Compare commits

..

52 commits

Author SHA1 Message Date
4fbac5cfe6
unbound(role): add config flag in README
Some checks failed
/ build (pull_request) Successful in 28s
/ Ansible Lint (pull_request) Failing after 2m44s
/ Ansible Lint (push) Failing after 2m45s
2026-08-07 22:56:07 +02:00
5378c3f360
auth-dns(host): ccchh.net remove unused 2026-08-07 22:56:07 +02:00
51b2cac907
z9-router(host): remove netwan, vlan55 untagged, add and fix DNS, fix formatting 2026-08-07 22:56:07 +02:00
c45fb91f76
kea_dhcp(role): seperate package installes 2026-08-07 22:55:57 +02:00
47fbd96642
kea_dhcp(role): update README 2026-08-07 22:55:57 +02:00
897ee5fa43
kea_dhcp(role): remove unused 2026-08-07 22:55:57 +02:00
7eabd88e2c
unbound(role): update readme and move task block to top level and remove unused 2026-08-07 22:55:57 +02:00
82760d2bc2
light(host): remove resolver from nginx conf 2026-08-07 22:55:56 +02:00
c2130adbb5
auth-dns(host): remove unused unfi ipv6 and specify comments 2026-08-07 22:55:56 +02:00
14b54797ec
README.md: correct sentence 2026-08-07 22:55:56 +02:00
49f07b0872
z9-router(host): move yate from vlan 55 to 52 2026-08-07 22:55:56 +02:00
1452c85b9d
z9-router(host): change mac address of yate in dhcp 2026-08-07 22:55:56 +02:00
8043198569
z9-router(host): add dhcp and dns for dooris-legacy 2026-08-07 22:55:56 +02:00
ffb88164ee
z9-router(host): change vlan 54 to 55 and remove netwan move vlan 400 to netlan 2026-08-07 22:55:56 +02:00
b76fac2255
general: update gitignore 2026-08-07 22:55:55 +02:00
58ea3ef7a3
z9-router(host): update host kea config
- edit config to work with update kea role
- fix ipv6 addresses
2026-08-07 22:55:55 +02:00
32caa40f77
unbound(role): fix some unbound setup stuff 2026-08-07 22:55:55 +02:00
8d9cb0007c
kea_dhcp(role): update to newest fux noc version 2026-08-07 22:55:55 +02:00
6006dbca27
z9-router(host): nftables conf fix indent and allow dhcpv6 2026-08-07 22:55:55 +02:00
9271cbda97
unbound(role): fix systemd unit of prometheus exporter 2026-08-07 22:55:34 +02:00
4ec4c1f942
z9-router(host): fix systemd-networkd configs 2026-08-07 22:55:34 +02:00
83f654037a
unbound(role): fix unbound prometheus exporter install on debian
- download debian image from github und verify checksum
- setup systemd service unit
2026-08-07 22:55:33 +02:00
6b05c4b05a
unbound(role): fix unbound config template
- fix some indentation problems
- fix access control
- fix remote control unix socket and thrust anchor file (because debain
appamour ist annoying)
  - add unbound-anchor package
2026-08-07 22:55:33 +02:00
db6ef3fcb2
kea_dhcp(role): fix include wars check 2026-08-07 22:55:33 +02:00
fa91690485
z9(pve01): change thinkcccore0 to pve01 2026-08-07 22:55:33 +02:00
04d24ccb6f
z9(group): remove all old ip references and change them to new ones 2026-08-07 22:55:33 +02:00
9e92a3c390
z9(group): remove all z9 references as subdomain 2026-08-07 22:55:33 +02:00
a0b0e8188f
unbound(role): move resolvd vars to task 2026-08-07 22:55:33 +02:00
5423558ab4
unbound(role): make unbound thread number configurable 2026-08-07 22:55:32 +02:00
bb141ddab3
unbound(role): reformat config template and use all vcpus 2026-08-07 22:55:32 +02:00
9a5dafb2bc
unbound(role): remove tags inside role 2026-08-07 22:55:32 +02:00
a4bb9a82d2
unbound(role): add FIXME note to unbound prometheus exporter install 2026-08-07 22:55:32 +02:00
1a0ac38861
unbound(role): use existing deploy_systemd_resolved_config role and some reordering 2026-08-07 22:55:32 +02:00
613e0528d7
kea_dhcp(role): make stork-agent.env smaller and add link to documentation 2026-08-07 22:55:32 +02:00
6734843e8a
kea_dhcp(role): fix indentation in template 2026-08-07 22:55:32 +02:00
c803b1fc67
kea_dhcp(role): add README.md 2026-08-07 22:55:31 +02:00
7440e8fd15
kea_dhcp(role): some fixes and removing arch part
- remove tags from tasks
- remove archlinux part
- use debian default package for kea
2026-08-07 22:55:31 +02:00
ebc6c8a9b8
z9-router(host): fix some spelling and a wireguard peer address 2026-08-07 22:55:31 +02:00
8351c28cd0
z9-router(host): add ansible pull 2026-08-07 22:55:31 +02:00
1dff022146
z9-router(host): rename rt1 to z9-router 2026-08-07 22:55:31 +02:00
010b8d1224
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-08-07 22:55:31 +02:00
aeaa80d2c4
rt1(z9 host): create host and configure networkd and nftables 2026-08-07 22:55:31 +02:00
7f421b2409 Update to current version
All checks were successful
/ build (push) Successful in 33s
/ Ansible Lint (push) Successful in 2m41s
2026-08-04 23:16:39 +02:00
6c4f2dc9b6 Update with correct prefixes
All checks were successful
/ build (push) Successful in 30s
/ Ansible Lint (push) Successful in 2m45s
2026-08-04 18:44:51 +02:00
849f63cd1b Activate sync
All checks were successful
/ build (push) Successful in 28s
/ Ansible Lint (push) Successful in 3m21s
2026-08-04 09:13:50 +02:00
68289025d2 Merge branch 'main' of git.hamburg.ccc.de:CCCHH/ansible-infra
All checks were successful
/ build (push) Successful in 54s
/ Ansible Lint (push) Successful in 3m22s
2026-08-03 08:58:31 +02:00
03ba0cf126 Use correct IP prefix in example 2026-08-03 08:58:29 +02:00
9a78164b7b
roles(dooris): remove blank line to make ansible-lint happy
All checks were successful
/ build (push) Successful in 30s
/ Ansible Lint (push) Successful in 2m28s
2026-08-03 00:06:44 +02:00
9266123f42 Explain that you can use a default route
Some checks failed
/ build (push) Successful in 28s
/ Ansible Lint (push) Failing after 2m17s
#133
2026-08-02 18:12:02 +02:00
24124e9f3d Document wg setup
Some checks failed
/ build (push) Successful in 29s
/ Ansible Lint (push) Failing after 2m24s
First step for #133
2026-08-02 18:09:29 +02:00
f749ed436c Use fixed port range to allow for better fw rules
Some checks failed
/ build (push) Successful in 45s
/ Ansible Lint (push) Failing after 2m38s
2026-08-02 17:25:30 +02:00
0377db2812 Use correct hostname for yate 2026-08-02 17:24:58 +02:00
10 changed files with 69 additions and 5 deletions

