3 Commits
Author SHA1 Message Date
andonome 17b0cf5e0b add wireguard credentials 2026-02-02 22:33:31 +01:00
andonome 89472a3a70 create wireguard playbook 2026-01-26 22:22:04 +01:00
andonome dd6fb1cf50 add bare ansible config 2026-01-26 21:00:47 +01:00
20 changed files with 241 additions and 208 deletions
+46
View File
@@ -0,0 +1,46 @@
hosts = $(wildcard host_vars/*.yml)
logs = $(patsubst host_vars/%.yml, logs/%.json, $(hosts) )
playbooks = $(wildcard playbooks/*.yml)
plays = $(patsubst playbooks/%.yml, %, $(playbooks) )
defaults += $(wildcard logs/*)
###### Recipes ######
.PHONY: help
help: ## Print the help message.
@awk 'BEGIN {FS = ":.*?## "} /^[0-9a-zA-Z._-]+:.*?## / {printf "\033[36m%s\033[0m : %s\n", $$1, $$2}' $(MAKEFILE_LIST) | \
column -s ':' -t
.PHONY: lint
lint: $(playbooks) | .ansible/ ## Check syntax and lint all playbooks
ansible-playbook --syntax-check $^
ansible-lint $^
.PHONY: records
records: $(logs) ## Current info on each host
$(logs): logs/%.json: | logs/
ansible -m setup $(basename $(@F) ) > $@
-include logs/play.mk
make_play = printf '.PHONY: %s\n%s: %s \#\# %s\n\n' '$(notdir $(basename $1) )' '$(notdir $(basename $1) )' '$1' '$(shell grep -m1 -oP 'name: \K.*' $1)'
logs/play.mk: playbooks/*.yml
@$(RM) $@
@$(foreach book, $^, \
$(call make_play, $(book), $@ ) >> $@ ; \
printf '\t%s\n\n' 'ansible-playbook $(book)' >> $@ ; \
)
%/:
mkdir $@
echo '*' > $@.gitignore
.PHONY: clean
clean: ## Remove generated files.
$(RM) $(defaults)
+7
View File
@@ -0,0 +1,7 @@
[defaults]
inventory = hosts.yaml
local_tmp = .ansible
cow_selection = random
vault_password_file = pass.sh
interpreter_python = auto_silent
@@ -0,0 +1,7 @@
$ANSIBLE_VAULT;1.1;AES256
39653235613163636362653036663563383839313836643563323462616163353364323862313039
6564656661323039393563636133303132626663366233390a343535383963353763383364376438
36306435396461393132653161393238623562393465356166343764336661376434333335643863
3865373732363761620a613236613963396638613831326332386530326239373062333933646239
39313336383366636133646336653236303261346238306336663564373063383634313361356335
6334353863363931643338663833333065343435333231623466
@@ -0,0 +1 @@
GH+qA1Au9BraGhNt7Aqp8tdhGVfH8ENnY3VzKhe69XQ=
+9
View File
@@ -0,0 +1,9 @@
$ANSIBLE_VAULT;1.1;AES256
37363765623839666637633861353139353935323364343538356536653561373266336161353937
3466653434666163313936393366613666393863616262320a643930663038326666653064613062
62613661396538363539643938323033663932326362626335333438653865623038336136623030
3735366564366431330a373061393766346631643434383364646431346231356466663737626435
64303835343237383761633939643431333439643933636139666163393637363430633261633736
34626631366163616439366534393031353063363138356638323634313430666330613833386661
61346365313534353535633365626364303565363565353765353833363065343232633866633132
63643930633266653765
+16
View File
@@ -0,0 +1,16 @@
all:
vars:
username: dmz
locale: Europe/Belgrade
libc_locale: en_GB.UTF-8 UTF-8
var_locale: LANG=en_GB.UTF-8
ungrouped:
hosts:
nimbus:
cloud:
hosts:
nimbus:
arch:
hosts:
nimbus:
+3
View File
@@ -0,0 +1,3 @@
#!/bin/sh
pass dmz/xecut/dmz_ansible
+106
View File
@@ -0,0 +1,106 @@
---
- name: Install Wireguard on Server
hosts: nimbus
become: true
tasks:
- name: Install wireguard tools and dig
ansible.builtin.package:
name:
- wireguard-tools
- bind
- name: Copy keys to server
ansible.builtin.copy:
src: wireguard/
dest: /etc/wireguard/server_public_key
- name: Remember the public key
ansible.builtin.command: cat /etc/wireguard/server_public_key
register: wireguard_public_key
- name: Get server public IP
ansible.builtin.command: dig +short myip.opendns.com @resolver1.opendns.com
register: wireguard_public_ip
- name: Allow ipv4 forwarding
ansible.builtin.lineinfile:
path: /etc/sysctl.d/wg.conf
line: net.ipv4.ip_forward=1
create: yes
- name: Start the wireguard service
ansible.builtin.service:
name: wg-quick@wg0
enabled: yes
- name: Install Wireguard on Host
hosts: localhost
become: true
tasks:
- name: Install wireguard tools
ansible.builtin.package:
name:
- wireguard-tools
- name: Create private key
ansible.builtin.shell:
chdir: /etc/wireguard/
creates: /etc/wireguard/dmz_public_key
cmd: "wg genkey | tee dmz_private_key | wg pubkey > dmz_public_key"
- name: Remember the public key
ansible.builtin.command: cat /etc/wireguard/dmz_public_key
register: client_public_key
- name: Generate Server Config
hosts: nimbus
become: true
tasks:
- name: Create wg0 configuration
ansible.builtin.shell:
chdir: /etc/wireguard/
creates: /etc/wireguard/wg0.conf
cmd: |
echo "
[Interface]
Address = 10.0.0.1/24
SaveConfig = true
PrivateKey = $(cat server_private_key)
ListenPort = 51900
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = {{ hostvars['localhost']['client_public_key']['stdout'] }}
AllowedIPs = 10.0.0.2/32
" > /etc/wireguard/wg0.conf
- name: Generate Client Config
hosts: localhost
become: true
tasks:
- name: Create wg0 client configuration
ansible.builtin.shell:
chdir: /etc/wireguard/
creates: /etc/wireguard/wg0-client.conf
cmd: |
echo "
[Interface]
Address = 10.0.0.2/32
PrivateKey = $(cat dmz_private_key)
DNS = 9.9.9.9
[Peer]
PublicKey = {{ hostvars['nimbus']['wireguard_public_key']['stdout'] }}
Endpoint = space.xecut.me:51900
AllowedIPs = 10.0.0.1/32
" > /etc/wireguard/wg0-client.conf
+14
View File
@@ -0,0 +1,14 @@
[Interface]
Address = 10.0.0.1/24
SaveConfig = true
PrivateKey = {{ wg_private_key }}
ListenPort = 51900
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
[Peer]
PublicKey = {{ wg_public_key }}
AllowedIPs = 10.0.0.2/32
+25 -9
View File
@@ -18,13 +18,29 @@ VMID: 119
`/var/discourse_docker/discourse_doctor`
Latest update:
## Docker rebuild errors
`/var/discourse_docker/launcher rebuild web_only`
```
Plugin name is 'ldap', but plugin directory is named 'discourse-ldap-auth'
rake aborted!
ActiveRecord::NoDatabaseError: We could not find your database: discoursedb. Available database configurations can be found in config/database.yml. (ActiveRecord::NoDatabaseError)
```
```
FAILED
--------------------
Pups::ExecError: cd /var/www/discourse && su discourse -c 'bundle exec rake db:migrate' failed with return #<Process::Status: pid 593 exit 1>
Location of failure: /usr/local/lib/ruby/gems/3.3.0/gems/pups-1.3.0/lib/pups/exec_command.rb:131:in `spawn'
exec failed with the params {"cd"=>"$home", "tag"=>"migrate", "hook"=>"db_migrate", "cmd"=>["su discourse -c 'bundle exec rake db:migrate'"]}
bootstrap failed with exit code 1
** FAILED TO BOOTSTRAP ** please scroll up and look for earlier error messages, there may be more than one.
./discourse-doctor may help diagnose the problem.
a9a704b1ee166487d8cd2acd5bd9bcc050ed0ec93fc065f58440e4ae208e1937
```
- The forum has been restored; images should load when clicked but may not display immediately.
- Resolved several problems sequentially: admin panel and updates were failing, Docker builds failed due to PostgreSQL 13, upgraded to 15.
- Restored from backup and created a new backup from the old SQL server, transferring data via PostgreSQL 15.
- Manually enabled the required vector extension on the new database because Discourse could not do it automatically.
- Docker container rebuild succeeded only after disabling the SSL template in the Docker configuration.
- After rebuild, the forum returned with new posts but login failed and media/files were missing.
- Uploaded files after May 1 were lost; database and uploads backups were found in the shared folder.
- Login issue was caused by a missing SSL template; resolved by setting up an Nginx reverseproxy with a selfsigned certificate on the forum VM, allowing SSL access through the main HTTP VM.
+7 -4
View File
@@ -5,6 +5,10 @@ name: ISP Router
location: kralizec
ISP: Orion
name: ISP Router
location: krov
ISP: Yettel
%rec: host
%doc: These are the real machines, most of which run VMs or containters.
%key: name
@@ -13,10 +17,8 @@ name: moxx
location: kralizec
local_access: 192.168.1.200:8006
name: nimbus
location: xecut
description: raspberry pi
os: Arch Linux Aarm
name: Serverko
location: krov
%rec: lxc
%doc: A container, usually on a Proxmox host.
@@ -88,3 +90,4 @@ host: Serverko
name: tor12
host: nginx
-36
View File
@@ -1,36 +0,0 @@
# Service Catalog: sumadijamoxx
## 🛠️ Overview
IP addresses follow the container ID pattern:
`101 ssh12` -> `192.168.7.101`
| VMID | Name | OS | Notes |
| :--- | :--- | :--- | :--- |
| [101](./ssh12/) | [ssh12](./ssh12/) | 12 | SSH Jump host |
| [102](./nginx13/) | [nginx13](./nginx13/) | 13 | Proxy |
| [103](./searxng12/) | [searxng12](./searxng12/) | 12 | Search |
| [104](./homepage12/) | [homepage12](./homepage12/) | 12 | Dashboard |
| [105](./pastebin13/) | [pastebin13](./pastebin13/) | 13 | Pastebin |
| [106](./librespeed-rust12/) | [librespeed-rust12](./librespeed-rust12/) | 12 | Speedtest |
| [107](./tor13/) | [tor13](./tor13/) | 13 | Tor Onion Service |
| [200](./wireguard12/) | [wireguard12](./wireguard12/) | 12 | VPN |
##### Legend
- `12` -> Debian 12
- `13` -> Debian 13
## 🌐 Forwarded Ports
- `192.168.7.243:443` -> `443`
- `192.168.7.243:80` -> `80`
- `192.168.7.101:22` -> `22`
## 🌐 Public URLs
- Website: https://sumadija.dmz.rs
- Pastebin: https://pastebin.dmz.rs
-21
View File
@@ -1,21 +0,0 @@
---
VMID: 109
---
# Nginx
**VMID:** 102
**OS/Version:** Debian 13
## 🌐 Connectivity
- **Local IP:** `192.168.7.109`
- **Internal Port:** `80`
- **External/Proxy URL:** `https://sumadija.dmz.rs`
- **Access Type:** Local / Public (via proxy)
## 🛠️ Details
- **Dependencies:** None
## 📝 Notes
- Forwarded to port 80 and 443.
