Merge branch 'master' into add-dnsmasq
This commit is contained in:
4
.github/workflows/linters.yml
vendored
4
.github/workflows/linters.yml
vendored
@@ -26,6 +26,10 @@ jobs:
|
||||
# run: ansible-galaxy install -r requirements.yml
|
||||
# shell: micromamba-shell {0}
|
||||
|
||||
- name: "Install community.general collection"
|
||||
run: ansible-galaxy collection install community.general
|
||||
shell: micromamba-shell {0}
|
||||
|
||||
- name: Check workflow files themselves with ActionLint
|
||||
run: actionlint
|
||||
shell: micromamba-shell {0}
|
||||
|
||||
4
.github/workflows/molecule.yml
vendored
4
.github/workflows/molecule.yml
vendored
@@ -78,6 +78,10 @@ jobs:
|
||||
run: ansible-galaxy install -r requirements.yml
|
||||
shell: micromamba-shell {0}
|
||||
|
||||
- name: "Install community.general collection"
|
||||
run: ansible-galaxy collection install community.general
|
||||
shell: micromamba-shell {0}
|
||||
|
||||
- name: "Run Molecule tests"
|
||||
if: ${{ matrix.role != '__no_role__' }}
|
||||
working-directory: ${{ matrix.role }}
|
||||
|
||||
@@ -7,3 +7,4 @@
|
||||
|
||||
- [mount_device](roles/mount_device/README.md)
|
||||
- [alertmanager](roles/alertmanager/README.md)
|
||||
- [wg_hub](roles/wg_hub/README.md)
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
namespace: genlab
|
||||
name: common
|
||||
version: 0.0.1
|
||||
version: 0.4.0
|
||||
readme: README.md
|
||||
authors:
|
||||
- Alexander Gorelyshev (corvus-migratorius@proton.me)
|
||||
|
||||
37
roles/ufw/README.md
Normal file
37
roles/ufw/README.md
Normal file
@@ -0,0 +1,37 @@
|
||||
template
|
||||
=========
|
||||
|
||||
Whitelist network ports with UFW
|
||||
|
||||
Requirements
|
||||
------------
|
||||
|
||||
None
|
||||
|
||||
Role Variables
|
||||
--------------
|
||||
|
||||
None
|
||||
|
||||
Dependencies
|
||||
------------
|
||||
|
||||
None
|
||||
|
||||
Example Playbook
|
||||
----------------
|
||||
|
||||
```yaml
|
||||
roles:
|
||||
- role: genlab.ufw
|
||||
```
|
||||
|
||||
License
|
||||
-------
|
||||
|
||||
BSD
|
||||
|
||||
Author Information
|
||||
------------------
|
||||
|
||||
corvus-migratorius@proton.me
|
||||
4
roles/ufw/defaults/main.yml
Normal file
4
roles/ufw/defaults/main.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
ufw_rules: []
|
||||
ufw_limit_ssh: false
|
||||
ufw_openssh_port: 22
|
||||
4
roles/ufw/handlers/main.yml
Normal file
4
roles/ufw/handlers/main.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
- name: "Reload-ufw"
|
||||
community.general.ufw:
|
||||
state: reloaded
|
||||
17
roles/ufw/meta/main.yml
Normal file
17
roles/ufw/meta/main.yml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
galaxy_info:
|
||||
role_name: ufw
|
||||
namespace: genlab
|
||||
author: "Alexander Gorelyshev"
|
||||
company: "Genlab, LLC"
|
||||
description: "Whitelist network ports with UFW"
|
||||
license: "MIT"
|
||||
min_ansible_version: "2.1"
|
||||
|
||||
platforms:
|
||||
- name: "Ubuntu"
|
||||
versions: ["focal", "jammy"]
|
||||
|
||||
galaxy_tags: []
|
||||
|
||||
dependencies: []
|
||||
17
roles/ufw/molecule/default/converge.yml
Normal file
17
roles/ufw/molecule/default/converge.yml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
- name: Converge
|
||||
hosts: all
|
||||
vars:
|
||||
custom_rules:
|
||||
- port: 80
|
||||
- port: 9080
|
||||
src: "10.2.1.0/24"
|
||||
- interface: eth0@if288
|
||||
direction: in
|
||||
comment: "Allow all incoming traffic on eth0@if288"
|
||||
|
||||
roles:
|
||||
- role: genlab.common.ufw
|
||||
disable_ipv6: true
|
||||
ufw_limit_ssh: true
|
||||
ufw_rules: "{{ custom_rules }}"
|
||||
27
roles/ufw/molecule/default/molecule.yml
Normal file
27
roles/ufw/molecule/default/molecule.yml
Normal file
@@ -0,0 +1,27 @@
|
||||
---
|
||||
dependency:
|
||||
name: galaxy
|
||||
|
||||
driver:
|
||||
name: docker
|
||||
|
||||
platforms:
|
||||
- name: ubuntu
|
||||
image: geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2204}-ansible:latest
|
||||
pre_build_image: true
|
||||
command: ${MOLECULE_DOCKER_COMMAND:-""}
|
||||
volumes:
|
||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
||||
cgroupns_mode: host
|
||||
privileged: true
|
||||
|
||||
provisioner:
|
||||
name: ansible
|
||||
|
||||
verifier:
|
||||
name: ansible
|
||||
|
||||
lint: |
|
||||
set -e
|
||||
yamllint .
