289 lines
7.6 KiB
YAML
Executable file
289 lines
7.6 KiB
YAML
Executable file
---
|
|
- name: Apply common configuration to all nodes
|
|
hosts: all
|
|
become: true
|
|
# become_method: sudo
|
|
gather_facts: true
|
|
remote_user: ansible
|
|
roles:
|
|
- base
|
|
tags:
|
|
- common
|
|
|
|
tasks:
|
|
- name: Set timezone
|
|
community.general.timezone:
|
|
name: "{{ timezone }}"
|
|
|
|
# Resolver play disabled - no hosts in resolvers group
|
|
#- name: Apply resolver config
|
|
# hosts: resolvers
|
|
# gather_facts: true
|
|
# roles:
|
|
# - { role: resolvers, become: true }
|
|
|
|
# NS play disabled - replaced by BIND9 play below
|
|
#- name: Apply ns config
|
|
# hosts: ns
|
|
# gather_facts: true
|
|
# become: true
|
|
# roles:
|
|
# - role: ns
|
|
|
|
# NetBox plays disabled - no hosts in netbox group
|
|
#- name: Apply netbox config
|
|
# hosts: netbox
|
|
# gather_facts: true
|
|
# become: true
|
|
# roles:
|
|
# - role: caddy_ansible.caddy_ansible
|
|
# caddy_systemd_network_dependency: true
|
|
# caddy_setcap: true
|
|
# caddy_systemd_capabilities_enabled: true
|
|
# caddy_systemd_capabilities: "CAP_NET_BIND_SERVICE"
|
|
# caddy_config: |
|
|
# {{ netbox.domain }} {
|
|
# bind {{ netbox.bind_address }}
|
|
# log {
|
|
# level error
|
|
# }
|
|
# route /static* {
|
|
# uri strip_prefix /static
|
|
# root * /opt/netbox/netbox/static
|
|
# file_server
|
|
# }
|
|
# @notStatic not path /static*
|
|
# encode gzip zstd
|
|
# reverse_proxy @notStatic http://localhost:{{ netbox.port }} {
|
|
# header_up Host {http.request.host}
|
|
# header_up X-Real-IP {http.request.remote.host}
|
|
# header_up X-Forwarded-For {http.request.remote.host}
|
|
# header_up X-Forwarded-Port {http.request.port}
|
|
# header_up X-Forwarded-Proto {http.request.scheme}
|
|
# }
|
|
# }
|
|
#
|
|
#- name: Apply firewall rules to netbox
|
|
# hosts: netbox
|
|
# become: true
|
|
# # remote_user: graham
|
|
# handlers:
|
|
# - import_tasks: playbook_handlers.yml
|
|
#
|
|
# tasks:
|
|
# - name: Permit traffic in default zone for http service
|
|
# ansible.posix.firewalld:
|
|
# zone: public
|
|
# service: http
|
|
# permanent: true
|
|
# state: enabled
|
|
#
|
|
# - name: Permit traffic in default zone for https service
|
|
# ansible.posix.firewalld:
|
|
# zone: public
|
|
# service: https
|
|
# permanent: true
|
|
# state: enabled
|
|
# notify:
|
|
# - Restart firewalld
|
|
|
|
# Tailscale play disabled - no hosts in tailscale_home group
|
|
#- name: Tailscale
|
|
# hosts: tailscale_home
|
|
# become: true
|
|
# gather_facts: true
|
|
# vars:
|
|
# inject_facts_as_vars: false
|
|
# roles:
|
|
# - role: artis3n.tailscale
|
|
# vars:
|
|
# # Pull Tailscale auth key from environment variable
|
|
# tailscale_authkey: "{{ lookup('ansible.builtin.env', 'TAILSCALE_KEY') }}"
|
|
# tailscale_args: "--ssh --advertise-exit-node"
|
|
# pre_tasks:
|
|
# - name: Debug - Check Tailscale key (will be partially redacted)
|
|
# debug:
|
|
# msg: "Key exists and starts with: {{ lookup('ansible.builtin.env', 'TAILSCALE_KEY')[0:10] }}..."
|
|
|
|
- name: Install and configure Caddy
|
|
hosts: caddy_servers
|
|
become: true
|
|
tags:
|
|
- caddy
|
|
roles:
|
|
- caddy
|
|
|
|
- name: Configure PostgreSQL servers
|
|
hosts: postgresql_servers
|
|
become: true
|
|
gather_facts: true
|
|
tags:
|
|
- postgresql
|
|
- database
|
|
|
|
pre_tasks:
|
|
- name: Set hostname
|
|
hostname:
|
|
name: "{{ inventory_hostname }}"
|
|
|
|
- name: Update /etc/hosts
|
|
lineinfile:
|
|
path: /etc/hosts
|
|
regexp: '^127\.0\.1\.1'
|
|
line: "127.0.1.1 {{ inventory_hostname }}"
|
|
state: present
|
|
|
|
- name: Update apt cache
|
|
apt:
|
|
update_cache: yes
|
|
cache_valid_time: 3600
|
|
|
|
- name: Install Python dependencies for Ansible
|
|
apt:
|
|
name:
|
|
- python3-apt
|
|
- python3-psycopg2
|
|
state: present
