From d0d2b4135a4dd1d99a18c4d8e0cec1fab43831dc Mon Sep 17 00:00:00 2001
From: anima
Date: Sun, 16 Nov 2025 19:50:52 +0100
Subject: [PATCH] rewrite with higher security
---
README.md | 13 +++-
client_wg1.conf.j2 | 9 +++
installer.yml | 159 +++++++++++++++++++++++++++++++++++++++++++++
tasks_debian.yml | 50 ++++++++++++++
vars_archlinux.yml | 5 ++
vars_debian.yml | 5 ++
vars_secrets.yml | 64 ++++++++++++++++++
7 files changed, 304 insertions(+), 1 deletion(-)
create mode 100644 client_wg1.conf.j2
create mode 100755 installer.yml
create mode 100644 tasks_debian.yml
create mode 100644 vars_archlinux.yml
create mode 100644 vars_debian.yml
create mode 100644 vars_secrets.yml
diff --git a/README.md b/README.md
index eb6790c..d875307 100644
--- a/README.md
+++ b/README.md
@@ -1,2 +1,13 @@
-# clientmgmt
+# Ansible as installer
+## Requirements
+Ansible must be installed ;-)
+
+### Debian // Ubuntu
+> apt install -y ansible
+
+## RHEL // CentOS // Rocky
+> yum install -y ansible
+
+## Arch
+> pacman -S ansible
\ No newline at end of file
diff --git a/client_wg1.conf.j2 b/client_wg1.conf.j2
new file mode 100644
index 0000000..0cfddab
--- /dev/null
+++ b/client_wg1.conf.j2
@@ -0,0 +1,9 @@
+[Interface]
+PrivateKey = {{ wireguard.client_key}}
+Address = {{ wireguard.client_ip }}
+
+[Peer]
+PublicKey = {{ wireguard.server_pubkey }}
+Endpoint = {{ wireguard.server_address }}:{{ wireguard.server_port }}
+AllowedIPs = {{ wireguard.vpnnet }}
+PersistentKeepalive = 25
\ No newline at end of file
diff --git a/installer.yml b/installer.yml
new file mode 100755
index 0000000..5f414cc
--- /dev/null
+++ b/installer.yml
@@ -0,0 +1,159 @@
+#!/usr/bin/ansible-playbook --inventory=localhost,
+---
+- hosts: localhost
+ connection: local
+ force_handlers: true
+ vars:
+ ansible_python_interpreter: auto_silent
+ vars_files:
+ - secret_vars.yml
+# check if user == root
+ pre_tasks:
+ - set_fact:
+ eff_uid_number: "{{ lookup('pipe', 'id -u') }}"
+
+ - block:
+ - debug:
+ msg: "Run as root!"
+ - meta: end_play
+ when: eff_uid_number|int != 0
+
+# run playbook
+ tasks:
+ - name: include distibution vars
+ ansible.builtin.include_vars:
+ file: "vars_{{ ansible_distribution | lower }}.yaml"
+
+ # prepare ansible user
+ - name: create ansible user
+ user:
+ name: "{{ admin_user_ansible }}"
+ uid: 2001
+ groups: "{{ sudo_group }}"
+ shell: /bin/bash
+ home: /srv/ansible
+ comment: Ansible Service User
+
+ - name: set ansible user sudo passless
+ copy:
+ dest: "/etc/sudoers.d/adm-ansible"
+ content: "adm-ansible ALL=(ALL) NOPASSWD: ALL"
+ mode: 0600
+ owner: root
+
+ - name: add ansible auth key
+ no_log: true
+ ansible.posix.authorized_key:
+ user: adm-ansible
+ key: "{{ ssh_key_ansible }}"
+
+ - name: enable ssh
+ systemd:
+ name: sshd
+ state: started
+ enabled: yes
+
+ - name: set ssh port
+ lineinfile:
+ dest: /etc/ssh/sshd_config
+ regex: "^[#]?Port"
+ line: "Port {{ ssh_port }}"
+ notify: restart sshd
+
+ - name: disable ansible password login
+ blockinfile:
+ dest: /etc/ssh/sshd_config
+ block: |
+ Match User {{ admin_user_ansible }}
+ PasswordAuthentication no
+ notify: restart sshd
+
+
+ # installs
+ - name: install default packages with package manager
+ ansible.builtin.package:
+ name:
+ - "{{ item }}"
+ state: present
+ loop: "{{ package_installs }}"
+ when: package_installs is defined
+
+ # debian tasks
+ - name: import distribution tasks
+ ignore_errors: yes
+ ansible.builtin.include_tasks:
+ file: "tasks_{{ ansible_distribution }}.yml"
+
+ - name: ensure dirs exist
+ ansible.builtin.file:
+ path: "{{ item.value }}"
+ state: directory
+ mode: '0777'
+ loop: "{{ directorys | dict2items}}"
+ when: directorys is defined
+
+ - name: get appimage programms
+ ansible.builtin.get_url:
+ url: "{{ item.url }}"
+ dest: "{{ directorys.appimage_dir }}/{{ item.name }}.appimage"
+ mode: '0775'
+ loop: "{{ appimages }}"
+ when: appimages is defined
+
+ - name: get executable programms
+ ansible.builtin.get_url:
+ url: "{{ item.url }}"
+ dest: "/usr/bin/{{ item.name }}"
+ mode: '0775'
+ loop: "{{ executables }}"
+ when: executables is defined
+
+ # wireguard setup
+ - name: check file wg0
+ no_log: true
+ stat:
+ path: /etc/wireguard/wg0.conf
+ register: interface_wg0
+
+ - name: create client wireguard config
+ no_log: true
+ template:
+ dest: /etc/wireguard/wg1.conf
+ src: client_wg1.conf.j2
+ owner: root
+ group: root
+ mode: '0600'
+ when: not interface_wg0.stat.exists
+ notify: restart wg-quick@wg1
+
+ - name: start wireguard and enable on boot
+ no_log: true
+ systemd:
+ name: wg-quick@wg1
+ enabled: yes
+ state: started
+ when: not interface_wg0.stat.exists
+ notify: discord push
+
+ handlers:
+ - name: restart sshd
+ systemd:
+ name: sshd
+ state: restarted
+
+ - name: restart wg-quick@wg1
+ systemd:
+ name: sshd
+ state: restarted
+
+ - name: discord push
+ no_log: true
+ uri:
+ url: "{{ discord_url }}"
+ method: 'POST'
+ body_format: json
+ body: {
+ 'content': "i am online",
+ 'username': "{{ ansible_hostname }}"
+ }
+ status_code: 204
\ No newline at end of file
diff --git a/tasks_debian.yml b/tasks_debian.yml
new file mode 100644
index 0000000..afbaac0
--- /dev/null
+++ b/tasks_debian.yml
@@ -0,0 +1,50 @@
+- block:
+ - name: add gpg keys
+ ansible.builtin.apt_key:
+ url: "{{ item.gpg }}"
+ state: present
+ loop: "{{ nondefault_package_installs }}"
+ when: nondefault_package_installs is defined
+
+ - name: update apt source.list.d
+ ansible.builtin.apt_repository:
+ repo: "{{ item.source }}"
+ state: present
+ filename: programms
+ update_cache: yes
+ loop: "{{ nondefault_package_installs }}"
+ when: nondefault_package_installs is defined
+
+ - name: install non-default packages with package manager
+ ansible.builtin.package:
+ name:
+ - "{{ item.name }}"
+ state: present
+ loop: "{{ nondefault_package_installs }}"
+ when: nondefault_package_installs is defined
+
+ - name: download deb files
+ ansible.builtin.get_url:
+ url: "{{ item.url }}"
+ dest: "/tmp/{{ item.name }}.deb"
+ mode: "0440"
+ loop: "{{ deb_installs }}"
+ when: deb_installs is defined
+
+ - name: install deb files
+ ansible.builtin.apt:
+ deb: "/tmp/{{ item.name }}.deb"
+ loop: "{{ deb_installs }}"
+ when: deb_installs is defined
+
+ - name: update all packages
+ apt:
+ name: '*'
+ state: latest
+ update_cache: yes
+
+ - name: clean apt cache
+ apt:
+ autoclean: yes
+
+ when: ansible_os_family == "Debian"
\ No newline at end of file
diff --git a/vars_archlinux.yml b/vars_archlinux.yml
new file mode 100644
index 0000000..dd86289
--- /dev/null
+++ b/vars_archlinux.yml
@@ -0,0 +1,5 @@
+sudo_group: wheel
+package_installs:
+ - curl
+ - vim
+ - wireguard-tools
\ No newline at end of file
diff --git a/vars_debian.yml b/vars_debian.yml
new file mode 100644
index 0000000..b30b00c
--- /dev/null
+++ b/vars_debian.yml
@@ -0,0 +1,5 @@
+sudo_group: sudo
+package_installs:
+ - vim
+ - curl
+ - wireguard
\ No newline at end of file
diff --git a/vars_secrets.yml b/vars_secrets.yml
new file mode 100644
index 0000000..9410529
--- /dev/null
+++ b/vars_secrets.yml
@@ -0,0 +1,64 @@
+$ANSIBLE_VAULT;1.1;AES256
+31646238623838666665656266656634383962303336616663323664626338393139616439303661
+3061313932663361346561306632653735623338633034650a343263663937313366303065333861
+63306537326131346431343635373630396662613131346666633065653735626661626537666433
+3837313461333430340a323665336330366237323264393733663762316361363437386134626336
+63373839386338313739373630343065356163613732303536346133633666316438623866363539
+31313131636434633063383532373064303536653734663530633065336562666339383233616661
+36376336653738626266643033346666633834396436336232623561313763636535336161663639
+62623966333365623066646136623130333339383633396461323661663536303937663936333830
+38336265353765376266383939356664303137636639386266336639623965653765373966306666
+34643634663964363765366133353062326431333764653761343531306537653564386335656335
+62363733303266396161623363376566306366653166356630656262623132393337373832313130
+63663163346662613862613435633132383830306430613265373234626430646336666137303534
+39623834666535366166346432376337303135386134353131326566343562353066323436323263
+34343934333636653436323930333533653139303061633063383335356531336166663063626237
+64633965373239386366303234353663633664666439306130656666343935386231663035323135
+35663261343065363738313931323163313434373032626132643936656164343931313538323364
+31626131643235653235623838613663333636623937356434343162386136343731646665623532
+63626130303065313031613761323039663061333466666366656136316337626464666665636662
+34393833613165623663343133313834313433623530333561303064656262613231306430396431
+31666538616332363130666361306339373065323936333565643634303436343232333834653261
+36656639363532343530646237393236356665643739303263326634616236363030656533383138
+31636165396132346366663965326335343634356461626661366631306161316135613232663562
+62616433623564643130656532656365646661313762633136633838386135616565663266313562
+36323238343637353164646562313634376631306535323730313335633533313536393962386664
+65343235373838313338613135333265653236643438643530323963353261356661666566396230
+34376630616631383930333263643036666237313036633739356431373762623430623831396634
+62373632646638343033393534633231303332303764616633633433393034323836383634653136
+32666432383933393432393535653330393137613437333136326466353837666633383934656133
+33373734346664336231316232636230613639616361343761333935613030396239313862303538
+36356165663666623764633330313439393565396634346237656361643039356565313331623461
+33656533313436336530643030376136633933316634363131363637626566633839633264313138
+30383262616166363061376237373765363931393737663733643066613464346535383862376531
+65306230393431333265623030353861653363353661366265663163643033333231643165353666
+35646466343032626261323131376464386266373264623330333864323561326234366639623431
+39656664373135313939313066633964323532623266316333363961323634336237316135626164
+33313063303166303830623338353366626338653637343431613039333562306164393939643031
+35633434643263313039363935356665643730613936653738613932356533336336663439383739
+64346562323962666239626364666635666363313232613738333638646666643437343264306232
+31666638303735383433303032626133383332386263636362366330356538303466643832306635
+34313239383466326135666366356461346464323334373763313362363238383935633062366636
+61386331306239346264346338326132336464393965633932643436376339613238303666626339
+32353237633761343734376465396535346263303630386461633736303364336238373536333764
+65663632393036353731323163616338343838303366303362623531363636383236386535616462
+30386330333530633536396537623062653865353830653431376433323934393638363338376536
+62356538633236373635303631353435366136323139386238653039636566346364626166316366
+62396635383166336235333963616563343366656434313230373330376533353866366236646131
+64386363373232613266626435393362333134633738653132656461306339333066623962343537
+31373764346263313466353037316264646662663437356562326535616365383366616662333739
+35626163336332353730373839373066633738633861343335623964353638316364346365393166
+37386566333764373637336361666666333131303034383561663337313461306137316364313666
+39336238373631366636326434333236303766373437383638656637616362393830366438643133
+63613434343033313534383832616465613063633761613965633136333961383333356363343538
+33303430643732613231643730393930333132656662333931366666376138666365313631643261
+32666634323962316562646630313733353466393366623631333962386163356439346563343833
+37613133313163653136316237636434633035633239316332643433343533343534313739633537
+39353462636264383336323830336334613237306537626632613366653161383864613337623933
+61333132343666616438613635643663383138373364303536653736323962633461633332333162
+35663563666664626332303331353138336131313764396436623734346563646363386633373263
+33366566306364623962326534653739316233326163366237643264666365616466393631336638
+36313539623236643364643037383638626239313132646430393161306336393531343536336538
+32623336333766323534663639663334376338343666636537353264666539666638343961353832
+33333666353635396463353739313065323964623437343435623761643131343733366130613337
+396237303039396537306435643530376664