new z9 ccchh router #98
4
.gitignore
vendored
|
|
@ -1,2 +1,4 @@
|
||||||
.ansible/
|
.ansible/
|
||||||
**/__pycache__
|
**/__pycache__
|
||||||
|
**/.DS_store
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -51,6 +51,7 @@ keys:
|
||||||
- &host_light_ansible_pull_age_key age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
- &host_light_ansible_pull_age_key age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
||||||
- &host_waybackproxy_ansible_pull_age_key age197tmckjll9999v5apqh5h70dktdxzxn92uyzce5j7jmesvnneecs9p7m5j
|
- &host_waybackproxy_ansible_pull_age_key age197tmckjll9999v5apqh5h70dktdxzxn92uyzce5j7jmesvnneecs9p7m5j
|
||||||
- &host_yate_ansible_pull_age_key age1yc9s8r7zt6tc7scfyxc3345khdwqrx0lwj4z6yp56h6rmauev50s5yqr22
|
- &host_yate_ansible_pull_age_key age1yc9s8r7zt6tc7scfyxc3345khdwqrx0lwj4z6yp56h6rmauev50s5yqr22
|
||||||
|
- &host_z9_router_ansible_pull_age_key age1tx03yh67f052jzehvtvzmhe5ja6ca0rlugw8pr9v7q67z38w2ahs2a4alp
|
||||||
|
|
||||||
creation_rules:
|
creation_rules:
|
||||||
## group vars
|
## group vars
|
||||||
|
|
@ -262,6 +263,12 @@ creation_rules:
|
||||||
*admin_gpg_keys
|
*admin_gpg_keys
|
||||||
age:
|
age:
|
||||||
- *host_yate_ansible_pull_age_key
|
- *host_yate_ansible_pull_age_key
|
||||||
|
- path_regex: "inventories/z9/host_vars/z9-router\\.sops\\..+"
|
||||||
|
key_groups:
|
||||||
|
- pgp:
|
||||||
|
*admin_gpg_keys
|
||||||
|
age:
|
||||||
|
- *host_z9_router_ansible_pull_age_key
|
||||||
# general
|
# general
|
||||||
- path_regex: ".+\\.sops\\..+"
|
- path_regex: ".+\\.sops\\..+"
|
||||||
key_groups:
|
key_groups:
|
||||||
|
|
|
||||||
|
|
@ -2,7 +2,7 @@
|
||||||
|
|
||||||
Folgende Geräte und Server werden duch dieses Ansible Repository verwaltet:
|
Folgende Geräte und Server werden duch dieses Ansible Repository verwaltet:
|
||||||
|
|
||||||
* Diverse VMs auf dem ThinkCCCluster
|
* Diverse VMs im z9 (PVE Cluster)
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
|
|||||||
* Diverse VMs auf dem Chaosknoten
|
* Diverse VMs auf dem Chaosknoten
|
||||||
|
|
||||||
Host-spezifische Konfigurationsdateien liegen unter `resources/` und werden für jeweils über eine `host_vars`-Datei im Inventory geladen.
|
Host-spezifische Konfigurationsdateien liegen unter `resources/` und werden für jeweils über eine `host_vars`-Datei im Inventory geladen.
|
||||||
|
|
|
||||||
|
|
@ -2,213 +2,225 @@ metrics__chaos_password: ENC[AES256_GCM,data:seOU504dZ9K21+NK1MBf9isee2L2rueP6Bl
|
||||||
msmtp__smtp_password: ENC[AES256_GCM,data:FAih8FghRYDx3QGFCjKoJ8Zq0TkeCIx4n1jTx4/sASgECqvucg==,iv:8NDn3wj/bXsbHbuce3ycJTBVWde6XAVxv4NuMUkMbIM=,tag:jeE2b0i/8JPtguLYQvdV1w==,type:str]
|
msmtp__smtp_password: ENC[AES256_GCM,data:FAih8FghRYDx3QGFCjKoJ8Zq0TkeCIx4n1jTx4/sASgECqvucg==,iv:8NDn3wj/bXsbHbuce3ycJTBVWde6XAVxv4NuMUkMbIM=,tag:jeE2b0i/8JPtguLYQvdV1w==,type:str]
|
||||||
sops:
|
sops:
|
||||||
age:
|
age:
|
||||||
- recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
|
- enc: |
|
||||||
enc: |
|
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB1VWJQWnBhcDc3VXh3TnMy
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAxTzAzaVFSRDQwN2llbmdl
|
||||||
RFljQU0vNS9iY3AvTWFraUxneHIremlDeUZvCmdzd0twWHZEdTZSbHpLbEpRRDNX
|
alBBVDZwTWhWUkV2L3ZLZmNDUDRyTitDaFVzCkNRTEN4ODV5ekxRVlBZT3ZIM2pj
|
||||||
aGI4ZlczN0tFbC94TzJ4bm9aUjkwcVEKLS0tIHRGSGdkQkN6ZEVTUjl1cGhMZzVI
|
Z0JxYUlobHZCeGxxNE9PcENkR2h2VDAKLS0tIFZiVXJHSU5naXhSSEFobVZBN1Rl
|
||||||
S2FtSktoWmF2TjZCZnNlYWpWYzQ4MzQKeK7f+UPSanQsOIXNjzZa9B5FafNFsN3W
|
NnVDUVRyVWxlUnMydVhiQ2s0bGMzTGcKh97/UOPxrKieK5dKdGyRqCRi8Sm5UNcT
|
||||||
sjssDdbNQ1OEn2CLWRVQl1umKrADuvd85fMu3gUZrycZRDCCfsBzVg==
|
I9jLCPqX8Utt0e2EEp+ivJwFxgo7QuNCYWu6jtPCO/Zmc5Q/2tJQ9Q==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
- recipient: age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
recipient: age1j0876shgsn7f2thxh9kx9x5uwnh45z6sy2jlk2qz5jhgedm26g5srn9kax
|
||||||
enc: |
|
- enc: |
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBkSmVEVyt3OCtvUUNqV2FR
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBuVUtpb0FmeUduNW9EdHJw
|
||||||
QW5WaDBFcnZVMTV3QWdSLzhxRENCdGNaVFU0CmxqM0xIWUVCSUwvY1pBVjQ0RCtq
|
WEY0WllWdE8vRlVhODU1dUcxUnF3WE5mUG5vCnBQRlNkblNHbUFESXhvQ05YdGVW
|
||||||
T0psSG84VWdpY1dYa2doeFZXd2RKNVEKLS0tIGNFeDFRYzBDN3NWcnpUSVhEWitY
|
UkhjdjdvclRmTk55UXRGRStXREFiVVkKLS0tIDlkMHhxVkxEK1BjV2orQUtndGc2
|
||||||
RXhLRkp3ajdlNGY4R3hRcWVSUU04T0UKdprDhBpp0aMc733Wx/K7hS/nLVohvlft
|
Mk8rZm14SzFWTjJTanVXaE53UmViS28KQmnPfzLhgLasSuu1Aflp/JDWo1hqvYjb
|
||||||
N9aSQdcRoqT3/iMGu/6xdqbeq0/7a/U+6JvhYyWLkLsrzw2mlVRoIw==
|
BijruPUZ3NuoZ4Wuo56FLlTLrch051fI3ottzy85FfX3lRnWZ2IK8g==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
- recipient: age197tmckjll9999v5apqh5h70dktdxzxn92uyzce5j7jmesvnneecs9p7m5j
|
recipient: age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
||||||
enc: |
|
- enc: |
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQWWM1WFdidkY4a2hLNm03
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBQSm9FZ1VmVWhadldRY0JU
|
||||||
TGdNNE9ZK2lvelhYQndTYy9sUzM4TkN5elRZClJwQU1qeCtwUlFzeVE2d0FSSCsz
|
c2R5d0tNMDV5U2tzbVorai91RTFyZFdUMWo0CmxLVUJYdVFUN296U3Q3MTJQM0JW
|
||||||
WTdzQWZLYXpqUHcxc3VEWHZvNmZibU0KLS0tIElCTWdraXRLcHNHMjR2eDVxVCta
|
LzNTYlVVVitRYmk3azQ4VXBLWTZiZjQKLS0tIDhXdFZaK1BWVFp4M09jbk0zdGpF
|
||||||
bHhVdFpOdDB0eUR5d2hhdWJlcmJDMjgKBbVkm7LNwnoUVrUF3NPI7d25b6tAIr1t
|
dGxmUUZkQS9sMXZoeTJETGpvQW5VQ0EK9Y/trD7VhjQnqY+KryPfEv1J/D4NCWsx
|
||||||
HelMjQU5YFM7DvRYFOlNpgO7WmddNSq3C6WYa8AZDGpsjc6GypcLVw==
|
CHv0R1ps6A0qoRJzS1UNxU5bLXDX1RGQiU/arhJ7LXFxHrNOdObsZQ==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
- recipient: age1yc9s8r7zt6tc7scfyxc3345khdwqrx0lwj4z6yp56h6rmauev50s5yqr22
|
recipient: age197tmckjll9999v5apqh5h70dktdxzxn92uyzce5j7jmesvnneecs9p7m5j
|
||||||
enc: |
|
- enc: |
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAzTmRaRXorMzBQZWwyNFp5
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBreTY4bzJ3T1FHOVdhS05v
|
||||||
VHdUUElyd1V2dUcvQ3k2STQ0d1QyMytsRG1BCm5CVCtRWU5FVmErQWl2N3Y4QTc1
|
dG40VWdVeWRpamdqd2ttajFJUjdYVHB0ZXdVCmk0UUJuRHdsUnE3ZThNakpwY3po
|
||||||
Mnh3K01QUnk2MGpSZk1NRVJWUlhFYWMKLS0tIEFOM0pMa3RVNUppS2xOakFVM1lR
|
b3dtWXNNSUlvbzVHcXVIclNlaVNub00KLS0tIEMwL2FYcEZ1dkZ5MFl0S3pWSWFJ
|
||||||
cnlBL29XQVlsL1ZCenBIYTQ3S3JxQjQKq09vbn1XOC1jIXDpv+ThFMk9k7SyYknr
|
NGdXVXA4UGJIOTN4UnhoMjRYaTRNWXMKGJNomXuB5TqXZKWk3Ub/rEc69CrfYABw
|
||||||
MBJRBp/0PrKBo/Xk+RCSWSLjgali5Cc8KTjDTJyBG8rFzzvLIazBRg==
|
bBBidbCQBrv7cnsvjsVpHHGaTwyP9Nk1ceF/gbv9fD9gZ7dwt3SA1A==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
recipient: age1yc9s8r7zt6tc7scfyxc3345khdwqrx0lwj4z6yp56h6rmauev50s5yqr22
|
||||||
|
- enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrQWhjNHlDU0RKRmdKTzh0
|
||||||
|
M3dhOGcrc1N5SnozMHhSQWNUdERPSjRrZ3lZClBpd1lrbXY5OEVnMVgwTGl4YmUw
|
||||||
|
bWpJR0Z6RDZubG9lS1BIVnEvMWhEdlkKLS0tIFhSbVFhVnZIN2xETXlWNlh3TVVG
|
||||||
|
N1VTSWN3SEU5U2Uxc2lRUmwwaWc0L1UKfPWAEs93dF10GZdlQt3yeDltk/9Djmuh
|
||||||
|
3ZeGLgkOjcJPXO2hFQMZoJY7a2ZRIxN5Oa8PGwuy7DEtmQ9PdP/mbg==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
recipient: age1tx03yh67f052jzehvtvzmhe5ja6ca0rlugw8pr9v7q67z38w2ahs2a4alp
|
||||||
lastmodified: "2026-05-23T22:10:20Z"
|
lastmodified: "2026-05-23T22:10:20Z"
|
||||||
mac: ENC[AES256_GCM,data:JbnKG1qyAkvFDXr2iHu+gk7nRjedmm+dEK8vBFW5YzndWE4QKoYWeaqRHBk7wdWO9kpZgU2rFiu4Be+ikotoMS8jKAcd5wWSrWtSreaZxxiD2TWMWX8HwPtETnYe0rjrEZ3kPcUj4QPyNTphfbH3ARLjthedRXNF70NDc+DIpAY=,iv:4LN3oslWUWqoY3rQNVDSmlJn1o0c8JQELzsWd5btn7Y=,tag:c8X1q9XMMUkXed93j9C6ww==,type:str]
|
mac: ENC[AES256_GCM,data:JbnKG1qyAkvFDXr2iHu+gk7nRjedmm+dEK8vBFW5YzndWE4QKoYWeaqRHBk7wdWO9kpZgU2rFiu4Be+ikotoMS8jKAcd5wWSrWtSreaZxxiD2TWMWX8HwPtETnYe0rjrEZ3kPcUj4QPyNTphfbH3ARLjthedRXNF70NDc+DIpAY=,iv:4LN3oslWUWqoY3rQNVDSmlJn1o0c8JQELzsWd5btn7Y=,tag:c8X1q9XMMUkXed93j9C6ww==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMAxK/JaB2/SdtAQ//VIMBtLL8lhncJeItw53fQW4Lia0hs84yuKLuSBucNXhy
|
hQIMAxK/JaB2/SdtAQ//cayg/ELKtybgayA4z+xOUK10zQJDE/U43BcPRMrBN0+x
|
||||||
x3LT5r21C5CZ+JnucrGPxur4clsLnDnng2CgyWhksJNknk6smQIq3ZhyBd/OJzS4
|
VLu/C96Eom/dJN62SM2QamThHu454HMZj1PjDynMUzgfVqXEg/eG45bBBweWrI65
|
||||||
zNGUJIbitJsDaKjTrYDCdsQ3KVcRBDMu3ow7vzeP4wnL4qU5fUuQ7S2rK6a1hfMB
|
s0tuzLmsqpdt9TJ5t0znliL2DYS3MPfmYRNbAsYsCbQd4I0YpxdzQwTvURdzjpUG
|
||||||
eTQmn4wD/Rl+Q0AWEo2V/X8UgchwGPeuOXfju2t9+1UVE0kUJdXw/JIrGyR8XrYM
|
nVBUfzfcYH1Yqq8BVtR40MKfa/DbOsJGENHtpkQ9UDAa3gwVQs0NyZRQzg5w364C
|
||||||
6ZGXB3mPnlZTZjqhXVSFSSOUTRYu/0g+s/JuDLpgl8gVP+oDvSCPrB2pDNK+o2Oo
|
UvItYlU77ZCKPkyOQuciLn4sM5poihu3UNWp855QsDK6fZVuxPTS4Cn54cfwdOTe
|
||||||
VbQbJMg6lMbIuewd0ZTTeCv/TFU9O51RtkFyxHIEW7dVelDrNkuciAG1mDUHFUUw
|
rL/ZQjLcHJ7PRmZUiWR6GVNDrY55u7zhORD4b8BgrpWW4hhxpp/ENjnRmNt8jKR2
|
||||||
MHeWDjngeCzr1hj1Z78P1bvR7I2pqBQiWT+d/e50S5quNRVjtLVEjuU7r1eKiPDu
|
dJ/5/uC4HBX0fM3mbfpUn19BxCk9+gFPmNUOUZ93UxpQ28l1lZxeiLBOHAw1srEs
|
||||||
pL1lYJZZu5+uY1nWE4qeJiI1KambjP9/C+RUCF38yT1wNvxrbwsM9haXGbI3t2cU
|
7ZfFrJ0osedPGHu8rVOe93DCAtb/oNxr1xvGuDK/licRkEh8t8cvuoVsVhYFjNBc
|
||||||
X/RRpK5VKKKwbBqyQmkZX7xaDR13hLF2vLtdVw6L9nYVVactfnFr9HKDV95HUnhO
|
UKXIPrhvuSj69c3OiHa+u9fNZJX2XAi0oOcZqGp+sQCCgUCA15I5QiqTpalCSTKt
|
||||||
uevmzu+ShtAt9FMXz86dLYmBx90A2BSWxb6sKvZkG8UDY+vVT1K0gNK4kwxR9rKt
|
/Stoj9BsmlSiy8YD2XBjmzHHVxJHfl8XHcuONKc3e4UmVjKlzkzc0bI73Y6XiEvt
|
||||||
LFzCq1a3ftx3UvrNMCwaboGQZLpRtiKr0lNQvGLpH/SRDZ2HksinV16FNVuN74HS
|
zRIUmWxfvAvqP/zPcMSwaZke5h7N7ywKcjM+RHB4NqRUVYlBNwIWXvi7f5BdLhrU
|
||||||
XgG5HnRO9/lkL2Bn+ms7Q6+ki9QmC21FlLGJOBQIi+VHNVwy6J8XQlrs5NZPy6Ib
|
aAEJAhBcA//3NJxuDzlf1zoXGKOhGIwNv5/Qb1n13OKIT2s0nfbqEHgAUm+tX3gk
|
||||||
LmWIV6BdIRejCAITlVeBRBpXymdUBicPLa/VQMK2s9L3SS7MUcv+4j+vje9YR5M=
|
VKKMqFuVmq2mkAaxXWFq20VC6djTJJS1QOaNsc6x3bJ6iDtYV19Ddn/20jbmbqmn
|
||||||
=IEFm
|
XbCDvb50nubC
|
||||||
|
=ZByJ
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: EF643F59E008414882232C78FFA8331EEB7D6B70
|
fp: EF643F59E008414882232C78FFA8331EEB7D6B70
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQEMA1QflAioE8i3AQf7BB0RdJbe8Ro2Fv4Phw+VaR0rUIuQKWOb7zf3/9YCbV2w
|
hQEMA1QflAioE8i3AQgAm+iazJdcOXiq08MvSGMQ9/NAvrgcDav4561Hew23n4Ms
|
||||||
rICGVIx7V1vJF5R5RgSfk0RDrLN3Pfoq/7Jfkq6bMoHIVCHSFdryHfjG5Dgm49Xv
|
tKC5VLXf3l1f6yjhBZy6mnslYOWWdJ+X4XK0OqWkRr/t7zxEK4M6PC6g1W5hkaFU
|
||||||
gDZ2CPAHPn15mG0Rr/67YUWsC2Jy4y6/JY478wzYu4Og9IkxkeBd6ufBFB6bTn4H
|
+9DrkBLKss8atz3EhexK6GeljTuRpVWM629BtvMPBo/41eyue78TLf81vCkbUJkC
|
||||||
qB7B2hfkyQzA66zoxc0r2O1mchbJ3A4pVJw0v2I/sWCiZoJQKmt8ksoEK8BAQCWC
|
UpeB4alsETvD9Oz0ZRT8fipuXzdpGSjobOIgQa9bKwFMXXGY2fwBuKW8gVtSgbXP
|
||||||
E8sozb2opRzFaUCZSNEdhz/rnbV8u5wW378kd8kHSOlWxaFZNkWUP42YQiNTkd9/
|
mKwqvGaSdHz30BxQExmLne5ERKHOvzac2woG5tOmKPaihg8pbvuq/VjS2K0mzS5q
|
||||||
YpxxGvwCTIpHGAYFtU7CV7QfQHzTuAOz7ZElPZsYkdJeAZCwUFO24nzwpxYS43AV
|
cbwyq/u4d5fGEFQYqMARW1aiyo3NjYk4xWDcGo5Ql9JeAdwhj3Wgm1wccULt2Hj7
|
||||||
29IHXvlKAQkjJunix0bPGcE3D6T8CUs0wXL2sUSDcvgOOQZSezRn4UNEqFCftjJ4
|
z/V1utNINoB0bPFb8ZQMmPpwAeH6nnoqjWmmoRSW0tL/EaPh5xQXdEuU+DloT5f+
|
||||||
Gmldo/baMO2Y054/iA0jvNmHRk6sJCY8aRYv9m5Fqg==
|
k8c2KQC+v4bh6BMUcycAeIG/h4vKsgz/Jc6BWKKD2g==
|
||||||
=n7Qb
|
=G51B
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 21C9579E6503CA815A68ABD8541F9408A813C8B7
|
fp: 21C9579E6503CA815A68ABD8541F9408A813C8B7
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMAz5uSgHG2iMJARAA4zyDJtNqK5w6QPYMyEtjuoAmva91yLA4oAU/diRpFXHx
|
hQIMAz5uSgHG2iMJAQ/+NjXRTghMiYErsXenuJRaWdwHZ+6DkkG8nC5b+Aigljgu
|
||||||
D4UzksW8moYqmaiWblFy1HeQJFwZWrxnXeqg9B7PFOkhriIG7al4DpV2wXoCjami
|
OJg5UQgYtX5W5T79uUuEh5BWKO5bMHBwDNHQC7Hn1FseYgrOxcoSYOsewlb8t2QH
|
||||||
DIkewGoeZjTbPNxsDVl0SbDafCARQFnQ8LNTmM2hi2X/ACg+c8mSM7eK6C3mh8yG
|
fqGLLhv82nRnU0nTs8W/yvrBH/ub0kAtuko1jkPSAWnoonmeEW970iLVIF9lCVYJ
|
||||||
Bo2EsuCnIqzwzV6XbGCKnfOUh0QekWM7Jc/e3oYGSgCP2N5wb2PLVsW1220qdPvo
|
idF+DDSiic9RDpHd4Csuxdv+1Q8OcaOW1HVAUrfrKOvC17sawd1Cat2DWC8EcOVD
|
||||||
8D1l5cDVj2Pgq7fnfbxZGJYSfdgJb1YweH8mjHk3gHU68AGeeSkV+VwcBGV2HObg
|
clNn6A91FBCTxVnxwM4j2J/NXP1JRIGnlxaa4lATQMiX8lfheu0LyEpsFZai55RC
|
||||||
hKSbVWcyGAHrP1ppCNyXr5ZkBgyvdB/EjxjLqTLq7sdTnqjLLbMLgi9CCI0NuDMI
|
dq20HWqPgYHiamp6eGQ+Uqe5edx6F5YX/25S2Jfrx4D5vRh0PFx6blY0kgZJp16a
|
||||||
jfgMjOdaImjUvvr8lCl7dOMyp9wc6ks0bwRbfG3AMLGKWeR+un3uaDYujD0bQLqZ
|
ywNiMtLPh7HjOMbB1v7bcWtIDWrIhWDtyJ7axny8sMamCLCPOwPpPvdL/B5YOntm
|
||||||
m0g5mx1wHxNCJIb2ZQ6UVjDlnatTYGBnxEupqxr9PFyny0MRhaiYkuDIh4tHW3nH
|
+0wMXHXCLCaljzsa5GFIyVYj3pTY/6O0Fgkv+6ow08ndPjsViHNikufCSW0ueIFF
|
||||||
xyCHN9QIO2/EktLkM4wcfhOeVgdpfvKgT+cMG9kS/yfInZ5ZAGvXznzvfNZZtKDL
|
ehv0V2+AHhedoHChFZI/DEbGzIKVcr7JAA+GHAIWcklg7O5hss+/rr7nYxVB0A+t
|
||||||
fLvvF5AqYbN05c0h56WJa65tIT75P2wI6ZBncCSLqSAzyXWlZFV6UBP+5QLEkQaE
|
Sfp5kVMInLpCPLRm2retun3zPF8+R0kN/ZrkLy02K7z4rrD8wVE5QUvSCWbpKdfS
|
||||||
WtY8y2907OAx1v8g6vc5v5oHMqfwfWC4nuFbkoJo/ZbfvtDWq4eFZfkUKY3Au5LS
|
deWIy4lp9wRXSunag1/CxqvrH3ZszlxSZPEQkC4hez+xOS//L/5QsiP52SavB9PS
|
||||||
XgE/l6NTtWknF4nPYIRaibum4527ke053JdD/50eqfuRv8MFIHbRPfWE4lE6lgev
|
XgHvkL3slXXsdnIgm3cYnHqEBf2rXLQR/ZTzusXMLEBaGCd9JB33T/Lz+TUftCUI
|
||||||
+/j0Ef9sYRu726Sv3wAgT7K6PmCFsLN1319OmjkZpBAJiNsxx9qwXyqgTpTvb34=
|
xxLwzFvm+dEvQ6bOB6/OvSMBIsvVzMZxaIblwZRdIYfQovEdKLCRc+F4lTqV8fE=
|
||||||
=Hr9J
|
=1lXS
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 18DFCE01456DAB52EA38A6584EDC64F35FA1D6A5
|
fp: 18DFCE01456DAB52EA38A6584EDC64F35FA1D6A5
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hF4DsZXvxFXTXoQSAQdAp7TsXm2MaBAh0qB3eOjtFuegcEsmtdQHsMP0rs0N/m0w
|
hF4DsZXvxFXTXoQSAQdAJAr+RX2f5gW5PpXJ/WA+1qMPFjuWuDccIk1ecWzc4kEw
|
||||||
bbbzXLwq1TGL82l5Qon4NnX9Jg5gXnKydWOiKWhxCsQ0iHJ7eupJLxyfDD/kzga+
|
sNH69jVC0JL7l5RMrJTAaY0GRTMrJffoz28JxpVbUVFEpeHsd+myGCcD1jZyS1MX
|
||||||
0l4BRUpbBFslWWa8Fb7zfNA7kslhkaQIJAmN92Yh/2NdkpmNEpMMaIrx2p2jK4Iz
|
0l4BllCKEsOVnEKKxOscOIctaIw8/MDNnLSoP04JI2xVKKThor+UwUhRzg+fVwxH
|
||||||
mwGUQlUz4ZkK10xy+9LMaAtmLhBJgBhDTKKzw7OAsRAnASq2gXA/4wqEVgBU9BxB
|
uEiHsx0xA/q0HVXhTNIvIWn0CKx/4uV8JwVa9JqjSSyQVm8PBwU+UTfXMQ5VcuHv
|
||||||
=tBBK
|
=uxSy
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 9633412309CCB83BFA39BA5F2FEF746201D7FCFE
|
fp: 9633412309CCB83BFA39BA5F2FEF746201D7FCFE
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hF4DerEtaFuTeewSAQdAlBZhTjLL3YPqorSXq0jet/0CXmeZeLL8inGvm/HgmgIw
|
hF4DerEtaFuTeewSAQdA2k3VLlMvCocHQ1ULFwTJKqscSb2FScq8A2I1TIdlfXAw
|
||||||
aplmjWHB80err0ffZeRfcvqx9DGujpwlgoFGDxjqn4LIqoNg6YK/VfFb9pXUvIOv
|
jWLzGphdsfHuNBEsocoixm4nKAdhjgBsud2rfYkuwxpqX2MlBr6ikpN73dXlHtt2
|
||||||
0l4B9xQ4DlaYOX1egCQUBw3KcdcnNlcEZwTOwTKn0Hg3gXp0u3TYlJFZAchw2G+l
|
0l4BkUvmqlioN961OV7nssbeQLzb49C9Gzm5S1dQqBQVCt/7qGodTHHiQON7bYJp
|
||||||
XJjlWiwJN2gKfEG7hrtZ7MJkYJFsqMFa1aC1oWHduxU4jmdRdQqdIaQDsqkcqJc3
|
+OgUaI6bKZjd9Lhm/u98dTH2cdPm1B5bUQPDzptWX5vG8euzBQxXc7OrGsTFyYME
|
||||||
=KNVY
|
=e/rg
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 057870A2C72CD82566A3EC983695F4FCBCAE4912
|
fp: 057870A2C72CD82566A3EC983695F4FCBCAE4912
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMAxjNhCKPP69fARAAhSBdgW04fKM8tAU8sC6h8/4e0Io3W/D2l6P7nZiD9WVR
|
hQIMAxjNhCKPP69fAQ//VLyOILC6lpvlq0W7NeYfUzL7KtKYXVDF7aSQ/b6Vn7Of
|
||||||
2pUqS12mlNCoRt1I2empyJ5vm1wjor34BCuSCiyfLQ1WIlBJlDro96ygpsHZGmam
|
ggc9n40n6FkMJqknhbvSnhhlFdzVOCZkLy/hinNk+jF2POBlLbzBjCuzQSP+ZDyC
|
||||||
tNcrgwc7y6rg4ycqUWr+H+WVZ0kw1IYYKbfAjMAJF5lQqzz+VMvET9BbmvA595MO
|
Dll2UJ/khITd+tQ4zwrFLpixr518Fgcj8NOgtljUovxR1bGIzYogpmiVFJEd0cT4
|
||||||
l/dnMColnjxxBiYBIzO7mnli+uqRHB79rM2VVlrqoT+C2s9zuPfpJfY0PJaCbbdg
|
k7ldv5WbZtB2UprhPPpNe+98BaUvuSvA9RWCogaBbuQpY2p3g9t9Zo58spOawbP4
|
||||||
BlffAMqs9m2JZdDr2r0lrN/jyLUB2d3l9NCcF6UYP6tjgZsKmHv/JxSgXLf6IklE
|
ccz7Pu03Esy3cenlnCt3G7gl19viIh+wHKrIXPa8dGO6TEsrRMPT0tNEs8iUJyDO
|
||||||
wolO04qgDRK7jeO2UGEniweVQNi7hqA4vkp2TskGbfVsS10PyLYKw4N19GedLS3c
|
TNEgo6+yxQ2p+08EzAh0BCRwljqnPLjS/h2s2s208Z5rBOCpLY9RuoXz7JRvZ06p
|
||||||
ZxRGde42Fze/PrccWq8bGdOfWhPBo2/MEyqVW4lgTeCCwrFRO3UNyYcWo7cmaN1q
|
gBgPFSIH12VBGjfqCB1uZIatbtLQLjOo6+UU0evM65WhKw3//tUnLrox1reoiRzO
|
||||||
lz7uaV6ffqbUDJSkjkphvxnJtuX62x9Uv/wcwrJuZUarSNclQ0nQV/e5wc7SzPgM
|
ro4JuytP+f4PylQRsr3jOYKRKCBzoZOOPZbVEpwQeBOe9zzxDgVQqHgVDDZQzCcw
|
||||||
B+GLeR4tnconDZGFq8q+KKuHe7MSx2uwiZsJIVXohcZwhkd9wk5YQBPc8i4aP0NQ
|
VTHCrs4XVHxPH0aRMlS4A80xbH7VncYbcbf8a6VrTpnPflv0OryWMWDqLBzmIPgM
|
||||||
wsb+QptuM8VpCEVAwKOUjp7IRRfUyqAIlmIRDkTijmHknSmI9HZXPyCvTLoy1Szf
|
W1Bz/hq/o6br+g4uAKjt4GTdTwWYxptA5L84aMoihpXRu0MaPhG+7MRsXpEa/+Ll
|
||||||
KDrN1MAma6b4gsru1fFnVizXQyZozl5RVZFP2Uv+ndugdvRE5sv5aevlzgaWFg3S
|
+ybl2DLpm6zm0iixkJuxwtOdQOGjqJqC/GLw/EZJTt2aO+ZUb8dLrChNmR7HJAjS
|
||||||
XgFqaFwId78UDNTrxcs4EzjHmlwg4E05G9pUqbA9zBDdCqwlD4+6CfAgQ46A6ptY
|
XgGBpFYao1AQqLZU3c+5B2/9/3rtOoVX1DQXhUsji5NkaHyYO8usauj9evPUf4qx
|
||||||
5p2QQJ3KXgJXrtlJySq8piReyq3mpagtWZJfAazovJA/ZF4o/xs9ZIu/q3qxHSE=
|
FAQRWua5/zp/cTlNWU3GknqtJ1G0g1mrkiVeBZCRxIK2Iyvyav7RALJ1jlkyW5c=
|
||||||
=nR8y
|
=meb0
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: F38C9D4228FC6F674E322D9C3326D914EB9B8F55
|
fp: F38C9D4228FC6F674E322D9C3326D914EB9B8F55
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA46L6MuPqfJqARAAjpM3MO83b2EUtzyZs66HWH6Kd60rl3QODTqs4PQm1cH5
|
hQIMA46L6MuPqfJqAQ/+NK0D10olgDK4KcArzoMtrJR7qwbrceSeKwaQGsUB1+RZ
|
||||||
HdzfVJ2IDo1y+FMTMmfJov6xBqnlalNaOvg8XFAkKTUkZgUHRW/q1WXP4FywTWmP
|
xv6pZJ0zyw7McTuUV2I4bLYHy/TffSyJk5vLSSTGFXgHVdfKmjvm7VDEp5d2uKku
|
||||||
aJV47x4dOQXQgj/i/ykMspUgsxA5049/nG1y06Wsm2agLO3KjL6KIJAx0LI28XPU
|
GW3Qh73quldfhd5GjO+F9V/S3rCysrNMpTmPnR5ha877FKGtc8168XRhIpe/1+mP
|
||||||
qA/NFtfNuEAv7DGS2LGz1+X1hnRYcBX/oUgpihzActWmMORD6VS7xZGcMdF2/+Ex
|
mvlE6h0Xizbx9myGR+ie17nHpoH+tjTtQFH640s38+xDgH6AozwWGUe/g5TdLaLJ
|
||||||
OCDAnwT0cBSAihBSLTmEMJ4xfmMG228nbLqm9r/gELgVIsIL5hXWz0CtxaewwLQQ
|
8SKHyQnS8hOHQDkttvhWRbyhKa8WuGyOKSjuQ81HIv+/UPxh1fs7vovPHM8rtIyy
|
||||||
XFMm/ZV/G6bZKRJzKPOR9EcPMF7Z+nnBts9wKNlE+WA32p7zu7hjvEFZhLiDKYlN
|
xGcWPzUeoKQiV2nyXUP3BqglhOhD1vokh3ejDcxwWWKuyASCSXhhvW7KMsV3Stdd
|
||||||
+nFcx/rvyWB6sbFK0xn2x5MonxWNVUy58PnqGWmPi2VtXT1al1zSAoKAgg8Xdw21
|
E3O1nyOi4+2I2E4TQo0NLt5mTJonPbvSn4IvV0LuatrG902UeNNZRRwQv3ZrVp6f
|
||||||
PQENtxqeUSLXXb0SZXFptMmYStwqoaFusLOCLW42DogFU246o14veDDtsS619T5G
|
G2ZJ9HNSs+Tp9H8cJzBGjDBYjC6/d3GGWi7N/5G/n6C7T6W81BgO8UiQOleEDF1c
|
||||||
RrszsNg543i3ra7MIm99YRXyniUaDp5VlKufPkWRexIT5YZYalOLtdLcaTTzfr7J
|
Bi6NPNeoGL8fivVGlGTHpLcpPpbYz+1ynsFs1ho4+v5bHS5w+UfvVvQC7dlDKmR0
|
||||||
x4PNVOK2ddtmlKbbakvvmPWS3iBEUGMqw69dPhEdpY8yy7HJ2jpXX7TiezNqGJ9w
|
fUAkllcxLSnzKkpKis1HF+Gp+lSNc75/BzOeTA2gS3c8H9jMuncRolndPX1rVJA3
|
||||||
XqtI9RJmWrr0/zSoim0EpHDwXZhSf7YVcwTs0XCtwrXcQT6DLaZJr8cny/G1ErLS
|
mrLiQE/Mja9NaYHzUROKIHDEUOQ1ZzvpcRduggvfj6Gb2wzNdUdR5QrXnLeI2jbS
|
||||||
XgEdnUqFpB1D0bacmRpfHA3PLZJd/x0QfwZ/b7gzz3f1xRfMXgnsM4iYu1S8+VAW
|
XgHO7Jr0HrHzr/+p+w89U+uH4b7onseYDiAjfLjAZpcYwkzuy7b2ZUmpLq1BjZRo
|
||||||
Dy21iVFZledWfrmuXh/PkLFftLipYK6tc0n922kFFxCn/xSP0yx9qKlNwzyduNI=
|
zs+rSqv4BP0Xa7LNIFrHj4OeL9ivwP7Kw/Tb36hU8DJ8xDfilx81n69Fer/cJ8Y=
|
||||||
=4+Bv
|
=BNfm
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 8996B62CBD159DCADD3B6DC08BB33A8ABCF7BC4A
|
fp: 8996B62CBD159DCADD3B6DC08BB33A8ABCF7BC4A
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hF4DQrf1tCqiJxoSAQdActtZQL4KWrCP8UUZa/fLeDltuNV9JjxTYiI9upoH12Qw
|
hF4DQrf1tCqiJxoSAQdA7az9ylWMB3fWHwSVRmU8Gu4Qnd6HIyMuiG46weuS/Cww
|
||||||
6n8EBLgKKNw1Hsb40u9M5Ro7Xzbys7zwZsL5CxEgFGDBxthtcdaI/ykjU0W3poLE
|
QMCknkfCG06HtMrOcroNigaj7G6FEvDm64sUkpW/ggWkHUUEMuwi5jcKIdx7XdbJ
|
||||||
0l4BcMpLoCyxxwIn49GpFxHiv84Q9xhouSMmCTe2p3bn5zCRBnKsetVHtEti4iRF
|
0l4BDGUF81uOghQUq/JqDtiYPD8IzRHMXbJmXiO+4y6DE5b1t99wBUt3C5K5H91D
|
||||||
sY9FipGcyiNHfkp8KsWeUxD/j1QUIkGODXt2RqYkO8ltA5QS3kUCPErmWYymEAEu
|
U3blcYO6GROPSkVp8ZIzfnWLvyVoWInd1ZiRs19n9MN6Yf8uWfx9/3xvN2kKQyvj
|
||||||
=RFaD
|
=4X+A
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: B71138A6A8964A3C3B8899857B4F70C356765BAB
|
fp: B71138A6A8964A3C3B8899857B4F70C356765BAB
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hF4DzAGzViGx4qcSAQdAoNdta1fDVjzrPWeSfKrmslkoFi86I2nWplPOli/gFXsw
|
hF4DzAGzViGx4qcSAQdA/+jZ9/0jHioWKE2TK24OFDKjJ8futm2TP8z6Xat3uxww
|
||||||
2Cx+wmejLlc61RE5sqAaQJc+0ctRezwXzBJbkuqznZ2jWPCK2A1EQ7r3Q7USCCca
|
DGwSznxagIkVgdTNKqAWmzGvOum8xDBqzP232CM8B/oxmwIjuIV8+FXtJuFHA/4b
|
||||||
0lgB6XOo0ByOj/W4TrrGn7VmwLvEqIiWCt5zk4BEUSVc62Ffv48dcwL3hsB3HlRw
|
0lgBN9loSuX5uL5O4uWzPulEhqjFElrWRZXLHZn7uIWipW/7mP8CGu02wwV/lme5
|
||||||
6FXyR+2zwyEU5fuddFO4nMi8AXB6cfU6F4ugFgwn92lCgTom7IULY1D7
|
jvtJ6EjgopmHrxyaJqRk+e65gxBYKvxTQ1H1iETCUq8lOnxSBZVY5m5K
|
||||||
=Czq/
|
=7H6g
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: D2E9C0807BF681F5E164DAFC5EE1B61CD90954CD
|
fp: D2E9C0807BF681F5E164DAFC5EE1B61CD90954CD
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hQIMA2pVdGTIrZI+AQ/7B7h5br3PMgum71smOTJMBfl4OaxkQAirJeG/z2fjqbAG
|
hQIMA2pVdGTIrZI+AQ//aZjaPgcAM6RSG6QCnYJgn8EDEhG7HDvXmb58G7VfxArr
|
||||||
l9q62H1cutGKS/IYOFLE0OQaRwmHtkdTkrdmf9yIuAktcdAGAeqwnYW3LwM3t7U1
|
m+K4Hc3hW0Hh/c7/bzu2QWniN1ie4apqFSvQmAIJ3zQZSyOsqhzvbmyTFRAyzpzO
|
||||||
nfZRJH5Hi4xcSVVaWHn5mX0QpxzrCye1EIjHvPRx6/bWHD5sW9qnkZAlAvEJS3/K
|
lOAo/s0xMu8s5V055vC2KWnKuqb9+WtWgJPotkpOf7wQM3aqtvXKFnPa74ihjXdt
|
||||||
jdyBLLlK8AITpsX4eeVnmVLZBjbVEXPlXfFCh9PFyqrl+iyBBY9bO2aMzWldbQIr
|
uuopRsOsZPiG8MLcqkCrTy+pd1PywrqwjKeva+mfgbM8zpypw4kwLwrljsxCThkZ
|
||||||
j1551Xe1wKAOn5SJTg2Mrm5ehBKfH53HY6ubCy9acbv5ZTe6JuStseWordtRNNXY
|
To4dH+K8oesvSeyVOKWtAwnjQsPa3Zn5CFWXNwPnn2kpjyMoNRo07xuRkfHYI4L/
|
||||||
9eVmR3MRVoFWgK4Ccb9Qq8l+uEHRuQfG9K7dSnxQIJpHCOAQO9oi3/ykDt9Vgvo6
|
7D8zz07XdN47kJbEj2BYjChURtbxkFbAxq+IUDgbNDW+M7VQCKZW+vOFjwmFJAlT
|
||||||
WKPpvyuJpWc5Tn+WF1qhz5wDTRX6XY+cUoHkUqZXG0qMTIfMLIAFZ6MuslHU9f6J
|
CCco2I3lmrVX1j9BTMRr/3aQNbY/OzOxk0qjYZGnPqV1bH4IazaDFUB8pOdmit2t
|
||||||
PlY0FTnwp5/v9rK/rjXZkfIxKjQtSWZwkZCszZ0WtNVuaY3KO6KYrd9rolFFYjqn
|
KBzDt1L26V0Ek1CpOp1dcJxneITXX1j5IqjMbl0TzyoJ9CxsSaOWfZ6XsBBSXZNZ
|
||||||
I2xFGnTNZwh3tjG/3INoMwilOkIUNXr18k6FsPqVCAhj1Oo0iNxb3j+3pGJsH9iN
|
VnDENbBAOGcJgatjmC2qH5FCNio7vMRRncX5j82sytDRWbj/7XHENFpfXyGPIuYg
|
||||||
ciTLeM8MsFW9MYXG23i65a5WVXi8hMTcyqCy9GyxLeFprt2DaH2HaBahF3RIWPop
|
AaHyxSVegFCeRUHpzXo+qeFpNFR4407v+otVaEdxbfj6MQfMZ7tDUOde+97NNRow
|
||||||
KTNsvW1aawy+lDUyr4mBy9F0TA8Z1/db3l950Gtuz5s9/7D6bbmRn72O++W1RD3S
|
tAMUOAN9yhGuEPMPr4stQUz4lHseGMX3VdpJH8UQH+BxVdJhzKg0H/+6bAmnRi/U
|
||||||
XgE3QuksqaIh7ZGt8tVPREEHpBWmPCskh35vLoqeO1QxGxzJcjrcuNeHtOH44EEj
|
aAEJAhAi7DZdrKpPPkDijPKnXCPJB+IzdAJdOCsnIhZFzaiDUo+RLvP9bEpoqv4m
|
||||||
mHzYUydn0e1jwKZkATG23DiBCyMpcNAWmsMH45wmk0fgNLdQhuslhKLqOUDLpN0=
|
ZFMtiF7P7bXyeNIObCCsgKhdX0thXI9lZvv7k9M4lAbFhPS9vlmDwf25t2Nm9Um8
|
||||||
=Ygd+
|
2tbINg+K23jp
|
||||||
|
=syE6
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 878FEA3CB6A6F6E7CD80ECBE28506E3585F9F533
|
fp: 878FEA3CB6A6F6E7CD80ECBE28506E3585F9F533
|
||||||
- created_at: "2026-05-20T02:08:49Z"
|
- created_at: "2026-05-25T17:17:13Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
-----BEGIN PGP MESSAGE-----
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
hF4DKKbvh61jX5USAQdA8qtjYHoUe+GUdy3obbF+pNmvfuKQUqkMHa6V5ZXOpXAw
|
hF4DKKbvh61jX5USAQdAHw+hxKofus/fR32ThZOHfkL+8TIPvWeYnTYe5UUCC1ww
|
||||||
M/kx52Vu5xOdynB3NMBXsfTVH7KXh0f06HcehTREOkhlwVMYPcvDQQdzgJ3Xodpc
|
AtCE+MfZvMgRx7gUpVPcdWtch6nlFzun+r84QfPopFk4S824JFEkK8jG0scYCpy3
|
||||||
0l4BdYtmbmk9ETTqr+wXvf+6BMYIuvyhsLLSqyWyCxJv7blQYsxsc3EAHZ4LB0ZS
|
1GgBCQIQm+g/LWX0T3Do0NXrRGIuw0fiKrQiOpEhbO6a6ez/pES0zKKBdlH+scQl
|
||||||
/lw6gQ5lmQyvVt9PQZayt6Iku0+WMJcgrf9xykOAm3N2QrtUnr4jHV3FydvTiUwR
|
+nLZoz6Mw5mkwhY6zIKsrikuQ/+sciO2fIq9tI4MR6cvD5gmVrGEjIyOZ4xgl3X9
|
||||||
=snV0
|
nX6OVR9w8cR7rA==
|
||||||
|
=voeW
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
|
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
|
||||||
unencrypted_suffix: _unencrypted
|
unencrypted_suffix: _unencrypted
|
||||||
|
|
|
||||||
|
|
@ -40,7 +40,7 @@ alloy_config_default: |
|
||||||
source_labels = ["instance"]
|
source_labels = ["instance"]
|
||||||
target_label = "instance"
|
target_label = "instance"
|
||||||
regex = "([^:]+)"
|
regex = "([^:]+)"
|
||||||
replacement = "${1}.z9.ccchh.net"
|
replacement = "${1}.ccchh.net"
|
||||||
action = "replace"
|
action = "replace"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,11 +1,9 @@
|
||||||
ansible_pull__age_private_key: ENC[AES256_GCM,data:VEGxr8C7RlEhyQhf+to/OrbfPPKkyL7iUU1yDXGAzmmPCQ4VftK71eiyN7OS6pG8J89Mj4Sy/dcY4SUX+rTl/q1csZMn9t4NBN8=,iv:JcrdyFLX5srZfRj9SA+RXf+CRZi5GEcApgyYsHoHTGE=,tag:xdJ4GmK3afZDkXmkrriStg==,type:str]
|
ansible_pull__age_private_key: ENC[AES256_GCM,data:VEGxr8C7RlEhyQhf+to/OrbfPPKkyL7iUU1yDXGAzmmPCQ4VftK71eiyN7OS6pG8J89Mj4Sy/dcY4SUX+rTl/q1csZMn9t4NBN8=,iv:JcrdyFLX5srZfRj9SA+RXf+CRZi5GEcApgyYsHoHTGE=,tag:xdJ4GmK3afZDkXmkrriStg==,type:str]
|
||||||
secret__acme_dns_api_key_light_ccchh_net: ENC[AES256_GCM,data:SLUNVJQ4Nkos+tYH0l9ndJI8mrfZFC9i/qQqkcHgfLaNjL1tFuAFfQ==,iv:cc7DsiqzMlc2lh3D63cElMQcOeYT7oNxmRy7irSr9/s=,tag:dBnTAJXvgWlmq5vVGxrykw==,type:str]
|
secret__acme_dns_api_key_light_ccchh_net: ENC[AES256_GCM,data:SLUNVJQ4Nkos+tYH0l9ndJI8mrfZFC9i/qQqkcHgfLaNjL1tFuAFfQ==,iv:cc7DsiqzMlc2lh3D63cElMQcOeYT7oNxmRy7irSr9/s=,tag:dBnTAJXvgWlmq5vVGxrykw==,type:str]
|
||||||
secret__acme_dns_api_key_light_z9_ccchh_net: ENC[AES256_GCM,data:m6+Sk533qTRfhrwv7U2RydJh/j7KjJKHiEetyzgvJV1dgWXmE5AhYA==,iv:lAGv4vfxA+DQfwaHiDp3NMel0tjmZl96nKUAN8QGFe4=,tag:h0wM/F9E4dIy+NYLIVUpxg==,type:str]
|
|
||||||
secret__acme_dns_api_key_light_werkstatt_ccchh_net: ENC[AES256_GCM,data:zJ9hQo1jmQ5+d0oU+CD+cQh89HshPpguZCak7Nfjdb2bygUXJrEIIw==,iv:y+FSB/k5LixKJOm9egWsjhByQAdv7TfJHvv3job2oYg=,tag:CmuUqnCI3V/aOOUitzYT9Q==,type:str]
|
secret__acme_dns_api_key_light_werkstatt_ccchh_net: ENC[AES256_GCM,data:zJ9hQo1jmQ5+d0oU+CD+cQh89HshPpguZCak7Nfjdb2bygUXJrEIIw==,iv:y+FSB/k5LixKJOm9egWsjhByQAdv7TfJHvv3job2oYg=,tag:CmuUqnCI3V/aOOUitzYT9Q==,type:str]
|
||||||
sops:
|
sops:
|
||||||
age:
|
age:
|
||||||
- recipient: age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
- enc: |
|
||||||
enc: |
|
|
||||||
-----BEGIN AGE ENCRYPTED FILE-----
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBSNzBtc3lkZHlqeTFIa2RX
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBSNzBtc3lkZHlqeTFIa2RX
|
||||||
ZWgyV0lZQ0wxRm4vZ0Q3Y1d4RTlhYzk0ZUdzCkQ5VjdlSldCc0ZqZlBIOTMrclV6
|
ZWgyV0lZQ0wxRm4vZ0Q3Y1d4RTlhYzk0ZUdzCkQ5VjdlSldCc0ZqZlBIOTMrclV6
|
||||||
|
|
@ -13,8 +11,9 @@ sops:
|
||||||
azNiRDFuU2V4V25iV3dORW42UGZPRmsKOsa+36+NKjmS8xMAoCueJdhIIUtdhl15
|
azNiRDFuU2V4V25iV3dORW42UGZPRmsKOsa+36+NKjmS8xMAoCueJdhIIUtdhl15
|
||||||
3grlxNwv4axlKNy1ynSSmneyAZ6g+OF80b4YNxzZYcfnECB1VnDENA==
|
3grlxNwv4axlKNy1ynSSmneyAZ6g+OF80b4YNxzZYcfnECB1VnDENA==
|
||||||
-----END AGE ENCRYPTED FILE-----
|
-----END AGE ENCRYPTED FILE-----
|
||||||
lastmodified: "2026-04-11T01:24:10Z"
|
recipient: age1llkxtfx4dgnezmukj4ganx4ql9k4ga4ca9zuanf5r568jfp8peeqal490q
|
||||||
mac: ENC[AES256_GCM,data:D7qAgDZX8B0oNdZovHE74sSZI5X3qd8oDPHWl13Q2ohLnp9vJsFxrKntXxeeHASzQceDv2RQ1exwq7ZPor62sLFx+xO1Dc0Awpq1eoclDlHPyKlvT3pgkcB8IxDO/FuO+7hg/bJkmTHhbHTiHLGQDWN2sQev309Eka86lQyCzIQ=,iv:OBCobeUp+GwdDQhrNtTJhiRVMxRJafq5g1rhMoEFhjc=,tag:OSAWMn2NPZnVKcRX+eJf+Q==,type:str]
|
lastmodified: "2026-05-26T09:09:21Z"
|
||||||
|
mac: ENC[AES256_GCM,data:NGVGI70dGuJS4qMfpy3tE9MTvX9O8Rwt+Nv+gdqLUkleMEe8sWKbAgfFyWIYxroo7AXFEl3jIFQ7pmcvnSTUBprR7mL3//3QcXQXthxW/mVCf4DRtr7fcqAtctTrC2iRZnZ1YrOz/sSO7G0bgmcx43tYDZPZ+udNKO2pvZvclCE=,iv:xvDS6QVfOPcLk0C12YES2CVKCs6pWl7xPReWtgCyMIw=,tag:pXfFkbWWQpMlwE6g6nO2hQ==,type:str]
|
||||||
pgp:
|
pgp:
|
||||||
- created_at: "2026-05-20T02:08:48Z"
|
- created_at: "2026-05-20T02:08:48Z"
|
||||||
enc: |-
|
enc: |-
|
||||||
|
|
@ -187,4 +186,4 @@ sops:
|
||||||
-----END PGP MESSAGE-----
|
-----END PGP MESSAGE-----
|
||||||
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
|
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
|
||||||
unencrypted_suffix: _unencrypted
|
unencrypted_suffix: _unencrypted
|
||||||
version: 3.12.2
|
version: 3.13.1
|
||||||
|
|
|
||||||
|
|
@ -67,12 +67,6 @@ certbot__certs:
|
||||||
subdomain: "e59f55ee-9013-469d-a146-a159721b6fea"
|
subdomain: "e59f55ee-9013-469d-a146-a159721b6fea"
|
||||||
apiUser: "33e96ec7-1f98-4f70-92be-85a42dabd211"
|
apiUser: "33e96ec7-1f98-4f70-92be-85a42dabd211"
|
||||||
apiKey: "{{ secret__acme_dns_api_key_light_ccchh_net }}"
|
apiKey: "{{ secret__acme_dns_api_key_light_ccchh_net }}"
|
||||||
- commonName: "light.z9.ccchh.net"
|
|
||||||
challengeType: "dns-01-acme-dns"
|
|
||||||
dns_01_acme_dns:
|
|
||||||
subdomain: "3bc9e7ce-03dd-4533-a059-b5d38407eaa5"
|
|
||||||
apiUser: "c3b00882-ca2a-4d11-9ebd-fccfb8618b75"
|
|
||||||
apiKey: "{{ secret__acme_dns_api_key_light_z9_ccchh_net }}"
|
|
||||||
- commonName: "light-werkstatt.ccchh.net"
|
- commonName: "light-werkstatt.ccchh.net"
|
||||||
challengeType: "dns-01-acme-dns"
|
challengeType: "dns-01-acme-dns"
|
||||||
dns_01_acme_dns:
|
dns_01_acme_dns:
|
||||||
|
|
|
||||||
218
inventories/z9/host_vars/z9-router.sops.yaml
Normal file
|
|
@ -0,0 +1,218 @@
|
||||||
|
ansible_pull__age_private_key: ENC[AES256_GCM,data:TlMDo9sUTYznxKOGityGLexk54mM7LU9+U4ln0YYhO5fhXXmwvySxyMLHlaKzSlpU2/mRRy/0v7AIOuRVZx5XqV8X2JJsv3/NeY=,iv:r66g2UQ663KvWyAISitbHBRaLBlJ0gB2g/TW9JiL0Ls=,tag:VEq3Fqj+t40uBo9g4Icfew==,type:str]
|
||||||
|
secrets__secrets:
|
||||||
|
- name: ENC[AES256_GCM,data:gt9BarzsfE/GJ5gQeelgePquW6KAgE3Exv4=,iv:IPpUQI+zkf8O+ej+ZxLFyWUOrxGGlZvmDRG0ut2cNsA=,tag:GP66MvcKyCqyKV814+uMYg==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:2ljp324rAsF2zk2631TI7bV1xKxdFr4u4NxrsPYnjWsL0PX0n0KhJ1qvJCs=,iv:0+DxsTTiNLOg5iH83bFT/d+0uW2rn6bATSm3xc5PEdE=,tag:XbBDrrjriXPedyT4+sBBwA==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:SnVl,iv:GgdWFZ1tMFaUacisA47oJBXDgG11uHfw8tBYcPQt844=,tag:pHtSdg+9qPmm+Vm5gTanpg==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:9i4hZU7Hv/IMlI/1oYthx8g57nrst9LHZQk=,iv:IQanD/CA64A+hVyTQBiTvWdXyY8qNF9BpehWZxI5a9c=,tag:RiY0OJe2xbFPG6wfe5XjiA==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:68GUwG1Q2s2jH92HS0FQWrcMHJP8fHjrOqr21gsdswxKekQrpxX5B3BBFfM=,iv:HOsNUAKE5rOmKgZft2JK1NnZUuhk261d9WYWJS22nLM=,tag:3husFvB57AGVFzF7hKzLpw==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:9zAa,iv:Cb4tNsiPKWrkdIHHSGvK10FwGeInPetReVnW0JUTEHw=,tag:THD3QfnWb5fLXluVRFzuag==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:2lJUcDJ7ECJ1bF4Fg1VwOR2tBIQ77ZvDAbFF8w==,iv:HrPWIetjN/lOyQ7Mvk0sM1w+bWldlNfWhvw7/sfqKN8=,tag:AJL0s+f0O/yR4G3RVd1IHQ==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:68GUwG1Q2s2jH92HS0FQWrcMHJP8fHjrOqr21gsdswxKekQrpxX5B3BBFfM=,iv:HOsNUAKE5rOmKgZft2JK1NnZUuhk261d9WYWJS22nLM=,tag:3husFvB57AGVFzF7hKzLpw==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:Pv0/,iv:Gh6X7H+DkIO64lpcDrsH5nmWwRZRU9avs40HG1eiFcA=,tag:oGMD/kqgd0pl+BeQO7LqQw==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:ESxpEp9k9BdD1GJv+af+U3ny0+RPuaJjWDhQ,iv:DxsZLiDF8F+ixepbUdlitMJ7DLHjGNFNuxRwLl7efo8=,tag:STnv/oLzbchdiwXfKP3fow==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:W2h5AcoT85OkekPeRkrf1m0bDdBjG/YNSbWlrcZtP7FjaPh/F+cx+J6oRRI=,iv:CLVXTqfstpIU3BX/Zdcnp9w0gWxeGDI/G1MNl6xr4ZU=,tag:yCqN4r1MV/VTWQvZ6COfIw==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:m3q2,iv:BKsE9OL4FMZpDS9zS+TiNvjR5jQ7EAsw9ER73Q9oSEE=,tag:r31ZCaMO4S2Pmk+FdDsdQA==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:IRwwy+WQxgQ8cDpB8HaCLpKwJj7oC87p0XOxWRo=,iv:BLXNMcigvaOeY6y4NlLPMMWQt9XFi6nodRwIYFgAAnU=,tag:OdQalmujOgrzW8oi64xMRg==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:C5oIcuEYtODsvjQZnbqbWVfP63mQzcRuh8f5rlBCyjwSq2mZiYGQe9t0T78=,iv:sITUDo9SKZTSwPfsMv4m4U0ruuVCcaxu7SUT52U4FSE=,tag:4CsSMJWQQPAIeK8DwUDBqg==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:UEeH,iv:P/maaKER4lCW9/oASsJH+QBy5U1uHythvefRRnlXjn0=,tag:aXSow6dtU7VeGEtQQacHIw==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:r0sbpjaGjezoNlyl1khy+Dly+8xbbfQZNB8om/E4/tj9lmM=,iv:MLrglBJA6BrHGmFRprlQcf5/Hqh952e5OyQQ9nPxumY=,tag:Se05kMBkSQ7TRxzij7Fo8A==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:/c1nRf1eZhbUmoQWvcj8yDaVPtyAN7Uu+S054q3C1/kXlQ7CgOe4CrMXnmk=,iv:ppar0aCKuIU3DOjwAoliZ5TOL199Z+Ffo4pCktjs0W8=,tag:nfaGutK+5KnlWBKU1MTxkQ==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:P/P+,iv:B0WlRVgZEgSQRsiRfi5o2+lXkFIZ8Oy5uemtwU06zPw=,tag:D5fs5HF1pKckRNVm+6r/pg==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:7mwuykEqbGISOa2n+pWb6INLsHYdjyf2HxTtWpAr5xP1,iv:NMcg+L2DFtBO1nhyPid31yzLr+ZX7DUGl/WxV1MnrqU=,tag:65/BiUEI8v5oMlQqpKNDRg==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:SObbA3D/sGN5/i5ps4Zz3alygIXKbSgptFjfPHlwC8G588O+gKAkvKQwU/s=,iv:PY2vLfI3gInFeQbse49KC2/zZ9O4jeXAQ0fpP84GHHE=,tag:214Mb8hIYDkQ4+UkRWtc9w==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:ysBR,iv:ewZ73lNcdx5KQTM/HQRhptSqAqKgZzAhIubrqDp0ueg=,tag:RqcrNGQwkLufo2bdn1WJXQ==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:bES9O6JI4wTnuZsup9gflfaozeUDkfjVGNIFn8RnZQ==,iv:98kigM3KZIN5qXNdgfLg5WLmxzAsYCjNqVzyUPco/BI=,tag:1fwEtwQ6i9QQC3OCewN0eA==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:flO3Nb4u2WfWNVhn8k5Bgo3LmsHo2cVnLCsrz8ST9Ip7gO9FY9d27FQgphM=,iv:aiDoq+41cSjwcCZRaIPLtbltkOpc7FeuNN7swPqkHXQ=,tag:OhzcY2xKKJF2jZVRseXCFg==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:YGOs,iv:QjGXlX90R7zqIeUQGIblD6aYtzqpGxc6hW0nT+2q84c=,tag:7kRcKtQTp9teaP+Yw1x4MA==,type:int]
|
||||||
|
- name: ENC[AES256_GCM,data:ERsggezMBbs1YwbIgwzKSAEHWWOWYxap8IDdn2YtEKvZexqu,iv:XbObLp2QERgt57tc/Cpha1CWXi+GttcIU8hJFGSp8e8=,tag:FqCuSbvLRERpVnQTzQsfpQ==,type:str]
|
||||||
|
content: ENC[AES256_GCM,data:QPoZA71CwE8EFE0I+6z0z0O1bUCMQDDDG7wGNoxXKt3ovLkFt21r8WG7VhA=,iv:InX6A71f3DGTg1wO4G0ECf488+FnKgTHffVwvJ9hHQ0=,tag:EVxwJlneN1CbMLXto7uLFw==,type:str]
|
||||||
|
group: ENC[AES256_GCM,data:2P64,iv:mOdlGn9zSb/Z97R6FBAJSZhk/g4hVOBwCI4/j3BwhPQ=,tag:OcvhT6QVfJvAYYBQyHPykg==,type:int]
|
||||||
|
sops:
|
||||||
|
age:
|
||||||
|
- enc: |
|
||||||
|
-----BEGIN AGE ENCRYPTED FILE-----
|
||||||
|
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAxallVTFdueHBucXBVNzIx
|
||||||
|
cENqanlOOUticExzVnlERS90b2hWQ2VldUE4Cm9SVmhZejVzanRDTkJhQzhwM3BM
|
||||||
|
MGcwTEZ4YVQvdjc3clBHei93VEN5SkkKLS0tIGI3KzRPbjlNTFFBL2huYlZSVTZh
|
||||||
|
OVdXYVRkVVJwbVltSHBXRktIY3BYL2sKe+eqKzYeCUWx0KmT0+aM+TwWRj+P0Ecp
|
||||||
|
tnFHmQgnEPypIhVvZtzL7i64kL6sHizTmNhbw+hlnCztvsdEV5T0cw==
|
||||||
|
-----END AGE ENCRYPTED FILE-----
|
||||||
|
recipient: age1tx03yh67f052jzehvtvzmhe5ja6ca0rlugw8pr9v7q67z38w2ahs2a4alp
|
||||||
|
lastmodified: "2026-08-07T21:01:32Z"
|
||||||
|
mac: ENC[AES256_GCM,data:pVSBNwQVHta0vrUi9ZIo/+FLHZaeS+/R/xtNCvC+/NlEaksqcP7jQ8/Dk4DZAlPVtdupkKco0YqfTomccrp59BcAL9DAw1HpHJOeLhBdgB99fcWAkbGnzNIRS0/bOco+sDQUXGxg2HlQpFuwMFYQIfHFyqD0ivNSwLSHflrSwAM=,iv:7U9X87wd6/3SDun+BLgILH9XHJJY+GAlJd6kRSBfRGQ=,tag:wk/Hb1nw8MmLE5B08AC3jA==,type:str]
|
||||||
|
pgp:
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMAxK/JaB2/SdtARAAlyJLMDlT4FLpMKaC3ygn1cfA2390Dz24lzKlHmwl5GgE
|
||||||
|
yS9bdTGMpcM8zPOQoqaoy/my3kgx2/U3q7WiCTMdUyYePAWuJFh8ZRZjw/hPpv6n
|
||||||
|
GwYgK3M2C1I9++zmZD5LlR4TaTTpr99+hctYrrp79QJddgozUzAQ44g7WvDm5VhI
|
||||||
|
bb2UVSo0MpWvLEMXHqH9YZcjkQyVg/DL+IaU1rM9pmpZxoN7+0jQY4ci1ZeHVo9e
|
||||||
|
DbYcjMazBLakjZxxdtHrqx3DjZgbYCancMy/dUKVuvDF/lN35WWSxslv14BNHljL
|
||||||
|
+/9YBDRgIr11x9j1hq241UwBW+6mSFxWF3qQ5esdR5xlLEqbm27PYGtqC4LIdzRX
|
||||||
|
ZUvdujuQ2PHCYJY/jKWSf0cdfXKEGorc1ZGOV9FNq9L+aKvfmRLWfzX4D0Hp47H2
|
||||||
|
d3itVuA9KYOdzmk6O+8FZv/VK1042L90tOPJhrtE287KhcJ2CvfT/Az4Qot8xg3c
|
||||||
|
tXmO3cWQpigXxJPfKRPjmmLJ9nq0BnBXj5ngkVz7d8R3FR1J/+TWG0F1VU7YeW2+
|
||||||
|
Z04RAbbKf36xUTqnaV34EDum4QLLdTMra6fPYPy0KiQYIKDcRSdHeM/hEs7JXP1c
|
||||||
|
zbUX4xuBOXl7kWYR0e3MUTzxYiQBr9BvSDY+7sGQCb+fPw+AKvFxig1grjsnZvPU
|
||||||
|
ZgEJAhAUE/ebqBa2nGimcAPn3PfeihehcmjLg7HmyWBPkHHMt/TIOztjkbGiQSC/
|
||||||
|
jBP+rhjmFxm0WKUGM4dkh14JkMgz7DZ9fozzLfo8zN8beuSDDzX1BndTIMBQJj8P
|
||||||
|
Q/rk1NL6pg==
|
||||||
|
=UXJ9
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: EF643F59E008414882232C78FFA8331EEB7D6B70
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQEMA1QflAioE8i3AQgAg+PBxAqWTfRhxP7GxDfQBPK3d52zshP9xhutqANzszhs
|
||||||
|
nbo3nHWj/vjvHlEuD+Rr/lr9qxsE3qS4ON7FG929RoB1YFHJnQl29Xym2Q34T0Hy
|
||||||
|
Ih3dibykm0t/NE+fuxsU4iU0imtjqhqA6P0+8FNF3UeCg60brcqlrBTXM9jFqlZ2
|
||||||
|
9nuvk75HkM1FoHiKx837qAd+RjNNO7xKUpn+EX0l0l9tScuPqUkWNQxLrbHrcO5M
|
||||||
|
bcEC1syZHQKCiucsesS1pJ7TFWOJsnamZyaqhzANGwWdhYwGQv37bWKr6dYTCy3q
|
||||||
|
rsT2NxQK4/N9CxmP6xWeAZbX00BDhNMfEQVtTlYLgdJcAS433Hiw+DSEwGu2zvTa
|
||||||
|
pHtQlGlaoOZemNnthw0NO6JQWGhz6Bx5QqYmbrshtVKNPh87vNVV0HhL/fQ7qwLp
|
||||||
|
uCgnMi3P59r8EKDZqTSp0YGfE2bx2hpBDnyJ42A=
|
||||||
|
=rOz4
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 21C9579E6503CA815A68ABD8541F9408A813C8B7
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMAz5uSgHG2iMJAQ/7BOewbq1xQgTOruTFebugbSrodtfUlIDpCez+FZMw3Gos
|
||||||
|
uwfp6jslBKXHidsA39CRktJ40EYqygmBgcxGTvHGC94VwSl7OfCjHsyfD/93L358
|
||||||
|
XsjpTHXBO/mOjQmJ2smhZx+q+iMLpJnq2QA8mGUI5uzPTjXD19sD9QdYdHF2p8D6
|
||||||
|
mdpVWED2gRf/sDoN+y3c/iZvMTN2HeDCx5d/wIgl3mmoHLvWRO8pNBV3EUg3ZBiv
|
||||||
|
fc0Y7m/0KOqW1itE4yg9IoPBWJg2jYSZTkRnQMPEkKEEHNtbx6dq5tLOYUIIwOwC
|
||||||
|
5JlL76BRoaul6ousBSHV8OWCAvS2N8OC+l0ATzk99p/h4zY7PCG7NhkKAOgYfWFa
|
||||||
|
/z5u6J6TMrmeLZjknFXepuVAzNmDU0CmuhMwZankGKq6lmsQQnHvdq8+ExGGWhfK
|
||||||
|
m6I8nPvG654md9H7Y3HusHa6y1rkf9gZp1UFzhvXQgZdvc7K5pJrhxjGUnEg6sS0
|
||||||
|
m4daDRuNLW32PXiwoWTtTJfOQFv0t1f1eEKI9DO/O8/4fNtIvmI/8HDcdF1XzDnt
|
||||||
|
lGnyD9cZ5jKsKjGrT9DcvJhyTGWDFeBDTY+rlt52E8NbrzWUjX4J7Gyz8QRY9j7m
|
||||||
|
wRi4uaVt5KBmB8Ibo2bMTUXU3Db/0p8nCAg/89D1fP6FF4izg3GU4oD3vJyl81XS
|
||||||
|
XAH8tGT9wbjXuhomyhqemDYb0QdTRfpAznm4AS36qbeU/Tvj4M+Nm64qLpj7FFtK
|
||||||
|
aeDas4lzgeQf6/cdd5ItLlRHhlBOJEmjHVzRR4npabCWZojP8PTac1IlBgvS
|
||||||
|
=OH/y
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 18DFCE01456DAB52EA38A6584EDC64F35FA1D6A5
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hF4DsZXvxFXTXoQSAQdAIjnFVslIKlmP0X12z6AdWNqxkpVBDFvf03ToWQEQv3Uw
|
||||||
|
8ka0OYl32rH6UiiSE1Vve1wZ/iVvK9/il6UhTpeAt8bIiCq6gEGR9Ba5NJnm6rSG
|
||||||
|
0lwBwzEtaARPJbbcWu7Jl+dAQ0quP6uVS55OYBuSannlaPrQ5qBuS14AtuQ3UEVz
|
||||||
|
EbcLJ0b4lGL7hgyAf2E6nuDTkPGPChAJ5H5DfrB74ZB30GcYBTzwj13+jWx/VQ==
|
||||||
|
=Hxuh
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 9633412309CCB83BFA39BA5F2FEF746201D7FCFE
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hF4DerEtaFuTeewSAQdANsYlCeGhhqmBgnqcSuNdQBUwYKpucDrb6aR9Siyukjww
|
||||||
|
72Gin/635k9bYXwknA1rPyTMvG00giQgjUr/QK6PSD/eGi0QOtMZLj1JRi8f5EU+
|
||||||
|
0lwB+MIM9+EEzHJ96ouzL3bu0e++NvRY1Qjyx1Xi43bM96eBeLZ5DAc1eTSdWizQ
|
||||||
|
EWTorcmXffkdfOQx1zrlGZo/qvfj5F706VcwX4aZwok/ASRmSeCfEXLgGLCwqQ==
|
||||||
|
=ccBm
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 057870A2C72CD82566A3EC983695F4FCBCAE4912
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMAxjNhCKPP69fAQ/+IRYUQhf7zzIZy3AKAtQgyMKRINOUUqOEv6IKmNQaaQP7
|
||||||
|
K5JXnVi2gjgBuG+2gH9iCEimIggnWxFhHerfOps+NkAI6y7kFz5hnMtOY2Qf3vxT
|
||||||
|
Hoyq4l6Yn+gG1HSLozVr9dTQPjyGOKJkm36ZKpM7gqSuLNP2ijKARzay4Chg3i+p
|
||||||
|
E1TVTVoEczrPdLg3O2fd5mi2UT1k3E4QREti0k6K4juMWqMz+5iJ5X98qCdmE1eX
|
||||||
|
L5dmW0QSUChzBVw+7NEcxeNx5WsbhWgPA5m2+bng3V8tHqAwrRUCoxn2+yabnsZB
|
||||||
|
Z0Z7TgcLk0Xnezw+BkT3bOsKgv+atE5lm2rBiRUHRDR3S04j0Ju6fJHf24CNy5ES
|
||||||
|
xMF7BE23SgmqUq0BrvdJB0ToNKYGMM0C5Xg4vGRiE61+18TiFIeC3mF9suvFFKc+
|
||||||
|
houq6Cy7q3O5PEqEbu6t5vXAZHwL9Th+ZatIIe9jSToiZiLEOIEmiYptR009/OWq
|
||||||
|
v6ADzaAE6+i6HZ62xBYQuZFkiUrRKxYzTHFn0A10QUJrJgbWr8QjS76oKi8feEDC
|
||||||
|
BJAOwE/0aK+l46hI6mlh6rgeSy8XdOPLEnL4+1HjlshhTTiW1rE2cr0ZiTTA6UFX
|
||||||
|
UhABIUi6jiLnM13L+auulU1UZQ8wxp73okrcuu6g2bPT/l7zO9YNOCocWVPQa5vS
|
||||||
|
XAH7qrW533ttg2XAczCdALMulV2N5GHl7TbgRQBkdoBAKL+6oKfxbOZeQM2nrfZT
|
||||||
|
arytZbnjgCcy5ygnjeziRvWwLk7sysEpAQqQNRm50m2Cq+2ccedRP6zFzUhc
|
||||||
|
=4hCA
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: F38C9D4228FC6F674E322D9C3326D914EB9B8F55
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA46L6MuPqfJqAQ/9G5pRNmw775xCYA+foCx9rM7eLXJFl2DjaI3a/O0yVc6t
|
||||||
|
32xtPuaHwTnP00Pbbo5Vc9QG7k0Fr3Rgy+ep1lGzeCMoHwF9xk98LspDtYZoKopE
|
||||||
|
6/L6KLldSauRv0rPVhCQHpZFsnx1VxaJiXn9vAW17+imC9SgqLYGWyrxAtLCOOqH
|
||||||
|
N68RnTsEDquXixEs82ao0EmQXPquimJgSx+xVSF4yitYYLLLHyUL+drMNuVb9q9Y
|
||||||
|
oAIdEL1svDIieTbTKGQUqZ8Alf8f/0cqPWpEkDwYIyB/i9KDkH5Oj7uBBRtVLGxQ
|
||||||
|
VxE32wO1xpXvKgUY2PhWD2rOBVDG8dW/hyqvc1WgIeo1A6FTq34b5dGC2lmTRngB
|
||||||
|
9mBjUd59zeOvdXLmoGwXgbjVhpgnm/5wlUeiIC3xR9MjW3znRBT6ujCaglpAdXBC
|
||||||
|
0AIugssGcuXbP9Tj5zMVlbdi2dj6Ylc8S1Tj/OjwxHCCj6AWRqpxN5vY28RiLFGy
|
||||||
|
+eAsryzPk6UTCPIydiWwsrP+w8EhbllFxzZM+Sn+fshAHdRug+EeyT3h5V5JF+Ko
|
||||||
|
BZCrZkwYqAcVkJjEYlukjvxVFvo+T6tRMz4F4yNgjqFjneUaeLCc6RllaT696H0Y
|
||||||
|
8+lw5rK+XpcXBZqso6vsLChRdZQJjoj9lkjRDbmhOkaRglikC6Cx+mpY1/XnGvDS
|
||||||
|
XAFWOuNKjN/xIRtaDc6tmeWsKkuqghjHiMeRqw10/kTBjniMLLJIN9ssj4HjYqC3
|
||||||
|
CsqyHqZmrbITUMr718gX1kkAvzF/fVAXT8YshOcK7rQbiMQJCZqeBp3fY7FC
|
||||||
|
=5yPR
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 8996B62CBD159DCADD3B6DC08BB33A8ABCF7BC4A
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hF4DQrf1tCqiJxoSAQdAfLqKILCrCv2s2V7bLntk5lHI6Dc1FQlCg3LAefc8oTIw
|
||||||
|
a3UZU3OajQ1CCIhhu02JSlTKZm2z+pZKVHy+s5EgCqwAWTfPNAnyPT0ZGrhIdcah
|
||||||
|
0lwBdg2Tq3+Nhix1ZuA/mUgcrbRBcFKlHY+IGEgOHKLJld9UPF2xEjTX6nmLyuTR
|
||||||
|
6x+HW/7vVuc/jcFeQEmokhQw/SICVdyD7NQua4k1agLkty3hGcm1XCsfyKfj+w==
|
||||||
|
=Bxf9
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: B71138A6A8964A3C3B8899857B4F70C356765BAB
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hF4DzAGzViGx4qcSAQdAr2tfPiCpUkxFj4rgSiLf7y4iyKbsgEY87iYH3GAZTVcw
|
||||||
|
vK2YpjSVgFRoJNx9s3bFr+9UG0LFmKvDZEP83ThQizYs2I/N7MSU8ERRImshaQMH
|
||||||
|
0lYB4At0RHC1mp8eKqhRgXenOtpfCiBACtlIdS9m1aqcU6i9Drgt86Bk/LC/HSvJ
|
||||||
|
MUOit2PP7QZVRWV6F8wAHlUFd6bdTKv9eOCZLSB6mY6DQmkp93FIMg==
|
||||||
|
=lQcB
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: D2E9C0807BF681F5E164DAFC5EE1B61CD90954CD
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hQIMA2pVdGTIrZI+ARAAjNHCArTtU9D8zw5yJzvf0KSwQoOaQWHui7AqQkvQ8mJv
|
||||||
|
8+Vo9sb+JoSuFHQqqDbOU+VFpmc9CZ6HCJaWqO2gZVgjxrsrPgyfq795LBd6GhX5
|
||||||
|
6zwUH2huxv+n7XkfjN4HHJAlSj0pRyL3fyojdOdtXCTuBGbofLIBJUbuD1wro1K+
|
||||||
|
nSHLvdBEitn8afKt5/SaatB8Prwyet6E6J4HluXFQjl+KdrRHHvXImmhNSR4yfIr
|
||||||
|
yQt2s8qapSvLhrUw9/GFXqM/jg4ZlDhPUhCAKI2Pr5PbsRMBqwdkSrDeB7MHdsU6
|
||||||
|
tI4uyb7j8m3VMbFKNVpuluwgk47V+W/h+jtZetSR6ewYsXJjgHNmX6JX73XzR7R+
|
||||||
|
q4EBfSAxR7ByZ/HHuumUH6BKBj8IcNJQwtEkLIZmLZ3OdFtJP3YY0esV+gEhG6K7
|
||||||
|
m2Zl9C7axuYmvoLrqygaChmxMhMiebTPNkD/dH5Ircwl2cXfHC+bvF2WO73DTk9G
|
||||||
|
emHzrkniEtuUs+svMhT3NKM3/mpOJTiNezdH39HZADzkBwZ5Mmkfe4mbXByfRN7F
|
||||||
|
AEJWmnOcpXwXE9//sRbkRr+CGmB86raZE22wHPuk6U9IyVFJm8hJbOzFc7rwu1Eo
|
||||||
|
0YWBCsc9dA+jH8hIKrIfXwqnfhYjTrX+oZJeK/8McOwfF7I2G9YrPAgwbokQmtLU
|
||||||
|
ZgEJAhC8ryOvXwp2kP9sv6nbXIEcwrX8lRjkEWduf6ZAWAfQ5FGBSPzR8WnZWGzN
|
||||||
|
PCxjg7utA9AHBChF1duwOV2Qr5XW8HTUGAx4fc0T0rjC862vSwf8yAY89WWJyUfk
|
||||||
|
n8qhhdw1uw==
|
||||||
|
=KgOe
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 878FEA3CB6A6F6E7CD80ECBE28506E3585F9F533
|
||||||
|
- created_at: "2026-05-25T17:17:14Z"
|
||||||
|
enc: |-
|
||||||
|
-----BEGIN PGP MESSAGE-----
|
||||||
|
|
||||||
|
hF4DKKbvh61jX5USAQdAYrtySnoCK7k4ZZIyllSAr23fozsiZb9Nf6Q+r56i3lAw
|
||||||
|
7IxBdJc2ipMxafy1Ntq0wfAYYk7nY6Vz1XtB+ekVeYLOjDmHRnJWq/Jw0K8wLvWT
|
||||||
|
1GYBCQIQ/0zDLdFOrMNjVPMutGVJOkpm7mbD30GpgRugzEf2NZePGtptqnP6i1t1
|
||||||
|
izBqFRByftV1MUw1uWgTFgB8zEVDh6gG0QAYeRuu3NS9QhwR71Wlu2J4eu+VhZi7
|
||||||
|
AKabk3T3Z00=
|
||||||
|
=A2ad
|
||||||
|
-----END PGP MESSAGE-----
|
||||||
|
fp: 41FFAF3D519CF5C039FBD8414BCC213729AF0E49
|
||||||
|
unencrypted_suffix: _unencrypted
|
||||||
|
version: 3.13.3
|
||||||
16
inventories/z9/host_vars/z9-router.yaml
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
systemd_networkd__config_dir: 'resources/z9/z9-router/systemd_networkd/'
|
||||||
|
systemd_networkd__global_config: "{{ lookup('ansible.builtin.file', 'resources/z9/z9-router/systemd_networkd_global_config.conf') }}"
|
||||||
|
nftables__config: "{{ lookup('ansible.builtin.file', 'resources/z9/z9-router/nftables/nftables.conf') }}"
|
||||||
|
ansible_pull__timer_on_calendar: "*-*-* 04:00:00 Europe/Berlin"
|
||||||
|
ansible_pull__timer_randomized_delay_sec: 0min
|
||||||
|
unbound_access_control: [ "10.89.208.0/20", "2a07:c481:1::/48" ]
|
||||||
|
deploy_systemd_resolved_config__enable: false
|
||||||
|
deploy_systemd_resolved_config__dns:
|
||||||
|
- 127.0.0.1
|
||||||
|
deploy_systemd_resolved_config__fallback_dns:
|
||||||
|
- 127.0.0.1
|
||||||
|
kea_dhcp__include_vars: resources/z9/z9-router/kea_dhcp.yaml
|
||||||
|
secrets__folder:
|
||||||
|
owner: "root"
|
||||||
|
mode: "0754"
|
||||||
|
group: 998
|
||||||
|
|
@ -1,20 +1,28 @@
|
||||||
all:
|
all:
|
||||||
hosts:
|
hosts:
|
||||||
dooris:
|
dooris:
|
||||||
ansible_host: dooris.z9.ccchh.net
|
ansible_host: dooris.ccchh.net
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
light:
|
light:
|
||||||
ansible_host: light.z9.ccchh.net
|
ansible_host: light.ccchh.net
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
opensourcetorrents:
|
opensourcetorrents:
|
||||||
ansible_host: opensourcetorrents.ccchh.net
|
ansible_host: opensourcetorrents.ccchh.net
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
|
pve01:
|
||||||
|
ansible_host: pve01.ccchh.net
|
||||||
waybackproxy:
|
waybackproxy:
|
||||||
ansible_host: waybackproxy.ccchh.net
|
ansible_host: waybackproxy.ccchh.net
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
yate:
|
yate:
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
It's fine, just feel like It's fine, just feel like `rt1` is one of those obscure names again, which gives more trouble than benefit.
bitwhisker
commented
do you have an idea/a proposal for a better name? do you have an idea/a proposal for a better name?
maybe z9-router or something like that?
I would say it would not be a good idea to name it just router,
because of the indirect name collision with the chaosknoten router.
june
commented
Oh, that totally makes sense. I'm fine with the name, if others really like it, but personally I would prefer something like Oh, that totally makes sense. I'm fine with the name, if others really like it, but personally I would prefer something like `z9-router` indeed.
|
|||||||
ansible_host: yate.z9.ccchh.net
|
ansible_host: yate.z9.ccchh.net
|
||||||
ansible_user: chaos
|
ansible_user: chaos
|
||||||
|
z9-router:
|
||||||
|
ansible_host: z9-router.ccchh.net
|
||||||
|
ansible_user: chaos
|
||||||
|
base_config_hosts:
|
||||||
|
hosts:
|
||||||
|
z9-router:
|
||||||
certbot_hosts:
|
certbot_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
light:
|
light:
|
||||||
|
|
@ -27,13 +35,14 @@ foobazdmx_hosts:
|
||||||
light:
|
light:
|
||||||
hypervisors:
|
hypervisors:
|
||||||
hosts:
|
hosts:
|
||||||
thinkcccore0:
|
pve01:
|
||||||
infrastructure_authorized_keys_hosts:
|
infrastructure_authorized_keys_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
dooris:
|
dooris:
|
||||||
light:
|
light:
|
||||||
waybackproxy:
|
waybackproxy:
|
||||||
yate:
|
yate:
|
||||||
|
z9-router:
|
||||||
nginx_hosts:
|
nginx_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
light:
|
light:
|
||||||
|
|
@ -46,19 +55,34 @@ transmission:
|
||||||
opensourcetorrents:
|
opensourcetorrents:
|
||||||
proxmox_vm_template_hosts:
|
proxmox_vm_template_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
thinkcccore0:
|
pve01:
|
||||||
|
systemd_networkd_hosts:
|
||||||
|
hosts:
|
||||||
|
z9-router:
|
||||||
|
nftables_hosts:
|
||||||
|
hosts:
|
||||||
|
z9-router:
|
||||||
|
unbound_hosts:
|
||||||
|
hosts:
|
||||||
|
z9-router:
|
||||||
|
kea_dhcp_hosts:
|
||||||
|
hosts:
|
||||||
|
z9-router:
|
||||||
alloy_hosts:
|
alloy_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
light:
|
light:
|
||||||
yate:
|
yate:
|
||||||
dooris:
|
dooris:
|
||||||
|
z9-router:
|
||||||
ansible_pull_hosts:
|
ansible_pull_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
dooris:
|
dooris:
|
||||||
light:
|
light:
|
||||||
waybackproxy:
|
waybackproxy:
|
||||||
yate:
|
yate:
|
||||||
|
z9-router:
|
||||||
secrets_hosts:
|
secrets_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
|
z9-router:
|
||||||
forgejo_runner_hosts:
|
forgejo_runner_hosts:
|
||||||
hosts:
|
hosts:
|
||||||
|
|
|
||||||
|
|
@ -27,6 +27,20 @@
|
||||||
tags:
|
tags:
|
||||||
- nftables
|
- nftables
|
||||||
|
|
||||||
|
- name: Ensure unbound deployment on unbound_hosts
|
||||||
|
hosts: unbound_hosts
|
||||||
|
roles:
|
||||||
|
- unbound
|
||||||
|
tags:
|
||||||
|
- unbound
|
||||||
|
|
||||||
|
- name: Ensure kea_dhcp deployment on kea_dhcp_hosts
|
||||||
|
hosts: kea_dhcp_hosts
|
||||||
|
roles:
|
||||||
|
- kea_dhcp
|
||||||
|
tags:
|
||||||
|
- kea_dhcp
|
||||||
|
|
||||||
- name: Ensure deployment of infrastructure authorized keys
|
- name: Ensure deployment of infrastructure authorized keys
|
||||||
hosts: infrastructure_authorized_keys_hosts
|
hosts: infrastructure_authorized_keys_hosts
|
||||||
roles:
|
roles:
|
||||||
|
|
|
||||||
|
|
@ -16,6 +16,8 @@ $TTL 60 ; 1 minutes
|
||||||
;
|
;
|
||||||
rt-wan A 185.161.129.134
|
rt-wan A 185.161.129.134
|
||||||
AAAA 2a07:c481::1:2
|
AAAA 2a07:c481::1:2
|
||||||
|
z9-router A 10.89.213.1
|
||||||
|
AAAA 2a07:c481:1:36::1
|
||||||
sw-rack-1 A 10.89.213.2
|
sw-rack-1 A 10.89.213.2
|
||||||
AAAA 2a07:c481:1:36::2
|
AAAA 2a07:c481:1:36::2
|
||||||
sw-rack-2-poe A 10.89.213.3
|
sw-rack-2-poe A 10.89.213.3
|
||||||
|
|
@ -44,27 +46,92 @@ unifi A 10.89.213.21
|
||||||
|
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
If this is commented out, can this be just removed or re-established? If this is commented out, can this be just removed or re-established?
|
|||||||
|
|
||||||
|
stb marked this conversation as resolved
june
commented
Maybe explicitly call this "Internal Club-Services" now that we have the category "Public Club-Services". Maybe explicitly call this "Internal Club-Services" now that we have the category "Public Club-Services".
|
|||||||
;
|
;
|
||||||
; Club-Services
|
; Internal Club-Services
|
||||||
;
|
;
|
||||||
xr18 A 172.31.200.29
|
xr18 A 10.89.208.15
|
||||||
dooris A 172.31.200.16
|
AtemMini A 10.89.212.234
|
||||||
AAAA 2a07:c481:1:d0::1c
|
|
||||||
hmdooris-ccu A 172.31.200.17
|
|
||||||
|
|
||||||
club-assistant AAAA 2a07:c481:1:d0::a
|
beamer A 10.89.208.11
|
||||||
A 10.31.208.10
|
ir-bridge-beamer A 10.89.212.213
|
||||||
_acme-challenge.club-assistant CNAME d50ad73a-f82d-4244-87f0-6f5195b37d21.auth.acmedns.hamburg.ccc.de.
|
Big-Room-Beamer A 10.89.208.14
|
||||||
;esphome AAAA 2a07:c481:1:d0::66
|
|
||||||
;zigbee2mqtt A 185.161.129.132
|
prusamk3 A 10.89.212.3
|
||||||
;light AAAA 2a07:c481:1:d0::16
|
prusamk4 A 10.89.212.4
|
||||||
|
|
||||||
|
wled-kueche A 10.89.212.33
|
||||||
|
wled-serverschrank A 10.89.212.34
|
||||||
|
wled-couch A 10.89.212.35
|
||||||
|
|
||||||
|
laser A 10.89.212.36
|
||||||
|
laser-eth A 10.89.212.37
|
||||||
|
|
||||||
|
okilaser A 10.89.212.235
|
||||||
|
|
||||||
|
t-mix A 10.89.212.42
|
||||||
|
fritz-fon A 10.89.212.86
|
||||||
|
|
||||||
|
staubi A 10.89.212.232
|
||||||
|
staubiv2 A 10.89.212.233
|
||||||
|
|
||||||
|
hp-color A 10.89.209.28
|
||||||
|
|
||||||
|
|
||||||
|
club-assistant A 10.89.213.22
|
||||||
|
AAAA 2a07:c481:1:36::32
|
||||||
|
_acme-challenge.club-assistant CNAME d50ad73a-f82d-4244-87f0-6f5195b37d21.auth.acmedns.hamburg.ccc.de
|
||||||
|
|
||||||
|
|
||||||
|
esphome A 10.89.212.210
|
||||||
|
AAAA 2a07:c481:1:34::66
|
||||||
|
hauptraum-esphome A 10.89.212.211
|
||||||
|
werkstatt-esphome A 10.89.212.212
|
||||||
|
|
||||||
|
|
||||||
|
light A 10.89.213.28
|
||||||
|
AAAA 2a07:c481:1:36::31
|
||||||
_acme-challenge.light CNAME e59f55ee-9013-469d-a146-a159721b6fea.auth.acmedns.hamburg.ccc.de.
|
_acme-challenge.light CNAME e59f55ee-9013-469d-a146-a159721b6fea.auth.acmedns.hamburg.ccc.de.
|
||||||
;light-werkstatt AAAA 2a07:c481:1:d0::16
|
light-werkstatt CNAME light.ccchh.net.
|
||||||
_acme-challenge.light-werkstatt CNAME f408acc0-d9f5-4525-bb01-28938e3bb7d0.auth.acmedns.hamburg.ccc.de.
|
_acme-challenge.light-werkstatt CNAME f408acc0-d9f5-4525-bb01-28938e3bb7d0.auth.acmedns.hamburg.ccc.de.
|
||||||
;buba A 10.31.211.137
|
|
||||||
|
pi-dmx-werkstatt A 10.89.212.215
|
||||||
|
|
||||||
|
|
||||||
|
dooris A 10.89.208.16
|
||||||
|
AAAA 2a07:c481:1:33::1c
|
||||||
_acme-challenge.dooris CNAME 37caae1f-b77f-4eb1-aa71-dc3f7ed24360.auth.acmedns.hamburg.ccc.de.
|
_acme-challenge.dooris CNAME 37caae1f-b77f-4eb1-aa71-dc3f7ed24360.auth.acmedns.hamburg.ccc.de.
|
||||||
yate A 10.31.208.12
|
|
||||||
;staubiv2 A 10.31.210.233
|
dooris-legacy A 10.89.208.31
|
||||||
prusa-mk4 A 10.31.210.4
|
|
||||||
|
hmdooris-ccu A 10.89.208.17
|
||||||
|
|
||||||
|
dooris-ng A 10.89.209.29
|
||||||
|
|
||||||
|
|
||||||
|
buba A 10.89.212.137
|
||||||
|
|
||||||
|
yate A 10.89.212.25
|
||||||
|
|
||||||
|
muzak A 10.89.208.13
|
||||||
|
|
||||||
|
encoder-ccchh A 10.89.209.166
|
||||||
|
|
||||||
|
ki10 A 10.89.209.254
|
||||||
|
|
||||||
|
Ziggy A 10.89.212.11
|
||||||
|
|
||||||
|
legacy A 10.89.212.12
|
||||||
|
|
||||||
|
foobarpay A 10.89.212.23
|
||||||
|
|
||||||
|
foobackup A 10.89.212.24
|
||||||
|
|
||||||
|
ender3v2-sonic-pad A 10.89.212.27
|
||||||
|
|
||||||
|
octopi A 10.89.212.31
|
||||||
|
|
||||||
|
433mhz-bridge A 10.89.212.32
|
||||||
|
|
||||||
|
;cisco-slm248p A 10.89.208.27
|
||||||
|
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I assume these deprecated entries are for documentation purposes? I assume these deprecated entries are for documentation purposes?
|
|||||||
|
|
||||||
;
|
;
|
||||||
|
|
@ -73,3 +140,4 @@ prusa-mk4 A 10.31.210.4
|
||||||
|
|
||||||
opensourcetorrents A 185.161.130.67
|
opensourcetorrents A 185.161.130.67
|
||||||
AAAA 2a07:c481:1:35::42
|
AAAA 2a07:c481:1:35::42
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -12,9 +12,6 @@ server {
|
||||||
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
||||||
ssl_trusted_certificate /etc/letsencrypt/live/light-werkstatt.ccchh.net/chain.pem;
|
ssl_trusted_certificate /etc/letsencrypt/live/light-werkstatt.ccchh.net/chain.pem;
|
||||||
|
|
||||||
# replace with the IP address of your resolver
|
|
||||||
resolver 10.31.208.1;
|
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
proxy_pass http://127.0.0.1:8081;
|
proxy_pass http://127.0.0.1:8081;
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I'm not quite sure, if this is actually needed for resolving hostnames in the config. If everything works without the I'm not quite sure, if this is actually needed for resolving hostnames in the config. If everything works without the `resolver` config option, then lets just remove it.
|
|||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
|
|
@ -25,23 +22,6 @@ server {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
server {
|
|
||||||
listen 443 ssl;
|
|
||||||
listen [::]:443 ssl;
|
|
||||||
http2 on;
|
|
||||||
|
|
||||||
server_name light.z9.ccchh.net;
|
|
||||||
|
|
||||||
ssl_certificate /etc/letsencrypt/live/light.z9.ccchh.net/fullchain.pem;
|
|
||||||
ssl_certificate_key /etc/letsencrypt/live/light.z9.ccchh.net/privkey.pem;
|
|
||||||
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
|
||||||
ssl_trusted_certificate /etc/letsencrypt/live/light.z9.ccchh.net/chain.pem;
|
|
||||||
|
|
||||||
location / {
|
|
||||||
return 307 https://light.ccchh.net$request_uri;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
server {
|
server {
|
||||||
listen 443 ssl;
|
listen 443 ssl;
|
||||||
listen [::]:443 ssl;
|
listen [::]:443 ssl;
|
||||||
|
|
@ -54,9 +34,6 @@ server {
|
||||||
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
# verify chain of trust of OCSP response using Root CA and Intermediate certs
|
||||||
ssl_trusted_certificate /etc/letsencrypt/live/light.ccchh.net/chain.pem;
|
ssl_trusted_certificate /etc/letsencrypt/live/light.ccchh.net/chain.pem;
|
||||||
|
|
||||||
# replace with the IP address of your resolver
|
|
||||||
resolver 10.31.208.1;
|
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
proxy_pass http://127.0.0.1:8080;
|
proxy_pass http://127.0.0.1:8080;
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
|
|
|
||||||
|
|
@ -81,7 +81,7 @@ ${called}^fo370381tr317349_00$=inbound_fonial
|
||||||
^.*$=echo [z9] "\0" ${caller}->${called} ; log
|
^.*$=echo [z9] "\0" ${caller}->${called} ; log
|
||||||
|
|
||||||
; test service numbers
|
; test service numbers
|
||||||
^91$=sip/sip:ha@10.31.208.10:5060; called=ha;format=opus ; Homeassistant
|
^91$=sip/sip:ha@10.89.213.22:5060; called=ha;format=opus ; Homeassistant
|
||||||
^98$=external/playrec/echo.sh ; Echotest
|
^98$=external/playrec/echo.sh ; Echotest
|
||||||
^99$=external/play/tts.sh;mode=text;text=Hallo Hallo Hallo ; TTS test
|
^99$=external/play/tts.sh;mode=text;text=Hallo Hallo Hallo ; TTS test
|
||||||
|
|
||||||
|
|
|
||||||
311
resources/z9/z9-router/kea_dhcp.yaml
Normal file
|
|
@ -0,0 +1,311 @@
|
||||||
|
kea_dhcp__dns_servers:
|
||||||
|
v4:
|
||||||
|
- 185.161.129.134
|
||||||
|
v6:
|
||||||
|
- 2a07:c481::1:2
|
||||||
|
|
||||||
|
kea_dhcp__dhcp4:
|
||||||
|
enable: true
|
||||||
|
interfaces: ["netlan.51", "netlan.52", "netlan"]
|
||||||
|
subnets:
|
||||||
|
- id: 1
|
||||||
|
subnet: 10.89.208.0/22
|
||||||
|
option-data:
|
||||||
|
- name: domain-name-servers
|
||||||
|
data: "10.89.208.1"
|
||||||
|
- name: routers
|
||||||
|
data: 10.89.208.1
|
||||||
|
pools:
|
||||||
|
- pool: "10.89.208.32 - 10.89.211.250"
|
||||||
|
reservations:
|
||||||
|
- ip-address: 10.89.208.11
|
||||||
|
hostname: beamer
|
||||||
|
hw-address: "ac:87:a3:18:9e:01"
|
||||||
|
- ip-address: 10.89.208.12
|
||||||
|
hostname: Brother-CCCHH
|
||||||
|
hw-address: "00:80:77:04:3a:55"
|
||||||
|
- ip-address: 10.89.208.13
|
||||||
|
hostname: muzak
|
||||||
|
hw-address: "00:11:24:5f:4f:80"
|
||||||
|
- ip-address: 10.89.208.14
|
||||||
|
hostname: Big-Room-Beamer
|
||||||
|
hw-address: "64:d2:c4:db:08:5c"
|
||||||
|
- ip-address: 10.89.208.15
|
||||||
|
hostname: xr18
|
||||||
|
hw-address: "34:8d:13:13:1f:33"
|
||||||
|
- ip-address: 10.89.208.16
|
||||||
|
hostname: dooris
|
||||||
|
hw-address: "bc:24:11:b3:93:9c"
|
||||||
|
- ip-address: 10.89.208.17
|
||||||
|
hostname: hmdooris-ccu
|
||||||
|
hw-address: "bc:24:11:5f:2d:b1"
|
||||||
|
- ip-address: 10.89.208.27
|
||||||
|
hostname: cisco-slm248p
|
||||||
|
hw-address: "00:23:eb:b0:fc:3f"
|
||||||
|
- ip-address: 10.89.208.47
|
||||||
|
hw-address: "6c:df:fb:0b:34:21"
|
||||||
|
- ip-address: 10.89.208.48
|
||||||
|
hw-address: "6c:df:fb:0d:91:63"
|
||||||
|
- ip-address: 10.89.209.28
|
||||||
|
hostname: hp-color
|
||||||
|
hw-address: "3c:52:82:29:21:79"
|
||||||
|
- ip-address: 10.89.208.31
|
||||||
|
hostname: dooris-legacy
|
||||||
|
hw-address: "b8:27:eb:80:a5:66"
|
||||||
|
- ip-address: 10.89.209.29
|
||||||
|
hostname: dooris-ng
|
||||||
|
hw-address: "6c:4b:90:19:21:a1"
|
||||||
|
- ip-address: 10.89.209.166
|
||||||
|
hostname: encoder-ccchh
|
||||||
|
hw-address: "00:4e:01:a2:40:d7"
|
||||||
|
- ip-address: 10.89.209.254
|
||||||
|
hostname: ki10
|
||||||
|
hw-address: "dc:a6:32:a9:ff:82"
|
||||||
|
- id: 2
|
||||||
|
subnet: 10.89.212.0/24
|
||||||
|
option-data:
|
||||||
|
- name: domain-name-servers
|
||||||
|
data: "10.89.212.1"
|
||||||
|
- name: routers
|
||||||
|
data: 10.89.212.1
|
||||||
|
pools:
|
||||||
|
- pool: "10.89.212.32 - 10.89.212.250"
|
||||||
|
reservations:
|
||||||
|
- ip-address: 10.89.212.3
|
||||||
|
hostname: prusamk3
|
||||||
|
hw-address: "10:9c:70:2e:59:3e"
|
||||||
|
- ip-address: 10.89.212.4
|
||||||
|
hostname: prusamk4
|
||||||
|
hw-address: "10:9c:70:2e:6e:f0"
|
||||||
|
- ip-address: 10.89.212.11
|
||||||
|
hostname: Ziggy
|
||||||
|
hw-address: "44:17:93:53:65:57"
|
||||||
|
- ip-address: 10.89.212.12
|
||||||
|
hostname: legacy
|
||||||
|
hw-address: "00:15:65:a1:ed:98"
|
||||||
|
- ip-address: 10.89.212.23
|
||||||
|
hostname: foobarpay
|
||||||
|
hw-address: "f4:f2:6d:09:a6:73"
|
||||||
|
- ip-address: 10.89.212.24
|
||||||
|
hostname: foobackup
|
||||||
|
hw-address: "bc:24:11:20:1a:a8"
|
||||||
|
- ip-address: 10.89.212.25
|
||||||
|
hostname: yate
|
||||||
|
hw-address: "bc:24:11:bf:8f:95"
|
||||||
|
- ip-address: 10.89.212.27
|
||||||
|
hostname: ender3v2-sonic-pad
|
||||||
|
hw-address: "fc:ee:91:00:0e:14"
|
||||||
|
- ip-address: 10.89.212.31
|
||||||
|
hostname: octopi
|
||||||
|
hw-address: "b8:27:eb:0f:d8:09"
|
||||||
|
- ip-address: 10.89.212.32
|
||||||
|
hostname: 433mhz-bridge
|
||||||
|
hw-address: "0c:b8:15:fe:e3:34"
|
||||||
|
- ip-address: 10.89.212.33
|
||||||
|
hostname: wled-kueche
|
||||||
|
hw-address: "30:ae:a4:7a:8d:a0"
|
||||||
|
- ip-address: 10.89.212.34
|
||||||
|
hostname: wled-serverschrank
|
||||||
|
hw-address: "18:fe:34:a6:64:76"
|
||||||
|
- ip-address: 10.89.212.35
|
||||||
|
hostname: wled-couch
|
||||||
|
hw-address: "64:b7:08:40:ab:c0"
|
||||||
|
- ip-address: 10.89.212.36
|
||||||
|
hostname: laser
|
||||||
|
hw-address: "b8:27:eb:be:38:fa"
|
||||||
|
- ip-address: 10.89.212.37
|
||||||
|
hostname: laser-eth
|
||||||
|
hw-address: "b8:27:eb:eb:6d:af"
|
||||||
|
- ip-address: 10.89.212.42
|
||||||
|
hostname: t-mix
|
||||||
|
hw-address: "40:a5:ef:d9:eb:93"
|
||||||
|
- ip-address: 10.89.212.137
|
||||||
|
hostname: ccchh-buba
|
||||||
|
hw-address: "b8:27:eb:29:bd:77"
|
||||||
|
- ip-address: 10.89.212.86
|
||||||
|
hostname: fritz-fon
|
||||||
|
hw-address: "00:1f:3f:c9:e5:b2"
|
||||||
|
- ip-address: 10.89.212.210
|
||||||
|
hostname: esphome
|
||||||
|
hw-address: "7e:3c:f0:77:8a:f4"
|
||||||
|
- ip-address: 10.89.212.211
|
||||||
|
hostname: hauptraum-esphome
|
||||||
|
hw-address: "e8:db:84:e8:18:d2"
|
||||||
|
- ip-address: 10.89.212.212
|
||||||
|
hostname: werkstatt-esphome
|
||||||
|
hw-address: "3c:71:bf:26:42:32"
|
||||||
|
- ip-address: 10.89.212.213
|
||||||
|
hostname: ir-bridge-beamer
|
||||||
|
hw-address: "8c:ce:4e:51:93:dd"
|
||||||
|
- ip-address: 10.89.212.215
|
||||||
|
hostname: pi-dmx-werkstatt
|
||||||
|
hw-address: "b8:27:eb:65:e5:31"
|
||||||
|
- ip-address: 10.89.212.227
|
||||||
|
hostname: SIP-T46S
|
||||||
|
hw-address: "80:5e:c0:09:bf:55"
|
||||||
|
- ip-address: 10.89.212.230
|
||||||
|
hostname: SIP-T46S
|
||||||
|
hw-address: "80:5e:c0:22:33:08"
|
||||||
|
- ip-address: 10.89.212.232
|
||||||
|
hostname: staubi
|
||||||
|
hw-address: "b8:4d:43:98:51:2b"
|
||||||
|
- ip-address: 10.89.212.233
|
||||||
|
hostname: staubiv2
|
||||||
|
hw-address: "70:c9:32:82:25:b2"
|
||||||
|
- ip-address: 10.89.212.234
|
||||||
|
hostname: AtemMini
|
||||||
|
hw-address: "7c:2e:0d:13:72:a8"
|
||||||
|
- ip-address: 10.89.212.235
|
||||||
|
hostname: okilaser
|
||||||
|
hw-address: "2c:ff:65:22:b4:63"
|
||||||
|
- id: 3
|
||||||
|
subnet: 10.89.213.0/24
|
||||||
|
option-data:
|
||||||
|
- name: domain-name-servers
|
||||||
|
data: "10.89.213.1"
|
||||||
|
- name: routers
|
||||||
|
data: 10.89.213.1
|
||||||
|
pools:
|
||||||
|
- pool: "10.89.213.32 - 10.89.213.250"
|
||||||
|
reservations:
|
||||||
|
- ip-address: 10.89.213.2
|
||||||
|
hostname: sw-rack-1
|
||||||
|
hw-address: "F0:9F:C2:10:C3:AA"
|
||||||
|
- ip-address: 10.89.213.3
|
||||||
|
hostname: sw-rack-2-peo
|
||||||
|
hw-address: "44:d9:e7:06:69:5d"
|
||||||
|
- ip-address: 10.89.213.4
|
||||||
|
hostname: sw-main-1
|
||||||
|
hw-address: "a8:9c:6c:16:df:cc"
|
||||||
|
- ip-address: 10.89.213.5
|
||||||
|
hostname: sw-main-2
|
||||||
|
hw-address: "a8:9c:6c:16:e8:86"
|
||||||
|
- ip-address: 10.89.213.6
|
||||||
|
hostname: sw-shop-1
|
||||||
|
hw-address: "C0:4A:00:FB:DA:C5"
|
||||||
|
- ip-address: 10.89.213.7
|
||||||
|
hostname: sw-shop-2-peo
|
||||||
|
hw-address: "f4:e2:c6:bf:20:ee"
|
||||||
|
- ip-address: 10.89.213.8
|
||||||
|
hostname: sw-shop-3-peo
|
||||||
|
hw-address: "d8:b3:70:85:72:76"
|
||||||
|
- ip-address: 10.89.213.11
|
||||||
|
hostname: pve01
|
||||||
|
hw-address: "38:05:25:30:80:35"
|
||||||
|
- ip-address: 10.89.213.12
|
||||||
|
hostname: pve02
|
||||||
|
hw-address: "b8:85:84:b1:57:b6"
|
||||||
|
- ip-address: 10.89.213.13
|
||||||
|
hostname: pve03
|
||||||
|
hw-address: "98:fa:9b:a2:ed:e8"
|
||||||
|
- ip-address: 10.89.213.15
|
||||||
|
hostname: pbs
|
||||||
|
hw-address: "BC:24:11:D6:2C:81"
|
||||||
|
- ip-address: 10.89.213.21
|
||||||
|
hostname: unifi
|
||||||
|
hw-address: "BC:24:11:25:77:60"
|
||||||
|
- ip-address: 10.89.213.22
|
||||||
|
hostname: club-assistant
|
||||||
|
hw-address: "7a:55:61:c3:a2:89"
|
||||||
|
- ip-address: 10.89.213.23
|
||||||
|
hostname: automation
|
||||||
|
hw-address: "f2:20:75:5a:2f:8c"
|
||||||
|
- ip-address: 10.89.213.25
|
||||||
|
hostname: ptouch-print-server
|
||||||
|
hw-address: "bc:24:11:f2:cf:8f"
|
||||||
|
- ip-address: 10.89.213.26
|
||||||
|
hostname: mqtt
|
||||||
|
hw-address: "bc:24:11:48:85:73"
|
||||||
|
- ip-address: 10.89.213.27
|
||||||
|
hostname: factorio
|
||||||
|
hw-address: "bc:24:11:a3:43:7f"
|
||||||
|
- ip-address: 10.89.213.28
|
||||||
|
hostname: light
|
||||||
|
hw-address: "72:61:ea:e6:49:e3"
|
||||||
|
- ip-address: 10.89.213.29
|
||||||
|
hostname: homematic
|
||||||
|
hw-address: "fe:3a:42:77:3a:be"
|
||||||
|
- ip-address: 10.89.213.30
|
||||||
|
hostname: proxmox-backup-server
|
||||||
|
hw-address: "8a:48:dd:a3:22:40"
|
||||||
|
|
||||||
|
kea_dhcp__dhcp6:
|
||||||
|
enable: true
|
||||||
|
interfaces: ["netlan.51", "netlan.52", "netlan"]
|
||||||
|
subnets:
|
||||||
|
- id: 1
|
||||||
|
subnet: "2a07:c481:1:33::/64"
|
||||||
|
interface: "netlan.51"
|
||||||
|
option-data:
|
||||||
|
- name: "dns-servers"
|
||||||
|
data: "2a07:c481:1:33::1"
|
||||||
|
pools:
|
||||||
|
- pool: "2a07:c481:1:33::/64"
|
||||||
|
allocator: random
|
||||||
|
reservations:
|
||||||
|
- ip-addresses: ["2a07:c481:1:33::1c"]
|
||||||
|
hostname: dooris
|
||||||
|
hw-address: "bc:24:11:b3:93:9c"
|
||||||
|
- id: 2
|
||||||
|
subnet: "2a07:c481:1:34::/64"
|
||||||
|
interface: "netlan.52"
|
||||||
|
option-data:
|
||||||
|
- name: "dns-servers"
|
||||||
|
data: "2a07:c481:1:34::1"
|
||||||
|
pools:
|
||||||
|
- pool: "2a07:c481:1:34::/64"
|
||||||
|
reservations:
|
||||||
|
- ip-addresses: ["2a07:c481:1:34::66"]
|
||||||
|
hostname: esphome
|
||||||
|
hw-address: "7e:3c:f0:77:8a:f4"
|
||||||
|
- id: 3
|
||||||
|
subnet: "2a07:c481:1:36::/64"
|
||||||
|
interface: "netlan.54"
|
||||||
|
option-data:
|
||||||
|
- name: "dns-servers"
|
||||||
|
data: "2a07:c481:1:36::1"
|
||||||
|
pools:
|
||||||
|
- pool: "2a07:c481:1:36::/64"
|
||||||
|
reservations:
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::2"]
|
||||||
|
hostname: sw-rack-1
|
||||||
|
hw-address: "F0:9F:C2:10:C3:AA"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::3"]
|
||||||
|
hostname: sw-rack-2-peo
|
||||||
|
hw-address: "44:d9:e7:06:69:5d"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::4"]
|
||||||
|
hostname: sw-main-1
|
||||||
|
hw-address: "a8:9c:6c:16:df:cc"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::5"]
|
||||||
|
hostname: sw-main-2
|
||||||
|
hw-address: "a8:9c:6c:16:e8:86"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::6"]
|
||||||
|
hostname: sw-shop-1
|
||||||
|
hw-address: "C0:4A:00:FB:DA:C5"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::7"]
|
||||||
|
hostname: sw-shop-2-peo
|
||||||
|
hw-address: "f4:e2:c6:bf:20:ee"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::8"]
|
||||||
|
hostname: sw-shop-3-peo
|
||||||
|
hw-address: "d8:b3:70:85:72:76"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::b"]
|
||||||
|
hostname: pve01
|
||||||
|
hw-address: "38:05:25:30:80:35"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::c"]
|
||||||
|
hostname: pve02
|
||||||
|
hw-address: "b8:85:84:b1:57:b6"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::d"]
|
||||||
|
hostname: pve03
|
||||||
|
hw-address: "98:fa:9b:a2:ed:e8"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::f"]
|
||||||
|
hostname: pbs
|
||||||
|
hw-address: "BC:24:11:D6:2C:81"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::21"]
|
||||||
|
hostname: unifi
|
||||||
|
hw-address: "BC:24:11:25:77:60"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::31"]
|
||||||
|
hostname: light
|
||||||
|
hw-address: "72:61:ea:e6:49:e3"
|
||||||
|
- ip-addresses: ["2a07:c481:1:36::32"]
|
||||||
|
hostname: club-assistant
|
||||||
|
hw-address: "7a:55:61:c3:a2:89"
|
||||||
118
resources/z9/z9-router/nftables/nftables.conf
Normal file
|
|
@ -0,0 +1,118 @@
|
||||||
|
#!/usr/sbin/nft -f
|
||||||
|
flush ruleset
|
||||||
|
|
||||||
|
## Variables
|
||||||
|
|
||||||
|
# Hosts
|
||||||
|
|
||||||
|
|
||||||
|
# Interfaces
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
If this isn't in use, it can just be removed. If this isn't in use, it can just be removed.
|
|||||||
|
define if_netlan = "netlan"
|
||||||
|
define if_wg56_management = "wg56"
|
||||||
|
define if_netwan_400_fux_uplink = "netwan.400"
|
||||||
|
define if_netlan_51_clients = "netlan.51"
|
||||||
|
define if_netlan_52_iot = "netlan.52"
|
||||||
|
define if_netlan_53_public = "netlan.53"
|
||||||
|
define if_netlan_55_management = "netlan"
|
||||||
|
|
||||||
|
# Interface Groups
|
||||||
|
define wan_ifs = { $if_netwan_400_fux_uplink }
|
||||||
|
define lan_ifs = { $if_netlan_51_clients,
|
||||||
|
$if_netlan_52_iot,
|
||||||
|
$if_netlan_53_public,
|
||||||
|
$if_netlan_55_management }
|
||||||
|
define v4_exposed_ifs = { $if_netlan_53_public }
|
||||||
|
define v6_exposed_ifs = { $if_netlan_53_public }
|
||||||
|
define v4_nat_ifs = { $if_netlan_51_clients,
|
||||||
|
$if_netlan_52_iot,
|
||||||
|
$if_netlan_55_management }
|
||||||
|
|
||||||
|
|
||||||
|
## Rules
|
||||||
|
table inet reverse-path-forwarding {
|
||||||
|
chain rpf-filter {
|
||||||
|
type filter hook prerouting priority mangle + 10; policy drop;
|
||||||
|
|
||||||
|
# Only allow packets if their source address is routed via their incoming interface.
|
||||||
|
# https://github.com/NixOS/nixpkgs/blob/d9d87c51960050e89c79e4025082ed965e770d68/nixos/modules/services/networking/firewall-nftables.nix#L100
|
||||||
|
fib saddr . mark . iif oif exists accept
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
table inet host {
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority filter; policy drop;
|
||||||
|
|
||||||
|
iifname "lo" accept comment "allow loopback"
|
||||||
|
|
||||||
|
ct state invalid drop
|
||||||
|
ct state established,related accept
|
||||||
|
|
||||||
|
ip protocol icmp accept
|
||||||
|
# ICMPv6
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Some spacing seems to be off here. Some spacing seems to be off here.