|
||||
ansible-lint .
|
||||
28
roles/ufw/molecule/default/verify.yml
Normal file
28
roles/ufw/molecule/default/verify.yml
Normal file
@@ -0,0 +1,28 @@
|
||||
---
|
||||
- name: Verify
|
||||
hosts: all
|
||||
gather_facts: false
|
||||
any_errors_fatal: true
|
||||
|
||||
tasks:
|
||||
- name: "Get the UFW status"
|
||||
register: ufw_status
|
||||
changed_when: false
|
||||
ansible.builtin.command:
|
||||
cmd: ufw status
|
||||
|
||||
- name: "Verify expected UFW status"
|
||||
vars:
|
||||
expected:
|
||||
- "Status: active"
|
||||
- ""
|
||||
- "To Action From"
|
||||
- "-- ------ ----"
|
||||
- "22/tcp LIMIT Anywhere "
|
||||
- "80 ALLOW Anywhere "
|
||||
- "9080 ALLOW 10.2.1.0/24 "
|
||||
- "Anywhere on eth0@if288 ALLOW Anywhere # Allow all incoming traffic on eth0@if288"
|
||||
ansible.builtin.assert:
|
||||
that: ufw_status.stdout_lines == expected
|
||||
success_msg: "UFW has the expected state"
|
||||
fail_msg: "Unexpected UFW state (some rules may have not been applied correctly)"
|
||||
54
roles/ufw/tasks/main.yml
Normal file
54
roles/ufw/tasks/main.yml
Normal file
@@ -0,0 +1,54 @@
|
||||
---
|
||||
- name: "Ensure that ufw is installed"
|
||||
ansible.builtin.apt:
|
||||
name: ufw
|
||||
update_cache: true
|
||||
|
||||
- name: "Disable IPv6"
|
||||
when: (disable_ipv6 is defined) and (disable_ipv6 is true)
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/default/ufw
|
||||
regexp: ^IPV6
|
||||
line: IPV6=no
|
||||
|
||||
- name: "Deny incoming connections"
|
||||
notify: Reload-ufw
|
||||
community.general.ufw:
|
||||
direction: incoming
|
||||
proto: any
|
||||
policy: deny
|
||||
|
||||
- name: "Allow outgoing connections"
|
||||
notify: Reload-ufw
|
||||
community.general.ufw:
|
||||
direction: outgoing
|
||||
proto: any
|
||||
policy: allow
|
||||
|
||||
- name: "Allow SSH access"
|
||||
notify: Reload-ufw
|
||||
community.general.ufw:
|
||||
rule: "{{ ufw_limit_ssh | ternary('limit', 'allow') }}"
|
||||
port: "{{ ufw_openssh_port }}"
|
||||
proto: tcp
|
||||
|
||||
- name: "Set whitelist rules"
|
||||
notify: Reload-ufw
|
||||
loop: "{{ ufw_rules }}"
|
||||
community.general.ufw:
|
||||
rule: "{{ item.rule | default('allow') }}"
|
||||
comment: "{{ item.comment | default(omit) }}"
|
||||
port: "{{ item.port | default(omit) }}"
|
||||
proto: "{{ item.proto | default('any') }}"
|
||||
src: "{{ item.src | default('any') }}"
|
||||
dest: "{{ item.dest | default(omit) }}"
|
||||
interface: "{{ item.interface | default(omit) }}"
|
||||
direction: "{{ item.direction | default(omit) }}"
|
||||
route: "{{ item.route | default(false) }}"
|
||||
|
||||
- name: "Enable the ufw service"
|
||||
community.general.ufw:
|
||||
state: enabled
|
||||
|
||||
- name: "Flush handlers"
|
||||
ansible.builtin.meta: flush_handlers
|
||||
1
roles/ufw/vars/main.yml
Normal file
1
roles/ufw/vars/main.yml
Normal file
@@ -0,0 +1 @@
|
||||
---
|
||||
43
roles/wg_hub/README.md
Normal file
43
roles/wg_hub/README.md
Normal file
@@ -0,0 +1,43 @@
|
||||
template
|
||||
=========
|
||||
|
||||
Template for Ansible role monorepos.
|
||||
|
||||
⚠️ Do not forget to update:
|
||||
|
||||
- `meta/main.yml`
|
||||
- Conda/Mamba manifests
|
||||
- this README =)
|
||||
|
||||
Requirements
|
||||
------------
|
||||
|
||||
None
|
||||
|
||||
Role Variables
|
||||
--------------
|
||||
|
||||
None
|
||||
|
||||
Dependencies
|
||||
------------
|
||||
|
||||
None
|
||||
|
||||
Example Playbook
|
||||
----------------
|
||||
|
||||
```yaml
|
||||
roles:
|
||||
- role: genlab.template
|
||||
```
|
||||
|
||||
License
|
||||
-------
|
||||
|
||||
BSD
|
||||
|
||||
Author Information
|
||||
------------------
|
||||
|
||||
corvus-migratorius@proton.me
|
||||
7
roles/wg_hub/defaults/main.yml
Normal file
7
roles/wg_hub/defaults/main.yml
Normal file
@@ -0,0 +1,7 @@
|
||||
---
|
||||
wg_hub_iface_name: wg0
|
||||
wg_hub_host_id: hub
|
||||
wg_hub_ipv4_vpn_addr: 10.0.0.254
|
||||
wg_hub_ipv4_vpn_cidr: 24
|
||||
wg_hub_wg_port: 51820
|
||||
wg_hub_hide_secrets: true
|
||||
7
roles/wg_hub/handlers/main.yml
Normal file
7
roles/wg_hub/handlers/main.yml
Normal file
@@ -0,0 +1,7 @@
|
||||
---
|
||||
- name: "Run the Wireguard service"
|
||||
ansible.builtin.systemd_service:
|
||||
name: wg-quick@{{ wg_hub_iface_name | replace("-", "_") }}
|
||||
state: restarted
|
||||
enabled: true
|
||||
daemon_reload: true
|
||||
17
roles/wg_hub/meta/main.yml
Normal file
17
roles/wg_hub/meta/main.yml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
galaxy_info:
|
||||
role_name: "wg_hub"
|
||||
namespace: genlab
|
||||
author: "Alexander Gorelyshev"
|
||||
company: "Genlab, LLC"
|
||||
description: ""
|
||||
license: "MIT"
|
||||
min_ansible_version: "2.1"
|
||||
|
||||
platforms:
|
||||
- name: "Ubuntu"
|
||||
versions: ["jammy", "noble"]
|
||||
|
||||
galaxy_tags: []
|
||||
|
||||
dependencies: []
|
||||
24
roles/wg_hub/molecule/default/converge.yml
Normal file
24
roles/wg_hub/molecule/default/converge.yml
Normal file
@@ -0,0 +1,24 @@
|
||||
---
|
||||
- name: Converge
|
||||
hosts: all
|
||||
vars:
|
||||
wg_hub_iface_name: adm
|
||||
wg_hub_ipv4_vpn_addr: 10.0.0.254
|
||||
wg_hub_ipv4_vpn_cidr: 24
|
||||
wg_hub_wg_port: 51820
|
||||
wg_hub_wg_pkey: gABk6e/n3UDgudEVlUrEVcVdn0tc0YVDeCASsI10QFA=
|
||||
wg_hub_wg_pubkey: EvcoZ21/p0AHz5y95jwjVIR9puljc2kXqh/f3U1A4nk=
|
||||
wg_hub_hide_secrets: false
|
||||
# dns_server: 127.0.0.1:5300 # doesn't work in Github Actions environment
|
||||
peers:
|
||||
- wg_hub_host_id: alpha
|
||||
wg_hub_ipv4_vpn_addr: 10.0.0.1
|
||||
wg_hub_wg_pubkey: LfEJgNiJ05nx4nWB0Pj3wS3WRyFq567fsdDh4XZqRF0=
|
||||
wg_psk: i3JCrQOfptZhgpL+BTm/65MPW/ljJexCgiuWMIqZJYo=
|
||||
- wg_hub_host_id: beta
|
||||
wg_hub_ipv4_vpn_addr: 10.0.0.2
|
||||
wg_hub_wg_pubkey: oq3Fcwwfxsi5f5UHcZKtxMwQ2aSeHOUe3r35soUUYzU=
|
||||
wg_psk: Z/z7Qo8hW97UcImYE/ZbCxpNmizfVhvl0dzygtvtYYg=
|
||||
|
||||
roles:
|
||||
- role: genlab.common.wg_hub
|
||||
27
roles/wg_hub/molecule/default/molecule.yml
Normal file
27
roles/wg_hub/molecule/default/molecule.yml
Normal file
@@ -0,0 +1,27 @@
|
||||
---
|
||||
dependency:
|
||||
name: galaxy
|
||||
|
||||
driver:
|
||||
name: docker
|
||||
|
||||
platforms:
|
||||
- name: ubuntu
|
||||
image: geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2204}-ansible:latest
|
||||
pre_build_image: true
|
||||
command: ${MOLECULE_DOCKER_COMMAND:-""}
|
||||
volumes:
|
||||
- /sys/fs/cgroup:/sys/fs/cgroup:rw
|
||||
cgroupns_mode: host
|
||||
privileged: true
|
||||
|
||||
provisioner:
|
||||
name: ansible
|
||||
|
||||
verifier:
|
||||
name: ansible
|
||||
|
||||
lint: |
|
||||
set -e
|
||||
yamllint .
