Compare commits
9 Commits
main
...
vpn_client
| Author | SHA1 | Date |
|---|---|---|
|
|
18bcc1e762 | |
|
|
9e1f369572 | |
|
|
f22495d3c5 | |
|
|
b9bec36883 | |
|
|
b00d3612e3 | |
|
|
75def3e389 | |
|
|
a90119ffe1 | |
|
|
7df65a0b04 | |
|
|
3726195aa3 |
|
|
@ -4,7 +4,7 @@ new_sudo:
|
||||||
hserve1:
|
hserve1:
|
||||||
hserve2:
|
hserve2:
|
||||||
mini1:
|
mini1:
|
||||||
backs.hassallab.it:
|
|
||||||
|
|
||||||
|
|
||||||
distributed:
|
distributed:
|
||||||
|
|
@ -28,7 +28,4 @@ distributed:
|
||||||
forgejo:
|
forgejo:
|
||||||
hosts:
|
hosts:
|
||||||
hserve1:
|
hserve1:
|
||||||
borg:
|
|
||||||
hosts:
|
|
||||||
backs.hassallab.it:
|
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,2 +0,0 @@
|
||||||
---
|
|
||||||
borg_backup_server: backs.hassallab.it
|
|
||||||
|
|
@ -1,3 +1,5 @@
|
||||||
---
|
---
|
||||||
docker_users:
|
docker_users:
|
||||||
- "{{ ansible_user }}"
|
- "{{ ansible_user }}"
|
||||||
|
|
||||||
|
docker_compose_projects_base_path: "/home/{{ ansible_user }}/compose_projects"
|
||||||
|
|
|
||||||
|
|
@ -1,38 +1,33 @@
|
||||||
$ANSIBLE_VAULT;1.1;AES256
|
$ANSIBLE_VAULT;1.1;AES256
|
||||||
37383965623033356461393931656332323239323065326639613132306337393864366132366436
|
63663638383238373238386231396435393236303735313430633639326436636237396363356636
|
||||||
3130323864613235326338663735303931343363616435310a613164376464353130656539663036
|
3335633566393761386331363065363230313134396562370a663439363937316338656361663563
|
||||||
31306261346331623261363533306336663731383664356136366662393632383136353338616130
|
63366332333231666235613830663031663432613066376461316137336166646464323938373163
|
||||||
6365626664643733620a323563316331663638333566653363323733373839656330333930363161
|
6436373935383464360a363536383139616636613033653035356464643432303838663130373938
|
||||||
64666538656164653230633031663636343639393432326531343639356438316335633364633739
|
66336361363038393365653562323431633439336534373664356638313535316333633839366330
|
||||||
63303236313861383532386365613938303763373934303230626366636639643433646631343163
|
36383661363766386232616533323765386137656139373137623630356562386562653762336465
|
||||||
64316264616237336239346237643065396335313938373734613065383133616532626162393033
|
63363163643639616235353436613664636434393734393565316161633664323131396638346165
|
||||||
34613661353537373464643964356138653033623764353662386265316135353738353837616463
|
65616263643335396566393630636233306637313264366338636636666663373537613663663736
|
||||||
32653161303034363563373136303633326130643263653532313166383061306662333662623166
|
31613739643130353532306366626264363630623933313561366534393630613534643139353466
|
||||||
31363630303466353062356530383864666133376262333030323837313561653262313434663465
|
37373963333531666139356335393563623739323165356362616536656231663466366562333839
|
||||||
64376566346536303137646561316438346335343864346139653561663362613861633131393336
|
39393761396265303032343664353634383132323039373135376636633234656666323433633934
|
||||||
63346631373336666633386533313261366166663136306531333638363365383833643965613435
|
39613665643730373931383233643932373861396137306334353839663031633762663034396233
|
||||||
39376430653239323438613062653435653337663534633933323663613035643466303231346130
|
62616339613431333330666639356332376539616338626635653635386464366436643036383363
|
||||||
30643862633464663334386565356432323132336333653633373232333363653734666264333733
|
38663632346265303330666639613130396130626362643865316537323931633465326666636139
|
||||||
34333162333439336361313236313161626331396266653238313737656361663736383165393439
|
37383565326661656566313738636236663137636361616461616536393338363333663634373861
|
||||||
63326234626533663238353264353736303166383366633038373437366463666263616564303166
|
35643361663735316339663561643032343335666361383932316332393661643739393631343530
|
||||||
64393465396364313932316138393839613538343231343734336363663536646632373431623130
|
63366166386135653762343136643462336161653433653032363539336630636133623435313337
|
||||||
38653339396134303861636162326531616332353735336330623035633864323238333761363335
|
34333466396336633662653731343535383334303738366533653763326434366561393762386166
|
||||||
39373664613736613961666161323566303030656461623331353931363961323366653038656130
|
31303163396432343463666236336136653065633132613234643430646631356632306562653034
|
||||||
33356664353635343962343662313063633938343833643938626234383831363536623363366663
|
36643763313137626333313836383866323431343230326366663136643736383435326533613362
|
||||||
39343035393362326530316233303137616532356664353035393462306238303738653131346264
|
66613864656230303561626661613632363761316334306530323137616365396439623966623664
|
||||||
62636465613062326436333830306264656461356331306262363230336231643566633861633161
|
31386339313136366631616432623430363231646462653866313264333138383666313638396438
|
||||||
64393533313535333832343136343131376239363063613530383335326132336433626563333633
|
62386639346235663463633365386362326239666261303438656339306662623464633962353833
|
||||||
36386163613163616538643337666131663535333134626535613734393061653033633734613837
|
66323865613465353434666431663833363431356235376530636365313264626364633231633937
|
||||||
30373065623564333035616566373038393330613933623235613837383039626537653964366362
|
66356563656138663733653935643231613437316137383930353738363561666131393838346464
|
||||||
36643963373134613965333764396162303562633935633736633531336631353638613833643834
|
36646366303434323162363736343362623461343561363862313730316361383631313837366638
|
||||||
37366566663635323739643661393433353538636165623435356366333438393162393239363430
|
66353738396661323536383532323639303961313862663330636161643635636231393536383466
|
||||||
34626331303439343135353834336134396133636532643333336266626365616166363237376364
|
61366435663330633863343165636630373237356563636261636562613863633831643432323436
|
||||||
35323631656263343630643062376131386132356139623561653536313036316261323938636562
|
63396461643639396363653031666262386230346533346136633166636438336233333234313839
|
||||||
63343030623033373563626538383862626136343965613162326439316436306133663066656161
|
34373439363963633262663733663335353535343137366436336562336161373231346266393336
|
||||||
62393839326134613436626163626565303364373362356631363166316461323734323532623461
|
38303065323030653233323831303566336233336162323563336330366539303836663462346434
|
||||||
37303438666161653833363263633963323137303463343434363338303034303238313136343237
|
62643331643931383364
|
||||||
38346566613865646236343332666230356135343638623031383963666662336131616462383634
|
|
||||||
37383635376661386461306362373631373731313433643038316661613934663232666236613061
|
|
||||||
34353631323132353434623065613238383235316135373338383463626137313530366334333034
|
|
||||||
66613531646233643563336530623733343438666136383931363431306663383361313134646466
|
|
||||||
62623262643232356438653633306466383638336137366363336564643532623239
|
|
||||||
|
|
|
||||||
|
|
@ -1,4 +0,0 @@
|
||||||
configure_borg_server: true
|
|
||||||
borg_auth_users:
|
|
||||||
- host: fabotest
|
|
||||||
key: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEArNhKFcJ6T08sn7kTTLf+rO9HEvgOvqfhv5HQ2sRf2tFYfjfCb0zHKnMkgW+sy5gMU10Lyx1r7juXCvqRC955uIM97m1B1Xc6sVqASVKuGPhCKfhxEaMAyBcWFdE+HYbCOPYVN+JMrcwWfbblwiZTtK1OCqaEUvDDI7cFeU68noXwggEp46T48eqMUdi541D9Y+BVx9HYAo6OCQz0+6eXwxJL+tpRcAAXIMMWv362CYHoOgIU45R7xVSMLY1k/HLrcEAblwxEaSpduCH5cWUXZE/56IyxpvP44BxZkVhNdqJLmg4hxBQWhoMNYiTZxbLay3W2TwBCM111cAtUx4M/jQ== fabio@pc-fabio"
|
|
||||||
|
|
@ -1,7 +0,0 @@
|
||||||
---
|
|
||||||
pangolin_mail_host: "smtp.ionos.it"
|
|
||||||
pangolin_mail_port: 587
|
|
||||||
pangolin_mail_user: "system@hassallab.it"
|
|
||||||
pangolin_mail_password: "{{ pangolin_mail_crypted_password }}"
|
|
||||||
pangolin_no_reply_address: "system@hassallab.it"
|
|
||||||
pangolin_mail_secure_flag: false
|
|
||||||
|
|
@ -6,9 +6,9 @@ pangolin_admin_email: "hassallah@mail.com"
|
||||||
|
|
||||||
pangolin_gerbil_subnet_group: "10.42.0.0/16"
|
pangolin_gerbil_subnet_group: "10.42.0.0/16"
|
||||||
|
|
||||||
# # Email (SMTP) settings
|
# Email (SMTP) settings
|
||||||
# pangolin_email_smtp_host: "mail.com"
|
pangolin_email_smtp_host: "mail.com"
|
||||||
# pangolin_email_smtp_port: 587
|
pangolin_email_smtp_port: 587
|
||||||
# pangolin_email_smtp_user: "pango.lin@mail.com"
|
pangolin_email_smtp_user: "pango.lin@mail.com"
|
||||||
# pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
|
pangolin_email_smtp_pass: "{{ pangolin_mail_crypted_password }}"
|
||||||
# pangolin_email_no_reply: "no-reply@mail.com"
|
pangolin_email_no_reply: "no-reply@mail.com"
|
||||||
|
|
@ -4,15 +4,3 @@ newt_secret: "{{ test_nginx_newt_secret }}"
|
||||||
|
|
||||||
|
|
||||||
forgejo_db_password : "{{ forgejo_db_crypted_password }}"
|
forgejo_db_password : "{{ forgejo_db_crypted_password }}"
|
||||||
|
|
||||||
configure_borg_client: true
|
|
||||||
borg_repos:
|
|
||||||
- name: web
|
|
||||||
borg_passphrase: "{{ hserve1_backup_web_crypted_password }}"
|
|
||||||
paths_to_backup:
|
|
||||||
- "/home/{{ ansible_user }}/web"
|
|
||||||
- name: test
|
|
||||||
borg_passphrase: "dummy_secret"
|
|
||||||
paths_to_backup:
|
|
||||||
- "/home/{{ ansible_user }}"
|
|
||||||
- "/proc/version"
|
|
||||||
|
|
@ -3,19 +3,7 @@
|
||||||
Qui vengono riportati i playbook disponibili, descrizione e utilizzo.
|
Qui vengono riportati i playbook disponibili, descrizione e utilizzo.
|
||||||
**NB** Ci si aspetta che i playbook siano idempotenti. In caso contrario e' importante riportarlo nella documentazione corrente.
