Skip to content
Snippets Groups Projects
Verified Commit 0261160b authored by Rafael László's avatar Rafael László :speech_balloon:
Browse files

Update playbook to use kszk base role

parent 8a01662f
No related branches found
No related tags found
No related merge requests found
...@@ -20,7 +20,7 @@ with `ansible-playbook harbor/base.yaml`. ...@@ -20,7 +20,7 @@ with `ansible-playbook harbor/base.yaml`.
The playbook handles everything and auto start The playbook handles everything and auto start
harbor. harbor.
If you want to change the configuration If you want to change the configuration
refer to the `ansible/harbor/templates/home/user/harbor/harbor.yml` file refer to the `ansible/main/templates/home/user/harbor/harbor.yml` file
## LDAP ## LDAP
......
...@@ -2,7 +2,7 @@ ...@@ -2,7 +2,7 @@
- hosts: harbor - hosts: harbor
become: true become: true
roles: roles:
- role: kszk-k8s.base - role: kszk.base
tags: ["base"] tags: ["base"]
- role: kszk.iptables - role: kszk.iptables
tags: ["iptables"] tags: ["iptables"]
......
...@@ -14,7 +14,7 @@ ...@@ -14,7 +14,7 @@
-A INPUT -i lo -j ACCEPT -A INPUT -i lo -j ACCEPT
-A INPUT -p icmp -j ACCEPT -A INPUT -p icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport {{ ssh.port }} --src 152.66.0.0/8,192.168.0.0/16,10.0.0.0/8 -j ACCEPT -A INPUT -p tcp -m tcp --dport {{ base_ssh.port }} --src 152.66.0.0/8,192.168.0.0/16,10.0.0.0/8 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
# Accept from the Kubernetes cluster # Accept from the Kubernetes cluster
......
...@@ -14,7 +14,7 @@ ...@@ -14,7 +14,7 @@
-A INPUT -i lo -j ACCEPT -A INPUT -i lo -j ACCEPT
-A INPUT -p ipv6-icmp -j ACCEPT -A INPUT -p ipv6-icmp -j ACCEPT
-A INPUT -p tcp -m tcp --dport {{ ssh.port }} --src 2001:738:2001::/48 -j ACCEPT -A INPUT -p tcp -m tcp --dport {{ base_ssh.port }} --src 2001:738:2001::/48 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
# TODO node exporter from Kubernetes ipv6 # TODO node exporter from Kubernetes ipv6
......
# KSZK Base role # KSZK Base role
motd_playbook_url: https://git.sch.bme.hu/kszk/sysadmin/kubernetes/harbor base_motd_playbook_url: https://git.sch.bme.hu/kszk/sysadmin/kubernetes/harbor
base_hostname: harbor
base_motd_text: "Harbor"
hostname: harbor base_users:
motd_text: "Harbor"
user: harbor
users:
- name: rlacko - name: rlacko
sudo: yes sudo: yes
passwordless_sudo: yes passwordless_sudo: yes
ssh_key: https://git.sch.bme.hu/rlacko.keys ssh_key: https://git.sch.bme.hu/rlacko.keys
- name: harbor - name: harbor
sudo: yes sudo: no
passwordless_sudo: yes passwordless_sudo: no
ssh: base_ssh:
port: 10022 port: 10022
permitRootLogin: "no" permitRootLogin: "no"
pubkeyAuthentication: "yes" pubkeyAuthentication: "yes"
...@@ -22,7 +20,7 @@ ssh: ...@@ -22,7 +20,7 @@ ssh:
allow: allow:
users: "rlacko" users: "rlacko"
netplan: base_netplan:
network: network:
version: 2 version: 2
renderer: networkd renderer: networkd
...@@ -42,6 +40,7 @@ iptables_rules_v6_file: etc/iptables/rules.v6.j2 ...@@ -42,6 +40,7 @@ iptables_rules_v6_file: etc/iptables/rules.v6.j2
# Playbook vars # Playbook vars
user: harbor
harbor_hostname: harbor.sch.bme.hu harbor_hostname: harbor.sch.bme.hu
acme_email: laszlo.rafael@kszk.bme.hu acme_email: laszlo.rafael@kszk.bme.hu
sites: sites:
......
...@@ -5,10 +5,10 @@ collections: ...@@ -5,10 +5,10 @@ collections:
- ansible.posix - ansible.posix
roles: roles:
- src: git@git.sch.bme.hu:kszk/sysadmin/kubernetes/base-ansible-role.git - src: git@git.sch.bme.hu:kszk/ansible/roles/base.git
scm: git scm: git
version: master version: master
name: kszk-k8s.base name: kszk.base
- src: git@git.sch.bme.hu:kszk/ansible/roles/iptables.git - src: git@git.sch.bme.hu:kszk/ansible/roles/iptables.git
scm: git scm: git
version: master version: master
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment