add dooris role for setup of dooris interaction on the node itself #129

Open
lilly wants to merge 2 commits from new-dooris-role into main
14 changed files with 157 additions and 50 deletions
Showing only changes of commit cf7b7ebbed - Show all commits

add dooris role for setup of dooris interaction on the node itself
Some checks failed
/ build (pull_request) Successful in 29s
/ Ansible Lint (push) Failing after 3m15s
/ Ansible Lint (pull_request) Failing after 3m14s

lilly 2026-07-19 16:59:38 +02:00
Signed by: lilly
SSH key fingerprint: SHA256:y9T5GFw2A20WVklhetIxG1+kcg/Ce0shnQmbu1LQ37g

View file

@ -1,11 +1,11 @@
secret__dooris_client_secret: ENC[AES256_GCM,data:v85gIBNH4s4j36crJ+Pb2lu2cdZpwz0xndHzBKZNGKg=,iv:Rlt6R7JMcHTAAVPiTtFaxqsWD8G5B9Ab3yqItYdFR+E=,tag:dlMHaxTMx3LgOzCsTLUdzw==,type:str]
secret__dooris_ccujack_password: ENC[AES256_GCM,data:bHeftSA7eC1cSydBRumksRgw2v0=,iv:X/pfsvQPZREifGjHDGx8mVk2TDrlrRVb6MiAr01wI9o=,tag:ti//x7eDbheMG6Hsn2KBlg==,type:str]
dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str]
dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str]
dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str]
ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str]
secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str]
sops:
age:
- recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
enc: |
- enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrYW9aYzMxeFYxemp5MUlR
NGJOaDRCc2E5bGdjSnFkcm5YMTdaSldKSFVVCmJmNERQbDF0Y2NDZGNnWVE5UlIy
@ -13,8 +13,9 @@ sops:
YVc5c281N0Fod2hib29wOEJXZkZKOXMKx2g337TvrUk5hXZNbxlPlrWOydYbSBoW
aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2026-04-19T21:46:01Z"
mac: ENC[AES256_GCM,data:5VlEYqo7ez4EgdMqGGnelc02EoT/bCLYVbPGHth4kd+DhOaJ1EXhmVB5eiX3AwyRl2nr79z/idCDJ6R1QdfQ5v8rYnnWcqehtiIIz0RBXhbED/hN2oz48yRhIX9vCB0gjsK6cacDzTCHP0tPEsQF+Ax4uWdXNHKnZVYS70qxbEI=,iv:noc3LJdiZ10w9O6JfwTxzLUNKT74rfdTX/Gb94fP3JI=,tag:WgFpYsFO3WjrjCs/7R634w==,type:str]
recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
lastmodified: "2026-07-23T16:56:18Z"
mac: ENC[AES256_GCM,data:hdX55T++CCuklTmttDNI99hNs48hhK1LfastyrPiF/PYMjj2bXr6zrT+J4IurhZxs00kHLiiBe2sMkIRF4v66xoV7YaAfR9wrsrUOtG4T/YoLgSuCrZt35yXvA928XcSS92oUgR7uoD5y7ZkII3T0w4mOm4OVtBrjc9zGTwd3Zc=,iv:V9UzvQlVEfFVVz2ELDSwpI8rC6Xk5/RUmaAsxdkHsK0=,tag:rorczKSSUIbgYiPLtmyqRg==,type:str]
pgp:
- created_at: "2026-05-20T02:08:48Z"
enc: |-
@ -187,4 +188,4 @@ sops:
-----END PGP MESSAGE-----
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
unencrypted_suffix: _unencrypted
version: 3.12.2
version: 3.13.2

View file

@ -1,21 +1,5 @@
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'resources/z9/dooris/docker_compose/compose.yaml.j2') }}"
docker_compose__configuration_files: [ ]
dooris__hostname: "dooris.ccchh.net"
dooris__openid_client_id: "dooris"
dooris__ccujack_user: "dooris"
certbot__acme_account_email_address: le-admin@hamburg.ccc.de
certbot__certs:
- commonName: "dooris.ccchh.net"
challengeType: "dns-01-acme-dns"
dns_01_acme_dns:
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
certbot__new_cert_commands:
- "systemctl restart nginx.service"
nginx__version_spec: ""
nginx__deploy_redirect_conf: false
nginx__configurations:
- name: dooris.ccchh.net
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/dooris.ccchh.net.conf') }}"
- name: http_handler
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/http_handler.conf') }}"

View file

@ -17,11 +17,9 @@ all:
ansible_user: chaos
certbot_hosts:
hosts:
dooris:
light:
docker_compose_hosts:
hosts:
dooris:
waybackproxy:
yate:
foobazdmx_hosts:
@ -38,7 +36,6 @@ infrastructure_authorized_keys_hosts:
yate:
nginx_hosts:
hosts:
dooris:
light:
waybackproxy:
ola_hosts:

View file

@ -170,3 +170,10 @@
- transmission
tags:
- transmission
- name: Setup dooris
hosts: dooris
roles:
- dooris
tags:
- dooris

View file

@ -1,17 +0,0 @@
---
services:
dooris:
image: git.hamburg.ccc.de/ccchh/dooris:latest
environment:
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
DOORIS_OPENID_CLIENT_ID: dooris
DOORIS_OPENID_CLIENT_SECRET: "{{ secret__dooris_client_secret }}"
DOORIS_BASE_URL: https://dooris.ccchh.net
DOORIS_CCUJACK_USER: "dooris"
DOORIS_CCUJACK_PASSWORD: "{{ secret__dooris_ccujack_password }}"
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
network_mode: host
restart: unless-stopped
volumes:
- "./state:/srv/state/:rw"

