feat: first commit
This commit is contained in:
commit
5fdf790556
25 files changed
+1957
No files matched your search
@@ -0,0 +1,4 @@
|
|||||||
|
.venv
|
||||||
|
.vscode
|
||||||
|
|
||||||
|
*.pem
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
# VPS setup ansible script
|
||||||
|
Setup VPS for basic needs with ansible playbook
|
||||||
@@ -0,0 +1,38 @@
|
|||||||
|
// prime the server with knowledge of the root servers
|
||||||
|
//zone "." {
|
||||||
|
// type hint;
|
||||||
|
// file "/usr/share/dns/root.hints";
|
||||||
|
//};
|
||||||
|
|
||||||
|
// be authoritative for the localhost forward and reverse zones, and for
|
||||||
|
// broadcast zones as per RFC 1912
|
||||||
|
|
||||||
|
view "ext" {
|
||||||
|
match-clients{"any";};
|
||||||
|
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "/usr/share/dns/root.hints";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "localhost" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/db.local";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "127.in-addr.arpa" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/db.127";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "0.in-addr.arpa" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/db.0";
|
||||||
|
};
|
||||||
|
|
||||||
|
zone "255.in-addr.arpa" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/db.255";
|
||||||
|
};
|
||||||
|
|
||||||
|
};
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
//
|
||||||
|
// Do any local configuration here
|
||||||
|
//
|
||||||
|
|
||||||
|
// Consider adding the 1918 zones here, if they are not used in your
|
||||||
|
// organization
|
||||||
|
//include "/etc/bind/zones.rfc1918";
|
||||||
|
|
||||||
|
acl "int-8" {10.8.0.0/24;};
|
||||||
|
acl "int-9" {10.9.0.0/24;};
|
||||||
|
|
||||||
|
view "int-8" {
|
||||||
|
match-clients{"int-8";};
|
||||||
|
|
||||||
|
zone "ra-tech.pro" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/zones/db.ra-tech.pro";
|
||||||
|
};
|
||||||
|
zone "0.8.10.in-addr.arpa" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/zones/db.10.8.0";
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
view "int-9" {
|
||||||
|
match-clients{"int-9";};
|
||||||
|
|
||||||
|
zone "ra-tech.pro" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/zones/db.v9.ra-tech.pro";
|
||||||
|
};
|
||||||
|
zone "0.9.10.in-addr.arpa" {
|
||||||
|
type master;
|
||||||
|
file "/etc/bind/zones/db.10.9.0";
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
options {
|
||||||
|
directory "/var/cache/bind";
|
||||||
|
|
||||||
|
// If there is a firewall between you and nameservers you want
|
||||||
|
// to talk to, you may need to fix the firewall to allow multiple
|
||||||
|
// ports to talk. See http://www.kb.cert.org/vuls/id/800113
|
||||||
|
|
||||||
|
// If your ISP provided one or more IP addresses for stable
|
||||||
|
// nameservers, you probably want to use them as forwarders.
|
||||||
|
// Uncomment the following block, and insert the addresses replacing
|
||||||
|
// the all-0's placeholder.
|
||||||
|
|
||||||
|
// forwarders {
|
||||||
|
// 0.0.0.0;
|
||||||
|
// };
|
||||||
|
|
||||||
|
//========================================================================
|
||||||
|
// If BIND logs error messages about the root key being expired,
|
||||||
|
// you will need to update your keys. See https://www.isc.org/bind-keys
|
||||||
|
//========================================================================
|
||||||
|
dnssec-validation auto;
|
||||||
|
|
||||||
|
listen-on {
|
||||||
|
10.8.0.0/24;
|
||||||
|
10.9.0.0/24;
|
||||||
|
};
|
||||||
|
|
||||||
|
allow-query { any; };
|
||||||
|
|
||||||
|
forwarders {
|
||||||
|
8.8.8.8;
|
||||||
|
8.8.4.4;
|
||||||
|
};
|
||||||
|
|
||||||
|
//listen-on-v6 { any; };
|
||||||
|
};
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
view "ext" {
|
||||||
|
// prime the server with knowledge of the root servers
|
||||||
|
zone "." {
|
||||||
|
type hint;
|
||||||
|
file "/usr/share/dns/root.hints";
|
||||||
|
};
|
||||||
|
}
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
;
|
||||||
|
; BIND reverse data file for local loopback interface
|
||||||
|
;
|
||||||
|
$TTL 604800
|
||||||
|
$ORIGIN 0.8.10.in-addr.arpa.
|
||||||
|
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||||
|
1 ; Serial
|
||||||
|
604800 ; Refresh
|
||||||
|
86400 ; Retry
|
||||||
|
2419200 ; Expire
|
||||||
|
604800 ) ; Negative Cache TTL
|
||||||
|
;
|
||||||
|
; name servers
|
||||||
|
IN NS ns.ra-tech.pro.
|
||||||
|
|
||||||
|
; PTR Records
|
||||||
|
1 IN PTR ns.ra-tech.pro.
|
||||||
|
1 IN PTR vps.ra-tech.pro.
|
||||||
|
10 IN PTR odroid.ra-tech.pro.
|
||||||
|
10 IN PTR jenkins.ra-tech.pro.
|
||||||
|
10 IN PTR nexus.ra-tech.pro.
|
||||||
|
10 IN PTR docker.ra-tech.pro.
|
||||||
|
10 IN PTR sonar.ra-tech.pro.
|
||||||
|
10 IN PTR cloud.ra-tech.pro.
|
||||||
|
10 IN PTR db.ra-tech.pro.
|
||||||
|
10 IN PTR dashboard.cloud.ra-tech.pro.
|
||||||
|
10 IN PTR garden-manager.db.ra-tech.pro.
|
||||||
|
10 IN PTR giga-ai-agent.db.ra-tech.pro.
|
||||||
|
10 IN PTR vault.ra-tech.pro.
|
||||||
|
10 IN PTR docker-registry.ra-tech.pro.
|
||||||
|
10 IN PTR snapshots.docker-registry.ra-tech.pro.
|
||||||
|
10 IN PTR prometheus.ra-tech.pro.
|
||||||
|
10 IN PTR pki.ra-tech.pro.
|
||||||
|
10 IN PTR grafana.ra-tech.pro.
|
||||||
|
10 IN PTR hfs.ra-tech.pro.
|
||||||
|
10 IN PTR kafka-1.ra-tech.pro.
|
||||||
|
10 IN PTR kafka.ra-tech.pro.
|
||||||
|
10 IN PTR elasticsearch.ra-tech.pro.
|
||||||
|
10 IN PTR kibana.ra-tech.pro.
|
||||||
|
10 IN PTR chrome.selenium.ra-tech.pro.
|
||||||
|
10 IN PTR git.ra-tech.pro.
|
||||||
@@ -0,0 +1,41 @@
|
|||||||
|
;
|
||||||
|
; BIND reverse data file for local loopback interface
|
||||||
|
;
|
||||||
|
$TTL 604800
|
||||||
|
$ORIGIN 0.9.10.in-addr.arpa.
|
||||||
|
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||||
|
1 ; Serial
|
||||||
|
604800 ; Refresh
|
||||||
|
86400 ; Retry
|
||||||
|
2419200 ; Expire
|
||||||
|
604800 ) ; Negative Cache TTL
|
||||||
|
;
|
||||||
|
; name servers
|
||||||
|
IN NS ns.ra-tech.pro.
|
||||||
|
|
||||||
|
; PTR Records
|
||||||
|
1 IN PTR ns.ra-tech.pro.
|
||||||
|
1 IN PTR vps.ra-tech.pro.
|
||||||
|
10 IN PTR odroid.ra-tech.pro.
|
||||||
|
10 IN PTR jenkins.ra-tech.pro.
|
||||||
|
10 IN PTR nexus.ra-tech.pro.
|
||||||
|
10 IN PTR docker.ra-tech.pro.
|
||||||
|
10 IN PTR sonar.ra-tech.pro.
|
||||||
|
10 IN PTR cloud.ra-tech.pro.
|
||||||
|
10 IN PTR db.ra-tech.pro.
|
||||||
|
10 IN PTR dashboard.cloud.ra-tech.pro.
|
||||||
|
10 IN PTR garden-manager.db.ra-tech.pro.
|
||||||
|
10 IN PTR giga-ai-agent.db.ra-tech.pro.
|
||||||
|
10 IN PTR vault.ra-tech.pro.
|
||||||
|
10 IN PTR docker-registry.ra-tech.pro.
|
||||||
|
10 IN PTR snapshots.docker-registry.ra-tech.pro.
|
||||||
|
10 IN PTR prometheus.ra-tech.pro.
|
||||||
|
10 IN PTR pki.ra-tech.pro.
|
||||||
|
10 IN PTR grafana.ra-tech.pro.
|
||||||
|
10 IN PTR hfs.ra-tech.pro.
|
||||||
|
10 IN PTR kafka-1.ra-tech.pro.
|
||||||
|
10 IN PTR kafka.ra-tech.pro.
|
||||||
|
10 IN PTR elasticsearch.ra-tech.pro.
|
||||||
|
10 IN PTR kibana.ra-tech.pro.
|
||||||
|
10 IN PTR chrome.selenium.ra-tech.pro.
|
||||||
|
10 IN PTR git.ra-tech.pro.
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
;
|
||||||
|
; BIND data file for local loopback interface
|
||||||
|
;
|
||||||
|
$TTL 604800
|
||||||
|
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||||
|
1 ; Serial
|
||||||
|
604800 ; Refresh
|
||||||
|
86400 ; Retry
|
||||||
|
2419200 ; Expire
|
||||||
|
604800 ) ; Negative Cache TTL
|
||||||
|
|
||||||
|
; name servers - NS records
|
||||||
|
IN NS ns.ra-tech.pro.
