add dooris role for setup of dooris interaction on the node itself #129

Open
lilly wants to merge 2 commits from new-dooris-role into main
15 changed files with 158 additions and 50 deletions

View file

@ -1,11 +1,11 @@
secret__dooris_client_secret: ENC[AES256_GCM,data:v85gIBNH4s4j36crJ+Pb2lu2cdZpwz0xndHzBKZNGKg=,iv:Rlt6R7JMcHTAAVPiTtFaxqsWD8G5B9Ab3yqItYdFR+E=,tag:dlMHaxTMx3LgOzCsTLUdzw==,type:str] dooris__static_api_token: ENC[AES256_GCM,data:pXmjn36FnOwA7fWAd3Go4W1CiMeRbbAiquj9KI/pQEDy1qDuobBbBft25m3uSAo6VI02PW2oZ4koY8uoPDUwNA==,iv:TNaZjwGBHvIbmF7VPIOo5mYzH1NEIyKIgjzkrobNCoI=,tag:4dHZepMxUGcvBYEp0kNwYQ==,type:str]
secret__dooris_ccujack_password: ENC[AES256_GCM,data:bHeftSA7eC1cSydBRumksRgw2v0=,iv:X/pfsvQPZREifGjHDGx8mVk2TDrlrRVb6MiAr01wI9o=,tag:ti//x7eDbheMG6Hsn2KBlg==,type:str] dooris__openid_client_secret: ENC[AES256_GCM,data:PqmtHR6LCGXcK5dyqKihUqU6+lydW0mJf7kMMf41qh4=,iv:ZjIl8jwB2lfJHjwcDEFFCbafMBnpzkccxBvvsjg+ia8=,tag:+eCnr9ojv9uUoO9k5khY6w==,type:str]
dooris__ccujack_password: ENC[AES256_GCM,data:FBbrdoQRdVZ+1n8WZg42jZz/xvQ=,iv:GLuen+LiB4MrvU71gEdVYWbdHKaDcEKify3vPePuoO0=,tag:nuqkP0cJLsvNAieWDNY3HA==,type:str]
ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str] ansible_pull__age_private_key: ENC[AES256_GCM,data:Yi4ST1zDVN4dLDs9i6aajUvEzTSYvwfYIRZUC278rgdO0bGk4y6saevmqK4mUnpIpz8M+ze//1OTDTgU6K4AE1TsX8vWB7fboGE=,iv:srZYtxDXXkCu5h7HwYbMtPr7PYhhgJ8rZQ3H4TOJmTk=,tag:iq6YEEyzYd6rNoAIgdk5Sw==,type:str]
secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str] secret__acme_dns_api_key_dooris_ccchh_net: ENC[AES256_GCM,data:1qDNE8CeXo6SA5vaZYQ/2yNUE9Y1nUkL976Qsq6D9QYCc3fIrkKMXg==,iv:clOa/vwup2QS0Yvq8JTFGhCkuviWWBPNzp0tht8WZXY=,tag:WwN035cE5AxVSpJqRqkGqw==,type:str]
sops: sops:
age: age:
- recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax - enc: |
enc: |
-----BEGIN AGE ENCRYPTED FILE----- -----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrYW9aYzMxeFYxemp5MUlR YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrYW9aYzMxeFYxemp5MUlR
NGJOaDRCc2E5bGdjSnFkcm5YMTdaSldKSFVVCmJmNERQbDF0Y2NDZGNnWVE5UlIy NGJOaDRCc2E5bGdjSnFkcm5YMTdaSldKSFVVCmJmNERQbDF0Y2NDZGNnWVE5UlIy
@ -13,8 +13,9 @@ sops:
YVc5c281N0Fod2hib29wOEJXZkZKOXMKx2g337TvrUk5hXZNbxlPlrWOydYbSBoW YVc5c281N0Fod2hib29wOEJXZkZKOXMKx2g337TvrUk5hXZNbxlPlrWOydYbSBoW
aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg== aHvFML6xynRtBrMsp9IebicBxZKSWLi7uHi+LuAzkIcqpAlJUUBAbg==
-----END AGE ENCRYPTED FILE----- -----END AGE ENCRYPTED FILE-----
lastmodified: "2026-04-19T21:46:01Z" recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
mac: ENC[AES256_GCM,data:5VlEYqo7ez4EgdMqGGnelc02EoT/bCLYVbPGHth4kd+DhOaJ1EXhmVB5eiX3AwyRl2nr79z/idCDJ6R1QdfQ5v8rYnnWcqehtiIIz0RBXhbED/hN2oz48yRhIX9vCB0gjsK6cacDzTCHP0tPEsQF+Ax4uWdXNHKnZVYS70qxbEI=,iv:noc3LJdiZ10w9O6JfwTxzLUNKT74rfdTX/Gb94fP3JI=,tag:WgFpYsFO3WjrjCs/7R634w==,type:str] lastmodified: "2026-07-23T16:56:18Z"
mac: ENC[AES256_GCM,data:hdX55T++CCuklTmttDNI99hNs48hhK1LfastyrPiF/PYMjj2bXr6zrT+J4IurhZxs00kHLiiBe2sMkIRF4v66xoV7YaAfR9wrsrUOtG4T/YoLgSuCrZt35yXvA928XcSS92oUgR7uoD5y7ZkII3T0w4mOm4OVtBrjc9zGTwd3Zc=,iv:V9UzvQlVEfFVVz2ELDSwpI8rC6Xk5/RUmaAsxdkHsK0=,tag:rorczKSSUIbgYiPLtmyqRg==,type:str]
pgp: pgp:
- created_at: "2026-05-20T02:08:48Z" - created_at: "2026-05-20T02:08:48Z"
enc: |- enc: |-
@ -187,4 +188,4 @@ sops:
-----END PGP MESSAGE----- -----END PGP MESSAGE-----
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49 fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
unencrypted_suffix: _unencrypted unencrypted_suffix: _unencrypted
version: 3.12.2 version: 3.13.2