|
|||||||
|
# https://datatracker.ietf.org/doc/html/rfc4890#autoid-24
|
||||||
|
# Allowlist consisting of: "Traffic That Must Not Be Dropped" and "Traffic That Normally Should Not Be Dropped"
|
||||||
|
# Error messages that are essential to the establishment and maintenance of communications:
|
||||||
|
icmpv6 type { destination-unreachable, packet-too-big } accept
|
||||||
|
icmpv6 type { time-exceeded } accept
|
||||||
|
icmpv6 type { parameter-problem } accept
|
||||||
|
# Connectivity checking messages:
|
||||||
|
icmpv6 type { echo-request, echo-reply } accept
|
||||||
|
# Address Configuration and Router Selection messages:
|
||||||
|
icmpv6 type { nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert, ind-neighbor-solicit, ind-neighbor-advert } accept
|
||||||
|
# Link-Local Multicast Receiver Notification messages:
|
||||||
|
icmpv6 type { mld-listener-query, mld-listener-report, mld-listener-done, mld2-listener-report } accept
|
||||||
|
# SEND Certificate Path Notification messages:
|
||||||
|
icmpv6 type { 148, 149 } accept
|
||||||
|
# Multicast Router Discovery messages:
|
||||||
|
icmpv6 type { 151, 152, 153 } accept
|
||||||
|
|
||||||
|
# Allow SSH access.
|
||||||
|
tcp dport 22 accept comment "allow ssh access"
|
||||||
|
|
||||||
|
# Allow WireGuard access.
|
||||||
|
udp dport 51820 accept comment "allow WireGuard access"
|
||||||
|
|
||||||
|
# Allow DHCP server access.
|
||||||
|
iifname { $lan_ifs } udp dport 67 accept comment "allow dhcp server access"
|
||||||
|
iifname { $lan_ifs } udp dport 547 accept comment "allow dhcpv6 server access"
|
||||||
|
|
||||||
|
# Allow DNS server access from lan_ifs
|
||||||
|
iifname { $lan_ifs, $if_wg56_management } meta l4proto { tcp, udp } th dport 53 accept comment "allow dns server access from lan_ifs"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
table ip v4nat {
|
||||||
|
chain prerouting {
|
||||||
|
type nat hook prerouting priority dstnat; policy accept;
|
||||||
|
}
|
||||||
|
|
||||||
|
chain postrouting {
|
||||||
|
type nat hook postrouting priority srcnat; policy accept;
|
||||||
|
|
||||||
|
iifname { $v4_nat_ifs, $if_wg56_management } oifname $wan_ifs masquerade
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
table inet forward {
|
||||||
|
chain forward {
|
||||||
|
type filter hook forward priority filter; policy drop;
|
||||||
|
|
||||||
|
ct state invalid drop
|
||||||
|
ct state established,related accept
|
||||||
|
|
||||||
|
# Allow internet access.
|
||||||
|
iifname { $lan_ifs, $if_wg56_management } oifname $wan_ifs accept comment "allow internet access"
|
||||||
|
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Some spacing seems to be off here as well. Some spacing seems to be off here as well.
|
|||||||
|
# Allow access to exposed networks from internet.
|
||||||
|
meta nfproto ipv4 oifname $v4_exposed_ifs accept comment "allow v4 exposed network access"
|
||||||
|
meta nfproto ipv6 oifname $v6_exposed_ifs accept comment "allow v6 exposed network access"
|
||||||
|
|
||||||
|
# Allow clients and management to most
|
||||||
|
iifname { $if_netlan_51_clients, $if_netlan_55_management, $if_wg56_management } oifname $lan_ifs accept comment "Allow clients and management to lan interfaces"
|
||||||
|
|
||||||
|
# Fux PVE backups
|
||||||
|
ip6 saddr { 2a07:c481:0:1::/64 } ip6 daddr { 2a07:c481:1:36::15/128 } accept comment "allow Fux PVE to access CCCHH PBS"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
6
resources/z9/z9-router/systemd_networkd/00-netlan.link
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
[Match]
|
||||||
|
MACAddress=BC:24:11:72:A3:27
|
||||||
|
Type=ether
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
Name=netlan
|
||||||
|
|
@ -0,0 +1,8 @@
|
||||||
|
[NetDev]
|
||||||
|
Name=netlan.51
|
||||||
|
Kind=vlan
|
||||||
|
MACAddress=BC:24:11:BD:D3:F9
|
||||||
|
|
||||||
|
[VLAN]
|
||||||
|
Id=51
|
||||||
|
|
||||||
|
|
@ -0,0 +1,8 @@
|
||||||
|
[NetDev]
|
||||||
|
Name=netlan.52
|
||||||
|
Kind=vlan
|
||||||
|
MACAddress=BC:24:11:88:28:15
|
||||||
|
|
||||||
|
[VLAN]
|
||||||
|
Id=52
|
||||||
|
|
||||||
|
|
@ -0,0 +1,8 @@
|
||||||
|
[NetDev]
|
||||||
|
Name=netlan.53
|
||||||
|
Kind=vlan
|
||||||
|
MACAddress=BC:24:11:3C:3C:BE
|
||||||
|
|
||||||
|
[VLAN]
|
||||||
|
Id=53
|
||||||
|
|
||||||
|
|
@ -0,0 +1,8 @@
|
||||||
|
[NetDev]
|
||||||
|
Name=netwan.400
|
||||||
|
Kind=vlan
|
||||||
|
MACAddress=BC:24:11:C3:27:45
|
||||||
|
|
||||||
|
[VLAN]
|
||||||
|
Id=400
|
||||||
|
|
||||||
90
resources/z9/z9-router/systemd_networkd/10-wg56.netdev
Normal file
|
|
@ -0,0 +1,90 @@
|
||||||
|
[NetDev]
|
||||||
|
Description=Admin-Wireguard
|
||||||
|
Kind=wireguard
|
||||||
|
Name=wg56
|
||||||
|
|
||||||
|
[WireGuard]
|
||||||
|
ListenPort=51820
|
||||||
|
PrivateKeyFile=/etc/ansible_secrets/wireguard_wg55_private_key
|
||||||
|
|
||||||
|
# WireGuard Peers
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = stb
|
||||||
|
AllowedIPs = 10.89.214.2/32,2a07:c481:1:37::2/128
|
||||||
|
PublicKey = vILSL4dbaC5IaTsRhJviamV18ssxWSj+qLVyowLQ214=
|
||||||
|
PersistentKeepalive = 30
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = fi
|
||||||
|
AllowedIPs = 10.89.214.3/32,2a07:c481:1:37::3/128
|
||||||
|
PublicKey = UHi/if5uW2V3+8Q3R+uk6/XpRi4fPXbw7chsKI4xlkI=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_fi_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = jtbx
|
||||||
|
AllowedIPs = 10.89.214.4/32,2a07:c481:1:37::4/128
|
||||||
|
PublicKey = NyyEqdWgScgsnTF8Zz/Om4Lc84fdFMwVtvaCmLEkUlQ=
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = June
|
||||||
|
AllowedIPs = 10.89.214.6/32,2a07:c481:1:37::6/128
|
||||||
|
PublicKey = 6jAEB+f9przBGxPhuvv9U9gvZDEBQNqpQSD0BoGqXQQ=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_June_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = Max
|
||||||
|
AllowedIPs = 10.89.214.7/32,2a07:c481:1:37::7/128
|
||||||
|
PublicKey = oC1hJjtlAgLX/CmbwTC+LPmd1uwluQTwsN8RaMNmHn0=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_Max_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = dario
|
||||||
|
AllowedIPs = 10.89.214.9/32,2a07:c481:1:37::9/128
|
||||||
|
PublicKey = bYF2EGRGpEGjiKcasi/oaWoWeLsgqsF6FGaq3Z4ERww=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_dario_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = June-mobile
|
||||||
|
AllowedIPs = 10.89.214.11/32,2a07:c481:1:37::11/128
|
||||||
|
PublicKey = 6edjXykegUgGjbkIG1aJyBlX1SgTKcqXXaSBVPHdKDc=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_June-mobile_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = djerun_at_ferrum.local
|
||||||
|
AllowedIPs = 10.89.214.12/32,2a07:c481:1:37::12/128
|
||||||
|
PublicKey = aHbdkTHhPkd+o7wWfTua9nd72aF4OVp66zGtpaoD8Fg=
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = c6ristian
|
||||||
|
AllowedIPs = 10.89.214.13/32,2a07:c481:1:37::13/128
|
||||||
|
PublicKey = 6ndwj3Ur6AqfUPWuyPYXIaGZs2ujJKawSQ9LEvlYzEc=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_c6ristian_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = langoor
|
||||||
|
AllowedIPs = 10.89.214.14/32,2a07:c481:1:37::14/128
|
||||||
|
PublicKey = qTnVQlQa1m4SucFFNli/xM6QWfsdWx2baRAit7Cg8RM=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_langoor_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = langoor_home
|
||||||
|
AllowedIPs = 10.89.214.15/32,2a07:c481:1:37::15/128
|
||||||
|
PublicKey = NeMDs2+5rHuKO5ZYXVUR76GorgdesFUnDOFECQ3RzG4=
|
||||||
|
PresharedKeyFile = /etc/ansible_secrets/wireguard_wg55_peer_langoor_home_psk
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = lilly-lillysLaptop
|
||||||
|
AllowedIPs = 10.89.214.16/32,2a07:c481:1:37::16/128
|
||||||
|
PublicKey = IBsI+N8qUNpQnDc5HnqQ2Zo/1graFM0RMIecHmAF+Vk=
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = bitwhisker
|
||||||
|
AllowedIPs = 10.89.214.17/32,2a07:c481:1:37::a/128
|
||||||
|
PublicKey = DvEGvQPGi+IxeRTIA72Gx3WNINcrV9HRNB1v7mHnhjA=
|
||||||
|
|
||||||
|
[WireGuardPeer]
|
||||||
|
# friendly_name = forestcat
|
||||||
|
AllowedIPs = 10.89.214.18/32,2a07:c481:1:37::b/128
|
||||||
|
PublicKey = PdJ7KlIeASizj0WTY87d7oSi14/MebrhRa+L8YiPoQE=
|
||||||
|
|
||||||
36
resources/z9/z9-router/systemd_networkd/20-netlan.network
Normal file
|
|
@ -0,0 +1,36 @@
|
||||||
|
[Match]
|
||||||
|
Name=netlan
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
RequiredForOnline=no
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
DHCP=no
|
||||||
|
DNS=10.89.213.1
|
||||||
|
DNS=2a07:c481:1:36::1
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I guess those commented out options can just be removed, if they aren't needed. I guess those commented out options can just be removed, if they aren't needed.
|
|||||||
|
|
||||||
|
VLAN=netlan.51
|
||||||
|
VLAN=netlan.52
|
||||||
|
VLAN=netlan.53
|
||||||
|
#VLAN=netlan.55 # vlan 55 ist untaged im pve
|
||||||
|
VLAN=netwan.400
|
||||||
|
|
||||||
|
#Description=Management
|
||||||
|
|
||||||
|
# Masquerading done in nftables (nftables.conf).
|
||||||
|
IPv6SendRA=yes
|
||||||
|
|
||||||
|
[Address]
|
||||||
|
Address=10.89.213.1/24
|
||||||
|
|
||||||
|
[IPv6SendRA]
|
||||||
|
UplinkInterface=netwan.400
|
||||||
|
EmitDomains=true
|
||||||
|
Domains=ccchh.net
|
||||||
|
Managed=true
|
||||||
|
|
||||||
|
[IPv6Prefix]
|
||||||
|
Prefix=2a07:c481:1:36::/64
|
||||||
|
Assign=true
|
||||||
|
Token=static:::1
|
||||||
|
|
||||||
6
resources/z9/z9-router/systemd_networkd/20-wg56.network
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
[Match]
|
||||||
|
Name=wg56
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
Address=10.89.214.1/24
|
||||||
|
Address=2a07:c481:1:37::1/64
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
[Match]
|
||||||
|
Name=netlan.51
|
||||||
|
Type=vlan
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
RequiredForOnline=no
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
Description=clients
|
||||||
|
DNS=10.89.208.1
|
||||||
|
DNS=2a07:c481:1:33::1
|
||||||
|
|
||||||
|
# Masquerading done in nftables (nftables.conf).
|
||||||
|
IPv6SendRA=yes
|
||||||
|
|
||||||
|
[Address]
|
||||||
|
Address=10.89.208.1/22
|
||||||
|
|
||||||
|
[IPv6SendRA]
|
||||||
|
UplinkInterface=netwan.400
|
||||||
|
EmitDomains=true
|
||||||
|
Domains=ccchh.net
|
||||||
|
Managed=true
|
||||||
|
|
||||||
|
[IPv6Prefix]
|
||||||
|
Prefix=2a07:c481:1:33::/64
|
||||||
|
Assign=true
|
||||||
|
Token=static:::1
|
||||||
|
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
[Match]
|
||||||
|
Name=netlan.52
|
||||||
|
Type=vlan
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
RequiredForOnline=no
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
Description=IoT
|
||||||
|
DNS=10.89.212.1
|
||||||
|
DNS=2a07:c481:1:34::1
|
||||||
|
|
||||||
|
# Masquerading done in nftables (nftables.conf).
|
||||||
|
IPv6SendRA=yes
|
||||||
|
|
||||||
|
[Address]
|
||||||
|
Address=10.89.212.1/24
|
||||||
|
|
||||||
|
[IPv6SendRA]
|
||||||
|
UplinkInterface=netwan.400
|
||||||
|
EmitDomains=true
|
||||||
|
Domains=ccchh.net
|
||||||
|
Managed=true
|
||||||
|
|
||||||
|
[IPv6Prefix]
|
||||||
|
Prefix=2a07:c481:1:34::/64
|
||||||
|
Assign=true
|
||||||
|
Token=static:::1
|
||||||
|
|
||||||
|
|
@ -0,0 +1,29 @@
|
||||||
|
[Match]
|
||||||
|
Name=netlan.53
|
||||||
|
Type=vlan
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
RequiredForOnline=no
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
Description=public
|
||||||
|
DNS=185.161.130.65
|
||||||
|
DNS=2a07:c481:1:35::1
|
||||||
|
|
||||||
|
# Masquerading done in nftables (nftables.conf).
|
||||||
|
IPv6SendRA=yes
|
||||||
|
|
||||||
|
[Address]
|
||||||
|
Address=185.161.130.65/28
|
||||||
|
|
||||||
|
[IPv6SendRA]
|
||||||
|
UplinkInterface=netwan.400
|
||||||
|
EmitDomains=true
|
||||||
|
Domains=ccchh.net
|
||||||
|
Managed=true
|
||||||
|
|
||||||
|
[IPv6Prefix]
|
||||||
|
Prefix=2a07:c481:1:35::/64
|
||||||
|
Assign=true
|
||||||
|
Token=static:::1
|
||||||
|
|
||||||
|
|
@ -0,0 +1,28 @@
|
||||||
|
[Match]
|
||||||
|
Name=netwan.400
|
||||||
|
Type=vlan
|
||||||
|
|
||||||
|
[Link]
|
||||||
|
RequiredForOnline=no
|
||||||
|
|
||||||
|
[Network]
|
||||||
|
Description=fux-uplink
|
||||||
|
|
||||||
|
DNS=185.161.128.66
|
||||||
|
DNS=2a07:c481:0:4::2
|
||||||
|
DNS=185.161.128.67
|
||||||
|
DNS=2a07:c481:0:4::3
|
||||||
|
|
||||||
|
IPv6AcceptRA=no
|
||||||
|
# Masquerading done in nftables (nftables.conf).
|
||||||
|
IPv6SendRA=no
|
||||||
|
|
||||||
|
[Address]
|
||||||
|
Address=185.161.129.134/25
|
||||||
|
[Address]
|
||||||
|
Address=2a07:c481::1:2/64
|
||||||
|
|
||||||
|
[Route]
|
||||||
|
Gateway=185.161.129.129
|
||||||
|
[Route]
|
||||||
|
Gateway=2a07:c481::1
|
||||||
|
|
@ -0,0 +1,3 @@
|
||||||
|
[Network]
|
||||||
|
IPv4Forwarding=true
|
||||||
|
IPv6Forwarding=true
|
||||||
112
roles/kea_dhcp/README.md
Normal file
|
|
@ -0,0 +1,112 @@
|
||||||
|
# Role `kea_dhcp`
|
||||||
|
|
||||||
|
Install and manage Kea DHCP and [Stork Agent](https://stork.readthedocs.io/en/latest/man/stork-agent.8.html).
|
||||||
|
|
||||||
|
## Supported Distributions
|
||||||
|
|
||||||
|
Should work on Debian-based distributions.
|
||||||
|
|
||||||
|
## Required Arguments
|
||||||
|
|
||||||
|
None.
|
||||||
|
|
||||||
|
## Optional Arguments
|
||||||
|
|
||||||
|
- `kea_dhcp__stork_agent.enable`: Enable Kea DHCP stork agent.
|
||||||
|
Defaults to `false`.
|
||||||
|
- `kea_dhcp__stork_agent.prometheus_only`: Only enable the prometheus endpoint in stork agent.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `kea_dhcp__dns_servers.v4`: List of IPv4 DNS Servers in DHCP response.
|
||||||
|
Defaults to FUX DNS Servers.
|
||||||
|
- `kea_dhcp__dns_servers.v6`: List of IPv6 DNS Servers in DHCP response.
|
||||||
|
Defaults to FUX DNS Servers.
|
||||||
|
- `kea_dhcp__include_vars`: Path to YAML File to separately load VARs for Kea config templating.
|
||||||
|
- `kea_dhcp__dhcp4.enable`: Enable Kea DHCP4 Service.
|
||||||
|
Defaults to `false`.
|
||||||
|
- `kea_dhcp__dhcp4.interfaces`: List of interfaces the DHCP4 Server should listen to and serve.
|
||||||
|
Defaults to the empty list (`[ ]`).
|
||||||
|
- `kea_dhcp__dhcp4.control-sockets`: List of Kea DHCP4 control sockets.
|
||||||
|
Defaults to the list with one entry (see below).
|
||||||
|
- `kea_dhcp__dhcp4.control-sockets.*.socket-name`: Control socket name.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.control-sockets.0.socket-name: /var/run/kea-dhcp4-ctrl-agent.sock`.
|
||||||
|
- `kea_dhcp__dhcp4.control-sockets.*.socket-type`: Control socket type.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.control-sockets.0.socket-type: unix`.
|
||||||
|
- `kea_dhcp__dhcp4.lease-database.type`: Type of lease database.
|
||||||
|
Defaults to `memfile`.
|
||||||
|
- `kea_dhcp__dhcp4.lease-database.persist`: Persist the lease database.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `kea_dhcp__dhcp4.hooks-libraries`: List of custom processing hooks.
|
||||||
|
Details at: https://kea.readthedocs.io/en/kea-3.0.0/arm/hooks.html#hooks-libraries.
|
||||||
|
Defaults to `undefined`.
|
||||||
|
- `kea_dhcp__dhcp4.option-data`: List of DHCP4 Options.
|
||||||
|
Defaults to a list with one entry (see below).
|
||||||
|
- `kea_dhcp__dhcp4.option-data.*.name`: Name of DHCP4 Option.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.option-data.0.name: "domain-name-servers"`.
|
||||||
|
- `kea_dhcp__dhcp4.option-data.*.code`: DHCP4 Option code.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.option-data.0.code: 6`.
|
||||||
|
- `kea_dhcp__dhcp4.option-data.*.csv-format`: DHCP4 Option as csv format.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.option-data.0.csv-format: true`.
|
||||||
|
- `kea_dhcp__dhcp4.option-data.*.data`: DHCP4 Option data.
|
||||||
|
Defaults to `kea_dhcp__dhcp4.option-data.0.data: "{{ kea_dhcp__dns_servers.v4 | join(',') }}"`.
|
||||||
|
- `kea_dhcp__dhcp4.logging`: List of loggers.
|
||||||
|
Defaults to one logger to `stdout`.
|
||||||
|
- `kea_dhcp__dhcp4.subnets`: List of subnets the DHCP4 server should manage.
|
||||||
|
Defaults to the empty list (`[ ]`).
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.id`: ID of interface (starts with 1).
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.subnet`: Subnet on interface.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.pools`: List of DHCP pools in subnet.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.pools.*.pool`: DHCP pool in range format.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.reservations`: List of DHCP lease reservations.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.reservations.*.ip-address`: IP address of reservation.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.reservations.*.hostname`: Hostname of reservation.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.reservations.*.hw-address`: Hardware address of reservation.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.option-data`: List of DHCP lease reservations.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.option-data.*.name`: Name of DHCP4 Option.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.option-data.*.code`: DHCP4 Option code.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.option-data.*.csv-format`: DHCP4 Option as csv format.
|
||||||
|
- `kea_dhcp__dhcp4.subnets.*.option-data.*.data`: DHCP4 Option data.
|
||||||
|
- `kea_dhcp__dhcp6.enable`: Enable Kea DHCP6 Service.
|
||||||
|
Defaults to `false`.
|
||||||
|
- `kea_dhcp__dhcp6.interfaces`: List of interfaces the DHCP6 Server should listen to and serve.
|
||||||
|
Defaults to the empty list (`[ ]`).
|
||||||
|
- `kea_dhcp__dhcp6.control-sockets`: List of Kea DHCP6 control sockets.
|
||||||
|
Defaults to the list with one entry (see below).
|
||||||
|
- `kea_dhcp__dhcp6.control-sockets.*.socket-name`: Control socket name.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.control-sockets.0.socket-name: /var/run/kea-dhcp6-ctrl-agent.sock`.
|
||||||
|
- `kea_dhcp__dhcp6.control-sockets.*.socket-type`: Control socket type.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.control-sockets.0.socket-type: unix`.
|
||||||
|
- `kea_dhcp__dhcp6.lease-database.type`: Type of lease database.
|
||||||
|
Defaults to `memfile`.
|
||||||
|
- `kea_dhcp__dhcp6.lease-database.persist`: Persist the lease database.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `kea_dhcp__dhcp6.hooks-libraries`: List of custom processing hooks.
|
||||||
|
Details at: https://kea.readthedocs.io/en/kea-3.0.0/arm/hooks.html#hooks-libraries.
|
||||||
|
Defaults to `undefined`.
|
||||||
|
- `kea_dhcp__dhcp6.option-data`: List of DHCP6 Options.
|
||||||
|
Defaults to a list with one entry (see below).
|
||||||
|
- `kea_dhcp__dhcp6.option-data.*.name`: Name of DHCP6 Option.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.option-data.0.name: "domain-name-servers"`.
|
||||||
|
- `kea_dhcp__dhcp6.option-data.*.code`: DHCP6 Option code.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.option-data.0.code: 6`.
|
||||||
|
- `kea_dhcp__dhcp6.option-data.*.csv-format`: DHCP6 Option as csv format.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.option-data.0.csv-format: true`.
|
||||||
|
- `kea_dhcp__dhcp6.option-data.*.data`: DHCP6 Option data.
|
||||||
|
Defaults to `kea_dhcp__dhcp6.option-data.0.data: "{{ kea_dhcp__dns_servers.v6 | join(',') }}"`.
|
||||||
|
- `kea_dhcp__dhcp6.logging`: List of loggers.
|
||||||
|
Defaults to one logger to `stdout`.
|
||||||
|
- `kea_dhcp__dhcp6.subnets`: List of subnets the DHCP6 server should manage.
|
||||||
|
Defaults to the empty list (`[ ]`).
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.id`: ID of interface (starts with 1).
