Compare commits
22 Commits
v0.0.7d-ld
...
main
Author | SHA1 | Date | |
---|---|---|---|
35c46449fa | |||
575a2fa87a | |||
|
30b74c50e2 | ||
597ff383f7 | |||
c482540de6 | |||
ce37973f9d | |||
|
a2c1636a0f | ||
|
d107c26449 | ||
|
d0efb480c8 | ||
|
be47dbabd2 | ||
24d8892b4c | |||
|
2c828574ef | ||
|
a5f0d258a5 | ||
|
52b9f3af87 | ||
8dc1f9a891 | |||
|
0d3860211b | ||
|
7a2311ae25 | ||
|
ebcd50bf69 | ||
|
30eeabb58b | ||
|
542978fd75 | ||
b7d8e6e9d4 | |||
|
ea4ecb2fae |
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2023040501 ; Serial
|
2023051000 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -36,4 +36,5 @@ s-web2 IN A 192.168.101.2
|
|||||||
s-lb.gsb.lan IN A 192.168.100.10
|
s-lb.gsb.lan IN A 192.168.100.10
|
||||||
ns IN CNAME s-infra.gsb.lan.
|
ns IN CNAME s-infra.gsb.lan.
|
||||||
wpad IN CNAME s-infra.gsb.lan.
|
wpad IN CNAME s-infra.gsb.lan.
|
||||||
peertube IN A 192.168.100.20
|
s-peertube IN A 192.168.100.20
|
||||||
|
peertube IN CNAME s-peertube
|
||||||
|
@ -28,4 +28,3 @@ $TTL 604800
|
|||||||
11.0 IN PTR s-elk.gsb.lan.
|
11.0 IN PTR s-elk.gsb.lan.
|
||||||
17.0 IN PTR s-gestsup.lan
|
17.0 IN PTR s-gestsup.lan
|
||||||
254.0 IN PTR r-int.gsb.lan.
|
254.0 IN PTR r-int.gsb.lan.
|
||||||
100.20 IN PTR s-peertube
|
|
||||||
|
@ -22,5 +22,5 @@
|
|||||||
command: "cp /root/tools/ansible/roles/fog/files/fogsettings /opt/fog/"
|
command: "cp /root/tools/ansible/roles/fog/files/fogsettings /opt/fog/"
|
||||||
|
|
||||||
- name: fichier fogsettings en .fogsettings
|
- name: fichier fogsettings en .fogsettings
|
||||||
command: "mv /opt/fog/fogsettings /opt/fog/.fogsettings"
|
command: "mv /opt/fog/fogsettings /opt/fog/.fogsettings"
|
||||||
|
|
||||||
|
@ -51,6 +51,7 @@ table filter {
|
|||||||
chain FORWARD {
|
chain FORWARD {
|
||||||
policy ACCEPT;
|
policy ACCEPT;
|
||||||
|
|
||||||
|
proto icmp icmp-type echo-request ACCEPT;
|
||||||
# connection tracking
|
# connection tracking
|
||||||
mod state state INVALID DROP;
|
mod state state INVALID DROP;
|
||||||
mod state state (ESTABLISHED RELATED) ACCEPT;
|
mod state state (ESTABLISHED RELATED) ACCEPT;
|
||||||
|
@ -14,7 +14,7 @@
|
|||||||
host: localhost
|
host: localhost
|
||||||
|
|
||||||
- name: installation de k3s...
|
- name: installation de k3s...
|
||||||
shell: curl -sfL https://get.k3s.io | sh -s - --docker
|
shell: curl -sfL https://get.k3s.io | INSTALL_K3S_EXEC="--node-ip=192.168.100.20 --flannel-iface=enp0s8" sh -s - --docker
|
||||||
|
|
||||||
- name: attente de l'installation de k3s...
|
- name: attente de l'installation de k3s...
|
||||||
wait_for:
|
wait_for:
|
||||||
|
9
roles/peertube/files/finish
Normal file
9
roles/peertube/files/finish
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
MYHOST=peertube.gsb.lan;
|
||||||
|
export KUBECONFIG=/etc/rancher/k3s/k3s.yaml;
|
||||||
|
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.cert -subj /CN="${MYHOST}"/O="${MYHOST}" -addext "subjectAltName = DNS:${MYHOST}";
|
||||||
|
kubectl create secret tls tls-peertube --key tls.key --cert tls.cert;
|
||||||
|
helm repo add postgresql https://charts.bitnami.com/bitnami;
|
||||||
|
helm repo add redis https://charts.bitnami.com/bitnami;
|
||||||
|
helm repo add mail https://bokysan.github.io/docker-postfix;
|
||||||
|
helm install --create-namespace -n peertube peertube-gsb /root/tools/peertube/helm/ ;
|
||||||
|
kubectl config view --raw > ~/.kube/config
|
@ -1 +1,4 @@
|
|||||||
|
domain gsb.lan
|
||||||
|
search gsb.lan
|
||||||
|
nameserver 172.16.0.1
|
||||||
nameserver 192.168.99.99
|
nameserver 192.168.99.99
|
@ -45,7 +45,7 @@ peertube:
|
|||||||
dbPasswd: user # must be consistent with postgresql configuration
|
dbPasswd: user # must be consistent with postgresql configuration
|
||||||
dbSsl: false # disabled by default WARNING: ssl connection feature not tested, use at your own risk
|
dbSsl: false # disabled by default WARNING: ssl connection feature not tested, use at your own risk
|
||||||
dbHostname: peertube-gsb-postgresql # must be consistent with postgresql configuration
|
dbHostname: peertube-gsb-postgresql # must be consistent with postgresql configuration
|
||||||
webHostname: s-peertube.gsb.lan # must be changed to your local setup
|
webHostname: peertube.gsb.lan # must be changed to your local setup
|
||||||
secret: b2753b0f37444974de0e81f04815e6a889fcf8960bd203a01b624d8fa8a37683
|
secret: b2753b0f37444974de0e81f04815e6a889fcf8960bd203a01b624d8fa8a37683
|
||||||
smtpHostname: peertube-gsb-mail # must be consistent with mail configuration
|
smtpHostname: peertube-gsb-mail # must be consistent with mail configuration
|
||||||
smtpPort: 587 # must be consistent with mail configuration
|
smtpPort: 587 # must be consistent with mail configuration
|
||||||
@ -98,21 +98,21 @@ redis:
|
|||||||
|
|
||||||
## ingress configuration is very specific this part must be configured or else you'll get 503 or 404 errors
|
## ingress configuration is very specific this part must be configured or else you'll get 503 or 404 errors
|
||||||
ingress:
|
ingress:
|
||||||
enabled: false
|
enabled: true
|
||||||
className: ""
|
className: ""
|
||||||
annotations:
|
annotations:
|
||||||
kubernetes.io/ingress.class: nginx
|
kubernetes.io/ingress.class: traefik
|
||||||
nginx.ingress.kubernetes.io/proxy-body-size: 4G # this caps the size of imported videos, if set low this might prevent you from uploading videos
|
traefik.ingress.kubernetes.io/proxy-body-size: 6G # this caps the size of imported videos, if set low this might prevent you from uploading videos
|
||||||
# kubernetes.io/tls-acme: "true"
|
# kubernetes.io/tls-acme: "true"
|
||||||
hosts:
|
hosts:
|
||||||
- host: # your domain here
|
- host: peertube.gsb.lan
|
||||||
paths:
|
paths:
|
||||||
- path: /
|
- path: /
|
||||||
pathType: ImplementationSpecific
|
pathType: ImplementationSpecific
|
||||||
tls:
|
tls:
|
||||||
# - secretName: chart-example-tls
|
- secretName: tls-peertube
|
||||||
- hosts:
|
- hosts:
|
||||||
- # your domain here
|
- peertube.gsb.lan
|
||||||
|
|
||||||
resources: {}
|
resources: {}
|
||||||
autoscaling:
|
autoscaling:
|
||||||
|
@ -18,17 +18,11 @@
|
|||||||
dest: /root/tools/peertube/helm/
|
dest: /root/tools/peertube/helm/
|
||||||
mode: '0644'
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: copie du script finish...
|
||||||
|
copy:
|
||||||
|
src: /root/tools/ansible/gsb2023/roles/peertube/files/finish
|
||||||
|
dest: /root
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
- name: installation de helm...
|
- name: installation de helm...
|
||||||
shell: curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
shell: curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
||||||
|
|
||||||
- name: exposition du cluster...
|
|
||||||
command: KUBECONFIG=/etc/rancher/k3s/k3s.yaml
|
|
||||||
|
|
||||||
- name: mise a jour de la configuration de kubectl...
|
|
||||||
command: kubectl config view --raw > ~/.kube/config
|
|
||||||
|
|
||||||
- name: installation de peertube...
|
|
||||||
shell: helm repo add postgresql https://charts.bitnami.com/bitnami && helm repo add redis https://charts.bitnami.com/bitnami && helm repo add mail https://bokysan.github.io/docker-postfix
|
|
||||||
|
|
||||||
- name: lancement du helm chart peertube...
|
|
||||||
shell: helm install --create-namespace -n peertube peertube-gsb /root/tools/peertube/helm/
|
|
||||||
|
@ -34,4 +34,4 @@ iface enp0s10 inet static
|
|||||||
allow-hotplug enp0s16
|
allow-hotplug enp0s16
|
||||||
iface enp0s16 inet static
|
iface enp0s16 inet static
|
||||||
address 172.16.0.254/24
|
address 172.16.0.254/24
|
||||||
|
post-up sleep 10 && systemctl restart isc-dhcp-server
|
||||||
|
@ -17,3 +17,13 @@
|
|||||||
|
|
||||||
#- name: extraction fog.tar.gz
|
#- name: extraction fog.tar.gz
|
||||||
#unarchive: src=/tmp/fog.tar.gz dest=/var/www/ copy=no
|
#unarchive: src=/tmp/fog.tar.gz dest=/var/www/ copy=no
|
||||||
|
|
||||||
|
#- name: delais 2 secondes isc-dhcp-service
|
||||||
|
# become: yes
|
||||||
|
# lineinfile:
|
||||||
|
# path: /etc/init.d/isc-dhcp-server
|
||||||
|
# insertafter: '^\s+start\)$'
|
||||||
|
# line: " sleep 2"
|
||||||
|
# firstmatch: yes
|
||||||
|
# state: present
|
||||||
|
# backup: yes
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
#ajout du sleep 5
|
# ajout du sleep 5
|
||||||
|
|
||||||
éditer "/etc/init.d/isc-dhcp-server"
|
~~éditer "/etc/init.d/isc-dhcp-server"~~
|
||||||
aller au "case \"$1\" in" et rajouter "sleep 5" avant le "if"
|
~~aller au "case \"$1\" in" et rajouter "sleep 5" avant le "if"~~
|
||||||
|
|
||||||
|
@ -1,3 +1,4 @@
|
|||||||
|
@echo off
|
||||||
net group gg-backup /ADD
|
net group gg-backup /ADD
|
||||||
call mkusr uBackup "u-backup" gg-backup
|
call mkusr uBackup "u-backup" gg-backup
|
||||||
icacls "C:\gsb\partages\public" /Grant:r uBackup:M /T
|
icacls "C:\gsb\partages\public" /Grant:r uBackup:M /T
|
@ -1,3 +1,4 @@
|
|||||||
|
@echo off
|
||||||
call mkusr aDupont "Albert Dupon" gg-compta
|
call mkusr aDupont "Albert Dupon" gg-compta
|
||||||
call mkusr cSeum "Claire Seum" gg-compta
|
call mkusr cSeum "Claire Seum" gg-compta
|
||||||
call mkusr nPaul "Nicolas Paul" gg-compta
|
call mkusr nPaul "Nicolas Paul" gg-compta
|
||||||
|
2
windows/mkusr-nextcloud.cmd
Normal file
2
windows/mkusr-nextcloud.cmd
Normal file
@ -0,0 +1,2 @@
|
|||||||
|
@echo off
|
||||||
|
call mkusr nextcloud "nextcloud" nextcloud
|
Loading…
x
Reference in New Issue
Block a user