Compare commits
1 commit
5efa02c79d
...
aec9ba7c12
| Author | SHA1 | Date | |
|---|---|---|---|
|
aec9ba7c12 |
11 changed files with 64 additions and 88 deletions
|
|
@ -1,6 +1,6 @@
|
||||||
dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str]
|
dooris_static_api_token: ENC[AES256_GCM,data:JbmbaXKxBouw/mFqZGcH8pi9Cb3Vyl4i0zV5ZqUwBkGmMuylj3ocLpZZ0Ur+gGGG0MIuFwOvfnctJFLTcVylNQ==,iv:tYpWo2rANvCJidaZ2L+e3dnEJByy0Y9PYbAvQDEZL7Q=,tag:NGqnEftvqAVRZOuJqkyCVQ==,type:str]
|
||||||
dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str]
|
secret__dooris_client_secret: ENC[AES256_GCM,data:v85gIBNH4s4j36crJ+Pb2lu2cdZpwz0xndHzBKZNGKg=,iv:Rlt6R7JMcHTAAVPiTtFaxqsWD8G5B9Ab3yqItYdFR+E=,tag:dlMHaxTMx3LgOzCsTLUdzw==,type:str]
|
||||||
dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str]
|
secret__dooris_ccujack_password: ENC[AES256_GCM,data:bHeftSA7eC1cSydBRumksRgw2v0=,iv:X/pfsvQPZREifGjHDGx8mVk2TDrlrRVb6MiAr01wI9o=,tag:ti//x7eDbheMG6Hsn2KBlg==,type:str]
|
||||||
ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str]
|
ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str]
|
||||||
secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str]
|
secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str]
|
||||||
sops:
|
sops:
|
||||||
|
|
@ -14,8 +14,8 @@ sops:
|
||||||
aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg==
|
aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
|
recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
|
||||||
lastmodified: "2026-07-23T16:56:18Z"
|
lastmodified: "2026-07-19T14:13:08Z"
|
||||||
mac: ENC[AES256_GCM,data:hdX55T++CCuklTmttDNI99hNs48hhK1LfastyrPiF/PYMjj2bXr6zrT+J4IurhZxs00kHLiiBe2sMkIRF4v66xoV7YaAfR9wrsrUOtG4T/YoLgSuCrZt35yXvA928XcSS92oUgR7uoD5y7ZkII3T0w4mOm4OVtBrjc9zGTwd3Zc=,iv:V9UzvQlVEfFVVz2ELDSwpI8rC6Xk5/RUmaAsxdkHsK0=,tag:rorczKSSUIbgYiPLtmyqRg==,type:str]
|
mac: ENC[AES256_GCM,data:ZjgYzR6w5Vw0yomgqFQyqfqeHlFExyh26K1cpt6dHSuokpmOBVZ2yMdKBpPbhzxtqTWW+7dTFFdRK0ksIan4Niq1Rvh+W+Gi0UfG0nD3541oODuceqWv8Itr6ke4C+x/VlfBoG0eiUfqVPuEE27vpGF5YM5xZ4lH0SIhexWbLU4=,iv:Zor5Kgpm3B9Z61BF2knDJn5woNx/QVNYbhdpPgwqQn0=,tag:cE2xBmvD+qDxyzXh2Md0TQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-05-20T02:08:48Z"
|
- created_at: "2026-05-20T02:08:48Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,23 @@
|
||||||
dooris__hostname: "dooris.ccchh.net"
|
dooris_url: "https://dooris.ccchh.net"
|
||||||
dooris__openid_client_id: "dooris"
|
|
||||||
dooris__ccujack_user: "dooris"
|
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'resources/z9/dooris/docker_compose/compose.yaml.j2') }}"
|
||||||
|
docker_compose__configuration_files: [ ]
|
||||||
|
|
||||||
certbot__acme_account_email_address: le-admin@hamburg.ccc.de
|
certbot__acme_account_email_address: le-admin@hamburg.ccc.de
|
||||||
|
certbot__certs:
|
||||||
|
- commonName: "dooris.ccchh.net"
|
||||||
|
challengeType: "dns-01-acme-dns"
|
||||||
|
dns_01_acme_dns:
|
||||||
|
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
|
||||||
|
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
|
||||||
|
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
|
||||||
|
certbot__new_cert_commands:
|
||||||
|
- "systemctl restart nginx.service"
|
||||||
|
|
||||||
|
nginx__version_spec: ""
|
||||||
|
nginx__deploy_redirect_conf: false
|
||||||
|
nginx__configurations:
|
||||||
|
- name: dooris.ccchh.net
|
||||||
|
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/dooris.ccchh.net.conf') }}"
|
||||||
|
- name: http_handler
|
||||||
|
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/http_handler.conf') }}"
|
||||||
|
|
|
||||||
|
|
@ -17,9 +17,11 @@ all:
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
certbot_hosts:
|
certbot_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
|
dooris:
|
||||||
light:
|
light:
|
||||||
docker_compose_hosts:
|
docker_compose_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
|
dooris:
|
||||||
waybackproxy:
|
waybackproxy:
|
||||||
yate:
|
yate:
|
||||||
foobazdmx_hosts:
|
foobazdmx_hosts:
|
||||||
|
|
@ -36,6 +38,7 @@ infrastructure_authorized_keys_hosts:
|
||||||
yate:
|
yate:
|
||||||
nginx_hosts:
|
nginx_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
|
dooris:
|
||||||
light:
|
light:
|
||||||
waybackproxy:
|
waybackproxy:
|
||||||
ola_hosts:
|
ola_hosts:
|
||||||
|
|
|
||||||
18
resources/z9/dooris/docker_compose/compose.yaml.j2
Normal file
18
resources/z9/dooris/docker_compose/compose.yaml.j2
Normal file
|
|
@ -0,0 +1,18 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
services:
|
||||||
|
dooris:
|
||||||
|
image: git.hamburg.ccc.de/ccchh/dooris:latest
|
||||||
|
environment:
|
||||||
|
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
|
||||||
|
DOORIS_OPENID_CLIENT_ID: dooris
|
||||||
|
DOORIS_OPENID_CLIENT_SECRET: "{{ secret__dooris_client_secret }}"
|
||||||
|
DOORIS_BASE_URL: https://dooris.ccchh.net
|
||||||
|
DOORIS_CCUJACK_USER: "dooris"
|
||||||
|
DOORIS_CCUJACK_PASSWORD: "{{ secret__dooris_ccujack_password }}"
|
||||||
|
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
|
||||||
|
DOORIS_STATIC_API_TOKENS: "{{ dooris_static_api_token }}"
|
||||||
|
network_mode: host
|
||||||
|
restart: unless-stopped
|
||||||
|
volumes:
|
||||||
|
- "./state:/srv/state/:rw"
|
||||||
|
|
@ -4,12 +4,12 @@ server {
|
||||||
listen [::]:443 ssl http2;
|
listen [::]:443 ssl http2;
|
||||||
listen 443 ssl http2;
|
listen 443 ssl http2;
|
||||||
|
|
||||||
server_name {{ dooris__hostname }};
|
server_name dooris.ccchh.net;
|
||||||
|
|
||||||
ssl_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/fullchain.pem;
|
ssl_certificate /etc/letsencrypt/live/dooris.ccchh.net/fullchain.pem;
|
||||||
ssl_certificate_key /etc/letsencrypt/live/{{ dooris__hostname }}/privkey.pem;
|
ssl_certificate_key /etc/letsencrypt/live/dooris.ccchh.net/privkey.pem;
|
||||||
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
||||||
ssl_trusted_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/chain.pem;
|
ssl_trusted_certificate /etc/letsencrypt/live/dooris.ccchh.net/chain.pem;
|
||||||
|
|
||||||
# HSTS (ngx_http_headers_module is required) (63072000 seconds)
|
# HSTS (ngx_http_headers_module is required) (63072000 seconds)
|
||||||
add_header Strict-Transport-Security "max-age=63072000" always;
|
add_header Strict-Transport-Security "max-age=63072000" always;
|
||||||
|
|
@ -1,4 +1,3 @@
|
||||||
---
|
---
|
||||||
allow_duplicates: false
|
|
||||||
dependencies:
|
dependencies:
|
||||||
- role: docker
|
- role: docker
|
||||||
|
|
|
||||||
|
|
@ -1,32 +1,13 @@
|
||||||
argument_specs:
|
argument_specs:
|
||||||
main:
|
main:
|
||||||
options:
|
options:
|
||||||
dooris__static_api_token:
|
|
||||||
description: "A static token that is valid on the servers API and can operate locks"
|
|
||||||
required: true
|
|
||||||
type: str
|
|
||||||
|
|
||||||
dooris__hostname:
|
dooris_static_api_token:
|
||||||
description: "The hostname on which the dooris server is reachable"
|
description: "A static token that is valid on the servers API and can operate locks"