|
||||||
|
|
||||||
|
; name servers - A records
|
||||||
|
ns.ra-tech.pro. IN A 10.8.0.1
|
||||||
|
|
||||||
|
; 10.8.0.0/24 - A records
|
||||||
|
vps.ra-tech.pro. IN A 10.8.0.1
|
||||||
|
odroid.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
jenkins.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
nexus.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
docker.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
sonar.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
dashboard.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
db.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
garden-manager.db.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
giga-ai-agent.db.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
vault.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
docker-registry.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
snapshots.docker-registry.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
pki.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
prometheus.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
grafana.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
syncthing.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
kuber.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
api.garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
solr.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
auth.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
hfs.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
kafka-1.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
kafka.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
elasticsearch.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
kibana.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
chrome.selenium.ra-tech.pro. IN A 10.8.0.10
|
||||||
|
git.ra-tech.pro. IN A 10.8.0.10
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
;
|
||||||
|
; BIND data file for local loopback interface
|
||||||
|
;
|
||||||
|
$TTL 604800
|
||||||
|
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||||
|
1 ; Serial
|
||||||
|
604800 ; Refresh
|
||||||
|
86400 ; Retry
|
||||||
|
2419200 ; Expire
|
||||||
|
604800 ) ; Negative Cache TTL
|
||||||
|
|
||||||
|
; name servers - NS records
|
||||||
|
IN NS ns.ra-tech.pro.
|
||||||
|
|
||||||
|
; name servers - A records
|
||||||
|
ns.ra-tech.pro. IN A 10.9.0.1
|
||||||
|
|
||||||
|
; 10.8.0.0/24 - A records
|
||||||
|
vps.ra-tech.pro. IN A 10.9.0.1
|
||||||
|
odroid.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
jenkins.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
nexus.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
docker.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
sonar.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
dashboard.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
db.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
garden-manager.db.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
giga-ai-agent.db.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
vault.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
docker-registry.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
snapshots.docker-registry.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
pki.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
prometheus.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
grafana.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
syncthing.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
kuber.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
api.garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
solr.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
auth.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
hfs.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
kafka-1.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
kafka.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
elasticsearch.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
kibana.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
chrome.selenium.ra-tech.pro. IN A 10.9.0.10
|
||||||
|
git.ra-tech.pro. IN A 10.9.0.10
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Cloak server
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/local/bin/ck-server -c /etc/cloak/server.json
|
||||||
|
Restart=always
|
||||||
|
Type=exec
|
||||||
|
User=cloak
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=default.target
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{
|
||||||
|
"ProxyBook": {
|
||||||
|
"openvpn": [
|
||||||
|
"tcp",
|
||||||
|
"{{ public_ip }}:5690"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"BindAddr": [
|
||||||
|
":5691"
|
||||||
|
],
|
||||||
|
"BypassUID": [
|
||||||
|
"hs3Zsj/9mvt7+3bhgkg7Tw==",
|
||||||
|
"VF3YuD37EPGcMyfJOBM+zw==",
|
||||||
|
"2GT18pqRxb6BOqJWQK42rg==",
|
||||||
|
"LN9ESPPnGDN5bU4qJJGm3Q=="
|
||||||
|
],
|
||||||
|
"RedirAddr": "vk.ru",
|
||||||
|
"PrivateKey": "cFMDGEt3L8Rm7APM9creW3KBrYrVP3pIjZvlNgV32Fs=",
|
||||||
|
"AdminUID": "rVobMUVWAh1Do4QF/wzdVw==",
|
||||||
|
"DatabasePath": "/opt/cloak/userinfo.db"
|
||||||
|
}
|
||||||
@@ -0,0 +1,200 @@
|
|||||||
|
hosts:
|
||||||
|
- ra-tech.dev
|
||||||
|
- xmpp.ra-itech.ru
|
||||||
|
|
||||||
|
hosts_alias:
|
||||||
|
"64.188.58.223": "ra-tech.dev"
|
||||||
|
|
||||||
|
language: ru
|
||||||
|
|
||||||
|
loglevel: info
|
||||||
|
|
||||||
|
certfiles:
|
||||||
|
- /etc/ejabberd/server.pem
|
||||||
|
- /etc/ejabberd/server-key.pem
|
||||||
|
- /etc/ejabberd/certs/fullchain.pem
|
||||||
|
- /etc/ejabberd/certs/privkey.pem
|
||||||
|
|
||||||
|
auth_method: internal
|
||||||
|
auth_password_format: scram
|
||||||
|
auth_scram_hash: sha512
|
||||||
|
|
||||||
|
sql_database: /opt/ejabberd/sqlite/db.sqlite
|
||||||
|
sql_type: sqlite
|
||||||
|
sql_pool_size: 1
|
||||||
|
|
||||||
|
s2s_access:
|
||||||
|
deny: all
|
||||||
|
|
||||||
|
acl:
|
||||||
|
admin:
|
||||||
|
user:
|
||||||
|
- kodacci@ra-tech.dev
|
||||||
|
- kodacci@xmpp.ra-itech.ru
|
||||||
|
disabled_servers:
|
||||||
|
server:
|
||||||
|
- "p2.siacs.eu"
|
||||||
|
|
||||||
|
access_rules:
|
||||||
|
configure:
|
||||||
|
allow: admin
|
||||||
|
announce:
|
||||||
|
allow: admin
|
||||||
|
c2s:
|
||||||
|
deny: blocked
|
||||||
|
allow: all
|
||||||
|
pubsub_createnode:
|
||||||
|
allow: admin
|
||||||
|
s2s:
|
||||||
|
deny: disabled_servers
|
||||||
|
|
||||||
|
shaper:
|
||||||
|
fast: 3000000
|
||||||
|
|
||||||
|
shaper_rules:
|
||||||
|
max_user_sessions: 50
|
||||||
|
max_user_offline_messages: 5000
|
||||||
|
c2s_shaper: fast
|
||||||
|
|
||||||
|
modules:
|
||||||
|
mod_adhoc: {}
|
||||||
|
mod_adhoc_api: {}
|
||||||
|
mod_admin_extra: {}
|
||||||
|
mod_announce:
|
||||||
|
access: announce
|
||||||
|
mod_avatar: {}
|
||||||
|
mod_blocking: {}
|
||||||
|
mod_bosh: {}
|
||||||
|
mod_caps: {}
|
||||||
|
