Compare commits
14 Commits
v0.0.4l-ch
...
v0.0.4s-ps
Author | SHA1 | Date | |
---|---|---|---|
39ee37f3e8 | |||
1f4c957726 | |||
89515287b0 | |||
77d1440da7 | |||
be66b9e2f4 | |||
91417b7f8e | |||
69052938f7 | |||
81af190640 | |||
8b80414e46 | |||
91acd3c18d | |||
8498d7be15 | |||
15e57a4a40 | |||
8b59a5553f | |||
5f1b04fd96 |
@ -24,6 +24,7 @@
|
|||||||
192.168.99.16 s-fog.gsb.adm
|
192.168.99.16 s-fog.gsb.adm
|
||||||
192.168.99.20 s-kea1.gsb.adm
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
192.168.99.21 s-kea2.gsb.adm
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
|
192.168.99.22 s-awx.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -23,6 +23,7 @@
|
|||||||
192.168.99.14 s-nas.gsb.adm
|
192.168.99.14 s-nas.gsb.adm
|
||||||
192.168.99.20 s-kea1.gsb.adm
|
192.168.99.20 s-kea1.gsb.adm
|
||||||
192.168.99.21 s-kea2.gsb.adm
|
192.168.99.21 s-kea2.gsb.adm
|
||||||
|
192.168.99.22 s-awx.gsb.adm
|
||||||
192.168.99.50 s-lb-bd.gsb.adm
|
192.168.99.50 s-lb-bd.gsb.adm
|
||||||
192.168.99.101 s-lb-web1.gsb.adm
|
192.168.99.101 s-lb-web1.gsb.adm
|
||||||
192.168.99.102 s-lb-web2.gsb.adm
|
192.168.99.102 s-lb-web2.gsb.adm
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2024011500 ; Serial
|
2024011800 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -29,6 +29,7 @@ s-elk IN A 172.16.0.11
|
|||||||
s-gestsup IN A 172.16.0.17
|
s-gestsup IN A 172.16.0.17
|
||||||
s-kea1 IN A 172.16.0.20
|
s-kea1 IN A 172.16.0.20
|
||||||
s-kea2 IN A 172.16.0.21
|
s-kea2 IN A 172.16.0.21
|
||||||
|
s-awx IN A 172.16.0.22
|
||||||
r-int IN A 172.16.0.254
|
r-int IN A 172.16.0.254
|
||||||
r-int-lnk IN A 192.168.200.254
|
r-int-lnk IN A 192.168.200.254
|
||||||
r-ext IN A 192.168.200.253
|
r-ext IN A 192.168.200.253
|
||||||
|
@ -5,7 +5,7 @@
|
|||||||
;
|
;
|
||||||
$TTL 604800
|
$TTL 604800
|
||||||
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
@ IN SOA s-infra.gsb.lan. root.s-infra.gsb.lan. (
|
||||||
2024011500 ; Serial
|
2024011800 ; Serial
|
||||||
7200 ; Refresh
|
7200 ; Refresh
|
||||||
86400 ; Retry
|
86400 ; Retry
|
||||||
8419200 ; Expire
|
8419200 ; Expire
|
||||||
@ -23,6 +23,7 @@ $TTL 604800
|
|||||||
9.0 IN PTR s-itil.gsb.lan.
|
9.0 IN PTR s-itil.gsb.lan.
|
||||||
20.0 IN PTR s-kea1.gsb.lan.
|
20.0 IN PTR s-kea1.gsb.lan.
|
||||||
21.0 IN PTR s-kea2.gsb.lan.
|
21.0 IN PTR s-kea2.gsb.lan.
|
||||||
|
22.0 IN PTR s-awx.gsb.lan.
|
||||||
101.1 IN PTR s-web1
|
101.1 IN PTR s-web1
|
||||||
101.2 IN PTR s-web2
|
101.2 IN PTR s-web2
|
||||||
100.10 IN PTR s-lb
|
100.10 IN PTR s-lb
|
||||||
|
@ -1,16 +1,13 @@
|
|||||||
---
|
---
|
||||||
- name: Supprime le fichier getdocker.sh si déjà présent
|
- name: on recupere getdocker
|
||||||
file:
|
get_url:
|
||||||
state: absent
|
url: http://s-adm.gsb.adm/gsbstore/getdocker.sh
|
||||||
path: /tmp/getdocker.sh
|
dest: /usr/local/bin
|
||||||
|
|
||||||
- name: Télécharge le script d'installation de docker
|
- name: on verifie si docker est installe
|
||||||
uri:
|
command: which docker
|
||||||
url: 'https://get.docker.com'
|
register: docker_present
|
||||||
method: GET
|
|
||||||
dest: /tmp/getdocker.sh
|
|
||||||
mode: a+x
|
|
||||||
register: result
|
|
||||||
|
|
||||||
- name: Execution du script getdocker
|
- name: Execution du script getdocker si docker n'est pas deja installe
|
||||||
shell: bash /tmp/getdocker.sh
|
shell: bash /usr/local/bin/getdocker.sh
|
||||||
|
when: docker_present.stdout.find('/usr/bin/docker') == -1
|
||||||
|
@ -16,7 +16,7 @@
|
|||||||
|
|
||||||
- name: 20 - decompresse wordpress
|
- name: 20 - decompresse wordpress
|
||||||
unarchive:
|
unarchive:
|
||||||
src: https://fr.wordpress.org/latest-fr_FR.tar.gz
|
src: http://s-adm.gsb.adm/gsbstore/wordpress-6.4.2-fr_FR.tar.gz
|
||||||
dest: /home/
|
dest: /home/
|
||||||
remote_src: yes
|
remote_src: yes
|
||||||
|
|
||||||
|
@ -1,2 +1,2 @@
|
|||||||
depl_url: "http://s-adm.gsb.adm/gsbstore/"
|
depl_url: "http://s-adm.gsb.adm/gsbstore/"
|
||||||
depl_wordpress: "wordpress-6.1.1-fr_FR.tar.gz"
|
depl_wordpress: "wordpress-6.4.2-fr_FR.tar.gz"
|
||||||
|
@ -7,15 +7,15 @@ iface lo inet loopback
|
|||||||
# carte n-adm
|
# carte n-adm
|
||||||
allow-hotplug enp0s3
|
allow-hotplug enp0s3
|
||||||
iface enp0s3 inet static
|
iface enp0s3 inet static
|
||||||
address 192.168.99.101/24
|
address 192.168.99.102/24
|
||||||
|
|
||||||
# Réseau n-dmz-lb
|
# Réseau n-dmz-lb
|
||||||
allow-hotplug enp0s8
|
allow-hotplug enp0s8
|
||||||
iface enp0s8 inet static
|
iface enp0s8 inet static
|
||||||
address 192.168.101.1/24
|
address 192.168.101.2/24
|
||||||
|
|
||||||
# réseau n-dmz-db
|
# réseau n-dmz-db
|
||||||
allow-hotplug enp0s9
|
allow-hotplug enp0s9
|
||||||
iface enp0s9 inet static
|
iface enp0s9 inet static
|
||||||
address 192.168.102.1/24
|
address 192.168.102.2/24
|
||||||
post-up mount -o rw 192.168.102.253:/home/wordpress /var/www/html
|
post-up mount -o rw 192.168.102.253:/home/wordpress /var/www/html
|
||||||
|
23
roles/post/files/interfaces.s-awx
Normal file
23
roles/post/files/interfaces.s-awx
Normal file
@ -0,0 +1,23 @@
|
|||||||
|
# This file describes the network interfaces available on your system
|
||||||
|
# and how to activate them. For more information, see interfaces(5).
|
||||||
|
|
||||||
|
#source /etc/network/interfaces.d/*
|
||||||
|
|
||||||
|
# The loopback network interface
|
||||||
|
auto lo
|
||||||
|
iface lo inet loopback
|
||||||
|
|
||||||
|
# cote n-adm
|
||||||
|
allow-hotplug enp0s3
|
||||||
|
iface enp0s3 inet static
|
||||||
|
address 192.168.99.22/24
|
||||||
|
gateway 192.168.99.99
|
||||||
|
|
||||||
|
# Cote n-infra
|
||||||
|
allow-hotplug enp0s8
|
||||||
|
iface enp0s8 inet static
|
||||||
|
address 172.16.0.22/24
|
||||||
|
up ip route add 172.16.64.0/24 via 172.16.0.254
|
||||||
|
up ip route add 172.16.128.0/24 via 172.16.0.254
|
||||||
|
up ip route add 192.168.0.0/16 via 172.16.0.254
|
||||||
|
up ip route add 192.168.200.0/24 via 172.16.0.254
|
@ -1,13 +1,21 @@
|
|||||||
|
## **Explication de l'installation du VPN :**
|
||||||
|
L'installation se fait en 3 phases. Dans un premier temps il faut installer par le playbook **r-vp1**. Ensuite dans un second temps **r-vp2** et pour finir notre filtrage avec **ferm**
|
||||||
|
|
||||||
|
## **Explication des dossiers pour Wireguard :**
|
||||||
|
|
||||||
|
Le dossier wireguard-r = r-vp1
|
||||||
|
wireguard-l = r-vp2
|
||||||
|
|
||||||
# <p align="center">Procédure d'installation </p>
|
# <p align="center">Procédure d'installation </p>
|
||||||
|
|
||||||
de **r-vp1** et de copie du fichier wg0-b.conf.
|
|
||||||
|
|
||||||
***
|
***
|
||||||
## Sur **r-vp1**:
|
## Sur **r-vp1**:
|
||||||
Attendre la fin de l'installation. Ensuite lancer un serveur http avec python3 pour récuperer le fichier wg0-b.conf sur **r-vp2** .
|
|
||||||
|
|
||||||
### 🛠️ Lancer le script
|
Lancer le playbook : *ansible-playbook -i localhost, -c local* r-vp1.yml sur **r-vp1**
|
||||||
|
|
||||||
|
Attendre la fin de l'installation. Ensuite lancer le scipt r-vp1-post.sh
|
||||||
|
|
||||||
|
### 🛠️ Lancer le script r-vp1-post.sh
|
||||||
```bash
|
```bash
|
||||||
cd /tools/ansible/gsb2023/Scripts
|
cd /tools/ansible/gsb2023/Scripts
|
||||||
```
|
```
|
||||||
|
@ -34,3 +34,10 @@
|
|||||||
- { regexp: '^(ServerActive\s*=\s*).*$', replace: 'ServerActive = 192.168.99.8' }
|
- { regexp: '^(ServerActive\s*=\s*).*$', replace: 'ServerActive = 192.168.99.8' }
|
||||||
- { regexp: '^(Hostname\s*=\s*).*$', replace: 'Hostname = {{ ansible_hostname }}' }
|
- { regexp: '^(Hostname\s*=\s*).*$', replace: 'Hostname = {{ ansible_hostname }}' }
|
||||||
- { regexp: '^(Include\s*=\s*).*$', replace: 'Include = /etc/zabbix/zabbix_agentd.d/*.conf' }
|
- { regexp: '^(Include\s*=\s*).*$', replace: 'Include = /etc/zabbix/zabbix_agentd.d/*.conf' }
|
||||||
|
|
||||||
|
- name: Enable Zabbix agent service
|
||||||
|
service:
|
||||||
|
name: zabbix-agent
|
||||||
|
state: restarted
|
||||||
|
enabled: yes
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user