Compare commits

..

42 commits

Author SHA1 Message Date
69c36161be
unbound(role): add config flag in README
Some checks failed
/ build (pull_request) Successful in 29s
/ Ansible Lint (push) Failing after 2m43s
/ Ansible Lint (pull_request) Failing after 2m42s
2026-08-07 22:48:55 +02:00
b57b216d7b
auth-dns(host): ccchh.net remove unused
Some checks failed
/ build (pull_request) Successful in 31s
/ Ansible Lint (pull_request) Failing after 2m47s
/ Ansible Lint (push) Failing after 2m54s
2026-08-07 22:35:22 +02:00
251f0c61d2
z9-router(host): remove netwan, vlan55 untagged, add and fix DNS, fix formatting 2026-08-07 22:34:03 +02:00
71f39678d1
kea_dhcp(role): seperate package installes 2026-08-07 22:29:34 +02:00
1ac7f13e79
kea_dhcp(role): update README 2026-08-07 22:29:08 +02:00
21585c6271
kea_dhcp(role): remove unused 2026-08-07 22:28:44 +02:00
0fb738411c
unbound(role): update readme and move task block to top level and remove unused 2026-08-07 22:27:48 +02:00
031fa6af9c
light(host): remove resolver from nginx conf 2026-08-02 16:45:50 +02:00
80ce470e04
auth-dns(host): remove unused unfi ipv6 and specify comments 2026-08-02 16:43:12 +02:00
164c7c1447
README.md: correct sentence
Some checks failed
/ build (pull_request) Successful in 32s
/ Ansible Lint (pull_request) Failing after 2m59s
/ Ansible Lint (push) Failing after 3m4s
2026-08-02 02:35:23 +02:00
210da2ab4d
z9-router(host): move yate from vlan 55 to 52
Some checks failed
/ build (pull_request) Successful in 30s
/ Ansible Lint (push) Failing after 2m38s
/ Ansible Lint (pull_request) Failing after 2m41s
2026-08-02 00:03:07 +02:00
84fe7fa4c0
z9-router(host): change mac address of yate in dhcp
Some checks failed
/ build (pull_request) Successful in 31s
/ Ansible Lint (pull_request) Failing after 2m41s
/ Ansible Lint (push) Failing after 2m42s
2026-08-01 23:58:27 +02:00
ab6e812244
z9-router(host): add dhcp and dns for dooris-legacy
Some checks failed
/ build (pull_request) Successful in 53s
/ Ansible Lint (push) Failing after 3m0s
/ Ansible Lint (pull_request) Failing after 3m1s
2026-08-01 23:31:06 +02:00
2f8b38b6a1
z9-router(host): change vlan 54 to 55 and remove netwan move vlan 400 to netlan 2026-08-01 23:30:36 +02:00
d2f91f2f28
general: update gitignore
Some checks failed
/ Ansible Lint (pull_request) Failing after 5s
/ Ansible Lint (push) Failing after 6s
/ build (pull_request) Failing after 18s
2026-07-31 21:08:25 +02:00
162da4b9f6
z9-router(host): update host kea config
- edit config to work with update kea role
- fix ipv6 addresses
2026-07-31 21:08:25 +02:00
97b02ab59a
unbound(role): fix some unbound setup stuff 2026-07-31 21:08:25 +02:00
32fea8c540
kea_dhcp(role): update to newest fux noc version 2026-07-31 21:08:25 +02:00
86710851b4
z9-router(host): nftables conf fix indent and allow dhcpv6 2026-07-31 21:08:25 +02:00
9dcdac403c
unbound(role): fix systemd unit of prometheus exporter 2026-07-31 21:08:25 +02:00
3df834021a
z9-router(host): fix systemd-networkd configs 2026-07-31 21:08:25 +02:00
114dfa5ebf
unbound(role): fix unbound prometheus exporter install on debian
- download debian image from github und verify checksum
- setup systemd service unit
2026-07-31 21:08:24 +02:00
ce94115331
unbound(role): fix unbound config template
- fix some indentation problems
- fix access control
- fix remote control unix socket and thrust anchor file (because debain
appamour ist annoying)
  - add unbound-anchor package
2026-07-31 21:08:24 +02:00
784ea057c0
kea_dhcp(role): fix include wars check 2026-07-31 21:08:24 +02:00
240315190c
z9(pve01): change thinkcccore0 to pve01 2026-07-31 21:08:24 +02:00
4bf213920b
z9(group): remove all old ip references and change them to new ones 2026-07-31 21:08:24 +02:00
1fd1cdad39
z9(group): remove all z9 references as subdomain 2026-07-31 21:04:45 +02:00
a6799bc905
unbound(role): move resolvd vars to task 2026-07-31 21:04:45 +02:00
70bcc322e6
unbound(role): make unbound thread number configurable 2026-07-31 21:04:45 +02:00
08c098766a
unbound(role): reformat config template and use all vcpus 2026-07-31 21:04:45 +02:00
2bed99ef0f
unbound(role): remove tags inside role 2026-07-31 21:04:45 +02:00
1eea864297
unbound(role): add FIXME note to unbound prometheus exporter install 2026-07-31 21:04:44 +02:00
0ca1ad0760
unbound(role): use existing deploy_systemd_resolved_config role and some reordering 2026-07-31 21:04:44 +02:00
c950dd7ba7
kea_dhcp(role): make stork-agent.env smaller and add link to documentation 2026-07-31 21:04:44 +02:00
baa439f0b2
kea_dhcp(role): fix indentation in template 2026-07-31 21:04:44 +02:00
d5aa0001cd
kea_dhcp(role): add README.md 2026-07-31 21:04:44 +02:00
04c4bac819
kea_dhcp(role): some fixes and removing arch part
- remove tags from tasks
- remove archlinux part
- use debian default package for kea
2026-07-31 21:04:44 +02:00
aff7431cdd
z9-router(host): fix some spelling and a wireguard peer address 2026-07-31 21:04:44 +02:00
969f7b4c8d
z9-router(host): add ansible pull 2026-07-31 21:04:44 +02:00
608437746b
z9-router(host): rename rt1 to z9-router 2026-07-31 21:04:43 +02:00
a5d8b11517
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-07-31 21:04:43 +02:00
90f4ecbcc5
rt1(z9 host): create host and configure networkd and nftables 2026-07-31 21:04:43 +02:00
10 changed files with 5 additions and 69 deletions

View file

@ -1,43 +0,0 @@
---
title: "Wiregard Admin VPN"
summary: How to configure your Wireguard client to access the Z9 network
---
# Onboarding
tbd. where to add your key
# Local Client Configuration
## Example Config
Replace `YOUR_IP_IN_DEC` with your IP in decimal, and `YOUR_IP_IN_HEX` with your IP in hexadecimal.
See [resources/z9/z9-router/systemd_networkd/10-wg56.netdev](resources/z9/z9-router/systemd_networkd/10-wg56.netdev) for the Wireguard endpoints configured on the router.
```
[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.89.214.YOUR_IP_IN_DEC/32, 2a07:c481:1:37::YOUR_IP_IN_HEX/128
[Peer]
PublicKey = fmlxjh3iOfpgrHQQpK3dyOD0BvDppGCUkFuMSroqQR4=
AllowedIPs = 10.89.208.0/20, 2a07:c481:1::/48, 212.12.48.120/29, 2a00:14b0:4200:3000::/64, 212.12.50.208/29, 2a00:14b0:42:100::/56, 212.12.51.128/28, 2a00:14b0:f000:23::/64
Endpoint = rt-wan.ccchh.net:51820
```
## AllowedIDs
The following prefixes should be tunneled to gain access to both CCCHH Z9 resources as well as Chaosknoten. It is also possible to run a default route through wireguard, but please do not abuse this as a general VPN for purposes other than admin tasks.
| Prefix | Description |
|--|--|
| [10.89.208.0/20](https://netbox.hamburg.ccc.de/ipam/prefixes/114/prefixes/) | prefix for CCCHH Z9 local networks |
| [2a07:c481:1::/48](https://netbox.hamburg.ccc.de/ipam/prefixes/50/) | prefix for CCCHH Z9 local networks |
| 212.12.48.120/29 | Fakep refix for hosts that come from [212.12.48.0/24](https://netbox.hamburg.ccc.de/ipam/prefixes/12/) |
| [2a00:14b0:4200:3000::/64](https://netbox.hamburg.ccc.de/ipam/prefixes/36/) | Public IPv6 in Wieske's shared network |
| [212.12.50.208/29](https://netbox.hamburg.ccc.de/ipam/prefixes/13/) | Public IPv4 for VMs on chaosknoten, routed by router |
| [2a00:14b0:42:100::/56](https://netbox.hamburg.ccc.de/ipam/prefixes/46/) | Public IPv6 for VMs on chaosknoten, routed by router |
| [212.12.51.128/28](https://netbox.hamburg.ccc.de/ipam/prefixes/15/) | IPv4 for VMs on chaosknoten, routed by Wieske |
| [2a00:14b0:f000:23::/64](https://netbox.hamburg.ccc.de/ipam/prefixes/35/) |IPv6 for VMs on chaosknoten, routed by Wieske |

View file

@ -1,2 +0,0 @@
# renovate: datasource=docker depName=codeberg.org/git-pages/git-pages
git_pages__version: latest

View file

@ -6,9 +6,3 @@ docker_compose__configuration_files:
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regexroute.conf.j2') }}"
- name: regfile.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regfile.conf.j2') }}"
- name: rmanager.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/rmanager.conf.j2') }}"
- name: yrtpchan.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/yrtpchan.conf.j2') }}"
- name: ysipchan.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/ysipchan.conf.j2') }}"

View file

@ -15,7 +15,7 @@ all:
ansible_host: waybackproxy.ccchh.net
ansible_user: chaos
yate:
ansible_host: yate.z9.ccchh.net
ansible_host: yate.ccchh.net
ansible_user: chaos
z9-router:
ansible_host: z9-router.ccchh.net

View file

@ -72,7 +72,7 @@ services:
restart: unless-stopped
command: ["uv", "run", "main.py", "sync"]
environment:
- DRY_RUN=false
- DRY_RUN=true
- KEYCLOAK_CLIENT_ID=mailman-sync
- KEYCLOAK_CLIENT_SECRET={{ secret__lists__keycloak_client_secret }}
- KEYCLOAK_REALM=ccchh

View file

@ -57,7 +57,7 @@ x-shared:
LETSENCRYPT_HOST:
LETSENCRYPT_EMAIL:
image: ${IMAGE_REPO:-ghcr.io/zammad/zammad}:${VERSION:-7.1.2}
image: ${IMAGE_REPO:-ghcr.io/zammad/zammad}:${VERSION:-6.5.3}
restart: ${RESTART:-always}
volumes:
- zammad-storage:/opt/zammad/storage
@ -76,7 +76,7 @@ services:
user: 0:0
zammad-elasticsearch:
image: elasticsearch:${ELASTICSEARCH_VERSION:-8.19.19}
image: elasticsearch:${ELASTICSEARCH_VERSION:-8.19.13}
restart: ${RESTART:-always}
volumes:
- elasticsearch-data:/usr/share/elasticsearch/data

View file

@ -1,4 +0,0 @@
; https://github.com/eventphone/yate/blob/master/conf.d/rmanager.conf.sample
[general]
; password: string: Password required to authenticate as admin, default empty!
;password=

View file

@ -1,4 +0,0 @@
; https://github.com/eventphone/yate/blob/master/conf.d/yrtpchan.conf.sample
[general]
minport=42000
maxport=42999

View file

@ -1,6 +0,0 @@
; Setting for all SIP channels
; https://github.com/eventphone/yate/blob/master/conf.d/ysipchan.conf.sample
[general]
; try to avoid `Transport(general) received likely truncated packet with length 1500, try to increase maxpkt`
maxpkt=8192

View file

@ -45,3 +45,4 @@ argument_specs:
apiKey:
required: true
type: str