refactor: restructure inventory, split roles and add new services

This commit is contained in:
2026-09-07 19:50:34 +00:00
parent 33ddc88ee9
commit ba9e1a664f
114 changed files with 1117 additions and 418 deletions
+19
View File
@@ -0,0 +1,19 @@
#!/bin/sh
set -e
out=$(/opt/xray-lists/venv/bin/xray-lists)
echo "$out"
dns_changed=0
elements_changed=0
if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi
if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi
if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12;
elif [ "$dns_changed" -eq 1 ]; then exit 10;
elif [ "$elements_changed" -eq 1 ]; then exit 11;
fi
exit 0
+13
View File
@@ -0,0 +1,13 @@
[Unit]
Description=Update Xray lists
[Service]
Type=oneshot
ExecStart=/bin/sh -c '\
/var/lib/xray-lists/update.sh; \
rc=$$?; \
case "$$rc" in \
10) systemctl restart dnsmasq ;; \
11) nft -f /etc/nftables.conf ;; \
12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \
esac'
+10
View File
@@ -0,0 +1,10 @@
[Unit]
Description=Run xray-lists update
[Timer]
OnBootSec=5min
OnUnitActiveSec=12h
Persistent=true
[Install]
WantedBy=timers.target
+15 -5
View File
@@ -1,16 +1,26 @@
---
- name: reload nftables
ansible.builtin.command: nft -f /etc/nftables.conf
listen: reload nftables
- name: restart dnsmasq
ansible.builtin.service:
name: dnsmasq
state: restarted
- name: restart xray-lists timer
ansible.builtin.systemd:
- name: run xray-lists systemd timer unit
ansible.builtin.systemd_service:
name: xray-lists.timer
daemon_reload: true
state: started
enabled: true
- name: update xray-lists
ansible.builtin.systemd_service:
name: xray-lists.service
state: started
- name: restart xray-lists timer
ansible.builtin.systemd_service:
name: xray-lists.timer
daemon_reload: true
state: restarted
daemon_reload: yes
listen: restart xray-lists timer
+12 -23
View File
@@ -1,33 +1,22 @@
---
#- name: collect xray policy hosts
# ansible.builtin.set_fact:
# _xray_hosts_with_policy: >-
# {{
# (_xray_hosts_with_policy | default([]))
# + [{'inventory_hostname': item, 'xray_policy': hostvars[item].xray_policy}]
# }}
# loop: "{{ groups[xray_managed_group] }}"
# when: hostvars[item].xray_policy is defined
#- name: validate xray policy sets
# ansible.builtin.assert:
# that:
# - (item.1.bypass | default(item.1.proxy)) == 'all' or
# (item.1.bypass | default(item.1.proxy)) in xray_ip_sets or
# (item.1.bypass | default(item.1.proxy)) in xray_domain_sets or
# (item.1.bypass | default(item.1.proxy)) in (xray_static_sets | default([]))
# fail_msg: "host {{ item.0.inventory_hostname }}: unknown xray set '{{ item.1.bypass | default(item.1.proxy) }}'"
# quiet: true
# loop: "{{ query('ansible.builtin.subelements', _xray_hosts_with_policy | default([]), 'xray_policy', {'skip_missing': True}) }}"
# loop_control:
# label: "{{ item.0.inventory_hostname }} -> {{ item.1.bypass | default(item.1.proxy) }}"
- name: ensure /etc/nftables.d exists
ansible.builtin.file:
path: /etc/nftables.d
state: directory
mode: "0755"
- name: render xray-lists config
ansible.builtin.template:
src: xray-config.yaml.j2
dest: /var/lib/xray-lists/config.yaml
mode: "0640"
notify: restart xray-lists timer
register: xray_lists_config
- name: update xray-lists
ansible.builtin.systemd_service:
