Compare commits
9
Commits
29d4f33a46
..
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
161f8fc94e
|
||
|
|
3208cd0b09
|
||
|
|
e5f178e583
|
||
|
|
1accba1566
|
||
|
|
101c1cc0aa
|
||
|
|
a367b3c5e4
|
||
|
|
673e318824
|
||
|
|
71261e4017
|
||
|
|
9fb64cef30
|
+1
-1
@@ -20,7 +20,7 @@ uv.lock
|
||||
/.devcontainer/
|
||||
.lock
|
||||
/.cache/
|
||||
/roles/**/files/user/wg/containerized/*.conf
|
||||
/roles/**/files/user/wg/authorized_clients.d/*.conf
|
||||
|
||||
# Try tyo avoid any plain-text passwords
|
||||
*pwd*
|
||||
|
||||
@@ -89,7 +89,7 @@ Other common ones, especially for services, are `port` (which can be an integer
|
||||
|
||||
## Essential Usage
|
||||
|
||||
Before running any Ansible playbooks in either development or production mode, make sure to specify the username and the home directory path of the user on the system you are currently using in `{ANSIBLE_PROJECT_ROOT}/vars/local_facts.yml`.
|
||||
Before running any Ansible [playbooks](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_intro.html) in either development or production mode, make sure to specify the username and the home directory path of the user on the system you are currently using in `{ANSIBLE_PROJECT_ROOT}/vars/local_facts.yml`.
|
||||
|
||||
### Development Mode
|
||||
|
||||
@@ -184,11 +184,11 @@ ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=staging1.test" --ext
|
||||
|
||||
As long as you are matching the appropriate set of [playbook variable files](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_variables.html#defining-variables-in-included-files-and-roles) or settings files with the [playbook](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_intro.html) according to its need of those variable definitions/declarations, mostly determined by [the intended targeted hosts' own variables](https://docs.ansible.com/projects/ansible/latest/inventory_guide/intro_inventory.html#host-variables) together with role [handlers](https://docs.ansible.com/projects/ansible/latest/inventory_guide/intro_inventory.html#host-variables), and as long as you have appropriately set up software installations, (see [Software Management](#software-management)) creating new/custom [playbooks](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_intro.html) should be relatively easy.
|
||||
|
||||
Depending on what you are trying to do with a new playbook, the best approach may be to just copy/duplicate the extant playbook files and then edit them, as this allows one to mitigate errors as well as have a reliable reference point for changes.
|
||||
Depending on what you are trying to do with a new [playbook](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_intro.html), the best approach may be to just copy/duplicate the extant [playbook files](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_intro.html) and then edit them, as this allows one to mitigate errors as well as have a reliable reference point for changes.
|
||||
|
||||
### CLI Tool
|
||||
|
||||
As an alternative, you can use the `skato-ansible` shell script in `$ANSIBLE_PROJECT_ROOT` as an abstraction of the `ansible-playbook` commands for the container routing case, though it is a WIP that currently only makes sense for development mode playbook executions. I plan to replace it with a CLI app covering more intended use-cases.
|
||||
As an alternative, you can use the `skato-ansible` shell script in `$ANSIBLE_PROJECT_ROOT` as an abstraction of the `ansible-playbook` commands for the container routing case. I plan to replace it with a CLI app covering more intended use-cases.
|
||||
|
||||
When using the `skato-ansible.sh` script in development mode for the container routing use case:
|
||||
|
||||
@@ -196,15 +196,34 @@ When using the `skato-ansible.sh` script in development mode for the container r
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
./skato-ansible.sh init vps -s 0 -v 2 -m dev -n staging0.test
|
||||
./skato-ansible.sh init vps -v 3 -m dev -n staging0.test
|
||||
./skato-ansible.sh populate-agent staging
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 2 -m dev -n staging0.test
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 3 -m dev -n staging0.test
|
||||
|
||||
./skato-ansible.sh init homeserver -s 0 -v 2 -m dev -n staging1.test
|
||||
./skato-ansible.sh init homeserver -v 3 -m dev -n staging1.test
|
||||
# BELOW ONLY IF $SKANSIBLE_SSH_KEY ALTERED IN THE SHELL SCRIPT
|
||||
# ./skato-ansible.sh populate-agent staging
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 2 -m dev -n staging1.test
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 3 -m dev -n staging1.test
|
||||
```
|
||||
|
||||
Otherwise, in production mode:
|
||||
|
||||
```bash
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
INVENTORY_HOSTNAMES=(web1 web2)
|
||||
FQDN=web.site
|
||||
|
||||
./skato-ansible.sh init vps -v 3 -n "${INVENTORY_HOSTNAMES[0]}" -d "$FQDN"
|
||||
./skato-ansible.sh populate-agent staging
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 3 -n "${INVENTORY_HOSTNAMES[0]}" -d "$FQDN"
|
||||
|
||||
./skato-ansible.sh init homeserver -v 3 -n "${INVENTORY_HOSTNAMES[1]}" -d "$FQDN"
|
||||
# BELOW ONLY IF $SKANSIBLE_SSH_KEY ALTERED IN THE SHELL SCRIPT
|
||||
# ./skato-ansible.sh populate-agent staging
|
||||
./skato-ansible.sh bootstrap vps -s 1 -v 3 -n "${INVENTORY_HOSTNAMES[1]}" -d "$FQDN"
|
||||
```
|
||||
|
||||
> [!IMPORTANT]
|
||||
> If you have different SSH keypairs for staging, make sure to change the value of `SKANSIBLE_SSH_KEYS` environment variable in the `${ANSIBLE_PROJECT_ROOT}/skato-ansible.sh` shell script before running the above shell script from `$ANSIBLE_PROJECT_ROOT`.
|
||||
> If you have different SSH keypairs for staging, make sure to change the value of `SKANSIBLE_SSH_KEYS` environment variable in the `${ANSIBLE_PROJECT_ROOT}/skato-ansible.sh` shell script before running the above shell scripts from `$ANSIBLE_PROJECT_ROOT`.
|
||||
|
||||
@@ -195,6 +195,14 @@ pkgs:
|
||||
suites: ~
|
||||
comps: ~
|
||||
handler: default
|
||||
- name: "kitty-terminfo"
|
||||
uri: ~
|
||||
sigkey: ~
|
||||
sources: ~
|
||||
types: ~
|
||||
suites: ~
|
||||
comps: ~
|
||||
handler: default
|
||||
- name: "git-doc"
|
||||
uri: ~
|
||||
sigkey: ~
|
||||
|
||||
@@ -409,6 +409,14 @@ pkgs:
|
||||
suites: ~
|
||||
comps: ~
|
||||
handler: default
|
||||
- name: minidlna
|
||||
uri: ~
|
||||
sigkey: ~
|
||||
sources: ~
|
||||
types: ~
|
||||
suites: ~
|
||||
comps: ~
|
||||
handler: default
|
||||
userspace:
|
||||
- name: aria2
|
||||
uri: ~
|
||||
|
||||
@@ -83,7 +83,7 @@
|
||||
- name: Dupliciating DSNet VPN service client configuration files to control node
|
||||
ansible.builtin.fetch:
|
||||
src: "{{ ansible_user_home.stdout }}/.wg/authorized_clients.d/{{ item.name }}{{ (idx | string) }}.conf"
|
||||
dest: "./roles/init-server/files/user/wg/containerized/{{ item.name }}{{ (idx | string) }}.conf"
|
||||
dest: "./roles/init-server/files/user/wg/authorized_clients.d/{{ item.name }}{{ (idx | string) }}.conf"
