Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8d795250f6 | ||
|
|
d3e03c1675 | ||
|
|
2076557875 | ||
|
|
00c1bb8b20 | ||
|
|
8d6025bcf3 | ||
|
|
491ba60d3c | ||
|
|
8e44f56f95 |
@@ -8,21 +8,13 @@ help: ## Print the help message
|
|||||||
sort | \
|
sort | \
|
||||||
column -s ':' -t
|
column -s ':' -t
|
||||||
|
|
||||||
include wg.mk
|
|
||||||
|
|
||||||
.PHONY: check
|
.PHONY: check
|
||||||
check: ## Check you have all dependencies
|
check: ## Check you have all dependencies
|
||||||
@command -v graph-easy >/dev/null || { echo "Install perl-graph-easy" && exit 1 ;}
|
@command -v graph-easy >/dev/null || { echo "Install perl-graph-easy" && exit 1 ;}
|
||||||
@command -v ansible >/dev/null || { echo "Install ansible" && exit 1 ;}
|
|
||||||
@command -v recsel >/dev/null || { echo "Install recutils" && exit 1 ;}
|
@command -v recsel >/dev/null || { echo "Install recutils" && exit 1 ;}
|
||||||
@command -v wg >/dev/null || { echo "Install wireguard" && exit 1 ;}
|
|
||||||
@command -v lowdown >/dev/null || { echo "Install lowdown" && exit 1 ;}
|
@command -v lowdown >/dev/null || { echo "Install lowdown" && exit 1 ;}
|
||||||
@echo "All dependencies installed"
|
@echo "All dependencies installed"
|
||||||
|
|
||||||
%/:
|
|
||||||
mkdir $@
|
|
||||||
echo '*' > $@.gitignore
|
|
||||||
|
|
||||||
########## Network Map ##########
|
########## Network Map ##########
|
||||||
|
|
||||||
graph_program != type graph-easy > /dev/null && printf graph-easy || printf dot
|
graph_program != type graph-easy > /dev/null && printf graph-easy || printf dot
|
||||||
|
|||||||
@@ -1,46 +0,0 @@
|
|||||||
hosts = $(wildcard host_vars/*.yml)
|
|
||||||
|
|
||||||
logs = $(patsubst host_vars/%.yml, logs/%.json, $(hosts) )
|
|
||||||
|
|
||||||
playbooks = $(wildcard playbooks/*.yml)
|
|
||||||
plays = $(patsubst playbooks/%.yml, %, $(playbooks) )
|
|
||||||
|
|
||||||
defaults += $(wildcard logs/*)
|
|
||||||
|
|
||||||
###### Recipes ######
|
|
||||||
|
|
||||||
.PHONY: help
|
|
||||||
help: ## Print the help message.
|
|
||||||
@awk 'BEGIN {FS = ":.*?## "} /^[0-9a-zA-Z._-]+:.*?## / {printf "\033[36m%s\033[0m : %s\n", $$1, $$2}' $(MAKEFILE_LIST) | \
|
|
||||||
column -s ':' -t
|
|
||||||
|
|
||||||
.PHONY: lint
|
|
||||||
lint: $(playbooks) | .ansible/ ## Check syntax and lint all playbooks
|
|
||||||
ansible-playbook --syntax-check $^
|
|
||||||
ansible-lint $^
|
|
||||||
|
|
||||||
.PHONY: records
|
|
||||||
records: $(logs) ## Current info on each host
|
|
||||||
|
|
||||||
$(logs): logs/%.json: | logs/
|
|
||||||
ansible -m setup $(basename $(@F) ) > $@
|
|
||||||
|
|
||||||
-include logs/play.mk
|
|
||||||
|
|
||||||
make_play = printf '.PHONY: %s\n%s: %s \#\# %s\n\n' '$(notdir $(basename $1) )' '$(notdir $(basename $1) )' '$1' '$(shell grep -m1 -oP 'name: \K.*' $1)'
|
|
||||||
|
|
||||||
logs/play.mk: playbooks/*.yml
|
|
||||||
@$(RM) $@
|
|
||||||
@$(foreach book, $^, \
|
|
||||||
$(call make_play, $(book), $@ ) >> $@ ; \
|
|
||||||
printf '\t%s\n\n' 'ansible-playbook $(book)' >> $@ ; \
|
|
||||||
)
|
|
||||||
|
|
||||||
%/:
|
|
||||||
mkdir $@
|
|
||||||
echo '*' > $@.gitignore
|
|
||||||
|
|
||||||
.PHONY: clean
|
|
||||||
clean: ## Remove generated files.