name: xray-lists.service
state: started
when: xray_lists_config.changed
- name: bootstrap empty config files
ansible.builtin.copy:
+14 -61
View File
@@ -18,9 +18,14 @@
- /opt/xray-lists
- /var/lib/xray-lists
- name: create python venv for xray-lists
command: python3 -m venv /opt/xray-lists/venv
args:
creates: /opt/xray-lists/venv/bin/pip
- name: clone xray-lists repository
git:
repo: 'https://gitea.oyacoi.ru/pyrschtjag/xray-lists'
repo: "http://10.1.0.104:3000/pyrschtjag/xray-lists.git"
dest: /opt/xray-lists-src
version: main
force: yes
@@ -37,72 +42,20 @@
- name: deploy update helper script
copy:
src: update.sh
dest: /var/lib/xray-lists/update.sh
owner: root
group: root
mode: '0755'
content: |
#!/bin/sh
set -e
out=$(/opt/xray-lists/venv/bin/xray-lists)
echo "$out"
dns_changed=0
elements_changed=0
if echo "$out" | grep -A 10 "changed:" | grep -q "nftsets.conf"; then dns_changed=1; fi
if echo "$out" | grep -A 10 "changed:" | grep -q "\.elements\.nft"; then elements_changed=1; fi
if [ "$dns_changed" -eq 1 ] && [ "$elements_changed" -eq 1 ]; then exit 12;
elif [ "$dns_changed" -eq 1 ]; then exit 10;
elif [ "$elements_changed" -eq 1 ]; then exit 11;
fi
exit 0
- name: deploy systemd service unit
- name: deploy systemd service and timer unit
copy:
dest: /etc/systemd/system/xray-lists.service
src: "{{ item }}"
dest: "/etc/systemd/system/{{ item }}"
owner: root
group: root
mode: '0644'
content: |
[Unit]
Description=Update Xray lists
[Service]
Type=oneshot
ExecStart=/bin/sh -c '\
/var/lib/xray-lists/update.sh; \
rc=$$?; \
case "$$rc" in \
10) systemctl restart dnsmasq ;; \
11) nft -f /etc/nftables.conf ;; \
12) nft -f /etc/nftables.conf && systemctl restart dnsmasq ;; \
esac'
- name: deploy systemd timer unit
copy:
dest: /etc/systemd/system/xray-lists.timer
owner: root
group: root
mode: '0644'
content: |
[Unit]
Description=Run xray-lists update daily and on boot
[Timer]
OnBootSec=5min
OnUnitActiveSec=12h
Persistent=true
[Install]
WantedBy=timers.target
- name: enable and start xray-lists
ansible.builtin.systemd:
name: xray-lists.timer
enabled: true
state: started
loop:
- xray-lists.service
- xray-lists.timer
notify: run xray-lists systemd timer unit
@@ -10,7 +10,7 @@
invalid_xray_set_{{ name }}
{% endif %}
{% endmacro %}
{% for item in groups[xray_managed_group] | default([]) | sort %}
{% for item in xray_managed_group | default([]) | sort %}
{% set client = hostvars[item] %}
{% if client.xray_policy is defined %}
{% set src_ip = client.container_ip %}
+1 -1
View File
@@ -4,7 +4,7 @@ set {{ id }}_ip {
type ipv4_addr
flags interval
auto-merge
include "{{ xray_lists_global.output_dir }}/{{ id }}.elements.nft"
include "{{ xray_lists_global.output_dir }}/{{ id }}_ip.elements.nft"
}
{% endfor -%}
{%- for id, item in xray_domain_sets.items() -%}
@@ -6,9 +6,9 @@ global:
{% if xray_lists_global.proxy is defined %}
proxy: "{{ xray_lists_global.proxy }}"
{% endif %}
{% if xray_lists_global.proxy_user is defined %}
proxy_user: "{{ xray_lists_global.proxy_user }}"
proxy_pass: "{{ xray_lists_global.proxy_pass }}"
{% if proxy_user is defined %}
proxy_user: "{{ proxy_user }}"
proxy_pass: "{{ proxy_pass }}"
{% endif %}
http_timeout: {{ xray_lists_global.http_timeout | default(20) }}
ip_sets: