84 lines
2.1 KiB
YAML
84 lines
2.1 KiB
YAML
---
|
|
- name: write initial icvpn peers
|
|
shell: /usr/bin/python3 /home/admin/clones/icvpn-scripts/mkbgp -{{ item }} -f bird -x mwu -d ebgp_icvpn -s /home/admin/clones/icvpn-meta > /etc/bird/icvpn_ipv{{ item }}_peers.conf
|
|
args:
|
|
chdir: /home/admin/clones/icvpn-scripts
|
|
creates: /etc/bird/icvpn_ipv{{ item }}_peers.conf
|
|
notify:
|
|
- reload bird{{ item }}
|
|
with_items:
|
|
- 4
|
|
- 6
|
|
|
|
- name: write initial icvpn roa config
|
|
shell: /usr/bin/python3 /home/admin/clones/icvpn-scripts/mkroa -{{ item.key }} -f bird -x mwu -m {{ item.value.max_prefix }} -s /home/admin/clones/icvpn-meta > /etc/bird/icvpn_ipv{{ item.key }}_roa.conf
|
|
args:
|
|
chdir: /home/admin/clones/icvpn-scripts
|
|
creates: /etc/bird/icvpn_ipv{{ item.key }}_roa.conf
|
|
notify:
|
|
- reload bird{{ item.key }}
|
|
with_dict:
|
|
4:
|
|
max_prefix: 20
|
|
6:
|
|
max_prefix: 64
|
|
|
|
- name: write icvpn bird configuration
|
|
template:
|
|
src: icvpn_ipv{{ item }}.conf.j2
|
|
dest: /etc/bird/icvpn_ipv{{ item }}.conf
|
|
mode: 0640
|
|
owner: bird
|
|
group: bird
|
|
notify: reload bird{{ item }}
|
|
with_items:
|
|
- 4
|
|
- 6
|
|
|
|
- name: set file attributes for ipv4 roa and peer config
|
|
file:
|
|
path: "{{ item }}"
|
|
mode: 0640
|
|
owner: admin
|
|
group: bird
|
|
notify:
|
|
- reload bird4
|
|
with_items:
|
|
- /etc/bird/icvpn_ipv4_peers.conf
|
|
- /etc/bird/icvpn_ipv4_roa.conf
|
|
|
|
- name: set file attributes for ipv6 roa and peer config
|
|
file:
|
|
path: "{{ item }}"
|
|
mode: 0640
|
|
owner: admin
|
|
group: bird
|
|
notify:
|
|
- reload bird6
|
|
with_items:
|
|
- /etc/bird/icvpn_ipv6_peers.conf
|
|
- /etc/bird/icvpn_ipv6_roa.conf
|
|
|
|
- name: write systemd unit icvpn-update.service
|
|
template:
|
|
src: icvpn-update.service.j2
|
|
dest: /etc/systemd/system/icvpn-update.service
|
|
owner: root
|
|
group: root
|
|
mode: 0644
|
|
notify: reload systemd
|
|
|
|
- name: write systemd timer icvpn-update.timer
|
|
template:
|
|
src: icvpn-update.timer.j2
|
|
dest: /etc/systemd/system/icvpn-update.timer
|
|
owner: root
|
|
group: root
|
|
mode: 0644
|
|
notify: reload systemd
|
|
|
|
- name: configure systemd unit/timer icvpn-update
|
|
systemd:
|
|
name: icvpn-update.timer
|
|
enabled: yes
|
|
state: started
|