Compare commits

..
2 Commits
174 changed files with 2162 additions and 708 deletions
+4
View File
@@ -0,0 +1,4 @@
locale_default: en_US.UTF-8
locales_list:
- en_US.UTF-8
- ru_RU.UTF-8
-4
View File
@@ -1,4 +0,0 @@
nft_managed_group: all
dnsmasq_managed_group: all
xray_managed_group: all
xray_core_group: all
+1
View File
@@ -0,0 +1 @@
timezone_name: Europe/Samara
-103
View File
@@ -1,103 +0,0 @@
$ANSIBLE_VAULT;1.1;AES256
36306165333832633935626535303038333964363533393135303736393561653763666534626538
3931363931616363643366656130616236646538303737380a343234643634316632326137613535
64316133356635323935623162366533313563316335376439336534323234623038373038373361
3933353334353939660a656163383564313632393434653435376437643538613138383764336364
35356235666661303736373335333139653530346335313731343136303039396661633164383433
35373935633136343764356439333865303032353864373138313736623666626563343362626264
63613261376163326633626234376339326132303930396562356631306463316361643334643938
62616665346336373630393833626430386233343539636336383539383232643766386339323433
31313764356338643533383637303165393064303233373363656435623261653763376138333863
62643366303866656433376561323739393334663361653166653366303835373863633737316231
64383336373535343539633365616562386361353532373465386461363863393266313237626634
61656663373833376330316631653161373130303639313231306134323630356335383561316564
61343835333533633166316431323234383837393734313630643065313132396234343064343764
39353865633865333862666364666434386533313534306236346133663031393664353664336362
34616438356337303536613832386635353565653362366533386436626564613038333938646561
37643931653633323165303638336535366337643465376335366135373331336633356466366630
38356535303438626438646239303933373366363836336364613333336234343033343932346561
64343834353638323235616466346130353431333864386637653636346536323462623430383661
31336661643135303331323434653964306133376237326263333265376230353737623236656234
63666661633330613933366462346262363532336437653062363837366533306131383634616534
34323234343839306265626261323565326164633239616461363930386164373564633062323331
36383439313730343532373065663665396236336335646465613931323563623734656164653138
32646665326162666462396265663638333531336231316462393536356163626466306663643266
35663162313836316361316136323636613532343366653437656666343731643863653031373961
36383065626431643830623362303931306634316561343961623464656562323830656435646464
37353532666635653433363930333862626332663233646565383061646164353332646330303239
30663635343637633431643538346263376366306434333334623566326336396432626264396265
63386536333139633438353163656132626533313332376633336165373662616561373532363939
63303132616465363534623664343533313164353866313131653538643837353764663837393661
65346431376435303364633835323431663064366532343737356339303462323733303134396230
33303665646133663365356638653637633163313863393564343661326666663335636338613531
37303333316166353536633762343265383139326431383936643464363761353330353864303239
37633236306266636165393732656537616161613165653265366562376664313964323939333861
37326235613835623530353531376262383165616232613535316634646135313138393131343737
39346233623330643863393762393638316164303066353762623139343730656334613035336430
65666235346663616131383630663033646330396333303666333639636433323065663232613564
61313337363138353234363530613964353530383261346661336465373266356135633030363239
61626664633335336631383661613465613037366237643939623862653264323136623436623836
61366132313338313934663435626366643838313835653730366131616238313133306232346439
37396263653462346139353638646663383130383634626234373034366536366662643539656530
61363436383137306535633765636564313832303835643831666562323165623032633835636639
61303831393037303464623561326265336662613932316666633133653161346537303965373931
63323633396438383131316661353435363130346262343862373037646536376363363039613864
63333065626637326465353033643065313837393830376161383033383265363866323533616539
63303532343761643636316336313031633330366332666566386234343339663733373866646435
36386338303863353136373336356432386531366237393866653931363537363361313035633438
30393864393639326562393039323561316531396437326535663932626663313832393232373939
35393439336562613031366637363536333938313534663035343839363534356137303064333030
37353066313031326563666531383062396665643437666333623232333662373739656263633463
36393933393239373939346438366266623937393634633139393362613335393832303262393038
31323733663736626139376566363863303439386161623834363533613433373631666334396631
30316633623336613136643666363738633133393966303938643432626638373037643139343538
31303633653039663131623839643363636133646230626231353765613665326638376663613265
61303131663137313465353036636362316139333566316632363265656461323939666161653861
37336664313039353533336334306461326363323536386366376634383437633862356563366234
35663662316266373837393663643733613931326464323133313134333964626161303564383931
61663335343462353237396438353366396535306364363436343739393864633232623463323934
32353933326337616361396365323835373333333030373762386536313534396434386537623835
61393633616265633664636432303162333262656135343339313235656565633364383461383031
63333138383263646563643039306134366138383137366466316331636339653066636331643036
35303238626566393663663139343362363438383436316635363433303530666435323232386431
62663365643961356137333933353230366161313463653865356432616232373833346239646361
38356339313937396632633033326337353434653361303530373963343163653363363134323836
35323639333261636563346435623334366635316139656434356165646362613031383931393766
39643530303966653830636363336334326336303438386364316263303639623236613632326637
33313837333232613735353831393038376433336436646530663265396466333762323332383030
36646237653731363236663935333862336533383438646536376336333633326333383530613765
37373937396264643761353762383335373036313230303661353239313362363630326232323735
31653830663838666634643232346235353266323061636563646630636339613064306339363961
34343664646434326137643436333362633763363133656332666335636265363662383235316533
37316632373135646637393565316131396235353662396139323962363939386666323134306530
31363034373661626131633366313438616465306464393330303263306665646135396436313230
32376232613763326336326266323637626530636562653534313431343839643034333663323336
31303530636336366430353066316335386535616265626632376631393237633563383763333938
34373835326336646230636535643531326639326566376237353835643632323432393132396130
66323864636438346464363466346263393765633966646263363030656266356330636139316565
33396365336235356639343432393238343264653163316663303235343038663262326237613363
30663136633436663431323663653337656235313335323732373738336335646264656534666236
35663339663762313135313732653766363139373130366330646537663435383438656637353134
66396233656162316164386564366232666265303230303032323663663538373237326236396337
34396265653730626566336437373564636461636433393133343933626630393035343634326338
64656231653361306262316339613938613432353137393962383036633164616531326236366664
39613939356265366433653966323566396138323935303137313739373038626162623465366437
66313133623231666361666236316666303533383430663834666139616131366161313563353063
65316130396135346332343338653231646437623761623231343135666330643532643665656162
65636334353637376634646139313135383564363435666333363431326332333131633131623861
34626563376135366365316466653539306465653437376263363163663964656436303631343531
39353936303566303661376331323862323532356637666535326539626637393666333264663734
33303536613164623437613834386562616565373438663065643663316665373331633232343330
34343535666662396238313135326564303665373231386361383135666437636435303831316662
61656238336236333963363637363030313537356662633130633332636564306131623262383535
64326536616235623038393363323766633736333131666361623961353434623738376135353332
35643664356566653035326235363464633233336534646639383662333438333530373930623665
65306634383539323064313235656531623261626535383832356263396539636433316434323632
39303335346662613232626231353938336362636266303538363234646163663038313663313765
66313365303738303262633061346530343966653830663535363164626665366239333030343833
66326364376238626263336666393665346630383534313261623931343062353432366434653566
39616530313837633335376435306533353638333734623766343732643064653363633763373134
30623962333761303833393339313931633633323561303765366565323333666633313563343132
62346139613131626664363735336330636264666638343330336238636338386263363339383963
30393236623930376235353532646432616331373637303261346264623133643738623163663035
3666313562366662363833356165343337336264336264393261
@@ -1,4 +0,0 @@
xray_id: "{{ encrypted_xray_id }}"
xray_xhttp_path: "{{ encrypted_xray_xhttp_path }}"
xray_encryption: "{{ encrypted_xray_encryption }}"
xray_outbounds: "{{ encrypted_xray_outbounds }}"
+15
View File
@@ -0,0 +1,15 @@
$ANSIBLE_VAULT;1.1;AES256
37633533653037393835663435613364366430616366386631383963363265643963626232666132
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
62303435393932303333666434373764366463633838636533363532363732333739313437376566
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
32316330363134383761373966636464336532373863643666336363376230366237373636323234
34623265306362343765643435356236326363393431313832623937323239613834636434303938
34353763373761373739366431326162636134636135633735643930346565623430323931386239
31353762646435343639616138303130663735373932386631643834633864366638613431643966
33643833313331373735393864333665376663316534316638656363376365383834313566613037
64373764363634326463303631643231616435383738353032323537633230633063653331633734
39336265326138636232323762633936383864303565376361663664316364343039623730376234
30396435396433613532623332663335633132356662336239653536383638376435393738643439
39663537343231343734656265383762623731383336663234636638373962363535656539343765
6163656436303665346232643162383338326333386465303564
+15 -5
View File
@@ -1,5 +1,15 @@
ansible_connection: community.proxmox.proxmox_pct_remote
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
ansible_python_interpreter: /usr/bin/python3
$ANSIBLE_VAULT;1.1;AES256
37633533653037393835663435613364366430616366386631383963363265643963626232666132
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
62303435393932303333666434373764366463633838636533363532363732333739313437376566
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
32316330363134383761373966636464336532373863643666336363376230366237373636323234
34623265306362343765643435356236326363393431313832623937323239613834636434303938
34353763373761373739366431326162636134636135633735643930346565623430323931386239
31353762646435343639616138303130663735373932386631643834633864366638613431643966
33643833313331373735393864333665376663316534316638656363376365383834313566613037
64373764363634326463303631643231616435383738353032323537633230633063653331633734
39336265326138636232323762633936383864303565376361663664316364343039623730376234
30396435396433613532623332663335633132356662336239653536383638376435393738643439
39663537343231343734656265383762623731383336663234636638373962363535656539343765
6163656436303665346232643162383338326333386465303564
+4
View File
@@ -0,0 +1,4 @@
ansible_connection: ssh
ansible_user: root
ansible_host: "{{ container_ip }}"
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
+3 -3
View File
@@ -1,12 +1,12 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: [tcp,udp]
port: [3478,5349]
nft_from:
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
proto: [tcp,udp]
port: [3478,5349]
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
proto: udp
port: ["49152-65535"]
+1
View File
@@ -0,0 +1 @@
ansible_python_interpreter: /usr/bin/python3
+25
View File
@@ -0,0 +1,25 @@
zfs:
- name: rpool/data/pgsql
extra_zfs_properties:
quota: "21474836480"
- name: rpool/data/vaultwarden
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/gitea
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/slskd
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/rtorrent
extra_zfs_properties:
quota: "1073741824"
- name: rpool/data/jellfin
extra_zfs_properties:
quota: "5368709120"
- name: rpool/data/prosody
extra_zfs_properties:
quota: "10737418240"
- name: rpool/data/steamcmd
extra_zfs_properties:
quota: "21474836480"
+1 -1
View File
@@ -4,7 +4,7 @@ nft_to:
port: 5432
nft_from:
- iface: wg0
- iface: tun0
proto: tcp
port: 22
+9
View File
@@ -0,0 +1,9 @@
certbot_certs:
- domains:
- liqueur.oyacoi.ru
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
post_hook: "systemctl start nginx && systemctl start stunnel4"
- domains:
- absinthe.oyacoi.ru
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
post_hook: "systemctl start nginx && systemctl start stunnel4"
+2
View File
@@ -0,0 +1,2 @@
ansible_python_interpreter: /usr/bin/python3
ansible_password: "{{ ssh_password }}"
+1
View File
@@ -0,0 +1 @@
openvpn_role: server
+6
View File
@@ -0,0 +1,6 @@
$ANSIBLE_VAULT;1.1;AES256
37353538363139326635383437313831346265623562383533386261623437366462343663363261
3264363465656165343038656631373436613235343232620a663633636264383736303030323938
30336565383337613637613963343132646665613932393237323437373434646335383531303461
6134393232336132350a393333613362306462613839333732343963363961653561666437383037
35366561393537643463396462356464663162316632613331316230643932666233
+23
View File
@@ -0,0 +1,23 @@
openvpn_client_bundle_dir: /etc/easy-rsa/ovpn
openvpn_instances:
- name: tun0
pki_dir: /etc/easy-rsa/pki/tun0
clients:
- name: mur89
- name: matr10
- name: tap0
pki_dir: /etc/easy-rsa/pki/tap0
clients:
- name: ltrefilov
- name: lnosov
ip: 10.1.0.220
route_metric: 50
- name: aborovlev
ip: 10.1.0.221
route_metric: 50
- name: dperesypkin
ip: 10.1.0.222
route_metric: 50
- name: dkarpcov
ip: 10.1.0.223
route_metric: 50
+2 -2
View File
@@ -1,10 +1,10 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: 25565
nft_from:
- iface: [eth0,wg0]
- iface: [br-eth0,tun0]
proto: tcp
port: 25565
+4 -1
View File
@@ -35,6 +35,9 @@ nft_to:
- to: bylampa
proto: tcp
port: 80
- to: ps3
proto: tcp
port: 80
- to: firebat
proto: tcp
port: 8006
@@ -43,6 +46,6 @@ nft_to:
port: [23333,24444]
nft_from:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: [80,443,24444]
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+20 -1
View File
@@ -1,4 +1,7 @@
nft_to:
- to: nginx
proto: tcp
port: [80,443]
- to: nfs
proto: [tcp,udp]
port: [2049,111,32765,32767]
@@ -9,7 +12,23 @@ nft_to:
proto: tcp
port: 22
nft_dst:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
nft_from:
- iface: eth1
proto: tcp
port: [3783,4321,28900,29900,29901]
- iface: eth1
proto: udp
port: [6500,6515,13139,27900]
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
- proxy: all
+2 -2
View File
@@ -1,5 +1,5 @@
nft_dst:
- iface: [eth0,eth0.2]
- iface: [br-eth0,eth0.2]
proto: tcp
port: [5000,5222,5223,5280,5270,5269]
@@ -9,7 +9,7 @@ nft_to:
port: 5432
nft_from:
- iface: [eth0,eth0.2,wg0]
- iface: [br-eth0,eth0.2,tun0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
+3 -1
View File
@@ -1,3 +1,5 @@
dnsmasq:
- name: rustdesk.dttx.ru
ip: 176.119.157.97
ip_from: liqueur
- name: fs.dttx.ru
ip_from: liqueur
-6
View File
@@ -1,6 +0,0 @@
ansible_host: 10.1.0.1
ansible_connection: ssh
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
zone_iface: eth0
container_ip: 10.1.0.1
+1
View File
@@ -0,0 +1 @@
ifupdown2_manage_prerequisites: true
+2
View File
@@ -0,0 +1,2 @@
zone_iface: "eth0"
container_ip: "10.1.0.1"
@@ -0,0 +1,3 @@
nft_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
dnsmasq_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
xray_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
+1
View File
@@ -0,0 +1 @@
nftables_bootstrap_files: true
+1
View File
@@ -0,0 +1 @@
openvpn_role: client
+6
View File
@@ -0,0 +1,6 @@
user:
- name: steamcmd
create_home: true
home: /var/lib/steamcmd
shell: /bin/bash
system: true
+100
View File
@@ -0,0 +1,100 @@
$ANSIBLE_VAULT;1.1;AES256
65616666356261363366373733653631636132613931366637383432656566366636313864666230
6136653839653366336561613365383535616231613064660a343139643135653933343731363038
36396436353033396265646338666537623237323166373664626633366432373037613631636236