|
||||||
required: true
|
required: true
|
||||||
type: str
|
type: str
|
||||||
|
|
||||||
dooris__openid_client_id:
|
dooris_url:
|
||||||
description: "Client-ID in CCCHH ID for dooris"
|
description: "The URL on which the dooris server is reachable"
|
||||||
required: true
|
required: true
|
||||||
type: str
|
type: str
|
||||||
|
|
||||||
dooris__openid_client_secret:
|
|
||||||
description: "Client-Secret in CCCHH ID for dooris"
|
|
||||||
required: true
|
|
||||||
type: str
|
|
||||||
|
|
||||||
dooris__ccujack_user:
|
|
||||||
description: "Username for authentication against homematic ccujack"
|
|
||||||
required: true
|
|
||||||
type: str
|
|
||||||
|
|
||||||
dooris__ccujack_password:
|
|
||||||
description: "Password for authentication against homematic ccujack"
|
|
||||||
required: true
|
|
||||||
type: str
|
|
||||||
|
|
|
||||||
|
|
@ -1,27 +1,2 @@
|
||||||
dependencies:
|
dependencies:
|
||||||
- role: docker_compose
|
- docker_compose
|
||||||
vars:
|
|
||||||
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'compose.yaml.j2') }}"
|
|
||||||
docker_compose__configuration_files: []
|
|
||||||
|
|
||||||
- role: certbot
|
|
||||||
vars:
|
|
||||||
certbot__new_cert_commands:
|
|
||||||
- "systemctl restart nginx.service"
|
|
||||||
certbot__certs:
|
|
||||||
- commonName: "dooris.ccchh.net"
|
|
||||||
challengeType: "dns-01-acme-dns"
|
|
||||||
dns_01_acme_dns:
|
|
||||||
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
|
|
||||||
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
|
|
||||||
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
|
|
||||||
|
|
||||||
- role: nginx
|
|
||||||
vars:
|
|
||||||
nginx__version_spec: ""
|
|
||||||
nginx__deploy_redirect_conf: false
|
|
||||||
nginx__configurations:
|
|
||||||
- name: "{{ dooris__hostname }}"
|
|
||||||
content: "{{ lookup('ansible.builtin.template', 'nginx/site.conf') }}"
|
|
||||||
- name: http_handler
|
|
||||||
content: "{{ lookup('ansible.builtin.template', 'nginx/http_handler.conf') }}"
|
|
||||||
|
|
|
||||||
|
|
@ -1,17 +0,0 @@
|
||||||
---
|
|
||||||
services:
|
|
||||||
dooris:
|
|
||||||
image: git.hamburg.ccc.de/ccchh/dooris:latest
|
|
||||||
environment:
|
|
||||||
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
|
|
||||||
DOORIS_OPENID_CLIENT_ID: "{{ dooris__openid_client_id }}"
|
|
||||||
DOORIS_OPENID_CLIENT_SECRET: "{{ dooris__openid_client_secret }}"
|
|
||||||
DOORIS_BASE_URL: "https://{{ dooris__hostname }}"
|
|
||||||
DOORIS_CCUJACK_USER: "{{ dooris__ccujack_user }}"
|
|
||||||
DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}"
|
|
||||||
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
|
|
||||||
DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}"
|
|
||||||
network_mode: host
|
|
||||||
restart: unless-stopped
|
|
||||||
volumes:
|
|
||||||
- "./state:/srv/state/:rw"
|
|
||||||
|
|
@ -3,4 +3,4 @@
|
||||||
Match User dooris
|
Match User dooris
|
||||||
AuthorizedKeysFile /ansible_docker_compose/state/dooris_authorized_keys
|
AuthorizedKeysFile /ansible_docker_compose/state/dooris_authorized_keys
|
||||||
ForceCommand /ansible_docker_compose/state/ssh-cli
|
ForceCommand /ansible_docker_compose/state/ssh-cli
|
||||||
SetEnv DOORIS_SERVER_URL=https://{{ dooris__hostname }} DOORIS_API_TOKEN={{ dooris__static_api_token}}
|
SetEnv DOORIS_SERVER_URL={{ dooris_url }} DOORIS_API_TOKEN={{ dooris_static_api_token }}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue