Compare commits
16
Commits
6d7779af3f
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c640406c10 | ||
|
|
ba9e1a664f | ||
|
|
33ddc88ee9 | ||
|
|
6e248bb709 | ||
|
|
4e6aace464 | ||
|
|
d5762dfc07 | ||
|
|
fa6a65aed2 | ||
|
|
47e6340bf0 | ||
|
|
681f384810 | ||
|
|
66062e6122 | ||
|
|
271c290498 | ||
|
|
abeb2e0eb9 | ||
|
|
98873cb5eb | ||
|
|
a928e0ec70 | ||
|
|
7ce01c7173 | ||
|
|
3020de7dc1 |
@@ -0,0 +1 @@
|
||||
.vault_pass
|
||||
@@ -3,6 +3,7 @@ inventory = inventory/
|
||||
roles_path = roles/
|
||||
host_key_checking = False
|
||||
forks = 8
|
||||
vault_password_file = .vault_pass
|
||||
|
||||
[inventory]
|
||||
enable_plugins = community.proxmox.proxmox, host_list, yaml, ini
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
locale_default: en_US.UTF-8
|
||||
locales_list:
|
||||
- en_US.UTF-8
|
||||
- ru_RU.UTF-8
|
||||
@@ -1,3 +0,0 @@
|
||||
nft_managed_group: all
|
||||
dnsmasq_managed_group: all
|
||||
xray_managed_group: all
|
||||
@@ -0,0 +1 @@
|
||||
timezone_name: Europe/Samara
|
||||
@@ -0,0 +1,15 @@
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
||||
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
||||
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
||||
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
||||
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
||||
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
||||
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
||||
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
||||
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
||||
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
||||
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
||||
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
||||
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
||||
6163656436303665346232643162383338326333386465303564
|
||||
@@ -1,5 +1,15 @@
|
||||
ansible_connection: community.proxmox.proxmox_pct_remote
|
||||
ansible_host: 10.1.0.4
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||
ansible_python_interpreter: /usr/bin/python3
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
37633533653037393835663435613364366430616366386631383963363265643963626232666132
|
||||
3564383139306565306131636561356234643066313261620a623230643766353564343231303232
|
||||
62303435393932303333666434373764366463633838636533363532363732333739313437376566
|
||||
3936633633373066610a386334626637376162656637653764323163306365393438666164353332
|
||||
32316330363134383761373966636464336532373863643666336363376230366237373636323234
|
||||
34623265306362343765643435356236326363393431313832623937323239613834636434303938
|
||||
34353763373761373739366431326162636134636135633735643930346565623430323931386239
|
||||
31353762646435343639616138303130663735373932386631643834633864366638613431643966
|
||||
33643833313331373735393864333665376663316534316638656363376365383834313566613037
|
||||
64373764363634326463303631643231616435383738353032323537633230633063653331633734
|
||||
39336265326138636232323762633936383864303565376361663664316364343039623730376234
|
||||
30396435396433613532623332663335633132356662336239653536383638376435393738643439
|
||||
39663537343231343734656265383762623731383336663234636638373962363535656539343765
|
||||
6163656436303665346232643162383338326333386465303564
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
ansible_connection: ssh
|
||||
ansible_user: root
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||
@@ -1,4 +1,2 @@
|
||||
nft_from:
|
||||
- iface: [eth1,eth0.2]
|
||||
to: camera0
|
||||
proto: [tcp,udp]
|
||||
dhcp-host:
|
||||
- mac: "b8:88:80:92:b5:4c"
|
||||
|
||||
@@ -1,12 +1,12 @@
|
||||
nft_dst:
|
||||
- iface: [eth0,eth0.2]
|
||||
- iface: [br-eth0,eth0.2]
|
||||
proto: [tcp,udp]
|
||||
port: [3478,5349]
|
||||
|
||||
nft_from:
|
||||
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
||||
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
||||
proto: [tcp,udp]
|
||||
port: [3478,5349]
|
||||
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
|
||||
- iface: [br-eth0,eth0.2,eth0.3,eth0.4,tun0]
|
||||
proto: udp
|
||||
port: ["49152-65535"]
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
ansible_python_interpreter: /usr/bin/python3
|
||||
@@ -0,0 +1,25 @@
|
||||
zfs:
|
||||
- name: rpool/data/pgsql
|
||||
extra_zfs_properties:
|
||||
quota: "21474836480"
|
||||
- name: rpool/data/vaultwarden
|
||||
extra_zfs_properties:
|
||||
quota: "5368709120"
|
||||
- name: rpool/data/gitea
|
||||
extra_zfs_properties:
|
||||
quota: "5368709120"
|
||||
- name: rpool/data/slskd
|
||||
extra_zfs_properties:
|
||||
quota: "5368709120"
|
||||
- name: rpool/data/rtorrent
|
||||
extra_zfs_properties:
|
||||
quota: "1073741824"
|
||||
- name: rpool/data/jellfin
|
||||
extra_zfs_properties:
|
||||
quota: "5368709120"
|
||||
- name: rpool/data/prosody
|
||||
extra_zfs_properties:
|
||||
quota: "10737418240"
|
||||
- name: rpool/data/steamcmd
|
||||
extra_zfs_properties:
|
||||
quota: "21474836480"
|
||||
@@ -0,0 +1,2 @@
|
||||
dhcp-host:
|
||||
- mac: "d4:f0:ea:78:ec:a0"
|
||||
@@ -1,5 +1,10 @@
|
||||
nft_to:
|
||||
- to: pgsql
|
||||
proto: tcp
|
||||
port: 5432
|
||||
|
||||
nft_from:
|
||||
- iface: wg0
|
||||
- iface: tun0
|
||||
proto: tcp
|
||||
port: 22
|
||||
|
||||
|
||||
@@ -1,4 +1,22 @@
|
||||
nft_to:
|
||||
- to: nginx
|
||||
proto: tcp
|
||||
port: [80, 81, 443, 444, 24445]
|
||||
port: [80,81,443,444,24445,5222,5223,5269,5000,5270,5280]
|
||||
- to: coturn
|
||||
proto: tcp
|
||||
port: [3478,5349]
|
||||
- to: coturn
|
||||
proto: udp
|
||||
port: [3478,5349,"49152-65535"]
|
||||
- to: mcsmanager
|
||||
proto: tcp
|
||||
port: 25565
|
||||
- to: steamcmd
|
||||
proto: udp
|
||||
port: [2456,2457]
|
||||
- to: rbpi4
|
||||
proto: tcp
|
||||
port: "21114-21119"
|
||||
- to: rbpi4
|
||||
proto: udp
|
||||
port: 21116
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
xray_policy:
|
||||
- bypass: private
|
||||
- bypass: russian_whitelist
|
||||
- proxy: all
|
||||
@@ -0,0 +1,9 @@
|
||||
certbot_certs:
|
||||
- domains:
|
||||
- liqueur.oyacoi.ru
|
||||
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
||||
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
||||
- domains:
|
||||
- absinthe.oyacoi.ru
|
||||
pre_hook: "systemctl stop stunnel4 && systemctl stop nginx"
|
||||
post_hook: "systemctl start nginx && systemctl start stunnel4"
|
||||
@@ -0,0 +1,2 @@
|
||||
ansible_python_interpreter: /usr/bin/python3
|
||||
ansible_password: "{{ ssh_password }}"
|
||||
@@ -0,0 +1 @@
|
||||
openvpn_role: server
|
||||
@@ -0,0 +1,6 @@
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
37353538363139326635383437313831346265623562383533386261623437366462343663363261
|
||||
3264363465656165343038656631373436613235343232620a663633636264383736303030323938
|
||||
30336565383337613637613963343132646665613932393237323437373434646335383531303461
|
||||
6134393232336132350a393333613362306462613839333732343963363961653561666437383037
|
||||
35366561393537643463396462356464663162316632613331316230643932666233
|
||||
@@ -0,0 +1,23 @@
|
||||
openvpn_client_bundle_dir: /etc/easy-rsa/ovpn
|
||||
openvpn_instances:
|
||||
- name: tun0
|
||||
pki_dir: /etc/easy-rsa/pki/tun0
|
||||
clients:
|
||||
- name: mur89
|
||||
- name: matr10
|
||||
- name: tap0
|
||||
pki_dir: /etc/easy-rsa/pki/tap0
|
||||
clients:
|
||||
- name: ltrefilov
|
||||
- name: lnosov
|
||||
ip: 10.1.0.220
|
||||
route_metric: 50
|
||||
- name: aborovlev
|
||||
ip: 10.1.0.221
|
||||
route_metric: 50
|
||||
- name: dperesypkin
|
||||
ip: 10.1.0.222
|
||||
route_metric: 50
|
||||
- name: dkarpcov
|
||||
ip: 10.1.0.223
|
||||
route_metric: 50
|
||||
@@ -1,10 +1,10 @@
|
||||
nft_dst:
|
||||
- iface: [eth0,eth0.2]
|
||||
- iface: [br-eth0,eth0.2]
|
||||
proto: tcp
|
||||
port: 25565
|
||||
|
||||
nft_from:
|
||||
- iface: [eth0,wg0]
|
||||
- iface: [br-eth0,tun0]
|
||||
proto: tcp
|
||||
port: 25565
|
||||
|
||||
|
||||
@@ -35,8 +35,17 @@ nft_to:
|
||||
- to: bylampa
|
||||
proto: tcp
|
||||
port: 80
|
||||
- to: ps3
|
||||
proto: tcp
|
||||
port: 80
|
||||
- to: firebat
|
||||
proto: tcp
|
||||
port: 8006
|
||||
- to: mcsmanager
|
||||
proto: tcp
|
||||
port: [23333,24444]
|
||||
|
||||
nft_from:
|
||||
- iface: [eth0,eth0.2]
|
||||
- iface: [br-eth0,eth0.2]
|
||||
proto: tcp
|
||||
port: [80,443,24444]
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
xray_policy:
|
||||
- bypass: private
|
||||
- bypass: russian_whitelist
|
||||
- proxy: all
|
||||
@@ -1,7 +1,10 @@
|
||||
nft_to:
|
||||
- to: nginx
|
||||
proto: tcp
|
||||
port: [80,443]
|
||||
- to: nfs
|
||||
proto: [tcp, udp]
|
||||
port: [2049, 111, 32765, 32767]
|
||||
proto: [tcp,udp]
|
||||
port: [2049,111,32765,32767]
|
||||
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
|
||||
proto: tcp
|
||||
port: 22
|
||||
@@ -9,6 +12,22 @@ nft_to:
|
||||
proto: tcp
|
||||
port: 22
|
||||
|
||||
nft_dst:
|
||||
- iface: eth1
|
||||
proto: tcp
|
||||
port: [3783,4321,28900,29900,29901]
|
||||
- iface: eth1
|
||||
proto: udp
|
||||
port: [6500,6515,13139,27900]
|
||||
|
||||
nft_from:
|
||||
- iface: eth1
|
||||
proto: tcp
|
||||
port: [3783,4321,28900,29900,29901]
|
||||
- iface: eth1
|
||||
proto: udp
|
||||
port: [6500,6515,13139,27900]
|
||||
|
||||
xray_policy:
|
||||
- bypass: private
|
||||
- bypass: russian_whitelist
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
nft_dst:
|
||||
- iface: [eth0,eth0.2]
|
||||
- iface: [br-eth0,eth0.2]
|
||||
proto: tcp
|
||||
port: [5000,5222,5223,5280,5270,5269]
|
||||
|
||||
@@ -9,7 +9,7 @@ nft_to:
|
||||
port: 5432
|
||||
|
||||
nft_from:
|
||||
- iface: [eth0,eth0.2,wg0]
|
||||
- iface: [br-eth0,eth0.2,tun0]
|
||||
proto: tcp
|
||||
port: [5000,5222,5223,5269,5270,5280]
|
||||
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
dnsmasq:
|
||||
- name: rustdesk.dttx.ru
|
||||
ip: 176.119.157.97
|
||||
ip_from: liqueur
|
||||
- name: fs.dttx.ru
|
||||
ip_from: liqueur
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
ansible_host: 10.1.0.1
|
||||
ansible_connection: ssh
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
zone_iface: eth0
|
||||
container_ip: 10.1.0.1
|
||||
@@ -0,0 +1 @@
|
||||
ifupdown2_manage_prerequisites: true
|
||||
@@ -0,0 +1,2 @@
|
||||
zone_iface: "eth0"
|
||||
container_ip: "10.1.0.1"
|
||||
@@ -0,0 +1,3 @@
|
||||
nft_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||
dnsmasq_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||
xray_managed_group: "{{ groups['internal'] + groups['proxmox_all_lxc'] }}"
|
||||
@@ -0,0 +1 @@
|
||||
nftables_bootstrap_files: true
|
||||
@@ -0,0 +1 @@
|
||||
openvpn_role: client
|
||||
@@ -0,0 +1,6 @@
|
||||
user:
|
||||
- name: steamcmd
|
||||
create_home: true
|
||||
home: /var/lib/steamcmd
|
||||
shell: /bin/bash
|
||||
system: true
|
||||
@@ -0,0 +1,100 @@
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
65616666356261363366373733653631636132613931366637383432656566366636313864666230
|
||||
6136653839653366336561613365383535616231613064660a343139643135653933343731363038
|
||||
36396436353033396265646338666537623237323166373664626633366432373037613631636236
|
||||
6134633533636361310a663966353432366436383333666266666238636239666136316665353665
|
||||
33353161626637353063613738376130333533393565383065613732663637653334636130383663
|
||||
65376666373861326639343362353136303038396535303234326135633665366164393239376430
|
||||
38343932613935343930376131373837376235633432373535356162616333653432666131333261
|
||||
30313436613465626330393936613166663563636435356136613930303933323238336565663232
|
||||
35616665333339313365323837383832393563353238326234643934393234323462336363303232
|
||||
30383863366331656331336135313362303235396266613661356562333064653736396531323463
|
||||
63353736633139353764356634376531613738393965393264623462333232366233396233643533
|
||||
65653364643235373837303731363565656265616633336236313266373635646233623362636161
|
||||
61346432336636633030616232343738666136366666353135656237653437663565643032663562
|
||||
31633764343537666633386237633662306362303732353761353937323039623238353439383336
|
||||
39356236646333666535326337616337313233646365333830343637376533373661636364313362
|
||||
35333132353364343836366639356465323636313564636433393361636536323432363232376337
|
||||
37653835666664386437316163323261336135613330636537633934633839633538343238323035
|
||||
38653163626266316137383433656630313234326530313533376337393865643162613532326463
|
||||
38613533373263303138333237303739393261396364646330646334386338636538343265393238
|
||||
64653036366237396233323064323732393831343563643238363964333633636362303866373530
|
||||
35383433643163366534613931666563376133336663393332666465616436343562613833653766
|
||||
32663237383466356433383065336664393664326536346364313536656565613635666665643133
|
||||
35366165643163636166613735313036326232656330313637353133323265646162333565643930
|
||||
38643666396431316165626433383236653663376263663736323838343435396639636162663738
|
||||
64366238363532363433313336393937353561643635343466393761623161643235663366633932
|
||||
30303339306333643331323962333035393933653431383139653531626533396131663564353237
|
||||
65346637383133626630376639663630333265346434656361386463343162393131393631396638
|
||||
64353931643733356362376139633037363434316366396266363665613563663565366466616336
|
||||
65663561666163613639643136613132303662396661653830363862346535656436613739376363
|
||||
61633562346331333566313165373133633137663831313534323737623564306437346562356362
|
||||
66363965313337303265343966656330356361326666353134636465613833356134383833323537
|
||||
63353965346666656364633230333539383464613637333131356637326535333733356139396363
|
||||
64393938366533346165386165333336333638316166663236373131366334363037626662323737
|
||||
39376162616333623638383038396465356130353261303730613632623265333764633330303238
|
||||
34653338346430636231376339306632376236613865383737663530353465366536313864636639
|
||||
39663237383564363063663266396537393536353466643564613432646663373263306164646336
|
||||
38626334373138376436336130386266343766363636636437363862303635356231323336306135
|
||||
61353561643761336133623565306233383333363963393765363163323139373935313636663065
|
||||
30333237313738633338663630363430373232343939303134363436653563393231656262333033
|
||||
38323837646131626162383237373736306634386631613864623338303235666132353837626665
|
||||
35303533623533366437656133653239613563363232343535363234346466343936393132376332
|
||||
64626137363564656661653466396631346364356561313562373965623539616362383835383234
|
||||