6134633533636361310a663966353432366436383333666266666238636239666136316665353665
33353161626637353063613738376130333533393565383065613732663637653334636130383663
65376666373861326639343362353136303038396535303234326135633665366164393239376430
38343932613935343930376131373837376235633432373535356162616333653432666131333261
30313436613465626330393936613166663563636435356136613930303933323238336565663232
35616665333339313365323837383832393563353238326234643934393234323462336363303232
30383863366331656331336135313362303235396266613661356562333064653736396531323463
63353736633139353764356634376531613738393965393264623462333232366233396233643533
65653364643235373837303731363565656265616633336236313266373635646233623362636161
61346432336636633030616232343738666136366666353135656237653437663565643032663562
31633764343537666633386237633662306362303732353761353937323039623238353439383336
39356236646333666535326337616337313233646365333830343637376533373661636364313362
35333132353364343836366639356465323636313564636433393361636536323432363232376337
37653835666664386437316163323261336135613330636537633934633839633538343238323035
38653163626266316137383433656630313234326530313533376337393865643162613532326463
38613533373263303138333237303739393261396364646330646334386338636538343265393238
64653036366237396233323064323732393831343563643238363964333633636362303866373530
35383433643163366534613931666563376133336663393332666465616436343562613833653766
32663237383466356433383065336664393664326536346364313536656565613635666665643133
35366165643163636166613735313036326232656330313637353133323265646162333565643930
38643666396431316165626433383236653663376263663736323838343435396639636162663738
64366238363532363433313336393937353561643635343466393761623161643235663366633932
30303339306333643331323962333035393933653431383139653531626533396131663564353237
65346637383133626630376639663630333265346434656361386463343162393131393631396638
64353931643733356362376139633037363434316366396266363665613563663565366466616336
65663561666163613639643136613132303662396661653830363862346535656436613739376363
61633562346331333566313165373133633137663831313534323737623564306437346562356362
66363965313337303265343966656330356361326666353134636465613833356134383833323537
63353965346666656364633230333539383464613637333131356637326535333733356139396363
64393938366533346165386165333336333638316166663236373131366334363037626662323737
39376162616333623638383038396465356130353261303730613632623265333764633330303238
34653338346430636231376339306632376236613865383737663530353465366536313864636639
39663237383564363063663266396537393536353466643564613432646663373263306164646336
38626334373138376436336130386266343766363636636437363862303635356231323336306135
61353561643761336133623565306233383333363963393765363163323139373935313636663065
30333237313738633338663630363430373232343939303134363436653563393231656262333033
38323837646131626162383237373736306634386631613864623338303235666132353837626665
35303533623533366437656133653239613563363232343535363234346466343936393132376332
64626137363564656661653466396631346364356561313562373965623539616362383835383234
30323262353833336332623863626465376238383133633462303465393463663337356464613236
31313232383738313136303439623563393861623039393536373539303838623832323238336432
39633661626364313034623832363763313031333565373363323636393265333530633837623934
64626535646661333266303461633664346461396237333633613736303239336530616236336561
65626532303063396131376335663738393362633937393131396134316235376338623165643233
39373533373033633838626239343232323733336633333837383834666661383162366337303435
61666638393938653666643834313831613134633731353665366133633334356535343464373461
61303632663936363866353764653130386233326362343466623338326234386363653432303437
30333361653662633863323731383438373764653834363062613665613862623338336233663263
37353738373131333333353662636561323234393634643734376539383965346530386265323063
32636364653365656236396665623735656630393632333330653738643736383664396230663033
64303763336339623638653831653039353731356430626530636335623235366635313339386137
64613239653538653262393265356463643739383634663432393231636561376139653834646664
65356534336264643039303762623533616431353130353332663230336133383461386161333737
33316438303935663937373335323339656535393163616166346535313830343462303738313133
36653038343639373336663961396137366632653138396139346431363431336331376339333135
30343331626636323332393337626231326463316665373734653934653531663663393937333838
37656534626639343639366366653131313137633534316137333730346531326232353137633332
34303236386138623038303263613966346532323637303665353931333930613339626362666433
36666335356464373962376335653266663138373130303639633661393036663663323538343837
32613837636166646634626137346532656364343730616663646130356631333634353766623938
32366431623032353937363462633661396365353962393931623538366365353761353365643231
35656361393162663066393539363262663966653032356465326534616230313438323437346638
37356661376361396164646135666161373732393830343932626565663535346437346236343361
34346134343438643338636437613733323065646638646364663930353062653233353066383530
33633731396562663338393838376639363034373965353465643263613632646135346432323235
64353435363032343537633035613739336637356339373164383964313062313932653336616366
30666465613263373561373366326630366636643639616138366363346561346363646139333838
30316266376330393861666137356263336638323939666431336131383339306437333832306235
37366135613230666165396136343030643630356462333830623230613133356563666533373763
66353637393430306465373465316433386131373431343436663533663264333662333865616139
65643738656666333830383833346334383430666537313733613833356239383730666437326532
38393061326136333533653565343962333336616665633034356334653366313435383630623537
32323065363137656336626130633361353763653664303636373736326363306439346263383437
33636139656437303965353362313865333535366337666466366430353837353930656638393334
32313561306132386331383633333931353336313639366434313931333733663630386436336230
32376365613061383636326366326265623038373766316561643163646564396638336537303131
39383163323337336561616666336637316435323534353961623834656664316262623834346336
36343536336439363762333538376261663934636566323962313565303137653036653434376434
61623732613936393838386163366561373539393635303664333931396565633437393931353965
62313838636461343037626332613530663336353562656563323939323636373164363930616265
62656465366330363466386261323039323766376237303263666634653561643439323630666431
62316162366436383065623961323062353034653935626638393862366535616330356135303761
34613438393730663562633239373935383264366361376536633331323062343535626262326133
63383731613664663339613830353231643866326362663336653336666530343633376465376161
37313666346261313137363864396531643765363166663931633338383037363933646436323863
34333862613730326630356437373531373838383265383238383863373339326439643035626431
63313537623339343564326534636234646635653434356161303530393236663832316233306261
63663864383862393634656630393533326438396164623037623961363833616664666437626563
63363334323930363930326231363339363233646263643861393034656562363434383034633961
36663865393430333964626231396431663634623536656237326430356334653739333339336337
36306663316638376631323165383963636562336438383639333632316133323933653539336664
38636531326230333665653937303639616338303063666561353435353764373431643234623338
66313963373964613237346238303566316138383364666238616333663437323135376466366166
39376130336635646131653237363461663664633336663837356265616133653031613662323861
38303266613934376136366430313934373462363630633037323461306134653637623035383936
343164306335323561333737633538633333
@@ -4,36 +4,29 @@ xray_ip_sets:
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
cdn:
urls:
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
telegram:
urls:
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
russian_whitelist:
urls:
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
cloudflare:
static:
- 1.1.1.1
- 1.0.0.1
google:
urls:
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