|
||||
flat: true
|
||||
loop: "{{ vpn.clients }}"
|
||||
loop_control:
|
||||
|
||||
@@ -173,7 +173,7 @@
|
||||
block:
|
||||
- name: Creating subdirectory for VPN client container specified by Compose file
|
||||
ansible.builtin.file:
|
||||
path: "{{ ansible_user_home.stdout }}/.wg/containerized"
|
||||
path: "{{ ansible_user_home.stdout }}/.wg/authorized_clients.d"
|
||||
recurse: true
|
||||
owner: "{{ ansible_user }}"
|
||||
group: "{{ ansible_user }}"
|
||||
@@ -183,8 +183,8 @@
|
||||
become_user: "{{ current_user.stdout }}"
|
||||
when: ((fqdn is defined and fqdn != None) and item.name == fqdn) or item.name == inventory_hostname
|
||||
ansible.builtin.copy:
|
||||
src: "user/wg/containerized/{{ item.name }}{{ (idx | string) }}.conf"
|
||||
dest: "{{ ansible_user_home.stdout }}/.wg/containerized/"
|
||||
src: "user/wg/authorized_clients.d/{{ item.name }}{{ (idx | string) }}.conf"
|
||||
dest: "{{ ansible_user_home.stdout }}/.wg/authorized_clients.d/"
|
||||
owner: "{{ ansible_user }}"
|
||||
group: "{{ ansible_user }}"
|
||||
mode: "644"
|
||||
|
||||
+23
-21
@@ -15,24 +15,24 @@ if [[ "$1" == "version" ]]; then
|
||||
fi
|
||||
|
||||
if [[ "$1" == "show-defaults" ]]; then
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
printf "Private SSH keys available throufh SSH agent: |\n%s\n" "$(ssh-add -l)"
|
||||
fi
|
||||
|
||||
if [[ "$1" == "start-agent" ]]; then
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
eval "$(ssh-agent -s)"
|
||||
fi
|
||||
|
||||
if [[ "$1" == "list-agent" ]]; then
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
ssh-add -l
|
||||
fi
|
||||
|
||||
if [[ "$1" == "populate-agent" ]]; then
|
||||
shift 1
|
||||
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
|
||||
if [[ "$1" == "all" ]]; then
|
||||
for SKANSIBLE_SSH_KEY in ~/.ssh/*; do
|
||||
@@ -69,7 +69,7 @@ fi
|
||||
if [[ "$1" == "init" ]]; then
|
||||
shift 1
|
||||
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
|
||||
if [[ "$1" == "vps" ]]; then
|
||||
SKANSIBLE_PLAY_HOST="$1"
|
||||
@@ -82,7 +82,7 @@ if [[ "$1" == "init" ]]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
while getopts "htm:s:n:v:u:" opt; do
|
||||
while getopts "htd:m:s:n:v:u:" opt; do
|
||||
case $opt in
|
||||
h) Help "init";;
|
||||
s) SKANSIBLE_STAGE="$OPTARG";;
|
||||
@@ -91,6 +91,7 @@ if [[ "$1" == "init" ]]; then
|
||||
t) SKANSIBLE_UNITTEST=True;;
|
||||
u) export ANSIBLE_REMOTE_USER="$OPTARG";;
|
||||
m) SKANSIBLE_MODE="$OPTARG";;
|
||||
d) SKANSIBLE_FQDN="$OPTARG";;
|
||||
*) echo "Err: Invalid option set"; exit 1;;
|
||||
esac
|
||||
done
|
||||
@@ -99,23 +100,23 @@ if [[ "$1" == "init" ]]; then
|
||||
# SKANSIBLE_CONN_HOST=staging${SKANSIBLE_STAGE}.test
|
||||
if [[ "$SKANSIBLE_STAGE" == 0 ]]; then
|
||||
if [[ "$SKANSIBLE_UNITTEST" == "True" ]]; then
|
||||
sudo ansible-playbook -CKk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
sudo ansible-playbook -CKk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
else
|
||||
sudo ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
sudo ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
elif [[ "$SKANSIBLE_STAGE" == 1 ]]; then
|
||||
if [[ "$SKANSIBLE_UNITTEST" == "True" ]]; then
|
||||
sudo ansible-playbook -CK -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
sudo ansible-playbook -CK -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
else
|
||||