View file

@ -0,0 +1,43 @@
---
title: "Wiregard Admin VPN"
summary: How to configure your Wireguard client to access the Z9 network
---
# Onboarding
tbd. where to add your key
# Local Client Configuration
## Example Config
Replace `YOUR_IP_IN_DEC` with your IP in decimal, and `YOUR_IP_IN_HEX` with your IP in hexadecimal.
See [resources/z9/z9-router/systemd_networkd/10-wg56.netdev](resources/z9/z9-router/systemd_networkd/10-wg56.netdev) for the Wireguard endpoints configured on the router.
```
[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 10.89.214.YOUR_IP_IN_DEC/32, 2a07:c481:1:37::YOUR_IP_IN_HEX/128
[Peer]
PublicKey = fmlxjh3iOfpgrHQQpK3dyOD0BvDppGCUkFuMSroqQR4=
AllowedIPs = 10.89.208.0/20, 2a07:c481:1::/48, 212.12.48.120/29, 2a00:14b0:4200:3000::/64, 212.12.50.208/29, 2a00:14b0:42:100::/56, 212.12.51.128/28, 2a00:14b0:f000:23::/64
Endpoint = rt-wan.ccchh.net:51820
```
## AllowedIDs
The following prefixes should be tunneled to gain access to both CCCHH Z9 resources as well as Chaosknoten. It is also possible to run a default route through wireguard, but please do not abuse this as a general VPN for purposes other than admin tasks.
| Prefix | Description |
|--|--|
| [10.89.208.0/20](https://netbox.hamburg.ccc.de/ipam/prefixes/114/prefixes/) | prefix for CCCHH Z9 local networks |
| [2a07:c481:1::/48](https://netbox.hamburg.ccc.de/ipam/prefixes/50/) | prefix for CCCHH Z9 local networks |
| 212.12.48.120/29 | Fakep refix for hosts that come from [212.12.48.0/24](https://netbox.hamburg.ccc.de/ipam/prefixes/12/) |
| [2a00:14b0:4200:3000::/64](https://netbox.hamburg.ccc.de/ipam/prefixes/36/) | Public IPv6 in Wieske's shared network |
| [212.12.50.208/29](https://netbox.hamburg.ccc.de/ipam/prefixes/13/) | Public IPv4 for VMs on chaosknoten, routed by router |
| [2a00:14b0:42:100::/56](https://netbox.hamburg.ccc.de/ipam/prefixes/46/) | Public IPv6 for VMs on chaosknoten, routed by router |
| [212.12.51.128/28](https://netbox.hamburg.ccc.de/ipam/prefixes/15/) | IPv4 for VMs on chaosknoten, routed by Wieske |
| [2a00:14b0:f000:23::/64](https://netbox.hamburg.ccc.de/ipam/prefixes/35/) |IPv6 for VMs on chaosknoten, routed by Wieske |

