add nginx, sshd, ssl roles

This commit is contained in:
2026-09-20 22:14:56 +00:00
parent ba9e1a664f
commit c640406c10
131 changed files with 1535 additions and 780 deletions
@@ -0,0 +1,9 @@
setuid = stunnel4
setgid = stunnel4
pid = /var/run/stunnel4/absinthe.pid
output = /var/log/stunnel4/absinthe.log
[openvpn]
cert = /etc/letsencrypt/live/absinthe.oyacoi.ru/fullchain.pem
key = /etc/letsencrypt/live/absinthe.oyacoi.ru/privkey.pem
accept = 127.0.0.1:8444
connect = 127.0.0.1:1195
@@ -0,0 +1,9 @@
setuid = stunnel4
setgid = stunnel4
pid = /var/run/stunnel4/liqueur.pid
output = /var/log/stunnel4/liqueur.log
[openvpn]
cert = /etc/letsencrypt/live/liqueur.oyacoi.ru/fullchain.pem
key = /etc/letsencrypt/live/liqueur.oyacoi.ru/privkey.pem
accept = 127.0.0.1:8443
connect = 127.0.0.1:1194
+6
View File
@@ -0,0 +1,6 @@
---
- name: restart stunnel4
ansible.builtin.service:
name: stunnel4
state: restarted
listen: restart stunnel4
+36
View File
@@ -0,0 +1,36 @@
---
- name: ensure /var/run/stunnel exists
ansible.builtin.file:
path: /var/run/stunnel
owner: stunnel4
group: stunnel4
state: directory
mode: "0755"
- name: ensure /var/log/stunnel exists
ansible.builtin.file:
path: /var/log/stunnel
state: directory
owner: stunnel4
group: stunnel4
mode: "0755"
- name: deploy stunnel config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/stunnel/{{ item | basename }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('fileglob', role_path + '/files/' + inventory_hostname + '/*.conf') }}"
notify: restart stunnel4
- name: render stunnel config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/stunnel/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
notify: restart stunnel4
+6
View File
@@ -0,0 +1,6 @@
---
- name: install stunnel4
ansible.builtin.apt:
name: stunnel4
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,9 @@
setuid = stunnel4
setgid = stunnel4
pid = /var/run/stunnel/absinthe.pid
output = /var/log/stunnel/absinthe.log
client = yes
[openvpn]
sni = absinthe.oyacoi.ru
accept = 127.0.0.1:1195
connect = {{ hostvars['liqueur'].container_ip }}:443
@@ -0,0 +1,9 @@
setuid = stunnel4
setgid = stunnel4
pid = /var/run/stunnel/liqueur.pid
output = /var/log/stunnel/liqueur.log
client = yes
[openvpn]
sni = liqueur.oyacoi.ru
accept = 127.0.0.1:1194
connect = {{ hostvars['liqueur'].container_ip }}:443