Compare commits
7 Commits
7ca6f6a2ab
...
master
Author | SHA1 | Date | |
---|---|---|---|
d7cab54470 | |||
b64076ed5d | |||
e5321fc0d2 | |||
67ea094453 | |||
a81cf75e13 | |||
5d18b79372 | |||
86a1d988c7 |
@ -111,3 +111,7 @@ export EDITOR=vim
|
||||
## - set beep more quiet
|
||||
## -
|
||||
#xset b 10 500 50
|
||||
|
||||
# turn off the beep (only in bash tab-complete ?)
|
||||
# only if interactiv shell
|
||||
[[ "$-" =~ "i" ]] && bind 'set bell-style none'
|
||||
|
@ -171,3 +171,4 @@ set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\
|
||||
set laststatus=2
|
||||
highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
|
||||
set belloff=all
|
||||
|
@ -1,178 +0,0 @@
|
||||
" An example for a vimrc file.
|
||||
"
|
||||
" Maintainer: Bram Moolenaar <Bram@vim.org>
|
||||
" Last change: 1999 Sep 09
|
||||
"
|
||||
" To use it, copy it to
|
||||
" for Unix and OS/2: ~/.vimrc
|
||||
" for Amiga: s:.vimrc
|
||||
" for MS-DOS and Win32: $VIM\_vimrc
|
||||
|
||||
" This line should not be removed as it ensures that various options are
|
||||
" properly set to work with the Vim-related packages available in Debian.
|
||||
runtime! debian.vim
|
||||
|
||||
set nocompatible " Use Vim defaults (much better!)
|
||||
set bs=2 " allow backspacing over everything in insert mode
|
||||
set ai " always set autoindenting on
|
||||
" set backup " keep a backup file
|
||||
"set viminfo='20,\"50 " read/write a .viminfo file, don't store more
|
||||
" than 50 lines of registers
|
||||
set viminfo='20,\"50,:20,%,n~/.viminfo
|
||||
set history=50 " keep 50 lines of command line history
|
||||
set ruler " show the cursor position all the time
|
||||
set ignorecase " suchen case-insenitiv
|
||||
set showmatch " zeige passende klammern
|
||||
set shell=/bin/bash " shell to start with !
|
||||
set expandtab " tabs --> blanks
|
||||
set showmode " anzeige INSERT/REPLACE/...
|
||||
|
||||
" set smartcase " Do smart case matching
|
||||
|
||||
set incsearch " Incremental search
|
||||
" Start searching when you type the first character of
|
||||
" the search string. As you type in more characters, the
|
||||
" search is refined.
|
||||
|
||||
set t_Co=256 " To enable 256 colors in vim, put this your .vimrc before setting the colorscheme
|
||||
|
||||
" einrueckung
|
||||
"set noexpandtab
|
||||
set expandtab
|
||||
set shiftwidth=3
|
||||
set tabstop=3
|
||||
set softtabstop=3
|
||||
" Round indent to multiple of 'shiftwidth' for > and < commands
|
||||
set shiftround
|
||||
"set number
|
||||
|
||||
" For Win32 GUI: remove 't' flag from 'guioptions': no tearoff menu entries
|
||||
" let &guioptions = substitute(&guioptions, "t", "", "g")
|
||||
|
||||
" Don't use Ex mode, use Q for formatting
|
||||
map Q gq
|
||||
|
||||
" Make p in isual Visual mode replace the selected text with the "" register.
|
||||
vnoremap p <Esc>:let current_reg = @"<CR>gvdi<C-R>=current_reg<CR><Esc>
|
||||
|
||||
" Switch syntax highlighting on, when the terminal has colors
|
||||
" Also switch on highlighting the last used search pattern.
|
||||
if &t_Co > 2 || has("gui_running")
|
||||
syntax on
|
||||
set hlsearch
|
||||
endif
|
||||
|
||||
" Only do this part when compiled with support for autocommands.
|
||||
if has("autocmd")
|
||||
|
||||
" In text files, always limit the width of text to 78 characters
|
||||
autocmd BufRead *.txt set tw=78
|
||||
|
||||
augroup cprog
|
||||
" Remove all cprog autocommands
|
||||
au!
|
||||
|
||||
" When starting to edit a file:
|
||||
" For C and C++ files set formatting of comments and set C-indenting on.
|
||||
" For other files switch it off.
|
||||
" Don't change the order, it's important that the line with * comes first.
|
||||
autocmd FileType * set formatoptions=tcql nocindent comments&
|
||||
autocmd FileType c,cpp set formatoptions=croql cindent comments=sr:/*,mb:*,el:*/,://
|
||||
augroup END
|
||||
|
||||
augroup gzip
|
||||
" Remove all gzip autocommands
|
||||
au!
|
||||
|
||||
" Enable editing of gzipped files
|
||||
" set binary mode before reading the file
|
||||
autocmd BufReadPre,FileReadPre *.gz,*.bz2 set bin
|
||||
autocmd BufReadPost,FileReadPost *.gz call GZIP_read("gunzip")
|
||||
autocmd BufReadPost,FileReadPost *.bz2 call GZIP_read("bunzip2")
|
||||
autocmd BufWritePost,FileWritePost *.gz call GZIP_write("gzip")
|
||||
autocmd BufWritePost,FileWritePost *.bz2 call GZIP_write("bzip2")
|
||||
autocmd FileAppendPre *.gz call GZIP_appre("gunzip")
|
||||
autocmd FileAppendPre *.bz2 call GZIP_appre("bunzip2")
|
||||
autocmd FileAppendPost *.gz call GZIP_write("gzip")
|
||||
autocmd FileAppendPost *.bz2 call GZIP_write("bzip2")
|
||||
|
||||
" After reading compressed file: Uncompress text in buffer with "cmd"
|
||||
fun! GZIP_read(cmd)
|
||||
let ch_save = &ch
|
||||
set ch=2
|
||||
execute "'[,']!" . a:cmd
|
||||
set nobin
|
||||
let &ch = ch_save
|
||||
execute ":doautocmd BufReadPost " . expand("%:r")
|
||||
endfun
|
||||
|
||||
" After writing compressed file: Compress written file with "cmd"
|
||||
fun! GZIP_write(cmd)
|
||||
if rename(expand("<afile>"), expand("<afile>:r")) == 0
|
||||
execute "!" . a:cmd . " <afile>:r"
|
||||
endif
|
||||
endfun
|
||||
|
||||
" Before appending to compressed file: Uncompress file with "cmd"
|
||||
fun! GZIP_appre(cmd)
|
||||
execute "!" . a:cmd . " <afile>"
|
||||
call rename(expand("<afile>:r"), expand("<afile>"))
|
||||
endfun
|
||||
|
||||
augroup END
|
||||
|
||||
" This is disabled, because it changes the jumplist. Can't use CTRL-O to go
|
||||
" back to positions in previous files more than once.
|
||||
if 0
|
||||
" When editing a file, always jump to the last cursor position.
|
||||
" This must be after the uncompress commands.
|
||||
autocmd BufReadPost * if line("'\"") && line("'\"") <= line("$") | exe "normal `\"" | endif
|
||||
endif
|
||||
|
||||
endif " has("autocmd")
|
||||
|
||||
" toggle syntax highlighting
|
||||
map <F12> :if exists("syntax_on") <Bar> syntax off <Bar> else <Bar> syntax on <Bar> endif <CR><ESC>
|
||||
map <F11> :nohls <CR>
|
||||
|
||||
" use <F6> to toggle line numbers
|
||||
nmap <silent> <F6> :set number!<CR>
|
||||
|
||||
|
||||
" If using a dark background within the editing area and syntax highlighting
|
||||
" turn on this option as well
|
||||
set background=dark
|
||||
|
||||
|
||||
" set color for search
|
||||
hi clear search
|
||||
hi search term=bold,reverse cterm=bold,reverse gui=bold,reverse
|
||||
|
||||
" set color for Comment
|
||||
hi clear Comment
|
||||
"highlight Comment term=bold cterm=bold ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=bold cterm=bold ctermfg=grey guifg=#80a0ff gui=bold
|
||||
highlight Comment term=none cterm=none ctermfg=grey guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=177 guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=215 guifg=#80a0ff gui=bold
|
||||
|
||||
" Go back to the position the cursor was on the last time this file was edited
|
||||
au BufReadPost * if line("'\"") > 0 && line("'\"") <= line("$")|execute("normal `\"")|endif
|
||||
|
||||
" visual shifting (does not exit Visual mode)
|
||||
vnoremap < <gv
|
||||
vnoremap > >gv
|
||||
|
||||
" Scroll when cursor gets within 3 characters of top/bottom edge
|
||||
set scrolloff=3
|
||||
|
||||
" Show line, column number, and relative position within a file in the status line
|
||||
" set statusline=%F%m%r%h%w\ [FORMAT=%{&ff}]\ [TYPE=%Y]\ [ASCII=\%03.3b]\ [HEX=\%02.2B]\ [POS=%04l,%04v][%p%%]\ [LEN=%L]
|
||||
"set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)%(\|\ syntax:\ %{synIDattr(synID(line('.'),col('.'),0),'name')}%)\ \ %=line:\ %l/%L\ \|\ column:\ %c%V\ \|\ relative\:\ %p%%\
|
||||
set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)\ \ %=line:\ %l/%L\ \|\ col:\ %c%V\ \|\ %p%%
|
||||
" Always show status line, even for one window
|
||||
set laststatus=2
|
||||
highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
|
||||
colorscheme PaperColor
|
@ -1,178 +0,0 @@
|
||||
" An example for a vimrc file.
|
||||
"
|
||||
" Maintainer: Bram Moolenaar <Bram@vim.org>
|
||||
" Last change: 1999 Sep 09
|
||||
"
|
||||
" To use it, copy it to
|
||||
" for Unix and OS/2: ~/.vimrc
|
||||
" for Amiga: s:.vimrc
|
||||
" for MS-DOS and Win32: $VIM\_vimrc
|
||||
|
||||
" This line should not be removed as it ensures that various options are
|
||||
" properly set to work with the Vim-related packages available in Debian.
|
||||
runtime! debian.vim
|
||||
|
||||
set nocompatible " Use Vim defaults (much better!)
|
||||
set bs=2 " allow backspacing over everything in insert mode
|
||||
set ai " always set autoindenting on
|
||||
" set backup " keep a backup file
|
||||
"set viminfo='20,\"50 " read/write a .viminfo file, don't store more
|
||||
" than 50 lines of registers
|
||||
set viminfo='20,\"50,:20,%,n~/.viminfo
|
||||
set history=50 " keep 50 lines of command line history
|
||||
set ruler " show the cursor position all the time
|
||||
set ignorecase " suchen case-insenitiv
|
||||
set showmatch " zeige passende klammern
|
||||
set shell=/bin/bash " shell to start with !
|
||||
set expandtab " tabs --> blanks
|
||||
set showmode " anzeige INSERT/REPLACE/...
|
||||
|
||||
" set smartcase " Do smart case matching
|
||||
|
||||
set incsearch " Incremental search
|
||||
" Start searching when you type the first character of
|
||||
" the search string. As you type in more characters, the
|
||||
" search is refined.
|
||||
|
||||
set t_Co=256 " To enable 256 colors in vim, put this your .vimrc before setting the colorscheme
|
||||
|
||||
" einrueckung
|
||||
"set noexpandtab
|
||||
set expandtab
|
||||
set shiftwidth=3
|
||||
set tabstop=3
|
||||
set softtabstop=3
|
||||
" Round indent to multiple of 'shiftwidth' for > and < commands
|
||||
set shiftround
|
||||
"set number
|
||||
|
||||
" For Win32 GUI: remove 't' flag from 'guioptions': no tearoff menu entries
|
||||
" let &guioptions = substitute(&guioptions, "t", "", "g")
|
||||
|
||||
" Don't use Ex mode, use Q for formatting
|
||||
map Q gq
|
||||
|
||||
" Make p in isual Visual mode replace the selected text with the "" register.
|
||||
vnoremap p <Esc>:let current_reg = @"<CR>gvdi<C-R>=current_reg<CR><Esc>
|
||||
|
||||
" Switch syntax highlighting on, when the terminal has colors
|
||||
" Also switch on highlighting the last used search pattern.
|
||||
if &t_Co > 2 || has("gui_running")
|
||||
syntax on
|
||||
set hlsearch
|
||||
endif
|
||||
|
||||
" Only do this part when compiled with support for autocommands.
|
||||
if has("autocmd")
|
||||
|
||||
" In text files, always limit the width of text to 78 characters
|
||||
autocmd BufRead *.txt set tw=78
|
||||
|
||||
augroup cprog
|
||||
" Remove all cprog autocommands
|
||||
au!
|
||||
|
||||
" When starting to edit a file:
|
||||
" For C and C++ files set formatting of comments and set C-indenting on.
|
||||
" For other files switch it off.
|
||||
" Don't change the order, it's important that the line with * comes first.
|
||||
autocmd FileType * set formatoptions=tcql nocindent comments&
|
||||
autocmd FileType c,cpp set formatoptions=croql cindent comments=sr:/*,mb:*,el:*/,://
|
||||
augroup END
|
||||
|
||||
augroup gzip
|
||||
" Remove all gzip autocommands
|
||||
au!
|
||||
|
||||
" Enable editing of gzipped files
|
||||
" set binary mode before reading the file
|
||||
autocmd BufReadPre,FileReadPre *.gz,*.bz2 set bin
|
||||
autocmd BufReadPost,FileReadPost *.gz call GZIP_read("gunzip")
|
||||
autocmd BufReadPost,FileReadPost *.bz2 call GZIP_read("bunzip2")
|
||||
autocmd BufWritePost,FileWritePost *.gz call GZIP_write("gzip")
|
||||
autocmd BufWritePost,FileWritePost *.bz2 call GZIP_write("bzip2")
|
||||
autocmd FileAppendPre *.gz call GZIP_appre("gunzip")
|
||||
autocmd FileAppendPre *.bz2 call GZIP_appre("bunzip2")
|
||||
autocmd FileAppendPost *.gz call GZIP_write("gzip")
|
||||
autocmd FileAppendPost *.bz2 call GZIP_write("bzip2")
|
||||
|
||||
" After reading compressed file: Uncompress text in buffer with "cmd"
|
||||
fun! GZIP_read(cmd)
|
||||
let ch_save = &ch
|
||||
set ch=2
|
||||
execute "'[,']!" . a:cmd
|
||||
set nobin
|
||||
let &ch = ch_save
|
||||
execute ":doautocmd BufReadPost " . expand("%:r")
|
||||
endfun
|
||||
|
||||
" After writing compressed file: Compress written file with "cmd"
|
||||
fun! GZIP_write(cmd)
|
||||
if rename(expand("<afile>"), expand("<afile>:r")) == 0
|
||||
execute "!" . a:cmd . " <afile>:r"
|
||||
endif
|
||||
endfun
|
||||
|
||||
" Before appending to compressed file: Uncompress file with "cmd"
|
||||
fun! GZIP_appre(cmd)
|
||||
execute "!" . a:cmd . " <afile>"
|
||||
call rename(expand("<afile>:r"), expand("<afile>"))
|
||||
endfun
|
||||
|
||||
augroup END
|
||||
|
||||
" This is disabled, because it changes the jumplist. Can't use CTRL-O to go
|
||||
" back to positions in previous files more than once.
|
||||
if 0
|
||||
" When editing a file, always jump to the last cursor position.
|
||||
" This must be after the uncompress commands.
|
||||
autocmd BufReadPost * if line("'\"") && line("'\"") <= line("$") | exe "normal `\"" | endif
|
||||
endif
|
||||
|
||||
endif " has("autocmd")
|
||||
|
||||
" toggle syntax highlighting
|
||||
map <F12> :if exists("syntax_on") <Bar> syntax off <Bar> else <Bar> syntax on <Bar> endif <CR><ESC>
|
||||
map <F11> :nohls <CR>
|
||||
|
||||
" use <F6> to toggle line numbers
|
||||
nmap <silent> <F6> :set number!<CR>
|
||||
|
||||
|
||||
" If using a dark background within the editing area and syntax highlighting
|
||||
" turn on this option as well
|
||||
set background=dark
|
||||
|
||||
|
||||
" set color for search
|
||||
hi clear search
|
||||
hi search term=bold,reverse cterm=bold,reverse gui=bold,reverse
|
||||
|
||||
" set color for Comment
|
||||
hi clear Comment
|
||||
"highlight Comment term=bold cterm=bold ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=bold cterm=bold ctermfg=grey guifg=#80a0ff gui=bold
|
||||
highlight Comment term=none cterm=none ctermfg=grey guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=177 guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=215 guifg=#80a0ff gui=bold
|
||||
|
||||
" Go back to the position the cursor was on the last time this file was edited
|
||||
au BufReadPost * if line("'\"") > 0 && line("'\"") <= line("$")|execute("normal `\"")|endif
|
||||
|
||||
" visual shifting (does not exit Visual mode)
|
||||
vnoremap < <gv
|
||||
vnoremap > >gv
|
||||
|
||||
" Scroll when cursor gets within 3 characters of top/bottom edge
|
||||
set scrolloff=3
|
||||
|
||||
" Show line, column number, and relative position within a file in the status line
|
||||
" set statusline=%F%m%r%h%w\ [FORMAT=%{&ff}]\ [TYPE=%Y]\ [ASCII=\%03.3b]\ [HEX=\%02.2B]\ [POS=%04l,%04v][%p%%]\ [LEN=%L]
|
||||
"set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)%(\|\ syntax:\ %{synIDattr(synID(line('.'),col('.'),0),'name')}%)\ \ %=line:\ %l/%L\ \|\ column:\ %c%V\ \|\ relative\:\ %p%%\
|
||||
set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)\ \ %=line:\ %l/%L\ \|\ col:\ %c%V\ \|\ %p%%
|
||||
" Always show status line, even for one window
|
||||
set laststatus=2
|
||||
highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
|
||||
colorscheme PaperColor
|
@ -113,3 +113,7 @@ export EDITOR=vim
|
||||
## - set beep more quiet
|
||||
## -
|
||||
#xset b 10 500 50
|
||||
|
||||
# turn off the beep (only in bash tab-complete ?)
|
||||
# only if interactiv shell
|
||||
[[ "$-" =~ "i" ]] && bind 'set bell-style none'
|
||||
|
@ -178,4 +178,6 @@ highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
"Remove all trailing whitespace by pressing F5
|
||||
nnoremap <F5> :let _s=@/<Bar>:%s/\s\+$//e<Bar>:let @/=_s<Bar><CR>
|
||||
|
||||
set belloff=all
|
||||
|
||||
colorscheme PaperColor
|
||||
|
@ -76,3 +76,7 @@ export LINES=64
|
||||
## - set beep more quiet
|
||||
## -
|
||||
#xset b 10 500 50
|
||||
|
||||
# turn off the beep (only in bash tab-complete ?)
|
||||
# only if interactiv shell
|
||||
[[ "$-" =~ "i" ]] && bind 'set bell-style none'
|
||||
|
@ -178,4 +178,6 @@ highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
"Remove all trailing whitespace by pressing F5
|
||||
nnoremap <F5> :let _s=@/<Bar>:%s/\s\+$//e<Bar>:let @/=_s<Bar><CR>
|
||||
|
||||
set belloff=all
|
||||
|
||||
colorscheme PaperColor
|
||||
|
@ -1,173 +0,0 @@
|
||||
" An example for a vimrc file.
|
||||
"
|
||||
" Maintainer: Bram Moolenaar <Bram@vim.org>
|
||||
" Last change: 1999 Sep 09
|
||||
"
|
||||
" To use it, copy it to
|
||||
" for Unix and OS/2: ~/.vimrc
|
||||
" for Amiga: s:.vimrc
|
||||
" for MS-DOS and Win32: $VIM\_vimrc
|
||||
|
||||
" This line should not be removed as it ensures that various options are
|
||||
" properly set to work with the Vim-related packages available in Debian.
|
||||
runtime! debian.vim
|
||||
|
||||
set nocompatible " Use Vim defaults (much better!)
|
||||
set bs=2 " allow backspacing over everything in insert mode
|
||||
set ai " always set autoindenting on
|
||||
" set backup " keep a backup file
|
||||
"set viminfo='20,\"50 " read/write a .viminfo file, don't store more
|
||||
" than 50 lines of registers
|
||||
set viminfo='20,\"50,:20,%,n~/.viminfo
|
||||
set history=50 " keep 50 lines of command line history
|
||||
set ruler " show the cursor position all the time
|
||||
set ignorecase " suchen case-insenitiv
|
||||
set showmatch " zeige passende klammern
|
||||
set shell=/bin/bash " shell to start with !
|
||||
set expandtab " tabs --> blanks
|
||||
set showmode " anzeige INSERT/REPLACE/...
|
||||
|
||||
" set smartcase " Do smart case matching
|
||||
|
||||
set incsearch " Incremental search
|
||||
" Start searching when you type the first character of
|
||||
" the search string. As you type in more characters, the
|
||||
" search is refined.
|
||||
|
||||
set t_Co=256 " To enable 256 colors in vim, put this your .vimrc before setting the colorscheme
|
||||
|
||||
" einrueckung
|
||||
set shiftwidth=3
|
||||
set tabstop=3
|
||||
" Round indent to multiple of 'shiftwidth' for > and < commands
|
||||
set shiftround
|
||||
|
||||
" For Win32 GUI: remove 't' flag from 'guioptions': no tearoff menu entries
|
||||
" let &guioptions = substitute(&guioptions, "t", "", "g")
|
||||
|
||||
" Don't use Ex mode, use Q for formatting
|
||||
map Q gq
|
||||
|
||||
" Make p in isual Visual mode replace the selected text with the "" register.
|
||||
vnoremap p <Esc>:let current_reg = @"<CR>gvdi<C-R>=current_reg<CR><Esc>
|
||||
|
||||
" Switch syntax highlighting on, when the terminal has colors
|
||||
" Also switch on highlighting the last used search pattern.
|
||||
if &t_Co > 2 || has("gui_running")
|
||||
syntax on
|
||||
set hlsearch
|
||||
endif
|
||||
|
||||
" Only do this part when compiled with support for autocommands.
|
||||
if has("autocmd")
|
||||
|
||||
" In text files, always limit the width of text to 78 characters
|
||||
autocmd BufRead *.txt set tw=78
|
||||
|
||||
augroup cprog
|
||||
" Remove all cprog autocommands
|
||||
au!
|
||||
|
||||
" When starting to edit a file:
|
||||
" For C and C++ files set formatting of comments and set C-indenting on.
|
||||
" For other files switch it off.
|
||||
" Don't change the order, it's important that the line with * comes first.
|
||||
autocmd FileType * set formatoptions=tcql nocindent comments&
|
||||
autocmd FileType c,cpp set formatoptions=croql cindent comments=sr:/*,mb:*,el:*/,://
|
||||
augroup END
|
||||
|
||||
augroup gzip
|
||||
" Remove all gzip autocommands
|
||||
au!
|
||||
|
||||
" Enable editing of gzipped files
|
||||
" set binary mode before reading the file
|
||||
autocmd BufReadPre,FileReadPre *.gz,*.bz2 set bin
|
||||
autocmd BufReadPost,FileReadPost *.gz call GZIP_read("gunzip")
|
||||
autocmd BufReadPost,FileReadPost *.bz2 call GZIP_read("bunzip2")
|
||||
autocmd BufWritePost,FileWritePost *.gz call GZIP_write("gzip")
|
||||
autocmd BufWritePost,FileWritePost *.bz2 call GZIP_write("bzip2")
|
||||
autocmd FileAppendPre *.gz call GZIP_appre("gunzip")
|
||||
autocmd FileAppendPre *.bz2 call GZIP_appre("bunzip2")
|
||||
autocmd FileAppendPost *.gz call GZIP_write("gzip")
|
||||
autocmd FileAppendPost *.bz2 call GZIP_write("bzip2")
|
||||
|
||||
" After reading compressed file: Uncompress text in buffer with "cmd"
|
||||
fun! GZIP_read(cmd)
|
||||
let ch_save = &ch
|
||||
set ch=2
|
||||
execute "'[,']!" . a:cmd
|
||||
set nobin
|
||||
let &ch = ch_save
|
||||
execute ":doautocmd BufReadPost " . expand("%:r")
|
||||
endfun
|
||||
|
||||
" After writing compressed file: Compress written file with "cmd"
|
||||
fun! GZIP_write(cmd)
|
||||
if rename(expand("<afile>"), expand("<afile>:r")) == 0
|
||||
execute "!" . a:cmd . " <afile>:r"
|
||||
endif
|
||||
endfun
|
||||
|
||||
" Before appending to compressed file: Uncompress file with "cmd"
|
||||
fun! GZIP_appre(cmd)
|
||||
execute "!" . a:cmd . " <afile>"
|
||||
call rename(expand("<afile>:r"), expand("<afile>"))
|
||||
endfun
|
||||
|
||||
augroup END
|
||||
|
||||
" This is disabled, because it changes the jumplist. Can't use CTRL-O to go
|
||||
" back to positions in previous files more than once.
|
||||
if 0
|
||||
" When editing a file, always jump to the last cursor position.
|
||||
" This must be after the uncompress commands.
|
||||
autocmd BufReadPost * if line("'\"") && line("'\"") <= line("$") | exe "normal `\"" | endif
|
||||
endif
|
||||
|
||||
endif " has("autocmd")
|
||||
|
||||
" toggle syntax highlighting
|
||||
map <F12> :if exists("syntax_on") <Bar> syntax off <Bar> else <Bar> syntax on <Bar> endif <CR><ESC>
|
||||
map <F11> :nohls <CR>
|
||||
|
||||
" use <F6> to toggle line numbers
|
||||
nmap <silent> <F6> :set number!<CR>
|
||||
|
||||
|
||||
" If using a dark background within the editing area and syntax highlighting
|
||||
" turn on this option as well
|
||||
set background=dark
|
||||
|
||||
|
||||
" set color for search
|
||||
hi clear search
|
||||
hi search term=bold,reverse cterm=bold,reverse gui=bold,reverse
|
||||
|
||||
" set color for Comment
|
||||
hi clear Comment
|
||||
"highlight Comment term=bold cterm=bold ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=LightBlue guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=bold cterm=bold ctermfg=grey guifg=#80a0ff gui=bold
|
||||
highlight Comment term=none cterm=none ctermfg=grey guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=177 guifg=#80a0ff gui=bold
|
||||
"highlight Comment term=none cterm=none ctermfg=215 guifg=#80a0ff gui=bold
|
||||
|
||||
" Go back to the position the cursor was on the last time this file was edited
|
||||
au BufReadPost * if line("'\"") > 0 && line("'\"") <= line("$")|execute("normal `\"")|endif
|
||||
|
||||
" visual shifting (does not exit Visual mode)
|
||||
vnoremap < <gv
|
||||
vnoremap > >gv
|
||||
|
||||
" Scroll when cursor gets within 3 characters of top/bottom edge
|
||||
set scrolloff=3
|
||||
|
||||
" Show line, column number, and relative position within a file in the status line
|
||||
" set statusline=%F%m%r%h%w\ [FORMAT=%{&ff}]\ [TYPE=%Y]\ [ASCII=\%03.3b]\ [HEX=\%02.2B]\ [POS=%04l,%04v][%p%%]\ [LEN=%L]
|
||||
"set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)%(\|\ syntax:\ %{synIDattr(synID(line('.'),col('.'),0),'name')}%)\ \ %=line:\ %l/%L\ \|\ column:\ %c%V\ \|\ relative\:\ %p%%\
|
||||
set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\ %{&ff}\ %)\ \ %=line:\ %l/%L\ \|\ col:\ %c%V\ \|\ %p%%
|
||||
" Always show status line, even for one window
|
||||
set laststatus=2
|
||||
highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
|
@ -73,3 +73,7 @@ export LINES=64
|
||||
## - set beep more quiet
|
||||
## -
|
||||
#xset b 10 500 50
|
||||
|
||||
# turn off the beep (only in bash tab-complete ?)
|
||||
# only if interactiv shell
|
||||
[[ "$-" =~ "i" ]] && bind 'set bell-style none'
|
||||
|
@ -175,4 +175,6 @@ set statusline=\ %F\ %(\|\ flags:\ %R%M%H%W\ %)%(\|\ type:\ %Y\ %)%(\|\ format:\
|
||||
set laststatus=2
|
||||
highlight StatusLine cterm=none ctermfg=white ctermbg=blue
|
||||
|
||||
set belloff=all
|
||||
|
||||
colorscheme PaperColor
|
||||
|
@ -2941,6 +2941,10 @@ samba_netbios_name:
|
||||
#
|
||||
samba_server_min_protocol: []
|
||||
|
||||
# samba_allow_insecure_wide_links
|
||||
#
|
||||
samba_allow_insecure_wide_links: !!str no
|
||||
|
||||
samba_groups: []
|
||||
|
||||
# samba_user:
|
||||
|
@ -282,6 +282,7 @@ default_user:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOvOkCWNKUJ5o9e+0NhY4IFZv8LA7tkkkEFjr8nqFKhe root@formbricks-nd'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJPbony+4g4iFS32Cv/Bkmet4FsCAsrGTffwWm2eM16x root@git.warenform'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDqqmBWh3qmnx41NiLCn1LhVG0mn4++IUvRNC0OMh6h6 root@gitoea'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICR9o0+6jnfmXKOedKP6IZgt5lRIPFSJJ4FbMjz2SPkH root@gw-campus'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFEm1P7Pg3Tlm02bxkropKf3CcyTCAB3YCMxPSjai2lc root@gw-dissens'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBYFe6i0UdPRyENvfaJSJVCHtmnlJmhbqGEsdIlTapsj root@initiativenserver'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ54/I+TdZUA+Xc6bixSa3f0hN5y4kWW+xl9kqSZPBYS root@keycloak-nd'
|
||||
@ -328,6 +329,7 @@ default_user:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMUnxlKIffm8a5BmoQE40h8ut0R6eCxcm+Iewv3evmE9 root@oolm-shop'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF4ylglAkPst7G6kES2lE96ECp0AGXGjzCVkZSqGVru6 root@oolm-shop-dev'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIUZ0WNd3rTqHH1tiXAELwssGw6xUP1ROdhgxKbMinYY root@oolm-web'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEJJCzTmrRp0s0qpkf9HYyx4lL+zs1jTAYcCsvqpJ72p root@super-opferhilfefonds'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID82UUUkYKYFbJdmTcMYu+vl3M0FVQznXFbngqPoumP+ root@prometheus-nd'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJU5HzfGYZwWeaoAGGFF7/3VQP19ce6Rgn5wcOR98Q3o root@server26'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBRfCFz6mPdn3TKVCgffHQAKt3LN/0srS/gBsMoOyZpi root@shop-agr'
|
||||
|
@ -252,6 +252,9 @@ default_user:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIE1RkJYM8qcEagoKt9gNVaeBbXZEJscqIBNnhL/KZfSA root@munin.oopen.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIj2SdZgxG4NCjUiCXY7msCG+Vn6MQ5jsGxrs2qn1QZh root@mx'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHQAvCK/h7+8h8hPm3WyeEdBbhY4SdOSWJYxuFW24XbM root@nd'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICwG3cYT1S5ttaf7OCB2dfBAg4FFA3OO3HPTkiclaVFi root@server22'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJyse/Fby2JiHjM10uotVfsBYO0W1EgmtFG2q+Q1xe38 root@server24'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIH9V1aqgZSqu7vfK9e5qGKm+ICHd8VglRr0Brm4kXfu root@server25'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBOOYhdtNPAQP8BlgSYBaMfWl8Yv4Y9ww7SWeLOn0HXH root@web0'
|
||||
|
||||
|
||||
|
@ -168,6 +168,68 @@ resolved_fallback_nameserver:
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users
|
||||
# ---
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$sHxqz7NyYdn38ZegSbewO.$PPHR0n.XeMcS3AQ9KybllBT.2hxpYlQ7AiVhxHgUOX8
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: localadmin
|
||||
user_id: 1051
|
||||
group_id: 1051
|
||||
group: localadmin
|
||||
home: /home/localadmin
|
||||
password: $y$j9T$1WH8G2UkuN1jjp4QLuoeC0$dXpOnJUfMMAqAXlwN8XD0pq78r.a4UZOgt3LY4afxy/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$WmitGB98lhPLJ39Iy4YfH.$irv0LP1bB5ImQKBUr1acEif6Ed6zDu6gLQuGQd/i5s0
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup'
|
||||
|
||||
|
||||
- name: borg
|
||||
user_id: 1065
|
||||
group_id: 1065
|
||||
group: borg
|
||||
home: /home/borg
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF7MKFmJ2kJrNs5DhlPqfizZgz3wNpzFAITo63p/VBOe root@file-ah'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIItQLQ7lhBY2USF4Jcp4teF+1NydI73VeHYbQW8q4Mcw root@gw-ah'
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
@ -201,7 +201,7 @@ cron_user_special_time_entries:
|
||||
|
||||
sudoers_file_user_aliases:
|
||||
- name: MAIN_USER
|
||||
entry: 'josephine, julius, julius-e, sebastian'
|
||||
entry: 'josephine, julius, julius-e, leonie, buero1, buero2, buero3, referendariat, refa, ref1, sebastian, buero-05, buero-06, lap-01'
|
||||
|
||||
sudoers_file_cmnd_aliases:
|
||||
- name: REBOOT
|
||||
@ -360,6 +360,14 @@ samba_user:
|
||||
groups:
|
||||
- buero
|
||||
password: 'N-ba2R+i/2eM'
|
||||
- name: lap-01
|
||||
groups:
|
||||
- buero
|
||||
password: 'X_2yYs2AIo.E'
|
||||
# - name: lap-02
|
||||
# groups:
|
||||
# - buero
|
||||
# password: 'N.i/_UXcG5C9'
|
||||
|
||||
base_home: /data/home
|
||||
|
||||
|
@ -143,6 +143,68 @@ resolved_fallback_nameserver:
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users
|
||||
# ---
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$sHxqz7NyYdn38ZegSbewO.$PPHR0n.XeMcS3AQ9KybllBT.2hxpYlQ7AiVhxHgUOX8
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: localadmin
|
||||
user_id: 1051
|
||||
group_id: 1051
|
||||
group: localadmin
|
||||
home: /home/localadmin
|
||||
password: $y$j9T$1WH8G2UkuN1jjp4QLuoeC0$dXpOnJUfMMAqAXlwN8XD0pq78r.a4UZOgt3LY4afxy/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$WmitGB98lhPLJ39Iy4YfH.$irv0LP1bB5ImQKBUr1acEif6Ed6zDu6gLQuGQd/i5s0
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup'
|
||||
|
||||
#extra_user:
|
||||
#
|
||||
# - name: borg
|
||||
# user_id: 1065
|
||||
# group_id: 1065
|
||||
# group: borg
|
||||
# home: /home/borg
|
||||
# password: $y$j9T$SZty9T8ZWbnyHR2S85xaG.$GhxHOKG9fKErT9s5TAehXXyZJSkNaIcXY18Rg1iMyhC
|
||||
# shell: /bin/bash
|
||||
# ssh_keys:
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHXrNhcgNtZykTgzcwX/L1cL8qpSyQQy75M01UpjdSmA root@file-dissens'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFEm1P7Pg3Tlm02bxkropKf3CcyTCAB3YCMxPSjai2lc root@gw-dissens'
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
@ -400,6 +462,11 @@ samba_user:
|
||||
- projekte
|
||||
password: '20.ros1tsa-mahd1+24+'
|
||||
|
||||
- name: selma.albrecht
|
||||
groups:
|
||||
- projekte
|
||||
password: '20-sel-ma.al-brecht/25!'
|
||||
|
||||
- name: sarah.klemm
|
||||
groups:
|
||||
- gf
|
||||
@ -408,6 +475,11 @@ samba_user:
|
||||
- verwaltung
|
||||
password: '20.s4r4h_kl3mm-24!'
|
||||
|
||||
- name: selma.albrecht
|
||||
groups:
|
||||
- projekte
|
||||
password: '20-sel-ma.al-brecht/25!'
|
||||
|
||||
- name: scan
|
||||
groups:
|
||||
- team
|
||||
|
@ -174,6 +174,67 @@ resolved_fallback_nameserver:
|
||||
- 172.16.182.254
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users
|
||||
# ---
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$sHxqz7NyYdn38ZegSbewO.$PPHR0n.XeMcS3AQ9KybllBT.2hxpYlQ7AiVhxHgUOX8
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: localadmin
|
||||
user_id: 1051
|
||||
group_id: 1051
|
||||
group: localadmin
|
||||
home: /home/localadmin
|
||||
password: $y$j9T$1WH8G2UkuN1jjp4QLuoeC0$dXpOnJUfMMAqAXlwN8XD0pq78r.a4UZOgt3LY4afxy/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$WmitGB98lhPLJ39Iy4YfH.$irv0LP1bB5ImQKBUr1acEif6Ed6zDu6gLQuGQd/i5s0
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup'
|
||||
|
||||
|
||||
- name: borg
|
||||
user_id: 1065
|
||||
group_id: 1065
|
||||
group: borg
|
||||
home: /home/borg
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAMFUnBjVV0WjUlhd2FT49nXlpHUDPEwaJ7bAvRJfB56 root@file-ebs'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBK8Ngbtl8Yjtk1JkT0Xn1HVIAHKdtfh0qicnnJTa3Kx root@gw-ebs'
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
@ -261,6 +322,9 @@ samba_netbios_name: FILE-EBS
|
||||
|
||||
samba_groups:
|
||||
|
||||
- name: sysadm
|
||||
group_id: 1050
|
||||
|
||||
- name: admin
|
||||
group_id: 1100
|
||||
|
||||
@ -312,6 +376,12 @@ samba_user:
|
||||
- recherche
|
||||
password: 'IrcR3uo-QJ.5'
|
||||
|
||||
- name: winadm
|
||||
groups:
|
||||
- admin
|
||||
- sysadm
|
||||
password: 'ZbPS.Lh6d-9E'
|
||||
|
||||
- name: buero
|
||||
groups:
|
||||
- alle
|
||||
@ -452,6 +522,21 @@ samba_shares:
|
||||
vfs_object_recycle: false
|
||||
|
||||
|
||||
# ---
|
||||
# - This share will be written by Windows Server 2016 configured at
|
||||
# - "Windows Zubehör" -> "Windows Server-Sicherung"
|
||||
# ---
|
||||
- name: WinServer2022-Backup
|
||||
comment: WinServer2022-Backup on Fileserver
|
||||
path: /data/samba/shares/WinServer2022-Backup
|
||||
group_valid_users: sysadm
|
||||
group_write_list: sysadm
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
guest_ok: !!str yes
|
||||
vfs_object_recycle: false
|
||||
|
||||
|
||||
|
||||
# ==============================
|
||||
|
||||
|
527
host_vars/file-fm.fm.netz.yml
Normal file
527
host_vars/file-fm.fm.netz.yml
Normal file
@ -0,0 +1,527 @@
|
||||
---
|
||||
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eno1np0
|
||||
# use only once per device (for the first device entry)
|
||||
headline: eno1 - LAN
|
||||
|
||||
# auto & allow are only used for the first device entry
|
||||
allow: [] # array of allow-[stanzas] eg. allow-hotplug
|
||||
auto: true
|
||||
|
||||
family: inet
|
||||
method: static
|
||||
description:
|
||||
address: 192.168.222.10
|
||||
netmask: 24
|
||||
gateway: 192.168.222.254
|
||||
|
||||
# optional dns settings nameservers: []
|
||||
#
|
||||
# nameservers:
|
||||
# - 194.150.168.168 # dns.as250.net
|
||||
# - 91.239.100.100 # anycast.censurfridns.dk
|
||||
# search: warenform.de
|
||||
#
|
||||
#nameservers:
|
||||
# - 192.168.222.1
|
||||
#search: blkr.netz
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.222.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.132.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 192.168.222.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- fm.netz
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users
|
||||
# ---
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$UHsnOrOT5qXnAwrPCzB7A1$jnqz4CHvLEaIke3RxnresjAOS6NfcTxyDH/fbKnXTC/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: localadmin
|
||||
user_id: 1051
|
||||
group_id: 1051
|
||||
group: localadmin
|
||||
home: /home/localadmin
|
||||
password: $y$j9T$1WH8G2UkuN1jjp4QLuoeC0$dXpOnJUfMMAqAXlwN8XD0pq78r.a4UZOgt3LY4afxy/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$WmitGB98lhPLJ39Iy4YfH.$irv0LP1bB5ImQKBUr1acEif6Ed6zDu6gLQuGQd/i5s0
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup'
|
||||
|
||||
|
||||
- name: borg
|
||||
user_id: 1065
|
||||
group_id: 1065
|
||||
group: borg
|
||||
home: /home/borg
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHUvk8+UduCcBbQO1YxXSU8SaGIl8x+TBmIFmPb9JQu8 root@gw-fm'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN0ibOee8TvYlrEzKno5J6h3ZQs79i0wPElqYvQxAymK root@file-fm'
|
||||
|
||||
#extra_user:
|
||||
#
|
||||
# - name: borg
|
||||
# user_id: 1065
|
||||
# group_id: 1065
|
||||
# group: borg
|
||||
# home: /home/borg
|
||||
# password: $y$j9T$SZty9T8ZWbnyHR2S85xaG.$GhxHOKG9fKErT9s5TAehXXyZJSkNaIcXY18Rg1iMyhC
|
||||
# shell: /bin/bash
|
||||
# ssh_keys:
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHXrNhcgNtZykTgzcwX/L1cL8qpSyQQy75M01UpjdSmA root@file-dissens'
|
||||
# - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFEm1P7Pg3Tlm02bxkropKf3CcyTCAB3YCMxPSjai2lc root@gw-dissens'
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_entries:
|
||||
|
||||
- name: "Daily Backup "
|
||||
minute: "03"
|
||||
hour: "00"
|
||||
job: /root/crontab/backup-rborg2/rborg2.sh
|
||||
|
||||
- name: "Check if postfix mailservice is running. Restart service if needed."
|
||||
minute: "*/11"
|
||||
hour: "*"
|
||||
job: /root/bin/monitoring/check_postfix.sh
|
||||
|
||||
- name: "Check if ntpsec is running. Restart service if needed."
|
||||
minute: "*/7"
|
||||
hour: "*"
|
||||
job: /root/bin/monitoring/check_ntpsec_service.sh
|
||||
|
||||
- name: "Check if SSH service is running. Restart service if needed."
|
||||
minute: "*/13"
|
||||
hour: "*"
|
||||
job: /root/bin/monitoring/check_ssh.sh
|
||||
|
||||
- name: "Check if systemd-resolved service is running. Restart service if needed."
|
||||
minute: "*/17"
|
||||
hour: "*"
|
||||
job: /root/bin/monitoring/check_systemd_service.sh systemd-resolved
|
||||
|
||||
- name: "Check Postfix E-Mail LOG file for 'fatal' errors."
|
||||
minute: "*/30"
|
||||
hour: "*"
|
||||
job: /root/bin/postfix/check-postfix-fatal-errors.sh
|
||||
|
||||
- name: "Clean up Samba Trash Dirs"
|
||||
minute: "02"
|
||||
hour: "23"
|
||||
job: /root/bin/samba/clean_samba_trash.sh
|
||||
|
||||
- name: "Set (group and access) Permissons for Samba shares"
|
||||
minute: "14"
|
||||
hour: "23"
|
||||
job: /root/bin/samba/set_permissions_samba_shares.sh
|
||||
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart DNS Cache service 'systemd-resolved'"
|
||||
special_time: reboot
|
||||
job: "sleep 10 ; /bin/systemctl restart systemd-resolved"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
sudoers_file_user_aliases:
|
||||
- name: MAIN_USER
|
||||
entry: 'sysadm'
|
||||
|
||||
sudoers_file_cmnd_aliases:
|
||||
- name: REBOOT
|
||||
entry: '/sbin/reboot'
|
||||
- name: MANAGE_SERVICE
|
||||
entry: '/usr/bin/systemctl'
|
||||
|
||||
|
||||
sudoers_file_user_privileges:
|
||||
- name: MAIN_USER
|
||||
entry: ALL = REBOOT
|
||||
- name: MAIN_USER
|
||||
entry: ALL = MANAGE_SERVICE
|
||||
|
||||
# - name: julius
|
||||
# entry: 'ALL=(root) NOPASSWD: /sbin/reboot'
|
||||
# - name: josephine
|
||||
# entry: 'ALL=(root) NOPASSWD: /sbin/reboot'
|
||||
# - name: sebastian
|
||||
# entry: 'ALL=(root) NOPASSWD: /sbin/reboot'
|
||||
# - name: julius-e
|
||||
# entry: 'ALL=(root) NOPASSWD: /sbin/reboot'
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/ntp.yml
|
||||
# ---
|
||||
|
||||
local_ntp_service: true
|
||||
|
||||
ntp_server: gw-fm.fm.netz
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/nfs.yml
|
||||
# ---
|
||||
|
||||
nfs_server: 192.168.222.10
|
||||
|
||||
# Set 'fs_encrypted' to true if filesystem lives on an encrypted
|
||||
# partition.
|
||||
#
|
||||
# NOTE !!
|
||||
# Take car to increase 'fsid' in case of more than one export
|
||||
#
|
||||
nfs_exports:
|
||||
- src: 192.168.222.10:/data/samba/shares
|
||||
path: /data/samba/shares
|
||||
mount_opts: users,rsize=8192,wsize=8192,hard,intr
|
||||
export_opt: rw,root_squash,sync,subtree_check
|
||||
export_networks:
|
||||
- 192.168.222.0/24
|
||||
- 10.0.222.0/24
|
||||
- 10.1.222.0/24
|
||||
- 192.168.63.0/24
|
||||
use_fsid_option: true
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/samba-config-server.yml
|
||||
# vars used by roles/common/tasks/samba-user.yml
|
||||
# ---
|
||||
|
||||
samba_server_ip: 192.168.222.10
|
||||
samba_server_cidr_prefix: 24
|
||||
|
||||
samba_workgroup: FM
|
||||
|
||||
samba_netbios_name: FILE-FM
|
||||
|
||||
samba_server_min_protocol: !!str NT1
|
||||
|
||||
samba_groups:
|
||||
- name: buero
|
||||
group_id: 1100
|
||||
- name: projekte
|
||||
group_id: 1200
|
||||
- name: verwaltung
|
||||
group_id: 1300
|
||||
|
||||
samba_user:
|
||||
- name: sysadm
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: 'k6-C5.X-/YGm'
|
||||
|
||||
- name: chris
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: !vault |
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
63643330373231636537366333326630333265303265653933613835656262323863363038653234
|
||||
3462653135633266373439626263356636646637643035340a653466356235346663626163306363
|
||||
61313164643061306433643738643563303036646334376536626531383965303036386162393832
|
||||
6631333038306462610a356535633265633563633962333137326533633834636331343562633765
|
||||
3631
|
||||
|
||||
- name: agnieszka
|
||||
groups:
|
||||
- buero
|
||||
password: '20%4gni_eszk4-25-'
|
||||
|
||||
- name: anja
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: '20-4nj4.m4y3r_25?'
|
||||
|
||||
- name: anna
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
password: '20.4n.n4-25!'
|
||||
|
||||
- name: barbara
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: '20.b4rb4r4-25?'
|
||||
|
||||
- name: dominique
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: '20/do-m1-ni1que/25?'
|
||||
|
||||
- name: franziska
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: '20-fr4nzisk4.25%'
|
||||
|
||||
- name: karina
|
||||
groups:
|
||||
- buero
|
||||
password: '20_k4-ri-n4/25.'
|
||||
|
||||
- name: linda
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
password: '20-l1n-d4.25%'
|
||||
|
||||
- name: michael
|
||||
groups:
|
||||
- buero
|
||||
password: '20.m1cha-3l/25/'
|
||||
|
||||
- name: stephanie
|
||||
groups:
|
||||
- buero
|
||||
- projekte
|
||||
- verwaltung
|
||||
password: '20.st3pha-ni3_25%'
|
||||
|
||||
base_home: /data/home
|
||||
|
||||
# remove_samba_users:
|
||||
# - name: name1
|
||||
# - name: name2
|
||||
#
|
||||
remove_samba_users: []
|
||||
#remove_samba_users:
|
||||
# - name: elenor.faellgrem
|
||||
# - name: maiken.schiele
|
||||
|
||||
samba_shares:
|
||||
|
||||
- name: Buero
|
||||
comment: Buero auf Fileserver
|
||||
path: /data/samba/shares/Buero
|
||||
group_valid_users: buero
|
||||
group_write_list: buero
|
||||
file_create_mask: !!str 660
|
||||
dir_create_mask: !!str 2770
|
||||
vfs_object_recycle: true
|
||||
recycle_path: '@Recycle'
|
||||
|
||||
- name: Projekte
|
||||
comment: Projekte auf Fileserver
|
||||
path: /data/samba/shares/Projekte
|
||||
group_valid_users: projekte
|
||||
group_write_list: projekte
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
vfs_object_recycle: true
|
||||
recycle_path: '@Recycle'
|
||||
|
||||
- name: Verwaltung
|
||||
comment: Verwaltung auf Fileserver
|
||||
path: /data/samba/shares/Verwaltung
|
||||
group_valid_users: verwaltung
|
||||
group_write_list: verwaltung
|
||||
file_create_mask: !!str 660
|
||||
dir_create_mask: !!str 2770
|
||||
vfs_object_recycle: true
|
||||
recycle_path: '@Recycle'
|
||||
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
@ -279,7 +279,7 @@ samba_user:
|
||||
- advoware
|
||||
- alle
|
||||
- kanzlei
|
||||
password: ''
|
||||
password: 'YKQRa.M9-6rL'
|
||||
|
||||
- name: aphex2
|
||||
groups:
|
||||
|
@ -184,6 +184,9 @@ network_interfaces:
|
||||
# User Networks Stockhausen
|
||||
- /sbin/ip route add 192.168.11.0/24 via 172.16.111.254
|
||||
- /sbin/ip route add 192.168.78.0/24 via 172.16.111.254
|
||||
# User Networks Campus
|
||||
#- /sbin/ip route add 192.168.72.0/24 via 172.16.111.254
|
||||
#- /sbin/ip route add 192.168.73.0/24 via 172.16.111.254
|
||||
# User Network Novalishaus
|
||||
- /sbin/ip route add 192.168.81.0/24 via 172.16.111.254
|
||||
# Management Network Stockhausen
|
||||
@ -192,12 +195,20 @@ network_interfaces:
|
||||
- /sbin/ip route add 10.10.9.0/24 via 172.16.111.254
|
||||
# IPMI Stockhausen
|
||||
- /sbin/ip route add 10.11.11.0/24 via 172.16.111.254
|
||||
# WLAN Gast Novalishaus
|
||||
- /sbin/ip route add 10.21.0.0/20 via 172.16.111.254
|
||||
# WLAN privat Novalishaus
|
||||
- /sbin/ip route add 10.31.0.0/20 via 172.16.111.254
|
||||
# Management Netork Campus
|
||||
#- /sbin/ip route add 10.72.1.0/24 via 172.16.111.254
|
||||
# WLan Router Stockhausen
|
||||
- /sbin/ip route add 10.112.1.0/24 via 172.16.111.254
|
||||
# WLan Netz
|
||||
- /sbin/ip route add 10.113.0.0/16 via 172.16.111.254
|
||||
# Unifi WLan Netz Stockhausen
|
||||
# Unifi WLan Netz Stockhausen Gast
|
||||
- /sbin/ip route add 10.121.0.0/20 via 172.16.111.254
|
||||
# Unifi WLan Netz Stockhausen privat
|
||||
- /sbin/ip route add 10.131.0.0/20 via 172.16.111.254
|
||||
# Richtfunkantennen Stockhausen (2) / Schlechtenwegen / Kirschbaumhaus
|
||||
- /sbin/ip route add 10.10.111.0/24 via 172.16.111.254
|
||||
# VPN Netz Stockhausen - Novalishaus (Schlechtenwegen)
|
||||
|
@ -21,7 +21,7 @@ network_interface_required_packages:
|
||||
network_interfaces:
|
||||
|
||||
- device: eno1
|
||||
headline: eno1 - Uplink WiDSL via (static) line to Fritz!Box 7490
|
||||
headline: eno1 - Uplink DSL via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -33,46 +33,82 @@ network_interfaces:
|
||||
# - 172.16.81.254
|
||||
#search: ga.netz ga.intra
|
||||
|
||||
|
||||
- device: eno5
|
||||
headline: eno5 - LAN
|
||||
- device: eno2
|
||||
headline: eno2 - Uplink Lehrer-und Schülerdatenbank (LUSD)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.72.254
|
||||
address: 192.168.100.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# VLAN 321 - for Ubiquiti UniFi Accesspoints Guest NET
|
||||
- /sbin/ip link add link eno5 name eno5.22 type vlan id 21
|
||||
# VLAN 331 - for Ubiquiti UniFi Accesspoints private NET
|
||||
- /sbin/ip link add link eno5 name eno5.32 type vlan id 31
|
||||
# Traffic zur ehrer-und Schülerdatenbank (LUSD)
|
||||
- /sbin/ip route add 10.9.131.0/24 via 192.168.100.253
|
||||
|
||||
|
||||
- device: eno5.22
|
||||
headline: eno5 - VLAN 22 (Ubiquiti UniFi Accesspoints Guest NET)
|
||||
auto: true
|
||||
|
||||
- device: eno3
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.22.15.254
|
||||
netmask: 20
|
||||
method: manual
|
||||
post-up:
|
||||
# VLAN 10 LAN 1 Campus
|
||||
- /sbin/ip link add link eno3 name eno3.10 type vlan id 10
|
||||
|
||||
- device: eno5.32
|
||||
headline: eno5 - VLAN 32 (Ubiquiti UniFi Accesspoints private NET)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.32.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: eno5:ns
|
||||
headline: eno5:ns - Alias on eno5 (Nameserver)
|
||||
- device: eno3:ns
|
||||
headline: eno3:ns - Alias on eno3 (Nameserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.72.1
|
||||
netmask: 32
|
||||
|
||||
- device: eno3.10
|
||||
headline: eno3.10 - LAN 1 Campus - network 192.168.72.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.72.254
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eno3 up
|
||||
|
||||
|
||||
- device: eno4
|
||||
family: inet
|
||||
method: manual
|
||||
post-up:
|
||||
# VLAN 20 - LAN 2 Campus including UniFi Accesspoints
|
||||
- /sbin/ip link add link eno4 name eno4.20 type vlan id 20
|
||||
|
||||
- device: eno4.20
|
||||
headline: eno4.20 - LAN 2 Campus - network 192.168.73.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.73.254
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eno4 up
|
||||
|
||||
|
||||
- device: eno6
|
||||
headline: eno6 - Management Network Campus - network 10.72.1.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.72.1.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: eno7
|
||||
headline: eno7 - network 192.168.11.0/24 (LAN Stockhausen)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.72/24
|
||||
gateway: 192.168.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
@ -93,57 +129,6 @@ network_interfaces:
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_entries:
|
||||
|
||||
- name: "Check if Postfix Mailservice is up and running?"
|
||||
minute: "*/15"
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_postfix.sh
|
||||
|
||||
- name: "Check if SSH service is up and running?"
|
||||
minute: "*/15"
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_ssh.sh
|
||||
|
||||
- name: "Check if OpenVPN service is up and running?"
|
||||
minute: "*/30"
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_vpn.sh
|
||||
|
||||
- name: "Check if nameservice (bind) is running?"
|
||||
minute: '*/10'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_dns.sh
|
||||
|
||||
- name: "Check forwarding ( /proc/sys/net/ipv4/ip_forward contains \"1\" )"
|
||||
minute: "0-59/2"
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_forwarding.sh
|
||||
|
||||
- name: "Copy gateway configuration"
|
||||
minute: "09"
|
||||
hour: "3"
|
||||
job: /root/bin/manage-gw-config/copy_gateway-config.sh GA-NH
|
||||
|
||||
|
||||
#cron_user_special_time_entries: []
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Check if Postfix Service is running at boot time"
|
||||
special_time: reboot
|
||||
job: "sleep 7 ; /root/bin/monitoring/check_postfix.sh"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Restart Systemd's resolved at boottime."
|
||||
special_time: reboot
|
||||
job: "sleep 10 ; /bin/systemctl restart systemd-resolved"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 15 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
@ -215,8 +200,8 @@ resolved_nameserver:
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- ga.netz
|
||||
- ga.intra
|
||||
- campus.netz
|
||||
- campus.intra
|
||||
|
||||
resolved_dnssec: false
|
||||
|
591
host_vars/ga-st-gw-neu.ga.netz.yml.00
Normal file
591
host_vars/ga-st-gw-neu.ga.netz.yml.00
Normal file
@ -0,0 +1,591 @@
|
||||
---
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eno1np0
|
||||
headline: eno1np0 - Temporary LAN network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.18
|
||||
netmask: 24
|
||||
|
||||
- device: enp129s0f2
|
||||
headline: enp129s0f2 - Uplink static line (radio) to Altenschlirf
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.111.254
|
||||
netmask: 24
|
||||
up:
|
||||
# - For management Antennas
|
||||
- /sbin/ip link add link enp129s0f2 name enp129s0f2.111 type vlan id 111
|
||||
post-up:
|
||||
# - Static routes to Altenschlirf (Router Ip-Address Altenschlirf: 172.16.111.253)
|
||||
# -
|
||||
# - Telefon Altenshlirf
|
||||
- /sbin/ip route add 172.16.210.0/24 via 172.16.111.253
|
||||
# User Network Altenshlirf
|
||||
- /sbin/ip route add 192.168.10.0/24 via 172.16.111.253
|
||||
# Management Network Altenschlirf
|
||||
- /sbin/ip route add 10.10.10.0/24 via 172.16.111.253
|
||||
# WLan Router (Accesspoints) Altenshlirf
|
||||
- /sbin/ip route add 10.122.1.0/24 via 172.16.111.253
|
||||
# # WLan Networks Altenshlirf
|
||||
- /sbin/ip route add 10.123.0.0/16 via 172.16.111.253
|
||||
# DSL via Fritzbox Altenschlirf
|
||||
- /sbin/ip route add 172.16.10.0/24 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf guest NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.221.0.0/20 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf private NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.231.0.0/20 via 172.16.111.253
|
||||
# VPN home Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.0.10.0/24 via 172.16.111.253
|
||||
# VPN 'gw-ckubu' Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.1.10.0/24 via 172.16.111.253
|
||||
# private networks 'ckubu'
|
||||
#
|
||||
# connections from private ckubu networks ist routed through VPN Altenschlirf (gw-ckubu),
|
||||
# so we route them back to that gateway..
|
||||
- /sbin/ip route add 192.168.63.0/24 via 172.16.111.253
|
||||
- /sbin/ip route add 192.168.64.0/24 via 172.16.111.253
|
||||
|
||||
|
||||
- device: enp129s0f2.111
|
||||
headline: enp129s0f2.111 - network 10.10.111.0 (management antennas)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.111.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: enp1s0f0
|
||||
headline: enp1s0f0 - holds VLAN 211 device for Network Telefons Stockhausen
|
||||
auto: false
|
||||
family: inet
|
||||
method: manual
|
||||
up:
|
||||
- /sbin/ip link add link enp1s0f0 name enp1s0f0.211 type vlan id 211
|
||||
|
||||
|
||||
- device: enp1s0f0.211
|
||||
headline: enp1s0f0.211 - Network Telefons Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
# Note:
|
||||
# !! 172.16.211.254 is reserved for LANCom Router (DSL line teleefon).
|
||||
# This LANCom Router IS NOT pngable !!
|
||||
address: 172.16.211.1
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig enp1s0f0 up
|
||||
|
||||
|
||||
- device: enp1s0f2
|
||||
headline: enp1s0f2 - Uplink DSL surf2 via (static) line to Fritz!Box 7490 (formaly Zyxel 6501)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.11.1
|
||||
netmask: 24
|
||||
gateway: 172.16.11.254
|
||||
|
||||
|
||||
- device: enp1s0f3
|
||||
headline: enp1s0f3 - Uplink DSL surf3 via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.13.1
|
||||
netmask: 24
|
||||
gateway: 172.16.13.254
|
||||
|
||||
|
||||
- device: enp1s0f1
|
||||
headline: enp1s0f1 - Uplink DSL surf1 via (static) line to Fritz!Box 7490 (Mailserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.12.1
|
||||
netmask: 24
|
||||
gateway: 172.16.12.254
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond0
|
||||
headline: bond0 - LAG (Link Aggregation) on devices enp129s0f0 and enp194s0f0
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.1.9.254
|
||||
netmask: 24
|
||||
bond:
|
||||
slaves: enp129s0f0 enp194s0f0
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 11 for management network Stockhausen/Schloss 10.10.11.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.11 type vlan id 11
|
||||
# VLAN 78 for network Georgshaus 192.168.78.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.78 type vlan id 78
|
||||
|
||||
|
||||
- device: bond0.11
|
||||
headline: bond0.11 - VLAN 11 on interface bond0 (Management Network Stockhausen)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond0.78
|
||||
headline: bond0.78 - VLAN 78 on interface bond0 (Georgshaus ?)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.78.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond1
|
||||
headline: bond1 - LAG (Link Aggregation) on devices enp129s0f1 and enp194s0f1 - Main Network Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.254
|
||||
netmask: 24
|
||||
nameservers:
|
||||
- 192.168.11.1
|
||||
- 192.168.10.3
|
||||
search: ga.netz ga.intra
|
||||
bond:
|
||||
slaves: enp129s0f1 enp194s0f1
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints
|
||||
- /sbin/ip link add link bond1 name bond1.121 type vlan id 121
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints Guests
|
||||
- /sbin/ip link add link bond1 name bond1.131 type vlan id 131
|
||||
# Route ???
|
||||
- /sbin/ip route add 10.11.16.0/24 via 192.168.11.6
|
||||
# Route to management network campus
|
||||
- /sbin/ip route add 10.72.1.0/24 via 192.168.11.72
|
||||
# Route to LAN campus
|
||||
- /sbin/ip route add 192.168.72.0/24 via 192.168.11.72
|
||||
# Route to WLAN campus
|
||||
- /sbin/ip route add 192.168.73.0/24 via 192.168.11.72
|
||||
|
||||
|
||||
- device: bond1.121
|
||||
headline: bond1.121 - VLAN 121 on interface bond1 for Ubiquiti UniFi Accesspoints Guest NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.121.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1.131
|
||||
headline: bond1.131 - VLAN 131 on interface bond1 for Ubiquiti UniFi Accesspoints private NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.131.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1:ns
|
||||
headline: bond1:ns - Alias IP on bond1 device for Nameservice
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.1
|
||||
netmask: 32
|
||||
|
||||
|
||||
- device: bond1:1
|
||||
headline: bond1:1 - Alias IP on bond1 device for (depricated) Management Network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.9.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond1:ap
|
||||
headline: bond1:ap - Alias IP on bond1 device for Network Accesspoints
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.112.1.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# - Wireless Networks routed through appropriate Accesspoints
|
||||
# -
|
||||
- /sbin/ip route add 10.113.1.0/24 via 10.112.1.1
|
||||
- /sbin/ip route add 10.113.2.0/24 via 10.112.1.2
|
||||
- /sbin/ip route add 10.113.3.0/24 via 10.112.1.3
|
||||
- /sbin/ip route add 10.113.4.0/24 via 10.112.1.4
|
||||
- /sbin/ip route add 10.113.5.0/24 via 10.112.1.5
|
||||
- /sbin/ip route add 10.113.6.0/24 via 10.112.1.6
|
||||
- /sbin/ip route add 10.113.7.0/24 via 10.112.1.7
|
||||
- /sbin/ip route add 10.113.8.0/24 via 10.112.1.8
|
||||
- /sbin/ip route add 10.113.9.0/24 via 10.112.1.9
|
||||
- /sbin/ip route add 10.113.10.0/24 via 10.112.1.10
|
||||
- /sbin/ip route add 10.113.11.0/24 via 10.112.1.11
|
||||
- /sbin/ip route add 10.113.12.0/24 via 10.112.1.12
|
||||
- /sbin/ip route add 10.113.13.0/24 via 10.112.1.13
|
||||
- /sbin/ip route add 10.113.14.0/24 via 10.112.1.14
|
||||
- /sbin/ip route add 10.113.15.0/24 via 10.112.1.15
|
||||
|
||||
|
||||
- device: bond1:ipmi
|
||||
headline: bond1:ipmi - Alias IP on bond1 for IPMI Addresses Servr Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.11.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 127.0.0.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- ga.netz
|
||||
- ga.intra
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 192.168.10.1
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 15 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
insert_ssh_keypair_backup_server: false
|
||||
ssh_keypair_backup_server:
|
||||
- name: backup
|
||||
backup_user: back
|
||||
priv_key_src: root/.ssh/id_rsa.backup.oopen.de
|
||||
priv_key_dest: /root/.ssh/id_rsa
|
||||
pub_key_src: root/.ssh/id_rsa.backup.oopen.de.pub
|
||||
pub_key_dest: /root/.ssh/id_rsa.pub
|
||||
|
||||
insert_keypair_backup_client: true
|
||||
ssh_keypair_backup_client:
|
||||
- name: backup
|
||||
priv_key_src: root/.ssh/id_ed25519.oopen-server
|
||||
priv_key_dest: /root/.ssh/id_ed25519
|
||||
pub_key_src: root/.ssh/id_ed25519.oopen-server.pub
|
||||
pub_key_dest: /root/.ssh/id_ed25519.pub
|
||||
target: backup.oopen.de
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$rDrvWa/KInzTe601YYf9./$WjDlaItCrgX7gu4nCs481y8WLxiRaNJCC/MgFgKuzg3
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: maadmin
|
||||
password: $y$j9T$LCkYWvykWzrpFxIlmSUB01$e1ROfZxXAU53UdAwZAECzED4iV4LS02Q4IPQ2fycv51
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
|
||||
- name: wadmin
|
||||
password: $6$sLWIXKTW$i/STlSS0LijkrnGR/XMbaxJsEbrRdDYgqyCqIr.muLN5towes8yHDCXsyCYDjuaBNKPHXyFpr8lclg5DOm9OF1
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$awYUu9oRvV39ojITZOC7D1$czTh5HHIE32PXb0vl40ayAarm39txR4jaH1QzBscqfC
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$wpg8hlvMpO4PAWSVdLoJq/$dgpQh4cEnbUOQkkZzKUM4S8XzNS/Md5gMmMuNTqec74
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
|
||||
sudo_users:
|
||||
- chris
|
||||
- sysadm
|
||||
- maadmin
|
||||
- wadmin
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
install_bind_packages: true
|
||||
|
||||
bind9_gateway_acl:
|
||||
- local-net:
|
||||
name: local-net
|
||||
entries:
|
||||
- 127.0.0.0/8
|
||||
- 172.16.0.0/12
|
||||
- 192.168.0.0/16
|
||||
- 10.0.0.0/8
|
||||
- fc00::/7
|
||||
- fe80::/10
|
||||
- ::1/128
|
||||
- internaldns:
|
||||
name: internaldns
|
||||
entries:
|
||||
- '# Nameserver Gateway Stockhausen'
|
||||
- 192.168.11.1
|
||||
- '# Domain Controller Stockhausen'
|
||||
- 192.168.10.3
|
||||
- '# Nameserver Gateway Altenschlirf'
|
||||
- 192.168.10.1
|
||||
- '# Domain Controller Altenschlirf'
|
||||
- 192.168.10.3
|
||||
- 192.168.10.6
|
||||
- 172.16.0.1
|
||||
- '# Nameserver Gateway Novalishaus'
|
||||
- 192.168.81.1
|
||||
- 10.2.11.2
|
||||
- '# Nameserver wolle'
|
||||
- 10.113.12.3
|
||||
- '# Postfix Mailserver'
|
||||
- 192.168.11.2
|
||||
- '# Mail Relay System'
|
||||
- 192.168.10.2
|
||||
|
||||
bind9_gateway_listen_on_v6:
|
||||
- none
|
||||
|
||||
bind9_gateway_listen_on:
|
||||
- any
|
||||
|
||||
#bind9_gateway_allow_transfer: {}
|
||||
bind9_gateway_allow_transfer:
|
||||
- internaldns
|
||||
|
||||
bind9_transfer_source: !!str "192.168.11.1"
|
||||
bind9_notify_source: !!str "192.168.11.1"
|
||||
|
||||
#bind9_gateway_allow_query: {}
|
||||
bind9_gateway_allow_query:
|
||||
- local-net
|
||||
|
||||
#bind9_gateway_allow_query_cache: {}
|
||||
bind9_gateway_allow_query_cache:
|
||||
- local-net
|
||||
|
||||
bind9_gateway_recursion: !!str "yes"
|
||||
#bind9_gateway_allow_recursion: {}
|
||||
bind9_gateway_allow_recursion:
|
||||
- local-net
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
git_firewall_repository:
|
||||
name: ipt-gateway
|
||||
repo: https://git.oopen.de/firewall/ipt-gateway
|
||||
dest: /usr/local/src/ipt-gateway
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
||||
|
592
host_vars/ga-st-gw-neu.ga.netz.yml.01
Normal file
592
host_vars/ga-st-gw-neu.ga.netz.yml.01
Normal file
@ -0,0 +1,592 @@
|
||||
---
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: lan0
|
||||
headline: lan0 - Temporary LAN network
|
||||
auto: false
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.18
|
||||
gateway: 192.168.11.254
|
||||
netmask: 24
|
||||
|
||||
- device: lan4
|
||||
headline: lan4 - Uplink static line (radio) to Altenschlirf
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.111.254
|
||||
netmask: 24
|
||||
up:
|
||||
# - For management Antennas
|
||||
- /sbin/ip link add link lan4 name lan4.111 type vlan id 111
|
||||
post-up:
|
||||
# - Static routes to Altenschlirf (Router Ip-Address Altenschlirf: 172.16.111.253)
|
||||
# -
|
||||
# - Telefon Altenshlirf
|
||||
- /sbin/ip route add 172.16.210.0/24 via 172.16.111.253
|
||||
# User Network Altenshlirf
|
||||
- /sbin/ip route add 192.168.10.0/24 via 172.16.111.253
|
||||
# Management Network Altenschlirf
|
||||
- /sbin/ip route add 10.10.10.0/24 via 172.16.111.253
|
||||
# WLan Router (Accesspoints) Altenshlirf
|
||||
- /sbin/ip route add 10.122.1.0/24 via 172.16.111.253
|
||||
# # WLan Networks Altenshlirf
|
||||
- /sbin/ip route add 10.123.0.0/16 via 172.16.111.253
|
||||
# DSL via Fritzbox Altenschlirf
|
||||
- /sbin/ip route add 172.16.10.0/24 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf guest NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.221.0.0/20 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf private NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.231.0.0/20 via 172.16.111.253
|
||||
# VPN home Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.0.10.0/24 via 172.16.111.253
|
||||
# VPN 'gw-ckubu' Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.1.10.0/24 via 172.16.111.253
|
||||
# private networks 'ckubu'
|
||||
#
|
||||
# connections from private ckubu networks ist routed through VPN Altenschlirf (gw-ckubu),
|
||||
# so we route them back to that gateway..
|
||||
- /sbin/ip route add 192.168.63.0/24 via 172.16.111.253
|
||||
- /sbin/ip route add 192.168.64.0/24 via 172.16.111.253
|
||||
|
||||
|
||||
- device: lan4.111
|
||||
headline: lan4.111 - network 10.10.111.0 (management antennas)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.111.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: lan6
|
||||
headline: lan6 - holds VLAN 211 device for Network Telefons Stockhausen
|
||||
auto: false
|
||||
family: inet
|
||||
method: manual
|
||||
up:
|
||||
- /sbin/ip link add link lan6 name lan6.211 type vlan id 211
|
||||
|
||||
|
||||
- device: lan6.211
|
||||
headline: lan6.211 - Network Telefons Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
# Note:
|
||||
# !! 172.16.211.254 is reserved for LANCom Router (DSL line teleefon).
|
||||
# This LANCom Router IS NOT pngable !!
|
||||
address: 172.16.211.1
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig lan6 up
|
||||
|
||||
|
||||
- device: lan8
|
||||
headline: lan8 - Uplink DSL surf2 via (static) line to Fritz!Box 7490 (formaly Zyxel 6501)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.11.1
|
||||
netmask: 24
|
||||
gateway: 172.16.11.254
|
||||
|
||||
|
||||
- device: lan9
|
||||
headline: lan9 - Uplink DSL surf3 via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.13.1
|
||||
netmask: 24
|
||||
gateway: 172.16.13.254
|
||||
|
||||
|
||||
- device: lan7
|
||||
headline: lan7 - Uplink DSL surf1 via (static) line to Fritz!Box 7490 (Mailserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.12.1
|
||||
netmask: 24
|
||||
gateway: 172.16.12.254
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond0
|
||||
headline: bond0 - LAG (Link Aggregation) on devices lan2 and lan10
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.1.9.254
|
||||
netmask: 24
|
||||
bond:
|
||||
slaves: lan2 lan10
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 11 for management network Stockhausen/Schloss 10.10.11.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.11 type vlan id 11
|
||||
# VLAN 78 for network Georgshaus 192.168.78.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.78 type vlan id 78
|
||||
|
||||
|
||||
- device: bond0.11
|
||||
headline: bond0.11 - VLAN 11 on interface bond0 (Management Network Stockhausen)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond0.78
|
||||
headline: bond0.78 - VLAN 78 on interface bond0 (Georgshaus ?)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.78.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond1
|
||||
headline: bond1 - LAG (Link Aggregation) on devices lan3 and lan11 - Main Network Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.254
|
||||
netmask: 24
|
||||
nameservers:
|
||||
- 192.168.11.1
|
||||
- 192.168.10.3
|
||||
search: ga.netz ga.intra
|
||||
bond:
|
||||
slaves: lan3 lan11
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints
|
||||
- /sbin/ip link add link bond1 name bond1.121 type vlan id 121
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints Guests
|
||||
- /sbin/ip link add link bond1 name bond1.131 type vlan id 131
|
||||
# Route ???
|
||||
- /sbin/ip route add 10.11.16.0/24 via 192.168.11.6
|
||||
# Route to management network campus
|
||||
- /sbin/ip route add 10.72.1.0/24 via 192.168.11.72
|
||||
# Route to LAN campus
|
||||
- /sbin/ip route add 192.168.72.0/24 via 192.168.11.72
|
||||
# Route to WLAN campus
|
||||
- /sbin/ip route add 192.168.73.0/24 via 192.168.11.72
|
||||
|
||||
|
||||
- device: bond1.121
|
||||
headline: bond1.121 - VLAN 121 on interface bond1 for Ubiquiti UniFi Accesspoints Guest NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.121.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1.131
|
||||
headline: bond1.131 - VLAN 131 on interface bond1 for Ubiquiti UniFi Accesspoints private NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.131.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1:ns
|
||||
headline: bond1:ns - Alias IP on bond1 device for Nameservice
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.1
|
||||
netmask: 32
|
||||
|
||||
|
||||
- device: bond1:1
|
||||
headline: bond1:1 - Alias IP on bond1 device for (depricated) Management Network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.9.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond1:ap
|
||||
headline: bond1:ap - Alias IP on bond1 device for Network Accesspoints
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.112.1.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# - Wireless Networks routed through appropriate Accesspoints
|
||||
# -
|
||||
- /sbin/ip route add 10.113.1.0/24 via 10.112.1.1
|
||||
- /sbin/ip route add 10.113.2.0/24 via 10.112.1.2
|
||||
- /sbin/ip route add 10.113.3.0/24 via 10.112.1.3
|
||||
- /sbin/ip route add 10.113.4.0/24 via 10.112.1.4
|
||||
- /sbin/ip route add 10.113.5.0/24 via 10.112.1.5
|
||||
- /sbin/ip route add 10.113.6.0/24 via 10.112.1.6
|
||||
- /sbin/ip route add 10.113.7.0/24 via 10.112.1.7
|
||||
- /sbin/ip route add 10.113.8.0/24 via 10.112.1.8
|
||||
- /sbin/ip route add 10.113.9.0/24 via 10.112.1.9
|
||||
- /sbin/ip route add 10.113.10.0/24 via 10.112.1.10
|
||||
- /sbin/ip route add 10.113.11.0/24 via 10.112.1.11
|
||||
- /sbin/ip route add 10.113.12.0/24 via 10.112.1.12
|
||||
- /sbin/ip route add 10.113.13.0/24 via 10.112.1.13
|
||||
- /sbin/ip route add 10.113.14.0/24 via 10.112.1.14
|
||||
- /sbin/ip route add 10.113.15.0/24 via 10.112.1.15
|
||||
|
||||
|
||||
- device: bond1:ipmi
|
||||
headline: bond1:ipmi - Alias IP on bond1 for IPMI Addresses Servr Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.11.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 127.0.0.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- ga.netz
|
||||
- ga.intra
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 192.168.10.1
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 15 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
insert_ssh_keypair_backup_server: false
|
||||
ssh_keypair_backup_server:
|
||||
- name: backup
|
||||
backup_user: back
|
||||
priv_key_src: root/.ssh/id_rsa.backup.oopen.de
|
||||
priv_key_dest: /root/.ssh/id_rsa
|
||||
pub_key_src: root/.ssh/id_rsa.backup.oopen.de.pub
|
||||
pub_key_dest: /root/.ssh/id_rsa.pub
|
||||
|
||||
insert_keypair_backup_client: true
|
||||
ssh_keypair_backup_client:
|
||||
- name: backup
|
||||
priv_key_src: root/.ssh/id_ed25519.oopen-server
|
||||
priv_key_dest: /root/.ssh/id_ed25519
|
||||
pub_key_src: root/.ssh/id_ed25519.oopen-server.pub
|
||||
pub_key_dest: /root/.ssh/id_ed25519.pub
|
||||
target: backup.oopen.de
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$rDrvWa/KInzTe601YYf9./$WjDlaItCrgX7gu4nCs481y8WLxiRaNJCC/MgFgKuzg3
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: maadmin
|
||||
password: $y$j9T$LCkYWvykWzrpFxIlmSUB01$e1ROfZxXAU53UdAwZAECzED4iV4LS02Q4IPQ2fycv51
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
|
||||
- name: wadmin
|
||||
password: $6$sLWIXKTW$i/STlSS0LijkrnGR/XMbaxJsEbrRdDYgqyCqIr.muLN5towes8yHDCXsyCYDjuaBNKPHXyFpr8lclg5DOm9OF1
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$awYUu9oRvV39ojITZOC7D1$czTh5HHIE32PXb0vl40ayAarm39txR4jaH1QzBscqfC
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$wpg8hlvMpO4PAWSVdLoJq/$dgpQh4cEnbUOQkkZzKUM4S8XzNS/Md5gMmMuNTqec74
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
|
||||
sudo_users:
|
||||
- chris
|
||||
- sysadm
|
||||
- maadmin
|
||||
- wadmin
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
install_bind_packages: true
|
||||
|
||||
bind9_gateway_acl:
|
||||
- local-net:
|
||||
name: local-net
|
||||
entries:
|
||||
- 127.0.0.0/8
|
||||
- 172.16.0.0/12
|
||||
- 192.168.0.0/16
|
||||
- 10.0.0.0/8
|
||||
- fc00::/7
|
||||
- fe80::/10
|
||||
- ::1/128
|
||||
- internaldns:
|
||||
name: internaldns
|
||||
entries:
|
||||
- '# Nameserver Gateway Stockhausen'
|
||||
- 192.168.11.1
|
||||
- '# Domain Controller Stockhausen'
|
||||
- 192.168.10.3
|
||||
- '# Nameserver Gateway Altenschlirf'
|
||||
- 192.168.10.1
|
||||
- '# Domain Controller Altenschlirf'
|
||||
- 192.168.10.3
|
||||
- 192.168.10.6
|
||||
- 172.16.0.1
|
||||
- '# Nameserver Gateway Novalishaus'
|
||||
- 192.168.81.1
|
||||
- 10.2.11.2
|
||||
- '# Nameserver wolle'
|
||||
- 10.113.12.3
|
||||
- '# Postfix Mailserver'
|
||||
- 192.168.11.2
|
||||
- '# Mail Relay System'
|
||||
- 192.168.10.2
|
||||
|
||||
bind9_gateway_listen_on_v6:
|
||||
- none
|
||||
|
||||
bind9_gateway_listen_on:
|
||||
- any
|
||||
|
||||
#bind9_gateway_allow_transfer: {}
|
||||
bind9_gateway_allow_transfer:
|
||||
- internaldns
|
||||
|
||||
bind9_transfer_source: !!str "192.168.11.1"
|
||||
bind9_notify_source: !!str "192.168.11.1"
|
||||
|
||||
#bind9_gateway_allow_query: {}
|
||||
bind9_gateway_allow_query:
|
||||
- local-net
|
||||
|
||||
#bind9_gateway_allow_query_cache: {}
|
||||
bind9_gateway_allow_query_cache:
|
||||
- local-net
|
||||
|
||||
bind9_gateway_recursion: !!str "yes"
|
||||
#bind9_gateway_allow_recursion: {}
|
||||
bind9_gateway_allow_recursion:
|
||||
- local-net
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
git_firewall_repository:
|
||||
name: ipt-gateway
|
||||
repo: https://git.oopen.de/firewall/ipt-gateway
|
||||
dest: /usr/local/src/ipt-gateway
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
||||
|
@ -20,8 +20,17 @@ network_interface_required_packages:
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eth2
|
||||
headline: eth2 - Uplink static line (radio) to Altenschlirf
|
||||
- device: lan0
|
||||
headline: lan0 - Temporary LAN network
|
||||
auto: false
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.18
|
||||
#gateway: 192.168.11.254
|
||||
netmask: 24
|
||||
|
||||
- device: lan4
|
||||
headline: lan4 - Uplink static line (radio) to Altenschlirf
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -29,7 +38,7 @@ network_interfaces:
|
||||
netmask: 24
|
||||
up:
|
||||
# - For management Antennas
|
||||
- /sbin/ip link add link eth2 name eth2.111 type vlan id 111
|
||||
- /sbin/ip link add link lan4 name lan4.111 type vlan id 111
|
||||
post-up:
|
||||
# - Static routes to Altenschlirf (Router Ip-Address Altenschlirf: 172.16.111.253)
|
||||
# -
|
||||
@ -63,8 +72,8 @@ network_interfaces:
|
||||
- /sbin/ip route add 192.168.64.0/24 via 172.16.111.253
|
||||
|
||||
|
||||
- device: eth2.111
|
||||
headline: eth2.111 - network 10.10.111.0 (management antennas)
|
||||
- device: lan4.111
|
||||
headline: lan4.111 - network 10.10.111.0 (management antennas)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -72,17 +81,17 @@ network_interfaces:
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: eth8
|
||||
headline: eth8 - holds VLAN 211 device for Network Telefons Stockhausen
|
||||
- device: lan6
|
||||
headline: lan6 - holds VLAN 211 device for Network Telefons Stockhausen
|
||||
auto: false
|
||||
family: inet
|
||||
method: manual
|
||||
up:
|
||||
- /sbin/ip link add link eth8 name eth8.211 type vlan id 211
|
||||
- /sbin/ip link add link lan6 name lan6.211 type vlan id 211
|
||||
|
||||
|
||||
- device: eth8.211
|
||||
headline: eth8.211 - Network Telefons Stockhausen
|
||||
- device: lan6.211
|
||||
headline: lan6.211 - Network Telefons Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -92,11 +101,11 @@ network_interfaces:
|
||||
address: 172.16.211.1
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eth8 up
|
||||
- /sbin/ifconfig lan6 up
|
||||
|
||||
|
||||
- device: eth9
|
||||
headline: eth9 - Uplink DSL surf2 via (static) line to Fritz!Box 7490 (formaly Zyxel 6501)
|
||||
- device: lan8
|
||||
headline: lan8 - Uplink DSL surf2 via (static) line to Fritz!Box 7490 (formaly Zyxel 6501)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -105,8 +114,8 @@ network_interfaces:
|
||||
gateway: 172.16.11.254
|
||||
|
||||
|
||||
- device: eth10
|
||||
headline: eth10 - Uplink DSL surf3 via (static) line to Fritz!Box 7490
|
||||
- device: lan9
|
||||
headline: lan9 - Uplink DSL surf3 via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -115,8 +124,8 @@ network_interfaces:
|
||||
gateway: 172.16.13.254
|
||||
|
||||
|
||||
- device: eth11
|
||||
headline: eth11 - Uplink DSL surf1 via (static) line to Fritz!Box 7490 (Mailserver)
|
||||
- device: lan7
|
||||
headline: lan7 - Uplink DSL surf1 via (static) line to Fritz!Box 7490 (Mailserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -131,14 +140,14 @@ network_interfaces:
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond0
|
||||
headline: bond0 - LAG (Link Aggregation) on devices eth0 and eth4
|
||||
headline: bond0 - LAG (Link Aggregation) on devices lan2 and lan10
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.1.9.254
|
||||
netmask: 24
|
||||
bond:
|
||||
slaves: eth0 eth4
|
||||
slaves: lan2 lan10
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
@ -180,8 +189,8 @@ network_interfaces:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond1
|
||||
headline: bond1 - LAG (Link Aggregation) on devices eth1 and eth5 - Main Network Stockhausen
|
||||
- device: sfp0
|
||||
headline: sfp0 - Main Network Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -191,30 +200,36 @@ network_interfaces:
|
||||
- 192.168.11.1
|
||||
- 192.168.10.3
|
||||
search: ga.netz ga.intra
|
||||
bond:
|
||||
slaves: eth1 eth5
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
#bond:
|
||||
# slaves: lan3 lan11
|
||||
# # Mode 4 (802.3ad)
|
||||
# #
|
||||
# # also possible here:
|
||||
# # - Mode 5: balance-tlb
|
||||
# # - Mode 6: balance-alb
|
||||
# mode: 4
|
||||
# miimon: 100
|
||||
# lacp-rate: 1
|
||||
# ad-select: count
|
||||
# downdelay: 200
|
||||
# updelay: 200
|
||||
post-up:
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints
|
||||
- /sbin/ip link add link bond1 name bond1.121 type vlan id 121
|
||||
- /sbin/ip link add link sfp0 name sfp0.121 type vlan id 121
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints Guests
|
||||
- /sbin/ip link add link bond1 name bond1.131 type vlan id 131
|
||||
- /sbin/ip link add link sfp0 name sfp0.131 type vlan id 131
|
||||
# Route ???
|
||||
- /sbin/ip route add 10.11.16.0/24 via 192.168.11.6
|
||||
# Route to management network campus
|
||||
- /sbin/ip route add 10.72.1.0/24 via 192.168.11.72
|
||||
# Route to LAN campus
|
||||
- /sbin/ip route add 192.168.72.0/24 via 192.168.11.72
|
||||
# Route to WLAN campus
|
||||
- /sbin/ip route add 192.168.73.0/24 via 192.168.11.72
|
||||
|
||||
|
||||
- device: bond1.121
|
||||
headline: bond1.121 - VLAN 121 on interface bond1 for Ubiquiti UniFi Accesspoints Guest NET
|
||||
- device: sfp0.121
|
||||
headline: sfp0.121 - VLAN 121 on interface sfp0 for Ubiquiti UniFi Accesspoints Guest NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -222,8 +237,8 @@ network_interfaces:
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1.131
|
||||
headline: bond1.131 - VLAN 131 on interface bond1 for Ubiquiti UniFi Accesspoints private NET
|
||||
- device: sfp0.131
|
||||
headline: sfp0.131 - VLAN 131 on interface sfp0 for Ubiquiti UniFi Accesspoints private NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -231,8 +246,8 @@ network_interfaces:
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1:ns
|
||||
headline: bond1:ns - Alias IP on bond1 device for Nameservice
|
||||
- device: sfp0:ns
|
||||
headline: sfp0:ns - Alias IP on sfp0 device for Nameservice
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -240,8 +255,8 @@ network_interfaces:
|
||||
netmask: 32
|
||||
|
||||
|
||||
- device: bond1:1
|
||||
headline: bond1:1 - Alias IP on bond1 device for (depricated) Management Network
|
||||
- device: sfp0:1
|
||||
headline: sfp0:1 - Alias IP on sfp0 device for (depricated) Management Network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -249,8 +264,8 @@ network_interfaces:
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond1:ap
|
||||
headline: bond1:ap - Alias IP on bond1 device for Network Accesspoints
|
||||
- device: sfp0:ap
|
||||
headline: sfp0:ap - Alias IP on sfp0 device for Network Accesspoints
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
@ -276,8 +291,8 @@ network_interfaces:
|
||||
- /sbin/ip route add 10.113.15.0/24 via 10.112.1.15
|
||||
|
||||
|
||||
- device: bond1:ipmi
|
||||
headline: bond1:ipmi - Alias IP on bond1 for IPMI Addresses Servr Stockhausen
|
||||
- device: sfp0:ipmi
|
||||
headline: sfp0:ipmi - Alias IP on sfp0 for IPMI Addresses Servr Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
|
583
host_vars/ga-st-gw.ga.netz.yml.00
Normal file
583
host_vars/ga-st-gw.ga.netz.yml.00
Normal file
@ -0,0 +1,583 @@
|
||||
---
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eth2
|
||||
headline: eth2 - Uplink static line (radio) to Altenschlirf
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.111.254
|
||||
netmask: 24
|
||||
up:
|
||||
# - For management Antennas
|
||||
- /sbin/ip link add link eth2 name eth2.111 type vlan id 111
|
||||
post-up:
|
||||
# - Static routes to Altenschlirf (Router Ip-Address Altenschlirf: 172.16.111.253)
|
||||
# -
|
||||
# - Telefon Altenshlirf
|
||||
- /sbin/ip route add 172.16.210.0/24 via 172.16.111.253
|
||||
# User Network Altenshlirf
|
||||
- /sbin/ip route add 192.168.10.0/24 via 172.16.111.253
|
||||
# Management Network Altenschlirf
|
||||
- /sbin/ip route add 10.10.10.0/24 via 172.16.111.253
|
||||
# WLan Router (Accesspoints) Altenshlirf
|
||||
- /sbin/ip route add 10.122.1.0/24 via 172.16.111.253
|
||||
# # WLan Networks Altenshlirf
|
||||
- /sbin/ip route add 10.123.0.0/16 via 172.16.111.253
|
||||
# DSL via Fritzbox Altenschlirf
|
||||
- /sbin/ip route add 172.16.10.0/24 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf guest NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.221.0.0/20 via 172.16.111.253
|
||||
# - WLAN Gemeinschaft Altenschlirf private NET (Unifi routet Network)
|
||||
- /sbin/ip route add 10.231.0.0/20 via 172.16.111.253
|
||||
# VPN home Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.0.10.0/24 via 172.16.111.253
|
||||
# VPN 'gw-ckubu' Network Altenschlirf
|
||||
#
|
||||
- /sbin/ip route add 10.1.10.0/24 via 172.16.111.253
|
||||
# private networks 'ckubu'
|
||||
#
|
||||
# connections from private ckubu networks ist routed through VPN Altenschlirf (gw-ckubu),
|
||||
# so we route them back to that gateway..
|
||||
- /sbin/ip route add 192.168.63.0/24 via 172.16.111.253
|
||||
- /sbin/ip route add 192.168.64.0/24 via 172.16.111.253
|
||||
|
||||
|
||||
- device: eth2.111
|
||||
headline: eth2.111 - network 10.10.111.0 (management antennas)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.111.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: eth8
|
||||
headline: eth8 - holds VLAN 211 device for Network Telefons Stockhausen
|
||||
auto: false
|
||||
family: inet
|
||||
method: manual
|
||||
up:
|
||||
- /sbin/ip link add link eth8 name eth8.211 type vlan id 211
|
||||
|
||||
|
||||
- device: eth8.211
|
||||
headline: eth8.211 - Network Telefons Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
# Note:
|
||||
# !! 172.16.211.254 is reserved for LANCom Router (DSL line teleefon).
|
||||
# This LANCom Router IS NOT pngable !!
|
||||
address: 172.16.211.1
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eth8 up
|
||||
|
||||
|
||||
- device: eth9
|
||||
headline: eth9 - Uplink DSL surf2 via (static) line to Fritz!Box 7490 (formaly Zyxel 6501)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.11.1
|
||||
netmask: 24
|
||||
gateway: 172.16.11.254
|
||||
|
||||
|
||||
- device: eth10
|
||||
headline: eth10 - Uplink DSL surf3 via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.13.1
|
||||
netmask: 24
|
||||
gateway: 172.16.13.254
|
||||
|
||||
|
||||
- device: eth11
|
||||
headline: eth11 - Uplink DSL surf1 via (static) line to Fritz!Box 7490 (Mailserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.12.1
|
||||
netmask: 24
|
||||
gateway: 172.16.12.254
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond0
|
||||
headline: bond0 - LAG (Link Aggregation) on devices eth0 and eth4
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.1.9.254
|
||||
netmask: 24
|
||||
bond:
|
||||
slaves: eth0 eth4
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 11 for management network Stockhausen/Schloss 10.10.11.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.11 type vlan id 11
|
||||
# VLAN 78 for network Georgshaus 192.168.78.0/24
|
||||
- /sbin/ip link add link bond0 name bond0.78 type vlan id 78
|
||||
|
||||
|
||||
- device: bond0.11
|
||||
headline: bond0.11 - VLAN 11 on interface bond0 (Management Network Stockhausen)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond0.78
|
||||
headline: bond0.78 - VLAN 78 on interface bond0 (Georgshaus ?)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.78.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ----------
|
||||
# Note: Install the 'ifenslave' package, necessary to enable bonding:
|
||||
#
|
||||
# apt-get install ifenslave
|
||||
# ----------
|
||||
- device: bond1
|
||||
headline: bond1 - LAG (Link Aggregation) on devices eth3 and eth5 - Main Network Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.254
|
||||
netmask: 24
|
||||
nameservers:
|
||||
- 192.168.11.1
|
||||
- 192.168.10.3
|
||||
search: ga.netz ga.intra
|
||||
bond:
|
||||
slaves: eth3 eth5
|
||||
# Mode 4 (802.3ad)
|
||||
#
|
||||
# also possible here:
|
||||
# - Mode 5: balance-tlb
|
||||
# - Mode 6: balance-alb
|
||||
mode: 4
|
||||
miimon: 100
|
||||
lacp-rate: 1
|
||||
ad-select: count
|
||||
downdelay: 200
|
||||
updelay: 200
|
||||
post-up:
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints
|
||||
- /sbin/ip link add link bond1 name bond1.121 type vlan id 121
|
||||
# VLAN 121 - for Ubiquiti UniFi Accesspoints Guests
|
||||
- /sbin/ip link add link bond1 name bond1.131 type vlan id 131
|
||||
# Route ???
|
||||
- /sbin/ip route add 10.11.16.0/24 via 192.168.11.6
|
||||
# Route to management network campus
|
||||
- /sbin/ip route add 10.72.1.0/24 via 192.168.11.72
|
||||
# Route to LAN campus
|
||||
- /sbin/ip route add 192.168.72.0/24 via 192.168.11.72
|
||||
# Route to WLAN campus
|
||||
- /sbin/ip route add 192.168.73.0/24 via 192.168.11.72
|
||||
|
||||
|
||||
- device: bond1.121
|
||||
headline: bond1.121 - VLAN 121 on interface bond1 for Ubiquiti UniFi Accesspoints Guest NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.121.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1.131
|
||||
headline: bond1.131 - VLAN 131 on interface bond1 for Ubiquiti UniFi Accesspoints private NET
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.131.15.254
|
||||
netmask: 20
|
||||
|
||||
|
||||
- device: bond1:ns
|
||||
headline: bond1:ns - Alias IP on bond1 device for Nameservice
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.1
|
||||
netmask: 32
|
||||
|
||||
|
||||
- device: bond1:1
|
||||
headline: bond1:1 - Alias IP on bond1 device for (depricated) Management Network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.10.9.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: bond1:ap
|
||||
headline: bond1:ap - Alias IP on bond1 device for Network Accesspoints
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.112.1.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# - Wireless Networks routed through appropriate Accesspoints
|
||||
# -
|
||||
- /sbin/ip route add 10.113.1.0/24 via 10.112.1.1
|
||||
- /sbin/ip route add 10.113.2.0/24 via 10.112.1.2
|
||||
- /sbin/ip route add 10.113.3.0/24 via 10.112.1.3
|
||||
- /sbin/ip route add 10.113.4.0/24 via 10.112.1.4
|
||||
- /sbin/ip route add 10.113.5.0/24 via 10.112.1.5
|
||||
- /sbin/ip route add 10.113.6.0/24 via 10.112.1.6
|
||||
- /sbin/ip route add 10.113.7.0/24 via 10.112.1.7
|
||||
- /sbin/ip route add 10.113.8.0/24 via 10.112.1.8
|
||||
- /sbin/ip route add 10.113.9.0/24 via 10.112.1.9
|
||||
- /sbin/ip route add 10.113.10.0/24 via 10.112.1.10
|
||||
- /sbin/ip route add 10.113.11.0/24 via 10.112.1.11
|
||||
- /sbin/ip route add 10.113.12.0/24 via 10.112.1.12
|
||||
- /sbin/ip route add 10.113.13.0/24 via 10.112.1.13
|
||||
- /sbin/ip route add 10.113.14.0/24 via 10.112.1.14
|
||||
- /sbin/ip route add 10.113.15.0/24 via 10.112.1.15
|
||||
|
||||
|
||||
- device: bond1:ipmi
|
||||
headline: bond1:ipmi - Alias IP on bond1 for IPMI Addresses Servr Stockhausen
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.11.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 127.0.0.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- ga.netz
|
||||
- ga.intra
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 192.168.10.1
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 15 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
insert_ssh_keypair_backup_server: false
|
||||
ssh_keypair_backup_server:
|
||||
- name: backup
|
||||
backup_user: back
|
||||
priv_key_src: root/.ssh/id_rsa.backup.oopen.de
|
||||
priv_key_dest: /root/.ssh/id_rsa
|
||||
pub_key_src: root/.ssh/id_rsa.backup.oopen.de.pub
|
||||
pub_key_dest: /root/.ssh/id_rsa.pub
|
||||
|
||||
insert_keypair_backup_client: true
|
||||
ssh_keypair_backup_client:
|
||||
- name: backup
|
||||
priv_key_src: root/.ssh/id_ed25519.oopen-server
|
||||
priv_key_dest: /root/.ssh/id_ed25519
|
||||
pub_key_src: root/.ssh/id_ed25519.oopen-server.pub
|
||||
pub_key_dest: /root/.ssh/id_ed25519.pub
|
||||
target: backup.oopen.de
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$rDrvWa/KInzTe601YYf9./$WjDlaItCrgX7gu4nCs481y8WLxiRaNJCC/MgFgKuzg3
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: maadmin
|
||||
password: $y$j9T$LCkYWvykWzrpFxIlmSUB01$e1ROfZxXAU53UdAwZAECzED4iV4LS02Q4IPQ2fycv51
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
|
||||
- name: wadmin
|
||||
password: $6$sLWIXKTW$i/STlSS0LijkrnGR/XMbaxJsEbrRdDYgqyCqIr.muLN5towes8yHDCXsyCYDjuaBNKPHXyFpr8lclg5DOm9OF1
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$awYUu9oRvV39ojITZOC7D1$czTh5HHIE32PXb0vl40ayAarm39txR4jaH1QzBscqfC
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$wpg8hlvMpO4PAWSVdLoJq/$dgpQh4cEnbUOQkkZzKUM4S8XzNS/Md5gMmMuNTqec74
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
|
||||
sudo_users:
|
||||
- chris
|
||||
- sysadm
|
||||
- maadmin
|
||||
- wadmin
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
install_bind_packages: true
|
||||
|
||||
bind9_gateway_acl:
|
||||
- local-net:
|
||||
name: local-net
|
||||
entries:
|
||||
- 127.0.0.0/8
|
||||
- 172.16.0.0/12
|
||||
- 192.168.0.0/16
|
||||
- 10.0.0.0/8
|
||||
- fc00::/7
|
||||
- fe80::/10
|
||||
- ::1/128
|
||||
- internaldns:
|
||||
name: internaldns
|
||||
entries:
|
||||
- '# Nameserver Gateway Stockhausen'
|
||||
- 192.168.11.1
|
||||
- '# Domain Controller Stockhausen'
|
||||
- 192.168.10.3
|
||||
- '# Nameserver Gateway Altenschlirf'
|
||||
- 192.168.10.1
|
||||
- '# Domain Controller Altenschlirf'
|
||||
- 192.168.10.3
|
||||
- 192.168.10.6
|
||||
- 172.16.0.1
|
||||
- '# Nameserver Gateway Novalishaus'
|
||||
- 192.168.81.1
|
||||
- 10.2.11.2
|
||||
- '# Nameserver wolle'
|
||||
- 10.113.12.3
|
||||
- '# Postfix Mailserver'
|
||||
- 192.168.11.2
|
||||
- '# Mail Relay System'
|
||||
- 192.168.10.2
|
||||
|
||||
bind9_gateway_listen_on_v6:
|
||||
- none
|
||||
|
||||
bind9_gateway_listen_on:
|
||||
- any
|
||||
|
||||
#bind9_gateway_allow_transfer: {}
|
||||
bind9_gateway_allow_transfer:
|
||||
- internaldns
|
||||
|
||||
bind9_transfer_source: !!str "192.168.11.1"
|
||||
bind9_notify_source: !!str "192.168.11.1"
|
||||
|
||||
#bind9_gateway_allow_query: {}
|
||||
bind9_gateway_allow_query:
|
||||
- local-net
|
||||
|
||||
#bind9_gateway_allow_query_cache: {}
|
||||
bind9_gateway_allow_query_cache:
|
||||
- local-net
|
||||
|
||||
bind9_gateway_recursion: !!str "yes"
|
||||
#bind9_gateway_allow_recursion: {}
|
||||
bind9_gateway_allow_recursion:
|
||||
- local-net
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
git_firewall_repository:
|
||||
name: ipt-gateway
|
||||
repo: https://git.oopen.de/firewall/ipt-gateway
|
||||
dest: /usr/local/src/ipt-gateway
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
||||
|
394
host_vars/gw-campus.oopen.de.yml
Normal file
394
host_vars/gw-campus.oopen.de.yml
Normal file
@ -0,0 +1,394 @@
|
||||
---
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eno1
|
||||
headline: eno1 - Uplink DSL via (static) line to Fritz!Box 7490
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.72.1
|
||||
netmask: 24
|
||||
gateway: 172.16.72.254
|
||||
#nameservers:
|
||||
# - 192.168.81.1
|
||||
# - 172.16.81.254
|
||||
#search: ga.netz ga.intra
|
||||
|
||||
- device: eno2
|
||||
headline: eno2 - Uplink Lehrer-und Schülerdatenbank (LUSD)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.100.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# Traffic zur ehrer-und Schülerdatenbank (LUSD)
|
||||
- /sbin/ip route add 10.9.131.0/24 via 192.168.100.253
|
||||
|
||||
|
||||
|
||||
- device: eno3
|
||||
family: inet
|
||||
method: manual
|
||||
post-up:
|
||||
# VLAN 10 LAN 1 Campus
|
||||
- /sbin/ip link add link eno3 name eno3.10 type vlan id 10
|
||||
|
||||
- device: eno3:ns
|
||||
headline: eno3:ns - Alias on eno3 (Nameserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.72.1
|
||||
netmask: 32
|
||||
|
||||
- device: eno3.10
|
||||
headline: eno3.10 - LAN 1 Campus - network 192.168.72.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.72.254
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eno3 up
|
||||
|
||||
|
||||
- device: eno4
|
||||
family: inet
|
||||
method: manual
|
||||
post-up:
|
||||
# VLAN 20 - LAN 2 Campus including UniFi Accesspoints
|
||||
- /sbin/ip link add link eno4 name eno4.20 type vlan id 20
|
||||
|
||||
- device: eno4.20
|
||||
headline: eno4.20 - LAN 2 Campus - network 192.168.73.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.73.254
|
||||
netmask: 24
|
||||
pre-up:
|
||||
- /sbin/ifconfig eno4 up
|
||||
|
||||
|
||||
- device: eno6
|
||||
headline: eno6 - Management Network Campus - network 10.72.1.0/24
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 10.72.1.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
- device: eno7
|
||||
headline: eno7 - network 192.168.11.0/24 (LAN Stockhausen)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.11.72
|
||||
#gateway: 192.168.11.254
|
||||
netmask: 24
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 127.0.0.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- campus.netz
|
||||
- campus.intra
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
insert_ssh_keypair_backup_server: false
|
||||
ssh_keypair_backup_server:
|
||||
- name: backup
|
||||
backup_user: back
|
||||
priv_key_src: root/.ssh/id_rsa.backup.oopen.de
|
||||
priv_key_dest: /root/.ssh/id_rsa
|
||||
pub_key_src: root/.ssh/id_rsa.backup.oopen.de.pub
|
||||
pub_key_dest: /root/.ssh/id_rsa.pub
|
||||
|
||||
insert_keypair_backup_client: true
|
||||
ssh_keypair_backup_client:
|
||||
- name: backup
|
||||
priv_key_src: root/.ssh/id_ed25519.oopen-server
|
||||
priv_key_dest: /root/.ssh/id_ed25519
|
||||
pub_key_src: root/.ssh/id_ed25519.oopen-server.pub
|
||||
pub_key_dest: /root/.ssh/id_ed25519.pub
|
||||
target: backup.oopen.de
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$rDrvWa/KInzTe601YYf9./$WjDlaItCrgX7gu4nCs481y8WLxiRaNJCC/MgFgKuzg3
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: maadmin
|
||||
password: $y$j9T$LCkYWvykWzrpFxIlmSUB01$e1ROfZxXAU53UdAwZAECzED4iV4LS02Q4IPQ2fycv51
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
|
||||
- name: wadmin
|
||||
password: $6$sLWIXKTW$i/STlSS0LijkrnGR/XMbaxJsEbrRdDYgqyCqIr.muLN5towes8yHDCXsyCYDjuaBNKPHXyFpr8lclg5DOm9OF1
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$awYUu9oRvV39ojITZOC7D1$czTh5HHIE32PXb0vl40ayAarm39txR4jaH1QzBscqfC
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHCQRRXy0+9D+mhLniRlUpZZ3kZdZcQKXBsGnlsFYaRi maadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIF5GDIFA6/i6lzkr+EP/EZM9glrK0eSR0nmrEFgUJ4n8 wadmin@ga-st-lsx1'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID17MN6fUg0D1dMSgVYIBpIy+sDBBmiaHmXRXU63TXJA wadmin@ga-st-li1303'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtK8/rxHL1MKX5AHrgAzUYu0kV+1iYCmknpTQ7F0ham wadmin@wolf-debtest'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIcaDFxj0pYjOv/ohFVxVY2RKvy6ACZFPX9UkrUPHkbN wadmin@wolf-x1'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$wpg8hlvMpO4PAWSVdLoJq/$dgpQh4cEnbUOQkkZzKUM4S8XzNS/Md5gMmMuNTqec74
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
|
||||
sudo_users:
|
||||
- chris
|
||||
- sysadm
|
||||
- maadmin
|
||||
- wadmin
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
install_bind_packages: true
|
||||
|
||||
bind9_gateway_acl:
|
||||
- local-net:
|
||||
name: local-net
|
||||
entries:
|
||||
- 127.0.0.0/8
|
||||
- 172.16.0.0/12
|
||||
- 192.168.0.0/16
|
||||
- 10.0.0.0/8
|
||||
- fc00::/7
|
||||
- fe80::/10
|
||||
- ::1/128
|
||||
- internaldns:
|
||||
name: internaldns
|
||||
entries:
|
||||
- '# Nameserver Gateway Stockhausen'
|
||||
- 192.168.11.1
|
||||
- '# Domain Controller Stockhausen'
|
||||
- 192.168.10.3
|
||||
- '# Nameserver Gateway Altenschlirf'
|
||||
- 192.168.10.1
|
||||
- '# Domain Controller Altenschlirf'
|
||||
- 192.168.10.3
|
||||
- 192.168.10.6
|
||||
- 172.16.0.1
|
||||
- '# Nameserver Gateway Novalishaus'
|
||||
- 192.168.81.1
|
||||
- 10.2.11.2
|
||||
- '# Nameserver wolle'
|
||||
- 10.113.12.3
|
||||
- '# Postfix Mailserver'
|
||||
- 192.168.11.2
|
||||
- '# Mail Relay System'
|
||||
- 192.168.10.2
|
||||
|
||||
bind9_gateway_listen_on_v6:
|
||||
- none
|
||||
|
||||
bind9_gateway_listen_on:
|
||||
- any
|
||||
|
||||
#bind9_gateway_allow_transfer: {}
|
||||
bind9_gateway_allow_transfer:
|
||||
- none
|
||||
|
||||
bind9_transfer_source: !!str "192.168.81.1"
|
||||
bind9_notify_source: !!str "192.168.81.1"
|
||||
|
||||
#bind9_gateway_allow_query: {}
|
||||
bind9_gateway_allow_query:
|
||||
- local-net
|
||||
|
||||
#bind9_gateway_allow_query_cache: {}
|
||||
bind9_gateway_allow_query_cache:
|
||||
- local-net
|
||||
|
||||
bind9_gateway_recursion: !!str "yes"
|
||||
#bind9_gateway_allow_recursion: {}
|
||||
bind9_gateway_allow_recursion:
|
||||
- local-net
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
git_firewall_repository:
|
||||
name: ipt-gateway
|
||||
repo: https://git.oopen.de/firewall/ipt-gateway
|
||||
dest: /usr/local/src/ipt-gateway
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
||||
|
@ -82,6 +82,53 @@ sshd_hostkeyalgorithms:
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users
|
||||
# ---
|
||||
|
||||
default_user:
|
||||
|
||||
- name: chris
|
||||
password: $y$j9T$JPKlR6kIk7GJStSdmAQWq/$e1vJER6KL/dk1diFNtC.COw9lu2uT6ZdrUgGcNVb912
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: sysadm
|
||||
user_id: 1050
|
||||
group_id: 1050
|
||||
group: sysadm
|
||||
password: $y$j9T$sHxqz7NyYdn38ZegSbewO.$PPHR0n.XeMcS3AQ9KybllBT.2hxpYlQ7AiVhxHgUOX8
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: localadmin
|
||||
user_id: 1051
|
||||
group_id: 1051
|
||||
group: localadmin
|
||||
home: /home/localadmin
|
||||
password: $y$j9T$1WH8G2UkuN1jjp4QLuoeC0$dXpOnJUfMMAqAXlwN8XD0pq78r.a4UZOgt3LY4afxy/
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOQHMUKlDh2ufno5pZOhUY5xFljC1R5zQ/GjOHDkS58D root@sol'
|
||||
|
||||
- name: back
|
||||
user_id: 1060
|
||||
group_id: 1060
|
||||
group: back
|
||||
password: $y$j9T$WmitGB98lhPLJ39Iy4YfH.$irv0LP1bB5ImQKBUr1acEif6Ed6zDu6gLQuGQd/i5s0
|
||||
shell: /bin/bash
|
||||
ssh_keys:
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIO90culn3sicU2chTHn40ytcTay0nUIHap0uF/5fVM6P chris@sol'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKd0AwTHbDBK4Dgs+IZWmtnDBjoVIogOUvkLIYvsff1y root@backup.open.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de'
|
||||
- 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup'
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
303
host_vars/gw-fm.oopen.de.yml
Normal file
303
host_vars/gw-fm.oopen.de.yml
Normal file
@ -0,0 +1,303 @@
|
||||
---
|
||||
|
||||
# ---
|
||||
# vars used by roles/network_interfaces
|
||||
# ---
|
||||
|
||||
|
||||
# If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted
|
||||
network_manage_devices: True
|
||||
|
||||
# Should the interfaces be reloaded after config change?
|
||||
network_interface_reload: False
|
||||
|
||||
network_interface_path: /etc/network/interfaces.d
|
||||
network_interface_required_packages:
|
||||
- vlan
|
||||
- bridge-utils
|
||||
- ifmetric
|
||||
- ifupdown
|
||||
- ifenslave
|
||||
|
||||
network_interfaces:
|
||||
|
||||
- device: eno1
|
||||
headline: eno1 - Uplink DSL via Fritz!Box
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 172.16.222.1
|
||||
netmask: 24
|
||||
gateway: 172.16.222.254
|
||||
|
||||
|
||||
- device: eno2
|
||||
headline: eno2 - LAN
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.222.254
|
||||
netmask: 24
|
||||
post-up:
|
||||
# VLAN 13 Guest Net
|
||||
- /sbin/ip link add link eno2 name eno2.13 type vlan id 13
|
||||
|
||||
|
||||
- device: eno2:ns
|
||||
headline: eno2:ns - Alias on eno2 (Nameserver)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.222.1
|
||||
netmask: 32
|
||||
|
||||
|
||||
- device: eno2.13
|
||||
headline: eno2.13 - Guest Network
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.223.254
|
||||
netmask: 24
|
||||
|
||||
- device: eno2.13:ns
|
||||
headline: eno2.13:ns - alias on eno2.13 (Guest Network)
|
||||
auto: true
|
||||
family: inet
|
||||
method: static
|
||||
address: 192.168.223.1
|
||||
netmask: 32
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_user
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/basic.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sshd.yml
|
||||
# ---
|
||||
|
||||
sshd_hostkeyalgorithms:
|
||||
- ssh-ed25519
|
||||
- ssh-ed25519-cert-v01@openssh.com
|
||||
- rsa-sha2-256
|
||||
- rsa-sha2-512
|
||||
- ecdsa-sha2-nistp256
|
||||
- rsa-sha2-256-cert-v01@openssh.com
|
||||
- rsa-sha2-512-cert-v01@openssh.com
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/apt.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 127.0.0.1
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- ~.
|
||||
- fm.netz
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 172.16.222.254
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
|
||||
cron_user_entries:
|
||||
|
||||
- name: "Check if Postfix Mailservice is up and running?"
|
||||
minute: '*/15'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_postfix.sh
|
||||
|
||||
- name: "Check if SSH service is up and running?"
|
||||
minute: '*/15'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_ssh.sh
|
||||
|
||||
- name: "Check if OpenVPN service is up and running?"
|
||||
minute: '*/30'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_vpn.sh
|
||||
|
||||
- name: "Check if nameservice (bind) is running?"
|
||||
minute: '*/10'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_dns.sh
|
||||
|
||||
- name: "Check forwarding ( /proc/sys/net/ipv4/ip_forward contains \"1\" )"
|
||||
minute: '0-59/2'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_forwarding.sh
|
||||
|
||||
# - name: "Speedtest"
|
||||
# minute: '17'
|
||||
# hour: '*0-8'
|
||||
# job: /root/bin/admin-stuff/speedtest.sh
|
||||
|
||||
- name: "Copy gateway configuration"
|
||||
minute: '09'
|
||||
hour: '3'
|
||||
job: /root/bin/manage-gw-config/copy_gateway-config.sh FM
|
||||
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Check if Postfix Service is running at boot time"
|
||||
special_time: reboot
|
||||
job: "sleep 7 ; /root/bin/monitoring/check_postfix.sh"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Restart Systemd's resolved at boottime."
|
||||
special_time: reboot
|
||||
job: "sleep 10 ; /bin/systemctl restart systemd-resolved"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 15 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users.yml
|
||||
# ---
|
||||
|
||||
insert_ssh_keypair_backup_server: false
|
||||
ssh_keypair_backup_server:
|
||||
- name: backup
|
||||
backup_user: back
|
||||
priv_key_src: root/.ssh/id_rsa.backup.oopen.de
|
||||
priv_key_dest: /root/.ssh/id_rsa
|
||||
pub_key_src: root/.ssh/id_rsa.backup.oopen.de.pub
|
||||
pub_key_dest: /root/.ssh/id_rsa.pub
|
||||
|
||||
insert_keypair_backup_client: true
|
||||
ssh_keypair_backup_client:
|
||||
- name: backup
|
||||
priv_key_src: root/.ssh/id_ed25519.oopen-server
|
||||
priv_key_dest: /root/.ssh/id_ed25519
|
||||
pub_key_src: root/.ssh/id_ed25519.oopen-server.pub
|
||||
pub_key_dest: /root/.ssh/id_ed25519.pub
|
||||
target: backup.oopen.de
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/users-systemfiles.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/webadmin-user.yml
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/sudoers.yml
|
||||
# ---
|
||||
#
|
||||
# see: roles/common/tasks/vars
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/caching-nameserver.yml
|
||||
# ---
|
||||
|
||||
install_bind_packages: true
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/git.yml
|
||||
# ---
|
||||
|
||||
git_firewall_repository:
|
||||
name: ipt-gateway
|
||||
repo: https://git.oopen.de/firewall/ipt-gateway
|
||||
dest: /usr/local/src/ipt-gateway
|
||||
|
||||
# ==============================
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by scripts/reset_root_passwd.yml
|
||||
# ---
|
||||
|
||||
root_user:
|
||||
name: root
|
||||
password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq.
|
||||
|
@ -123,11 +123,16 @@ cron_user_special_time_entries:
|
||||
job: "sleep 10 ; /root/bin/monitoring/check_postfix.sh > /dev/null 2>&1"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Check if mattermost service is running. Restart service if needed."
|
||||
special_time: reboot
|
||||
job: "sleep 10 ; /root/bin/monitoring/check_local_mattermost_service.sh > /dev/null 2>&1"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
cron_user_entries:
|
||||
|
||||
- name: "Check if mattermost service ist running - Restart Service if needed."
|
||||
minute: '*/6'
|
||||
minute: '*/16'
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_local_mattermost_service.sh
|
||||
|
||||
|
@ -273,6 +273,11 @@ cron_user_entries:
|
||||
hour: '*'
|
||||
job: /root/bin/monitoring/check_ntpsec_service.sh > /dev/null 2>&1
|
||||
|
||||
- name: "Check if all autostart LX-Container are running.?"
|
||||
minute: '*/10'
|
||||
hour: '*'
|
||||
job: /root/bin/LXC/boot-autostart-lx-container.sh
|
||||
|
||||
|
||||
|
||||
# ---
|
||||
|
@ -63,8 +63,6 @@ network_interfaces:
|
||||
# search: warenform.de
|
||||
#
|
||||
nameservers:
|
||||
- 195.201.179.131
|
||||
- 95.217.204.204
|
||||
search: oopen.de warenform.de
|
||||
|
||||
# optional additional subnets/ips subnets: []
|
||||
@ -105,6 +103,13 @@ network_interfaces:
|
||||
vlan: {}
|
||||
|
||||
# inline hook scripts
|
||||
#
|
||||
# example:
|
||||
#
|
||||
# up:
|
||||
# - !!str "ip addr add 83.223.86.115/24 dev br0"
|
||||
# - !!str "ip route add default via 83.223.86.1"
|
||||
#
|
||||
pre-up: [] # pre-up script lines
|
||||
up:
|
||||
- !!str "ip addr add 83.223.85.203/24 dev br0"
|
||||
@ -114,6 +119,7 @@ network_interfaces:
|
||||
down: [] # down script lines
|
||||
post-down: [] # post-down script lines
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/ansible_dependencies
|
||||
# ---
|
||||
@ -139,6 +145,76 @@ network_interfaces:
|
||||
# ---
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/systemd-resolved.yml
|
||||
# ---
|
||||
|
||||
systemd_resolved: true
|
||||
|
||||
# CyberGhost - Schnelle Verbindung mit Keine-Logs-Datenschutzrichtlinie
|
||||
# Primäre DNS-Adresse: 38.132.106.139
|
||||
# Sekundäre DNS-Adresse: 194.187.251.67
|
||||
#
|
||||
# Cloudflare (USA) Bester kostenloser DNS-Server für Gaming mit zuverlässigen Verbindungen
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 1.1.1.1
|
||||
# IPv6: 2606:4700:4700::1111
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 1.0.0.1
|
||||
# IPv6: 2606:4700:4700::1001
|
||||
#
|
||||
# Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 8.8.8.8
|
||||
# IPv6: 2001:4860:4860::8888
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 8.8.4.4
|
||||
# IPv6: 2001:4860:4860::8844
|
||||
#
|
||||
# Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug
|
||||
# primäre DNS-Adresse
|
||||
# IPv4: 9.9.9.9
|
||||
# IPv6: 2620:fe::fe
|
||||
# sekundäre DNS-Adresse
|
||||
# IPv4: 149.112.112.112
|
||||
# IPv6: 2620:fe::9
|
||||
#
|
||||
# OpenNIC - https://www.opennic.org/
|
||||
# IPv4: 195.10.195.195 - ns31.de
|
||||
# IPv4: 94.16.114.254 - ns28.de
|
||||
# IPv4: 51.254.162.59 - ns9.de
|
||||
# IPv4: 194.36.144.87 - ns29.de
|
||||
# IPv6: 2a00:f826:8:2::195 - ns31.de
|
||||
#
|
||||
# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS)
|
||||
# IPv4: 5.1.66.255
|
||||
# IPv6: 2001:678:e68:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# IPv4: 185.150.99.255
|
||||
# IPv6: 2001:678:ed0:f000::
|
||||
# Servername für DNS-over-TLS: dot.ffmuc.net
|
||||
# für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb)
|
||||
resolved_nameserver:
|
||||
- 195.201.179.131
|
||||
- 95.217.204.204
|
||||
|
||||
# search domains
|
||||
#
|
||||
# If there are more than one search domains, then specify them here in the order in which
|
||||
# the resolver should also search them
|
||||
#
|
||||
#resolved_domains: []
|
||||
resolved_domains:
|
||||
- oopen.de
|
||||
|
||||
resolved_dnssec: false
|
||||
|
||||
# dns.as250.net: 194.150.168.168
|
||||
#
|
||||
resolved_fallback_nameserver:
|
||||
- 194.150.168.168
|
||||
|
||||
|
||||
# ---
|
||||
# vars used by roles/common/tasks/cron.yml
|
||||
# ---
|
||||
@ -156,7 +232,7 @@ cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart DNS Cache service 'systemd-resolved'"
|
||||
special_time: reboot
|
||||
job: "sleep 5 ; /bin/systemctl restart systemd-resolved"
|
||||
job: "sleep 5 ; /bin/systemctl restart systemd-resolved > /dev/null 2>&1"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Check if postfix mailservice is running. Restart service if needed."
|
||||
@ -250,210 +326,6 @@ git_firewall_repository:
|
||||
# vars used by roles/common/tasks/samba-user.yml
|
||||
# ---
|
||||
|
||||
samba_server_ip: 83.223.85.203
|
||||
samba_server_cidr_prefix: 24
|
||||
|
||||
samba_workgroup: AH
|
||||
|
||||
samba_netbios_name: FILE-AH
|
||||
|
||||
samba_groups:
|
||||
- name: verwaltung
|
||||
group_id: 1200
|
||||
- name: intern
|
||||
group_id: 1210
|
||||
- name: hoffmann-elberling
|
||||
group_id: 1220
|
||||
- name: gubitz-partner
|
||||
group_id: 1230
|
||||
|
||||
samba_user:
|
||||
- name: buero
|
||||
groups:
|
||||
- verwaltung
|
||||
- intern
|
||||
password: 'buero2011'
|
||||
- name: axel
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- hoffmann-elberling
|
||||
password: 'ah-kiel.2018'
|
||||
- name: bjoern
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- hoffmann-elberling
|
||||
password: 'bjoern2011'
|
||||
- name: gubitz
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
password: '20gubitz12'
|
||||
- name: schaar
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
password: '20schaar12'
|
||||
- name: molkentin
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
password: 20molkentin12
|
||||
- name: buerooben
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- hoffmann-elberling
|
||||
password: 'buero2013'
|
||||
- name: back
|
||||
groups: []
|
||||
password: !vault |
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
63643330373231636537366333326630333265303265653933613835656262323863363038653234
|
||||
3462653135633266373439626263356636646637643035340a653466356235346663626163306363
|
||||
61313164643061306433643738643563303036646334376536626531383965303036386162393832
|
||||
6631333038306462610a356535633265633563633962333137326533633834636331343562633765
|
||||
3631
|
||||
- name: buchholz
|
||||
groups:
|
||||
- buero
|
||||
- intern
|
||||
- verwaltung
|
||||
password: '20-buch_holz-20'
|
||||
- name: schmidt
|
||||
groups:
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
password: '20-schmidt_21%'
|
||||
- name: kiel-nb1
|
||||
groups:
|
||||
- buero
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
- hoffmann-elberling
|
||||
password: '20-note%book1-20'
|
||||
- name: kiel-nb2
|
||||
groups:
|
||||
- buero
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
- hoffmann-elberling
|
||||
password: '20-note%book2-20'
|
||||
- name: chris
|
||||
groups:
|
||||
- buero
|
||||
- intern
|
||||
- verwaltung
|
||||
- gubitz-partner
|
||||
- hoffmann-elberling
|
||||
password: !vault |
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
63643330373231636537366333326630333265303265653933613835656262323863363038653234
|
||||
3462653135633266373439626263356636646637643035340a653466356235346663626163306363
|
||||
61313164643061306433643738643563303036646334376536626531383965303036386162393832
|
||||
6631333038306462610a356535633265633563633962333137326533633834636331343562633765
|
||||
3631
|
||||
|
||||
base_home: /home
|
||||
|
||||
# remove_samba_users:
|
||||
# - name: name1
|
||||
# - name: name2
|
||||
#
|
||||
remove_samba_users: []
|
||||
|
||||
samba_shares:
|
||||
- name: profiles-RDP
|
||||
comment: Users profiles RDP
|
||||
path: /data/samba/profiles-RDP
|
||||
guest_ok: !!str no
|
||||
browseable: !!str no
|
||||
valid_users: '%S'
|
||||
file_create_mask: !!str 600
|
||||
dir_create_mask: !!str 700
|
||||
|
||||
- name: Buero
|
||||
path: /data/samba/shares/Buero
|
||||
group_valid_users: intern
|
||||
group_write_list: intern
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: Verwaltung
|
||||
path: /data/samba/shares/Verwaltung
|
||||
group_valid_users: verwaltung
|
||||
group_write_list: verwaltung
|
||||
file_create_mask: !!str 660
|
||||
dir_create_mask: !!str 2770
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: Scans_schnell
|
||||
path: /data/samba/shares/Scans_schnell
|
||||
group_valid_users: intern
|
||||
group_write_list: intern
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: Hoffmann-Elberling
|
||||
path: /data/samba/shares/Hoffmann-Elberling
|
||||
group_valid_users: hoffmann-elberling
|
||||
group_write_list: hoffmann-elberling
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: Gubitz-Partner
|
||||
path: /data/samba/shares/Gubitz-Partner
|
||||
group_valid_users: gubitz-partner
|
||||
group_write_list: gubitz-partner
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: Gubitz-Backup
|
||||
path: /data/samba/shares/Gubitz-Backup
|
||||
group_valid_users: gubitz
|
||||
group_write_list: gubitz
|
||||
file_create_mask: !!str 660
|
||||
dir_create_mask: !!str 2770
|
||||
vfs_object_recycle: true
|
||||
recycle_path: recycle
|
||||
|
||||
- name: WinServer2016-Backup
|
||||
comment: WinServer2016-Backup on Fileserver
|
||||
path: /data/samba/shares/WinServer2016-Backup
|
||||
group_valid_users: {}
|
||||
group_write_list: {}
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
guest_ok: !!str yes
|
||||
vfs_object_recycle: true
|
||||
recycle_path: {}
|
||||
|
||||
- name: Advoware-Backup
|
||||
comment: Advoware-Backup (only read) on Fileserver
|
||||
path: /data/samba/shares/Advoware-Backup
|
||||
group_valid_users: back
|
||||
group_write_list: back
|
||||
file_create_mask: !!str 664
|
||||
dir_create_mask: !!str 2775
|
||||
guest_ok: !!str yes
|
||||
vfs_object_recycle: true
|
||||
|
||||
|
||||
|
||||
# ==============================
|
||||
|
@ -345,6 +345,8 @@ cron_user_entries:
|
||||
sudoers_file_user_privileges:
|
||||
- name: back
|
||||
entry: 'ALL=(www-data) NOPASSWD: /usr/local/php/bin/php'
|
||||
- name: www-data
|
||||
entry: 'ALL=(root) NOPASSWD: /root/bin/nextcloud/add-new-account.sh'
|
||||
|
||||
|
||||
# ---
|
||||
|
@ -249,7 +249,7 @@ cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 2 ; /bin/systemctl restart ntpsec"
|
||||
job: "sleep 2 ; /bin/systemctl restart ntpsec > /dev/null 2>&1"
|
||||
insertafter: PATH
|
||||
|
||||
|
||||
|
@ -235,11 +235,6 @@ cron_env_entries:
|
||||
|
||||
cron_user_special_time_entries:
|
||||
|
||||
- name: "Restart NTP service 'ntpsec'"
|
||||
special_time: reboot
|
||||
job: "sleep 2 ; /bin/systemctl restart ntpsec"
|
||||
insertafter: PATH
|
||||
|
||||
- name: "Restart DNS Cache service 'systemd-resolved'"
|
||||
special_time: reboot
|
||||
job: "sleep 5 ; /bin/systemctl restart systemd-resolved"
|
||||
|
@ -203,6 +203,8 @@ samba_netbios_name: ZAPATA
|
||||
|
||||
samba_server_min_protocol: !!str NT1
|
||||
|
||||
samba_allow_insecure_wide_links: !!str yes
|
||||
|
||||
samba_groups:
|
||||
- name: buero
|
||||
group_id: 1100
|
||||
@ -384,6 +386,7 @@ samba_user:
|
||||
groups:
|
||||
- buero
|
||||
- beratung
|
||||
- verwaltung
|
||||
password: '20_simon_18!'
|
||||
|
||||
- name: ute
|
||||
@ -411,6 +414,7 @@ samba_shares:
|
||||
group_write_list: buero
|
||||
file_create_mask: !!str 660
|
||||
dir_create_mask: !!str 2770
|
||||
wide_links: !!str yes
|
||||
vfs_object_recycle: true
|
||||
recycle_path: '@Recycle'
|
||||
|
||||
|
68
hosts
68
hosts
@ -43,8 +43,8 @@ gw-ak.oopen.de
|
||||
gw-akb.oopen.de
|
||||
172.16.82.2
|
||||
gw-dissens.oopen.de
|
||||
gw-dissens.oopen.de
|
||||
gw-ebs.oopen.de
|
||||
gw-fm.oopen.de
|
||||
gw-elster.oopen.de
|
||||
gw-fhxb.oopen.de
|
||||
gw-ckubu.local.netz
|
||||
@ -62,6 +62,7 @@ gw-kb.oopen.de
|
||||
bbb-server.b3-bornim.netz
|
||||
file-ah.kanzlei-kiel.netz
|
||||
file-ebs.ebs.netz
|
||||
file-fm.fm.netz
|
||||
file-fhxb.fhxb.netz
|
||||
file-km.anw-km.netz
|
||||
file-kb.anw-kb.netz
|
||||
@ -78,9 +79,10 @@ at-10-neu.ak.netz
|
||||
|
||||
ga-st-gw-ersatz.ga.netz
|
||||
ga-st-gw.ga.netz
|
||||
ga-st-gw-neu.ga.netz
|
||||
ga-al-gw.oopen.de
|
||||
ga-nh-gw.oopen.de
|
||||
ga-campus-gw-temp.ga.netz
|
||||
gw-campus.oopen.de
|
||||
ga-st-lxc1.ga.netz
|
||||
ga-st-mail.ga.netz
|
||||
ga-st-mm.ga.netz
|
||||
@ -142,6 +144,9 @@ o13-web.oopen.de
|
||||
# Freiheit für daniela
|
||||
o14.oopen.de
|
||||
|
||||
# VBRG - Opferhilfefonds
|
||||
o15.oopen.de
|
||||
|
||||
o17.oopen.de
|
||||
test.mx.oopen.de
|
||||
|
||||
@ -175,7 +180,6 @@ o24.oopen.de
|
||||
cl-irights.oopen.de
|
||||
cl-irights-neu.oopen.de
|
||||
mm-irights.oopen.de
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# IL - PAD
|
||||
o25.oopen.de
|
||||
@ -205,9 +209,6 @@ o31.oopen.de
|
||||
mail.cadus.org
|
||||
web.cadus.org
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# BigBlueButton - O.OPEN
|
||||
o33.oopen.de
|
||||
|
||||
@ -254,9 +255,6 @@ cp-flr.oopen.de
|
||||
# Kotti-Coop e.V.
|
||||
o41.oopen.de
|
||||
|
||||
# AgR - Shop
|
||||
shop-dev.aufstehen-gegen-rassismus.de
|
||||
|
||||
# RAV
|
||||
o42.oopen.de
|
||||
mm-rav.oopen.de
|
||||
@ -344,6 +342,9 @@ o13-git.oopen.de
|
||||
# Freiheit für daniela
|
||||
o14.oopen.de
|
||||
|
||||
# VBRG - Opferhilfefonds
|
||||
o15.oopen.de
|
||||
|
||||
o17.oopen.de
|
||||
test.mx.oopen.de
|
||||
test.mariadb.oopen.de
|
||||
@ -382,7 +383,6 @@ o24.oopen.de
|
||||
cl-irights.oopen.de
|
||||
cl-irights-neu.oopen.de
|
||||
ga-st-mm.ga.netz
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# IL - PAD
|
||||
o25.oopen.de
|
||||
@ -412,9 +412,6 @@ o31.oopen.de
|
||||
mail.cadus.org
|
||||
web.cadus.org
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# BigBlueButton - O.OPEN
|
||||
o33.oopen.de
|
||||
|
||||
@ -462,9 +459,6 @@ cp-flr.oopen.de
|
||||
o41.oopen.de
|
||||
g.mx.oopen.de
|
||||
|
||||
# AgR - Shop
|
||||
shop-dev.aufstehen-gegen-rassismus.de
|
||||
|
||||
# RAV
|
||||
o42.oopen.de
|
||||
mm-rav.oopen.de
|
||||
@ -536,6 +530,11 @@ file-dissens.dissens.netz
|
||||
gw-ebs.oopen.de
|
||||
file-ebs.ebs.netz
|
||||
|
||||
# Faire Mobilitaet
|
||||
gw-fm.oopen.de
|
||||
file-fm.fm.netz
|
||||
|
||||
|
||||
# Kanzlei Elster Jena
|
||||
gw-elster.oopen.de
|
||||
|
||||
@ -562,9 +561,10 @@ gw-d11.oopen.de
|
||||
# - GA - Gemeinschaft Altensclirf
|
||||
ga-st-gw-ersatz.ga.netz
|
||||
ga-st-gw.ga.netz
|
||||
ga-st-gw-neu.ga.netz
|
||||
ga-al-gw.oopen.de
|
||||
ga-nh-gw.oopen.de
|
||||
ga-campus-gw-temp.ga.netz
|
||||
gw-campus.oopen.de
|
||||
|
||||
ga-st-lxc1.ga.netz
|
||||
ga-st-mail.ga.netz
|
||||
@ -852,16 +852,12 @@ mm-migration.oopen.de
|
||||
# o24.oopen.de
|
||||
mm-irights.oopen.de
|
||||
ga-st-mm.ga.netz
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# Hetzner Cloud CX31 - AK
|
||||
|
||||
# o29.oopen.de . Dissens
|
||||
cl-dissens.oopen.de
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# Nextcloud / DokuWiki VBER
|
||||
o34.oopen.de
|
||||
|
||||
@ -990,7 +986,6 @@ mm-migration.oopen.de
|
||||
# o24.oopen.de
|
||||
mm-irights.oopen.de
|
||||
ga-st-mm.ga.netz
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# o27.oopen.de
|
||||
mail.faire-mobilitaet.de
|
||||
@ -1087,7 +1082,6 @@ cl-irights.oopen.de
|
||||
cl-irights-neu.oopen.de
|
||||
mm-irights.oopen.de
|
||||
ga-st-mm.ga.netz
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# Hetzner Cloud CX31 - AK
|
||||
|
||||
@ -1108,9 +1102,6 @@ cloud.akweb.de
|
||||
web.cadus.org
|
||||
mail.cadus.org
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# Nextcloud / DokuWiki VBER
|
||||
o34.oopen.de
|
||||
|
||||
@ -1358,6 +1349,7 @@ at-10-neu.ak.netz
|
||||
bbb-server.b3-bornim.netz
|
||||
file-ah.kanzlei-kiel.netz
|
||||
file-ebs.ebs.netz
|
||||
file-fm.fm.netz
|
||||
file-fhxb.fhxb.netz
|
||||
file-km.anw-km.netz
|
||||
file-kb.anw-kb.netz
|
||||
@ -1373,6 +1365,7 @@ file-blkr.blkr.netz
|
||||
file-dissens.dissens.netz
|
||||
file-ah.kanzlei-kiel.netz
|
||||
file-ebs.ebs.netz
|
||||
file-fm.fm.netz
|
||||
file-fhxb.fhxb.netz
|
||||
|
||||
|
||||
@ -1426,9 +1419,6 @@ ga-al-kvm3.ga.netz
|
||||
# Kotti-Coop e.V.
|
||||
o41.oopen.de
|
||||
|
||||
# AgR - Shop
|
||||
shop-dev.aufstehen-gegen-rassismus.de
|
||||
|
||||
# o43 - ND App
|
||||
formbricks-nd.oopen.de
|
||||
test-nd.oopen.de
|
||||
@ -1458,7 +1448,6 @@ o27.oopen.de
|
||||
o29.oopen.de
|
||||
o30.oopen.de
|
||||
o31.oopen.de
|
||||
o32.oopen.de
|
||||
o34.oopen.de
|
||||
o35.oopen.de
|
||||
o36.oopen.de
|
||||
@ -1567,7 +1556,6 @@ cl-irights.oopen.de
|
||||
cl-irights-neu.oopen.de
|
||||
mm-irights.oopen.de
|
||||
ga-st-mm.ga.netz
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# - o27.oopen.de
|
||||
cl-fm.oopen.de
|
||||
@ -1582,9 +1570,6 @@ cl-dissens.oopen.de
|
||||
meet.akweb.de
|
||||
cloud.akweb.de
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# BigBlueButton - O.OPEN
|
||||
o33.oopen.de
|
||||
|
||||
@ -1641,6 +1626,7 @@ at-10-neu.ak.netz
|
||||
bbb-server.b3-bornim.netz
|
||||
file-ah.kanzlei-kiel.netz
|
||||
file-ebs.ebs.netz
|
||||
file-fm.fm.netz
|
||||
file-fhxb.fhxb.netz
|
||||
file-km.anw-km.netz
|
||||
file-kb.anw-kb.netz
|
||||
@ -1772,7 +1758,6 @@ o24.oopen.de
|
||||
cl-irights.oopen.de
|
||||
cl-irights-neu.oopen.de
|
||||
mm-irights.oopen.de
|
||||
mm-irights-migration.oopen.de
|
||||
|
||||
# IL - PAD
|
||||
o25.oopen.de
|
||||
@ -1802,9 +1787,6 @@ o31.oopen.de
|
||||
mail.cadus.org
|
||||
web.cadus.org
|
||||
|
||||
# etventure
|
||||
o32.oopen.de
|
||||
|
||||
# BigBlueButton - O.OPEN
|
||||
o33.oopen.de
|
||||
|
||||
@ -1852,9 +1834,6 @@ cp-flr.oopen.de
|
||||
# Kotti-Coop e.V.
|
||||
o41.oopen.de
|
||||
|
||||
# AgR - Shop
|
||||
shop-dev.aufstehen-gegen-rassismus.de
|
||||
|
||||
# RAV
|
||||
o42.oopen.de
|
||||
mm-rav.oopen.de
|
||||
@ -1880,6 +1859,7 @@ at-10-neu.ak.netz
|
||||
bbb-server.b3-bornim.netz
|
||||
file-ah.kanzlei-kiel.netz
|
||||
file-ebs.ebs.netz
|
||||
file-fm.fm.netz
|
||||
file-fhxb.fhxb.netz
|
||||
file-km.anw-km.netz
|
||||
file-kb.anw-kb.netz
|
||||
@ -1903,6 +1883,7 @@ gw-b3.oopen.de
|
||||
gw-d11.oopen.de
|
||||
gw-dissens.oopen.de
|
||||
gw-ebs.oopen.de
|
||||
gw-fm.oopen.de
|
||||
gw-elster.oopen.de
|
||||
gw-blkr.oopen.de
|
||||
gw-ak.oopen.de
|
||||
@ -1926,9 +1907,10 @@ k1371.dyndns.org
|
||||
|
||||
ga-st-gw-ersatz.ga.netz
|
||||
ga-st-gw.ga.netz
|
||||
ga-st-gw-neu.ga.netz
|
||||
ga-al-gw.oopen.de
|
||||
ga-nh-gw.oopen.de
|
||||
ga-campus-gw-temp.ga.netz
|
||||
gw-campus.oopen.de
|
||||
|
||||
|
||||
# Gateway/Firewall Server office network
|
||||
@ -2008,7 +1990,7 @@ ga-al-kvm2.ga.netz
|
||||
ga-al-kvm3.ga.netz
|
||||
ga-al-relay.ga.netz
|
||||
ga-nh-gw.oopen.de.yml
|
||||
ga-campus-gw-temp.ga.netz
|
||||
gw-campus.oopen.de
|
||||
ga-st-lxc1.ga.netz
|
||||
ga-st-mail.ga.netz
|
||||
ga-st-services.ga.netz
|
||||
|
@ -52,6 +52,14 @@ options {
|
||||
any;
|
||||
};
|
||||
|
||||
allow-query {
|
||||
127.0.0.1;
|
||||
::1 ;
|
||||
{% for acl in acl_caching_nameserver %}
|
||||
{{ acl.name }};
|
||||
{% endfor %}
|
||||
};
|
||||
|
||||
allow-recursion {
|
||||
127.0.0.1;
|
||||
::1 ;
|
||||
@ -69,6 +77,11 @@ options {
|
||||
::1;
|
||||
};
|
||||
|
||||
allow-query {
|
||||
127.0.0.1;
|
||||
::1;
|
||||
};
|
||||
|
||||
allow-recursion {
|
||||
127.0.0.1;
|
||||
::1;
|
||||
|
@ -269,6 +269,30 @@
|
||||
# public shares, not just authenticated ones
|
||||
usershare allow guests = yes
|
||||
|
||||
# In normal operation the option wide links which allows the server to follow
|
||||
# symlinks outside of a share path is automatically disabled when unix extensions
|
||||
# are enabled on a Samba server. This is done for security purposes to prevent
|
||||
# UNIX clients creating symlinks to areas of the server file system that the
|
||||
# administrator does not wish to export.
|
||||
#
|
||||
# Setting allow insecure wide links to true disables the link between these two
|
||||
# parameters, removing this protection and allowing a site to configure the server
|
||||
# to follow symlinks (by setting wide links to "true") even when unix extensions is
|
||||
# turned on.
|
||||
#
|
||||
# It is not recommended to enable this option unless you fully understand the
|
||||
# implications of allowing the server to follow symbolic links created by UNIX clients.
|
||||
# For most normal Samba configurations this would be considered a security hole and
|
||||
# setting this parameter is not recommended.
|
||||
#
|
||||
# This option was added at the request of sites who had deliberately set Samba up
|
||||
# in this way and needed to continue supporting this functionality without having to
|
||||
# patch the Samba code.
|
||||
#
|
||||
# Default: allow insecure wide links = no
|
||||
#
|
||||
allow insecure wide links = {{ samba_allow_insecure_wide_links|default('no') }}
|
||||
|
||||
#======================= Share Definitions =======================
|
||||
|
||||
# {{ ansible_managed }}
|
||||
@ -368,6 +392,26 @@
|
||||
|
||||
force group = +{{ item.group_write_list }}
|
||||
{% endif %}
|
||||
{%- if item.wide_links is defined and item.wide_links|length > 0 %}
|
||||
# This parameter controls whether or not links in the UNIX file system may be
|
||||
# followed by the server. Links that point to areas within the directory tree
|
||||
# exported by the server are always allowed; this parameter controls access only to
|
||||
# areas that are outside the directory tree being exported.
|
||||
#
|
||||
# Note: Turning this parameter on when UNIX extensions are enabled will allow UNIX
|
||||
# clients to create symbolic links on the share that can point to files or
|
||||
# directories outside restricted path exported by the share definition. This can
|
||||
# cause access to areas outside of the share. Due to this problem, this paramete
|
||||
# will be automatically disabled (with a message in the log file) if the unix
|
||||
# extensions option is on.
|
||||
#
|
||||
# See the parameter allow insecure wide links if you wish to change this coupling
|
||||
# between the two parameters.
|
||||
#
|
||||
# Default: wide links = no
|
||||
#
|
||||
wide links = yes
|
||||
{% endif %}
|
||||
{% if item.vfs_object_recycle is defined and item.vfs_object_recycle|bool %}
|
||||
{% if item.recycle_path is defined and item.recycle_path|length > 0 %}
|
||||
|
||||
|
Reference in New Issue
Block a user