Compare commits
13 Commits
v0.0.3f-ps
...
v0.0.3r-jm
Author | SHA1 | Date | |
---|---|---|---|
262b7bdb13 | |||
c45dc50d12 | |||
d1116a91c3 | |||
9c8dca44c9 | |||
ce3b6e0a77 | |||
a03298ed54 | |||
80b54a50df | |||
045af9bea2 | |||
6b10b981f4 | |||
3811e2df5c | |||
27aad0dcb5 | |||
c03c066d41 | |||
beca7dbdcc |
@ -90,8 +90,8 @@ bash chname <nouveau_nom_de_machine>` , puis redémarrer
|
|||||||
cd gsb2024/pre
|
cd gsb2024/pre
|
||||||
bash inst-depl
|
bash inst-depl
|
||||||
cd /root/tools/ansible/gsb2024/pre
|
cd /root/tools/ansible/gsb2024/pre
|
||||||
bash gsbboot
|
DEPL=192.168.99.99 bash gsbboot
|
||||||
cd .. ; bash pull-config
|
cd ../.. ; bash pull-config
|
||||||
```
|
```
|
||||||
- redémarrer
|
- redémarrer
|
||||||
- la machine **s-adm** doit etre opérationnelle
|
- la machine **s-adm** doit etre opérationnelle
|
||||||
@ -121,8 +121,7 @@ mkdir -p tools/ansible ; cd tools/ansible
|
|||||||
git clone https://gitea.lyc-lecastel.fr/gsb/gsb2024.git
|
git clone https://gitea.lyc-lecastel.fr/gsb/gsb2024.git
|
||||||
cd gsb2024/pre
|
cd gsb2024/pre
|
||||||
DEPL=192.168.99.99 bash gsbboot
|
DEPL=192.168.99.99 bash gsbboot
|
||||||
cd ../..
|
cd ../.. ; bash pull-config
|
||||||
bash pull-config
|
|
||||||
```
|
```
|
||||||
|
|
||||||
#### Etape 3
|
#### Etape 3
|
||||||
|
@ -1,7 +1,7 @@
|
|||||||
file:
|
file:
|
||||||
/etc/wireguard/wg0.conf:
|
/etc/wireguard/wg0.conf:
|
||||||
exists: true
|
exists: true
|
||||||
mode: "0644"
|
mode: "0600"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
filetype: file
|
filetype: file
|
||||||
@ -10,11 +10,11 @@ package:
|
|||||||
wireguard:
|
wireguard:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1
|
||||||
wireguard-tools:
|
wireguard-tools:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1+b1
|
||||||
service:
|
service:
|
||||||
isc-dhcp-server:
|
isc-dhcp-server:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
@ -22,6 +22,8 @@
|
|||||||
192.168.99.14 s-nas.gsb.adm
|
192.168.99.14 s-nas.gsb.adm
|
||||||
192.168.99.15 s-san.gsb.adm
|
192.168.99.15 s-san.gsb.adm
|
||||||
192.168.99.16 s-fog.gsb.adm
|
192.168.99.16 s-fog.gsb.adm
|
||||||
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -21,6 +21,8 @@
|
|||||||
192.168.99.12 r-int.gsb.adm
|
192.168.99.12 r-int.gsb.adm
|
||||||
192.168.99.13 r-ext.gsb.adm
|
192.168.99.13 r-ext.gsb.adm
|
||||||
192.168.99.14 s-nas.gsb.adm
|
192.168.99.14 s-nas.gsb.adm
|
||||||
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2023051000 ; Serial
|
2024011500 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -27,6 +27,8 @@ s-mon IN A 172.16.0.8
|
|||||||
s-itil IN A 172.16.0.9
|
s-itil IN A 172.16.0.9
|
||||||
s-elk IN A 172.16.0.11
|
s-elk IN A 172.16.0.11
|
||||||
s-gestsup IN A 172.16.0.17
|
s-gestsup IN A 172.16.0.17
|
||||||
|
s-kea1 IN A 172.16.0.20
|
||||||
|
s-kea2 IN A 172.16.0.21
|
||||||
r-int IN A 172.16.0.254
|
r-int IN A 172.16.0.254
|
||||||
r-int-lnk IN A 192.168.200.254
|
r-int-lnk IN A 192.168.200.254
|
||||||
r-ext IN A 192.168.200.253
|
r-ext IN A 192.168.200.253
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2023040501 ; Serial
|
2024011500 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -21,6 +21,8 @@ $TTL 604800
