diff --git a/inventory/group_vars/all/locales.yml b/inventory/group_vars/all/locales.yml new file mode 100644 index 0000000..fe68a2f --- /dev/null +++ b/inventory/group_vars/all/locales.yml @@ -0,0 +1,4 @@ +locales_list: + - en_US.UTF-8 + - ru_RU.UTF-8 +locale_default: en_US.UTF-8 diff --git a/inventory/group_vars/all/main_vars.yml b/inventory/group_vars/all/main_vars.yml deleted file mode 100644 index 459196c..0000000 --- a/inventory/group_vars/all/main_vars.yml +++ /dev/null @@ -1,4 +0,0 @@ -nft_managed_group: all -dnsmasq_managed_group: all -xray_managed_group: all -xray_core_group: all diff --git a/inventory/group_vars/all/timezone.yml b/inventory/group_vars/all/timezone.yml new file mode 100644 index 0000000..d308eca --- /dev/null +++ b/inventory/group_vars/all/timezone.yml @@ -0,0 +1 @@ +timezone_name: Europe/Samara diff --git a/inventory/group_vars/all/vault.yml b/inventory/group_vars/all/vault.yml index 720d4c1..afc2365 100644 --- a/inventory/group_vars/all/vault.yml +++ b/inventory/group_vars/all/vault.yml @@ -1,103 +1,125 @@ $ANSIBLE_VAULT;1.1;AES256 -36306165333832633935626535303038333964363533393135303736393561653763666534626538 -3931363931616363643366656130616236646538303737380a343234643634316632326137613535 -64316133356635323935623162366533313563316335376439336534323234623038373038373361 -3933353334353939660a656163383564313632393434653435376437643538613138383764336364 -35356235666661303736373335333139653530346335313731343136303039396661633164383433 -35373935633136343764356439333865303032353864373138313736623666626563343362626264 -63613261376163326633626234376339326132303930396562356631306463316361643334643938 -62616665346336373630393833626430386233343539636336383539383232643766386339323433 -31313764356338643533383637303165393064303233373363656435623261653763376138333863 -62643366303866656433376561323739393334663361653166653366303835373863633737316231 -64383336373535343539633365616562386361353532373465386461363863393266313237626634 -61656663373833376330316631653161373130303639313231306134323630356335383561316564 -61343835333533633166316431323234383837393734313630643065313132396234343064343764 -39353865633865333862666364666434386533313534306236346133663031393664353664336362 -34616438356337303536613832386635353565653362366533386436626564613038333938646561 -37643931653633323165303638336535366337643465376335366135373331336633356466366630 -38356535303438626438646239303933373366363836336364613333336234343033343932346561 -64343834353638323235616466346130353431333864386637653636346536323462623430383661 -31336661643135303331323434653964306133376237326263333265376230353737623236656234 -63666661633330613933366462346262363532336437653062363837366533306131383634616534 -34323234343839306265626261323565326164633239616461363930386164373564633062323331 -36383439313730343532373065663665396236336335646465613931323563623734656164653138 -32646665326162666462396265663638333531336231316462393536356163626466306663643266 -35663162313836316361316136323636613532343366653437656666343731643863653031373961 -36383065626431643830623362303931306634316561343961623464656562323830656435646464 -37353532666635653433363930333862626332663233646565383061646164353332646330303239 -30663635343637633431643538346263376366306434333334623566326336396432626264396265 -63386536333139633438353163656132626533313332376633336165373662616561373532363939 -63303132616465363534623664343533313164353866313131653538643837353764663837393661 -65346431376435303364633835323431663064366532343737356339303462323733303134396230 -33303665646133663365356638653637633163313863393564343661326666663335636338613531 -37303333316166353536633762343265383139326431383936643464363761353330353864303239 -37633236306266636165393732656537616161613165653265366562376664313964323939333861 -37326235613835623530353531376262383165616232613535316634646135313138393131343737 -39346233623330643863393762393638316164303066353762623139343730656334613035336430 -65666235346663616131383630663033646330396333303666333639636433323065663232613564 -61313337363138353234363530613964353530383261346661336465373266356135633030363239 -61626664633335336631383661613465613037366237643939623862653264323136623436623836 -61366132313338313934663435626366643838313835653730366131616238313133306232346439 -37396263653462346139353638646663383130383634626234373034366536366662643539656530 -61363436383137306535633765636564313832303835643831666562323165623032633835636639 -61303831393037303464623561326265336662613932316666633133653161346537303965373931 -63323633396438383131316661353435363130346262343862373037646536376363363039613864 -63333065626637326465353033643065313837393830376161383033383265363866323533616539 -63303532343761643636316336313031633330366332666566386234343339663733373866646435 -36386338303863353136373336356432386531366237393866653931363537363361313035633438 -30393864393639326562393039323561316531396437326535663932626663313832393232373939 -35393439336562613031366637363536333938313534663035343839363534356137303064333030 -37353066313031326563666531383062396665643437666333623232333662373739656263633463 -36393933393239373939346438366266623937393634633139393362613335393832303262393038 -31323733663736626139376566363863303439386161623834363533613433373631666334396631 -30316633623336613136643666363738633133393966303938643432626638373037643139343538 -31303633653039663131623839643363636133646230626231353765613665326638376663613265 -61303131663137313465353036636362316139333566316632363265656461323939666161653861 -37336664313039353533336334306461326363323536386366376634383437633862356563366234 -35663662316266373837393663643733613931326464323133313134333964626161303564383931 -61663335343462353237396438353366396535306364363436343739393864633232623463323934 -32353933326337616361396365323835373333333030373762386536313534396434386537623835 -61393633616265633664636432303162333262656135343339313235656565633364383461383031 -63333138383263646563643039306134366138383137366466316331636339653066636331643036 -35303238626566393663663139343362363438383436316635363433303530666435323232386431 -62663365643961356137333933353230366161313463653865356432616232373833346239646361 -38356339313937396632633033326337353434653361303530373963343163653363363134323836 -35323639333261636563346435623334366635316139656434356165646362613031383931393766 -39643530303966653830636363336334326336303438386364316263303639623236613632326637 -33313837333232613735353831393038376433336436646530663265396466333762323332383030 -36646237653731363236663935333862336533383438646536376336333633326333383530613765 -37373937396264643761353762383335373036313230303661353239313362363630326232323735 -31653830663838666634643232346235353266323061636563646630636339613064306339363961 -34343664646434326137643436333362633763363133656332666335636265363662383235316533 -37316632373135646637393565316131396235353662396139323962363939386666323134306530 -31363034373661626131633366313438616465306464393330303263306665646135396436313230 -32376232613763326336326266323637626530636562653534313431343839643034333663323336 -31303530636336366430353066316335386535616265626632376631393237633563383763333938 -34373835326336646230636535643531326639326566376237353835643632323432393132396130 -66323864636438346464363466346263393765633966646263363030656266356330636139316565 -33396365336235356639343432393238343264653163316663303235343038663262326237613363 -30663136633436663431323663653337656235313335323732373738336335646264656534666236 -35663339663762313135313732653766363139373130366330646537663435383438656637353134 -66396233656162316164386564366232666265303230303032323663663538373237326236396337 -34396265653730626566336437373564636461636433393133343933626630393035343634326338 -64656231653361306262316339613938613432353137393962383036633164616531326236366664 -39613939356265366433653966323566396138323935303137313739373038626162623465366437 -66313133623231666361666236316666303533383430663834666139616131366161313563353063 -65316130396135346332343338653231646437623761623231343135666330643532643665656162 -65636334353637376634646139313135383564363435666333363431326332333131633131623861 -34626563376135366365316466653539306465653437376263363163663964656436303631343531 -39353936303566303661376331323862323532356637666535326539626637393666333264663734 -33303536613164623437613834386562616565373438663065643663316665373331633232343330 -34343535666662396238313135326564303665373231386361383135666437636435303831316662 -61656238336236333963363637363030313537356662633130633332636564306131623262383535 -64326536616235623038393363323766633736333131666361623961353434623738376135353332 -35643664356566653035326235363464633233336534646639383662333438333530373930623665 -65306634383539323064313235656531623261626535383832356263396539636433316434323632 -39303335346662613232626231353938336362636266303538363234646163663038313663313765 -66313365303738303262633061346530343966653830663535363164626665366239333030343833 -66326364376238626263336666393665346630383534313261623931343062353432366434653566 -39616530313837633335376435306533353638333734623766343732643064653363633763373134 -30623962333761303833393339313931633633323561303765366565323333666633313563343132 -62346139613131626664363735336330636264666638343330336238636338386263363339383963 -30393236623930376235353532646432616331373637303261346264623133643738623163663035 -3666313562366662363833356165343337336264336264393261 +64303032323732383634613632656438656637373538316134623639346132306337356632316263 +6536663939336664353530313331326436393335303933340a626637346333353363316531613037 +61323139653638343331666235653136306237633464643832326164663463313135623836656236 +6462316234316537350a653235373462636130383235616165363730303463366234333838653361 +37336333643961656637396434303839323065633564346635363734316165316463306364396665 +38666463313164326461303933353765346230623164646232316463396232666435326435633863 +31663563653733336433373836326637323061383435643831363038386638333261333934313465 +33313930616561336436653961306262343730306638386531663564396136633232356133363566 +34313635626333363632373530373334373335653035353734623065393034616235613663383533 +37393362343736643630323134666166666662313333386132366165386535343635376337386665 +34306663666261303035626539393064656234616463303130303037343738626561653732643038 +62663339366465326639663164656239393234643763313935636131303165633765386330653263 +31336562656530356433626664303361636230396262633435356632376637363461643035613831 +39326566626533616538316232656336333166313833363038626338633131383230313961636634 +36386366353639326532393362323330626336303731393661306531623065303465303963376134 +34636261333837396364656237393033373639323063393839363732633963306262303232333935 +37346531653730306361646562396233346161353964326534646465386364636230616231653730 +32326664653566353030663666386162616136386436346565666464663661646463376632633230 +66353039373536643431323533636238666533643431636165633265383733633238633237313830 +35386438613239353539636637353366633062306562633733303666656565313366343461326236 +30393232656264323530623031346536646235323738313462396432376333623137613138303130 +30386461366265336230303530363564336363663262386335313366613634356230333336383936 +33643936613266353636313234393761633363353530396333393937393261326364383032653930 +63666137363564386566393564373263636436353838633538333133376364616434653839633662 +66396239386537663266383462373838346137306232613637313063353664313931313362313035 +36343463363165306635303064346531643933313564376635633231316363663931643635623061 +31366163386536336339656637626533656639396161363136306136373262356436393839386537 +39663439633338356136623235633430663932316561343830336634623137386161623733303465 +61373965636262346436343431373032656131393535386537353066393935303335623639316166 +65613266363362376631376537373764333562633336353836333132633533616161313032383536 +61386538326335326535306430643339303936633532303865363431366537373637313335313639 +32386434366638323433663332373233333865636233333261313038353633343661663164656237 +32336361653039363931316232613737306264386462383332393266373665653364316530383733 +65663335346533653534646133393139666435363036646135353933343834643064353161333033 +62656133343930626433643434336362643035343039633831643264613739333037666338636633 +31623963343565333538353233313537616236393864333566393932626466646534376536623430 +61636262313035393862316430313934633262616534656433316538386664333730343165343931 +65363532616662323262643863323631623938343433623066316231303734613533393039663035 +62646665666634663930383362303137623532373338343764613962343532313161613765383436 +36363432326433303363303736643733623061663663326434643162616235303461353961383462 +35323964353036373334323464336462313435646236333266333233303933356636636637633064 +32626135353862316265376163336637396633326265323761353765663931356461666563613163 +66393264303133613530623164663764643163353163313232623335373231626237636165646631 +32646363323265353336363063653334333062626462663961373463306638373437373836396566 +63346564626134666632393132303464616233323565363734396432373339653336646139323330 +34393761366363363132316231616536643638316138396665633262646438366539346337646266 +65383739343931313038653230343432643863633035636538386239363962663365326265383934 +35346263306361343932383763373737396565306438363362343733653865343162373833326338 +36386433383935613336353833396561633030646232316463333430316535373136353966643336 +65343431313935656630666630383664396134326666643733653463333162613034333061343035 +62313338646639306362343533616563396531363466373231626662313136373234646430613434 +64356430303362376531373336653836653039643165633538666661633134636165643962316437 +30326465633761353034316434623164636561313836323163613439633364636662373163633838 +62333565656237303464346461343534326463616264336265393835343837366335626364653264 +39393338346532383132613331353839373937396538303863326637616333356161386433373230 +38666265336361616233656633613234653232613833376131613865643832386665613236386236 +31363638303366326165396566343566623765633133626666656132366465613432383235306233 +38623733303932623730343638393137663665326134303462666462373639323730656637646663 +32656335323634316432373039653463333737323732646461366565626262373332333861323838 +66343337373437623366373464613532313665343830306465623433616330656165306166643837 +39323335303766353364636365646266333139313530303633353764643964363466633661366335 +31396335313435386135393232363633366239303765666435663733323532346338336562663562 +30313836343366663564623036303334383537343435396634323130663834643364306132363838 +36653564366463323936393035633866633431363134396361623366666231376566646562303739 +61633831353034356431643738633862383466613466626534313962323639663562373031623339 +61396566613134323137333039363330636663353439653964353934656532306563613536623038 +31333065353763303062363836313037313362393132313630366362656133663936303836363366 +37383561636437396364383037643136613066376162363864386336663731333463623563343630 +65326238656237663634656332316230646338393436353239373663386561626162333164356363 +31333364663463656662303134383430356235386436376438646236303966383733353738666365 +36623839623865366637626463626164303735316439336437383231323238636561633261616138 +39313463653030313932663733343135313736326132376161653534383131613066303438333034 +66376264626439636131313135326163333032343635333562663761653539363833616464376465 +62336237656139326161616636393435346663346162646237333935373263616530376135656635 +63383862666533373639663838333930343931383137363565633264623036353462663333373733 +64303933396337633961303064353066363161636233353165393833373861653839303333376336 +65386133663863396634393832626436653766623537663934616463393966346233386433343664 +63333232623764326132636637666437333636303633663430643339623530633664656130636466 +33363536393261626461646161373234383237376564663039343065316232646130636334653763 +37336237613361633931326639663436393033633434326239393232346166393035633034646135 +64636365613138333534333038373932653339383761653735396430336163613565383238383166 +30656632303130376633656536323264373661363765633162353138626530353539643463626532 +32363933633733393736623131633339363962663864393431653232303763333735393138623936 +33616133326261356432396264653339323030386463366434393837336530326338613461646530 +61333430376633666461356230316464326265636634343634636664393230383266363834346234 +66313161366262313362653662383334353763663437336565356331353230383262396236613261 +36336431366234616263326330366239616533613036353735303533653339636161393836353139 +32636162356536366231346631666236653935666265633637363566626235333838353936613764 +36306361336432346463336235626666356137363438626135393065623238316661643637363762 +64653466363165656330383134626230353034653963346532376166653735633634316366303036 +30353561646437636263636132346235656338316466363331396539616537343137303065633638 +63386630393533663638633935376235396133646462343762363931396638363263393236373731 +63643135343235333830383661643539393733306333316630663262313732373235663133663531 +65616264386264313739393161386637323336653336346436636563393561636530303632343030 +35303234323737653965333266623539313863376362633931313838323964633137336435306666 +37326232396362396131353561323932336530643865633831613939383763366137373734303339 +38356663346164643665326334613839646539353261306165316162366630363765306530623730 +35303364656436336135396365616132376433383764356363333035396661623936333865356635 +66663234636533386532623161386632366666393730643231613135356631646636343332646261 +32623237356264623430666330306433313165626633636137666433323566633666383938623362 +61346439323535643766643132326261383734386337363337303435326663326537303533336266 +39363361386235306365366366323562336634643335383861623066653937336362383662356535 +39636233346331376664356334663561383963616536636537656339373332613766626337613436 +36383361646436306562323862376165356436646339643030303132663430373330663064626230 +34393561393464626531626138326161353530393964663933653238393361373766376434653464 +32656338356332626261323363396433343263623831366363346161376434666261323534383466 +30363237653439663036313035383536303566376334386262623963356366333563326236343461 +31636266393864613935633235613462313931633635366333343835656366613832633035393331 +32393633303939386138376363653934653031303362653139636238383732643834376633643830 +64653132393166346464343062613033383837643466316534646334313263386238646432333330 +32646537613762326361663863353339633631333562383231323165663338383931313961386634 +33653232353931383635366265396266663531386239373931383563393130666237316539346563 +61303563306161663065383332306563313136616265383866373139376332636363326563386539 +62323363643432303561373130623863306365363961663838613633303135623036333134623939 +62646363333335386366623264633937396232613339663165613963393463303132323933656330 +38623038303934343835353731656234626138323963393136383261306630343138303963343036 +64353664646465626331346334336636313462303366643665316163346361323363393032343336 +32623066363935346538323364356135323964393738383539373861663934653735396637333934 +64626631663264373065396436323334323638356139356465346463333231646331326130383061 +63313335333062336131623339333665356237663862393734343661613465393430626465326564 +64663838363033323665613732633334356532316665646338333333613465643637656661663634 +65326565663339316634383632386430653461663930633466303232636536303039303731396363 +66363063383832303165396261313030663636333938663134323030396139373539663833326637 +33373961646466663639 diff --git a/inventory/group_vars/all/xray_outbounds.yml b/inventory/group_vars/all/xray_outbounds.yml deleted file mode 100644 index 586322a..0000000 --- a/inventory/group_vars/all/xray_outbounds.yml +++ /dev/null @@ -1,4 +0,0 @@ -xray_id: "{{ encrypted_xray_id }}" -xray_xhttp_path: "{{ encrypted_xray_xhttp_path }}" -xray_encryption: "{{ encrypted_xray_encryption }}" -xray_outbounds: "{{ encrypted_xray_outbounds }}" diff --git a/inventory/group_vars/static.yml b/inventory/group_vars/static.yml new file mode 100644 index 0000000..da7f640 --- /dev/null +++ b/inventory/group_vars/static.yml @@ -0,0 +1,4 @@ +ansible_connection: ssh +ansible_user: root +ansible_host: "{{ container_ip }}" +ansible_ssh_private_key_file: "~/.ssh/id_ed25519" diff --git a/inventory/host_vars/firebat.yml b/inventory/host_vars/firebat/dnsmasq.yml similarity index 100% rename from inventory/host_vars/firebat.yml rename to inventory/host_vars/firebat/dnsmasq.yml diff --git a/inventory/host_vars/firebat/main.yml b/inventory/host_vars/firebat/main.yml new file mode 100644 index 0000000..f1a3ed4 --- /dev/null +++ b/inventory/host_vars/firebat/main.yml @@ -0,0 +1 @@ +ansible_python_interpreter: /usr/bin/python3 diff --git a/inventory/host_vars/firebat/zfs.yml b/inventory/host_vars/firebat/zfs.yml new file mode 100644 index 0000000..febdb4b --- /dev/null +++ b/inventory/host_vars/firebat/zfs.yml @@ -0,0 +1,25 @@ +zfs: + - name: rpool/data/pgsql + extra_zfs_properties: + quota: "21474836480" + - name: rpool/data/vaultwarden + extra_zfs_properties: + quota: "5368709120" + - name: rpool/data/gitea + extra_zfs_properties: + quota: "5368709120" + - name: rpool/data/slskd + extra_zfs_properties: + quota: "5368709120" + - name: rpool/data/rtorrent + extra_zfs_properties: + quota: "1073741824" + - name: rpool/data/jellfin + extra_zfs_properties: + quota: "5368709120" + - name: rpool/data/prosody + extra_zfs_properties: + quota: "10737418240" + - name: rpool/data/steamcmd + extra_zfs_properties: + quota: "21474836480" diff --git a/inventory/host_vars/nginx.yml b/inventory/host_vars/nginx.yml index d64be64..7c8cc80 100644 --- a/inventory/host_vars/nginx.yml +++ b/inventory/host_vars/nginx.yml @@ -35,6 +35,9 @@ nft_to: - to: bylampa proto: tcp port: 80 + - to: ps3 + proto: tcp + port: 80 - to: firebat proto: tcp port: 8006 diff --git a/inventory/host_vars/note13.yml b/inventory/host_vars/note13.yml new file mode 100644 index 0000000..b8472c5 --- /dev/null +++ b/inventory/host_vars/note13.yml @@ -0,0 +1,4 @@ +xray_policy: + - bypass: private + - bypass: russian_whitelist + - proxy: all diff --git a/inventory/host_vars/oyacoi-odcm.yml b/inventory/host_vars/oyacoi-odcm.yml index f0ff14d..7b4aff2 100644 --- a/inventory/host_vars/oyacoi-odcm.yml +++ b/inventory/host_vars/oyacoi-odcm.yml @@ -1,4 +1,7 @@ nft_to: + - to: nginx + proto: tcp + port: [80,443] - to: nfs proto: [tcp,udp] port: [2049,111,32765,32767] @@ -9,7 +12,23 @@ nft_to: proto: tcp port: 22 +nft_dst: + - iface: eth1 + proto: tcp + port: [3783,4321,28900,29900,29901] + - iface: eth1 + proto: udp + port: [6500,6515,13139,27900] + +nft_from: + - iface: eth1 + proto: tcp + port: [3783,4321,28900,29900,29901] + - iface: eth1 + proto: udp + port: [6500,6515,13139,27900] + xray_policy: - bypass: private - bypass: russian_whitelist - - proxy: all + - proxy: all diff --git a/inventory/host_vars/router.yml b/inventory/host_vars/router.yml deleted file mode 100644 index 5dcb9d9..0000000 --- a/inventory/host_vars/router.yml +++ /dev/null @@ -1,6 +0,0 @@ -ansible_host: 10.1.0.1 -ansible_connection: ssh -ansible_user: root -ansible_ssh_private_key_file: ~/.ssh/id_ed25519 -zone_iface: eth0 -container_ip: 10.1.0.1 diff --git a/inventory/host_vars/router/ifupdown2.yml b/inventory/host_vars/router/ifupdown2.yml new file mode 100644 index 0000000..196f5fa --- /dev/null +++ b/inventory/host_vars/router/ifupdown2.yml @@ -0,0 +1,37 @@ +ifupdown2: + - iface: lo + method: loopback + routing: + - "post-up ip rule add fwmark 0x1 lookup 100 2>/dev/null || true" + - "post-up ip route add local 0.0.0.0/0 dev lo table 100 2>/dev/null || true" + - "pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true" + - "pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true" + - iface: eth0 + method: static + address: 10.1.0.1/24 + - iface: eth0.2 + method: static + address: 10.2.0.1/24 + vlan-raw-device: eth0 + - iface: eth0.3 + method: static + address: 10.3.0.1/24 + vlan-raw-device: eth0 + - iface: eth0.4 + method: static + address: 10.4.0.1/24 + vlan-raw-device: eth0 + - iface: eth0.10 + method: static + address: 10.10.0.1/24 + vlan-raw-device: eth0 + - iface: eth0.11 + method: static + address: 10.11.0.1/24 + vlan-raw-device: eth0 + - iface: eth0.12 + method: static + address: 10.12.0.1/24 + vlan-raw-device: eth0 + - iface: eth1 + method: dhcp diff --git a/inventory/host_vars/router/logrotate.yml b/inventory/host_vars/router/logrotate.yml new file mode 100644 index 0000000..d358efe --- /dev/null +++ b/inventory/host_vars/router/logrotate.yml @@ -0,0 +1,13 @@ +logrotate: + - name: xray-core + paths: + - /var/log/xray-core/access.log + - /var/log/xray-core/error.log + options: + - daily + - rotate 4 + - compress + - delaycompress + - missingok + - notifempty + - copytruncate diff --git a/inventory/host_vars/router/main.yml b/inventory/host_vars/router/main.yml new file mode 100644 index 0000000..1255a5c --- /dev/null +++ b/inventory/host_vars/router/main.yml @@ -0,0 +1,2 @@ +zone_iface: "eth0" +container_ip: "10.1.0.1" diff --git a/inventory/host_vars/router/managed_group.yml b/inventory/host_vars/router/managed_group.yml new file mode 100644 index 0000000..32255d3 --- /dev/null +++ b/inventory/host_vars/router/managed_group.yml @@ -0,0 +1,3 @@ +nft_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}" +dnsmasq_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}" +xray_managed_group: "{{ groups['static'] + groups['proxmox_all_lxc'] }}" diff --git a/inventory/host_vars/router/sysctl.yml b/inventory/host_vars/router/sysctl.yml new file mode 100644 index 0000000..699c8fb --- /dev/null +++ b/inventory/host_vars/router/sysctl.yml @@ -0,0 +1,5 @@ +sysctl: + net.ipv4.ip_forward: 1 + net.ipv4.conf.lo.rp_filter: 0 + net.ipv4.conf.all.rp_filter: 0 + net.ipv4.conf.wg0.rp_filter: 0 diff --git a/inventory/group_vars/all/xray_sets.yml b/inventory/host_vars/router/xray-lists.yml similarity index 95% rename from inventory/group_vars/all/xray_sets.yml rename to inventory/host_vars/router/xray-lists.yml index 6090012..9a80f05 100644 --- a/inventory/group_vars/all/xray_sets.yml +++ b/inventory/host_vars/router/xray-lists.yml @@ -4,36 +4,29 @@ xray_ip_sets: - https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst - https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst - https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst - cdn: urls: - https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt - telegram: urls: - https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt - russian_whitelist: urls: - https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt - https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt - cloudflare: static: - 1.1.1.1 - 1.0.0.1 - google: urls: - https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt - xray_domain_sets: v2ray: urls: - https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify - https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft - https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai - torrent: static: - bt.t-ru.org @@ -47,31 +40,23 @@ xray_domain_sets: - nnmclub.to - rutor.info - bigfangroup.org - vps: static: - dev.oyacoi.ru - vector.oyacoi.ru - terraform: static: - terraform.io - hashicorp.com - output_rules: - cloudflare - xray_static_sets: - private - xray_lists_global: cache_dir: /var/lib/xray-lists/cache output_dir: /var/lib/xray-lists/generated dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf proxy: "socks5h://127.0.0.1:1080" - proxy_user: "{{ encrypted_proxy_user }}" - proxy_pass: "{{ encrypted_proxy_pass }}" http_timeout: 20 - xray_tproxy_port: 61219 xray_fwmark: "0x00000001" diff --git a/inventory/host_vars/router/zerotier-one.yml b/inventory/host_vars/router/zerotier-one.yml new file mode 100644 index 0000000..a9982dc --- /dev/null +++ b/inventory/host_vars/router/zerotier-one.yml @@ -0,0 +1,7 @@ +$ANSIBLE_VAULT;1.1;AES256 +30313538656633333565613030356534313035646337323763663565326431323437623636656365 +3139663263383363626438396133623639636565386230640a333166373634343630663566396264 +64613435643864373264323061336438396339326466663637363536663165373231333738313466 +6532343566653238620a336633376336303439656163393165323364663033663432643034396262 +61383431663836613335623761366433366364363938643935636634313631653935306230346234 +3934303233633837356437636639353563376563613237646133 diff --git a/inventory/host_vars/runner.yml b/inventory/host_vars/runner.yml index 7702a04..0845210 100644 --- a/inventory/host_vars/runner.yml +++ b/inventory/host_vars/runner.yml @@ -1,4 +1,7 @@ nft_to: + - to: [zone:eth0.12] + proto: tcp + port: 22 - to: firebat proto: tcp port: [22, 8006] diff --git a/inventory/host_vars/steamcmd.yml b/inventory/host_vars/steamcmd.yml deleted file mode 100644 index ca4773d..0000000 --- a/inventory/host_vars/steamcmd.yml +++ /dev/null @@ -1,9 +0,0 @@ -nft_dst: - - iface: eth0 - proto: udp - port: 2456 - -nft_from: - - iface: [eth0,wg0] - proto: udp - port: [2456,2457] diff --git a/inventory/host_vars/steamcmd/main.yml b/inventory/host_vars/steamcmd/main.yml new file mode 100644 index 0000000..bd1642a --- /dev/null +++ b/inventory/host_vars/steamcmd/main.yml @@ -0,0 +1,15 @@ +nft_dst: + - iface: eth1 + proto: udp + port: [2456,2457] + +nft_from: + - iface: [eth0,wg0] + proto: tcp + port: [5000,5222,5223,5269,5270,5280] + - iface: [eth0,wg0] + proto: udp + port: [2302,2304,2456,2457,27016] + - iface: eth1 + proto: udp + port: [2456,2457] diff --git a/inventory/host_vars/steamcmd/user.yml b/inventory/host_vars/steamcmd/user.yml new file mode 100644 index 0000000..5ed4d4d --- /dev/null +++ b/inventory/host_vars/steamcmd/user.yml @@ -0,0 +1,6 @@ +user: + - name: steamcmd + create_home: true + home: /var/lib/steamcmd + shell: /bin/bash + system: true diff --git a/inventory/host_vars/tanix.yml b/inventory/host_vars/tanix.yml new file mode 100644 index 0000000..54f6347 --- /dev/null +++ b/inventory/host_vars/tanix.yml @@ -0,0 +1,4 @@ +xray_policy: + - bypass: private + - bypass: russian_whitelist + - proxy: all diff --git a/inventory/proxmox.yml b/inventory/proxmox.yml index a581001..424b614 100644 --- a/inventory/proxmox.yml +++ b/inventory/proxmox.yml @@ -1,13 +1,20 @@ -plugin: community.proxmox.proxmox -url: https://10.1.0.4:8006 -user: root@pam -password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}" -validate_certs: false -want_facts: true - -filter_by_types: - - lxc - -compose: - zone_iface: "'eth0.' ~ proxmox_net0.tag" - container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')" +$ANSIBLE_VAULT;1.1;AES256 +37386530393166613762313561626462336132393166653364343962396164323734313165383763 +6234663630386531323464643538353865613334656264620a316630336537396363303333343637 +38636437633264373866616366666337366362306438306430633566316234323935363237343762 +3533393634633733330a626139316231383738626465373566303565633135646164323535326635 +38313138383063646237303634376237623661633830363531323563613131613530663730653533 +36643330623366636363613437313030303463613163323333663865633538343266353134386631 +36663530376238656262346662383532613631636234323431303935323138306163323839636338 +61373735366332356138313762663633393165663732653565663066613636366538376263366337 +31386337623562313731386563313736346139353961663231353862636138303938323235633038 +38636562646533633261346264373466373536376530623639366262613365366437373334396665 +30653037366339383538313965663865636462633139616332386165663564616263666533363034 +38643065303832666335623035326566653437393638373261343138636530373839646231643665 +33323338333231643435663336653232373732636335656238376563666632313131656432336233 +63636437643838316166666137386361386233346633316166333662323838313565653233346537 +61383966343434323539326364646230336339353337326539333031376464353732326331333864 +34303431363632386562616131306436373464393165396437613535323230353862346662346265 +33303137383033313534393438343934653037643936633361343638616461643935386430616133 +62633262306538663961646263613239313261633764663532616138313663343863643965613730 +396266656366353238353038333832336234 diff --git a/inventory/static.yml b/inventory/static.yml index 8a461ec..e0fed4e 100644 --- a/inventory/static.yml +++ b/inventory/static.yml @@ -13,9 +13,6 @@ all: firebat: container_ip: "10.1.0.4" zone_iface: "eth0" - ansible_host: 10.1.0.4 - ansible_user: root - ansible_ssh_private_key_file: "~/.ssh/id_ed25519" ps2: container_ip: "10.1.0.5" diff --git a/playbooks/firebat.yml b/playbooks/firebat.yml new file mode 100644 index 0000000..75b6d11 --- /dev/null +++ b/playbooks/firebat.yml @@ -0,0 +1,11 @@ +--- +- name: configure over ssh + hosts: firebat + vars: + ansible_connection: ssh + ansible_host: "{{ container_ip }}" + ansible_user: root + ansible_ssh_private_key_file: ~/.ssh/id_ed25519 + ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' + roles: + - zfs diff --git a/playbooks/router.yml b/playbooks/router.yml index 1efe0e3..c6c1522 100644 --- a/playbooks/router.yml +++ b/playbooks/router.yml @@ -1,9 +1,29 @@ --- -- hosts: router - become: yes +- name: configure over pct + hosts: router + gather_facts: false roles: - - router + - authorized_key + - ifupdown2 + +- name: configure over ssh + hosts: router + vars: + ansible_connection: ssh + ansible_host: "{{ container_ip }}" + ansible_user: root + ansible_ssh_private_key_file: ~/.ssh/id_ed25519 + ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' + roles: + - timezone + - locales + - sysctl + - xray-core + - xray-client + - logrotate + - dnsmasq - xray-lists - unbound - - dnsmasq + - wireguard-tools + - zerotier-one - nftables diff --git a/playbooks/steamcmd.yml b/playbooks/steamcmd.yml new file mode 100644 index 0000000..a97b920 --- /dev/null +++ b/playbooks/steamcmd.yml @@ -0,0 +1,20 @@ +--- +- name: configure over pct + hosts: steamcmd + gather_facts: false + roles: + - authorized_key + +- name: configure over ssh + hosts: steamcmd + vars: + ansible_connection: ssh + ansible_host: "{{ container_ip }}" + ansible_user: root + ansible_ssh_private_key_file: ~/.ssh/id_ed25519 + ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no' + roles: + - timezone + - locales + - user + - steamcmd diff --git a/roles/apt/tasks/apt.yml b/roles/apt/tasks/apt.yml new file mode 100644 index 0000000..fceac5c --- /dev/null +++ b/roles/apt/tasks/apt.yml @@ -0,0 +1,5 @@ +- name: install package + ansible.builtin.apt: + name: "{{ item }}" + update_cache: true + loop: "{{ apt }}" diff --git a/roles/apt/tasks/main.yml b/roles/apt/tasks/main.yml new file mode 100644 index 0000000..88e74a9 --- /dev/null +++ b/roles/apt/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include apt install + ansible.builtin.include_tasks: apt.yml diff --git a/roles/authorized_key/tasks/main.yml b/roles/authorized_key/tasks/main.yml new file mode 100644 index 0000000..155a347 --- /dev/null +++ b/roles/authorized_key/tasks/main.yml @@ -0,0 +1,15 @@ +--- +- name: ensure .ssh exists + ansible.builtin.file: + path: /root/.ssh + state: directory + mode: '0700' + owner: root + group: root + +- name: set authorized key + ansible.posix.authorized_key: + user: root + state: present + key: "{{ item }}" + loop: "{{ ssh_keys }}" diff --git a/roles/dnsmasq/tasks/configure.yml b/roles/dnsmasq/tasks/configure.yml new file mode 100644 index 0000000..08d7a40 --- /dev/null +++ b/roles/dnsmasq/tasks/configure.yml @@ -0,0 +1,39 @@ +--- +- name: ensure /etc/dnsmasq.d exists + ansible.builtin.file: + path: /etc/dnsmasq.d + state: directory + mode: "0755" + +- name: deploy dnsmasq rule + ansible.builtin.copy: + src: "{{ item }}" + dest: "/etc/dnsmasq.d/{{ item }}" + mode: "0644" + loop: + - 10-upstream.conf + - 20-custom-domains.conf + - 20-dhcp.conf + - 20-dns-optimizations.conf + notify: restart dnsmasq + +- name: render local + ansible.builtin.template: + src: 90-local.conf.j2 + dest: /etc/dnsmasq.d/90-local.conf + mode: "0644" + notify: restart dnsmasq + +- name: render dhcp-host + ansible.builtin.template: + src: 90-dhcp-host.conf.j2 + dest: /etc/dnsmasq.d/90-dhcp-host.conf + mode: "0644" + notify: restart dnsmasq + +- name: render domain + ansible.builtin.template: + src: 90-domains.conf.j2 + dest: /etc/dnsmasq.d/90-domains.conf + mode: "0644" + notify: restart dnsmasq diff --git a/roles/dnsmasq/tasks/install.yml b/roles/dnsmasq/tasks/install.yml new file mode 100644 index 0000000..385d635 --- /dev/null +++ b/roles/dnsmasq/tasks/install.yml @@ -0,0 +1,6 @@ +--- +- name: install dnsmasq + ansible.builtin.apt: + name: dnsmasq + state: latest + update_cache: true diff --git a/roles/dnsmasq/tasks/main.yml b/roles/dnsmasq/tasks/main.yml index 08d7a40..2b27600 100644 --- a/roles/dnsmasq/tasks/main.yml +++ b/roles/dnsmasq/tasks/main.yml @@ -1,39 +1,6 @@ --- -- name: ensure /etc/dnsmasq.d exists - ansible.builtin.file: - path: /etc/dnsmasq.d - state: directory - mode: "0755" +- name: include dnsmasq install + ansible.builtin.include_tasks: install.yml -- name: deploy dnsmasq rule - ansible.builtin.copy: - src: "{{ item }}" - dest: "/etc/dnsmasq.d/{{ item }}" - mode: "0644" - loop: - - 10-upstream.conf - - 20-custom-domains.conf - - 20-dhcp.conf - - 20-dns-optimizations.conf - notify: restart dnsmasq - -- name: render local - ansible.builtin.template: - src: 90-local.conf.j2 - dest: /etc/dnsmasq.d/90-local.conf - mode: "0644" - notify: restart dnsmasq - -- name: render dhcp-host - ansible.builtin.template: - src: 90-dhcp-host.conf.j2 - dest: /etc/dnsmasq.d/90-dhcp-host.conf - mode: "0644" - notify: restart dnsmasq - -- name: render domain - ansible.builtin.template: - src: 90-domains.conf.j2 - dest: /etc/dnsmasq.d/90-domains.conf - mode: "0644" - notify: restart dnsmasq +- name: include dnsmasq configurure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/dnsmasq/templates/90-dhcp-host.conf.j2 b/roles/dnsmasq/templates/90-dhcp-host.conf.j2 index d7c4d71..3a1b8d5 100644 --- a/roles/dnsmasq/templates/90-dhcp-host.conf.j2 +++ b/roles/dnsmasq/templates/90-dhcp-host.conf.j2 @@ -1,5 +1,5 @@ #jinja2: trim_blocks: True, lstrip_blocks: True -{% for item in groups[dnsmasq_managed_group] | sort %} +{% for item in dnsmasq_managed_group | sort %} {% set client = hostvars[item] %} {% set ip = client.container_ip | default(client.ansible_host | default(none)) %} {% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %} diff --git a/roles/dnsmasq/templates/90-domains.conf.j2 b/roles/dnsmasq/templates/90-domains.conf.j2 index 30e760b..1c63235 100644 --- a/roles/dnsmasq/templates/90-domains.conf.j2 +++ b/roles/dnsmasq/templates/90-domains.conf.j2 @@ -1,5 +1,5 @@ #jinja2: trim_blocks: True, lstrip_blocks: True -{% for item in groups[dnsmasq_managed_group] | sort %} +{% for item in dnsmasq_managed_group | sort %} {% set client = hostvars[item] %} {% if 'dnsmasq' in client and client.dnsmasq %} {% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %} diff --git a/roles/dnsmasq/templates/90-local.conf.j2 b/roles/dnsmasq/templates/90-local.conf.j2 index bdc277c..e6dbdbb 100644 --- a/roles/dnsmasq/templates/90-local.conf.j2 +++ b/roles/dnsmasq/templates/90-local.conf.j2 @@ -1,5 +1,5 @@ #jinja2: trim_blocks: True, lstrip_blocks: True -{% for item in groups[dnsmasq_managed_group] | sort %} +{% for item in dnsmasq_managed_group | sort %} {% set client = hostvars[item] %} {% set ip = client.container_ip | default(client.ansible_host | default(none)) %} {% if ip %} diff --git a/roles/router/tasks/main.yml b/roles/ifupdown2/tasks/main.yml similarity index 100% rename from roles/router/tasks/main.yml rename to roles/ifupdown2/tasks/main.yml diff --git a/roles/ifupdown2/tasks/network.yml b/roles/ifupdown2/tasks/network.yml new file mode 100644 index 0000000..9f48892 --- /dev/null +++ b/roles/ifupdown2/tasks/network.yml @@ -0,0 +1,13 @@ +--- +- name: deploy ifupdown interfaces config + ansible.builtin.template: + src: interfaces + dest: /etc/network/interfaces + owner: root + group: root + mode: '0644' + register: interfaces_conf + +- name: reload ifupdown2 + command: ifreload -a + when: interfaces_conf.changed diff --git a/roles/ifupdown2/templates/interfaces b/roles/ifupdown2/templates/interfaces new file mode 100644 index 0000000..15f9acb --- /dev/null +++ b/roles/ifupdown2/templates/interfaces @@ -0,0 +1,20 @@ +{% for item in ifupdown2 %} +auto {{ item.iface }} +iface {{ item.iface }}{% if item.method is defined %} inet {{ item.method }} +{% endif %} + +{% if item.address is defined %} + address {{ item.address }} +{% endif %} +{% if item['vlan-raw-device'] is defined %} + vlan-raw-device {{ item['vlan-raw-device'] }} +{% endif %} +{% if item.routing is defined %} +{% for route in item.routing %} + {{ route }} +{% endfor %} +{% endif %} +{% if not loop.last %} + +{% endif %} +{% endfor %} diff --git a/roles/locales/tasks/configure.yml b/roles/locales/tasks/configure.yml new file mode 100644 index 0000000..24b59b8 --- /dev/null +++ b/roles/locales/tasks/configure.yml @@ -0,0 +1,22 @@ +--- +- name: set required locales + community.general.locale_gen: + name: "{{ item }}" + state: present + loop: "{{ locales_list }}" + +- name: configure /etc/default/locale + ansible.builtin.copy: + dest: /etc/default/locale + content: LANG={{ locale_default }} + owner: root + group: root + mode: '0644' + +- name: configure /etc/locale.conf + ansible.builtin.copy: + dest: /etc/locale.conf + content: LANG={{ locale_default }} + owner: root + group: root + mode: '0644' diff --git a/roles/locales/tasks/main.yml b/roles/locales/tasks/main.yml new file mode 100644 index 0000000..1d2ac0b --- /dev/null +++ b/roles/locales/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include locales configure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/logrotate/tasks/configure.yml b/roles/logrotate/tasks/configure.yml new file mode 100644 index 0000000..3f06759 --- /dev/null +++ b/roles/logrotate/tasks/configure.yml @@ -0,0 +1,9 @@ +--- +- name: deploy logrotate config + ansible.builtin.template: + src: logrotate.conf.j2 + dest: "/etc/logrotate.d/{{ item.name }}" + mode: "0644" + loop: "{{ logrotate }}" + loop_control: + label: "{{ item.name }}" diff --git a/roles/logrotate/tasks/main.yml b/roles/logrotate/tasks/main.yml new file mode 100644 index 0000000..1df2df5 --- /dev/null +++ b/roles/logrotate/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include logrotate configure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/logrotate/templates/logrotate.conf.j2 b/roles/logrotate/templates/logrotate.conf.j2 new file mode 100644 index 0000000..7fb2840 --- /dev/null +++ b/roles/logrotate/templates/logrotate.conf.j2 @@ -0,0 +1,5 @@ +{{ item.paths | join(' ') }} { +{% for opt in item.options %} + {{ opt }} +{% endfor %} +} diff --git a/roles/nftables/files/10-filter.nft b/roles/nftables/files/10-filter.nft index 42cc23f..cc9cc20 100644 --- a/roles/nftables/files/10-filter.nft +++ b/roles/nftables/files/10-filter.nft @@ -35,6 +35,9 @@ chain forward { iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept + iifname "zt*" oifname "eth0" accept + iifname "eth0" oifname "zt*" accept + tcp flags syn tcp option maxseg size set rt mtu include "/etc/nftables.d/90-forward.nft" diff --git a/roles/nftables/tasks/install.yml b/roles/nftables/tasks/install.yml index 49d4014..3526db0 100644 --- a/roles/nftables/tasks/install.yml +++ b/roles/nftables/tasks/install.yml @@ -1,5 +1,6 @@ --- - name: install nftables - ansible.builtin.package: + ansible.builtin.apt: name: nftables - state: present + state: latest + update_cache: true diff --git a/roles/nftables/tasks/main.yml b/roles/nftables/tasks/main.yml index afead39..d716569 100644 --- a/roles/nftables/tasks/main.yml +++ b/roles/nftables/tasks/main.yml @@ -2,5 +2,5 @@ - name: include nftables install ansible.builtin.include_tasks: install.yml -- name: include nftables configurure +- name: include nftables configure ansible.builtin.include_tasks: configure.yml diff --git a/roles/nftables/templates/90-dstnat.nft.j2 b/roles/nftables/templates/90-dstnat.nft.j2 index 04a50df..1fe9eca 100644 --- a/roles/nftables/templates/90-dstnat.nft.j2 +++ b/roles/nftables/templates/90-dstnat.nft.j2 @@ -1,5 +1,5 @@ #jinja2: trim_blocks: True, lstrip_blocks: True -{% for item in groups[nft_managed_group] | sort %} +{% for item in nft_managed_group | sort %} {% set client = hostvars[item] %} {% if 'nft_dst' in client and client.nft_dst is not none %} {% set target_ip = client.container_ip %} diff --git a/roles/nftables/templates/90-forward.nft.j2 b/roles/nftables/templates/90-forward.nft.j2 index d4b4fef..564d5d4 100644 --- a/roles/nftables/templates/90-forward.nft.j2 +++ b/roles/nftables/templates/90-forward.nft.j2 @@ -1,5 +1,5 @@ #jinja2: trim_blocks: True, lstrip_blocks: True -{% for item in groups[nft_managed_group] | sort %} +{% for item in nft_managed_group | sort %} {% set client = hostvars[item] %} {% if 'nft_to' in client and client.nft_to is not none %} {% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %} @@ -27,7 +27,7 @@ iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{ {% endfor %} {% endif %} {% endfor %} -{% for item in groups[nft_managed_group] | sort %} +{% for item in nft_managed_group | sort %} {% set client = hostvars[item] %} {% if 'nft_from' in client and client.nft_from is not none %} {% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %} diff --git a/roles/router/files/ifupdown2/interfaces b/roles/router/files/ifupdown2/interfaces deleted file mode 100644 index acb310e..0000000 --- a/roles/router/files/ifupdown2/interfaces +++ /dev/null @@ -1,52 +0,0 @@ -auto lo -iface lo inet loopback - post-up ip rule add fwmark 0x1 lookup 100 2>/dev/null || true - post-up ip route add local 0.0.0.0/0 dev lo table 100 2>/dev/null || true - pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true - pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true - -auto eth0 -iface eth0 inet manual - address 10.1.0.1/24 - -auto eth0.2 -iface eth0.2 inet static - address 10.2.0.1/24 - vlan-raw-device eth0 - -auto eth0.3 -iface eth0.3 inet static - address 10.3.0.1/24 - vlan-raw-device eth0 - -auto eth0.4 -iface eth0.4 inet static - address 10.4.0.1/24 - vlan-raw-device eth0 - -auto eth0.10 -iface eth0.10 inet static - address 10.10.0.1/24 - vlan-raw-device eth0 - -auto eth0.11 -iface eth0.11 inet static - address 10.11.0.1/24 - vlan-raw-device eth0 - -auto eth0.12 -iface eth0.12 inet static - address 10.12.0.1/24 - vlan-raw-device eth0 - -auto eth1 -iface eth1 inet dhcp - -auto wg0 -iface wg0 inet manual - post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true - post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true - post-up ip route add default dev wg0 table 199 2>/dev/null || true - pre-down ip route del default dev wg0 table 199 2>/dev/null || true - pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true - pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true diff --git a/roles/router/files/sysctl/01-forwarding.conf b/roles/router/files/sysctl/01-forwarding.conf deleted file mode 100644 index 119d730..0000000 --- a/roles/router/files/sysctl/01-forwarding.conf +++ /dev/null @@ -1 +0,0 @@ -net.ipv4.ip_forward=1 diff --git a/roles/router/files/sysctl/02-rpfilter.conf b/roles/router/files/sysctl/02-rpfilter.conf deleted file mode 100644 index 24d5762..0000000 --- a/roles/router/files/sysctl/02-rpfilter.conf +++ /dev/null @@ -1,3 +0,0 @@ -net.ipv4.conf.lo.rp_filter=0 -net.ipv4.conf.all.rp_filter=0 -net.ipv4.conf.wg0.rp_filter=0 diff --git a/roles/router/handlers/main.yml b/roles/router/handlers/main.yml deleted file mode 100644 index 15c6aa3..0000000 --- a/roles/router/handlers/main.yml +++ /dev/null @@ -1,3 +0,0 @@ ---- -- name: reload ifupdown2 - command: ifreload -a diff --git a/roles/router/tasks/network.yml b/roles/router/tasks/network.yml deleted file mode 100644 index 76f484f..0000000 --- a/roles/router/tasks/network.yml +++ /dev/null @@ -1,9 +0,0 @@ ---- -- name: deploy ifupdown config - copy: - src: ifupdown2/interfaces - dest: /etc/network/interfaces - owner: root - group: root - mode: '0644' - notify: reload ifupdown2 diff --git a/roles/steamcmd/files/dayz.service b/roles/steamcmd/files/dayz.service new file mode 100644 index 0000000..5c01f88 --- /dev/null +++ b/roles/steamcmd/files/dayz.service @@ -0,0 +1,15 @@ +[Unit] +Description=dayz server +Wants=network.target +After=syslog.target network-online.target + +[Service] +Type=simple +Restart=on-failure +RestartSec=10 +User=steamcmd +WorkingDirectory=/mnt/steamcmd/dayz +ExecStart=/mnt/steamcmd/dayz/DayZServer -config=serverDZ-custom.cfg -port=2302 + +[Install] +WantedBy=multi-user.target diff --git a/roles/steamcmd/files/serverDZ.cfg b/roles/steamcmd/files/serverDZ.cfg new file mode 100644 index 0000000..a767d4f --- /dev/null +++ b/roles/steamcmd/files/serverDZ.cfg @@ -0,0 +1,32 @@ +hostname = "oyacoi"; +password = "ff32167"; +passwordAdmin = ""; +description = ""; +enableWhitelist = 0; +maxPlayers = 1; +verifySignatures = 2; +forceSameBuild = 1; +disableVoN = 1; +vonCodecQuality = 0; +shardId = "123abc"; +disable3rdPerson=1; +disableCrosshair=1; +disablePersonalLight = 1; +lightingConfig = 0; +serverTime="SystemTime"; +serverTimeAcceleration=6; +serverNightTimeAcceleration=12; +serverTimePersistent=0; +guaranteedUpdates=1; +loginQueueConcurrentPlayers=5; +loginQueueMaxPlayers=0; +instanceId = 1; +storageAutoFix = 1; + +class Missions +{ + class DayZ + { + template="dayzOffline.sakhal"; + }; +}; diff --git a/roles/steamcmd/files/start_server.sh b/roles/steamcmd/files/start_server.sh new file mode 100644 index 0000000..95fa3b5 --- /dev/null +++ b/roles/steamcmd/files/start_server.sh @@ -0,0 +1,13 @@ +#!