Compare commits
	
		
			123 Commits
		
	
	
		
			alpine
			...
			0ffb1b1a36
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						
						
							
						
						0ffb1b1a36
	
				 | 
					
					
						|||
| 
						
						
							
						
						68f0b85eb3
	
				 | 
					
					
						|||
| 
						
						
							
						
						ebbde530d2
	
				 | 
					
					
						|||
| 
						
						
							
						
						ab47df6031
	
				 | 
					
					
						|||
| 
						
						
							
						
						de75b2ffb6
	
				 | 
					
					
						|||
| 
						
						
							
						
						e10d83dadd
	
				 | 
					
					
						|||
| 
						
						
							
						
						f070fd9a64
	
				 | 
					
					
						|||
| 
						
						
							
						
						6e1527b1a8
	
				 | 
					
					
						|||
| 
						
						
							
						
						ebd8b0632b
	
				 | 
					
					
						|||
| 
						
						
							
						
						df26b6c17e
	
				 | 
					
					
						|||
| 
						
						
							
						
						d92151b8a6
	
				 | 
					
					
						|||
| 
						
						
							
						
						b13ead0657
	
				 | 
					
					
						|||
| 
						
						
							
						
						89ced6f952
	
				 | 
					
					
						|||
| 
						
						
							
						
						ae5ba0607a
	
				 | 
					
					
						|||
| 
						
						
							
						
						89fd642b78
	
				 | 
					
					
						|||
| 
						
						
							
						
						65e6dd34cd
	
				 | 
					
					
						|||
| 
						
						
							
						
						0421807e4d
	
				 | 
					
					
						|||
| 
						
						
							
						
						d5eed5055e
	
				 | 
					
					
						|||
| 
						
						
							
						
						f8752bb3e7
	
				 | 
					
					
						|||
| 
						
						
							
						
						170e591701
	
				 | 
					
					
						|||
| 
						
						
							
						
						8d6c3c57c3
	
				 | 
					
					
						|||
| 
						
						
							
						
						79b29f0c51
	
				 | 
					
					
						|||
| 
						
						
							
						
						a4acc85704
	
				 | 
					
					
						|||
| 
						
						
							
						
						f7b9aa67f5
	
				 | 
					
					
						|||
| 
						
						
							
						
						0a39c4f0ef
	
				 | 
					
					
						|||
| 
						
						
							
						
						85323d789c
	
				 | 
					
					
						|||
| 
						
						
							
						
						341a1bf11e
	
				 | 
					
					
						|||
| 
						
						
							
						
						6ee389eda5
	
				 | 
					
					
						|||
| 
						
						
							
						
						83fea62b0f
	
				 | 
					
					
						|||
| 
						
						
							
						
						0d1a5fbb25
	
				 | 
					
					
						|||
| 
						
						
							
						
						4d8444abf2
	
				 | 
					
					
						|||
| 
						
						
							
						
						e8486f6c9e
	
				 | 
					
					
						|||
| 
						
						
							
						
						20cd6f213c
	
				 | 
					
					
						|||
| 
						
						
							
						
						eb80e797c6
	
				 | 
					
					
						|||
| 
						
						
							
						
						736bb8eb38
	
				 | 
					
					
						|||
| 
						
						
							
						
						34a30c4d13
	
				 | 
					
					
						|||
| 
						
						
							
						
						c03e75d736
	
				 | 
					
					
						|||
| 
						
						
							
						
						d08f10f9c8
	
				 | 
					
					
						|||
| 
						
						
							
						
						8467dc1300
	
				 | 
					
					
						|||
| 
						
						
							
						
						635bb5234d
	
				 | 
					
					
						|||
| 
						
						
							
						
						37901da5b5
	
				 | 
					
					
						|||
| 
						
						
							
						
						e36ae3b11e
	
				 | 
					
					
						|||
| 
						
						
							
						
						81c1231a28
	
				 | 
					
					
						|||
| 
						
						
							
						
						bb6f058025
	
				 | 
					
					
						|||
| 
						
						
							
						
						547395b26e
	
				 | 
					
					
						|||
| 
						
						
							
						
						15208241d3
	
				 | 
					
					
						|||
| 
						
						
							
						
						0fd05d496e
	
				 | 
					
					
						|||
| 
						
						
							
						
						023a0d48ba
	
				 | 
					
					
						|||
| 
						
						
							
						
						c687b7a91a
	
				 | 
					
					
						|||
| 
						
						
							
						
						bd4ae36bb6
	
				 | 
					
					
						|||
| 
						
						
							
						
						b60637c7d9
	
				 | 
					
					
						|||
| 
						
						
							
						
						479127a5e4
	
				 | 
					
					
						|||
| 
						
						
							
						
						d261f81642
	
				 | 
					
					
						|||
| 
						
						
							
						
						6bc044d454
	
				 | 
					
					
						|||
| 
						
						
							
						
						9e07e27fbe
	
				 | 
					
					
						|||
| 
						
						
							
						
						575a9fdfe6
	
				 | 
					
					
						|||
| 
						
						
							
						
						35fa3b0d72
	
				 | 
					
					
						|||
| 
						
						
							
						
						ba5760bf8c
	
				 | 
					
					
						|||
| 
						
						
							
						
						5e918da88e
	
				 | 
					
					
						|||
| 
						
						
							
						
						f7e87ea7be
	
				 | 
					
					
						|||
| 
						
						
							
						
						7b233eb31d
	
				 | 
					
					
						|||
| 
						
						
							
						
						b5ea575d8d
	
				 | 
					
					
						|||
| 
						
						
							
						
						98cc3a8c2e
	
				 | 
					
					
						|||
| 
						
						
							
						
						a67d901641
	
				 | 
					
					
						|||
| 
						
						
							
						
						7ae100faeb
	
				 | 
					
					
						|||
| 
						
						
							
						
						debcb21161
	
				 | 
					
					
						|||
| 
						
						
							
						
						8dd7663b3c
	
				 | 
					
					
						|||
| 
						
						
							
						
						cba2a7a996
	
				 | 
					
					
						|||
| 
						
						
							
						
						197bdf7666
	
				 | 
					
					
						|||
| 
						
						
							
						
						46fc2ce3d4
	
				 | 
					
					
						|||
| 
						
						
							
						
						b4d50166f4
	
				 | 
					
					
						|||
| 
						
						
							
						
						c336b217c5
	
				 | 
					
					
						|||
| 
						
						
							
						
						af6c3dd12a
	
				 | 
					
					
						|||
| 
						
						
							
						
						b66c724109
	
				 | 
					
					
						|||
| 
						
						
							
						
						8bc2b6f493
	
				 | 
					
					
						|||
| 
						
						
							
						
						a74d6dfc08
	
				 | 
					
					
						|||
| 
						
						
							
						
						d3922e7878
	
				 | 
					
					
						|||
| 
						
						
							
						
						14814aa5d9
	
				 | 
					
					
						|||
| 
						
						
							
						
						3b053167b1
	
				 | 
					
					
						|||
| 
						
						
							
						
						9bba0d96bb
	
				 | 
					
					
						|||
| 
						
						
							
						
						38c333045b
	
				 | 
					
					
						|||
| 
						
						
							
						
						d4ede33099
	
				 | 
					
					
						|||
| 
						
						
							
						
						0bad75788d
	
				 | 
					
					
						|||
| 
						
						
							
						
						892033b880
	
				 | 
					
					
						|||
| 7c6ab2a652 | |||
| 
						
						
							
						
						1c95c1faa8
	
				 | 
					
					
						|||
| 
						
						
							
						
						9ea14de6f5
	
				 | 
					
					
						|||
| 
						
						
							
						
						9b7a31ebf9
	
				 | 
					
					
						|||
| 
						
						
							
						
						d7c34a30a3
	
				 | 
					
					
						|||
| 
						
						
							
						
						ee5f4cdf74
	
				 | 
					
					
						|||
| 
						
						
							
						
						b014c09a2c
	
				 | 
					
					
						|||
| 
						
						
							
						
						531ff99af0
	
				 | 
					
					
						|||
| 
						
						
							
						
						82d3a7ff2a
	
				 | 
					
					
						|||
| 
						
						
							
						
						6c3cf40a16
	
				 | 
					
					
						|||
| 
						
						
							
						
						681be5eb19
	
				 | 
					
					
						|||
| 
						
						
							
						
						4fae56a386
	
				 | 
					
					
						|||
| 
						
						
							
						
						1d5db7bdbe
	
				 | 
					
					
						|||
| 
						
						
							
						
						32da3a3341
	
				 | 
					
					
						|||
| 
						
						
							
						
						31a3f5832a
	
				 | 
					
					
						|||
| 
						
						
							
						
						3e7130b519
	
				 | 
					
					
						|||
| 
						
						
							
						
						bd0b6a16de
	
				 | 
					
					
						|||
| 
						
						
							
						
						7145298f90
	
				 | 
					
					
						|||
| 
						
						
							
						
						1bfd2bc441
	
				 | 
					
					
						|||
| 
						
						
							
						
						884b3b8425
	
				 | 
					
					
						|||
| 
						
						
							
						
						e06a0c4093
	
				 | 
					
					
						|||
| 
						
						
							
						
						7ba5afcec4
	
				 | 
					
					
						|||
| 
						
						
							
						
						d3978e5b07
	
				 | 
					
					
						|||
| 
						
						
							
						
						4150dac57b
	
				 | 
					
					
						|||
| 
						
						
							
						
						58bc9d191f
	
				 | 
					
					
						|||
| 
						
						
							
						
						96cefc7f74
	
				 | 
					
					
						|||
| 
						
						
							
						
						f85eb2841a
	
				 | 
					
					
						|||
| 
						
						
							
						
						5d506ebc65
	
				 | 
					
					
						|||
| 
						
						
							
						
						af49f27551
	
				 | 
					
					
						|||
| 
						
						
							
						
						f341d2e5eb
	
				 | 
					
					
						|||
| 
						
						
							
						
						ceba0ea417
	
				 | 
					
					
						|||
| 
						
						
							
						
						a34cb1e666
	
				 | 
					
					
						|||
| 
						
						
							
						
						65fc52c5e5
	
				 | 
					
					
						|||
| 
						
						
							
						
						7f13c8c675
	
				 | 
					
					
						|||
| 
						
						
							
						
						9c36cfb8e5
	
				 | 
					
					
						|||
| 
						
						
							
						
						7f72a9eda4
	
				 | 
					
					
						|||
| 
						
						
							
						
						6e96d48ea6
	
				 | 
					
					
						|||
| 
						
						
							
						
						db412066b3
	
				 | 
					
					
						|||
| 
						
						
							
						
						63a836e2a7
	
				 | 
					
					
						
							
								
								
									
										2
									
								
								Pipfile
									
									
									
									
									
								
							
							
						
						
									
										2
									
								
								Pipfile
									
									
									
									
									
								
							@@ -9,4 +9,4 @@ verify_ssl = true
 | 
			
		||||
ansible = "*"
 | 
			
		||||
 | 
			
		||||
[requires]
 | 
			
		||||
python_version = "3.9"
 | 
			
		||||
python_version = "3.10"
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										365
									
								
								Pipfile.lock
									
									
									
										generated
									
									
									
								
							
							
						
						
									
										365
									
								
								Pipfile.lock
									
									
									
										generated
									
									
									
								
							@@ -1,11 +1,11 @@
 | 
			
		||||
{
 | 
			
		||||
    "_meta": {
 | 
			
		||||
        "hash": {
 | 
			
		||||
            "sha256": "65b615b857250757470e21fc3a4b1cdfe75b4b012c0d1d633a5ebf1988d9cb91"
 | 
			
		||||
            "sha256": "317b86105eac498eb2ff0ec57bfeb1077ed615c3ee3895d07e72708f6366314f"
 | 
			
		||||
        },
 | 
			
		||||
        "pipfile-spec": 6,
 | 
			
		||||
        "requires": {
 | 
			
		||||
            "python_version": "3.9"
 | 
			
		||||
            "python_version": "3.10"
 | 
			
		||||
        },
 | 
			
		||||
        "sources": [
 | 
			
		||||
            {
 | 
			
		||||
@@ -18,204 +18,251 @@
 | 
			
		||||
    "default": {
 | 
			
		||||
        "ansible": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:ae97002e4fb1ed3de947428ff43906c76c66751fe104721cf6b25fa115dbbe8d"
 | 
			
		||||
                "sha256:7604f264f9bdf31442ea152fa4eb77fe700100ff5e54103822d284551b7524bc"
 | 
			
		||||
            ],
 | 
			
		||||
            "index": "pypi",
 | 
			
		||||
            "version": "==2.10.6"
 | 
			
		||||
            "version": "==5.1.0"
 | 
			
		||||
        },
 | 
			
		||||
        "ansible-base": {
 | 
			
		||||
        "ansible-core": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:33ae323923b841f3d822f355380ce7c92610440362efeed67b4b39db41e555af"
 | 
			
		||||
                "sha256:a4508707262be11bb4dd98a006f1b14817879a055e6b6c46ad9fca8894fb3073"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4'",
 | 
			
		||||
            "version": "==2.10.5"
 | 
			
		||||
            "markers": "python_version >= '3.8'",
 | 
			
		||||
            "version": "==2.12.1"
 | 
			
		||||
        },
 | 
			
		||||
        "cffi": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:00a1ba5e2e95684448de9b89888ccd02c98d512064b4cb987d48f4b40aa0421e",
 | 
			
		||||
                "sha256:00e28066507bfc3fe865a31f325c8391a1ac2916219340f87dfad602c3e48e5d",
 | 
			
		||||
                "sha256:045d792900a75e8b1e1b0ab6787dd733a8190ffcf80e8c8ceb2fb10a29ff238a",
 | 
			
		||||
                "sha256:0638c3ae1a0edfb77c6765d487fee624d2b1ee1bdfeffc1f0b58c64d149e7eec",
 | 
			
		||||
                "sha256:105abaf8a6075dc96c1fe5ae7aae073f4696f2905fde6aeada4c9d2926752362",
 | 
			
		||||
                "sha256:155136b51fd733fa94e1c2ea5211dcd4c8879869008fc811648f16541bf99668",
 | 
			
		||||
                "sha256:1a465cbe98a7fd391d47dce4b8f7e5b921e6cd805ef421d04f5f66ba8f06086c",
 | 
			
		||||
                "sha256:1d2c4994f515e5b485fd6d3a73d05526aa0fcf248eb135996b088d25dfa1865b",
 | 
			
		||||
                "sha256:2c24d61263f511551f740d1a065eb0212db1dbbbbd241db758f5244281590c06",
 | 
			
		||||
                "sha256:51a8b381b16ddd370178a65360ebe15fbc1c71cf6f584613a7ea08bfad946698",
 | 
			
		||||
                "sha256:594234691ac0e9b770aee9fcdb8fa02c22e43e5c619456efd0d6c2bf276f3eb2",
 | 
			
		||||
                "sha256:5cf4be6c304ad0b6602f5c4e90e2f59b47653ac1ed9c662ed379fe48a8f26b0c",
 | 
			
		||||
                "sha256:64081b3f8f6f3c3de6191ec89d7dc6c86a8a43911f7ecb422c60e90c70be41c7",
 | 
			
		||||
                "sha256:6bc25fc545a6b3d57b5f8618e59fc13d3a3a68431e8ca5fd4c13241cd70d0009",
 | 
			
		||||
                "sha256:798caa2a2384b1cbe8a2a139d80734c9db54f9cc155c99d7cc92441a23871c03",
 | 
			
		||||
                "sha256:7c6b1dece89874d9541fc974917b631406233ea0440d0bdfbb8e03bf39a49b3b",
 | 
			
		||||
                "sha256:7ef7d4ced6b325e92eb4d3502946c78c5367bc416398d387b39591532536734e",
 | 
			
		||||
                "sha256:840793c68105fe031f34d6a086eaea153a0cd5c491cde82a74b420edd0a2b909",
 | 
			
		||||
                "sha256:8d6603078baf4e11edc4168a514c5ce5b3ba6e3e9c374298cb88437957960a53",
 | 
			
		||||
                "sha256:9cc46bc107224ff5b6d04369e7c595acb700c3613ad7bcf2e2012f62ece80c35",
 | 
			
		||||
                "sha256:9f7a31251289b2ab6d4012f6e83e58bc3b96bd151f5b5262467f4bb6b34a7c26",
 | 
			
		||||
                "sha256:9ffb888f19d54a4d4dfd4b3f29bc2c16aa4972f1c2ab9c4ab09b8ab8685b9c2b",
 | 
			
		||||
                "sha256:a5ed8c05548b54b998b9498753fb9cadbfd92ee88e884641377d8a8b291bcc01",
 | 
			
		||||
                "sha256:a7711edca4dcef1a75257b50a2fbfe92a65187c47dab5a0f1b9b332c5919a3fb",
 | 
			
		||||
                "sha256:af5c59122a011049aad5dd87424b8e65a80e4a6477419c0c1015f73fb5ea0293",
 | 
			
		||||
                "sha256:b18e0a9ef57d2b41f5c68beefa32317d286c3d6ac0484efd10d6e07491bb95dd",
 | 
			
		||||
                "sha256:b4e248d1087abf9f4c10f3c398896c87ce82a9856494a7155823eb45a892395d",
 | 
			
		||||
                "sha256:ba4e9e0ae13fc41c6b23299545e5ef73055213e466bd107953e4a013a5ddd7e3",
 | 
			
		||||
                "sha256:c6332685306b6417a91b1ff9fae889b3ba65c2292d64bd9245c093b1b284809d",
 | 
			
		||||
                "sha256:d5ff0621c88ce83a28a10d2ce719b2ee85635e85c515f12bac99a95306da4b2e",
 | 
			
		||||
                "sha256:d9efd8b7a3ef378dd61a1e77367f1924375befc2eba06168b6ebfa903a5e59ca",
 | 
			
		||||
                "sha256:df5169c4396adc04f9b0a05f13c074df878b6052430e03f50e68adf3a57aa28d",
 | 
			
		||||
                "sha256:ebb253464a5d0482b191274f1c8bf00e33f7e0b9c66405fbffc61ed2c839c775",
 | 
			
		||||
                "sha256:ec80dc47f54e6e9a78181ce05feb71a0353854cc26999db963695f950b5fb375",
 | 
			
		||||
                "sha256:f032b34669220030f905152045dfa27741ce1a6db3324a5bc0b96b6c7420c87b",
 | 
			
		||||
                "sha256:f60567825f791c6f8a592f3c6e3bd93dd2934e3f9dac189308426bd76b00ef3b",
 | 
			
		||||
                "sha256:f803eaa94c2fcda012c047e62bc7a51b0bdabda1cad7a92a522694ea2d76e49f"
 | 
			
		||||
                "sha256:00c878c90cb53ccfaae6b8bc18ad05d2036553e6d9d1d9dbcf323bbe83854ca3",
 | 
			
		||||
                "sha256:0104fb5ae2391d46a4cb082abdd5c69ea4eab79d8d44eaaf79f1b1fd806ee4c2",
 | 
			
		||||
                "sha256:06c48159c1abed75c2e721b1715c379fa3200c7784271b3c46df01383b593636",
 | 
			
		||||
                "sha256:0808014eb713677ec1292301ea4c81ad277b6cdf2fdd90fd540af98c0b101d20",
 | 
			
		||||
                "sha256:10dffb601ccfb65262a27233ac273d552ddc4d8ae1bf93b21c94b8511bffe728",
 | 
			
		||||
                "sha256:14cd121ea63ecdae71efa69c15c5543a4b5fbcd0bbe2aad864baca0063cecf27",
 | 
			
		||||
                "sha256:17771976e82e9f94976180f76468546834d22a7cc404b17c22df2a2c81db0c66",
 | 
			
		||||
                "sha256:181dee03b1170ff1969489acf1c26533710231c58f95534e3edac87fff06c443",
 | 
			
		||||
                "sha256:23cfe892bd5dd8941608f93348c0737e369e51c100d03718f108bf1add7bd6d0",
 | 
			
		||||
                "sha256:263cc3d821c4ab2213cbe8cd8b355a7f72a8324577dc865ef98487c1aeee2bc7",
 | 
			
		||||
                "sha256:2756c88cbb94231c7a147402476be2c4df2f6078099a6f4a480d239a8817ae39",
 | 
			
		||||
                "sha256:27c219baf94952ae9d50ec19651a687b826792055353d07648a5695413e0c605",
 | 
			
		||||
                "sha256:2a23af14f408d53d5e6cd4e3d9a24ff9e05906ad574822a10563efcef137979a",
 | 
			
		||||
                "sha256:31fb708d9d7c3f49a60f04cf5b119aeefe5644daba1cd2a0fe389b674fd1de37",
 | 
			
		||||
                "sha256:3415c89f9204ee60cd09b235810be700e993e343a408693e80ce7f6a40108029",
 | 
			
		||||
                "sha256:3773c4d81e6e818df2efbc7dd77325ca0dcb688116050fb2b3011218eda36139",
 | 
			
		||||
                "sha256:3b96a311ac60a3f6be21d2572e46ce67f09abcf4d09344c49274eb9e0bf345fc",
 | 
			
		||||
                "sha256:3f7d084648d77af029acb79a0ff49a0ad7e9d09057a9bf46596dac9514dc07df",
 | 
			
		||||
                "sha256:41d45de54cd277a7878919867c0f08b0cf817605e4eb94093e7516505d3c8d14",
 | 
			
		||||
                "sha256:4238e6dab5d6a8ba812de994bbb0a79bddbdf80994e4ce802b6f6f3142fcc880",
 | 
			
		||||
                "sha256:45db3a33139e9c8f7c09234b5784a5e33d31fd6907800b316decad50af323ff2",
 | 
			
		||||
                "sha256:45e8636704eacc432a206ac7345a5d3d2c62d95a507ec70d62f23cd91770482a",
 | 
			
		||||
                "sha256:4958391dbd6249d7ad855b9ca88fae690783a6be9e86df65865058ed81fc860e",
 | 
			
		||||
                "sha256:4a306fa632e8f0928956a41fa8e1d6243c71e7eb59ffbd165fc0b41e316b2474",
 | 
			
		||||
                "sha256:57e9ac9ccc3101fac9d6014fba037473e4358ef4e89f8e181f8951a2c0162024",
 | 
			
		||||
                "sha256:59888172256cac5629e60e72e86598027aca6bf01fa2465bdb676d37636573e8",
 | 
			
		||||
                "sha256:5e069f72d497312b24fcc02073d70cb989045d1c91cbd53979366077959933e0",
 | 
			
		||||
                "sha256:64d4ec9f448dfe041705426000cc13e34e6e5bb13736e9fd62e34a0b0c41566e",
 | 
			
		||||
                "sha256:6dc2737a3674b3e344847c8686cf29e500584ccad76204efea14f451d4cc669a",
 | 
			
		||||
                "sha256:74fdfdbfdc48d3f47148976f49fab3251e550a8720bebc99bf1483f5bfb5db3e",
 | 
			
		||||
                "sha256:75e4024375654472cc27e91cbe9eaa08567f7fbdf822638be2814ce059f58032",
 | 
			
		||||
                "sha256:786902fb9ba7433aae840e0ed609f45c7bcd4e225ebb9c753aa39725bb3e6ad6",
 | 
			
		||||
                "sha256:8b6c2ea03845c9f501ed1313e78de148cd3f6cad741a75d43a29b43da27f2e1e",
 | 
			
		||||
                "sha256:91d77d2a782be4274da750752bb1650a97bfd8f291022b379bb8e01c66b4e96b",
 | 
			
		||||
                "sha256:91ec59c33514b7c7559a6acda53bbfe1b283949c34fe7440bcf917f96ac0723e",
 | 
			
		||||
                "sha256:920f0d66a896c2d99f0adbb391f990a84091179542c205fa53ce5787aff87954",
 | 
			
		||||
                "sha256:a5263e363c27b653a90078143adb3d076c1a748ec9ecc78ea2fb916f9b861962",
 | 
			
		||||
                "sha256:abb9a20a72ac4e0fdb50dae135ba5e77880518e742077ced47eb1499e29a443c",
 | 
			
		||||
                "sha256:c2051981a968d7de9dd2d7b87bcb9c939c74a34626a6e2f8181455dd49ed69e4",
 | 
			
		||||
                "sha256:c21c9e3896c23007803a875460fb786118f0cdd4434359577ea25eb556e34c55",
 | 
			
		||||
                "sha256:c2502a1a03b6312837279c8c1bd3ebedf6c12c4228ddbad40912d671ccc8a962",
 | 
			
		||||
                "sha256:d4d692a89c5cf08a8557fdeb329b82e7bf609aadfaed6c0d79f5a449a3c7c023",
 | 
			
		||||
                "sha256:da5db4e883f1ce37f55c667e5c0de439df76ac4cb55964655906306918e7363c",
 | 
			
		||||
                "sha256:e7022a66d9b55e93e1a845d8c9eba2a1bebd4966cd8bfc25d9cd07d515b33fa6",
 | 
			
		||||
                "sha256:ef1f279350da2c586a69d32fc8733092fd32cc8ac95139a00377841f59a3f8d8",
 | 
			
		||||
                "sha256:f54a64f8b0c8ff0b64d18aa76675262e1700f3995182267998c31ae974fbc382",
 | 
			
		||||
                "sha256:f5c7150ad32ba43a07c4479f40241756145a1f03b43480e058cfd862bf5041c7",
 | 
			
		||||
                "sha256:f6f824dc3bce0edab5f427efcfb1d63ee75b6fcb7282900ccaf925be84efb0fc",
 | 
			
		||||
                "sha256:fd8a250edc26254fe5b33be00402e6d287f562b6a5b2152dec302fa15bb3e997",
 | 
			
		||||
                "sha256:ffaa5c925128e29efbde7301d8ecaf35c8c60ffbcd6a1ffd3a552177c8e5e796"
 | 
			
		||||
            ],
 | 
			
		||||
            "version": "==1.14.4"
 | 
			
		||||
            "version": "==1.15.0"
 | 
			
		||||
        },
 | 
			
		||||
        "cryptography": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:0003a52a123602e1acee177dc90dd201f9bb1e73f24a070db7d36c588e8f5c7d",
 | 
			
		||||
                "sha256:0e85aaae861d0485eb5a79d33226dd6248d2a9f133b81532c8f5aae37de10ff7",
 | 
			
		||||
                "sha256:594a1db4511bc4d960571536abe21b4e5c3003e8750ab8365fafce71c5d86901",
 | 
			
		||||
                "sha256:69e836c9e5ff4373ce6d3ab311c1a2eed274793083858d3cd4c7d12ce20d5f9c",
 | 
			
		||||
                "sha256:788a3c9942df5e4371c199d10383f44a105d67d401fb4304178020142f020244",
 | 
			
		||||
                "sha256:7e177e4bea2de937a584b13645cab32f25e3d96fc0bc4a4cf99c27dc77682be6",
 | 
			