@@ -1,20 +0,0 @@
---
VMID: 105
---
# PrivateBin
**VMID:** 105
**OS/Version:** Debian 13
## 🌐 Connectivity
- **Local IP:** `192.168.7.105`
- **Internal Port:** `[N/A]`
- **External/Proxy URL:** `https://pastebin.dmz.rs`
- **Access Type:** Forwarded
## 🛠️ Details
- **Built with:** [PrivateBin Proxmox Script](https://community-scripts.github.io/ProxmoxVE/scripts?id=privatebin)
- **Dependencies:** None
## 📝 Notes
- Not yet public/forwarded.
-17
View File
@@ -1,17 +0,0 @@
# Router
**VMID:** [N/A]
**OS/Version:** TPLink (Hopefully OpenWRT in future)
## 🌐 Connectivity
- **Local IP:** 192.168.7.1
- **Internal Port:** `[N/A]`
- **External/Proxy URL:** `[N/A]`
- **Access Type:** Local
## 🛠️ Details
- **Built with:** N/A
## 📝 Notes
- Router is inside the existing network for further forwarding.
- Contact coja (best on xmpp) for access/info.
-20
View File
@@ -1,20 +0,0 @@
---
VMID: 102
---
# SearXNG
**VMID:** 103
**OS/Version:** Debian 12
## 🌐 Connectivity
- **Local IP:** `192.168.7.103`
- **Internal Port:** `[N/A]`
- **External/Proxy URL:** `https://search.dmz.rs`
- **Access Type:** Local (Not yet public/forwarded)
## 🛠️ Details
- **Built with:** [SearXNG Proxmox Script](https://community-scripts.github.io/ProxmoxVE/scripts?id=searxng)
- **Dependencies:** None
## 📝 Notes
- Not yet public/forwarded.
-24
View File
@@ -1,24 +0,0 @@
---
VMID: 101
---
# SSH Gateway
**VMID:** 101
**OS/Version:** Debian 12
## 🌐 Connectivity
- **Local IP:** `192.168.7.101`
- **Internal Port:** `22`
- **External/Proxy URL:** `https://sumadija.dmz.rs`
- **Access Type:** Public (via SSH forwarding)
## 🛠️ Details
- **Built with:** N/A
- **Dependencies:** None
## 📝 Notes
- SSH port from this container should be forwarded to `sumadija.dmz.rs`.
- SSH access to other containers is done through this one with SSH jump.
- **Security:** Passwords are disabled; only key verification is used.
- [Wiki Guide](https://wiki.dmz.rs/en/sysadmin/ssh)
-24
View File
@@ -1,24 +0,0 @@
---
VMID: 107
---
# Tor Onion Service
**VMID:** 107
**OS/Version:** Debian 13
## 🌐 Connectivity
- **Local IP:** `192.168.7.107`
- **Internal Port:** `[N/A]`
- **External/Proxy URL:** `[Tor Onion Address]`
- **Access Type:** Public (via Tor)
## 🛠️ Details
- **Built with:** N/A
- **Dependencies:** None
## 📝 Notes
- This container hosts the Tor onion service, used for remote access to Proxmox through Tor.
- **Credentials:** Stored in **dmzadmin** (password manager).
- **Remote access targets:**
- `ssh12` -> port 22
- `smoxx` -> port 8006
@@ -1,5 +0,0 @@
---
VMID: 200
---
Wireguard server for VPN access to sumadija network
-28
View File
@@ -1,28 +0,0 @@
# Service Catalog: serverko
## 🛠️ Overview
IP addresses follow the container ID pattern:
`101 ssh13` -> `192.168.6.101`
| VMID | Name | OS | Notes |
| :--- | :--- | :--- | :--- |
| [100](./nginx12/) | [nginx12](./nginx12/) | 12 | Proxy |
| [101](./ssh13/) | [ssh13](./ssh13/) | 13 | SSH Jump host |
| [102](./dmzrs12/) | [dmzrs12](./dmzrs12/) | 12 | website |
| [103](./tor13/) | [tor13](./tor13/) | 13 | Tor Onion Service |
##### Legend
- `12` -> Debian 12
- `13` -> Debian 13
## 🌐 Forwarded Ports
none
## 🌐 Public URLs
none