diff --git a/ansible/inventories/distributed.yaml b/ansible/inventories/distributed.yaml index 56ef2b6..d251e2b 100644 --- a/ansible/inventories/distributed.yaml +++ b/ansible/inventories/distributed.yaml @@ -20,7 +20,7 @@ distributed: nextcloud: hosts: hserve2: - ansible_host: 192.168.1.0 + ansible_host: 192.168.1.130 nginx: hosts: hserve1: diff --git a/ansible/inventories/group_vars/all/main.yaml b/ansible/inventories/group_vars/all/main.yaml new file mode 100644 index 0000000..d55c0e5 --- /dev/null +++ b/ansible/inventories/group_vars/all/main.yaml @@ -0,0 +1,2 @@ +--- +become_exe_value: "sudo" \ No newline at end of file diff --git a/ansible/inventories/group_vars/all/vault.yaml b/ansible/inventories/group_vars/all/vault.yaml index 8dd5674..baa29e8 100644 --- a/ansible/inventories/group_vars/all/vault.yaml +++ b/ansible/inventories/group_vars/all/vault.yaml @@ -1,29 +1,33 @@ $ANSIBLE_VAULT;1.1;AES256 -38356639333633663161333637663539623835623666653738333235336563373030653036393837 -3235613032363938623938303463333562656561316636660a626532363638396138613637323265 -66663562366431333139616134333039323737356437393031643463363362363335636464333162 -3430353964646133660a666234613262396464363134313935383661393438616237633961643233 -31646435326336353130323139323961343561646137636332333139643033303664333035663538 -30346138613061616432656431613437306462666432646239373236323633346131663431366564 -66663031353366663766663330346633306233653033626134343738303937393934393936646533 -63613338323631366537353531356538643738393562346161666566393639363138663832306639 -32336433643134323433633433376137363834353763643834393530356536316565653831616165 -32306661353761643139343838313535333365646265613537626533346338333239626137363533 -39323930636336396134313561346463313662333734643536366433663030393130646366396564 -66656335353138376638353939316263306633613563663465636366353437333536353731326562 -66313862373830383736323330616236643066393032353961643166663935333966386562646335 -62616634363964333062306637656331396339643662663132623533636663313962376266353137 -30663131326365613635616234616138366236303938386536346633393839393732653964316636 -36626262663463306434386332353166313162356365643866393638663564343161643430373937 -37336233396632316537626465323866373463306565633835363263616362653266303364373835 -30386163626239356333353232343662643438353965346335613937346366386331343965343738 -32633732366161653834663766326536343065613463643263333065396532356635376362336335 -36386339343832623664323732363638616632363964373732336565636161396237333934353931 -66656339653731343534666635663331336238646561353664323438356339343164353531303362 -38333535333064386562346234656232653938316337343163616361633834656234333036393932 -37303539663032363134613335663937363165636135663338656434633031336631613236346663 -31376535353235636362346462333530633334313266613433396361333331363936643863323261 -61653564393238323935373935653662636363353063613432653531393337613664336433663337 -34383533376362303439303132363665313437363134333432643566636335393739616639613961 -32626163333961343331323364636238353137613835363363613538333231303031323033383634 -65643735636133313964 +63663638383238373238386231396435393236303735313430633639326436636237396363356636 +3335633566393761386331363065363230313134396562370a663439363937316338656361663563 +63366332333231666235613830663031663432613066376461316137336166646464323938373163 +6436373935383464360a363536383139616636613033653035356464643432303838663130373938 +66336361363038393365653562323431633439336534373664356638313535316333633839366330 +36383661363766386232616533323765386137656139373137623630356562386562653762336465 +63363163643639616235353436613664636434393734393565316161633664323131396638346165 +65616263643335396566393630636233306637313264366338636636666663373537613663663736 +31613739643130353532306366626264363630623933313561366534393630613534643139353466 +37373963333531666139356335393563623739323165356362616536656231663466366562333839 +39393761396265303032343664353634383132323039373135376636633234656666323433633934 +39613665643730373931383233643932373861396137306334353839663031633762663034396233 +62616339613431333330666639356332376539616338626635653635386464366436643036383363 +38663632346265303330666639613130396130626362643865316537323931633465326666636139 +37383565326661656566313738636236663137636361616461616536393338363333663634373861 +35643361663735316339663561643032343335666361383932316332393661643739393631343530 +63366166386135653762343136643462336161653433653032363539336630636133623435313337 +34333466396336633662653731343535383334303738366533653763326434366561393762386166 +31303163396432343463666236336136653065633132613234643430646631356632306562653034 +36643763313137626333313836383866323431343230326366663136643736383435326533613362 +66613864656230303561626661613632363761316334306530323137616365396439623966623664 +31386339313136366631616432623430363231646462653866313264333138383666313638396438 +62386639346235663463633365386362326239666261303438656339306662623464633962353833 +66323865613465353434666431663833363431356235376530636365313264626364633231633937 +66356563656138663733653935643231613437316137383930353738363561666131393838346464 +36646366303434323162363736343362623461343561363862313730316361383631313837366638 +66353738396661323536383532323639303961313862663330636161643635636231393536383466 +61366435663330633863343165636630373237356563636261636562613863633831643432323436 +63396461643639396363653031666262386230346533346136633166636438336233333234313839 +34373439363963633262663733663335353535343137366436336562336161373231346266393336 +38303065323030653233323831303566336233336162323563336330366539303836663462346434 +62643331643931383364 diff --git a/ansible/inventories/group_vars/new_sudo/main.yaml b/ansible/inventories/group_vars/new_sudo/main.yaml index 58490a0..0b1b0d5 100644 --- a/ansible/inventories/group_vars/new_sudo/main.yaml +++ b/ansible/inventories/group_vars/new_sudo/main.yaml @@ -1,2 +1,2 @@ --- -become_exe: sudo.ws \ No newline at end of file +become_exe_value: "sudo.ws" \ No newline at end of file diff --git a/ansible/inventories/group_vars/pangolin/node_setup.yaml b/ansible/inventories/group_vars/pangolin/node_setup.yaml new file mode 100644 index 0000000..7b192e7 --- /dev/null +++ b/ansible/inventories/group_vars/pangolin/node_setup.yaml @@ -0,0 +1,3 @@ +--- +configure_swap: true +ip_tables_config: true \ No newline at end of file diff --git a/ansible/inventories/host_vars/hserve2.yaml b/ansible/inventories/host_vars/hserve2.yaml new file mode 100644 index 0000000..e05715a --- /dev/null +++ b/ansible/inventories/host_vars/hserve2.yaml @@ -0,0 +1,4 @@ +--- +pangolin_site_id: 5hraslci7wl46nj +newt_secret: "{{ hserve2_crypted_site_secret }}" +nextcloud_docker_mastercontainer_volume_dir: "/home/{{ ansible_user }}/docker_data/nextcloud_aio_mastercontainer" \ No newline at end of file diff --git a/ansible/playbooks/authentik.yaml b/ansible/playbooks/authentik.yaml index 150e05b..9f0b30a 100644 --- a/ansible/playbooks/authentik.yaml +++ b/ansible/playbooks/authentik.yaml @@ -1,10 +1,15 @@ --- - name: Install / remove authentik hosts: authentik - become: true - debugger: on_failed - roles: - - geerlingguy.docker - - newt_client - - ax-bzh.authentik + tasks: + - include_role: + name: geerlingguy.docker + apply: + become: true + become_exe: "{{ become_exe_value }}" + - include_role: + name: "{{ item }}" + loop : + - newt_client + - ax-bzh.authentik diff --git a/ansible/playbooks/bootstrap.yaml b/ansible/playbooks/bootstrap.yaml index 008a181..a9958e8 100644 --- a/ansible/playbooks/bootstrap.yaml +++ b/ansible/playbooks/bootstrap.yaml @@ -2,6 +2,7 @@ - name: Bootstrap node hosts: all become: true + become_exe: "{{ become_exe_value }}" tasks: - name: Add the ansible group ansible.builtin.group: diff --git a/ansible/playbooks/forgejo.yaml b/ansible/playbooks/forgejo.yaml index da01c0d..57eb852 100644 --- a/ansible/playbooks/forgejo.yaml +++ b/ansible/playbooks/forgejo.yaml @@ -1,5 +1,15 @@ --- - name : Install Forgejo hosts: forgejo - roles: - - forgejo \ No newline at end of file + tasks: + - include_role: + name: geerlingguy.docker + apply: + become: true + become_exe: "{{ become_exe_value }}" + + - include_role: + name: "{{ item }}" + loop : + - newt_client + - forgejo \ No newline at end of file diff --git a/ansible/playbooks/nextcloud.yaml b/ansible/playbooks/nextcloud.yaml new file mode 100644 index 0000000..492641e --- /dev/null +++ b/ansible/playbooks/nextcloud.yaml @@ -0,0 +1,15 @@ +--- +- name: Install Nextcloud + hosts: nextcloud + tasks: + - include_role: + name: geerlingguy.docker + apply: + become: true + become_exe: "{{ become_exe_value }}" + + - include_role: + name: "{{ item }}" + loop: + - newt_client + - nextcloud_aio \ No newline at end of file diff --git a/ansible/playbooks/pangolin.yaml b/ansible/playbooks/pangolin.yaml index b7858cf..2d1d4e8 100644 --- a/ansible/playbooks/pangolin.yaml +++ b/ansible/playbooks/pangolin.yaml @@ -1,7 +1,14 @@ --- - name: Install and configure Pangolin hosts: pangolin - become: true - roles: - - geerlingguy.docker - - pangolin \ No newline at end of file + tasks: + - include_role: + name: "{{ item }}" + apply: + become: true + become_exe: "{{ become_exe_value }}" + loop: + - geerlingguy.docker + - prepare_node + + - include_role: pangolin \ No newline at end of file diff --git a/ansible/playbooks/roles/forgejo/tasks/main.yaml b/ansible/playbooks/roles/forgejo/tasks/main.yaml index daaca37..e2b48ee 100644 --- a/ansible/playbooks/roles/forgejo/tasks/main.yaml +++ b/ansible/playbooks/roles/forgejo/tasks/main.yaml @@ -1,6 +1,2 @@ --- -- include_role: - name: geerlingguy.docker - apply: - become: true - include_tasks: forgejo_docker.yaml \ No newline at end of file diff --git a/ansible/playbooks/roles/nextcloud_aio/defaults/main.yaml b/ansible/playbooks/roles/nextcloud_aio/defaults/main.yaml new file mode 100644 index 0000000..cea8237 --- /dev/null +++ b/ansible/playbooks/roles/nextcloud_aio/defaults/main.yaml @@ -0,0 +1,4 @@ +nextcloud_docker_image_name: "ghcr.io/nextcloud-releases/all-in-one" +nextcloud_docker_image_tag: latest +nextcloud_docker_skip_domain_validation: "true" +nextcloud_docker_mastercontainer_volume_dir: /usr/data/nextcloud_aio_mastercontainer \ No newline at end of file diff --git a/ansible/playbooks/roles/nextcloud_aio/tasks/main.yaml b/ansible/playbooks/roles/nextcloud_aio/tasks/main.yaml new file mode 100644 index 0000000..a18beca --- /dev/null +++ b/ansible/playbooks/roles/nextcloud_aio/tasks/main.yaml @@ -0,0 +1,2 @@ +--- +- import_tasks: nextcloud_docker_aio.yaml \ No newline at end of file diff --git a/ansible/playbooks/roles/nextcloud_aio/tasks/nextcloud_docker_aio.yaml b/ansible/playbooks/roles/nextcloud_aio/tasks/nextcloud_docker_aio.yaml new file mode 100644 index 0000000..021ef65 --- /dev/null +++ b/ansible/playbooks/roles/nextcloud_aio/tasks/nextcloud_docker_aio.yaml @@ -0,0 +1,33 @@ +--- +- name: Pull docker image + docker_image: + name: "{{ nextcloud_docker_image_name }}" + tag: "{{ nextcloud_docker_image_tag }}" + source: pull + +- name: Create Master Container volume dir + file: + path: "{{ nextcloud_docker_mastercontainer_volume_dir }}" + state: directory + mode: "0766" + +- name: Create container + docker_container: + name: nextcloud-aio-mastercontainer + image: "{{ nextcloud_docker_image_name }}:{{ nextcloud_docker_image_tag }}" + ports: + - "8080:8080" + # - "80:80" + # - "8443:8443" + env: + APACHE_PORT: "11000" + APACHE_IP_BINDING: "0.0.0.0" + # APACHE_ADDITIONAL_NETWORK: "" + SKIP_DOMAIN_VALIDATION: "{{ nextcloud_docker_skip_domain_validation }}" + volumes: + - nextcloud_aio_mastercontainer:/mnt/docker-aio-config + - /var/run/docker.sock:/var/run/docker.sock:ro + networks: + - name: newt_compose_default + restart_policy : "always" + init : true \ No newline at end of file diff --git