Compare commits

...
Author SHA1 Message Date
29a7a2a731 add configuration required for dooris -> spaceapid integration
All checks were successful
/ build (pull_request) Successful in 30s
/ Ansible Lint (pull_request) Successful in 3m12s
/ Ansible Lint (push) Successful in 4m13s
2026-08-11 17:39:43 +02:00
73760a9995
fix ansible-lint warnings
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 4m35s
2026-08-11 17:38:51 +02:00
39d8ff4ef8
update wireguard publicKey for lilly
Some checks failed
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m26s
2026-08-11 17:33:57 +02:00
10 changed files with 58 additions and 33 deletions

View file

@ -1,6 +1,7 @@
dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str] dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str]
dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str] dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str]
dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str] dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str]
dooris__spaceapid_password: ENC[AES256_GCM,data:3MLPzV7NxvOLQSHoBgPdR1WeGGhDZVnxDHDNviPseOQDkFkqUXFGPtfPQqI/pjs0VV607ehw+SfF3T8tMhorgA==,iv:U5j0SmM9rNsQTSxuLSiuG6zyMxVjfdNnu9BPXcaDjko=,tag:glvUmu79iCFEXmGDvm7Vuw==,type:str]
dooris__acmedns: dooris__acmedns:
subdomain: ENC[AES256_GCM,data:XncJZ7qT51dLSkvfIc0Nc3SFxK1y/ip1cO4HA9CJMFtQy+mP,iv:mgwfx0QMzHadvUDZDYCzsiP1Oh+P/5DekbZ4M6y08t4=,tag:4oyXvAJEOFlw7wrrrhwspQ==,type:str] subdomain: ENC[AES256_GCM,data:XncJZ7qT51dLSkvfIc0Nc3SFxK1y/ip1cO4HA9CJMFtQy+mP,iv:mgwfx0QMzHadvUDZDYCzsiP1Oh+P/5DekbZ4M6y08t4=,tag:4oyXvAJEOFlw7wrrrhwspQ==,type:str]
apiUser: ENC[AES256_GCM,data:YLhXPrrts+JtwRMLrU2oM8hLTiFvZuqrlLrNKtgoL8IUdTxe,iv:L2R0YNRNoMuWGMYvgwRLP0RZwxqmMfQL4REyMX6VIuo=,tag:LegIPuVqMcxpIL1ZksIgbg==,type:str] apiUser: ENC[AES256_GCM,data:YLhXPrrts+JtwRMLrU2oM8hLTiFvZuqrlLrNKtgoL8IUdTxe,iv:L2R0YNRNoMuWGMYvgwRLP0RZwxqmMfQL4REyMX6VIuo=,tag:LegIPuVqMcxpIL1ZksIgbg==,type:str]
@ -17,8 +18,8 @@ sops:
aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg== aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg==
-----END AGE ENCRYPTED FILE----- -----END AGE ENCRYPTED FILE-----
recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
lastmodified: "2026-07-29T12:14:25Z" lastmodified: "2026-08-11T14:12:13Z"
mac: ENC[AES256_GCM,data:rBtCeee53GXl+upHXGP4TTpUvszMzV0r1eQqzE7jG3WP/ywqfWqsM+sp3124wQzHTZoMxJc0m95YAseSdA+7EFSAQPRRdpfzMxTpoKQBFHS0BfgM/14ppB+kDER1ucNKT521+PyOjbmB86ovTc8MfR2vsHDZ+FrIopUGzPpcBPs=,iv:JiSoJxPt9JW/kWy0aVz6jGNOoQPkZKG/vTkdis/fKSo=,tag:0V6hicsuT6/qLjGb/+fJPw==,type:str] mac: ENC[AES256_GCM,data:yFvVk8J3Kjf7hYQ5E7tN0Dpa8943n2OLcVKEQWcyMFrl991cYjpti+a766Bx79KgaBqSW70E7Y13KfdXw0wpETte+KwpXEmlh54/3UihdvcavcH0ep7zZhyXEtoBfDTKoFMkvDgmQbljnOOWbWpW0X60lyWe0/xHIHJonlZ7PuY=,iv:9HdGaa4CXKJfI7LgY7oSsLU0VPZZ+dSW+k1s9v5xZkk=,tag:g4BSo09RAslC3H1djw6B2Q==,type:str]
pgp: pgp:
- created_at: "2026-05-20T02:08:48Z" - created_at: "2026-05-20T02:08:48Z"
enc: |- enc: |-
@ -191,4 +192,4 @@ sops:
-----END PGP MESSAGE----- -----END PGP MESSAGE-----
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49 fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
unencrypted_suffix: _unencrypted unencrypted_suffix: _unencrypted
version: 3.13.2 version: 3.13.3

