#!/usr/bin/ansible-playbook --inventory=localhost, --- - hosts: localhost connection: local force_handlers: true vars: ansible_python_interpreter: auto_silent vars_files: - secret_vars.yml # check if user == root pre_tasks: - set_fact: eff_uid_number: "{{ lookup('pipe', 'id -u') }}" - block: - debug: msg: "Run as root!" - meta: end_play when: eff_uid_number|int != 0 # run playbook tasks: - name: include distibution vars ansible.builtin.include_vars: file: "vars_{{ ansible_distribution | lower }}.yaml" # prepare ansible user - name: create ansible user user: name: "{{ admin_user_ansible }}" uid: 2001 groups: "{{ sudo_group }}" shell: /bin/bash home: /srv/ansible comment: Ansible Service User - name: set ansible user sudo passless copy: dest: "/etc/sudoers.d/adm-ansible" content: "adm-ansible ALL=(ALL) NOPASSWD: ALL" mode: 0600 owner: root - name: add ansible auth key no_log: true ansible.posix.authorized_key: user: adm-ansible key: "{{ ssh_key_ansible }}" - name: enable ssh systemd: name: sshd state: started enabled: yes - name: set ssh port lineinfile: dest: /etc/ssh/sshd_config regex: "^[#]?Port" line: "Port {{ ssh_port }}" notify: restart sshd - name: disable ansible password login blockinfile: dest: /etc/ssh/sshd_config block: | Match User {{ admin_user_ansible }} PasswordAuthentication no notify: restart sshd # installs - name: install default packages with package manager ansible.builtin.package: name: - "{{ item }}" state: present loop: "{{ package_installs }}" when: package_installs is defined # debian tasks - name: import distribution tasks ignore_errors: yes ansible.builtin.include_tasks: file: "tasks_{{ ansible_distribution }}.yml" - name: ensure dirs exist ansible.builtin.file: path: "{{ item.value }}" state: directory mode: '0777' loop: "{{ directorys | dict2items}}" when: directorys is defined - name: get appimage programms ansible.builtin.get_url: url: "{{ item.url }}" dest: "{{ directorys.appimage_dir }}/{{ item.name }}.appimage" mode: '0775' loop: "{{ appimages }}" when: appimages is defined - name: get executable programms ansible.builtin.get_url: url: "{{ item.url }}" dest: "/usr/bin/{{ item.name }}" mode: '0775' loop: "{{ executables }}" when: executables is defined # wireguard setup - name: check file wg0 no_log: true stat: path: /etc/wireguard/wg0.conf register: interface_wg0 - name: create client wireguard config no_log: true template: dest: /etc/wireguard/wg1.conf src: client_wg1.conf.j2 owner: root group: root mode: '0600' when: not interface_wg0.stat.exists notify: restart wg-quick@wg1 - name: start wireguard and enable on boot no_log: true systemd: name: wg-quick@wg1 enabled: yes state: started when: not interface_wg0.stat.exists notify: discord push handlers: - name: restart sshd systemd: name: sshd state: restarted - name: restart wg-quick@wg1 systemd: name: sshd state: restarted - name: discord push no_log: true uri: url: "{{ discord_url }}" method: 'POST' body_format: json body: { 'content': "i am online", 'username': "{{ ansible_hostname }}" } status_code: 204