refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
+5
View File
@@ -0,0 +1,5 @@
- name: install package
ansible.builtin.apt:
name: "{{ item }}"
update_cache: true
loop: "{{ apt }}"
+3
View File
@@ -0,0 +1,3 @@
---
- name: include apt install
ansible.builtin.include_tasks: apt.yml
+15
View File
@@ -0,0 +1,15 @@
---
- name: ensure .ssh exists
ansible.builtin.file:
path: /root/.ssh
state: directory
mode: '0700'
owner: root
group: root
- name: set authorized key
ansible.posix.authorized_key:
user: root
state: present
key: "{{ item }}"
loop: "{{ ssh_keys }}"
+39
View File
@@ -0,0 +1,39 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: deploy dnsmasq rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/dnsmasq.d/{{ item }}"
mode: "0644"
loop:
- 10-upstream.conf
- 20-custom-domains.conf
- 20-dhcp.conf
- 20-dns-optimizations.conf
notify: restart dnsmasq
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render dhcp-host
ansible.builtin.template:
src: 90-dhcp-host.conf.j2
dest: /etc/dnsmasq.d/90-dhcp-host.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
+6
View File
@@ -0,0 +1,6 @@
---
- name: install dnsmasq
ansible.builtin.apt:
name: dnsmasq
state: latest
update_cache: true
+4 -37
View File
@@ -1,39 +1,6 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: include dnsmasq install
ansible.builtin.include_tasks: install.yml
- name: deploy dnsmasq rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/dnsmasq.d/{{ item }}"
mode: "0644"
loop:
- 10-upstream.conf
- 20-custom-domains.conf
- 20-dhcp.conf
- 20-dns-optimizations.conf
notify: restart dnsmasq
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render dhcp-host
ansible.builtin.template:
src: 90-dhcp-host.conf.j2
dest: /etc/dnsmasq.d/90-dhcp-host.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
- name: include dnsmasq configurure
ansible.builtin.include_tasks: configure.yml
+1 -1
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
+1 -1
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'dnsmasq' in client and client.dnsmasq %}
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
+1 -1
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if ip %}
+13
View File
@@ -0,0 +1,13 @@
---
- name: deploy ifupdown interfaces config
ansible.builtin.template:
src: interfaces
dest: /etc/network/interfaces
owner: root
group: root
mode: '0644'
register: interfaces_conf
- name: reload ifupdown2
command: ifreload -a
when: interfaces_conf.changed
+20
View File
@@ -0,0 +1,20 @@
{% for item in ifupdown2 %}
auto {{ item.iface }}
iface {{ item.iface }}{% if item.method is defined %} inet {{ item.method }}
{% endif %}
{% if item.address is defined %}
address {{ item.address }}
{% endif %}
{% if item['vlan-raw-device'] is defined %}
vlan-raw-device {{ item['vlan-raw-device'] }}
{% endif %}
{% if item.routing is defined %}
{% for route in item.routing %}
{{ route }}
{% endfor %}
{% endif %}
{% if not loop.last %}
{% endif %}
{% endfor %}
+22
View File
@@ -0,0 +1,22 @@
---
- name: set required locales
community.general.locale_gen:
name: "{{ item }}"
state: present
loop: "{{ locales_list }}"
- name: configure /etc/default/locale
ansible.builtin.copy:
dest: /etc/default/locale
content: LANG={{ locale_default }}
owner: root
group: root
mode: '0644'
- name: configure /etc/locale.conf
ansible.builtin.copy:
dest: /etc/locale.conf
content: LANG={{ locale_default }}
owner: root
group: root
mode: '0644'
+3
View File
@@ -0,0 +1,3 @@
---
- name: include locales configure
ansible.builtin.include_tasks: configure.yml
+9
View File
@@ -0,0 +1,9 @@
---
- name: deploy logrotate config
ansible.builtin.template:
src: logrotate.conf.j2
dest: "/etc/logrotate.d/{{ item.name }}"
mode: "0644"
loop: "{{ logrotate }}"
loop_control:
label: "{{ item.name }}"
+3
View File
@@ -0,0 +1,3 @@
---
- name: include logrotate configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,5 @@
{{ item.paths | join(' ') }} {
{% for opt in item.options %}
{{ opt }}
{% endfor %}
}
+3
View File
@@ -35,6 +35,9 @@ chain forward {
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
iifname "zt*" oifname "eth0" accept
iifname "eth0" oifname "zt*" accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
+3 -2
View File
@@ -1,5 +1,6 @@
---
- name: install nftables
ansible.builtin.package:
ansible.builtin.apt:
name: nftables
state: present
state: latest
update_cache: true
+1 -1
View File
@@ -2,5 +2,5 @@
- name: include nftables install
ansible.builtin.include_tasks: install.yml
- name: include nftables configurure
- name: include nftables configure
ansible.builtin.include_tasks: configure.yml
+1 -1
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_dst' in client and client.nft_dst is not none %}
{% set target_ip = client.container_ip %}
+2 -2
View File
@@ -1,5 +1,5 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_to' in client and client.nft_to is not none %}
{% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %}
@@ -27,7 +27,7 @@ iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{
{% endfor %}
{% endif %}
{% endfor %}
{% for item in groups[nft_managed_group] | sort %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_from' in client and client.nft_from is not none %}
{% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %}
-52
View File
@@ -1,52 +0,0 @@
auto lo
iface lo inet loopback
post-up ip rule add fwmark 0x1 lookup 100 2>/dev/null || true
post-up ip route add local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
auto eth0
iface eth0 inet manual
address 10.1.0.1/24
auto eth0.2
iface eth0.2 inet static
address 10.2.0.1/24
vlan-raw-device eth0
auto eth0.3
iface eth0.3 inet static
address 10.3.0.1/24
vlan-raw-device eth0
auto eth0.4
iface eth0.4 inet static
address 10.4.0.1/24
vlan-raw-device eth0
auto eth0.10
iface eth0.10 inet static
address 10.10.0.1/24
vlan-raw-device eth0
auto eth0.11
iface eth0.11 inet static
address 10.11.0.1/24
vlan-raw-device eth0
auto eth0.12
iface eth0.12 inet static
address 10.12.0.1/24
vlan-raw-device eth0
auto eth1
iface eth1 inet dhcp
auto wg0
iface wg0 inet manual
post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
post-up ip route add default dev wg0 table 199 2>/dev/null || true
pre-down ip route del default dev wg0 table 199 2>/dev/null || true
pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
@@ -1 +0,0 @@
net.ipv4.ip_forward=1
@@ -1,3 +0,0 @@
net.ipv4.conf.lo.rp_filter=0
net.ipv4.conf.all.rp_filter=0
net.ipv4.conf.wg0.rp_filter=0
-3
View File
@@ -1,3 +0,0 @@
---
- name: reload ifupdown2
command: ifreload -a
-9
View File
@@ -1,9 +0,0 @@
---
- name: deploy ifupdown config
copy:
src: ifupdown2/interfaces
dest: /etc/network/interfaces
owner: root
group: root
mode: '0644'
notify: reload ifupdown2
+15
View File
@@ -0,0 +1,15 @@
[Unit]
Description=dayz server
Wants=network.target
After=syslog.target network-online.target
[Service]
Type=simple
Restart=on-failure
RestartSec=10
User=steamcmd
WorkingDirectory=/mnt/steamcmd/dayz
ExecStart=/mnt/steamcmd/dayz/DayZServer -config=serverDZ-custom.cfg -port=2302
[Install]
WantedBy=multi-user.target
+32
View File
@@ -0,0 +1,32 @@
hostname = "oyacoi";
password = "ff32167";
passwordAdmin = "";
description = "";
enableWhitelist = 0;
maxPlayers = 1;
verifySignatures = 2;
forceSameBuild = 1;
disableVoN = 1;
vonCodecQuality = 0;
shardId = "123abc";
disable3rdPerson=1;
disableCrosshair=1;
disablePersonalLight = 1;
lightingConfig = 0;
serverTime="SystemTime";
serverTimeAcceleration=6;
serverNightTimeAcceleration=12;
serverTimePersistent=0;
guaranteedUpdates=1;
loginQueueConcurrentPlayers=5;
loginQueueMaxPlayers=0;
instanceId = 1;
storageAutoFix = 1;
class Missions
{
class DayZ
{
template="dayzOffline.sakhal";
};
};
+13
View File
@@ -0,0 +1,13 @@
#!/bin/bash
export templdpath=$LD_LIBRARY_PATH
export LD_LIBRARY_PATH=./linux64:$LD_LIBRARY_PATH
export SteamAppId=892970
echo "Starting server PRESS CTRL-C to exit"
