
|
||||||
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
|
|
||||||
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
|
|
||||||
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
|
|
||||||
}
|
|
||||||
|
|
||||||
chain vpn_postrouting_snat {
|
|
||||||
type nat hook postrouting priority srcnat; policy accept;
|
|
||||||
|
|
||||||
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
|
|
||||||
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
|
|
||||||
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
|
|
||||||
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
|
|
||||||
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
|
|
||||||
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
|
|
||||||
}
|
|
||||||
|
|
||||||
chain vpn_prerouting_pbr {
|
|
||||||
type filter hook prerouting priority mangle - 10; policy accept;
|
|
||||||
|
|
||||||
iifname wg0 ct state new counter ct mark set 0x000000c7
|
|
||||||
ip daddr 10.0.0.0/8 return
|
|
||||||
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
|
|
||||||
}
|
|
||||||
|
|
||||||
chain vpn_output_pbr {
|
|
||||||
type route hook output priority mangle - 10; policy accept;
|
|
||||||
|
|
||||||
ct mark 0x000000c7 counter meta mark set 0x000000c7
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
chain proxy_prerouting {
|
|
||||||
type filter hook prerouting priority filter - 50; policy accept;
|
|
||||||
|
|
||||||
fib daddr type local accept
|
|
||||||
|
|
||||||
include "/etc/nftables.d/90-proxy.nft"
|
|
||||||
}
|
|
||||||
|
|
||||||
chain proxy_output {
|
|
||||||
type route hook output priority mangle; policy accept;
|
|
||||||
|
|
||||||
#meta mark 0x000000ff return
|
|
||||||
|
|
||||||
#meta l4proto { tcp, udp } ip daddr @cloudflare_ip meta mark set 0x00000001 accept
|
|
||||||
}
|
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
#!/usr/sbin/nft -f
|
|
||||||
|
|
||||||
flush ruleset
|
|
||||||
|
|
||||||
table inet filter {
|
|
||||||
include "/etc/nftables.d/40-sets.nft"
|
|
||||||
include "/etc/nftables.d/90-sets.nft"
|
|
||||||
include "/etc/nftables.d/10-filter.nft"
|
|
||||||
include "/etc/nftables.d/20-vpn.nft"
|
|
||||||
include "/etc/nftables.d/30-proxy.nft"
|
|
||||||
}
|
|
||||||
|
|
||||||
table ip nat {
|
|
||||||
include "/etc/nftables.d/10-nat.nft"
|
|
||||||
}
|
|
||||||
@@ -2,7 +2,6 @@ chain postrouting {
|
|||||||
type nat hook postrouting priority srcnat; policy accept;
|
type nat hook postrouting priority srcnat; policy accept;
|
||||||
oifname eth1 masquerade
|
oifname eth1 masquerade
|
||||||
}
|
}
|
||||||
|
|
||||||
chain prerouting {
|
chain prerouting {
|
||||||
type nat hook prerouting priority dstnat; policy accept;
|
type nat hook prerouting priority dstnat; policy accept;
|
||||||
include "/etc/nftables.d/90-dstnat.nft"
|
include "/etc/nftables.d/90-dstnat.nft"
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
flowtable ft {
|
||||||
|
hook ingress priority filter
|
||||||
|
devices = { eth0, eth1 }
|
||||||
|
}
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority filter; policy drop;
|
||||||
|
ct state established,related accept
|
||||||
|
ct state invalid drop
|
||||||
|
iif lo accept
|
||||||
|
meta mark 0x00000001 accept
|
||||||
|
iifname br-eth0 tcp dport 22 accept
|
||||||
|
iifname eth0.11 tcp dport 22 accept
|
||||||
|
iifname tun0 tcp dport 22 accept
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
||||||
|
iifname eth0.3 udp dport 67 accept
|
||||||
|
iifname eth1 udp dport 68 accept
|
||||||
|
include "/etc/nftables.d/90-input.nft"
|
||||||
|
}
|
||||||
|
chain forward {
|
||||||
|
type filter hook forward priority filter; policy drop;
|
||||||
|
ct state established,related accept
|
||||||
|
ct state invalid drop
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||||
|
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||||
|
tcp flags syn tcp option maxseg size set rt mtu
|
||||||
|
include "/etc/nftables.d/90-forward.nft"
|
||||||
|
}
|
||||||
|
chain output {
|
||||||
|
type route hook output priority filter; policy accept;
|
||||||
|
include "/etc/nftables.d/90-output.nft"
|
||||||
|
}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
chain proxy_prerouting {
|
||||||
|
type filter hook prerouting priority filter - 50; policy accept;
|
||||||
|
fib daddr type local accept
|
||||||
|
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
|
||||||
|
include "/etc/nftables.d/90-proxy-prerouting.nft"
|
||||||
|
}
|
||||||
|
chain proxy_output {
|
||||||
|
type route hook output priority mangle; policy accept;
|
||||||
|
meta mark != 0 return
|
||||||
|
include "/etc/nftables.d/90-proxy-output.nft"
|
||||||
|
}
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
---
|
---
|
||||||
- name: reload nftables
|
- name: restart nftables
|
||||||
ansible.builtin.command: nft -f /etc/nftables.conf
|
ansible.builtin.command: nft -f /etc/nftables.conf
|
||||||
listen: reload nftables
|
listen: restart nftables
|
||||||
|
|||||||
@@ -0,0 +1,58 @@
|
|||||||
|
---
|
||||||
|
- name: ensure /etc/nftables.d exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/nftables.d
|
||||||
|