mod_carboncopy: {}
|
||||||
|
mod_client_state: {}
|
||||||
|
mod_configure: {}
|
||||||
|
mod_disco: {}
|
||||||
|
mod_fail2ban: {}
|
||||||
|
mod_http_api: {}
|
||||||
|
mod_last: {}
|
||||||
|
mod_muc:
|
||||||
|
access_admin:
|
||||||
|
- allow: admin
|
||||||
|
mod_muc_admin: {}
|
||||||
|
mod_offline:
|
||||||
|
access_max_user_messages: max_user_offline_messages
|
||||||
|
mod_ping:
|
||||||
|
send_pings: true
|
||||||
|
ping_interval: 1 min
|
||||||
|
mod_privacy: {}
|
||||||
|
mod_private: {}
|
||||||
|
mod_push: {}
|
||||||
|
mod_push_keepalive: {}
|
||||||
|
mod_roster:
|
||||||
|
versioning: true
|
||||||
|
mod_s2s_bidi: {}
|
||||||
|
mod_s2s_dialback: {}
|
||||||
|
mod_shared_roster: {}
|
||||||
|
mod_stream_mgmt:
|
||||||
|
resend_on_timeout: if_offline
|
||||||
|
mod_stun_disco:
|
||||||
|
access: c2s
|
||||||
|
credentials_lifetime: 12h
|
||||||
|
services:
|
||||||
|
- host: xmpp.ra-itech.ru
|
||||||
|
port: 3478
|
||||||
|
type: stun
|
||||||
|
transport: udp
|
||||||
|
restricted: false
|
||||||
|
- host: xmpp.ra-itech.ru
|
||||||
|
port: 3478
|
||||||
|
type: turn
|
||||||
|
transport: udp
|
||||||
|
restricted: true
|
||||||
|
- host: xmpp.ra-itech.ru
|
||||||
|
port: 5349
|
||||||
|
type: stuns
|
||||||
|
transport: tcp
|
||||||
|
restricted: false
|
||||||
|
- host: xmpp.ra-itech.ru
|
||||||
|
port: 5349
|
||||||
|
type: turns
|
||||||
|
transport: tcp
|
||||||
|
restricted: true
|
||||||
|
mod_vcard: {}
|
||||||
|
mod_vcard_xupdate: {}
|
||||||
|
mod_version:
|
||||||
|
show_os: false
|
||||||
|
mod_pubsub:
|
||||||
|
access_createnode: pubsub_createnode
|
||||||
|
plugins:
|
||||||
|
- flat
|
||||||
|
- pep
|
||||||
|
force_node_config:
|
||||||
|
## Avoid buggy clients to make their bookmarks public
|
||||||
|
storage:bookmarks:
|
||||||
|
access_model: whitelist
|
||||||
|
mod_proxy65:
|
||||||
|
access: c2s
|
||||||
|
max_connections: 50
|
||||||
|
port: 7788
|
||||||
|
shaper: fast
|
||||||
|
mod_http_fileserver:
|
||||||
|
accesslog: /opt/ejabberd/logs/access.log
|
||||||
|
docroot:
|
||||||
|
/files: /opt/fileserver
|
||||||
|
mod_http_upload:
|
||||||
|
access: c2s
|
||||||
|
docroot: /opt/fileserver
|
||||||
|
put_url: "https://@HOST@:5443/upload"
|
||||||
|
get_url: "https://@HOST@:5443/files"
|
||||||
|
mod_mam:
|
||||||
|
access_preferences: c2s
|
||||||
|
db_type: sql
|
||||||
|
|
||||||
|
listen:
|
||||||
|
- port: 5222
|
||||||
|
ip: "::"
|
||||||
|
module: ejabberd_c2s
|
||||||
|
shaper: c2s_shaper
|
||||||
|
access: c2s
|
||||||
|
max_stanza_size: 262144
|
||||||
|
starttls: true
|
||||||
|
allow_unencrypted_sasl2: false
|
||||||
|
cafile: /etc/ejabberd/ca.pem
|
||||||
|
starttls_required: true
|
||||||
|
tls_verify: true
|
||||||
|
|
||||||
|
- port: 5223
|
||||||
|
ip: "::"
|
||||||
|
module: ejabberd_c2s
|
||||||
|
shaper: c2s_shaper
|
||||||
|
access: c2s
|
||||||
|
max_stanza_size: 262144
|
||||||
|
starttls: true
|
||||||
|
starttls_required: true
|
||||||
|
tls_verify: false
|
||||||
|
|
||||||
|
- port: 3478
|
||||||
|
transport: udp
|
||||||
|
module: ejabberd_stun
|
||||||
|
use_turn: true
|
||||||
|
turn_min_port: 49152
|
||||||
|
turn_max_port: 65535
|
||||||
|
turn_ip: 64.188.58.223
|
||||||
|
|
||||||
|
- port: 5349
|
||||||
|
transport: tcp
|
||||||
|
module: ejabberd_stun
|
||||||
|
use_turn: true
|
||||||
|
tls: true
|
||||||
|
turn_min_port: 49152
|
||||||
|
turn_max_port: 65535
|
||||||
|
ip: 64.188.58.223
|
||||||
|
turn_ip: 64.188.58.223
|
||||||
|
|
||||||
|
- port: 5443
|
||||||
|
ip: "::"
|
||||||
|
transport: tcp
|
||||||
|
module: ejabberd_http
|
||||||
|
tls: true
|
||||||
|
request_handlers:
|
||||||
|
/files: mod_http_fileserver
|
||||||
|
/upload: mod_http_upload
|
||||||
|
/bosh: mod_bosh
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
global
|
||||||
|
log /dev/log local0
|
||||||
|
log /dev/log local1 notice
|
||||||
|
chroot /var/lib/haproxy
|
||||||
|
stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners
|
||||||
|
stats timeout 30s
|
||||||
|
user haproxy
|
||||||
|
group haproxy
|
||||||
|
daemon
|
||||||
|
|
||||||
|
# Default SSL material locations
|
||||||
|
ca-base /etc/ssl/certs
|
||||||
|
crt-base /etc/ssl/private
|
||||||
|
|
||||||
|
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
|
||||||
|
#ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
||||||
|
#ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
||||||
|
#ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
|
||||||
|
|
||||||
|
defaults
|
||||||
|
log global
|
||||||
|
mode http
|
||||||
|
option httplog
|
||||||
|
option dontlognull
|
||||||
|
timeout connect 5000
|
||||||
|
timeout client 50000
|
||||||
|
timeout server 50000
|
||||||
|
errorfile 400 /etc/haproxy/errors/400.http
|
||||||
|
errorfile 403 /etc/haproxy/errors/403.http
|
||||||
|
errorfile 408 /etc/haproxy/errors/408.http
|
||||||
|
errorfile 500 /etc/haproxy/errors/500.http
|
||||||
|
errorfile 502 /etc/haproxy/errors/502.http
|
||||||
|
errorfile 503 /etc/haproxy/errors/503.http
|
||||||
|
errorfile 504 /etc/haproxy/errors/504.http
|
||||||
|
|
||||||
|
frontend jenkins_webhook_front
|
||||||
|
mode http
|
||||||
|
bind :7777 ssl crt /etc/haproxy/certs/64.188.58.223.pem
|
||||||
|
http-request set-header X-Forwarded-For %[src]
|
||||||
|
use_backend jenkins_webhook_back if { path /github-webhook/ } || { path /github-webhook }
|
||||||
|
|
||||||
|
backend jenkins_webhook_back
|
||||||
|
mode http
|
||||||
|
http-request set-header Host jenkins.ra-tech.pro
|
||||||
|
server jenkins_main jenkins.ra-tech.pro:443 ssl verify none check resolvers nameservers
|
||||||
|
|
||||||
|
resolvers nameservers
|
||||||
|
nameserver ra-tech 10.8.0.1:53
|
||||||
|
#nameserver google 8.8.8.8:53
|
||||||
|
|
||||||
|
frontend stats
|
||||||
|
bind 10.8.0.1:8404
|
||||||
|
bind 10.9.0.1:8404
|
||||||
|
mode http
|
||||||
|
http-request use-service prometheus-exporter if { path /metrics }
|
||||||
|
stats enable
|
||||||
|
stats uri /stats
|
||||||
|
stats refresh 15s
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
vps_servers:
|
||||||
|
vars:
|
||||||
|
ansible_become: true
|
||||||
|
ansible_become_user: root
|
||||||
|
ansible_become_method: su
|
||||||
|
ansible_user: kodacci
|
||||||
|
hosts:
|
||||||
|
ru-vpn:
|
||||||
|
ansible_host: ru-vpn.ra-itech.ru
|
||||||
|
public_ip: 45.87.247.103
|
||||||
|
public_ip_iface: ens3
|
||||||
|
ansible_port: 12801
|
||||||
|
|
||||||
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Node Exporter
|
||||||
|
Wants=network-online.target
|
||||||
|
After=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
User=node_exporter
|
||||||
|
Group=node_exporter
|
||||||
|
Type=simple
|
||||||
|
ExecStart=/usr/local/bin/node_exporter
|
||||||
|
Restart=always
|
||||||
|
RestartSec=3
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# 2048 bit OpenVPN static key
|
||||||
|
#
|
||||||
|
-----BEGIN OpenVPN Static key V1-----
|
||||||
|
ca6b90a1782a8940fbfd685dd1c92cff
|
||||||
|
7958116231f3f096569271880c54a53f
|
||||||
|
0aeb0872933e9ca7c3efaaed3b63831b
|
||||||
|
21be29430b4dd8634200131a197470de
|
||||||
|
061d716c133e25f7edd3802beba11851
|
||||||
|
f5c1347f63c1ce072ba26219a9f68f13
|
||||||
|
76057ff561468d267792e0f249342956
|
||||||
|
d4df6c72efffcc21c7d09d1b5415cebc
|
||||||
|
bf4cdc0369bc8bc16a86a7b7c5f61ae5
|
||||||
|
9b87777aeccdbcf9d50f15aa4427adb8
|
||||||
|
2263df1c1475471989a8eff935e0c5ac
|
||||||
|
e85580b0f90633bf92570aaa15910850
|
||||||
|
d4017e502f0eeaf46f555ff9740c655c
|
||||||
|
26db7bf2f06948249e75a869d4d47e89
|
||||||
|
847ce8f14969a5cc3b60928838146305
|
||||||
|
797f11d4cf08d4c06223c47747ec8798
|
||||||
|
-----END OpenVPN Static key V1-----
|
||||||
@@ -0,0 +1,320 @@
|
|||||||
|
#################################################
|
||||||
|
# Sample OpenVPN 2.0 config file for #
|
||||||
|
# multi-client server. #
|
||||||
|
# #
|
||||||
|
# This file is for the server side #
|
||||||
|
# of a many-clients <-> one-server #
|
||||||
|
# OpenVPN configuration. #
|
||||||
|
# #
|
||||||
|
# OpenVPN also supports #
|
||||||
|
# single-machine <-> single-machine #
|
||||||
|
# configurations (See the Examples page #
|
||||||
|
# on the web site for more info). #
|
||||||
|
# #
|
||||||
|
# This config should work on Windows #
|
||||||
|
# or Linux/BSD systems. Remember on #
|
||||||
|
# Windows to quote pathnames and use #
|
||||||
|
# double backslashes, e.g.: #
|
||||||
|
# "C:\\Program Files\\OpenVPN\\config\\foo.key" #
|
||||||
|
# #
|
||||||
|
# Comments are preceded with '#' or ';' #
|
||||||
|
#################################################
|
||||||
|
|
||||||
|
# Which local IP address should OpenVPN
|
||||||
|
# listen on? (optional)
|
||||||
|
;local a.b.c.d
|
||||||
|
|
||||||
|
# Which TCP/UDP port should OpenVPN listen on?
|
||||||
|
# If you want to run multiple OpenVPN instances
|
||||||
|
# on the same machine, use a different port
|
||||||
|
# number for each one. You will need to
|
||||||
|
# open up this port on your firewall.
|
||||||
|
# port 1194
|
||||||
|
port 5690
|
||||||
|
|
||||||
|
# TCP or UDP server?
|
||||||
|
proto tcp
|
||||||
|
;proto udp
|
||||||
|
|
||||||
|
# "dev tun" will create a routed IP tunnel,
|
||||||
|
# "dev tap" will create an ethernet tunnel.
|
||||||
|
# Use "dev tap0" if you are ethernet bridging
|
||||||
|
# and have precreated a tap0 virtual interface
|
||||||
|
# and bridged it with your ethernet interface.
|
||||||
|
# If you want to control access policies
|
||||||
|
# over the VPN, you must create firewall
|
||||||
|
# rules for the the TUN/TAP interface.
|
||||||
|
# On non-Windows systems, you can give
|
||||||
|
# an explicit unit number, such as tun0.
|
||||||
|
# On Windows, use "dev-node" for this.
|
||||||
|
# On most systems, the VPN will not function
|
||||||
|
# unless you partially or fully disable
|
||||||
|
# the firewall for the TUN/TAP interface.
|
||||||
|
;dev tap
|
||||||
|
dev tun
|
||||||
|
|
||||||
|
# Windows needs the TAP-Win32 adapter name
|
||||||
|
# from the Network Connections panel if you
|
||||||
|
# have more than one. On XP SP2 or higher,
|
||||||
|
# you may need to selectively disable the
|
||||||
|
# Windows firewall for the TAP adapter.
|
||||||
|
# Non-Windows systems usually don't need this.
|
||||||
|
;dev-node MyTap
|
||||||
|
|
||||||
|
# SSL/TLS root certificate (ca), certificate
|
||||||
|
# (cert), and private key (key). Each client
|
||||||
|
# and the server must have their own cert and
|
||||||
|
# key file. The server and all clients will
|
||||||
|
# use the same ca file.
|
||||||
|
#
|
||||||
|
# See the "easy-rsa" directory for a series
|
||||||
|
# of scripts for generating RSA certificates
|
||||||
|
# and private keys. Remember to use
|
||||||
|
# a unique Common Name for the server
|
||||||
|
# and each of the client certificates.
|
||||||
|
#
|
||||||
|
# Any X509 key management system can be used.
|
||||||
|
# OpenVPN can also use a PKCS #12 formatted key file
|
||||||
|
# (see "pkcs12" directive in man page).
|
||||||
|
ca ca.pem
|
||||||
|
cert server.pem
|
||||||
|
key server-key.pem # This file should be kept secret
|
||||||
|
|
||||||
|
# Diffie hellman parameters.
|
||||||
|
# Generate your own with:
|
||||||
|
# openssl dhparam -out dh2048.pem 2048
|
||||||
|
#dh dh2048.pem
|
||||||
|
dh none
|
||||||
|
|
||||||
|
# Network topology
|
||||||
|
# Should be subnet (addressing via IP)
|
||||||
|
# unless Windows clients v2.0.9 and lower have to
|
||||||
|
# be supported (then net30, i.e. a /30 per client)
|
||||||
|
# Defaults to net30 (not recommended)
|
||||||
|
;topology subnet
|
||||||
|
|
||||||
|
# Configure server mode and supply a VPN subnet
|
||||||
|
# for OpenVPN to draw client addresses from.
|
||||||
|
# The server will take 10.8.0.1 for itself,
|
||||||
|
# the rest will be made available to clients.
|
||||||
|
# Each client will be able to reach the server
|
||||||
|
# on 10.8.0.1. Comment this line out if you are
|
||||||
|
# ethernet bridging. See the man page for more info.
|
||||||
|
server 10.8.0.0 255.255.255.0
|
||||||
|
|
||||||
|
# Maintain a record of client <-> virtual IP address
|
||||||
|
# associations in this file. If OpenVPN goes down or
|
||||||
|
# is restarted, reconnecting clients can be assigned
|
||||||
|
# the same virtual IP address from the pool that was
|
||||||
|
# previously assigned.
|
||||||
|
ifconfig-pool-persist /var/log/openvpn/ipp.txt
|
||||||
|
|
||||||
|
# Configure server mode for ethernet bridging.
|
||||||
|
# You must first use your OS's bridging capability
|
||||||
|
# to bridge the TAP interface with the ethernet
|
||||||
|
# NIC interface. Then you must manually set the
|
||||||
|
# IP/netmask on the bridge interface, here we
|
||||||
|
# assume 10.8.0.4/255.255.255.0. Finally we
|
||||||
|
# must set aside an IP range in this subnet
|
||||||
|
# (start=10.8.0.50 end=10.8.0.100) to allocate
|
||||||
|
# to connecting clients. Leave this line commented
|
||||||
|
# out unless you are ethernet bridging.
|
||||||
|
;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100
|
||||||
|
|
||||||
|
# Configure server mode for ethernet bridging
|
||||||
|
# using a DHCP-proxy, where clients talk
|
||||||
|
# to the OpenVPN server-side DHCP server
|
||||||
|
# to receive their IP address allocation
|
||||||
|
# and DNS server addresses. You must first use
|
||||||
|
# your OS's bridging capability to bridge the TAP
|
||||||
|
# interface with the ethernet NIC interface.
|
||||||
|
# Note: this mode only works on clients (such as
|
||||||
|
# Windows), where the client-side TAP adapter is
|
||||||
|
# bound to a DHCP client.
|
||||||
|
;server-bridge
|
||||||
|
|
||||||
|
# Push routes to the client to allow it
|
||||||
|
# to reach other private subnets behind
|
||||||
|
# the server. Remember that these
|
||||||
|
# private subnets will also need
|
||||||
|
# to know to route the OpenVPN client
|
||||||
|
# address pool (10.8.0.0/255.255.255.0)
|
||||||
|
# back to the OpenVPN server.
|
||||||
|
;push "route 192.168.10.0 255.255.255.0"
|
||||||
|
;push "route 192.168.20.0 255.255.255.0"
|
||||||
|
|
||||||
|
# To assign specific IP addresses to specific
|
||||||
|
# clients or if a connecting client has a private
|
||||||
|
# subnet behind it that should also have VPN access,
|
||||||
|
# use the subdirectory "ccd" for client-specific
|
||||||
|
# configuration files (see man page for more info).
|
||||||
|
|
||||||
|
# EXAMPLE: Suppose the client
|
||||||
|
# having the certificate common name "Thelonious"
|
||||||
|
# also has a small subnet behind his connecting
|
||||||
|
# machine, such as 192.168.40.128/255.255.255.248.
|
||||||
|
# First, uncomment out these lines:
|
||||||
|
;client-config-dir ccd
|
||||||
|
;route 192.168.40.128 255.255.255.248
|
||||||
|
# Then create a file ccd/Thelonious with this line:
|
||||||
|
# iroute 192.168.40.128 255.255.255.248
|
||||||
|
# This will allow Thelonious' private subnet to
|
||||||
|
# access the VPN. This example will only work
|
||||||
|
# if you are routing, not bridging, i.e. you are
|
||||||
|
# using "dev tun" and "server" directives.
|
||||||
|
|
||||||
|
# EXAMPLE: Suppose you want to give
|
||||||
|
# Thelonious a fixed VPN IP address of 10.9.0.1.
|
||||||
|
# First uncomment out these lines:
|
||||||
|
;client-config-dir ccd
|
||||||
|
;route 10.9.0.0 255.255.255.252
|
||||||
|
# Then add this line to ccd/Thelonious:
|
||||||
|
# ifconfig-push 10.9.0.1 10.9.0.2
|
||||||
|
|
||||||
|
# Suppose that you want to enable different
|
||||||
|
# firewall access policies for different groups
|
||||||
|
# of clients. There are two methods:
|
||||||
|
# (1) Run multiple OpenVPN daemons, one for each
|
||||||
|
# group, and firewall the TUN/TAP interface
|
||||||
|
# for each group/daemon appropriately.
|
||||||
|
# (2) (Advanced) Create a script to dynamically
|
||||||
|
# modify the firewall in response to access
|
||||||
|
# from different clients. See man
|
||||||
|
# page for more info on learn-address script.
|
||||||
|
;learn-address ./script
|
||||||
|
|
||||||
|
# If enabled, this directive will configure
|
||||||
|
# all clients to redirect their default
|
||||||
|
# network gateway through the VPN, causing
|
||||||
|
# all IP traffic such as web browsing and
|
||||||
|
# and DNS lookups to go through the VPN
|
||||||
|
# (The OpenVPN server machine may need to NAT
|
||||||
|
# or bridge the TUN/TAP interface to the internet
|
||||||
|
# in order for this to work properly).
|
||||||
|
push "redirect-gateway def1 bypass-dhcp"
|
||||||
|
|
||||||
|
# Certain Windows-specific network settings
|
||||||
|
# can be pushed to clients, such as DNS
|
||||||
|
# or WINS server addresses. CAVEAT:
|
||||||
|
# http://openvpn.net/faq.html#dhcpcaveats
|
||||||
|
# The addresses below refer to the public
|
||||||
|
# DNS servers provided by opendns.com.
|
||||||
|
# push "dhcp-option DNS 208.67.222.222"
|
||||||
|
push "dhcp-option DNS 10.8.0.1"
|
||||||
|
push "dhcp-option DNS 208.67.220.220"
|
||||||
|
|
||||||
|
# Uncomment this directive to allow different
|
||||||
|
# clients to be able to "see" each other.
|
||||||
|
# By default, clients will only see the server.
|
||||||
|
# To force clients to only see the server, you
|
||||||
|
# will also need to appropriately firewall the
|
||||||
|
# server's TUN/TAP interface.
|
||||||
|
;client-to-client
|
||||||
|
|
||||||
|
# Uncomment this directive if multiple clients
|
||||||
|
# might connect with the same certificate/key
|
||||||
|
# files or common names. This is recommended
|
||||||
|
# only for testing purposes. For production use,
|
||||||
|
# each client should have its own certificate/key
|
||||||
|
# pair.
|
||||||
|
#
|
||||||
|
# IF YOU HAVE NOT GENERATED INDIVIDUAL
|
||||||
|
# CERTIFICATE/KEY PAIRS FOR EACH CLIENT,
|
||||||
|
# EACH HAVING ITS OWN UNIQUE "COMMON NAME",
|
||||||
|
# UNCOMMENT THIS LINE OUT.
|
||||||
|
;duplicate-cn
|
||||||
|
|
||||||
|
# The keepalive directive causes ping-like
|
||||||
|
# messages to be sent back and forth over
|
||||||
|
# the link so that each side knows when
|
||||||
|
# the other side has gone down.
|
||||||
|
# Ping every 10 seconds, assume that remote
|
||||||
|
# peer is down if no ping received during
|
||||||
|
# a 120 second time period.
|
||||||
|
keepalive 10 120
|
||||||
|
|
||||||
|
# For extra security beyond that provided
|
||||||
|
# by SSL/TLS, create an "HMAC firewall"
|
||||||
|
# to help block DoS attacks and UDP port flooding.
|
||||||
|
#
|
||||||
|
# Generate with:
|
||||||
|
# openvpn --genkey --secret ta.key
|
||||||
|
#
|
||||||
|
# The server and each client must have
|
||||||
|
# a copy of this key.
|
||||||
|
# The second parameter should be '0'
|
||||||
|
# on the server and '1' on the clients.
|
||||||
|
#tls-auth ta.key 0 # This file is secret
|
||||||
|
tls-crypt ta.key
|
||||||
|
|
||||||
|
# Select a cryptographic cipher.
|
||||||
|
# This config item must be copied to
|
||||||
|
# the client config file as well.
|
||||||
|
# Note that v2.4 client/server will automatically
|
||||||
|
# negotiate AES-256-GCM in TLS mode.
|
||||||
|
# See also the ncp-cipher option in the manpage
|
||||||
|
cipher AES-256-GCM
|
||||||
|
auth SHA256
|
||||||
|
|
||||||
|
# Enable compression on the VPN link and push the
|
||||||
|
# option to the client (v2.4+ only, for earlier
|
||||||
|
# versions see below)
|
||||||
|
;compress lz4-v2
|
||||||
|
;push "compress lz4-v2"
|
||||||
|
|
||||||
|
# For compression compatible with older clients use comp-lzo
|
||||||
|
# If you enable it here, you must also
|
||||||
|
# enable it in the client config file.
|
||||||
|
;comp-lzo
|
||||||
|
|
||||||
|
# The maximum number of concurrently connected
|
||||||
|
# clients we want to allow.
|
||||||
|
;max-clients 100
|
||||||
|
|
||||||
|
# It's a good idea to reduce the OpenVPN
|
||||||
|
# daemon's privileges after initialization.
|
||||||
|
#
|
||||||
|
# You can uncomment this out on
|
||||||
|
# non-Windows systems.
|
||||||
|
user nobody
|
||||||
|
group nogroup
|
||||||
|
|
||||||
|
# The persist options will try to avoid
|
||||||
|
# accessing certain resources on restart
|
||||||
|
# that may no longer be accessible because
|
||||||
|
# of the privilege downgrade.
|
||||||
|
persist-key
|
||||||
|
persist-tun
|
||||||
|
|
||||||
|
# Output a short status file showing
|
||||||
|
# current connections, truncated
|
||||||
|
# and rewritten every minute.
|
||||||
|
status /var/log/openvpn/openvpn-status.log
|
||||||
|
|
||||||
|
# By default, log messages will go to the syslog (or
|
||||||
|
# on Windows, if running as a service, they will go to
|
||||||
|
# the "\Program Files\OpenVPN\log" directory).
|
||||||
|
# Use log or log-append to override this default.
|
||||||
|
# "log" will truncate the log file on OpenVPN startup,
|
||||||
|
# while "log-append" will append to it. Use one
|
||||||
|
# or the other (but not both).
|
||||||
|
;log /var/log/openvpn/openvpn.log
|
||||||
|
;log-append /var/log/openvpn/openvpn.log
|
||||||
|
|
||||||
|
# Set the appropriate level of log
|
||||||
|
# file verbosity.
|
||||||
|
#
|
||||||
|
# 0 is silent, except for fatal errors
|
||||||
|
# 4 is reasonable for general usage
|
||||||
|
# 5 and 6 can help to debug connection problems
|
||||||
|
# 9 is extremely verbose
|
||||||
|
verb 3
|
||||||
|
|
||||||
|
# Silence repeating messages. At most 20
|
||||||
|
# sequential messages of the same message
|
||||||
|
# category will be output to the log.
|
||||||
|
;mute 20
|
||||||
|
|
||||||
|
# Notify the client that when the server restarts so it
|
||||||
|
# can automatically reconnect.
|
||||||
|
explicit-exit-notify 1
|
||||||
+503
@@ -0,0 +1,503 @@
|
|||||||
|
- name: Setup ufw port forwarding for VPNs subnets
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
gather_facts: true
|
||||||
|
tasks:
|
||||||
|
- name: Install ufw
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: ufw
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
# - name: Configure ufw port forwarding
|
||||||
|
# ansible.builtin.lineinfile:
|
||||||
|
# path: '/etc/sysctl.conf'
|
||||||
|
# regexp: '^#?net.ipv4.ip_forward='
|
||||||
|
# line: 'net.ipv4.ip_forward=1'
|
||||||
|
# state: present
|
||||||
|
# notify: Reload sysctl
|
||||||
|
|
||||||
|
- name: Configure ufw port forwarding
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'sysctl/99-ipv4-forward.conf'
|
||||||
|
dest: '/etc/sysctl.d/99-ipv4-forward.conf'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify: Reload sysctl
|
||||||
|
|
||||||
|
- name: Set ufw default forwarding policy
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: '/etc/default/ufw'
|
||||||
|
regexp: '^DEFAULT_FORWARD_POLICY='
|
||||||
|
line: 'DEFAULT_FORWARD_POLICY="ACCEPT"'
|
||||||
|
state: present
|
||||||
|
notify: Reload ufw
|
||||||
|
|
||||||
|
- name: Add postrouting nat
|
||||||
|
ansible.builtin.blockinfile:
|
||||||
|
path: '/etc/ufw/before.rules'
|
||||||
|
insertbefore: '^\*filter'
|
||||||
|
block: |
|
||||||
|
# VPN NAT
|
||||||
|
*nat
|
||||||
|
:POSTROUTING ACCEPT [0:0]
|
||||||
|
-A POSTROUTING -s 10.9.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||||
|
-A POSTROUTING -s 10.8.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||||
|
-A POSTROUTING -s 10.10.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||||
|
COMMIT
|
||||||
|
# END VPN NAT
|
||||||
|
notify: Reload ufw
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Reload sysctl
|
||||||
|
ansible.builtin.command: sysctl -p /etc/sysctl.d/99-ipv4-forward.conf
|
||||||
|
register: result
|
||||||
|
changed_when: result.rc == 0
|
||||||
|
|
||||||
|
- name: Reload ufw
|
||||||
|
ansible.builtin.command: ufw reload
|
||||||
|
register: result
|
||||||
|
changed_when: result.rc == 0
|
||||||
|
|
||||||
|
- name: Setup strongswan
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
gather_facts: true
|
||||||
|
tasks:
|
||||||
|
- name: Uninstall strongswan legacy packages if present
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- strongswan-starter
|
||||||
|
- strongswan-charon
|
||||||
|
state: absent
|
||||||
|
purge: true
|
||||||
|
autoremove: true
|
||||||
|
|
||||||
|
- name: Install strongswan with swanctl and vici
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- charon-systemd
|
||||||
|
- strongswan-swanctl
|
||||||
|
- libcharon-extra-plugins
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Copy strongswan config
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 'strongswan/ra-tech.conf.j2'
|
||||||
|
dest: '/etc/swanctl/conf.d/ra-tech.conf'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: Copy strongswan dhcp module config
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 'strongswan/charon/dhcp.conf.j2'
|
||||||
|
dest: '/etc/strongswan.d/charon/dhcp.conf'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: Copy Root CA
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'strongswan/ca.pem'
|
||||||
|
dest: '/etc/swanctl/x509ca/ca-crt.pem'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: Copy keys
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'strongswan/keys/'
|
||||||
|
dest: '/etc/swanctl/rsa/'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0640'
|
||||||
|
|
||||||
|
- name: Copy certificates
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'strongswan/certs/'
|
||||||
|
dest: '/etc/swanctl/x509/'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify:
|
||||||
|
- Restart strongswan service
|
||||||
|
|
||||||
|
- name: Configure ra0 iface
|
||||||
|
ansible.builtin.script: 'strongswan/iface-ra0-up.sh'
|
||||||
|
|
||||||
|
- name: Copy ra0 iface setup script
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'strongswan/iface-ra0-up.sh'
|
||||||
|
dest: '/usr/local/bin'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Copy ra0 startup service
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'strongswan/iface-ra0.service'
|
||||||
|
dest: '/etc/systemd/system/iface-ra0.service'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify:
|
||||||
|
- Reload ra0 startup service
|
||||||
|
|
||||||
|
- name: Ufw allow strongswan ports
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
proto: udp
|
||||||
|
port: '{{ item }}'
|
||||||
|
loop:
|
||||||
|
- '500'
|
||||||
|
- '4500'
|
||||||
|
|
||||||
|
- name: Ufw allow from vpn subnet
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
proto: any
|
||||||
|
src: '10.9.0.0/24'
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Restart strongswan service
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: strongswan
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: Reload ra0 startup service
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: iface-ra0.service
|
||||||
|
enabled: true
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Setup cloak