|
|
||||||
$(RM) $(defaults)
|
|
||||||
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
[defaults]
|
|
||||||
inventory = hosts.yaml
|
|
||||||
local_tmp = .ansible
|
|
||||||
cow_selection = random
|
|
||||||
vault_password_file = pass.sh
|
|
||||||
interpreter_python = auto_silent
|
|
||||||
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
37363765623839666637633861353139353935323364343538356536653561373266336161353937
|
|
||||||
3466653434666163313936393366613666393863616262320a643930663038326666653064613062
|
|
||||||
62613661396538363539643938323033663932326362626335333438653865623038336136623030
|
|
||||||
3735366564366431330a373061393766346631643434383364646431346231356466663737626435
|
|
||||||
64303835343237383761633939643431333439643933636139666163393637363430633261633736
|
|
||||||
34626631366163616439366534393031353063363138356638323634313430666330613833386661
|
|
||||||
61346365313534353535633365626364303565363565353765353833363065343232633866633132
|
|
||||||
63643930633266653765
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
all:
|
|
||||||
vars:
|
|
||||||
username: dmz
|
|
||||||
locale: Europe/Belgrade
|
|
||||||
libc_locale: en_GB.UTF-8 UTF-8
|
|
||||||
var_locale: LANG=en_GB.UTF-8
|
|
||||||
|
|
||||||
wireguard:
|
|
||||||
hosts:
|
|
||||||
192.168.10.93:
|
|
||||||
arch:
|
|
||||||
hosts:
|
|
||||||
10.0.0.1:
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
|
|
||||||
pass dmz/xecut/dmz_ansible
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
33343563633965306633313265643038646236633465353133386365346663336163646430333962
|
|
||||||
6165663662663065623232383636336236376363623762640a633139343330646532333631396639
|
|
||||||
39323432323636626166636561383539353161646636666131623833396138666531616366633032
|
|
||||||
3064646331643732660a613562343637393134323830643263393464363332663664623761636636
|
|
||||||
38343638623539636134633735313161353233333936396638653066346163613335353266343334
|
|
||||||
39313062633261393038636131313665653631333039633533363236636131323337633031386436
|
|
||||||
38366435386334303366636231643565383931373936313365363165666464636236376262363336
|
|
||||||
31363664336535343363646231306237383739326239356232343761623937666533663131323266
|
|
||||||
30323138663666666538353063623566333961326233646533323831363433653764323566333564
|
|
||||||
37633865313966336164336433306663343435653062396533633037333430366266376465613039
|
|
||||||
35373762306363393534373861633839353736373463346638613838636466383762336562386434
|
|
||||||
37666133666662633331313863636161343031666438363638356538623164343764353431373566
|
|
||||||
35653662326134366366323835623265663530323132313138393566653063376163366132326232
|
|
||||||
62653337383336396466386631393739633164646433373231656664376463306333643663393061
|
|
||||||
32303535323336313364343131333633633261313761326566643733646564313432396165316532
|
|
||||||
62303539653763343963343865626135633738666331366334353530393961623337363035333662
|
|
||||||
38396533376166363164623531396238356632336534386636363364646263623334336666343834
|
|
||||||
37396235346431393033303834323163646561643162646135383162623034343366613431366563
|
|
||||||
66386330323933363035393330326539336134616364303037633230663664373335663739343361
|
|
||||||
36653533333139336331393239626335623337663133393538343361303431636661316666383733
|
|
||||||
64343234306336353163323235633031343138643661333863373965623666336331636339653862
|
|
||||||
61616431366439643063313336336530383164313639646130383362643339386264333264376236
|
|
||||||
63333531616561636638376635623738623933363933663439373137396334623361656233616236
|
|
||||||
64386638653336616366653836663762306334363065356162353431633332633537623362643363
|
|
||||||
3265
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
$ANSIBLE_VAULT;1.1;AES256
|
|
||||||
39653235613163636362653036663563383839313836643563323462616163353364323862313039
|
|
||||||
6564656661323039393563636133303132626663366233390a343535383963353763383364376438
|
|
||||||
36306435396461393132653161393238623562393465356166343764336661376434333335643863
|
|
||||||
3865373732363761620a613236613963396638613831326332386530326239373062333933646239
|
|
||||||
39313336383366636133646336653236303261346238306336663564373063383634313361356335
|
|
||||||
6334353863363931643338663833333065343435333231623466
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
GH+qA1Au9BraGhNt7Aqp8tdhGVfH8ENnY3VzKhe69XQ=
|
|
||||||
@@ -1,38 +0,0 @@
|
|||||||
---
|
|
||||||
- name: Install Wireguard on Server
|
|
||||||
hosts: wireguard
|
|
||||||
user: root
|
|
||||||
|
|
||||||
tasks:
|
|
||||||
- name: Install wireguard tools and dig
|
|
||||||
ansible.builtin.package:
|
|
||||||
name:
|
|
||||||
- wireguard-tools
|
|
||||||
- bind
|
|
||||||
|
|
||||||
- name: Copy keys to server
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: wireguard/wg0.conf
|
|
||||||
dest: /etc/wireguard/wg0.conf
|
|
||||||
notify: Reload systemd daemon
|
|
||||||
|
|
||||||
- name: Get server public IP
|
|
||||||
ansible.builtin.command: dig +short myip.opendns.com @resolver1.opendns.com
|
|
||||||
register: wireguard_public_ip
|
|
||||||
|
|
||||||
- name: Allow ipv4 forwarding
|
|
||||||
ansible.builtin.lineinfile:
|
|
||||||
path: /etc/sysctl.d/wg.conf
|
|
||||||
line: net.ipv4.ip_forward=1
|
|
||||||
create: yes
|
|
||||||
|
|
||||||
- name: Start the wireguard service
|
|
||||||
ansible.builtin.service:
|
|
||||||
name: wg-quick@wg0
|
|
||||||
enabled: yes
|
|
||||||
|
|
||||||
handlers:
|
|
||||||
- name: Reload systemd daemon
|
|
||||||
ansible.builtin.command:
|
|
||||||
cmd: systemctl daemon-reload
|
|
||||||
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
|
|
||||||
[Interface]
|
|
||||||
Address = 10.0.0.1/24
|
|
||||||
SaveConfig = true
|
|
||||||
PrivateKey = {{ wg_private_key }}
|
|
||||||
ListenPort = 51900
|
|
||||||
|
|
||||||
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
|
||||||
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
|
|
||||||
|
|
||||||
[Peer]
|
|
||||||
PublicKey = {{ wg_public_key }}
|
|
||||||
AllowedIPs = 10.0.0.2/32
|
|
||||||
|
|
||||||
@@ -18,29 +18,13 @@ VMID: 119
|
|||||||
`/var/discourse_docker/discourse_doctor`
|
`/var/discourse_docker/discourse_doctor`
|
||||||
|
|
||||||
|
|
||||||
## Docker rebuild errors
|
Latest update:
|
||||||
|
|
||||||
`/var/discourse_docker/launcher rebuild web_only`
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
Plugin name is 'ldap', but plugin directory is named 'discourse-ldap-auth'
|
|
||||||
rake aborted!