|
||||
ansible-lint .
|
||||
13
roles/wg_hub/molecule/default/verify.yml
Normal file
13
roles/wg_hub/molecule/default/verify.yml
Normal file
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: Verify
|
||||
hosts: all
|
||||
gather_facts: false
|
||||
any_errors_fatal: true
|
||||
vars:
|
||||
iface_name: adm
|
||||
|
||||
tasks:
|
||||
- name: "Check that the Wireguard service is running"
|
||||
ansible.builtin.service:
|
||||
name: wg-quick@{{ iface_name }}
|
||||
state: started
|
||||
54
roles/wg_hub/tasks/main.yml
Normal file
54
roles/wg_hub/tasks/main.yml
Normal file
@@ -0,0 +1,54 @@
|
||||
---
|
||||
- name: "Install wireguard system-wide"
|
||||
ansible.builtin.apt:
|
||||
name: wireguard
|
||||
state: present
|
||||
update_cache: true
|
||||
cache_valid_time: 3600
|
||||
|
||||
- name: "Ensure no dashes in the interface name"
|
||||
when: "'-' in wg_hub_iface_name"
|
||||
ansible.builtin.fail:
|
||||
msg: "The interface name must not contain dashes, got: '{{ wg_hub_iface_name }}'"
|
||||
|
||||
- name: "Create the Hub configuration file"
|
||||
no_log: "{{ wg_hub_hide_secrets }}"
|
||||
notify: "Run the Wireguard service"
|
||||
ansible.builtin.blockinfile:
|
||||
path: "/etc/wireguard/{{ wg_hub_iface_name }}.conf"
|
||||
create: true
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0600"
|
||||
state: present
|
||||
block: |
|
||||
[Interface]
|
||||
Address = {{ wg_hub_ipv4_vpn_addr }}/32
|
||||
ListenPort = {{ wg_hub_wg_port }}
|
||||
PrivateKey = {{ wg_hub_wg_pkey }}
|
||||
|
||||
PreUp = sysctl -w net.ipv4.ip_forward=1
|
||||
{% if dns_server is defined %}
|
||||
PostUp = resolvectl dns %i {{ dns_server }}; resolvectl domain %i {{ wg_hub_iface_name }}.local
|
||||
{% endif %}
|
||||
PostDown = sysctl -w net.ipv4.ip_forward=0
|
||||
|
||||
- name: "Add [Peer] sections to the Hub configuration file"
|
||||
no_log: "{{ wg_hub_hide_secrets }}"
|
||||
notify: "Run the Wireguard service"
|
||||
loop: "{{ peers }}"
|
||||
vars:
|
||||
domain_name: "{{ item.wg_hub_host_id }}.{{ wg_hub_iface_name }}.local"
|
||||
ansible.builtin.blockinfile:
|
||||
path: "/etc/wireguard/{{ wg_hub_iface_name }}.conf"
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0600"
|
||||
marker: "# {mark} ANSIBLE MANAGED SPOKE BLOCK: {{ domain_name }}"
|
||||
block: |
|
||||
#
|
||||
[Peer] # {{ domain_name }}
|
||||
PublicKey = {{ item.wg_hub_wg_pubkey }}
|
||||
PresharedKey = {{ item.wg_psk }}
|
||||
AllowedIPs = {{ item.wg_hub_ipv4_vpn_addr }}/32
|
||||
#
|
||||
1
roles/wg_hub/vars/main.yml
Normal file
1
roles/wg_hub/vars/main.yml
Normal file
@@ -0,0 +1 @@
|
||||
---
|
||||
Reference in New Issue
Block a user