add nginx, sshd, ssl roles

This commit is contained in:
2026-09-20 22:14:56 +00:00
parent ba9e1a664f
commit c640406c10
131 changed files with 1535 additions and 780 deletions
+7
View File
@@ -0,0 +1,7 @@
{
"dns": {
"tag": "dns-in",
"servers": ["localhost"],
"queryStrategy": "UseIPv4"
}
}
@@ -0,0 +1,35 @@
{
"inbounds": [
{
"tag": "tproxy-in",
"port": 61219,
"listen": "0.0.0.0",
"protocol": "dokodemo-door",
"settings": {
"followRedirect": true,
"network": "tcp,udp"
},
"streamSettings": {
"sockopt": {
"tproxy": "tproxy"
}
}
},
{
"tag": "socks-in",
"ip": "127.0.0.1",
"port": 1080,
"protocol": "socks",
"settings": {
"auth": "password",
"accounts": [
{
"user": "embargo",
"pass": "moistnes12"
}
],
"udp": true
}
}
]
}
+9
View File
@@ -0,0 +1,9 @@
{
"log": {
"access": "/var/log/xray-core/access.log",
"error": "/var/log/xray-core/error.log",
"loglevel": "warning",
"dnsLog": false,
"maskAddress": ""
}
}
+23
View File
@@ -0,0 +1,23 @@
{
"policy": {
"levels": {
"0": {
"handshake": 4,
"connIdle": 300,
"uplinkOnly": 2,
"downlinkOnly": 5,
"statsUserUplink": false,
"statsUserDownlink": false,
"statsUserOnline": false,
"bufferSize": 512
}
},
"system": {
"statsInboundUplink": false,
"statsInboundDownlink": false,
"statsOutboundUplink": false,
"statsOutboundDownlink": false
}
}
}
+5 -1
View File
@@ -6,12 +6,16 @@ Wants=network-online.target
[Service]
Type=simple
User=root
User=xray-core
Group=xray-core
WorkingDirectory=/opt/xray-core
ExecStart=/opt/xray-core/xray -confdir /opt/xray-core/config
Restart=on-failure
RestartSec=3s
LimitNOFILE=65535
AmbientCapabilities=CAP_NET_BIND_SERVICE CAP_NET_ADMIN
CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_NET_ADMIN
NoNewPrivileges=true
[Install]
WantedBy=multi-user.target
+13
View File
@@ -0,0 +1,13 @@
---
- name: validate xray-core config
ansible.builtin.command: su -s /bin/sh xray-core -c "/opt/xray-core/xray run -test -confdir /opt/xray-core/config"
changed_when: false
listen: restart xray-core
- name: restart xray-core systemd service unit
ansible.builtin.systemd_service:
name: xray-core
daemon_reload: true
state: restarted
enabled: true
listen: restart xray-core
+36
View File
@@ -0,0 +1,36 @@
---
- name: ensure /opt/xray-core/config exists
ansible.builtin.file:
path: /opt/xray-core/config
state: directory
owner: xray-core
group: xray-core
mode: "0755"
- name: ensure /var/log/xray-core exists
ansible.builtin.file:
path: /var/log/xray-core
state: directory
owner: xray-core
group: xray-core
mode: "0755"
- name: deploy xray-core static config
ansible.builtin.copy:
src: "{{ item }}"
dest: "/opt/xray-core/config/{{ item | basename }}"
owner: xray-core
group: xray-core
mode: "0644"
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.jsonc') }}"
notify: restart xray-core
- name: render xray-core dynamic config
ansible.builtin.template:
src: "{{ item }}"
dest: "/opt/xray-core/config/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: xray-core
group: xray-core
mode: "0644"
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.jsonc.j2') }}"
notify: restart xray-core
+6 -1
View File
@@ -10,6 +10,7 @@
return_content: yes
register: xray_release
run_once: true
check_mode: false
- name: set current xray-core version
ansible.builtin.set_fact:
@@ -25,6 +26,8 @@
- name: ensure xray-core directory exists
ansible.builtin.file:
path: /opt/xray-core
owner: xray-core
group: xray-core
state: directory
mode: '0755'
@@ -33,10 +36,12 @@
src: "{{ xray_asset_url }}"
dest: /opt/xray-core
remote_src: yes
owner: xray-core
group: xray-core
when: xray_version not in (xray_current_version.stdout | default(''))
- name: deploy xray-core systemd service unit
ansible.builtin.copy:
src: xray-core.service
dest: /etc/systemd/system/xray-core.service
mode: 755
mode: 0644
+6
View File
@@ -1,3 +1,9 @@
---
- name: include xray-core user
ansible.builtin.include_tasks: user.yml
- name: include xray-core install
ansible.builtin.include_tasks: install.yml
- name: include xray-core configure
ansible.builtin.include_tasks: configure.yml
+16
View File
@@ -0,0 +1,16 @@
---
- name: create xray-core system group
ansible.builtin.group:
name: xray-core
system: true
state: present
- name: create xray-core system user
ansible.builtin.user:
name: xray-core
group: xray-core
system: true
shell: /usr/sbin/nologin
home: /opt/xray-core
create_home: false
state: present
@@ -0,0 +1,8 @@
{
"observatory": {
"subjectSelector": ["vless-"],
"probeUrl": "https://www.google.com/generate_204",
"probeInterval": "30s",
"enableConcurrency": true
}
}
@@ -0,0 +1,57 @@
{
"outbounds": [
{% for item in xray_outbounds %}
{
"tag": "vless-{{ item.tag }}",
"protocol": "vless",
"settings": {
"vnext": [
{
"address": "{{ item.address }}",
"port": 443,
"users": [
{
"id": "{{ xray_id }}",
"flow": "xtls-rprx-vision",
"encryption": "{{ xray_encryption }}"
}
]
}
],
"domainStrategy": "UseIPv4"
},
"streamSettings": {
"network": "xhttp",
"xhttpSettings": {
"path": "{{ xray_xhttp_path }}",
"mode": "stream-one"
},
"security": "tls",
"tlsSettings": {
"alpn": [
"h2",
"h3"
],
"fingerprint": "firefox"
}
}
},
{% endfor %}
{
"tag": "direct",
"protocol": "freedom",
"settings": {
"domainStrategy": "UseIPv4"
}
},
{
"tag": "blocked",
"protocol": "blackhole",
"settings": {
"response": {
"type": "none"
}
}
}
]
}
@@ -0,0 +1,41 @@
{
"routing": {
"domainStrategy": "IPIfNonMatch",
{% if xray_outbounds | length > 1 %}
"balancers": [
{
"tag": "balancer-vless",
"selector": ["vless-"],
"strategy": {
"type": "leastLoad",
"settings": {
"costs": [
{% for item in xray_outbounds %}
{
"match": "vless-{{ item.tag }}",
"value": {{ item.value }}
}{{ "," if not loop.last else "" }}
{% endfor %}
]
}
}
}
],
{% endif %}
"rules": [
{
"type": "field",
"protocol": ["bittorrent"],
"outboundTag": "direct"
},
{
"type": "field",
"inboundTag": [
"tproxy-in",
"socks-in"
],
"balancerTag": "{{ 'balancer-vless' if xray_outbounds | length > 1 else 'vless-' ~ xray_outbounds[0].tag }}"
}
]
}
}