|
|
||||||
ActiveRecord::NoDatabaseError: We could not find your database: discoursedb. Available database configurations can be found in config/database.yml. (ActiveRecord::NoDatabaseError)
|
|
||||||
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
FAILED
|
|
||||||
--------------------
|
|
||||||
Pups::ExecError: cd /var/www/discourse && su discourse -c 'bundle exec rake db:migrate' failed with return #<Process::Status: pid 593 exit 1>
|
|
||||||
Location of failure: /usr/local/lib/ruby/gems/3.3.0/gems/pups-1.3.0/lib/pups/exec_command.rb:131:in `spawn'
|
|
||||||
exec failed with the params {"cd"=>"$home", "tag"=>"migrate", "hook"=>"db_migrate", "cmd"=>["su discourse -c 'bundle exec rake db:migrate'"]}
|
|
||||||
bootstrap failed with exit code 1
|
|
||||||
** FAILED TO BOOTSTRAP ** please scroll up and look for earlier error messages, there may be more than one.
|
|
||||||
./discourse-doctor may help diagnose the problem.
|
|
||||||
a9a704b1ee166487d8cd2acd5bd9bcc050ed0ec93fc065f58440e4ae208e1937
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
|
- The forum has been restored; images should load when clicked but may not display immediately.
|
||||||
|
- Resolved several problems sequentially: admin panel and updates were failing, Docker builds failed due to PostgreSQL 13, upgraded to 15.
|
||||||
|
- Restored from backup and created a new backup from the old SQL server, transferring data via PostgreSQL 15.
|
||||||
|
- Manually enabled the required vector extension on the new database because Discourse could not do it automatically.
|
||||||
|
- Docker container rebuild succeeded only after disabling the SSL template in the Docker configuration.
|
||||||
|
- After rebuild, the forum returned with new posts but login failed and media/files were missing.
|
||||||
|
- Uploaded files after May 1 were lost; database and uploads backups were found in the shared folder.
|
||||||
|
- Login issue was caused by a missing SSL template; resolved by setting up an Nginx reverse‑proxy with a self‑signed certificate on the forum VM, allowing SSL access through the main HTTP VM.
|
||||||
|
|||||||
@@ -0,0 +1,36 @@
|
|||||||
|
# Service Catalog: sumadijamoxx
|
||||||
|
|
||||||
|
## 🛠️ Overview
|
||||||
|
|
||||||
|
IP addresses follow the container ID pattern:
|
||||||
|
`101 ssh12` -> `192.168.7.101`
|
||||||
|
|
||||||
|
|
||||||
|
| VMID | Name | OS | Notes |
|
||||||
|
| :--- | :--- | :--- | :--- |
|
||||||
|
| [101](./ssh12/) | [ssh12](./ssh12/) | 12 | SSH Jump host |
|
||||||
|
| [102](./nginx13/) | [nginx13](./nginx13/) | 13 | Proxy |
|
||||||
|
| [103](./searxng12/) | [searxng12](./searxng12/) | 12 | Search |
|
||||||
|
| [104](./homepage12/) | [homepage12](./homepage12/) | 12 | Dashboard |
|
||||||
|
| [105](./pastebin13/) | [pastebin13](./pastebin13/) | 13 | Pastebin |
|
||||||
|
| [106](./librespeed-rust12/) | [librespeed-rust12](./librespeed-rust12/) | 12 | Speedtest |
|
||||||
|
| [107](./tor13/) | [tor13](./tor13/) | 13 | Tor Onion Service |
|
||||||
|
| [200](./wireguard12/) | [wireguard12](./wireguard12/) | 12 | VPN |
|
||||||
|
|
||||||
|
|
||||||
|
##### Legend
|
||||||
|
|
||||||
|
- `12` -> Debian 12
|
||||||
|
- `13` -> Debian 13
|
||||||
|
|
||||||
|
## 🌐 Forwarded Ports
|
||||||
|
|
||||||
|
- `192.168.7.243:443` -> `443`
|
||||||
|
- `192.168.7.243:80` -> `80`
|
||||||
|
- `192.168.7.101:22` -> `22`
|
||||||
|
|
||||||
|
## 🌐 Public URLs
|
||||||
|
|
||||||
|
- Website: https://sumadija.dmz.rs
|
||||||
|
- Pastebin: https://pastebin.dmz.rs
|
||||||
|
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
---
|
||||||
|
VMID: 109
|
||||||
|
---
|
||||||
|
# Nginx
|
||||||
|
|
||||||
|
**VMID:** 102
|
||||||
|
**OS/Version:** Debian 13
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** `192.168.7.109`
|
||||||
|
- **Internal Port:** `80`
|
||||||
|
- **External/Proxy URL:** `https://sumadija.dmz.rs`
|
||||||
|
- **Access Type:** Local / Public (via proxy)
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Dependencies:** None
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- Forwarded to port 80 and 443.
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
VMID: 105
|
||||||
|
---
|
||||||
|
# PrivateBin
|
||||||
|
|
||||||
|
**VMID:** 105
|
||||||
|
**OS/Version:** Debian 13
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** `192.168.7.105`
|
||||||
|
- **Internal Port:** `[N/A]`
|
||||||
|
- **External/Proxy URL:** `https://pastebin.dmz.rs`
|
||||||
|
- **Access Type:** Forwarded
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Built with:** [PrivateBin Proxmox Script](https://community-scripts.github.io/ProxmoxVE/scripts?id=privatebin)
|
||||||
|
- **Dependencies:** None
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- Not yet public/forwarded.
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Router
|
||||||
|
|
||||||
|
**VMID:** [N/A]
|
||||||
|
**OS/Version:** TPLink (Hopefully OpenWRT in future)
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** 192.168.7.1
|
||||||
|
- **Internal Port:** `[N/A]`
|
||||||
|
- **External/Proxy URL:** `[N/A]`
|
||||||
|
- **Access Type:** Local
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Built with:** N/A
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- Router is inside the existing network for further forwarding.
|
||||||
|
- Contact coja (best on xmpp) for access/info.
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
VMID: 102
|
||||||
|
---
|
||||||
|
# SearXNG
|
||||||
|
|
||||||
|
**VMID:** 103
|
||||||
|
**OS/Version:** Debian 12
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** `192.168.7.103`
|
||||||
|
- **Internal Port:** `[N/A]`
|
||||||
|
- **External/Proxy URL:** `https://search.dmz.rs`
|
||||||
|
- **Access Type:** Local (Not yet public/forwarded)
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Built with:** [SearXNG Proxmox Script](https://community-scripts.github.io/ProxmoxVE/scripts?id=searxng)
|
||||||
|
- **Dependencies:** None
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- Not yet public/forwarded.
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
---
|
||||||
|
VMID: 101
|
||||||
|
---
|
||||||
|
# SSH Gateway
|
||||||
|
|
||||||
|
**VMID:** 101
|
||||||
|
**OS/Version:** Debian 12
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** `192.168.7.101`
|
||||||
|
- **Internal Port:** `22`
|
||||||
|
- **External/Proxy URL:** `https://sumadija.dmz.rs`
|
||||||
|
- **Access Type:** Public (via SSH forwarding)
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Built with:** N/A
|
||||||
|
- **Dependencies:** None
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- SSH port from this container should be forwarded to `sumadija.dmz.rs`.
|
||||||
|
- SSH access to other containers is done through this one with SSH jump.
|
||||||
|
- **Security:** Passwords are disabled; only key verification is used.
|
||||||
|
- [Wiki Guide](https://wiki.dmz.rs/en/sysadmin/ssh)
|
||||||
|
|
||||||
@@ -0,0 +1,24 @@
|
|||||||
|
---
|
||||||
|
VMID: 107
|
||||||
|
---
|
||||||
|
# Tor Onion Service
|
||||||
|
|
||||||
|
**VMID:** 107
|
||||||
|
**OS/Version:** Debian 13
|
||||||
|
|
||||||
|
## 🌐 Connectivity
|
||||||
|
- **Local IP:** `192.168.7.107`
|
||||||
|
- **Internal Port:** `[N/A]`
|
||||||
|
- **External/Proxy URL:** `[Tor Onion Address]`
|
||||||
|
- **Access Type:** Public (via Tor)
|
||||||
|
|
||||||
|
## 🛠️ Details
|
||||||
|
- **Built with:** N/A
|
||||||
|
- **Dependencies:** None
|
||||||
|
|
||||||
|
## 📝 Notes
|
||||||
|
- This container hosts the Tor onion service, used for remote access to Proxmox through Tor.
