mirror of
https://forgejo.ellis.link/continuwuation/continuwuity.git
synced 2026-05-26 20:49:55 +00:00
126 lines
3.9 KiB
YAML
126 lines
3.9 KiB
YAML
---
|
|
# Copyright Red Hat, Inc. All Rights Reserved.
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License"); you may
|
|
# not use this file except in compliance with the License. You may obtain
|
|
# a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
|
|
# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
|
|
# License for the specific language governing permissions and limitations
|
|
# under the License.
|
|
#
|
|
# Author: David Moreau Simard <dms@redhat.com>
|
|
|
|
# ansible_port can change throughout this role, keep a copy around
|
|
- name: Set configured port fact
|
|
set_fact:
|
|
configured_port: "{{ ansible_port }}"
|
|
|
|
# From localhost, check if we're able to reach {{ inventory_hostname }} on
|
|
# port 22
|
|
- name: Check if we're using the default SSH port
|
|
wait_for:
|
|
port: "22"
|
|
state: "started"
|
|
host: "{{ inventory_hostname }}"
|
|
connect_timeout: "5"
|
|
timeout: "5"
|
|
delegate_to: "localhost"
|
|
ignore_errors: true
|
|
register: default_ssh
|
|
|
|
# If reachable, continue the following tasks with this port
|
|
- name: Set inventory ansible_port to default
|
|
set_fact:
|
|
ansible_port: "22"
|
|
when: default_ssh is defined and
|
|
default_ssh.state is defined and
|
|
default_ssh.state == "started"
|
|
register: ssh_port_set
|
|
|
|
# If unreachable on port 22, check if we're able to reach
|
|
# {{ inventory_hostname }} on {{ ansible_port }} provided by the inventory
|
|
# from localhost
|
|
- name: Check if we're using the inventory-provided SSH port
|
|
wait_for:
|
|
port: "{{ ansible_port }}"
|
|
state: "started"
|
|
host: "{{ inventory_hostname }}"
|
|
connect_timeout: "5"
|
|
timeout: "10"
|
|
delegate_to: "localhost"
|
|
ignore_errors: true
|
|
register: configured_ssh
|
|
when: default_ssh is defined and
|
|
default_ssh.state is undefined
|
|
|
|
# If {{ ansible_port }} is reachable, we don't need to do anything special
|
|
- name: SSH port is configured properly
|
|
debug:
|
|
msg: "SSH port is configured properly"
|
|
when: configured_ssh is defined and
|
|
configured_ssh.state is defined and
|
|
configured_ssh.state == "started"
|
|
register: ssh_port_set
|
|
|
|
# If the SSH port is neither the default or the configured, give up.
|
|
- name: Fail if SSH port was not auto-detected (unknown)
|
|
fail:
|
|
msg: "The SSH port is neither 22 or {{ ansible_port }}."
|
|
when: ssh_port_set is undefined
|
|
|
|
# Sanity check, make sure Ansible is able to connect to the host
|
|
- name: Confirm host connection works
|
|
ping:
|
|
|
|
- name: Setup alternate SSH port
|
|
become: true
|
|
lineinfile:
|
|
dest: "/etc/ssh/sshd_config"
|
|
regexp: "^#?Port"
|
|
line: "Port {{ configured_port }}"
|
|
notify: "Restart sshd"
|
|
- name: Creates sshd socket override directory
|
|
become: true
|
|
file:
|
|
path: /etc/systemd/system/sshd.socket.d
|
|
state: directory
|
|
- name: Setup alternate SSH port (systemd)
|
|
become: true
|
|
copy:
|
|
dest: "/etc/systemd/system/sshd.socket.d/override.conf"
|
|
content: |
|
|
[Socket]
|
|
ListenStream=
|
|
ListenStream={{ configured_port }}
|
|
notify: "Restart sshd"
|
|
|
|
- name: Setup selinux for alternate SSH port
|
|
ignore_errors: true
|
|
seport:
|
|
ports: "{{ configured_port }}"
|
|
proto: "tcp"
|
|
setype: "ssh_port_t"
|
|
state: "present"
|
|
|
|
|
|
# We notified "Restart sshd" if we modified the sshd config.
|
|
# By calling flush_handlers, we make sure the handler is run *right now*
|
|
- name: Ensure SSH is reloaded if need be
|
|
meta: flush_handlers
|
|
|
|
# We're done, make sure ansible_port is set properly so that any tasks
|
|
# after this use the right ansible_port.
|
|
- name: Ensure we use the configured SSH port for the remainder of the role
|
|
set_fact:
|
|
ansible_port: "{{ configured_port }}"
|
|
|
|
# Gather facts should be set to false when running this role since it will
|
|
# fail if the Ansible SSH port is not set correctly.
|
|
# We run setup to gather facts here once the SSH port is set up.
|
|
- name: Run deferred setup to gather facts
|
|
setup: |