diff --git a/inventories/z9/host_vars/dooris.sops.yaml b/inventories/z9/host_vars/dooris.sops.yaml index 9620b051..73c87269 100644 --- a/inventories/z9/host_vars/dooris.sops.yaml +++ b/inventories/z9/host_vars/dooris.sops.yaml @@ -1,14 +1,11 @@ -dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str] -dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str] -dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str] -dooris__acmedns: - subdomain: ENC[AES256_GCM,data:XncJZ7qT51dLSkvfIc0Nc3SFxK1y/ip1cO4HA9CJMFtQy+mP,iv:mgwfx0QMzHadvUDZDYCzsiP1Oh+P/5DekbZ4M6y08t4=,tag:4oyXvAJEOFlw7wrrrhwspQ==,type:str] - apiUser: ENC[AES256_GCM,data:YLhXPrrts+JtwRMLrU2oM8hLTiFvZuqrlLrNKtgoL8IUdTxe,iv:L2R0YNRNoMuWGMYvgwRLP0RZwxqmMfQL4REyMX6VIuo=,tag:LegIPuVqMcxpIL1ZksIgbg==,type:str] - apiKey: ENC[AES256_GCM,data:NbyLJeFhUOac3pWkMTjdRPd9IKSwLYZR6ahiFljLJo5So5nnsL/tAw==,iv:DerEdaPnUWr3pCPzq8A8y5qIH3RKwHZ+EqKh8sHAVaU=,tag:PrxKMdRwxGPCP7Z9XDuI0A==,type:str] +secret__dooris_client_secret: ENC[AES256_GCM,data:v85gIBNH4s4j36crJ+Pb2lu2cdZpwz0xndHzBKZNGKg=,iv:Rlt6R7JMcHTAAVPiTtFaxqsWD8G5B9Ab3yqItYdFR+E=,tag:dlMHaxTMx3LgOzCsTLUdzw==,type:str] +secret__dooris_ccujack_password: ENC[AES256_GCM,data:bHeftSA7eC1cSydBRumksRgw2v0=,iv:X/pfsvQPZREifGjHDGx8mVk2TDrlrRVb6MiAr01wI9o=,tag:ti//x7eDbheMG6Hsn2KBlg==,type:str] ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str] +secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str] sops: age: - - enc: | + - recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax + enc: | -----BEGIN AGE ENCRYPTED FILE----- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrYW9aYzMxeFYxemp5MUlR NGJOaDRCc2E5bGdjSnFkcm5YMTdaSldKSFVVCmJmNERQbDF0Y2NDZGNnWVE5UlIy @@ -16,9 +13,8 @@ sops: YVc5c281N0Fod2hib29wOEJXZkZKOXMKx2g337TvrUk5hXZNbxlPlrWOydYbSBoW aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg== -----END AGE ENCRYPTED FILE----- - recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax - lastmodified: "2026-07-29T12:14:25Z" - mac: ENC[AES256_GCM,data:rBtCeee53GXl+upHXGP4TTpUvszMzV0r1eQqzE7jG3WP/ywqfWqsM+sp3124wQzHTZoMxJc0m95YAseSdA+7EFSAQPRRdpfzMxTpoKQBFHS0BfgM/14ppB+kDER1ucNKT521+PyOjbmB86ovTc8MfR2vsHDZ+FrIopUGzPpcBPs=,iv:JiSoJxPt9JW/kWy0aVz6jGNOoQPkZKG/vTkdis/fKSo=,tag:0V6hicsuT6/qLjGb/+fJPw==,type:str] + lastmodified: "2026-04-19T21:46:01Z" + mac: ENC[AES256_GCM,data:5VlEYqo7ez4EgdMqGGnelc02EoT/bCLYVbPGHth4kd+DhOaJ1EXhmVB5eiX3AwyRl2nr79z/idCDJ6R1QdfQ5v8rYnnWcqehtiIIz0RBXhbED/hN2oz48yRhIX9vCB0gjsK6cacDzTCHP0tPEsQF+Ax4uWdXNHKnZVYS70qxbEI=,iv:noc3LJdiZ10w9O6JfwTxzLUNKT74rfdTX/Gb94fP3JI=,tag:WgFpYsFO3WjrjCs/7R634w==,type:str] pgp: - created_at: "2026-05-20T02:08:48Z" enc: |- @@ -191,4 +187,4 @@ sops: -----END PGP MESSAGE----- fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49 unencrypted_suffix: _unencrypted - version: 3.13.2 + version: 3.12.2 diff --git a/inventories/z9/host_vars/dooris.yaml b/inventories/z9/host_vars/dooris.yaml index 14231924..3792153d 100644 --- a/inventories/z9/host_vars/dooris.yaml +++ b/inventories/z9/host_vars/dooris.yaml @@ -1,5 +1,21 @@ -dooris__hostname: "dooris.ccchh.net" -dooris__openid_client_id: "dooris" -dooris__ccujack_user: "dooris" +docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'resources/z9/dooris/docker_compose/compose.yaml.j2') }}" +docker_compose__configuration_files: [ ] certbot__acme_account_email_address: le-admin@hamburg.ccc.de +certbot__certs: + - commonName: "dooris.ccchh.net" + challengeType: "dns-01-acme-dns" + dns_01_acme_dns: + subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360" + apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e" + apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}" +certbot__new_cert_commands: + - "systemctl restart nginx.service" + +nginx__version_spec: "" +nginx__deploy_redirect_conf: false +nginx__configurations: + - name: dooris.ccchh.net + content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/dooris.ccchh.net.conf') }}" + - name: http_handler + content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/http_handler.conf') }}" diff --git a/inventories/z9/hosts.yaml b/inventories/z9/hosts.yaml index b4373d6c..38e29fd6 100644 --- a/inventories/z9/hosts.yaml +++ b/inventories/z9/hosts.yaml @@ -17,9 +17,11 @@ all: ansible_user: chaos certbot_hosts: hosts: + dooris: light: docker_compose_hosts: hosts: + dooris: waybackproxy: yate: foobazdmx_hosts: @@ -36,6 +38,7 @@ infrastructure_authorized_keys_hosts: yate: nginx_hosts: hosts: + dooris: light: waybackproxy: ola_hosts: diff --git a/playbooks/deploy.yaml b/playbooks/deploy.yaml index 59fe15a4..7a144409 100644 --- a/playbooks/deploy.yaml +++ b/playbooks/deploy.yaml @@ -170,10 +170,3 @@ - transmission tags: - transmission - -- name: Setup dooris - hosts: dooris - roles: - - dooris - tags: - - dooris diff --git a/resources/z9/dooris/docker_compose/compose.yaml.j2 b/resources/z9/dooris/docker_compose/compose.yaml.j2 new file mode 100644 index 00000000..e81b2335 --- /dev/null +++ b/resources/z9/dooris/docker_compose/compose.yaml.j2 @@ -0,0 +1,17 @@ +--- + +services: + dooris: + image: git.hamburg.ccc.de/ccchh/dooris:latest + environment: + DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/ + DOORIS_OPENID_CLIENT_ID: dooris + DOORIS_OPENID_CLIENT_SECRET: "{{ secret__dooris_client_secret }}" + DOORIS_BASE_URL: https://dooris.ccchh.net + DOORIS_CCUJACK_USER: "dooris" + DOORIS_CCUJACK_PASSWORD: "{{ secret__dooris_ccujack_password }}" + DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys" + network_mode: host + restart: unless-stopped + volumes: + - "./state:/srv/state/:rw" diff --git a/roles/dooris/templates/nginx/site.conf b/resources/z9/dooris/nginx/dooris.ccchh.net.conf similarity index 84% rename from roles/dooris/templates/nginx/site.conf rename to resources/z9/dooris/nginx/dooris.ccchh.net.conf index a5c2b1c1..efb5b1f1 100644 --- a/roles/dooris/templates/nginx/site.conf +++ b/resources/z9/dooris/nginx/dooris.ccchh.net.conf @@ -4,12 +4,12 @@ server { listen [::]:443 ssl http2; listen 443 ssl http2; - server_name {{ dooris__hostname }}; + server_name dooris.ccchh.net; - ssl_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/fullchain.pem; - ssl_certificate_key /etc/letsencrypt/live/{{ dooris__hostname }}/privkey.pem; + ssl_certificate /etc/letsencrypt/live/dooris.ccchh.net/fullchain.pem; + ssl_certificate_key /etc/letsencrypt/live/dooris.ccchh.net/privkey.pem; # verify chain of trust of OCSP response using Root CA and Intermediate certs - ssl_trusted_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/chain.pem; + ssl_trusted_certificate /etc/letsencrypt/live/dooris.ccchh.net/chain.pem; # HSTS (ngx_http_headers_module is required) (63072000 seconds) add_header Strict-Transport-Security "max-age=63072000" always; diff --git a/roles/dooris/templates/nginx/http_handler.conf b/resources/z9/dooris/nginx/http_handler.conf similarity index 100% rename from roles/dooris/templates/nginx/http_handler.conf rename to resources/z9/dooris/nginx/http_handler.conf diff --git a/roles/docker_compose/meta/main.yaml b/roles/docker_compose/meta/main.yaml index 1fbb2364..cb7d8e04 100644 --- a/roles/docker_compose/meta/main.yaml +++ b/roles/docker_compose/meta/main.yaml @@ -1,4 +1,3 @@ --- -allow_duplicates: false dependencies: - role: docker diff --git a/roles/dooris/README.md b/roles/dooris/README.md deleted file mode 100644 index f868b1d5..00000000 --- a/roles/dooris/README.md +++ /dev/null @@ -1,16 +0,0 @@ -# dooris - -Deployment configuration of [dooris](https://git.hamburg.ccc.de/CCCHH/dooris) on our host. -For an exact description of host requirements, see the README of dooris itself. - -## Required Arguments - -- `dooris__hostname`: The hostname on which the dooris server is reachable -- `dooris__ccujack_user`: Username for authentication against homematic ccujack -- `dooris__ccujack_password` Password for authentication against homematic ccujack -- `dooris__openid_client_id`: Client-ID in CCCHH ID for dooris -- `dooris__openid_client_secret`: Client-Secret in CCCHH ID for dooris -- `dooris__static_api_token`: A static token that is valid on the servers API and can operate locks -- `dooris__acmedns`: Configuration of ACMEDNS domain + credentials for dooris. - Must be a dict with keys `subdomain`, `apiUser`, `apiKey` which are shown when creating a domain in ACMEDNS. - diff --git a/roles/dooris/handlers/main.yml b/roles/dooris/handlers/main.yml deleted file mode 100644 index 0e3528f6..00000000 --- a/roles/dooris/handlers/main.yml +++ /dev/null @@ -1,5 +0,0 @@ -- name: "reload sshd" - become: true - ansible.builtin.systemd_service: - name: "ssh.service" - state: "reloaded" diff --git a/roles/dooris/meta/argument_specs.yml b/roles/dooris/meta/argument_specs.yml deleted file mode 100644 index 2d2726ac..00000000 --- a/roles/dooris/meta/argument_specs.yml +++ /dev/null @@ -1,48 +0,0 @@ -argument_specs: - main: - options: - dooris__static_api_token: - description: "A static token that is valid on the servers API and can operate locks" - required: true - type: str - - dooris__hostname: - description: "The hostname on which the dooris server is reachable" - required: true - type: str - - dooris__openid_client_id: - description: "Client-ID in CCCHH ID for dooris" - required: true - type: str - - dooris__openid_client_secret: - description: "Client-Secret in CCCHH ID for dooris" - required: true - type: str - - dooris__ccujack_user: - description: "Username for authentication against homematic ccujack" - required: true - type: str - - dooris__ccujack_password: - description: "Password for authentication against homematic ccujack" - required: true - type: str - - dooris__acmedns: - description: "Configuration of ACMEDNS domain + credentials for dooris" - required: true - type: dict - options: - subdomain: - required: true - type: str - apiUser: - required: true - type: str - apiKey: - required: true - type: str - diff --git a/roles/dooris/meta/main.yml