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Create go download directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /opt/go
|
||||||
|
state: directory
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Download go
|
||||||
|
ansible.builtin.get_url:
|
||||||
|
url: 'https://go.dev/dl/go1.26.0.linux-amd64.tar.gz'
|
||||||
|
dest: '/opt/go/go1.26.0.linux-amd64.tar.gz'
|
||||||
|
mode: '0644'
|
||||||
|
timeout: 60
|
||||||
|
|
||||||
|
- name: Unpack go
|
||||||
|
ansible.builtin.unarchive:
|
||||||
|
src: '/opt/go/go1.26.0.linux-amd64.tar.gz'
|
||||||
|
dest: '/usr/local'
|
||||||
|
remote_src: true
|
||||||
|
|
||||||
|
- name: Install git and make
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name:
|
||||||
|
- git
|
||||||
|
- make
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Clone cloak git repository
|
||||||
|
ansible.builtin.git:
|
||||||
|
repo: 'https://github.com/cbeuw/Cloak.git'
|
||||||
|
dest: '/opt/git/Cloak'
|
||||||
|
single_branch: true
|
||||||
|
version: master
|
||||||
|
|
||||||
|
- name: Build cloak
|
||||||
|
community.general.make:
|
||||||
|
chdir: '/opt/git/Cloak'
|
||||||
|
environment:
|
||||||
|
PATH: '{{ ansible_env.PATH }}:/usr/local/go/bin'
|
||||||
|
|
||||||
|
- name: Setup cloak server
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: '/opt/git/Cloak/build/ck-server'
|
||||||
|
remote_src: true
|
||||||
|
dest: '/usr/local/bin'
|
||||||
|
owner: 'root'
|
||||||
|
group: 'root'
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Add cloak group
|
||||||
|
ansible.builtin.group:
|
||||||
|
name: cloak
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Add user for cloak
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: cloak
|
||||||
|
group: cloak
|
||||||
|
state: present
|
||||||
|
createhome: false
|
||||||
|
|
||||||
|
- name: Create cloak directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: '/etc/cloak'
|
||||||
|
state: directory
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Setup cloak server configuration
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: 'cloak/server.json.j2'
|
||||||
|
dest: '/etc/cloak/server.json'
|
||||||
|
owner: root
|
||||||
|
group: cloak
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: Create cloak server data dir
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: '/opt/cloak'
|
||||||
|
state: directory
|
||||||
|
owner: cloak
|
||||||
|
group: cloak
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Setup cloak systemd service
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'cloak/cloak.service'
|
||||||
|
dest: '/etc/systemd/system/cloak.service'
|
||||||
|
mode: '0644'
|
||||||
|
notify: Reload cloak service
|
||||||
|
|
||||||
|
- name: Ufw allow cloak port
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
port: '5691'
|
||||||
|
proto: tcp
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Reload cloak service
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: cloak.service
|
||||||
|
state: started
|
||||||
|
enabled: false
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Setup openvpn server
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Install openvpn server
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: openvpn
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Copy certificates
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'openvpn/certs/'
|
||||||
|
dest: '/etc/openvpn/server/'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0640'
|
||||||
|
|
||||||
|
- name: Copy openvpn config
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'openvpn/server.conf'
|
||||||
|
dest: '/etc/openvpn/server/server.conf'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify:
|
||||||
|
- Restart openvpn server
|
||||||
|
|
||||||
|
- name: Ufw allow openvpn port
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
proto: tcp
|
||||||
|
port: '5690'
|
||||||
|
|
||||||
|
- name: Ufw allow from vpn subnet
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
proto: any
|
||||||
|
src: '10.8.0.0/24'
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Restart openvpn server
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: openvpn-server@server
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: Setup bind9
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Install bind9
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: bind9
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Copy bind9 config
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: '{{ item }}'
|
||||||
|
dest: '/etc/bind/'
|
||||||
|
owner: root
|
||||||
|
group: bind
|
||||||
|
mode: '0644'
|
||||||
|
loop:
|
||||||
|
- 'bind9/named.conf.local'
|
||||||
|
- 'bind9/named.conf.options'
|
||||||
|
- 'bind9/named.conf.default-zones'
|
||||||
|
- 'bind9/named.conf.root-hints'
|
||||||
|
|
||||||
|
- name: Copy bind9 zones
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'bind9/zones/'
|
||||||
|
dest: '/etc/bind/zones/'
|
||||||
|
owner: root
|
||||||
|
group: bind
|
||||||
|
mode: '0644'
|
||||||
|
notify:
|
||||||
|
- Restart bind9
|
||||||
|
|
||||||
|
- name: Ufw allow bind9 ports
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
name: Bind9
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Restart bind9
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: named
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Setup prometheus node exporter
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Create node-exporter download directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /opt/node-exporter
|
||||||
|
state: directory
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Download node exporter executable
|
||||||
|
ansible.builtin.get_url:
|
||||||
|
url: 'https://github.com/prometheus/node_exporter/releases/download/v1.10.2/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||||
|
dest: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||||
|
mode: '0644'
|
||||||
|
|
||||||
|
- name: Extract node_exporter
|
||||||
|
ansible.builtin.unarchive:
|
||||||
|
src: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||||
|
dest: '/usr/local/bin'
|
||||||
|
remote_src: true
|
||||||
|
include:
|
||||||
|
- 'node_exporter-1.10.2.linux-amd64/node_exporter'
|
||||||
|
extra_opts:
|
||||||
|
- '--strip-components=1'
|
||||||
|
|
||||||
|
- name: Add node-exporter group
|
||||||
|
ansible.builtin.group:
|
||||||
|
name: node_exporter
|
||||||
|
state: present
|
||||||
|
|
||||||
|
- name: Add user for node exporter
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: node_exporter
|
||||||
|
group: node_exporter
|
||||||
|
state: present
|
||||||
|
createhome: false
|
||||||
|
|
||||||
|
- name: Setup node-exporter service
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'node-exporter/node-exporter.service'
|
||||||
|
dest: '/etc/systemd/system/node-exporter.service'
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0644'
|
||||||
|
notify: Reload node-exporter
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Reload node-exporter
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: node-exporter
|
||||||
|
state: started
|
||||||
|
enabled: true
|
||||||
|
daemon_reload: true
|
||||||
|
|
||||||
|
- name: Setup haproxy
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Install haproxy
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: haproxy
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Create haproxy certs directory
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/haproxy/certs/
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: haproxy
|
||||||
|
mode: '0755'
|
||||||
|
|
||||||
|
- name: Copy server certificate and key
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'haproxy/64.188.58.223.pem'
|
||||||
|
dest: '/etc/haproxy/certs/64.188.58.223.pem'
|
||||||
|
owner: root
|
||||||
|
group: haproxy
|
||||||
|
mode: '0640'
|
||||||
|
|
||||||
|
- name: Copy configuration
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'haproxy/haproxy.cfg'
|
||||||
|
dest: '/etc/haproxy/haproxy.cfg'
|
||||||
|
owner: root
|
||||||
|
group: haproxy
|
||||||
|
mode: '0644'
|
||||||
|
notify: Restart haproxy
|
||||||
|
|
||||||
|
- name: Allow ufw jenkins webhook port
|
||||||
|
community.general.ufw:
|
||||||
|
rule: allow
|
||||||
|
port: '7777'
|
||||||
|
proto: tcp
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Restart haproxy
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: haproxy
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
- name: Setup tiny proxy
|
||||||
|
hosts: vps_servers
|
||||||
|
become: true
|
||||||
|
tasks:
|
||||||
|
- name: Install tiny proxy
|
||||||
|
ansible.builtin.apt:
|
||||||
|
name: tinyproxy
|
||||||
|
state: present
|
||||||
|
update_cache: true
|
||||||
|
|
||||||
|
- name: Configure tiny proxy
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: 'tinyproxy/tinyproxy.conf'
|
||||||
|
dest: '/etc/tinyproxy/tinyproxy.conf'
|
||||||
|
mode: '0644'
|
||||||
|
notify: Restart tinyproxy
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
- name: Restart tinyproxy
|
||||||
|
ansible.builtin.systemd:
|
||||||
|
name: tinyproxy
|
||||||
|
state: restarted
|
||||||
|
enabled: true
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
dhcp {
|
||||||
|
load = yes
|
||||||
|
force_server_address = yes
|
||||||
|
server = 10.9.0.255
|
||||||
|
interface = {{ public_ip_iface }}
|
||||||
|
}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
set +e
|
||||||
|
|
||||||
|
echo "Confiugring ra0 network interface at $(date)"
|
||||||
|
|
||||||
|
ip link add ra0 type xfrm if_id 0x21
|
||||||
|
ip link set ra0 up
|
||||||
|
ip addr add 10.9.0.1/24 brd + dev ra0
|
||||||
|
ip route add 10.9.0.0/24 dev ra0
|
||||||
|
|
||||||
|
set -e
|
||||||
|
|
||||||
|
exit 0
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Configure ra0 interface on startup
|
||||||
|
After=network.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
ExecStart=/usr/local/bin/iface-ra0-up.sh
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
@@ -0,0 +1,92 @@
|
|||||||
|
connections {
|
||||||
|
ra-tech {
|
||||||
|
pools = ra-tech-pool
|
||||||
|
local {
|
||||||
|
auth = pubkey
|
||||||
|
certs = vps-crt.pem
|
||||||
|
id = vps.ra-tech.dev
|
||||||
|
}
|
||||||
|
remote {
|
||||||
|
auth = pubkey
|
||||||
|
}
|
||||||
|
children {
|
||||||
|
ra-tech {
|
||||||
|
local_ts = 0.0.0.0/0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
send_cert = always
|
||||||
|
if_id_in = 0x21
|
||||||
|
if_id_out = 0x21
|
||||||
|
}
|
||||||
|
ra-tech-ip {
|
||||||
|
pools = ra-tech-pool
|
||||||
|
local {
|
||||||
|
auth = pubkey
|
||||||
|
certs = ip-vps-crt.pem
|
||||||
|
id = {{ public_ip }}
|
||||||
|
}
|
||||||
|
remote {
|
||||||
|
auth = pubkey
|
||||||
|
}
|
||||||
|
children {
|
||||||
|
ra-tech-ip {
|
||||||
|
local_ts = 0.0.0.0/0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
send_cert = always
|
||||||
|
if_id_in = 0x21
|
||||||
|
if_id_out = 0x21
|
||||||
|
}
|
||||||
|
ra-tech-subnet {
|
||||||
|
pools = ra-tech-pool
|
||||||
|
local {
|
||||||
|
auth = pubkey
|
||||||
|
certs = vpn-subnet-crt.pem
|
||||||
|
id = vpn-subnet.ra-tech.dev
|
||||||
|
}
|
||||||
|
remote {
|
||||||
|
auth = pubkey
|
||||||
|
}
|
||||||
|
children {
|
||||||
|
ra-tech-subnet {
|
||||||
|
local_ts = 10.9.0.0/24
|
||||||
|
}
|
||||||
|
}
|
||||||
|
send_cert = always
|
||||||
|
if_id_in = 0x21
|
||||||
|
if_id_out = 0x21
|
||||||
|
}
|
||||||
|
ra-tech-odroid {
|
||||||
|
pools = odroid-pool
|
||||||
|
local {
|
||||||
|
auth = pubkey
|
||||||
|
certs = odroid-vps-crt.pem
|
||||||
|
id = odroid-vps.ra-tech.dev
|
||||||
|
}
|
||||||
|
remote {
|
||||||
|
auth = pubkey
|
||||||
|
id = odroid@ra-tech.dev
|
||||||
|
}
|
||||||
|
children {
|
||||||
|
ra-tech-odroid {
|
||||||
|
local_ts = 0.0.0.0/0
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if_id_in = 0x21
|
||||||
|
if_id_out = 0x21
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pools {
|
||||||
|
ra-tech-pool {
|
||||||
|
addrs = 10.9.0.11 - 10.9.0.30
|
||||||
|
dns = 10.9.0.1
|
||||||
|
netmask = 255.255.255.0
|
||||||
|
}
|
||||||
|
|
||||||
|
odroid-pool {
|
||||||
|
addrs = 10.9.0.10
|
||||||
|
dns = 10.9.0.1
|
||||||
|
netmask = 255.255.255.0
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
net.ipv4.ip_forward=1
|
||||||
@@ -0,0 +1,356 @@
|
|||||||
|
##
|
||||||
|
## tinyproxy.conf -- tinyproxy daemon configuration file
|
||||||
|
##
|
||||||
|
## This example tinyproxy.conf file contains example settings
|
||||||
|
## with explanations in comments. For decriptions of all
|
||||||
|
## parameters, see the tinproxy.conf(5) manual page.
|
||||||
|
##
|
||||||
|
|
||||||
|
#
|
||||||
|
# User/Group: This allows you to set the user and group that will be
|
||||||
|
# used for tinyproxy after the initial binding to the port has been done
|
||||||
|
# as the root user. Either the user or group name or the UID or GID
|
||||||
|
# number may be used.
|
||||||
|
#
|
||||||
|
User tinyproxy
|
||||||
|
Group tinyproxy
|
||||||
|
|
||||||
|
#
|
||||||
|
# Port: Specify the port which tinyproxy will listen on. Please note
|
||||||
|
# that should you choose to run on a port lower than 1024 you will need
|
||||||
|
# to start tinyproxy using root.
|
||||||
|
#
|
||||||
|
Port 8888
|
||||||
|
|
||||||
|
#
|
||||||
|
# Listen: If you have multiple interfaces this allows you to bind to
|
||||||
|
# only one. If this is commented out, tinyproxy will bind to all
|
||||||
|
# interfaces present.
|
||||||
|
#
|
||||||
|
Listen 10.9.0.1
|
||||||
|
Listen 10.8.0.1
|
||||||
|
|
||||||
|
#
|
||||||
|
# Bind: This allows you to specify which interface will be used for
|
||||||
|
# outgoing connections. This is useful for multi-home'd machines where
|
||||||
|
# you want all traffic to appear outgoing from one particular interface.
|
||||||
|
#
|
||||||
|
#Bind 192.168.0.1
|
||||||
|
|
||||||
|
#
|
||||||
|
# BindSame: If enabled, tinyproxy will bind the outgoing connection to the
|
||||||
|
# ip address of the incoming connection.
|
||||||
|
#
|
||||||
|
#BindSame yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# Timeout: The maximum number of seconds of inactivity a connection is
|
||||||
|
# allowed to have before it is closed by tinyproxy.
|
||||||
|
#
|
||||||
|
Timeout 600
|
||||||
|
|
||||||
|
#
|
||||||
|
# ErrorFile: Defines the HTML file to send when a given HTTP error
|
||||||
|
# occurs. You will probably need to customize the location to your
|
||||||
|
# particular install. The usual locations to check are:
|
||||||
|
# /usr/local/share/tinyproxy
|
||||||
|
# /usr/share/tinyproxy
|
||||||
|
# /etc/tinyproxy
|
||||||
|
#
|
||||||
|
#ErrorFile 404 "/usr/share/tinyproxy/404.html"
|
||||||
|
#ErrorFile 400 "/usr/share/tinyproxy/400.html"
|
||||||
|
#ErrorFile 503 "/usr/share/tinyproxy/503.html"
|
||||||
|
#ErrorFile 403 "/usr/share/tinyproxy/403.html"
|
||||||
|
#ErrorFile 408 "/usr/share/tinyproxy/408.html"
|
||||||
|
|
||||||
|
#
|
||||||
|
# DefaultErrorFile: The HTML file that gets sent if there is no
|
||||||
|
# HTML file defined with an ErrorFile keyword for the HTTP error
|
||||||
|
# that has occured.
|
||||||
|
#
|
||||||
|
DefaultErrorFile "/usr/share/tinyproxy/default.html"
|
||||||
|
|
||||||
|
#
|
||||||
|
# StatHost: This configures the host name or IP address that is treated
|
||||||
|
# as the stat host: Whenever a request for this host is received,
|
||||||
|
# Tinyproxy will return an internal statistics page instead of
|
||||||
|
# forwarding the request to that host. The default value of StatHost is
|
||||||
|
# tinyproxy.stats.
|
||||||
|
#
|
||||||
|
StatHost "tinyproxy.stats"
|
||||||
|
#
|
||||||
|
|
||||||
|
#
|
||||||
|
# StatFile: The HTML file that gets sent when a request is made
|
||||||
|
# for the stathost. If this file doesn't exist a basic page is
|
||||||
|
# hardcoded in tinyproxy.
|
||||||
|
#
|
||||||
|
StatFile "/usr/share/tinyproxy/stats.html"
|
||||||
|
|
||||||
|
#
|
||||||
|
# LogFile: Allows you to specify the location where information should
|
||||||
|
# be logged to. If you would prefer to log to syslog, then disable this
|
||||||
|
# and enable the Syslog directive. These directives are mutually
|
||||||
|
# exclusive. If neither Syslog nor LogFile are specified, output goes
|
||||||
|
# to stdout.
|
||||||
|
#
|
||||||
|
LogFile "/var/log/tinyproxy/tinyproxy.log"
|
||||||
|
|
||||||
|
#
|
||||||
|
# Syslog: Tell tinyproxy to use syslog instead of a logfile. This
|
||||||
|
# option must not be enabled if the Logfile directive is being used.
|
||||||
|
# These two directives are mutually exclusive.
|
||||||
|
#
|
||||||
|
Syslog On
|
||||||
|
|
||||||
|
#
|
||||||
|
# LogLevel: Warning
|
||||||
|
#
|
||||||
|
# Set the logging level. Allowed settings are:
|
||||||
|
# Critical (least verbose)
|
||||||
|
# Set the logging level. Allowed settings are:
|
||||||
|
# Critical (least verbose)
|
||||||
|
# Error
|
||||||
|
# Warning
|
||||||
|
# Notice
|
||||||
|
# Connect (to log connections without Info's noise)
|
||||||
|
# Info (most verbose)
|
||||||
|
#
|
||||||
|
# The LogLevel logs from the set level and above. For example, if the
|
||||||
|
# LogLevel was set to Warning, then all log messages from Warning to
|
||||||
|
# Critical would be output, but Notice and below would be suppressed.
|
||||||
|
#
|
||||||
|
LogLevel Info
|
||||||
|
|
||||||
|
#
|
||||||
|
# PidFile: Write the PID of the main tinyproxy thread to this file so it
|
||||||
|
# can be used for signalling purposes.
|
||||||
|
# If not specified, no pidfile will be written.
|
||||||
|
#
|
||||||
|
PidFile "/run/tinyproxy/tinyproxy.pid"
|
||||||
|
|
||||||
|
#
|
||||||
|
# XTinyproxy: Tell Tinyproxy to include the X-Tinyproxy header, which
|
||||||
|
# contains the client's IP address.
|
||||||
|
#
|
||||||
|
#XTinyproxy Yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# Upstream:
|
||||||
|
#
|
||||||
|
# Turns on upstream proxy support.
|
||||||
|
#
|
||||||
|
# The upstream rules allow you to selectively route upstream connections
|
||||||
|
# based on the host/domain of the site being accessed.
|
||||||
|
#
|
||||||
|
# Syntax: upstream type (user:pass@)ip:port ("domain")
|
||||||
|
# Or: upstream none "domain"
|
||||||
|
# The parts in parens are optional.
|
||||||
|
# Possible types are http, socks4, socks5, none
|
||||||
|
#
|
||||||
|
# For example:
|
||||||
|
# # connection to test domain goes through testproxy
|
||||||
|
# upstream http testproxy:8008 ".test.domain.invalid"
|
||||||
|
# upstream http testproxy:8008 ".our_testbed.example.com"
|
||||||
|
# upstream http testproxy:8008 "192.168.128.0/255.255.254.0"
|
||||||
|
#
|
||||||
|
# # upstream proxy using basic authentication
|
||||||
|
# upstream http user:pass@testproxy:8008 ".test.domain.invalid"
|
||||||
|
#
|
||||||
|
# # no upstream proxy for internal websites and unqualified hosts
|
||||||
|
# upstream none ".internal.example.com"
|
||||||
|
# upstream none "www.example.com"
|
||||||
|
# upstream none "10.0.0.0/8"
|
||||||
|
# upstream none "192.168.0.0/255.255.254.0"
|
||||||
|
# upstream none "."
|
||||||
|
#
|
||||||
|
# # connection to these boxes go through their DMZ firewalls
|
||||||
|
# upstream http cust1_firewall:8008 "testbed_for_cust1"
|
||||||
|
# upstream http cust2_firewall:8008 "testbed_for_cust2"
|
||||||
|
#
|
||||||
|
# # default upstream is internet firewall
|
||||||
|
# upstream http firewall.internal.example.com:80
|
||||||
|
#
|
||||||
|
# You may also use SOCKS4/SOCKS5 upstream proxies:
|
||||||
|
# upstream socks4 127.0.0.1:9050
|
||||||
|
# upstream socks5 socksproxy:1080
|
||||||
|
#
|
||||||
|
# The LAST matching rule wins the route decision. As you can see, you
|
||||||
|
# can use a host, or a domain:
|
||||||
|
# name matches host exactly
|
||||||
|
# .name matches any host in domain "name"
|
||||||
|
# . matches any host with no domain (in 'empty' domain)
|
||||||
|
# IP/bits matches network/mask
|
||||||
|
# IP/mask matches network/mask
|
||||||
|
#
|
||||||
|
#Upstream http some.remote.proxy:port
|
||||||
|
|
||||||
|
#
|
||||||
|
# MaxClients: This is the absolute highest number of threads which will
|
||||||
|
# be created. In other words, only MaxClients number of clients can be
|
||||||
|
# connected at the same time.
|
||||||
|
#
|
||||||
|
MaxClients 100
|
||||||
|
|
||||||
|
#
|
||||||
|
# MinSpareServers/MaxSpareServers: These settings set the upper and
|
||||||
|
# lower limit for the number of spare servers which should be available.
|
||||||
|
#
|
||||||
|
# If the number of spare servers falls below MinSpareServers then new
|
||||||
|
# server processes will be spawned. If the number of servers exceeds
|
||||||
|
# MaxSpareServers then the extras will be killed off.
|
||||||
|
#
|
||||||
|
MinSpareServers 5
|
||||||
|
MaxSpareServers 20
|
||||||
|
|
||||||
|
#
|
||||||
|
# StartServers: The number of servers to start initially.
|
||||||
|
#
|
||||||
|
StartServers 10
|
||||||
|
|
||||||
|
#
|
||||||
|
# MaxRequestsPerChild: The number of connections a thread will handle
|
||||||
|
# before it is killed. In practise this should be set to 0, which
|
||||||
|
# disables thread reaping. If you do notice problems with memory
|
||||||
|
# leakage, then set this to something like 10000.
|
||||||
|
#
|
||||||
|
MaxRequestsPerChild 0
|
||||||
|
|
||||||
|
#
|
||||||
|
# Allow: Customization of authorization controls. If there are any
|
||||||
|
# access control keywords then the default action is to DENY. Otherwise,
|
||||||
|
# the default action is ALLOW.
|
||||||
|
#
|
||||||
|
# The order of the controls are important. All incoming connections are
|
||||||
|
# tested against the controls based on order.
|
||||||
|
#
|
||||||
|
Allow 127.0.0.1
|
||||||
|
Allow 10.9.0.0/24
|
||||||
|
Allow 10.8.0.0/24
|
||||||
|
#Allow 192.168.0.0/16
|
||||||
|
#Allow 172.16.0.0/12
|
||||||
|
#Allow 10.0.0.0/8
|
||||||
|
|
||||||
|
# BasicAuth: HTTP "Basic Authentication" for accessing the proxy.
|
||||||
|
# If there are any entries specified, access is only granted for authenticated
|
||||||
|
# users.
|
||||||
|
#BasicAuth user password
|
||||||
|
|
||||||
|
#
|
||||||
|
# AddHeader: Adds the specified headers to outgoing HTTP requests that
|
||||||
|
# Tinyproxy makes. Note that this option will not work for HTTPS
|
||||||
|
# traffic, as Tinyproxy has no control over what headers are exchanged.
|
||||||
|
#
|
||||||
|
#AddHeader "X-My-Header" "Powered by Tinyproxy"
|
||||||
|
|
||||||
|
#
|
||||||
|
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
|
||||||
|
#
|
||||||
|
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
|
||||||
|
# the real host name is a security concern. If the following directive
|
||||||
|
# is enabled, the string supplied will be used as the host name in the
|
||||||
|
# Via header; otherwise, the server's host name will be used.
|
||||||
|
#
|
||||||
|
ViaProxyName "tinyproxy"
|
||||||
|
|
||||||
|
#
|
||||||
|
# DisableViaHeader: When this is set to yes, Tinyproxy does NOT add
|
||||||
|
# the Via header to the requests. This virtually puts Tinyproxy into
|
||||||
|
# stealth mode. Note that RFC 2616 requires proxies to set the Via
|
||||||
|
# header, so by enabling this option, you break compliance.
|
||||||
|
# Don't disable the Via header unless you know what you are doing...
|
||||||
|
#
|
||||||
|
#DisableViaHeader Yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# Filter: This allows you to specify the location of the filter file.
|
||||||
|
#
|
||||||
|
#Filter "/etc/tinyproxy/filter"
|
||||||
|
|
||||||
|
#
|
||||||
|
# FilterURLs: Filter based on URLs rather than domains.
|
||||||
|
#
|
||||||
|
#FilterURLs On
|
||||||
|
|
||||||
|
#
|
||||||
|
# FilterExtended: Use POSIX Extended regular expressions rather than
|
||||||
|
# basic.
|
||||||
|
#
|
||||||
|
#FilterExtended On
|
||||||
|
|
||||||
|
#
|
||||||
|
# FilterCaseSensitive: Use case sensitive regular expressions.
|
||||||
|
#
|
||||||
|
#FilterCaseSensitive On
|
||||||
|
|
||||||
|
#
|
||||||
|
# FilterDefaultDeny: Change the default policy of the filtering system.
|
||||||
|
# If this directive is commented out, or is set to "No" then the default
|
||||||
|
# policy is to allow everything which is not specifically denied by the
|
||||||
|
# filter file.
|
||||||
|
#
|
||||||
|
# However, by setting this directive to "Yes" the default policy becomes
|
||||||
|
# to deny everything which is _not_ specifically allowed by the filter
|
||||||
|
# file.
|
||||||
|
#
|
||||||
|
#FilterDefaultDeny Yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# Anonymous: If an Anonymous keyword is present, then anonymous proxying
|
||||||
|
# is enabled. The headers listed are allowed through, while all others
|
||||||
|
# are denied. If no Anonymous keyword is present, then all headers are
|
||||||
|
# allowed through. You must include quotes around the headers.
|
||||||
|
#
|
||||||
|
# Most sites require cookies to be enabled for them to work correctly, so
|
||||||
|
# you will need to allow Cookies through if you access those sites.
|
||||||
|
#
|
||||||
|
#Anonymous "Host"
|
||||||
|
#Anonymous "Authorization"
|
||||||
|
#Anonymous "Cookie"
|
||||||
|
|
||||||
|
#
|
||||||
|
# ConnectPort: This is a list of ports allowed by tinyproxy when the
|
||||||
|
# CONNECT method is used. To disable the CONNECT method altogether, set
|
||||||
|
# the value to 0. If no ConnectPort line is found, all ports are
|
||||||
|
# allowed.
|
||||||
|
#
|
||||||
|
# The following two ports are used by SSL.
|
||||||
|
#
|
||||||
|
ConnectPort 443
|
||||||
|
ConnectPort 563
|
||||||
|
|
||||||
|
#
|
||||||
|
# Configure one or more ReversePath directives to enable reverse proxy
|
||||||
|
# support. With reverse proxying it's possible to make a number of
|
||||||
|
# sites appear as if they were part of a single site.
|
||||||
|
#
|
||||||
|
# If you uncomment the following two directives and run tinyproxy
|
||||||
|
# on your own computer at port 8888, you can access Google using
|
||||||
|
# http://localhost:8888/google/ and Wired News using
|
||||||
|
# http://localhost:8888/wired/news/. Neither will actually work
|
||||||
|
# until you uncomment ReverseMagic as they use absolute linking.
|
||||||
|
#
|
||||||
|
#ReversePath "/google/" "http://www.google.com/"
|
||||||
|
#ReversePath "/wired/" "http://www.wired.com/"
|
||||||
|
|
||||||
|
#
|
||||||
|
# When using tinyproxy as a reverse proxy, it is STRONGLY recommended
|
||||||
|
# that the normal proxy is turned off by uncommenting the next directive.
|
||||||
|
#
|
||||||
|
#ReverseOnly Yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# Use a cookie to track reverse proxy mappings. If you need to reverse
|
||||||
|
# proxy sites which have absolute links you must uncomment this.
|
||||||
|
#
|
||||||
|
#ReverseMagic Yes
|
||||||
|
|
||||||
|
#
|
||||||
|
# The URL that's used to access this reverse proxy. The URL is used to
|
||||||
|
# rewrite HTTP redirects so that they won't escape the proxy. If you
|
||||||
|
# have a chain of reverse proxies, you'll need to put the outermost
|
||||||
|
# URL here (the address which the end user types into his/her browser).
|
||||||
|
#
|
||||||
|
# If not set then no rewriting occurs.
|
||||||
|
#
|
||||||
|
#ReverseBaseURL "http://localhost:8888/"
|
||||||
Reference in new issue
Block a user