[INFO] Créer le rôle

This commit is contained in:
pulsar89.5 2023-05-17 13:49:56 +02:00
parent ddb7a1a06a
commit 120ad4915e
6 changed files with 63 additions and 3 deletions

View File

@ -1,3 +1,3 @@
# role_modele # role_stubby
Modèle Rôle de déploiement de stubby.

20
defaults/main.yml Normal file
View File

@ -0,0 +1,20 @@
---
# defaults file for dnsmasq
stubby_listen_addresses:
- 127.0.0.1
- 0::1
stubby_upstream_recursive_servers:
- address_data: 2a0f:fc80::0
tls_port: 853
tls_auth_name: "dns0.eu"
- address_data: 2a0f:fc81::0
tls_port: 853
tls_auth_name: "dns0.eu"
- address_data: 193.110.81.0
tls_port: 853
tls_auth_name: "dns0.eu"
- address_data: 185.253.5.0
tls_port: 853
tls_auth_name: "dns0.eu"

8
handlers/main.yml Normal file
View File

@ -0,0 +1,8 @@
---
# handlers file for stubby
- name: Redémarrer stubby.service
ansible.builtin.systemd:
state: restarted
name: stubby.service
become: true

View File

@ -1,7 +1,7 @@
galaxy_info: galaxy_info:
namespace: ykn namespace: ykn
author: pulsar89.5 author: pulsar89.5
description: Rôle modèle description: Rôle de déploiement de stubby
license: GPL-3.0-or-later license: GPL-3.0-or-later

14
tasks/main.yml Normal file
View File

@ -0,0 +1,14 @@
---
# tasks file for stubby
- name: Installer stubby
ansible.builtin.apt:
name: stubby
become: true
- name: configurer stubby
ansible.builtin.template:
src: stubby.yml.j2
dest: /etc/stubby/stubby.yml
become: true
notify: Redémarrer stubby.service

18
templates/stubby.yml.j2 Normal file
View File

@ -0,0 +1,18 @@
# {{ ansible_managed }}
resolution_type: GETDNS_RESOLUTION_STUB
dns_transport_list:
- GETDNS_TRANSPORT_TLS
tls_authentication: GETDNS_AUTHENTICATION_REQUIRED
tls_query_padding_blocksize: 128
edns_client_subnet_private: 1
round_robin_upstreams: 1
idle_timeout: 10000
listen_addresses:
{% for item in stubby_listen_addresses %}
- {{ item }}
{% endfor %}
upstream_recursive_servers:
{{ stubby_upstream_recursive_servers | to_yaml(indent=8, width=1337) }}