Adding multiples ansible roles, playbooks and inventory
This commit is contained in:
122
roles/deploy_ssh_key/files/sshd_config
Normal file
122
roles/deploy_ssh_key/files/sshd_config
Normal file
@@ -0,0 +1,122 @@
|
||||
|
||||
# This is the sshd server system-wide configuration file. See
|
||||
# sshd_config(5) for more information.
|
||||
|
||||
# This sshd was compiled with PATH=/usr/local/bin:/usr/bin:/bin:/usr/games
|
||||
|
||||
# The strategy used for options in the default sshd_config shipped with
|
||||
# OpenSSH is to specify options with their default value where
|
||||
# possible, but leave them commented. Uncommented options override the
|
||||
# default value.
|
||||
|
||||
Include /etc/ssh/sshd_config.d/*.conf
|
||||
|
||||
#Port 22
|
||||
#AddressFamily any
|
||||
#ListenAddress 0.0.0.0
|
||||
#ListenAddress ::
|
||||
|
||||
#HostKey /etc/ssh/ssh_host_rsa_key
|
||||
#HostKey /etc/ssh/ssh_host_ecdsa_key
|
||||
#HostKey /etc/ssh/ssh_host_ed25519_key
|
||||
|
||||
# Ciphers and keying
|
||||
#RekeyLimit default none
|
||||
|
||||
# Logging
|
||||
#SyslogFacility AUTH
|
||||
#LogLevel INFO
|
||||
|
||||
# Authentication:
|
||||
|
||||
#LoginGraceTime 2m
|
||||
#PermitRootLogin prohibit-password
|
||||
#StrictModes yes
|
||||
#MaxAuthTries 6
|
||||
#MaxSessions 10
|
||||
|
||||
#PubkeyAuthentication yes
|
||||
|
||||
# Expect .ssh/authorized_keys2 to be disregarded by default in future.
|
||||
#AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2
|
||||
|
||||
#AuthorizedPrincipalsFile none
|
||||
|
||||
#AuthorizedKeysCommand none
|
||||
#AuthorizedKeysCommandUser nobody
|
||||
|
||||
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
|
||||
#HostbasedAuthentication no
|
||||
# Change to yes if you don't trust ~/.ssh/known_hosts for
|
||||
# HostbasedAuthentication
|
||||
#IgnoreUserKnownHosts no
|
||||
# Don't read the user's ~/.rhosts and ~/.shosts files
|
||||
#IgnoreRhosts yes
|
||||
|
||||
# To disable tunneled clear text passwords, change to no here!
|
||||
#PasswordAuthentication yes
|
||||
#PermitEmptyPasswords no
|
||||
|
||||
# Change to yes to enable challenge-response passwords (beware issues with
|
||||
# some PAM modules and threads)
|
||||
KbdInteractiveAuthentication no
|
||||
|
||||
# Kerberos options
|
||||
#KerberosAuthentication no
|
||||
#KerberosOrLocalPasswd yes
|
||||
#KerberosTicketCleanup yes
|
||||
#KerberosGetAFSToken no
|
||||
|
||||
# GSSAPI options
|
||||
#GSSAPIAuthentication no
|
||||
#GSSAPICleanupCredentials yes
|
||||
#GSSAPIStrictAcceptorCheck yes
|
||||
#GSSAPIKeyExchange no
|
||||
|
||||
# Set this to 'yes' to enable PAM authentication, account processing,
|
||||
# and session processing. If this is enabled, PAM authentication will
|
||||
# be allowed through the KbdInteractiveAuthentication and
|
||||
# PasswordAuthentication. Depending on your PAM configuration,
|
||||
# PAM authentication via KbdInteractiveAuthentication may bypass
|
||||
# the setting of "PermitRootLogin prohibit-password".
|
||||
# If you just want the PAM account and session checks to run without
|
||||
# PAM authentication, then enable this but set PasswordAuthentication
|
||||
# and KbdInteractiveAuthentication to 'no'.
|
||||
UsePAM yes
|
||||
|
||||
#AllowAgentForwarding yes
|
||||
#AllowTcpForwarding yes
|
||||
#GatewayPorts no
|
||||
X11Forwarding yes
|
||||
#X11DisplayOffset 10
|
||||
#X11UseLocalhost yes
|
||||
#PermitTTY yes
|
||||
PrintMotd no
|
||||
#PrintLastLog yes
|
||||
#TCPKeepAlive yes
|
||||
#PermitUserEnvironment no
|
||||
#Compression delayed
|
||||
#ClientAliveInterval 0
|
||||
#ClientAliveCountMax 3
|
||||
#UseDNS no
|
||||
#PidFile /run/sshd.pid
|
||||
#MaxStartups 10:30:100
|
||||
#PermitTunnel no
|
||||
#ChrootDirectory none
|
||||
#VersionAddendum none
|
||||
|
||||
# no default banner path
|
||||
#Banner none
|
||||
|
||||
# Allow client to pass locale environment variables
|
||||
AcceptEnv LANG LC_*
|
||||
|
||||
# override default of no subsystems
|
||||
Subsystem sftp /usr/lib/openssh/sftp-server
|
||||
|
||||
# Example of overriding settings on a per-user basis
|
||||
#Match User anoncvs
|
||||
# X11Forwarding no
|
||||
# AllowTcpForwarding no
|
||||
# PermitTTY no
|
||||
# ForceCommand cvs server
|
||||
29
roles/deploy_ssh_key/tasks/main.yml
Normal file
29
roles/deploy_ssh_key/tasks/main.yml
Normal file
@@ -0,0 +1,29 @@
|
||||
---
|
||||
- name: S'assurer que le répertoire .ssh existe
|
||||
file:
|
||||
path: "~/.ssh"
|
||||
state: directory
|
||||
mode: '0700'
|
||||
|
||||
- name: Ajouter la clé publique au fichier authorized_keys
|
||||
ansible.posix.authorized_key:
|
||||
user: root
|
||||
state: present
|
||||
key: "{{ lookup('file', '/home/riesjack/.ssh/ansible.pub') }}"
|
||||
|
||||
- name: Ajouter la clé publique au fichier authorized_keys
|
||||
ansible.posix.authorized_key:
|
||||
user: root
|
||||
state: present
|
||||
key: "{{ lookup('file', '/home/riesjack/.ssh/riesjack.pub') }}"
|
||||
|
||||
- name: Inject ssh config to remove open ssh root
|
||||
copy:
|
||||
src: ../files/sshd_config
|
||||
dest: /etc/ssh/sshd_config
|
||||
|
||||
- name: Restart SSH service
|
||||
ansible.builtin.systemd:
|
||||
name: ssh
|
||||
state: restarted
|
||||
enabled: yes
|
||||
13
roles/prometheus-agent/tasks/main.yml
Normal file
13
roles/prometheus-agent/tasks/main.yml
Normal file
@@ -0,0 +1,13 @@
|
||||
---
|
||||
- name: Install Prometheus Package
|
||||
apt:
|
||||
name: prometheus-node-exporter
|
||||
state: present
|
||||
update_cache: yes
|
||||
|
||||
- name: Activate & Start Node Exporter daemon service
|
||||
ansible.builtin.systemd:
|
||||
name: prometheus-node-exporter
|
||||
enabled: yes
|
||||
state: started
|
||||
...
|
||||
0
roles/prometheus_config/tasks/main.yml
Normal file
0
roles/prometheus_config/tasks/main.yml
Normal file
44
roles/prometheus_config/templates/prometheus.yml
Normal file
44
roles/prometheus_config/templates/prometheus.yml
Normal file
@@ -0,0 +1,44 @@
|
||||
# Sample config for Prometheus.
|
||||
|
||||
global:
|
||||
scrape_interval: 15s # Set the scrape interval to every 15 seconds. Default is every 1 minute.
|
||||
evaluation_interval: 15s # Evaluate rules every 15 seconds. The default is every 1 minute.
|
||||
# scrape_timeout is set to the global default (10s).
|
||||
|
||||
# Attach these labels to any time series or alerts when communicating with
|
||||
# external systems (federation, remote storage, Alertmanager).
|
||||
external_labels:
|
||||
monitor: 'example'
|
||||
|
||||
# Alertmanager configuration
|
||||
alerting:
|
||||
alertmanagers:
|
||||
- static_configs:
|
||||
- targets: ['localhost:9093']
|
||||
|
||||
# Load rules once and periodically evaluate them according to the global 'evaluation_interval'.
|
||||
rule_files:
|
||||
# - "first_rules.yml"
|
||||
# - "second_rules.yml"
|
||||
|
||||
# A scrape configuration containing exactly one endpoint to scrape:
|
||||
# Here it's Prometheus itself.
|
||||
scrape_configs:
|
||||
# The job name is added as a label `job=<job_name>` to any timeseries scraped from this config.
|
||||
- job_name: 'prometheus'
|
||||
|
||||
# Override the global default and scrape targets from this job every 5 seconds.
|
||||
scrape_interval: 5s
|
||||
scrape_timeout: 5s
|
||||
|
||||
# metrics_path defaults to '/metrics'
|
||||
# scheme defaults to 'http'.
|
||||
|
||||
static_configs:
|
||||
- targets: ['localhost:9090']
|
||||
|
||||
- job_name: node
|
||||
# If prometheus-node-exporter is installed, grab stats about the local
|
||||
# machine by default.
|
||||
static_configs:
|
||||
- targets: ['localhost:9100']
|
||||
17
roles/proxmox/tasks/ct_create.yml
Normal file
17
roles/proxmox/tasks/ct_create.yml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
- name: Create new container
|
||||
community.general.proxmox:
|
||||
node: "{{ proxmox_node }}"
|
||||
api_host: "{{ proxmox_api_host }}"
|
||||
api_user: "{{ proxmox_api_user }}"
|
||||
api_password: "{{ proxmox_api_password }}"
|
||||
hostname: "{{ proxmox_ct_create_hostname }}"
|
||||
pubkey: "{{ proxmox_ct_create_pubkey }}"
|
||||
ostemplate: "{{ proxmox_ct_create_ostemplate }}"
|
||||
cores: 2
|
||||
memory: "{{ proxmox_ct_create_ram }}"
|
||||
swap: "{{ proxmox_ct_create_swap}}"
|
||||
netif: "{{ proxmox_ct_create_net_config }}"
|
||||
vmid: "{{ proxmox_ct_create_vmid | default(999999) }}"
|
||||
tags: "{{ proxmox_ct_create_tags}}"
|
||||
...
|
||||
25
roles/proxmox/tasks/ct_remove.yml
Normal file
25
roles/proxmox/tasks/ct_remove.yml
Normal file
@@ -0,0 +1,25 @@
|
||||
---
|
||||
- name: Get VMID
|
||||
ansible.builtin.shell: >-
|
||||
pct list | awk '{print $1,$3}' | grep -E '^[0-9]+ {{ proxmox_ct_name }}$'| awk '{print $1}'
|
||||
args:
|
||||
executable: /bin/bash
|
||||
register: vmid
|
||||
delegate_to: "{{ proxmox_node }}"
|
||||
|
||||
|
||||
- name: Stop container
|
||||
community.general.proxmox:
|
||||
vmid: "{{ vmid.stdout }}"
|
||||
api_user: "{{ proxmox_api_user }}"
|
||||
api_password: "{{ proxmox_api_password }}"
|
||||
api_host: "{{ proxmox_api_host }}"
|
||||
state: stopped
|
||||
|
||||
- name: Remove container
|
||||
community.general.proxmox:
|
||||
vmid: "{{ vmid.stdout }}"
|
||||
api_user: "{{ proxmox_api_user }}"
|
||||
api_password: "{{ proxmox_api_password }}"
|
||||
api_host: "{{ proxmox_api_host }}"
|
||||
state: absent
|
||||
18
roles/proxmox/tasks/main.yml
Normal file
18
roles/proxmox/tasks/main.yml
Normal file
@@ -0,0 +1,18 @@
|
||||
---
|
||||
- name: Proxmox Create new container
|
||||
ansible.builtin.include_tasks:
|
||||
file: ct_create.yml
|
||||
apply:
|
||||
tags:
|
||||
- ct_create
|
||||
tags:
|
||||
- always
|
||||
|
||||
- name: Proxmox Remove contrainer
|
||||
ansible.builtin.include_tasks:
|
||||
file: ct_remove.yml
|
||||
apply:
|
||||
tags:
|
||||
- ct_remove
|
||||
tags:
|
||||
- always
|
||||
4
roles/proxmox/tasks/test.yml
Normal file
4
roles/proxmox/tasks/test.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
---
|
||||
- name: Testing
|
||||
ansible.builtin.debug:
|
||||
msg: "nzefùînfùaineaùzifnazùeifnaze"
|
||||
17
roles/proxmox/vars/main.yml
Normal file
17
roles/proxmox/vars/main.yml
Normal file
@@ -0,0 +1,17 @@
|
||||
---
|
||||
proxmox_api_host: 192.168.1.252
|
||||
proxmox_api_user: api@pve
|
||||
proxmox_api_password: JeSuisUneAPI!!
|
||||
############################################
|
||||
proxmox_ct_create_pubkey: ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAqvnjzBjQ5xbuAHeKnpRl4vTU1amyZLB+3O1YfYvpya
|
||||
proxmox_ct_name: 7d2d
|
||||
proxmox_node: pve-portable
|
||||
proxmox_ct_create_hostname: "{{ proxmox_ct_name }}"
|
||||
proxmox_ct_create_ostemplate: local:vztmpl/debian-12-standard_12.7-1_amd64.tar.zst
|
||||
proxmox_ct_create_net_config: {net0: "name=eth0,gw=192.168.1.1,ip=192.168.1.121/24,bridge=vmbr0"}
|
||||
proxmox_ct_create_ram: 16384
|
||||
proxmox_ct_create_swap: 4096
|
||||
proxmox_ct_create_vmid: 5000
|
||||
proxmox_ct_create_tags: 7d2d,steamcmd,debian12
|
||||
steamcmd_game_server_id: 294420
|
||||
...
|
||||
50
roles/proxmox/vars/vault.yml
Normal file
50
roles/proxmox/vars/vault.yml
Normal file
@@ -0,0 +1,50 @@
|
||||
$ANSIBLE_VAULT;1.1;AES256
|
||||
30326363333936333832363034343736613433393666333632373130666538346462343939353834
|
||||
6230636533616432643362643539313466636631356630640a346331666539316161343166353034
|
||||
64393035333062616436626634373135653332303062343335663833656433343337393663343239
|
||||
6366303037353266370a353861396564383333376531646138663930383462616362663331343435
|
||||
33616437656363326134616165653837303133653330386138363766363335626161346630646233
|
||||
36616334663862396237366263323761663932623036323234306235633363663233333534303739
|
||||
31363466356236366230613264313435366163346237363030373639663836393831653936313164
|
||||
38383232626364353639613934336263323436383938383439666239613037383134363735353931
|
||||
38646437333565356261663861373231633832373865643866643631323963373330643862643736
|
||||
39623933643836373563343265626330383030366630383134633862346262323036656134666636
|
||||
66633662396330643063626532663937373961633332643330663235323263666230636635363639
|
||||
63353261663636343165663135343763626431393639633263636233376164663465653565343235
|
||||
36343734633531316133366432626636396564343461336432313738363035626630383930626663
|
||||
37303537656566353131653465663063373263623163313337313764343166323937386165636439
|
||||
34326333306637313437616561393038313335613966353039323735663136303066643462613236
|
||||
32376236613235653933633363653635373266313935373439316332313137353565383237646434
|
||||
63313234313165393262616635363631613566323837626537323034303232356632303933333562
|
||||
35396465633431303938393363386565653361343239643962613930366163633835396139323963
|
||||
38376130373431363330646263336463636236346534303231396635386262663730373039356139
|
||||
33323065393562366337333637303064613232306436613637356566386334623064386163616235
|
||||
31376539393163643734616337663934653032393134346563396564383431383332393363646164
|
||||
64333566326166323664363762663462343963386635656163313337613064386161656332316531
|
||||
66333330613166323933323931343031353862646335633836353439323933643464373335373737
|
||||
34326236353937343462623635326564633633613535353664613538383634316565653433306437
|
||||
35636635363230343533653566636236376638613162336139663364373733383537353662656230
|
||||
33656263613530313132393836343263623661656638383639363739313339333434353062623933
|
||||
38653230666430323337353632326663623334353163316533336236663137393435346236316338
|
||||
61616465356131373033323832333135633735333632363965646230633434663838383263393334
|
||||
62366162333134323239653831356130393564363132376437343433343237626566333064343565
|
||||
63333665336565343161353663363763616530613836383061646536363133373838626661373830
|
||||
39333764616334356563393737343466306638363336333962353331613737303865326436613036
|
||||
33333061306631313931623962353135396366373731623830393466663933386662393635336433
|
||||
61353636653233316564343761643139313365373866363561353839623666373338356631366536
|
||||
65356264303636613961373234356337636563663937656563336263326637643234363839336237
|
||||
33363862333265636261393062643339333734323532663930346363666337613635383733663161
|
||||
37353265666634626339386131353161313339613935396239333164306131666665613063353539
|
||||
63376235623136373934353932383433333937393032363338636165383864313761663961636537
|
||||
33626336623335306536666235336532396536383935663865643862653231613630343463646632
|
||||
61326563386266363463396136366136306662363638616132666364333733643037336363613361
|
||||
36306539326561663866663765643738376536326131626431666466323661313835623866343736
|
||||
63326135643434626264313866346165373062393532323132323364626265393132373337316536
|
||||
65636130313063363938373138636530353662343861363961366563633032393961366338653263
|
||||
61373065303162356566633239326437376130383739393666343566303464663333373634636638
|
||||
30663236313931393830336265363336656261333764373230373936623463373662383238336165
|
||||
32386233323836663839333731383763663236616533633234363838333334363737323538376266
|
||||
66613764623761356365303336343731633139363763383531353361303031653465343539623538
|
||||
31643961646234643436356433333830613037623464373566626632303839646539383061386335
|
||||
30303465366334663536326165346139633236396538383138313862383833653138353164393931
|
||||
3030
|
||||
11
roles/steamcmd/tasks/install_gameserver.yml
Normal file
11
roles/steamcmd/tasks/install_gameserver.yml
Normal file
@@ -0,0 +1,11 @@
|
||||
---
|
||||
- name: Create specific {{ steam_cmd_game_name }} server directory
|
||||
ansible.builtin.file:
|
||||
path: "{{ steamcmd_game_server_path }}"
|
||||
state: directory
|
||||
mode: 755
|
||||
|
||||
- name: Install game server from steamcmd
|
||||
ansible.builtin.shell: /usr/games/steamcmd +force_install_dir "{{ steamcmd_game_server_path }}" +login anonymous +app_update "{{ steamcmd_game_server_id }}" +quit
|
||||
args:
|
||||
executable: /bin/bash
|
||||
31
roles/steamcmd/tasks/install_steamcmd.yml
Normal file
31
roles/steamcmd/tasks/install_steamcmd.yml
Normal file
@@ -0,0 +1,31 @@
|
||||
---
|
||||
- name: Update APT cache
|
||||
ansible.builtin.apt:
|
||||
update_cache: yes
|
||||
|
||||
- name: Install software-properties-common package (Debian)
|
||||
ansible.builtin.apt:
|
||||
name: software-properties-common
|
||||
update_cache: yes
|
||||
|
||||
- name: Install sudo package (Debian)
|
||||
ansible.builtin.apt:
|
||||
name: sudo
|
||||
|
||||
- name: Install steamcmd on debian 12
|
||||
ansible.builtin.shell: |
|
||||
sudo apt update -y; sudo apt install software-properties-common -y ; sudo apt-add-repository non-free -y; sudo dpkg --add-architecture i386; sudo apt update -y
|
||||
sudo apt install steamcmd -y
|
||||
|
||||
|
||||
# - name: Install dependences and steamcmd package
|
||||
# ansible.builtin.shell: |
|
||||
# apt upgrade -y
|
||||
# apt-add-repository -yn non-free non-free-firmware
|
||||
# dpkg --add-architecture i386
|
||||
# echo steam steam/license note '' | debconf-set-selections
|
||||
# echo steam steam/question select "I AGREE" | debconf-set-selections
|
||||
# apt update -y
|
||||
# ACCEPT_EULA=Y apt install steamcmd -y
|
||||
# args:
|
||||
# executable: /bin/bash
|
||||
19
roles/steamcmd/tasks/main.yml
Normal file
19
roles/steamcmd/tasks/main.yml
Normal file
@@ -0,0 +1,19 @@
|
||||
---
|
||||
- name: SteamCMD Installer
|
||||
include_tasks:
|
||||
file: install_steamcmd.yml
|
||||
apply:
|
||||
tags:
|
||||
- install_steamcmd
|
||||
tags:
|
||||
- always
|
||||
|
||||
|
||||
- name: SteamCMD - Install game server
|
||||
include_tasks:
|
||||
file: install_gameserver.yml
|
||||
apply:
|
||||
tags:
|
||||
- install_gameserver
|
||||
tags: always
|
||||
...
|
||||
3
roles/steamcmd/vars/main.yml
Normal file
3
roles/steamcmd/vars/main.yml
Normal file
@@ -0,0 +1,3 @@
|
||||
steam_cmd_game_name: ark
|
||||
steamcmd_game_server_path: "/srv/{{ steam_cmd_game_name }}"
|
||||
steamcmd_game_server_id: 376030
|
||||
Reference in New Issue
Block a user