more things

This commit is contained in:
Uumas
2021-03-21 20:45:41 +02:00
parent 10d835e82c
commit 1a98add866
9 changed files with 209 additions and 0 deletions

11
docs/vars/optional.yaml Normal file
View File

@@ -0,0 +1,11 @@
---
install_packages:
- vim
- git
- etckeeper
- net-tools
- nmap
- ncdu
- fish
- parted

5
docs/vars/required.yaml Normal file
View File

@@ -0,0 +1,5 @@
---
timezone: 'Europe/Helsinki'
domain: 'example.tld'
email: 'admin@domain.tld'

View File

@@ -0,0 +1,6 @@
---
- name: reload caddy
systemd:
name: caddy
state: reloaded

View File

@@ -0,0 +1,45 @@
---
- name: Install dependencies
apt:
name:
- debian-keyring
- debian-archive-keyring
- apt-transport-https
update_cache: yes
- name: Add caddy repo signing key
apt_key:
id: '65760C51EDEA2017CEA2CA15155B6D79CA56EA34'
url: 'https://dl.cloudsmith.io/public/caddy/stable/gpg.key'
- name: Add caddy repo
apt_repository:
repo: "deb https://dl.cloudsmith.io/public/caddy/stable/deb/debian any-version main"
filename: 'caddy-stable'
mode: '644'
- name: Install caddy
apt:
name: caddy
- name: Remove default settings from caddyfile
blockinfile:
path: /etc/caddy/Caddyfile
marker: "{mark}"
marker_begin: ':80'
marker_end: '# https://caddyserver.com/docs/caddyfile'
state: absent
validate: 'caddy validate --config %s --adapter caddyfile'
backup: yes
- name: Put caddy general config in place
blockinfile:
path: /etc/caddy/Caddyfile
marker: "# {mark} ANSIBLE MANAGED BLOCK general"
block: |
{
email {{ email }}
}
validate: 'caddy validate --config %s --adapter caddyfile'
backup: yes
notify: reload caddy

View File

@@ -26,3 +26,4 @@
- docker-ce
- docker-ce-cli
- containerd.io
- python-docker

View File

@@ -0,0 +1,5 @@
---
dependencies:
- docker
- caddy

View File

@@ -0,0 +1,124 @@
---
- name: Jitsi meet docker network
docker_network:
name: meet.jitsi
- name: Jitsi meet web
docker_container:
name: 'jitsi_meet_web'
image: 'jitsi/web:latest'
pull: yes
container_default_behavior: no_defaults
published_ports:
- "{{ localhost_ip }}:{{ ports.jitsi_http }}:80"
env:
DISABLE_HTTPS: '1'
PUBLIC_URL: "{{ jitsi_external_url }}"
TZ: "{{ timezone }}"
ENABLE_PREJOIN_PAGE: '1'
ENABLE_REQUIRE_DISPLAY_NAME: '1'
ENABLE_NOISY_MIC_DETECTION: '0'
ENABLE_RECORDING: '0'
JICOFO_AUTH_USER: focus
XMPP_BOSH_URL_BASE: 'http://xmpp.meet.jitsi:5280'
XMPP_DOMAIN: meet.jitsi
XMPP_AUTH_DOMAIN: auth.meet.jitsi
XMPP_MUC_DOMAIN: muc.meet.jitsi
restart_policy: always
networks:
- name: meet.jitsi
aliases:
- meet.jitsi
- name: Jitsi meet prosody
docker_container:
name: 'jitsi_meet_prosody'
image: 'jitsi/prosody:latest'
pull: yes
container_default_behavior: no_defaults
env:
PUBLIC_URL: "{{ jitsi_external_url }}"
TZ: "{{ timezone }}"
ENABLE_LOBBY: '1'
JICOFO_COMPONENT_SECRET: "{{ jitsi_pw.jicofo_component }}"
JICOFO_AUTH_USER: focus
JICOFO_AUTH_PASSWORD: "{{ jitsi_pw.jicofo_auth }}"
JVB_AUTH_USER: jvb
JVB_AUTH_PASSWORD: "{{ jitsi_pw.jvb_auth }}"
XMPP_DOMAIN: meet.jitsi
XMPP_AUTH_DOMAIN: auth.meet.jitsi
XMPP_INTERNAL_MUC_DOMAIN: internal-muc.meet.jitsi
XMPP_MUC_DOMAIN: muc.meet.jitsi
restart_policy: always
exposed_ports:
- '5222'
- '5347'
networks:
- name: meet.jitsi
aliases:
- xmpp.meet.jitsi
- name: Jitsi meet jicofo
docker_container:
name: 'jitsi_meet_jicofo'
image: 'jitsi/jicofo:latest'
pull: yes
container_default_behavior: no_defaults
env:
TZ: "{{ timezone }}"
JVB_BREWERY_MUC: jvbbrewery
JICOFO_COMPONENT_SECRET: "{{ jitsi_pw.jicofo_component }}"
JICOFO_AUTH_USER: focus
JICOFO_AUTH_PASSWORD: "{{ jitsi_pw.jicofo_auth }}"
XMPP_DOMAIN: meet.jitsi
XMPP_AUTH_DOMAIN: auth.meet.jitsi
XMPP_MUC_DOMAIN: muc.meet.jitsi
XMPP_INTERNAL_MUC_DOMAIN: internal-muc.meet.jitsi
XMPP_SERVER: xmpp.meet.jitsi
ENABLE_RECORDING: '0'
restart_policy: always
networks:
- name: meet.jitsi
aliases:
- meet.jitsi
- name: Jitsi meet video bridge
docker_container:
name: 'jitsi_meet_jvb'
image: 'jitsi/jvb:latest'
pull: yes
container_default_behavior: no_defaults
published_ports:
- "{{ ports.jitsi_jvb | default(10000) }}:10000/udp"
- "{{ ports.jitsi_jvb_tcp | default(4443) }}:4443"
env:
PUBLIC_URL: "{{ jitsi_external_url }}"
TZ: "{{ timezone }}"
JVB_PORT: '10000'
JVB_TCP_PORT: '4443'
JVB_TCP_HARVESTER_DISABLED: 'false'
JVB_BREWERY_MUC: jvbbrewery
JVB_STUN_SERVERS: 'meet-jit-si-turnrelay.jitsi.net:443'
JVB_AUTH_USER: jvb
JVB_AUTH_PASSWORD: "{{ jitsi_pw.jvb_auth }}"
XMPP_AUTH_DOMAIN: auth.meet.jitsi
XMPP_INTERNAL_MUC_DOMAIN: internal-muc.meet.jitsi
XMPP_SERVER: xmpp.meet.jitsi
restart_policy: always
networks:
- name: meet.jitsi
aliases:
- meet.jitsi
- name: Add caddy reverse proxy config
blockinfile:
path: /etc/caddy/Caddyfile
marker: "# {mark} ANSIBLE MANAGED BLOCK jitsi"
block: |
{{ jitsi_external_url }} {
reverse_proxy http://{{ localhost_ip }}:{{ ports.jitsi_http }}
}
validate: 'caddy validate --config %s --adapter caddyfile'
backup: yes
notify: reload caddy

View File

@@ -0,0 +1,11 @@
---
install_packages:
- vim
- git
- etckeeper
- net-tools
- nmap
- ncdu
- fish
- parted

View File

@@ -3,3 +3,4 @@
- name: Install packages
apt:
name: "{{ install_packages }}"
update_cache: yes