Compare commits
18 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bd13f3a938 | |||
|
|
ca3cc077d6 | ||
|
|
904dcb399d | ||
|
|
0b9f100aa5 | ||
|
|
90167ae771 | ||
|
|
a84ea36b37 | ||
|
|
dc68166c27 | ||
|
|
c9339c1f3b | ||
|
|
0755fa30b2 | ||
|
|
76b57fb097 | ||
|
|
49d61b875e | ||
|
|
ffba32f382 | ||
|
|
2b56aaf46c | ||
|
|
154899586e | ||
|
|
c7aae63e16 | ||
|
|
a9fa164ebe | ||
|
|
5431276c8e | ||
|
|
a0228786d3 |
@@ -9,7 +9,7 @@ sudo: false
|
||||
addons:
|
||||
apt:
|
||||
packages:
|
||||
- python-pip
|
||||
- python-pip
|
||||
|
||||
install:
|
||||
# Install ansible
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
[TODO] Update build
|
||||
[](https://travis-ci.org/m4rcu5nl/ansible-role-zerotier) [](https://github.com/m4rcu5nl/ansible-role-zerotier/issues)
|
||||
|
||||
ZeroTier
|
||||
@@ -13,7 +14,6 @@ Technically this role has no requirements. If it's ran without any variables set
|
||||
[**zerotier_network_id**](#zerotier_network_id): when set hosts are told to join this network.
|
||||
[**zerotier_api_accesstoken**](#zerotier_api_accesstoken): when set the role can handle member authentication and configuration using the ZeroTier API.
|
||||
|
||||
|
||||
Role Variables
|
||||
--------------
|
||||
|
||||
@@ -35,7 +35,7 @@ Role Variables
|
||||
### zerotier_member_description
|
||||
*Type*: string
|
||||
*Default value*: `""`
|
||||
*Description*: Optional desription for a member.
|
||||
*Description*: Optional description for a member.
|
||||
|
||||
### zerotier_api_accesstoken
|
||||
*Type*: string
|
||||
@@ -50,7 +50,7 @@ Role Variables
|
||||
### zerotier_api_delegate
|
||||
*Type*: string
|
||||
*Default value*: `localhost`
|
||||
*Description*: Option to delegate tasks for Zerotier API calls. This is usefull in a situation where API calls can only be made from a whitelisted management server, for example.
|
||||
*Description*: Option to delegate tasks for Zerotier API calls. This is useful in a situation where API calls can only be made from a white-listed management server, for example.
|
||||
|
||||
Example Playbook
|
||||
----------------
|
||||
@@ -59,7 +59,7 @@ Example Playbook
|
||||
- hosts: servers
|
||||
vars:
|
||||
zerotier_network_id: 1234567890qwerty
|
||||
zerotier_accesstoken: "{{ vault_zerotier_accesstoken }}"
|
||||
zerotier_api_accesstoken: "{{ vault_zerotier_accesstoken }}"
|
||||
zerotier_register_short_hostname: true
|
||||
|
||||
roles:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
---
|
||||
# defaults file for ansible-role-zerotier
|
||||
zerotier_api_accesstoken: "{{ zerotier_accesstoken | default() }}" # For backwards compatibility
|
||||
zerotier_api_url: https://my.zerotier.com
|
||||
zerotier_api_url: https://api.zerotier.com
|
||||
zerotier_api_delegate: localhost
|
||||
zerotier_apt_state: present
|
||||
zerotier_member_register_short_hostname: "{{ zerotier_register_short_hostname | default(false) }}" # For backwards compatibility
|
||||
|
||||
@@ -6,7 +6,7 @@ NETWORKS=$(zerotier-cli listnetworks | tail -n+2)
|
||||
|
||||
function file_content {
|
||||
if [ ! -z "$NETWORKS" ]; then
|
||||
network_count=$(echo $NETWORKS |wc -l)
|
||||
network_count=$(echo "$NETWORKS" |wc -l)
|
||||
counter=1
|
||||
|
||||
echo "{"
|
||||
@@ -15,7 +15,7 @@ function file_content {
|
||||
while read -r; do
|
||||
network=($REPLY)
|
||||
echo " \"${network[2]}\": {"
|
||||
echo " \"status\":\"${network[5]}\""
|
||||
echo " \"status\":\"${network[5]}\","
|
||||
echo " \"device\":\"${network[7]}\""
|
||||
|
||||
if [ "$counter" -eq "$network_count" ]; then
|
||||
|
||||
@@ -16,7 +16,7 @@ galaxy_info:
|
||||
# - CC-BY
|
||||
license: GPLv3
|
||||
|
||||
min_ansible_version: 2.4
|
||||
min_ansible_version: 2.9
|
||||
|
||||
# If this a Container Enabled role, provide the minimum Ansible Container version.
|
||||
# min_ansible_container_version:
|
||||
@@ -33,19 +33,19 @@ galaxy_info:
|
||||
# platforms is a list of platforms, and each platform has a name and a list of versions.
|
||||
#
|
||||
platforms:
|
||||
- name: EL
|
||||
versions:
|
||||
- 7
|
||||
- name: Debian
|
||||
versions:
|
||||
- stretch
|
||||
- name: Ubuntu
|
||||
versions:
|
||||
- Bionic
|
||||
- Cosmic
|
||||
- name: Fedora
|
||||
versions:
|
||||
- 28
|
||||
- name: EL
|
||||
versions:
|
||||
- 7
|
||||
- name: Debian
|
||||
versions:
|
||||
- stretch
|
||||
- name: Ubuntu
|
||||
versions:
|
||||
- Bionic
|
||||
- Cosmic
|
||||
- name: Fedora
|
||||
versions:
|
||||
- 39
|
||||
# - name: SomePlatform
|
||||
# versions:
|
||||
# - all
|
||||
@@ -54,15 +54,16 @@ galaxy_info:
|
||||
# - 99.99
|
||||
|
||||
galaxy_tags:
|
||||
- zerotier
|
||||
- networking
|
||||
# List tags for your role here, one per line. A tag is a keyword that describes
|
||||
# and categorizes the role. Users find roles by searching for tags. Be sure to
|
||||
# remove the '[]' above, if you add tags to this list.
|
||||
#
|
||||
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
|
||||
# Maximum 20 tags per role.
|
||||
- zerotier
|
||||
- networking
|
||||
# List tags for your role here, one per line. A tag is a keyword that describes
|
||||
# and categorizes the role. Users find roles by searching for tags. Be sure to
|
||||
# remove the '[]' above, if you add tags to this list.
|
||||
#
|
||||
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
|
||||
# Maximum 20 tags per role.
|
||||
|
||||
dependencies: []
|
||||
dependencies:
|
||||
[]
|
||||
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
|
||||
# if you add dependencies to this list.
|
||||
|
||||
@@ -1,38 +1,39 @@
|
||||
---
|
||||
- block:
|
||||
- name: Authorize new members to network
|
||||
uri:
|
||||
url: "{{ zerotier_api_url }}/api/network/{{ zerotier_network_id }}/member/{{ ansible_local.zerotier.node_id }}"
|
||||
method: POST
|
||||
headers:
|
||||
Authorization: bearer {{ zerotier_api_accesstoken }}
|
||||
body:
|
||||
hidden: false
|
||||
config:
|
||||
authorized: "{{ zerotier_authorize_member }}"
|
||||
body_format: json
|
||||
- name: Authorize new members to network
|
||||
uri:
|
||||
url: "{{ zerotier_api_url }}/api/v1/network/{{ zerotier_network_id }}/member/{{ ansible_local['zerotier']['node_id'] }}"
|
||||
method: POST
|
||||
headers:
|
||||
Authorization: bearer {{ zerotier_api_accesstoken }}
|
||||
body:
|
||||
hidden: false
|
||||
config:
|
||||
authorized: "{{ zerotier_authorize_member }}"
|
||||
body_format: json
|
||||
register: auth_apiresult
|
||||
delegate_to: "{{ zerotier_api_delegate }}"
|
||||
when:
|
||||
- ansible_local.zerotier.networks[zerotier_network_id] is not defined or ansible_local.zerotier.networks[zerotier_network_id].status != 'OK'
|
||||
delegate_to: "{{ zerotier_api_delegate }}"
|
||||
when:
|
||||
- ansible_local['zerotier']['networks'][zerotier_network_id] is not defined or
|
||||
ansible_local['zerotier']['networks'][zerotier_network_id]['status'] != 'OK'
|
||||
|
||||
- name: Configure members in network
|
||||
uri:
|
||||
url: "{{ zerotier_api_url }}/api/network/{{ zerotier_network_id }}/member/{{ ansible_local.zerotier.node_id }}"
|
||||
method: POST
|
||||
headers:
|
||||
Authorization: bearer {{ zerotier_api_accesstoken }}
|
||||
body:
|
||||
name: "{{ zerotier_member_register_short_hostname | ternary(inventory_hostname_short, inventory_hostname) }}"
|
||||
description: "{{ zerotier_member_description | default() }}"
|
||||
config:
|
||||
ipAssignments: "{{ zerotier_member_ip_assignments | default([]) | list }}"
|
||||
body_format: json
|
||||
- name: Configure members in network
|
||||
uri:
|
||||
url: "{{ zerotier_api_url }}/api/v1/network/{{ zerotier_network_id }}/member/{{ ansible_local['zerotier']['node_id'] }}"
|
||||
method: POST
|
||||
headers:
|
||||
Authorization: bearer {{ zerotier_api_accesstoken }}
|
||||
body:
|
||||
name: "{{ zerotier_member_register_short_hostname | ternary(inventory_hostname_short, inventory_hostname) }}"
|
||||
description: "{{ zerotier_member_description | default() }}"
|
||||
config:
|
||||
ipAssignments: "{{ zerotier_member_ip_assignments | default([]) | list }}"
|
||||
body_format: json
|
||||
register: conf_apiresult
|
||||
delegate_to: "{{ zerotier_api_delegate }}"
|
||||
delegate_to: "{{ zerotier_api_delegate }}"
|
||||
|
||||
when:
|
||||
- not ansible_check_mode
|
||||
- not ansible_check_mode
|
||||
tags:
|
||||
- configuration
|
||||
- configuration
|
||||
become: false
|
||||
|
||||
@@ -1,30 +1,29 @@
|
||||
---
|
||||
|
||||
- include_tasks: install/{{ ansible_os_family }}.yml
|
||||
- include_tasks: install/{{ ansible_facts['os_family'] }}.yml
|
||||
tags:
|
||||
- installation
|
||||
- repositories
|
||||
- installation
|
||||
- repositories
|
||||
|
||||
- block: #Install and enable zerotier-one
|
||||
- name: Install zerotier-one
|
||||
package:
|
||||
name: zerotier-one
|
||||
state: present
|
||||
update_cache: yes
|
||||
register: zerotier_client
|
||||
- name: Install zerotier-one
|
||||
package:
|
||||
name: zerotier-one
|
||||
state: present
|
||||
update_cache: yes
|
||||
register: zerotier_client
|
||||
|
||||
- name: Start zerotier-one service
|
||||
service:
|
||||
name: zerotier-one
|
||||
state: started
|
||||
when:
|
||||
- zerotier_client is succeeded
|
||||
notify:
|
||||
- enable zerotier-one
|
||||
- name: Start zerotier-one service
|
||||
service:
|
||||
name: zerotier-one
|
||||
state: started
|
||||
when:
|
||||
- zerotier_client is succeeded
|
||||
notify:
|
||||
- enable zerotier-one
|
||||
|
||||
when:
|
||||
- zerotier_repo is not defined or zerotier_repo is succeeded
|
||||
- not ansible_check_mode
|
||||
- zerotier_repo is not defined or zerotier_repo is succeeded
|
||||
- not ansible_check_mode
|
||||
tags:
|
||||
- installation
|
||||
- packages
|
||||
- installation
|
||||
- packages
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
- name: Add ZeroTier PGP key
|
||||
apt_key:
|
||||
url: "{{ zerotier_gpg_url }}"
|
||||
id: "{{ zerotier_gpg_fingerprint }}"
|
||||
|
||||
- name: Check if Ubuntu release has dedicated repo
|
||||
uri:
|
||||
@@ -11,12 +12,12 @@
|
||||
register: release_repo
|
||||
|
||||
- block:
|
||||
- name: Overwrite Ubuntu release repo name
|
||||
set_fact:
|
||||
zerotier_deb_release_repo: bionic
|
||||
- name: Overwrite Ubuntu release repo name
|
||||
set_fact:
|
||||
zerotier_deb_release_repo: bionic
|
||||
|
||||
- name: Re-gather facts
|
||||
setup: ~
|
||||
- name: Re-gather facts
|
||||
setup: ~
|
||||
|
||||
when:
|
||||
- ansible_facts['distribution'] == "Ubuntu"
|
||||
|
||||
@@ -2,6 +2,7 @@
|
||||
rpm_key:
|
||||
state: present
|
||||
key: "{{ zerotier_gpg_url }}"
|
||||
fingerprint: "{{ zerotier_gpg_fingerprint }}"
|
||||
|
||||
- name: Add ZeroTier repo for RHEL/CentOS
|
||||
yum_repository:
|
||||
@@ -11,7 +12,7 @@
|
||||
gpgcheck: yes
|
||||
enabled: yes
|
||||
register: zerotier_repo
|
||||
when: ansible_distribution != "Fedora"
|
||||
when: ansible_facts['distribution'] != "Fedora"
|
||||
|
||||
- name: Add zerotier repo for Fedora
|
||||
yum_repository:
|
||||
@@ -21,4 +22,4 @@
|
||||
gpgcheck: yes
|
||||
enabled: yes
|
||||
register: zerotier_repo
|
||||
when: ansible_distribution == "Fedora"
|
||||
when: ansible_facts['distribution'] == "Fedora"
|
||||
|
||||
@@ -4,4 +4,4 @@
|
||||
args:
|
||||
creates: /var/lib/zerotier-one/networks.d/{{ zerotier_network_id }}.conf
|
||||
tags:
|
||||
- configuration
|
||||
- configuration
|
||||
|
||||
@@ -2,21 +2,20 @@
|
||||
# tasks file for ansible-role-zerotier
|
||||
- import_tasks: install.yml
|
||||
when:
|
||||
- not skip_install|default(false)|bool
|
||||
- not skip_install | default(false) | bool
|
||||
|
||||
- block:
|
||||
- name: Update ansible_local facts
|
||||
script: set_facts.sh
|
||||
|
||||
- name: Re-gather facts
|
||||
setup: ~
|
||||
- name: Update ansible_local facts
|
||||
script: set_facts.sh
|
||||
|
||||
- name: Re-gather ansible_local facts
|
||||
setup: filter=ansible_local
|
||||
|
||||
- import_tasks: authorize_node.yml
|
||||
when:
|
||||
- zerotier_api_accesstoken | length > 0
|
||||
- ansible_local.zerotier.node_id is defined
|
||||
- zerotier_api_accesstoken | length > 0
|
||||
- ansible_local['zerotier']['node_id'] is defined
|
||||
|
||||
- import_tasks: join_network.yml
|
||||
when:
|
||||
- zerotier_network_id is defined
|
||||
- zerotier_network_id is defined
|
||||
|
||||
@@ -3,3 +3,4 @@
|
||||
zerotier_download_base_url: http://download.zerotier.com
|
||||
zerotier_deb_release_repo: "{{ ansible_facts['distribution_release'] }}"
|
||||
zerotier_gpg_url: https://download.zerotier.com/contact@zerotier.com.gpg
|
||||
zerotier_gpg_fingerprint: 74A5E9C458E1A431F1DA57A71657198823E52A61
|
||||
|
||||
Reference in New Issue
Block a user