30323262353833336332623863626465376238383133633462303465393463663337356464613236
|
||||
31313232383738313136303439623563393861623039393536373539303838623832323238336432
|
||||
39633661626364313034623832363763313031333565373363323636393265333530633837623934
|
||||
64626535646661333266303461633664346461396237333633613736303239336530616236336561
|
||||
65626532303063396131376335663738393362633937393131396134316235376338623165643233
|
||||
39373533373033633838626239343232323733336633333837383834666661383162366337303435
|
||||
61666638393938653666643834313831613134633731353665366133633334356535343464373461
|
||||
61303632663936363866353764653130386233326362343466623338326234386363653432303437
|
||||
30333361653662633863323731383438373764653834363062613665613862623338336233663263
|
||||
37353738373131333333353662636561323234393634643734376539383965346530386265323063
|
||||
32636364653365656236396665623735656630393632333330653738643736383664396230663033
|
||||
64303763336339623638653831653039353731356430626530636335623235366635313339386137
|
||||
64613239653538653262393265356463643739383634663432393231636561376139653834646664
|
||||
65356534336264643039303762623533616431353130353332663230336133383461386161333737
|
||||
33316438303935663937373335323339656535393163616166346535313830343462303738313133
|
||||
36653038343639373336663961396137366632653138396139346431363431336331376339333135
|
||||
30343331626636323332393337626231326463316665373734653934653531663663393937333838
|
||||
37656534626639343639366366653131313137633534316137333730346531326232353137633332
|
||||
34303236386138623038303263613966346532323637303665353931333930613339626362666433
|
||||
36666335356464373962376335653266663138373130303639633661393036663663323538343837
|
||||
32613837636166646634626137346532656364343730616663646130356631333634353766623938
|
||||
32366431623032353937363462633661396365353962393931623538366365353761353365643231
|
||||
35656361393162663066393539363262663966653032356465326534616230313438323437346638
|
||||
37356661376361396164646135666161373732393830343932626565663535346437346236343361
|
||||
34346134343438643338636437613733323065646638646364663930353062653233353066383530
|
||||
33633731396562663338393838376639363034373965353465643263613632646135346432323235
|
||||
64353435363032343537633035613739336637356339373164383964313062313932653336616366
|
||||
30666465613263373561373366326630366636643639616138366363346561346363646139333838
|
||||
30316266376330393861666137356263336638323939666431336131383339306437333832306235
|
||||
37366135613230666165396136343030643630356462333830623230613133356563666533373763
|
||||
66353637393430306465373465316433386131373431343436663533663264333662333865616139
|
||||
65643738656666333830383833346334383430666537313733613833356239383730666437326532
|
||||
38393061326136333533653565343962333336616665633034356334653366313435383630623537
|
||||
32323065363137656336626130633361353763653664303636373736326363306439346263383437
|
||||
33636139656437303965353362313865333535366337666466366430353837353930656638393334
|
||||
32313561306132386331383633333931353336313639366434313931333733663630386436336230
|
||||
32376365613061383636326366326265623038373766316561643163646564396638336537303131
|
||||
39383163323337336561616666336637316435323534353961623834656664316262623834346336
|
||||
36343536336439363762333538376261663934636566323962313565303137653036653434376434
|
||||
61623732613936393838386163366561373539393635303664333931396565633437393931353965
|
||||
62313838636461343037626332613530663336353562656563323939323636373164363930616265
|
||||
62656465366330363466386261323039323766376237303263666634653561643439323630666431
|
||||
62316162366436383065623961323062353034653935626638393862366535616330356135303761
|
||||
34613438393730663562633239373935383264366361376536633331323062343535626262326133
|
||||
63383731613664663339613830353231643866326362663336653336666530343633376465376161
|
||||
37313666346261313137363864396531643765363166663931633338383037363933646436323863
|
||||
34333862613730326630356437373531373838383265383238383863373339326439643035626431
|
||||
63313537623339343564326534636234646635653434356161303530393236663832316233306261
|
||||
63663864383862393634656630393533326438396164623037623961363833616664666437626563
|
||||
63363334323930363930326231363339363233646263643861393034656562363434383034633961
|
||||
36663865393430333964626231396431663634623536656237326430356334653739333339336337
|
||||
36306663316638376631323165383963636562336438383639333632316133323933653539336664
|
||||
38636531326230333665653937303639616338303063666561353435353764373431643234623338
|
||||
66313963373964613237346238303566316138383364666238616333663437323135376466366166
|
||||
39376130336635646131653237363461663664633336663837356265616133653031613662323861
|
||||
38303266613934376136366430313934373462363630633037323461306134653637623035383936
|
||||
343164306335323561333737633538633333
|
||||
@@ -4,36 +4,29 @@ xray_ip_sets:
|
||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
|
||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
|
||||
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
|
||||
|
||||
cdn:
|
||||
urls:
|
||||
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
|
||||
|
||||
telegram:
|
||||
urls:
|
||||
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
|
||||
|
||||
russian_whitelist:
|
||||
urls:
|
||||
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
|
||||
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
|
||||
|
||||
cloudflare:
|
||||
static:
|
||||
- 1.1.1.1
|
||||
- 1.0.0.1
|
||||
|
||||
google:
|
||||
urls:
|
||||
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
|
||||
|
||||
xray_domain_sets:
|
||||
v2ray:
|
||||
urls:
|
||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
|
||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
|
||||
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
|
||||
|
||||
torrent:
|
||||
static:
|
||||
- bt.t-ru.org
|
||||
@@ -43,31 +36,27 @@ xray_domain_sets:
|
||||
- rutracker.org
|
||||
- rutracker.net
|
||||
- tapochek.net
|
||||
- bt.tapochek.net
|
||||
- nnmclub.to
|
||||
- rutor.info
|
||||
- bigfangroup.org
|
||||
|
||||
vps:
|
||||
static:
|
||||
- dev.oyacoi.ru
|
||||
- vector.oyacoi.ru
|
||||
|
||||
terraform:
|
||||
static:
|
||||
- terraform.io
|
||||
- hashicorp.com
|
||||
|
||||
output_rules:
|
||||
- cloudflare
|
||||
xray_static_sets:
|
||||
- private
|
||||
|
||||
xray_lists_global:
|
||||
cache_dir: /var/lib/xray-lists/cache
|
||||
output_dir: /var/lib/xray-lists/generated
|
||||
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
|
||||
proxy: "socks5h://127.0.0.1:1080"
|
||||
proxy_user: "{{ lookup('env', 'SOCKS5_USERNAME') }}"
|
||||
proxy_pass: "{{ lookup('env', 'SOCKS5_PASSWORD') }}"
|
||||
http_timeout: 20
|
||||
|
||||
xray_tproxy_port: 61219
|
||||
xray_fwmark: "0x00000001"
|
||||
@@ -1,7 +1,13 @@
|
||||
nft_to:
|
||||
- to: [zone:eth0.12]
|
||||
proto: tcp
|
||||
port: 22
|
||||
- to: firebat
|
||||
proto: tcp
|
||||
port: [22, 8006]
|
||||
- to: nginx
|
||||
proto: tcp
|
||||
port: 443
|
||||
|
||||
xray_policy:
|
||||
- proxy: terraform
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
nft_dst:
|
||||
- iface: eth0
|
||||
proto: udp
|
||||
port: 2456
|
||||
|
||||
nft_from:
|
||||
- iface: [eth0,wg0]
|
||||
proto: udp
|
||||
port: [2456,2457]
|
||||
@@ -0,0 +1,15 @@
|
||||
nft_dst:
|
||||
- iface: eth1
|
||||
proto: udp
|
||||
port: [2456,2457]
|
||||
|
||||
nft_from:
|
||||
- iface: [br-eth0,tun0]
|
||||
proto: tcp
|
||||
port: [5000,5222,5223,5269,5270,5280]
|
||||
- iface: [br-eth0,tun0]
|
||||
proto: udp
|
||||
port: [2302,2304,2456,2457,27016]
|
||||
- iface: eth1
|
||||
proto: udp
|
||||
port: [2456,2457]
|
||||
@@ -0,0 +1,6 @@
|
||||
user:
|
||||
- name: steamcmd
|
||||
create_home: true
|
||||
home: /var/lib/steamcmd
|
||||
shell: /bin/bash
|
||||
system: true
|
||||
@@ -0,0 +1,4 @@
|
||||
xray_policy:
|
||||
- bypass: private
|
||||
- bypass: russian_whitelist
|
||||
- proxy: all
|
||||
@@ -0,0 +1,2 @@
|
||||
dhcp-host:
|
||||
- mac: "c8:5c:cc:91:71:58"
|
||||
@@ -8,3 +8,8 @@ nft_to:
|
||||
- to: [xiawrt,rbpi4]
|
||||
proto: tcp
|
||||
port: 22
|
||||
|
||||
xray_policy:
|
||||
- bypass: private
|
||||
- bypass: russian_whitelist
|
||||
- proxy: all
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
dhcp-host:
|
||||
- mac: "ac:ba:c0:9c:1e:4c"
|
||||
+20
-13
@@ -1,13 +1,20 @@
|
||||
plugin: community.proxmox.proxmox
|
||||
url: https://10.1.0.4:8006
|
||||
user: root@pam
|
||||
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
|
||||
validate_certs: false
|
||||
want_facts: true
|
||||
|
||||
filter_by_types:
|
||||
- lxc
|
||||
|
||||
compose:
|
||||
zone_iface: "'eth0.' ~ proxmox_net0.tag"
|
||||
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
37386530393166613762313561626462336132393166653364343962396164323734313165383763
|
||||
6234663630386531323464643538353865613334656264620a316630336537396363303333343637
|
||||
38636437633264373866616366666337366362306438306430633566316234323935363237343762
|
||||
3533393634633733330a626139316231383738626465373566303565633135646164323535326635
|
||||
38313138383063646237303634376237623661633830363531323563613131613530663730653533
|
||||
36643330623366636363613437313030303463613163323333663865633538343266353134386631
|
||||
36663530376238656262346662383532613631636234323431303935323138306163323839636338
|
||||
61373735366332356138313762663633393165663732653565663066613636366538376263366337
|
||||
31386337623562313731386563313736346139353961663231353862636138303938323235633038
|
||||
38636562646533633261346264373466373536376530623639366262613365366437373334396665
|
||||
30653037366339383538313965663865636462633139616332386165663564616263666533363034
|
||||
38643065303832666335623035326566653437393638373261343138636530373839646231643665
|
||||
33323338333231643435663336653232373732636335656238376563666632313131656432336233
|
||||
63636437643838316166666137386361386233346633316166333662323838313565653233346537
|
||||
61383966343434323539326364646230336339353337326539333031376464353732326331333864
|
||||
34303431363632386562616131306436373464393165396437613535323230353862346662346265
|
||||
33303137383033313534393438343934653037643936633361343638616461643935386430616133
|
||||
62633262306538663961646263613239313261633764663532616138313663343863643965613730
|
||||
396266656366353238353038333832336234
|
||||
|
||||
+49
-22
@@ -1,37 +1,34 @@
|
||||
all:
|
||||
children:
|
||||
static:
|
||||
internal:
|
||||
hosts:
|
||||
workuter:
|
||||
container_ip: "10.1.0.2"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
oyacoi-odcm:
|
||||
container_ip: "10.1.0.3"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
firebat:
|
||||
container_ip: "10.1.0.4"
|
||||
zone_iface: "eth0"
|
||||
ansible_host: 10.1.0.4
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
ps2:
|
||||
container_ip: "10.1.0.5"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
ps3:
|
||||
container_ip: "10.1.0.6"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
tanix:
|
||||
container_ip: "10.1.0.8"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
bananawrt:
|
||||
container_ip: "10.1.0.100"
|
||||
zone_iface: "eth0"
|
||||
zone_iface: "br-eth0"
|
||||
|
||||
ps4:
|
||||
container_ip: "10.2.0.2"
|
||||
@@ -57,26 +54,56 @@ all:
|
||||
container_ip: "10.2.0.7"
|
||||
zone_iface: "eth0.2"
|
||||
|
||||
psp:
|
||||
3ds:
|
||||
container_ip: "10.2.0.8"
|
||||
zone_iface: "eth0.2"
|
||||
|
||||
dsi:
|
||||
container_ip: "10.2.0.9"
|
||||
zone_iface: "eth0.2"
|
||||
yandex-lite-2:
|
||||
container_ip: "10.3.0.2"
|
||||
zone_iface: "eth0.3"
|
||||
|
||||
3ds:
|
||||
container_ip: "10.2.0.10"
|
||||
zone_iface: "eth0.2"
|
||||
fryer:
|
||||
container_ip: "10.3.0.3"
|
||||
zone_iface: "eth0.3"
|
||||
|
||||
vacuum:
|
||||
container_ip: "10.3.0.4"
|
||||
zone_iface: "eth0.3"
|
||||
|
||||
camera0:
|
||||
container_ip: "10.3.0.5"
|
||||
zone_iface: "eth0.3"
|
||||
|
||||
psp:
|
||||
container_ip: "10.4.0.2"
|
||||
zone_iface: "eth0.4"
|
||||
|
||||
dsi:
|
||||
container_ip: "10.4.0.3"
|
||||
zone_iface: "eth0.4"
|
||||
|
||||
xiawrt:
|
||||
container_ip: "10.250.250.1"
|
||||
zone_iface: "wg0"
|
||||
container_ip: "192.168.1.1"
|
||||
zone_iface: "tun0"
|
||||
|
||||
rbpi4:
|
||||
container_ip: "10.250.250.5"
|
||||
zone_iface: "wg0"
|
||||
container_ip: "192.168.1.5"
|
||||
zone_iface: "tun0"
|
||||
|
||||
haproxy:
|
||||
container_ip: "172.168.0.1"
|
||||
zone_iface: "tun0"
|
||||
|
||||
external:
|
||||
hosts:
|
||||
liqueur:
|
||||
container_ip: "130.49.213.132"
|
||||
zone_iface: "eht1"
|
||||
|
||||
vector:
|
||||
container_ip: "144.31.155.100"
|
||||
zone_iface: "eht1"
|
||||
|
||||
dev:
|
||||
container_ip: "178.173.249.148"
|
||||
zone_iface: "eht1"
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
---
|
||||
- hosts: router
|
||||
become: true
|
||||
roles:
|
||||
- dnsmasq
|
||||
@@ -0,0 +1,29 @@
|
||||
---
|
||||
- name: deploy rasy-rsa
|
||||
hosts: localhost
|
||||
connection: local
|
||||
become: true
|
||||
roles:
|
||||
- easy-rsa
|
||||
|
||||
- name: configure liqueur openvpn
|
||||
hosts: liqueur
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- openvpn
|
||||
|
||||
- name: configure router openvpn
|
||||
hosts: router
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- openvpn
|
||||
@@ -0,0 +1,11 @@
|
||||
---
|
||||
- name: configure over ssh
|
||||
hosts: firebat
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- zfs
|
||||
@@ -0,0 +1,23 @@
|
||||
---
|
||||
- name: configure over ssh
|
||||
hosts: liqueur
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: >-
|
||||
-o UserKnownHostsFile=/dev/null
|
||||
-o StrictHostKeyChecking=no
|
||||
-o PreferredAuthentications=publickey,password
|
||||
-o PubkeyAuthentication=yes
|
||||
roles:
|
||||
- authorized_key
|
||||
- sshd
|
||||
- certbot
|
||||
- sysctl
|
||||
- nginx
|
||||
- nftables
|
||||
- stunnel4
|
||||
- openvpn
|
||||
- haproxy
|
||||
@@ -1,14 +0,0 @@
|
||||
---
|
||||
- hosts: router
|
||||
become: true
|
||||
roles:
|
||||
- xray-lists
|
||||
- dnsmasq
|
||||
- nftables
|
||||
|
||||
tasks:
|
||||
- name: enable update timer
|
||||
systemd:
|
||||
name: xray-lists.timer
|
||||
enabled: yes
|
||||
state: started
|
||||
+25
-12
@@ -1,15 +1,28 @@
|
||||
---
|
||||
- hosts: router
|
||||
become: yes
|
||||
- name: configure over pct
|
||||
hosts: router
|
||||
gather_facts: false
|
||||
roles:
|
||||
- router
|
||||
- xray-lists
|
||||
- dnsmasq
|
||||
- nftables
|
||||
- authorized_key
|
||||
- ifupdown2
|
||||
|
||||
tasks:
|
||||
- name: enable update timer
|
||||
systemd:
|
||||
name: xray-lists.timer
|
||||
enabled: yes
|
||||
state: started
|
||||
- name: configure over ssh
|
||||
hosts: router
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- timezone
|
||||
- locales
|
||||
- sysctl
|
||||
- stunnel4
|
||||
- openvpn
|
||||
- xray-core
|
||||
- logrotate
|
||||
- dnsmasq
|
||||
- xray-lists
|
||||
- unbound
|
||||
- nftables
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
- name: configure over pct
|
||||
hosts: steamcmd
|
||||
gather_facts: false
|
||||
roles:
|
||||
- authorized_key
|
||||
|
||||
- name: configure over ssh
|
||||
hosts: steamcmd
|
||||
vars:
|
||||
ansible_connection: ssh
|
||||
ansible_host: "{{ container_ip }}"
|
||||
ansible_user: root
|
||||
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
|
||||
ansible_ssh_common_args: '-o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no'
|
||||
roles:
|
||||
- timezone
|
||||
- locales
|
||||
- user
|
||||
- steamcmd
|
||||
@@ -1,5 +0,0 @@
|
||||
---
|
||||
- hosts: router
|
||||
become: true
|
||||
roles:
|
||||
- xray-lists
|
||||
@@ -0,0 +1,15 @@
|
||||
---
|
||||
- name: ensure .ssh exists
|
||||
ansible.builtin.file:
|
||||
path: /root/.ssh
|
||||
state: directory
|
||||
mode: '0700'
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
- name: set authorized key
|
||||
ansible.posix.authorized_key:
|
||||
user: root
|
||||
state: present
|
||||
key: "{{ item }}"
|
||||
loop: "{{ ssh_keys }}"
|
||||
@@ -0,0 +1,20 @@
|
||||
---
|
||||
- name: install certbot
|
||||
ansible.builtin.apt:
|
||||
name: certbot
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: issue certificate if missing
|
||||
ansible.builtin.command:
|
||||
cmd: >
|
||||
certbot certonly --standalone
|
||||
--non-interactive --agree-tos
|
||||
--register-unsafely-without-email
|
||||
--pre-hook "{{ item.pre_hook }}"
|
||||
--post-hook "{{ item.post_hook }}"
|
||||
{{ item.domains | map('regex_replace', '^(.*)$', '-d \1') | join(' ') }}
|
||||
creates: "/etc/letsencrypt/live/{{ item.domains[0] }}/fullchain.pem"
|
||||
loop: "{{ certbot_certs }}"
|
||||
loop_control:
|
||||
label: "{{ item.domains | join(',') }}"
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install certbot
|
||||
ansible.builtin.apt:
|
||||
name: certbot
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include certbot install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include certbot configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,14 @@
|
||||
interface=lo
|
||||
interface=br-eth0
|
||||
interface=eth0.2
|
||||
interface=eth0.3
|
||||
interface=eth0.4
|
||||
interface=eth0.10
|
||||
interface=eth0.11
|
||||
interface=eth0.12
|
||||
bind-dynamic
|
||||
no-resolv
|
||||
server=127.0.0.1#5353
|
||||
#server=1.1.1.1
|
||||
domain=lan
|
||||
local=/lan/
|
||||
@@ -0,0 +1,10 @@
|
||||
server=/dev.oyacoi.ru/9.9.9.9
|
||||
server=/vector.oyacoi.ru/9.9.9.9
|
||||
server=/.themoviedb.org/9.9.9.9
|
||||
server=/.tmdb.org/9.9.9.9
|
||||
server=/tmdb-image-prod.b-cdn.net/9.9.9.9
|
||||
server=/infolada.ru/217.113.115.150
|
||||
server=/infolada.ru/217.113.114.100
|
||||
server=/start.infolada.ru/217.113.115.150
|
||||
server=/start.infolada.ru/217.113.114.100
|
||||
conf-file=/var/lib/xray-lists/generated/nftsets.conf
|
||||
@@ -0,0 +1,3 @@
|
||||
dhcp-range=interface:eth0.3,10.3.0.200,10.3.0.254,255.255.255.0,2h
|
||||
dhcp-option=interface:eth0.3,option:router,10.3.0.1
|
||||
dhcp-option=interface:eth0.3,option:dns-server,10.3.0.1
|
||||
@@ -0,0 +1,4 @@
|
||||
filterwin2k
|
||||
domain-needed
|
||||
bogus-priv
|
||||
cache-size=0
|
||||
@@ -0,0 +1,39 @@
|
||||
---
|
||||
- name: ensure /etc/dnsmasq.d exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/dnsmasq.d
|
||||
state: directory
|
||||
mode: "0755"
|
||||
|
||||
- name: deploy dnsmasq rule
|
||||
ansible.builtin.copy:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/dnsmasq.d/{{ item }}"
|
||||
mode: "0644"
|
||||
loop:
|
||||
- 10-upstream.conf
|
||||
- 20-custom-domains.conf
|
||||
- 20-dhcp.conf
|
||||
- 20-dns-optimizations.conf
|
||||
notify: restart dnsmasq
|
||||
|
||||
- name: render local
|
||||
ansible.builtin.template:
|
||||
src: 90-local.conf.j2
|
||||
dest: /etc/dnsmasq.d/90-local.conf
|
||||
mode: "0644"
|
||||
notify: restart dnsmasq
|
||||
|
||||
- name: render dhcp-host
|
||||
ansible.builtin.template:
|
||||
src: 90-dhcp-host.conf.j2
|
||||
dest: /etc/dnsmasq.d/90-dhcp-host.conf
|
||||
mode: "0644"
|
||||
notify: restart dnsmasq
|
||||
|
||||
- name: render domain
|
||||
ansible.builtin.template:
|
||||
src: 90-domains.conf.j2
|
||||
dest: /etc/dnsmasq.d/90-domains.conf
|
||||
mode: "0644"
|
||||
notify: restart dnsmasq
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install dnsmasq
|
||||
ansible.builtin.apt:
|
||||
name: dnsmasq
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -1,20 +1,6 @@
|
||||
---
|
||||
- name: ensure /etc/dnsmasq.d exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/dnsmasq.d
|
||||
state: directory
|
||||
mode: "0755"
|
||||
- name: include dnsmasq install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: render local
|
||||
ansible.builtin.template:
|
||||
src: 90-local.conf.j2
|
||||
dest: /etc/dnsmasq.d/90-local.conf
|
||||
mode: "0644"
|
||||
notify: restart dnsmasq
|
||||
|
||||
- name: render domain
|
||||
ansible.builtin.template:
|
||||
src: 90-domains.conf.j2
|
||||
dest: /etc/dnsmasq.d/90-domains.conf
|
||||
mode: "0644"
|
||||
notify: restart dnsmasq
|
||||
- name: include dnsmasq configurure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{% for item in dnsmasq_managed_group | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||
{% if client['dhcp-host'] is defined and client['dhcp-host'] and ip %}
|
||||
{% set entries = client['dhcp-host'] if (client['dhcp-host'] is iterable and client['dhcp-host'] is not string) else [client['dhcp-host']] %}
|
||||
{% for entry in entries %}
|
||||
{% if entry.mac %}
|
||||
dhcp-host={{ entry.mac }},{{ ip }},{{ item }}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
@@ -1,15 +1,9 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{% for item in groups[dnsmasq_managed_group] | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% if 'dnsmasq' in client and client.dnsmasq %}
|
||||
{% set default_ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||
{% set domains = client.dnsmasq if (client.dnsmasq is iterable and client.dnsmasq is not string) else [client.dnsmasq] %}
|
||||
{% for d in domains %}
|
||||
{% set entry = d if (d is mapping) else {'name': d} %}
|
||||
{% set ip = entry.ip | default(default_ip) %}
|
||||
{% if ip %}
|
||||
{% for item in dnsmasq_managed_group | sort %}
|
||||
{% for entry in hostvars[item].dnsmasq | default([]) %}
|
||||
{% set ip = entry.ip | default(hostvars[entry.ip_from].container_ip if entry.ip_from is defined else none) %}
|
||||
{% if ip %}
|
||||
host-record={{ entry.name }},{{ ip }}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% endfor %}
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{% for item in groups[dnsmasq_managed_group] | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||
{% if ip %}
|
||||
{% for item in dnsmasq_managed_group | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% set ip = client.container_ip | default(client.ansible_host | default(none)) %}
|
||||
{% if ip %}
|
||||
host-record={{ item }},{{ item }}.lan,{{ ip }}
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
|
||||
@@ -0,0 +1,18 @@
|
||||
---
|
||||
- name: ensure local output directory exists
|
||||
ansible.builtin.file:
|
||||
path: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}"
|
||||
state: directory
|
||||
mode: '0700'
|
||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||
delegate_to: localhost
|
||||
become: false
|
||||
|
||||
- name: render standalone client bundles
|
||||
ansible.builtin.template:
|
||||
src: "{{ role_path }}/templates/client-certs/{{ item.0.name }}.conf.j2"
|
||||
dest: "{{ openvpn_client_bundle_dir }}/{{ item.0.name }}/{{ item.1.name }}.ovpn"
|
||||
mode: '0600'
|
||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||
delegate_to: localhost
|
||||
become: false
|
||||
@@ -0,0 +1,82 @@
|
||||
---
|
||||
- name: prepare list of client certificates
|
||||
ansible.builtin.set_fact:
|
||||
cert_list: "{{ cert_list | default([]) + [ {'instance': item.0.name, 'pki_dir': item.0.pki_dir, 'client': item.1} ] }}"
|
||||
loop: "{{ openvpn_instances | subelements('clients') }}"
|
||||
|
||||
- name: ensure local PKI directories exist
|
||||
ansible.builtin.file:
|
||||
path: "{{ item.pki_dir }}"
|
||||
state: directory
|
||||
mode: '0700'
|
||||
loop: "{{ openvpn_instances }}"
|
||||
|
||||
- name: init pki if missing
|
||||
ansible.builtin.command:
|
||||
cmd: /opt/easy-rsa/easyrsa --batch init-pki
|
||||
creates: "{{ item.pki_dir }}/private"
|
||||
environment:
|
||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||
loop: "{{ openvpn_instances }}"
|
||||
|
||||
- name: build ca if missing
|
||||
ansible.builtin.command:
|
||||
cmd: /opt/easy-rsa/easyrsa --batch build-ca nopass
|
||||
creates: "{{ item.pki_dir }}/ca.crt"
|
||||
environment:
|
||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||
EASYRSA_REQ_CN: "CA-{{ item.name }}"
|
||||
loop: "{{ openvpn_instances }}"
|
||||
|
||||
- name: build server cert if missing
|
||||
ansible.builtin.command:
|
||||
cmd: /opt/easy-rsa/easyrsa --batch build-server-full server nopass
|
||||
creates: "{{ item.pki_dir }}/issued/server.crt"
|
||||
environment:
|
||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||
loop: "{{ openvpn_instances }}"
|
||||
|
||||
- name: generate dh params if missing
|
||||
ansible.builtin.command:
|
||||
cmd: /opt/easy-rsa/easyrsa gen-dh
|
||||
creates: "{{ item.pki_dir }}/dh.pem"
|
||||
environment:
|
||||
EASYRSA_PKI: "{{ item.pki_dir }}"
|
||||
loop: "{{ openvpn_instances }}"
|
||||
|
||||
- name: check client certificates validity
|
||||
ansible.builtin.command:
|
||||
cmd: "openssl x509 -checkend 2592000 -in {{ item.pki_dir }}/issued/{{ item.client.name }}.crt"
|
||||
register: cert_check
|
||||
failed_when: false
|
||||
changed_when: false
|
||||
loop: "{{ cert_list }}"
|
||||
|
||||
- name: remove old cert file before reissue
|
||||
ansible.builtin.file:
|
||||
path: "{{ item.item.pki_dir }}/issued/{{ item.item.client.name }}.crt"
|
||||
state: absent
|
||||
loop: "{{ cert_check.results }}"
|
||||
when: item.rc != 0
|
||||
|
||||
- name: remove old req file before reissue
|
||||
ansible.builtin.file:
|
||||
path: "{{ item.item.pki_dir }}/reqs/{{ item.item.client.name }}.req"
|
||||
state: absent
|
||||
loop: "{{ cert_check.results }}"
|
||||
when: item.rc != 0
|
||||
|
||||
- name: remove old key file before reissue
|
||||
ansible.builtin.file:
|
||||
path: "{{ item.item.pki_dir }}/private/{{ item.item.client.name }}.key"
|
||||
state: absent
|
||||
loop: "{{ cert_check.results }}"
|
||||
when: item.rc != 0
|
||||
|
||||
- name: issue or renew client certificates
|
||||
ansible.builtin.command:
|
||||
cmd: /opt/easy-rsa/easyrsa --batch build-client-full "{{ item.item.client.name }}" nopass
|
||||
environment:
|
||||
EASYRSA_PKI: "{{ item.item.pki_dir }}"
|
||||
when: item.rc != 0
|
||||
loop: "{{ cert_check.results }}"
|
||||
@@ -0,0 +1,35 @@
|
||||
---
|
||||
- name: get latest easy-rsa release info
|
||||
ansible.builtin.uri:
|
||||
url: https://api.github.com/repos/OpenVPN/easy-rsa/releases/latest
|
||||
return_content: true
|
||||
register: easyrsa_release
|
||||
run_once: true
|
||||
check_mode: false
|
||||
|
||||
- name: set current easy-rsa version
|
||||
ansible.builtin.set_fact:
|
||||
easyrsa_version: "{{ easyrsa_release.json.tag_name | replace('v', '') }}"
|
||||
easyrsa_asset_url: "{{ easyrsa_release.json.assets | selectattr('name', 'search', 'EasyRSA.*\\.tgz') | map(attribute='browser_download_url') | first }}"
|
||||
|
||||
- name: check easy-rsa installed version
|
||||
ansible.builtin.command: /opt/easy-rsa/easyrsa version
|
||||
register: easyrsa_current_version
|
||||
changed_when: false
|
||||
failed_when: false
|
||||
|
||||
- name: ensure easy-rsa directory exists
|
||||
ansible.builtin.file:
|
||||
path: /opt/easy-rsa
|
||||
state: directory
|
||||
mode: '0755'
|
||||
check_mode: false
|
||||
|
||||
- name: update easy-rsa
|
||||
ansible.builtin.unarchive:
|
||||
src: "{{ easyrsa_asset_url }}"
|
||||
dest: /opt/easy-rsa
|
||||
remote_src: true
|
||||
extra_opts:
|
||||
- --strip-components=1
|
||||
when: easyrsa_version not in (easyrsa_current_version.stdout | default(''))
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
- name: include install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
|
||||
- name: include client-certs.yml
|
||||
ansible.builtin.include_tasks: client-certs.yml
|
||||
@@ -0,0 +1,26 @@
|
||||
client
|
||||
dev tap0
|
||||
proto tcp
|
||||
remote 127.0.0.1 1195
|
||||
resolv-retry infinite
|
||||
nobind
|
||||
persist-key
|
||||
persist-tun
|
||||
remote-cert-tls server
|
||||
auth SHA256
|
||||
cipher AES-256-GCM
|
||||
verb 3
|
||||
{% if item.1.ip is defined %}
|
||||
route-metric {{ item.1.route_metric | default(50) }}
|
||||
script-security 2
|
||||
up "C:\\Windows\\System32\\netsh.exe interface ip set address name="OpenVPN TAP-Windows6" static {{ item.1.ip }} 255.255.255.0"
|
||||
{% endif %}
|
||||
<ca>
|
||||
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
||||
</ca>
|
||||
<cert>
|
||||
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
||||
</cert>
|
||||
<key>
|
||||
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
||||
</key>
|
||||
@@ -0,0 +1,21 @@
|
||||
client
|
||||
dev tun0
|
||||
proto tcp
|
||||
remote 127.0.0.1 1194
|
||||
resolv-retry infinite
|
||||
nobind
|
||||
persist-key
|
||||
persist-tun
|
||||
remote-cert-tls server
|
||||
auth SHA256
|
||||
cipher AES-256-GCM
|
||||
verb 3
|
||||
<ca>
|
||||
{{ lookup('file', item.0.pki_dir + '/ca.crt') }}
|
||||
</ca>
|
||||
<cert>
|
||||
{{ lookup('file', item.0.pki_dir + '/issued/' + item.1.name + '.crt') }}
|
||||
</cert>
|
||||
<key>
|
||||
{{ lookup('file', item.0.pki_dir + '/private/' + item.1.name + '.key') }}
|
||||
</key>
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: validate haproxy config
|
||||
ansible.builtin.command: haproxy -c -f /etc/haproxy/haproxy.cfg
|
||||
changed_when: false
|
||||
listen: restart haproxy
|
||||
|
||||
- name: restart haproxy systemd service unit
|
||||
ansible.builtin.systemd_service:
|
||||
name: haproxy
|
||||
daemon_reload: true
|
||||
state: restarted
|
||||
enabled: true
|
||||
listen: restart haproxy
|
||||
@@ -0,0 +1,10 @@
|
||||
---
|
||||
- name: render haproxy config
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/haproxy/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('fileglob', role_path + '/templates/' + inventory_hostname + '/*.cfg.j2') }}"
|
||||
notify: restart haproxy
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: install haproxy
|
||||
ansible.builtin.apt:
|
||||
name: haproxy
|
||||
state: latest
|
||||
update_cache: true
|
||||
@@ -0,0 +1,6 @@
|
||||
---
|
||||
- name: include install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,90 @@
|
||||
global
|
||||
log /dev/log local2
|
||||
chroot /var/lib/haproxy
|
||||
maxconn 4000
|
||||
user haproxy
|
||||
group haproxy
|
||||
daemon
|
||||
stats socket /var/lib/haproxy/stats mode 660 level admin
|
||||
|
||||
defaults
|
||||
log global
|
||||
mode tcp
|
||||
option tcplog
|
||||
option dontlognull
|
||||
retries 3
|
||||
timeout connect 5s
|
||||
timeout client 1h
|
||||
timeout server 1h
|
||||
timeout check 10s
|
||||
|
||||
frontend http_frontend
|
||||
bind 127.0.0.1:10080
|
||||
mode http
|
||||
option httplog
|
||||
acl host_dttx hdr_end(host) -m end dttx.ru
|
||||
use_backend dttx_http_srv if host_dttx
|
||||
default_backend oyacoi_http_srv
|
||||
|
||||
backend oyacoi_http_srv
|
||||
mode http
|
||||
server oyacoi_srv {{ hostvars['nginx']['container_ip'] }}:81 send-proxy-v2
|
||||
|
||||
backend dttx_http_srv
|
||||
mode http
|
||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:81 send-proxy-v2
|
||||
|
||||
frontend https_frontend
|
||||
bind 127.0.0.1:10443
|
||||
mode tcp
|
||||
option tcplog
|
||||
tcp-request inspect-delay 5s
|
||||
tcp-request content accept if { req_ssl_hello_type 1 }
|
||||
acl host_dttx req_ssl_sni -m end dttx.ru
|
||||
acl host_telemt req_ssl_sni -m end regionculture.ru
|
||||
use_backend dttx_https_srv if host_dttx
|
||||
use_backend telemt_https_srv if host_telemt
|
||||
default_backend oyacoi_https_srv
|
||||
|
||||
backend oyacoi_https_srv
|
||||
mode tcp
|
||||
server nginx_srv {{ hostvars['nginx']['container_ip'] }}:444 send-proxy-v2
|
||||
|
||||
backend dttx_https_srv
|
||||
mode tcp
|
||||
server dttx_srv {{ hostvars['rbpi4']['container_ip'] }}:444 send-proxy-v2
|
||||
|
||||
backend telemt_https_srv
|
||||
mode tcp
|
||||
option tcp-check
|
||||
server telemt_srv {{ hostvars['vector']['container_ip'] }}:8080 check send-proxy-v2
|
||||
server telemt_srv_backup {{ hostvars['dev']['container_ip'] }}:8080 check send-proxy-v2 backup
|
||||
|
||||
listen mcsmanager_service
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:24444
|
||||
mode tcp
|
||||
server mcs_srv {{ hostvars['mcsmanager']['container_ip'] }}:24445 send-proxy-v2
|
||||
|
||||
listen xmpp_c2s
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5222
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5222
|
||||
|
||||
listen xmpp_legacy_ssl
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5223
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5223
|
||||
|
||||
listen xmpp_s2s
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5269
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5269
|
||||
|
||||
listen prosody_proxy65
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5000
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5000
|
||||
|
||||
listen prosody_components
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5270
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5270
|
||||
|
||||
listen prosody_bosh_http
|
||||
bind {{ hostvars['liqueur']['container_ip'] }}:5280
|
||||
server prosody_srv {{ hostvars['prosody']['container_ip'] }}:5280
|
||||
@@ -5,9 +5,16 @@ iface lo inet loopback
|
||||
pre-down ip route del local 0.0.0.0/0 dev lo table 100 2>/dev/null || true
|
||||
pre-down ip rule del fwmark 0x1 lookup 100 2>/dev/null || true
|
||||
|
||||
auto br-eth0
|
||||
iface br-eth0 inet static
|
||||
address 10.1.0.1/24
|
||||
bridge_ports eth0 tap0
|
||||
bridge_stp off
|
||||
pre-up ip tuntap add dev tap0 mode tap || true
|
||||
post-down ip tuntap del dev tap0 mode tap || true
|
||||
|
||||
auto eth0
|
||||
iface eth0 inet manual
|
||||
address 10.1.0.1/24
|
||||
|
||||
auto eth0.2
|
||||
iface eth0.2 inet static
|
||||
@@ -41,12 +48,3 @@ iface eth0.12 inet static
|
||||
|
||||
auto eth1
|
||||
iface eth1 inet dhcp
|
||||
|
||||
auto wg0
|
||||
iface wg0 inet manual
|
||||
post-up ip route add 10.250.250.0/24 dev wg0 2>/dev/null || true
|
||||
post-up ip rule add fwmark 0xc7 lookup 199 2>/dev/null || true
|
||||
post-up ip route add default dev wg0 table 199 2>/dev/null || true
|
||||
pre-down ip route del default dev wg0 table 199 2>/dev/null || true
|
||||
pre-down ip rule del fwmark 0xc7 lookup 199 2>/dev/null || true
|
||||
pre-down ip route del 10.250.250.0/24 dev wg0 2>/dev/null || true
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: deploy ifupdown interfaces
|
||||
ansible.builtin.copy:
|
||||
src: "{{ inventory_hostname }}/interfaces"
|
||||
dest: /etc/network/interfaces
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
register: interfaces_conf
|
||||
|
||||
- name: reload ifupdown2
|
||||
command: ifreload -a
|
||||
when: interfaces_conf.changed
|
||||
@@ -0,0 +1,7 @@
|
||||
---
|
||||
- name: include configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
|
||||
- name: include prerequisites
|
||||
ansible.builtin.include_tasks: prerequisites.yml
|
||||
tags: ifupdown2_prereqs
|
||||
@@ -0,0 +1,17 @@
|
||||
---
|
||||
- name: install bridge-utils
|
||||
ansible.builtin.package:
|
||||
name: bridge-utils
|
||||
state: present
|
||||
register: bridge_utils_install
|
||||
|
||||
- name: ensure rt_tables.d directory exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/iproute2/rt_tables.d
|
||||
state: directory
|
||||
mode: "0755"
|
||||
register: rt_tables_dir
|
||||
|
||||
- name: reload ifupdown2
|
||||
ansible.builtin.command: ifreload -a
|
||||
when: bridge_utils_install.changed or rt_tables_dir.changed
|
||||
@@ -0,0 +1,14 @@
|
||||
---
|
||||
- name: set required locales
|
||||
community.general.locale_gen:
|
||||
name: "{{ item }}"
|
||||
state: present
|
||||
loop: "{{ locales_list }}"
|
||||
|
||||
- name: configure /etc/locale.conf
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/locale.conf
|
||||
content: LANG={{ locale_default }}
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
- name: include locales configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -0,0 +1,9 @@
|
||||
/var/log/xray-core/*.log {
|
||||
daily
|
||||
rotate 4
|
||||
compress
|
||||
delaycompress
|
||||
missingok
|
||||
notifempty
|
||||
copytruncate
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
---
|
||||
- name: deploy logrotate config
|
||||
ansible.builtin.copy:
|
||||
src: "{{ inventory_hostname }}/"
|
||||
dest: "/etc/logrotate.d/"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
@@ -0,0 +1,3 @@
|
||||
---
|
||||
- name: include logrotate configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
@@ -1,49 +0,0 @@
|
||||
flowtable ft {
|
||||
hook ingress priority filter
|
||||
devices = { eth0, eth1 }
|
||||
}
|
||||
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
|
||||
iif lo accept
|
||||
ip protocol icmp accept
|
||||
ip6 nexthdr icmpv6 accept
|