|
|||||||
7.0 IN PTR s-nxc.gsb.lan.
|
7.0 IN PTR s-nxc.gsb.lan.
|
||||||
8.0 IN PTR s-mon.gsb.lan.
|
8.0 IN PTR s-mon.gsb.lan.
|
||||||
9.0 IN PTR s-itil.gsb.lan.
|
9.0 IN PTR s-itil.gsb.lan.
|
||||||
|
20.0 IN PTR s-kea1.gsb.lan.
|
||||||
|
21.0 IN PTR s-kea2.gsb.lan.
|
||||||
101.1 IN PTR s-web1
|
101.1 IN PTR s-web1
|
||||||
101.2 IN PTR s-web2
|
101.2 IN PTR s-web2
|
||||||
100.10 IN PTR s-lb
|
100.10 IN PTR s-lb
|
||||||
|
@ -42,7 +42,7 @@ tftpAdvOpts=''
|
|||||||
sslpath='/opt/fog/snapins/ssl/'
|
sslpath='/opt/fog/snapins/ssl/'
|
||||||
backupPath='/home/'
|
backupPath='/home/'
|
||||||
armsupport='0'
|
armsupport='0'
|
||||||
php_ver='8.2'
|
php_ver='7.4'
|
||||||
#php_verAdds='-7.4'
|
#php_verAdds='-7.4'
|
||||||
sslprivkey='/opt/fog/snapins/ssl//.srvprivate.key'
|
sslprivkey='/opt/fog/snapins/ssl//.srvprivate.key'
|
||||||
sendreports='Y'
|
sendreports='Y'
|
||||||
|
@ -4,7 +4,7 @@
|
|||||||
|
|
||||||
Ce role a pour objectif d'installer et d'éditer les fichiers de configuration de systemd journal remote afin que les machines lançant ce rôle puissent recevoir les logs des autres machine du parc.
|
Ce role a pour objectif d'installer et d'éditer les fichiers de configuration de systemd journal remote afin que les machines lançant ce rôle puissent recevoir les logs des autres machine du parc.
|
||||||
|
|
||||||
## Opérations réaliser par le role:
|
## Opérations réalisées par le role:
|
||||||
Le role réalise les opération suivante:
|
Le role réalise les opération suivante:
|
||||||
* installation du paquet **systemd-journal-remote**.
|
* installation du paquet **systemd-journal-remote**.
|
||||||
* Démarrage et activation (au démarrage) du service **systemd-journal-remote.socket.
|
* Démarrage et activation (au démarrage) du service **systemd-journal-remote.socket.