# Tip: Make a local copy of this script to avoid it being overwritten by steam.
# NOTE: Minimum password length is 5 characters & Password cant be in the server name.
# NOTE: You need to make sure the ports 2456-2458 is being forwarded to your server through your local router & firewall.
./valheim_server.x86_64 -name "oyacoi" -port 2456 -world "world0" -password "ff32167" -public 0
export LD_LIBRARY_PATH=$templdpath
+15
View File
@@ -0,0 +1,15 @@
[Unit]
Description=valheim server
Wants=network.target
After=syslog.target network-online.target
[Service]
Type=simple
Restart=on-failure
RestartSec=10
User=steamcmd
WorkingDirectory=/mnt/steamcmd/valheim
ExecStart=/bin/bash /mnt/steamcmd/valheim/start_server-custom.sh
[Install]
WantedBy=multi-user.target
+14
View File
@@ -0,0 +1,14 @@
---
- name: restart valheim
ansible.builtin.systemd:
daemon_reload: true
name: valheim.service
state: restarted
enabled: true
- name: restart dayz
ansible.builtin.systemd:
daemon_reload: true
name: dayz.service
state: restarted
enabled: true
+4
View File
@@ -0,0 +1,4 @@
- name: install package
ansible.builtin.apt:
name: steamcmd
update_cache: true
+23
View File
@@ -0,0 +1,23 @@
- name: check steam session
ansible.builtin.stat:
path: /var/lib/steamcmd/.local/share/Steam/config/config.vdf
register: steam_session
- name: abort if steam authorization is missing
ansible.builtin.fail:
msg: "Manual Steam authorization required. Please log in interactively."
when: not steam_session.stat.exists
- name: install valheim server
ansible.builtin.command:
cmd: su - steamcmd -c "/usr/games/steamcmd +force_install_dir /mnt/steamcmd/valheim +login anonymous +app_update 896660 validate +exit"
register: valheim_result
changed_when: "'downloading' in valheim_result.stdout"
notify: restart valheim
- name: install dayz server
ansible.builtin.command:
cmd: su - steamcmd -c "/usr/games/steamcmd +force_install_dir /mnt/steamcmd/dayz +login gshinzu +app_update 223350 validate +exit"
register: dayz_result
changed_when: "'downloading' in dayz_result.stdout"
notify: restart dayz
+34
View File
@@ -0,0 +1,34 @@
---
- name: deploy start_server.sh
ansible.builtin.copy:
src: start_server.sh
dest: /mnt/steamcmd/valheim/start_server-custom.sh
owner: steamcmd
group: steamcmd
mode: '0775'
- name: deploy valheim.service
ansible.builtin.copy:
src: valheim.service
dest: /etc/systemd/system/valheim.service
owner: root
group: root
mode: '0644'
notify: restart valheim
- name: deploy serverDZ.cfg
ansible.builtin.copy:
src: serverDZ.cfg
dest: /mnt/steamcmd/dayz/serverDZ-custom.cfg
owner: steamcmd
group: steamcmd
mode: '0755'
- name: deploy dayz.service
ansible.builtin.copy:
src: dayz.service
dest: /etc/systemd/system/dayz.service
owner: root
group: root
mode: '0644'
notify: restart dayz
+14
View File
@@ -0,0 +1,14 @@
---
- name: configure debian-unstable.sources
ansible.builtin.deb822_repository:
name: debian-unstable
types: deb
uris: http://deb.debian.org/debian
suites:
- unstable
components:
- contrib
- main
- non-free
signed_by: /usr/share/keyrings/debian-archive-keyring.gpg
state: present
+6
View File
@@ -0,0 +1,6 @@
- name: accept agreement
ansible.builtin.debconf:
name: steamcmd
question: steam/question
vtype: string
value: "I AGREE"
+14
View File
@@ -0,0 +1,14 @@
---
- name: create valheim dir
ansible.builtin.file:
path: /mnt/steamcmd/valheim
owner: steamcmd