xray_domain_sets:
v2ray:
urls:
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
torrent:
static:
- bt.t-ru.org
@@ -47,31 +40,23 @@ xray_domain_sets:
- nnmclub.to
- rutor.info
- bigfangroup.org
vps:
static:
- dev.oyacoi.ru
- vector.oyacoi.ru
terraform:
static:
- terraform.io
- hashicorp.com
output_rules:
- cloudflare
xray_static_sets:
- private
xray_lists_global:
cache_dir: /var/lib/xray-lists/cache
output_dir: /var/lib/xray-lists/generated
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
proxy: "socks5h://127.0.0.1:1080"
proxy_user: "{{ encrypted_proxy_user }}"
proxy_pass: "{{ encrypted_proxy_pass }}"
http_timeout: 20
xray_tproxy_port: 61219
xray_fwmark: "0x00000001"
+3
View File
@@ -1,4 +1,7 @@
nft_to:
- to: [zone:eth0.12]
proto: tcp
port: 22
- to: firebat
proto: tcp
port: [22, 8006]
-9
View File
@@ -1,9 +0,0 @@
nft_dst:
- iface: eth0
proto: udp
port: 2456
nft_from:
- iface: [eth0,wg0]
proto: udp
port: [2456,2457]
+15
View File
@@ -0,0 +1,15 @@
nft_dst:
- iface: eth1
proto: udp
port: [2456,2457]
nft_from:
- iface: [br-eth0,tun0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
- iface: [br-eth0,tun0]
proto: udp
port: [2302,2304,2456,2457,27016]
- iface: eth1
proto: udp
port: [2456,2457]
+6
View File
@@ -0,0 +1,6 @@
user:
- name: steamcmd
create_home: true
home: /var/lib/steamcmd
shell: /bin/bash
system: true
+4
View File
@@ -0,0 +1,4 @@
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+5
View File
@@ -8,3 +8,8 @@ nft_to:
- to: [xiawrt,rbpi4]
proto: tcp
port: 22
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+20 -13
View File
@@ -1,13 +1,20 @@
plugin: community.proxmox.proxmox
url: https://10.1.0.4:8006
user: root@pam
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
validate_certs: false
want_facts: true
filter_by_types:
- lxc
compose:
zone_iface: "'eth0.' ~ proxmox_net0.tag"
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
$ANSIBLE_VAULT;1.1;AES256
37386530393166613762313561626462336132393166653364343962396164323734313165383763
6234663630386531323464643538353865613334656264620a316630336537396363303333343637
38636437633264373866616366666337366362306438306430633566316234323935363237343762
3533393634633733330a626139316231383738626465373566303565633135646164323535326635
38313138383063646237303634376237623661633830363531323563613131613530663730653533
36643330623366636363613437313030303463613163323333663865633538343266353134386631
36663530376238656262346662383532613631636234323431303935323138306163323839636338
61373735366332356138313762663633393165663732653565663066613636366538376263366337
31386337623562313731386563313736346139353961663231353862636138303938323235633038
38636562646533633261346264373466373536376530623639366262613365366437373334396665
30653037366339383538313965663865636462633139616332386165663564616263666533363034
38643065303832666335623035326566653437393638373261343138636530373839646231643665
33323338333231643435663336653232373732636335656238376563666632313131656432336233
63636437643838316166666137386361386233346633316166333662323838313565653233346537
61383966343434323539326364646230336339353337326539333031376464353732326331333864
34303431363632386562616131306436373464393165396437613535323230353862346662346265
33303137383033313534393438343934653037643936633361343638616461643935386430616133
62633262306538663961646263613239313261633764663532616138313663343863643965613730
396266656366353238353038333832336234
+30 -19
View File
@@ -1,37 +1,34 @@
all:
children:
static:
internal:
hosts:
workuter:
container_ip: "10.1.0.2"
zone_iface: "eth0"
zone_iface: "br-eth0"
oyacoi-odcm:
container_ip: "10.1.0.3"
zone_iface: "eth0"
zone_iface: "br-eth0"
firebat:
container_ip: "10.1.0.4"
zone_iface: "eth0"
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
zone_iface: "br-eth0"
ps2:
container_ip: "10.1.0.5"
zone_iface: "eth0"
zone_iface: "br-eth0"
ps3:
container_ip: "10.1.0.6"
zone_iface: "eth0"
zone_iface: "br-eth0"
tanix:
container_ip: "10.1.0.8"
zone_iface: "eth0"
zone_iface: "br-eth0"
bananawrt:
container_ip: "10.1.0.100"
zone_iface: "eth0"
zone_iface: "br-eth0"
ps4:
container_ip: "10.2.0.2"
@@ -85,14 +82,28 @@ all:
container_ip: "10.4.0.3"
zone_iface: "eth0.4"
haproxy:
container_ip: "10.255.255.100"
zone_iface: "wg0"
xiawrt:
container_ip: "10.250.250.1"
zone_iface: "wg0"
container_ip: "192.168.1.1"
zone_iface: "tun0"
rbpi4:
container_ip: "10.250.250.5"
zone_iface: "wg0"
container_ip: "192.168.1.5"
zone_iface: "tun0"
haproxy:
container_ip: "172.168.0.1"
zone_iface: "tun0"
external:
hosts:
liqueur:
container_ip: "130.49.213.132"
zone_iface: "eht1"
vector:
container_ip: "144.31.155.100"
zone_iface: "eht1"
dev:
container_ip: "178.173.249.148"
zone_iface: "eht1"
+29
View File
@@ -0,0 +1,29 @@
---
- name: deploy rasy-rsa
hosts: localhost
connection: local
become: true
roles:
- easy-rsa
- name: configure liqueur openvpn
hosts: liqueur
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- openvpn
- name: configure router openvpn
hosts: router
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- openvpn
+11
View File
@@ -0,0 +1,11 @@
---
- name: configure over ssh
hosts: firebat
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- zfs
+23
View File
@@ -0,0 +1,23 @@
---
- name: configure over ssh
hosts: liqueur
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: >-
-o UserKnownHostsFile=/dev/null
-o StrictHostKeyChecking=no
-o PreferredAuthentications=publickey,password
-o PubkeyAuthentication=yes
roles:
- authorized_key
- sshd
- certbot
- sysctl
- nginx
- nftables
- stunnel4
- openvpn
- haproxy
+23 -4
View File
@@ -1,9 +1,28 @@
---
- hosts: router
become: yes
- name: configure over pct
hosts: router
gather_facts: false
roles:
- router
- authorized_key
- ifupdown2
- name: configure over ssh
hosts: router
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- timezone
- locales
- sysctl
- stunnel4
- openvpn
- xray-core
- logrotate
- dnsmasq
- xray-lists
- unbound
- dnsmasq
- nftables
+20
View File
@@ -0,0 +1,20 @@
---
- name: configure over pct
hosts: steamcmd
gather_facts: false
roles:
- authorized_key
- name: configure over ssh
hosts: steamcmd
vars:
ansible_connection: ssh
ansible_host: "{{ container_ip }}"
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
roles:
- timezone
- locales
- user
- steamcmd
-5
View File
@@ -1,5 +0,0 @@
---
- hosts: router
become: yes
roles:
- xray-core
+15
View File
@@ -0,0 +1,15 @@
---
- name: ensure .ssh exists
ansible.builtin.file:
path: /root/.ssh
state: directory
mode: '0700'
owner: root
group: root
- name: set authorized key
ansible.posix.authorized_key:
user: root
state: present
key: "{{ item }}"
loop: "{{ ssh_keys }}"
+20
View File
@@ -0,0 +1,20 @@
---
- name: install certbot
ansible.builtin.apt:
name: certbot
state: present
update_cache: true
- name: issue certificate if missing
ansible.builtin.command:
cmd: >
certbot certonly --standalone
--non-interactive --agree-tos
--register-unsafely-without-email
--pre-hook "{{ item.pre_hook }}"
--post-hook "{{ item.post_hook }}"
{{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }}
creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem"
loop: "{{ certbot_certs }}"
loop_control:
label: "{{ item.domains | join(',') }}"
+6
View File
@@ -0,0 +1,6 @@
---
- name: install certbot
ansible.builtin.apt:
name: certbot
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include certbot install
ansible.builtin.include_tasks: install.yml
- name: include certbot configure
ansible.builtin.include_tasks: configure.yml
+1 -1
View File
@@ -1,5 +1,5 @@
interface=lo
interface=eth0
interface=br-eth0
interface=eth0.2
interface=eth0.3
interface=eth0.4
+39
View File
@@ -0,0 +1,39 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: deploy dnsmasq rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/dnsmasq.d/{{ item }}"
mode: "0644"
loop:
- 10-upstream.conf
- 20-custom-domains.conf
- 20-dhcp.conf
- 20-dns-optimizations.conf
notify: restart dnsmasq
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render dhcp-host
ansible.builtin.template:
src: 90-dhcp-host.conf.j2
dest: /etc/dnsmasq.d/90-dhcp-host.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
+6
