fix: NetBird je samostatna aplikace (apt balicek), ne Docker sluzba

roles/netbird/tasks/main.yml:
- apt balicek 'netbird' (oficialni NetBird Linux klient)
- neni Docker, neni sluzba - je to VPN klient

roles/netbird/defaults/main.yml:
- odebrano netbird_run_as_system_service (nepotreba)
- pridana poznamka o instalaci

playbook priprav-novy-server.yml:
- hlavicka: 'NetBird (mesh VPN klient - apt balicek, NE Docker)'

group_vars/all.yml.example:
- pridana dokumentace https://docs.netbird.io/get-started/install
- komentare rikaji, ze to neni Docker sluzba

README.md:
- tabulka roli: 'apt balicek, ne Docker'
- krok 8: 'NetBird (mesh VPN klient - apt balicek)'

Postup instalace:
- Linux server: ansible role -> apt install netbird
- macOS workstation: brew install --cask netbird (v Brewfile)
- Windows: instalator z netbird.io
- Registrace: netbird up --setup-key <key> (z app.netbird.io)
This commit is contained in:
2026-08-01 20:51:01 +02:00
parent dfc1ca514d
commit f91234c8fb
5 changed files with 42 additions and 22 deletions
+2 -2
View File
@@ -44,7 +44,7 @@ a Ansible to udělá **na všech serverech** najednou.
| `ssh-klice` | Nasadí SSH klíč pro `deploy` (heslo = klíč, ne heslo) | | `ssh-klice` | Nasadí SSH klíč pro `deploy` (heslo = klíč, ne heslo) |
| `docker` | Docker Engine + Compose plugin + nastavení daemon.json | | `docker` | Docker Engine + Compose plugin + nastavení daemon.json |
| `adresare` | `/home/deploy/{docker,scripts,backups,logs,~/.local/bin}` + 14 složek pro služby | | `adresare` | `/home/deploy/{docker,scripts,backups,logs,~/.local/bin}` + 14 složek pro služby |
| `netbird` | Nainstaluje NetBird (mesh VPN klient) a registruje přes setup key | | `netbird` | Nainstaluje NetBird klienta (mesh VPN) apt balíček, ne Docker |
### ⚙️ Konfigurace ### ⚙️ Konfigurace
@@ -134,7 +134,7 @@ ansible-playbook -i inventory.yml playbooks/priprav-novy-server.yml
7. ✅ Nainstaluje Docker Engine + Compose plugin 7. ✅ Nainstaluje Docker Engine + Compose plugin
8. ✅ Přidá `deploy` do `docker` group (docker **bez sudo**) 8. ✅ Přidá `deploy` do `docker` group (docker **bez sudo**)
7. ✅ Vytvoří adresářovou strukturu pro 14 Docker služeb 7. ✅ Vytvoří adresářovou strukturu pro 14 Docker služeb
8. ✅ Nainstaluje NetBird (mesh VPN) a registruje přes setup key 8. ✅ Nainstaluje NetBird (mesh VPN klient apt balíček)
9. ✅ Nainstaluje fail2ban (ochrana proti brute-force SSH) 9. ✅ Nainstaluje fail2ban (ochrana proti brute-force SSH)
**Trvání:** 5-10 minut. **Trvání:** 5-10 minut.
+9 -3
View File
@@ -19,13 +19,19 @@ deploy_ssh_public_keys:
- "ssh-ed25519 AAAAC3Nz... hermes@mac" # <-- nahrad svym klicem - "ssh-ed25519 AAAAC3Nz... hermes@mac" # <-- nahrad svym klicem
# ============================================ # ============================================
# NETBIRD (mesh VPN - klient) # NETBIRD (mesh VPN - samostatna aplikace)
# ============================================ # ============================================
# NetBird je WireGuard-based mesh VPN klient.
# Ne Docker sluzba - instaluje se jako apt balicek (Linux) nebo brew cask (mac).
# Dokumentace: https://docs.netbird.io/get-started/install
#
# Setup key z NetBird dashboardu: https://app.netbird.io/ -> Setup Keys # Setup key z NetBird dashboardu: https://app.netbird.io/ -> Setup Keys
# Napr: AAAA-BBBB-CCCC-DDDD-EEEE # Napr: AAAA-BBBB-CCCC-DDDD-EEEE
# Prazdne = NetBird se nainstaluje ale nezaregistruje (setup rucne) #
# Pokud je prazdne, NetBird se pouze nainstaluje - registraci provedes rucne:
# sudo netbird up --setup-key <tvuj-key>
#
netbird_setup_key: "" netbird_setup_key: ""
netbird_run_as_system_service: true
netbird_management_url: "https://api.netbird.io" netbird_management_url: "https://api.netbird.io"
# ============================================ # ============================================
+2 -2
View File
@@ -9,7 +9,7 @@
# 5. Docker Engine + Compose plugin # 5. Docker Engine + Compose plugin
# 6. Uzivatel deploy v docker group (docker bez sudo) # 6. Uzivatel deploy v docker group (docker bez sudo)
# 7. Adresarova struktura (/home/deploy/{docker,scripts,backups,logs,...}) # 7. Adresarova struktura (/home/deploy/{docker,scripts,backups,logs,...})
# 8. NetBird (mesh VPN - klient + setup key) # 8. NetBird (mesh VPN klient - apt balicek, NE Docker)
# 9. fail2ban (SSH jail) # 9. fail2ban (SSH jail)
# #
# Poznamka: firewall (UFW) se nenastavuje - podle pozadavku uzivatele. # Poznamka: firewall (UFW) se nenastavuje - podle pozadavku uzivatele.
@@ -113,7 +113,7 @@
SSH pristup: deploy@{{ ansible_host | default(inventory_hostname) }}:{{ ssh_port }} SSH pristup: deploy@{{ ansible_host | default(inventory_hostname) }}:{{ ssh_port }}
Docker: docker --version (bez sudo) Docker: docker --version (bez sudo)
NetBird: netbird status (mesh VPN) NetBird: netbird status (mesh VPN klient, ne Docker)
Sluzby: /home/{{ deploy_user }}/docker/<sluzba>/ Sluzby: /home/{{ deploy_user }}/docker/<sluzba>/
Dalsi kroky: Dalsi kroky:
+13 -7
View File
@@ -1,15 +1,21 @@
--- ---
# Promenne pro netbird roli # Promenne pro netbird roli
# NetBird - WireGuard-based mesh VPN (https://netbird.io) # NetBird - WireGuard-based mesh VPN klient (https://netbird.io)
#
# Setup klice pro NetBird registraci # POZNAMKA: NetBird je samostatna aplikace (klient), NE Docker sluzba.
# - Linux: instaluje se jako apt balicek (netbird)
# - macOS: instaluje se pres brew cask (netbird)
# - Windows: instalator z netbird.io
# Viz: https://docs.netbird.io/get-started/install
#
# Setup key pro automatickou registraci (po prvnim spusteni).
# Najdes v NetBird dashboardu: https://app.netbird.io/ -> Setup Keys # Najdes v NetBird dashboardu: https://app.netbird.io/ -> Setup Keys
# Napr: AAAA-BBBB-CCCC-DDDD-EEEE # Napr: AAAA-BBBB-CCCC-DDDD-EEEE
#
# Pokud je prazdne, NetBird se pouze nainstaluje - registraci provedes rucne:
# netbird up --setup-key <tvuj-key>
#
netbird_setup_key: "" netbird_setup_key: ""
# NetBird spust jako systemova sluzba (root)
# Pro user-level: netbird up --setup-key XXX (interaktivni)
netbird_run_as_system_service: true
# Vychozi Management Server (self-hosted nebo oficialni) # Vychozi Management Server (self-hosted nebo oficialni)
netbird_management_url: "https://api.netbird.io" netbird_management_url: "https://api.netbird.io"
+16 -8
View File
@@ -1,19 +1,19 @@
--- ---
- name: Stahnout NetBird GPG klic - name: Stahnout NetBird GPG klic (oficialni repo)
ansible.builtin.get_url: ansible.builtin.get_url:
url: https://pkgs.netbird.io/deb/public.key url: https://pkgs.netbird.io/deb/public.key
dest: /etc/apt/keyrings/netbird.asc dest: /etc/apt/keyrings/netbird.asc
mode: "0644" mode: "0644"
force: true force: true
- name: Pridat NetBird repo - name: Pridat NetBird APT repo
ansible.builtin.apt_repository: ansible.builtin.apt_repository:
repo: "deb [signed-by=/etc/apt/keyrings/netbird.asc] https://pkgs.netbird.io/deb stable main" repo: "deb [signed-by=/etc/apt/keyrings/netbird.asc] https://pkgs.netbird.io/deb stable main"
filename: netbird filename: netbird
state: present state: present
update_cache: true update_cache: true
- name: Nainstalovat NetBird - name: Nainstalovat NetBird klienta (apt balicek)
ansible.builtin.apt: ansible.builtin.apt:
name: name:
- netbird - netbird
@@ -27,11 +27,12 @@
- ansible.builtin.debug: - ansible.builtin.debug:
msg: "NetBird nainstalovan: {{ netbird_version_output.stdout }}" msg: "NetBird nainstalovan: {{ netbird_version_output.stdout }}"
- name: Spust NetBird s setup key (system service) - name: Registrace NetBird pomoci setup key (volitelne)
ansible.builtin.command: netbird up --setup-key {{ netbird_setup_key }} --management-url {{ netbird_management_url }} ansible.builtin.command: >
when: netbird up
- netbird_setup_key | length > 0 --setup-key {{ netbird_setup_key }}
- netbird_run_as_system_service | bool --management-url {{ netbird_management_url }}
when: netbird_setup_key | length > 0
register: netbird_up_result register: netbird_up_result
changed_when: netbird_up_result.rc == 0 changed_when: netbird_up_result.rc == 0
failed_when: false failed_when: false
@@ -44,3 +45,10 @@
- ansible.builtin.debug: - ansible.builtin.debug:
msg: "NetBird status: {{ netbird_status_output.stdout }}" msg: "NetBird status: {{ netbird_status_output.stdout }}"
when: netbird_setup_key | length > 0 when: netbird_setup_key | length > 0
- ansible.builtin.debug:
msg: >
NetBird nainstalovan, ale nezaregistrovany.
Pro registraci spust rucne:
sudo netbird up --setup-key <tvuj-key>
Dashboard: https://app.netbird.io/
when: netbird_setup_key | length == 0