Add an RPZ blocklist on the Unbound resolvers that returns NXDOMAIN for a set of domains (and subdomains) and logs only those matches under rpz-log tag "blocklist". Domains are templated from resolver_blocked_domains (single source of truth) into /etc/unbound/blocklist.rpz; respip module enabled for RPZ support. Fix deprecation warnings across the Ansible tree: - apt_repository -> deb822_repository (monitor, aprsc, uisp, grafana), removing stale .list files and adding update_cache where deb822 drops it - community.mysql.* -> ansible.mysql.* (monitor) and requirements.yml - top-level facts -> ansible_facts[...] (ansible_os_family, distribution_release, fqdn, architecture, default_ipv4) repo-wide
49 lines
1.5 KiB
Django/Jinja
Executable file
49 lines
1.5 KiB
Django/Jinja
Executable file
{% if ansible_facts['fqdn'] in groups['ntp'] %}
|
|
driftfile /var/lib/ntp/ntp.drift
|
|
|
|
statistics loopstats peerstats clockstats
|
|
filegen loopstats file loopstats type day enable
|
|
filegen peerstats file peerstats type day enable
|
|
filegen clockstats file clockstats type day enable
|
|
|
|
# GPS Serial data reference
|
|
#server 127.127.28.0 minpoll 4 maxpoll 4
|
|
#fudge 127.127.28.0 time1 0.0 refid GPS
|
|
|
|
# GPS PPS reference
|
|
server 127.127.28.1 minpoll 4 maxpoll 4 prefer
|
|
fudge 127.127.28.1 refid PPS
|
|
|
|
pool us.pool.ntp.org iburst
|
|
|
|
restrict -4 default kod notrap nomodify nopeer noquery limited
|
|
restrict -6 default kod notrap nomodify nopeer noquery limited
|
|
|
|
# Local users may interrogate the ntp server more closely.
|
|
restrict 127.0.0.1
|
|
restrict ::1
|
|
|
|
# Needed for adding pool entries
|
|
restrict source notrap nomodify noquery
|
|
|
|
{% else %}
|
|
driftfile /var/lib/ntp/ntp.drift
|
|
|
|
statistics loopstats peerstats clockstats
|
|
filegen loopstats file loopstats type day enable
|
|
filegen peerstats file peerstats type day enable
|
|
filegen clockstats file clockstats type day enable
|
|
|
|
# By default, exchange time with everybody, but don't allow configuration.
|
|
restrict -4 default kod notrap nomodify nopeer noquery limited
|
|
restrict -6 default kod notrap nomodify nopeer noquery limited
|
|
|
|
# Local users may interrogate the ntp server more closely.
|
|
restrict 127.0.0.1
|
|
restrict ::1
|
|
|
|
server {{ ntpserver | default('0.us.pool.ntp.org') }}
|
|
|
|
# Needed for adding pool entries
|
|
restrict source notrap nomodify noquery
|
|
{% endif %}
|