Compare commits
11 Commits
v0.0.3k-fr
...
v0.0.3v-ps
Author | SHA1 | Date | |
---|---|---|---|
b5237811e1 | |||
25bb47afd3 | |||
addabae478 | |||
a57998f5de | |||
262b7bdb13 | |||
c45dc50d12 | |||
d1116a91c3 | |||
9c8dca44c9 | |||
ce3b6e0a77 | |||
a03298ed54 | |||
80b54a50df |
@ -1,21 +1,20 @@
|
|||||||
file:
|
file:
|
||||||
/etc/wireguard/wg0.conf:
|
/etc/wireguard/wg0.conf:
|
||||||
exists: true
|
exists: true
|
||||||
mode: "0644"
|
mode: "0600"
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
filetype: file
|
filetype: file
|
||||||
contains:
|
contains: []
|
||||||
- AllowedIPs = 10.0.0.2/32, 172.16.128.0/24
|
|
||||||
package:
|
package:
|
||||||
wireguard:
|
wireguard:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1
|
||||||
wireguard-tools:
|
wireguard-tools:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1+b1
|
||||||
service:
|
service:
|
||||||
wg-quick@wg0:
|
wg-quick@wg0:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
@ -1,7 +1,8 @@
|
|||||||
file:
|
file:
|
||||||
/etc/wireguard/wg0.conf:
|
/etc/wireguard/wg0.conf:
|
||||||
exists: true
|
exists: true
|
||||||
mode: "0644"
|
mode: "0600"
|
||||||
|
size: 374
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
filetype: file
|
filetype: file
|
||||||
@ -10,11 +11,11 @@ package:
|
|||||||
wireguard:
|
wireguard:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1
|
||||||
wireguard-tools:
|
wireguard-tools:
|
||||||
installed: true
|
installed: true
|
||||||
versions:
|
versions:
|
||||||
- 1.0.20210223-1
|
- 1.0.20210914-1+b1
|
||||||
service:
|
service:
|
||||||
isc-dhcp-server:
|
isc-dhcp-server:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
@ -22,6 +22,8 @@
|
|||||||
192.168.99.14 s-nas.gsb.adm
|
192.168.99.14 s-nas.gsb.adm
|
||||||
192.168.99.15 s-san.gsb.adm
|
192.168.99.15 s-san.gsb.adm
|
||||||
192.168.99.16 s-fog.gsb.adm
|
192.168.99.16 s-fog.gsb.adm
|
||||||
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -21,6 +21,8 @@
|
|||||||
192.168.99.12 r-int.gsb.adm
|
192.168.99.12 r-int.gsb.adm
|
||||||
192.168.99.13 r-ext.gsb.adm
|
192.168.99.13 r-ext.gsb.adm
|
||||||
192.168.99.14 s-nas.gsb.adm
|
192.168.99.14 s-nas.gsb.adm
|
||||||
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2023051000 ; Serial
|
2024011500 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -27,6 +27,8 @@ s-mon IN A 172.16.0.8
|
|||||||
s-itil IN A 172.16.0.9
|
s-itil IN A 172.16.0.9
|
||||||
s-elk IN A 172.16.0.11
|
s-elk IN A 172.16.0.11
|
||||||
s-gestsup IN A 172.16.0.17
|
s-gestsup IN A 172.16.0.17
|
||||||
|
s-kea1 IN A 172.16.0.20
|
||||||
|
s-kea2 IN A 172.16.0.21
|
||||||
r-int IN A 172.16.0.254
|
r-int IN A 172.16.0.254
|
||||||
r-int-lnk IN A 192.168.200.254
|
r-int-lnk IN A 192.168.200.254
|
||||||
r-ext IN A 192.168.200.253
|
r-ext IN A 192.168.200.253
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2023040501 ; Serial
|
2024011500 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -21,6 +21,8 @@ $TTL 604800
|
|||||||
7.0 IN PTR s-nxc.gsb.lan.
|
7.0 IN PTR s-nxc.gsb.lan.
|
||||||
8.0 IN PTR s-mon.gsb.lan.
|
8.0 IN PTR s-mon.gsb.lan.
|
||||||
9.0 IN PTR s-itil.gsb.lan.
|
9.0 IN PTR s-itil.gsb.lan.
|
||||||
|
20.0 IN PTR s-kea1.gsb.lan.
|
||||||
|
21.0 IN PTR s-kea2.gsb.lan.
|
||||||
101.1 IN PTR s-web1
|
101.1 IN PTR s-web1
|
||||||
101.2 IN PTR s-web2
|
101.2 IN PTR s-web2
|
||||||
100.10 IN PTR s-lb
|
100.10 IN PTR s-lb
|
||||||
|
46
roles/fog/files/.fogsettings.single-if
Normal file
46
roles/fog/files/.fogsettings.single-if
Normal file
@ -0,0 +1,46 @@
|
|||||||
|
## Start of FOG Settings
|
||||||
|
## Created by the FOG Installer
|
||||||
|
## Find more information about this file in the FOG Project wiki:
|
||||||
|
## https://wiki.fogproject.org/wiki/index.php?title=.fogsettings
|
||||||
|
## Version: 1.5.10
|
||||||
|
## Install time: mar. 16 janv. 2024 15:27:57
|
||||||
|
ipaddress='192.168.99.100'
|
||||||
|
copybackold='0'
|
||||||
|
interface='enp0s3'
|
||||||
|
submask='255.255.255.0'
|
||||||
|
hostname='s-fog.gsb.lan'
|
||||||
|
routeraddress='192.168.99.99'
|
||||||
|
plainrouter='192.168.99.99'
|
||||||
|
dnsaddress='192.168.99.99'
|
||||||
|
username='fogproject'
|
||||||
|
password='zbSw#FaGPS7O1bJ5tpfj'
|
||||||
|
osid='2'
|
||||||
|
osname='Debian'
|
||||||
|
dodhcp='Y'
|
||||||
|
bldhcp='0'
|
||||||
|
dhcpd='isc-dhcp-server'
|
||||||
|
blexports='1'
|
||||||
|
installtype='N'
|
||||||
|
snmysqluser='fogmaster'
|
||||||
|
snmysqlpass='cbZjO*gCONbbldV4a6l1'
|
||||||
|
snmysqlhost='localhost'
|
||||||
|
mysqldbname='fog'
|
||||||
|
installlang='0'
|
||||||
|
storageLocation='/images'
|
||||||
|
fogupdateloaded=1
|
||||||
|
docroot='/var/www/html/'
|
||||||
|
webroot='/fog/'
|
||||||
|
caCreated='yes'
|
||||||
|
httpproto='http'
|
||||||
|
startrange=''
|
||||||
|
endrange=''
|
||||||
|
packages='apache2 bc build-essential cpp curl g++ gawk gcc genisoimage git gzip htmldoc isolinux lftp libapache2-mod-php libc6 libcurl4 liblzma-dev m4 mariadb-client mariadb-server net-tools nfs-kernel-server openssh-server php php-bcmath php-cli php-curl php-fpm php-gd php-json php-ldap php-mbstring php-mysql tar tftpd-hpa tftp-hpa unzip vsftpd wget zlib1g'
|
||||||
|
noTftpBuild=''
|
||||||
|
tftpAdvOpts=''
|
||||||
|
sslpath='/opt/fog/snapins/ssl/'
|
||||||
|
backupPath='/home/'
|
||||||
|
armsupport=''
|
||||||
|
php_ver='7.4'
|
||||||
|
sslprivkey='/opt/fog/snapins/ssl//.srvprivate.key'
|
||||||
|
sendreports='Y'
|
||||||
|
## End of FOG Settings
|
@ -42,7 +42,7 @@ tftpAdvOpts=''
|
|||||||
sslpath='/opt/fog/snapins/ssl/'
|
sslpath='/opt/fog/snapins/ssl/'
|
||||||
backupPath='/home/'
|
backupPath='/home/'
|
||||||
armsupport='0'
|
armsupport='0'
|
||||||
php_ver='8.2'
|
php_ver='7.4'
|
||||||
#php_verAdds='-7.4'
|
#php_verAdds='-7.4'
|
||||||
sslprivkey='/opt/fog/snapins/ssl//.srvprivate.key'
|
sslprivkey='/opt/fog/snapins/ssl//.srvprivate.key'
|
||||||
sendreports='Y'
|
sendreports='Y'
|
||||||
|
@ -42,8 +42,8 @@
|
|||||||
src: "/tmp/{{ depl_fog }}"
|
src: "/tmp/{{ depl_fog }}"
|
||||||
dest: "/tmp/"
|
dest: "/tmp/"
|
||||||
|
|
||||||
- name: Exécution du script d'installation Fog
|
#- name: Exécution du script d'installation Fog
|
||||||
ansible.builtin.shell: sudo bash /tmp/fogproject-1.5.10/bin/installfog.sh --recreate-keys -f /tmp/fogsettings -y
|
# ansible.builtin.shell: sudo bash /tmp/fogproject-1.5.10/bin/installfog.sh --recreate-keys -f /tmp/fogsettings -y
|
||||||
args:
|
# args:
|
||||||
chdir: "/tmp/fogproject-1.5.10/"
|
# chdir: "/tmp/fogproject-1.5.10/"
|
||||||
|
|
||||||
|
14
roles/kea/README.md
Normal file
14
roles/kea/README.md
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
# Rôle Kea
|
||||||
|
***
|
||||||
|
Rôle du Kea pour la haute disponibilité dhcp
|
||||||
|
|
||||||
|
## Tables des matières
|
||||||
|
1. [Que fait le rôle Kea ?]
|
||||||
|
|
||||||
|
|
||||||
|
## Que fait le rôle Kea ?
|
||||||
|
Il permet de configurer les serveur kea en mode haute disponibilité.
|
||||||
|
|
||||||
|
### Installation et configuration de kea
|
||||||
|
|
||||||
|
Le rôle kea va installer les packets kea dhcp4, hook, admin une fois les packets installer. Nous allons configurer les 2 serveurs kea pour qu'il distribut les ip de n-user et soit en haute disponibilité.
|
8
roles/kea/default/main.yml
Normal file
8
roles/kea/default/main.yml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
#variable kea
|
||||||
|
kea_ver: "2.4.1"
|
||||||
|
kea_dbname: ""
|
||||||
|
kea_dbuser: ""
|
||||||
|
kea_dbpasswd: ""
|
||||||
|
kea_dhcp4_dir: "/etc/kea/kea-dhcp4.conf"
|
||||||
|
kea_ctrl_dir: "/etc/kea/kea-ctrl-agent.conf"
|
||||||
|
|
5
roles/kea/handlers/main.yml
Normal file
5
roles/kea/handlers/main.yml
Normal file
@ -0,0 +1,5 @@
|
|||||||
|
- name: restart zabbix agent
|
||||||
|
service:
|
||||||
|
name: zabbix-agent
|
||||||
|
state: restarted
|
||||||
|
enabled: yes
|
65
roles/kea/tasks/main.yml
Normal file
65
roles/kea/tasks/main.yml
Normal file
@ -0,0 +1,65 @@
|
|||||||
|
- name: installation des dépendances
|
||||||
|
apt:
|
||||||
|
name:
|
||||||
|
- liblog4cplus-2.0.5
|
||||||
|
- libmariadb3
|
||||||
|
- libpq5
|
||||||
|
- mariadb-common
|
||||||
|
- mysql-common
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: telechargemement du paquet isc-kea-common
|
||||||
|
get_url:
|
||||||
|
url: "https://dl.cloudsmith.io/public/isc/kea-2-4/deb/debian/pool/bookworm/main/i/is/isc-kea-common_2.4.1-isc20231123184533/isc-kea-common_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
dest: "/tmp"
|
||||||
|
|
||||||
|
- name: telechargement du paquet isc-kea-dhcp4
|
||||||
|
get_url:
|
||||||
|
url: "https://dl.cloudsmith.io/public/isc/kea-2-4/deb/debian/pool/bookworm/main/i/is/isc-kea-dhcp4_2.4.1-isc20231123184533/isc-kea-dhcp4_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
dest: "/tmp"
|
||||||
|
|
||||||
|
- name: telechargement du paquet isc-kea-ctrl-agent
|
||||||
|
get_url:
|
||||||
|
url: "https://dl.cloudsmith.io/public/isc/kea-2-4/deb/debian/pool/bookworm/main/i/is/isc-kea-ctrl-agent_2.4.1-isc20231123184533/isc-kea-ctrl-agent_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
dest: "/tmp"
|
||||||
|
|
||||||
|
- name: telechargement du paquet isc-kea-hooks
|
||||||
|
get_url:
|
||||||
|
url: "https://dl.cloudsmith.io/public/isc/kea-2-4/deb/debian/pool/bookworm/main/i/is/isc-kea-hooks_2.4.1-isc20231123184533/isc-kea-hooks_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
dest: "/tmp"
|
||||||
|
- name: Update apt
|
||||||
|
apt:
|
||||||
|
update_cache: yes
|
||||||
|
|
||||||
|
- name: Installation paquet isc-kea-common
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-common_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
|
||||||
|
- name: Installation isc-kea-dhcp4
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-dhcp4_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Installation isc-kea-ctrl-agent
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-ctrl-agent_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
|
||||||
|
- name: Installation isc-kea-ctrl-agent
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-ctrl-agent_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Installation isc-kea-hooks
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-ctrl-agent_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
||||||
|
|
||||||
|
|
||||||
|
- name: Installation isc-kea-hooks
|
||||||
|
apt:
|
||||||
|
deb: "/tmp/isc-kea-ctrl-agent_2.4.1-isc20231123184533_amd64.deb"
|
||||||
|
state: present
|
26
roles/post/files/interfaces.s-kea1
Normal file
26
roles/post/files/interfaces.s-kea1
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
# This file describes the network interfaces available on your system
|
||||||
|
# and how to activate them. For more information, see interfaces(5).
|
||||||
|
|
||||||
|
# The loopback network interface
|
||||||
|
auto lo
|
||||||
|
iface lo inet loopback
|
||||||
|
|
||||||
|
# cote N-adm
|
||||||
|
allow-hotplug enp0s3
|
||||||
|
iface enp0s3 inet static
|
||||||
|
address 192.168.99.20
|
||||||
|
netmask 255.255.255.0
|
||||||
|
gateway 192.168.99.99
|
||||||
|
|
||||||
|
|
||||||
|
# cote N-infra
|
||||||
|
allow-hotplug enp0s8
|
||||||
|
iface enp0s8 inet static
|
||||||
|
address 172.16.0.20
|
||||||
|
netmask 255.255.255.0
|
||||||
|
|
||||||
|
#cote N-user
|
||||||
|
allow-hotplug enp0s9
|
||||||
|
iface enp0s9 inet static
|
||||||
|
address 172.16.64.20
|
||||||
|
netmask 255.255.255.0
|
26
roles/post/files/interfaces.s-kea2
Normal file
26
roles/post/files/interfaces.s-kea2
Normal file
@ -0,0 +1,26 @@
|
|||||||
|
# This file describes the network interfaces available on your system
|
||||||
|
# and how to activate them. For more information, see interfaces(5).
|
||||||
|
|
||||||
|
# The loopback network interface
|
||||||
|
auto lo
|
||||||
|
iface lo inet loopback
|
||||||
|
|
||||||
|
# cote N-adm
|
||||||
|
allow-hotplug enp0s3
|
||||||
|
iface enp0s3 inet static
|
||||||
|
address 192.168.99.21
|
||||||
|
netmask 255.255.255.0
|
||||||
|
gateway 192.168.99.99
|
||||||
|
|
||||||
|
|
||||||
|
# cote N-infra
|
||||||
|
allow-hotplug enp0s8
|
||||||
|
iface enp0s8 inet static
|
||||||
|
address 172.16.0.21
|
||||||
|
netmask 255.255.255.0
|
||||||
|
|
||||||
|
#cote N-user
|
||||||
|
allow-hotplug enp0s9
|
||||||
|
iface enp0s9 inet static
|
||||||
|
address 172.16.64.21
|
||||||
|
netmask 255.255.255.0
|
12
s-fog.yml
12
s-fog.yml
@ -5,10 +5,10 @@
|
|||||||
roles:
|
roles:
|
||||||
- base
|
- base
|
||||||
- goss
|
- goss
|
||||||
- dhcp-fog
|
#- dhcp-fog
|
||||||
- ssh-cli
|
# - ssh-cli
|
||||||
- snmp-agent
|
# - snmp-agent
|
||||||
# - syslog-cli
|
# - syslog-cli
|
||||||
# - fog
|
- fog
|
||||||
- - journald-snd
|
#- - journald-snd
|
||||||
- post
|
#- post
|
||||||
|
@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
- name: Zabbix
|
- name: Zabbix
|
||||||
hosts: all
|
hosts: localhost
|
||||||
# become: yes
|
become: yes
|
||||||
# become_method: sudo
|
become_method: sudo
|
||||||
# become_user: root
|
# become_user: root
|
||||||
# vars:
|
# vars:
|
||||||
# access: "Restricted Nagios4 Access"
|
# access: "Restricted Nagios4 Access"
|
||||||
|
@ -100,6 +100,10 @@ elif [[ "${vm}" == "s-nxc" ]] ; then
|
|||||||
create_if "${vm}" "n-adm" "n-infra"
|
create_if "${vm}" "n-adm" "n-infra"
|
||||||
elif [[ "${vm}" == "s-fog" ]] ; then
|
elif [[ "${vm}" == "s-fog" ]] ; then
|
||||||
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
|
elif [[ "${vm}" == "s-kea1" ]] ; then
|
||||||
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
|
elif [[ "${vm}" == "s-kea2" ]] ; then
|
||||||
|
create_if "${vm}" "n-adm" "n-infra" "n-user"
|
||||||
elif [[ "${vm}" == "s-dns-ext" ]] ; then
|
elif [[ "${vm}" == "s-dns-ext" ]] ; then
|
||||||
create_if "${vm}" "n-adm" "n-dmz"
|
create_if "${vm}" "n-adm" "n-dmz"
|
||||||
elif [[ "${vm}" == "s-web-ext" ]] ; then
|
elif [[ "${vm}" == "s-web-ext" ]] ; then
|
||||||
|
@ -102,6 +102,22 @@ elseif ($args[0] -eq "s-fog") {
|
|||||||
create_if $args[0] "int" 3 "n-user"
|
create_if $args[0] "int" 3 "n-user"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
elseif ($args[0] -eq "s-kea1") {
|
||||||
|
|
||||||
|
create_vm $args[0]
|
||||||
|
create_if $args[0] "int" 1 "n-adm"
|
||||||
|
create_if $args[0] "int" 2 "n-infra"
|
||||||
|
create_if $args[0] "int" 3 "n-user"
|
||||||
|
}
|
||||||
|
|
||||||
|
elseif ($args[0] -eq "s-kea2") {
|
||||||
|
|
||||||
|
create_vm $args[0]
|
||||||
|
create_if $args[0] "int" 1 "n-adm"
|
||||||
|
create_if $args[0] "int" 2 "n-infra"
|
||||||
|
create_if $args[0] "int" 3 "n-user"
|
||||||
|
}
|
||||||
|
|
||||||
elseif ($args[0] -eq "s-agence") {
|
elseif ($args[0] -eq "s-agence") {
|
||||||
|
|
||||||
create_vm $args[0]
|
create_vm $args[0]
|
||||||
|
Reference in New Issue
Block a user