group: steamcmd
state: "directory"
- name: create dayz dir
ansible.builtin.file:
path: /mnt/steamcmd/dayz
owner: steamcmd
group: steamcmd
state: "directory"
+10
View File
@@ -0,0 +1,10 @@
---
- name: check if i386 architecture
ansible.builtin.command: dpkg --print-foreign-architectures
register: check_i386
changed_when: false
failed_when: false
- name: add i386 architecture
ansible.builtin.command: dpkg --add-architecture i386
when: "'i386' not in check_i386.stdout"
+21
View File
@@ -0,0 +1,21 @@
---
- name: include deb822
ansible.builtin.include_tasks: deb822.yml
- name: include i386
ansible.builtin.include_tasks: i386.yml
- name: include file
ansible.builtin.include_tasks: file.yml
- name: include debconf
ansible.builtin.include_tasks: debconf.yml
- name: include apt
ansible.builtin.include_tasks: apt.yml
- name: include command
ansible.builtin.include_tasks: command.yml
- name: include copy
ansible.builtin.include_tasks: copy.yml
+3
View File
@@ -0,0 +1,3 @@
---
- name: reload sysctl
ansible.builtin.command: sysctl -p /etc/sysctl.d/99-custom.conf
+8
View File
@@ -0,0 +1,8 @@
- name: deploy sysctl config
ansible.builtin.template:
src: sysctl.conf.j2
dest: "/etc/sysctl.d/99-custom.conf"
owner: root
group: root
mode: '0644'
notify: reload sysctl
+3
View File
@@ -0,0 +1,3 @@
---
- name: include sysctl configure
ansible.builtin.include_tasks: configure.yml
+3
View File
@@ -0,0 +1,3 @@
{% for key, value in sysctl.items() %}
{{ key }} = {{ value }}
{% endfor %}
+4
View File
@@ -0,0 +1,4 @@
---
- name: set system timezone
community.general.timezone:
name: "{{ timezone_name }}"
+3
View File
@@ -0,0 +1,3 @@
---
- name: include timezone configure
ansible.builtin.include_tasks: configure.yml
+3 -2
View File
@@ -1,5 +1,6 @@
---
- name: install unbound
ansible.builtin.package:
ansible.builtin.apt:
name: unbound
state: present
state: latest
update_cache: true
+10
View File
@@ -0,0 +1,10 @@
---
- name: add user
ansible.builtin.user:
name: "{{ item.name }}"
create_home: "{{ item.create_home | default(false) }}"
home: "{{ item.home | default(omit) }}"
shell: "{{ item.shell | default('/usr/sbin/nologin') }}"
state: "{{ item.state | default('present') }}"
system: "{{ item.system }}"
loop: "{{ user }}"
+7
View File
@@ -0,0 +1,7 @@
---
- name: restart wg0 systemd service unit
ansible.builtin.systemd_service:
name: wg-quick@wg0
daemon_reload: true
state: restarted
enabled: true
+21
View File
@@ -0,0 +1,21 @@
---
- name: ensure /etc/wireguard exists
ansible.builtin.file:
path: /etc/wireguard
state: directory
mode: "0700"
- name: deploy wireguard config
ansible.builtin.template:
src: "wg0.conf.j2"
dest: "/etc/wireguard/wg0.conf"
mode: "0644"
register: wg0_conf
- name: restart wg0 systemd service unit
ansible.builtin.systemd_service:
name: wg-quick@wg0
daemon_reload: true
state: restarted
enabled: true
when: wg0_conf.changed
+6
View File
@@ -0,0 +1,6 @@
---
- name: install wireguard-tools
ansible.builtin.apt:
name: wireguard-tools
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include wireguard-tools install
ansible.builtin.include_tasks: install.yml
- name: include wireguard-tools configurure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,17 @@
[Interface]
PrivateKey = {{ wg_private_key }}
Address = {{ wg_address }}
Table = off
PostUp = ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