|
||||||
|
- **Credentials:** Stored in **dmzadmin** (password manager).
|
||||||
|
- **Remote access targets:**
|
||||||
|
- `ssh12` -> port 22
|
||||||
|
- `smoxx` -> port 8006
|
||||||
@@ -0,0 +1,5 @@
|
|||||||
|
---
|
||||||
|
VMID: 200
|
||||||
|
---
|
||||||
|
|
||||||
|
Wireguard server for VPN access to sumadija network
|
||||||
@@ -1,54 +0,0 @@
|
|||||||
public_key = $(shell cat /etc/wireguard/dmz_public_key)
|
|
||||||
name := $(shell git config list | grep user.nam | cut -d= -f2)
|
|
||||||
|
|
||||||
|
|
||||||
# Local keys
|
|
||||||
|
|
||||||
wireguard/dmz_private_key: | /bin/wg wireguard/
|
|
||||||
wg genkey > $@
|
|
||||||
chmod 700 $@
|
|
||||||
|
|
||||||
wireguard/dmz_public_key: wireguard/dmz_private_key | /bin/wg
|
|
||||||
$| pubkey < $< > $@
|
|
||||||
|
|
||||||
##############################
|
|
||||||
|
|
||||||
wgkeys.rec: wireguard/dmz_public_key
|
|
||||||
$(info Adding wireguard key as '$(name)')
|
|
||||||
recins --verbose $@ -t $(basename $@) -f name -v '$(name)' -f pubkey -v '$(shell cat $<)'
|
|
||||||
git add $@
|
|
||||||
git commit -m"add wireguard key for $(name)"
|
|
||||||
$(info Remember to git push)
|
|
||||||
|
|
||||||
wireguard/dmz.conf: wireguard/dmz_bare.conf | wireguard/dmz_private_key
|
|
||||||
sed 's#PRIVATE_KEY#$(shell cat $|)#' $< > $@
|
|
||||||
|
|
||||||
wireguard/dmz_bare.conf: wgkeys.rec | xecut/nimbus/dmz.conf
|
|
||||||
recsel $< -t $(basename $<) -e 'name = "$(name)"' | recfmt -f $| > $@
|
|
||||||
|
|
||||||
###### Wireguard configuration #####
|
|
||||||
|
|
||||||
wireguard/wg_peers.txt: wgkeys.rec | xecut/nimbus/wg_peer.fmt
|
|
||||||
recsel $< -t $(basename $<) | recfmt -f $| > $@
|
|
||||||
|
|
||||||
ignored += ansible/playbooks/files/wireguard/wg0.conf
|
|
||||||
|
|
||||||
ansible/playbooks/files/wireguard/wg0.conf: wireguard/wg_peers.txt | ansible/playbooks/files/wireguard/server_head
|
|
||||||
cd ansible && ansible-vault view playbooks/files/wireguard/server_head > playbooks/files/wireguard/wg0.conf
|
|
||||||
cat $< >> $@
|
|
||||||
cd ansible && ansible-vault encrypt playbooks/files/wireguard/wg0.conf
|
|
||||||
|
|
||||||
|
|
||||||
##### Installing Wireguard Client #####
|
|
||||||
|
|
||||||
.PHONY: wg-create
|
|
||||||
wg-create: wireguard/dmz.conf ## Set up wireguard keys (do this before installing)
|
|
||||||
|
|
||||||
.PHONY: wg-install
|
|
||||||
wg-install:| /etc/wireguard/dmz.conf ## Install wireguard keys (use sudo)
|
|
||||||
/etc/wireguard/dmz.conf:| wireguard/dmz.conf /bin/wg
|
|
||||||
cp $< $@
|
|
||||||
|
|
||||||
.PHONY: wg-setup
|
|
||||||
wg-setup: ansible/playbooks/files/wireguard/wg0.conf ## Renew the wireguard config
|
|
||||||
make -C ansible wireguard
|
|
||||||
-19
@@ -1,19 +0,0 @@
|
|||||||
%rec: wgkeys
|
|
||||||
%key: id
|
|
||||||
%type: name,pubkey line
|
|
||||||
%type: id int
|
|
||||||
%auto: id
|
|
||||||
%mandatory: name
|
|
||||||
+ pubkey
|
|
||||||
|
|
||||||
id: 2
|
|
||||||
name: Malin Freeborn
|
|
||||||
pubkey: loNnXRalD0ZyOLadSWm31rqOuRfEbgtX9O4/z7eSIho=
|
|
||||||
|
|
||||||
id: 3
|
|
||||||
name: coja
|
|
||||||
pubkey: snfw8r1hIAtTABGd7K9xIZ9RH62qMEK4fRqVm4EbniQ=
|
|
||||||
|
|
||||||
id: 4
|
|
||||||
name: netstat
|
|
||||||
pubkey: Z8bk25hHo6oadOX7KtoLUDXGW9r+thMiR320aiGmQAQ=
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
# Client configuration for wireguard to nimbus at xecut.
|
|
||||||
|
|
||||||
[Interface]
|
|
||||||
Address = 10.0.0.{{id}}/32
|
|
||||||
PrivateKey = PRIVATE_KEY
|
|
||||||
|
|
||||||
[Peer]
|
|
||||||
PublicKey = GH+qA1Au9BraGhNt7Aqp8tdhGVfH8ENnY3VzKhe69XQ=
|
|
||||||
Endpoint = space.xecut.me:51900
|
|
||||||
AllowedIPs = 10.0.0.1/24
|
|
||||||
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
[Peer]
|
|
||||||
PublicKey = {{pubkey}}
|
|
||||||
AllowedIPs = 10.0.0.{{id}}/32
|
|
||||||
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
|
|
||||||
[Interface]
|
|
||||||
Address = 10.0.0.1/24
|
|
||||||
SaveConfig = true
|
|
||||||
PrivateKey = PRIVATE_KEY
|
|
||||||
ListenPort = 51900
|
|
||||||
|
|
||||||
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
|
|
||||||
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
|
|
||||||
|
|
||||||
[Peer]
|
|
||||||
PublicKey = GH+qA1Au9BraGhNt7Aqp8tdhGVfH8ENnY3VzKhe69XQ=
|
|
||||||
AllowedIPs = 10.0.0.2/32
|
|
||||||
|
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
# Service Catalog: serverko
|
||||||
|
|
||||||
|
## 🛠️ Overview
|
||||||
|
|
||||||
|
IP addresses follow the container ID pattern:
|
||||||
|
`101 ssh13` -> `192.168.6.101`
|
||||||
|
|
||||||
|
|
||||||
|
| VMID | Name | OS | Notes |
|
||||||
|
| :--- | :--- | :--- | :--- |
|
||||||
|
| [100](./nginx12/) | [nginx12](./nginx12/) | 12 | Proxy |
|
||||||
|
| [101](./ssh13/) | [ssh13](./ssh13/) | 13 | SSH Jump host |
|
||||||
|
| [102](./dmzrs12/) | [dmzrs12](./dmzrs12/) | 12 | website |
|
||||||
|
| [103](./tor13/) | [tor13](./tor13/) | 13 | Tor Onion Service |
|
||||||
|
|
||||||
|
|
||||||
|
##### Legend
|
||||||
|
|
||||||
|
- `12` -> Debian 12
|
||||||
|
- `13` -> Debian 13
|
||||||
|
|
||||||
|
## 🌐 Forwarded Ports
|
||||||
|
|
||||||
|
none
|
||||||
|
|
||||||
|
## 🌐 Public URLs
|
||||||
|
|
||||||
|
none
|
||||||
Reference in New Issue
Block a user