refactor: restructure inventory, split roles and add new services
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
---
|
||||
- name: restart wg0 systemd service unit
|
||||
ansible.builtin.systemd_service:
|
||||
name: wg-quick@wg0
|
||||
daemon_reload: true
|
||||
state: restarted
|
||||
enabled: true
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
- name: ensure /etc/wireguard exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/wireguard
|
||||
state: directory
|
||||
mode: "0700"
|
||||
|
||||
- name: deploy wireguard config
|
||||
ansible.builtin.template:
|
||||
src: "wg0.conf.j2"
|
||||
dest: "/etc/wireguard/wg0.conf"
|
||||
mode: "0644"
|
||||
register: wg0_conf
|
||||
|
||||
- name: restart wg0 systemd service unit
|
||||
ansible.builtin.systemd_service:
|
||||
name: wg-quick@wg0
|
||||
daemon_reload: true
|
||||
state: restarted
|
||||
enabled: true
|
||||
when: wg0_conf.changed
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install wireguard-tools
|
||||
ansible.builtin.apt:
|
||||
name: wireguard-tools
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include wireguard-tools install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include wireguard-tools configurure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,17 @@
|
||||
[Interface]
|
||||
PrivateKey = {{ wg_private_key }}
|
||||
Address = {{ wg_address }}
|
||||
Table = off
|
||||
PostUp = ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
|
||||
PostUp = ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
|
||||
PostUp = ip route add default dev wg0 table 199 2>/dev/null || true
|
||||
PreDown = ip route del default dev wg0 table 199 2>/dev/null || true
|
||||
PreDown = ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
|
||||
PreDown = ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
|
||||
|
||||
[Peer]
|
||||
PublicKey = {{ wg_public_key }}
|
||||
PresharedKey = {{ wg_presharedkey }}
|
||||
Endpoint = {{ wg_endpoint_address }}:{{ wg_endpoint_port }}
|
||||
PersistentKeepalive = 25
|
||||
AllowedIPs = 0.0.0.0/0
|
||||
Reference in New Issue
Block a user