PostUp = ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
PostUp = ip route add default dev wg0 table 199 2>/dev/null || true
PreDown = ip route del default dev wg0 table 199 2>/dev/null || true
PreDown = ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
PreDown = ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
[Peer]
PublicKey = {{ wg_public_key }}
PresharedKey = {{ wg_presharedkey }}
Endpoint = {{ wg_endpoint_address }}:{{ wg_endpoint_port }}
PersistentKeepalive = 25
AllowedIPs = 0.0.0.0/0
@@ -2,7 +2,7 @@
"inbounds": [
{
"port": 61219,
"listen": "127.0.0.1",
"listen": "0.0.0.0",
"protocol": "dokodemo-door",
"settings": {
"followRedirect": true,
+43
View File
@@ -0,0 +1,43 @@
---
- name: ensure /opt/xray-core/config exists
ansible.builtin.file:
path: /opt/xray-core/config
state: directory
mode: 0755
- name: ensure /var/log/xray-core exists
ansible.builtin.file:
path: /var/log/xray-core
state: directory
mode: 0755
- name: deploy static xray-core config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/opt/xray-core/config/{{ item }}"
mode: 0744
loop:
- dns.jsonc
- inbounds.jsonc
- log.jsonc
- policy.jsonc
register: xray_core_static_config
- name: deploy dynamic xray-core config
ansible.builtin.template:
src: "{{ item }}.j2"
dest: "/opt/xray-core/config/{{ item }}"
mode: 0744
loop:
- observatory.jsonc
- outbounds.jsonc
- routing.jsonc
register: xray_core_dynamic_config
- name: restart xray-core systemd service unit
ansible.builtin.systemd_service:
name: xray-core
daemon_reload: true
state: restarted
enabled: true
when: xray_core_static_config.changed or xray_core_dynamic_config.changed
+3
View File
@@ -0,0 +1,3 @@
---
- name: include xray-core configurure
ansible.builtin.include_tasks: configure.yml
+17
View File
@@ -0,0 +1,17 @@
[Unit]
Description=Xray-core Service
Documentation=https://github.com/xtls/xray-core
After=network.target network-online.target nftables.service
Wants=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/xray-core
ExecStart=/opt/xray-core/xray -confdir /opt/xray-core/config
Restart=on-failure
RestartSec=3s
LimitNOFILE=65535
[Install]
WantedBy=multi-user.target
-6
View File
@@ -1,6 +0,0 @@
---
- name: restart xray-core
ansible.builtin.service:
name: xray-core
state: restarted
listen: restart xray-core
-33
View File
@@ -1,33 +0,0 @@
---
- name: ensure /etc/xray-core exists
ansible.builtin.file:
path: /etc/xray-core/config
state: directory
mode: "0755"
- name: ensure /var/log/xray-core exists
ansible.builtin.file:
path: /var/log/xray-core
state: directory
mode: "0755"
- name: deploy static xray-core config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/xray-core/config/{{ item }}"
mode: "0744"
loop:
- dns.jsonc
- inbounds.jsonc
- log.jsonc
- policy.jsonc
- name: deploy dynamic xray-core config
ansible.builtin.template:
src: "{{ item }}.j2"
dest: "/etc/xray-core/config/{{ item }}"
mode: "0744"
loop:
- observatory.jsonc
- outbounds.jsonc
- routing.jsonc
+39 -2
View File
@@ -1,5 +1,42 @@
---
- name: install unbound
- name: install unzip
ansible.builtin.package:
name: unbound
name: unzip
state: present
- name: get latest xray-core release info
ansible.builtin.uri:
url: https://api.github.com/repos/XTLS/Xray-core/releases/latest
return_content: yes
register: xray_release
run_once: true
- name: set current xray-core version
ansible.builtin.set_fact:
