Compare commits

..

No commits in common. "main" and "pangolin" have entirely different histories.

58 changed files with 98 additions and 945 deletions

View File

@ -444,7 +444,7 @@ interpreter_python=auto_silent
;become_ask_pass=False
# (string) executable to use for privilege escalation, otherwise Ansible will depend on PATH.
;become_exe=sudo.ws
;become_exe=
# (string) Flags to pass to the privilege escalation executable.
;become_flags=

View File

@ -1,34 +1,7 @@
---
new_sudo:
hosts:
hserve1:
hserve2:
mini1:
backs.hassallab.it:
distributed:
children:
pangolin:
hosts:
edge1:
ansible_host: 172.104.128.23
authentik:
hosts:
mini1:
ansible_host: 192.168.1.66
nextcloud:
hosts:
hserve2:
ansible_host: 192.168.1.130
nginx:
hosts:
hserve1:
ansible_host: 192.168.1.142
forgejo:
hosts:
hserve1:
borg:
hosts:
backs.hassallab.it:
ansible_host: 172.104.128.23

View File

@ -1,8 +1,5 @@
---
ansible_user: ansible
ansible_group: ansible
ansible_user_uid: 1100
ansible_group_uid: 1100
to_set_authorized_keys:
- label: hassallah
key: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEArNhKFcJ6T08sn7kTTLf+rO9HEvgOvqfhv5HQ2sRf2tFYfjfCb0zHKnMkgW+sy5gMU10Lyx1r7juXCvqRC955uIM97m1B1Xc6sVqASVKuGPhCKfhxEaMAyBcWFdE+HYbCOPYVN+JMrcwWfbblwiZTtK1OCqaEUvDDI7cFeU68noXwggEp46T48eqMUdi541D9Y+BVx9HYAo6OCQz0+6eXwxJL+tpRcAAXIMMWv362CYHoOgIU45R7xVSMLY1k/HLrcEAblwxEaSpduCH5cWUXZE/56IyxpvP44BxZkVhNdqJLmg4hxBQWhoMNYiTZxbLay3W2TwBCM111cAtUx4M/jQ=="

View File

@ -1,2 +0,0 @@
---
borg_backup_server: backs.hassallab.it

View File

@ -1,3 +0,0 @@
---
docker_users:
- "{{ ansible_user }}"

View File

@ -1,2 +0,0 @@
---
become_exe_value: "sudo"

View File

@ -1,3 +0,0 @@
---
pangolin_secret: "{{ pangolin_crypted_secret }}"
base_domain: "hassallab.it"

View File

@ -1,38 +1,15 @@
$ANSIBLE_VAULT;1.1;AES256
37383965623033356461393931656332323239323065326639613132306337393864366132366436
3130323864613235326338663735303931343363616435310a613164376464353130656539663036
31306261346331623261363533306336663731383664356136366662393632383136353338616130
6365626664643733620a323563316331663638333566653363323733373839656330333930363161
64666538656164653230633031663636343639393432326531343639356438316335633364633739
63303236313861383532386365613938303763373934303230626366636639643433646631343163
64316264616237336239346237643065396335313938373734613065383133616532626162393033
34613661353537373464643964356138653033623764353662386265316135353738353837616463
32653161303034363563373136303633326130643263653532313166383061306662333662623166
31363630303466353062356530383864666133376262333030323837313561653262313434663465
64376566346536303137646561316438346335343864346139653561663362613861633131393336
63346631373336666633386533313261366166663136306531333638363365383833643965613435
39376430653239323438613062653435653337663534633933323663613035643466303231346130
30643862633464663334386565356432323132336333653633373232333363653734666264333733
34333162333439336361313236313161626331396266653238313737656361663736383165393439
63326234626533663238353264353736303166383366633038373437366463666263616564303166
64393465396364313932316138393839613538343231343734336363663536646632373431623130
38653339396134303861636162326531616332353735336330623035633864323238333761363335
39373664613736613961666161323566303030656461623331353931363961323366653038656130
33356664353635343962343662313063633938343833643938626234383831363536623363366663
39343035393362326530316233303137616532356664353035393462306238303738653131346264
62636465613062326436333830306264656461356331306262363230336231643566633861633161
64393533313535333832343136343131376239363063613530383335326132336433626563333633
36386163613163616538643337666131663535333134626535613734393061653033633734613837
30373065623564333035616566373038393330613933623235613837383039626537653964366362
36643963373134613965333764396162303562633935633736633531336631353638613833643834
37366566663635323739643661393433353538636165623435356366333438393162393239363430
34626331303439343135353834336134396133636532643333336266626365616166363237376364
35323631656263343630643062376131386132356139623561653536313036316261323938636562
63343030623033373563626538383862626136343965613162326439316436306133663066656161
62393839326134613436626163626565303364373362356631363166316461323734323532623461
37303438666161653833363263633963323137303463343434363338303034303238313136343237
38346566613865646236343332666230356135343638623031383963666662336131616462383634
37383635376661386461306362373631373731313433643038316661613934663232666236613061
34353631323132353434623065613238383235316135373338383463626137313530366334333034
66613531646233643563336530623733343438666136383931363431306663383361313134646466
62623262643232356438653633306466383638336137366363336564643532623239
35316234643930663465333664613362323061613838343333313331636366616163366162303165
3565383837343936306536633765616638646437356562630a396536396664303736303965383863
64383632386534316230366337633462613336666636633138626438336163373138616363323835
3137666361653932390a393432313565323939356232376430393762336136613762363036343961
36613462636630626430303636613130346533336534386165633232326238366134376233613466
35613338333035623237303336653137333133666234643466643166633636343234616430346130
31643238653833663761326262626536636537666162653863363934363165323134646564653736
65663334363037636266383930356664356531356664303261333539636462356533396634616130
63336431376532323630323531386437313639393639353332393061633764613030613261393862
36373738613136663165623834376462356139353932626364366164643038323665346639346462
30356166343639653632313833333565393436633733346136653538663235636333383333313533
31306634366535306464313738356662646130363662653062366635333837666464633330393038
31376561323264633063616530656661396331353165626135366462373663346333373131396535
6430326664303432393137353864366339366639643332356134

View File

@ -1,4 +0,0 @@
configure_borg_server: true
borg_auth_users:
- host: fabotest
key: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEArNhKFcJ6T08sn7kTTLf+rO9HEvgOvqfhv5HQ2sRf2tFYfjfCb0zHKnMkgW+sy5gMU10Lyx1r7juXCvqRC955uIM97m1B1Xc6sVqASVKuGPhCKfhxEaMAyBcWFdE+HYbCOPYVN+JMrcwWfbblwiZTtK1OCqaEUvDDI7cFeU68noXwggEp46T48eqMUdi541D9Y+BVx9HYAo6OCQz0+6eXwxJL+tpRcAAXIMMWv362CYHoOgIU45R7xVSMLY1k/HLrcEAblwxEaSpduCH5cWUXZE/56IyxpvP44BxZkVhNdqJLmg4hxBQWhoMNYiTZxbLay3W2TwBCM111cAtUx4M/jQ== fabio@pc-fabio"

View File

@ -1,2 +0,0 @@
---
become_exe_value: "sudo.ws"

View File

@ -1,7 +0,0 @@
---
pangolin_mail_host: "smtp.ionos.it"
pangolin_mail_port: 587
pangolin_mail_user: "system@hassallab.it"
pangolin_mail_password: "{{ pangolin_mail_crypted_password }}"
pangolin_no_reply_address: "system@hassallab.it"
pangolin_mail_secure_flag: false

View File

@ -0,0 +1,14 @@
---
pangolin_dashboard_url: "https://pangolin.hassallab.it"
pangolin_base_domain: "hassallab.it"
pangolin_secret: "{{ pangolin_crypted_secret }}"
pangolin_admin_email: "hassallah@mail.com"
pangolin_gerbil_subnet_group: "10.42.0.0/16"
# Email (SMTP) settings
pangolin_email_smtp_host: "mail.com"
pangolin_email_smtp_port: 587
pangolin_email_smtp_user: "pango.lin@mail.com"
pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
pangolin_email_no_reply: "no-reply@mail.com"

View File

@ -1,3 +0,0 @@
---
configure_swap: true
ip_tables_config: true

View File

@ -1,14 +0,0 @@
---
pangolin_dashboard_url: "https://pangolin.{{ base_domain}}"
pangolin_base_domain: "{{ base_domain }}"
pangolin_secret: "{{ pangolin_crypted_secret }}"
pangolin_admin_email: "hassallah@mail.com"
pangolin_gerbil_subnet_group: "10.42.0.0/16"
# # Email (SMTP) settings
# pangolin_email_smtp_host: "mail.com"
# pangolin_email_smtp_port: 587
# pangolin_email_smtp_user: "pango.lin@mail.com"
# pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
# pangolin_email_no_reply: "no-reply@mail.com"

View File

@ -1,18 +0,0 @@
---
pangolin_site_id: 7drc3dz2bg5gbq5
newt_secret: "{{ test_nginx_newt_secret }}"
forgejo_db_password : "{{ forgejo_db_crypted_password }}"
configure_borg_client: true
borg_repos:
- name: web
borg_passphrase: "{{ hserve1_backup_web_crypted_password }}"
paths_to_backup:
- "/home/{{ ansible_user }}/web"
- name: test
borg_passphrase: "dummy_secret"
paths_to_backup:
- "/home/{{ ansible_user }}"
- "/proc/version"

View File

@ -1,4 +0,0 @@
---
pangolin_site_id: 5hraslci7wl46nj
newt_secret: "{{ hserve2_crypted_site_secret }}"
nextcloud_docker_mastercontainer_volume_dir: "/home/{{ ansible_user }}/docker_data/nextcloud_aio_mastercontainer"

View File

@ -1,17 +0,0 @@
---
pangolin_site_id: "original-steppe-polecat"
newt_compose_network: "proxy-network"
authentik_subdomain: "idp"
# The hostname at which authentik is served.
authentik_base_domain: "{{ base_domain }}"
authentik_secret_key: "{{ authentik_crypted_secret_key }}"
authentik_postgres_user: "authentik_ps"
authentik_postgres_password: "{{ authentik_crypted_postgres_password }}"
#authentik_api_token : "{{ authentik_crypted_token }}"
authentik_email_enabled: false
authentik_bootstrap_enabled: false

View File

@ -3,19 +3,7 @@
Qui vengono riportati i playbook disponibili, descrizione e utilizzo.
**NB** Ci si aspetta che i playbook siano idempotenti. In caso contrario e' importante riportarlo nella documentazione corrente.
### Summary
- [Bootstrap](#bootstrap)
- [VPN Server](#vpn-server)
- [Pangolin](#pangolin)
- [Forgejo](#forgejo)
- [Authentik](#authentik)
- [Nextcloud](#nextcloud)
- [Static Nginx Page](#static-nginx-page)
- [Borg Backups](#borg-backups)
### Bootstrap
Implementa la configurazione di base di un nodo per poter essere gestito dagli altri playbook, in particolare :
- crea l'utente ansible
- registra le chiavi ssh degli utenti configurati
@ -79,73 +67,7 @@ Il playbook installa docker e docker compose. Attraverso docker compose vengono
Il playbook utilizza :
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
- Il ruolo ***prepare_node***
- Il ruolo ***pangolin*** preso da [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main)
- I ruoli common e pangolin definiti in [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main), riportati staticamente come ruolo *pangolin*
I parametri attesi dal playbook sono quelli definiti nei ruoli da cui dipende.
### Forgejo
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [forgejo](https://forgejo.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
Il playbook utilizza :
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
- I ruoli ***forgejo*** e ***newt_client***
### Authentik
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [authentik](https://docs.goauthentik.io/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
Il playbook utilizza :
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
- [ax-bzh.authentik](https://galaxy.ansible.com/ui/standalone/roles/ax-bzh/authentik/documentation/) attraverso ***ansible galaxy***
- Il ruolo ***newt_client***
### Nextcloud
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nextcloud AIO](https://github.com/nextcloud/all-in-one) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
Il playbook utilizza :
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
- I ruoli ***newt_client*** e ***nextcloud_aio***
### Static Nginx Page
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nginx](https://nginx.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
Il playbook utilizza :
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
- I ruoli ***newt_client*** e ***nginx***
### Borg Backups
Il playbook configura sia i client che il server per i backup effettuati con [borg](https://www.borgbackup.org/). I client vengono risolti dinamicamente verificando la presenza della seguente configurazione in esempio:
```
configure_borg_client: True
borg_repos:
- name: test
borg_passphrase: "dummy_secret"
paths_to_backup:
- "/home/{{ ansible_user }}"
- "/proc/version"
```
Per ogni client vengono configurati :
- l'utente e relative credenziali per connettersi al borg server
- Un servizio systemd **borg\_backup.service** e relativo timer **borg\_backup.timer** per eseguire il backup
- Uno script che esegue effettivamente il backup **"/home/{{borg_user}}/backup\_script.sh"** verso *"ssh://{{ borg\_user }}@{{ borg\_backup_server }}/./"*
Sul server vengono configurati:
- L'utente con cui eseguire borg service
- Le credenziali attese utilizzate dai vari client e i rispettivi path permessi per eseguire i report.
Sul server i permessi concessi ai vari client vengono limitati definendo su ***/home/{{borg\_user}}/.ssh/authorized\_keys*** le limitazioni di path (accesso solo al proprio repo) e di operation (solo ***"borg serve"***) con la seguente istruzione :
```
command=\"cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}\",restrict
```
E' possibile configurare il server per servire borg anche con altre credenziali e path, per casi non coperti dal playbook (e.g. borg backups usato direttamente da Nextcloud AIO) attraverso il seguente attributo:
```
borg_auth_users:
- host: fabotest
key: "ssh-rsa ********"
```
Il playbook utilizza il role ***borg***

View File

@ -1,15 +0,0 @@
---
- name: Install / remove authentik
hosts: authentik
tasks:
- include_role:
name: geerlingguy.docker
apply:
become: true
become_exe: "{{ become_exe_value }}"
- include_role:
name: "{{ item }}"
loop :
- newt_client
- ax-bzh.authentik

View File

@ -2,7 +2,6 @@
- name: Bootstrap node
hosts: all
become: true
become_exe: "{{ become_exe_value }}"
tasks:
- name: Add the ansible group
ansible.builtin.group:
@ -27,7 +26,7 @@
- name: Set ansible user as sudoer
ansible.builtin.copy:
content: "ansible ALL = (ALL) NOPASSWD:ALL\n"
content: "ansible ALL = (ALL) NOPASSWD:ALL"
dest: /etc/sudoers.d/ansible
owner: root
group: root

View File

@ -1,30 +0,0 @@
---
- name: Evaluate borg client nodes
hosts: all
gather_facts: false
tasks:
- name: Gather configured clients
ansible.builtin.group_by:
key: "borg_clients_{{ configure_borg_client | default('False') }}"
# Creates: borg_clients_True and borg_clients_False
- name: Configure borg backups system
hosts: borg_clients_True:borg
debugger: on_failed
tasks:
- name: Configure clients
include_role:
name: borg
apply:
become: true
become_exe: "{{ become_exe_value }}"
when: "{{ configure_borg_client | default(false) }} "
- name: Configure server
include_role:
name: borg
apply:
become: true
become_exe: "{{ become_exe_value }}"
when: "{{ configure_borg_server | default(false) }} "

View File

@ -1,15 +0,0 @@
---
- name : Install Forgejo
hosts: forgejo
tasks:
- include_role:
name: geerlingguy.docker
apply:
become: true
become_exe: "{{ become_exe_value }}"
- include_role:
name: "{{ item }}"
loop :
- newt_client
- forgejo

View File

@ -1,15 +0,0 @@
---
- name: Install Nextcloud
hosts: nextcloud
tasks:
- include_role:
name: geerlingguy.docker
apply:
become: true
become_exe: "{{ become_exe_value }}"
- include_role:
name: "{{ item }}"
loop:
- newt_client
- nextcloud_aio

View File

@ -1,15 +1,7 @@
---
- name: Install and configure Pangolin
hosts: pangolin
tasks:
- include_role:
name: "{{ item }}"
apply:
become: true
become_exe: "{{ become_exe_value }}"
loop:
- geerlingguy.docker
- prepare_node
- include_role:
name: pangolin
become: true
roles:
- geerlingguy.docker
- pangolin

View File

@ -1,8 +0,0 @@
---
borg_user: borg
borg_group: borg
borg_home: "/home/{{ borg_user }}"
borg_pool: "{{ borg_home }}/repos"
borg_pool_dest : /usr/backups/borg_repos
borg_repo_base: "ssh://{{ borg_user }}@{{ borg_backup_server }}/./"
borg_auth_users: []

View File

@ -1,44 +0,0 @@
---
- name: Define backup script
ansible.builtin.template:
dest: "/home/{{borg_user}}/backup_script.sh"
src: templates/backup_script.sh.j2
owner: root
mode: "0701"
- name: Define backup service
ansible.builtin.template:
dest: /etc/systemd/system/borg_backup.service
src: templates/borg_backup.service.j2
owner: root
mode: "0700"
- name: Define backup timer
ansible.builtin.copy:
content: |
[Unit]
Description=Daily Backup Timer
[Timer]
OnCalendar=*-*-* 02:00:00
Persistent=true
RandomizedDelaySec=300
[Install]
WantedBy=timers.target
dest: /etc/systemd/system/borg_backup.timer
- name: Reload systemd
ansible.builtin.systemd_service:
daemon_reload: true
# Add entry in borg_auth_users for server configuration
# borg_auth_users:
# - host: fabotest
# # Chiave di esempio per test
# key: "ssh-rsa ****"
- name: Register public key for server configuration
set_fact:
borg_auth_users: "{{ borg_auth_users + [{'host': inventory_hostname, 'key':borg_user_definition.ssh_public_key}] }}"

View File

@ -1,52 +0,0 @@
---
- name: Set ssh directory
file:
path: "{{ borg_home }}/.ssh"
owner: "{{ borg_user }}"
group: "{{ borg_group }}"
mode: "0700"
state: directory
- name: Create pool directory
file:
path: "{{ borg_pool_dest}}"
owner: "{{ borg_user }}"
group: "{{ borg_group }}"
mode: "0700"
state: directory
- name: Set pool directory link
file:
src: "{{ borg_pool_dest }}"
dest: "{{ borg_pool }}"
state: link
- name: Gathering clients configurations
set_fact:
borg_auth_users: "{{ borg_auth_users + hostvars[item]['borg_auth_users']}}"
loop: "{{ groups['borg_clients_True'] }}"
- name: Creating pool sub directories
file:
path: "{{ borg_pool }}/{{ item.host }}"
owner: "{{ borg_user }}"
group: "{{ borg_group }}"
mode: "0700"
state: directory
with_items: "{{ borg_auth_users }}"
- name: Defining authorized_key
authorized_key:
user: "{{ borg_user }}"
key: "{{ item.key }}"
key_options: "command=\"cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}\",restrict"
with_items: "{{ borg_auth_users }}"
- name: Setting authorized keys file
file:
path: "{{ borg_home }}/.ssh/authorized_keys"
owner: "{{ borg_user }}"
group: "{{ borg_group }}"
mode: "0600"
state: file

View File

@ -1,9 +0,0 @@
---
- name: Prepare borg
include_tasks: prepare_borg.yaml
- name: Configure server
include_tasks: configure_borg_server.yaml
when: "{{ configure_borg_server | default(false) }}"
- name: Configure client
include_tasks: configure_borg_client.yaml
when: "{{ configure_borg_client | default(false) }} "

View File

@ -1,21 +0,0 @@
---
- name: Install borg and requirements
ansible.builtin.package:
name: borgbackup
state: present
- name: Set borg user group
group:
name: "{{ borg_group }}"
state: present
- name: Set borg user
user:
name: "{{ borg_user }}"
shell: /bin/bash
home: "{{ borg_home }}"
create_home: true
group: "{{ borg_group }}"
state: present
generate_ssh_key: "{{ configure_borg_client | default(false) }}"
register: borg_user_definition

View File

@ -1,86 +0,0 @@
#!/bin/bash
{% for repo_item in borg_repos %}
# Setting this, so the repo does not need to be given on the commandline:
export BORG_REPO="{{borg_repo_base}}{{repo_item.name}}"
# See the section "Passphrase notes" for more infos.
export BORG_PASSPHRASE="'{{ repo_item.borg_passphrase }}'"
# some helpers and error handling:
info() { logger "$*"; }
trap 'echo $( date ) Backup interrupted >&2; exit 2' INT TERM
info "Trying to initialize repo. NB returns error if already initialized"
borg init --encryption=repokey
info "Starting backup for repo {{repo_item.name}}"
# Backup the most important directories into an archive named after
# the machine this script is currently running on:
borg create \
--verbose \
--filter AME \
--list \
--stats \
--show-rc \
--compression lz4 \
--exclude-caches \
--exclude 'home/*/.cache/*' \
--exclude 'var/tmp/*' \
\
::"'{{ inventory_hostname }}-{now}'"\
{% for item in repo_item.paths_to_backup %}
{{ item }}\
{% endfor %}
backup_exit=$?
info "Pruning repository {{ repo_item.name }}"
# Use the `prune` subcommand to maintain 7 daily, 4 weekly and 6 monthly
# archives of THIS machine. The '{hostname}-*' matching is very important to
# limit prune's operation to this machine's archives and not apply to
# other machines' archives also:
borg prune \
--list \
--glob-archives "'{{ inventory_hostname }}-*'" \
--show-rc \
--keep-daily 7 \
--keep-weekly 4 \
--keep-monthly 6
prune_exit=$?
# actually free repo disk space by compacting segments
info "Compacting repository {{ repo_item.name }}"
borg compact
compact_exit=$?
# use highest exit code as global exit code
global_exit=$(( backup_exit > prune_exit ? backup_exit : prune_exit ))
global_exit=$(( compact_exit > global_exit ? compact_exit : global_exit ))
if [ ${global_exit} -eq 0 ]; then
info "Backup, Prune, and Compact finished successfully"
elif [ ${global_exit} -eq 1 ]; then
info "Backup, Prune, and/or Compact finished with warnings"
else
info "Backup, Prune, and/or Compact finished with errors"
fi
# end loop for repos
{% endfor %}
exit ${global_exit}

View File

@ -1,13 +0,0 @@
[Unit]
Description=Borg Backup
[Service]
Type=oneshot
User={{ borg_user }}
ExecStart=/home/{{borg_user}}/backup_script.sh
AmbientCapabilities=CAP_DAC_READ_SEARCH
StandardOutput=journal
StandardError=journal
SyslogIdentifier=borg

View File

@ -1,34 +0,0 @@
---
- name: Create docker compose directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/compose_projects/forgejo"
state: directory
mode: '0755'
register: compose_dir
- name: Create data directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/forgejo/data"
state: directory
mode: '0755'
register: forgejo_data_dir
- name: Create DB data directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/forgejo/db"
state: directory
mode: '0755'
register: forgejo_db_dir
- name: Copy compose file
ansible.builtin.template:
src: templates/forgejo_compose.yaml.j2
dest: "{{ compose_dir.path }}/compose.yaml"
- name: Starting forgejo compose project
community.docker.docker_compose_v2:
project_src: "{{ compose_dir.path }}"

View File

@ -1,2 +0,0 @@
---
- include_tasks: forgejo_docker.yaml

View File

@ -1,52 +0,0 @@
networks:
forgejo:
external: false
newt:
name: newt_compose_default
external: true
services:
server:
image: codeberg.org/forgejo/forgejo:16.0.1
container_name: forgejo
restart: always
environment:
- USER_UID={{ ansible_user_uid }}
- USER_GID={{ ansible_group_uid }}
- FORGEJO__database__DB_TYPE=postgres
- FORGEJO__database__HOST=db:5432
- FORGEJO__database__NAME=forgejo
- FORGEJO__database__USER=forgejo
- FORGEJO__database__PASSWD={{ forgejo_db_password }}
networks:
- forgejo
- newt
volumes:
- {{ forgejo_data_dir.path }}:/data
- /etc/localtime:/etc/localtime:ro
ports:
- '3000:3000'
- '222:22'
depends_on:
- db
db:
image: postgres:14
restart: always
environment:
- POSTGRES_USER=forgejo
- POSTGRES_PASSWORD={{ forgejo_db_password }}
- POSTGRES_DB=forgejo
networks:
- forgejo
volumes:
- {{ forgejo_db_dir.path }}:/var/lib/postgresql/data

View File

@ -1,23 +0,0 @@
---
- name: Create docker compose directory
ansible.builtin.file:
path: "/home/{{ ansible_user }}/compose_projects/newt_compose"
state: directory
mode: '0755'
register: compose_dir
- name: Copy compose file
ansible.builtin.template:
src: templates/newt_compose.yaml.j2
dest: "{{ compose_dir.path }}/compose.yaml"
- name: Copy secret file
ansible.builtin.template:
src: templates/newt-config.secret.j2
dest: "{{ compose_dir.path }}/newt-config.secret"
- name: Starting newt project
community.docker.docker_compose_v2:
project_src: "{{ compose_dir.path }}"

View File

@ -1,2 +0,0 @@
---
- include_tasks: docker_newt.yaml

View File

@ -1,10 +0,0 @@
{
"id": "{{ pangolin_site_id }}",
"secret": "{{ newt_secret }}",
"endpoint": "https://pangolin.{{ base_domain }}",
"dockerSocket": "unix:///var/run/docker.sock",
"dockerEnforceNetworkValidation": true,
"tlsClientCert": ""
}

View File

@ -1,16 +0,0 @@
services:
newt:
image: fosrl/newt
container_name: newt
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
- CONFIG_FILE=/run/secrets/newt-config
secrets:
- newt-config
secrets:
newt-config:
file: ./newt-config.secret

View File

@ -1,4 +0,0 @@
nextcloud_docker_image_name: "ghcr.io/nextcloud-releases/all-in-one"
nextcloud_docker_image_tag: latest
nextcloud_docker_skip_domain_validation: "true"
nextcloud_docker_mastercontainer_volume_dir: /usr/data/nextcloud_aio_mastercontainer

View File

@ -1,2 +0,0 @@
---
- import_tasks: nextcloud_docker_aio.yaml

View File

@ -1,33 +0,0 @@
---
- name: Pull docker image
docker_image:
name: "{{ nextcloud_docker_image_name }}"
tag: "{{ nextcloud_docker_image_tag }}"
source: pull
- name: Create Master Container volume dir
file:
path: "{{ nextcloud_docker_mastercontainer_volume_dir }}"
state: directory
mode: "0766"
- name: Create container
docker_container:
name: nextcloud-aio-mastercontainer
image: "{{ nextcloud_docker_image_name }}:{{ nextcloud_docker_image_tag }}"
ports:
- "8080:8080"
# - "80:80"
# - "8443:8443"
env:
APACHE_PORT: "11000"
APACHE_IP_BINDING: "0.0.0.0"
# APACHE_ADDITIONAL_NETWORK: ""
SKIP_DOMAIN_VALIDATION: "{{ nextcloud_docker_skip_domain_validation }}"
volumes:
- nextcloud_aio_mastercontainer:/mnt/docker-aio-config
- /var/run/docker.sock:/var/run/docker.sock:ro
networks:
- name: newt_compose_default
restart_policy : "always"
init : true

View File

@ -1,55 +0,0 @@
---
- name: Pull docker image
docker_image:
name: "nginx"
source: pull
- name: Create site dir
file:
path: "/home/{{ ansible_user }}/web/static_nginx_site"
state: directory
register: site_dir
- name: Create index.html
template:
src: templates/index.html.j2
dest: "{{site_dir.path}}/index.html"
- name: Create nginx conf dir
file:
path: "/home/{{ ansible_user }}/nginx/conf"
state: directory
register: nginx_conf_dir
- name: Copy nginx config
template:
src: templates/nginx.conf.j2
dest: "{{ nginx_conf_dir.path }}/nginx.conf"
- name: Create nginx logs dir
file:
path: "/home/{{ ansible_user }}/nginx/logs"
state: directory
register: nginx_logs_dir
- name: Create container
docker_container:
name: nginx-static
image: nginx
ports:
- "80:80"
volumes:
- "{{ site_dir.path }}:/usr/share/nginx/html"
- "{{ nginx_conf_dir.path }}:/etc/nginx/conf.d"
- "{{ nginx_logs_dir.path }}:/var/log/nginx"
restart_policy : "unless-stopped"
networks:
- name: "newt_compose_default"
init : true
recreate: true
state: started

View File

@ -1,2 +0,0 @@
---
- include_tasks: docker_nginx.yaml

View File

@ -1,13 +0,0 @@
<!DOCTYPE html>
<html lang=”en”>
<head>
<meta charset=”UTF-8″>
<meta name=”viewport” content=”width=device-width, initial-scale=1.0″>
<title>Welcome to My NGINX App</title>
<link rel=”stylesheet” href=”style.css”>
</head>
<body>
<h1>Static</h1>
<p>This is a static web page served by NGINX inside a Docker container.</p>
</body>
</html>

View File

@ -1,13 +0,0 @@
server {
listen 80;
root /usr/share/nginx/html;
index index.html index.htm;
server_name static1;
client_max_body_size 32m;
access_log /var/log/nginx/static1.access.log;
error_log /var/log/nginx/static1.error.log debug;
error_page 500 502 503 504 /50x.html;
location = /50x.html {
root /var/lib/nginx/html;
}
}

View File

@ -1,52 +1,38 @@
---
- name: Ensure Pangolin directory exists
ansible.builtin.file:
path: "/home/{{ ansible_user }}/compose_projects/pangolin"
path: /home/ubuntu/pangolin
state: directory
mode: '0755'
register: compose_dir
- name: Ensure Pangolin config directory exists
ansible.builtin.file:
path: "{{ compose_dir.path }}/pangolin_config"
path: /home/ubuntu/pangolin/pangolin_config
state: directory
mode: '0755'
register: pangolin_config
- name: Template Pangolin config file
ansible.builtin.template:
src: pangolin_config.yml.j2
dest: "{{ pangolin_config.path }}/config.yaml"
dest: /home/ubuntu/pangolin/pangolin_config/config.yaml
- name: Ensure Traefik config directory exists
ansible.builtin.file:
path: "{{ pangolin_config.path }}/traefik"
mode: '0755'
path: /home/ubuntu/pangolin/config/traefik
state: directory
register: traefik_config
- name: Ensure gerbil config directory exists
ansible.builtin.file:
path: "{{ pangolin_config.path }}/gerbil"
mode: '0755'
state: directory
register: gerbil_config
- name: Template Traefik config file
ansible.builtin.template:
src: traefik_config.yml.j2
dest: "{{ traefik_config.path }}/traefik_config.yml"
dest: /home/ubuntu/pangolin/config/traefik/traefik_config.yml
- name: Template Traefik dynamic config file
ansible.builtin.template:
src: dynamic_config.yml.j2
dest: "{{ traefik_config.path }}/dynamic_config.yml"
dest: /home/ubuntu/pangolin/config/traefik/dynamic_config.yml
- name: Template docker-compose.yml for Pangolin
ansible.builtin.template:
src: docker-compose.yml.j2
dest: "{{ compose_dir.path }}/docker-compose.yml"
dest: /home/ubuntu/pangolin/docker-compose.yml
register: pangolin_compose_template
- name: Check if Pangolin container is running
@ -76,27 +62,23 @@
when: pangolin_compose_needs_up
ignore_errors: true
- name: (Re)Start Pangolin and Gerbil with Docker Compose
community.docker.docker_compose_v2:
project_src: "{{ compose_dir.path }}"
register: docker_compose_status
state: restarted
# ansible.builtin.shell: |
# cd /home/ubuntu/pangolin
# docker compose up -d --force-recreate
# when: pangolin_compose_needs_up
# register: docker_compose_up
# failed_when: docker_compose_up.rc != 0
- name: Start Pangolin and Gerbil with Docker Compose (force recreate if needed)
ansible.builtin.shell: |
cd /home/ubuntu/pangolin
docker compose up -d --force-recreate
when: pangolin_compose_needs_up
register: docker_compose_up
failed_when: docker_compose_up.rc != 0
# - name: Check Docker Compose service status
# ansible.builtin.shell: |
# cd /home/ubuntu/pangolin
# docker compose ps
# register: docker_compose_status
- name: Check Docker Compose service status
ansible.builtin.shell: |
cd /home/ubuntu/pangolin
docker compose ps
register: docker_compose_status
- name: Display Docker Compose service status
ansible.builtin.debug:
msg: "{{ docker_compose_status }}"
msg: "{{ docker_compose_status.stdout_lines }}"
- name: "Assert that mandatory variables are defined and not default"
ansible.builtin.assert:

View File

@ -1,3 +1,3 @@
---
- ansible.builtin.include_tasks:
file: docker_pangolin.yaml
- ansible.builtin.include_tasks: prepare_node.yaml
- ansible.builtin.include_tasks: docker_pangolin.yaml

View File

@ -1,4 +1,34 @@
---
- name: Update all packages
ansible.builtin.apt:
update_cache: true
upgrade: dist
- name: Install essential packages
ansible.builtin.apt:
name:
- net-tools
- curl
- wget
- htop
- vim
state: present
- name: Add 1GB swap file
ansible.builtin.shell: |
fallocate -l 1G /swapfile
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
args:
creates: /swapfile
- name: Make swap persistent
ansible.builtin.lineinfile:
dest: /etc/fstab
line: '/swapfile none swap sw 0 0'
state: present
- name: Configure iptables firewall rules
ansible.builtin.iptables:
chain: INPUT
@ -12,7 +42,6 @@
- { protocol: tcp, port: '443', description: 'HTTPS for secure web traffic' }
- { protocol: udp, port: '51820', description: 'WireGuard VPN traffic' }
become: true
become_exe: "{{ become_exe_value }}"
register: iptables_result
- name: Display iptables configuration status

View File

@ -1,10 +1,10 @@
services:
pangolin:
image: fosrl/pangolin:ee-latest
image: fosrl/pangolin:latest
container_name: pangolin
restart: unless-stopped
volumes:
- {{ pangolin_config.path }}:/app/config
- ./pangolin_config:/app/config
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3001/api/v1/"]
interval: "3s"
@ -24,7 +24,7 @@ services:
- --remoteConfig=http://pangolin:3001/api/v1/gerbil/get-config
- --reportBandwidthTo=http://pangolin:3001/api/v1/gerbil/receive-bandwidth
volumes:
- {{ gerbil_config.path }}:/var/config
- ./gerbil_config/:/var/config
cap_add:
- NET_ADMIN
- SYS_MODULE
@ -44,9 +44,9 @@ services:
command:
- --configFile=/etc/traefik/traefik_config.yml
volumes:
- {{ traefik_config.path }}:/etc/traefik:ro # Volume to store the Traefik configuration
- {{ pangolin_config.path }}/letsencrypt:/letsencrypt # Volume to store the Let's Encrypt certificates
- {{ traefik_config.path }}/logs:/var/log/traefik # Volume to store Traefik logs
- ./config/traefik:/etc/traefik:ro # Volume to store the Traefik configuration
- ./config/letsencrypt:/letsencrypt # Volume to store the Let's Encrypt certificates
- ./config/traefik/logs:/var/log/traefik # Volume to store Traefik logs
networks:
default:
driver: bridge

View File

@ -20,12 +20,3 @@ server:
gerbil:
start_port: {{ pangolin_gerbil_start_port }}
base_endpoint: "{{ pangolin_dashboard_url | regex_replace('^https://', '') }}" # Gerbil endpoint should be the FQDN, not the full URL
email:
smtp_host: "{{ pangolin_mail_host}}"
smtp_port: {{ pangolin_mail_port }}
smtp_user: "{{ pangolin_mail_user }}"
smtp_pass: "{{ pangolin_mail_password }}"
smtp_secure: {{ pangolin_mail_secure_flag }}
no-reply: "{{ pangolin_no_reply_address }}"

View File

@ -1,6 +0,0 @@
---
- include_tasks: updates.yaml
- include_tasks: swap.yaml
when: configure_swap is defined
- include_tasks: iptables.yaml
when: ip_tables_coonfig is defined

View File

@ -1,15 +0,0 @@
---
- name: Add 1GB swap file
ansible.builtin.shell: |
fallocate -l 1G /swapfile
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
args:
creates: /swapfile
- name: Make swap persistent
ansible.builtin.lineinfile:
dest: /etc/fstab
line: '/swapfile none swap sw 0 0'
state: present

View File

@ -1,15 +0,0 @@
---
- name: Update all packages
ansible.builtin.apt:
update_cache: true
upgrade: dist
- name: Install essential packages
ansible.builtin.apt:
name:
- net-tools
- curl
- wget
- htop
- vim
state: present

View File

@ -1,15 +0,0 @@
---
- name : Nginx static with docker
hosts: all
tasks:
- include_role:
name: geerlingguy.docker
apply:
become: true
become_exe: "{{ become_exe_value }}"
- include_role:
name: "{{ item }}"
loop :
- newt_client
- nginx

View File

@ -1,10 +0,0 @@
---
- name: tests
hosts: all
tasks:
- name: testing
shell: echo $USER
- name: testing sudo
become: true
shell: echo $USER

View File

@ -2,6 +2,5 @@
- name: Configure VPN Server
hosts: wireguard_server
become: true
become_exe: "{{ become_exe_value }}"
roles:
- wireguard_server

View File

@ -1,19 +1,7 @@
# requirements.yml
---
roles:
# Used by pangolin playbook
- name: geerlingguy.docker
# Used by authentik playbook
- name: ax-bzh.authentik
collections:
# Used by role wireguard_server
- name: ansible.netcommon
# Used by ax-bzh.authentik
- name: community.docker
version: ">=3.0.0"
- name: community.general
# Used by role wireguard_server
- name: ansible.netcommon