Compare commits
15 Commits
| Author | SHA1 | Date |
|---|---|---|
|
|
b7bcc1a8b2 | |
|
|
e876f32de1 | |
|
|
b51e51c322 | |
|
|
218b701b65 | |
|
|
d591e1620e | |
|
|
3021b68b19 | |
|
|
017090b83d | |
|
|
551a189120 | |
|
|
35b217632e | |
|
|
93c0220c47 | |
|
|
100b206596 | |
|
|
1007d542a8 | |
|
|
aca913b266 | |
|
|
c8f3775f29 | |
|
|
537966a964 |
|
|
@ -1,35 +1,38 @@
|
|||
$ANSIBLE_VAULT;1.1;AES256
|
||||
61383036613265336537636538366661373461373031323533396231616237346464653964333735
|
||||
6665333762393635633538633630383739653531363937610a396632333065623965393635363632
|
||||
32313761663832383534326438383462333939346438326134346565393133323136356233363162
|
||||
3736343264313731380a613434663438393732633237373637653937356333633131656564653835
|
||||
61636462663936646138343639376133336430316664643366383133626634646630336630343133
|
||||
35636466346332366338353836303735363765393533343665333637363161616665336136666639
|
||||
39643132346237393962376561306432616630306335313464613561336639333863303337306139
|
||||
33383362666130646630373338626161613034613664343631383263353634626663656637316133
|
||||
39386565636265313039373833623336336464313462643962336164666533636566316630383133
|
||||
38633134346261343630313838303037313538363465363764646561653262663631633832643435
|
||||
30613232623865316233366435383539373262373730656564366634646633333666373437666365
|
||||
66353536313137363839663264653833306533386230313761303565323237616239363630623361
|
||||
66366462663261626432623634386263333631383732343562656362393366646533336637656235
|
||||
63653066356161653363616231386338653632303765366636353035323336356165326431383163
|
||||
32343863333762343236313232353066623330313563303738626234353030646235643937393330
|
||||
62663834356366363164633835663034393734643264373936633764646535366161356137346239
|
||||
39653533663132343036373637346332646534653637353930383261633232633735653430666462
|
||||
39613561643835616634653465363732656136393335633736363137656663326330386231323262
|
||||
31373661333231643937393961653030386437343866356466313931663961393933366233303737
|
||||
63646232646339393664616630336163373239326566613233666238313031343232653132623665
|
||||
62313835373437396335396534346637356632353764623635356237643037613131323236663462
|
||||
36366639656438303964626636346232323936653866383566386662396238643336373430393635
|
||||
61383435313162366636616265663465396165396234303238636362373036653834303963363638
|
||||
62336265356264653935633762633764313036346131633463633966373436623838396238366662
|
||||
37633939333037316237303233393361613538363739326162633233636232393939643233626462
|
||||
31343534393534353664646164343261363531386134306263313135386333356562363939323961
|
||||
65653035343330393939353462376565643234633738366163653532616135316365303236353138
|
||||
39303039333661643963356666336662663037326239663866333561386663326534666466633633
|
||||
36333536633331336266653433316363666632393033393330333739383831623539656661313433
|
||||
63333835353835653664623736393532663366623637653466336530393565323535343665303733
|
||||
63383562396266613266616330666231346231323865343133373435653239623835326633363666
|
||||
63353539356430386638313739653532303635616531643263376535656433346533353962383565
|
||||
31623236613533623334653235303533353437626162353331383734663539333037383161633636
|
||||
6161393763656532356535396238376162353165366365316337
|
||||
37383965623033356461393931656332323239323065326639613132306337393864366132366436
|
||||
3130323864613235326338663735303931343363616435310a613164376464353130656539663036
|
||||
31306261346331623261363533306336663731383664356136366662393632383136353338616130
|
||||
6365626664643733620a323563316331663638333566653363323733373839656330333930363161
|
||||
64666538656164653230633031663636343639393432326531343639356438316335633364633739
|
||||
63303236313861383532386365613938303763373934303230626366636639643433646631343163
|
||||
64316264616237336239346237643065396335313938373734613065383133616532626162393033
|
||||
34613661353537373464643964356138653033623764353662386265316135353738353837616463
|
||||
32653161303034363563373136303633326130643263653532313166383061306662333662623166
|
||||
31363630303466353062356530383864666133376262333030323837313561653262313434663465
|
||||
64376566346536303137646561316438346335343864346139653561663362613861633131393336
|
||||
63346631373336666633386533313261366166663136306531333638363365383833643965613435
|
||||
39376430653239323438613062653435653337663534633933323663613035643466303231346130
|
||||
30643862633464663334386565356432323132336333653633373232333363653734666264333733
|
||||
34333162333439336361313236313161626331396266653238313737656361663736383165393439
|
||||
63326234626533663238353264353736303166383366633038373437366463666263616564303166
|
||||
64393465396364313932316138393839613538343231343734336363663536646632373431623130
|
||||
38653339396134303861636162326531616332353735336330623035633864323238333761363335
|
||||
39373664613736613961666161323566303030656461623331353931363961323366653038656130
|
||||
33356664353635343962343662313063633938343833643938626234383831363536623363366663
|
||||
39343035393362326530316233303137616532356664353035393462306238303738653131346264
|
||||
62636465613062326436333830306264656461356331306262363230336231643566633861633161
|
||||
64393533313535333832343136343131376239363063613530383335326132336433626563333633
|
||||
36386163613163616538643337666131663535333134626535613734393061653033633734613837
|
||||
30373065623564333035616566373038393330613933623235613837383039626537653964366362
|
||||
36643963373134613965333764396162303562633935633736633531336631353638613833643834
|
||||
37366566663635323739643661393433353538636165623435356366333438393162393239363430
|
||||
34626331303439343135353834336134396133636532643333336266626365616166363237376364
|
||||
35323631656263343630643062376131386132356139623561653536313036316261323938636562
|
||||
63343030623033373563626538383862626136343965613162326439316436306133663066656161
|
||||
62393839326134613436626163626565303364373362356631363166316461323734323532623461
|
||||
37303438666161653833363263633963323137303463343434363338303034303238313136343237
|
||||
38346566613865646236343332666230356135343638623031383963666662336131616462383634
|
||||
37383635376661386461306362373631373731313433643038316661613934663232666236613061
|
||||
34353631323132353434623065613238383235316135373338383463626137313530366334333034
|
||||
66613531646233643563336530623733343438666136383931363431306663383361313134646466
|
||||
62623262643232356438653633306466383638336137366363336564643532623239
|
||||
|
|
|
|||
|
|
@ -0,0 +1,7 @@
|
|||
---
|
||||
pangolin_mail_host: "smtp.ionos.it"
|
||||
pangolin_mail_port: 587
|
||||
pangolin_mail_user: "system@hassallab.it"
|
||||
pangolin_mail_password: "{{ pangolin_mail_crypted_password }}"
|
||||
pangolin_no_reply_address: "system@hassallab.it"
|
||||
pangolin_mail_secure_flag: false
|
||||
|
|
@ -6,9 +6,9 @@ pangolin_admin_email: "hassallah@mail.com"
|
|||
|
||||
pangolin_gerbil_subnet_group: "10.42.0.0/16"
|
||||
|
||||
# Email (SMTP) settings
|
||||
pangolin_email_smtp_host: "mail.com"
|
||||
pangolin_email_smtp_port: 587
|
||||
pangolin_email_smtp_user: "pango.lin@mail.com"
|
||||
pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
|
||||
pangolin_email_no_reply: "no-reply@mail.com"
|
||||
# # Email (SMTP) settings
|
||||
# pangolin_email_smtp_host: "mail.com"
|
||||
# pangolin_email_smtp_port: 587
|
||||
# pangolin_email_smtp_user: "pango.lin@mail.com"
|
||||
# pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
|
||||
# pangolin_email_no_reply: "no-reply@mail.com"
|
||||
|
|
@ -3,7 +3,19 @@
|
|||
Qui vengono riportati i playbook disponibili, descrizione e utilizzo.
|
||||
**NB** Ci si aspetta che i playbook siano idempotenti. In caso contrario e' importante riportarlo nella documentazione corrente.