xray_version: "{{ xray_release.json.tag_name }}"
xray_asset_url: "{{ xray_release.json.assets | selectattr('name', 'equalto', 'Xray-linux-64.zip') | map(attribute='browser_download_url') | first }}"
- name: check xray-core installed version
ansible.builtin.command: /opt/xray-core/xray version
register: xray_current_version
changed_when: false
failed_when: false
- name: ensure xray-core directory exists
ansible.builtin.file:
path: /opt/xray-core
state: directory
mode: '0755'
- name: update xray-core
ansible.builtin.unarchive:
src: "{{ xray_asset_url }}"
dest: /opt/xray-core
remote_src: yes
when: xray_version not in (xray_current_version.stdout | default(''))
- name: deploy xray-core systemd service unit
ansible.builtin.copy:
src: xray-core.service
dest: /etc/systemd/system/xray-core.service
mode: 755
+2 -5
View File
@@ -1,6 +1,3 @@
---
#- name: include unbound install
# ansible.builtin.include_tasks: install.yml
- name: include xray-core configurure
ansible.builtin.include_tasks: configure.yml
- name: include xray-core install
ansible.builtin.include_tasks: install.yml
+19
View File
@@ -0,0 +1,19 @@
#!/bin/sh
set -e
out=$(/opt/xray-lists/venv/bin/xray-lists)
echo "$out"
dns_changed=0
elements_changed=0
if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi
if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi
if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12;
elif [ "$dns_changed" -eq 1 ]; then exit 10;
elif [ "$elements_changed" -eq 1 ]; then exit 11;
fi
exit 0
+13
View File
@@ -0,0 +1,13 @@
[Unit]
Description=Update Xray lists
[Service]
Type=oneshot
ExecStart=/bin/sh -c '\
/var/lib/xray-lists/update.sh; \
rc=$$?; \
case "$$rc" in \
10) systemctl restart dnsmasq ;; \
11) nft -f /etc/nftables.conf ;; \
12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \
esac'
+10
View File
@@ -0,0 +1,10 @@
[Unit]
Description=Run xray-lists update
[Timer]
OnBootSec=5min
OnUnitActiveSec=12h
Persistent=true
[Install]
WantedBy=timers.target
+15 -5
View File
@@ -1,16 +1,26 @@
---
- name: reload nftables
ansible.builtin.command: nft -f /etc/nftables.conf
listen: reload nftables
- name: restart dnsmasq
ansible.builtin.service:
name: dnsmasq
state: restarted
- name: restart xray-lists timer
ansible.builtin.systemd:
- name: run xray-lists systemd timer unit
ansible.builtin.systemd_service:
name: xray-lists.timer
daemon_reload: true
state: started
enabled: true
- name: update xray-lists
ansible.builtin.systemd_service:
name: xray-lists.service
state: started
- name: restart xray-lists timer
ansible.builtin.systemd_service:
name: xray-lists.timer
daemon_reload: true
state: restarted
daemon_reload: yes
listen: restart xray-lists timer
+12 -23
View File
@@ -1,33 +1,22 @@
---
#- name: collect xray policy hosts
# ansible.builtin.set_fact:
# _xray_hosts_with_policy: >-
# {{
# (_xray_hosts_with_policy | default([]))
# + [{'inventory_hostname': item, 'xray_policy': hostvars[item].xray_policy}]
# }}
# loop: "{{ groups[xray_managed_group] }}"
# when: hostvars[item].xray_policy is defined
#- name: validate xray policy sets
