From 5fdf790556af23ac7be86d5d384a8ec8b1fe0c2c Mon Sep 17 00:00:00 2001 From: Andrey Ryabtsevwq Date: Sun, 11 Oct 2026 00:13:32 +0300 Subject: [PATCH] feat: first commit --- .gitignore | 4 + README.md | 2 + bind9/named.conf.default-zones | 38 +++ bind9/named.conf.local | 36 ++ bind9/named.conf.options | 36 ++ bind9/named.conf.root-hints | 7 + bind9/zones/db.10.8.0 | 41 +++ bind9/zones/db.10.9.0 | 41 +++ bind9/zones/db.ra-tech.pro | 54 +++ bind9/zones/db.v9.ra-tech.pro | 54 +++ cloak/cloak.service | 12 + cloak/server.json.j2 | 21 ++ ejabberd/ejabberd.yaml | 200 +++++++++++ haproxy/haproxy.cfg | 58 ++++ inventory.yaml | 14 + node-exporter/node-exporter.service | 15 + openvpn/certs/ta.key | 21 ++ openvpn/server.conf | 320 ++++++++++++++++++ playbook.yaml | 503 ++++++++++++++++++++++++++++ strongswan/charon/dhcp.conf.j2 | 6 + strongswan/iface-ra0-up.sh | 14 + strongswan/iface-ra0.service | 11 + strongswan/ra-tech.conf.j2 | 92 +++++ sysctl/99-ipv4-forward.conf | 1 + tinyproxy/tinyproxy.conf | 356 ++++++++++++++++++++ 25 files changed, 1957 insertions(+) create mode 100644 .gitignore create mode 100644 README.md create mode 100644 bind9/named.conf.default-zones create mode 100644 bind9/named.conf.local create mode 100644 bind9/named.conf.options create mode 100644 bind9/named.conf.root-hints create mode 100644 bind9/zones/db.10.8.0 create mode 100644 bind9/zones/db.10.9.0 create mode 100644 bind9/zones/db.ra-tech.pro create mode 100644 bind9/zones/db.v9.ra-tech.pro create mode 100644 cloak/cloak.service create mode 100644 cloak/server.json.j2 create mode 100644 ejabberd/ejabberd.yaml create mode 100644 haproxy/haproxy.cfg create mode 100644 inventory.yaml create mode 100644 node-exporter/node-exporter.service create mode 100644 openvpn/certs/ta.key create mode 100644 openvpn/server.conf create mode 100644 playbook.yaml create mode 100644 strongswan/charon/dhcp.conf.j2 create mode 100644 strongswan/iface-ra0-up.sh create mode 100644 strongswan/iface-ra0.service create mode 100644 strongswan/ra-tech.conf.j2 create mode 100644 sysctl/99-ipv4-forward.conf create mode 100644 tinyproxy/tinyproxy.conf diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..c49d4cc --- /dev/null +++ b/.gitignore @@ -0,0 +1,4 @@ +.venv +.vscode + +*.pem \ No newline at end of file diff --git a/README.md b/README.md new file mode 100644 index 0000000..0714be4 --- /dev/null +++ b/README.md @@ -0,0 +1,2 @@ +# VPS setup ansible script +Setup VPS for basic needs with ansible playbook diff --git a/bind9/named.conf.default-zones b/bind9/named.conf.default-zones new file mode 100644 index 0000000..e35e11c --- /dev/null +++ b/bind9/named.conf.default-zones @@ -0,0 +1,38 @@ +// prime the server with knowledge of the root servers +//zone "." { +// type hint; +// file "/usr/share/dns/root.hints"; +//}; + +// be authoritative for the localhost forward and reverse zones, and for +// broadcast zones as per RFC 1912 + +view "ext" { + match-clients{"any";}; + + zone "." { + type hint; + file "/usr/share/dns/root.hints"; + }; + + zone "localhost" { + type master; + file "/etc/bind/db.local"; + }; + + zone "127.in-addr.arpa" { + type master; + file "/etc/bind/db.127"; + }; + + zone "0.in-addr.arpa" { + type master; + file "/etc/bind/db.0"; + }; + + zone "255.in-addr.arpa" { + type master; + file "/etc/bind/db.255"; + }; + +}; \ No newline at end of file diff --git a/bind9/named.conf.local b/bind9/named.conf.local new file mode 100644 index 0000000..71668c4 --- /dev/null +++ b/bind9/named.conf.local @@ -0,0 +1,36 @@ +// +// Do any local configuration here +// + +// Consider adding the 1918 zones here, if they are not used in your +// organization +//include "/etc/bind/zones.rfc1918"; + +acl "int-8" {10.8.0.0/24;}; +acl "int-9" {10.9.0.0/24;}; + +view "int-8" { + match-clients{"int-8";}; + + zone "ra-tech.pro" { + type master; + file "/etc/bind/zones/db.ra-tech.pro"; + }; + zone "0.8.10.in-addr.arpa" { + type master; + file "/etc/bind/zones/db.10.8.0"; + }; +}; + +view "int-9" { + match-clients{"int-9";}; + + zone "ra-tech.pro" { + type master; + file "/etc/bind/zones/db.v9.ra-tech.pro"; + }; + zone "0.9.10.in-addr.arpa" { + type master; + file "/etc/bind/zones/db.10.9.0"; + }; +}; \ No newline at end of file diff --git a/bind9/named.conf.options b/bind9/named.conf.options new file mode 100644 index 0000000..b5eb41a --- /dev/null +++ b/bind9/named.conf.options @@ -0,0 +1,36 @@ +options { + directory "/var/cache/bind"; + + // If there is a firewall between you and nameservers you want + // to talk to, you may need to fix the firewall to allow multiple + // ports to talk. See http://www.kb.cert.org/vuls/id/800113 + + // If your ISP provided one or more IP addresses for stable + // nameservers, you probably want to use them as forwarders. + // Uncomment the following block, and insert the addresses replacing + // the all-0's placeholder. + + // forwarders { + // 0.0.0.0; + // }; + + //======================================================================== + // If BIND logs error messages about the root key being expired, + // you will need to update your keys. See https://www.isc.org/bind-keys + //======================================================================== + dnssec-validation auto; + + listen-on { + 10.8.0.0/24; + 10.9.0.0/24; + }; + + allow-query { any; }; + + forwarders { + 8.8.8.8; + 8.8.4.4; + }; + + //listen-on-v6 { any; }; +}; \ No newline at end of file diff --git a/bind9/named.conf.root-hints b/bind9/named.conf.root-hints new file mode 100644 index 0000000..9731543 --- /dev/null +++ b/bind9/named.conf.root-hints @@ -0,0 +1,7 @@ +view "ext" { + // prime the server with knowledge of the root servers + zone "." { + type hint; + file "/usr/share/dns/root.hints"; + }; +} diff --git a/bind9/zones/db.10.8.0 b/bind9/zones/db.10.8.0 new file mode 100644 index 0000000..d92a1c4 --- /dev/null +++ b/bind9/zones/db.10.8.0 @@ -0,0 +1,41 @@ +; +; BIND reverse data file for local loopback interface +; +$TTL 604800 +$ORIGIN 0.8.10.in-addr.arpa. +@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. ( + 1 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL +; +; name servers + IN NS ns.ra-tech.pro. + +; PTR Records +1 IN PTR ns.ra-tech.pro. +1 IN PTR vps.ra-tech.pro. +10 IN PTR odroid.ra-tech.pro. +10 IN PTR jenkins.ra-tech.pro. +10 IN PTR nexus.ra-tech.pro. +10 IN PTR docker.ra-tech.pro. +10 IN PTR sonar.ra-tech.pro. +10 IN PTR cloud.ra-tech.pro. +10 IN PTR db.ra-tech.pro. +10 IN PTR dashboard.cloud.ra-tech.pro. +10 IN PTR garden-manager.db.ra-tech.pro. +10 IN PTR giga-ai-agent.db.ra-tech.pro. +10 IN PTR vault.ra-tech.pro. +10 IN PTR docker-registry.ra-tech.pro. +10 IN PTR snapshots.docker-registry.ra-tech.pro. +10 IN PTR prometheus.ra-tech.pro. +10 IN PTR pki.ra-tech.pro. +10 IN PTR grafana.ra-tech.pro. +10 IN PTR hfs.ra-tech.pro. +10 IN PTR kafka-1.ra-tech.pro. +10 IN PTR kafka.ra-tech.pro. +10 IN PTR elasticsearch.ra-tech.pro. +10 IN PTR kibana.ra-tech.pro. +10 IN PTR chrome.selenium.ra-tech.pro. +10 IN PTR git.ra-tech.pro. diff --git a/bind9/zones/db.10.9.0 b/bind9/zones/db.10.9.0 new file mode 100644 index 0000000..535c5d9 --- /dev/null +++ b/bind9/zones/db.10.9.0 @@ -0,0 +1,41 @@ +; +; BIND reverse data file for local loopback interface +; +$TTL 604800 +$ORIGIN 0.9.10.in-addr.arpa. +@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. ( + 1 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL +; +; name servers + IN NS ns.ra-tech.pro. + +; PTR Records +1 IN PTR ns.ra-tech.pro. +1 IN PTR vps.ra-tech.pro. +10 IN PTR odroid.ra-tech.pro. +10 IN PTR jenkins.ra-tech.pro. +10 IN PTR nexus.ra-tech.pro. +10 IN PTR docker.ra-tech.pro. +10 IN PTR sonar.ra-tech.pro. +10 IN PTR cloud.ra-tech.pro. +10 IN PTR db.ra-tech.pro. +10 IN PTR dashboard.cloud.ra-tech.pro. +10 IN PTR garden-manager.db.ra-tech.pro. +10 IN PTR giga-ai-agent.db.ra-tech.pro. +10 IN PTR vault.ra-tech.pro. +10 IN PTR docker-registry.ra-tech.pro. +10 IN PTR snapshots.docker-registry.ra-tech.pro. +10 IN PTR prometheus.ra-tech.pro. +10 IN PTR pki.ra-tech.pro. +10 IN PTR grafana.ra-tech.pro. +10 IN PTR hfs.ra-tech.pro. +10 IN PTR kafka-1.ra-tech.pro. +10 IN PTR kafka.ra-tech.pro. +10 IN PTR elasticsearch.ra-tech.pro. +10 IN PTR kibana.ra-tech.pro. +10 IN PTR chrome.selenium.ra-tech.pro. +10 IN PTR git.ra-tech.pro. diff --git a/bind9/zones/db.ra-tech.pro b/bind9/zones/db.ra-tech.pro new file mode 100644 index 0000000..08a3c1f --- /dev/null +++ b/bind9/zones/db.ra-tech.pro @@ -0,0 +1,54 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. ( + 1 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + +; name servers - NS records + IN NS ns.ra-tech.pro. + +; name servers - A records +ns.ra-tech.pro. IN A 10.8.0.1 + +; 10.8.0.0/24 - A records +vps.ra-tech.pro. IN A 10.8.0.1 +odroid.ra-tech.pro. IN A 10.8.0.10 +jenkins.ra-tech.pro. IN A 10.8.0.10 +nexus.ra-tech.pro. IN A 10.8.0.10 +docker.ra-tech.pro. IN A 10.8.0.10 +sonar.ra-tech.pro. IN A 10.8.0.10 +cloud.ra-tech.pro. IN A 10.8.0.10 +dashboard.cloud.ra-tech.pro. IN A 10.8.0.10 +db.ra-tech.pro. IN A 10.8.0.10 +garden-manager.db.ra-tech.pro. IN A 10.8.0.10 +giga-ai-agent.db.ra-tech.pro. IN A 10.8.0.10 +vault.ra-tech.pro. IN A 10.8.0.10 +docker-registry.ra-tech.pro. IN A 10.8.0.10 +snapshots.docker-registry.ra-tech.pro. IN A 10.8.0.10 +pki.ra-tech.pro. IN A 10.8.0.10 +prometheus.ra-tech.pro. IN A 10.8.0.10 +grafana.ra-tech.pro. IN A 10.8.0.10 +syncthing.ra-tech.pro. IN A 10.8.0.10 +kuber.ra-tech.pro. IN A 10.8.0.10 +garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10 +garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10 +api.garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10 +api.garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10 +solr.ra-tech.pro. IN A 10.8.0.10 +auth.ra-tech.pro. IN A 10.8.0.10 +api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10 +api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10 +giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10 +giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10 +hfs.ra-tech.pro. IN A 10.8.0.10 +kafka-1.ra-tech.pro. IN A 10.8.0.10 +kafka.ra-tech.pro. IN A 10.8.0.10 +elasticsearch.ra-tech.pro. IN A 10.8.0.10 +kibana.ra-tech.pro. IN A 10.8.0.10 +chrome.selenium.ra-tech.pro. IN A 10.8.0.10 +git.ra-tech.pro. IN A 10.8.0.10 diff --git a/bind9/zones/db.v9.ra-tech.pro b/bind9/zones/db.v9.ra-tech.pro new file mode 100644 index 0000000..bd54346 --- /dev/null +++ b/bind9/zones/db.v9.ra-tech.pro @@ -0,0 +1,54 @@ +; +; BIND data file for local loopback interface +; +$TTL 604800 +@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. ( + 1 ; Serial + 604800 ; Refresh + 86400 ; Retry + 2419200 ; Expire + 604800 ) ; Negative Cache TTL + +; name servers - NS records + IN NS ns.ra-tech.pro. + +; name servers - A records +ns.ra-tech.pro. IN A 10.9.0.1 + +; 10.8.0.0/24 - A records +vps.ra-tech.pro. IN A 10.9.0.1 +odroid.ra-tech.pro. IN A 10.9.0.10 +jenkins.ra-tech.pro. IN A 10.9.0.10 +nexus.ra-tech.pro. IN A 10.9.0.10 +docker.ra-tech.pro. IN A 10.9.0.10 +sonar.ra-tech.pro. IN A 10.9.0.10 +cloud.ra-tech.pro. IN A 10.9.0.10 +dashboard.cloud.ra-tech.pro. IN A 10.9.0.10 +db.ra-tech.pro. IN A 10.9.0.10 +garden-manager.db.ra-tech.pro. IN A 10.9.0.10 +giga-ai-agent.db.ra-tech.pro. IN A 10.9.0.10 +vault.ra-tech.pro. IN A 10.9.0.10 +docker-registry.ra-tech.pro. IN A 10.9.0.10 +snapshots.docker-registry.ra-tech.pro. IN A 10.9.0.10 +pki.ra-tech.pro. IN A 10.9.0.10 +prometheus.ra-tech.pro. IN A 10.9.0.10 +grafana.ra-tech.pro. IN A 10.9.0.10 +syncthing.ra-tech.pro. IN A 10.9.0.10 +kuber.ra-tech.pro. IN A 10.9.0.10 +garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10 +garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10 +api.garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10 +api.garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10 +solr.ra-tech.pro. IN A 10.9.0.10 +auth.ra-tech.pro. IN A 10.9.0.10 +api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10 +api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10 +giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10 +giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10 +hfs.ra-tech.pro. IN A 10.9.0.10 +kafka-1.ra-tech.pro. IN A 10.9.0.10 +kafka.ra-tech.pro. IN A 10.9.0.10 +elasticsearch.ra-tech.pro. IN A 10.9.0.10 +kibana.ra-tech.pro. IN A 10.9.0.10 +chrome.selenium.ra-tech.pro. IN A 10.9.0.10 +git.ra-tech.pro. IN A 10.9.0.10 diff --git a/cloak/cloak.service b/cloak/cloak.service new file mode 100644 index 0000000..c385a9d --- /dev/null +++ b/cloak/cloak.service @@ -0,0 +1,12 @@ +[Unit] +Description=Cloak server +After=network.target + +[Service] +ExecStart=/usr/local/bin/ck-server -c /etc/cloak/server.json +Restart=always +Type=exec +User=cloak + +[Install] +WantedBy=default.target \ No newline at end of file diff --git a/cloak/server.json.j2 b/cloak/server.json.j2 new file mode 100644 index 0000000..1805948 --- /dev/null +++ b/cloak/server.json.j2 @@ -0,0 +1,21 @@ +{ + "ProxyBook": { + "openvpn": [ + "tcp", + "{{ public_ip }}:5690" + ] + }, + "BindAddr": [ + ":5691" + ], + "BypassUID": [ + "hs3Zsj/9mvt7+3bhgkg7Tw==", + "VF3YuD37EPGcMyfJOBM+zw==", + "2GT18pqRxb6BOqJWQK42rg==", + "LN9ESPPnGDN5bU4qJJGm3Q==" + ], + "RedirAddr": "vk.ru", + "PrivateKey": "cFMDGEt3L8Rm7APM9creW3KBrYrVP3pIjZvlNgV32Fs=", + "AdminUID": "rVobMUVWAh1Do4QF/wzdVw==", + "DatabasePath": "/opt/cloak/userinfo.db" +} \ No newline at end of file diff --git a/ejabberd/ejabberd.yaml b/ejabberd/ejabberd.yaml new file mode 100644 index 0000000..a369abb --- /dev/null +++ b/ejabberd/ejabberd.yaml @@ -0,0 +1,200 @@ +hosts: + - ra-tech.dev + - xmpp.ra-itech.ru + +hosts_alias: + "64.188.58.223": "ra-tech.dev" + +language: ru + +loglevel: info + +certfiles: + - /etc/ejabberd/server.pem + - /etc/ejabberd/server-key.pem + - /etc/ejabberd/certs/fullchain.pem + - /etc/ejabberd/certs/privkey.pem + +auth_method: internal +auth_password_format: scram +auth_scram_hash: sha512 + +sql_database: /opt/ejabberd/sqlite/db.sqlite +sql_type: sqlite +sql_pool_size: 1 + +s2s_access: + deny: all + +acl: + admin: + user: + - kodacci@ra-tech.dev + - kodacci@xmpp.ra-itech.ru + disabled_servers: + server: + - "p2.siacs.eu" + +access_rules: + configure: + allow: admin + announce: + allow: admin + c2s: + deny: blocked + allow: all + pubsub_createnode: + allow: admin + s2s: + deny: disabled_servers + +shaper: + fast: 3000000 + +shaper_rules: + max_user_sessions: 50 + max_user_offline_messages: 5000 + c2s_shaper: fast + +modules: + mod_adhoc: {} + mod_adhoc_api: {} + mod_admin_extra: {} + mod_announce: + access: announce + mod_avatar: {} + mod_blocking: {} + mod_bosh: {} + mod_caps: {} + mod_carboncopy: {} + mod_client_state: {} + mod_configure: {} + mod_disco: {} + mod_fail2ban: {} + mod_http_api: {} + mod_last: {} + mod_muc: + access_admin: + - allow: admin + mod_muc_admin: {} + mod_offline: + access_max_user_messages: max_user_offline_messages + mod_ping: + send_pings: true + ping_interval: 1 min + mod_privacy: {} + mod_private: {} + mod_push: {} + mod_push_keepalive: {} + mod_roster: + versioning: true + mod_s2s_bidi: {} + mod_s2s_dialback: {} + mod_shared_roster: {} + mod_stream_mgmt: + resend_on_timeout: if_offline + mod_stun_disco: + access: c2s + credentials_lifetime: 12h + services: + - host: xmpp.ra-itech.ru + port: 3478 + type: stun + transport: udp + restricted: false + - host: xmpp.ra-itech.ru + port: 3478 + type: turn + transport: udp + restricted: true + - host: xmpp.ra-itech.ru + port: 5349 + type: stuns + transport: tcp + restricted: false + - host: xmpp.ra-itech.ru + port: 5349 + type: turns + transport: tcp + restricted: true + mod_vcard: {} + mod_vcard_xupdate: {} + mod_version: + show_os: false + mod_pubsub: + access_createnode: pubsub_createnode + plugins: + - flat + - pep + force_node_config: + ## Avoid buggy clients to make their bookmarks public + storage:bookmarks: + access_model: whitelist + mod_proxy65: + access: c2s + max_connections: 50 + port: 7788 + shaper: fast + mod_http_fileserver: + accesslog: /opt/ejabberd/logs/access.log + docroot: + /files: /opt/fileserver + mod_http_upload: + access: c2s + docroot: /opt/fileserver + put_url: "https://@HOST@:5443/upload" + get_url: "https://@HOST@:5443/files" + mod_mam: + access_preferences: c2s + db_type: sql + +listen: + - port: 5222 + ip: "::" + module: ejabberd_c2s + shaper: c2s_shaper + access: c2s + max_stanza_size: 262144 + starttls: true + allow_unencrypted_sasl2: false + cafile: /etc/ejabberd/ca.pem + starttls_required: true + tls_verify: true + + - port: 5223 + ip: "::" + module: ejabberd_c2s + shaper: c2s_shaper + access: c2s + max_stanza_size: 262144 + starttls: true + starttls_required: true + tls_verify: false + + - port: 3478 + transport: udp + module: ejabberd_stun + use_turn: true + turn_min_port: 49152 + turn_max_port: 65535 + turn_ip: 64.188.58.223 + + - port: 5349 + transport: tcp + module: ejabberd_stun + use_turn: true + tls: true + turn_min_port: 49152 + turn_max_port: 65535 + ip: 64.188.58.223 + turn_ip: 64.188.58.223 + + - port: 5443 + ip: "::" + transport: tcp + module: ejabberd_http + tls: true + request_handlers: + /files: mod_http_fileserver + /upload: mod_http_upload + /bosh: mod_bosh \ No newline at end of file diff --git a/haproxy/haproxy.cfg b/haproxy/haproxy.cfg new file mode 100644 index 0000000..0c27df2 --- /dev/null +++ b/haproxy/haproxy.cfg @@ -0,0 +1,58 @@ +global + log /dev/log local0 + log /dev/log local1 notice + chroot /var/lib/haproxy + stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners + stats timeout 30s + user haproxy + group haproxy + daemon + + # Default SSL material locations + ca-base /etc/ssl/certs + crt-base /etc/ssl/private + + # See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate + #ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 + #ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256 + #ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets + +defaults + log global + mode http + option httplog + option dontlognull + timeout connect 5000 + timeout client 50000 + timeout server 50000 + errorfile 400 /etc/haproxy/errors/400.http + errorfile 403 /etc/haproxy/errors/403.http + errorfile 408 /etc/haproxy/errors/408.http + errorfile 500 /etc/haproxy/errors/500.http + errorfile 502 /etc/haproxy/errors/502.http + errorfile 503 /etc/haproxy/errors/503.http + errorfile 504 /etc/haproxy/errors/504.http + +frontend jenkins_webhook_front + mode http + bind :7777 ssl crt /etc/haproxy/certs/64.188.58.223.pem + http-request set-header X-Forwarded-For %[src] + use_backend jenkins_webhook_back if { path /github-webhook/ } || { path /github-webhook } + +backend jenkins_webhook_back + mode http + http-request set-header Host jenkins.ra-tech.pro + server jenkins_main jenkins.ra-tech.pro:443 ssl verify none check resolvers nameservers + +resolvers nameservers + nameserver ra-tech 10.8.0.1:53 + #nameserver google 8.8.8.8:53 + +frontend stats + bind 10.8.0.1:8404 + bind 10.9.0.1:8404 + mode http + http-request use-service prometheus-exporter if { path /metrics } + stats enable + stats uri /stats + stats refresh 15s diff --git a/inventory.yaml b/inventory.yaml new file mode 100644 index 0000000..a737a9e --- /dev/null +++ b/inventory.yaml @@ -0,0 +1,14 @@ +vps_servers: + vars: + ansible_become: true + ansible_become_user: root + ansible_become_method: su + ansible_user: kodacci + hosts: + ru-vpn: + ansible_host: ru-vpn.ra-itech.ru + public_ip: 45.87.247.103 + public_ip_iface: ens3 + ansible_port: 12801 + + diff --git a/node-exporter/node-exporter.service b/node-exporter/node-exporter.service new file mode 100644 index 0000000..aa5fee8 --- /dev/null +++ b/node-exporter/node-exporter.service @@ -0,0 +1,15 @@ +[Unit] +Description=Node Exporter +Wants=network-online.target +After=network-online.target + +[Service] +User=node_exporter +Group=node_exporter +Type=simple +ExecStart=/usr/local/bin/node_exporter +Restart=always +RestartSec=3 + +[Install] +WantedBy=multi-user.target \ No newline at end of file diff --git a/openvpn/certs/ta.key b/openvpn/certs/ta.key new file mode 100644 index 0000000..20c7c71 --- /dev/null +++ b/openvpn/certs/ta.key @@ -0,0 +1,21 @@ +# +# 2048 bit OpenVPN static key +# +-----BEGIN OpenVPN Static key V1----- +ca6b90a1782a8940fbfd685dd1c92cff +7958116231f3f096569271880c54a53f +0aeb0872933e9ca7c3efaaed3b63831b +21be29430b4dd8634200131a197470de +061d716c133e25f7edd3802beba11851 +f5c1347f63c1ce072ba26219a9f68f13 +76057ff561468d267792e0f249342956 +d4df6c72efffcc21c7d09d1b5415cebc +bf4cdc0369bc8bc16a86a7b7c5f61ae5 +9b87777aeccdbcf9d50f15aa4427adb8 +2263df1c1475471989a8eff935e0c5ac +e85580b0f90633bf92570aaa15910850 +d4017e502f0eeaf46f555ff9740c655c +26db7bf2f06948249e75a869d4d47e89 +847ce8f14969a5cc3b60928838146305 +797f11d4cf08d4c06223c47747ec8798 +-----END OpenVPN Static key V1----- diff --git a/openvpn/server.conf b/openvpn/server.conf new file mode 100644 index 0000000..11fdf5f --- /dev/null +++ b/openvpn/server.conf @@ -0,0 +1,320 @@ +################################################# +# Sample OpenVPN 2.0 config file for # +# multi-client server. # +# # +# This file is for the server side # +# of a many-clients <-> one-server # +# OpenVPN configuration. # +# # +# OpenVPN also supports # +# single-machine <-> single-machine # +# configurations (See the Examples page # +# on the web site for more info). # +# # +# This config should work on Windows # +# or Linux/BSD systems. Remember on # +# Windows to quote pathnames and use # +# double backslashes, e.g.: # +# "C:\\Program Files\\OpenVPN\\config\\foo.key" # +# # +# Comments are preceded with '#' or ';' # +################################################# + +# Which local IP address should OpenVPN +# listen on? (optional) +;local a.b.c.d + +# Which TCP/UDP port should OpenVPN listen on? +# If you want to run multiple OpenVPN instances +# on the same machine, use a different port +# number for each one. You will need to +# open up this port on your firewall. +# port 1194 +port 5690 + +# TCP or UDP server? +proto tcp +;proto udp + +# "dev tun" will create a routed IP tunnel, +# "dev tap" will create an ethernet tunnel. +# Use "dev tap0" if you are ethernet bridging +# and have precreated a tap0 virtual interface +# and bridged it with your ethernet interface. +# If you want to control access policies +# over the VPN, you must create firewall +# rules for the the TUN/TAP interface. +# On non-Windows systems, you can give +# an explicit unit number, such as tun0. +# On Windows, use "dev-node" for this. +# On most systems, the VPN will not function +# unless you partially or fully disable +# the firewall for the TUN/TAP interface. +;dev tap +dev tun + +# Windows needs the TAP-Win32 adapter name +# from the Network Connections panel if you +# have more than one. On XP SP2 or higher, +# you may need to selectively disable the +# Windows firewall for the TAP adapter. +# Non-Windows systems usually don't need this. +;dev-node MyTap + +# SSL/TLS root certificate (ca), certificate +# (cert), and private key (key). Each client +# and the server must have their own cert and +# key file. The server and all clients will +# use the same ca file. +# +# See the "easy-rsa" directory for a series +# of scripts for generating RSA certificates +# and private keys. Remember to use +# a unique Common Name for the server +# and each of the client certificates. +# +# Any X509 key management system can be used. +# OpenVPN can also use a PKCS #12 formatted key file +# (see "pkcs12" directive in man page). +ca ca.pem +cert server.pem +key server-key.pem # This file should be kept secret + +# Diffie hellman parameters. +# Generate your own with: +# openssl dhparam -out dh2048.pem 2048 +#dh dh2048.pem +dh none + +# Network topology +# Should be subnet (addressing via IP) +# unless Windows clients v2.0.9 and lower have to +# be supported (then net30, i.e. a /30 per client) +# Defaults to net30 (not recommended) +;topology subnet + +# Configure server mode and supply a VPN subnet +# for OpenVPN to draw client addresses from. +# The server will take 10.8.0.1 for itself, +# the rest will be made available to clients. +# Each client will be able to reach the server +# on 10.8.0.1. Comment this line out if you are +# ethernet bridging. See the man page for more info. +server 10.8.0.0 255.255.255.0 + +# Maintain a record of client <-> virtual IP address +# associations in this file. If OpenVPN goes down or +# is restarted, reconnecting clients can be assigned +# the same virtual IP address from the pool that was +# previously assigned. +ifconfig-pool-persist /var/log/openvpn/ipp.txt + +# Configure server mode for ethernet bridging. +# You must first use your OS's bridging capability +# to bridge the TAP interface with the ethernet +# NIC interface. Then you must manually set the +# IP/netmask on the bridge interface, here we +# assume 10.8.0.4/255.255.255.0. Finally we +# must set aside an IP range in this subnet +# (start=10.8.0.50 end=10.8.0.100) to allocate +# to connecting clients. Leave this line commented +# out unless you are ethernet bridging. +;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100 + +# Configure server mode for ethernet bridging +# using a DHCP-proxy, where clients talk +# to the OpenVPN server-side DHCP server +# to receive their IP address allocation +# and DNS server addresses. You must first use +# your OS's bridging capability to bridge the TAP +# interface with the ethernet NIC interface. +# Note: this mode only works on clients (such as +# Windows), where the client-side TAP adapter is +# bound to a DHCP client. +;server-bridge + +# Push routes to the client to allow it +# to reach other private subnets behind +# the server. Remember that these +# private subnets will also need +# to know to route the OpenVPN client +# address pool (10.8.0.0/255.255.255.0) +# back to the OpenVPN server. +;push "route 192.168.10.0 255.255.255.0" +;push "route 192.168.20.0 255.255.255.0" + +# To assign specific IP addresses to specific +# clients or if a connecting client has a private +# subnet behind it that should also have VPN access, +# use the subdirectory "ccd" for client-specific +# configuration files (see man page for more info). + +# EXAMPLE: Suppose the client +# having the certificate common name "Thelonious" +# also has a small subnet behind his connecting +# machine, such as 192.168.40.128/255.255.255.248. +# First, uncomment out these lines: +;client-config-dir ccd +;route 192.168.40.128 255.255.255.248 +# Then create a file ccd/Thelonious with this line: +# iroute 192.168.40.128 255.255.255.248 +# This will allow Thelonious' private subnet to +# access the VPN. This example will only work +# if you are routing, not bridging, i.e. you are +# using "dev tun" and "server" directives. + +# EXAMPLE: Suppose you want to give +# Thelonious a fixed VPN IP address of 10.9.0.1. +# First uncomment out these lines: +;client-config-dir ccd +;route 10.9.0.0 255.255.255.252 +# Then add this line to ccd/Thelonious: +# ifconfig-push 10.9.0.1 10.9.0.2 + +# Suppose that you want to enable different +# firewall access policies for different groups +# of clients. There are two methods: +# (1) Run multiple OpenVPN daemons, one for each +# group, and firewall the TUN/TAP interface +# for each group/daemon appropriately. +# (2) (Advanced) Create a script to dynamically +# modify the firewall in response to access +# from different clients. See man +# page for more info on learn-address script. +;learn-address ./script + +# If enabled, this directive will configure +# all clients to redirect their default +# network gateway through the VPN, causing +# all IP traffic such as web browsing and +# and DNS lookups to go through the VPN +# (The OpenVPN server machine may need to NAT +# or bridge the TUN/TAP interface to the internet +# in order for this to work properly). +push "redirect-gateway def1 bypass-dhcp" + +# Certain Windows-specific network settings +# can be pushed to clients, such as DNS +# or WINS server addresses. CAVEAT: +# http://openvpn.net/faq.html#dhcpcaveats +# The addresses below refer to the public +# DNS servers provided by opendns.com. +# push "dhcp-option DNS 208.67.222.222" +push "dhcp-option DNS 10.8.0.1" +push "dhcp-option DNS 208.67.220.220" + +# Uncomment this directive to allow different +# clients to be able to "see" each other. +# By default, clients will only see the server. +# To force clients to only see the server, you +# will also need to appropriately firewall the +# server's TUN/TAP interface. +;client-to-client + +# Uncomment this directive if multiple clients +# might connect with the same certificate/key +# files or common names. This is recommended +# only for testing purposes. For production use, +# each client should have its own certificate/key +# pair. +# +# IF YOU HAVE NOT GENERATED INDIVIDUAL +# CERTIFICATE/KEY PAIRS FOR EACH CLIENT, +# EACH HAVING ITS OWN UNIQUE "COMMON NAME", +# UNCOMMENT THIS LINE OUT. +;duplicate-cn + +# The keepalive directive causes ping-like +# messages to be sent back and forth over +# the link so that each side knows when +# the other side has gone down. +# Ping every 10 seconds, assume that remote +# peer is down if no ping received during +# a 120 second time period. +keepalive 10 120 + +# For extra security beyond that provided +# by SSL/TLS, create an "HMAC firewall" +# to help block DoS attacks and UDP port flooding. +# +# Generate with: +# openvpn --genkey --secret ta.key +# +# The server and each client must have +# a copy of this key. +# The second parameter should be '0' +# on the server and '1' on the clients. +#tls-auth ta.key 0 # This file is secret +tls-crypt ta.key + +# Select a cryptographic cipher. +# This config item must be copied to +# the client config file as well. +# Note that v2.4 client/server will automatically +# negotiate AES-256-GCM in TLS mode. +# See also the ncp-cipher option in the manpage +cipher AES-256-GCM +auth SHA256 + +# Enable compression on the VPN link and push the +# option to the client (v2.4+ only, for earlier +# versions see below) +;compress lz4-v2 +;push "compress lz4-v2" + +# For compression compatible with older clients use comp-lzo +# If you enable it here, you must also +# enable it in the client config file. +;comp-lzo + +# The maximum number of concurrently connected +# clients we want to allow. +;max-clients 100 + +# It's a good idea to reduce the OpenVPN +# daemon's privileges after initialization. +# +# You can uncomment this out on +# non-Windows systems. +user nobody +group nogroup + +# The persist options will try to avoid +# accessing certain resources on restart +# that may no longer be accessible because +# of the privilege downgrade. +persist-key +persist-tun + +# Output a short status file showing +# current connections, truncated +# and rewritten every minute. +status /var/log/openvpn/openvpn-status.log + +# By default, log messages will go to the syslog (or +# on Windows, if running as a service, they will go to +# the "\Program Files\OpenVPN\log" directory). +# Use log or log-append to override this default. +# "log" will truncate the log file on OpenVPN startup, +# while "log-append" will append to it. Use one +# or the other (but not both). +;log /var/log/openvpn/openvpn.log +;log-append /var/log/openvpn/openvpn.log + +# Set the appropriate level of log +# file verbosity. +# +# 0 is silent, except for fatal errors +# 4 is reasonable for general usage +# 5 and 6 can help to debug connection problems +# 9 is extremely verbose +verb 3 + +# Silence repeating messages. At most 20 +# sequential messages of the same message +# category will be output to the log. +;mute 20 + +# Notify the client that when the server restarts so it +# can automatically reconnect. +explicit-exit-notify 1 \ No newline at end of file diff --git a/playbook.yaml b/playbook.yaml new file mode 100644 index 0000000..1b41fa5 --- /dev/null +++ b/playbook.yaml @@ -0,0 +1,503 @@ +- name: Setup ufw port forwarding for VPNs subnets + hosts: vps_servers + become: true + gather_facts: true + tasks: + - name: Install ufw + ansible.builtin.apt: + name: ufw + state: present + update_cache: true + + # - name: Configure ufw port forwarding + # ansible.builtin.lineinfile: + # path: '/etc/sysctl.conf' + # regexp: '^#?net.ipv4.ip_forward=' + # line: 'net.ipv4.ip_forward=1' + # state: present + # notify: Reload sysctl + + - name: Configure ufw port forwarding + ansible.builtin.copy: + src: 'sysctl/99-ipv4-forward.conf' + dest: '/etc/sysctl.d/99-ipv4-forward.conf' + owner: root + group: root + mode: '0644' + notify: Reload sysctl + + - name: Set ufw default forwarding policy + ansible.builtin.lineinfile: + path: '/etc/default/ufw' + regexp: '^DEFAULT_FORWARD_POLICY=' + line: 'DEFAULT_FORWARD_POLICY="ACCEPT"' + state: present + notify: Reload ufw + + - name: Add postrouting nat + ansible.builtin.blockinfile: + path: '/etc/ufw/before.rules' + insertbefore: '^\*filter' + block: | + # VPN NAT + *nat + :POSTROUTING ACCEPT [0:0] + -A POSTROUTING -s 10.9.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE + -A POSTROUTING -s 10.8.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE + -A POSTROUTING -s 10.10.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE + COMMIT + # END VPN NAT + notify: Reload ufw + + handlers: + - name: Reload sysctl + ansible.builtin.command: sysctl -p /etc/sysctl.d/99-ipv4-forward.conf + register: result + changed_when: result.rc == 0 + + - name: Reload ufw + ansible.builtin.command: ufw reload + register: result + changed_when: result.rc == 0 + +- name: Setup strongswan + hosts: vps_servers + become: true + gather_facts: true + tasks: + - name: Uninstall strongswan legacy packages if present + ansible.builtin.apt: + name: + - strongswan-starter + - strongswan-charon + state: absent + purge: true + autoremove: true + + - name: Install strongswan with swanctl and vici + ansible.builtin.apt: + name: + - charon-systemd + - strongswan-swanctl + - libcharon-extra-plugins + state: present + update_cache: true + + - name: Copy strongswan config + ansible.builtin.template: + src: 'strongswan/ra-tech.conf.j2' + dest: '/etc/swanctl/conf.d/ra-tech.conf' + owner: root + group: root + mode: '0644' + + - name: Copy strongswan dhcp module config + ansible.builtin.template: + src: 'strongswan/charon/dhcp.conf.j2' + dest: '/etc/strongswan.d/charon/dhcp.conf' + owner: root + group: root + mode: '0644' + + - name: Copy Root CA + ansible.builtin.copy: + src: 'strongswan/ca.pem' + dest: '/etc/swanctl/x509ca/ca-crt.pem' + owner: root + group: root + mode: '0644' + + - name: Copy keys + ansible.builtin.copy: + src: 'strongswan/keys/' + dest: '/etc/swanctl/rsa/' + owner: root + group: root + mode: '0640' + + - name: Copy certificates + ansible.builtin.copy: + src: 'strongswan/certs/' + dest: '/etc/swanctl/x509/' + owner: root + group: root + mode: '0644' + notify: + - Restart strongswan service + + - name: Configure ra0 iface + ansible.builtin.script: 'strongswan/iface-ra0-up.sh' + + - name: Copy ra0 iface setup script + ansible.builtin.copy: + src: 'strongswan/iface-ra0-up.sh' + dest: '/usr/local/bin' + owner: root + group: root + mode: '0755' + + - name: Copy ra0 startup service + ansible.builtin.copy: + src: 'strongswan/iface-ra0.service' + dest: '/etc/systemd/system/iface-ra0.service' + owner: root + group: root + mode: '0644' + notify: + - Reload ra0 startup service + + - name: Ufw allow strongswan ports + community.general.ufw: + rule: allow + proto: udp + port: '{{ item }}' + loop: + - '500' + - '4500' + + - name: Ufw allow from vpn subnet + community.general.ufw: + rule: allow + proto: any + src: '10.9.0.0/24' + + handlers: + - name: Restart strongswan service + ansible.builtin.systemd: + name: strongswan + state: restarted + enabled: true + + - name: Reload ra0 startup service + ansible.builtin.systemd: + name: iface-ra0.service + enabled: true + daemon_reload: true + +- name: Setup cloak + hosts: vps_servers + become: true + tasks: + - name: Create go download directory + ansible.builtin.file: + path: /opt/go + state: directory + mode: '0755' + + - name: Download go + ansible.builtin.get_url: + url: 'https://go.dev/dl/go1.26.0.linux-amd64.tar.gz' + dest: '/opt/go/go1.26.0.linux-amd64.tar.gz' + mode: '0644' + timeout: 60 + + - name: Unpack go + ansible.builtin.unarchive: + src: '/opt/go/go1.26.0.linux-amd64.tar.gz' + dest: '/usr/local' + remote_src: true + + - name: Install git and make + ansible.builtin.apt: + name: + - git + - make + state: present + update_cache: true + + - name: Clone cloak git repository + ansible.builtin.git: + repo: 'https://github.com/cbeuw/Cloak.git' + dest: '/opt/git/Cloak' + single_branch: true + version: master + + - name: Build cloak + community.general.make: + chdir: '/opt/git/Cloak' + environment: + PATH: '{{ ansible_env.PATH }}:/usr/local/go/bin' + + - name: Setup cloak server + ansible.builtin.copy: + src: '/opt/git/Cloak/build/ck-server' + remote_src: true + dest: '/usr/local/bin' + owner: 'root' + group: 'root' + mode: '0755' + + - name: Add cloak group + ansible.builtin.group: + name: cloak + state: present + + - name: Add user for cloak + ansible.builtin.user: + name: cloak + group: cloak + state: present + createhome: false + + - name: Create cloak directory + ansible.builtin.file: + path: '/etc/cloak' + state: directory + mode: '0755' + + - name: Setup cloak server configuration + ansible.builtin.template: + src: 'cloak/server.json.j2' + dest: '/etc/cloak/server.json' + owner: root + group: cloak + mode: '0644' + + - name: Create cloak server data dir + ansible.builtin.file: + path: '/opt/cloak' + state: directory + owner: cloak + group: cloak + mode: '0755' + + - name: Setup cloak systemd service + ansible.builtin.copy: + src: 'cloak/cloak.service' + dest: '/etc/systemd/system/cloak.service' + mode: '0644' + notify: Reload cloak service + + - name: Ufw allow cloak port + community.general.ufw: + rule: allow + port: '5691' + proto: tcp + + handlers: + - name: Reload cloak service + ansible.builtin.systemd: + name: cloak.service + state: started + enabled: false + daemon_reload: true + +- name: Setup openvpn server + hosts: vps_servers + become: true + tasks: + - name: Install openvpn server + ansible.builtin.apt: + name: openvpn + state: present + update_cache: true + + - name: Copy certificates + ansible.builtin.copy: + src: 'openvpn/certs/' + dest: '/etc/openvpn/server/' + owner: root + group: root + mode: '0640' + + - name: Copy openvpn config + ansible.builtin.copy: + src: 'openvpn/server.conf' + dest: '/etc/openvpn/server/server.conf' + owner: root + group: root + mode: '0644' + notify: + - Restart openvpn server + + - name: Ufw allow openvpn port + community.general.ufw: + rule: allow + proto: tcp + port: '5690' + + - name: Ufw allow from vpn subnet + community.general.ufw: + rule: allow + proto: any + src: '10.8.0.0/24' + + handlers: + - name: Restart openvpn server + ansible.builtin.systemd: + name: openvpn-server@server + state: restarted + enabled: true + +- name: Setup bind9 + hosts: vps_servers + become: true + tasks: + - name: Install bind9 + ansible.builtin.apt: + name: bind9 + state: present + update_cache: true + + - name: Copy bind9 config + ansible.builtin.copy: + src: '{{ item }}' + dest: '/etc/bind/' + owner: root + group: bind + mode: '0644' + loop: + - 'bind9/named.conf.local' + - 'bind9/named.conf.options' + - 'bind9/named.conf.default-zones' + - 'bind9/named.conf.root-hints' + + - name: Copy bind9 zones + ansible.builtin.copy: + src: 'bind9/zones/' + dest: '/etc/bind/zones/' + owner: root + group: bind + mode: '0644' + notify: + - Restart bind9 + + - name: Ufw allow bind9 ports + community.general.ufw: + rule: allow + name: Bind9 + + handlers: + - name: Restart bind9 + ansible.builtin.systemd: + name: named + state: restarted + enabled: true + daemon_reload: true + +- name: Setup prometheus node exporter + hosts: vps_servers + become: true + tasks: + - name: Create node-exporter download directory + ansible.builtin.file: + path: /opt/node-exporter + state: directory + mode: '0755' + + - name: Download node exporter executable + ansible.builtin.get_url: + url: 'https://github.com/prometheus/node_exporter/releases/download/v1.10.2/node_exporter-1.10.2.linux-amd64.tar.gz' + dest: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz' + mode: '0644' + + - name: Extract node_exporter + ansible.builtin.unarchive: + src: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz' + dest: '/usr/local/bin' + remote_src: true + include: + - 'node_exporter-1.10.2.linux-amd64/node_exporter' + extra_opts: + - '--strip-components=1' + + - name: Add node-exporter group + ansible.builtin.group: + name: node_exporter + state: present + + - name: Add user for node exporter + ansible.builtin.user: + name: node_exporter + group: node_exporter + state: present + createhome: false + + - name: Setup node-exporter service + ansible.builtin.copy: + src: 'node-exporter/node-exporter.service' + dest: '/etc/systemd/system/node-exporter.service' + owner: root + group: root + mode: '0644' + notify: Reload node-exporter + + handlers: + - name: Reload node-exporter + ansible.builtin.systemd: + name: node-exporter + state: started + enabled: true + daemon_reload: true + +- name: Setup haproxy + hosts: vps_servers + become: true + tasks: + - name: Install haproxy + ansible.builtin.apt: + name: haproxy + state: present + update_cache: true + + - name: Create haproxy certs directory + ansible.builtin.file: + path: /etc/haproxy/certs/ + state: directory + owner: root + group: haproxy + mode: '0755' + + - name: Copy server certificate and key + ansible.builtin.copy: + src: 'haproxy/64.188.58.223.pem' + dest: '/etc/haproxy/certs/64.188.58.223.pem' + owner: root + group: haproxy + mode: '0640' + + - name: Copy configuration + ansible.builtin.copy: + src: 'haproxy/haproxy.cfg' + dest: '/etc/haproxy/haproxy.cfg' + owner: root + group: haproxy + mode: '0644' + notify: Restart haproxy + + - name: Allow ufw jenkins webhook port + community.general.ufw: + rule: allow + port: '7777' + proto: tcp + + handlers: + - name: Restart haproxy + ansible.builtin.systemd: + name: haproxy + state: restarted + enabled: true + +- name: Setup tiny proxy + hosts: vps_servers + become: true + tasks: + - name: Install tiny proxy + ansible.builtin.apt: + name: tinyproxy + state: present + update_cache: true + + - name: Configure tiny proxy + ansible.builtin.copy: + src: 'tinyproxy/tinyproxy.conf' + dest: '/etc/tinyproxy/tinyproxy.conf' + mode: '0644' + notify: Restart tinyproxy + + handlers: + - name: Restart tinyproxy + ansible.builtin.systemd: + name: tinyproxy + state: restarted + enabled: true diff --git a/strongswan/charon/dhcp.conf.j2 b/strongswan/charon/dhcp.conf.j2 new file mode 100644 index 0000000..9a47eaf --- /dev/null +++ b/strongswan/charon/dhcp.conf.j2 @@ -0,0 +1,6 @@ +dhcp { + load = yes + force_server_address = yes + server = 10.9.0.255 + interface = {{ public_ip_iface }} +} \ No newline at end of file diff --git a/strongswan/iface-ra0-up.sh b/strongswan/iface-ra0-up.sh new file mode 100644 index 0000000..b98c12f --- /dev/null +++ b/strongswan/iface-ra0-up.sh @@ -0,0 +1,14 @@ +#!/bin/bash + +set +e + +echo "Confiugring ra0 network interface at $(date)" + +ip link add ra0 type xfrm if_id 0x21 +ip link set ra0 up +ip addr add 10.9.0.1/24 brd + dev ra0 +ip route add 10.9.0.0/24 dev ra0 + +set -e + +exit 0 \ No newline at end of file diff --git a/strongswan/iface-ra0.service b/strongswan/iface-ra0.service new file mode 100644 index 0000000..d59aaed --- /dev/null +++ b/strongswan/iface-ra0.service @@ -0,0 +1,11 @@ +[Unit] +Description=Configure ra0 interface on startup +After=network.target + +[Service] +ExecStart=/usr/local/bin/iface-ra0-up.sh +Type=oneshot +RemainAfterExit=yes + +[Install] +WantedBy=multi-user.target \ No newline at end of file diff --git a/strongswan/ra-tech.conf.j2 b/strongswan/ra-tech.conf.j2 new file mode 100644 index 0000000..b95d42a --- /dev/null +++ b/strongswan/ra-tech.conf.j2 @@ -0,0 +1,92 @@ +connections { + ra-tech { + pools = ra-tech-pool + local { + auth = pubkey + certs = vps-crt.pem + id = vps.ra-tech.dev + } + remote { + auth = pubkey + } + children { + ra-tech { + local_ts = 0.0.0.0/0 + } + } + send_cert = always + if_id_in = 0x21 + if_id_out = 0x21 + } + ra-tech-ip { + pools = ra-tech-pool + local { + auth = pubkey + certs = ip-vps-crt.pem + id = {{ public_ip }} + } + remote { + auth = pubkey + } + children { + ra-tech-ip { + local_ts = 0.0.0.0/0 + } + } + send_cert = always + if_id_in = 0x21 + if_id_out = 0x21 + } + ra-tech-subnet { + pools = ra-tech-pool + local { + auth = pubkey + certs = vpn-subnet-crt.pem + id = vpn-subnet.ra-tech.dev + } + remote { + auth = pubkey + } + children { + ra-tech-subnet { + local_ts = 10.9.0.0/24 + } + } + send_cert = always + if_id_in = 0x21 + if_id_out = 0x21 + } + ra-tech-odroid { + pools = odroid-pool + local { + auth = pubkey + certs = odroid-vps-crt.pem + id = odroid-vps.ra-tech.dev + } + remote { + auth = pubkey + id = odroid@ra-tech.dev + } + children { + ra-tech-odroid { + local_ts = 0.0.0.0/0 + } + } + if_id_in = 0x21 + if_id_out = 0x21 + } +} + +pools { + ra-tech-pool { + addrs = 10.9.0.11 - 10.9.0.30 + dns = 10.9.0.1 + netmask = 255.255.255.0 + } + + odroid-pool { + addrs = 10.9.0.10 + dns = 10.9.0.1 + netmask = 255.255.255.0 + } +} diff --git a/sysctl/99-ipv4-forward.conf b/sysctl/99-ipv4-forward.conf new file mode 100644 index 0000000..119d730 --- /dev/null +++ b/sysctl/99-ipv4-forward.conf @@ -0,0 +1 @@ +net.ipv4.ip_forward=1 diff --git a/tinyproxy/tinyproxy.conf b/tinyproxy/tinyproxy.conf new file mode 100644 index 0000000..b73906a --- /dev/null +++ b/tinyproxy/tinyproxy.conf @@ -0,0 +1,356 @@ +## +## tinyproxy.conf -- tinyproxy daemon configuration file +## +## This example tinyproxy.conf file contains example settings +## with explanations in comments. For decriptions of all +## parameters, see the tinproxy.conf(5) manual page. +## + +# +# User/Group: This allows you to set the user and group that will be +# used for tinyproxy after the initial binding to the port has been done +# as the root user. Either the user or group name or the UID or GID +# number may be used. +# +User tinyproxy +Group tinyproxy + +# +# Port: Specify the port which tinyproxy will listen on. Please note +# that should you choose to run on a port lower than 1024 you will need +# to start tinyproxy using root. +# +Port 8888 + +# +# Listen: If you have multiple interfaces this allows you to bind to +# only one. If this is commented out, tinyproxy will bind to all +# interfaces present. +# +Listen 10.9.0.1 +Listen 10.8.0.1 + +# +# Bind: This allows you to specify which interface will be used for +# outgoing connections. This is useful for multi-home'd machines where +# you want all traffic to appear outgoing from one particular interface. +# +#Bind 192.168.0.1 + +# +# BindSame: If enabled, tinyproxy will bind the outgoing connection to the +# ip address of the incoming connection. +# +#BindSame yes + +# +# Timeout: The maximum number of seconds of inactivity a connection is +# allowed to have before it is closed by tinyproxy. +# +Timeout 600 + +# +# ErrorFile: Defines the HTML file to send when a given HTTP error +# occurs. You will probably need to customize the location to your +# particular install. The usual locations to check are: +# /usr/local/share/tinyproxy +# /usr/share/tinyproxy +# /etc/tinyproxy +# +#ErrorFile 404 "/usr/share/tinyproxy/404.html" +#ErrorFile 400 "/usr/share/tinyproxy/400.html" +#ErrorFile 503 "/usr/share/tinyproxy/503.html" +#ErrorFile 403 "/usr/share/tinyproxy/403.html" +#ErrorFile 408 "/usr/share/tinyproxy/408.html" + +# +# DefaultErrorFile: The HTML file that gets sent if there is no +# HTML file defined with an ErrorFile keyword for the HTTP error +# that has occured. +# +DefaultErrorFile "/usr/share/tinyproxy/default.html" + +# +# StatHost: This configures the host name or IP address that is treated +# as the stat host: Whenever a request for this host is received, +# Tinyproxy will return an internal statistics page instead of +# forwarding the request to that host. The default value of StatHost is +# tinyproxy.stats. +# +StatHost "tinyproxy.stats" +# + +# +# StatFile: The HTML file that gets sent when a request is made +# for the stathost. If this file doesn't exist a basic page is +# hardcoded in tinyproxy. +# +StatFile "/usr/share/tinyproxy/stats.html" + +# +# LogFile: Allows you to specify the location where information should +# be logged to. If you would prefer to log to syslog, then disable this +# and enable the Syslog directive. These directives are mutually +# exclusive. If neither Syslog nor LogFile are specified, output goes +# to stdout. +# +LogFile "/var/log/tinyproxy/tinyproxy.log" + +# +# Syslog: Tell tinyproxy to use syslog instead of a logfile. This +# option must not be enabled if the Logfile directive is being used. +# These two directives are mutually exclusive. +# +Syslog On + +# +# LogLevel: Warning +# +# Set the logging level. Allowed settings are: +# Critical (least verbose) +# Set the logging level. Allowed settings are: +# Critical (least verbose) +# Error +# Warning +# Notice +# Connect (to log connections without Info's noise) +# Info (most verbose) +# +# The LogLevel logs from the set level and above. For example, if the +# LogLevel was set to Warning, then all log messages from Warning to +# Critical would be output, but Notice and below would be suppressed. +# +LogLevel Info + +# +# PidFile: Write the PID of the main tinyproxy thread to this file so it +# can be used for signalling purposes. +# If not specified, no pidfile will be written. +# +PidFile "/run/tinyproxy/tinyproxy.pid" + +# +# XTinyproxy: Tell Tinyproxy to include the X-Tinyproxy header, which +# contains the client's IP address. +# +#XTinyproxy Yes + +# +# Upstream: +# +# Turns on upstream proxy support. +# +# The upstream rules allow you to selectively route upstream connections +# based on the host/domain of the site being accessed. +# +# Syntax: upstream type (user:pass@)ip:port ("domain") +# Or: upstream none "domain" +# The parts in parens are optional. +# Possible types are http, socks4, socks5, none +# +# For example: +# # connection to test domain goes through testproxy +# upstream http testproxy:8008 ".test.domain.invalid" +# upstream http testproxy:8008 ".our_testbed.example.com" +# upstream http testproxy:8008 "192.168.128.0/255.255.254.0" +# +# # upstream proxy using basic authentication +# upstream http user:pass@testproxy:8008 ".test.domain.invalid" +# +# # no upstream proxy for internal websites and unqualified hosts +# upstream none ".internal.example.com" +# upstream none "www.example.com" +# upstream none "10.0.0.0/8" +# upstream none "192.168.0.0/255.255.254.0" +# upstream none "." +# +# # connection to these boxes go through their DMZ firewalls +# upstream http cust1_firewall:8008 "testbed_for_cust1" +# upstream http cust2_firewall:8008 "testbed_for_cust2" +# +# # default upstream is internet firewall +# upstream http firewall.internal.example.com:80 +# +# You may also use SOCKS4/SOCKS5 upstream proxies: +# upstream socks4 127.0.0.1:9050 +# upstream socks5 socksproxy:1080 +# +# The LAST matching rule wins the route decision. As you can see, you +# can use a host, or a domain: +# name matches host exactly +# .name matches any host in domain "name" +# . matches any host with no domain (in 'empty' domain) +# IP/bits matches network/mask +# IP/mask matches network/mask +# +#Upstream http some.remote.proxy:port + +# +# MaxClients: This is the absolute highest number of threads which will +# be created. In other words, only MaxClients number of clients can be +# connected at the same time. +# +MaxClients 100 + +# +# MinSpareServers/MaxSpareServers: These settings set the upper and +# lower limit for the number of spare servers which should be available. +# +# If the number of spare servers falls below MinSpareServers then new +# server processes will be spawned. If the number of servers exceeds +# MaxSpareServers then the extras will be killed off. +# +MinSpareServers 5 +MaxSpareServers 20 + +# +# StartServers: The number of servers to start initially. +# +StartServers 10 + +# +# MaxRequestsPerChild: The number of connections a thread will handle +# before it is killed. In practise this should be set to 0, which +# disables thread reaping. If you do notice problems with memory +# leakage, then set this to something like 10000. +# +MaxRequestsPerChild 0 + +# +# Allow: Customization of authorization controls. If there are any +# access control keywords then the default action is to DENY. Otherwise, +# the default action is ALLOW. +# +# The order of the controls are important. All incoming connections are +# tested against the controls based on order. +# +Allow 127.0.0.1 +Allow 10.9.0.0/24 +Allow 10.8.0.0/24 +#Allow 192.168.0.0/16 +#Allow 172.16.0.0/12 +#Allow 10.0.0.0/8 + +# BasicAuth: HTTP "Basic Authentication" for accessing the proxy. +# If there are any entries specified, access is only granted for authenticated +# users. +#BasicAuth user password + +# +# AddHeader: Adds the specified headers to outgoing HTTP requests that +# Tinyproxy makes. Note that this option will not work for HTTPS +# traffic, as Tinyproxy has no control over what headers are exchanged. +# +#AddHeader "X-My-Header" "Powered by Tinyproxy" + +# +# ViaProxyName: The "Via" header is required by the HTTP RFC, but using +# +# ViaProxyName: The "Via" header is required by the HTTP RFC, but using +# the real host name is a security concern. If the following directive +# is enabled, the string supplied will be used as the host name in the +# Via header; otherwise, the server's host name will be used. +# +ViaProxyName "tinyproxy" + +# +# DisableViaHeader: When this is set to yes, Tinyproxy does NOT add +# the Via header to the requests. This virtually puts Tinyproxy into +# stealth mode. Note that RFC 2616 requires proxies to set the Via +# header, so by enabling this option, you break compliance. +# Don't disable the Via header unless you know what you are doing... +# +#DisableViaHeader Yes + +# +# Filter: This allows you to specify the location of the filter file. +# +#Filter "/etc/tinyproxy/filter" + +# +# FilterURLs: Filter based on URLs rather than domains. +# +#FilterURLs On + +# +# FilterExtended: Use POSIX Extended regular expressions rather than +# basic. +# +#FilterExtended On + +# +# FilterCaseSensitive: Use case sensitive regular expressions. +# +#FilterCaseSensitive On + +# +# FilterDefaultDeny: Change the default policy of the filtering system. +# If this directive is commented out, or is set to "No" then the default +# policy is to allow everything which is not specifically denied by the +# filter file. +# +# However, by setting this directive to "Yes" the default policy becomes +# to deny everything which is _not_ specifically allowed by the filter +# file. +# +#FilterDefaultDeny Yes + +# +# Anonymous: If an Anonymous keyword is present, then anonymous proxying +# is enabled. The headers listed are allowed through, while all others +# are denied. If no Anonymous keyword is present, then all headers are +# allowed through. You must include quotes around the headers. +# +# Most sites require cookies to be enabled for them to work correctly, so +# you will need to allow Cookies through if you access those sites. +# +#Anonymous "Host" +#Anonymous "Authorization" +#Anonymous "Cookie" + +# +# ConnectPort: This is a list of ports allowed by tinyproxy when the +# CONNECT method is used. To disable the CONNECT method altogether, set +# the value to 0. If no ConnectPort line is found, all ports are +# allowed. +# +# The following two ports are used by SSL. +# +ConnectPort 443 +ConnectPort 563 + +# +# Configure one or more ReversePath directives to enable reverse proxy +# support. With reverse proxying it's possible to make a number of +# sites appear as if they were part of a single site. +# +# If you uncomment the following two directives and run tinyproxy +# on your own computer at port 8888, you can access Google using +# http://localhost:8888/google/ and Wired News using +# http://localhost:8888/wired/news/. Neither will actually work +# until you uncomment ReverseMagic as they use absolute linking. +# +#ReversePath "/google/" "http://www.google.com/" +#ReversePath "/wired/" "http://www.wired.com/" + +# +# When using tinyproxy as a reverse proxy, it is STRONGLY recommended +# that the normal proxy is turned off by uncommenting the next directive. +# +#ReverseOnly Yes + +# +# Use a cookie to track reverse proxy mappings. If you need to reverse +# proxy sites which have absolute links you must uncomment this. +# +#ReverseMagic Yes + +# +# The URL that's used to access this reverse proxy. The URL is used to +# rewrite HTTP redirects so that they won't escape the proxy. If you +# have a chain of reverse proxies, you'll need to put the outermost +# URL here (the address which the end user types into his/her browser). +# +# If not set then no rewriting occurs. +# +#ReverseBaseURL "http://localhost:8888/"