View File
@@ -0,0 +1,6 @@
---
- name: install dnsmasq
ansible.builtin.apt:
name: dnsmasq
state: latest
update_cache: true
+4 -37
View File
@@ -1,39 +1,6 @@
---
- name: ensure /etc/dnsmasq.d exists
ansible.builtin.file:
path: /etc/dnsmasq.d
state: directory
mode: "0755"
- name: include dnsmasq install
ansible.builtin.include_tasks: install.yml
- name: deploy dnsmasq rule
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/dnsmasq.d/{{ item }}"
mode: "0644"
loop:
- 10-upstream.conf
- 20-custom-domains.conf
- 20-dhcp.conf
- 20-dns-optimizations.conf
notify: restart dnsmasq
- name: render local
ansible.builtin.template:
src: 90-local.conf.j2
dest: /etc/dnsmasq.d/90-local.conf
mode: "0644"
notify: restart dnsmasq
- name: render dhcp-host
ansible.builtin.template:
src: 90-dhcp-host.conf.j2
dest: /etc/dnsmasq.d/90-dhcp-host.conf
mode: "0644"
notify: restart dnsmasq
- name: render domain
ansible.builtin.template:
src: 90-domains.conf.j2
dest: /etc/dnsmasq.d/90-domains.conf
mode: "0644"
notify: restart dnsmasq
- name: include dnsmasq configurure
ansible.builtin.include_tasks: configure.yml
+10 -10
View File
@@ -1,13 +1,13 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
{% for entry in entries %}
{% if entry.mac %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
{% for entry in entries %}
{% if entry.mac %}
dhcp-host={{ entry.mac }},{{ ip }},{{ item }}
{% endif %}
{% endfor %}
{% endif %}
{% endif %}
{% endfor %}
{% endif %}
{% endfor %}
+6 -12
View File
@@ -1,15 +1,9 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'dnsmasq' in client and client.dnsmasq %}
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% set domains = client.dnsmasq if (client.dnsmasq is iterable and client.dnsmasq is not string) else [client.dnsmasq] %}
{% for d in domains %}
{% set entry = d if (d is mapping) else {'name': d} %}
{% set ip = entry.ip | default(default_ip) %}
{% if ip %}
{% for item in dnsmasq_managed_group | sort %}
{% for entry in hostvars[item].dnsmasq | default([]) %}
{% set ip = entry.ip | default(hostvars[entry.ip_from].container_ip if entry.ip_from is defined else none) %}
{% if ip %}
host-record={{ entry.name }},{{ ip }}
{% endif %}
{% endfor %}
{% endif %}
{% endif %}
{% endfor %}
{% endfor %}
+5 -5
View File
@@ -1,8 +1,8 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[dnsmasq_managed_group] | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if ip %}
{% for item in dnsmasq_managed_group | sort %}
{% set client = hostvars[item] %}
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
{% if ip %}
host-record={{ item }},{{ item }}.lan,{{ ip }}
{% endif %}
{% endif %}
{% endfor %}
+18
View File
@@ -0,0 +1,18 @@
---
- name: ensure local output directory exists
ansible.builtin.file:
path: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}"
state: directory
mode: '0700'
loop: "{{ openvpn_instances | subelements('clients') }}"
delegate_to: localhost
become: false
- name: render standalone client bundles
ansible.builtin.template:
src: "{{ role_path }}/templates/client-certs/{{ item.0.name }}.conf.j2"
dest: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}/{{ item.1.name }}.ovpn"
mode: '0600'
loop: "{{ openvpn_instances | subelements('clients') }}"
delegate_to: localhost
become: false
+82
View File
@@ -0,0 +1,82 @@
---
- name: prepare list of client certificates
ansible.builtin.set_fact:
cert_list: "{{ cert_list | default([]) + [ {'instance': item.0.name, 'pki_dir': item.0.pki_dir, 'client': item.1} ] }}"
loop: "{{ openvpn_instances | subelements('clients') }}"
- name: ensure local PKI directories exist
ansible.builtin.file:
path: "{{ item.pki_dir }}"
state: directory
mode: '0700'
loop: "{{ openvpn_instances }}"
- name: init pki if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch init-pki
creates: "{{ item.pki_dir }}/private"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: build ca if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-ca nopass
creates: "{{ item.pki_dir }}/ca.crt"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
EASYRSA_REQ_CN: "CA-{{ item.name }}"
loop: "{{ openvpn_instances }}"
- name: build server cert if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-server-full server nopass
creates: "{{ item.pki_dir }}/issued/server.crt"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: generate dh params if missing
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa gen-dh
creates: "{{ item.pki_dir }}/dh.pem"
environment:
EASYRSA_PKI: "{{ item.pki_dir }}"
loop: "{{ openvpn_instances }}"
- name: check client certificates validity
ansible.builtin.command:
cmd: "openssl x509 -checkend 2592000 -in {{ item.pki_dir }}/issued/{{ item.client.name }}.crt"
register: cert_check
failed_when: false
changed_when: false
loop: "{{ cert_list }}"
- name: remove old cert file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/issued/{{ item.item.client.name }}.crt"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: remove old req file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/reqs/{{ item.item.client.name }}.req"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: remove old key file before reissue
ansible.builtin.file:
path: "{{ item.item.pki_dir }}/private/{{ item.item.client.name }}.key"
state: absent
loop: "{{ cert_check.results }}"
when: item.rc != 0
- name: issue or renew client certificates
ansible.builtin.command:
cmd: /opt/easy-rsa/easyrsa --batch build-client-full "{{ item.item.client.name }}" nopass
environment:
EASYRSA_PKI: "{{ item.item.pki_dir }}"
when: item.rc != 0
loop: "{{ cert_check.results }}"
+35
View File
@@ -0,0 +1,35 @@
---
- name: get latest easy-rsa release info
ansible.builtin.uri:
url: https://api.github.com/repos/OpenVPN/easy-rsa/releases/latest
return_content: true
register: easyrsa_release
run_once: true
check_mode: false
- name: set current easy-rsa version
ansible.builtin.set_fact:
easyrsa_version: "{{ easyrsa_release.json.tag_name | replace('v', '') }}"
easyrsa_asset_url: "{{ easyrsa_release.json.assets | selectattr('name', 'search', 'EasyRSA.*\\.tgz') | map(attribute='browser_download_url') | first }}"
- name: check easy-rsa installed version
ansible.builtin.command: /opt/easy-rsa/easyrsa version
register: easyrsa_current_version
changed_when: false
failed_when: false
- name: ensure easy-rsa directory exists
ansible.builtin.file:
path: /opt/easy-rsa
state: directory
mode: '0755'
check_mode: false
- name: update easy-rsa
ansible.builtin.unarchive:
src: "{{ easyrsa_asset_url }}"
dest: /opt/easy-rsa
remote_src: true
extra_opts:
- --strip-components=1
when: easyrsa_version not in (easyrsa_current_version.stdout | default(''))
+9
View File
@@ -0,0 +1,9 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
- name: include client-certs.yml
ansible.builtin.include_tasks: client-certs.yml
@@ -0,0 +1,26 @@
client
dev tap0
proto tcp
remote 127.0.0.1 1195
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
auth SHA256
cipher AES-256-GCM
verb 3
{% if item.1.ip is defined %}
route-metric {{ item.1.route_metric | default(50) }}
script-security 2
up "C:\\Windows\\System32\\netsh.exe interface ip set address name="OpenVPN TAP-Windows6" static {{ item.1.ip }} 255.255.255.0"
{% endif %}
<ca>
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
</ca>
<cert>
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
</cert>
<key>
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
</key>
@@ -0,0 +1,21 @@
client
dev tun0
proto tcp
remote 127.0.0.1 1194
resolv-retry infinite
nobind
persist-key
persist-tun
remote-cert-tls server
auth SHA256
cipher AES-256-GCM
verb 3
<ca>
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
</ca>
<cert>
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
</cert>
<key>
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
</key>
+13
View File
@@ -0,0 +1,13 @@
---
- name: validate haproxy config
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
changed_when: false
listen: restart haproxy
- name: restart haproxy systemd service unit
ansible.builtin.systemd_service:
name: haproxy
daemon_reload: true
state: restarted
enabled: true
listen: restart haproxy
+10
View File
