Toto repo ma novou cistou historii (1 commit). Predchozi historie byla smazana, protoze obsahovala osobni udaje (IP, emaily, hesla, klice, tokeny, Volume cesty). Soubory v aktualnim commit uz tyto udaje neobsahuji (nahradeno placeholdery <server-ip>, CHANGE_ME, admin@example.com atd.). Pokud chces zpet kompletni seznam starych commitu, mas je ve svem lokalnim working tree - git log --all ukaze prazdno (protoze jsme smazali .git/ a zacali znovu).
148 lines
3.5 KiB
YAML
148 lines
3.5 KiB
YAML
---
|
|
# Bootstrap noveho Ubuntu serveru
|
|
# - aktualizace systemu
|
|
# - deploy user (UID 1000)
|
|
# - SSH hardening
|
|
# - UFW firewall
|
|
# - fail2ban
|
|
# - Docker
|
|
#
|
|
# Pouziti:
|
|
# ansible-playbook -i inventory.yml playbooks/bootstrap-server.yml
|
|
#
|
|
- name: Bootstrap home server
|
|
hosts: homeservers
|
|
become: true
|
|
gather_facts: true
|
|
|
|
vars:
|
|
deploy_user: deploy
|
|
deploy_uid: 1000
|
|
ssh_port: 22
|
|
# Verejny klic pro deploy uzivatele (nastav pred spustenim)
|
|
# deploy_ssh_key: "ssh-ed25519 AAAAC3Nz... hermes@mac"
|
|
|
|
tasks:
|
|
- name: Update apt cache
|
|
ansible.builtin.apt:
|
|
update_cache: true
|
|
cache_valid_time: 3600
|
|
|
|
- name: Upgrade vsech baliku
|
|
ansible.builtin.apt:
|
|
upgrade: dist
|
|
update_cache: true
|
|
|
|
- name: Instalace zakladnich baliku
|
|
ansible.builtin.apt:
|
|
name:
|
|
- curl
|
|
- wget
|
|
- git
|
|
- vim
|
|
- htop
|
|
- ca-certificates
|
|
- gnupg
|
|
- ufw
|
|
- fail2ban
|
|
- bash-completion
|
|
state: present
|
|
|
|
- name: Nastav timezone
|
|
community.general.timezone:
|
|
name: "{{ timezone }}"
|
|
|
|
- name: Vytvor deploy uzivatele
|
|
ansible.builtin.user:
|
|
name: "{{ deploy_user }}"
|
|
uid: "{{ deploy_uid }}"
|
|
shell: /bin/bash
|
|
create_home: true
|
|
password: ""
|
|
|
|
- name: Nastav SSH klic pro deploy uzivatele
|
|
ansible.posix.authorized_key:
|
|
user: "{{ deploy_user }}"
|
|
state: present
|
|
key: "{{ deploy_ssh_key }}"
|
|
when: deploy_ssh_key is defined
|
|
|
|
- name: Povol deploy uzivateli sudo bez hesla
|
|
ansible.builtin.copy:
|
|
dest: "/etc/sudoers.d/{{ deploy_user }}"
|
|
content: "{{ deploy_user }} ALL=(ALL) NOPASSWD:ALL\n"
|
|
mode: "0440"
|
|
|
|
- name: SSH hardening
|
|
ansible.builtin.lineinfile:
|
|
path: /etc/ssh/sshd_config
|
|
regexp: "^#?{{ item.key }}"
|
|
line: "{{ item.key }} {{ item.value }}"
|
|
state: present
|
|
loop:
|
|
- { key: "Port", value: "{{ ssh_port }}" }
|
|
- { key: "PermitRootLogin", value: "no" }
|
|
- { key: "PasswordAuthentication", value: "no" }
|
|
- { key: "X11Forwarding", value: "no" }
|
|
- { key: "ClientAliveInterval", value: "300" }
|
|
- { key: "ClientAliveCountMax", value: "2" }
|
|
notify: Restart ssh
|
|
|
|
- name: UFW vychozi pravidla
|
|
community.general.ufw:
|
|
direction: incoming
|
|
policy: deny
|
|
notify: Reload ufw
|
|
|
|
- name: Povol SSH pres UFW
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "{{ ssh_port }}"
|
|
proto: tcp
|
|
|
|
- name: Povol HTTP a HTTPS
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "{{ item }}"
|
|
proto: tcp
|
|
loop:
|
|
- "80"
|
|
- "443"
|
|
|
|
- name: Aktivuj UFW
|
|
community.general.ufw:
|
|
state: enabled
|
|
|
|
- name: Konfigurace fail2ban
|
|
ansible.builtin.copy:
|
|
dest: /etc/fail2ban/jail.local
|
|
content: |
|
|
[DEFAULT]
|
|
bantime = 1h
|
|
findtime = 10m
|
|
maxretry = 5
|
|
|
|
[sshd]
|
|
enabled = true
|
|
port = {{ ssh_port }}
|
|
filter = sshd
|
|
logpath = /var/log/auth.log
|
|
maxretry = 3
|
|
mode: "0644"
|
|
notify: Restart fail2ban
|
|
|
|
handlers:
|
|
- name: Restart ssh
|
|
ansible.builtin.service:
|
|
name: sshd
|
|
state: restarted
|
|
|
|
- name: Reload ufw
|
|
community.general.ufw:
|
|
state: reloaded
|
|
|
|
- name: Restart fail2ban
|
|
ansible.builtin.service:
|
|
name: fail2ban
|
|
state: restarted
|