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.subnet`: Subnet on interface.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.pools`: List of DHCP pools in subnet.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.pools.*.pool`: DHCP pool in range format.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.reservations`: List of DHCP lease reservations.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.reservations.*.ip-address`: IP address of reservation.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.reservations.*.hostname`: Hostname of reservation.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.reservations.*.hw-address`: Hardware address of reservation.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.option-data`: List of DHCP lease reservations.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.option-data.*.name`: Name of DHCP6 Option.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.option-data.*.code`: DHCP6 Option code.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.option-data.*.csv-format`: DHCP6 Option as csv format.
|
||||||
|
- `kea_dhcp__dhcp6.subnets.*.option-data.*.data`: DHCP6 Option data.
|
||||||
|
|
||||||
86
roles/kea_dhcp/defaults/main.yaml
Normal file
|
|
@ -0,0 +1,86 @@
|
||||||
|
---
|
||||||
|
# Set Kea group name based on distribution
|
||||||
|
kea_dhcp__service_group: "{{ '_kea' if ansible_facts['distribution'] == 'Debian' else 'kea' }}"
|
||||||
|
kea_dhcp__unit_base_name: "{{ 'isc-kea' if ansible_facts['distribution'] == 'Debian' else 'kea' }}"
|
||||||
|
kea_dhcp__unit_base_sufix: "{{ '-server' if ansible_facts['distribution'] == 'Debian' else '' }}"
|
||||||
|
|
||||||
|
kea_dhcp__version_repo: "kea-3-0"
|
||||||
|
kea_dhcp__dns_servers:
|
||||||
|
v6:
|
||||||
|
- "2a07:c481:0:4::2"
|
||||||
|
- "2a07:c481:0:4::3"
|
||||||
|
v4:
|
||||||
|
- "185.161.128.66"
|
||||||
|
- "185.161.128.67"
|
||||||
|
kea_dhcp__ntp_servers:
|
||||||
|
v4:
|
||||||
|
- "185.161.128.7"
|
||||||
|
- "185.161.128.8"
|
||||||
|
v6: "2a07:c481:0:3::7"
|
||||||
|
fqdn: ntp.z9.fux-eg.net
|
||||||
|
kea_dhcp__sntp_servers:
|
||||||
|
v6:
|
||||||
|
- "2a07:c481:0:3::7"
|
||||||
|
- "2a07:c481:0:3::8"
|
||||||
|
|
||||||
|
kea_dhcp__stork_agent_defaults:
|
||||||
|
enable: false
|
||||||
|
prometheus_only: true
|
||||||
|
kea_dhcp__stork_agent: {}
|
||||||
|
|
||||||
|
kea_dhcp__dhcp4_defaults:
|
||||||
|
enable: false
|
||||||
|
interfaces: [ ]
|
||||||
|
control-sockets:
|
||||||
|
- socket-name: /var/run/kea/dhcp4-ctrl-agent.sock
|
||||||
|
socket-type: unix
|
||||||
|
lease-database:
|
||||||
|
type: memfile
|
||||||
|
persist: true
|
||||||
|
option-data:
|
||||||
|
- name: domain-name-servers
|
||||||
|
code: 6
|
||||||
|
csv-format: true
|
||||||
|
data: "{{ kea_dhcp__dns_servers.v4 | join(',') }}"
|
||||||
|
- name: ntp-servers
|
||||||
|
code: 42
|
||||||
|
data: "{{ kea_dhcp__ntp_servers.v4 | join(',') }}"
|
||||||
|
logging:
|
||||||
|
- name: kea-dhcp4
|
||||||
|
output-options:
|
||||||
|
- output: stdout
|
||||||
|
severity: INFO
|
||||||
|
kea_dhcp__dhcp4: {}
|
||||||
|
|
||||||
|
kea_dhcp__dhcp6_defaults:
|
||||||
|
enable: false
|
||||||
|
interfaces: [ ]
|
||||||
|
control-sockets:
|
||||||
|
- socket-name: /var/run/kea/dhcp6-ctrl-agent.sock
|
||||||
|
socket-type: unix
|
||||||
|
lease-database:
|
||||||
|
type: memfile
|
||||||
|
persist: true
|
||||||
|
option-data:
|
||||||
|
- name: dns-servers
|
||||||
|
code: 23
|
||||||
|
data: "{{ kea_dhcp__dns_servers.v6 | join(',') }}"
|
||||||
|
- name: sntp-servers
|
||||||
|
code: 31
|
||||||
|
data: "{{ kea_dhcp__sntp_servers.v6 | join(',') }}"
|
||||||
|
- name: ntp-server
|
||||||
|
code: 56
|
||||||
|
- name: ntp-server-address
|
||||||
|
space: v6-ntp-server-suboptions
|
||||||
|
data: "{{ kea_dhcp__ntp_servers.v6 }}"
|
||||||
|
- name: ntp-server-fqdn
|
||||||
|
space: v6-ntp-server-suboptions
|
||||||
|
data: "{{ kea_dhcp__ntp_servers.fqdn }}"
|
||||||
|
logging:
|
||||||
|
- name: kea-dhcp6
|
||||||
|
output-options:
|
||||||
|
- output: stdout
|
||||||
|
severity: INFO
|
||||||
|
kea_dhcp__dhcp6: {}
|
||||||
|
|
||||||
|
kea_dhcp__include_vars:
|
||||||
37
roles/kea_dhcp/handlers/main.yml
Normal file
|
|
@ -0,0 +1,37 @@
|
||||||
|
---
|
||||||
|
- name: Systemd_daemon_reload
|
||||||
|
become: true
|
||||||
|
ansible.builtin.systemd_service:
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Kea_dhcp4.restarted_debian
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Called "reloaded" even tho the action is Called "reloaded" even tho the action is `restarted`. One of them needs to be adjusted.
|
|||||||
|
listen: Kea_dhcp4.restarted
|
||||||
|
become: true
|
||||||
|
ansible.builtin.service:
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Again, I think rather not having the checks makes more sense for our use case. Again, I think rather not having the checks makes more sense for our use case.
|
|||||||
|
name: isc-kea-dhcp4-server
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Same restarted/reloaded comment as above. Same restarted/reloaded comment as above.
|
|||||||
|
|
||||||
|
- name: Kea_dhcp6.restarted_debian
|
||||||
|
listen: Kea_dhcp6.restarted
|
||||||
|
become: true
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: isc-kea-dhcp6-server
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Same restarted/reloaded comment as above. Same restarted/reloaded comment as above.
|
|||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: Kea_ctrl.restarted_debian
|
||||||
|
listen: Kea_ctrl.restarted
|
||||||
|
become: true
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: isc-kea-ctrl-agent
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: Stork_agent.restarted_debian
|
||||||
|
listen: Stork_agent.restarted
|
||||||
|
become: true
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: isc-stork-agent
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
134
roles/kea_dhcp/meta/argument_specs.yaml
Normal file
|
|
@ -0,0 +1,134 @@
|
||||||
|
---
|
||||||
|
argument_specs:
|
||||||
|
main:
|
||||||
|
short_description: "Role for managing Kea DHCP server"
|
||||||
|
options:
|
||||||
|
kea_dhcp__stork_agent_defaults:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Default configuration for Stork Agent."
|
||||||
|
- "Merged with kea_dhcp__stork_agent using combine(recursive=True)."
|
||||||
|
options:
|
||||||
|
enable:
|
||||||
|
type: "bool"
|
||||||
|
default: false
|
||||||
|
prometheus_only:
|
||||||
|
type: "bool"
|
||||||
|
default: true
|
||||||
|
kea_dhcp__stork_agent:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Host/group override for Stork Agent configuration."
|
||||||
|
- "Merged on top of kea_dhcp__stork_agent_defaults using combine(recursive=True)."
|
||||||
|
- "Only specify the keys you want to override."
|
||||||
|
kea_dhcp__version_repo:
|
||||||
|
type: "str"
|
||||||
|
description:
|
||||||
|
- "Version of Kea DHCP repository to use."
|
||||||
|
- "The versions can be found at https://cloudsmith.io/~isc/repos/"
|
||||||
|
default: "kea-3-0"
|
||||||
|
kea_dhcp__ntp_servers:
|
||||||
|
type: "dict"
|
||||||
|
description: "Default NTP servers advertised to DHCP clients (DHCPv4 option 42, DHCPv6 option 56)."
|
||||||
|
options:
|
||||||
|
v4:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
v6:
|
||||||
|
type: "str"
|
||||||
|
fqdn:
|
||||||
|
type: "str"
|
||||||
|
kea_dhcp__sntp_servers:
|
||||||
|
type: "dict"
|
||||||
|
description: "Default SNTP servers advertised to DHCPv6 clients (option 31)."
|
||||||
|
options:
|
||||||
|
v4:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
v6:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
kea_dhcp__dns_servers:
|
||||||
|
type: "dict"
|
||||||
|
description: "Default DNS servers for DHCP clients"
|
||||||
|
options:
|
||||||
|
v6:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
v4:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
kea_dhcp__dhcp4_defaults:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Default configuration for DHCPv4 service."
|
||||||
|
- "Merged with kea_dhcp__dhcp4 using combine(recursive=True)."
|
||||||
|
options:
|
||||||
|
enable:
|
||||||
|
type: "bool"
|
||||||
|
default: false
|
||||||
|
interfaces:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
default: []
|
||||||
|
control-sockets:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
lease-database:
|
||||||
|
type: "dict"
|
||||||
|
hooks-libraries:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
option-data:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
subnets:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
logging:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
kea_dhcp__dhcp4:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Host/group override for DHCPv4 configuration."
|
||||||
|
- "Merged on top of kea_dhcp__dhcp4_defaults using combine(recursive=True)."
|
||||||
|
- "Only specify the keys you want to override."
|
||||||
|
- "See kea_dhcp__dhcp4_defaults for available options."
|
||||||
|
kea_dhcp__dhcp6_defaults:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Default configuration for DHCPv6 service."
|
||||||
|
- "Merged with kea_dhcp__dhcp6 using combine(recursive=True)."
|
||||||
|
options:
|
||||||
|
enable:
|
||||||
|
type: "bool"
|
||||||
|
default: false
|
||||||
|
interfaces:
|
||||||
|
type: "list"
|
||||||
|
elements: "str"
|
||||||
|
default: []
|
||||||
|
control-sockets:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
lease-database:
|
||||||
|
type: "dict"
|
||||||
|
hooks-libraries:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
option-data:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
subnets:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
logging:
|
||||||
|
type: "list"
|
||||||
|
elements: "dict"
|
||||||
|
kea_dhcp__dhcp6:
|
||||||
|
type: "dict"
|
||||||
|
description:
|
||||||
|
- "Host/group override for DHCPv6 configuration."
|
||||||
|
- "Merged on top of kea_dhcp__dhcp6_defaults using combine(recursive=True)."
|
||||||
|
- "Only specify the keys you want to override."
|
||||||
|
- "See kea_dhcp__dhcp6_defaults for available options."
|
||||||
42
roles/kea_dhcp/tasks/install_debian.yaml
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
---
|
||||||
|
- name: Register isc-kea apt repository
|
||||||
|
become: true
|
||||||
|
register: kea_dhcp__repo
|
||||||
|
ansible.builtin.deb822_repository:
|
||||||
|
name: "isc-{{ kea_dhcp__version_repo }}"
|
||||||
|
uris: "https://dl.cloudsmith.io/public/isc/{{ kea_dhcp__version_repo }}/deb/debian"
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
To clarify: I assume the Debian package isn't sufficient then? To clarify: I assume the Debian package isn't sufficient then?
(in reference to: https://git.hamburg.ccc.de/CCCHH/ansible-infra/pulls/98#issuecomment-4686)
bitwhisker
commented
yes yes
|
|||||||
|
suites: "{{ ansible_facts['distribution_release'] }}"
|
||||||
|
components: main
|
||||||
|
signed_by: "https://dl.cloudsmith.io/public/isc/{{ kea_dhcp__version_repo }}/gpg.key"
|
||||||
|
|
||||||
|
- name: Install Kea packages
|
||||||
|
become: true
|
||||||
|
block:
|
||||||
|
- name: Update cache
|
||||||
|
ansible.builtin.apt:
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Again, I think installing this conditionally, if we also deploy the configs conditionally, makes sense. Again, I think installing this conditionally, if we also deploy the configs conditionally, makes sense.
(in reference to: https://git.hamburg.ccc.de/CCCHH/ansible-infra/pulls/98#issuecomment-4657)
|
|||||||
|
update_cache: "{{ kea_dhcp__repo.changed }}"
|
||||||
|
- name: Install isc-kea-dhcp4
|
||||||
|
when: kea_dhcp__dhcp4.enable
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- isc-kea-dhcp4
|
||||||
|
- name: Install isc-kea-dhcp6
|
||||||
|
when: kea_dhcp__dhcp6.enable
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- isc-kea-dhcp6
|
||||||
|
- name: Install isc-kea-hooks
|
||||||
|
when: kea_dhcp__dhcp4.enable or kea_dhcp__dhcp6.enable
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- isc-kea-hooks
|
||||||
|
- name: Install isc-kea-ctrl-agent
|
||||||
|
when: kea_dhcp__stork_agent.enable
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- isc-kea-ctrl-agent
|
||||||
|
- name: Install isc-kea-admin
|
||||||
|
when: kea_dhcp__dhcp4.enable or kea_dhcp__dhcp6.enable
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- isc-kea-admin
|
||||||
42
roles/kea_dhcp/tasks/kea.yaml
Normal file
|
|
@ -0,0 +1,42 @@
|
||||||
|
---
|
||||||
|
- name: Deploy kea-dhcp4 configuration file
|
||||||
|
become: true
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
I would rather just stick to only having tags at the playbook level. I don't think this kind granular control for the role is really needed as it the config files also shouldn't trigger a reload, if not changed. I would rather just stick to only having tags at the playbook level. I don't think this kind granular control for the role is really needed as it the config files also shouldn't trigger a reload, if not changed.
bitwhisker
commented
this was just copied from the fux noc ansible, but I can remove it this was just copied from the fux noc ansible, but I can remove it
|
|||||||
|
when: kea_dhcp__dhcp4.enable
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: kea-dhcp4.conf.j2
|
||||||
|
dest: /etc/kea/kea-dhcp4.conf
|
||||||
|
backup: true
|
||||||
|
owner: root
|
||||||
|
group: "{{ kea_dhcp__service_group }}"
|
||||||
|
mode: "u=rw,g=r,o="
|
||||||
|
validate: "/usr/sbin/kea-dhcp4 -T %s" # does not work with debian apparmor policys
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
If this doesn't work on our target platform, than maybe just don't have this check. Does this fail? If this doesn't work on our target platform, than maybe just don't have this check. Does this fail?
bitwhisker
commented
this does not fail, because we deactivated app armor, this is just a comment, for if some one in the future has this problem this does not fail, because we deactivated app armor, this is just a comment, for if some one in the future has this problem
|
|||||||
|
notify:
|
||||||
|
- Kea_dhcp4.restarted
|
||||||
|
|
||||||
|
- name: Deploy kea-dhcp6 configuration file
|
||||||
|
become: true
|
||||||
|
when: kea_dhcp__dhcp6.enable
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: kea-dhcp6.conf.j2
|
||||||
|
dest: /etc/kea/kea-dhcp6.conf
|
||||||
|
backup: true
|
||||||
|
owner: root
|
||||||
|
group: "{{ kea_dhcp__service_group }}"
|
||||||
|
mode: "u=rw,g=r,o="
|
||||||
|
validate: /usr/sbin/kea-dhcp6 -T %s # does not work with debian apparmor policys
|
||||||
|
notify:
|
||||||
|
- Kea_dhcp6.restarted
|
||||||
|
|
||||||
|
- name: Copy kea-ctrl-agent configuration file
|
||||||
|
become: true
|
||||||
|
when: kea_dhcp__stork_agent.enable
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: kea-ctrl-agent.conf.j2
|
||||||
|
dest: /etc/kea/kea-ctrl-agent.conf
|
||||||
|
owner: root
|
||||||
|
group: "{{ kea_dhcp__service_group }}"
|
||||||
|
mode: "u=rw,g=r,o="
|
||||||
|
validate: /usr/sbin/kea-ctrl-agent -t %s # does not work with debian apparmor policys
|
||||||
|
notify:
|
||||||
|
- Kea_ctrl.restarted
|
||||||
|
- Stork_agent.restarted
|
||||||
23
roles/kea_dhcp/tasks/main.yml
Normal file
|
|
@ -0,0 +1,23 @@
|
||||||
|
---
|
||||||
|
- name: Include config vars
|
||||||
|
when: kea_dhcp__include_vars != None
|
||||||
|
ansible.builtin.include_vars:
|
||||||
|
file: "{{ kea_dhcp__include_vars }}"
|
||||||
|
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Again, getting rid of the Arch Linux logic also greatly simplifies this file. Again, getting rid of the Arch Linux logic also greatly simplifies this file.
bitwhisker
commented
this was just copied from the fux noc ansible, but I can remove it this was just copied from the fux noc ansible, but I can remove it
|
|||||||
|
- name: Merge default vars with host_vars
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
kea_dhcp__stork_agent: "{{ kea_dhcp__stork_agent_defaults | combine(kea_dhcp__stork_agent, recursive=True) }}"
|
||||||
|
kea_dhcp__dhcp4: "{{ kea_dhcp__dhcp4_defaults | combine(kea_dhcp__dhcp4, recursive=True) }}"
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I would rather remove this check and have it just fail while running the Ansible playbook, rather than installing a broken Kea deployment. I would rather remove this check and have it just fail while running the Ansible playbook, rather than installing a broken Kea deployment.
|
|||||||
|
kea_dhcp__dhcp6: "{{ kea_dhcp__dhcp6_defaults | combine(kea_dhcp__dhcp6, recursive=True) }}"
|
||||||
|
|
||||||
|
- name: Setup Kea DHCP
|
||||||
|
block:
|
||||||
|
- name: Install Kea on Debian
|
||||||
|
ansible.builtin.import_tasks: install_debian.yaml
|
||||||
|
|
||||||
|
- name: Configure Kea
|
||||||
|
ansible.builtin.include_tasks: kea.yaml
|
||||||
|
|
||||||
|
- name: Run stork-agent tasks
|
||||||
|
when: kea_dhcp__stork_agent.enable
|
||||||
|
ansible.builtin.include_tasks: stork-agent.yaml
|
||||||
50
roles/kea_dhcp/tasks/stork-agent.yaml
Normal file
|
|
@ -0,0 +1,50 @@
|
||||||
|
---
|
||||||
|
- name: Install stork-agent
|
||||||
|
block:
|
||||||
|
- name: Install stork-agent on Debian
|
||||||
|
block:
|
||||||
|
- name: Register isc-stork apt repository
|
||||||
|
become: true
|
||||||
|
register: "kea_dhcp_install_repo"
|
||||||
|
ansible.builtin.deb822_repository:
|
||||||
|
name: isc-stork
|
||||||
|
uris: https://dl.cloudsmith.io/public/isc/stork/deb/debian
|
||||||
|
suites: any-version
|
||||||
|
components: main
|
||||||
|
signed_by: https://dl.cloudsmith.io/public/isc/stork/gpg.key
|
||||||
|
|
||||||
|
- name: Install isc-stork-agent
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: isc-stork-agent
|
||||||
|
update_cache: "{{ kea_dhcp_install_repo.changed }}"
|
||||||
|
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
We don't even have this role present in our repo, so just getting rid of the Arch Linux logic probably makes sense. We don't even have this role present in our repo, so just getting rid of the Arch Linux logic probably makes sense.
|
|||||||
|
- name: Add stork-agent user to kea group on Debian
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: stork-agent
|
||||||
|
groups: [ "{{ kea_dhcp__service_group }}" ]
|
||||||
|
append: true
|
||||||
|
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Same here with the distro check. Same here with the distro check.
|
|||||||
|
- name: Config for stork-agent
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: stork-agent.env.j2
|
||||||
|
dest: /etc/stork/agent.env
|
||||||
|
owner: root
|
||||||
|
group: "{{ kea_dhcp__service_group }}"
|
||||||
|
mode: "0660"
|
||||||
|
notify:
|
||||||
|
- Systemd_daemon_reload
|
||||||
|
- Stork_agent.restarted
|
||||||
|
|
||||||
|
- name: Flush handlers
|
||||||
|
ansible.builtin.meta: flush_handlers
|
||||||
|
|
||||||
|
- name: Ensure that stork kea exporter is working
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: "http://localhost:9547/metrics"
|
||||||
|
method: GET
|
||||||
|
register: kea_dhcp_stork_status_code
|
||||||
|
retries: 6
|
||||||
|
delay: 5
|
||||||
|
until: kea_dhcp_stork_status_code.status == 200
|
||||||
20
roles/kea_dhcp/templates/kea-ctrl-agent.conf.j2
Normal file
|
|
@ -0,0 +1,20 @@
|
||||||
|
{
|
||||||
|
"Control-agent": {
|
||||||
|
"http-host": "127.0.0.1",
|
||||||
|
"http-port": 8000,
|
||||||
|
"control-sockets": {
|
||||||
|
{% if kea_dhcp__dhcp4.enable | default(false) %}
|
||||||
|
"dhcp4": {
|
||||||
|
"socket-type": "{{ kea_dhcp__dhcp4['control-sockets'][0]['socket-type'] }}",
|
||||||
|
"socket-name": "{{ kea_dhcp__dhcp4['control-sockets'][0]['socket-name'] }}"
|
||||||
|
}{% if kea_dhcp__dhcp6.enable %},{% endif %}
|
||||||
|
{% endif %}
|
||||||
|
{% if kea_dhcp__dhcp6.enable | default(false) %}
|
||||||
|
"dhcp6": {
|
||||||
|
"socket-type": "{{ kea_dhcp__dhcp6['control-sockets'][0]['socket-type'] }}",
|
||||||
|
"socket-name": "{{ kea_dhcp__dhcp6['control-sockets'][0]['socket-name'] }}"
|
||||||
|
},
|
||||||
|
{% endif %}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
32
roles/kea_dhcp/templates/kea-dhcp4.conf.j2
Normal file
|
|
@ -0,0 +1,32 @@
|
||||||
|
{
|
||||||
|
"Dhcp4": {
|
||||||
|
"interfaces-config": {
|
||||||
|
"interfaces": {{ kea_dhcp__dhcp4.interfaces | to_nice_json | indent(12) }}
|
||||||
|
},
|
||||||
|
"control-sockets": {{ kea_dhcp__dhcp4['control-sockets'] | to_nice_json | indent(8) }},
|
||||||
|
"lease-database": {{ kea_dhcp__dhcp4['lease-database'] | to_nice_json | indent(8) }},
|
||||||
|
{% if kea_dhcp__dhcp4['hooks-libraries'] is defined and kea_dhcp__dhcp4['hooks-libraries'] %}
|
||||||
|
"hooks-libraries": {{ kea_dhcp__dhcp4['hooks-libraries'] | to_nice_json | indent(8) }},
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
This option isn't documented in the README. This option isn't documented in the README.
|
|||||||
|
{% endif %}
|
||||||
|
{% if kea_dhcp__dhcp4['option-data'] is defined and kea_dhcp__dhcp4['option-data'] %}
|
||||||
|
"option-data": {{ kea_dhcp__dhcp4['option-data'] | to_nice_json | indent(8) }},
|
||||||
|
{% endif %}
|
||||||
|
"loggers": {{ kea_dhcp__dhcp4['logging'] | to_nice_json | indent(8) }},
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
This option isn't documented in the README. This option isn't documented in the README.