# ansible.builtin.assert:
# that:
# - (item.1.bypass | default(item.1.proxy)) == 'all' or
# (item.1.bypass | default(item.1.proxy)) in xray_ip_sets or
# (item.1.bypass | default(item.1.proxy)) in xray_domain_sets or
# (item.1.bypass | default(item.1.proxy)) in (xray_static_sets | default([]))
# fail_msg: "host {{ item.0.inventory_hostname }}: unknown xray set '{{ item.1.bypass | default(item.1.proxy) }}'"
# quiet: true
# loop: "{{ query('ansible.builtin.subelements', _xray_hosts_with_policy | default([]), 'xray_policy', {'skip_missing': True}) }}"
# loop_control:
# label: "{{ item.0.inventory_hostname }} -> {{ item.1.bypass | default(item.1.proxy) }}"
- name: ensure /etc/nftables.d exists
ansible.builtin.file:
path: /etc/nftables.d
state: directory
mode: "0755"
- name: render xray-lists config
ansible.builtin.template:
src: xray-config.yaml.j2
dest: /var/lib/xray-lists/config.yaml
mode: "0640"
notify: restart xray-lists timer
register: xray_lists_config
- name: update xray-lists
ansible.builtin.systemd_service:
name: xray-lists.service
state: started
when: xray_lists_config.changed
- name: bootstrap empty config files
ansible.builtin.copy:
+14 -61
View File
@@ -18,9 +18,14 @@
- /opt/xray-lists
- /var/lib/xray-lists
- name: create python venv for xray-lists
command: python3 -m venv /opt/xray-lists/venv
args:
creates: /opt/xray-lists/venv/bin/pip
- name: clone xray-lists repository
git:
repo: 'https://gitea.oyacoi.ru/pyrschtjag/xray-lists'
repo: "http://10.1.0.104:3000/pyrschtjag/xray-lists.git"
dest: /opt/xray-lists-src
version: main
force: yes
@@ -37,72 +42,20 @@
- name: deploy update helper script
copy:
src: update.sh
dest: /var/lib/xray-lists/update.sh
owner: root
group: root
mode: '0755'
content: |
#!/bin/sh
set -e
out=$(/opt/xray-lists/venv/bin/xray-lists)
echo "$out"
dns_changed=0
elements_changed=0
if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi
if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi
if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12;
elif [ "$dns_changed" -eq 1 ]; then exit 10;
elif [ "$elements_changed" -eq 1 ]; then exit 11;
fi
exit 0
- name: deploy systemd service unit
- name: deploy systemd service and timer unit
copy:
dest: /etc/systemd/system/xray-lists.service
src: "{{ item }}"
dest: "/etc/systemd/system/{{ item }}"
owner: root
group: root
mode: '0644'
content: |
[Unit]
Description=Update Xray lists
[Service]
Type=oneshot
ExecStart=/bin/sh -c '\
/var/lib/xray-lists/update.sh; \
rc=$$?; \
case "$$rc" in \
10) systemctl restart dnsmasq ;; \
11) nft -f /etc/nftables.conf ;; \
12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \
esac'
- name: deploy systemd timer unit
copy:
dest: /etc/systemd/system/xray-lists.timer
owner: root
group: root
mode: '0644'
content: |
[Unit]
Description=Run xray-lists update daily and on boot
[Timer]
OnBootSec=5min
OnUnitActiveSec=12h
Persistent=true
[Install]
WantedBy=timers.target
- name: enable and start xray-lists
ansible.builtin.systemd:
name: xray-lists.timer
enabled: true
state: started
loop:
- xray-lists.service
- xray-lists.timer
notify: run xray-lists systemd timer unit
@@ -10,7 +10,7 @@
invalid_xray_set_{{ name }}
{% endif %}
{% endmacro %}
{% for item in groups[xray_managed_group] | default([]) | sort %}
{% for item in xray_managed_group | default([]) | sort %}
{% set client = hostvars[item] %}
{% if client.xray_policy is defined %}
{% set src_ip = client.container_ip %}
+1 -1
View File
@@ -4,7 +4,7 @@ set {{ id }}_ip {
type ipv4_addr
flags interval
auto-merge
include "{{ xray_lists_global.output_dir }}/{{ id }}.elements.nft"
include "{{ xray_lists_global.output_dir }}/{{ id }}_ip.elements.nft"
