Merge branch 'master' into add-dnsmasq

This commit is contained in:
Sergey Malyuk
2025-12-11 10:54:12 +03:00
22 changed files with 392 additions and 1 deletions

View File

@@ -26,6 +26,10 @@ jobs:
# run: ansible-galaxy install -r requirements.yml # run: ansible-galaxy install -r requirements.yml
# shell: micromamba-shell {0} # shell: micromamba-shell {0}
- name: "Install community.general collection"
run: ansible-galaxy collection install community.general
shell: micromamba-shell {0}
- name: Check workflow files themselves with ActionLint - name: Check workflow files themselves with ActionLint
run: actionlint run: actionlint
shell: micromamba-shell {0} shell: micromamba-shell {0}

View File

@@ -78,6 +78,10 @@ jobs:
run: ansible-galaxy install -r requirements.yml run: ansible-galaxy install -r requirements.yml
shell: micromamba-shell {0} shell: micromamba-shell {0}
- name: "Install community.general collection"
run: ansible-galaxy collection install community.general
shell: micromamba-shell {0}
- name: "Run Molecule tests" - name: "Run Molecule tests"
if: ${{ matrix.role != '__no_role__' }} if: ${{ matrix.role != '__no_role__' }}
working-directory: ${{ matrix.role }} working-directory: ${{ matrix.role }}

View File

@@ -7,3 +7,4 @@
- [mount_device](roles/mount_device/README.md) - [mount_device](roles/mount_device/README.md)
- [alertmanager](roles/alertmanager/README.md) - [alertmanager](roles/alertmanager/README.md)
- [wg_hub](roles/wg_hub/README.md)

View File

@@ -1,7 +1,7 @@
--- ---
namespace: genlab namespace: genlab
name: common name: common
version: 0.0.1 version: 0.4.0
readme: README.md readme: README.md
authors: authors:
- Alexander Gorelyshev (corvus-migratorius@proton.me) - Alexander Gorelyshev (corvus-migratorius@proton.me)

37
roles/ufw/README.md Normal file
View File

@@ -0,0 +1,37 @@
template
=========
Whitelist network ports with UFW
Requirements
------------
None
Role Variables
--------------
None
Dependencies
------------
None
Example Playbook
----------------
```yaml
roles:
- role: genlab.ufw
```
License
-------
BSD
Author Information
------------------
corvus-migratorius@proton.me

View File

@@ -0,0 +1,4 @@
---
ufw_rules: []
ufw_limit_ssh: false
ufw_openssh_port: 22

View File

@@ -0,0 +1,4 @@
---
- name: "Reload-ufw"
community.general.ufw:
state: reloaded

17
roles/ufw/meta/main.yml Normal file
View File

@@ -0,0 +1,17 @@
---
galaxy_info:
role_name: ufw
namespace: genlab
author: "Alexander Gorelyshev"
company: "Genlab, LLC"
description: "Whitelist network ports with UFW"
license: "MIT"
min_ansible_version: "2.1"
platforms:
- name: "Ubuntu"
versions: ["focal", "jammy"]
galaxy_tags: []
dependencies: []

View File

@@ -0,0 +1,17 @@
---
- name: Converge
hosts: all
vars:
custom_rules:
- port: 80
- port: 9080
src: "10.2.1.0/24"
- interface: eth0@if288
direction: in
comment: "Allow all incoming traffic on eth0@if288"
roles:
- role: genlab.common.ufw
disable_ipv6: true
ufw_limit_ssh: true
ufw_rules: "{{ custom_rules }}"

View File

@@ -0,0 +1,27 @@
---
dependency:
name: galaxy
driver:
name: docker
platforms:
- name: ubuntu
image: geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2204}-ansible:latest
pre_build_image: true
command: ${MOLECULE_DOCKER_COMMAND:-""}
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup:rw
cgroupns_mode: host
privileged: true
provisioner:
name: ansible
verifier:
name: ansible
lint: |
set -e
yamllint .
ansible-lint .

View File

@@ -0,0 +1,28 @@
---
- name: Verify
hosts: all
gather_facts: false
any_errors_fatal: true
tasks:
- name: "Get the UFW status"
register: ufw_status
changed_when: false
ansible.builtin.command:
cmd: ufw status
- name: "Verify expected UFW status"
vars:
expected:
- "Status: active"
- ""
- "To Action From"
- "-- ------ ----"
- "22/tcp LIMIT Anywhere "
- "80 ALLOW Anywhere "
- "9080 ALLOW 10.2.1.0/24 "
- "Anywhere on eth0@if288 ALLOW Anywhere # Allow all incoming traffic on eth0@if288"
ansible.builtin.assert:
that: ufw_status.stdout_lines == expected
success_msg: "UFW has the expected state"
fail_msg: "Unexpected UFW state (some rules may have not been applied correctly)"

54
roles/ufw/tasks/main.yml Normal file
View File

@@ -0,0 +1,54 @@
---
- name: "Ensure that ufw is installed"
ansible.builtin.apt:
name: ufw
update_cache: true
- name: "Disable IPv6"
when: (disable_ipv6 is defined) and (disable_ipv6 is true)
ansible.builtin.lineinfile:
path: /etc/default/ufw
regexp: ^IPV6
line: IPV6=no
- name: "Deny incoming connections"
notify: Reload-ufw
community.general.ufw:
direction: incoming
proto: any
policy: deny
- name: "Allow outgoing connections"
notify: Reload-ufw
community.general.ufw:
direction: outgoing
proto: any
policy: allow
- name: "Allow SSH access"
notify: Reload-ufw
community.general.ufw:
rule: "{{ ufw_limit_ssh | ternary('limit', 'allow') }}"
port: "{{ ufw_openssh_port }}"
proto: tcp
- name: "Set whitelist rules"
notify: Reload-ufw
loop: "{{ ufw_rules }}"
community.general.ufw:
rule: "{{ item.rule | default('allow') }}"
comment: "{{ item.comment | default(omit) }}"
port: "{{ item.port | default(omit) }}"
proto: "{{ item.proto | default('any') }}"
src: "{{ item.src | default('any') }}"
dest: "{{ item.dest | default(omit) }}"
interface: "{{ item.interface | default(omit) }}"
direction: "{{ item.direction | default(omit) }}"
route: "{{ item.route | default(false) }}"
- name: "Enable the ufw service"
community.general.ufw:
state: enabled
- name: "Flush handlers"
ansible.builtin.meta: flush_handlers

1
roles/ufw/vars/main.yml Normal file
View File

@@ -0,0 +1 @@
---

43
roles/wg_hub/README.md Normal file
View File

@@ -0,0 +1,43 @@
template
=========
Template for Ansible role monorepos.
⚠️ Do not forget to update:
- `meta/main.yml`
- Conda/Mamba manifests
- this README =)
Requirements
------------
None
Role Variables
--------------
None
Dependencies
------------
None
Example Playbook
----------------
```yaml
roles:
- role: genlab.template
```
License
-------
BSD
Author Information
------------------
corvus-migratorius@proton.me

View File

@@ -0,0 +1,7 @@
---
wg_hub_iface_name: wg0
wg_hub_host_id: hub
wg_hub_ipv4_vpn_addr: 10.0.0.254
wg_hub_ipv4_vpn_cidr: 24
wg_hub_wg_port: 51820
wg_hub_hide_secrets: true

View File

@@ -0,0 +1,7 @@
---
- name: "Run the Wireguard service"
ansible.builtin.systemd_service:
name: wg-quick@{{ wg_hub_iface_name | replace("-", "_") }}
state: restarted
enabled: true
daemon_reload: true

View File

@@ -0,0 +1,17 @@
---
galaxy_info:
role_name: "wg_hub"
namespace: genlab
author: "Alexander Gorelyshev"
company: "Genlab, LLC"
description: ""
license: "MIT"
min_ansible_version: "2.1"
platforms:
- name: "Ubuntu"
versions: ["jammy", "noble"]
galaxy_tags: []
dependencies: []

View File

@@ -0,0 +1,24 @@
---
- name: Converge
hosts: all
vars:
wg_hub_iface_name: adm
wg_hub_ipv4_vpn_addr: 10.0.0.254
wg_hub_ipv4_vpn_cidr: 24
wg_hub_wg_port: 51820
wg_hub_wg_pkey: gABk6e/n3UDgudEVlUrEVcVdn0tc0YVDeCASsI10QFA=
wg_hub_wg_pubkey: EvcoZ21/p0AHz5y95jwjVIR9puljc2kXqh/f3U1A4nk=
wg_hub_hide_secrets: false
# dns_server: 127.0.0.1:5300 # doesn't work in Github Actions environment
peers:
- wg_hub_host_id: alpha
wg_hub_ipv4_vpn_addr: 10.0.0.1
wg_hub_wg_pubkey: LfEJgNiJ05nx4nWB0Pj3wS3WRyFq567fsdDh4XZqRF0=
wg_psk: i3JCrQOfptZhgpL+BTm/65MPW/ljJexCgiuWMIqZJYo=
- wg_hub_host_id: beta
wg_hub_ipv4_vpn_addr: 10.0.0.2
wg_hub_wg_pubkey: oq3Fcwwfxsi5f5UHcZKtxMwQ2aSeHOUe3r35soUUYzU=
wg_psk: Z/z7Qo8hW97UcImYE/ZbCxpNmizfVhvl0dzygtvtYYg=
roles:
- role: genlab.common.wg_hub

View File

@@ -0,0 +1,27 @@
---
dependency:
name: galaxy
driver:
name: docker
platforms:
- name: ubuntu
image: geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2204}-ansible:latest
pre_build_image: true
command: ${MOLECULE_DOCKER_COMMAND:-""}
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup:rw
cgroupns_mode: host
privileged: true
provisioner:
name: ansible
verifier:
name: ansible
lint: |
set -e
yamllint .
ansible-lint .

View File

@@ -0,0 +1,13 @@
---
- name: Verify
hosts: all
gather_facts: false
any_errors_fatal: true
vars:
iface_name: adm
tasks:
- name: "Check that the Wireguard service is running"
ansible.builtin.service:
name: wg-quick@{{ iface_name }}
state: started

View File

@@ -0,0 +1,54 @@
---
- name: "Install wireguard system-wide"
ansible.builtin.apt:
name: wireguard
state: present
update_cache: true
cache_valid_time: 3600
- name: "Ensure no dashes in the interface name"
when: "'-' in wg_hub_iface_name"
ansible.builtin.fail:
msg: "The interface name must not contain dashes, got: '{{ wg_hub_iface_name }}'"
- name: "Create the Hub configuration file"
no_log: "{{ wg_hub_hide_secrets }}"
notify: "Run the Wireguard service"
ansible.builtin.blockinfile:
path: "/etc/wireguard/{{ wg_hub_iface_name }}.conf"
create: true
owner: root
group: root
mode: "0600"
state: present
block: |
[Interface]
Address = {{ wg_hub_ipv4_vpn_addr }}/32
ListenPort = {{ wg_hub_wg_port }}
PrivateKey = {{ wg_hub_wg_pkey }}
PreUp = sysctl -w net.ipv4.ip_forward=1
{% if dns_server is defined %}
PostUp = resolvectl dns %i {{ dns_server }}; resolvectl domain %i {{ wg_hub_iface_name }}.local
{% endif %}
PostDown = sysctl -w net.ipv4.ip_forward=0
- name: "Add [Peer] sections to the Hub configuration file"
no_log: "{{ wg_hub_hide_secrets }}"
notify: "Run the Wireguard service"
loop: "{{ peers }}"
vars:
domain_name: "{{ item.wg_hub_host_id }}.{{ wg_hub_iface_name }}.local"
ansible.builtin.blockinfile:
path: "/etc/wireguard/{{ wg_hub_iface_name }}.conf"
owner: root
group: root
mode: "0600"
marker: "# {mark} ANSIBLE MANAGED SPOKE BLOCK: {{ domain_name }}"
block: |
#
[Peer] # {{ domain_name }}
PublicKey = {{ item.wg_hub_wg_pubkey }}
PresharedKey = {{ item.wg_psk }}
AllowedIPs = {{ item.wg_hub_ipv4_vpn_addr }}/32
#

View File

@@ -0,0 +1 @@
---