|
||||
|
||||
### Summary
|
||||
- [Bootstrap](#bootstrap)
|
||||
- [VPN Server](#vpn-server)
|
||||
- [Pangolin](#pangolin)
|
||||
- [Forgejo](#forgejo)
|
||||
- [Authentik](#authentik)
|
||||
- [Nextcloud](#nextcloud)
|
||||
- [Static Nginx Page](#static-nginx-page)
|
||||
- [Borg Backups](#borg-backups)
|
||||
|
||||
|
||||
### Bootstrap
|
||||
|
||||
Implementa la configurazione di base di un nodo per poter essere gestito dagli altri playbook, in particolare :
|
||||
- crea l'utente ansible
|
||||
- registra le chiavi ssh degli utenti configurati
|
||||
|
|
@ -67,7 +79,73 @@ Il playbook installa docker e docker compose. Attraverso docker compose vengono
|
|||
|
||||
Il playbook utilizza :
|
||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||
- I ruoli common e pangolin definiti in [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main), riportati staticamente come ruolo *pangolin*
|
||||
- Il ruolo ***prepare_node***
|
||||
- Il ruolo ***pangolin*** preso da [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main)
|
||||
|
||||
I parametri attesi dal playbook sono quelli definiti nei ruoli da cui dipende.
|
||||
|
||||
I parametri attesi dal playbook sono quelli definiti nei ruoli da cui dipende.
|
||||
### Forgejo
|
||||
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [forgejo](https://forgejo.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
||||
|
||||
Il playbook utilizza :
|
||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||
- I ruoli ***forgejo*** e ***newt_client***
|
||||
|
||||
### Authentik
|
||||
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [authentik](https://docs.goauthentik.io/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
||||
|
||||
Il playbook utilizza :
|
||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||
- [ax-bzh.authentik](https://galaxy.ansible.com/ui/standalone/roles/ax-bzh/authentik/documentation/) attraverso ***ansible galaxy***
|
||||
- Il ruolo ***newt_client***
|
||||
|
||||
### Nextcloud
|
||||
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nextcloud AIO](https://github.com/nextcloud/all-in-one) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
||||
|
||||
Il playbook utilizza :
|
||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||
- I ruoli ***newt_client*** e ***nextcloud_aio***
|
||||
|
||||
### Static Nginx Page
|
||||
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nginx](https://nginx.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
||||
|
||||
Il playbook utilizza :
|
||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||
- I ruoli ***newt_client*** e ***nginx***
|
||||
|
||||
### Borg Backups
|
||||
Il playbook configura sia i client che il server per i backup effettuati con [borg](https://www.borgbackup.org/). I client vengono risolti dinamicamente verificando la presenza della seguente configurazione in esempio:
|
||||
|
||||
```
|
||||
configure_borg_client: True
|
||||
borg_repos:
|
||||
- name: test
|
||||
borg_passphrase: "dummy_secret"
|
||||
paths_to_backup:
|
||||
- "/home/{{ ansible_user }}"
|
||||
- "/proc/version"
|
||||
```
|
||||
|
||||
Per ogni client vengono configurati :
|
||||
- l'utente e relative credenziali per connettersi al borg server
|
||||
- Un servizio systemd **borg\_backup.service** e relativo timer **borg\_backup.timer** per eseguire il backup
|
||||
- Uno script che esegue effettivamente il backup **"/home/{{borg_user}}/backup\_script.sh"** verso *"ssh://{{ borg\_user }}@{{ borg\_backup_server }}/./"*
|
||||
|
||||
Sul server vengono configurati:
|
||||
- L'utente con cui eseguire borg service
|
||||
- Le credenziali attese utilizzate dai vari client e i rispettivi path permessi per eseguire i report.