@@ -0,0 +1,10 @@
---
- name: render haproxy config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
notify: restart haproxy
+6
View File
@@ -0,0 +1,6 @@
---
- name: install haproxy
ansible.builtin.apt:
name: haproxy
state: latest
update_cache: true
+6
View File
@@ -0,0 +1,6 @@
---
- name: include install
ansible.builtin.include_tasks: install.yml
- name: include configure
ansible.builtin.include_tasks: configure.yml
@@ -0,0 +1,90 @@
global
log /dev/log local2
chroot /var/lib/haproxy
maxconn 4000
user haproxy
group haproxy
daemon
stats socket /var/lib/haproxy/stats mode 660 level admin
defaults
log global
mode tcp
option tcplog
option dontlognull
retries 3
timeout connect 5s
timeout client 1h
timeout server 1h
timeout check 10s
frontend http_frontend
bind 127.0.0.1:10080
mode http
option httplog
acl host_dttx hdr_end(host) -m end dttx.ru
use_backend dttx_http_srv if host_dttx
default_backend oyacoi_http_srv
backend oyacoi_http_srv
mode http
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
backend dttx_http_srv
mode http
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
frontend https_frontend
bind 127.0.0.1:10443
mode tcp
option tcplog
tcp-request inspect-delay 5s
tcp-request content accept if { req_ssl_hello_type 1 }
acl host_dttx req_ssl_sni -m end dttx.ru
acl host_telemt req_ssl_sni -m end regionculture.ru
use_backend dttx_https_srv if host_dttx
use_backend telemt_https_srv if host_telemt
default_backend oyacoi_https_srv
backend oyacoi_https_srv
mode tcp
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
backend dttx_https_srv
mode tcp
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
backend telemt_https_srv
mode tcp
option tcp-check
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
listen mcsmanager_service
bind {{ hostvars['liqueur']['container_ip'] }}:24444
mode tcp
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
listen xmpp_c2s
bind {{ hostvars['liqueur']['container_ip'] }}:5222
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
listen xmpp_legacy_ssl
bind {{ hostvars['liqueur']['container_ip'] }}:5223
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
listen xmpp_s2s
bind {{ hostvars['liqueur']['container_ip'] }}:5269
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
listen prosody_proxy65
bind {{ hostvars['liqueur']['container_ip'] }}:5000
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
listen prosody_components
bind {{ hostvars['liqueur']['container_ip'] }}:5270
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
listen prosody_bosh_http
bind {{ hostvars['liqueur']['container_ip'] }}:5280
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
@@ -5,9 +5,16 @@ iface lo inet loopback
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
auto br-eth0
iface br-eth0 inet static
address 10.1.0.1/24
bridge_ports eth0 tap0
bridge_stp off
pre-up ip tuntap add dev tap0 mode tap || true
post-down ip tuntap del dev tap0 mode tap || true
auto eth0
iface eth0 inet manual
address 10.1.0.1/24
auto eth0.2
iface eth0.2 inet static
@@ -41,12 +48,3 @@ iface eth0.12 inet static
auto eth1
iface eth1 inet dhcp
auto wg0
iface wg0 inet manual
post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
post-up ip route add default dev wg0 table 199 2>/dev/null || true
pre-down ip route del default dev wg0 table 199 2>/dev/null || true
pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
+13
View File
@@ -0,0 +1,13 @@
---
- name: deploy ifupdown interfaces
ansible.builtin.copy:
src: "{{ inventory_hostname }}/interfaces"
dest: /etc/network/interfaces
owner: root
group: root
mode: '0644'
register: interfaces_conf
- name: reload ifupdown2
command: ifreload -a
when: interfaces_conf.changed
+7
View File
@@ -0,0 +1,7 @@
---
- name: include configure
ansible.builtin.include_tasks: configure.yml
- name: include prerequisites
ansible.builtin.include_tasks: prerequisites.yml
tags: ifupdown2_prereqs
+17
View File
@@ -0,0 +1,17 @@
---
- name: install bridge-utils
ansible.builtin.package:
name: bridge-utils
state: present
register: bridge_utils_install
- name: ensure rt_tables.d directory exists
ansible.builtin.file:
path: /etc/iproute2/rt_tables.d
state: directory
mode: "0755"
register: rt_tables_dir
- name: reload ifupdown2
ansible.builtin.command: ifreload -a
when: bridge_utils_install.changed or rt_tables_dir.changed
+14
View File
@@ -0,0 +1,14 @@
---
- name: set required locales
community.general.locale_gen:
name: "{{ item }}"
state: present
loop: "{{ locales_list }}"
- name: configure /etc/locale.conf
ansible.builtin.copy:
dest: /etc/locale.conf
content: LANG={{ locale_default }}
owner: root
group: root
mode: '0644'
+3
View File
@@ -0,0 +1,3 @@
---
- name: include locales configure
ansible.builtin.include_tasks: configure.yml
+9
View File
@@ -0,0 +1,9 @@
/var/log/xray-core/*.log {
daily
rotate 4
compress
delaycompress
missingok
notifempty
copytruncate
}
+8
View File
@@ -0,0 +1,8 @@
---
- name: deploy logrotate config
ansible.builtin.copy:
src: "{{ inventory_hostname }}/"
dest: "/etc/logrotate.d/"
owner: root
group: root
mode: '0644'
+3
View File
@@ -0,0 +1,3 @@
---
- name: include logrotate configure
ansible.builtin.include_tasks: configure.yml
-47
View File
@@ -1,47 +0,0 @@
flowtable ft {
hook ingress priority filter
devices = { eth0, eth1 }
}
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iif lo accept
meta mark 0x00000001 accept
iifname eth0 tcp dport 22 accept
iifname eth0.11 tcp dport 22 accept
iifname eth1 udp dport 51820 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
iifname eth0.3 udp dport 67 accept
iifname eth1 udp dport 68 accept
#include "/etc/nftables.d/90-input.nft"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
}
chain output {
type route hook output priority filter; policy accept;
#include "/etc/nftables.d/90-output.nft"
}
-35
View File
@@ -1,35 +0,0 @@
chain vpn_prerouting_dnat {
type nat hook prerouting priority dstnat - 5; policy accept;
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
}
chain vpn_postrouting_snat {
type nat hook postrouting priority srcnat; policy accept;
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
}
chain vpn_prerouting_pbr {
type filter hook prerouting priority mangle - 10; policy accept;
iifname wg0 ct state new counter ct mark set 0x000000c7
ip daddr 10.0.0.0/8 return
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
}
chain vpn_output_pbr {
type route hook output priority mangle - 10; policy accept;
ct mark 0x000000c7 counter meta mark set 0x000000c7
}
-15
View File
@@ -1,15 +0,0 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
include "/etc/nftables.d/40-sets.nft"
include "/etc/nftables.d/90-sets.nft"
include "/etc/nftables.d/10-filter.nft"
include "/etc/nftables.d/20-vpn.nft"
include "/etc/nftables.d/30-proxy.nft"
}
table ip nat {
include "/etc/nftables.d/10-nat.nft"
}
@@ -2,7 +2,6 @@ chain postrouting {
type nat hook postrouting priority srcnat; policy accept;
oifname eth1 masquerade
}
chain prerouting {
type nat hook prerouting priority dstnat; policy accept;
include "/etc/nftables.d/90-dstnat.nft"
+34
View File
@@ -0,0 +1,34 @@
flowtable ft {
hook ingress priority filter
devices = { eth0, eth1 }
}
chain input {
type filter hook input priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iif lo accept
meta mark 0x00000001 accept
iifname br-eth0 tcp dport 22 accept
iifname eth0.11 tcp dport 22 accept
iifname tun0 tcp dport 22 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
iifname eth0.3 udp dport 67 accept
iifname eth1 udp dport 68 accept
include "/etc/nftables.d/90-input.nft"
}
chain forward {
type filter hook forward priority filter; policy drop;
ct state established,related accept
ct state invalid drop
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
tcp flags syn tcp option maxseg size set rt mtu
include "/etc/nftables.d/90-forward.nft"
}
chain output {
type route hook output priority filter; policy accept;
include "/etc/nftables.d/90-output.nft"
}
@@ -1,16 +1,11 @@
chain proxy_prerouting {
type filter hook prerouting priority filter - 50; policy accept;
fib daddr type local accept
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
