diff --git a/host_vars/a.ns.oopen.de.yml b/host_vars/a.ns.oopen.de.yml index e0d01c7..78622aa 100644 --- a/host_vars/a.ns.oopen.de.yml +++ b/host_vars/a.ns.oopen.de.yml @@ -40,8 +40,16 @@ extra_user: - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDF7Sx0YJlLjjg3Sm8uiXJyBeKKmZFum3D8Mw2VQZrXJgYOrVB/SVDXO4N5I6NOT5bvxs8c5DLV/4J4ewGP5dGSYiepRnkrRSBUUS6ICwkYfyXremHJ31uREfODRBA4Vnsmpw0SlbQ2I9IpYwsaD3/IDZehDgaCKu4D0/LIprZh0/u+WX7kOGb8Tkm/PBu2SSbAzURaMXn/UtGsUyrickAmEK9qXZDsNYgcwOqZaPtkMZP3mAdix/gKaWV07oU49zxBrouD8gRWAs/yOLvxOe1JDcH2ZExXl81jJYlUffKarBHsWNNE79hUInnH9YTfxP1AEC+MyFXxqKwz3Lk1dQyUo1TFtJTYY+/IHsXT/6KhbOi6twhj7U7uZEqaIWyo6N+WVL9fFhgmbSoVIE6KrBM5VtOdr33A3a+XeNAQGjW6mqOcv3iNUDipTnDTKkEAWQWWnK5YRuaJw1eUCoii/FDp0hRTWIqn+RVCgkOGgEjMIRC8tiQouCXxwfukfcq9zD8S8UCyyQY0uWRHm3uM5GHTmvIJHBXfXBSX/B+PgesSZVwICCiS/6ZSWT+6D5ObBdKGkz12A797YyaMsN7RtJn6OBhPRrGfqQLCIM7lpxJHAoQmTSMiuQp/TjHLedjAm3FvxET2ZvqPWg9QtvSzIoz2JOdKysZHGgbBdC7q6Cssvw== root@ga-st-mail-dehydrated' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQClupkurU+acJRtp2s9GgiC+rANqlup8SfhtulV0a/8z6nobjcpQWrfVq+MNjM7VghnlMAwMjz7tccFGyCmJoSS11RcnFtPmqnSNj0/TI8zyYOZUvZCczPBSeqs/IxawyYz91e3RlPWbpv71Nj+/EHUZApZkkdTkpYHduSJYWtKYA2l2Glzmjd2d2u/IFIkqXhvl1bT3RUMLZJqYdEwYAvlW2JB84EIWNf4ytcGcu6rakXCRP9o62BbRza3AfMgSfa45PLodPi5VpqDiTHSCIBll+VOuLqTgQCBYeANRPClMLbueVXXcMrmEwrDXeC0dpqTdgaF2Tz3xYsrAzTe6bcNJsGgGCQyTtDKpsAgoKb31agsyy68CoZto13Ea4WYsNVx0T3KaRlaDm98KqnUJXHJvXnLegqfXiURL5BpxXmAnFvZ0duHrtRkVpzeu5n5vz41RLnFHyLln2VE6a+IYdiLlPl2hC+7pswb+nBP9yNn6T4WQZNtHp4YssANuYKO+/gJaHpMJ1TqgL/Ip66erK+372M1T/6ibiU3+qHbwW7FbXVfn3Dz2abJGyNkoaZGpQIXtx0UxWYZHF8E35Z0ll9NQo1CnDvV3jA1aMnYVTv9DuSYxqLY34oHWXEFzMyStCRWup4Tfrp3pT61GRhb2h8kZi5dqQur9KrqWmA6HF9D+Q== root@lists.mx' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC82aW3qFetvOZSBJFCBnSONurzqAtkZT7cNA+0OuXgYmKXjsOaBlA2pm2a+rKS1Rs2VOzQFAHJMGaR/JGRYTU060jZaZmJhNgNbtqBicDeiEE0p1HfQCm/HSN5vf4Q8CRMDHxkaRxkWOIxvouxn2dkbZklZ+SZCNh42ZMMVC/q0UJmgTV2A5RCbd6eARs9u6lnix+PAhTYYLjsnyNSorr0g6FLb4367dg1klyyHuCNb0rjTZxnYTNDHGHTrYQUXIaZt16iWaxzmnSQi4fivmunGc2Xafhkea+lfxbSwtG68zeJC4D3QBGKZu8xtjyipj9v2LyBrXONgBXfBKs8b9dmhL/Qr4cIhaUdl0IDYaQ/UEBmy3z6CeUxrUsWoQP6st8299ndj1ul7sW2Q5QPH2hLX2PSLOoMygV0cho6oh1XEAkTsAgTXnqhp5G0vZF/2VFYyu2QP+0/yJawOSUE2TMJmA5yU7TMx5koDZL51Rj9XVFqouzRG+6gOOAnhHICfvQUYpS+WW/nqNYl1MI+9Gk29Em2YoBwb1zlep6gC5EyjTzx4h13ldSFSmHcEn9vptZeZv78Es/bT9ib8IdUS9oRatw9IEmA9xnWgHxcrTn1+QYJkbjc1cS2lFVR9wmm3/4It/RyWuxAf3k4qlzHzIS/F4St7MLjviPAWRxqyvroQQ== root@test.mx' - - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQD69d+9aX+dJ6GBx2NOA2CtBw20scewP/IzlzV4hNGwUnL4I3mElJL9mZLLpggS8sz0gvtQrD5SKDUJcG2OJbyq4U8uAf/0FJKmXc4i0+drYssJ2QtII1o7OZuZC9o+ryszE9vwTl8h4aTX23M7jXgShPLTqCp6Q2F9TiqS7DGkEHL4qlao0HthEY38YP0O24C0czlO1MVf6Me78fpKj9FeiBK4MMJyc9CUZbGrdxjTQhvHsO5b7Gwppf/gFBF/3gKHJiiG1AqQGFHZNwL0X6GyAAj4sK0HvfqVBaAa/4tFeuBGPp08huD1BjgJCKibQF4vBmB2ihi6F0FKGigYRuUkICwu6UOdKp1/LYtxnDCKMJUyz8r1ZL3qxzCJLGjLqlRXtT4cRK6tsPFf4DUIJYwYUm5FgS6WEVCP0wUvTUIgaJFhRspk/svMVEbWvnP+BS3/s7CSX4CSIrfMqTkwGUn/fLnhTNtmGs1yDponnH3QJqdc8suYcNvd6xadGpTVC9cqAeN8Fb06O+shOoR8/M8VkS2ePrll+svH6H2XapBWxFdDdnP4hzoVumHXqdzbucAOmz3xvKjXUROw2gSv2fXJlsvP//JJiEhRL3owcnB9mPaqUZhIKQmPC9VGoo6JwFzMpFbKSANoL+vL5p3ZFp6PtNAA74memJbQtqQBXJNsdQ== root@web-01-de-ns' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIf2ahqowiUbP4f3/qtdC1JmbjIdlF+i+TiWpxWam0yjiGuTPDjI1ud5vj0of2+P4DJy2dkDvF3yK7/Np7qpxIJgsj9HNiwIlGtfrwNCzqGlyPovjNpAr8cCR1P34K9CgHz4BInc//vjxlUXZpK17omOJ4KaVY1f/Eit0G5Y2TJ38BY6MztuUfou8PdJqITM3GM/YOk4iz2OnObDjHAbd6VTSn4yrYTkGT30axiCHdSy0XhvfUgB1yO08PIcOOogGkxRLYkvUAxwhDsFSpGzQBhUb1O5RqGnBs/aR4sxwjTaeO8mP6lpQMp2pz//I6448N3k5P1CwcJAqrkUuOk4o+jHWr5rSO+eKm4SQ74RBnAAM9bA0tpvCmO8kV2tsdbS4Yw94H4GfTgOPZ5Fe6Y8ciTR+bkGdp7sqm5DNtjZNZuwiFmoe2vj7RJlCNDIXhwVEGAWf+lFYCQKp05A13QoRYGg2aebaLSjw9XYBghNtwnmYkSb84xIoELmPKYrvdodO2uHgGxHBls1mFTz8m01kn+A49L3yY+cFZtSua/+YYoZLh1tNLAL4rBRCRVpZs+VHrmz0GCxwYMHkm9ti0SRPrb7jtH9DYwLUdci4pL8z/G4D2M92A66OZqIybgAJkkdl4H4mv9n05FPJ8RxPniD58x3AMTZNtkxGxn8UkTCSSGQ== root@web-01-opendkim' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICCvag/r50Dxfsh3fcG3fZSZ+vbsCwbV+WDoJ++zNSHl root@web-01-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFpQyckVQMI2YMbIQ9Gqf2JyGyM2JufIPf0lv7jvMxLI root@web-02-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPTp1tj4dDkHJsE4IPdgaMgLFQdE7S9P+4MOAnlLkwRm root@web-04-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB4GasLKut8CamCn7czQjgypI/dKp0WISHRiWAaiRhkL root@web-05-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOhpnE6LiGSkcj+RPLI07fdOmkbcetN9BuWZ0Q/qJGSl root@web-06-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH6Q9YZ6hxDy8JNcuMfF62Cels3oqAGXTrRpXt7fUfXt root@web-07-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMHJ2/ijXgZ9Lp2Ac0bIOnUgjDRidjub1ZHh6eJAUn8e root@web-08-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMHJ2/ijXgZ9Lp2Ac0bIOnUgjDRidjub1ZHh6eJAUn8e root@web-08-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHL4VNeSscKqL3ogA59+jKkZSUb8/WURbn6Fo5ekMKBE root@web-09-dns' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMvy+IDUeoVwLg+cJNcKzls5guOrVUretsf05v3Y2N+Y root@default-oopen-server' diff --git a/host_vars/b.ns.oopen.de.yml b/host_vars/b.ns.oopen.de.yml index 4ea3017..4eb8181 100644 --- a/host_vars/b.ns.oopen.de.yml +++ b/host_vars/b.ns.oopen.de.yml @@ -35,8 +35,17 @@ extra_user: - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDF7Sx0YJlLjjg3Sm8uiXJyBeKKmZFum3D8Mw2VQZrXJgYOrVB/SVDXO4N5I6NOT5bvxs8c5DLV/4J4ewGP5dGSYiepRnkrRSBUUS6ICwkYfyXremHJ31uREfODRBA4Vnsmpw0SlbQ2I9IpYwsaD3/IDZehDgaCKu4D0/LIprZh0/u+WX7kOGb8Tkm/PBu2SSbAzURaMXn/UtGsUyrickAmEK9qXZDsNYgcwOqZaPtkMZP3mAdix/gKaWV07oU49zxBrouD8gRWAs/yOLvxOe1JDcH2ZExXl81jJYlUffKarBHsWNNE79hUInnH9YTfxP1AEC+MyFXxqKwz3Lk1dQyUo1TFtJTYY+/IHsXT/6KhbOi6twhj7U7uZEqaIWyo6N+WVL9fFhgmbSoVIE6KrBM5VtOdr33A3a+XeNAQGjW6mqOcv3iNUDipTnDTKkEAWQWWnK5YRuaJw1eUCoii/FDp0hRTWIqn+RVCgkOGgEjMIRC8tiQouCXxwfukfcq9zD8S8UCyyQY0uWRHm3uM5GHTmvIJHBXfXBSX/B+PgesSZVwICCiS/6ZSWT+6D5ObBdKGkz12A797YyaMsN7RtJn6OBhPRrGfqQLCIM7lpxJHAoQmTSMiuQp/TjHLedjAm3FvxET2ZvqPWg9QtvSzIoz2JOdKysZHGgbBdC7q6Cssvw== root@ga-st-mail-dehydrated' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQClupkurU+acJRtp2s9GgiC+rANqlup8SfhtulV0a/8z6nobjcpQWrfVq+MNjM7VghnlMAwMjz7tccFGyCmJoSS11RcnFtPmqnSNj0/TI8zyYOZUvZCczPBSeqs/IxawyYz91e3RlPWbpv71Nj+/EHUZApZkkdTkpYHduSJYWtKYA2l2Glzmjd2d2u/IFIkqXhvl1bT3RUMLZJqYdEwYAvlW2JB84EIWNf4ytcGcu6rakXCRP9o62BbRza3AfMgSfa45PLodPi5VpqDiTHSCIBll+VOuLqTgQCBYeANRPClMLbueVXXcMrmEwrDXeC0dpqTdgaF2Tz3xYsrAzTe6bcNJsGgGCQyTtDKpsAgoKb31agsyy68CoZto13Ea4WYsNVx0T3KaRlaDm98KqnUJXHJvXnLegqfXiURL5BpxXmAnFvZ0duHrtRkVpzeu5n5vz41RLnFHyLln2VE6a+IYdiLlPl2hC+7pswb+nBP9yNn6T4WQZNtHp4YssANuYKO+/gJaHpMJ1TqgL/Ip66erK+372M1T/6ibiU3+qHbwW7FbXVfn3Dz2abJGyNkoaZGpQIXtx0UxWYZHF8E35Z0ll9NQo1CnDvV3jA1aMnYVTv9DuSYxqLY34oHWXEFzMyStCRWup4Tfrp3pT61GRhb2h8kZi5dqQur9KrqWmA6HF9D+Q== root@lists.mx' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC82aW3qFetvOZSBJFCBnSONurzqAtkZT7cNA+0OuXgYmKXjsOaBlA2pm2a+rKS1Rs2VOzQFAHJMGaR/JGRYTU060jZaZmJhNgNbtqBicDeiEE0p1HfQCm/HSN5vf4Q8CRMDHxkaRxkWOIxvouxn2dkbZklZ+SZCNh42ZMMVC/q0UJmgTV2A5RCbd6eARs9u6lnix+PAhTYYLjsnyNSorr0g6FLb4367dg1klyyHuCNb0rjTZxnYTNDHGHTrYQUXIaZt16iWaxzmnSQi4fivmunGc2Xafhkea+lfxbSwtG68zeJC4D3QBGKZu8xtjyipj9v2LyBrXONgBXfBKs8b9dmhL/Qr4cIhaUdl0IDYaQ/UEBmy3z6CeUxrUsWoQP6st8299ndj1ul7sW2Q5QPH2hLX2PSLOoMygV0cho6oh1XEAkTsAgTXnqhp5G0vZF/2VFYyu2QP+0/yJawOSUE2TMJmA5yU7TMx5koDZL51Rj9XVFqouzRG+6gOOAnhHICfvQUYpS+WW/nqNYl1MI+9Gk29Em2YoBwb1zlep6gC5EyjTzx4h13ldSFSmHcEn9vptZeZv78Es/bT9ib8IdUS9oRatw9IEmA9xnWgHxcrTn1+QYJkbjc1cS2lFVR9wmm3/4It/RyWuxAf3k4qlzHzIS/F4St7MLjviPAWRxqyvroQQ== root@test.mx' - - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQD69d+9aX+dJ6GBx2NOA2CtBw20scewP/IzlzV4hNGwUnL4I3mElJL9mZLLpggS8sz0gvtQrD5SKDUJcG2OJbyq4U8uAf/0FJKmXc4i0+drYssJ2QtII1o7OZuZC9o+ryszE9vwTl8h4aTX23M7jXgShPLTqCp6Q2F9TiqS7DGkEHL4qlao0HthEY38YP0O24C0czlO1MVf6Me78fpKj9FeiBK4MMJyc9CUZbGrdxjTQhvHsO5b7Gwppf/gFBF/3gKHJiiG1AqQGFHZNwL0X6GyAAj4sK0HvfqVBaAa/4tFeuBGPp08huD1BjgJCKibQF4vBmB2ihi6F0FKGigYRuUkICwu6UOdKp1/LYtxnDCKMJUyz8r1ZL3qxzCJLGjLqlRXtT4cRK6tsPFf4DUIJYwYUm5FgS6WEVCP0wUvTUIgaJFhRspk/svMVEbWvnP+BS3/s7CSX4CSIrfMqTkwGUn/fLnhTNtmGs1yDponnH3QJqdc8suYcNvd6xadGpTVC9cqAeN8Fb06O+shOoR8/M8VkS2ePrll+svH6H2XapBWxFdDdnP4hzoVumHXqdzbucAOmz3xvKjXUROw2gSv2fXJlsvP//JJiEhRL3owcnB9mPaqUZhIKQmPC9VGoo6JwFzMpFbKSANoL+vL5p3ZFp6PtNAA74memJbQtqQBXJNsdQ== root@web-01-de-ns' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIf2ahqowiUbP4f3/qtdC1JmbjIdlF+i+TiWpxWam0yjiGuTPDjI1ud5vj0of2+P4DJy2dkDvF3yK7/Np7qpxIJgsj9HNiwIlGtfrwNCzqGlyPovjNpAr8cCR1P34K9CgHz4BInc//vjxlUXZpK17omOJ4KaVY1f/Eit0G5Y2TJ38BY6MztuUfou8PdJqITM3GM/YOk4iz2OnObDjHAbd6VTSn4yrYTkGT30axiCHdSy0XhvfUgB1yO08PIcOOogGkxRLYkvUAxwhDsFSpGzQBhUb1O5RqGnBs/aR4sxwjTaeO8mP6lpQMp2pz//I6448N3k5P1CwcJAqrkUuOk4o+jHWr5rSO+eKm4SQ74RBnAAM9bA0tpvCmO8kV2tsdbS4Yw94H4GfTgOPZ5Fe6Y8ciTR+bkGdp7sqm5DNtjZNZuwiFmoe2vj7RJlCNDIXhwVEGAWf+lFYCQKp05A13QoRYGg2aebaLSjw9XYBghNtwnmYkSb84xIoELmPKYrvdodO2uHgGxHBls1mFTz8m01kn+A49L3yY+cFZtSua/+YYoZLh1tNLAL4rBRCRVpZs+VHrmz0GCxwYMHkm9ti0SRPrb7jtH9DYwLUdci4pL8z/G4D2M92A66OZqIybgAJkkdl4H4mv9n05FPJ8RxPniD58x3AMTZNtkxGxn8UkTCSSGQ== root@web-01-opendkim' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICCvag/r50Dxfsh3fcG3fZSZ+vbsCwbV+WDoJ++zNSHl root@web-01-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFpQyckVQMI2YMbIQ9Gqf2JyGyM2JufIPf0lv7jvMxLI root@web-02-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINXrY5D6+H12hpKTbU4vR8ZSOM457ipYfSbBNAbnYmJo root@web-03-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPTp1tj4dDkHJsE4IPdgaMgLFQdE7S9P+4MOAnlLkwRm root@web-04-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIB4GasLKut8CamCn7czQjgypI/dKp0WISHRiWAaiRhkL root@web-05-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOhpnE6LiGSkcj+RPLI07fdOmkbcetN9BuWZ0Q/qJGSl root@web-06-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIH6Q9YZ6hxDy8JNcuMfF62Cels3oqAGXTrRpXt7fUfXt root@web-07-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMHJ2/ijXgZ9Lp2Ac0bIOnUgjDRidjub1ZHh6eJAUn8e root@web-08-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMHJ2/ijXgZ9Lp2Ac0bIOnUgjDRidjub1ZHh6eJAUn8e root@web-08-dns' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHL4VNeSscKqL3ogA59+jKkZSUb8/WURbn6Fo5ekMKBE root@web-09-dns' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol' diff --git a/host_vars/file-km.anw-km.netz.yml b/host_vars/file-km.anw-km.netz.yml new file mode 100644 index 0000000..5b4a119 --- /dev/null +++ b/host_vars/file-km.anw-km.netz.yml @@ -0,0 +1,715 @@ +--- + +# --- +# vars used by roles/network_interfaces +# --- + + +# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted +network_manage_devices: True + +# Should the interfaces be reloaded after config change? +network_interface_reload: False + +network_interface_path: /etc/network/interfaces.d +network_interface_required_packages: + - vlan + - bridge-utils + - ifmetric + - ifupdown + - ifenslave + + +network_interfaces: + + - device: br0 + # use only once per device (for the first device entry) + headline: br0 - bridge over device enp97s0 + + # auto & allow are only used for the first device entry + allow: [] # array of allow-[stanzas] eg. allow-hotplug + auto: true + + family: inet + method: static + description: + address: 192.168.122.10 + netmask: 24 + gateway: 192.168.122.254 + + # optional dns settings nameservers: [] + # + # nameservers: + # - 194.150.168.168 # dns.as250.net + # - 91.239.100.100 # anycast.censurfridns.dk + # search: warenform.de + # + + # optional bridge parameters bridge: {} + # bridge: + # ports: + # stp: + # fd: + # maxwait: + # waitport: + bridge: + ports: enp97s0 # for mor devices support a blank separated list + stp: !!str off + fd: 5 + hello: 2 + maxage: 12 + + # inline hook scripts + pre-up: + - !!str "ip link set dev enp97s0 up" # pre-up script lines + up: [] #up script lines + post-up: [] # post-up script lines (alias for up) + pre-down: [] # pre-down script lines (alias for down) + down: [] # down script lines + post-down: [] # post-down script lines + + +# --- +# vars used by roles/ansible_dependencies +# --- + + +# --- +# vars used by roles/ansible_user +# --- + + +# --- +# vars used by roles/common/tasks/basic.yml +# --- + + +# --- +# vars used by roles/common/tasks/sshd.yml +# --- + + +# --- +# vars used by roles/common/tasks/apt.yml +# --- + + +# --- +# vars used by roles/common/tasks/systemd-resolved.yml +# --- + +systemd_resolved: true + +# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie +# Primäre DNS-Adresse: 38.132.106.139 +# Sekundäre DNS-Adresse: 194.187.251.67 +# +# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen +# primäre DNS-Adresse +# IPv4: 1.1.1.1 +# IPv6: 2606:4700:4700::1111 +# sekundäre DNS-Adresse +# IPv4: 1.0.0.1 +# IPv6: 2606:4700:4700::1001 +# +# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit +# primäre DNS-Adresse +# IPv4: 8.8.8.8 +# IPv6: 2001:4860:4860::8888 +# sekundäre DNS-Adresse +# IPv4: 8.8.4.4 +# IPv6: 2001:4860:4860::8844 +# +# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug +# primäre DNS-Adresse +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe +# sekundäre DNS-Adresse +# IPv4: 149.112.112.112 +# IPv6: 2620:fe::9 +# +# OpenNIC - https://www.opennic.org/ +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de +# IPv4: 194.36.144.87 - ns29.de +# IPv6: 2a00:f826:8:2::195 - ns31.de +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# IPv4: 5.1.66.255 +# IPv6: 2001:678:e68:f000:: +# Servername für DNS-over-TLS: dot.ffmuc.net +# IPv4: 185.150.99.255 +# IPv6: 2001:678:ed0:f000:: +# Servername für DNS-over-TLS: dot.ffmuc.net +# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb) +resolved_nameserver: + - 192.168.122.1 + +# search domains +# +# If there are more than one search domains, then specify them here in the order in which +# the resolver should also search them +# +#resolved_domains: [] +resolved_domains: + - ~. + - anw-km.netz + +resolved_dnssec: false + +# dns.as250.net: 194.150.168.168 +# +resolved_fallback_nameserver: + - 172.16.122.254 + + +# --- +# vars used by roles/common/tasks/cron.yml +# --- + +cron_user_special_time_entries: + + - name: "Restart DNS Cache service 'systemd-resolved'" + special_time: reboot + job: "sleep 10 ; /bin/systemctl restart systemd-resolved" + insertafter: PATH + + + +# --- +# vars used by roles/common/tasks/users.yml +# --- + +default_user: + + - name: chris + password: $6$bSHlaLHC$URSMVq090e/cJ1v55Jh9ws0w5WekhO7X3Y0RqryAl5R76K9khWBegC76Smjastja.xMiD57/LzUUXW7y9NvAL. + shell: /bin/bash + ssh_keys: + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol' + + - name: sysadm + user_id: 1050 + group_id: 1050 + group: sysadm + password: $6$EEVWxA5E$bNxU8EOp/tTcYVghFharUM10k3vRt2siEnIiiznfGmhMSM6zJTP0umdxql9VVEj856oKa.Sp.q3N2nthgNMeN1 + shell: /bin/bash + ssh_keys: + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol' + + - name: back + user_id: 1060 + group_id: 1060 + group: back + password: $6$GntX81EP$O1GEmQF.BbOQfTMMw/m/BDKSXmANVpqmz0nyzw4O4R2/iK9huGOAjT/2eq8FVdMghvNOvdwrWtwohO.Mg4V9n. + shell: /bin/bash + ssh_keys: + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol' + - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol' + +sudo_users: + - chris + - sysadm + + +# --- +# vars used by roles/common/tasks/users-systemfiles.yml +# --- + + +# --- +# vars used by roles/common/tasks/webadmin-user.yml +# --- + + +# --- +# vars used by roles/common/tasks/sudoers.yml +# --- +# +# see: roles/common/tasks/vars + + +# --- +# vars used by roles/common/tasks/caching-nameserver.yml +# --- + + +# --- +# vars used by roles/common/tasks/git.yml +# --- + + +# --- +# vars used by roles/common/tasks/samba-config-server.yml +# vars used by roles/common/tasks/samba-user.yml +# --- + +samba_server_ip: 192.168.122.10 +samba_server_cidr_prefix: 24 + +samba_workgroup: WORKGROUP + +samba_netbios_name: FILE-KM + +samba_server_min_protocol: !!str NT1 + +samba_groups: + - name: kanzlei + group_id: 1100 + - name: a-jur + group_id: 1110 + - name: intern + group_id: 1120 + - name: aulmann + group_id: 1130 + - name: howe + group_id: 1140 + - name: stahmann + group_id: 1150 + - name: traine + group_id: 1160 + - name: public + group_id: 1170 + - name: alle + group_id: 1180 + + + +samba_user: + + - name: advoware + groups: + - advoware + password: '9WNRbc49m3' + + - name: a-jur + groups: + - a-jur + - alle + - intern + - kanzlei + password: 'a-jur' + + - name: andrea + groups: + - advoware + - aulmann + - howe + - stahmann + - traine + - public + password: 'fXc3bmK9gj' + + - name: andreas + groups: + - a-jur + - advoware + - alle + - kanzlei + password: '' + + - name: aphex2 + groups: + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'J3KMRprK9H' + + - name: berenice + groups: + - kanzlei + - a-jur + - alle + password: 'berenice' + + - name: beuster + groups: + - advoware + - aulmann + - howe + - stahmann + - traine + - public + - alle + password: 'zlm17Kx' + + - name: buero + groups: + - kanzlei + - a-jur + - alle + password: 'buero' + + - name: buero2 + groups: + - kanzlei + - a-jur + - alle + password: 'buero2' + + - name: buero3 + groups: + - kanzlei + - a-jur + - alle + password: 'buero3' + + - name: buero4 + groups: + - kanzlei + - a-jur + - alle + password: 'buero4' + + - name: buero7 + groups: + - kanzlei + - a-jur + - alle + password: 'buero7' + + - name: chris + groups: + - a-jur + - advoware + - alle + - aulmann + - intern + - kanzlei + - stahmann + - traine + - public + password: !vault | + $ANSIBLE_VAULT;1.1;AES256 + 30383265366434633965346530666535363761396165393434643665393137353765653739636364 + 6330623334353763613065343336306434376335646666380a363030363335656261656236636562 + 63663763616630383264303039336562626537366634303636356237323630666635356130383165 + 3837613337343533650a663061366230353531316535656433643162353063383534323833323138 + 3430 + + - name: christina + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'qvR7zX4Lhs' + + - name: federico + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'zHfj9g3NcC' + + - name: gerhard + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'bHdhzWnTj9' + + - name: ho-st1 + groups: + - alle + - howe + - stahmann + password: '44-Ro-440' + + - name: howe-staff-1 + groups: + - advoware + - alle + - aulmann + - howe + password: '' + + - name: irina + groups: + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'W9NKv39pXW' + + - name: jessica + groups: + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'bV3pjPtjkR' + + - name: laura + groups: + - alle + - aulmann + - howe + - stahmann + - traine + password: '99-Hamburg-990' + + - name: lenovo3 + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'fndvLmrt7W' + + - name: lenovo4 + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'tpCMmTKj7H' + + - name: lenovo5 + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: 'L5Hannover51' + + - name: lenovo6 + groups: + - advoware + - alle + - aulmann + - howe + - stahmann + - traine + password: '66koeln66' + + - name: rm-buero1 + groups: + - alle + - a-jur + - kanzlei + password: '' + + - name: rm-buero2 + groups: + - alle + - a-jur + - kanzlei + password: '' + + - name: rolf + groups: + - alle + - aulmann + - howe + - stahmann + - traine + - public + password: '4xNVNFXgP4' + + - name: sysadm + groups: + - a-jur + - advoware + - alle + - aulmann + - intern + - kanzlei + - stahmann + - traine + - public + password: 'Ax_GSHh5' + + - name: thomas + groups: + - advoware + - alle + - traine + password: '55-tho-mas-550' + + - name: Tresen + groups: + - a-jur + - advoware + - alle + - kanzlei + - howe + - stahmann + - traine + - public + password: 'maltzwo2' + + - name: winadm + groups: + - a-jur + - advoware + - alle + - intern + - kanzlei + - public + password: 'Ax_GSHh5' + + + +base_home: /data/home + +# remove_samba_users: +# - name: name1 +# - name: name2 +# +remove_samba_users: [] +#remove_samba_users: +# - name: evren + +samba_shares: + + - name: a-jur + comment: a-jur Dokumente + path: /data/samba/a-jur + group_valid_users: a-jur + group_write_list: a-jur + file_create_mask: !!str 664 + dir_create_mask: !!str 2775 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: kanzlei + comment: Kanzlei auf Fileserver + path: /data/samba/kanzlei + group_valid_users: kanzlei + group_write_list: kanzlei + file_create_mask: !!str 664 + dir_create_mask: !!str 2775 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: install + comment: Install auf Fileserver + path: /data/samba/no-backup-shares/install + group_valid_users: intern + group_write_list: intern + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: false + + - name: aulmann + comment: Aulmann auf Fileserver + path: /data/samba/Aulmann + group_valid_users: aulmann + group_write_list: aulmann + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: howe + comment: Howe auf Fileserver + path: /data/samba/Howe + group_valid_users: howe + group_write_list: howe + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: stahmann + comment: Stahmann auf Fileserver + path: /data/samba/Stahmann + group_valid_users: stahmann + group_write_list: stahmann + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: traine + comment: Traine auf Fileserver + path: /data/samba/Traine + group_valid_users: traine + group_write_list: traine + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: public + comment: Public auf Fileserver + path: /data/samba/public + group_valid_users: public + group_write_list: public + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: Advoware-Schriftverkehr + comment: Advoware Dokumente + path: /data/samba/Advoware-Schriftverkehr + group_valid_users: advoware + group_write_list: advoware + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + + - name: alle + comment: Alle auf Fileserver + path: /data/samba/Alle + group_valid_users: alle + group_write_list: alle + file_create_mask: !!str 660 + dir_create_mask: !!str 2770 + vfs_object_recycle: true + recycle_path: '@Recycle' + +# - name: web +# comment: Web auf Fileserver +# path: /data/samba/Web +# group_valid_users: web +# group_write_list: web +# file_create_mask: !!str 660 +# dir_create_mask: !!str 2770 +# vfs_object_recycle: true +# recycle_path: '@Recycle' + + +# ============================== + + +# --- +# vars used by scripts/reset_root_passwd.yml +# --- + +root_user: + name: root + password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. diff --git a/hosts b/hosts index bbb2e99..79f0f5b 100644 --- a/hosts +++ b/hosts @@ -1645,9 +1645,15 @@ web-10.oopen.de lxc-host-kb.anw-kb.netz -[oopen_office] +[oopen_office_server] bbb-server.b3-bornim.netz +file-ah.kanzlei-kiel.netz +file-ebs.ebs.netz +file-fhxb.fhxb.netz +file-km.anw-km.netz +file-blkr.blkr.netz +zapata.opp.netz [gateway_server_ro] diff --git a/roles/common/tasks/basic.yml b/roles/common/tasks/basic.yml index 86a5856..cc28c6c 100644 --- a/roles/common/tasks/basic.yml +++ b/roles/common/tasks/basic.yml @@ -39,9 +39,9 @@ group: root owner: root when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] - - copy_plain_files_systemd is defined - - copy_plain_files_systemd|length > 0 + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] + - copy_plain_files_security_limits is defined + - copy_plain_files_security_limits|length > 0 tags: - systemd-config @@ -56,9 +56,9 @@ loop_control: label: 'dest: {{ item.name }}' when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] - - copy_plain_files_systemd is defined - - copy_plain_files_systemd|length > 0 + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] + - copy_plain_files_security_limits is defined + - copy_plain_files_security_limits|length > 0 tags: - systemd-config @@ -75,7 +75,7 @@ group: root owner: root when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] - copy_plain_files_systemd is defined - copy_plain_files_systemd|length > 0 tags: @@ -92,7 +92,7 @@ loop_control: label: 'dest: {{ item.name }}' when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] - copy_plain_files_systemd is defined - copy_plain_files_systemd|length > 0 tags: @@ -141,7 +141,7 @@ group: root owner: root when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] - copy_plain_files_sysctl is defined - copy_plain_files_sysctl|length > 0 tags: @@ -158,7 +158,7 @@ loop_control: label: 'dest: {{ item.name }}' when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] - copy_plain_files_sysctl is defined - copy_plain_files_sysctl|length > 0 tags: @@ -175,7 +175,7 @@ loop_control: label: 'dest: {{ item.name }}' when: - - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] + - inventory_hostname not in groups['lxc_guest'] or inventory_hostname in groups['lxc_host'] or inventory_hostname in groups['oopen_office_server'] - copy_additional_plain_files_sysctl is defined - copy_additional_plain_files_sysctl|length > 0 tags: diff --git a/zzz,yml b/zzz,yml new file mode 100644 index 0000000..aa3becf --- /dev/null +++ b/zzz,yml @@ -0,0 +1,13 @@ +password: !vault | + $ANSIBLE_VAULT;1.1;AES256 + 61333136626331663238616231306134343737646638393938386635346334313433363632653562 + 6166393561363037383638336337633461396363616163380a616563636361366365393537376365 + 62623964633838663963333034373833653330343235366536313031366363613863653939306138 + 3463333362333530330a623664643638326431373738313739366666303639363235316238323637 + 6534password: !vault | + $ANSIBLE_VAULT;1.1;AES256 + 38306635326230643435383165373037383061316439323431343838633339306139333733313939 + 3933316130363132663462316164623762613562636163640a643163643937353738313464326566 + 35373939656665653834343863303832633335633134326331646231653363313437336165333364 + 3638336363636265300a663266333762343936613138663631383363646435646364336135353233 + 6661 \ No newline at end of file diff --git a/zzz.yml b/zzz.yml new file mode 100644 index 0000000..e69de29