|
||||
|
||||
Sul server i permessi concessi ai vari client vengono limitati definendo su ***/home/{{borg\_user}}/.ssh/authorized\_keys*** le limitazioni di path (accesso solo al proprio repo) e di operation (solo ***"borg serve"***) con la seguente istruzione :
|
||||
```
|
||||
command=\"cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}\",restrict
|
||||
```
|
||||
|
||||
E' possibile configurare il server per servire borg anche con altre credenziali e path, per casi non coperti dal playbook (e.g. borg backups usato direttamente da Nextcloud AIO) attraverso il seguente attributo:
|
||||
|
||||
```
|
||||
borg_auth_users:
|
||||
- host: fabotest
|
||||
key: "ssh-rsa ********"
|
||||
```
|
||||
|
||||
Il playbook utilizza il role ***borg***
|
||||
|
|
|
|||
|
|
@ -11,4 +11,5 @@
|
|||
- geerlingguy.docker
|
||||
- prepare_node
|
||||
|
||||
- include_role: pangolin
|
||||
- include_role:
|
||||
name: pangolin
|
||||
|
|
@ -1,38 +1,52 @@
|
|||
---
|
||||
- name: Ensure Pangolin directory exists
|
||||
ansible.builtin.file:
|
||||
path: /home/ubuntu/pangolin
|
||||
path: "/home/{{ ansible_user }}/compose_projects/pangolin"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
register: compose_dir
|
||||
|
||||
- name: Ensure Pangolin config directory exists
|
||||
ansible.builtin.file:
|
||||
path: /home/ubuntu/pangolin/pangolin_config
|
||||
path: "{{ compose_dir.path }}/pangolin_config"
|
||||
state: directory
|
||||
mode: '0755'
|
||||
register: pangolin_config
|
||||
|
||||
- name: Template Pangolin config file
|
||||
ansible.builtin.template:
|
||||
src: pangolin_config.yml.j2
|
||||
dest: /home/ubuntu/pangolin/pangolin_config/config.yaml
|
||||
dest: "{{ pangolin_config.path }}/config.yaml"
|
||||
|
||||
- name: Ensure Traefik config directory exists
|
||||
ansible.builtin.file:
|
||||
path: /home/ubuntu/pangolin/config/traefik
|
||||
path: "{{ pangolin_config.path }}/traefik"
|
||||
mode: '0755'
|
||||
state: directory
|
||||
register: traefik_config
|
||||
|
||||
- name: Ensure gerbil config directory exists
|
||||
ansible.builtin.file:
|
||||
path: "{{ pangolin_config.path }}/gerbil"
|
||||
mode: '0755'
|
||||
state: directory
|
||||
register: gerbil_config
|
||||
|
||||
|
||||
- name: Template Traefik config file
|
||||
ansible.builtin.template:
|
||||
src: traefik_config.yml.j2
|
||||
dest: /home/ubuntu/pangolin/config/traefik/traefik_config.yml
|
||||
dest: "{{ traefik_config.path }}/traefik_config.yml"
|
||||
|
||||
- name: Template Traefik dynamic config file
|
||||
ansible.builtin.template:
|
||||
src: dynamic_config.yml.j2
|
||||
dest: /home/ubuntu/pangolin/config/traefik/dynamic_config.yml
|
||||
dest: "{{ traefik_config.path }}/dynamic_config.yml"
|
||||
|
||||
- name: Template docker-compose.yml for Pangolin
|
||||
ansible.builtin.template:
|
||||
src: docker-compose.yml.j2
|
||||
dest: /home/ubuntu/pangolin/docker-compose.yml
|
||||
dest: "{{ compose_dir.path }}/docker-compose.yml"
|
||||
register: pangolin_compose_template
|
||||
|
||||
- name: Check if Pangolin container is running
|
||||
|
|
@ -62,23 +76,27 @@
|
|||
when: pangolin_compose_needs_up
|
||||
ignore_errors: true
|
||||
|
||||
- name: Start Pangolin and Gerbil with Docker Compose (force recreate if needed)
|
||||
ansible.builtin.shell: |
|
||||
cd /home/ubuntu/pangolin
|
||||
docker compose up -d --force-recreate
|
||||
when: pangolin_compose_needs_up
|
||||
register: docker_compose_up
|
||||
failed_when: docker_compose_up.rc != 0
|
||||
|
||||
- name: Check Docker Compose service status
|
||||
ansible.builtin.shell: |
|
||||
cd /home/ubuntu/pangolin
|
||||
docker compose ps
|
||||
- name: (Re)Start Pangolin and Gerbil with Docker Compose
|
||||
community.docker.docker_compose_v2:
|
||||
project_src: "{{ compose_dir.path }}"
|
||||
register: docker_compose_status
|
||||
state: restarted
|
||||
# ansible.builtin.shell: |
|
||||
# cd /home/ubuntu/pangolin
|
||||
# docker compose up -d --force-recreate
|
||||
# when: pangolin_compose_needs_up
|
||||
# register: docker_compose_up
|
||||
# failed_when: docker_compose_up.rc != 0
|
||||
|
||||
# - name: Check Docker Compose service status
|
||||
# ansible.builtin.shell: |
|
||||
# cd /home/ubuntu/pangolin
|
||||
# docker compose ps
|
||||
# register: docker_compose_status
|
||||
|
||||
- name: Display Docker Compose service status
|
||||
ansible.builtin.debug:
|
||||
msg: "{{ docker_compose_status.stdout_lines }}"
|
||||
msg: "{{ docker_compose_status }}"
|
||||
|
||||
- name: "Assert that mandatory variables are defined and not default"
|
||||
ansible.builtin.assert:
|
||||
|
|
|
|||
|
|
@ -1,10 +1,3 @@
|
|||
---
|
||||
- ansible.builtin.include_tasks: prepare_node.yaml
|
||||
- include_role:
|
||||
name: geerlingguy.docker
|
||||
apply:
|
||||
become: true
|
||||
- ansible.builtin.include_tasks:
|
||||
file: docker_pangolin.yaml
|
||||
apply:
|
||||
become: true
|
||||
|
|
|
|||
|
|
@ -4,7 +4,7 @@ services:
|
|||
container_name: pangolin
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./pangolin_config:/app/config
|
||||
- {{ pangolin_config.path }}:/app/config
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:3001/api/v1/"]
|
||||
interval: "3s"
|
||||
|
|
@ -24,7 +24,7 @@ services:
|
|||
- --remoteConfig=http://pangolin:3001/api/v1/gerbil/get-config
|
||||
- --reportBandwidthTo=http://pangolin:3001/api/v1/gerbil/receive-bandwidth
|
||||
volumes:
|
||||
- ./gerbil_config/:/var/config
|
||||
- {{ gerbil_config.path }}:/var/config
|
||||
cap_add:
|
||||
- NET_ADMIN
|
||||
- SYS_MODULE
|
||||
|
|
@ -44,9 +44,9 @@ services:
|
|||
command:
|
||||
- --configFile=/etc/traefik/traefik_config.yml
|
||||
volumes:
|
||||
- ./config/traefik:/etc/traefik:ro # Volume to store the Traefik configuration
|
||||
- ./config/letsencrypt:/letsencrypt # Volume to store the Let's Encrypt certificates
|
||||
- ./config/traefik/logs:/var/log/traefik # Volume to store Traefik logs
|
||||
- {{ traefik_config.path }}:/etc/traefik:ro # Volume to store the Traefik configuration
|
||||
- {{ pangolin_config.path }}/letsencrypt:/letsencrypt # Volume to store the Let's Encrypt certificates
|
||||
- {{ traefik_config.path }}/logs:/var/log/traefik # Volume to store Traefik logs
|
||||
networks:
|
||||
default:
|
||||
driver: bridge
|
||||
|
|
|
|||
|
|
@ -20,3 +20,12 @@ server:
|
|||
gerbil:
|
||||
start_port: {{ pangolin_gerbil_start_port }}
|
||||
base_endpoint: "{{ pangolin_dashboard_url | regex_replace('^https://', '') }}" # Gerbil endpoint should be the FQDN, not the full URL
|
||||
|
||||
|
||||
email:
|
||||
smtp_host: "{{ pangolin_mail_host}}"
|
||||
smtp_port: {{ pangolin_mail_port }}
|
||||
smtp_user: "{{ pangolin_mail_user }}"
|
||||
smtp_pass: "{{ pangolin_mail_password }}"
|
||||
smtp_secure: {{ pangolin_mail_secure_flag }}
|
||||
no-reply: "{{ pangolin_no_reply_address }}"
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
---
|
||||
- include_role: updates.yaml
|
||||
- include_role: swap.yaml
|
||||
- include_tasks: updates.yaml
|
||||
- include_tasks: swap.yaml
|
||||
when: configure_swap is defined
|
||||
- include_role: iptables.yaml
|
||||
- include_tasks: iptables.yaml
|
||||
when: ip_tables_coonfig is defined
|
||||
|
|
|
|||
Loading…
Reference in New Issue