|
|||||||
|
"subnet4": [
|
||||||
|
{% for subnet in kea_dhcp__dhcp4.subnets %}
|
||||||
|
{
|
||||||
|
"id": {{ subnet.id }},
|
||||||
|
"subnet": "{{ subnet.subnet }}",
|
||||||
|
"pools": {{ subnet.pools | to_nice_json | indent(16) }},
|
||||||
|
{% if subnet.reservations is defined and subnet.reservations %}
|
||||||
|
"reservations": {{ subnet.reservations | to_nice_json | indent(16) }},
|
||||||
|
{% endif %}
|
||||||
|
{% if subnet['option-data'] is defined and subnet['option-data'] %}
|
||||||
|
"option-data": {{ subnet['option-data'] | to_nice_json | indent(16) }}
|
||||||
|
{% endif %}
|
||||||
|
}{% if not loop.last %},{% endif %}
|
||||||
|
|
||||||
|
{% endfor %}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
36
roles/kea_dhcp/templates/kea-dhcp6.conf.j2
Normal file
|
|
@ -0,0 +1,36 @@
|
||||||
|
{
|
||||||
|
"Dhcp6": {
|
||||||
|
"interfaces-config": {
|
||||||
|
"interfaces": {{ kea_dhcp__dhcp6.interfaces | to_nice_json | indent(12) }}
|
||||||
|
},
|
||||||
|
"control-sockets": {{ kea_dhcp__dhcp6['control-sockets'] | to_nice_json | indent(8) }},
|
||||||
|
"lease-database": {{ kea_dhcp__dhcp6['lease-database'] | to_nice_json | indent(8) }},
|
||||||
|
{% if kea_dhcp__dhcp6['hooks-libraries'] is defined and kea_dhcp__dhcp6['hooks-libraries'] %}
|
||||||
|
"hooks-libraries": {{ kea_dhcp__dhcp6['hooks-libraries'] | to_nice_json | indent(8) }},
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
This option isn't documented in the README. This option isn't documented in the README.
|
|||||||
|
{% endif %}
|
||||||
|
{% if kea_dhcp__dhcp6['option-data'] is defined and kea_dhcp__dhcp6['option-data'] %}
|
||||||
|
"option-data": {{ kea_dhcp__dhcp6['option-data'] | to_nice_json | indent(8) }},
|
||||||
|
{% endif %}
|
||||||
|
"loggers": {{ kea_dhcp__dhcp6['logging'] | to_nice_json | indent(8) }}{% if kea_dhcp__dhcp6.subnets is defined and kea_dhcp__dhcp6.subnets %},{% endif %}
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
This option isn't documented in the README. This option isn't documented in the README.
|
|||||||
|
{% if kea_dhcp__dhcp6.subnets is defined and kea_dhcp__dhcp6.subnets %}
|
||||||
|
"subnet6": [
|
||||||
|
{% for subnet in kea_dhcp__dhcp6.subnets %}
|
||||||
|
{
|
||||||
|
"id": {{ subnet.id }},
|
||||||
|
"subnet": "{{ subnet.subnet }}",
|
||||||
|
"interface": "{{ subnet.interface }}",
|
||||||
|
"allocator": "{{ subnet.allocator | default("iterative") }}",
|
||||||
|
"pools": {{ subnet.pools | to_nice_json | indent(16) }},
|
||||||
|
{% if subnet.reservations is defined and subnet.reservations %}
|
||||||
|
"reservations": {{ subnet.reservations | to_nice_json | indent(16) }},
|
||||||
|
{% endif %}
|
||||||
|
{% if subnet['option-data'] is defined and subnet['option-data'] %}
|
||||||
|
"option-data": {{ subnet['option-data'] | to_nice_json | indent(16) }}
|
||||||
|
{% endif %}
|
||||||
|
}{% if not loop.last %},{% endif %}
|
||||||
|
|
||||||
|
{% endfor %}
|
||||||
|
]
|
||||||
|
{% endif %}
|
||||||
|
}
|
||||||
|
}
|
||||||
12
roles/kea_dhcp/templates/stork-agent.env.j2
Normal file
|
|
@ -0,0 +1,12 @@
|
||||||
|
# See example config at: https://gitlab.isc.org/isc-projects/stork/-/blob/stable/etc/agent.env?ref_type=tags
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I would just get rid of all the commented out options, if we don't use them anyway (and instead maybe link to a full-fledged config example from the docs or something). I would just get rid of all the commented out options, if we don't use them anyway (and instead maybe link to a full-fledged config example from the docs or something).
(https://git.hamburg.ccc.de/CCCHH/ansible-infra/pulls/98#issuecomment-4660)
|
|||||||
|
|
||||||
|
{% if kea_dhcp__stork_agent.prometheus_only %}
|
||||||
|
### listen for Prometheus requests only, but not for commands from the Stork server
|
||||||
|
STORK_AGENT_LISTEN_PROMETHEUS_ONLY=true
|
||||||
|
{% endif %}
|
||||||
|
|
||||||
|
### Logging parameters
|
||||||
|
|
||||||
|
### Set logging level. Supported values are: DEBUG, INFO, WARN, ERROR
|
||||||
|
STORK_LOG_LEVEL=DEBUG
|
||||||
|
|
||||||
|
|
@ -22,3 +22,10 @@ None.
|
||||||
Defaults to `root`.
|
Defaults to `root`.
|
||||||
- `secrets__secrets.*.mode`: The mode of the secret file.
|
- `secrets__secrets.*.mode`: The mode of the secret file.
|
||||||
Defaults to `0640`.
|
Defaults to `0640`.
|
||||||
|
- `secrets__folder.owner`: The owner of `/etc/ansible_secrets`.
|
||||||
|
Defaults to `root`.
|
||||||
|
- `secrets__folder.group`: The group of `/etc/ansible_secrets`.
|
||||||
|
Defaults to `root`.
|
||||||
|
- `secrets__folder.mode`: The mode of `/etc/ansible_secrets`.
|
||||||
|
Defaults to `0750`.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -4,3 +4,13 @@ argument_specs:
|
||||||
secrets__secrets:
|
secrets__secrets:
|
||||||
type: list
|
type: list
|
||||||
required: false
|
required: false
|
||||||
|
secrets__folder:
|
||||||
|
owner:
|
||||||
|
type: string
|
||||||
|
required: false
|
||||||
|
group:
|
||||||
|
type: string
|
||||||
|
required: false
|
||||||
|
mode:
|
||||||
|
type: string
|
||||||
|
required: false
|
||||||
|
|
|
||||||
|
|
@ -35,9 +35,9 @@
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: "/etc/ansible_secrets"
|
path: "/etc/ansible_secrets"
|
||||||
state: directory
|
state: directory
|
||||||
owner: root
|
owner: "{{ secrets__folder.owner | default('root') }}"
|
||||||
group: root
|
group: "{{ secrets__folder.group | default('root') }}"
|
||||||
mode: "0750"
|
mode: "{{ secrets__folder.mode | default('0750') }}"
|
||||||
become: true
|
become: true
|
||||||
|
|
||||||
- name: ensure secrets are present
|
- name: ensure secrets are present
|
||||||
|
|
|
||||||
28
roles/unbound/README.md
Normal file
|
|
@ -0,0 +1,28 @@
|
||||||
|
# Unbound DNS resolver
|
||||||
|
|
||||||
|
Role for a validating, recursive, caching DNS resolver based on [Unbound](https://nlnetlabs.nl/projects/unbound/about/).
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
Spelling "fora" -> "for". Spelling "fora" -> "for".
|
|||||||
|
It is designed to be fast and lean and incorporates modern features based on open standards.
|
||||||
|
|
||||||
|
- [Documentation](https://unbound.docs.nlnetlabs.nl/en/latest/)
|
||||||
|
|
||||||
|
## Role Customization
|
||||||
|
|
||||||
|
The following variables can be used to customize this role:
|
||||||
|
|
||||||
|
- `unbound_install_prometheus_exporter`: Boolean of whether [Unbound Exporter](https://github.com/letsencrypt/unbound_exporter) should also be installed to expose resolver statistics in prometheus format.
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I think it would be nice to stick to the list format used in all the other roles for the sake of consistency. I think it would be nice to stick to the list format used in all the other roles for the sake of consistency.
|
|||||||
|
Defaults to `true`.
|
||||||
|
- `unbound_bind_interfaces`: List of interface names or IP addresseson which unbound will listen for dns queries.
|
||||||
|
Defaults to `[0.0.0.0, ::]`.
|
||||||
|
- `unbound_enable_unbound_control`: Boolean of whether the [remote control](https://unbound.docs.nlnetlabs.nl/en/latest/getting-started/configuration.html#set-up-remote-control) feature of unbound should be configured.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `unbound_enable_dnssec`: Boolean of whether dnssec validation should be enabled.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `unbound_access_control`: **Required** List of [unbound access control values](https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound.conf.html#:~:text=access-control:%20%3CIP%20netblock%3E%20%3Caction%3E).
|
||||||
|
Defaults to `[]`.
|
||||||
|
- `unbound_disable_systemd_networkd`: Boolean if true, systemd-networkd is disabled and the local system is pointed towards the configured dns resolver.
|
||||||
|
Defaults to `true`.
|
||||||
|
- `unbound_thread_count`: The number of threads unbound uses.
|
||||||
|
Defaults to max vCPU Count.
|
||||||
|
- `unbound_private_domain`: List of domains from witch unbound for the domain and its subdomains to allows resolving of RFC1918 addresses. (Not relevent on Debian)
|
||||||
|
Defaults to `[]`
|
||||||
|
|
||||||
7
roles/unbound/defaults/main.yml
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
unbound_install_prometheus_exporter: true
|
||||||
|
unbound_bind_interfaces: [ "0.0.0.0", "::" ]
|
||||||
|
unbound_disable_systemd_networkd: true
|
||||||
|
unbound_enable_unbound_control: true
|
||||||
|
unbound_enable_dnssec: true
|
||||||
|
unbound_access_control: [ ]
|
||||||
|
unbound_private_domain: [ ]
|
||||||
12
roles/unbound/files/prometheus-unbound-exporter.service
Normal file
|
|
@ -0,0 +1,12 @@
|
||||||
|
[Unit]
|
||||||
|
Description=Prometheus exporter for Unbound metrics, written in Go with pluggable metric collectors. The metrics exporter converts Unbound metric names to Prometheus metric names and labels by using a set of regular expressions.
|
||||||
|
Documentation=https://github.com/letsencrypt/unbound_exporter
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
EnvironmentFile=/etc/prometheus-unbound-exporter.conf
|
||||||
|
ExecStart=/bin/unbound_exporter $UNBOUND_EXPORTER_ARGS
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
17
roles/unbound/handlers/main.yml
Normal file
|
|
@ -0,0 +1,17 @@
|
||||||
|
- name: unbound.restarted
|
||||||
|
become: true
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Again, same comment as in the kea role, I don't think it makes sense to have granular tags in the role itself. Again, same comment as in the kea role, I don't think it makes sense to have granular tags in the role itself.
|
|||||||
|
ansible.builtin.systemd:
|
||||||
|
name: unbound.service
|
||||||
|
state: restarted
|
||||||
|
|
||||||
|
- name: prometheus-unbound-exporter.restarted
|
||||||
|
become: true
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
I think this handler isn't in use, is it? I think this handler isn't in use, is it?
|
|||||||
|
ansible.builtin.systemd:
|
||||||
|
name: prometheus-unbound-exporter.service
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: systemd-daemon-reload
|
||||||
|
become: true
|
||||||
|
ansible.builtin.systemd_service:
|
||||||
|
daemon_reload: true
|
||||||
54
roles/unbound/tasks/main.yml
Normal file
|
|
@ -0,0 +1,54 @@
|
||||||||
|
- name: install unbound dns resolver
|
||||||||
|
become: true
|
||||||||
|
ansible.builtin.package:
|
||||||||
|
stb marked this conversation as resolved
Outdated
june
commented
If all tasks are in the block, then this doesn't need to be a block. If all tasks are in the block, then this doesn't need to be a block.
|
|||||||||
|
name: unbound
|
||||||||
|
|
||||||||
|
- name: install unbound-anchor
|
||||||||
|
become: true
|
||||||||
|
ansible.builtin.package:
|
||||||||
|
name: unbound-anchor
|
||||||||
|
|
||||||||
|
- name: ensure correct directory permissions
|
||||||||
|
become: true
|
||||||||
|
ansible.builtin.file:
|
||||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
There is no Line 30 in 7832978
There is no `bind` package on Debian and we already install `dig` in the `base_config` role: https://git.hamburg.ccc.de/CCCHH/ansible-infra/src/commit/7832978ff732208f2f29f04ef446c7c51076c6d1/roles/base_config/tasks/main.yaml#L30
|
|||||||||
|
path: /etc/unbound
|
||||||||
|
state: directory
|
||||||||
|
mode: u=rwX,g=rX,o=rX
|
||||||||
|
recurse: true
|
||||||||
|
owner: unbound
|
||||||||
|
group: unbound
|
||||||||
|
|
||||||||
|
- name: configure unbound dns resolver
|
||||||||
|
become: true
|
||||||||
|
notify: unbound.restarted
|
||||||||
|
ansible.builtin.template:
|
||||||||
|
src: unbound.conf.j2
|
||||||||
|
dest: /etc/unbound/unbound.conf
|
||||||||
|
owner: unbound
|
||||||||
|
group: unbound
|
||||||||
|
mode: u=rw,g=r,o=r
|
||||||||
|
|
||||||||
|
- name: disable systemd-resolved
|
||||||||
|
when: unbound_disable_systemd_networkd
|
||||||||
|
ansible.builtin.include_role:
|
||||||||
|
name: deploy_systemd_resolved_config
|
||||||||
|
vars:
|
||||||||
|
deploy_systemd_resolved_config__enable: false
|
||||||||
|
deploy_systemd_resolved_config__dns:
|
||||||||
|
- 127.0.0.1
|
||||||||
|
deploy_systemd_resolved_config__fallback_dns:
|
||||||||
|
- 127.0.0.1
|
||||||||
|
|
||||||||
|
- name: flush handlers
|
||||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
We have a nice role for managing systemd-resolved already, so no need to duplicate functionality here. We have a nice role for managing systemd-resolved already, so no need to duplicate functionality here.
See: https://git.hamburg.ccc.de/CCCHH/ansible-infra/src/commit/7832978ff732208f2f29f04ef446c7c51076c6d1/roles/deploy_systemd_resolved_config
|
|||||||||
|
ansible.builtin.meta: flush_handlers
|
||||||||
|
|
||||||||
|
- name: ensure unbound is running and enabled
|
||||||||
|
become: true
|
||||||||
|
ansible.builtin.systemd:
|
||||||||
|
name: unbound.service
|
||||||||
|
state: started
|
||||||||
|
enabled: true
|
||||||||
|
|
||||||||
|
- name: install and configure prometheus-exporter for unbound
|
||||||||
|
ansible.builtin.import_tasks: prometheus-exporter.yml
|
||||||||
|
when: unbound_install_prometheus_exporter
|
||||||||
63
roles/unbound/tasks/prometheus-exporter.yml
Normal file
|
|
@ -0,0 +1,63 @@
|
||||||
|
---
|
||||||
|
- name: install unbound prometheus exporter
|
||||||
|
become: true
|
||||||
|
vars:
|
||||||
|
june marked this conversation as resolved
Outdated
june
commented
There's no There's no `unbound-prometheus-exporter` package on Debian.
|
|||||||
|
prometheus_unbound_exporter_version: "0.6.0"
|
||||||
|
prometheus_unbound_exporter_filename: "unbound_exporter-v{{ prometheus_unbound_exporter_version }}.x86_64.deb"
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
I would rather move the enable and start logic into the file itself, since that's not really the job of a handler. See the main unbound setup tasks for reference. I would rather move the enable and start logic into the file itself, since that's not really the job of a handler. See the main unbound setup tasks for reference.
|
|||||||
|
prometheus_unbound_exporter_github_api_url: "https://api.github.com/repos/letsencrypt/unbound_exporter/releases/tags/v{{ prometheus_unbound_exporter_version }}"
|
||||||
|
block:
|
||||||
|
- name: request github api
|
||||||
|
ansible.builtin.uri:
|
||||||
|
url: "{{ prometheus_unbound_exporter_github_api_url }}"
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
If we hardcode the version anyway, I think we should first check, if this version is already installed locally and only then hit the GitHub API. This avoids unnecessary steps and also avoids hitting the unreliable GitHub API for every run. If we hardcode the version anyway, I think we should first check, if this version is already installed locally and only then hit the GitHub API. This avoids unnecessary steps and also avoids hitting the unreliable GitHub API for every run.
One could either use apt (via a command or facts maybe?) to check for the installed version and only get a new one, if they differ or just keep the latest dep as a sort of canary file or something and only get a new one, if it isn't as expected.
Something similar is done for the Forgejo Runner installation, see https://git.hamburg.ccc.de/CCCHH/ansible-infra/src/commit/5ecf70ade373737ffef3a9766ab7b70d28fbe9a1/roles/forgejo_runner/tasks/main/01_install.yaml , tho this doesn't use apt, so can't really be adapted.
|
|||||||
|
method: GET
|
||||||
|
body_format: json
|
||||||
|
headers:
|
||||||
|
'Accept': 'application/vnd.github+json'
|
||||||
|
register: unbound_exporter_github_api_result
|
||||||
|
|
||||||
|
- name: get prometheus-unbound-exporter download url and digest
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
unbound_exporter_download_url: "{{ unbound_exporter_github_api_result.json.assets[0].browser_download_url }}"
|
||||||
|
unbound_exporter_download_digest: "{{ unbound_exporter_github_api_result.json.assets[0].digest }}"
|
||||||
|
|
||||||
|
- name: Download prometheus-unbound-exporter deb package with verified checksum
|
||||||
|
ansible.builtin.get_url:
|
||||||
|
url: "{{ unbound_exporter_download_url }}"
|
||||||
|
dest: "/tmp/{{ prometheus_unbound_exporter_filename }}"
|
||||||
|
checksum: "{{ unbound_exporter_download_digest }}"
|
||||||
|
mode: "u=r,g=r,o=r"
|
||||||
|
|
||||||
|
- name: Install prometheus-unbound-exporter deb package
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
deb: "/tmp/{{ prometheus_unbound_exporter_filename }}"
|
||||||
|
state: present
|
||||||
|
notify: prometheus-unbound-exporter.restarted
|
||||||
|
|
||||||
|
- name: deploy prometheus-unbound-exporter systemd service
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "prometheus-unbound-exporter.service"
|
||||||
|
dest: "/etc/systemd/system/prometheus-unbound-exporter.service"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify: systemd-daemon-reload
|
||||||
|
|
||||||
|
- name: enable unbound prometheus exporter
|
||||||
|
become: true
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: prometheus-unbound-exporter.service
|
||||||
|
enabled: true
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: configure unbound exporter
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /etc/prometheus-unbound-exporter.conf
|
||||||
|
content: |
|
||||||
|
UNBOUND_EXPORTER_ARGS="-unbound.ca "" -unbound.cert "" -unbound.host "unix:///run/unbound.ctl"
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify: prometheus-unbound-exporter.restarted
|
||||||
69
roles/unbound/templates/unbound.conf.j2
Normal file
|
|
@ -0,0 +1,69 @@
|
||||||
|
# ref: https://unbound.docs.nlnetlabs.nl/en/latest/manpages/unbound.conf.html
|
||||||
|
# unbound.conf(5) man page
|
||||||
|
server:
|
||||||
|
{% if unbound_enable_dnssec -%}
|
||||||
|
# location of the trust anchor file that enables DNSSEC
|
||||||
|
# this file is generated by the `unbound-anchor` command
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Is this still relevant on Debian? Again, we don't use Arch Linux in our infra. Is this still relevant on Debian? Again, we don't use Arch Linux in our infra.
|
|||||||
|
trust-anchor-file: "/usr/share/dns/root.key"
|
||||||
|
{% endif -%}
|
||||||
|
|
||||||
|
# num of threads
|
||||||
|
num-threads: {{ unbound_thread_count | default(ansible_facts['processor_vcpus']) }}
|
||||||
|
|
||||||
|
# more cache memory
|
||||||
|
rrset-cache-size: 60m
|
||||||
|
msg-cache-size: 30m
|
||||||
|
bitwhisker marked this conversation as resolved
Outdated
june
commented
Are those all the CPUs we use? Might it make sense to have this configurable or at least change the comment? Are those all the CPUs we use? Might it make sense to have this configurable or at least change the comment?
|
|||||||
|
|
||||||
|
# prefetch to keep the cache up to date
|
||||||
|
prefetch: yes
|
||||||
|
|
||||||
|
# fetch the DNSKEYs earlier in the validation process, when a DS record is encountered
|
||||||
|
prefetch-key: yes
|
||||||
|
|
||||||
|
# Faster UDP with multithreading (only on Linux).
|
||||||
|
so-reuseport: yes
|
||||||
|
|
||||||
|
# disable special large send buffer handling and just use kernel defaults
|
||||||
|
so-sndbuf: 0
|
||||||
|
|
||||||
|
# send minimal amount of information to upstream servers to enhance privacy
|
||||||
|
qname-minimisation: yes
|
||||||
|
|
||||||
|
# specify the interface to answer queries from by ip-address.
|
||||||
|
{% for i in unbound_bind_interfaces -%}
|
||||||
|
interface: "{{ i }}"
|
||||||
|
{% endfor %}
|
||||||
|
|
||||||
|
# addresses from the IP range that are allowed to connect to the resolver
|
||||||
|
{% for i in unbound_access_control -%}
|
||||||
|
access-control: {{ i }} allow
|
||||||
|
{% endfor -%}
|
||||||
|
|
||||||
|
{% for i in unbound_private_domain -%}
|
||||||
|
stb marked this conversation as resolved
Outdated
june
commented
This setting is missing from documentation in the README. This setting is missing from documentation in the README.
|
|||||||
|
private-domain: {{ i }}
|
||||||
|
{% endfor -%}
|
||||||
|
|
||||||
|
# The number of seconds between printing statistics to the log for every thread.
|
||||||
|
statistics-interval: 0
|
||||||
|
|
||||||
|
# Extended statistics are printed, Keeping track of more statistics takes time.
|
||||||
|
extended-statistics: yes
|
||||||
|
|
||||||
|
remote-control:
|
||||||
|
control-enable: {{ "yes" if unbound_enable_unbound_control else "no" }}
|
||||||
|
control-interface: "/run/unbound.ctl" # debian appamour does not allow any other path!!!
|
||||||
|
control-use-cert: no
|
||||||
|
|
||||||
|
|
||||||
|
# configure some zones for which this resolver will act authoritatively
|
||||||
|
# https://www.dns.icann.org/services/axfr/
|
||||||
|
{% for i in [ ".", "in-addr.arpa.", "arpa.", "root-servers.net.", "ip6.arpa.", "ip6-servers.arpa.", "mcast.net." ] %}
|
||||||
|
auth-zone:
|
||||||
|
name: "{{ i }}"
|
||||||
|
primary: "lax.xfr.dns.icann.org"
|
||||||
|
primary: "iad.xfr.dns.icann.org"
|
||||||
|
fallback-enabled: yes
|
||||||
|
for-downstream: no
|
||||||
|
for-upstream: yes
|
||||||
|
|
||||||
|
{% endfor %}
|
||||||
This sentence is now grammatically incorrect. Maybe: "Diverse VMs im z9 (PVE Cluster)"?