|
||||||
|
26
roles/post/files/interfaces.s-kea1
Normal file
26
roles/post/files/interfaces.s-kea1
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
# This file describes the network interfaces available on your system
|
||||||
|
# and how to activate them. For more information, see interfaces(5).
|
||||||
|
|
||||||
|
# The loopback network interface
|
||||||
|
auto lo
|
||||||
|
iface lo inet loopback
|
||||||
|
|
||||||
|
# cote N-adm
|
||||||
|
allow-hotplug enp0s3
|
||||||
|
iface enp0s3 inet static
|
||||||
|
address 192.168.99.20
|
||||||
|
netmask 255.255.255.0
|
||||||
|
gateway 192.168.99.99
|
||||||
|
|
||||||
|
|
||||||
|
# cote N-infra
|
||||||
|
allow-hotplug enp0s8
|
||||||
|
iface enp0s8 inet static
|
||||||
|
address 172.16.0.20
|
||||||
|
netmask 255.255.255.0
|
||||||
|
|
||||||
|
#cote N-user
|
||||||
|
allow-hotplug enp0s9
|
||||||
|
iface enp0s9 inet static
|
||||||
|
address 172.16.64.20
|
||||||
|
netmask 255.255.255.0
|
26
roles/post/files/interfaces.s-kea2
Normal file
26
roles/post/files/interfaces.s-kea2
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
# This file describes the network interfaces available on your system
|
||||||
|
# and how to activate them. For more information, see interfaces(5).
|
||||||
|
|
||||||
|
# The loopback network interface
|
||||||
|
auto lo
|
||||||
|
iface lo inet loopback
|
||||||
|
|
||||||
|
# cote N-adm
|
||||||
|
allow-hotplug enp0s3
|
||||||
|
iface enp0s3 inet static
|
||||||
|
address 192.168.99.21
|
||||||
|
netmask 255.255.255.0
|
||||||
|
gateway 192.168.99.99
|
||||||
|
|
||||||
|
|
||||||
|
# cote N-infra
|
||||||
|
allow-hotplug enp0s8
|
||||||
|
iface enp0s8 inet static
|
||||||
|
address 172.16.0.21
|
||||||
|
netmask 255.255.255.0
|
||||||
|
|
||||||
|
#cote N-user
|
||||||
|
allow-hotplug enp0s9
|
||||||
|
iface enp0s9 inet static
|
||||||
|
address 172.16.64.21
|
||||||
|
netmask 255.255.255.0
|
@ -18,25 +18,19 @@
|
|||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Enable Zabbix agent service
|
- name: Enable Zabbix agent service
|
||||||
systemd:
|
service:
|
||||||
name: zabbix-agent
|
name: zabbix-agent
|
||||||
state: restarted
|
state: restarted
|
||||||
enabled: yes
|
enabled: yes
|
||||||
|
|
||||||
- name: Rm package
|
- name: Replace Zabbix agent config
|
||||||
file:
|
replace:
|
||||||
path: "/tmp/zabbix-release_6.4-1+debian12_all.deb"
|
path: /etc/zabbix/zabbix_agentd.conf
|
||||||
state: absent
|
regexp: '{{ item.regexp }}'
|
||||||
|
replace: '{{ item.replace }}'
|
||||||
- name: config
|
backup: true
|
||||||
template:
|
loop:
|
||||||
src: zabbix_agentd.conf.temp
|
- { regexp: '^(Server\s*=\s*).*$', replace: 'Server = 127.0.0.1' }
|
||||||
dest: /etc/zabbix/zabbix_agentd.conf
|
- { regexp: '^(ServerActive\s*=\s*).*$', replace: 'ServerActive = 192.168.99.8' }
|
||||||
vars:
|
- { regexp: '^(Hostname\s*=\s*).*$', replace: 'Hostname = {{ ansible_hostname }}' }
|
||||||
PidFile: "/run/zabbix/zabbix_agentd.pid"
|
- { regexp: '^(Include\s*=\s*).*$', replace: 'Include = /etc/zabbix/zabbix_agentd.d/*.conf' }
|
||||||
LogFile: "/var/log/zabbix/zabbix_agentd.log"
|
|
||||||
LogFileSize: "0"
|
|
||||||
Server: "127.0.0.1"
|
|
||||||
ServerActive: "192.168.99.8"
|
|
||||||
Hostname: "{{ ansible_hostname }}"
|
|
||||||
Include: "/etc/zabbix/zabbix_agentd.d/*.conf"
|
|
||||||
|
@ -1,7 +0,0 @@
|
|||||||
PidFile={{ PidFile }}
|
|
||||||
LogFile={{ LogFile }}
|
|
||||||
LogFileSize={{ LogFileSize }}
|
|
||||||
Server={{ Server }}
|
|
||||||
ServerActive={{ ServerActive }}
|
|
||||||
Hostname={{ Hostname }}
|
|
||||||
Include={{ Include }}
|
|
@ -8,7 +8,7 @@
|
|||||||
- dnsmasq
|
- dnsmasq
|
||||||
- squid
|
- squid
|
||||||
# - local-store
|
# - local-store
|
||||||
# - zabbix-cli
|
# #- zabbix-cli
|
||||||
## - syslog-cli
|
## - syslog-cli
|
||||||
- post
|
- post
|
||||||
# - goss
|
# - goss
|
||||||
|
@ -8,7 +8,7 @@
|
|||||||
- appli
|
- appli
|
||||||
- ssh-cli
|
- ssh-cli
|
||||||
# - syslog-cli
|
# - syslog-cli
|
||||||
- zabbix-cli
|
#- zabbix-cli
|
||||||
- ssl-apache
|
- ssl-apache
|
||||||
- post
|
- post
|
||||||
|
|
||||||
|
@ -6,7 +6,7 @@
|
|||||||
- base
|
- base
|
||||||
- goss
|
- goss
|
||||||
# - proxy3
|
# - proxy3
|
||||||
- zabbix-cli
|
#- zabbix-cli
|
||||||
# - ssh-cli
|
# - ssh-cli
|
||||||
# - syslog-cli
|
# - syslog-cli
|
||||||
- smb-backup
|
- smb-backup
|
||||||
|
@ -5,10 +5,10 @@
|
|||||||
roles:
|
roles:
|
||||||
- base
|
- base
|
||||||
- goss
|
- goss
|
||||||
- dhcp-fog
|
#- dhcp-fog
|
||||||
- ssh-cli
|
# - ssh-cli
|
||||||
- snmp-agent
|
# - snmp-agent
|
||||||
# - syslog-cli
|
# - syslog-cli
|
||||||
# - fog
|
# - fog
|
||||||
- - journald-snd
|
#- - journald-snd
|
||||||
- post
|
- post
|
||||||
|
@ -4,7 +4,7 @@
|
|||||||
# include: config.yml
|
# include: config.yml
|
||||||
roles:
|
roles:
|
||||||
- base
|
- base
|
||||||
- zabbix-cli
|
#- zabbix-cli
|
||||||
- goss
|
- goss
|
||||||
- dns-master
|
- dns-master
|
||||||
- webautoconf
|
- webautoconf
|
||||||
|
@ -6,7 +6,7 @@
|
|||||||
- base
|
- base
|
||||||
- goss
|
- goss
|
||||||
- squid
|
- squid
|
||||||
- zabbix-cli
|
#- zabbix-cli
|
||||||
- ssh-cli
|
- ssh-cli
|
||||||
# - syslog-cli
|
# - syslog-cli
|
||||||
- post
|
- post
|
||||||
|
28
scripts/mkvm
28
scripts/mkvm
@ -1,19 +1,21 @@
|
|||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
mkvmrelease="v1.3.1"
|
mkvmrelease="v1.3.2"
|
||||||
|
|
||||||
ovarelease="2023c"
|
ovarelease="2023c"
|
||||||
ovafogrelease="2024a"
|
ovafogrelease="2024a"
|
||||||
#ovafile="$HOME/Téléchargements/debian-bullseye-gsb-${ovarelease}.ova"
|
#ovafile="$HOME/Téléchargements/debian-bullseye-gsb-${ovarelease}.ova"
|
||||||
ovafile="$HOME/Téléchargements/debian-bookworm-gsb-${ovarelease}.ova"
|
ovafile="$HOME/Téléchargements/debian-bookworm-gsb-${ovarelease}.ova"
|
||||||
ovafilefog="$HOME/Téléchargements/debian-bullseye-gsb-${ovafogrelease}.ova"
|
ovafilefog="$HOME/Téléchargements/debian-bullseye-gsb-${ovafogrelease}.ova"
|
||||||
|
startmode=0
|
||||||
deletemode=0
|
deletemode=0
|
||||||
|
|
||||||
usage () {
|
usage () {
|
||||||
echo "$0 - version ${mkvmrelease} - Ova version ${ovarelease}"
|
echo "$0 - version ${mkvmrelease} - Ova version ${ovarelease}"
|
||||||
echo "$0 : creation VM et parametrage interfaces"
|
echo "$0 : creation VM et parametrage interfaces"
|
||||||
echo "usage : $0 [-r] <s-adm|s-infra|r-int|r-ext|s-proxy|s-mon|s-appli|s-backup|s-itil|s-ncx|s-fog>"
|
echo "usage : $0 [-r] [-s] <s-adm|s-infra|r-int|r-ext|s-proxy|s-mon|s-appli|s-backup|s-itil|s-ncx|s-fog>"
|
||||||
echo " option -r : efface vm existante avant creation nouvelle"
|
echo " option -r : efface VM existante avant creation nouvelle"
|
||||||
|
echo " option -s : start VM apres creation"
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -59,12 +61,19 @@ fi
|
|||||||
if [[ $1 == "--help" ]] || [[ $1 == "-h" ]] || [[ $1 == "-V" ]] ; then
|
if [[ $1 == "--help" ]] || [[ $1 == "-h" ]] || [[ $1 == "-V" ]] ; then
|
||||||
usage
|
usage
|
||||||
fi
|
fi
|
||||||
if [[ $1 == "-r" ]] ; then
|
while [[ -n "$1" ]] ; do
|
||||||
|
if [[ "$1" == "-s" ]] ; then
|
||||||
|
startmode=1
|
||||||
|
shift
|
||||||
|
elif [[ "$1" == "-r" ]] ; then
|
||||||
deletemode=1
|
deletemode=1
|
||||||
shift
|
shift
|
||||||
|
else
|
||||||
|
parm=$1
|
||||||
|
shift
|
||||||
fi
|
fi
|
||||||
vm="$1"
|
done
|
||||||
|
vm="${parm}"
|
||||||
create_vm "${vm}"
|
create_vm "${vm}"
|
||||||
if [[ "${vm}" == "s-adm" ]] ; then
|
if [[ "${vm}" == "s-adm" ]] ; then
|
||||||
bash addint.s-adm
|
bash addint.s-adm
|
||||||
@ -91,6 +100,10 @@ elif [[ "${vm}" == "s-nxc" ]] ; then
|
|||||||
create_if "${vm}" "n-adm" "n-infra"
|
create_if "${vm}" "n-adm" "n-infra"
|
||||||
elif [[ "${vm}" == "s-fog" ]] ; then
|
elif [[ "${vm}" == "s-fog" ]] ; then
|
||||||
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
|
elif [[ "${vm}" == "s-kea1" ]] ; then
|
||||||
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
|
elif [[ "${vm}" == "s-kea2" ]] ; then
|
||||||
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
elif [[ "${vm}" == "s-dns-ext" ]] ; then
|
elif [[ "${vm}" == "s-dns-ext" ]] ; then
|
||||||
create_if "${vm}" "n-adm" "n-dmz"
|
create_if "${vm}" "n-adm" "n-dmz"
|
||||||
elif [[ "${vm}" == "s-web-ext" ]] ; then
|
elif [[ "${vm}" == "s-web-ext" ]] ; then
|
||||||
@ -123,3 +136,6 @@ else
|
|||||||
echo "$0 : vm ${vm} non prevue "
|
echo "$0 : vm ${vm} non prevue "
|
||||||
exit 2
|
exit 2
|
||||||
fi
|
fi
|
||||||
|
if [[ $startmode == 1 ]] ; then
|
||||||
|
vboxmanage startvm "${vm}" --type headless
|
||||||
|
fi
|
||||||
|
@ -102,6 +102,22 @@ elseif ($args[0] -eq "s-fog") {
|
|||||||
create_if $args[0] "int" 3 "n-user"
|
create_if $args[0] "int" 3 "n-user"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
elseif ($args[0] -eq "s-kea1") {
|
||||||
|
|
||||||
|
create_vm $args[0]
|
||||||
|
create_if $args[0] "int" 1 "n-adm"
|
||||||
|
create_if $args[0] "int" 2 "n-infra"
|
||||||
|
create_if $args[0] "int" 3 "n-user"
|
||||||
|
}
|
||||||
|
|
||||||
|
elseif ($args[0] -eq "s-kea2") {
|
||||||
|
|
||||||
|
create_vm $args[0]
|
||||||
|
create_if $args[0] "int" 1 "n-adm"
|
||||||
|
create_if $args[0] "int" 2 "n-infra"
|
||||||
|
create_if $args[0] "int" 3 "n-user"
|
||||||
|
}
|
||||||
|
|
||||||
elseif ($args[0] -eq "s-agence") {
|
elseif ($args[0] -eq "s-agence") {
|
||||||
|
|
||||||
create_vm $args[0]
|
create_vm $args[0]
|
||||||
|
Reference in New Issue
Block a user