View file

@ -1,21 +1,5 @@
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'resources/z9/dooris/docker_compose/compose.yaml.j2') }}" dooris__hostname: "dooris.ccchh.net"
docker_compose__configuration_files: [ ] dooris__openid_client_id: "dooris"
dooris__ccujack_user: "dooris"
certbot__acme_account_email_address: le-admin@hamburg.ccc.de certbot__acme_account_email_address: le-admin@hamburg.ccc.de
certbot__certs:
- commonName: "dooris.ccchh.net"
challengeType: "dns-01-acme-dns"
dns_01_acme_dns:
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
certbot__new_cert_commands:
- "systemctl restart nginx.service"
nginx__version_spec: ""
nginx__deploy_redirect_conf: false
nginx__configurations:
- name: dooris.ccchh.net
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/dooris.ccchh.net.conf') }}"
- name: http_handler
content: "{{ lookup('ansible.builtin.file', 'resources/z9/dooris/nginx/http_handler.conf') }}"

View file

@ -17,11 +17,9 @@ all:
ansible_user: chaos ansible_user: chaos
certbot_hosts: certbot_hosts:
hosts: hosts:
dooris:
light: light:
docker_compose_hosts: docker_compose_hosts:
hosts: hosts:
dooris:
waybackproxy: waybackproxy:
yate: yate:
foobazdmx_hosts: foobazdmx_hosts:
@ -38,7 +36,6 @@ infrastructure_authorized_keys_hosts:
yate: yate:
nginx_hosts: nginx_hosts:
hosts: hosts:
dooris:
light: light:
waybackproxy: waybackproxy:
ola_hosts: ola_hosts:

View file

@ -170,3 +170,10 @@
- transmission - transmission
tags: tags:
- transmission - transmission
- name: Setup dooris
hosts: dooris
roles:
- dooris
tags:
- dooris

View file

@ -1,17 +0,0 @@
---
services:
dooris:
image: git.hamburg.ccc.de/ccchh/dooris:latest
environment:
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
DOORIS_OPENID_CLIENT_ID: dooris
DOORIS_OPENID_CLIENT_SECRET: "{{ secret__dooris_client_secret }}"
DOORIS_BASE_URL: https://dooris.ccchh.net
DOORIS_CCUJACK_USER: "dooris"
DOORIS_CCUJACK_PASSWORD: "{{ secret__dooris_ccujack_password }}"
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
network_mode: host
restart: unless-stopped
volumes:
- "./state:/srv/state/:rw"

View file

@ -1,3 +1,4 @@
--- ---
allow_duplicates: false
dependencies: dependencies:
- role: docker - role: docker

14
roles/dooris/README.md Normal file
View file

@ -0,0 +1,14 @@
# dooris
Deployment configuration of [dooris](https://git.hamburg.ccc.de/CCCHH/dooris) on our host.
For an exact description of host requirements, see the README of dooris itself.
## Required Arguments
- `dooris__hostname`: The hostname on which the dooris server is reachable
- `dooris__ccujack_user`: Username for authentication against homematic ccujack
- `dooris__ccujack_password` Password for authentication against homematic ccujack
- `dooris__openid_client_id`: Client-ID in CCCHH ID for dooris
- `dooris__openid_client_secret`: Client-Secret in CCCHH ID for dooris
- `dooris__static_api_token`: A static token that is valid on the servers API and can operate locks

View file

@ -0,0 +1,5 @@
- name: "reload sshd"
become: true
ansible.builtin.systemd_service:
name: "ssh.service"
state: "reloaded"

View file

@ -0,0 +1,32 @@
argument_specs:
main:
options:
dooris__static_api_token:
description: "A static token that is valid on the servers API and can operate locks"
lilly marked this conversation as resolved Outdated

Please add another underscore between role name and variable name to match the convention used in the other roles (so dooris__static_api_token).

Please add another underscore between role name and variable name to match the convention used in the other roles (so `dooris__static_api_token`).
required: true
type: str
dooris__hostname:
description: "The hostname on which the dooris server is reachable"
lilly marked this conversation as resolved Outdated

Same here (so dooris__url).

Same here (so `dooris__url`).
required: true
type: str
dooris__openid_client_id:
description: "Client-ID in CCCHH ID for dooris"
required: true
type: str
dooris__openid_client_secret:
description: "Client-Secret in CCCHH ID for dooris"
required: true
type: str
dooris__ccujack_user:
description: "Username for authentication against homematic ccujack"
required: true
type: str
dooris__ccujack_password:
description: "Password for authentication against homematic ccujack"
required: true
type: str

View file

@ -0,0 +1,27 @@
dependencies:
- role: docker_compose
vars:
docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'compose.yaml.j2') }}"
docker_compose__configuration_files: []
- role: certbot
vars:
certbot__new_cert_commands:
- "systemctl restart nginx.service"
certbot__certs:
- commonName: "dooris.ccchh.net"
challengeType: "dns-01-acme-dns"
dns_01_acme_dns:
subdomain: "37caae1f-b77f-4eb1-aa71-dc3f7ed24360"
apiUser: "fd42b696-a394-4e2a-8fcc-d44c9fac5d4e"
apiKey: "{{ secret__acme_dns_api_key_dooris_ccchh_net }}"
- role: nginx
vars:
nginx__version_spec: ""
nginx__deploy_redirect_conf: false
nginx__configurations:
- name: "{{ dooris__hostname }}"
content: "{{ lookup('ansible.builtin.template', 'nginx/site.conf') }}"
- name: http_handler
content: "{{ lookup('ansible.builtin.template', 'nginx/http_handler.conf') }}"

View file

@ -0,0 +1,34 @@
- name: Create local dooris group
become: true
ansible.builtin.group:
name: "dooris"
gid: 10000
- name: Create local dooris user
become: true
ansible.builtin.user:
name: "dooris"
uid: 10000
group: "dooris"
system: true
password: "!"
home: "/ansible_docker_compose/state/"
shell: "/ansible_docker_compose/state/ssh-cli"
- name: Ensure dooris state directory exists and has correct permissions
become: true
ansible.builtin.file:
path: "/ansible_docker_compose/state/"
owner: "dooris"
group: "dooris"
mode: "u=rwx,g=rx,o="
- name: Create ssh server config for dooris user
become: true
notify: "reload sshd"
ansible.builtin.template:
src: sshd_config
dest: /etc/ssh/sshd_config.d/dooris.conf
owner: root
group: root
mode: u=rw,g=r,o=r

View file

@ -0,0 +1,17 @@
---
services:
dooris:
image: git.hamburg.ccc.de/ccchh/dooris:latest
environment:
DOORIS_OPENID_ISSUER: https://id.hamburg.ccc.de/realms/ccchh/
DOORIS_OPENID_CLIENT_ID: "{{ dooris__openid_client_id }}"
DOORIS_OPENID_CLIENT_SECRET: "{{ dooris__openid_client_secret }}"
DOORIS_BASE_URL: "https://{{ dooris__hostname }}"
DOORIS_CCUJACK_USER: "{{ dooris__ccujack_user }}"
DOORIS_CCUJACK_PASSWORD: "{{ dooris__ccujack_password }}"
DOORIS_AUTHORIZED_KEYS_FILE: "/srv/state/dooris_authorized_keys"
DOORIS_STATIC_API_TOKENS: "{{ dooris__static_api_token }}"
network_mode: host
restart: unless-stopped
volumes:
- "./state:/srv/state/:rw"

View file

@ -4,12 +4,12 @@ server {
listen [::]:443 ssl http2; listen [::]:443 ssl http2;
listen 443 ssl http2; listen 443 ssl http2;
server_name dooris.ccchh.net; server_name {{ dooris__hostname }};
ssl_certificate /etc/letsencrypt/live/dooris.ccchh.net/fullchain.pem; ssl_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/dooris.ccchh.net/privkey.pem; ssl_certificate_key /etc/letsencrypt/live/{{ dooris__hostname }}/privkey.pem;
# verify chain of trust of OCSP response using Root CA and Intermediate certs # verify chain of trust of OCSP response using Root CA and Intermediate certs
ssl_trusted_certificate /etc/letsencrypt/live/dooris.ccchh.net/chain.pem; ssl_trusted_certificate /etc/letsencrypt/live/{{ dooris__hostname }}/chain.pem;
# HSTS (ngx_http_headers_module is required) (63072000 seconds) # HSTS (ngx_http_headers_module is required) (63072000 seconds)
add_header Strict-Transport-Security "max-age=63072000" always; add_header Strict-Transport-Security "max-age=63072000" always;

View file

@ -0,0 +1,6 @@
# {{ ansible_managed }}
Match User dooris
AuthorizedKeysFile /ansible_docker_compose/state/dooris_authorized_keys
ForceCommand /ansible_docker_compose/state/ssh-cli
SetEnv DOORIS_SERVER_URL=https://{{ dooris__hostname }} DOORIS_API_TOKEN={{ dooris__static_api_token}}