|
|
|
|
roles:
|
|
- raid
|
|
- postgresql
|
|
|
|
- name: Provision BIND9 VM on Proxmox
|
|
hosts: localhost
|
|
gather_facts: false
|
|
tags:
|
|
- dns
|
|
- bind9
|
|
- provision
|
|
- never
|
|
vars:
|
|
# Proxmox connection settings (matches terraform/variables.tf)
|
|
proxmox_node: "{{ lookup('env', 'PROXMOX_NODE') | default('vm2-380', true) }}"
|
|
proxmox_api_host: 10.0.0.2
|
|
proxmox_api_user: "{{ lookup('env', 'PROXMOX_API_USER') | default('root@pam', true) }}"
|
|
proxmox_api_password: "{{ lookup('env', 'PROXMOX_API_PASSWORD') }}"
|
|
proxmox_storage: local-lvm
|
|
proxmox_template_name: debian-cloud-init
|
|
proxmox_template_vmid: 9000
|
|
|
|
# BIND9 VM configuration
|
|
vm_name: ns1.as393837.net
|
|
vm_vmid: 222
|
|
vm_ip: 204.110.191.222
|
|
vm_gateway: 204.110.191.254
|
|
vm_netmask: 255.255.255.224
|
|
vm_cores: 2
|
|
vm_memory: 2048
|
|
vm_disk_size: 64
|
|
ansible_ssh_key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFghGMnDdkfNC6JPEhMxrKhYDmNcXjHXp/y/mf3uLtzb"
|
|
|
|
tasks:
|
|
- name: Clone cloud-init template for BIND9 server
|
|
community.proxmox.proxmox_kvm:
|
|
node: "{{ proxmox_node }}"
|
|
vmid: "{{ proxmox_template_vmid }}"
|
|
clone: "{{ proxmox_template_name }}"
|
|
newid: "{{ vm_vmid }}"
|
|
name: "{{ vm_name }}"
|
|
api_user: "{{ proxmox_api_user }}"
|
|
api_password: "{{ proxmox_api_password }}"
|
|
api_host: "{{ proxmox_api_host }}"
|
|
storage: "{{ proxmox_storage }}"
|
|
timeout: 90
|
|
full: true
|
|
|
|
- name: Configure VM resources
|
|
community.proxmox.proxmox_kvm:
|
|
node: "{{ proxmox_node }}"
|
|
vmid: "{{ vm_vmid }}"
|
|
name: "{{ vm_name }}"
|
|
api_user: "{{ proxmox_api_user }}"
|
|
api_password: "{{ proxmox_api_password }}"
|
|
api_host: "{{ proxmox_api_host }}"
|
|
cores: "{{ vm_cores }}"
|
|
memory: "{{ vm_memory }}"
|
|
update: true
|
|
|
|
- name: Resize disk
|
|
community.proxmox.proxmox_disk:
|
|
vmid: "{{ vm_vmid }}"
|
|
api_user: "{{ proxmox_api_user }}"
|
|
api_password: "{{ proxmox_api_password }}"
|
|
api_host: "{{ proxmox_api_host }}"
|
|
disk: scsi0
|
|
size: "{{ vm_disk_size }}G"
|
|
state: resized
|
|
|
|
- name: Configure cloud-init network
|
|
community.proxmox.proxmox_kvm:
|
|
node: "{{ proxmox_node }}"
|
|
vmid: "{{ vm_vmid }}"
|
|
name: "{{ vm_name }}"
|
|
api_user: "{{ proxmox_api_user }}"
|
|
api_password: "{{ proxmox_api_password }}"
|
|
api_host: "{{ proxmox_api_host }}"
|
|
ipconfig:
|
|
ipconfig0: "ip={{ vm_ip }}/26,gw={{ vm_gateway }}"
|
|
nameservers:
|
|
- 1.1.1.1
|
|
- 8.8.8.8
|
|
ciuser: debian
|
|
cipassword: "sxcbctolxALGnj2R8GStXrfW8GVd3s/ju91fNon7T1U="
|
|
update: true
|
|
|
|
- name: Start VM
|
|
community.proxmox.proxmox_kvm:
|
|
node: "{{ proxmox_node }}"
|
|
vmid: "{{ vm_vmid }}"
|
|
name: "{{ vm_name }}"
|
|
api_user: "{{ proxmox_api_user }}"
|
|
api_password: "{{ proxmox_api_password }}"
|
|
api_host: "{{ proxmox_api_host }}"
|
|
state: started
|
|
|
|
- name: Wait for VM to be accessible via SSH
|
|
wait_for:
|
|
host: "{{ vm_ip }}"
|
|
port: 22
|
|
delay: 30
|
|
timeout: 300
|
|
state: started
|
|
|
|
- name: Add VM to in-memory inventory
|
|
add_host:
|
|
name: "{{ vm_name }}"
|
|
ansible_host: "{{ vm_ip }}"
|
|
groups: bind9_servers
|
|
|
|
- name: Configure BIND9 Servers
|
|
hosts: bind9_servers
|
|
become: yes
|
|
gather_facts: true
|
|
tags:
|
|
- dns
|
|
- bind9
|
|
roles:
|
|
- role: base
|
|
tags: base
|
|
- role: ns
|
|
tags: ns
|
|
|
|
# Plays from general.yml
|
|
- name: Apply general configuration to all nodes
|
|
hosts: all
|
|
become: yes
|
|
become_method: sudo
|
|
roles:
|
|
- general
|
|
tags:
|
|
- general
|
|
|
|
# Syncthing play disabled - no hosts in syncthing_servers group
|
|
#- name: Syncthing servers
|
|
# hosts: syncthing_servers
|
|
# become: yes
|
|
# become_method: sudo
|
|
# tags: syncthing
|
|
# roles:
|
|
# - syncthing
|