state: directory
|
||||||
|
mode: "0755"
|
||||||
|
when: nftables_bootstrap_files | default(false)
|
||||||
|
|
||||||
|
- name: bootstrap empty config files
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: "/etc/nftables.d/{{ item }}"
|
||||||
|
content: ""
|
||||||
|
force: false
|
||||||
|
mode: "0644"
|
||||||
|
loop:
|
||||||
|
- 10-sets.nft
|
||||||
|
- 20-sets.nft
|
||||||
|
- 30-nat.nft
|
||||||
|
- 40-filter.nft
|
||||||
|
- 50-proxy.nft
|
||||||
|
- 90-dstnat.nft
|
||||||
|
- 90-forward.nft
|
||||||
|
- 90-input.nft
|
||||||
|
- 90-output.nft
|
||||||
|
- 90-proxy-output.nft
|
||||||
|
- 90-proxy-prerouting.nft
|
||||||
|
when: nftables_bootstrap_files | default(false)
|
||||||
|
|
||||||
|
- name: deploy nftables rules
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/nftables.d/{{ item | basename }}"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.nft') }}"
|
||||||
|
notify: restart nftables
|
||||||
|
|
||||||
|
- name: render nftable rules
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/nftables.d/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.nft.j2') }}"
|
||||||
|
notify: restart nftables
|
||||||
|
|
||||||
|
- name: deploy nftables.conf
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: "{{ item }}"
|
||||||
|
dest: "/etc/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0644"
|
||||||
|
validate: "nft -c -f %s"
|
||||||
|
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
|
||||||
|
notify: restart nftables
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
- name: install nftables
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: nftables
|
||||||
|
state: latest
|
||||||
|
update_cache: true
|
||||||
@@ -1,41 +1,6 @@
|
|||||||
---
|
---
|
||||||
- name: ensure /etc/nftables.d exists
|
- name: include nftables install
|
||||||
ansible.builtin.file:
|
ansible.builtin.include_tasks: install.yml
|
||||||
path: /etc/nftables.d
|
|
||||||
state: directory
|
|
||||||
mode: "0755"
|
|
||||||
|
|
||||||
- name: deploy nftables rule
|
- name: include nftables configure
|
||||||
ansible.builtin.copy:
|
ansible.builtin.include_tasks: configure.yml
|
||||||
src: "{{ item }}"
|
|
||||||
dest: "/etc/nftables.d/{{ item }}"
|
|
||||||
mode: "0644"
|
|
||||||
loop:
|
|
||||||
- 10-filter.nft
|
|
||||||
- 10-nat.nft
|
|
||||||
- 20-vpn.nft
|
|
||||||
- 30-proxy.nft
|
|
||||||
- 40-sets.nft
|
|
||||||
notify: reload nftables
|
|
||||||
|
|
||||||
- name: render forward
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-forward.nft.j2
|
|
||||||
dest: /etc/nftables.d/90-forward.nft
|
|
||||||
mode: "0644"
|
|
||||||
notify: reload nftables
|
|
||||||
|
|
||||||
- name: render dstnat
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: 90-dstnat.nft.j2
|
|
||||||
dest: /etc/nftables.d/90-dstnat.nft
|
|
||||||
mode: "0644"
|
|
||||||
notify: reload nftables
|
|
||||||
|
|
||||||
- name: deploy nftables.conf
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: nftables.conf
|
|
||||||
dest: /etc/nftables.conf
|
|
||||||
mode: "0644"
|
|
||||||
validate: "nft -c -f %s"
|
|
||||||
notify: reload nftables
|
|
||||||
|
|||||||
@@ -1,31 +0,0 @@
|
|||||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
|
||||||
{% macro render_dstnat_rule(ifaces, proto, port, target_ip, item_name) %}
|
|
||||||
{% set lines = [] %}
|
|
||||||
{% set active_ifaces = ifaces if (ifaces is iterable and ifaces is not string) else [ifaces] %}
|
|
||||||
{% for current_iface in active_ifaces %}
|
|
||||||
{% set comment_str = ' comment "' ~ current_iface ~ ' -> ' ~ item_name ~ '"' %}
|
|
||||||
{% set rule_line = 'iifname "' ~ current_iface ~ '" ' ~ proto ~ ' dport ' ~ port ~ ' counter dnat ip to ' ~ target_ip ~ ':' ~ port ~ comment_str %}
|
|
||||||
{% set _ = lines.append(rule_line) %}
|
|
||||||
{% endfor %}
|
|
||||||
{{ lines | join('\n') }}
|
|
||||||
{% endmacro %}
|
|
||||||
{% filter regex_replace('\n[ \t]*\n+', '\n') %}
|
|
||||||
{% for item in groups[nft_managed_group] | sort %}
|
|
||||||
{% set client = hostvars[item] %}
|
|
||||||
{% if 'nft_dst' in client and client.nft_dst is not none %}
|
|
||||||
{% set target_ip = client.container_ip | default(client.ansible_host | default(item)) %}
|
|
||||||
{% set raw_expose = client.nft_dst %}
|
|
||||||
{% set exposes = raw_expose if (raw_expose is iterable and raw_expose is not string and raw_expose is not mapping) else [raw_expose] %}
|
|
||||||
{% for expose in exposes %}
|
|
||||||
{% set protos = expose.proto if (expose.proto is defined and expose.proto is iterable and expose.proto is not string) else [expose.proto | default('tcp')] %}
|
|
||||||
{% set ports = expose.port if (expose.port is defined and expose.port is iterable and expose.port is not string) else [expose.port] %}
|
|
||||||
{% set ifaces = expose.iface %}
|
|
||||||
{% for p in protos | sort %}
|
|
||||||
{% for port in ports | sort %}
|
|
||||||
{{ render_dstnat_rule(ifaces, p, port, target_ip, item) }}
|
|
||||||
{% endfor %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endif %}
|
|
||||||
{% endfor %}
|
|
||||||
{% endfilter %}
|
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user