include "/etc/nftables.d/90-proxy-prerouting.nft"
}
chain proxy_output {
type route hook output priority mangle; policy accept;
meta mark != 0 return
include "/etc/nftables.d/90-proxy-output.nft"
}
+38 -21
View File
@@ -4,38 +4,55 @@
path: /etc/nftables.d
state: directory
mode: "0755"
when: nftables_bootstrap_files | default(false)
- name: deploy nftables rule
- name: bootstrap empty config files
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item }}"
content: ""
force: false
mode: "0644"
loop:
- 10-filter.nft
- 10-nat.nft
- 20-vpn.nft
- 30-proxy.nft
- 40-sets.nft
- 10-sets.nft
- 20-sets.nft
- 30-nat.nft
- 40-filter.nft
- 50-proxy.nft
- 90-dstnat.nft
- 90-forward.nft
- 90-input.nft
- 90-output.nft
- 90-proxy-output.nft
- 90-proxy-prerouting.nft
when: nftables_bootstrap_files | default(false)
- name: deploy nftables rules
ansible.builtin.copy:
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item | basename }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.nft') }}"
notify: restart nftables
- name: render forward
- name: render nftable rules
ansible.builtin.template:
src: 90-forward.nft.j2
dest: /etc/nftables.d/90-forward.nft
mode: "0644"
notify: restart nftables
- name: render dstnat
ansible.builtin.template:
src: 90-dstnat.nft.j2
dest: /etc/nftables.d/90-dstnat.nft
mode: "0644"
src: "{{ item }}"
dest: "/etc/nftables.d/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.nft.j2') }}"
notify: restart nftables
- name: deploy nftables.conf
ansible.builtin.copy:
src: nftables.conf
dest: /etc/nftables.conf
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: "0644"
validate: "nft -c -f %s"
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
notify: restart nftables
+3 -2
View File
@@ -1,5 +1,6 @@
---
- name: install nftables
ansible.builtin.package:
ansible.builtin.apt:
name: nftables
state: present
state: latest
update_cache: true
+1 -1
View File
@@ -2,5 +2,5 @@
- name: include nftables install
ansible.builtin.include_tasks: install.yml
- name: include nftables configurure
- name: include nftables configure
ansible.builtin.include_tasks: configure.yml
-19
View File
@@ -1,19 +0,0 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'nft_dst' in client and client.nft_dst is not none %}
{% set target_ip = client.container_ip %}
{% for client in client.nft_dst %}
{% set ports = client.port if (client.port is iterable and client.port is not string) else [client.port] %}
{% set protos = client.proto if (client.proto is iterable and client.proto is not string) else [client.proto] %}
{% set ifaces = client.iface if (client.iface is iterable and client.iface is not string) else [client.iface] %}
{% for proto in protos %}
{% for port in ports %}
{% for iface in ifaces %}
iifname "{{ iface }}" {{ proto }} dport {{ port }} counter dnat ip to {{ target_ip }}:{{ port }} comment "{{ iface }} -> {{ item }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
@@ -1,47 +0,0 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in groups[nft_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'nft_to' in client and client.nft_to is not none %}
{% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %}
{% for rule in rules %}
{% set rule = rule if rule is mapping else {'to': rule} %}
{% set dests = rule.to if (rule.to is iterable and rule.to is not string) else [rule.to] %}
{% set protos = rule.proto if (rule.proto is iterable and rule.proto is not string) else [rule.proto | default(none)] %}
{% set ports = rule.port if (rule.port is iterable and rule.port is not string) else [rule.port | default(none)] %}
{% for dest in dests %}
{% if dest.startswith('zone:') %}
{% set oif = dest.split(':')[1] %}
{% set daddr = none %}
{% set dest_name = oif %}
{% else %}
{% set oif = hostvars[dest].zone_iface %}
{% set daddr = hostvars[dest].container_ip %}
{% set dest_name = dest %}
{% endif %}
{% for proto in protos %}
{% for port in ports %}
iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{ oif }}" {% if daddr %}ip daddr {{ daddr }} {% endif %}{% if proto and port %}{{ proto }} dport {{ port }} {% endif %}counter accept comment "{{ item }} -> {{ dest_name }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
{% for item in groups[nft_managed_group] | sort %}
{% set client = hostvars[item] %}
{% if 'nft_from' in client and client.nft_from is not none %}
{% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %}
{% for rule in rules %}
{% set ifaces = rule.iface if (rule.iface is iterable and rule.iface is not string) else [rule.iface] %}
{% set protos = rule.proto if (rule.proto is iterable and rule.proto is not string) else [rule.proto | default(none)] %}
{% set ports = rule.port if (rule.port is iterable and rule.port is not string) else [rule.port | default(none)] %}
{% for iface in ifaces %}
{% for proto in protos %}
{% for port in ports %}
iifname "{{ iface }}" oifname "{{ client.zone_iface }}" ip daddr {{ client.container_ip }} {% if proto and port %}{{ proto }} dport {{ port }} {% endif %}counter accept comment "{{ iface }} -> {{ item }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
@@ -0,0 +1,53 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
chain input {
type filter hook input priority filter;
policy drop;
iif "lo" accept
ct state established,related accept
ct state invalid drop
tcp dport 22 counter accept comment "ssh"
tcp dport 80 counter accept comment "http"
tcp dport 443 counter accept comment "https"
tcp dport 24444 counter accept comment "mcsmanager"
tcp dport { 5222, 5223, 5269, 5000, 5270, 5280 } counter accept comment "xmpp"
}
chain forward {
type filter hook forward priority filter;
policy drop;
ct state established,related accept
ip daddr {{ hostvars['coturn']['container_ip'] }} udp dport { 3478, 5349, 49152-65535 } counter accept
ip daddr {{ hostvars['coturn']['container_ip'] }} tcp dport { 3478, 5349 } counter accept
ip daddr {{ hostvars['mcsmanager']['container_ip'] }} tcp dport 25565 counter accept
ip daddr {{ hostvars['steamcmd']['container_ip'] }} udp dport 2456 counter accept
ip daddr {{ hostvars['steamcmd']['container_ip'] }} udp dport 2457 counter accept
ip daddr {{ hostvars['rbpi4']['container_ip'] }} udp dport 21116 counter accept
ip daddr {{ hostvars['rbpi4']['container_ip'] }} tcp dport 21114-21119 counter accept
iifname tun0 ip saddr {{ hostvars['workuter']['container_ip'] }} oifname tun0 ip daddr {{ hostvars['xiawrt']['container_ip'] }} tcp dport 22 counter accept
iifname tun0 ip saddr {{ hostvars['workuter']['container_ip'] }} oifname tun0 ip daddr {{ hostvars['rbpi4']['container_ip'] }} tcp dport 22 counter accept
iifname tun0 ip saddr {{ hostvars['oyacoi-odcm']['container_ip'] }} oifname tun0 ip daddr {{ hostvars['xiawrt']['container_ip'] }} tcp dport 22 counter accept
iifname tun0 ip saddr {{ hostvars['oyacoi-odcm']['container_ip'] }} oifname tun0 ip daddr {{ hostvars['rbpi4']['container_ip'] }} tcp dport 22 counter accept
}
chain output {
type filter hook output priority filter;
policy accept;
}
}
table ip nat {
chain prerouting {
type nat hook prerouting priority dstnat;
policy accept;
ip daddr {{ container_ip }} udp dport { 3478, 5349, 49152-65535 } counter dnat to {{ hostvars['coturn']['container_ip'] }}
ip daddr {{ container_ip }} tcp dport { 3478, 5349 } counter dnat to {{ hostvars['coturn']['container_ip'] }}
ip daddr {{ container_ip }} tcp dport 25565 counter dnat to {{ hostvars['mcsmanager']['container_ip'] }}
ip daddr {{ container_ip }} udp dport 2456 counter dnat to {{ hostvars['steamcmd']['container_ip'] }}
ip daddr {{ container_ip }} udp dport 2457 counter dnat to {{ hostvars['steamcmd']['container_ip'] }}
ip daddr {{ container_ip }} udp dport 21116 counter dnat to {{ hostvars['rbpi4']['container_ip'] }}
ip daddr {{ container_ip }} tcp dport 21114-21119 counter dnat to {{ hostvars['rbpi4']['container_ip'] }}
}
chain postrouting {
type nat hook postrouting priority srcnat;
policy accept;
}
}
@@ -4,7 +4,7 @@ set {{ id }}_ip {
type ipv4_addr
flags interval
auto-merge
include "{{ xray_lists_global.output_dir }}/{{ id }}.elements.nft"
include "{{ xray_lists_global.output_dir }}/{{ id }}_ip.elements.nft"
}
{% endfor -%}
{%- for id, item in xray_domain_sets.items() -%}
@@ -0,0 +1,19 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_dst' in client and client.nft_dst is not none %}
{% set target_ip = client.container_ip %}
{% for client in client.nft_dst %}
{% set ports = client.port if (client.port is iterable and client.port is not string) else [client.port] %}
{% set protos = client.proto if (client.proto is iterable and client.proto is not string) else [client.proto] %}
{% set ifaces = client.iface if (client.iface is iterable and client.iface is not string) else [client.iface] %}
{% for proto in protos %}
{% for port in ports %}
{% for iface in ifaces %}
iifname "{{ iface }}" {{ proto }} dport {{ port }} counter dnat ip to {{ target_ip }}:{{ port }} comment "{{ iface }} -> {{ item }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
@@ -0,0 +1,47 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_to' in client and client.nft_to is not none %}
{% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %}
{% for rule in rules %}
{% set rule = rule if rule is mapping else {'to': rule} %}
{% set dests = rule.to if (rule.to is iterable and rule.to is not string) else [rule.to] %}
{% set protos = rule.proto if (rule.proto is iterable and rule.proto is not string) else [rule.proto | default(none)] %}
{% set ports = rule.port if (rule.port is iterable and rule.port is not string) else [rule.port | default(none)] %}
{% for dest in dests %}
{% if dest.startswith('zone:') %}
{% set oif = dest.split(':')[1] %}
{% set daddr = none %}
{% set dest_name = oif %}
{% else %}
{% set oif = hostvars[dest].zone_iface %}
{% set daddr = hostvars[dest].container_ip %}
{% set dest_name = dest %}
{% endif %}
{% for proto in protos %}
{% for port in ports %}
iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{ oif }}" {% if daddr %}ip daddr {{ daddr }} {% endif %}{% if proto and port %}{{ proto }} dport {{ port }} {% endif %}counter accept comment "{{ item }} -> {{ dest_name }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
{% for item in nft_managed_group | sort %}
{% set client = hostvars[item] %}
{% if 'nft_from' in client and client.nft_from is not none %}
{% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %}
{% for rule in rules %}
{% set ifaces = rule.iface if (rule.iface is iterable and rule.iface is not string) else [rule.iface] %}
{% set protos = rule.proto if (rule.proto is iterable and rule.proto is not string) else [rule.proto | default(none)] %}
{% set ports = rule.port if (rule.port is iterable and rule.port is not string) else [rule.port | default(none)] %}
{% for iface in ifaces %}
{% for proto in protos %}
{% for port in ports %}
iifname "{{ iface }}" oifname "{{ client.zone_iface }}" ip daddr {{ client.container_ip }} {% if proto and port %}{{ proto }} dport {{ port }} {% endif %}counter accept comment "{{ iface }} -> {{ item }}"
{% endfor %}
{% endfor %}
{% endfor %}
{% endfor %}
{% endif %}
{% endfor %}
@@ -1,11 +1,11 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% macro set_daddr(rule) %}
{%- if rule in (xray_ip_sets | default([])) or rule in (xray_static_sets | default([])) -%}
{%- if rule in (xray_ip_sets | default([])) or rule in (xray_static_sets | default([])) -%}
{{ rule }}_ip
{%- elif rule in (xray_domain_sets | default([])) -%}
{%- elif rule in (xray_domain_sets | default([])) -%}
{{ rule }}_dom
{%- endif -%}
{%- endif -%}
{% endmacro %}
{% for rule in output_rules | default([]) | sort %}
ip daddr @{{ set_daddr(rule) }} meta mark set {{ xray_fwmark }} accept
{% endfor %}
ip daddr @{{ set_daddr(rule) }} meta mark set {{ xray_fwmark }} counter accept comment "router -> tproxy"
{% endfor %}
@@ -0,0 +1,28 @@
#jinja2: trim_blocks: True, lstrip_blocks: True
{% macro set_daddr(name) -%}
{%- if name == 'all' -%}
0.0.0.0/0
{%- elif name in (xray_ip_sets | default([])) or name in (xray_static_sets | default([])) -%}
@{{ name }}_ip
{%- elif name in (xray_domain_sets | default([])) -%}
@{{ name }}_dom
{%- else -%}
invalid_xray_set_{{ name }}
{%- endif -%}
{%- endmacro -%}
{% for item in xray_managed_group | default([]) | sort %}
{% set client = hostvars[item] %}
{% if client.xray_policy is defined %}
{% set src_ip = client.container_ip %}
{% for rule in client.xray_policy %}
{% set target_set = rule.bypass | default(rule.proxy) %}
{% if rule.bypass is defined %}
meta l4proto tcp ip saddr {{ src_ip }} ip daddr {{ set_daddr(target_set) }} counter accept comment "{{ item }} -> accept"
meta l4proto udp ip saddr {{ src_ip }} ip daddr {{ set_daddr(target_set) }} counter accept comment "{{ item }} -> accept"
{% elif rule.proxy is defined %}
meta l4proto tcp ip saddr {{ src_ip }} ip daddr {{ set_daddr(target_set) }} tproxy ip to :{{ xray_tproxy_port }} meta mark set {{ xray_fwmark }} counter accept comment "{{ item }} -> trpoxy"
meta l4proto udp ip saddr {{ src_ip }} ip daddr {{ set_daddr(target_set) }} tproxy ip to :{{ xray_tproxy_port }} meta mark set {{ xray_fwmark }} counter accept comment "{{ item }} -> tproxy"
{% endif %}
{% endfor %}
{% endif %}
{% endfor %}
@@ -0,0 +1,11 @@
#!/usr/sbin/nft -f
flush ruleset
table inet filter {
include "/etc/nftables.d/10-sets.nft"
include "/etc/nftables.d/20-sets.nft"
include "/etc/nftables.d/40-filter.nft"
include "/etc/nftables.d/50-proxy.nft"
}
table ip nat {
include "/etc/nftables.d/30-nat.nft"
}
+14
View File
@@ -0,0 +1,14 @@
# handlers/main.yml
---
- name: validate nginx config
ansible.builtin.command: nginx -t
changed_when: false
listen: restart nginx
- name: restart nginx systemd service unit
ansible.builtin.systemd_service:
name: nginx
daemon_reload: true
state: restarted
enabled: true
listen: restart nginx
+10
View File
@@ -0,0 +1,10 @@
---
- name: deploy nginx config
ansible.builtin.template:
src: "{{ item }}"
dest: "/etc/nginx/{{ item | basename | regex_replace('\\.j2$', '') }}"
owner: root
group: root
mode: '0644'
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
notify: restart nginx
+81
View File
@@ -0,0 +1,81 @@
---
- name: install prerequisites for nginx repository
ansible.builtin.apt:
name:
- curl
- gnupg2
- ca-certificates
- lsb-release
- debian-archive-keyring
state: present
update_cache: true
- name: check if nginx keyring already exists
ansible.builtin.stat:
path: /usr/share/keyrings/nginx-archive-keyring.gpg
register: nginx_keyring
- name: download nginx gpg key
ansible.builtin.get_url:
url: https://nginx.org/keys/nginx_signing.key
dest: /tmp/nginx_signing.key
mode: '0644'
when: not nginx_keyring.stat.exists
- name: dearmor nginx gpg key
ansible.builtin.command:
cmd: gpg --dearmor --yes -o /usr/share/keyrings/nginx-archive-keyring.gpg /tmp/nginx_signing.key
when: not nginx_keyring.stat.exists
- name: ensure /root/.gnupg exists
ansible.builtin.file:
path: /root/.gnupg
state: directory
mode: '0700'
owner: root
group: root
- name: verify nginx signing key fingerprint
ansible.builtin.command:
cmd: gpg --dry-run --quiet --no-keyring --import --import-options import-show /usr/share/keyrings/nginx-archive-keyring.gpg
register: nginx_key_check
changed_when: false
- name: check nginx signing key fingerprint
ansible.builtin.fail:
msg: "nginx signing key fingerprint mismatch! Got: {{ nginx_key_check.stdout }}"
when: "'573BFD6B3D8FBC641079A6ABABF5BD827BD9BF62' not in nginx_key_check.stdout"
- name: add nginx apt repository
ansible.builtin.copy:
dest: /etc/apt/sources.list.d/nginx.list
content: >-
deb [signed-by=/usr/share/keyrings/nginx-archive-keyring.gpg]
https://nginx.org/packages/{{ 'mainline/' if (nginx_use_mainline | default(false)) else '' }}debian
{{ ansible_facts['distribution_release'] }} nginx
owner: root
group: root
mode: '0644'
register: nginx_repo_file
- name: set up repository pinning for nginx
ansible.builtin.copy:
dest: /etc/apt/preferences.d/99nginx
content: |
Package: *
Pin: origin nginx.org
Pin: release o=nginx
Pin-Priority: 900
owner: root
group: root
mode: '0644'
- name: update apt cache
ansible.builtin.apt:
update_cache: true
when: nginx_repo_file.changed
- name: install nginx
ansible.builtin.apt:
name: nginx
state: present

Some files were not shown because too many files have changed in this diff Show More