sudo ansible-playbook -K -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
sudo ansible-playbook -K -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
fi
|
||||
else
|
||||
if [[ -z "$SKANSIBLE_CONN_HOST" ]]; then
|
||||
echo "When not doing staging, chosen or preferred host must be made explicit"
|
||||
if [[ -z "$SKANSIBLE_CONN_HOST" ]] && [[ -z "$SKANSIBLE_FQDN" ]]; then
|
||||
echo "When not doing staging, chosen or preferred host must be made explicit as well as desired FQDN"
|
||||
exit 1
|
||||
else
|
||||
sudo ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=prod" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
sudo ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-root}" --extra-vars "mode=prod" --extra-vars "fqdn=${SKANSIBLE_FQDN}" "init@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
fi
|
||||
|
||||
@@ -125,7 +126,7 @@ fi
|
||||
if [[ "$1" == "bootstrap" ]]; then
|
||||
shift 1
|
||||
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.env/bin/activate"
|
||||
source "${SKANSIBLE_SCRIPT_PATH}/.venv/bin/activate"
|
||||
|
||||
if [[ "$1" == "vps" ]]; then
|
||||
SKANSIBLE_PLAY_HOST="$1"
|
||||
@@ -138,7 +139,7 @@ if [[ "$1" == "bootstrap" ]]; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
while getopts "htm:s:n:v:u:" opt; do
|
||||
while getopts "htd:m:s:n:v:u:" opt; do
|
||||
case $opt in
|
||||
h) Help "bootstrap";;
|
||||
s) SKANSIBLE_STAGE="$OPTARG";;
|
||||
@@ -147,6 +148,7 @@ if [[ "$1" == "bootstrap" ]]; then
|
||||
t) SKANSIBLE_UNITTEST=True;;
|
||||
u) export ANSIBLE_REMOTE_USER="$OPTARG";;
|
||||
m) SKANSIBLE_MODE="$OPTARG";;
|
||||
d) SKANSIBLE_FQDN="$OPTARG";;
|
||||
*) echo "Err: Invalid option set"; exit 1;;
|
||||
esac
|
||||
done
|
||||
@@ -155,23 +157,23 @@ if [[ "$1" == "bootstrap" ]]; then
|
||||
# SKANSIBLE_CONN_HOST=staging${SKANSIBLE_STAGE}.test
|
||||
if [[ "$SKANSIBLE_STAGE" == 0 ]]; then
|
||||
if [[ "$SKANSIBLE_UNITTEST" == "True" ]]; then
|
||||
ansible-playbook -CKk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
ansible-playbook -CKk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
else
|
||||
ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
elif [[ "$SKANSIBLE_STAGE" == 1 ]]; then
|
||||
if [[ "$SKANSIBLE_UNITTEST" == "True" ]]; then
|
||||
ansible-playbook -CK -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
ansible-playbook -CK -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
else
|
||||
ansible-playbook -K -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
ansible-playbook -K -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=${SKANSIBLE_MODE}" --extra-vars "fqdn=${SKANSIBLE_FQDN:-staging.test}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
fi
|
||||
else
|
||||
if [[ -z "$SKANSIBLE_CONN_HOST" ]]; then
|
||||
echo "When not doing staging, chosen or preferred host must be made explicit"
|
||||
echo "When not doing staging, chosen or preferred host must be made explicit as well as desired FQDN"
|
||||
exit 1
|
||||
else
|
||||
ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=prod" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
ansible-playbook -Kk -i hosts.yml --extra-vars "chosen_host=${SKANSIBLE_CONN_HOST}" --extra-vars "chosen_user=${ANSIBLE_REMOTE_USER:-senpai}" --extra-vars "mode=prod" --extra-vars "fqdn=${SKANSIBLE_FQDN}" "administrate@${SKANSIBLE_PLAY_HOST}.yml"
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
Reference in New Issue
Block a user