|
**NB** Ci si aspetta che i playbook siano idempotenti. In caso contrario e' importante riportarlo nella documentazione corrente.
|
||||||
|
|
||||||
### Summary
|
|
||||||
- [Bootstrap](#bootstrap)
|
|
||||||
- [VPN Server](#vpn-server)
|
|
||||||
- [Pangolin](#pangolin)
|
|
||||||
- [Forgejo](#forgejo)
|
|
||||||
- [Authentik](#authentik)
|
|
||||||
- [Nextcloud](#nextcloud)
|
|
||||||
- [Static Nginx Page](#static-nginx-page)
|
|
||||||
- [Borg Backups](#borg-backups)
|
|
||||||
|
|
||||||
|
|
||||||
### Bootstrap
|
### Bootstrap
|
||||||
|
|
||||||
Implementa la configurazione di base di un nodo per poter essere gestito dagli altri playbook, in particolare :
|
Implementa la configurazione di base di un nodo per poter essere gestito dagli altri playbook, in particolare :
|
||||||
- crea l'utente ansible
|
- crea l'utente ansible
|
||||||
- registra le chiavi ssh degli utenti configurati
|
- registra le chiavi ssh degli utenti configurati
|
||||||
|
|
@ -79,73 +67,7 @@ Il playbook installa docker e docker compose. Attraverso docker compose vengono
|
||||||
|
|
||||||
Il playbook utilizza :
|
Il playbook utilizza :
|
||||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
||||||
- Il ruolo ***prepare_node***
|
- I ruoli common e pangolin definiti in [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main), riportati staticamente come ruolo *pangolin*
|
||||||
- Il ruolo ***pangolin*** preso da [pangolin-ansible-terraform](https://github.com/patelanuj21/pangolin-ansible-terraform/tree/main)
|
|
||||||
|
|
||||||
I parametri attesi dal playbook sono quelli definiti nei ruoli da cui dipende.
|
I parametri attesi dal playbook sono quelli definiti nei ruoli da cui dipende.
|
||||||
|
|
||||||
### Forgejo
|
|
||||||
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [forgejo](https://forgejo.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
|
||||||
|
|
||||||
Il playbook utilizza :
|
|
||||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
|
||||||
- I ruoli ***forgejo*** e ***newt_client***
|
|
||||||
|
|
||||||
### Authentik
|
|
||||||
Il playbook installa docker e docker compose. Attraverso docker compose vengono poi lanciati container per [authentik](https://docs.goauthentik.io/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
|
||||||
|
|
||||||
Il playbook utilizza :
|
|
||||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
|
||||||
- [ax-bzh.authentik](https://galaxy.ansible.com/ui/standalone/roles/ax-bzh/authentik/documentation/) attraverso ***ansible galaxy***
|
|
||||||
- Il ruolo ***newt_client***
|
|
||||||
|
|
||||||
### Nextcloud
|
|
||||||
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nextcloud AIO](https://github.com/nextcloud/all-in-one) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
|
||||||
|
|
||||||
Il playbook utilizza :
|
|
||||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
|
||||||
- I ruoli ***newt_client*** e ***nextcloud_aio***
|
|
||||||
|
|
||||||
### Static Nginx Page
|
|
||||||
Il playbook installa docker e docker compose. Attraverso docker viene poi lanciato il container per [Nginx](https://nginx.org/) e [newt_client](https://docs.pangolin.net/manage/sites/install-site).
|
|
||||||
|
|
||||||
Il playbook utilizza :
|
|
||||||
- [geerlingguy.docker](https://github.com/geerlingguy/ansible-role-docker) attraverso ansible galaxy
|
|
||||||
- I ruoli ***newt_client*** e ***nginx***
|
|
||||||
|
|
||||||
### Borg Backups
|
|
||||||
Il playbook configura sia i client che il server per i backup effettuati con [borg](https://www.borgbackup.org/). I client vengono risolti dinamicamente verificando la presenza della seguente configurazione in esempio:
|
|
||||||
|
|
||||||
```
|
|
||||||
configure_borg_client: True
|
|
||||||
borg_repos:
|
|
||||||
- name: test
|
|
||||||
borg_passphrase: "dummy_secret"
|
|
||||||
paths_to_backup:
|
|
||||||
- "/home/{{ ansible_user }}"
|
|
||||||
- "/proc/version"
|
|
||||||
```
|
|
||||||
|
|
||||||
Per ogni client vengono configurati :
|
|
||||||
- l'utente e relative credenziali per connettersi al borg server
|
|
||||||
- Un servizio systemd **borg\_backup.service** e relativo timer **borg\_backup.timer** per eseguire il backup
|
|
||||||
- Uno script che esegue effettivamente il backup **"/home/{{borg_user}}/backup\_script.sh"** verso *"ssh://{{ borg\_user }}@{{ borg\_backup_server }}/./"*
|
|
||||||
|
|
||||||
Sul server vengono configurati:
|
|
||||||
- L'utente con cui eseguire borg service
|
|
||||||
- Le credenziali attese utilizzate dai vari client e i rispettivi path permessi per eseguire i report.
|
|
||||||
|
|
||||||
Sul server i permessi concessi ai vari client vengono limitati definendo su ***/home/{{borg\_user}}/.ssh/authorized\_keys*** le limitazioni di path (accesso solo al proprio repo) e di operation (solo ***"borg serve"***) con la seguente istruzione :
|
|
||||||
```
|
|
||||||
command=\"cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}\",restrict
|
|
||||||
```
|
|
||||||
|
|
||||||
E' possibile configurare il server per servire borg anche con altre credenziali e path, per casi non coperti dal playbook (e.g. borg backups usato direttamente da Nextcloud AIO) attraverso il seguente attributo:
|
|
||||||
|
|
||||||
```
|
|
||||||
borg_auth_users:
|
|
||||||
- host: fabotest
|
|
||||||
key: "ssh-rsa ********"
|
|
||||||
```
|
|
||||||
|
|
||||||
Il playbook utilizza il role ***borg***
|
|
||||||
|
|
|
||||||
|
|
@ -1,30 +0,0 @@
|
||||||
---
|
|
||||||
- name: Evaluate borg client nodes
|
|
||||||
hosts: all
|
|
||||||
gather_facts: false
|
|
||||||
tasks:
|
|
||||||
- name: Gather configured clients
|
|
||||||
ansible.builtin.group_by:
|
|
||||||
key: "borg_clients_{{ configure_borg_client | default('False') }}"
|
|
||||||
# Creates: borg_clients_True and borg_clients_False
|
|
||||||
|
|
||||||
|
|
||||||
- name: Configure borg backups system
|
|
||||||
hosts: borg_clients_True:borg
|
|
||||||
debugger: on_failed
|
|
||||||
tasks:
|
|
||||||
- name: Configure clients
|
|
||||||
include_role:
|
|
||||||
name: borg
|
|
||||||
apply:
|
|
||||||
become: true
|
|
||||||
become_exe: "{{ become_exe_value }}"
|
|
||||||
when: "{{ configure_borg_client | default(false) }} "
|
|
||||||
|
|
||||||
- name: Configure server
|
|
||||||
include_role:
|
|
||||||
name: borg
|
|
||||||
apply:
|
|
||||||
become: true
|
|
||||||
become_exe: "{{ become_exe_value }}"
|
|
||||||
when: "{{ configure_borg_server | default(false) }} "
|
|
||||||
|
|
@ -1,8 +0,0 @@
|
||||||
---
|
|
||||||
borg_user: borg
|
|
||||||
borg_group: borg
|
|
||||||
borg_home: "/home/{{ borg_user }}"
|
|
||||||
borg_pool: "{{ borg_home }}/repos"
|
|
||||||
borg_pool_dest : /usr/backups/borg_repos
|
|
||||||
borg_repo_base: "ssh://{{ borg_user }}@{{ borg_backup_server }}/./"
|
|
||||||
borg_auth_users: []
|
|
||||||
|
|
@ -1,44 +0,0 @@
|
||||||
---
|
|
||||||
- name: Define backup script
|
|
||||||
ansible.builtin.template:
|
|
||||||
dest: "/home/{{borg_user}}/backup_script.sh"
|
|
||||||
src: templates/backup_script.sh.j2
|
|
||||||
owner: root
|
|
||||||
mode: "0701"
|
|
||||||
|
|
||||||
- name: Define backup service
|
|
||||||
ansible.builtin.template:
|
|
||||||
dest: /etc/systemd/system/borg_backup.service
|
|
||||||
src: templates/borg_backup.service.j2
|
|
||||||
owner: root
|
|
||||||
mode: "0700"
|
|
||||||
|
|
||||||
|
|
||||||
- name: Define backup timer
|
|
||||||
ansible.builtin.copy:
|
|
||||||
content: |
|
|
||||||
[Unit]
|
|
||||||
Description=Daily Backup Timer
|
|
||||||
|
|
||||||
[Timer]
|
|
||||||
OnCalendar=*-*-* 02:00:00
|
|
||||||
Persistent=true
|
|
||||||
RandomizedDelaySec=300
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=timers.target
|
|
||||||
dest: /etc/systemd/system/borg_backup.timer
|
|
||||||
|
|
||||||
- name: Reload systemd
|
|
||||||
ansible.builtin.systemd_service:
|
|
||||||
daemon_reload: true
|
|
||||||
|
|
||||||
# Add entry in borg_auth_users for server configuration
|
|
||||||
# borg_auth_users:
|
|
||||||
# - host: fabotest
|
|
||||||
# # Chiave di esempio per test
|
|
||||||
# key: "ssh-rsa ****"
|
|
||||||
|
|
||||||
- name: Register public key for server configuration
|
|
||||||
set_fact:
|
|
||||||
borg_auth_users: "{{ borg_auth_users + [{'host': inventory_hostname, 'key':borg_user_definition.ssh_public_key}] }}"
|
|
||||||
|
|
@ -1,52 +0,0 @@
|
||||||
---
|
|
||||||
- name: Set ssh directory
|
|
||||||
file:
|
|
||||||
path: "{{ borg_home }}/.ssh"
|
|
||||||
owner: "{{ borg_user }}"
|
|
||||||
group: "{{ borg_group }}"
|
|
||||||
mode: "0700"
|
|
||||||
state: directory
|
|
||||||
|
|
||||||
- name: Create pool directory
|
|
||||||
file:
|
|
||||||
path: "{{ borg_pool_dest}}"
|
|
||||||
owner: "{{ borg_user }}"
|
|
||||||
group: "{{ borg_group }}"
|
|
||||||
mode: "0700"
|
|
||||||
state: directory
|
|
||||||
|
|
||||||
- name: Set pool directory link
|
|
||||||
file:
|
|
||||||
src: "{{ borg_pool_dest }}"
|
|
||||||
dest: "{{ borg_pool }}"
|
|
||||||
state: link
|
|
||||||
|
|
||||||
|
|
||||||
- name: Gathering clients configurations
|
|
||||||
set_fact:
|
|
||||||
borg_auth_users: "{{ borg_auth_users + hostvars[item]['borg_auth_users']}}"
|
|
||||||
loop: "{{ groups['borg_clients_True'] }}"
|
|
||||||
|
|
||||||
- name: Creating pool sub directories
|
|
||||||
file:
|
|
||||||
path: "{{ borg_pool }}/{{ item.host }}"
|
|
||||||
owner: "{{ borg_user }}"
|
|
||||||
group: "{{ borg_group }}"
|
|
||||||
mode: "0700"
|
|
||||||
state: directory
|
|
||||||
with_items: "{{ borg_auth_users }}"
|
|
||||||
|
|
||||||
- name: Defining authorized_key
|
|
||||||
authorized_key:
|
|
||||||
user: "{{ borg_user }}"
|
|
||||||
key: "{{ item.key }}"
|
|
||||||
key_options: "command=\"cd {{ borg_pool }}/{{ item.host }};borg serve --restrict-to-path {{ borg_pool }}/{{ item.host }}\",restrict"
|
|
||||||
with_items: "{{ borg_auth_users }}"
|
|
||||||
|
|
||||||
- name: Setting authorized keys file
|
|
||||||
file:
|
|
||||||
path: "{{ borg_home }}/.ssh/authorized_keys"
|
|
||||||
owner: "{{ borg_user }}"
|
|
||||||
group: "{{ borg_group }}"
|
|
||||||
mode: "0600"
|
|
||||||
state: file
|
|
||||||
|
|
@ -1,9 +0,0 @@
|
||||||
---
|
|
||||||
- name: Prepare borg
|
|
||||||
include_tasks: prepare_borg.yaml
|
|
||||||
- name: Configure server
|
|
||||||
include_tasks: configure_borg_server.yaml
|
|
||||||
when: "{{ configure_borg_server | default(false) }}"
|
|
||||||
- name: Configure client
|
|
||||||
include_tasks: configure_borg_client.yaml
|
|
||||||
when: "{{ configure_borg_client | default(false) }} "
|
|
||||||
|
|
@ -1,21 +0,0 @@
|
||||||
---
|
|
||||||
- name: Install borg and requirements
|
|
||||||
ansible.builtin.package:
|
|
||||||
name: borgbackup
|
|
||||||
state: present
|
|
||||||
|
|
||||||
- name: Set borg user group
|
|
||||||
group:
|
|
||||||
name: "{{ borg_group }}"
|
|
||||||
state: present
|
|
||||||
|
|
||||||
- name: Set borg user
|
|
||||||
user:
|
|
||||||
name: "{{ borg_user }}"
|
|
||||||
shell: /bin/bash
|
|
||||||
home: "{{ borg_home }}"
|
|
||||||
create_home: true
|
|
||||||
group: "{{ borg_group }}"
|
|
||||||
state: present
|
|
||||||
generate_ssh_key: "{{ configure_borg_client | default(false) }}"
|
|
||||||
register: borg_user_definition
|
|
||||||
|
|
@ -1,86 +0,0 @@
|
||||||
#!/bin/bash
|
|
||||||
{% for repo_item in borg_repos %}
|
|
||||||
|
|
||||||
# Setting this, so the repo does not need to be given on the commandline:
|
|
||||||
export BORG_REPO="{{borg_repo_base}}{{repo_item.name}}"
|
|
||||||
|
|
||||||
# See the section "Passphrase notes" for more infos.
|
|
||||||
export BORG_PASSPHRASE="'{{ repo_item.borg_passphrase }}'"
|
|
||||||
|
|
||||||
# some helpers and error handling:
|
|
||||||
info() { logger "$*"; }
|
|
||||||
trap 'echo $( date ) Backup interrupted >&2; exit 2' INT TERM
|
|
||||||
|
|
||||||
info "Trying to initialize repo. NB returns error if already initialized"
|
|
||||||
borg init --encryption=repokey
|
|
||||||
|
|
||||||
info "Starting backup for repo {{repo_item.name}}"
|
|
||||||
|
|
||||||
# Backup the most important directories into an archive named after
|
|
||||||
# the machine this script is currently running on:
|
|
||||||
|
|
||||||
borg create \
|
|
||||||
--verbose \
|
|
||||||
--filter AME \
|
|
||||||
--list \
|
|
||||||
--stats \
|
|
||||||
--show-rc \
|
|
||||||
--compression lz4 \
|
|
||||||
--exclude-caches \
|
|
||||||
--exclude 'home/*/.cache/*' \
|
|
||||||
--exclude 'var/tmp/*' \
|
|
||||||
\
|
|
||||||
::"'{{ inventory_hostname }}-{now}'"\
|
|
||||||
{% for item in repo_item.paths_to_backup %}
|
|
||||||
{{ item }}\
|
|
||||||
{% endfor %}
|
|
||||||
|
|
||||||
backup_exit=$?
|
|
||||||
|
|
||||||
info "Pruning repository {{ repo_item.name }}"
|
|
||||||
|
|
||||||
# Use the `prune` subcommand to maintain 7 daily, 4 weekly and 6 monthly
|
|
||||||
# archives of THIS machine. The '{hostname}-*' matching is very important to
|
|
||||||
# limit prune's operation to this machine's archives and not apply to
|
|
||||||
# other machines' archives also:
|
|
||||||
|
|
||||||
borg prune \
|
|
||||||
--list \
|
|
||||||
--glob-archives "'{{ inventory_hostname }}-*'" \
|
|
||||||
--show-rc \
|
|
||||||
--keep-daily 7 \
|
|
||||||
--keep-weekly 4 \
|
|
||||||
--keep-monthly 6
|
|
||||||
|
|
||||||
prune_exit=$?
|
|
||||||
|
|
||||||
# actually free repo disk space by compacting segments
|
|
||||||
|
|
||||||
info "Compacting repository {{ repo_item.name }}"
|
|
||||||
|
|
||||||
borg compact
|
|
||||||
|
|
||||||
compact_exit=$?
|
|
||||||
|
|
||||||
# use highest exit code as global exit code
|
|
||||||
global_exit=$(( backup_exit > prune_exit ? backup_exit : prune_exit ))
|
|
||||||
global_exit=$(( compact_exit > global_exit ? compact_exit : global_exit ))
|
|
||||||
|
|
||||||
if [ ${global_exit} -eq 0 ]; then
|
|
||||||
info "Backup, Prune, and Compact finished successfully"
|
|
||||||
elif [ ${global_exit} -eq 1 ]; then
|
|
||||||
info "Backup, Prune, and/or Compact finished with warnings"
|
|
||||||
else
|
|
||||||
info "Backup, Prune, and/or Compact finished with errors"
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
# end loop for repos
|
|
||||||
|
|
||||||
{% endfor %}
|
|
||||||
|
|
||||||
|
|
||||||
exit ${global_exit}
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
@ -1,13 +0,0 @@
|
||||||
[Unit]
|
|
||||||
Description=Borg Backup
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=oneshot
|
|
||||||
User={{ borg_user }}
|
|
||||||
ExecStart=/home/{{borg_user}}/backup_script.sh
|
|
||||||
|
|
||||||
AmbientCapabilities=CAP_DAC_READ_SEARCH
|
|
||||||
|
|
||||||
StandardOutput=journal
|
|
||||||
StandardError=journal
|
|
||||||
SyslogIdentifier=borg
|
|
||||||
|
|
@ -1,14 +1,14 @@
|
||||||
---
|
---
|
||||||
- name: Create docker compose directory
|
- name: Create docker compose directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/home/{{ ansible_user }}/compose_projects/forgejo"
|
path: "{{ docker_compose_projects_base_path }}/forgejo"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
mode: '0755'
|
||||||
register: compose_dir
|
register: compose_dir
|
||||||
|
|
||||||
- name: Create data directory
|
- name: Create data directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/home/{{ ansible_user }}/forgejo/data"
|
path: "{{ compose_dir }}/data"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
mode: '0755'
|
||||||
register: forgejo_data_dir
|
register: forgejo_data_dir
|
||||||
|
|
@ -16,7 +16,7 @@
|
||||||
|
|
||||||
- name: Create DB data directory
|
- name: Create DB data directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/home/{{ ansible_user }}/forgejo/db"
|
path: "{{ compose_dir }}/db"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
mode: '0755'
|
||||||
register: forgejo_db_dir
|
register: forgejo_db_dir
|
||||||
|
|
|
||||||
|
|
@ -1,7 +1,7 @@
|
||||||
---
|
---
|
||||||
- name: Create docker compose directory
|
- name: Create docker compose directory
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/home/{{ ansible_user }}/compose_projects/newt_compose"
|
path: "{{ docker_compose_projects_base_path }}/newt_compose"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
mode: '0755'
|
||||||
register: compose_dir
|
register: compose_dir
|
||||||
|
|
|
||||||
|
|
@ -1,4 +1,12 @@
|
||||||
---
|
---
|
||||||
|
pangolin_version: "ee-latest"
|
||||||
|
gerbil_version: "latest"
|
||||||
|
traefik_version: "latest"
|
||||||
|
|
||||||
|
|
||||||
|
pangolin_base_path: "{{ docker_compose_projects_base_path }}/pangolin"
|
||||||
|
|
||||||
|
|
||||||
# Derived Variables
|
# Derived Variables
|
||||||
pangolin_cors_origin: "{{ pangolin_dashboard_url }}"
|
pangolin_cors_origin: "{{ pangolin_dashboard_url }}"
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,52 +1,46 @@
|
||||||
---
|
---
|
||||||
- name: Ensure Pangolin directory exists
|
- name: Ensure Pangolin directory exists
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/home/{{ ansible_user }}/compose_projects/pangolin"
|
path: "{{ pangolin_base_path }}"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
|
||||||
register: compose_dir
|
|
||||||
|
|
||||||
- name: Ensure Pangolin config directory exists
|
- name: Ensure Pangolin config directory exists
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "{{ compose_dir.path }}/pangolin_config"
|
path: "{{ pangolin_base_path }}/pangolin_config"
|
||||||
state: directory
|
state: directory
|
||||||
mode: '0755'
|
register: pangolin_config_dir
|
||||||
register: pangolin_config
|
|
||||||
|
|
||||||
- name: Template Pangolin config file
|
- name: Template Pangolin config file
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: pangolin_config.yml.j2
|
src: pangolin_config.yml.j2
|
||||||
dest: "{{ pangolin_config.path }}/config.yaml"
|
dest: "{{ pangolin_config_dir.path }}/config.yaml"
|
||||||
|
|
||||||
|
- name: Ensure Letsencrypt config directory exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "{{ pangolin_config_dir.path }}/letsencrypt"
|
||||||
|
state: directory
|
||||||
|
register: letsencrypt_config_directory
|
||||||
|
|
||||||
- name: Ensure Traefik config directory exists
|
- name: Ensure Traefik config directory exists
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "{{ pangolin_config.path }}/traefik"
|
path: "{{ pangolin_config_dir.path }}/traefik"
|
||||||
mode: '0755'
|
|
||||||
state: directory
|
state: directory
|
||||||
register: traefik_config
|
register: traefik_config_directory
|
||||||
|
|
||||||
- name: Ensure gerbil config directory exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: "{{ pangolin_config.path }}/gerbil"
|
|
||||||
mode: '0755'
|
|
||||||
state: directory
|
|
||||||
register: gerbil_config
|
|
||||||
|
|
||||||
|
|
||||||
- name: Template Traefik config file
|
- name: Template Traefik config file
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: traefik_config.yml.j2
|
src: traefik_config.yml.j2
|
||||||
dest: "{{ traefik_config.path }}/traefik_config.yml"
|
dest: "{{ traefik_config_directory.path }}/traefik_config.yml"
|
||||||
|
|
||||||
- name: Template Traefik dynamic config file
|
- name: Template Traefik dynamic config file
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: dynamic_config.yml.j2
|
src: dynamic_config.yml.j2
|
||||||
dest: "{{ traefik_config.path }}/dynamic_config.yml"
|
dest: "{{ traefik_config_directory.path }}/dynamic_config.yml"
|
||||||
|
|
||||||
- name: Template docker-compose.yml for Pangolin
|
- name: Template docker-compose.yml for Pangolin
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
src: docker-compose.yml.j2
|
src: docker-compose.yml.j2
|
||||||
dest: "{{ compose_dir.path }}/docker-compose.yml"
|
dest: "{{ pangolin_base_path }}/docker-compose.yml"
|
||||||
register: pangolin_compose_template
|
register: pangolin_compose_template
|
||||||
|
|
||||||
- name: Check if Pangolin container is running
|
- name: Check if Pangolin container is running
|
||||||
|
|
@ -76,27 +70,23 @@
|
||||||
when: pangolin_compose_needs_up
|
when: pangolin_compose_needs_up
|
||||||
ignore_errors: true
|
ignore_errors: true
|
||||||
|
|
||||||
- name: (Re)Start Pangolin and Gerbil with Docker Compose
|
- name: Start Pangolin and Gerbil with Docker Compose (force recreate if needed)
|
||||||
community.docker.docker_compose_v2:
|
ansible.builtin.shell: |
|
||||||
project_src: "{{ compose_dir.path }}"
|
cd {{ pangolin_base_path }}
|
||||||
register: docker_compose_status
|
docker compose up -d --force-recreate
|
||||||
state: restarted
|
when: pangolin_compose_needs_up
|
||||||
# ansible.builtin.shell: |
|
register: docker_compose_up
|
||||||
# cd /home/ubuntu/pangolin
|
failed_when: docker_compose_up.rc != 0
|
||||||
# docker compose up -d --force-recreate
|
|
||||||
# when: pangolin_compose_needs_up
|
|
||||||
# register: docker_compose_up
|
|
||||||
# failed_when: docker_compose_up.rc != 0
|
|
||||||
|
|
||||||
# - name: Check Docker Compose service status
|
- name: Check Docker Compose service status
|
||||||
# ansible.builtin.shell: |
|
ansible.builtin.shell: |
|
||||||
# cd /home/ubuntu/pangolin
|
cd {{ pangolin_base_path }}
|
||||||
# docker compose ps
|
docker compose ps
|
||||||
# register: docker_compose_status
|
register: docker_compose_status
|
||||||
|
|
||||||
- name: Display Docker Compose service status
|
- name: Display Docker Compose service status
|
||||||
ansible.builtin.debug:
|
ansible.builtin.debug:
|
||||||
msg: "{{ docker_compose_status }}"
|
msg: "{{ docker_compose_status.stdout_lines }}"
|
||||||
|
|
||||||
- name: "Assert that mandatory variables are defined and not default"
|
- name: "Assert that mandatory variables are defined and not default"
|
||||||
ansible.builtin.assert:
|
ansible.builtin.assert:
|
||||||
|
|
|
||||||
|
|
@ -1,10 +1,10 @@
|
||||||
services:
|
services:
|
||||||
pangolin:
|
pangolin:
|
||||||
image: fosrl/pangolin:ee-latest
|
image: fosrl/pangolin:{{ pangolin_version }}
|
||||||
container_name: pangolin
|
container_name: pangolin
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
volumes:
|
volumes:
|
||||||
- {{ pangolin_config.path }}:/app/config
|
- {{ pangolin_config_dir.path }}:/app/config
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD", "curl", "-f", "http://localhost:3001/api/v1/"]
|
test: ["CMD", "curl", "-f", "http://localhost:3001/api/v1/"]
|
||||||
interval: "3s"
|
interval: "3s"
|
||||||
|
|
@ -12,7 +12,7 @@ services:
|
||||||
retries: 15
|
retries: 15
|
||||||
|
|
||||||
gerbil:
|
gerbil:
|
||||||
image: fosrl/gerbil:1.0.0
|
image: fosrl/gerbil:{{ gerbil_version }}
|
||||||
container_name: gerbil
|
container_name: gerbil
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
depends_on:
|
depends_on:
|
||||||
|
|
@ -24,17 +24,18 @@ services:
|
||||||
- --remoteConfig=http://pangolin:3001/api/v1/gerbil/get-config
|
- --remoteConfig=http://pangolin:3001/api/v1/gerbil/get-config
|
||||||