b/roles/dooris/meta/main.yml deleted file mode 100644 index d2041dd8..00000000 --- a/roles/dooris/meta/main.yml +++ /dev/null @@ -1,27 +0,0 @@ -dependencies: - - role: docker_compose - vars: - docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'compose.yaml.j2') }}" - docker_compose__configuration_files: [ ] - - - role: certbot - vars: - certbot__new_cert_commands: - - "systemctl restart nginx.service" - certbot__certs: - - commonName: "{{ dooris__hostname }}" - challengeType: "dns-01-acme-dns" - dns_01_acme_dns: - subdomain: "{{ dooris__acmedns.subdomain }}" - apiUser: "{{ dooris__acmedns.apiUser }}" - apiKey: "{{ dooris__acmedns.apiKey }}" - - - role: nginx - vars: - nginx__version_spec: "" - nginx__deploy_redirect_conf: false - nginx__configurations: - - name: "{{ dooris__hostname }}" - content: "{{ lookup('ansible.builtin.template', 'nginx/site.conf') }}" - - name: http_handler - content: "{{ lookup('ansible.builtin.template', 'nginx/http_handler.conf') }}" diff --git a/roles/dooris/tasks/main.yml b/roles/dooris/tasks/main.yml deleted file mode 100644 index 659dccd6..00000000 --- a/roles/dooris/tasks/main.yml +++ /dev/null @@ -1,34 +0,0 @@ -- name: Create local dooris group - become: true - ansible.builtin.group: - name: "dooris" - gid: 10000 - -- name: Create local dooris user - become: true - ansible.builtin.user: - name: "dooris" - uid: 10000 - group: "dooris" - system: true - password: "!" - home: "/ansible_docker_compose/state/" - shell: "/ansible_docker_compose/state/ssh-cli" - -- name: Ensure dooris state directory exists and has correct permissions - become: true - ansible.builtin.file: - path: "/ansible_docker_compose/state/" - owner: "dooris" - group: "dooris" - mode: "u=rwx,g=rx,o=" - -- name: Create ssh server config for dooris user - become: true - notify: "reload sshd" - ansible.builtin.template: - src: sshd_config - dest: /etc/ssh/sshd_config.d/dooris.conf - owner: root - group: root - mode: u=rw,g=r,o=r diff --git a/roles/dooris/templates/compose.yaml.j2 b/roles/dooris/templates/compose.yaml.j2 deleted file mode 100644 index 2bb5e825..00000000 --- a/roles/dooris/templates/compose.yaml.j2 +++ /dev/null @@ -1,17 +0,0 @@ ---- -services: - dooris: - image: git.hamburg.ccc.de/ccchh/dooris:latest - environment: - DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/ - DOORIS_OPENID_CLIENT_ID: "{{ dooris__openid_client_id }}" - DOORIS_OPENID_CLIENT_SECRET: "{{ dooris__openid_client_secret }}" - DOORIS_BASE_URL: "https://{{ dooris__hostname }}" - DOORIS_CCUJACK_USER: "{{ dooris__ccujack_user }}" - DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}" - DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys" - DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}" - network_mode: host - restart: unless-stopped - volumes: - - "./state:/srv/state/:rw" diff --git a/roles/dooris/templates/sshd_config b/roles/dooris/templates/sshd_config deleted file mode 100644 index ea246f33..00000000 --- a/roles/dooris/templates/sshd_config +++ /dev/null @@ -1,6 +0,0 @@ -# {{ ansible_managed }} - -Match User dooris - AuthorizedKeysFile /ansible_docker_compose/state/dooris_authorized_keys - ForceCommand /ansible_docker_compose/state/ssh-cli - SetEnv DOORIS_SERVER_URL=https://{{ dooris__hostname }} DOORIS_API_TOKEN={{ dooris__static_api_token}}