Initial version of the caddy rule

Signed-off-by: Nis Wechselberg <enbewe@enbewe.de>
This commit is contained in:
Nis Wechselberg 2024-06-17 17:27:27 +02:00
parent 6b7f10a1e1
commit 79a75602b7
Signed by: eNBeWe
GPG key ID: 7B25171F921B9E57
10 changed files with 303 additions and 0 deletions

5
CHANGELOG.md Normal file
View file

@ -0,0 +1,5 @@
# Changelog
## 1.0.0
* Initial Release

26
README.md Normal file
View file

@ -0,0 +1,26 @@
# Ansible Collection - enbewe.caddy
Collecion for a multi-site reverse proxy, based on caddy (https://caddyserver.com/).
## Playbooks
### enbewe.caddy.deploy
Deploys the role `enbewe.caddy.caddy` to the host group called `caddy`.
## Roles
### enbewe.caddy.caddy
Installs the caddy server in a podman container and configures the server to act
as a reverse proxy to all configured sites.
#### Required variables
**caddy_networks** *(Type: list / elements=string)*
The list of podman networks the proxy should be part of.
**caddy_sites** *(Type: dict)
The sites that caddy should serve.
Each site has to have a `name`, that is used as the host in caddy config.
Additionally, the site should have the key `proxy_to`, that points to the address of the proxied service,
or it should have the key `directives` that can be used to create a free-form config for the site.
#### Optional variables
**caddy_use_local_certs** *(Default: false)*
Enforce usage of local certificates, instead of the default Letsencrypt certs.

67
galaxy.yml Normal file
View file

@ -0,0 +1,67 @@
---
### REQUIRED
# The namespace of the collection. This can be a company/brand/organization or product namespace under which all
# content lives. May only contain alphanumeric lowercase characters and underscores. Namespaces cannot start with
# underscores or numbers and cannot contain consecutive underscores
namespace: 'enbewe'
# The name of the collection. Has the same character restrictions as 'namespace'
name: 'caddy'
# The version of the collection. Must be compatible with semantic versioning
version: '1.0.0'
# The path to the Markdown (.md) readme file. This path is relative to the root of the collection
readme: 'README.md'
# A list of the collection's content authors. Can be just the name or in the format 'Full Name <email> (url)
# @nicks:irc/im.site#channel'
authors:
- 'Nis Wechselberg <enbewe+ansible@enbewe.de>'
### OPTIONAL but strongly recommended
# A short summary description of the collection
description: 'Caddy based reverse proxy'
# Either a single license or a list of licenses for content inside of a collection. Ansible Galaxy currently only
# accepts L(SPDX,https://spdx.org/licenses/) licenses. This key is mutually exclusive with 'license_file'
license:
- 'MIT'
# A list of tags you want to associate with the collection for indexing/searching. A tag name has the same character
# requirements as 'namespace' and 'name'
tags:
- 'linux'
# Collections that this collection requires to be installed for it to be usable. The key of the dict is the
# collection label 'namespace.name'. The value is a version range
# L(specifiers,https://python-semanticversion.readthedocs.io/en/latest/#requirement-specification). Multiple version
# range specifiers can be set and are separated by ','
dependencies:
containers.podman: '>=1.13.0'
# The URL of the originating SCM repository
repository: 'https://git.enbewe.de/Coding/ansible-collection-caddy'
# The URL to any online docs
# documentation: http://docs.example.com
# The URL to the homepage of the collection/project
# homepage: http://example.com
# The URL to the collection issue tracker
# issues: http://example.com/issue/tracker
# A list of file glob-like patterns used to filter any files or directories that should not be included in the build
# artifact. A pattern is matched from the relative path of the file or directory of the collection directory. This
# uses 'fnmatch' to match the files or directories. Some directories and files like 'galaxy.yml', '*.pyc', '*.retry',
# and '.git' are always filtered. Mutually exclusive with 'manifest'
# build_ignore: []
# A dict controlling use of manifest directives used in building the collection artifact. The key 'directives' is a
# list of MANIFEST.in style
# L(directives,https://packaging.python.org/en/latest/guides/using-manifest-in/#manifest-in-commands). The key
# 'omit_default_directives' is a boolean that controls whether the default directives are used. Mutually exclusive
# with 'build_ignore'
# manifest: null

52
meta/runtime.yml Normal file
View file

@ -0,0 +1,52 @@
---
# Collections must specify a minimum required ansible version to upload
# to galaxy
requires_ansible: '>=2.17.0'
# Content that Ansible needs to load from another location or that has
# been deprecated/removed
# plugin_routing:
# action:
# redirected_plugin_name:
# redirect: ns.col.new_location
# deprecated_plugin_name:
# deprecation:
# removal_version: "4.0.0"
# warning_text: |
# See the porting guide on how to update your playbook to
# use ns.col.another_plugin instead.
# removed_plugin_name:
# tombstone:
# removal_version: "2.0.0"
# warning_text: |
# See the porting guide on how to update your playbook to
# use ns.col.another_plugin instead.
# become:
# cache:
# callback:
# cliconf:
# connection:
# doc_fragments:
# filter:
# httpapi:
# inventory:
# lookup:
# module_utils:
# modules:
# netconf:
# shell:
# strategy:
# terminal:
# test:
# vars:
# Python import statements that Ansible needs to load from another location
# import_redirection:
# ansible_collections.ns.col.plugins.module_utils.old_location:
# redirect: ansible_collections.ns.col.plugins.module_utils.new_location
# Groups of actions/modules that take a common set of options
# action_groups:
# group_name:
# - module1
# - module2

5
playbooks/deploy.yml Normal file
View file

@ -0,0 +1,5 @@
---
- name: 'Deploy reverse proxy to host group'
hosts: 'caddy'
roles:
- 'enbewe.caddy.caddy'

31
plugins/README.md Normal file
View file

@ -0,0 +1,31 @@
# Collections Plugins Directory
This directory can be used to ship various plugins inside an Ansible collection. Each plugin is placed in a folder that
is named after the type of plugin it is in. It can also include the `module_utils` and `modules` directory that
would contain module utils and modules respectively.
Here is an example directory of the majority of plugins currently supported by Ansible:
```
└── plugins
├── action
├── become
├── cache
├── callback
├── cliconf
├── connection
├── filter
├── httpapi
├── inventory
├── lookup
├── module_utils
├── modules
├── netconf
├── shell
├── strategy
├── terminal
├── test
└── vars
```
A full list of plugin types can be found at [Working With Plugins](https://docs.ansible.com/ansible-core/2.17/plugins/plugins.html).

View file

@ -0,0 +1,2 @@
---
caddy_use_local_certs: false

View file

@ -0,0 +1,23 @@
---
- name: 'Reload caddy services'
become: true
ansible.builtin.service:
daemon-reload: true
- name: 'Restart caddy image'
become: true
ansible.builtin.service:
name: 'caddy-image.service'
state: 'restarted'
- name: 'Restart caddy volume'
become: true
ansible.builtin.service:
name: 'caddy-data-volume.service'
state: 'restarted'
- name: 'Restart caddy container'
become: true
ansible.builtin.service:
name: 'caddy.service'
state: 'restarted'

View file

@ -0,0 +1,75 @@
---
- name: 'Ensure required software is installed'
become: true
ansible.builtin.apt:
name: 'podman'
state: 'present'
- name: 'Define caddy image'
become: true
containers.podman.podman_image:
name: 'docker.io/library/caddy:latest'
state: 'quadlet'
notify:
- 'Reload caddy services'
- 'Restart caddy image'
- name: 'Define caddy data volume'
become: true
containers.podman.podman_volume:
name: 'caddy-data'
state: 'quadlet'
notify:
- 'Reload caddy services'
- 'Restart caddy volume'
- name: 'Create caddy conf directory'
become: true
ansible.builtin.file:
name: '/etc/caddy'
state: 'directory'
owner: 'root'
group: 'root'
mode: 'u=rwx,g=rx,o=rx'
- name: 'Generate Caddyfile'
become: true
ansible.builtin.template:
src: 'Caddyfile.j2'
dest: '/etc/caddy/Caddyfile'
owner: 'root'
group: 'root'
mode: 'u=rw,g=r,o=r'
notify:
- 'Restart caddy container'
- name: 'Create caddy container'
become: true
containers.podman.podman_container:
name: 'caddy'
image: 'caddy.image'
network: '{{ caddy_networks }}'
state: 'quadlet'
volume:
- '/etc/caddy:/etc/caddy'
- 'caddy-data.volume:/data'
publish:
- '80:80'
- '443:443'
quadlet_options: |
[Install]
WantedBy=default.target
[Unit]
Requires=caddy-image.service
After=caddy-image.service
Requires=caddy-data-volume.service
After=caddy-data-volume.service
{% for net in caddy_networks %}
Requires={{ net | replace('.network', '-network') }}.service
After={{ net | replace('.network', '-network') }}.service
{% endfor %}
notify:
- 'Reload caddy services'
- 'Restart caddy container'

View file

@ -0,0 +1,17 @@
{% if caddy_use_local_certs %}
{
local_certs
}
{% endif %}
{% for site in caddy_sites %}
{{ site.name }} {
{% if site.directives is defined %}
{{ site.directives }}
{% endif %}
{% if site.proxy_to is defined %}
reverse_proxy {{ site.proxy_to }}
{% endif %}
}
{% endfor %}