}
{% endfor -%}
{%- for id, item in xray_domain_sets.items() -%}
@@ -6,9 +6,9 @@ global:
{% if xray_lists_global.proxy is defined %}
proxy: "{{ xray_lists_global.proxy }}"
{% endif %}
{% if xray_lists_global.proxy_user is defined %}
proxy_user: "{{ xray_lists_global.proxy_user }}"
proxy_pass: "{{ xray_lists_global.proxy_pass }}"
{% if proxy_user is defined %}
proxy_user: "{{ proxy_user }}"
proxy_pass: "{{ proxy_pass }}"
{% endif %}
http_timeout: {{ xray_lists_global.http_timeout | default(20) }}
ip_sets:
+10
View File
@@ -0,0 +1,10 @@
---
- name: reload nftables
ansible.builtin.command: nft -f /etc/nftables.conf
- name: restart zerotier-one systemd service unit
ansible.builtin.systemd_service:
name: zerotier-one
daemon_reload: true
state: restarted
enabled: true
+31
View File
@@ -0,0 +1,31 @@
---
- name: create networks.d directory
ansible.builtin.file:
path: /var/lib/zerotier-one/networks.d
state: directory
mode: 0700
owner: zerotier-one
group: zerotier-one
- name: check if zerotier-one network config exists
ansible.builtin.stat:
path: "/var/lib/zerotier-one/networks.d/{{ zerotier_network_id }}.conf"
register: zerotier_network_stat
- name: create zerotier-one network config
ansible.builtin.file:
path: "/var/lib/zerotier-one/networks.d/{{ zerotier_network_id }}.conf"
state: touch
mode: "0600"
owner: zerotier-one
group: zerotier-one
when: not zerotier_network_stat.stat.exists
register: zerotier_network
- name: restart zerotier-one systemd service unit
ansible.builtin.systemd_service:
name: zerotier-one
daemon_reload: true
state: restarted
enabled: true
when: zerotier_network.changed
+16
View File
@@ -0,0 +1,16 @@
---
- name: add zerotier repository
ansible.builtin.deb822_repository:
name: zerotier
types: deb
uris: "http://download.zerotier.com/debian/trixie"
suites: "trixie"
components: main
signed_by: "https://download.zerotier.com/contact%40zerotier.com.gpg"
state: present
- name: install zerotier-one
ansible.builtin.apt:
name: zerotier-one
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
+17
View File
@@ -0,0 +1,17 @@
[Interface]
PrivateKey = {{ wg_private_key }}
Address = {{ wg_address }}
Table = off
PostUp = ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
PostUp = ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
PostUp = ip route add default dev wg0 table 199 2>/dev/null || true
PreDown = ip route del default dev wg0 table 199 2>/dev/null || true
PreDown = ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
PreDown = ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
[Peer]
PublicKey = {{ wg_public_key }}
PresharedKey = {{ wg_presharedkey }}
Endpoint = {{ wg_endpoint_address }}:{{ wg_endpoint_port }}
PersistentKeepalive = 25
AllowedIPs = 0.0.0.0/0
+7
View File
@@ -0,0 +1,7 @@
- name: manage zfs dataset permissions
ansible.builtin.file:
path: "/{{ item.name }}"
owner: "100000"
group: "100000"
loop: "{{ zfs }}"
when: item.state | default('present') != 'absent'
+6
View File
@@ -0,0 +1,6 @@
---
- name: include zfs
ansible.builtin.include_tasks: zfs.yml
- name: include file
ansible.builtin.include_tasks: file.yml
+6
View File
@@ -0,0 +1,6 @@
- name: manage zfs datasets
community.general.zfs:
name: "{{ item.name }}"
state: "{{ item.state | default('present') }}"
extra_zfs_properties: "{{ item.extra_zfs_properties | default(omit) }}"
loop: "{{ zfs }}"