||||
|
||||
meta mark 0x00000001 accept
|
||||
|
||||
iifname eth0 tcp dport 22 accept
|
||||
iifname eth0.11 tcp dport 22 accept
|
||||
|
||||
iifname eth1 udp dport 51820 accept
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
||||
|
||||
iifname eth0.3 udp dport 67 accept
|
||||
iifname eth1 udp dport 68 accept
|
||||
|
||||
#include "/etc/nftables.d/90-input.nft"
|
||||
}
|
||||
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||
|
||||
tcp flags syn tcp option maxseg size set rt mtu
|
||||
|
||||
include "/etc/nftables.d/90-forward.nft"
|
||||
}
|
||||
|
||||
chain output {
|
||||
type route hook output priority filter; policy accept;
|
||||
|
||||
#include "/etc/nftables.d/90-output.nft"
|
||||
}
|
||||
@@ -1,35 +0,0 @@
|
||||
chain vpn_prerouting_dnat {
|
||||
type nat hook prerouting priority dstnat - 5; policy accept;
|
||||
|
||||
iifname wg0 ip daddr 10.250.251.0/24 counter dnat ip prefix to 10.1.0.0/24
|
||||
iifname wg0 ip daddr 10.250.252.0/24 counter dnat ip prefix to 10.2.0.0/24
|
||||
iifname wg0 ip daddr 10.250.253.0/24 counter dnat ip prefix to 10.10.0.0/24
|
||||
iifname wg0 ip daddr 10.250.254.0/24 counter dnat ip prefix to 10.11.0.0/24
|
||||
iifname wg0 ip daddr 10.250.255.0/24 counter dnat ip prefix to 10.12.0.0/24
|
||||
iifname wg0 ip daddr 10.250.249.0/24 counter dnat ip prefix to 10.13.0.0/24
|
||||
}
|
||||
|
||||
chain vpn_postrouting_snat {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
|
||||
oifname wg0 ip saddr 10.1.0.0/24 counter snat ip prefix to 10.250.251.0/24
|
||||
oifname wg0 ip saddr 10.2.0.0/24 counter snat ip prefix to 10.250.252.0/24
|
||||
oifname wg0 ip saddr 10.10.0.0/24 counter snat ip prefix to 10.250.253.0/24
|
||||
oifname wg0 ip saddr 10.11.0.0/24 counter snat ip prefix to 10.250.254.0/24
|
||||
oifname wg0 ip saddr 10.12.0.0/24 counter snat ip prefix to 10.250.255.0/24
|
||||
oifname wg0 ip saddr 10.13.0.0/24 counter snat ip prefix to 10.250.249.0/24
|
||||
}
|
||||
|
||||
chain vpn_prerouting_pbr {
|
||||
type filter hook prerouting priority mangle - 10; policy accept;
|
||||
|
||||
iifname wg0 ct state new counter ct mark set 0x000000c7
|
||||
ip daddr 10.0.0.0/8 return
|
||||
iifname != "wg0" ct mark 0x000000c7 counter mark set 0x000000c7
|
||||
}
|
||||
|
||||
chain vpn_output_pbr {
|
||||
type route hook output priority mangle - 10; policy accept;
|
||||
|
||||
ct mark 0x000000c7 counter meta mark set 0x000000c7
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
chain proxy_prerouting {
|
||||
type filter hook prerouting priority filter - 50; policy accept;
|
||||
|
||||
fib daddr type local accept
|
||||
|
||||
include "/etc/nftables.d/90-proxy.nft"
|
||||
}
|
||||
|
||||
chain proxy_output {
|
||||
type route hook output priority mangle; policy accept;
|
||||
|
||||
#meta mark 0x000000ff return
|
||||
|
||||
#meta l4proto { tcp, udp } ip daddr @cloudflare_ip meta mark set 0x00000001 accept
|
||||
}
|
||||
@@ -1,15 +0,0 @@
|
||||
#!/usr/sbin/nft -f
|
||||
|
||||
flush ruleset
|
||||
|
||||
table inet filter {
|
||||
include "/etc/nftables.d/40-sets.nft"
|
||||
include "/etc/nftables.d/90-sets.nft"
|
||||
include "/etc/nftables.d/10-filter.nft"
|
||||
include "/etc/nftables.d/20-vpn.nft"
|
||||
include "/etc/nftables.d/30-proxy.nft"
|
||||
}
|
||||
|
||||
table ip nat {
|
||||
include "/etc/nftables.d/10-nat.nft"
|
||||
}
|
||||
@@ -2,7 +2,6 @@ chain postrouting {
|
||||
type nat hook postrouting priority srcnat; policy accept;
|
||||
oifname eth1 masquerade
|
||||
}
|
||||
|
||||
chain prerouting {
|
||||
type nat hook prerouting priority dstnat; policy accept;
|
||||
include "/etc/nftables.d/90-dstnat.nft"
|
||||
@@ -0,0 +1,34 @@
|
||||
flowtable ft {
|
||||
hook ingress priority filter
|
||||
devices = { eth0, eth1 }
|
||||
}
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iif lo accept
|
||||
meta mark 0x00000001 accept
|
||||
iifname br-eth0 tcp dport 22 accept
|
||||
iifname eth0.11 tcp dport 22 accept
|
||||
iifname tun0 tcp dport 22 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 61219 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 61219 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } udp dport 53 accept
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } tcp dport 53 accept
|
||||
iifname eth0.3 udp dport 67 accept
|
||||
iifname eth1 udp dport 68 accept
|
||||
include "/etc/nftables.d/90-input.nft"
|
||||
}
|
||||
chain forward {
|
||||
type filter hook forward priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||
iifname { br-eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||
tcp flags syn tcp option maxseg size set rt mtu
|
||||
include "/etc/nftables.d/90-forward.nft"
|
||||
}
|
||||
chain output {
|
||||
type route hook output priority filter; policy accept;
|
||||
include "/etc/nftables.d/90-output.nft"
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
chain proxy_prerouting {
|
||||
type filter hook prerouting priority filter - 50; policy accept;
|
||||
fib daddr type local accept
|
||||
meta mark 0x00000001 iif "lo" meta l4proto { tcp, udp } tproxy ip to :61219 counter accept
|
||||
include "/etc/nftables.d/90-proxy-prerouting.nft"
|
||||
}
|
||||
chain proxy_output {
|
||||
type route hook output priority mangle; policy accept;
|
||||
meta mark != 0 return
|
||||
include "/etc/nftables.d/90-proxy-output.nft"
|
||||
}
|
||||
@@ -1,4 +1,4 @@
|
||||
---
|
||||
- name: reload nftables
|
||||
- name: restart nftables
|
||||
ansible.builtin.command: nft -f /etc/nftables.conf
|
||||
listen: reload nftables
|
||||
listen: restart nftables
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
---
|
||||
- name: ensure /etc/nftables.d exists
|
||||
ansible.builtin.file:
|
||||
path: /etc/nftables.d
|
||||
state: directory
|
||||
mode: "0755"
|
||||
when: nftables_bootstrap_files | default(false)
|
||||
|
||||
- name: bootstrap empty config files
|
||||
ansible.builtin.copy:
|
||||
dest: "/etc/nftables.d/{{ item }}"
|
||||
content: ""
|
||||
force: false
|
||||
mode: "0644"
|
||||
loop:
|
||||
- 10-sets.nft
|
||||
- 20-sets.nft
|
||||
- 30-nat.nft
|
||||
- 40-filter.nft
|
||||
- 50-proxy.nft
|
||||
- 90-dstnat.nft
|
||||
- 90-forward.nft
|
||||
- 90-input.nft
|
||||
- 90-output.nft
|
||||
- 90-proxy-output.nft
|
||||
- 90-proxy-prerouting.nft
|
||||
when: nftables_bootstrap_files | default(false)
|
||||
|
||||
- name: deploy nftables rules
|
||||
ansible.builtin.copy:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/nftables.d/{{ item | basename }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/files/' + inventory_hostname + '/*.nft') }}"
|
||||
notify: restart nftables
|
||||
|
||||
- name: render nftable rules
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/nftables.d/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.nft.j2') }}"
|
||||
notify: restart nftables
|
||||
|
||||
- name: deploy nftables.conf
|
||||
ansible.builtin.template:
|
||||
src: "{{ item }}"
|
||||
dest: "/etc/{{ item | basename | regex_replace('\\.j2$', '') }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0644"
|
||||
validate: "nft -c -f %s"
|
||||
loop: "{{ query('ansible.builtin.fileglob', role_path + '/templates/' + inventory_hostname + '/*.conf.j2') }}"
|
||||
notify: restart nftables
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user