View file

@ -1,5 +1,6 @@
dooris__hostname: "dooris.ccchh.net" dooris__hostname: "dooris.ccchh.net"
dooris__openid_client_id: "dooris" dooris__openid_client_id: "dooris"
dooris__ccujack_user: "dooris" dooris__ccujack_user: "dooris"
dooris__spaceapid_user: "dooris"
certbot__acme_account_email_address: le-admin@hamburg.ccc.de certbot__acme_account_email_address: le-admin@hamburg.ccc.de

View file

@ -6,7 +6,7 @@ kea_dhcp__dns_servers:
kea_dhcp__dhcp4: kea_dhcp__dhcp4:
enable: true enable: true
interfaces: ["netlan.51", "netlan.52", "netlan"] interfaces: [ "netlan.51", "netlan.52", "netlan" ]
subnets: subnets:
- id: 1 - id: 1
subnet: 10.89.208.0/22 subnet: 10.89.208.0/22
@ -234,7 +234,7 @@ kea_dhcp__dhcp4:
kea_dhcp__dhcp6: kea_dhcp__dhcp6:
enable: true enable: true
interfaces: ["netlan.51", "netlan.52", "netlan"] interfaces: [ "netlan.51", "netlan.52", "netlan" ]
subnets: subnets:
- id: 1 - id: 1
subnet: "2a07:c481:1:33::/64" subnet: "2a07:c481:1:33::/64"
@ -246,7 +246,7 @@ kea_dhcp__dhcp6:
- pool: "2a07:c481:1:33::/64" - pool: "2a07:c481:1:33::/64"
allocator: random allocator: random
reservations: reservations:
- ip-addresses: ["2a07:c481:1:33::1c"] - ip-addresses: [ "2a07:c481:1:33::1c" ]
hostname: dooris hostname: dooris
hw-address: "bc:24:11:b3:93:9c" hw-address: "bc:24:11:b3:93:9c"
- id: 2 - id: 2
@ -258,7 +258,7 @@ kea_dhcp__dhcp6:
pools: pools:
- pool: "2a07:c481:1:34::/64" - pool: "2a07:c481:1:34::/64"
reservations: reservations:
- ip-addresses: ["2a07:c481:1:34::66"] - ip-addresses: [ "2a07:c481:1:34::66" ]
hostname: esphome hostname: esphome
hw-address: "7e:3c:f0:77:8a:f4" hw-address: "7e:3c:f0:77:8a:f4"
- id: 3 - id: 3
@ -270,45 +270,45 @@ kea_dhcp__dhcp6:
pools: pools:
- pool: "2a07:c481:1:36::/64" - pool: "2a07:c481:1:36::/64"
reservations: reservations:
- ip-addresses: ["2a07:c481:1:36::2"] - ip-addresses: [ "2a07:c481:1:36::2" ]
hostname: sw-rack-1 hostname: sw-rack-1
hw-address: "F0:9F:C2:10:C3:AA" hw-address: "F0:9F:C2:10:C3:AA"
- ip-addresses: ["2a07:c481:1:36::3"] - ip-addresses: [ "2a07:c481:1:36::3" ]
hostname: sw-rack-2-peo hostname: sw-rack-2-peo
hw-address: "44:d9:e7:06:69:5d" hw-address: "44:d9:e7:06:69:5d"
- ip-addresses: ["2a07:c481:1:36::4"] - ip-addresses: [ "2a07:c481:1:36::4" ]
hostname: sw-main-1 hostname: sw-main-1
hw-address: "a8:9c:6c:16:df:cc" hw-address: "a8:9c:6c:16:df:cc"
- ip-addresses: ["2a07:c481:1:36::5"] - ip-addresses: [ "2a07:c481:1:36::5" ]
hostname: sw-main-2 hostname: sw-main-2
hw-address: "a8:9c:6c:16:e8:86" hw-address: "a8:9c:6c:16:e8:86"
- ip-addresses: ["2a07:c481:1:36::6"] - ip-addresses: [ "2a07:c481:1:36::6" ]
hostname: sw-shop-1 hostname: sw-shop-1
hw-address: "C0:4A:00:FB:DA:C5" hw-address: "C0:4A:00:FB:DA:C5"
- ip-addresses: ["2a07:c481:1:36::7"] - ip-addresses: [ "2a07:c481:1:36::7" ]
hostname: sw-shop-2-peo hostname: sw-shop-2-peo
hw-address: "f4:e2:c6:bf:20:ee" hw-address: "f4:e2:c6:bf:20:ee"
- ip-addresses: ["2a07:c481:1:36::8"] - ip-addresses: [ "2a07:c481:1:36::8" ]
hostname: sw-shop-3-peo hostname: sw-shop-3-peo
hw-address: "d8:b3:70:85:72:76" hw-address: "d8:b3:70:85:72:76"
- ip-addresses: ["2a07:c481:1:36::b"] - ip-addresses: [ "2a07:c481:1:36::b" ]
hostname: pve01 hostname: pve01
hw-address: "38:05:25:30:80:35" hw-address: "38:05:25:30:80:35"
- ip-addresses: ["2a07:c481:1:36::c"] - ip-addresses: [ "2a07:c481:1:36::c" ]
hostname: pve02 hostname: pve02
hw-address: "b8:85:84:b1:57:b6" hw-address: "b8:85:84:b1:57:b6"
- ip-addresses: ["2a07:c481:1:36::d"] - ip-addresses: [ "2a07:c481:1:36::d" ]
hostname: pve03 hostname: pve03
hw-address: "98:fa:9b:a2:ed:e8" hw-address: "98:fa:9b:a2:ed:e8"
- ip-addresses: ["2a07:c481:1:36::f"] - ip-addresses: [ "2a07:c481:1:36::f" ]
hostname: pbs hostname: pbs
hw-address: "BC:24:11:D6:2C:81" hw-address: "BC:24:11:D6:2C:81"
- ip-addresses: ["2a07:c481:1:36::21"] - ip-addresses: [ "2a07:c481:1:36::21" ]
hostname: unifi hostname: unifi
hw-address: "BC:24:11:25:77:60" hw-address: "BC:24:11:25:77:60"
- ip-addresses: ["2a07:c481:1:36::31"] - ip-addresses: [ "2a07:c481:1:36::31" ]
hostname: light hostname: light
hw-address: "72:61:ea:e6:49:e3" hw-address: "72:61:ea:e6:49:e3"
- ip-addresses: ["2a07:c481:1:36::32"] - ip-addresses: [ "2a07:c481:1:36::32" ]
hostname: club-assistant hostname: club-assistant
hw-address: "7a:55:61:c3:a2:89" hw-address: "7a:55:61:c3:a2:89"

View file

@ -76,7 +76,7 @@ PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_langoor_home_psk
[WireGuardPeer] [WireGuardPeer]
# friendly_name = lilly-lillysLaptop # friendly_name = lilly-lillysLaptop
AllowedIPs = 10.89.214.16/32,2a07:c481:1:37::16/128 AllowedIPs = 10.89.214.16/32,2a07:c481:1:37::16/128
PublicKey = IBsI+N8qUNpQnDc5HnqQ2Zo/1graFM0RMIecHmAF+Vk= PublicKey = v0MiwjhCj1w4J3fKl2d18wNIdbdd9tvdjIRQTRjIeGY=
[WireGuardPeer] [WireGuardPeer]
# friendly_name = bitwhisker # friendly_name = bitwhisker

View file

@ -11,6 +11,9 @@ For an exact description of host requirements, see the README of dooris itself.
- `dooris__openid_client_id`: Client-ID in CCCHH ID for dooris - `dooris__openid_client_id`: Client-ID in CCCHH ID for dooris
- `dooris__openid_client_secret`: Client-Secret in CCCHH ID for dooris - `dooris__openid_client_secret`: Client-Secret in CCCHH ID for dooris
- `dooris__static_api_token`: A static token that is valid on the servers API and can operate locks - `dooris__static_api_token`: A static token that is valid on the servers API and can operate locks
- `dooris__spaceapid_user`: Username for authentication against our spaceapid
- `dooris__spaceapid_password`: Password for authentication against our spaceapid
- `dooris__main_lock`: Name or ID of the main lock whose status gets pushed to spaceapid
- `dooris__acmedns`: Configuration of ACMEDNS domain + credentials for dooris. - `dooris__acmedns`: Configuration of ACMEDNS domain + credentials for dooris.
Must be a dict with keys `subdomain`, `apiUser`, `apiKey` which are shown when creating a domain in ACMEDNS. Must be a dict with keys `subdomain`, `apiUser`, `apiKey` which are shown when creating a domain in ACMEDNS.

View file

@ -0,0 +1 @@
dooris__main_lock: ""

View file

@ -31,6 +31,21 @@ argument_specs:
required: true required: true
type: str type: str
dooris__spaceapid_user:
description: "Username for authentication against out spaceapid"
required: true
type: str
dooris__spaceapid_password:
description: "Password for authentication against out spaceapid"
required: true
type: str
dooris__main_lock:
description: "Name or ID of the main lock whose status gets pushed to spaceapid"
required: false
type: str
dooris__acmedns: dooris__acmedns:
description: "Configuration of ACMEDNS domain + credentials for dooris" description: "Configuration of ACMEDNS domain + credentials for dooris"
required: true required: true

View file

@ -11,6 +11,9 @@ services:
DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}" DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}"
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys" DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}" DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}"
DOORIS_SPACEAPID_USER: "{{ dooris__spaceapid_user }}"
DOORIS_SPACEAPID_PASSWORD: "{{ dooris__spaceapid_password }}"
DOORIS_MAIN_LOCK: "{{ dooris__main_lock }}"
network_mode: host network_mode: host
restart: unless-stopped restart: unless-stopped
volumes: volumes:

View file

@ -70,7 +70,7 @@ argument_specs:
interfaces: interfaces:
type: "list" type: "list"
elements: "str" elements: "str"
default: [] default: [ ]
control-sockets: control-sockets:
type: "list" type: "list"
elements: "dict" elements: "dict"
@ -107,7 +107,7 @@ argument_specs:
interfaces: interfaces:
type: "list" type: "list"
elements: "str" elements: "str"
default: [] default: [ ]
control-sockets: control-sockets:
type: "list" type: "list"
elements: "dict" elements: "dict"

View file

@ -5,12 +5,13 @@ argument_specs:
type: list type: list
required: false required: false
secrets__folder: secrets__folder:
owner: options:
type: string owner:
required: false type: str
group: required: false
type: string group:
required: false type: str
mode: required: false
type: string mode:
required: false type: str
required: false