/bin/bash +export templdpath=$LD_LIBRARY_PATH +export LD_LIBRARY_PATH=./linux64:$LD_LIBRARY_PATH +export SteamAppId=892970 + +echo "Starting server PRESS CTRL-C to exit" + +# Tip: Make a local copy of this script to avoid it being overwritten by steam. +# NOTE: Minimum password length is 5 characters & Password cant be in the server name. +# NOTE: You need to make sure the ports 2456-2458 is being forwarded to your server through your local router & firewall. +./valheim_server.x86_64 -name "oyacoi" -port 2456 -world "world0" -password "ff32167" -public 0 + +export LD_LIBRARY_PATH=$templdpath diff --git a/roles/steamcmd/files/valheim.service b/roles/steamcmd/files/valheim.service new file mode 100644 index 0000000..37907c5 --- /dev/null +++ b/roles/steamcmd/files/valheim.service @@ -0,0 +1,15 @@ +[Unit] +Description=valheim server +Wants=network.target +After=syslog.target network-online.target + +[Service] +Type=simple +Restart=on-failure +RestartSec=10 +User=steamcmd +WorkingDirectory=/mnt/steamcmd/valheim +ExecStart=/bin/bash /mnt/steamcmd/valheim/start_server-custom.sh + +[Install] +WantedBy=multi-user.target diff --git a/roles/steamcmd/handlers/main.yml b/roles/steamcmd/handlers/main.yml new file mode 100644 index 0000000..d244d3d --- /dev/null +++ b/roles/steamcmd/handlers/main.yml @@ -0,0 +1,14 @@ +--- +- name: restart valheim + ansible.builtin.systemd: + daemon_reload: true + name: valheim.service + state: restarted + enabled: true + +- name: restart dayz + ansible.builtin.systemd: + daemon_reload: true + name: dayz.service + state: restarted + enabled: true diff --git a/roles/steamcmd/tasks/apt.yml b/roles/steamcmd/tasks/apt.yml new file mode 100644 index 0000000..3467715 --- /dev/null +++ b/roles/steamcmd/tasks/apt.yml @@ -0,0 +1,4 @@ +- name: install package + ansible.builtin.apt: + name: steamcmd + update_cache: true diff --git a/roles/steamcmd/tasks/command.yml b/roles/steamcmd/tasks/command.yml new file mode 100644 index 0000000..762a87a --- /dev/null +++ b/roles/steamcmd/tasks/command.yml @@ -0,0 +1,23 @@ +- name: check steam session + ansible.builtin.stat: + path: /var/lib/steamcmd/.local/share/Steam/config/config.vdf + register: steam_session + +- name: abort if steam authorization is missing + ansible.builtin.fail: + msg: "Manual Steam authorization required. Please log in interactively." + when: not steam_session.stat.exists + +- name: install valheim server + ansible.builtin.command: + cmd: su - steamcmd -c "/usr/games/steamcmd +force_install_dir /mnt/steamcmd/valheim +login anonymous +app_update 896660 validate +exit" + register: valheim_result + changed_when: "'downloading' in valheim_result.stdout" + notify: restart valheim + +- name: install dayz server + ansible.builtin.command: + cmd: su - steamcmd -c "/usr/games/steamcmd +force_install_dir /mnt/steamcmd/dayz +login gshinzu +app_update 223350 validate +exit" + register: dayz_result + changed_when: "'downloading' in dayz_result.stdout" + notify: restart dayz diff --git a/roles/steamcmd/tasks/copy.yml b/roles/steamcmd/tasks/copy.yml new file mode 100644 index 0000000..6cde6f8 --- /dev/null +++ b/roles/steamcmd/tasks/copy.yml @@ -0,0 +1,34 @@ +--- +- name: deploy start_server.sh + ansible.builtin.copy: + src: start_server.sh + dest: /mnt/steamcmd/valheim/start_server-custom.sh + owner: steamcmd + group: steamcmd + mode: '0775' + +- name: deploy valheim.service + ansible.builtin.copy: + src: valheim.service + dest: /etc/systemd/system/valheim.service + owner: root + group: root + mode: '0644' + notify: restart valheim + +- name: deploy serverDZ.cfg + ansible.builtin.copy: + src: serverDZ.cfg + dest: /mnt/steamcmd/dayz/serverDZ-custom.cfg + owner: steamcmd + group: steamcmd + mode: '0755' + +- name: deploy dayz.service + ansible.builtin.copy: + src: dayz.service + dest: /etc/systemd/system/dayz.service + owner: root + group: root + mode: '0644' + notify: restart dayz diff --git a/roles/steamcmd/tasks/deb822.yml b/roles/steamcmd/tasks/deb822.yml new file mode 100644 index 0000000..372a2fd --- /dev/null +++ b/roles/steamcmd/tasks/deb822.yml @@ -0,0 +1,14 @@ +--- +- name: configure debian-unstable.sources + ansible.builtin.deb822_repository: + name: debian-unstable + types: deb + uris: http://deb.debian.org/debian + suites: + - unstable + components: + - contrib + - main + - non-free + signed_by: /usr/share/keyrings/debian-archive-keyring.gpg + state: present diff --git a/roles/steamcmd/tasks/debconf.yml b/roles/steamcmd/tasks/debconf.yml new file mode 100644 index 0000000..d3f0719 --- /dev/null +++ b/roles/steamcmd/tasks/debconf.yml @@ -0,0 +1,6 @@ +- name: accept agreement + ansible.builtin.debconf: + name: steamcmd + question: steam/question + vtype: string + value: "I AGREE" diff --git a/roles/steamcmd/tasks/file.yml b/roles/steamcmd/tasks/file.yml new file mode 100644 index 0000000..5c23c24 --- /dev/null +++ b/roles/steamcmd/tasks/file.yml @@ -0,0 +1,14 @@ +--- +- name: create valheim dir + ansible.builtin.file: + path: /mnt/steamcmd/valheim + owner: steamcmd + group: steamcmd + state: "directory" + +- name: create dayz dir + ansible.builtin.file: + path: /mnt/steamcmd/dayz + owner: steamcmd + group: steamcmd + state: "directory" diff --git a/roles/steamcmd/tasks/i386.yml b/roles/steamcmd/tasks/i386.yml new file mode 100644 index 0000000..3a1bdfd --- /dev/null +++ b/roles/steamcmd/tasks/i386.yml @@ -0,0 +1,10 @@ +--- +- name: check if i386 architecture + ansible.builtin.command: dpkg --print-foreign-architectures + register: check_i386 + changed_when: false + failed_when: false + +- name: add i386 architecture + ansible.builtin.command: dpkg --add-architecture i386 + when: "'i386' not in check_i386.stdout" diff --git a/roles/steamcmd/tasks/main.yml b/roles/steamcmd/tasks/main.yml new file mode 100644 index 0000000..7689268 --- /dev/null +++ b/roles/steamcmd/tasks/main.yml @@ -0,0 +1,21 @@ +--- +- name: include deb822 + ansible.builtin.include_tasks: deb822.yml + +- name: include i386 + ansible.builtin.include_tasks: i386.yml + +- name: include file + ansible.builtin.include_tasks: file.yml + +- name: include debconf + ansible.builtin.include_tasks: debconf.yml + +- name: include apt + ansible.builtin.include_tasks: apt.yml + +- name: include command + ansible.builtin.include_tasks: command.yml + +- name: include copy + ansible.builtin.include_tasks: copy.yml diff --git a/roles/sysctl/handlers/main.yml b/roles/sysctl/handlers/main.yml new file mode 100644 index 0000000..7983594 --- /dev/null +++ b/roles/sysctl/handlers/main.yml @@ -0,0 +1,3 @@ +--- +- name: reload sysctl + ansible.builtin.command: sysctl -p /etc/sysctl.d/99-custom.conf diff --git a/roles/sysctl/tasks/configure.yml b/roles/sysctl/tasks/configure.yml new file mode 100644 index 0000000..b0e871b --- /dev/null +++ b/roles/sysctl/tasks/configure.yml @@ -0,0 +1,8 @@ +- name: deploy sysctl config + ansible.builtin.template: + src: sysctl.conf.j2 + dest: "/etc/sysctl.d/99-custom.conf" + owner: root + group: root + mode: '0644' + notify: reload sysctl diff --git a/roles/sysctl/tasks/main.yml b/roles/sysctl/tasks/main.yml new file mode 100644 index 0000000..6988d9f --- /dev/null +++ b/roles/sysctl/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include sysctl configure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/sysctl/templates/sysctl.conf.j2 b/roles/sysctl/templates/sysctl.conf.j2 new file mode 100644 index 0000000..3df6ce7 --- /dev/null +++ b/roles/sysctl/templates/sysctl.conf.j2 @@ -0,0 +1,3 @@ +{% for key, value in sysctl.items() %} +{{ key }} = {{ value }} +{% endfor %} diff --git a/roles/timezone/tasks/configure.yml b/roles/timezone/tasks/configure.yml new file mode 100644 index 0000000..a3b3610 --- /dev/null +++ b/roles/timezone/tasks/configure.yml @@ -0,0 +1,4 @@ +--- +- name: set system timezone + community.general.timezone: + name: "{{ timezone_name }}" diff --git a/roles/timezone/tasks/main.yml b/roles/timezone/tasks/main.yml new file mode 100644 index 0000000..4ffff07 --- /dev/null +++ b/roles/timezone/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include timezone configure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/unbound/tasks/install.yml b/roles/unbound/tasks/install.yml index bf9843b..cbd8a46 100644 --- a/roles/unbound/tasks/install.yml +++ b/roles/unbound/tasks/install.yml @@ -1,5 +1,6 @@ --- - name: install unbound - ansible.builtin.package: + ansible.builtin.apt: name: unbound - state: present + state: latest + update_cache: true diff --git a/roles/user/tasks/main.yml b/roles/user/tasks/main.yml new file mode 100644 index 0000000..50d8e83 --- /dev/null +++ b/roles/user/tasks/main.yml @@ -0,0 +1,10 @@ +--- +- name: add user + ansible.builtin.user: + name: "{{ item.name }}" + create_home: "{{ item.create_home | default(false) }}" + home: "{{ item.home | default(omit) }}" + shell: "{{ item.shell | default('/usr/sbin/nologin') }}" + state: "{{ item.state | default('present') }}" + system: "{{ item.system }}" + loop: "{{ user }}" diff --git a/roles/wireguard-tools/handlers/main.yml b/roles/wireguard-tools/handlers/main.yml new file mode 100644 index 0000000..f28943b --- /dev/null +++ b/roles/wireguard-tools/handlers/main.yml @@ -0,0 +1,7 @@ +--- +- name: restart wg0 systemd service unit + ansible.builtin.systemd_service: + name: wg-quick@wg0 + daemon_reload: true + state: restarted + enabled: true diff --git a/roles/wireguard-tools/tasks/configure.yml b/roles/wireguard-tools/tasks/configure.yml new file mode 100644 index 0000000..e253ba5 --- /dev/null +++ b/roles/wireguard-tools/tasks/configure.yml @@ -0,0 +1,21 @@ +--- +- name: ensure /etc/wireguard exists + ansible.builtin.file: + path: /etc/wireguard + state: directory + mode: "0700" + +- name: deploy wireguard config + ansible.builtin.template: + src: "wg0.conf.j2" + dest: "/etc/wireguard/wg0.conf" + mode: "0644" + register: wg0_conf + +- name: restart wg0 systemd service unit + ansible.builtin.systemd_service: + name: wg-quick@wg0 + daemon_reload: true + state: restarted + enabled: true + when: wg0_conf.changed diff --git a/roles/wireguard-tools/tasks/install.yml b/roles/wireguard-tools/tasks/install.yml new file mode 100644 index 0000000..4ad71c4 --- /dev/null +++ b/roles/wireguard-tools/tasks/install.yml @@ -0,0 +1,6 @@ +--- +- name: install wireguard-tools + ansible.builtin.apt: + name: wireguard-tools + state: latest + update_cache: true diff --git a/roles/wireguard-tools/tasks/main.yml b/roles/wireguard-tools/tasks/main.yml new file mode 100644 index 0000000..e2643fc --- /dev/null +++ b/roles/wireguard-tools/tasks/main.yml @@ -0,0 +1,6 @@ +--- +- name: include wireguard-tools install + ansible.builtin.include_tasks: install.yml + +- name: include wireguard-tools configurure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/wireguard-tools/templates/wg0.conf.j2 b/roles/wireguard-tools/templates/wg0.conf.j2 new file mode 100644 index 0000000..5ce31f5 --- /dev/null +++ b/roles/wireguard-tools/templates/wg0.conf.j2 @@ -0,0 +1,17 @@ +[Interface] +PrivateKey = {{ wg_private_key }} +Address = {{ wg_address }} +Table = off +PostUp = ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true +PostUp = ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true +PostUp = ip route add default dev wg0 table 199 2>/dev/null || true +PreDown = ip route del default dev wg0 table 199 2>/dev/null || true +PreDown = ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true +PreDown = ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true + +[Peer] +PublicKey = {{ wg_public_key }} +PresharedKey = {{ wg_presharedkey }} +Endpoint = {{ wg_endpoint_address }}:{{ wg_endpoint_port }} +PersistentKeepalive = 25 +AllowedIPs = 0.0.0.0/0 diff --git a/roles/xray-core/files/dns.jsonc b/roles/xray-client/files/dns.jsonc similarity index 100% rename from roles/xray-core/files/dns.jsonc rename to roles/xray-client/files/dns.jsonc diff --git a/roles/xray-core/files/inbounds.jsonc b/roles/xray-client/files/inbounds.jsonc similarity index 95% rename from roles/xray-core/files/inbounds.jsonc rename to roles/xray-client/files/inbounds.jsonc index b928bb4..e214aec 100644 --- a/roles/xray-core/files/inbounds.jsonc +++ b/roles/xray-client/files/inbounds.jsonc @@ -2,7 +2,7 @@ "inbounds": [ { "port": 61219, - "listen": "127.0.0.1", + "listen": "0.0.0.0", "protocol": "dokodemo-door", "settings": { "followRedirect": true, diff --git a/roles/xray-core/files/log.jsonc b/roles/xray-client/files/log.jsonc similarity index 100% rename from roles/xray-core/files/log.jsonc rename to roles/xray-client/files/log.jsonc diff --git a/roles/xray-core/files/policy.jsonc b/roles/xray-client/files/policy.jsonc similarity index 100% rename from roles/xray-core/files/policy.jsonc rename to roles/xray-client/files/policy.jsonc diff --git a/roles/xray-client/tasks/configure.yml b/roles/xray-client/tasks/configure.yml new file mode 100644 index 0000000..bd552f0 --- /dev/null +++ b/roles/xray-client/tasks/configure.yml @@ -0,0 +1,43 @@ +--- +- name: ensure /opt/xray-core/config exists + ansible.builtin.file: + path: /opt/xray-core/config + state: directory + mode: 0755 + +- name: ensure /var/log/xray-core exists + ansible.builtin.file: + path: /var/log/xray-core + state: directory + mode: 0755 + +- name: deploy static xray-core config + ansible.builtin.copy: + src: "{{ item }}" + dest: "/opt/xray-core/config/{{ item }}" + mode: 0744 + loop: + - dns.jsonc + - inbounds.jsonc + - log.jsonc + - policy.jsonc + register: xray_core_static_config + +- name: deploy dynamic xray-core config + ansible.builtin.template: + src: "{{ item }}.j2" + dest: "/opt/xray-core/config/{{ item }}" + mode: 0744 + loop: + - observatory.jsonc + - outbounds.jsonc + - routing.jsonc + register: xray_core_dynamic_config + +- name: restart xray-core systemd service unit + ansible.builtin.systemd_service: + name: xray-core + daemon_reload: true + state: restarted + enabled: true + when: xray_core_static_config.changed or xray_core_dynamic_config.changed diff --git a/roles/xray-client/tasks/main.yml b/roles/xray-client/tasks/main.yml new file mode 100644 index 0000000..feb73d0 --- /dev/null +++ b/roles/xray-client/tasks/main.yml @@ -0,0 +1,3 @@ +--- +- name: include xray-core configurure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/xray-core/templates/observatory.jsonc.j2 b/roles/xray-client/templates/observatory.jsonc.j2 similarity index 100% rename from roles/xray-core/templates/observatory.jsonc.j2 rename to roles/xray-client/templates/observatory.jsonc.j2 diff --git a/roles/xray-core/templates/outbounds.jsonc.j2 b/roles/xray-client/templates/outbounds.jsonc.j2 similarity index 100% rename from roles/xray-core/templates/outbounds.jsonc.j2 rename to roles/xray-client/templates/outbounds.jsonc.j2 diff --git a/roles/xray-core/templates/routing.jsonc.j2 b/roles/xray-client/templates/routing.jsonc.j2 similarity index 100% rename from roles/xray-core/templates/routing.jsonc.j2 rename to roles/xray-client/templates/routing.jsonc.j2 diff --git a/roles/xray-core/files/xray-core.service b/roles/xray-core/files/xray-core.service new file mode 100644 index 0000000..6583b13 --- /dev/null +++ b/roles/xray-core/files/xray-core.service @@ -0,0 +1,17 @@ +[Unit] +Description=Xray-core Service +Documentation=https://github.com/xtls/xray-core +After=network.target network-online.target nftables.service +Wants=network-online.target + +[Service] +Type=simple +User=root +WorkingDirectory=/opt/xray-core +ExecStart=/opt/xray-core/xray -confdir /opt/xray-core/config +Restart=on-failure +RestartSec=3s +LimitNOFILE=65535 + +[Install] +WantedBy=multi-user.target diff --git a/roles/xray-core/handlers/main.yml b/roles/xray-core/handlers/main.yml deleted file mode 100644 index 398546e..0000000 --- a/roles/xray-core/handlers/main.yml +++ /dev/null @@ -1,6 +0,0 @@ ---- -- name: restart xray-core - ansible.builtin.service: - name: xray-core - state: restarted - listen: restart xray-core diff --git a/roles/xray-core/tasks/configure.yml b/roles/xray-core/tasks/configure.yml deleted file mode 100644 index ab2f83f..0000000 --- a/roles/xray-core/tasks/configure.yml +++ /dev/null @@ -1,33 +0,0 @@ ---- -- name: ensure /etc/xray-core exists - ansible.builtin.file: - path: /etc/xray-core/config - state: directory - mode: "0755" - -- name: ensure /var/log/xray-core exists - ansible.builtin.file: - path: /var/log/xray-core - state: directory - mode: "0755" - -- name: deploy static xray-core config - ansible.builtin.copy: - src: "{{ item }}" - dest: "/etc/xray-core/config/{{ item }}" - mode: "0744" - loop: - - dns.jsonc - - inbounds.jsonc - - log.jsonc - - policy.jsonc - -- name: deploy dynamic xray-core config - ansible.builtin.template: - src: "{{ item }}.j2" - dest: "/etc/xray-core/config/{{ item }}" - mode: "0744" - loop: - - observatory.jsonc - - outbounds.jsonc - - routing.jsonc diff --git a/roles/xray-core/tasks/install.yml b/roles/xray-core/tasks/install.yml index bf9843b..33fc3b0 100644 --- a/roles/xray-core/tasks/install.yml +++ b/roles/xray-core/tasks/install.yml @@ -1,5 +1,42 @@ --- -- name: install unbound +- name: install unzip ansible.builtin.package: - name: unbound + name: unzip state: present + +- name: get latest xray-core release info + ansible.builtin.uri: + url: https://api.github.com/repos/XTLS/Xray-core/releases/latest + return_content: yes + register: xray_release + run_once: true + +- name: set current xray-core version + ansible.builtin.set_fact: + xray_version: "{{ xray_release.json.tag_name }}" + xray_asset_url: "{{ xray_release.json.assets | selectattr('name', 'equalto', 'Xray-linux-64.zip') | map(attribute='browser_download_url') | first }}" + +- name: check xray-core installed version + ansible.builtin.command: /opt/xray-core/xray version + register: xray_current_version + changed_when: false + failed_when: false + +- name: ensure xray-core directory exists + ansible.builtin.file: + path: /opt/xray-core + state: directory + mode: '0755' + +- name: update xray-core + ansible.builtin.unarchive: + src: "{{ xray_asset_url }}" + dest: /opt/xray-core + remote_src: yes + when: xray_version not in (xray_current_version.stdout | default('')) + +- name: deploy xray-core systemd service unit + ansible.builtin.copy: + src: xray-core.service + dest: /etc/systemd/system/xray-core.service + mode: 755 diff --git a/roles/xray-core/tasks/main.yml b/roles/xray-core/tasks/main.yml index 2f87337..615e362 100644 --- a/roles/xray-core/tasks/main.yml +++ b/roles/xray-core/tasks/main.yml @@ -1,6 +1,3 @@ --- -#- name: include unbound install -# ansible.builtin.include_tasks: install.yml - -- name: include xray-core configurure - ansible.builtin.include_tasks: configure.yml +- name: include xray-core install + ansible.builtin.include_tasks: install.yml diff --git a/roles/xray-lists/files/update.sh b/roles/xray-lists/files/update.sh new file mode 100644 index 0000000..372758b --- /dev/null +++ b/roles/xray-lists/files/update.sh @@ -0,0 +1,19 @@ +#!/bin/sh + +set -e +out=$(/opt/xray-lists/venv/bin/xray-lists) + +echo "$out" + +dns_changed=0 +elements_changed=0 + +if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi +if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi + +if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12; +elif [ "$dns_changed" -eq 1 ]; then exit 10; +elif [ "$elements_changed" -eq 1 ]; then exit 11; +fi + +exit 0 diff --git a/roles/xray-lists/files/xray-lists.service b/roles/xray-lists/files/xray-lists.service new file mode 100644 index 0000000..9157f4f --- /dev/null +++ b/roles/xray-lists/files/xray-lists.service @@ -0,0 +1,13 @@ +[Unit] +Description=Update Xray lists + +[Service] +Type=oneshot +ExecStart=/bin/sh -c '\ +/var/lib/xray-lists/update.sh; \ +rc=$$?; \ +case "$$rc" in \ + 10) systemctl restart dnsmasq ;; \ + 11) nft -f /etc/nftables.conf ;; \ + 12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \ +esac' diff --git a/roles/xray-lists/files/xray-lists.timer b/roles/xray-lists/files/xray-lists.timer new file mode 100644 index 0000000..c726253 --- /dev/null +++ b/roles/xray-lists/files/xray-lists.timer @@ -0,0 +1,10 @@ +[Unit] +Description=Run xray-lists update + +[Timer] +OnBootSec=5min +OnUnitActiveSec=12h +Persistent=true + +[Install] +WantedBy=timers.target diff --git a/roles/xray-lists/handlers/main.yml b/roles/xray-lists/handlers/main.yml index 835f6ae..01b22a3 100644 --- a/roles/xray-lists/handlers/main.yml +++ b/roles/xray-lists/handlers/main.yml @@ -1,16 +1,26 @@ --- - name: reload nftables ansible.builtin.command: nft -f /etc/nftables.conf - listen: reload nftables - name: restart dnsmasq ansible.builtin.service: name: dnsmasq state: restarted -- name: restart xray-lists timer - ansible.builtin.systemd: +- name: run xray-lists systemd timer unit + ansible.builtin.systemd_service: name: xray-lists.timer + daemon_reload: true + state: started + enabled: true + +- name: update xray-lists + ansible.builtin.systemd_service: + name: xray-lists.service + state: started + +- name: restart xray-lists timer + ansible.builtin.systemd_service: + name: xray-lists.timer + daemon_reload: true state: restarted - daemon_reload: yes - listen: restart xray-lists timer diff --git a/roles/xray-lists/tasks/configure.yml b/roles/xray-lists/tasks/configure.yml index 885567d..047d08c 100644 --- a/roles/xray-lists/tasks/configure.yml +++ b/roles/xray-lists/tasks/configure.yml @@ -1,33 +1,22 @@ --- -#- name: collect xray policy hosts -# ansible.builtin.set_fact: -# _xray_hosts_with_policy: >- -# {{ - # (_xray_hosts_with_policy | default([])) - # + [{'inventory_hostname': item, 'xray_policy': hostvars[item].xray_policy}] - # }} - # loop: "{{ groups[xray_managed_group] }}" - # when: hostvars[item].xray_policy is defined - - #- name: validate xray policy sets - # ansible.builtin.assert: - # that: - # - (item.1.bypass | default(item.1.proxy)) == 'all' or - # (item.1.bypass | default(item.1.proxy)) in xray_ip_sets or - # (item.1.bypass | default(item.1.proxy)) in xray_domain_sets or - # (item.1.bypass | default(item.1.proxy)) in (xray_static_sets | default([])) - # fail_msg: "host {{ item.0.inventory_hostname }}: unknown xray set '{{ item.1.bypass | default(item.1.proxy) }}'" - # quiet: true - # loop: "{{ query('ansible.builtin.subelements', _xray_hosts_with_policy | default([]), 'xray_policy', {'skip_missing': True}) }}" - # loop_control: - # label: "{{ item.0.inventory_hostname }} -> {{ item.1.bypass | default(item.1.proxy) }}" +- name: ensure /etc/nftables.d exists + ansible.builtin.file: + path: /etc/nftables.d + state: directory + mode: "0755" - name: render xray-lists config ansible.builtin.template: src: xray-config.yaml.j2 dest: /var/lib/xray-lists/config.yaml mode: "0640" - notify: restart xray-lists timer + register: xray_lists_config + +- name: update xray-lists + ansible.builtin.systemd_service: + name: xray-lists.service + state: started + when: xray_lists_config.changed - name: bootstrap empty config files ansible.builtin.copy: diff --git a/roles/xray-lists/tasks/install.yml b/roles/xray-lists/tasks/install.yml index 1de635e..6a87b0f 100644 --- a/roles/xray-lists/tasks/install.yml +++ b/roles/xray-lists/tasks/install.yml @@ -18,9 +18,14 @@ - /opt/xray-lists - /var/lib/xray-lists +- name: create python venv for xray-lists + command: python3 -m venv /opt/xray-lists/venv + args: + creates: /opt/xray-lists/venv/bin/pip + - name: clone xray-lists repository git: - repo: 'https://gitea.oyacoi.ru/pyrschtjag/xray-lists' + repo: "http://10.1.0.104:3000/pyrschtjag/xray-lists.git" dest: /opt/xray-lists-src version: main force: yes @@ -37,72 +42,20 @@ - name: deploy update helper script copy: + src: update.sh dest: /var/lib/xray-lists/update.sh owner: root group: root mode: '0755' - content: | - #!/bin/sh - set -e - out=$(/opt/xray-lists/venv/bin/xray-lists) - - echo "$out" - - dns_changed=0 - elements_changed=0 - - if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi - if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi - - if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12; - elif [ "$dns_changed" -eq 1 ]; then exit 10; - elif [ "$elements_changed" -eq 1 ]; then exit 11; - fi - - exit 0 - -- name: deploy systemd service unit +- name: deploy systemd service and timer unit copy: - dest: /etc/systemd/system/xray-lists.service + src: "{{ item }}" + dest: "/etc/systemd/system/{{ item }}" owner: root group: root mode: '0644' - content: | - [Unit] - Description=Update Xray lists - - [Service] - Type=oneshot - ExecStart=/bin/sh -c '\ - /var/lib/xray-lists/update.sh; \ - rc=$$?; \ - case "$$rc" in \ - 10) systemctl restart dnsmasq ;; \ - 11) nft -f /etc/nftables.conf ;; \ - 12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \ - esac' - -- name: deploy systemd timer unit - copy: - dest: /etc/systemd/system/xray-lists.timer - owner: root - group: root - mode: '0644' - content: | - [Unit] - Description=Run xray-lists update daily and on boot - - [Timer] - OnBootSec=5min - OnUnitActiveSec=12h - Persistent=true - - [Install] - WantedBy=timers.target - -- name: enable and start xray-lists - ansible.builtin.systemd: - name: xray-lists.timer - enabled: true - state: started + loop: + - xray-lists.service + - xray-lists.timer + notify: run xray-lists systemd timer unit diff --git a/roles/xray-lists/templates/90-proxy-prerouting.nft.j2 b/roles/xray-lists/templates/90-proxy-prerouting.nft.j2 index 1264d7b..d50da1a 100644 --- a/roles/xray-lists/templates/90-proxy-prerouting.nft.j2 +++ b/roles/xray-lists/templates/90-proxy-prerouting.nft.j2 @@ -10,7 +10,7 @@ invalid_xray_set_{{ name }} {% endif %} {% endmacro %} -{% for item in groups[xray_managed_group] | default([]) | sort %} +{% for item in xray_managed_group | default([]) | sort %} {% set client = hostvars[item] %} {% if client.xray_policy is defined %} {% set src_ip = client.container_ip %} diff --git a/roles/xray-lists/templates/90-sets.nft.j2 b/roles/xray-lists/templates/90-sets.nft.j2 index 1681b27..d9c9e96 100644 --- a/roles/xray-lists/templates/90-sets.nft.j2 +++ b/roles/xray-lists/templates/90-sets.nft.j2 @@ -4,7 +4,7 @@ set {{ id }}_ip { type ipv4_addr flags interval auto-merge - include "{{ xray_lists_global.output_dir }}/{{ id }}.elements.nft" + include "{{ xray_lists_global.output_dir }}/{{ id }}_ip.elements.nft" } {% endfor -%} {%- for id, item in xray_domain_sets.items() -%} diff --git a/roles/xray-lists/templates/xray-config.yaml.j2 b/roles/xray-lists/templates/xray-config.yaml.j2 index 9cc3e7c..b29f5f2 100644 --- a/roles/xray-lists/templates/xray-config.yaml.j2 +++ b/roles/xray-lists/templates/xray-config.yaml.j2 @@ -6,9 +6,9 @@ global: {% if xray_lists_global.proxy is defined %} proxy: "{{ xray_lists_global.proxy }}" {% endif %} - {% if xray_lists_global.proxy_user is defined %} - proxy_user: "{{ xray_lists_global.proxy_user }}" - proxy_pass: "{{ xray_lists_global.proxy_pass }}" + {% if proxy_user is defined %} + proxy_user: "{{ proxy_user }}" + proxy_pass: "{{ proxy_pass }}" {% endif %} http_timeout: {{ xray_lists_global.http_timeout | default(20) }} ip_sets: diff --git a/roles/zerotier-one/handlers/main.yml b/roles/zerotier-one/handlers/main.yml new file mode 100644 index 0000000..8487597 --- /dev/null +++ b/roles/zerotier-one/handlers/main.yml @@ -0,0 +1,10 @@ +--- +- name: reload nftables + ansible.builtin.command: nft -f /etc/nftables.conf + +- name: restart zerotier-one systemd service unit + ansible.builtin.systemd_service: + name: zerotier-one + daemon_reload: true + state: restarted + enabled: true diff --git a/roles/zerotier-one/tasks/configure.yml b/roles/zerotier-one/tasks/configure.yml new file mode 100644 index 0000000..56ace6e --- /dev/null +++ b/roles/zerotier-one/tasks/configure.yml @@ -0,0 +1,31 @@ +--- +- name: create networks.d directory + ansible.builtin.file: + path: /var/lib/zerotier-one/networks.d + state: directory + mode: 0700 + owner: zerotier-one + group: zerotier-one + +- name: check if zerotier-one network config exists + ansible.builtin.stat: + path: "/var/lib/zerotier-one/networks.d/{{ zerotier_network_id }}.conf" + register: zerotier_network_stat + +- name: create zerotier-one network config + ansible.builtin.file: + path: "/var/lib/zerotier-one/networks.d/{{ zerotier_network_id }}.conf" + state: touch + mode: "0600" + owner: zerotier-one + group: zerotier-one + when: not zerotier_network_stat.stat.exists + register: zerotier_network + +- name: restart zerotier-one systemd service unit + ansible.builtin.systemd_service: + name: zerotier-one + daemon_reload: true + state: restarted + enabled: true + when: zerotier_network.changed diff --git a/roles/zerotier-one/tasks/install.yml b/roles/zerotier-one/tasks/install.yml new file mode 100644 index 0000000..b098284 --- /dev/null +++ b/roles/zerotier-one/tasks/install.yml @@ -0,0 +1,16 @@ +--- +- name: add zerotier repository + ansible.builtin.deb822_repository: + name: zerotier + types: deb + uris: "http://download.zerotier.com/debian/trixie" + suites: "trixie" + components: main + signed_by: "https://download.zerotier.com/contact%40zerotier.com.gpg" + state: present + +- name: install zerotier-one + ansible.builtin.apt: + name: zerotier-one + state: latest + update_cache: true diff --git a/roles/zerotier-one/tasks/main.yml b/roles/zerotier-one/tasks/main.yml new file mode 100644 index 0000000..4b0637c --- /dev/null +++ b/roles/zerotier-one/tasks/main.yml @@ -0,0 +1,6 @@ +--- +- name: include install + ansible.builtin.include_tasks: install.yml + +- name: include configure + ansible.builtin.include_tasks: configure.yml diff --git a/roles/zerotier-one/templates/wg0.conf.j2 b/roles/zerotier-one/templates/wg0.conf.j2 new file mode 100644 index 0000000..5ce31f5 --- /dev/null +++ b/roles/zerotier-one/templates/wg0.conf.j2 @@ -0,0 +1,17 @@ +[Interface] +PrivateKey = {{ wg_private_key }} +Address = {{ wg_address }} +Table = off +PostUp = ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true +PostUp = ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true +PostUp = ip route add default dev wg0 table 199 2>/dev/null || true +PreDown = ip route del default dev wg0 table 199 2>/dev/null || true +PreDown = ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true +PreDown = ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true + +[Peer] +PublicKey = {{ wg_public_key }} +PresharedKey = {{ wg_presharedkey }} +Endpoint = {{ wg_endpoint_address }}:{{ wg_endpoint_port }} +PersistentKeepalive = 25 +AllowedIPs = 0.0.0.0/0 diff --git a/roles/zfs/tasks/file.yml b/roles/zfs/tasks/file.yml new file mode 100644 index 0000000..f3adcc1 --- /dev/null +++ b/roles/zfs/tasks/file.yml @@ -0,0 +1,7 @@ +- name: manage zfs dataset permissions + ansible.builtin.file: + path: "/{{ item.name }}" + owner: "100000" + group: "100000" + loop: "{{ zfs }}" + when: item.state | default('present') != 'absent' diff --git a/roles/zfs/tasks/main.yml b/roles/zfs/tasks/main.yml new file mode 100644 index 0000000..5c13845 --- /dev/null +++ b/roles/zfs/tasks/main.yml @@ -0,0 +1,6 @@ +--- +- name: include zfs + ansible.builtin.include_tasks: zfs.yml + +- name: include file + ansible.builtin.include_tasks: file.yml diff --git a/roles/zfs/tasks/zfs.yml b/roles/zfs/tasks/zfs.yml new file mode 100644 index 0000000..032d409 --- /dev/null +++ b/roles/zfs/tasks/zfs.yml @@ -0,0 +1,6 @@ +- name: manage zfs datasets + community.general.zfs: + name: "{{ item.name }}" + state: "{{ item.state | default('present') }}" + extra_zfs_properties: "{{ item.extra_zfs_properties | default(omit) }}" + loop: "{{ zfs }}"