add nginx, sshd, ssl roles

This commit is contained in:
2026-09-20 22:14:56 +00:00
parent ba9e1a664f
commit c640406c10
131 changed files with 1535 additions and 780 deletions
+13
View File
@@ -0,0 +1,13 @@
---
- name: validate haproxy config
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
changed_when: false
listen: restart haproxy
- name: restart haproxy systemd service unit
ansible.builtin.systemd_service:
name: haproxy
daemon_reload: true
state: restarted
enabled: true
listen: restart haproxy
+10
View File
@@ -0,0 +1,10 @@
---
- name: render haproxy config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
notify: restart haproxy
+6
View File
@@ -0,0 +1,6 @@
---
- name: install haproxy
ansible.builtin.apt:
name: haproxy
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,90 @@
global
log /dev/log local2
chroot /var/lib/haproxy
maxconn 4000
user haproxy
group haproxy
daemon
stats socket /var/lib/haproxy/stats mode 660 level admin
defaults
log global
mode tcp
option tcplog
option dontlognull
retries 3
timeout connect 5s
timeout client 1h
timeout server 1h
timeout check 10s
frontend http_frontend
bind 127.0.0.1:10080
mode http
option httplog
acl host_dttx hdr_end(host) -m end dttx.ru
use_backend dttx_http_srv if host_dttx
default_backend oyacoi_http_srv
backend oyacoi_http_srv
mode http
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
backend dttx_http_srv
mode http
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
frontend https_frontend
bind 127.0.0.1:10443
mode tcp
option tcplog
tcp-request inspect-delay 5s
tcp-request content accept if { req_ssl_hello_type 1 }
acl host_dttx req_ssl_sni -m end dttx.ru
acl host_telemt req_ssl_sni -m end regionculture.ru
use_backend dttx_https_srv if host_dttx
use_backend telemt_https_srv if host_telemt
default_backend oyacoi_https_srv
backend oyacoi_https_srv
mode tcp
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
backend dttx_https_srv
mode tcp
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
backend telemt_https_srv
mode tcp
option tcp-check
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
listen mcsmanager_service
bind {{ hostvars['liqueur']['container_ip'] }}:24444
mode tcp
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
listen xmpp_c2s
bind {{ hostvars['liqueur']['container_ip'] }}:5222
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
listen xmpp_legacy_ssl
bind {{ hostvars['liqueur']['container_ip'] }}:5223
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
listen xmpp_s2s
bind {{ hostvars['liqueur']['container_ip'] }}:5269
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
listen prosody_proxy65
bind {{ hostvars['liqueur']['container_ip'] }}:5000
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
listen prosody_components
bind {{ hostvars['liqueur']['container_ip'] }}:5270
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
listen prosody_bosh_http
bind {{ hostvars['liqueur']['container_ip'] }}:5280
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280