# All hosts are debian 10 --- # Common - hosts: daily,compute,nfs,router become: yes handlers: - import_tasks: handlers.yml tasks: # Core - name: Install common packages apt: name: - apt-listchanges - chrony - curl - dma - git - htop - iperf3 - mosh - nmap - oidentd - rsync - smartmontools - snapd - speedtest-cli - tmux - unattended-upgrades - vim force_apt_get: yes update_cache: yes - name: Disable MOTDs command: chmod -x /etc/update-motd.d/10-uname args: warn: no - name: Set MOTD copy: src: files/motd dest: /etc/motd owner: root group: root mode: '0644' # TODO Change defaults - name: Configure unattended-upgrades copy: src: files/50unattended-upgrades dest: /etc/apt/apt.conf.d/50unattended-upgrades owner: root group: root mode: '0644' - name: Enable auto-upgrades copy: src: files/20auto-upgrades dest: /etc/apt/apt.conf.d/20auto-upgrades owner: root group: root mode: '0644' - name: Disable power and reset buttons copy: src: files/logind.conf dest: /etc/systemd/logind.conf owner: root group: root mode: '0644' notify: Restart systemd-logind service - name: Set chrony ntp servers copy: src: files/chrony.conf dest: /etc/chrony/chrony.conf owner: root group: root mode: '0644' notify: Restart chrony service # Core networking - name: Configure sshd_config to listen on 37121/2222/22 and disable password auth copy: src: files/sshd_config dest: /etc/ssh/sshd_config owner: root group: root mode: '0644' notify: Restart sshd service ## Changes will take effect during next reboot ## (determined by unattended-upgrades) - name: Configure sysctl with IPv6 privacy extensions template: src: templates/local.conf.j2 dest: /etc/sysctl.d/local.conf owner: root group: root mode: '0644' - name: Configure dma copy: src: files/dma.conf dest: /etc/dma/dma.conf owner: root group: mail mode: '0640' - debug: msg: 'Manually configure /etc/dma/auth.conf' - name: Configure smartd copy: src: files/smartd.conf dest: /etc/smartd.conf owner: root group: root mode: '0644' notify: Restart and enable smartd - name: Copy Dynamic DNS script template: src: templates/gandi-ddns.sh dest: /usr/local/bin/gandi-ddns.sh owner: root group: root mode: '0755' - name: Add Dynamic DNS cronjob cron: name: "Update dynamic dns" job: /usr/local/bin/gandi-ddns.sh special_time: daily user: root ### Router ##- hosts: router ## become: yes ## tasks: ## - name: Install frrouting and related router packages ## - name: Configure bgp, etc??? # Media networking (Wireguard VPN, NFS) - hosts: compute,nfs become: yes handlers: - import_tasks: handlers.yml tasks: - name: Add unstable repository shell: | echo "deb http://deb.debian.org/debian/ unstable main" > /etc/apt/sources.list.d/unstable.list printf 'Package: *\nPin: release a=unstable\nPin-Priority: 90\n' > /etc/apt/preferences.d/limit-unstable args: creates: /etc/apt/sources.list.d/unstable.list - name: Install media networking packages apt: name: - beets - nfs-common force_apt_get: yes update_cache: yes - debug: msg: Manually do beets config https://wiki.archlinux.org/index.php/Beets # NFS core config # ASSUMES /bigdata IS CONFIGURED (make sure dir is 755) - hosts: nfs become: yes handlers: - import_tasks: handlers.yml tasks: - name: Install zfs-zed, dma, and nfs-kernel-server apt: name: - dma - nfs-kernel-server - zfs-auto-snapshot - zfs-zed force_apt_get: yes update_cache: yes - name: Configure zfs-zed copy: src: files/zed.rc dest: /etc/zfs/zed.d/zed.rc owner: root group: root mode: '0644' notify: Restart zfs-zed - name: Install weekly bigdata scrub cron job cron: name: 'Scrub bigdata zfs pool' special_time: weekly job: 'zpool scrub bigdata' user: root - name: Install rclone apt: deb: https://github.com/rclone/rclone/releases/download/v1.49.2/rclone-v1.49.2-linux-amd64.deb force_apt_get: yes - debug: msg: Manually configure rclone remote drive - name: Export /bigdata copy: src: files/exports dest: /etc/exports owner: root group: root mode: '0644' notify: Re-export exportfs # Compute core config - hosts: compute become: yes tasks: - name: Install compute dependencies apt: name: - apt-transport-https - ca-certificates - gnupg2 - software-properties-common - sshfs force_apt_get: yes update_cache: yes - name: Mount bigdummy /bigdata via NFS mount: src: root@10.42.0.202:/bigdata path: /bigdata fstype: fuse.sshfs opts: reconnect,allow_other,_netdev,nonempty,IdentityFile=/home/paul/.ssh/id_rsa_fast state: mounted - name: Mount vtluug /media via sshfs mount: src: pew-media@dirtycow.vtluug.org:/nfs/cistern/share/media path: /media-vtluug fstype: fuse.sshfs opts: reconnect,allow_other,ro,_netdev,IdentityFile=/home/paul/.ssh/id_rsa_fast state: mounted - name: Add HAProxy GPG key apt_key: url: https://haproxy.debian.net/bernat.debian.org.gpg - name: Add HAProxy APT repository apt_repository: repo: deb http://haproxy.debian.net buster-backports-2.2 main - name: Install HAProxy apt: name: haproxy state: present force_apt_get: yes update_cache: yes - name: Install microk8s command: snap install microk8s --classic args: creates: /snap/bin/microk8s - debug: msg: - Start/Configure haproxy manually - Start microk8s manually