mirror of
https://forgejo.ellis.link/continuwuation/continuwuity.git
synced 2026-05-26 20:49:55 +00:00
Improve config to prepare for mail server
This commit is contained in:
@@ -1,3 +1,5 @@
|
|||||||
[privilege_escalation]
|
[privilege_escalation]
|
||||||
become=True
|
become=True
|
||||||
become_user=root
|
become_user=root
|
||||||
|
[ssh_connection]
|
||||||
|
pipelining=True
|
||||||
@@ -8,17 +8,17 @@
|
|||||||
ansible.builtin.debug:
|
ansible.builtin.debug:
|
||||||
msg: Hello world
|
msg: Hello world
|
||||||
# - name: Copy conduwuit backup
|
# - name: Copy conduwuit backup
|
||||||
# ansible.builtin.copy:
|
# ansible.posix.synchronize:
|
||||||
# src: ./conduwuit-testing
|
# src: ./conduwuit-testing
|
||||||
# dest: /var/opt/
|
# dest: /var/opt/
|
||||||
- name: Copy containers
|
- name: Copy containers
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../containers/
|
src: ../containers/
|
||||||
dest: /etc/containers/systemd
|
dest: /etc/containers/systemd
|
||||||
- name: Reload systemd generators
|
- name: Reload systemd generators
|
||||||
ansible.builtin.command: sudo systemctl daemon-reload
|
ansible.builtin.command: sudo systemctl daemon-reload
|
||||||
- name: Copy traefik config
|
- name: Copy traefik config
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../traefik/
|
src: ../traefik/
|
||||||
dest: /etc/traefik
|
dest: /etc/traefik
|
||||||
- name: Creates traefik state directory
|
- name: Creates traefik state directory
|
||||||
@@ -26,7 +26,7 @@
|
|||||||
path: /var/srv/traefik
|
path: /var/srv/traefik
|
||||||
state: directory
|
state: directory
|
||||||
- name: Copy kanidm config
|
- name: Copy kanidm config
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../kanidm/
|
src: ../kanidm/
|
||||||
dest: /etc/kanidm
|
dest: /etc/kanidm
|
||||||
- name: Creates kanidm data directory
|
- name: Creates kanidm data directory
|
||||||
@@ -34,15 +34,15 @@
|
|||||||
path: /var/opt/kanidm_data
|
path: /var/opt/kanidm_data
|
||||||
state: directory
|
state: directory
|
||||||
- name: Copy Element Web config
|
- name: Copy Element Web config
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../element-web/
|
src: ../element-web/
|
||||||
dest: /etc/element-web
|
dest: /etc/element-web
|
||||||
- name: Copy homepage config
|
- name: Copy homepage config
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../homepage/
|
src: ../homepage/
|
||||||
dest: /etc/homepage
|
dest: /etc/homepage
|
||||||
- name: Copy sentry relay config
|
- name: Copy sentry relay config
|
||||||
ansible.builtin.copy:
|
ansible.posix.synchronize:
|
||||||
src: ../sentry-relay/
|
src: ../sentry-relay/
|
||||||
dest: /etc/sentry-relay
|
dest: /etc/sentry-relay
|
||||||
# - name: install linux-system-roles
|
# - name: install linux-system-roles
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
[Unit]
|
[Unit]
|
||||||
Description=Conduwuit testing (matrix)
|
Description=Conduwuit testing (matrix)
|
||||||
Wants=network-online.target
|
Wants=network-online.target
|
||||||
|
Wants=traefik.service
|
||||||
After=network-online.target
|
After=network-online.target
|
||||||
Documentation=https://conduwuit.puppyirl.gay/
|
Documentation=https://conduwuit.puppyirl.gay/
|
||||||
|
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
[Unit]
|
[Unit]
|
||||||
Description=Conduwuit (matrix)
|
Description=Conduwuit (matrix)
|
||||||
Wants=network-online.target
|
Wants=network-online.target
|
||||||
|
Wants=traefik.service
|
||||||
After=network-online.target
|
After=network-online.target
|
||||||
Documentation=https://conduwuit.puppyirl.gay/
|
Documentation=https://conduwuit.puppyirl.gay/
|
||||||
|
|
||||||
|
|||||||
@@ -4,6 +4,7 @@
|
|||||||
Description=Maubot
|
Description=Maubot
|
||||||
Wants=network-online.target
|
Wants=network-online.target
|
||||||
After=network-online.target
|
After=network-online.target
|
||||||
|
After=conduwuit.service
|
||||||
Documentation=https://docs.mau.fi/maubot/index.html
|
Documentation=https://docs.mau.fi/maubot/index.html
|
||||||
|
|
||||||
[Container]
|
[Container]
|
||||||
|
|||||||
@@ -0,0 +1,19 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=traefik cert dumper
|
||||||
|
After=traefik.service
|
||||||
|
|
||||||
|
|
||||||
|
[Container]
|
||||||
|
ContainerName=traefik-cert-dumper
|
||||||
|
NoNewPrivileges=true
|
||||||
|
Image=ghcr.io/kereis/traefik-certs-dumper:latest
|
||||||
|
Volume=/etc/localtime:/etc/localtime:ro
|
||||||
|
Volume=/var/srv/traefik:/traefik:ro
|
||||||
|
Volume=traefik-certs.volume:/output
|
||||||
|
# AutoUpdate=registry
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Restart=unless-stopped
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=default.target
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
[Volume]
|
||||||
@@ -12,6 +12,12 @@ ContainerName=traefik
|
|||||||
PodmanArgs=--privileged
|
PodmanArgs=--privileged
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
Image=docker.io/library/traefik:3.0
|
Image=docker.io/library/traefik:3.0
|
||||||
|
|
||||||
|
# Static IPs assigned for proxy-protocol trust
|
||||||
|
IP=10.89.0.21
|
||||||
|
IP6=fd76:6f6d:f45e:ea1a::15
|
||||||
|
|
||||||
|
# HTTP(S)
|
||||||
PublishPort=0.0.0.0:80:80/tcp
|
PublishPort=0.0.0.0:80:80/tcp
|
||||||
PublishPort=0.0.0.0:443:443/tcp
|
PublishPort=0.0.0.0:443:443/tcp
|
||||||
PublishPort=0.0.0.0:443:443/udp
|
PublishPort=0.0.0.0:443:443/udp
|
||||||
@@ -26,9 +32,27 @@ PublishPort=0.0.0.0:8448:8448/udp
|
|||||||
PublishPort=[::]:8448:8448/tcp
|
PublishPort=[::]:8448:8448/tcp
|
||||||
PublishPort=[::]:8448:8448/udp
|
PublishPort=[::]:8448:8448/udp
|
||||||
|
|
||||||
# PublishPort=8448:8448/tcp
|
# SMTP
|
||||||
|
PublishPort=0.0.0.0:25:25/tcp
|
||||||
|
PublishPort=0.0.0.0:25:25/udp
|
||||||
|
PublishPort=[::]:25:25/tcp
|
||||||
|
PublishPort=[::]:25:25/udp
|
||||||
|
|
||||||
|
# SMTPS
|
||||||
|
PublishPort=0.0.0.0:465:465/tcp
|
||||||
|
PublishPort=0.0.0.0:465:465/udp
|
||||||
|
PublishPort=[::]:465:465/tcp
|
||||||
|
PublishPort=[::]:465:465/udp
|
||||||
|
|
||||||
|
# IMAPS
|
||||||
|
PublishPort=0.0.0.0:465:465/tcp
|
||||||
|
PublishPort=0.0.0.0:465:465/udp
|
||||||
|
PublishPort=[::]:465:465/tcp
|
||||||
|
PublishPort=[::]:465:465/udp
|
||||||
|
|
||||||
ReadOnly=true
|
ReadOnly=true
|
||||||
Volume=/run/podman/podman.sock:/var/run/docker.sock:z
|
Volume=/run/podman/podman.sock:/var/run/docker.sock:z
|
||||||
|
Volume=/etc/localtime:/etc/localtime:ro
|
||||||
Volume=/var/srv/traefik:/certificates:z
|
Volume=/var/srv/traefik:/certificates:z
|
||||||
Volume=/etc/traefik:/etc/traefik:ro,z
|
Volume=/etc/traefik:/etc/traefik:ro,z
|
||||||
Volume=kanidm-certs.volume:/kanidm_certs:ro,z
|
Volume=kanidm-certs.volume:/kanidm_certs:ro,z
|
||||||
|
|||||||
Reference in New Issue
Block a user