josiah
7b7284c32f
all of this is required for the synology LE role to work. this is still a massive WIP commit. synology LE works, but synology webdav using that LE cert does not yet work. there appears to be some cipher mismatch issue by default.
30 lines
969 B
Org Mode
30 lines
969 B
Org Mode
* setup from scratch:
|
|
** install dependencies
|
|
ansible-galaxy collection install -r requirements.yml
|
|
|
|
** run a play
|
|
~ansible-playbook -i hosts.yml all.yml --ask-vault-pass --ask-become-pass~
|
|
|
|
** preparing open_the_vault
|
|
|
|
* wg
|
|
|
|
** clients
|
|
you probably want to deploy clients individually most of the time. to do that, provide a tag, like:
|
|
~ansible-playbook -i hosts.yml client_matrix.yml --ask-vault-pass --ask-become-pass --tags matrix_client~
|
|
|
|
** adding a client
|
|
- generate a new public/private keypair
|
|
- ~umask 077~
|
|
- ~wg genkey | tee privatekey | wg pubkey > publickey~
|
|
- add the pubkey to the groupvars/main.yml
|
|
- add the privkey to the groupvars/vault.yml
|
|
- add a task referencing the new client
|
|
- add a template with the groupvars embedded.
|
|
|
|
* instructions on specific roles
|
|
** awfulAll
|
|
awfulAll is a single server that's a catch all for services that don't need a dedicated vm.
|
|
~ansible-playbook -i hosts.yml awfulAll.yml --tags awfulAll
|
|
~
|