a/ansible/playbooks/roles/pangolin/tasks/prepare_node.yaml b/ansible/playbooks/roles/prepare_node/tasks/iptables.yaml similarity index 53% rename from ansible/playbooks/roles/pangolin/tasks/prepare_node.yaml rename to ansible/playbooks/roles/prepare_node/tasks/iptables.yaml index 95581b0..d98b3b5 100644 --- a/ansible/playbooks/roles/pangolin/tasks/prepare_node.yaml +++ b/ansible/playbooks/roles/prepare_node/tasks/iptables.yaml @@ -1,34 +1,4 @@ --- -- name: Update all packages - ansible.builtin.apt: - update_cache: true - upgrade: dist - -- name: Install essential packages - ansible.builtin.apt: - name: - - net-tools - - curl - - wget - - htop - - vim - state: present - -- name: Add 1GB swap file - ansible.builtin.shell: | - fallocate -l 1G /swapfile - chmod 600 /swapfile - mkswap /swapfile - swapon /swapfile - args: - creates: /swapfile - -- name: Make swap persistent - ansible.builtin.lineinfile: - dest: /etc/fstab - line: '/swapfile none swap sw 0 0' - state: present - - name: Configure iptables firewall rules ansible.builtin.iptables: chain: INPUT @@ -42,9 +12,10 @@ - { protocol: tcp, port: '443', description: 'HTTPS for secure web traffic' } - { protocol: udp, port: '51820', description: 'WireGuard VPN traffic' } become: true + become_exe: "{{ become_exe_value }}" register: iptables_result - name: Display iptables configuration status ansible.builtin.debug: msg: "Configured firewall rules for ports: 80 (HTTP), 443 (HTTPS), 51820 (WireGuard UDP)" - when: iptables_result is changed + when: iptables_result is changed \ No newline at end of file diff --git a/ansible/playbooks/roles/prepare_node/tasks/main.yaml b/ansible/playbooks/roles/prepare_node/tasks/main.yaml new file mode 100644 index 0000000..967613a --- /dev/null +++ b/ansible/playbooks/roles/prepare_node/tasks/main.yaml @@ -0,0 +1,6 @@ +--- +- include_role: updates.yaml +- include_role: swap.yaml + when: configure_swap is defined +- include_role: iptables.yaml + when: ip_tables_coonfig is defined diff --git a/ansible/playbooks/roles/prepare_node/tasks/swap.yaml b/ansible/playbooks/roles/prepare_node/tasks/swap.yaml new file mode 100644 index 0000000..1476d93 --- /dev/null +++ b/ansible/playbooks/roles/prepare_node/tasks/swap.yaml @@ -0,0 +1,15 @@ +--- +- name: Add 1GB swap file + ansible.builtin.shell: | + fallocate -l 1G /swapfile + chmod 600 /swapfile + mkswap /swapfile + swapon /swapfile + args: + creates: /swapfile + +- name: Make swap persistent + ansible.builtin.lineinfile: + dest: /etc/fstab + line: '/swapfile none swap sw 0 0' + state: present diff --git a/ansible/playbooks/roles/prepare_node/tasks/updates.yaml b/ansible/playbooks/roles/prepare_node/tasks/updates.yaml new file mode 100644 index 0000000..6a3ca46 --- /dev/null +++ b/ansible/playbooks/roles/prepare_node/tasks/updates.yaml @@ -0,0 +1,15 @@ +--- +- name: Update all packages + ansible.builtin.apt: + update_cache: true + upgrade: dist + +- name: Install essential packages + ansible.builtin.apt: + name: + - net-tools + - curl + - wget + - htop + - vim + state: present diff --git a/ansible/playbooks/static_nginx_page.yaml b/ansible/playbooks/static_nginx_page.yaml index 54d4fd8..98b0b1f 100644 --- a/ansible/playbooks/static_nginx_page.yaml +++ b/ansible/playbooks/static_nginx_page.yaml @@ -1,9 +1,15 @@ --- - name : Nginx static with docker hosts: all - become: true - roles: - - geerlingguy.docker - - newt_client - - nginx - \ No newline at end of file + tasks: + - include_role: + name: geerlingguy.docker + apply: + become: true + become_exe: "{{ become_exe_value }}" + + - include_role: + name: "{{ item }}" + loop : + - newt_client + - nginx diff --git a/ansible/playbooks/vpn_server.yaml b/ansible/playbooks/vpn_server.yaml index 3b1af8e..5ca4a65 100644 --- a/ansible/playbooks/vpn_server.yaml +++ b/ansible/playbooks/vpn_server.yaml @@ -2,5 +2,6 @@ - name: Configure VPN Server hosts: wireguard_server become: true + become_exe: "{{ become_exe_value }}" roles: - wireguard_server