- --reportBandwidthTo=http://pangolin:3001/api/v1/gerbil/receive-bandwidth
|
- --reportBandwidthTo=http://pangolin:3001/api/v1/gerbil/receive-bandwidth
|
||||||
volumes:
|
volumes:
|
||||||
- {{ gerbil_config.path }}:/var/config
|
- ./gerbil_config/:/var/config
|
||||||
cap_add:
|
cap_add:
|
||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
- SYS_MODULE
|
- SYS_MODULE
|
||||||
ports:
|
ports:
|
||||||
- 51820:51820/udp
|
- 51820:51820/udp
|
||||||
|
- 21820:21820/udp
|
||||||
- 443:443 # Port for traefik because of the network_mode
|
- 443:443 # Port for traefik because of the network_mode
|
||||||
- 80:80 # Port for traefik because of the network_mode
|
- 80:80 # Port for traefik because of the network_mode
|
||||||
|
|
||||||
traefik:
|
traefik:
|
||||||
image: traefik:v3.4.1
|
image: traefik:{{ traefik_version }}
|
||||||
container_name: traefik
|
container_name: traefik
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
network_mode: service:gerbil # Ports appear on the gerbil service
|
network_mode: service:gerbil # Ports appear on the gerbil service
|
||||||
|
|
@ -44,9 +45,9 @@ services:
|
||||||
command:
|
command:
|
||||||
- --configFile=/etc/traefik/traefik_config.yml
|
- --configFile=/etc/traefik/traefik_config.yml
|
||||||
volumes:
|
volumes:
|
||||||
- {{ traefik_config.path }}:/etc/traefik:ro # Volume to store the Traefik configuration
|
- {{ traefik_config_directory.path }}:/etc/traefik:ro # Volume to store the Traefik configuration
|
||||||
- {{ pangolin_config.path }}/letsencrypt:/letsencrypt # Volume to store the Let's Encrypt certificates
|
- {{ letsencrypt_config_directory.path }}:/letsencrypt # Volume to store the Let's Encrypt certificates
|
||||||
- {{ traefik_config.path }}/logs:/var/log/traefik # Volume to store Traefik logs
|
- {{ traefik_config_directory.path }}/logs:/var/log/traefik # Volume to store Traefik logs
|
||||||
networks:
|
networks:
|
||||||
default:
|
default:
|
||||||
driver: bridge
|
driver: bridge
|
||||||
|
|
|
||||||
|
|
@ -20,12 +20,3 @@ server:
|
||||||
gerbil:
|
gerbil:
|
||||||
start_port: {{ pangolin_gerbil_start_port }}
|
start_port: {{ pangolin_gerbil_start_port }}
|
||||||
base_endpoint: "{{ pangolin_dashboard_url | regex_replace('^https://', '') }}" # Gerbil endpoint should be the FQDN, not the full URL
|
base_endpoint: "{{ pangolin_dashboard_url | regex_replace('^https://', '') }}" # Gerbil endpoint should be the FQDN, not the full URL
|
||||||
|
|
||||||
|
|
||||||
email:
|
|
||||||
smtp_host: "{{ pangolin_mail_host}}"
|
|
||||||
smtp_port: {{ pangolin_mail_port }}
|
|
||||||
smtp_user: "{{ pangolin_mail_user }}"
|
|
||||||
smtp_pass: "{{ pangolin_mail_password }}"
|
|
||||||
smtp_secure: {{ pangolin_mail_secure_flag }}
|
|
||||||
no-reply: "{{ pangolin_no_reply_address }}"
|
|
||||||
|
|
|
||||||
|
|
@ -11,11 +11,12 @@
|
||||||
- { protocol: tcp, port: '80', description: 'HTTP for Lets Encrypt ACME challenge' }
|
- { protocol: tcp, port: '80', description: 'HTTP for Lets Encrypt ACME challenge' }
|
||||||
- { protocol: tcp, port: '443', description: 'HTTPS for secure web traffic' }
|
- { protocol: tcp, port: '443', description: 'HTTPS for secure web traffic' }
|
||||||
- { protocol: udp, port: '51820', description: 'WireGuard VPN traffic' }
|
- { protocol: udp, port: '51820', description: 'WireGuard VPN traffic' }
|
||||||
|
- { protocol: udp, port: '21820', description: 'WireGuard VPN traffic clients' }
|
||||||
become: true
|
become: true
|
||||||
become_exe: "{{ become_exe_value }}"
|
become_exe: "{{ become_exe_value }}"
|
||||||
register: iptables_result
|
register: iptables_result
|
||||||
|
|
||||||
- name: Display iptables configuration status
|
- name: Display iptables configuration status
|
||||||
ansible.builtin.debug:
|
ansible.builtin.debug:
|
||||||
msg: "Configured firewall rules for ports: 80 (HTTP), 443 (HTTPS), 51820 (WireGuard UDP)"
|
msg: "Configured firewall rules for ports: 80 (HTTP), 443 (HTTPS), 51820 (WireGuard UDP), 21820 (VPN UDP clients)"
|
||||||
when: iptables_result is changed
|
when: iptables_result is changed
|
||||||
|
|
@ -1,6 +1,18 @@
|
||||||
---
|
---
|
||||||
- include_tasks: updates.yaml
|
- ansible.builtin.include_tasks:
|
||||||
- include_tasks: swap.yaml
|
file: updates.yaml
|
||||||
|
apply:
|
||||||
|
become: true
|
||||||
|
|
||||||
|
- ansible.builtin.include_tasks:
|
||||||
|
file: swap.yaml
|
||||||
|
apply:
|
||||||
|
become: true
|
||||||
when: configure_swap is defined
|
when: configure_swap is defined
|
||||||
- include_tasks: iptables.yaml
|
|
||||||
|
|
||||||
|
- ansible.builtin.include_tasks:
|
||||||
|
file: iptables.yaml
|
||||||
|
apply:
|
||||||
|
become: true
|
||||||
when: ip_tables_coonfig is defined
|
when: ip_tables_coonfig is defined
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue