[TIDY] Move to ansible_facts dict instead of injected variables

This commit is contained in:
Jannik Beyerstedt 2025-12-20 21:01:23 +01:00
parent cdd9bc58d2
commit ccf581edaa
6 changed files with 20 additions and 20 deletions

View file

@ -1,7 +1,7 @@
--- ---
# defaults file for tinc # defaults file for tinc
tinc_base_dir: /etc/tinc tinc_base_dir: /etc/tinc
tinc_tmp_pubkey: "tmp/rsa_key-{{ ansible_hostname | replace('-', '_') }}.pub" tinc_tmp_pubkey: "tmp/rsa_key-{{ ansible_facts['hostname'] | replace('-', '_') }}.pub"
# ID of the vpn to create # ID of the vpn to create
tinc_vpn_id: vpn0 tinc_vpn_id: vpn0

View file

@ -2,7 +2,7 @@
# Tinc VPN Hostfile Distribution # Tinc VPN Hostfile Distribution
- name: Distribute - Set different base dir for macOS - name: Distribute - Set different base dir for macOS
when: (override_os_family is defined) | ternary(override_os_family,ansible_os_family) == "Darwin" when: (override_os_family is defined) | ternary(override_os_family,ansible_facts['os_family']) == "Darwin"
ansible.builtin.set_fact: ansible.builtin.set_fact:
tinc_base_dir: /usr/local/etc/tinc tinc_base_dir: /usr/local/etc/tinc

View file

@ -2,15 +2,15 @@
# Tinc VPN Setup and Configuration # Tinc VPN Setup and Configuration
- name: Main - Set different base dir for macOS - name: Main - Set different base dir for macOS
when: (override_os_family is defined) | ternary(override_os_family, ansible_os_family) == "Darwin" when: (override_os_family is defined) | ternary(override_os_family, ansible_facts['os_family']) == "Darwin"
ansible.builtin.set_fact: ansible.builtin.set_fact:
tinc_base_dir: /usr/local/etc/tinc tinc_base_dir: /usr/local/etc/tinc
- name: Main - Install tinc - name: Main - Install tinc
ansible.builtin.include_tasks: "{{ item }}" ansible.builtin.include_tasks: "{{ item }}"
with_first_found: with_first_found:
- "setup-{{ ansible_distribution }}.yml" - "setup-{{ ansible_facts['distribution'] }}.yml"
- "setup-{{ (override_os_family is defined) | ternary(override_os_family, ansible_os_family) }}.yml" - "setup-{{ (override_os_family is defined) | ternary(override_os_family, ansible_facts['os_family']) }}.yml"
- name: Main - Create tinc directories - name: Main - Create tinc directories
become: true become: true
@ -38,14 +38,14 @@
become: true become: true
ansible.builtin.fetch: ansible.builtin.fetch:
src: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/rsa_key.pub" src: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/rsa_key.pub"
dest: "{{ role_path }}/templates/tmp/rsa_key-{{ ansible_hostname | replace('-', '_') }}.pub" dest: "{{ role_path }}/templates/tmp/rsa_key-{{ ansible_facts['hostname'] | replace('-', '_') }}.pub"
flat: true flat: true
- name: Main - Create own hostfile - name: Main - Create own hostfile
become: true become: true
ansible.builtin.template: ansible.builtin.template:
src: "{{ role_path }}/templates/hostfile.j2" src: "{{ role_path }}/templates/hostfile.j2"
dest: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/hosts/{{ ansible_hostname | replace('-', '_') }}" dest: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/hosts/{{ ansible_facts['hostname'] | replace('-', '_') }}"
- name: Main - Create tinc-up script - name: Main - Create tinc-up script
become: true become: true
@ -64,12 +64,12 @@
- name: Main - Fetch all hostfiles - name: Main - Fetch all hostfiles
become: true become: true
ansible.builtin.fetch: ansible.builtin.fetch:
src: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/hosts/{{ ansible_hostname | replace('-', '_') }}" src: "{{ tinc_base_dir }}/{{ tinc_vpn_id }}/hosts/{{ ansible_facts['hostname'] | replace('-', '_') }}"
dest: "{{ role_path }}/files/tmp/{{ ansible_hostname | replace('-', '_') }}" dest: "{{ role_path }}/files/tmp/{{ ansible_facts['hostname'] | replace('-', '_') }}"
flat: true flat: true
- name: "Main - Enable {{ tinc_vpn_id }}" - name: "Main - Enable {{ tinc_vpn_id }}"
when: ansible_os_family != 'Darwin' when: ansible_facts['os_family'] != 'Darwin'
become: true become: true
block: block:
- name: "Main - Enable {{ tinc_vpn_id }} in tinc config" - name: "Main - Enable {{ tinc_vpn_id }} in tinc config"

View file

@ -1,14 +1,14 @@
#!/bin/sh #!/bin/sh
{% if ansible_hostname == 'hetzner-01' %} {% if ansible_facts['hostname'] == 'hetzner-01' %}
/sbin/ifconfig $INTERFACE down /sbin/ifconfig $INTERFACE down
/usr/sbin/ip rule del to {{ tinc_remote_nets[0].net_cidr }} table 5 /usr/sbin/ip rule del to {{ tinc_remote_nets[0].net_cidr }} table 5
{% elif ansible_hostname == 'RaspiBeyerstedt' %} {% elif ansible_facts['hostname'] == 'RaspiBeyerstedt' %}
/sbin/ifconfig $INTERFACE down /sbin/ifconfig $INTERFACE down
/bin/ip route del {{ tinc_remote_nets[0].net_cidr }} dev eth0 /bin/ip route del {{ tinc_remote_nets[0].net_cidr }} dev eth0
{% elif ansible_os_family == 'Darwin' %} {% elif ansible_facts['os_family'] == 'Darwin' %}
/sbin/ifconfig $INTERFACE down /sbin/ifconfig $INTERFACE down
/sbin/route -n delete -net {{ tinc_remote_nets[0].net_cidr }} {{ tinc_remote_nets[0].gateway }} /sbin/route -n delete -net {{ tinc_remote_nets[0].net_cidr }} {{ tinc_remote_nets[0].gateway }}

View file

@ -1,12 +1,12 @@
#!/bin/sh #!/bin/sh
{% if ansible_hostname == 'hetzner-01' %} {% if ansible_facts['hostname'] == 'hetzner-01' %}
/sbin/ifconfig $INTERFACE {{ tinc_client_ip | ipaddr('address') }} netmask 255.255.255.0 /sbin/ifconfig $INTERFACE {{ tinc_client_ip | ipaddr('address') }} netmask 255.255.255.0
/usr/sbin/ip rule add to {{ tinc_remote_nets[0].net_cidr }} table 5 /usr/sbin/ip rule add to {{ tinc_remote_nets[0].net_cidr }} table 5
/usr/sbin/ip route add {{ tinc_remote_nets[0].net_cidr }} via {{ tinc_remote_nets[0].gateway }} dev {{ tinc_vpn_id }} table 5 /usr/sbin/ip route add {{ tinc_remote_nets[0].net_cidr }} via {{ tinc_remote_nets[0].gateway }} dev {{ tinc_vpn_id }} table 5
{% elif ansible_hostname == 'RaspiBeyerstedt' %} {% elif ansible_facts['hostname'] == 'RaspiBeyerstedt' %}
/sbin/ifconfig $INTERFACE {{ tinc_client_ip | ipaddr('address') }} netmask 255.255.255.0 /sbin/ifconfig $INTERFACE {{ tinc_client_ip | ipaddr('address') }} netmask 255.255.255.0
/bin/bash -c "echo 1 > /proc/sys/net/ipv4/ip_forward" /bin/bash -c "echo 1 > /proc/sys/net/ipv4/ip_forward"
@ -14,7 +14,7 @@
iptables -t nat -A POSTROUTING -o eth0 -s {{ tinc_vpn_net }} -j MASQUERADE iptables -t nat -A POSTROUTING -o eth0 -s {{ tinc_vpn_net }} -j MASQUERADE
{% elif ansible_os_family == 'Darwin' %} {% elif ansible_facts['os_family'] == 'Darwin' %}
# only a single endpoint works, because tun interface is p2p # only a single endpoint works, because tun interface is p2p
/sbin/ifconfig $INTERFACE inet {{ tinc_client_ip | ipaddr('address') }} {{ tinc_remote_nets[0].gateway }} up netmask 255.255.255.0 /sbin/ifconfig $INTERFACE inet {{ tinc_client_ip | ipaddr('address') }} {{ tinc_remote_nets[0].gateway }} up netmask 255.255.255.0

View file

@ -1,10 +1,10 @@
Name = {{ ansible_hostname | replace('-', '_') }} Name = {{ ansible_facts['hostname'] | replace('-', '_') }}
{% if (override_os_family is defined) | ternary(override_os_family,ansible_os_family) != 'Darwin' %} {% if (override_os_family is defined) | ternary(override_os_family,ansible_facts['os_family']) != 'Darwin' %}
Device = /dev/net/tun Device = /dev/net/tun
{% elif ternary(override_os_family,ansible_os_family) == 'Darwin' %} {% elif ternary(override_os_family,ansible_facts['os_family']) == 'Darwin' %}
DeviceType = utun DeviceType = utun
{% endif %} {% endif %}
{% if ansible_hostname | replace('-', '_') != tinc_central_host %} {% if ansible_facts['hostname'] | replace('-', '_') != tinc_central_host %}
ConnectTo = {{ tinc_central_host }} ConnectTo = {{ tinc_central_host }}
{% endif %} {% endif %}
AddressFamily = any AddressFamily = any