created major large-scale changes
This commit is contained in:
@@ -8,6 +8,23 @@
|
||||
when: ansible_facts["system"] == "Linux"
|
||||
ansible.builtin.shell:
|
||||
cmd: "echo {{ ansible_user }}"
|
||||
register: current_user
|
||||
- name: Informing user of requirement of two main domains
|
||||
when: (certbot.domains | length) < 2 or (certbot.domains | length) > 2
|
||||
ansible.builtin.fail:
|
||||
msg: Only two domains allowed and required
|
||||
- name: Informing user of requirement at least one wildcard
|
||||
when: (certbot.domains | select("regex", "^\\*\\.") | list | length) == 0
|
||||
ansible.builtin.fail:
|
||||
msg: At least one of the FQDNs must have a wildcard
|
||||
# - name: Setting the FQDN for development
|
||||
# when: compose.mode == "dev"
|
||||
# ansible.builtin.set_fact:
|
||||
# web_fqdn: "{{ (certbot.domains | map('regex_replace', '\\.([^\\.]*)$', '.test') | reject('regex', '^\\*\\.') | list)[0] }}"
|
||||
- name: Setting the FQDN
|
||||
# when: compose.mode == "prod"
|
||||
ansible.builtin.set_fact:
|
||||
web_fqdn: "{{ (certbot.domains | reject('regex', '^\\*\\.') | list)[0] }}"
|
||||
- name: Configuring Headscale
|
||||
become: true
|
||||
ansible.builtin.template:
|
||||
@@ -18,6 +35,7 @@
|
||||
mode: "644"
|
||||
force: true
|
||||
backup: true
|
||||
# validate: "headscale configtest"
|
||||
- name: Starting SystemD service
|
||||
become: true
|
||||
ansible.builtin.systemd_service:
|
||||
@@ -28,12 +46,55 @@
|
||||
- name: Registering a headscale user
|
||||
become: true
|
||||
ansible.builtin.command:
|
||||
# cmd: "headscale users create {{ item.username }} -d '{{ item.dname }}' -e '{{ item.email }}' -p '{{ pfp | default(default_pfp) }}'"
|
||||
cmd: "headscale users create {{ item.username }} -d '{{ item.dname }}' -e '{{ item.email }}'"
|
||||
# vars:
|
||||
# default_pfp: ~
|
||||
loop: "{{ tail.users }}"
|
||||
cmd: "headscale users create {{ headscale.users.admin.username }} -d '{{ headscale.users.admin.dname }}' -e '{{ headscale.users.admin.email }}'"
|
||||
register: headscale_registration
|
||||
changed_when:
|
||||
- "'User created' in headscale_registration.stdout"
|
||||
- headscale_registration.rc == 0
|
||||
- name: Creating an authentication key for this registered headscale user
|
||||
become: true
|
||||
ansible.builtin.command:
|
||||
cmd: "headscale preauthkeys create -e 24h -u 1"
|
||||
register: tailscale_admin_authkey
|
||||
- name: Pausing to inquire about how to proceed
|
||||
ansible.builtin.pause:
|
||||
prompt: "Type \"fetch\" to get the DSNet VPN service client configuration files, or \"show\" to see their contents for manual copying instead"
|
||||
echo: true
|
||||
register: data_method
|
||||
- name: Choosing Headscale authentication key to control node for copying
|
||||
when: data_method.user_input == "show"
|
||||
block:
|
||||
- name: Presenting Headscale authentication key to Control Node
|
||||
ansible.builtin.debug:
|
||||
msg: "Copy this client configuration of the headscale service:\n {{ tailscale_admin_authkey.stdout }}"
|
||||
- name: Giving opportunity to manually copy Headscale authentication key
|
||||
ansible.builtin.pause:
|
||||
- name: Choosing Headscale service client configuration files to control node machine
|
||||
when: data_method.user_input == "fetch"
|
||||
block:
|
||||
- name: Creating temporary file on managed node that stores Headscale authentication key
|
||||
ansible.builtin.copy:
|
||||
content: "{{ tailscale_admin_authkey.stdout }}"
|
||||
dest: "/tmp/headscale.key"
|
||||
owner: "{{ ansible_user }}"
|
||||
group: "{{ ansible_user }}"
|
||||
mode: "644"
|
||||
register: tailscale_admin_authkey_file
|
||||
- name: Placing Headscale authentication key into file on control node
|
||||
ansible.builtin.fetch:
|
||||
src: "{{ tailscale_admin_authkey_file.dest }}"
|
||||
dest: "./.tmp/{{ inventory_hostname }}-{{ headscale.users.admin.username }}@headscale/headscale.key"
|
||||
flat: true
|
||||
- name: Placing Headscale authentication key into file on control node
|
||||
ansible.builtin.fetch:
|
||||
src: "{{ tailscale_admin_authkey_file.dest }}"
|
||||
dest: "./roles/init-server/files/{{ item.name }}-{{ headscale.users.admin.username }}@headscale/headscale{{ (idx | string) }}.key"
|
||||
flat: true
|
||||
loop: "{{ headscale.clients }}"
|
||||
loop_control:
|
||||
index_var: idx
|
||||
- name: Informing control node of acquired files
|
||||
ansible.builtin.debug:
|
||||
msg: "The Headscale authentication key files have been duplicated to './.tmp/{{ inventory_hostname }}-{{ headscale.users.admin.username }}@headscale/headscale.key' at the control node."
|
||||
- name: Giving control node user time to read the aforementiioned message
|
||||
ansible.builtin.pause:
|
||||
seconds: 30
|
||||
Reference in New Issue
Block a user