View file

@ -0,0 +1,2 @@
# renovate: datasource=docker depName=codeberg.org/git-pages/git-pages
git_pages__version: latest

View file

@ -6,3 +6,9 @@ docker_compose__configuration_files:
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regexroute.conf.j2') }}" content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regexroute.conf.j2') }}"
- name: regfile.conf - name: regfile.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regfile.conf.j2') }}" content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/regfile.conf.j2') }}"
- name: rmanager.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/rmanager.conf.j2') }}"
- name: yrtpchan.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/yrtpchan.conf.j2') }}"
- name: ysipchan.conf
content: "{{ lookup('ansible.builtin.template', 'resources/z9/yate/docker_compose/ysipchan.conf.j2') }}"

View file

@ -15,7 +15,7 @@ all:
ansible_host: waybackproxy.ccchh.net ansible_host: waybackproxy.ccchh.net
ansible_user: chaos ansible_user: chaos
yate: yate:
ansible_host: yate.ccchh.net ansible_host: yate.z9.ccchh.net
ansible_user: chaos ansible_user: chaos
z9-router: z9-router:
ansible_host: z9-router.ccchh.net ansible_host: z9-router.ccchh.net

View file

@ -72,7 +72,7 @@ services:
restart: unless-stopped restart: unless-stopped
command: ["uv", "run", "main.py", "sync"] command: ["uv", "run", "main.py", "sync"]
environment: environment:
- DRY_RUN=true - DRY_RUN=false
- KEYCLOAK_CLIENT_ID=mailman-sync - KEYCLOAK_CLIENT_ID=mailman-sync
- KEYCLOAK_CLIENT_SECRET={{ secret__lists__keycloak_client_secret }} - KEYCLOAK_CLIENT_SECRET={{ secret__lists__keycloak_client_secret }}
- KEYCLOAK_REALM=ccchh - KEYCLOAK_REALM=ccchh

View file

@ -57,7 +57,7 @@ x-shared:
LETSENCRYPT_HOST: LETSENCRYPT_HOST:
LETSENCRYPT_EMAIL: LETSENCRYPT_EMAIL:
image: ${IMAGE_REPO:-ghcr.io/zammad/zammad}:${VERSION:-6.5.3} image: ${IMAGE_REPO:-ghcr.io/zammad/zammad}:${VERSION:-7.1.2}
restart: ${RESTART:-always} restart: ${RESTART:-always}
volumes: volumes:
- zammad-storage:/opt/zammad/storage - zammad-storage:/opt/zammad/storage
@ -76,7 +76,7 @@ services:
user: 0:0 user: 0:0
zammad-elasticsearch: zammad-elasticsearch:
image: elasticsearch:${ELASTICSEARCH_VERSION:-8.19.13} image: elasticsearch:${ELASTICSEARCH_VERSION:-8.19.19}
restart: ${RESTART:-always} restart: ${RESTART:-always}
volumes: volumes:
- elasticsearch-data:/usr/share/elasticsearch/data - elasticsearch-data:/usr/share/elasticsearch/data

View file

@ -0,0 +1,4 @@
; https://github.com/eventphone/yate/blob/master/conf.d/rmanager.conf.sample
[general]
; password: string: Password required to authenticate as admin, default empty!
;password=

View file

@ -0,0 +1,4 @@
; https://github.com/eventphone/yate/blob/master/conf.d/yrtpchan.conf.sample
[general]
minport=42000
maxport=42999

View file

@ -0,0 +1,6 @@
; Setting for all SIP channels
; https://github.com/eventphone/yate/blob/master/conf.d/ysipchan.conf.sample
[general]
; try to avoid `Transport(general) received likely truncated packet with length 1500, try to increase maxpkt`
maxpkt=8192

View file

@ -45,4 +45,3 @@ argument_specs:
apiKey: apiKey:
required: true required: true
type: str type: str