14
roles/dooris/README.md Normal file
View file

@ -0,0 +1,14 @@
# dooris
Deployment configuration of [dooris](https://git.hamburg.ccc.de/CCCHH/dooris) on our host.
For an exact description of host requirements, see the README of dooris itself.
## Required Arguments
- `dooris__hostname`: The hostname on which the dooris server is reachable
- `dooris__ccujack_user`: Username for authentication against homematic ccujack
- `dooris__ccujack_password` Password for authentication against homematic ccujack
- `dooris__openid_client_id`: Client-ID in CCCHH ID for dooris
- `dooris__openid_client_secret`: Client-Secret in CCCHH ID for dooris
- `dooris__static_api_token`: A static token that is valid on the servers API and can operate locks

View file

@ -0,0 +1,5 @@
- name: "reload sshd"
become: true
ansible.builtin.systemd_service:
name: "ssh.service"
state: "reloaded"

View file

@ -0,0 +1,32 @@
argument_specs:
main:
options:
dooris__static_api_token:
description: "A static token that is valid on the servers API and can operate locks"
lilly marked this conversation as resolved Outdated

Please add another underscore between role name and variable name to match the convention used in the other roles (so dooris__static_api_token).

Please add another underscore between role name and variable name to match the convention used in the other roles (so `dooris__static_api_token`).
required: true
type: str
dooris__hostname:
description: "The hostname on which the dooris server is reachable"
lilly marked this conversation as resolved Outdated

Same here (so dooris__url).

Same here (so `dooris__url`).
required: true
type: str
dooris__openid_client_id:
description: "Client-ID in CCCHH ID for dooris"
required: true
type: str
dooris__openid_client_secret:
description: "Client-Secret in CCCHH ID for dooris"
required: true
type: str
dooris__ccujack_user:
description: "Username for authentication against homematic ccujack"
required: true
type: str
dooris__ccujack_password:
description: "Password for authentication against homematic ccujack"
required: true
type: str

View file

@ -0,0 +1,27 @@
dependencies:
- role: docker_compose
vars:
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'compose.yaml.j2') }}"
docker_compose__configuration_files: []
- role: certbot
vars:
certbot__new_cert_commands:
- "systemctl restart nginx.service"
certbot__certs:
- commonName: "dooris.ccchh.net"
challengeType: "dns-01-acme-dns"
dns_01_acme_dns:
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
- role: nginx
vars:
nginx__version_spec: ""
nginx__deploy_redirect_conf: false
nginx__configurations:
- name: "{{ dooris__hostname }}"
content: "{{ lookup('ansible.builtin.template', 'nginx/site.conf') }}"
- name: http_handler
content: "{{ lookup('ansible.builtin.template', 'nginx/http_handler.conf') }}"

View file

@ -0,0 +1,34 @@
- name: Create local dooris group
become: true
ansible.builtin.group:
name: "dooris"
gid: 10000
- name: Create local dooris user
become: true
ansible.builtin.user:
name: "dooris"
uid: 10000
group: "dooris"
system: true
password: "!"
home: "/ansible_docker_compose/state/"
shell: "/ansible_docker_compose/state/ssh-cli"
- name: Ensure dooris state directory exists and has correct permissions
become: true
ansible.builtin.file:
path: "/ansible_docker_compose/state/"
owner: "dooris"
group: "dooris"
mode: "u=rwx,g=rx,o="
- name: Create ssh server config for dooris user
become: true
notify: "reload sshd"
ansible.builtin.template:
src: sshd_config
dest: /etc/ssh/sshd_config.d/dooris.conf
owner: root
group: root
mode: u=rw,g=r,o=r

View file

@ -0,0 +1,17 @@
---
services:
dooris:
image: git.hamburg.ccc.de/ccchh/dooris:latest
environment:
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
DOORIS_OPENID_CLIENT_ID: "{{ dooris__openid_client_id }}"
DOORIS_OPENID_CLIENT_SECRET: "{{ dooris__openid_client_secret }}"
DOORIS_BASE_URL: "https://{{ dooris__hostname }}"
DOORIS_CCUJACK_USER: "{{ dooris__ccujack_user }}"
DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}"
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}"
network_mode: host
restart: unless-stopped
volumes:
- "./state:/srv/state/:rw"

View file

@ -4,12 +4,12 @@ server {
listen [::]:443 ssl http2;
listen 443 ssl http2;
server_name dooris.ccchh.net;
server_name {{ dooris__hostname }};
ssl_certificate /etc/letsencrypt/live/dooris.ccchh.net/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dooris.ccchh.net/privkey.pem;
ssl_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/{{ dooris__hostname }}/privkey.pem;
# verify chain of trust of OCSP response using Root CA and Intermediate certs
ssl_trusted_certificate /etc/letsencrypt/live/dooris.ccchh.net/chain.pem;
ssl_trusted_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/chain.pem;
# HSTS (ngx_http_headers_module is required) (63072000 seconds)
add_header Strict-Transport-Security "max-age=63072000" always;

View file

@ -0,0 +1,6 @@
# {{ ansible_managed }}
Match User dooris
AuthorizedKeysFile /ansible_docker_compose/state/dooris_authorized_keys
ForceCommand /ansible_docker_compose/state/ssh-cli
SetEnv DOORIS_SERVER_URL=https://{{ dooris__hostname }} DOORIS_API_TOKEN={{ dooris__static_api_token}}