		||||
                "sha256:83d9d2dfec70364a74f4e7c70ad04d3ca2e6a08b703606993407bf46b97868c5",
 | 
			
		||||
                "sha256:84ef7a0c10c24a7773163f917f1cb6b4444597efd505a8aed0a22e8c4780f27e",
 | 
			
		||||
                "sha256:9e21301f7a1e7c03dbea73e8602905a4ebba641547a462b26dd03451e5769e7c",
 | 
			
		||||
                "sha256:9f6b0492d111b43de5f70052e24c1f0951cb9e6022188ebcb1cc3a3d301469b0",
 | 
			
		||||
                "sha256:a69bd3c68b98298f490e84519b954335154917eaab52cf582fa2c5c7efc6e812",
 | 
			
		||||
                "sha256:b4890d5fb9b7a23e3bf8abf5a8a7da8e228f1e97dc96b30b95685df840b6914a",
 | 
			
		||||
                "sha256:c366df0401d1ec4e548bebe8f91d55ebcc0ec3137900d214dd7aac8427ef3030",
 | 
			
		||||
                "sha256:dc42f645f8f3a489c3dd416730a514e7a91a59510ddaadc09d04224c098d3302"
 | 
			
		||||
                "sha256:0a817b961b46894c5ca8a66b599c745b9a3d9f822725221f0e0fe49dc043a3a3",
 | 
			
		||||
                "sha256:2d87cdcb378d3cfed944dac30596da1968f88fb96d7fc34fdae30a99054b2e31",
 | 
			
		||||
                "sha256:30ee1eb3ebe1644d1c3f183d115a8c04e4e603ed6ce8e394ed39eea4a98469ac",
 | 
			
		||||
                "sha256:391432971a66cfaf94b21c24ab465a4cc3e8bf4a939c1ca5c3e3a6e0abebdbcf",
 | 
			
		||||
                "sha256:39bdf8e70eee6b1c7b289ec6e5d84d49a6bfa11f8b8646b5b3dfe41219153316",
 | 
			
		||||
                "sha256:4caa4b893d8fad33cf1964d3e51842cd78ba87401ab1d2e44556826df849a8ca",
 | 
			
		||||
                "sha256:53e5c1dc3d7a953de055d77bef2ff607ceef7a2aac0353b5d630ab67f7423638",
 | 
			
		||||
                "sha256:596f3cd67e1b950bc372c33f1a28a0692080625592ea6392987dba7f09f17a94",
 | 
			
		||||
                "sha256:5d59a9d55027a8b88fd9fd2826c4392bd487d74bf628bb9d39beecc62a644c12",
 | 
			
		||||
                "sha256:6c0c021f35b421ebf5976abf2daacc47e235f8b6082d3396a2fe3ccd537ab173",
 | 
			
		||||
                "sha256:73bc2d3f2444bcfeac67dd130ff2ea598ea5f20b40e36d19821b4df8c9c5037b",
 | 
			
		||||
                "sha256:74d6c7e80609c0f4c2434b97b80c7f8fdfaa072ca4baab7e239a15d6d70ed73a",
 | 
			
		||||
                "sha256:7be0eec337359c155df191d6ae00a5e8bbb63933883f4f5dffc439dac5348c3f",
 | 
			
		||||
                "sha256:94ae132f0e40fe48f310bba63f477f14a43116f05ddb69d6fa31e93f05848ae2",
 | 
			
		||||
                "sha256:bb5829d027ff82aa872d76158919045a7c1e91fbf241aec32cb07956e9ebd3c9",
 | 
			
		||||
                "sha256:ca238ceb7ba0bdf6ce88c1b74a87bffcee5afbfa1e41e173b1ceb095b39add46",
 | 
			
		||||
                "sha256:ca28641954f767f9822c24e927ad894d45d5a1e501767599647259cbf030b903",
 | 
			
		||||
                "sha256:e0344c14c9cb89e76eb6a060e67980c9e35b3f36691e15e1b7a9e58a0a6c6dc3",
 | 
			
		||||
                "sha256:ebc15b1c22e55c4d5566e3ca4db8689470a0ca2babef8e3a9ee057a8b82ce4b1",
 | 
			
		||||
                "sha256:ec63da4e7e4a5f924b90af42eddf20b698a70e58d86a72d943857c4c6045b3ee"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'",
 | 
			
		||||
            "version": "==3.3.1"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==36.0.1"
 | 
			
		||||
        },
 | 
			
		||||
        "jinja2": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:03e47ad063331dd6a3f04a43eddca8a966a26ba0c5b7207a9a9e4e08f1b29419",
 | 
			
		||||
                "sha256:a6d58433de0ae800347cab1fa3043cebbabe8baa9d29e668f1c768cb87a333c6"
 | 
			
		||||
                "sha256:077ce6014f7b40d03b47d1f1ca4b0fc8328a692bd284016f806ed0eaca390ad8",
 | 
			
		||||
                "sha256:611bb273cd68f3b993fabdc4064fc858c5b47a973cb5aa7999ec1ba405c87cd7"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4'",
 | 
			
		||||
            "version": "==2.11.3"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==3.0.3"
 | 
			
		||||
        },
 | 
			
		||||
        "markupsafe": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:00bc623926325b26bb9605ae9eae8a215691f33cae5df11ca5424f06f2d1f473",
 | 
			
		||||
                "sha256:09027a7803a62ca78792ad89403b1b7a73a01c8cb65909cd876f7fcebd79b161",
 | 
			
		||||
                "sha256:09c4b7f37d6c648cb13f9230d847adf22f8171b1ccc4d5682398e77f40309235",
 | 
			
		||||
                "sha256:1027c282dad077d0bae18be6794e6b6b8c91d58ed8a8d89a89d59693b9131db5",
 | 
			
		||||
                "sha256:13d3144e1e340870b25e7b10b98d779608c02016d5184cfb9927a9f10c689f42",
 | 
			
		||||
                "sha256:195d7d2c4fbb0ee8139a6cf67194f3973a6b3042d742ebe0a9ed36d8b6f0c07f",
 | 
			
		||||
                "sha256:22c178a091fc6630d0d045bdb5992d2dfe14e3259760e713c490da5323866c39",
 | 
			
		||||
                "sha256:24982cc2533820871eba85ba648cd53d8623687ff11cbb805be4ff7b4c971aff",
 | 
			
		||||
                "sha256:29872e92839765e546828bb7754a68c418d927cd064fd4708fab9fe9c8bb116b",
 | 
			
		||||
                "sha256:2beec1e0de6924ea551859edb9e7679da6e4870d32cb766240ce17e0a0ba2014",
 | 
			
		||||
                "sha256:3b8a6499709d29c2e2399569d96719a1b21dcd94410a586a18526b143ec8470f",
 | 
			
		||||
                "sha256:43a55c2930bbc139570ac2452adf3d70cdbb3cfe5912c71cdce1c2c6bbd9c5d1",
 | 
			
		||||
                "sha256:46c99d2de99945ec5cb54f23c8cd5689f6d7177305ebff350a58ce5f8de1669e",
 | 
			
		||||
                "sha256:500d4957e52ddc3351cabf489e79c91c17f6e0899158447047588650b5e69183",
 | 
			
		||||
                "sha256:535f6fc4d397c1563d08b88e485c3496cf5784e927af890fb3c3aac7f933ec66",
 | 
			
		||||
                "sha256:596510de112c685489095da617b5bcbbac7dd6384aeebeda4df6025d0256a81b",
 | 
			
		||||
                "sha256:62fe6c95e3ec8a7fad637b7f3d372c15ec1caa01ab47926cfdf7a75b40e0eac1",
 | 
			
		||||
                "sha256:6788b695d50a51edb699cb55e35487e430fa21f1ed838122d722e0ff0ac5ba15",
 | 
			
		||||
                "sha256:6dd73240d2af64df90aa7c4e7481e23825ea70af4b4922f8ede5b9e35f78a3b1",
 | 
			
		||||
                "sha256:6f1e273a344928347c1290119b493a1f0303c52f5a5eae5f16d74f48c15d4a85",
 | 
			
		||||
                "sha256:6fffc775d90dcc9aed1b89219549b329a9250d918fd0b8fa8d93d154918422e1",
 | 
			
		||||
                "sha256:717ba8fe3ae9cc0006d7c451f0bb265ee07739daf76355d06366154ee68d221e",
 | 
			
		||||
                "sha256:79855e1c5b8da654cf486b830bd42c06e8780cea587384cf6545b7d9ac013a0b",
 | 
			
		||||
                "sha256:7c1699dfe0cf8ff607dbdcc1e9b9af1755371f92a68f706051cc8c37d447c905",
 | 
			
		||||
                "sha256:7fed13866cf14bba33e7176717346713881f56d9d2bcebab207f7a036f41b850",
 | 
			
		||||
                "sha256:84dee80c15f1b560d55bcfe6d47b27d070b4681c699c572af2e3c7cc90a3b8e0",
 | 
			
		||||
                "sha256:88e5fcfb52ee7b911e8bb6d6aa2fd21fbecc674eadd44118a9cc3863f938e735",
 | 
			
		||||
                "sha256:8defac2f2ccd6805ebf65f5eeb132adcf2ab57aa11fdf4c0dd5169a004710e7d",
 | 
			
		||||
                "sha256:98bae9582248d6cf62321dcb52aaf5d9adf0bad3b40582925ef7c7f0ed85fceb",
 | 
			
		||||
                "sha256:98c7086708b163d425c67c7a91bad6e466bb99d797aa64f965e9d25c12111a5e",
 | 
			
		||||
                "sha256:9add70b36c5666a2ed02b43b335fe19002ee5235efd4b8a89bfcf9005bebac0d",
 | 
			
		||||
                "sha256:9bf40443012702a1d2070043cb6291650a0841ece432556f784f004937f0f32c",
 | 
			
		||||
                "sha256:a6a744282b7718a2a62d2ed9d993cad6f5f585605ad352c11de459f4108df0a1",
 | 
			
		||||
                "sha256:acf08ac40292838b3cbbb06cfe9b2cb9ec78fce8baca31ddb87aaac2e2dc3bc2",
 | 
			
		||||
                "sha256:ade5e387d2ad0d7ebf59146cc00c8044acbd863725f887353a10df825fc8ae21",
 | 
			
		||||
                "sha256:b00c1de48212e4cc9603895652c5c410df699856a2853135b3967591e4beebc2",
 | 
			
		||||
                "sha256:b1282f8c00509d99fef04d8ba936b156d419be841854fe901d8ae224c59f0be5",
 | 
			
		||||
                "sha256:b1dba4527182c95a0db8b6060cc98ac49b9e2f5e64320e2b56e47cb2831978c7",
 | 
			
		||||
                "sha256:b2051432115498d3562c084a49bba65d97cf251f5a331c64a12ee7e04dacc51b",
 | 
			
		||||
                "sha256:b7d644ddb4dbd407d31ffb699f1d140bc35478da613b441c582aeb7c43838dd8",
 | 
			
		||||
                "sha256:ba59edeaa2fc6114428f1637ffff42da1e311e29382d81b339c1817d37ec93c6",
 | 
			
		||||
                "sha256:bf5aa3cbcfdf57fa2ee9cd1822c862ef23037f5c832ad09cfea57fa846dec193",
 | 
			
		||||
                "sha256:c8716a48d94b06bb3b2524c2b77e055fb313aeb4ea620c8dd03a105574ba704f",
 | 
			
		||||
                "sha256:caabedc8323f1e93231b52fc32bdcde6db817623d33e100708d9a68e1f53b26b",
 | 
			
		||||
                "sha256:cd5df75523866410809ca100dc9681e301e3c27567cf498077e8551b6d20e42f",
 | 
			
		||||
                "sha256:cdb132fc825c38e1aeec2c8aa9338310d29d337bebbd7baa06889d09a60a1fa2",
 | 
			
		||||
                "sha256:d53bc011414228441014aa71dbec320c66468c1030aae3a6e29778a3382d96e5",
 | 
			
		||||
                "sha256:d73a845f227b0bfe8a7455ee623525ee656a9e2e749e4742706d80a6065d5e2c",
 | 
			
		||||
                "sha256:d9be0ba6c527163cbed5e0857c451fcd092ce83947944d6c14bc95441203f032",
 | 
			
		||||
                "sha256:e249096428b3ae81b08327a63a485ad0878de3fb939049038579ac0ef61e17e7",
 | 
			
		||||
                "sha256:e8313f01ba26fbbe36c7be1966a7b7424942f670f38e666995b88d012765b9be",
 | 
			
		||||
                "sha256:feb7b34d6325451ef96bc0e36e1a6c0c1c64bc1fbec4b854f4529e51887b1621"
 | 
			
		||||
                "sha256:01a9b8ea66f1658938f65b93a85ebe8bc016e6769611be228d797c9d998dd298",
 | 
			
		||||
                "sha256:023cb26ec21ece8dc3907c0e8320058b2e0cb3c55cf9564da612bc325bed5e64",
 | 
			
		||||
                "sha256:0446679737af14f45767963a1a9ef7620189912317d095f2d9ffa183a4d25d2b",
 | 
			
		||||
                "sha256:04635854b943835a6ea959e948d19dcd311762c5c0c6e1f0e16ee57022669194",
 | 
			
		||||
                "sha256:0717a7390a68be14b8c793ba258e075c6f4ca819f15edfc2a3a027c823718567",
 | 
			
		||||
                "sha256:0955295dd5eec6cb6cc2fe1698f4c6d84af2e92de33fbcac4111913cd100a6ff",
 | 
			
		||||
                "sha256:0d4b31cc67ab36e3392bbf3862cfbadac3db12bdd8b02a2731f509ed5b829724",
 | 
			
		||||
                "sha256:10f82115e21dc0dfec9ab5c0223652f7197feb168c940f3ef61563fc2d6beb74",
 | 
			
		||||
                "sha256:168cd0a3642de83558a5153c8bd34f175a9a6e7f6dc6384b9655d2697312a646",
 | 
			
		||||
                "sha256:1d609f577dc6e1aa17d746f8bd3c31aa4d258f4070d61b2aa5c4166c1539de35",
 | 
			
		||||
                "sha256:1f2ade76b9903f39aa442b4aadd2177decb66525062db244b35d71d0ee8599b6",
 | 
			
		||||
                "sha256:20dca64a3ef2d6e4d5d615a3fd418ad3bde77a47ec8a23d984a12b5b4c74491a",
 | 
			
		||||
                "sha256:2a7d351cbd8cfeb19ca00de495e224dea7e7d919659c2841bbb7f420ad03e2d6",
 | 
			
		||||
                "sha256:2d7d807855b419fc2ed3e631034685db6079889a1f01d5d9dac950f764da3dad",
 | 
			
		||||
                "sha256:2ef54abee730b502252bcdf31b10dacb0a416229b72c18b19e24a4509f273d26",
 | 
			
		||||
                "sha256:36bc903cbb393720fad60fc28c10de6acf10dc6cc883f3e24ee4012371399a38",
 | 
			
		||||
                "sha256:37205cac2a79194e3750b0af2a5720d95f786a55ce7df90c3af697bfa100eaac",
 | 
			
		||||
                "sha256:3c112550557578c26af18a1ccc9e090bfe03832ae994343cfdacd287db6a6ae7",
 | 
			
		||||
                "sha256:3dd007d54ee88b46be476e293f48c85048603f5f516008bee124ddd891398ed6",
 | 
			
		||||
                "sha256:4296f2b1ce8c86a6aea78613c34bb1a672ea0e3de9c6ba08a960efe0b0a09047",
 | 
			
		||||
                "sha256:47ab1e7b91c098ab893b828deafa1203de86d0bc6ab587b160f78fe6c4011f75",
 | 
			
		||||
                "sha256:49e3ceeabbfb9d66c3aef5af3a60cc43b85c33df25ce03d0031a608b0a8b2e3f",
 | 
			
		||||
                "sha256:4dc8f9fb58f7364b63fd9f85013b780ef83c11857ae79f2feda41e270468dd9b",
 | 
			
		||||
                "sha256:4efca8f86c54b22348a5467704e3fec767b2db12fc39c6d963168ab1d3fc9135",
 | 
			
		||||
                "sha256:53edb4da6925ad13c07b6d26c2a852bd81e364f95301c66e930ab2aef5b5ddd8",
 | 
			
		||||
                "sha256:5855f8438a7d1d458206a2466bf82b0f104a3724bf96a1c781ab731e4201731a",
 | 
			
		||||
                "sha256:594c67807fb16238b30c44bdf74f36c02cdf22d1c8cda91ef8a0ed8dabf5620a",
 | 
			
		||||
                "sha256:5b6d930f030f8ed98e3e6c98ffa0652bdb82601e7a016ec2ab5d7ff23baa78d1",
 | 
			
		||||
                "sha256:5bb28c636d87e840583ee3adeb78172efc47c8b26127267f54a9c0ec251d41a9",
 | 
			
		||||
                "sha256:60bf42e36abfaf9aff1f50f52644b336d4f0a3fd6d8a60ca0d054ac9f713a864",
 | 
			
		||||
                "sha256:611d1ad9a4288cf3e3c16014564df047fe08410e628f89805e475368bd304914",
 | 
			
		||||
                "sha256:6300b8454aa6930a24b9618fbb54b5a68135092bc666f7b06901f897fa5c2fee",
 | 
			
		||||
                "sha256:63f3268ba69ace99cab4e3e3b5840b03340efed0948ab8f78d2fd87ee5442a4f",
 | 
			
		||||
                "sha256:6557b31b5e2c9ddf0de32a691f2312a32f77cd7681d8af66c2692efdbef84c18",
 | 
			
		||||
                "sha256:693ce3f9e70a6cf7d2fb9e6c9d8b204b6b39897a2c4a1aa65728d5ac97dcc1d8",
 | 
			
		||||
                "sha256:6a7fae0dd14cf60ad5ff42baa2e95727c3d81ded453457771d02b7d2b3f9c0c2",
 | 
			
		||||
                "sha256:6c4ca60fa24e85fe25b912b01e62cb969d69a23a5d5867682dd3e80b5b02581d",
 | 
			
		||||
                "sha256:6fcf051089389abe060c9cd7caa212c707e58153afa2c649f00346ce6d260f1b",
 | 
			
		||||
                "sha256:7d91275b0245b1da4d4cfa07e0faedd5b0812efc15b702576d103293e252af1b",
 | 
			
		||||
                "sha256:89c687013cb1cd489a0f0ac24febe8c7a666e6e221b783e53ac50ebf68e45d86",
 | 
			
		||||
                "sha256:8d206346619592c6200148b01a2142798c989edcb9c896f9ac9722a99d4e77e6",
 | 
			
		||||
                "sha256:905fec760bd2fa1388bb5b489ee8ee5f7291d692638ea5f67982d968366bef9f",
 | 
			
		||||
                "sha256:97383d78eb34da7e1fa37dd273c20ad4320929af65d156e35a5e2d89566d9dfb",
 | 
			
		||||
                "sha256:984d76483eb32f1bcb536dc27e4ad56bba4baa70be32fa87152832cdd9db0833",
 | 
			
		||||
                "sha256:99df47edb6bda1249d3e80fdabb1dab8c08ef3975f69aed437cb69d0a5de1e28",
 | 
			
		||||
                "sha256:9f02365d4e99430a12647f09b6cc8bab61a6564363f313126f775eb4f6ef798e",
 | 
			
		||||
                "sha256:a30e67a65b53ea0a5e62fe23682cfe22712e01f453b95233b25502f7c61cb415",
 | 
			
		||||
                "sha256:ab3ef638ace319fa26553db0624c4699e31a28bb2a835c5faca8f8acf6a5a902",
 | 
			
		||||
                "sha256:aca6377c0cb8a8253e493c6b451565ac77e98c2951c45f913e0b52facdcff83f",
 | 
			
		||||
                "sha256:add36cb2dbb8b736611303cd3bfcee00afd96471b09cda130da3581cbdc56a6d",
 | 
			
		||||
                "sha256:b2f4bf27480f5e5e8ce285a8c8fd176c0b03e93dcc6646477d4630e83440c6a9",
 | 
			
		||||
                "sha256:b7f2d075102dc8c794cbde1947378051c4e5180d52d276987b8d28a3bd58c17d",
 | 
			
		||||
                "sha256:baa1a4e8f868845af802979fcdbf0bb11f94f1cb7ced4c4b8a351bb60d108145",
 | 
			
		||||
                "sha256:be98f628055368795d818ebf93da628541e10b75b41c559fdf36d104c5787066",
 | 
			
		||||
                "sha256:bf5d821ffabf0ef3533c39c518f3357b171a1651c1ff6827325e4489b0e46c3c",
 | 
			
		||||
                "sha256:c47adbc92fc1bb2b3274c4b3a43ae0e4573d9fbff4f54cd484555edbf030baf1",
 | 
			
		||||
                "sha256:cdfba22ea2f0029c9261a4bd07e830a8da012291fbe44dc794e488b6c9bb353a",
 | 
			
		||||
                "sha256:d6c7ebd4e944c85e2c3421e612a7057a2f48d478d79e61800d81468a8d842207",
 | 
			
		||||
                "sha256:d7f9850398e85aba693bb640262d3611788b1f29a79f0c93c565694658f4071f",
 | 
			
		||||
                "sha256:d8446c54dc28c01e5a2dbac5a25f071f6653e6e40f3a8818e8b45d790fe6ef53",
 | 
			
		||||
                "sha256:deb993cacb280823246a026e3b2d81c493c53de6acfd5e6bfe31ab3402bb37dd",
 | 
			
		||||
                "sha256:e0f138900af21926a02425cf736db95be9f4af72ba1bb21453432a07f6082134",
 | 
			
		||||
                "sha256:e9936f0b261d4df76ad22f8fee3ae83b60d7c3e871292cd42f40b81b70afae85",
 | 
			
		||||
                "sha256:f0567c4dc99f264f49fe27da5f735f414c4e7e7dd850cfd8e69f0862d7c74ea9",
 | 
			
		||||
                "sha256:f5653a225f31e113b152e56f154ccbe59eeb1c7487b39b9d9f9cdb58e6c79dc5",
 | 
			
		||||
                "sha256:f826e31d18b516f653fe296d967d700fddad5901ae07c622bb3705955e1faa94",
 | 
			
		||||
                "sha256:f8ba0e8349a38d3001fae7eadded3f6606f0da5d748ee53cc1dab1d6527b9509",
 | 
			
		||||
                "sha256:f9081981fe268bd86831e5c75f7de206ef275defcb82bc70740ae6dc507aee51",
 | 
			
		||||
                "sha256:fa130dd50c57d53368c9d59395cb5526eda596d3ffe36666cd81a44d56e48872"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'",
 | 
			
		||||
            "version": "==1.1.1"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==2.0.1"
 | 
			
		||||
        },
 | 
			
		||||
        "packaging": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:5b327ac1320dc863dca72f4514ecc086f31186744b84a230374cc1fd776feae5",
 | 
			
		||||
                "sha256:67714da7f7bc052e064859c05c595155bd1ee9f69f76557e21f051443c20947a"
 | 
			
		||||
                "sha256:dd47c42927d89ab911e606518907cc2d3a1f38bbd026385970643f9c5b8ecfeb",
 | 
			
		||||
                "sha256:ef103e05f519cdc783ae24ea4e2e0f508a9c99b2d4969652eed6a2e1ea5bd522"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'",
 | 
			
		||||
            "version": "==20.9"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==21.3"
 | 
			
		||||
        },
 | 
			
		||||
        "pycparser": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:2d475327684562c3a96cc71adf7dc8c4f0565175cf86b6d7a404ff4c771f15f0",
 | 
			
		||||
                "sha256:7582ad22678f0fcd81102833f60ef8d0e57288b6b5fb00323d101be910e35705"
 | 
			
		||||
                "sha256:8ee45429555515e1f6b185e78100aea234072576aa43ab53aefcae078162fca9",
 | 
			
		||||
                "sha256:e644fdec12f7872f86c58ff790da456218b10f863970249516d60a5eaca77206"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'",
 | 
			
		||||
            "version": "==2.20"
 | 
			
		||||
            "version": "==2.21"
 | 
			
		||||
        },
 | 
			
		||||
        "pyparsing": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:c203ec8783bf771a155b207279b9bccb8dea02d8f0c9e5f8ead507bc3246ecc1",
 | 
			
		||||
                "sha256:ef9d7589ef3c200abe66653d3f1ab1033c3c419ae9b9bdb1240a85b024efc88b"
 | 
			
		||||
                "sha256:04ff808a5b90911829c55c4e26f75fa5ca8a2f5f36aa3a51f68e27033341d3e4",
 | 
			
		||||
                "sha256:d9bdec0013ef1eb5a84ab39a3b3868911598afa494f5faa038647101504e2b81"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.6' and python_version not in '3.0, 3.1, 3.2, 3.3'",
 | 
			
		||||
            "version": "==2.4.7"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==3.0.6"
 | 
			
		||||
        },
 | 
			
		||||
        "pyyaml": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:08682f6b72c722394747bddaf0aa62277e02557c0fd1c42cb853016a38f8dedf",
 | 
			
		||||
                "sha256:0f5f5786c0e09baddcd8b4b45f20a7b5d61a7e7e99846e3c799b05c7c53fa696",
 | 
			
		||||
                "sha256:129def1b7c1bf22faffd67b8f3724645203b79d8f4cc81f674654d9902cb4393",
 | 
			
		||||
                "sha256:294db365efa064d00b8d1ef65d8ea2c3426ac366c0c4368d930bf1c5fb497f77",
 | 
			
		||||
                "sha256:3b2b1824fe7112845700f815ff6a489360226a5609b96ec2190a45e62a9fc922",
 | 
			
		||||
                "sha256:3bd0e463264cf257d1ffd2e40223b197271046d09dadf73a0fe82b9c1fc385a5",
 | 
			
		||||
                "sha256:4465124ef1b18d9ace298060f4eccc64b0850899ac4ac53294547536533800c8",
 | 
			
		||||
                "sha256:49d4cdd9065b9b6e206d0595fee27a96b5dd22618e7520c33204a4a3239d5b10",
 | 
			
		||||
                "sha256:4e0583d24c881e14342eaf4ec5fbc97f934b999a6828693a99157fde912540cc",
 | 
			
		||||
                "sha256:5accb17103e43963b80e6f837831f38d314a0495500067cb25afab2e8d7a4018",
 | 
			
		||||
                "sha256:607774cbba28732bfa802b54baa7484215f530991055bb562efbed5b2f20a45e",
 | 
			
		||||
                "sha256:6c78645d400265a062508ae399b60b8c167bf003db364ecb26dcab2bda048253",
 | 
			
		||||
                "sha256:74c1485f7707cf707a7aef42ef6322b8f97921bd89be2ab6317fd782c2d53183",
 | 
			
		||||
                "sha256:8c1be557ee92a20f184922c7b6424e8ab6691788e6d86137c5d93c1a6ec1b8fb",
 | 
			
		||||
                "sha256:bb4191dfc9306777bc594117aee052446b3fa88737cd13b7188d0e7aa8162185",
 | 
			
		||||
                "sha256:c20cfa2d49991c8b4147af39859b167664f2ad4561704ee74c1de03318e898db",
 | 
			
		||||
                "sha256:d2d9808ea7b4af864f35ea216be506ecec180628aced0704e34aca0b040ffe46",
 | 
			
		||||
                "sha256:dd5de0646207f053eb0d6c74ae45ba98c3395a571a2891858e87df7c9b9bd51b",
 | 
			
		||||
                "sha256:e1d4970ea66be07ae37a3c2e48b5ec63f7ba6804bdddfdbd3cfd954d25a82e63",
 | 
			
		||||
                "sha256:e4fac90784481d221a8e4b1162afa7c47ed953be40d31ab4629ae917510051df",
 | 
			
		||||
                "sha256:fa5ae20527d8e831e8230cbffd9f8fe952815b2b7dae6ffec25318803a7528fc"
 | 
			
		||||
                "sha256:0283c35a6a9fbf047493e3a0ce8d79ef5030852c51e9d911a27badfde0605293",
 | 
			
		||||
                "sha256:055d937d65826939cb044fc8c9b08889e8c743fdc6a32b33e2390f66013e449b",
 | 
			
		||||
                "sha256:07751360502caac1c067a8132d150cf3d61339af5691fe9e87803040dbc5db57",
 | 
			
		||||
                "sha256:0b4624f379dab24d3725ffde76559cff63d9ec94e1736b556dacdfebe5ab6d4b",
 | 
			
		||||
                "sha256:0ce82d761c532fe4ec3f87fc45688bdd3a4c1dc5e0b4a19814b9009a29baefd4",
 | 
			
		||||
                "sha256:1e4747bc279b4f613a09eb64bba2ba602d8a6664c6ce6396a4d0cd413a50ce07",
 | 
			
		||||
                "sha256:213c60cd50106436cc818accf5baa1aba61c0189ff610f64f4a3e8c6726218ba",
 | 
			
		||||
                "sha256:231710d57adfd809ef5d34183b8ed1eeae3f76459c18fb4a0b373ad56bedcdd9",
 | 
			
		||||
                "sha256:277a0ef2981ca40581a47093e9e2d13b3f1fbbeffae064c1d21bfceba2030287",
 | 
			
		||||
                "sha256:2cd5df3de48857ed0544b34e2d40e9fac445930039f3cfe4bcc592a1f836d513",
 | 
			
		||||
                "sha256:40527857252b61eacd1d9af500c3337ba8deb8fc298940291486c465c8b46ec0",
 | 
			
		||||
                "sha256:473f9edb243cb1935ab5a084eb238d842fb8f404ed2193a915d1784b5a6b5fc0",
 | 
			
		||||
                "sha256:48c346915c114f5fdb3ead70312bd042a953a8ce5c7106d5bfb1a5254e47da92",
 | 
			
		||||
                "sha256:50602afada6d6cbfad699b0c7bb50d5ccffa7e46a3d738092afddc1f9758427f",
 | 
			
		||||
                "sha256:68fb519c14306fec9720a2a5b45bc9f0c8d1b9c72adf45c37baedfcd949c35a2",
 | 
			
		||||
                "sha256:77f396e6ef4c73fdc33a9157446466f1cff553d979bd00ecb64385760c6babdc",
 | 
			
		||||
                "sha256:819b3830a1543db06c4d4b865e70ded25be52a2e0631ccd2f6a47a2822f2fd7c",
 | 
			
		||||
                "sha256:897b80890765f037df3403d22bab41627ca8811ae55e9a722fd0392850ec4d86",
 | 
			
		||||
                "sha256:98c4d36e99714e55cfbaaee6dd5badbc9a1ec339ebfc3b1f52e293aee6bb71a4",
 | 
			
		||||
                "sha256:9df7ed3b3d2e0ecfe09e14741b857df43adb5a3ddadc919a2d94fbdf78fea53c",
 | 
			
		||||
                "sha256:9fa600030013c4de8165339db93d182b9431076eb98eb40ee068700c9c813e34",
 | 
			
		||||
                "sha256:a80a78046a72361de73f8f395f1f1e49f956c6be882eed58505a15f3e430962b",
 | 
			
		||||
                "sha256:b3d267842bf12586ba6c734f89d1f5b871df0273157918b0ccefa29deb05c21c",
 | 
			
		||||
                "sha256:b5b9eccad747aabaaffbc6064800670f0c297e52c12754eb1d976c57e4f74dcb",
 | 
			
		||||
                "sha256:c5687b8d43cf58545ade1fe3e055f70eac7a5a1a0bf42824308d868289a95737",
 | 
			
		||||
                "sha256:cba8c411ef271aa037d7357a2bc8f9ee8b58b9965831d9e51baf703280dc73d3",
 | 
			
		||||
                "sha256:d15a181d1ecd0d4270dc32edb46f7cb7733c7c508857278d3d378d14d606db2d",
 | 
			
		||||
                "sha256:d4db7c7aef085872ef65a8fd7d6d09a14ae91f691dec3e87ee5ee0539d516f53",
 | 
			
		||||
                "sha256:d4eccecf9adf6fbcc6861a38015c2a64f38b9d94838ac1810a9023a0609e1b78",
 | 
			
		||||
                "sha256:d67d839ede4ed1b28a4e8909735fc992a923cdb84e618544973d7dfc71540803",
 | 
			
		||||
                "sha256:daf496c58a8c52083df09b80c860005194014c3698698d1a57cbcfa182142a3a",
 | 
			
		||||
                "sha256:e61ceaab6f49fb8bdfaa0f92c4b57bcfbea54c09277b1b4f7ac376bfb7a7c174",
 | 
			
		||||
                "sha256:f84fbc98b019fef2ee9a1cb3ce93e3187a6df0b2538a651bfb890254ba9f90b5"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3, 3.4, 3.5'",
 | 
			
		||||
            "version": "==5.4.1"
 | 
			
		||||
            "markers": "python_version >= '3.6'",
 | 
			
		||||
            "version": "==6.0"
 | 
			
		||||
        },
 | 
			
		||||
        "six": {
 | 
			
		||||
        "resolvelib": {
 | 
			
		||||
            "hashes": [
 | 
			
		||||
                "sha256:30639c035cdb23534cd4aa2dd52c3bf48f06e5f4a941509c8bafd8ce11080259",
 | 
			
		||||
                "sha256:8b74bedcbbbaca38ff6d7491d76f2b06b3592611af620f8426e82dddb04a5ced"
 | 
			
		||||
                "sha256:8113ae3ed6d33c6be0bcbf03ffeb06c0995c099b7b8aaa5ddf2e9b3b3df4e915",
 | 
			
		||||
                "sha256:9b9b80d5c60e4c2a8b7fbf0712c3449dc01d74e215632e5199850c9eca687628"
 | 
			
		||||
            ],
 | 
			
		||||
            "markers": "python_version >= '2.7' and python_version not in '3.0, 3.1, 3.2, 3.3'",
 | 
			
		||||
            "version": "==1.15.0"
 | 
			
		||||
            "version": "==0.5.4"
 | 
			
		||||
        }
 | 
			
		||||
    },
 | 
			
		||||
    "develop": {}
 | 
			
		||||
 
 | 
			
		||||
@@ -4,7 +4,7 @@ Ansible playbook for base and initial configuration of the web server hosting my
 | 
			
		||||
## Assumptions
 | 
			
		||||
Before you can run this, a few things are assumed:
 | 
			
		||||
 | 
			
		||||
- You have a clean, minimal Ubuntu 18.04, Debian 10, or Ubuntu 20.04 host up and running
 | 
			
		||||
- You have a clean, minimal Ubuntu 18.04/20.04 or Debian 10/11 host up and running
 | 
			
		||||
- Python 3 is installed on the remote server (requirement of Ansible)
 | 
			
		||||
- You have a user account with password-less SSH access to the machine
 | 
			
		||||
- You have sudo privileges on the remote host
 | 
			
		||||
@@ -25,7 +25,7 @@ Once you've satisfied the the above assumptions, you can execute:
 | 
			
		||||
- Switch from `cron-apt` to [`unattended-upgrades`](https://wiki.debian.org/UnattendedUpgrades)
 | 
			
		||||
 | 
			
		||||
## License
 | 
			
		||||
Copyright (C) 2014–2020 Alan Orth
 | 
			
		||||
Copyright (C) 2014–2021 Alan Orth
 | 
			
		||||
 | 
			
		||||
The contents of this repository are free software: you can redistribute
 | 
			
		||||
it and/or modify it under the terms of the GNU General Public License
 | 
			
		||||
 
 | 
			
		||||
@@ -5,6 +5,7 @@ inventory=hosts
 | 
			
		||||
# instead of using --ask-vault-pass
 | 
			
		||||
ask_vault_pass=True
 | 
			
		||||
remote_user = provisioning
 | 
			
		||||
interpreter_python=auto
 | 
			
		||||
 | 
			
		||||
ansible_managed = This file is managed by Ansible.%n
 | 
			
		||||
  template: {file}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										8
									
								
								group_vars/web
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										8
									
								
								group_vars/web
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,8 @@
 | 
			
		||||
---
 | 
			
		||||
# file: group_vars/web
 | 
			
		||||
 | 
			
		||||
# all hosts run fail2ban with the sshd filter, but some can use other filters
 | 
			
		||||
extra_fail2ban_filters:
 | 
			
		||||
  - nginx
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
@@ -1,87 +0,0 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
37356463383831623061363666396235346361663734326234323239633332383431656534636337
 | 
			
		||||
3238613566336363636235393535373330363562333135630a626531343430396666323139633833
 | 
			
		||||
37656533353537393335393966323637326335666134613633643330313334383237383736623637
 | 
			
		||||
6533343338396536640a376466633436643162393533646464343930346665616165613835373630
 | 
			
		||||
66353037653339633038353033316463393234313630646138636633643066653636343739383730
 | 
			
		||||
65343161306339343931323737336531646131363034343163366137616231363638313330343365
 | 
			
		||||
31663932343436313364326331373733373830646637313733323335306161626135616438656363
 | 
			
		||||
32623333646637633636316139613234613232393462306364633966666639623231643735663266
 | 
			
		||||
35396266313936326532383139346361626532323263633662373139363638303961616638636535
 | 
			
		||||
65343862623865386436643930353834323566356164386432373434336536363262356638313333
 | 
			
		||||
64626633353565303538353634626438363131633164636263643938386538323932346337343730
 | 
			
		||||
31336266343532306531626234323962353930343333656436356436343666336335633233386462
 | 
			
		||||
34623332393734633761303762306336656232326533313131316331326639376338393437363834
 | 
			
		||||
32663766633037316266373064376638643237343434356166613862383963633231353531646432
 | 
			
		||||
36393438653234326330316438333862396163383231623034383963336435393533393263653739
 | 
			
		||||
38373764373034313231373536653233666230333437626431383161346636376434383135393434
 | 
			
		||||
30353361343136663135356536316630643163613930306363343830323932393635343936396535
 | 
			
		||||
38366638353737336637356237646332353438303632396238356364343464323064373031656331
 | 
			
		||||
31346134323965646336666336303835326463656339356131613633336539613234653332353539
 | 
			
		||||
35613362653335663863626532363433663634393036373462663833636333646661643865353533
 | 
			
		||||
39376535313635373434633466643135323762613539366135376536653761303134303964343534
 | 
			
		||||
65333934396638373239646339343732623139303037336133363533653330383261383437393061
 | 
			
		||||
37336334363237333437633664313637366566396232336337303235366337616530333261356662
 | 
			
		||||
39666531653762326364353534623431333530653935316161383535663762636136316239336233
 | 
			
		||||
35373962623934633663656337306439616431316165666563336532373135323566386431303733
 | 
			
		||||
36313264323066653164346338653433393337623666646162383666303930613939396662373965
 | 
			
		||||
38653863623935336632666366373764383136376163663137313234663761343066336235626232
 | 
			
		||||
35303532376537643663653431323830623364623362346437396664386363396632646364666130
 | 
			
		||||
62663265363334383663626661363632646432393463373564396633393235353434636437623261
 | 
			
		||||
30323866636332356136396662363930613961613961343963313733343033616539316131323262
 | 
			
		||||
65666665663731636633623464353430623135373430313065626438396363366335363466316132
 | 
			
		||||
64353730383761386563353133396262366265343637643931643565386461303138613565303239
 | 
			
		||||
37646339316366316431663237653230346464643433376639356462643133643234386131613965
 | 
			
		||||
66333831663832326131343134633231636633373735333634663861393531633738366136356130
 | 
			
		||||
38653534666662303539353534636537343665366231346565376437313037646162663365666630
 | 
			
		||||
33366631653530326234326333623333346535343362666263376561333334633533356264393637
 | 
			
		||||
64633864616430653663366133343962376233656562643335633336326335626664653861323334
 | 
			
		||||
65653864323062616234343636633435396332636635653266353032623637356133383538383034
 | 
			
		||||
36383936666238333366386637313434656332626266346439346566666537623039323936303936
 | 
			
		||||
62353130663632636636623466326663623639313433353766346230383138323461643962666562
 | 
			
		||||
65646234346631613139393265666663663537323236383832373532393662643566636164653364
 | 
			
		||||
39636133613937393433636231626238386463376434666166643662313661663635356436636165
 | 
			
		||||
38333830313638643863373162636530346433613366613437643932383035643464363732663633
 | 
			
		||||
38633065366638656635356462393935383665386532633936366437333233316563366231393935
 | 
			
		||||
32393736343365383164346634326336373436386630386630616436373139646531353038333562
 | 
			
		||||
39646132643332373563613664303931633735656135376561646166343934396130343834653461
 | 
			
		||||
62343662386239313731336538393430316263333966306530616161633763306331633834323633
 | 
			
		||||
35633237333136366439376666636461356131663830323832646462653035643561396337633362
 | 
			
		||||
64323532663637323966663262353266316361353931333738323762656532343165626266653035
 | 
			
		||||
36353462306361383233303464353766323466393862313037386139326231656230343630616139
 | 
			
		||||
34626533323065646636643736323535356461623063663262656562333466666634376239356633
 | 
			
		||||
38373362363030346434316261643236363337663237323032623339393936303130393662666434
 | 
			
		||||
33386134386633623930376334333466666137356432636131373562306533333836353332316136
 | 
			
		||||
63653533336232336632353465373263363037313933663131633763343366663034353364373661
 | 
			
		||||
63333166306332663837313334623231653561363964306337353564326266353366343538366433
 | 
			
		||||
63383335336566366564333735383337353765613035383135616135653662346133333338303730
 | 
			
		||||
36303334623335613836333938646366376634353664633731666235346638346662656634393631
 | 
			
		||||
35396262323939393562306530323763353939363264666331373266363937653063366138636364
 | 
			
		||||
36623835383961336331303439613731633734343135323938306263363637616235336461333732
 | 
			
		||||
65303636623766313038356266363666316665343832623662643263623233356232333062333933
 | 
			
		||||
65373763376430366565363161333330376138313130363534623364653434616438363732643333
 | 
			
		||||
61336631653762613231373236613164623566663730396163383136366430353439346637623965
 | 
			
		||||
39356138633037313165333034633234353666646132656532386332393962626239383633383833
 | 
			
		||||
64396430343535346438623233326632663839336233316336383261346330353739633331396362
 | 
			
		||||
65643161396430646436376636613061656566623038633665623938656232633665633365613837
 | 
			
		||||
36386633313032306238373063346662333539313931366232323931613165343639666437386630
 | 
			
		||||
63343766633336346632393231303566323562373236656135366135376262613163646235646635
 | 
			
		||||
31356264393231353335363331663666623832643638653064366438373063623462333631663631
 | 
			
		||||
32356664663332356538636462383364633036303733393161366565393361363530626431623532
 | 
			
		||||
34303538653032313138373339663833613637356364376561316535643238356633356130376665
 | 
			
		||||
37643231333037626164663634383666323333316235353832333335393262366235613461623166
 | 
			
		||||
30343933643637656262613337313962666432656632323631353066353838373864383734646361
 | 
			
		||||
35393966646331633466316636326162343831393639383034396133383537313138646339646163
 | 
			
		||||
37363736613135326634363031626132326664343732646161623362373036323337623063653064
 | 
			
		||||
37373839396261653764626338393438643634666463336263346566653366336536376464643934
 | 
			
		||||
31366261353734383064346433363730623762636463613432373338356337656665376338353965
 | 
			
		||||
34353866343734633661633466313132663463323962653431316536643565666364386438336236
 | 
			
		||||
35376163313462383130366337653239623866663837666238346262636238623932333435623634
 | 
			
		||||
65333132373436353533333834653131656638336362623535613366346266653863326431666137
 | 
			
		||||
32613563316138333837333131663637346634663962616230623534383239616132623130646137
 | 
			
		||||
62613863626632323838343736633765393666336664313563316535346130333462353063656166
 | 
			
		||||
62376237663566396665366238323937343434363964653133393163343932353761353038373234
 | 
			
		||||
33303462613837653730646462643765396631656536353335353532663033663433613032623833
 | 
			
		||||
36656534646163353266316531343137626131316536396338666262336136653734613838333133
 | 
			
		||||
62663937346566626131323033313432333562633337326634623866656363393165363235386265
 | 
			
		||||
6332653639336330336135333865633662363738613565303766
 | 
			
		||||
@@ -1,127 +1,163 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
35356461313263333464373365643730653766393437316133336138313761343130646131363861
 | 
			
		||||
3834623038366139376261326439633334393565346666650a323963393665366134386535316530
 | 
			
		||||
61316264343737383331663361353838656333623335393635393762303533313036373161393462
 | 
			
		||||
6664616164633039360a613766323932323266613166646635376333626333356364316233633931
 | 
			
		||||
37646436383339343938356164646262363032663063393038616535346139633435623265343762
 | 
			
		||||
33663036393761643861386538336665366537626464373931386535666237636439383133393636
 | 
			
		||||
31383938376331313531366237336463323563323134313037393435333239613663663234376239
 | 
			
		||||
62346163663061316666636138353962383336623133333030396534323033626632343561386466
 | 
			
		||||
30356266313566316565626562376364643238386561323165633730383262343638326337636264
 | 
			
		||||
35636264386262363264633833653265393962373435653639363733636562343238363931663031
 | 
			
		||||
63666135613437366166643130623034616636616632633838653464666130383365326434666234
 | 
			
		||||
32643164353766323131343137373438613663646635326338303934613065653466613036323961
 | 
			
		||||
38353034636434663061353138393130316432366539643937623935643834633964653630326564
 | 
			
		||||
31636563336138623433366536663632313863313435333531353865623066656631343032383937
 | 
			
		||||
65313535303563653762646261396366333737306331643037366433323030303265613638616164
 | 
			
		||||
36336338333837393235326539303964323261393039393533643538623634613432643532333863
 | 
			
		||||
66376166336662306564323433356330336662333433633061313266323638396165656665663965
 | 
			
		||||
38376465383662626633396366326466333436333338373361363039306539396337333061643264
 | 
			
		||||
37356562623130373765366331643332376337353065366561656261353131666533636466386432
 | 
			
		||||
31643438633464356464333065316139626166326164616666363666393562356239343637333030
 | 
			
		||||
39366231316462663265346464613333306336316163643131303235616432613565613733333466
 | 
			
		||||
33343036326435643736336465303861643739663536343965346433363231323065643733336634
 | 
			
		||||
63646133633037613964393935373161666161383862616333376638616336616537616363643661
 | 
			
		||||
36326665316332303537663935633431626533323838393638653661343665306332396130393866
 | 
			
		||||
66303231666533393132396538393963626132643366373539656437386663653261323465613366
 | 
			
		||||
39633964366362353866326562313834313266656265363161316261386638623737393034663665
 | 
			
		||||
66303966623830366431316432323863386332383362396534396166343238616534346335323761
 | 
			
		||||
31366164623465643331323330323736336337653230623362626230623365636364633261653765
 | 
			
		||||
38613566626537386134373133376139623062383736356634393739353665326164343131323833
 | 
			
		||||
31313038363663316636356431613032636131303964373564633462303735323364636131373033
 | 
			
		||||
30623336306663346639326638303930383466323938356163633964623565313261363139303238
 | 
			
		||||
31326666363164376261393062616339643039316163346362633865356433346636323664656262
 | 
			
		||||
65323565346137333338363864346437373261383936626531316330316539653339303464623462
 | 
			
		||||
32616635373631323465646632323732323432316332353033656339366639663732313939303733
 | 
			
		||||
37306130656662383237613361326161313039326561396538396333373362633365353130343963
 | 
			
		||||
35613833616635353266636265313766323635303764346236306664346432366632376132333034
 | 
			
		||||
65303235366137356634666138343232366533613966363030376537386162396638656637663932
 | 
			
		||||
66663939393737313634383430323339663634333533653265656163326637636635386163313333
 | 
			
		||||
38666236626131333139633834373534316638303364666135396361616130303061313431643936
 | 
			
		||||
64666134623666363937356334356134306463386466613365363136663136393833616430623836
 | 
			
		||||
65373663363664333766373136336636393663376535623532626632396665366436623661636665
 | 
			
		||||
62333961383034353664323333353766343939666636616539653236646634313333373639643765
 | 
			
		||||
32353161633665306463386633616131333130303139306134646134663865306463353838323565
 | 
			
		||||
39313538393034323065333031386634396261336131333763393466633335666238373663623564
 | 
			
		||||
38316633663536383730376532633830623939633662346636356632653031633335313732666663
 | 
			
		||||
33613133653666313564626261353730373637396137323964363866653964373838613130643337
 | 
			
		||||
32376165356236663332366566626639313038363138343061306438313435613862626564613830
 | 
			
		||||
61306262613262366539663338643962313066613665353063306537643561666462333763623866
 | 
			
		||||
30643230313334646535336662616137326437323438336361376562663361376230316362323235
 | 
			
		||||
65363630666464323638323761343033313763633866623361376636653631396263626239613764
 | 
			
		||||
64656163343435643838353033316364306134663833616231343831613338653330643466643630
 | 
			
		||||
62323039396231366136353432373732613465336163326132353731313765356163323866633736
 | 
			
		||||
35326665613165373339353165613036646665313065343432663563306664323163306535613338
 | 
			
		||||
31663138333639666133323139326339313733663334336637373866636661636538666630346233
 | 
			
		||||
31393364313433626565616661313265336165613534666232333835383963646433316632303533
 | 
			
		||||
62626134623830363533393833633439313034633965346163393932636464326664653335643833
 | 
			
		||||
35386332663736343766656232313031306534653434363164623530613232306531336561373534
 | 
			
		||||
37333763626135373538313561303737623035653832333533663534313035313530373037616634
 | 
			
		||||
30613937626664373333643735633164663930316235336663376132353338356333623431343535
 | 
			
		||||
37623138363937646665626535303463643330333233363136313134383939343535646539346363
 | 
			
		||||
61633966396234393961663735646634373266373264626635306162386632376262646336316266
 | 
			
		||||
36363166393332626533613736353038656266323263333036303964656662663436616532396665
 | 
			
		||||
64366638386164313466313630663138333066653061666362336661336539653339616234646538
 | 
			
		||||
30316334346162363065313438663865346434313564363863613532313637313430653439333962
 | 
			
		||||
34643039383030623564666230623264303338343564643961653531366463623166333661653630
 | 
			
		||||
38613062626464663963626233663837653533626532653239343065383036663162646261386535
 | 
			
		||||
36356231383263396365653639613664346361643666336463623136616330336161373336643535
 | 
			
		||||
36613530396266633861643530633732333436373966613437343736653537333531663466383438
 | 
			
		||||
64323064356262646133363463316639353630653766663731653030616461393139396265343033
 | 
			
		||||
31336662366465633264643065386432376435346236323565326562663161396435373762613839
 | 
			
		||||
36316365633937636330643837646335613262363734396261313633373731363466356632636532
 | 
			
		||||
37653036336665393733343832363739323739383730306635306666333566366663396230623433
 | 
			
		||||
64663338626239313265623838383933653539666666383633623939343461393036303230663562
 | 
			
		||||
35363232636635613739356536386439326537363965626261363962383231386532623565343662
 | 
			
		||||
61633931613131303836356366653030656333623235663266636535666632353666386666386630
 | 
			
		||||
36303134613262663335623330356639383432353133333137363665633565363037333136653933
 | 
			
		||||
64396230613837396435333835343265633638346232303738663764663032343061346539393135
 | 
			
		||||
63303064366130333030663739326331633762386332333162393631346234306363313737663261
 | 
			
		||||
31303437376339353634393438316139663862333530653339393030633932343765326435303530
 | 
			
		||||
30326566336361646563313433663063396338663661353832666561393437306131336465343332
 | 
			
		||||
63316533623362613062626337306530633833323132616662613366653566396136643936653435
 | 
			
		||||
33323938333666333439653037383335353763386132643362643361386232383964366237326538
 | 
			
		||||
32343061643462343265383234366465366232666434623634383132303138643333343663613039
 | 
			
		||||
65663339663030326364663561383833333432633437313232356265396532303735316234353565
 | 
			
		||||
39313532306437333238373064643238666632383166313832326662663762316165323936623239
 | 
			
		||||
62366239393530366666343866376566623863373333666266316334346138396566613263333539
 | 
			
		||||
38373438653663353537323961373434363735303838306262323330616538636333306366373663
 | 
			
		||||
62666462336331623761363036353331356632643664373665656332663530613931376666353261
 | 
			
		||||
64346531363265316439393633346334383439623338653334343739353464316436626635653139
 | 
			
		||||
39633232626463303463646162633131626538353232646663356335363663613234376338623539
 | 
			
		||||
30303765636635633331326337373334626664343063623130393438633863306531653631323763
 | 
			
		||||
63323661356362346536646430623864306135663766313833366165653066343439663064336331
 | 
			
		||||
33353135383830373831623463646461616665326139623565666464363961306461343361343665
 | 
			
		||||
30633331666533383161623130613963376266613533366334393262313730313630323836623162
 | 
			
		||||
33613637363431306632366230336537373732613337613830666635353632383834383465303261
 | 
			
		||||
39633334616561386163353661306564333632653731363434666562353561363462376563626563
 | 
			
		||||
63353666653637336666376138333966643237633434396561386164623435333836653238383261
 | 
			
		||||
30643331373138313062616532366265313831613938373865336435383564636266663462636461
 | 
			
		||||
63663230626532613130623566376437356337653564303033393737663735316130633234643163
 | 
			
		||||
30373264363331366435383837303762363531333335613738613463336139643333626239346232
 | 
			
		||||
31393631663861623330353536313731353332313135363436643161353435653865313666373639
 | 
			
		||||
37313734306461633338363033623535653066633135666463303261383366333266613830623138
 | 
			
		||||
37303963666139306632666537633137326434366231333435323335623130356332313165353733
 | 
			
		||||
37656238613138396635303765376666303631633034306133393639363662313066653062373638
 | 
			
		||||
63313961343932393964643538663863313664616164363264663438393639306161373539653265
 | 
			
		||||
34346535373939316563353437663066656439353161623337343935396463363231636262656565
 | 
			
		||||
61653766616238393030333837616631373736323837363136623337623539336661633533653663
 | 
			
		||||
37376530303630313861376261323231303464653666323237373466353037313230333861373366
 | 
			
		||||
61323964636235373030343462326166323533343266353236653138326639363664633066346239
 | 
			
		||||
66636439373262646536333134306363313531333437316536656337633764356339633933336131
 | 
			
		||||
64366565323438343864666462356232616263623530613631303265313861383135333562343263
 | 
			
		||||
39633938313435313266386538346132336638303938373964616535313035653063636435643538
 | 
			
		||||
31636134393930363635613733343538326637366661623833396531623832616238323637633866
 | 
			
		||||
35666266656465323830356432653839633763643430363431326632393664656464363238363364
 | 
			
		||||
64356132326561376330316434393765663661356466346463366538323439393531343632316134
 | 
			
		||||
65313436623664613230616562323138343831623033643338363839343837303334346361356433
 | 
			
		||||
63356163626432343733336531366333636466613863613438373662643266636134633934326432
 | 
			
		||||
31386634363161653965303230306336373434613232613237343836353061613533616237666462
 | 
			
		||||
35393935383431323764646465636563363633336463353064346631363531383061333135386161
 | 
			
		||||
64363366303262336464646232316231613332333732373932643562626534666634316565343164
 | 
			
		||||
39336436366163326137396236393034363162366634616233376465303063663330386137343733
 | 
			
		||||
65393231343634316365326663666532646162623633373530393563313861653638353932396137
 | 
			
		||||
38666161336432303666316263396538663665353334376637343762613262303062313932363831
 | 
			
		||||
65346637366163333233633562393535306263666330666636613363383939393035643132326162
 | 
			
		||||
35656130366237363136643938633931363731623662343536623136313436616265333138646239
 | 
			
		||||
3765356139356136346264386137316437303865646335643530
 | 
			
		||||
36643866316634653430343333316233346137663238373035376232643132663036343736376464
 | 
			
		||||
3033313234383933656361343938653362623265653030360a396638643333633137376231663538
 | 
			
		||||
65313537316564303330663730333131633165633238643532646435386436623163346366383533
 | 
			
		||||
3965636630393834620a343531623964626135636337313861653361393733333463633234363435
 | 
			
		||||
64643934346466663934613962613230623562323666353231326363343430336637323666383634
 | 
			
		||||
36626136643432343332343665343734653435383336313862383863626466663633363738313563
 | 
			
		||||
30303666306439333836306161633432346636396333653434666531353966353430666436623531
 | 
			
		||||
31636562656161333830313362653764306137396231346334613336346538306432636639386561
 | 
			
		||||
65323737383865313264623934613365373465323065616130333837386665666333623832626239
 | 
			
		||||
33333230643332373238363432306466613737373132643134363563613535376365616130333433
 | 
			
		||||
35653262356233626331643432396237306237363135623830643536653938363461303738613130
 | 
			
		||||
66613036393338393037386162383831663866323233383736303532363837663039376166363639
 | 
			
		||||
34666237333562643665653165393730646632316237663337383937353365333532336462656362
 | 
			
		||||
31353934393363363765616335626565343238336262653361306164383030303835303666326532
 | 
			
		||||
31386332346362633433356161643536333862373030306364393935663061396538616637623230
 | 
			
		||||
66383163396139306430343639346264336464646233316636666239643132376164613666363538
 | 
			
		||||
33356365643430383732396235623038643566623131616461376261343563353236306663656634
 | 
			
		||||
64643035373039383031303464346264383066623762323161643561366164313461613038633531
 | 
			
		||||
36383161363065366164383932623231626633646166313835343264373366393236626336353039
 | 
			
		||||
66646338303731346337363962353135346239306562663737363038306433386230326636336162
 | 
			
		||||
65313132626564663738633531333662666661326463643032656136376564643938623061346464
 | 
			
		||||
66653239663464306430613563666336643839323537626338666435336138613763313364323637
 | 
			
		||||
30666566326463623438316263623233333434623366306330656564636163336636623433646631
 | 
			
		||||
65316562616136626330333166646332366537666664303766346239316535333031396235303466
 | 
			
		||||
34393664373361356231333530323865646333653237613636386632393730623330653437393164
 | 
			
		||||
65343266373237386364373862656138633263666633333465623836366233663537393539393638
 | 
			
		||||
34643963363865383434633163623832646632393234636136346137366361393638393461306337
 | 
			
		||||
64653436313065326637363632336565306137613131306364336537613835306332633366313130
 | 
			
		||||
34393732643361663731383661646631353035353064613931333330653031626435353163323633
 | 
			
		||||
65326135376462666435643837333131313863313630336566333835613132383365343234366133
 | 
			
		||||
39336131363366616136663636663334386361646465336331343836626439316532376566353565
 | 
			
		||||
37643361646435643133336333643837633331316432303062623062396564373137613235363762
 | 
			
		||||
32363838333337363035343631353261653063316138626133303937623233326531333837383033
 | 
			
		||||
39366536333434303864616164313137613337643730306261626138343764663662393161613730
 | 
			
		||||
36303736306631636266336131396336646635653131336265623364633038363339353933636632
 | 
			
		||||
39626134353866313439333962376663393831303261633431303035663130613265333739616135
 | 
			
		||||
62623138386235653935383364623230343662333138653562633266336534383963326237663132
 | 
			
		||||
38646335623532383565303466386261613931666438313261653434633934353739613431636132
 | 
			
		||||
39633133656230666231383936396264313630353434313035643565333661393736386637313264
 | 
			
		||||
63636337373334313937643261313564333564383566633730396364653533666236643433643436
 | 
			
		||||
33363061356362386535323038383637613364393639646363366630373735353234333134636565
 | 
			
		||||
37653064636536376638626135393332626539346365353661636439323338653137383866663734
 | 
			
		||||
62303139363436646464383266396464313565376132393937356665396536623332376134393366
 | 
			
		||||
30346435313566313237326461346362353633353261373038656130323365383765613739323239
 | 
			
		||||
38633934643531633037623036623839386637663762366631633033646138323936353433326430
 | 
			
		||||
34396466653230643766636636393735373363616637386662333535643536626261653264346332
 | 
			
		||||
34336337646133646261353939353166393530323730333063393365626365383366633464633236
 | 
			
		||||
64656535613838313461623864666362373030636366373038373863616462373939356238353362
 | 
			
		||||
36363535653734343533666532343166313964303236313135386134623963386535306435656330
 | 
			
		||||
38386430303330303837326138356364373439313836636234656331643131646363386138653065
 | 
			
		||||
64353837396533303463643130613339663166333933643362303565623432643064353865393635
 | 
			
		||||
65663362666130623933623733323933343065633432613965373764383035316338316338373934
 | 
			
		||||
65383061386635316331366532626437303664636436306535663365373064346136393063623335
 | 
			
		||||
35643062363536633332313531356637313032666262366466626462666663303161653635666331
 | 
			
		||||
32343130383231323239363235313031346438323330383938303733323436646336353163356132
 | 
			
		||||
30336136646261323866663530336335636464623035626635333961623363396239353935636531
 | 
			
		||||
64373231386163663962313834333538333133376433623363306239393462383930306432396562
 | 
			
		||||
65393761633834663431353032393032396330393338343863333939323632393438646331613463
 | 
			
		||||
35363530653161653266616331356531666434353663643364316564623438316132383463356437
 | 
			
		||||
38626365343733383735383939646331376531376563623231323535323735356630336130383835
 | 
			
		||||
39633335373163656431336130333664306164336536356431323438333933636365303330393233
 | 
			
		||||
32353437393133646632373234376431626332626333343866643463653662373861346539663131
 | 
			
		||||
32393333633766633738393937356134313236343633636533376665316134653632623061353866
 | 
			
		||||
36373761366264653737386331383235306137323965363265653937353833343362633433313462
 | 
			
		||||
32316466356335366630373635376561636233336165666661653632323835336563313134343064
 | 
			
		||||
30333033333331303164323133613536613636373333663131633162616235316636346337333462
 | 
			
		||||
64306336636562353733613538343462626233303661363131333665366135306332346135323136
 | 
			
		||||
31306535643539303936346632623930333339353439376462633462626165633437393830373739
 | 
			
		||||
61653230646366623830353630336661623466316136373264353762313065346632366164653261
 | 
			
		||||
64313830303466306135313964613537633236383535343132613332613733316161623365333163
 | 
			
		||||
38633930323439303030316433343764356538313632366635653437346161646439663563323832
 | 
			
		||||
38363731353734303932653662326138646239306261383232643537313365393061383663643632
 | 
			
		||||
31343736373739643164623437663239616663373335643262336664326365656137643066383463
 | 
			
		||||
37356666306666353339626662326135636530386462613061326631366535383034303830323237
 | 
			
		||||
65316135343135383230656638363564303635363333623833373163326365393430663235623231
 | 
			
		||||
35646632643735363730613462656562356139323863616266343566343861356238623564326430
 | 
			
		||||
31306366366330363036616137363163663136316565313334616164346639663465666338316439
 | 
			
		||||
33643732343062313536313233333039366435386235333736333937633266653761616262346566
 | 
			
		||||
32636337623266656464636634643632316134376334653932363134613336346539656438633137
 | 
			
		||||
31306439663834663431346133653532636664636463376337616539393239316465636537633630
 | 
			
		||||
30363461343733653465666332646236386633396530333863616236383437333931643731626364
 | 
			
		||||
38393337656130666237373538393430306333333033306466343866303038643234646339306233
 | 
			
		||||
32336364363838636563643939626665643231636633666166653539313461393238333461383262
 | 
			
		||||
62346634633236343433336531396361323238386262313565396265663162353765343037303862
 | 
			
		||||
63633034363664313733633433356332333633366530643863316364653065623161663932323831
 | 
			
		||||
31646530613933613735333834373532616136393662346431656363346364353031303262326134
 | 
			
		||||
31343332386166646530373635343039323163323366616263346431353765303430353636373539
 | 
			
		||||
36346461303730313630373637346266323331373733383465323037343633313739306233336339
 | 
			
		||||
63646137643332623834343462333263356432366631663065383962373634366639656133323964
 | 
			
		||||
64343035323863373139313163323562643066306139363235626532396436663137653635353035
 | 
			
		||||
31396334346137626461633436343539366635356537306231353961333963616334323037346637
 | 
			
		||||
33626161333264643261656661643933653835356236333831343563653938303266323730363865
 | 
			
		||||
31363562383666633636343935386535306361386234346535613363613363393065363832306363
 | 
			
		||||
63643238383363646137306361306265666435363739306463663637343761643831633261633531
 | 
			
		||||
36626562636333336434613365316232343832646163396338613839643064653834633832376230
 | 
			
		||||
33343265386162303266373033353332393931633663623734396133326232303465666432356363
 | 
			
		||||
66306338616634616631363662313963386638343266383063313166353437373433623736333361
 | 
			
		||||
36333163386630376262616362613530346563383637656130363365366634633135323863646363
 | 
			
		||||
35323430343033323734363533326334303438663065656535666432376661613435623365316139
 | 
			
		||||
30623835373535623662633131393831376231623663316331313661646531393338613532623063
 | 
			
		||||
66343665356338636438646339663761336636653332646233326264373435346263386130383861
 | 
			
		||||
34623265373463653165383665306334643233373066356231343666663866373739336436653933
 | 
			
		||||
65623134306536333538333061303066636339376636333438623666366362666137653261376539
 | 
			
		||||
31346435613134303866333065306237343162333138643339313461663934643234303132613961
 | 
			
		||||
65393037396463663034636534323566366161623365666466393634373764333437383263656535
 | 
			
		||||
33643461636362646135626164373335386130303766633434633062356630336463623661396639
 | 
			
		||||
32646565623164363631383731666161343762393639343839373234326337643766336263353166
 | 
			
		||||
62633964303733643035326535656561366139626565643938356264646239336166316534373261
 | 
			
		||||
30623765623338616537353062666338376262393966373033346233383132653839323731626663
 | 
			
		||||
66393938313132653538313031323538333263333361303661646633366633353534373837313935
 | 
			
		||||
37323635633431623365643738623834653631323564393436326562326439666462306263653331
 | 
			
		||||
66316134616432323939373366343564623264336632376132663462396362663134643236643832
 | 
			
		||||
31393366653961323763333335303135383934633538636335303435636334343737306232373561
 | 
			
		||||
31343139363863326536613163663862343263313630336438666132306162646130613233393935
 | 
			
		||||
37336330643361323032366433313939616134366134393032613862616136393339643232356139
 | 
			
		||||
35326534623263353766326132623330323639303230616263636536366263643339663838376238
 | 
			
		||||
35323731303163616236306439343632353561646339663933313937363739303864336438626638
 | 
			
		||||
64633139633338623431343236333534373835356365343536636261386437613538303334663739
 | 
			
		||||
62396532353832323262343763353365333561643633353638313534393164366539353431396336
 | 
			
		||||
36653563633237333730376331326432663561343463616135613738663130323936373136393538
 | 
			
		||||
65636634363631313364326665336164653939356133333031633632373030623666373562623564
 | 
			
		||||
64616365616435393231646236623333333037346363666664666233306661353337343066626136
 | 
			
		||||
35666164356537323735636131383266393064373538303966353531636561623032643233346566
 | 
			
		||||
61633465376631656636366662373865623764336135323865316336663731383335303330616231
 | 
			
		||||
64313836373063313061626365316538653831316562333165616531643434633964333438333665
 | 
			
		||||
66376634323531356538343837326636636636393639396535346264656531613733386337353966
 | 
			
		||||
31363730646365313834316234626532663563613234643563366566373662616335623035393536
 | 
			
		||||
61653334346336613539313732383438313132653738393339373661336531633565303635353665
 | 
			
		||||
31383939643261666538356633326666363934643738636430383537636165623264616236633863
 | 
			
		||||
35336134386437383539303061343261313530313366316338663539383238663966653837663331
 | 
			
		||||
33386464653161376335316536633532383035363066653234626363343232393165313463343930
 | 
			
		||||
63323435613932626435363235396236313365636166663238323534623038663034303365326566
 | 
			
		||||
66306635373433313730343536633931643935323062643136383434643138306138363366663834
 | 
			
		||||
66613964303634616139323832363633363063653237366135613964663733376161373937323462
 | 
			
		||||
30313833623733336366356635323261613132393734613735393062333232313236326264323366
 | 
			
		||||
32376535616334376137663636633333323665333939363366313432633436653864306532393966
 | 
			
		||||
61636337356534373164653637633162613235623364396539623961353466303036383031363162
 | 
			
		||||
37313364613939613939343538633665666136363135656330623332656466383139656234336133
 | 
			
		||||
62366262663064623137626363613066366666313733623463623562636131323435346264653564
 | 
			
		||||
31323431663339653966336230356339303534353139663739363263633564373364323937386434
 | 
			
		||||
37306462653630326366316530656462316539373263366262313930356663376334343562303361
 | 
			
		||||
61623161613939616666386336626537333135346136643537326635383939663863623332373033
 | 
			
		||||
32643730313861636163623133323061333631333332373838636163326562633936363631653062
 | 
			
		||||
37336661626336623462616562333264373330323363363630313739363962323735393332303562
 | 
			
		||||
62393161323962393039346432353066646162336332663636343739343566363833333738316437
 | 
			
		||||
64333337363137643931366536396333633538633830353865323765616264356335383031353534
 | 
			
		||||
33376363386630303332643263383738386532373434613963613764326636333133303262393832
 | 
			
		||||
35373930383662383064333465633736363063363434333662396331633032353733353334363162
 | 
			
		||||
32393361643562623362333963663262363235326536396131643435306665343438333933616466
 | 
			
		||||
34326634373965313638666337326633653938343561663739333464343135346437636436633034
 | 
			
		||||
62333039373136656664363531373430356363363736306533386135323061316339326636643739
 | 
			
		||||
38363763653331646638613963646138666165666439643065363335343132613731623264376536
 | 
			
		||||
37366533636564346661343966373964353731623861633463363638356163346165643164373535
 | 
			
		||||
30373564326263393436326337653631383731313139636339356433333830666265343165323330
 | 
			
		||||
36616538616534626237623862636536303336343331383237333333656637303266616137336439
 | 
			
		||||
61653631636632366563373034346365313337356266636338336663643538303063613036383831
 | 
			
		||||
65613635336366316263336131666238386237366264396438383966313762626639643236313532
 | 
			
		||||
30663235666662396231376631366139653937646132343639396430643339393165656266636235
 | 
			
		||||
38356135666433323434613238356537306630643861353436323037353461326534313632386232
 | 
			
		||||
63643261373263646437373535333036336634396331616330353233613564363361396437326435
 | 
			
		||||
38396462643833313362633436303637323163663166653231653866643733616432323663316362
 | 
			
		||||
3037356363643462356137346638313963376637643162623062
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										111
									
								
								host_vars/web19
									
									
									
									
									
								
							
							
						
						
									
										111
									
								
								host_vars/web19
									
									
									
									
									
								
							@@ -1,111 +0,0 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
66313066303030333063353236313063303262626561316535646263633936336534356437353265
 | 
			
		||||
3432356362393665303438333166643066666164363861610a643434356531666366393936353233
 | 
			
		||||
37353036656435616361613164323038663364666464373964653337396465373061666533373938
 | 
			
		||||
6536323936393135370a666134613830306533623365363933376631313534326265666634366235
 | 
			
		||||
36623637383636396437333735336238343434353733303764326237303033303562353237353165
 | 
			
		||||
31653866633363623764353533356262643239613531643039393335313731383038343638663830
 | 
			
		||||
36356139336363343437666230656366636132613531613339353962373435643563313734646135
 | 
			
		||||
61613330323938363063313430343738306536636233353963636665393132643162303562666531
 | 
			
		||||
61343365326634303730656133633632353936386431303631363731313730666132656334353731
 | 
			
		||||
33616537313230666462653165643535386134663166346262363535383365616431613838383863
 | 
			
		||||
65326163303966373938653033613238326634393166643630316230613065353437306237313933
 | 
			
		||||
65366131396266393236373162343866383565633030356465613461353131643562343630336566
 | 
			
		||||
30633534636634616666616462383136373830623137396366626639373230373834316563343464
 | 
			
		||||
38303333366166323238346237646165383633383264333431663530326462323432366332333630
 | 
			
		||||
62633132666439313034616465663861323064646564303963633565353734353665313138373636
 | 
			
		||||
34653639353333373737613238626535356333633833363737646330643163326131386364646365
 | 
			
		||||
64356435636635663737376239313236356361363061313731626230366336326535663866373231
 | 
			
		||||
37623262613135636538343934336262633662383266653238613965356639626339303437306633
 | 
			
		||||
38373837653737313465376231363637353561303937336138343465376638326163643065336462
 | 
			
		||||
61633236373737363633646135396565303835643336393763393933613964663435306336346636
 | 
			
		||||
38316231383363616533616437366362376664393135623765646330323161366134323263376466
 | 
			
		||||
31386332333565643764343863353039313466643962373736643533666562353766383862326134
 | 
			
		||||
31633366636365313231366337313334333130373833656135396262373136393135353039623739
 | 
			
		||||
63626463636237633963323739303961663632376330336236663134666461383965303861333835
 | 
			
		||||
38663337393930383834653936636365663966333033346562356331306430306338333761353762
 | 
			
		||||
38363733356262363161353135633836336363376232326261623264623338663230663838386330
 | 
			
		||||
35353762393839646338366365313763346339666433306532353530353261363838356639623436
 | 
			
		||||
62306437616630663039653862393466353933333763386163373035373335343834663439633039
 | 
			
		||||
34613463303436366631396462363866656533343063356265333539353038326637613063326164
 | 
			
		||||
62663833363165643436343538666565386561383335393964313839626237623031343564656632
 | 
			
		||||
35613534636437306463373466653431336562303132313462326233663561343837323331353035
 | 
			
		||||
33303336356237306464363564666136633230396635623066376564373737353335356432343231
 | 
			
		||||
66633735316466633039663338316566343739373664316335366462356237366139363731643366
 | 
			
		||||
33353039373665333232383235303932623435366638313465396333316565646134343463336330
 | 
			
		||||
65306334623631386364353364313638643930306265343363666366663164643435333834376439
 | 
			
		||||
64396434366362343733323366343232653930646565313762376436663965626562636238623066
 | 
			
		||||
63303236326362323966666630343136336563343564393833636465333832396666396638653661
 | 
			
		||||
61323561393563326437386462656266303830353730313839613136656331323938616631386235
 | 
			
		||||
30633730303838313038313263363363633136623861326662623366613461343133356261633030
 | 
			
		||||
34333732343037396131343764366535343639326333353036353038656533333339306363653435
 | 
			
		||||
39656166393265356338656631353065653630303237663761386332323530663966343864663438
 | 
			
		||||
65356365386131333236396234623537323062363539383061323832363563326435306465663234
 | 
			
		||||
66316638376436613265353662646264666138666165343763393330613765346163356138616633
 | 
			
		||||
66373338393163333435666236386239663735653135386532633135646539316665313036323763
 | 
			
		||||
38666464363432656534313263306266323066646133353765386463343264633131633936373036
 | 
			
		||||
31326138633131393962633861333036373537366163613562383033336333616130636435326331
 | 
			
		||||
66653766653065306164613335623933616135393335383438356337633239363131303237653566
 | 
			
		||||
62636263383236656136376237646363363234363232643636623333396531363461303538373662
 | 
			
		||||
36313537393238626337613964623731666261316366346666323261386661643035353164613637
 | 
			
		||||
32303061336363306335306431613263646266303038323739636662326465303961616339333461
 | 
			
		||||
65626263366333333562386461636231636438623966626136663932303035343531363234356663
 | 
			
		||||
37313661353764343764396666633666613238323638646233353138383638353938303933396431
 | 
			
		||||
65366564353533363039383838313562663561633434393833636365303561333534393930653630
 | 
			
		||||
63663464613334623864313663383630353166363862373132343532393135313666626464376436
 | 
			
		||||
34616566663764363566663530646638363338653538353661393835383035346236646233363564
 | 
			
		||||
34656165303737326261353032363435333731363031343366353863313138653865346535636564
 | 
			
		||||
31393134336534616161303132353764343833636465356661376638633163643739383830616534
 | 
			
		||||
65386262663734356134303039623265303935363764623537326565633030613465666435636232
 | 
			
		||||
61623334393734616262613232306339396639643636373762653738333463616361653430656438
 | 
			
		||||
63316265303634323033303330353232636136333863366261656532383065313334386335666636
 | 
			
		||||
34303564636333356364663565333932343064333266383638663365366636643866353132373966
 | 
			
		||||
66336563346233656531643735663062393630616537656264323136353266623161353261333239
 | 
			
		||||
33636563376566333331366336353338343730383962653138636535623039643461303763333961
 | 
			
		||||
63373264333037653563643937373664373665343136396635316634613632653232353033666266
 | 
			
		||||
31333064623765326536386630353435333438326232633565663531303730636530386564366633
 | 
			
		||||
63326335333639376266396562343838636430643664303737373565363635643037616231393665
 | 
			
		||||
36636337633564373561343266666632656235646662633965663733383731633832373334646335
 | 
			
		||||
34396163636635633637393834396566663062633135383330396564656536333330623737636332
 | 
			
		||||
36646362623131366166626639386238616566323135323334636638393934663336663532306336
 | 
			
		||||
38396634393433623963316261303061616634333566306239366666373238376466633166623464
 | 
			
		||||
33313538663838373465626638316432613135386262376233633362616463623363646433353666
 | 
			
		||||
32633838303837656335333336353564343461373236353736623032663139333338646463323533
 | 
			
		||||
65326131616433666563343163663462393235366135633661366564623662303932626164366632
 | 
			
		||||
38306430356238633162656337303536663065653639353562343965663366373861646162653562
 | 
			
		||||
62306236326163393336643232663336656637623539353835613536653164393038623966316433
 | 
			
		||||
32623462343037616465623736306530633736623061343430356638633530313331306363323837
 | 
			
		||||
63396263393136363137643632623938316363386238346237333862303735363065386633366263
 | 
			
		||||
31313834646239323631393335633534383930373630663538653864383930666465653731616263
 | 
			
		||||
35333830633430343436646266663231303466343138643338343634346133613666613734313037
 | 
			
		||||
34383931643631633539346262653631336565623366343564303332333831346436373162356362
 | 
			
		||||
66383864313732303962653662333036373239343335623765616536306465623030393138663838
 | 
			
		||||
30313861636631393462653836626164373034666533323338383262393132396436666639363262
 | 
			
		||||
39356132343939366534666665393231346566663432653236376333323363643166393431316161
 | 
			
		||||
33343666316138353333346263346266343731613065356631336231373266343338393939663038
 | 
			
		||||
35343235393563623434313266306163323266346662623063353631663433646436613130636663
 | 
			
		||||
38356335616438633638383236333131663163613436303934386335363432323063303234383331
 | 
			
		||||
34636432653262643438653931313233626462623034346137303738643932353334373531303439
 | 
			
		||||
30366233373535343431373365393566383538363763313036623262343066346236303061326631
 | 
			
		||||
64376463336538363132656464666365343861393330313637356237666361343666633436346534
 | 
			
		||||
33636332386336646333616330613738343264626438613135313962336534373130316330366233
 | 
			
		||||
30316333636564326165663565666361643430656366393939616538323530383632636661326331
 | 
			
		||||
35366663646533313034333764626237623637363164356163636432653765656439326438383134
 | 
			
		||||
62623638633934336334393636333336633164343066336161333138653637333435306230653865
 | 
			
		||||
35363032393633623331363933373463623032333361616365373037666333643634343963663835
 | 
			
		||||
34363033363731346663643363383965336536353332646262326136353965353137383737336165
 | 
			
		||||
33613733656463376333376264633935373239363337323538356636636439393564373332323031
 | 
			
		||||
31623733663530326632373235313830396133373430613061613438653336653462316336623438
 | 
			
		||||
30343032346133363830656231663966653734326635333831626639393666303033653437326238
 | 
			
		||||
65333566643066393331323466366662383135383734313537663664376161323265613436653535
 | 
			
		||||
63643832616663303632623433636161333339376635333635626137326662396562633830343337
 | 
			
		||||
65376165376564396433343736313134656332383533356138383039386266636238613936653962
 | 
			
		||||
32373337346335383136303838343034376432363436356465613836366230313463303239373531
 | 
			
		||||
65383334646431346565656638353537333765623430333133663663326134646566306137643663
 | 
			
		||||
65643338386439666636376461356466396261326165333030623633613364343631343830653939
 | 
			
		||||
64323266626131666332666433386434313936306361633164373532626231366234623735333932
 | 
			
		||||
62306362346164336433336139313561366162303666353635653634396139313734626463663735
 | 
			
		||||
38306466626237626634666138363665326636316563356431333432313534363638613833613539
 | 
			
		||||
38306237353764376462323238663034646662393433623830616361623735343162666465626230
 | 
			
		||||
30633731323939633265323338373537383261333235303262633336636433316339383433653861
 | 
			
		||||
3861653261646632636364623830626561393864666135346634
 | 
			
		||||
@@ -1,49 +0,0 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
30313139316131383630353236343338323465653163323838616464396137656365393639613766
 | 
			
		||||
3733323562386139353933626339663039653437363037350a356263643762313634613736356363
 | 
			
		||||
30383534346664353030346233653163616330376562346164613731346566393330623165306234
 | 
			
		||||
3833306632616536650a386239363931326463663665346363313462646464646632643961343631
 | 
			
		||||
63393164366163353461633038653833623963363233396464663839653330386231303461636564
 | 
			
		||||
39613265343765323636373736646462333665303333373737633632346465343439386335623334
 | 
			
		||||
35333933363966623730643632313361356661303562393535646230626639363335623861323033
 | 
			
		||||
32356664663539343262336535623233326234356463373031356361633536366430346338393831
 | 
			
		||||
34666232373761643430356662653431646661646165663134633135663933616262393763356133
 | 
			
		||||
61323063383036313166643866303136656164386239326437303238623338306433633762303630
 | 
			
		||||
39396438396639666433376533333765313431383862383031333031616334656136643262636438
 | 
			
		||||
65626565333939616631336237633063396430376434626437313666646165333239376463383837
 | 
			
		||||
64656635343661353735666666306134653530303033326662613230663061613034383461326534
 | 
			
		||||
65306131326634643732326530336136623731663336656138383635383730653633373737386335
 | 
			
		||||
31316136643634613536366439393565633964643735333336613865366138396539663534646435
 | 
			
		||||
61626530353836366337643062366532323538326161633137353336626537633739393464646632
 | 
			
		||||
32343730356362393336313535303034363531373961616265623934393161306261663562653464
 | 
			
		||||
63336164366531636130343939353235343261316534613665316363346266396332633763346536
 | 
			
		||||
65633038366530356138373661306234316161343762343638366639653132333438613766343939
 | 
			
		||||
61316232386465643236326430396130333831666363313032623537383032646663396239663338
 | 
			
		||||
38313939306465353033663066633435626635353138336330336333616231363634653665386532
 | 
			
		||||
65326463663933343966356437353433313565316139366365323934643131346636323737626437
 | 
			
		||||
36343435643231366663323134656561666133303030383734316237386532396662366461646365
 | 
			
		||||
38303434363763363866383761386535383262323432333730323236353439653163613966333032
 | 
			
		||||
39306533333132373736313834326464643134393432303537643835336438393461663233333239
 | 
			
		||||
32333365663337653436303662393263366161326465663036373934373764363438656436666232
 | 
			
		||||
32326134393161656133613266633966396663353631616537363361396537623164373964636666
 | 
			
		||||
61613731306333303336316337343635316134363431646433333932633336363065393637343030
 | 
			
		||||
39366537656430663932616335323661316533643763643161613463646363656232346333303331
 | 
			
		||||
38363234333261653135316266313736366439343138666165366533353035613731633466396363
 | 
			
		||||
31663166336431653461663463383333623664356365396230353130386138363261356331663965
 | 
			
		||||
66636338336466366132633437396535643736333733633430373964343533366338666532346263
 | 
			
		||||
38353233303437663339616532636662373761393461666439663133373633653139613531393738
 | 
			
		||||
32383937373833323938356333343963306534633734393162363965356163643862643037636231
 | 
			
		||||
65366461663161353939633866323162613761663836626232346236343263386364303233313161
 | 
			
		||||
32313265366562313731656630393166336662616661313964666661616439343265383566383332
 | 
			
		||||
33386266366534383934363839636636316532613133636664323136373130363534333531613663
 | 
			
		||||
35333964626634643135663639373339626335643366333766386631363439393435626439636166
 | 
			
		||||
37616339313336656634393538323935383964343437646433636636383061366437386330643334
 | 
			
		||||
34383237353036396563643730373663383165623633326336313031326435623538376130393130
 | 
			
		||||
64636538663963303938623866626431313238646465633437333863363865666435636564323764
 | 
			
		||||
39303638663830656162393836366262663161633763656630663434386435643462353661353035
 | 
			
		||||
63336461333464363838313765653037393964633536636435666162346461633561386364333966
 | 
			
		||||
32623761373435366665363239626632646364323934383163346637356562653332373536343462
 | 
			
		||||
31323036356132373930656364393061306130353632623661663032343230633635336664376134
 | 
			
		||||
38363239396139333230346138386337313364353934396362373233376266383537346431653234
 | 
			
		||||
34323835306165613739383336303964656565373636343639303831386466623031396665343234
 | 
			
		||||
33373164663339653839
 | 
			
		||||
							
								
								
									
										46
									
								
								host_vars/web21
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										46
									
								
								host_vars/web21
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,46 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
65653532333862366436303432656664373261323934306234623534633335356466623330373063
 | 
			
		||||
3164363863313131303330363564326130383433646332640a373233653965653164353663633038
 | 
			
		||||
63363966646361366637643261613062393736366361356235633139323537636638396264316534
 | 
			
		||||
6366313732323066620a333738656661656537646632326262663862393434663435313037653564
 | 
			
		||||
66303732396261373436373538396466643330633336623066313933323266386438363566343834
 | 
			
		||||
38616661303931376136616532386637386130326264336430613336613836323666326261643838
 | 
			
		||||
36613565323062626662313864633539323538316562346533363437373766343764346132333631
 | 
			
		||||
66336135383732393939383133626662343335376531336364303662356566393034326635333066
 | 
			
		||||
64333635303633306639656161623631333139653034633939303565386330383236616364353136
 | 
			
		||||
62663536613565383064633235613539313933373530306164356462353861383761363931613430
 | 
			
		||||
37373939616564663562376635333862646234353133663331396661626234356665633835323137
 | 
			
		||||
39343462303438376131626335346637316238626462333430346539313838386662363031336636
 | 
			
		||||
34366132363439653137393662653661663262346632306533376565353037616362316161333566
 | 
			
		||||
30393530656566643136613039363537613035666465656530366637393664343665666534383837
 | 
			
		||||
63393133336664313466636538386338653937643563633737633962626562326637356661633463
 | 
			
		||||
61613231346532306265623361636330376563396266393330393166643833353165363934313533
 | 
			
		||||
66333832373035376334326336616534326566666361616665633363383032393236336634303232
 | 
			
		||||
36656336316635376431396233626539633839386533333436633264613761353361333565656233
 | 
			
		||||
65373331306434363938393339333133336461646130666535343965646536656263623530666333
 | 
			
		||||
36353664643132623465353661656466383363376261363534303462306661623564663561656664
 | 
			
		||||
37633936636263623065366666666530616264396334623766613036313735353264356162613836
 | 
			
		||||
35643737346530393933643537333561356465363239353630343333373038373836623231336437
 | 
			
		||||
30343932363864663435656634343138353638343461623665336461326565636164643231323133
 | 
			
		||||
65383664633665343365363764353566653635663137633033303731303030613565653565303433
 | 
			
		||||
35373930396166646134326165653436613137383630653338613634633361623432373839376430
 | 
			
		||||
38376630633363613632316530663839326538366366626230356337323536306665616661373261
 | 
			
		||||
36653965623936663963353836653636306362663062636466613034333532633534646635313737
 | 
			
		||||
33313962323636643132396166626566366466336238323163656332383530363833613633383165
 | 
			
		||||
66366239613530613264313739396661386165343162633237303034373765643037656564653061
 | 
			
		||||
63373036356134353633633532663365323932633531616261373735313737333033353532656434
 | 
			
		||||
36316339303930336464393261323035626330366133626137373034396166336263333964333963
 | 
			
		||||
62636432386531306133623163643461336137653331653861383139373938353162636566623566
 | 
			
		||||
35616637663638313566653832343634613632663861333162333932336264613730313864663663
 | 
			
		||||
38396563373339626365353766646565336335656539393738376331383038353436313963633438
 | 
			
		||||
33373433613034373763643434613365303938373764306662363635626636633266643035663836
 | 
			
		||||
65353632313137366231323764313036613134643830326330653763656362343561643964623361
 | 
			
		||||
64336565666630626339346563663931393035363938663734616666356435326638353131383434
 | 
			
		||||
65623539613662393936653161663264343132333936303661643534343536363165313564333037
 | 
			
		||||
39343561656461313265393466346662343530313230386266646662633262643464366661363630
 | 
			
		||||
63376463396631666366313266633964396137373661643764666537366539373337333731343933
 | 
			
		||||
31613232363436643236623935326265353666313861303531633462623363373536636534623532
 | 
			
		||||
66636533356363353735653839646263663631316239326164646463396532343038373861393033
 | 
			
		||||
36623962396231633164356335623865326632303237643864656335326435373234366536313565
 | 
			
		||||
34313638373063303434613663323136646263393036356336323532373130386536306235343165
 | 
			
		||||
6462
 | 
			
		||||
							
								
								
									
										130
									
								
								host_vars/web22
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										130
									
								
								host_vars/web22
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,130 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
36373430623764356339336538363637613761656163316533356331373837303939376237393137
 | 
			
		||||
3030626231376566333735303532346164363663353534630a633961333162663333303263643061
 | 
			
		||||
32353530376330353162663434316464373365353138363831386530326335663665336566376361
 | 
			
		||||
3766316665663038650a623730616333326534623431383833616438343964646538306437393634
 | 
			
		||||
61356439633731333932373532613132636134613366333338313235636331313336383165626362
 | 
			
		||||
31353265663461623937653636326430663239373061386336393435376336373461633263663834
 | 
			
		||||
31346635366538666466393763363663366332336561396238386334306265356363363366396466
 | 
			
		||||
36656438343536383433633465383630343539356538616134366163643837366563623365633763
 | 
			
		||||
62376532613337333938373533633361393834373462653238613565623263333034633664353861
 | 
			
		||||
37613231373638306633613662326437393933663961353062366164363862303031383339643036
 | 
			
		||||
31623533373338333462363266656232643136626435643563356332613231613635633861303664
 | 
			
		||||
36633962303435343138373530393339353339666234613839333161346263616634633466303861
 | 
			
		||||
62643061353835626535326630666330616563626133383861626537303633633639343730623634
 | 
			
		||||
32323733363165616366616635646233336164323464613332323733396464383834333832343532
 | 
			
		||||
31373466623465313838663163356435326533666532646436383063353565393339646366663964
 | 
			
		||||
66346131663832303532346666643538636334633238313538383463303933646462356430323461
 | 
			
		||||
38303833323036663835636637633335626239616531636231653465646332643064333264366362
 | 
			
		||||
31383039396237363936346262636331383334363665313535316262646433653430356537626139
 | 
			
		||||
30636135663638633462656363333262613362303363313565663538366333636632306339616630
 | 
			
		||||
35643262653131303935363630323530376263303037643861386366323533313936316239633635
 | 
			
		||||
30366436323033626638633366386637343661633666313037366633326331303462666633383566
 | 
			
		||||
34363135336632636434666262306638663762646130393462396565313563383732643961656638
 | 
			
		||||
62386137616430333162613062316432356432323934376536313537356361383334346531373932
 | 
			
		||||
62663232373265343464343766646239383064653333636431313030343334366264386436613666
 | 
			
		||||
66633966343637303064366165336566353338333432623631343038636631656338623936323833
 | 
			
		||||
64386234386164366539303530336265383536633937353462663530316264393637626239303732
 | 
			
		||||
61306465666431353334393663323932343836633837343231306165336330626362383238623962
 | 
			
		||||
34653235623861646132306136633630653864663366663063653430623032366462323637646362
 | 
			
		||||
62636537373563663435616630313532326465636466663766333038373337643432393839383738
 | 
			
		||||
30336633613863666539633734643137636331383932633833386330626363303539663938383136
 | 
			
		||||
36303037373965333334303564663131353039306538623934303566323338636237323734663435
 | 
			
		||||
39376431643235633134646665393035666561373864343364643536633461306638656535336435
 | 
			
		||||
35613066613465343632653234353735323735623864323736383066383432333333303737346131
 | 
			
		||||
63346164646630623735636563613432396463313266373635303339643834623463643133396364
 | 
			
		||||
39346532306336306333303163346137666130633338633366646431346363633961646430633636
 | 
			
		||||
33373462306636353962383537356435303134306663323834623132616264373539343038386537
 | 
			
		||||
34353561353636353131373139386639326534613337643535653536363531653534303434346433
 | 
			
		||||
65633638346538663265663038643939306463346438383966653961343832386562326662336137
 | 
			
		||||
37663733653836666435336466333438373230356336316231353635643465353039666432376433
 | 
			
		||||
33343130376238616538653366623637366432363333643163613239376439643461313961386166
 | 
			
		||||
37336238346137653435663361343666346662343465356139343062363631333839636361643433
 | 
			
		||||
66363039636165623739363762633464303932633564613336353537643964353336666566626165
 | 
			
		||||
63363130643330386465356663346138396637363732616436383365363037643261373536663765
 | 
			
		||||
65666338346431653539316366626565616263376433646635326138633935646165663664353735
 | 
			
		||||
31633939353534303266653838386466343761323235666237313732376364376566396639636236
 | 
			
		||||
39383332336663363139373562393665306462623964373864356365383864313336383364346338
 | 
			
		||||
36663637633437303232636335616538343737393034616632333732646634346634666665333930
 | 
			
		||||
36313334343162353865386630646138656539393064356233336636613863653233323330323237
 | 
			
		||||
34643039663265356230623432613733313162653230393539353362613365393763646536366330
 | 
			
		||||
65646638613064633330356536616266653834636362663466316235313235653732383333633066
 | 
			
		||||
35306337386238336633646631303165333039616161343633343539613937613733366231326561
 | 
			
		||||
62623038393337616330616639326638393034656233656262623630356138376233356562383337
 | 
			
		||||
34326431383438643162303236396563393266306362666135613565393930663263393635393332
 | 
			
		||||
32343733333134656337653362653337316561366438613662663535623865653166633637326538
 | 
			
		||||
36656532316235396461343235636139373361613339386163306464646339613036363564623438
 | 
			
		||||
61666630333234623236386536653862653766646132303332366536653165353466366366643239
 | 
			
		||||
31383139303638623435343362373431386139313836623366666364623037303038386633316561
 | 
			
		||||
30653238656633616662393566386464316134656465393333346438356432386230623431386661
 | 
			
		||||
31636538356335633961656261393034646437626135363430636233633035336332376165313539
 | 
			
		||||
61353365346263623639633262303265646637303339353739643734333732643365353739653630
 | 
			
		||||
33616266613664663932626633663638636237323463333634373630333432376334333136383164
 | 
			
		||||
65663630396262303936663438646465313032336632623365386134383661663938653631623230
 | 
			
		||||
33333466633033333963313239626463623765623931663430636131323036316161646562396561
 | 
			
		||||
39393066616366333237373138643163326132356135643639653633363131376235373631636466
 | 
			
		||||
62326433316131626266666131363361376532653833343262313435623164373832366133303065
 | 
			
		||||
38333233393663373831363064626463363662643364623737353939373263393338373265376661
 | 
			
		||||
32353462303234303034356233363235393632616261303236623330303632363839313138303761
 | 
			
		||||
66636436316163353765363331636438343666366630363265623536633963346133366662373664
 | 
			
		||||
36346234393432656436333563633333663135336262396262396135633765616237333730646239
 | 
			
		||||
32363037663830613864303636636564316161386561633030656164316639663065346665613463
 | 
			
		||||
62386266656564666334316333356436356234393431613436396263393139633066633230646439
 | 
			
		||||
66353836303332356136393565303163613363366538366165326434326137623535316636626533
 | 
			
		||||
32333733343831316538366637396138623832656138393033363533663461656436313630383965
 | 
			
		||||
31633533316134623262366133356331316134353233633466363738343362343366333834326566
 | 
			
		||||
30356161356630303431643762343062376437386337613737356264626566666562393139363437
 | 
			
		||||
39646664356438396239643739333631393561386666613764303962633039323161303063326131
 | 
			
		||||
64663437646236356332363936316235353062363336366166363461383339653565666336623363
 | 
			
		||||
33363335623161393337656466313130653061306533316266636463643032653139303232396564
 | 
			
		||||
62396364346436363930316266636437353433336534313066363834323962313636303264353765
 | 
			
		||||
62313366356237313461323763663939616561666262333739363231613838356161623163643234
 | 
			
		||||
38363633343763653733316361353364663339326330363865613163363537643331663231376239
 | 
			
		||||
62383034333039336162636235663631306435613063653633623466306430383062663161643636
 | 
			
		||||
32346264386663623530356132643862623233646461333564306165643537303233643535666237
 | 
			
		||||
38363365623037333630356165653730313533663263386161396132323361666165656639643235
 | 
			
		||||
31303737653034393862333933353233383830633438663133393237373964373162316439633636
 | 
			
		||||
32356433613537343537326465643466343632626164616332316232303838306566353838646566
 | 
			
		||||
65636236343966626532623932346265633433353937373366363563623035326365343031356566
 | 
			
		||||
36316462306437666633613562343137623430623435393261343437653531326565386634666539
 | 
			
		||||
32343363663831653437626139373564643334306633643035626333393035376364636232326461
 | 
			
		||||
35643335613865346437333035626433373331303038663136373030373236306165333465346537
 | 
			
		||||
31646365356638646464353336326132386537343534336335663962666261303138666333613537
 | 
			
		||||
36313133383061373032376634343632356437383436373763393933316634643266366536643734
 | 
			
		||||
62343531376165613933393266373131633165653434346635333433333866386634633564393331
 | 
			
		||||
62323932333438306565356435323035656330343861343031356634363535646131383232356465
 | 
			
		||||
34623433636331636633653333346261663933613437343533346364613262383432663139663530
 | 
			
		||||
31383035643239346333313532376139653937383262336530383664383563653865373532323934
 | 
			
		||||
62656134616363616236356430346239653138666339356365383336343965323265346333316566
 | 
			
		||||
66636565336230623962626365653636393363323134653866303234336637656563363162313038
 | 
			
		||||
65306134623963353135333436623662346265653035646438343737653733373666633532336464
 | 
			
		||||
65356561616633366437353037326164366335386165316339323162313231616338303235363338
 | 
			
		||||
63313062396264373038353263323736363838396330313738383933343033303665323731343834
 | 
			
		||||
38633734633332643833636238333462633039333731303936336130353830323639646437383538
 | 
			
		||||
30306632396161613163653734633962613037323536393330373364626134363832313566623631
 | 
			
		||||
34393038626235373734346538616538306130646136353262353930393262326336323366323662
 | 
			
		||||
62643465326338386633633338333439363064623637303535653532373933626462363433666563
 | 
			
		||||
35363430626533616434613436636330643565313466323665366562653034316536643135353839
 | 
			
		||||
36303731366534363539383730303134656535373365653633616530353134306561326562366666
 | 
			
		||||
37383436333936383630393433336262363436643664616366386636323632383661303035653065
 | 
			
		||||
31323964336136383332353434653933623939323437313734393534373731396631366532653963
 | 
			
		||||
32666136333034346263633533373634396334616137373935656136393331613562316462613737
 | 
			
		||||
66663831303539636433613334353137313536333134633831376338633463376162376663306335
 | 
			
		||||
63376565626334383030366366613061646238376432326239633230303763396163666535343336
 | 
			
		||||
38633034646334666365613363303536613936316539366333386166313863363562613135663233
 | 
			
		||||
35303038623364663462393364303538666262616336376534336235663736363535653661346262
 | 
			
		||||
39356163373435313933373234363032653861363834623033653665393730323138653534343962
 | 
			
		||||
33373837346265633536336234616637306536383866316162663133363239663036663932663030
 | 
			
		||||
39323536356635326162316361356261373737663939353266663337393334323132636564383764
 | 
			
		||||
37366237623836613062643134363536613239313564636665373437626533613732383731373961
 | 
			
		||||
36386139386665653532346361386238643038353731653864393166363964353463643331363562
 | 
			
		||||
32343165633964343630656439653965306432626134326232336634313562306539643364616264
 | 
			
		||||
35653966636166666364656336663632663036333034316261393835336466616262313434323634
 | 
			
		||||
33376635616466663865373639376466623935663836373565333835326163656531616531376665
 | 
			
		||||
64653733633735333464643962373731396563643437306161646332393864346364373463323166
 | 
			
		||||
35343139386162393762643131386132363536353163663464336437626266343132633464653339
 | 
			
		||||
63626634323564373838333636663161333261326436353963346133646533333933393939343438
 | 
			
		||||
62386264353061326533663038383039363838363138373030393561386638356266366436323762
 | 
			
		||||
38353933396535363336356238626664653461383865313362323034393232383832343635653239
 | 
			
		||||
31353438643139326631633332363736333932656534353366376464653266643039313364623365
 | 
			
		||||
3335
 | 
			
		||||
							
								
								
									
										85
									
								
								host_vars/web23
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										85
									
								
								host_vars/web23
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,85 @@
 | 
			
		||||
$ANSIBLE_VAULT;1.1;AES256
 | 
			
		||||
34643866316432643663656661633339313239653763623430356538363761393162626338336433
 | 
			
		||||
6535353761396539323630396230316637363536396631350a343338396638613636396364323762
 | 
			
		||||
62306431363961393937633033373963623064333363633034623430613031383032363562663536
 | 
			
		||||
3566646634303639340a366236343164666563366130636433383832656563376463333431303861
 | 
			
		||||
34323164323161303762616164366632663761626665323832366166386166636130383830633065
 | 
			
		||||
64646563396264303035636661663162393332613661663564316466313363656263646533633861
 | 
			
		||||
30366136316131643734356431633064373062613539643937626539373536666663646331643862
 | 
			
		||||
39366666386438373335396136616662346230363631326465373065333633313638303564336165
 | 
			
		||||
62323164373933396166363236396461623432363931636637613235636663613432636136616664
 | 
			
		||||
64643130373337353936663863356363653630633033343538623133616662386430343632303031
 | 
			
		||||
61386331346561346138643735393162616135633333343135653238366533663733626361656666
 | 
			
		||||
61616130313031646365613638633463353861353935623562646666393733656266643834396361
 | 
			
		||||
38333363633162636561323331646262643139643135666261343364333634613138343431623637
 | 
			
		||||
39383635393565656139666535386336616165623333386266383431663936313034393439626234
 | 
			
		||||
30386263323630303563613334393538306430396537613436613264646664616261323336366432
 | 
			
		||||
62333061333730393064666131346339623061306637633261333635336233363831353662653437
 | 
			
		||||
33626333333130386161323038333465613737393835656632346436396361383761303865333339
 | 
			
		||||
36613062353630316633336464336463633230633762366663396463303234343266323233326165
 | 
			
		||||
30303637353163613464633930336463326535623662636638643066333733623032353564393164
 | 
			
		||||
66363732393438393462353034626363636664316464356432363235366134326261326335306462
 | 
			
		||||
61623330656538633364373561336436353362303638356539393031336531396139343539353936
 | 
			
		||||
66323332336235393162376436346330386537336239636434346565386565373365343462323164
 | 
			
		||||
63373462313861653561313762363338623664333233316632303562393736346665626530643061
 | 
			
		||||
65353337623230643136616262623430323235346439626364376362653337303735646663326535
 | 
			
		||||
63393937366232623663623165323965303563323137383462623339396163353433343836383666
 | 
			
		||||
39633065373839646235326130633635316237366631333765343333613564333461326465356134
 | 
			
		||||
37663735393537333532363062633161313437623831356332663765613936383338343634386239
 | 
			
		||||
37303137623138396261663230303530343132346665386363346230663836656634316364373064
 | 
			
		||||
61666262363638376162393339636138353634633630333435383437313433316564663963323532
 | 
			
		||||
30383835336565346337613464343561343832653263663465393133343566333864633766613531
 | 
			
		||||
39653238633237373736663635306563323631346331353362343031303636366439356362306138
 | 
			
		||||
64656166653232633239633037373330343139636261646238613662613364656632643334343233
 | 
			
		||||
31633438386433633736663564613230393662316534336132333636326137353831373335396666
 | 
			
		||||
63636530633037643339326466386638323733363732323939323862326432303231393435616630
 | 
			
		||||
63303461616338386230303933636161306238613861326633636331376464643531333939303735
 | 
			
		||||
38653165303832313739363136616266363837613337306230336433643237326232356333343963
 | 
			
		||||
62316139393661323965313066636530393433613438633430373864343438623631666564386639
 | 
			
		||||
34656461643530636537383264313266653465333764623166383838373366323662653939613439
 | 
			
		||||
38386339393164363863373838303839353532346238643163616635363064343435393933303234
 | 
			
		||||
64306431623738656434333766343263653865393935626466353433386463623739393130386332
 | 
			
		||||
32623762353665393863383762643035313266643863363062626332316439616639616333623730
 | 
			
		||||
35373662316131393836333936656438316334363364323339343236376634323365386461373061
 | 
			
		||||
38363335353965646563646231653434623531336465333231396530623365306137643931633238
 | 
			
		||||
32663937616366393237623861323337623963353964313233353433643733313730666239373031
 | 
			
		||||
62316338623734303839616639303539643439613062656438633563653337626364316535373661
 | 
			
		||||
32313337366465656533653766356436623638316534623666346666646364633436656330663666
 | 
			
		||||
38636439333834313639316663326630356531613432353837616465353763623335623464363734
 | 
			
		||||
34366335656366323634636465353563633532616334636665396439326438656462386336326265
 | 
			
		||||
32393131636362633230366330633564376165313830616134393931613566383433646632363536
 | 
			
		||||
39636563313662656439613565353663613962653730313666636263373065613230313965336130
 | 
			
		||||
30346637323565333139643332336239646636643037316436373134663232373738363564613633
 | 
			
		||||
64396330316332616631346339323466376162336539656433353666643438323365663665623661
 | 
			
		||||
33656162643163323161373931353963303934643532343561643838336236386139316334636161
 | 
			
		||||
38316239356165373036306464313066623432383037613134633364373762313639366330306333
 | 
			
		||||
66643139336436643535353466393830363136386431373962656165633465326135616430316634
 | 
			
		||||
39333966373361613433333631353334343765643435353466626536636437333739353036346635
 | 
			
		||||
64346235336132393030666531343761366562396233386236356332343963363438373535633065
 | 
			
		||||
64643730333465316439363735396566636338303236623438393566316533613333396561353930
 | 
			
		||||
66633631303336346333306332663639643138656636373266353061623234386339313266376564
 | 
			
		||||
37376130336230366630396335343330663162396237366131306237663232316361633939333365
 | 
			
		||||
36366234663735393664353934303930616566336133313664313538326136343363323530343865
 | 
			
		||||
63663633383338323363353061393366353064346232623464333863666334616636333662323265
 | 
			
		||||
35653761323965376364343362643734646439373237333632373736353436326133376663346132
 | 
			
		||||
38373530333137323038653534623761353265313336303538376565626363626535663635313235
 | 
			
		||||
35663765376334366661383764663066383232323431623262626662623138323431383863363736
 | 
			
		||||
66366462303838656234373263653835373666623934633865353533316537363431646661636433
 | 
			
		||||
30383862626636613636323639313063323632323731613134303863356166613137363538333466
 | 
			
		||||
65666635666563616464616538343639363331336233663038616332663032616364393761343036
 | 
			
		||||
61373636623331636136313038333661613339623763663132306131663665663237363730646339
 | 
			
		||||
36363766376437643930663363333635666366343431376439613961353039663938303834316433
 | 
			
		||||
34326235386164373130643533373566653061366636623565303361666234616530346561386239
 | 
			
		||||
37346337336137663366353632323434343263636435313034646639376430633133626466343737
 | 
			
		||||
61656334656639393239633361316635646665633532323461663432633135353264383666666438
 | 
			
		||||
33306336343732643234623430653538613064653635363765303166303061316636393736663561
 | 
			
		||||
66393935663835633437326265656239353730626262333038616633326138623261343864613161
 | 
			
		||||
35333233613163666461323339663063646361646563653531356337373663343166613965366232
 | 
			
		||||
65313839633730386436633962373434643636396264646431653639343361363335633633383062
 | 
			
		||||
34356232366132346537313838663730323336613661376331636363353464316266633336383639
 | 
			
		||||
30373564333265653839666161643366313163356161356237383133636130333330316430613632
 | 
			
		||||
34376338383561613635323030613731636637653961646632363838316665313934646130663361
 | 
			
		||||
65633232396539646337333061326234316534333866383830343632306331663631343864313236
 | 
			
		||||
65613932643938313161353331613634656230303863653037343434373862353462336134646637
 | 
			
		||||
32616266353730336663613865316164626364303262663461363436323133653663636665323134
 | 
			
		||||
30306431336637663130
 | 
			
		||||
@@ -1,11 +1,13 @@
 | 
			
		||||
---
 | 
			
		||||
#file - roles/common/defaults/main.yml
 | 
			
		||||
 | 
			
		||||
# add a dummy API key for AbuseIPDB.com (override with real one in host_vars)
 | 
			
		||||
abuseipdb_api_key: dummy
 | 
			
		||||
fail2ban_maxretry: 6
 | 
			
		||||
# 1 hour in seconds
 | 
			
		||||
fail2ban_findtime: 3600
 | 
			
		||||
# 2 weeks in seconds
 | 
			
		||||
fail2ban_bantime: 1209600
 | 
			
		||||
fail2ban_ignoreip: 127.0.0.1/8,172.26.0.0/16,192.168.5.0/24
 | 
			
		||||
fail2ban_ignoreip: 127.0.0.1/8 172.26.0.0/16 192.168.5.0/24
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -1,2 +0,0 @@
 | 
			
		||||
[Journal]
 | 
			
		||||
Storage=persistent
 | 
			
		||||
							
								
								
									
										5
									
								
								roles/common/files/abusech-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										5
									
								
								roles/common/files/abusech-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,5 @@
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define ABUSECH_IPV4 = {
 | 
			
		||||
192.168.254.254
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										9995
									
								
								roles/common/files/abuseipdb-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										9995
									
								
								roles/common/files/abuseipdb-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										13
									
								
								roles/common/files/abuseipdb-ipv6.nft
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										13
									
								
								roles/common/files/abuseipdb-ipv6.nft
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,13 @@
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define ABUSEIPDB_IPV6 = {
 | 
			
		||||
2001:470:1:332::7,
 | 
			
		||||
2001:470:1:c84::15,
 | 
			
		||||
2001:470:1:c84::22,
 | 
			
		||||
2001:470:1:c84::23,
 | 
			
		||||
2001:470:1:c84::25,
 | 
			
		||||
2a00:d680:20:50::3292,
 | 
			
		||||
2a00:d680:20:50::4a10,
 | 
			
		||||
2a02:c206:2062:6450::1,
 | 
			
		||||
2a03:b0c0:2:f0::34d:c001
 | 
			
		||||
}
 | 
			
		||||
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							@@ -3,12 +3,13 @@
 | 
			
		||||
  <option name="family" value="inet6" />
 | 
			
		||||
  <short>abusers-ipv6</short>
 | 
			
		||||
  <description>A list of abusive IPv6 addresses.</description>
 | 
			
		||||
  <entry>2001:41d0:1:f934::1</entry>
 | 
			
		||||
  <entry>2001:41d0:602:238d::</entry>
 | 
			
		||||
  <entry>2001:41d0:a:2a31::</entry>
 | 
			
		||||
  <entry>2400:6180:0:d1::476:7001</entry>
 | 
			
		||||
  <entry>2402:1f00:8001:8bd::</entry>
 | 
			
		||||
  <entry>2604:a880:800:10::5bf:2001</entry>
 | 
			
		||||
  <entry>2a00:d680:20:50::bcb2</entry>
 | 
			
		||||
  <entry>2a02:2168:a01:33ee::1</entry>
 | 
			
		||||
  <entry>2001:470:1:332::7</entry>
 | 
			
		||||
  <entry>2001:470:1:c84::15</entry>
 | 
			
		||||
  <entry>2001:470:1:c84::22</entry>
 | 
			
		||||
  <entry>2001:470:1:c84::23</entry>
 | 
			
		||||
  <entry>2001:470:1:c84::25</entry>
 | 
			
		||||
  <entry>2a00:d680:20:50::3292</entry>
 | 
			
		||||
  <entry>2a00:d680:20:50::4a10</entry>
 | 
			
		||||
  <entry>2a02:c206:2062:6450::1</entry>
 | 
			
		||||
  <entry>2a03:b0c0:2:f0::34d:c001</entry>
 | 
			
		||||
</ipset>
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										89
									
								
								roles/common/files/aggregate-cidr-addresses.pl
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										89
									
								
								roles/common/files/aggregate-cidr-addresses.pl
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,89 @@
 | 
			
		||||
#!/usr/bin/perl
 | 
			
		||||
#
 | 
			
		||||
# aggregate-cidr-addresses - combine a list of CIDR address blocks
 | 
			
		||||
# Copyright (C) 2001,2007 Mark Suter <suter@zwitterion.org>
 | 
			
		||||
#
 | 
			
		||||
# This program is free software: you can redistribute it and/or modify
 | 
			
		||||
# it under the terms of the GNU General Public License as published by
 | 
			
		||||
# the Free Software Foundation, either version 3 of the License, or
 | 
			
		||||
# (at your option) any later version.
 | 
			
		||||
#
 | 
			
		||||
# This program is distributed in the hope that it will be useful,
 | 
			
		||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
 | 
			
		||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 | 
			
		||||
# GNU General Public License for more details.
 | 
			
		||||
#
 | 
			
		||||
# You should have received a copy of the GNU General Public License
 | 
			
		||||
# along with this program.  If not, see L<http://www.gnu.org/licenses/>.
 | 
			
		||||
#
 | 
			
		||||
# [MJS 22 Oct 2001] Aggregate CIDR addresses
 | 
			
		||||
# [MJS  9 Oct 2007] Overlap idea from Anthony Ledesma at theplanet dot com.
 | 
			
		||||
# [MJS 16 Feb 2012] Prompted to clarify license by Alexander Talos-Zens - at at univie dot ac dot at
 | 
			
		||||
# [MJS 21 Feb 2012] IPv6 fixes by Alexander Talos-Zens
 | 
			
		||||
# [MJS 21 Feb 2012] Split ranges into prefixes (fixes a 10+ year old bug)
 | 
			
		||||
 | 
			
		||||
use strict;
 | 
			
		||||
use warnings;
 | 
			
		||||
use English qw( -no_match_vars );
 | 
			
		||||
use Net::IP;
 | 
			
		||||
 | 
			
		||||
## Read in all the IP addresses
 | 
			
		||||
my @addrs = map { Net::IP->new($_) or die "$PROGRAM_NAME: Not an IP: \"$_\"."; }
 | 
			
		||||
    map { / \A \s* (.+?) \s* \Z /msix and $1; } <>;
 | 
			
		||||
 | 
			
		||||
## Split any ranges into prefixes
 | 
			
		||||
@addrs = map {
 | 
			
		||||
    defined $_->prefixlen ? $_ : map { Net::IP->new($_) }
 | 
			
		||||
        $_->find_prefixes
 | 
			
		||||
} @addrs;
 | 
			
		||||
 | 
			
		||||
## Sort the IP addresses
 | 
			
		||||
@addrs = sort { $a->version <=> $b->version or $a->bincomp( 'lt', $b ) ? -1 : $a->bincomp( 'gt', $b ) ? 1 : 0 } @addrs;
 | 
			
		||||
 | 
			
		||||
## Handle overlaps
 | 
			
		||||
my $count   = 0;
 | 
			
		||||
my $current = $addrs[0];
 | 
			
		||||
foreach my $next ( @addrs[ 1 .. $#addrs ] ) {
 | 
			
		||||
    my $r = $current->overlaps($next);
 | 
			
		||||
    if ( $current->version != $next->version or $r == $IP_NO_OVERLAP ) {
 | 
			
		||||
        $current = $next;
 | 
			
		||||
        $count++;
 | 
			
		||||
    }
 | 
			
		||||
    elsif ( $r == $IP_A_IN_B_OVERLAP ) {
 | 
			
		||||
        $current = $next;
 | 
			
		||||
        splice @addrs, $count, 1;
 | 
			
		||||
    }
 | 
			
		||||
    elsif ( $r == $IP_B_IN_A_OVERLAP or $r == $IP_IDENTICAL ) {
 | 
			
		||||
        splice @addrs, $count + 1, 1;
 | 
			
		||||
    }
 | 
			
		||||
    else {
 | 
			
		||||
        die "$PROGRAM_NAME: internal error - overlaps() returned an unexpected value!\n";
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
## Keep aggregating until we don't change anything
 | 
			
		||||
my $change = 1;
 | 
			
		||||
while ($change) {
 | 
			
		||||
    $change = 0;
 | 
			
		||||
    my @new_addrs = ();
 | 
			
		||||
    $current = $addrs[0];
 | 
			
		||||
    foreach my $next ( @addrs[ 1 .. $#addrs ] ) {
 | 
			
		||||
        if ( my $total = $current->aggregate($next) ) {
 | 
			
		||||
            $current = $total;
 | 
			
		||||
            $change  = 1;
 | 
			
		||||
        }
 | 
			
		||||
        else {
 | 
			
		||||
            push @new_addrs, $current;
 | 
			
		||||
            $current = $next;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    push @new_addrs, $current;
 | 
			
		||||
    @addrs = @new_addrs;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
## Print out the IP addresses
 | 
			
		||||
foreach (@addrs) {
 | 
			
		||||
    print $_->prefix(), "\n";
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# $Id: aggregate-cidr-addresses,v 1.9 2012/02/21 10:14:22 suter Exp suter $
 | 
			
		||||
							
								
								
									
										5
									
								
								roles/common/files/spamhaus-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										5
									
								
								roles/common/files/spamhaus-ipv4.nft
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,5 @@
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define SPAMHAUS_IPV4 = {
 | 
			
		||||
192.168.254.254/32
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										6
									
								
								roles/common/files/spamhaus-ipv4.xml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										6
									
								
								roles/common/files/spamhaus-ipv4.xml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,6 @@
 | 
			
		||||
<?xml version="1.0" encoding="utf-8"?>
 | 
			
		||||
<ipset type="hash:net">
 | 
			
		||||
  <option name="family" value="inet" />
 | 
			
		||||
  <short>spamhaus-ipv4</short>
 | 
			
		||||
  <description>Spamhaus DROP and EDROP lists placeholder (IPv4).</description>
 | 
			
		||||
</ipset>
 | 
			
		||||
							
								
								
									
										5
									
								
								roles/common/files/spamhaus-ipv6.nft
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										5
									
								
								roles/common/files/spamhaus-ipv6.nft
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,5 @@
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define SPAMHAUS_IPV6 = {
 | 
			
		||||
fd21:3523:74e0:7301::/64
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										6
									
								
								roles/common/files/spamhaus-ipv6.xml
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										6
									
								
								roles/common/files/spamhaus-ipv6.xml
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,6 @@
 | 
			
		||||
<?xml version="1.0" encoding="utf-8"?>
 | 
			
		||||
<ipset type="hash:net">
 | 
			
		||||
  <option name="family" value="inet6" />
 | 
			
		||||
  <short>spamhaus-ipv6</short>
 | 
			
		||||
  <description>Spamhaus DROP list placeholder (IPv6).</description>
 | 
			
		||||
</ipset>
 | 
			
		||||
							
								
								
									
										27
									
								
								roles/common/files/update-abusech-nftables.service
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										27
									
								
								roles/common/files/update-abusech-nftables.service
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,27 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Abuse.ch SSL Blacklist IPs
 | 
			
		||||
# This service will fail if nftables is not running so we use Requires to make
 | 
			
		||||
# sure that nftables is started.
 | 
			
		||||
Requires=nftables.service
 | 
			
		||||
# Make sure the network is up and nftables is started
 | 
			
		||||
After=network-online.target nftables.service
 | 
			
		||||
Wants=network-online.target update-abusech-nftables.timer
 | 
			
		||||
 | 
			
		||||
[Service]
 | 
			
		||||
# https://www.ctrl.blog/entry/systemd-service-hardening.html
 | 
			
		||||
# Doesn't need access to /home or /root
 | 
			
		||||
ProtectHome=true
 | 
			
		||||
# Possibly only works on Ubuntu 18.04+
 | 
			
		||||
ProtectKernelTunables=true
 | 
			
		||||
ProtectSystem=full
 | 
			
		||||
# Newer systemd can use ReadWritePaths to list files, but this works everywhere
 | 
			
		||||
ReadWriteDirectories=/etc/nftables
 | 
			
		||||
PrivateTmp=true
 | 
			
		||||
WorkingDirectory=/var/tmp
 | 
			
		||||
 | 
			
		||||
SyslogIdentifier=update-abusech-nftables
 | 
			
		||||
ExecStart=/usr/bin/flock -x update-abusech-nftables.lck \
 | 
			
		||||
          /usr/local/bin/update-abusech-nftables.sh
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=multi-user.target
 | 
			
		||||
							
								
								
									
										63
									
								
								roles/common/files/update-abusech-nftables.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										63
									
								
								roles/common/files/update-abusech-nftables.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,63 @@
 | 
			
		||||
#!/usr/bin/env bash
 | 
			
		||||
#
 | 
			
		||||
# update-abuseipdb-nftables.sh v0.0.1
 | 
			
		||||
#
 | 
			
		||||
# Download IP addresses seen using a blacklisted SSL certificate and load them
 | 
			
		||||
# into nftables sets. As of 2021-07-28 these appear to only be IPv4.
 | 
			
		||||
# 
 | 
			
		||||
# See: https://sslbl.abuse.ch/blacklist
 | 
			
		||||
#
 | 
			
		||||
# Copyright (C) 2021 Alan Orth
 | 
			
		||||
#
 | 
			
		||||
# SPDX-License-Identifier: GPL-3.0-only
 | 
			
		||||
 | 
			
		||||
# Exit on first error
 | 
			
		||||
set -o errexit
 | 
			
		||||
 | 
			
		||||
abusech_ipv4_set_path=/etc/nftables/abusech-ipv4.nft
 | 
			
		||||
abusech_list_temp=$(mktemp)
 | 
			
		||||
 | 
			
		||||
echo "Downloading Abuse.sh SSL Blacklist IPs"
 | 
			
		||||
 | 
			
		||||
abusech_response=$(curl -s -G -w "%{http_code}\n" https://sslbl.abuse.ch/blacklist/sslipblacklist.txt --output "$abusech_list_temp")
 | 
			
		||||
 | 
			
		||||
if [[ $abusech_response -ne 200 ]]; then
 | 
			
		||||
	echo "Abuse.ch responded: HTTP $abusech_response"
 | 
			
		||||
 | 
			
		||||
	exit 1
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
if [[ -f "$abusech_list_temp" ]]; then
 | 
			
		||||
    echo "Processing IPv4 list"
 | 
			
		||||
 | 
			
		||||
    abusech_ipv4_list_temp=$(mktemp)
 | 
			
		||||
    abusech_ipv4_set_temp=$(mktemp)
 | 
			
		||||
 | 
			
		||||
    # Remove comments, DOS carriage returns, and IPv6 addresses (even though
 | 
			
		||||
    # Abuse.ch seems to only have IPv4 addresses, let's not break our shit on
 | 
			
		||||
    # that assumption some time down the line).
 | 
			
		||||
    sed -e '/#/d' -e 's/
 | 
			
		||||
//' -e '/:/d' "$abusech_list_temp" > "$abusech_ipv4_list_temp"
 | 
			
		||||
 | 
			
		||||
    echo "Building abusech-ipv4 set"
 | 
			
		||||
    cat << NFT_HEAD > "$abusech_ipv4_set_temp"
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define ABUSECH_IPV4 = {
 | 
			
		||||
NFT_HEAD
 | 
			
		||||
 | 
			
		||||
    while read -r network; do
 | 
			
		||||
        # nftables doesn't mind if the last element in the set has a trailing
 | 
			
		||||
        # comma so we don't need to do anything special here.
 | 
			
		||||
        echo "$network," >> "$abusech_ipv4_set_temp"
 | 
			
		||||
    done < $abusech_ipv4_list_temp
 | 
			
		||||
 | 
			
		||||
    echo "}" >> "$abusech_ipv4_set_temp"
 | 
			
		||||
 | 
			
		||||
    install -m 0600 "$abusech_ipv4_set_temp" "$abusech_ipv4_set_path"
 | 
			
		||||
 | 
			
		||||
    rm -f "$abusech_list_temp" "$abusech_ipv4_list_temp" "$abusech_ipv4_set_temp"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
echo "Reloading nftables"
 | 
			
		||||
# The abusech nftables sets are included by nftables.conf
 | 
			
		||||
							
								
								
									
										12
									
								
								roles/common/files/update-abusech-nftables.timer
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								roles/common/files/update-abusech-nftables.timer
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,12 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Abuse.ch SSL Blacklist IPs
 | 
			
		||||
 | 
			
		||||
[Timer]
 | 
			
		||||
# Once a day at midnight
 | 
			
		||||
OnCalendar=*-*-* 00:00:00
 | 
			
		||||
# Add a random delay of 0–3600 seconds
 | 
			
		||||
RandomizedDelaySec=3600
 | 
			
		||||
Persistent=true
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=timers.target
 | 
			
		||||
							
								
								
									
										27
									
								
								roles/common/files/update-spamhaus-lists.service
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										27
									
								
								roles/common/files/update-spamhaus-lists.service
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,27 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Spamhaus lists
 | 
			
		||||
# This service will fail if firewalld is not running so we use Requires to make
 | 
			
		||||
# sure that firewalld is started.
 | 
			
		||||
Requires=firewalld.service
 | 
			
		||||
# Make sure the network is up and firewalld is started
 | 
			
		||||
After=network-online.target firewalld.service
 | 
			
		||||
Wants=network-online.target update-spamhaus-lists.timer
 | 
			
		||||
 | 
			
		||||
[Service]
 | 
			
		||||
# https://www.ctrl.blog/entry/systemd-service-hardening.html
 | 
			
		||||
# Doesn't need access to /home or /root
 | 
			
		||||
ProtectHome=true
 | 
			
		||||
# Possibly only works on Ubuntu 18.04+
 | 
			
		||||
ProtectKernelTunables=true
 | 
			
		||||
ProtectSystem=full
 | 
			
		||||
# Newer systemd can use ReadWritePaths to list files, but this works everywhere
 | 
			
		||||
ReadWriteDirectories=/etc/firewalld/ipsets
 | 
			
		||||
PrivateTmp=true
 | 
			
		||||
WorkingDirectory=/var/tmp
 | 
			
		||||
 | 
			
		||||
SyslogIdentifier=update-spamhaus-lists
 | 
			
		||||
ExecStart=/usr/bin/flock -x update-spamhaus-lists.lck \
 | 
			
		||||
          /usr/local/bin/update-spamhaus-lists.sh
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=multi-user.target
 | 
			
		||||
							
								
								
									
										107
									
								
								roles/common/files/update-spamhaus-lists.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										107
									
								
								roles/common/files/update-spamhaus-lists.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,107 @@
 | 
			
		||||
#!/usr/bin/env bash
 | 
			
		||||
#
 | 
			
		||||
# update-spamhaus-lists.sh v0.0.5
 | 
			
		||||
#
 | 
			
		||||
# Download Spamhaus DROP lists and load them into firewalld ipsets. Should work
 | 
			
		||||
# with both the iptables and nftables backends.
 | 
			
		||||
# 
 | 
			
		||||
# See: https://www.spamhaus.org/drop/
 | 
			
		||||
#
 | 
			
		||||
# Copyright (C) 2021 Alan Orth
 | 
			
		||||
#
 | 
			
		||||
# SPDX-License-Identifier: GPL-3.0-only
 | 
			
		||||
 | 
			
		||||
# Exit on first error
 | 
			
		||||
set -o errexit
 | 
			
		||||
 | 
			
		||||
firewalld_ipsets=$(firewall-cmd --get-ipsets)
 | 
			
		||||
xml_temp=$(mktemp)
 | 
			
		||||
spamhaus_ipv4_ipset_path=/etc/firewalld/ipsets/spamhaus-ipv4.xml
 | 
			
		||||
spamhaus_ipv6_ipset_path=/etc/firewalld/ipsets/spamhaus-ipv6.xml
 | 
			
		||||
 | 
			
		||||
function download() {
 | 
			
		||||
    echo "Downloading $1"
 | 
			
		||||
    wget -q -O - "https://www.spamhaus.org/drop/$1" > "$1"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
download drop.txt
 | 
			
		||||
download edrop.txt
 | 
			
		||||
download dropv6.txt
 | 
			
		||||
 | 
			
		||||
if [[ -f "drop.txt" && -f "edrop.txt" ]]; then
 | 
			
		||||
    echo "Processing IPv4 DROP lists"
 | 
			
		||||
 | 
			
		||||
    # Extract all networks from drop.txt and edrop.txt, skipping blank lines and
 | 
			
		||||
    # comments.
 | 
			
		||||
    networks=$(cat drop.txt edrop.txt | sed -e '/^$/d' -e '/^;.*/d' -e 's/[[:space:]];[[:space:]].*//')
 | 
			
		||||
 | 
			
		||||
    # If firewalld already has this ipset we should delete it first to emulate
 | 
			
		||||
    # `ipset flush` (but I don't want to use that because newer hosts might be
 | 
			
		||||
    # using nftables and firewalld will handle that for us).
 | 
			
		||||
    if [[ "$firewalld_ipsets" =~ spamhaus-ipv4 ]]; then
 | 
			
		||||
        echo "Deleting existing spamhaus-ipv4 ipset"
 | 
			
		||||
        # This deletes the firewalld ipset XML file as well as the ipset itself
 | 
			
		||||
        firewall-cmd --permanent --delete-ipset=spamhaus-ipv4
 | 
			
		||||
    else
 | 
			
		||||
        echo "Creating placeholder spamhaus-ipv4 ipset"
 | 
			
		||||
        # Create a placeholder ipset so firewalld doesn't complain when we try
 | 
			
		||||
        # to reload the ipset later after having added a new XML definition. I
 | 
			
		||||
        # don't know why, but depending on the system state there may not be a
 | 
			
		||||
        # ipset defined and firewalld errors on INVALID_IPSET.
 | 
			
		||||
        firewall-cmd --permanent --new-ipset=spamhaus-ipv4 --type=hash:net --option=family=inet
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    # I'm not proud of this, but writing the XML directly is WAY faster than
 | 
			
		||||
    # using firewall-cmd to add each entry one by one (and we can't add from
 | 
			
		||||
    # a file because many of our hosts are using old firewalld).
 | 
			
		||||
    cat << XML_HEAD > "$xml_temp"
 | 
			
		||||
<?xml version="1.0" encoding="utf-8"?>
 | 
			
		||||
<ipset type="hash:net">
 | 
			
		||||
  <option name="family" value="inet" />
 | 
			
		||||
  <short>spamhaus-ipv4</short>
 | 
			
		||||
  <description>Spamhaus DROP and EDROP lists (IPv4).</description>
 | 
			
		||||
XML_HEAD
 | 
			
		||||
 | 
			
		||||
    for network in $networks; do
 | 
			
		||||
		echo "    <entry>$network</entry>" >> "$xml_temp"
 | 
			
		||||
    done
 | 
			
		||||
 | 
			
		||||
    echo "</ipset>" >> "$xml_temp"
 | 
			
		||||
 | 
			
		||||
    install -m 0600 "$xml_temp" "$spamhaus_ipv4_ipset_path"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
if [[ -f "dropv6.txt" ]]; then
 | 
			
		||||
    echo "Processing IPv6 DROP list"
 | 
			
		||||
 | 
			
		||||
    networks=$(sed -e '/^$/d' -e '/^;.*/d' -e 's/[[:space:]];[[:space:]].*//' dropv6.txt)
 | 
			
		||||
 | 
			
		||||
    if [[ "$firewalld_ipsets" =~ spamhaus-ipv6 ]]; then
 | 
			
		||||
        echo "Deleting existing spamhaus-ipv6 ipset"
 | 
			
		||||
        firewall-cmd --permanent --delete-ipset=spamhaus-ipv6
 | 
			
		||||
    else
 | 
			
		||||
        echo "Creating placeholder spamhaus-ipv6 ipset"
 | 
			
		||||
        firewall-cmd --permanent --new-ipset=spamhaus-ipv6 --type=hash:net --option=family=inet6
 | 
			
		||||
    fi
 | 
			
		||||
 | 
			
		||||
    cat << XML_HEAD > "$xml_temp"
 | 
			
		||||
<?xml version="1.0" encoding="utf-8"?>
 | 
			
		||||
<ipset type="hash:net">
 | 
			
		||||
  <option name="family" value="inet6" />
 | 
			
		||||
  <short>spamhaus-ipv6</short>
 | 
			
		||||
  <description>Spamhaus DROP lists (IPv6).</description>
 | 
			
		||||
XML_HEAD
 | 
			
		||||
 | 
			
		||||
    for network in $networks; do
 | 
			
		||||
		echo "    <entry>$network</entry>" >> "$xml_temp"
 | 
			
		||||
    done
 | 
			
		||||
 | 
			
		||||
    echo "</ipset>" >> "$xml_temp"
 | 
			
		||||
 | 
			
		||||
    install -m 0600 "$xml_temp" "$spamhaus_ipv6_ipset_path"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
echo "Reloading firewalld"
 | 
			
		||||
firewall-cmd --reload
 | 
			
		||||
 | 
			
		||||
rm -v drop.txt edrop.txt dropv6.txt "$xml_temp"
 | 
			
		||||
							
								
								
									
										12
									
								
								roles/common/files/update-spamhaus-lists.timer
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								roles/common/files/update-spamhaus-lists.timer
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,12 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Spamhaus lists
 | 
			
		||||
 | 
			
		||||
[Timer]
 | 
			
		||||
# Once a day at midnight
 | 
			
		||||
OnCalendar=*-*-* 00:00:00
 | 
			
		||||
# Add a random delay of 0–3600 seconds
 | 
			
		||||
RandomizedDelaySec=3600
 | 
			
		||||
Persistent=true
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=timers.target
 | 
			
		||||
							
								
								
									
										27
									
								
								roles/common/files/update-spamhaus-nftables.service
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										27
									
								
								roles/common/files/update-spamhaus-nftables.service
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,27 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Spamhaus lists
 | 
			
		||||
# This service will fail if nftables is not running so we use Requires to make
 | 
			
		||||
# sure that nftables is started.
 | 
			
		||||
Requires=nftables.service
 | 
			
		||||
# Make sure the network is up and nftables is started
 | 
			
		||||
After=network-online.target nftables.service
 | 
			
		||||
Wants=network-online.target update-spamhaus-nftables.timer
 | 
			
		||||
 | 
			
		||||
[Service]
 | 
			
		||||
# https://www.ctrl.blog/entry/systemd-service-hardening.html
 | 
			
		||||
# Doesn't need access to /home or /root
 | 
			
		||||
ProtectHome=true
 | 
			
		||||
# Possibly only works on Ubuntu 18.04+
 | 
			
		||||
ProtectKernelTunables=true
 | 
			
		||||
ProtectSystem=full
 | 
			
		||||
# Newer systemd can use ReadWritePaths to list files, but this works everywhere
 | 
			
		||||
ReadWriteDirectories=/etc/nftables
 | 
			
		||||
PrivateTmp=true
 | 
			
		||||
WorkingDirectory=/var/tmp
 | 
			
		||||
 | 
			
		||||
SyslogIdentifier=update-spamhaus-nftables
 | 
			
		||||
ExecStart=/usr/bin/flock -x update-spamhaus-nftables.lck \
 | 
			
		||||
          /usr/local/bin/update-spamhaus-nftables.sh
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=multi-user.target
 | 
			
		||||
							
								
								
									
										91
									
								
								roles/common/files/update-spamhaus-nftables.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										91
									
								
								roles/common/files/update-spamhaus-nftables.sh
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,91 @@
 | 
			
		||||
#!/usr/bin/env bash
 | 
			
		||||
#
 | 
			
		||||
# update-spamhaus-nftables.sh v0.0.1
 | 
			
		||||
#
 | 
			
		||||
# Download Spamhaus DROP lists and load them into nftables sets.
 | 
			
		||||
# 
 | 
			
		||||
# See: https://www.spamhaus.org/drop/
 | 
			
		||||
#
 | 
			
		||||
# Copyright (C) 2021 Alan Orth
 | 
			
		||||
#
 | 
			
		||||
# SPDX-License-Identifier: GPL-3.0-only
 | 
			
		||||
 | 
			
		||||
# Exit on first error
 | 
			
		||||
set -o errexit
 | 
			
		||||
 | 
			
		||||
spamhaus_ipv4_set_path=/etc/nftables/spamhaus-ipv4.nft
 | 
			
		||||
spamhaus_ipv6_set_path=/etc/nftables/spamhaus-ipv6.nft
 | 
			
		||||
 | 
			
		||||
function download() {
 | 
			
		||||
    echo "Downloading $1"
 | 
			
		||||
    wget -q -O - "https://www.spamhaus.org/drop/$1" > "$1"
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
download drop.txt
 | 
			
		||||
download edrop.txt
 | 
			
		||||
download dropv6.txt
 | 
			
		||||
 | 
			
		||||
if [[ -f "drop.txt" && -f "edrop.txt" ]]; then
 | 
			
		||||
    echo "Processing IPv4 DROP lists"
 | 
			
		||||
 | 
			
		||||
    spamhaus_ipv4_list_temp=$(mktemp)
 | 
			
		||||
    spamhaus_ipv4_set_temp=$(mktemp)
 | 
			
		||||
 | 
			
		||||
    # Extract all networks from drop.txt and edrop.txt, skipping blank lines and
 | 
			
		||||
    # comments. Use aggregate-cidr-addresses.pl to merge overlapping IPv4 CIDR
 | 
			
		||||
    # ranges to work around a firewalld bug.
 | 
			
		||||
    #
 | 
			
		||||
    # See: https://bugzilla.redhat.com/show_bug.cgi?id=1836571
 | 
			
		||||
    cat drop.txt edrop.txt | sed -e '/^$/d' -e '/^;.*/d' -e 's/[[:space:]];[[:space:]].*//' | aggregate-cidr-addresses.pl > "$spamhaus_ipv4_list_temp"
 | 
			
		||||
 | 
			
		||||
    echo "Building spamhaus-ipv4 set"
 | 
			
		||||
    cat << NFT_HEAD > "$spamhaus_ipv4_set_temp"
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define SPAMHAUS_IPV4 = {
 | 
			
		||||
NFT_HEAD
 | 
			
		||||
 | 
			
		||||
    while read -r network; do
 | 
			
		||||
        # nftables doesn't mind if the last element in the set has a trailing
 | 
			
		||||
        # comma so we don't need to do anything special here.
 | 
			
		||||
        echo "$network," >> "$spamhaus_ipv4_set_temp"
 | 
			
		||||
    done < $spamhaus_ipv4_list_temp
 | 
			
		||||
 | 
			
		||||
    echo "}" >> "$spamhaus_ipv4_set_temp"
 | 
			
		||||
 | 
			
		||||
    install -m 0600 "$spamhaus_ipv4_set_temp" "$spamhaus_ipv4_set_path"
 | 
			
		||||
 | 
			
		||||
    rm -f "$spamhaus_ipv4_list_temp" "$spamhaus_ipv4_set_temp"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
if [[ -f "dropv6.txt" ]]; then
 | 
			
		||||
    echo "Processing IPv6 DROP lists"
 | 
			
		||||
 | 
			
		||||
    spamhaus_ipv6_list_temp=$(mktemp)
 | 
			
		||||
    spamhaus_ipv6_set_temp=$(mktemp)
 | 
			
		||||
 | 
			
		||||
    sed -e '/^$/d' -e '/^;.*/d' -e 's/[[:space:]];[[:space:]].*//' dropv6.txt > "$spamhaus_ipv6_list_temp"
 | 
			
		||||
 | 
			
		||||
    echo "Building spamhaus-ipv6 set"
 | 
			
		||||
    cat << NFT_HEAD > "$spamhaus_ipv6_set_temp"
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
 | 
			
		||||
define SPAMHAUS_IPV6 = {
 | 
			
		||||
NFT_HEAD
 | 
			
		||||
 | 
			
		||||
    while read -r network; do
 | 
			
		||||
        echo "$network," >> "$spamhaus_ipv6_set_temp"
 | 
			
		||||
    done < $spamhaus_ipv6_list_temp
 | 
			
		||||
 | 
			
		||||
    echo "}" >> "$spamhaus_ipv6_set_temp"
 | 
			
		||||
 | 
			
		||||
    install -m 0600 "$spamhaus_ipv6_set_temp" "$spamhaus_ipv6_set_path"
 | 
			
		||||
 | 
			
		||||
    rm -f "$spamhaus_ipv6_list_temp" "$spamhaus_ipv6_set_temp"
 | 
			
		||||
fi
 | 
			
		||||
 | 
			
		||||
echo "Reloading nftables"
 | 
			
		||||
# The spamhaus nftables sets are included by nftables.conf
 | 
			
		||||
/usr/sbin/nft -f /etc/nftables.conf
 | 
			
		||||
 | 
			
		||||
rm -v drop.txt edrop.txt dropv6.txt
 | 
			
		||||
							
								
								
									
										12
									
								
								roles/common/files/update-spamhaus-nftables.timer
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										12
									
								
								roles/common/files/update-spamhaus-nftables.timer
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,12 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Update Spamhaus lists
 | 
			
		||||
 | 
			
		||||
[Timer]
 | 
			
		||||
# Once a day at midnight
 | 
			
		||||
OnCalendar=*-*-* 00:00:00
 | 
			
		||||
# Add a random delay of 0–3600 seconds
 | 
			
		||||
RandomizedDelaySec=3600
 | 
			
		||||
Persistent=true
 | 
			
		||||
 | 
			
		||||
[Install]
 | 
			
		||||
WantedBy=timers.target
 | 
			
		||||
@@ -10,8 +10,14 @@
 | 
			
		||||
- name: restart firewalld
 | 
			
		||||
  systemd: name=firewalld state=restarted
 | 
			
		||||
 | 
			
		||||
- name: restart fail2ban
 | 
			
		||||
  systemd: name=fail2ban state=restarted
 | 
			
		||||
 | 
			
		||||
- name: reload systemd
 | 
			
		||||
  systemd: daemon_reload=yes
 | 
			
		||||
 | 
			
		||||
- name: restart nftables
 | 
			
		||||
  systemd: name=nftables state=restarted
 | 
			
		||||
 | 
			
		||||
# 2021-09-28: note to self to keep fail2ban at the end, as handlers are executed
 | 
			
		||||
# in the order they are defined, not in the order they are listed in the task's
 | 
			
		||||
# notify statement and we must restart fail2ban after updating the firewall.
 | 
			
		||||
- name: restart fail2ban
 | 
			
		||||
  systemd: name=fail2ban state=restarted
 | 
			
		||||
 
 | 
			
		||||
@@ -4,6 +4,11 @@
 | 
			
		||||
  template: src=etc/fail2ban/jail.d/sshd.local.j2 dest=/etc/fail2ban/jail.d/sshd.local owner=root mode=0644
 | 
			
		||||
  notify: restart fail2ban
 | 
			
		||||
 | 
			
		||||
- name: Configure fail2ban nginx filter
 | 
			
		||||
  when: "extra_fail2ban_filters is defined and 'nginx' in extra_fail2ban_filters"
 | 
			
		||||
  template: src=etc/fail2ban/jail.d/nginx.local.j2 dest=/etc/fail2ban/jail.d/nginx.local owner=root mode=0644
 | 
			
		||||
  notify: restart fail2ban
 | 
			
		||||
 | 
			
		||||
- name: Create fail2ban service override directory
 | 
			
		||||
  file: path=/etc/systemd/system/fail2ban.service.d state=directory owner=root mode=0755
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
@@ -1,7 +1,10 @@
 | 
			
		||||
---
 | 
			
		||||
# Debian 10 will use firewalld with the iptables backend.
 | 
			
		||||
# Debian 11 will use nftables directly, with no firewalld.
 | 
			
		||||
 | 
			
		||||
- block:
 | 
			
		||||
  - name: Set Debian firewall packages
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '<=')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      debian_firewall_packages:
 | 
			
		||||
        - firewalld
 | 
			
		||||
@@ -9,49 +12,146 @@
 | 
			
		||||
        - fail2ban
 | 
			
		||||
        - python3-systemd # for fail2ban systemd backend
 | 
			
		||||
 | 
			
		||||
  - name: Install firewalld and deps
 | 
			
		||||
    when: ansible_distribution_major_version is version('9', '>=')
 | 
			
		||||
    apt: pkg={{ debian_firewall_packages }} state=present
 | 
			
		||||
  - name: Set Debian firewall packages
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      debian_firewall_packages:
 | 
			
		||||
        - fail2ban
 | 
			
		||||
        - libnet-ip-perl # for aggregate-cidr-addresses.pl
 | 
			
		||||
        - nftables
 | 
			
		||||
        - python3-systemd
 | 
			
		||||
        - curl # for nftables update scripts
 | 
			
		||||
 | 
			
		||||
  - name: Install firewall packages
 | 
			
		||||
    apt: pkg={{ debian_firewall_packages }} state=present cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
  - name: Remove iptables on newer Debian
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    apt: pkg=iptables state=absent
 | 
			
		||||
 | 
			
		||||
  - name: Copy nftables.conf
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    template: src=nftables.conf.j2 dest=/etc/nftables.conf owner=root mode=0644
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart nftables
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Create /etc/nftables extra config directory
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    file: path=/etc/nftables state=directory owner=root mode=0755
 | 
			
		||||
 | 
			
		||||
  - name: Copy extra nftables configuration files
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    copy: src={{ item.src }} dest=/etc/nftables/{{ item.src }} owner=root group=root mode=0644 force={{ item.force }}
 | 
			
		||||
    loop:
 | 
			
		||||
      - { src: "spamhaus-ipv4.nft", force: "no" }
 | 
			
		||||
      - { src: "spamhaus-ipv6.nft", force: "no" }
 | 
			
		||||
      - { src: "abusech-ipv4.nft", force: "no" }
 | 
			
		||||
      - { src: "abuseipdb-ipv4.nft", force: "yes" }
 | 
			
		||||
      - { src: "abuseipdb-ipv6.nft", force: "yes" }
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart nftables
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Use iptables backend in firewalld
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '>=')
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '==')
 | 
			
		||||
    lineinfile:
 | 
			
		||||
      dest: /etc/firewalld/firewalld.conf
 | 
			
		||||
      regexp: '^FirewallBackend=nftables$'
 | 
			
		||||
      line: 'FirewallBackend=iptables'
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
# firewalld seems to have an issue with iptables 1.8.2 when using the nftables
 | 
			
		||||
# backend. Using individual calls seems to work around it.
 | 
			
		||||
# See: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931722
 | 
			
		||||
  - name: Use individual iptables calls
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '>=')
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '==')
 | 
			
		||||
    lineinfile:
 | 
			
		||||
      dest: /etc/firewalld/firewalld.conf
 | 
			
		||||
      regexp: '^IndividualCalls=no$'
 | 
			
		||||
      line: 'IndividualCalls=yes'
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy firewalld public zone file
 | 
			
		||||
    when: ansible_distribution_major_version is version('9', '>=')
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '<=')
 | 
			
		||||
    template: src=public.xml.j2 dest=/etc/firewalld/zones/public.xml owner=root mode=0600
 | 
			
		||||
 | 
			
		||||
  - name: Format public.xml firewalld zone file
 | 
			
		||||
    when: ansible_distribution_major_version is version('9', '>=')
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '<=')
 | 
			
		||||
    command: tidy -xml -iq -m -w 0 /etc/firewalld/zones/public.xml
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy ipsets of abusive IPs
 | 
			
		||||
    when: ansible_distribution_major_version is version('9', '>=')
 | 
			
		||||
  - name: Copy firewalld ipsets of abusive IPs
 | 
			
		||||
    when: ansible_distribution_major_version is version('10', '<=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/firewalld/ipsets/{{ item }} owner=root group=root mode=0600
 | 
			
		||||
    loop:
 | 
			
		||||
      - abusers-ipv4.xml
 | 
			
		||||
      - abusers-ipv6.xml
 | 
			
		||||
      - spamhaus-ipv4.xml
 | 
			
		||||
      - spamhaus-ipv6.xml
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy Spamhaus firewalld update script
 | 
			
		||||
    when: ansible_distribution_version is version('10', '<=')
 | 
			
		||||
    copy: src=update-spamhaus-lists.sh dest=/usr/local/bin/update-spamhaus-lists.sh mode=0755 owner=root group=root
 | 
			
		||||
 | 
			
		||||
  - name: Copy Spamhaus firewalld systemd units
 | 
			
		||||
    when: ansible_distribution_version is version('10', '<=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/systemd/system/{{ item }} mode=0644 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
        - update-spamhaus-lists.service
 | 
			
		||||
        - update-spamhaus-lists.timer
 | 
			
		||||
    register: spamhaus_firewalld_systemd_units
 | 
			
		||||
 | 
			
		||||
  - name: Copy Spamhaus nftables update scripts
 | 
			
		||||
    when: ansible_distribution_version is version('11', '>=')
 | 
			
		||||
    copy: src={{ item }} dest=/usr/local/bin/{{ item }} mode=0755 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
      - update-spamhaus-nftables.sh
 | 
			
		||||
      - aggregate-cidr-addresses.pl
 | 
			
		||||
      - update-abusech-nftables.sh
 | 
			
		||||
 | 
			
		||||
  - name: Copy nftables systemd units
 | 
			
		||||
    when: ansible_distribution_version is version('11', '>=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/systemd/system/{{ item }} mode=0644 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
        - update-spamhaus-nftables.service
 | 
			
		||||
        - update-spamhaus-nftables.timer
 | 
			
		||||
        - update-abusech-nftables.service
 | 
			
		||||
        - update-abusech-nftables.timer
 | 
			
		||||
    register: nftables_systemd_units
 | 
			
		||||
 | 
			
		||||
  # need to reload to pick up service/timer/environment changes
 | 
			
		||||
  - name: Reload systemd daemon
 | 
			
		||||
    systemd: daemon_reload=yes
 | 
			
		||||
    when: spamhaus_firewalld_systemd_units is changed or
 | 
			
		||||
          nftables_systemd_units is changed
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable Spamhaus firewalld update timer
 | 
			
		||||
    when: ansible_distribution_version is version('10', '<=')
 | 
			
		||||
    systemd: name=update-spamhaus-lists.timer state=started enabled=yes
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable nftables update timers
 | 
			
		||||
    when: ansible_distribution_version is version('11', '>=')
 | 
			
		||||
    systemd: name={{ item }} state=started enabled=yes
 | 
			
		||||
    loop:
 | 
			
		||||
      - update-spamhaus-nftables.timer
 | 
			
		||||
      - update-abusech-nftables.timer
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable nftables
 | 
			
		||||
    when: ansible_distribution_major_version is version('11', '>=')
 | 
			
		||||
    systemd: name=nftables state=started enabled=yes
 | 
			
		||||
 | 
			
		||||
  - include_tasks: fail2ban.yml
 | 
			
		||||
    when: ansible_distribution_major_version is version('9', '>=')
 | 
			
		||||
 
 | 
			
		||||
@@ -1,7 +1,11 @@
 | 
			
		||||
---
 | 
			
		||||
# Ubuntu 20.04 will use nftables directly, with no firewalld.
 | 
			
		||||
# Ubuntu 18.04 will use firewalld with the nftables backend.
 | 
			
		||||
# Ubuntu 16.04 will use firewalld with the iptables backend.
 | 
			
		||||
 | 
			
		||||
- block:
 | 
			
		||||
  - name: Set Ubuntu firewall packages
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '<')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      ubuntu_firewall_packages:
 | 
			
		||||
        - firewalld
 | 
			
		||||
@@ -9,53 +13,123 @@
 | 
			
		||||
        - fail2ban
 | 
			
		||||
        - python3-systemd # for fail2ban systemd backend
 | 
			
		||||
 | 
			
		||||
  - name: Install firewalld and deps
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
    apt: pkg={{ ubuntu_firewall_packages }} state=present
 | 
			
		||||
  - name: Set Ubuntu firewall packages
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      ubuntu_firewall_packages:
 | 
			
		||||
        - fail2ban
 | 
			
		||||
        - libnet-ip-perl # for aggregate-cidr-addresses.pl
 | 
			
		||||
        - nftables
 | 
			
		||||
        - python3-systemd
 | 
			
		||||
        - curl # for nftables update scripts
 | 
			
		||||
 | 
			
		||||
  - name: Install firewall packages
 | 
			
		||||
    apt: pkg={{ ubuntu_firewall_packages }} state=present cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
  - name: Remove ufw
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
    apt: pkg=ufw state=absent
 | 
			
		||||
 | 
			
		||||
  # I'm not sure why, but you can use firewalld with the nftables backend even
 | 
			
		||||
  # if nftables itself is not installed. In that case the only way to see the
 | 
			
		||||
  # currently active rules is with firewall-cmd. I prefer installing nftables
 | 
			
		||||
  # so that we can have somewhat of a parallel with iptables:
 | 
			
		||||
  #
 | 
			
		||||
  #   nft list ruleset
 | 
			
		||||
  #
 | 
			
		||||
  # See: https://firewalld.org/2018/07/nftables-backend
 | 
			
		||||
  - name: Install nftables
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '==')
 | 
			
		||||
    apt: pkg=nftables state=present
 | 
			
		||||
 | 
			
		||||
  - name: Use nftables backend in firewalld
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '==')
 | 
			
		||||
    lineinfile:
 | 
			
		||||
      dest: /etc/firewalld/firewalld.conf
 | 
			
		||||
      regexp: '^FirewallBackend=iptables$'
 | 
			
		||||
      line: 'FirewallBackend=nftables'
 | 
			
		||||
  - name: Copy nftables.conf
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    template: src=nftables.conf.j2 dest=/etc/nftables.conf owner=root mode=0644
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart nftables
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Create /etc/nftables extra config directory
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    file: path=/etc/nftables state=directory owner=root mode=0755
 | 
			
		||||
 | 
			
		||||
  - name: Copy extra nftables configuration files
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    copy: src={{ item.src }} dest=/etc/nftables/{{ item.src }} owner=root group=root mode=0644 force={{ item.force }}
 | 
			
		||||
    loop:
 | 
			
		||||
      - { src: "spamhaus-ipv4.nft", force: "no" }
 | 
			
		||||
      - { src: "spamhaus-ipv6.nft", force: "no" }
 | 
			
		||||
      - { src: "abusech-ipv4.nft", force: "no" }
 | 
			
		||||
      - { src: "abuseipdb-ipv4.nft", force: "yes" }
 | 
			
		||||
      - { src: "abuseipdb-ipv6.nft", force: "yes" }
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart nftables
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy firewalld public zone file
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    template: src=public.xml.j2 dest=/etc/firewalld/zones/public.xml owner=root mode=0600
 | 
			
		||||
 | 
			
		||||
  - name: Format public.xml firewalld zone file
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    command: tidy -xml -iq -m -w 0 /etc/firewalld/zones/public.xml
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy ipsets of abusive IPs
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
  - name: Copy firewalld ipsets of abusive IPs
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/firewalld/ipsets/{{ item }} owner=root group=root mode=0600
 | 
			
		||||
    loop:
 | 
			
		||||
      - abusers-ipv4.xml
 | 
			
		||||
      - abusers-ipv6.xml
 | 
			
		||||
      - spamhaus-ipv4.xml
 | 
			
		||||
      - spamhaus-ipv6.xml
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Copy Spamhaus firewalld update script
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    copy: src=update-spamhaus-lists.sh dest=/usr/local/bin/update-spamhaus-lists.sh mode=0755 owner=root group=root
 | 
			
		||||
 | 
			
		||||
  - name: Copy Spamhaus firewalld systemd units
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/systemd/system/{{ item }} mode=0644 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
        - update-spamhaus-lists.service
 | 
			
		||||
        - update-spamhaus-lists.timer
 | 
			
		||||
    register: spamhaus_firewalld_systemd_units
 | 
			
		||||
 | 
			
		||||
  - name: Copy nftables update scripts
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    copy: src={{ item }} dest=/usr/local/bin/{{ item }} mode=0755 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
      - update-spamhaus-nftables.sh
 | 
			
		||||
      - aggregate-cidr-addresses.pl
 | 
			
		||||
      - update-abusech-nftables.sh
 | 
			
		||||
 | 
			
		||||
  - name: Copy nftables systemd units
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    copy: src={{ item }} dest=/etc/systemd/system/{{ item }} mode=0644 owner=root group=root
 | 
			
		||||
    loop:
 | 
			
		||||
        - update-spamhaus-nftables.service
 | 
			
		||||
        - update-spamhaus-nftables.timer
 | 
			
		||||
        - update-abusech-nftables.service
 | 
			
		||||
        - update-abusech-nftables.timer
 | 
			
		||||
    register: nftables_systemd_units
 | 
			
		||||
 | 
			
		||||
  # need to reload to pick up service/timer/environment changes
 | 
			
		||||
  - name: Reload systemd daemon
 | 
			
		||||
    systemd: daemon_reload=yes
 | 
			
		||||
    when: spamhaus_firewalld_systemd_units is changed or
 | 
			
		||||
          nftables_systemd_units is changed
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable Spamhaus firewalld update timer
 | 
			
		||||
    when: ansible_distribution_version is version('18.04', '<=')
 | 
			
		||||
    systemd: name=update-spamhaus-lists.timer state=started enabled=yes
 | 
			
		||||
    notify:
 | 
			
		||||
      - restart firewalld
 | 
			
		||||
      - restart fail2ban
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable nftables update timers
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    systemd: name={{ item }} state=started enabled=yes
 | 
			
		||||
    loop:
 | 
			
		||||
      - update-spamhaus-nftables.timer
 | 
			
		||||
      - update-abusech-nftables.timer
 | 
			
		||||
 | 
			
		||||
  - name: Start and enable nftables
 | 
			
		||||
    when: ansible_distribution_version is version('20.04', '>=')
 | 
			
		||||
    systemd: name=nftables state=started enabled=yes
 | 
			
		||||
 | 
			
		||||
  - include_tasks: fail2ban.yml
 | 
			
		||||
    when: ansible_distribution_version is version('16.04', '>=')
 | 
			
		||||
 
 | 
			
		||||
@@ -1,18 +1,27 @@
 | 
			
		||||
---
 | 
			
		||||
# Hosts running Ubuntu 16.04+ and Debian 9+ use systemd init system and should
 | 
			
		||||
# use timedatectl as a network time client instead of the standalone ntp client.
 | 
			
		||||
# use systemd-timesyncd as a network time client instead of the standalone ntp
 | 
			
		||||
# client.
 | 
			
		||||
 | 
			
		||||
- name: Set timezone
 | 
			
		||||
  when: timezone is defined and ansible_service_mgr == 'systemd'
 | 
			
		||||
  command: /usr/bin/timedatectl set-timezone {{ timezone }}
 | 
			
		||||
  tags: timezone
 | 
			
		||||
 | 
			
		||||
# Apparently some cloud images don't have this installed by default. From what
 | 
			
		||||
# I can see on existing servers, systemd-timesyncd is a standalone package on
 | 
			
		||||
# Ubuntu 20.04 and Debian 11.
 | 
			
		||||
- name: Install systemd-timesyncd
 | 
			
		||||
  when: (ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==')) or
 | 
			
		||||
        (ansible_distribution == 'Debian' and ansible_distribution_version is version('11', '=='))
 | 
			
		||||
  apt: name=systemd-timesyncd state=present cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
- name: Start and enable systemd's NTP client
 | 
			
		||||
  when: ansible_service_mgr == 'systemd'
 | 
			
		||||
  systemd: name=systemd-timesyncd state=started enabled=yes
 | 
			
		||||
 | 
			
		||||
- name: Uninstall ntp on modern Ubuntu/Debian
 | 
			
		||||
  apt: name=ntp state=absent update_cache=yes
 | 
			
		||||
  apt: name=ntp state=absent
 | 
			
		||||
  when: ansible_service_mgr == 'systemd'
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -3,11 +3,13 @@
 | 
			
		||||
- block:
 | 
			
		||||
  - name: Configure apt mirror
 | 
			
		||||
    template: src=sources.list.j2 dest=/etc/apt/sources.list owner=root group=root mode=0644
 | 
			
		||||
    when: ansible_architecture != 'armv7l'
 | 
			
		||||
 | 
			
		||||
  - name: Set fact for base packages
 | 
			
		||||
    set_fact:
 | 
			
		||||
      base_packages:
 | 
			
		||||
        - git
 | 
			
		||||
        - git-lfs
 | 
			
		||||
        - tmux
 | 
			
		||||
        - iotop
 | 
			
		||||
        - htop
 | 
			
		||||
@@ -22,9 +24,11 @@
 | 
			
		||||
        - apt-transport-https # for https support in apt
 | 
			
		||||
        - gnupg2
 | 
			
		||||
        - zstd
 | 
			
		||||
        - rsync
 | 
			
		||||
        - lsof
 | 
			
		||||
 | 
			
		||||
  - name: Install base packages
 | 
			
		||||
    apt: name={{ base_packages }} state=present update_cache=yes cache_valid_time=3600
 | 
			
		||||
    apt: name={{ base_packages }} state=present cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
  - name: Configure cron-apt
 | 
			
		||||
    import_tasks: cron-apt.yml
 | 
			
		||||
 
 | 
			
		||||
@@ -6,12 +6,13 @@
 | 
			
		||||
    when: ansible_architecture != 'armv7l'
 | 
			
		||||
 | 
			
		||||
  - name: Upgrade base OS
 | 
			
		||||
    apt: upgrade=dist update_cache=yes cache_valid_time=3600
 | 
			
		||||
    apt: upgrade=dist cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
  - name: Set Ubuntu base packages
 | 
			
		||||
    set_fact:
 | 
			
		||||
      ubuntu_base_packages:
 | 
			
		||||
      - git
 | 
			
		||||
      - git-lfs
 | 
			
		||||
      - tmux
 | 
			
		||||
      - iotop
 | 
			
		||||
      - htop
 | 
			
		||||
@@ -25,9 +26,11 @@
 | 
			
		||||
      - unzip
 | 
			
		||||
      - apt-transport-https # for https support in apt
 | 
			
		||||
      - zstd
 | 
			
		||||
      - rsync
 | 
			
		||||
      - lsof
 | 
			
		||||
 | 
			
		||||
  - name: Install base packages
 | 
			
		||||
    apt: pkg={{ ubuntu_base_packages }} state=present update_cache=yes cache_valid_time=3600
 | 
			
		||||
    apt: pkg={{ ubuntu_base_packages }} state=present cache_valid_time=3600
 | 
			
		||||
 | 
			
		||||
  # We have to remove snaps one by one in a specific order because some depend
 | 
			
		||||
  # on others. Only after that can we remove the corresponding system packages.
 | 
			
		||||
 
 | 
			
		||||
@@ -13,6 +13,32 @@
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu'
 | 
			
		||||
  notify: reload sshd
 | 
			
		||||
 | 
			
		||||
# See: WeakDH (2015): https://weakdh.org/sysadmin.html
 | 
			
		||||
- name: Remove small Diffie-Hellman SSH moduli
 | 
			
		||||
  block:
 | 
			
		||||
    - name: Check unsafe Diffie-Hellman SSH moduli
 | 
			
		||||
      ansible.builtin.shell:
 | 
			
		||||
        cmd: awk '$5 < 3071' moduli
 | 
			
		||||
        chdir: /etc/ssh
 | 
			
		||||
        creates: moduli.safe
 | 
			
		||||
      register: check_unsafe_moduli
 | 
			
		||||
 | 
			
		||||
    - name: Extract safe Diffie-Hellman SSH moduli
 | 
			
		||||
      ansible.builtin.shell:
 | 
			
		||||
        cmd: awk '$5 >= 3071' moduli > moduli.safe
 | 
			
		||||
        chdir: /etc/ssh
 | 
			
		||||
        creates: moduli.safe
 | 
			
		||||
      when: check_unsafe_moduli.stdout | length > 0
 | 
			
		||||
      register: extract_safe_moduli
 | 
			
		||||
 | 
			
		||||
    - name: Replace unsafe Diffie-Hellman SSH moduli
 | 
			
		||||
      ansible.builtin.command:
 | 
			
		||||
        cmd: mv moduli.safe moduli
 | 
			
		||||
        chdir: /etc/ssh
 | 
			
		||||
      register: replace_small_moduli
 | 
			
		||||
      when: extract_safe_moduli is changed
 | 
			
		||||
      notify: reload sshd
 | 
			
		||||
 | 
			
		||||
- name: Remove DSA and ECDSA host keys
 | 
			
		||||
  file: name=/etc/ssh/{{ item }} state=absent
 | 
			
		||||
  loop:
 | 
			
		||||
 
 | 
			
		||||
@@ -5,7 +5,7 @@
 | 
			
		||||
  when: ansible_architecture != 'armv7l'
 | 
			
		||||
 | 
			
		||||
- name: Add GPG key for Tarsnap
 | 
			
		||||
  apt_key: id=0xFC72A10BF6B692AA url=https://pkg.tarsnap.com/tarsnap-deb-packaging-key.asc state=present
 | 
			
		||||
  apt_key: id=0xBF75EEAB040E447C url=https://pkg.tarsnap.com/tarsnap-deb-packaging-key.asc state=present
 | 
			
		||||
  register: add_tarsnap_apt_key
 | 
			
		||||
 | 
			
		||||
- name: Update apt cache
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										18
									
								
								roles/common/templates/etc/fail2ban/jail.d/nginx.local.j2
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										18
									
								
								roles/common/templates/etc/fail2ban/jail.d/nginx.local.j2
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,18 @@
 | 
			
		||||
[nginx]
 | 
			
		||||
enabled   = true
 | 
			
		||||
# See: /etc/fail2ban/filter.d/nginx-botsearch.conf
 | 
			
		||||
filter    = nginx-botsearch
 | 
			
		||||
{% if (ansible_distribution == 'Debian' and ansible_distribution_major_version is version('11', '>=')) or (ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '>=')) %}
 | 
			
		||||
# Integrate with nftables
 | 
			
		||||
banaction=nftables[type=allports]
 | 
			
		||||
{% else %}
 | 
			
		||||
# Integrate with firewalld and ipsets
 | 
			
		||||
banaction = firewallcmd-ipset
 | 
			
		||||
{% endif %}
 | 
			
		||||
backend   = pyinotify
 | 
			
		||||
logpath   = /var/log/nginx/*-access.log
 | 
			
		||||
# Try to find a non-existent wp-login.php once and get banned. Tough luck.
 | 
			
		||||
maxretry  = 1
 | 
			
		||||
findtime  = {{ fail2ban_findtime }}
 | 
			
		||||
bantime   = {{ fail2ban_bantime }}
 | 
			
		||||
ignoreip  = {{ fail2ban_ignoreip }}
 | 
			
		||||
@@ -2,8 +2,13 @@
 | 
			
		||||
enabled   = true
 | 
			
		||||
# See: /etc/fail2ban/filter.d/sshd.conf
 | 
			
		||||
filter    = sshd
 | 
			
		||||
{% if (ansible_distribution == 'Debian' and ansible_distribution_major_version is version('11', '>=')) or (ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '>=')) %}
 | 
			
		||||
# Integrate with nftables
 | 
			
		||||
banaction=nftables[type=allports]
 | 
			
		||||
{% else %}
 | 
			
		||||
# Integrate with firewalld and ipsets
 | 
			
		||||
banaction = firewallcmd-ipset
 | 
			
		||||
{% endif %}
 | 
			
		||||
backend   = systemd
 | 
			
		||||
maxretry  = {{ fail2ban_maxretry }}
 | 
			
		||||
findtime  = {{ fail2ban_findtime }}
 | 
			
		||||
 
 | 
			
		||||
@@ -2,14 +2,14 @@
 | 
			
		||||
PrivateDevices=yes
 | 
			
		||||
PrivateTmp=yes
 | 
			
		||||
ProtectHome=read-only
 | 
			
		||||
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=') %}
 | 
			
		||||
{% if (ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=')) or (ansible_distribution == 'Debian' and ansible_distribution_major_version is version('11','>=')) %}
 | 
			
		||||
ProtectSystem=strict
 | 
			
		||||
{% else %}
 | 
			
		||||
{# Older systemd versions don't have ProtectSystem=strict #}
 | 
			
		||||
ProtectSystem=full
 | 
			
		||||
{% endif %}
 | 
			
		||||
NoNewPrivileges=yes
 | 
			
		||||
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=') %}
 | 
			
		||||
{% if (ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=')) or (ansible_distribution == 'Debian' and ansible_distribution_major_version is version('11','>=')) %}
 | 
			
		||||
ReadWritePaths=-/var/run/fail2ban
 | 
			
		||||
ReadWritePaths=-/var/lib/fail2ban
 | 
			
		||||
ReadWritePaths=-/var/log/fail2ban.log
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										116
									
								
								roles/common/templates/nftables.conf.j2
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										116
									
								
								roles/common/templates/nftables.conf.j2
									
									
									
									
									
										Executable file
									
								
							@@ -0,0 +1,116 @@
 | 
			
		||||
#!/usr/sbin/nft -f
 | 
			
		||||
#
 | 
			
		||||
# Initially based on: https://wiki.nftables.org/wiki-nftables/index.php/Simple_ruleset_for_a_server
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
flush ruleset
 | 
			
		||||
 | 
			
		||||
# Lists updated daily by update-spamhaus-nftables.sh
 | 
			
		||||
include "/etc/nftables/spamhaus-ipv4.nft"
 | 
			
		||||
include "/etc/nftables/spamhaus-ipv6.nft"
 | 
			
		||||
 | 
			
		||||
# Lists updated monthly (manually)
 | 
			
		||||
include "/etc/nftables/abuseipdb-ipv4.nft"
 | 
			
		||||
include "/etc/nftables/abuseipdb-ipv6.nft"
 | 
			
		||||
 | 
			
		||||
# Lists updated daily by update-abusech-nftables.sh
 | 
			
		||||
include "/etc/nftables/abusech-ipv4.nft"
 | 
			
		||||
 | 
			
		||||
# Notes:
 | 
			
		||||
#   - tables hold chains, chains hold rules
 | 
			
		||||
#   - inet is for both ipv4 and ipv6
 | 
			
		||||
table inet filter {
 | 
			
		||||
    set spamhaus-ipv4 {
 | 
			
		||||
        type ipv4_addr
 | 
			
		||||
        # if the set contains prefixes we need to use the interval flag
 | 
			
		||||
        flags interval
 | 
			
		||||
        elements = $SPAMHAUS_IPV4
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    set spamhaus-ipv6 {
 | 
			
		||||
        type ipv6_addr
 | 
			
		||||
        flags interval
 | 
			
		||||
        elements = $SPAMHAUS_IPV6
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    set abusech-ipv4 {
 | 
			
		||||
        type ipv4_addr
 | 
			
		||||
        elements = $ABUSECH_IPV4
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    set abuseipdb-ipv4 {
 | 
			
		||||
        type ipv4_addr
 | 
			
		||||
        elements = $ABUSEIPDB_IPV4
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    set abuseipdb-ipv6 {
 | 
			
		||||
        type ipv6_addr
 | 
			
		||||
        elements = $ABUSEIPDB_IPV6
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    chain input {
 | 
			
		||||
        type filter hook input priority 0;
 | 
			
		||||
 | 
			
		||||
        ct state {established, related} accept comment "Allow traffic from established and related packets"
 | 
			
		||||
 | 
			
		||||
        ct state invalid counter drop comment "Early drop of invalid connections"
 | 
			
		||||
 | 
			
		||||
        ip saddr @spamhaus-ipv4 counter drop comment "Early drop of incoming packets matching spamhaus-ipv4 list"
 | 
			
		||||
        ip6 saddr @spamhaus-ipv6 counter drop comment "Early drop of incoming packets matching spamhaus-ipv6 list"
 | 
			
		||||
 | 
			
		||||
        ip saddr @abusech-ipv4 counter drop comment "Early drop of packets matching abusech-ipv4 list"
 | 
			
		||||
 | 
			
		||||
        ip saddr @abuseipdb-ipv4 counter drop comment "Early drop of incoming packets matching abuseipdb-ipv4 list"
 | 
			
		||||
        ip6 saddr @abuseipdb-ipv6 counter drop comment "Early drop of incoming packets matching abuseipdb-ipv6 list"
 | 
			
		||||
 | 
			
		||||
        iifname lo accept comment "Allow from loopback"
 | 
			
		||||
 | 
			
		||||
        ip protocol icmp limit rate 4/second accept comment "Allow ICMP"
 | 
			
		||||
        ip6 nexthdr ipv6-icmp limit rate 4/second accept comment "Allow IPv6 ICMP"
 | 
			
		||||
        ip protocol igmp limit rate 4/second accept comment "Allow IGMP"
 | 
			
		||||
 | 
			
		||||
        {# SSH rules #}
 | 
			
		||||
        ip saddr 0.0.0.0/0 ct state new tcp dport 22 counter accept comment "Allow SSH"
 | 
			
		||||
        ip6 saddr ::/0 ct state new tcp dport 22 counter accept comment "Allow SSH"
 | 
			
		||||
 | 
			
		||||
        {# Web rules #}
 | 
			
		||||
        {% if 'web' in group_names %}
 | 
			
		||||
        ip saddr 0.0.0.0/0 ct state new tcp dport 80 counter accept comment "Allow HTTP"
 | 
			
		||||
        ip saddr 0.0.0.0/0 ct state new tcp dport 443 counter accept comment "Allow HTTPS"
 | 
			
		||||
        ip6 saddr ::/0 ct state new tcp dport 80 counter accept comment "Allow HTTP"
 | 
			
		||||
        ip6 saddr ::/0 ct state new tcp dport 443 counter accept comment "Allow HTTPS"
 | 
			
		||||
        {% endif %}
 | 
			
		||||
 | 
			
		||||
        ip saddr 0.0.0.0/0 ct state new udp dport 60001-60003 counter accept comment "Allow mosh"
 | 
			
		||||
        ip6 saddr ::/0 ct state new udp dport 60001-60003 counter accept comment "Allow mosh"
 | 
			
		||||
 | 
			
		||||
        {# Extra rules #}
 | 
			
		||||
        {% if extra_iptables_rules is defined %}
 | 
			
		||||
        {% for rule in extra_iptables_rules %}
 | 
			
		||||
        ip saddr {{ ghetto_ipsets[rule.acl].src }} ct state new {{ rule.protocol }} dport {{ rule.port }} counter accept
 | 
			
		||||
 | 
			
		||||
        {% if ghetto_ipsets[rule.acl].ipv6src is defined %}
 | 
			
		||||
        ip6 saddr {{ ghetto_ipsets[rule.acl].ipv6src }} ct state new {{ rule.protocol }} dport {{ rule.port }} counter accept
 | 
			
		||||
        {% endif %}
 | 
			
		||||
 | 
			
		||||
        {% endfor %}
 | 
			
		||||
        {% endif %}
 | 
			
		||||
 | 
			
		||||
        # everything else
 | 
			
		||||
        reject with icmpx type port-unreachable
 | 
			
		||||
    }
 | 
			
		||||
    chain forward {
 | 
			
		||||
        type filter hook forward priority 0;
 | 
			
		||||
    }
 | 
			
		||||
    chain output {
 | 
			
		||||
        type filter hook output priority 0;
 | 
			
		||||
 | 
			
		||||
        ip daddr @spamhaus-ipv4 counter drop comment "Drop outgoing packets matching spamhaus-ipv4 list"
 | 
			
		||||
        ip6 daddr @spamhaus-ipv6 counter drop comment "Drop outgoing packets matching spamhaus-ipv6 list"
 | 
			
		||||
 | 
			
		||||
        ip daddr @abusech-ipv4 counter drop comment "Drop outgoing packets matching abusech-ipv4 list"
 | 
			
		||||
 | 
			
		||||
        ip daddr @abuseipdb-ipv4 counter drop comment "Drop outgoing packets matching abuseipdb-ipv4 list"
 | 
			
		||||
        ip6 daddr @abuseipdb-ipv6 counter drop comment "Drop outgoing packets matching abuseipdb-ipv6 list"
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
@@ -69,4 +69,13 @@
 | 
			
		||||
      <source ipset="abusers-ipv6"/>
 | 
			
		||||
      <drop/>
 | 
			
		||||
    </rule>
 | 
			
		||||
    <rule>
 | 
			
		||||
      <source ipset="spamhaus-ipv4"/>
 | 
			
		||||
      <drop/>
 | 
			
		||||
    </rule>
 | 
			
		||||
    <rule>
 | 
			
		||||
      <source ipset="spamhaus-ipv6"/>
 | 
			
		||||
      <drop/>
 | 
			
		||||
    </rule>
 | 
			
		||||
 | 
			
		||||
</zone>
 | 
			
		||||
 
 | 
			
		||||
@@ -9,7 +9,7 @@ deb http://security.ubuntu.com/ubuntu/ {{ ansible_distribution_release }}-securi
 | 
			
		||||
{% set apt_mirror    = apt_mirror | default('deb.debian.org') %}
 | 
			
		||||
deb http://{{ apt_mirror }}/debian/ {{ ansible_distribution_release }} main contrib non-free
 | 
			
		||||
 | 
			
		||||
deb http://security.debian.org/debian-security {{ ansible_distribution_release }}/updates main contrib non-free
 | 
			
		||||
deb http://security.debian.org/debian-security {{ ansible_distribution_release }}-security main contrib non-free
 | 
			
		||||
 | 
			
		||||
deb http://{{ apt_mirror }}/debian/ {{ ansible_distribution_release }}-updates main contrib non-free
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										143
									
								
								roles/common/templates/sshd_config_Debian-11.j2
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										143
									
								
								roles/common/templates/sshd_config_Debian-11.j2
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,143 @@
 | 
			
		||||
#	$OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $
 | 
			
		||||
 | 
			
		||||
# This is the sshd server system-wide configuration file.  See
 | 
			
		||||
# sshd_config(5) for more information.
 | 
			
		||||
 | 
			
		||||
# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin
 | 
			
		||||
 | 
			
		||||
# The strategy used for options in the default sshd_config shipped with
 | 
			
		||||
# OpenSSH is to specify options with their default value where
 | 
			
		||||
# possible, but leave them commented.  Uncommented options override the
 | 
			
		||||
# default value.
 | 
			
		||||
 | 
			
		||||
Include /etc/ssh/sshd_config.d/*.conf
 | 
			
		||||
 | 
			
		||||
#Port 22
 | 
			
		||||
#AddressFamily any
 | 
			
		||||
#ListenAddress 0.0.0.0
 | 
			
		||||
#ListenAddress ::
 | 
			
		||||
 | 
			
		||||
#HostKey /etc/ssh/ssh_host_rsa_key
 | 
			
		||||
HostKey /etc/ssh/ssh_host_ed25519_key
 | 
			
		||||
 | 
			
		||||
# Ciphers and keying
 | 
			
		||||
#RekeyLimit default none
 | 
			
		||||
 | 
			
		||||
# Logging
 | 
			
		||||
#SyslogFacility AUTH
 | 
			
		||||
# LogLevel VERBOSE logs user's key fingerprint on login. Needed to have a clear audit track of which key was using to log in.
 | 
			
		||||
LogLevel VERBOSE
 | 
			
		||||
 | 
			
		||||
# Authentication:
 | 
			
		||||
 | 
			
		||||
#LoginGraceTime 2m
 | 
			
		||||
PermitRootLogin prohibit-password
 | 
			
		||||
#StrictModes yes
 | 
			
		||||
MaxAuthTries 4
 | 
			
		||||
#MaxSessions 10
 | 
			
		||||
 | 
			
		||||
#PubkeyAuthentication yes
 | 
			
		||||
 | 
			
		||||
# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2
 | 
			
		||||
# but this is overridden so installations will only check .ssh/authorized_keys
 | 
			
		||||
AuthorizedKeysFile	.ssh/authorized_keys
 | 
			
		||||
 | 
			
		||||
#AuthorizedPrincipalsFile none
 | 
			
		||||
 | 
			
		||||
#AuthorizedKeysCommand none
 | 
			
		||||
#AuthorizedKeysCommandUser nobody
 | 
			
		||||
 | 
			
		||||
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
 | 
			
		||||
#HostbasedAuthentication no
 | 
			
		||||
# Change to yes if you don't trust ~/.ssh/known_hosts for
 | 
			
		||||
# HostbasedAuthentication
 | 
			
		||||
#IgnoreUserKnownHosts no
 | 
			
		||||
# Don't read the user's ~/.rhosts and ~/.shosts files
 | 
			
		||||
#IgnoreRhosts yes
 | 
			
		||||
 | 
			
		||||
# To disable tunneled clear text passwords, change to no here!
 | 
			
		||||
#PasswordAuthentication yes
 | 
			
		||||
#PermitEmptyPasswords no
 | 
			
		||||
 | 
			
		||||
# Change to yes to enable challenge-response passwords (beware issues with
 | 
			
		||||
# some PAM modules and threads)
 | 
			
		||||
ChallengeResponseAuthentication no
 | 
			
		||||
 | 
			
		||||
# Kerberos options
 | 
			
		||||
#KerberosAuthentication no
 | 
			
		||||
#KerberosOrLocalPasswd yes
 | 
			
		||||
#KerberosTicketCleanup yes
 | 
			
		||||
#KerberosGetAFSToken no
 | 
			
		||||
 | 
			
		||||
# GSSAPI options
 | 
			
		||||
#GSSAPIAuthentication no
 | 
			
		||||
#GSSAPICleanupCredentials yes
 | 
			
		||||
#GSSAPIStrictAcceptorCheck yes
 | 
			
		||||
#GSSAPIKeyExchange no
 | 
			
		||||
 | 
			
		||||
# Set this to 'yes' to enable PAM authentication, account processing,
 | 
			
		||||
# and session processing. If this is enabled, PAM authentication will
 | 
			
		||||
# be allowed through the ChallengeResponseAuthentication and
 | 
			
		||||
# PasswordAuthentication.  Depending on your PAM configuration,
 | 
			
		||||
# PAM authentication via ChallengeResponseAuthentication may bypass
 | 
			
		||||
# the setting of "PermitRootLogin without-password".
 | 
			
		||||
# If you just want the PAM account and session checks to run without
 | 
			
		||||
# PAM authentication, then enable this but set PasswordAuthentication
 | 
			
		||||
# and ChallengeResponseAuthentication to 'no'.
 | 
			
		||||
UsePAM yes
 | 
			
		||||
 | 
			
		||||
#AllowAgentForwarding yes
 | 
			
		||||
#AllowTcpForwarding yes
 | 
			
		||||
#GatewayPorts no
 | 
			
		||||
X11Forwarding no
 | 
			
		||||
#X11DisplayOffset 10
 | 
			
		||||
#X11UseLocalhost yes
 | 
			
		||||
#PermitTTY yes
 | 
			
		||||
PrintMotd no
 | 
			
		||||
#PrintLastLog yes
 | 
			
		||||
#TCPKeepAlive yes
 | 
			
		||||
#PermitUserEnvironment no
 | 
			
		||||
#Compression delayed
 | 
			
		||||
#ClientAliveInterval 0
 | 
			
		||||
#ClientAliveCountMax 3
 | 
			
		||||
#UseDNS no
 | 
			
		||||
#PidFile /var/run/sshd.pid
 | 
			
		||||
#MaxStartups 10:30:100
 | 
			
		||||
#PermitTunnel no
 | 
			
		||||
#ChrootDirectory none
 | 
			
		||||
#VersionAddendum none
 | 
			
		||||
 | 
			
		||||
# no default banner path
 | 
			
		||||
#Banner none
 | 
			
		||||
 | 
			
		||||
# Allow client to pass locale environment variables
 | 
			
		||||
AcceptEnv LANG LC_*
 | 
			
		||||
 | 
			
		||||
# override default of no subsystems
 | 
			
		||||
Subsystem	sftp	/usr/lib/openssh/sftp-server
 | 
			
		||||
 | 
			
		||||
# Example of overriding settings on a per-user basis
 | 
			
		||||
#Match User anoncvs
 | 
			
		||||
#	X11Forwarding no
 | 
			
		||||
#	AllowTcpForwarding no
 | 
			
		||||
#	PermitTTY no
 | 
			
		||||
#	ForceCommand cvs server
 | 
			
		||||
 
 | 
			
		||||
# Based on the ssh-audit profile for OpenSSH 8.4, but with but with all algos
 | 
			
		||||
# with less than 256 bits removed, as NSA's Suite B removed them years ago and
 | 
			
		||||
# the new (2018) CNSA suite is 256 bits and up.
 | 
			
		||||
#
 | 
			
		||||
# See: https://github.com/jtesta/ssh-audit/blob/master/src/ssh_audit/policy.py
 | 
			
		||||
# See: https://en.wikipedia.org/wiki/Commercial_National_Security_Algorithm_Suite
 | 
			
		||||
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes256-ctr
 | 
			
		||||
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
 | 
			
		||||
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
 | 
			
		||||
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes256-ctr
 | 
			
		||||
 | 
			
		||||
{% if ssh_allowed_users is defined and ssh_allowed_users %}
 | 
			
		||||
# Is there a list of allowed users?
 | 
			
		||||
# Is it populated? (An empty list is 'None', which evaluates as False in Python)
 | 
			
		||||
# merge the items of a list into one string using a space as a separator
 | 
			
		||||
# http://jinja.pocoo.org/docs/dev/templates/#join
 | 
			
		||||
AllowUsers {{ ssh_allowed_users|join(" ") }} {{ provisioning_user.name }}
 | 
			
		||||
{% endif %}
 | 
			
		||||
@@ -128,8 +128,8 @@ PasswordAuthentication yes
 | 
			
		||||
# ... but with ciphers and MACs with < 256 bits removed, as NSA's Suite B now
 | 
			
		||||
# does away with these! See: https://www.nsa.gov/ia/programs/suiteb_cryptography/index.shtml
 | 
			
		||||
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes256-ctr
 | 
			
		||||
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256
 | 
			
		||||
KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256
 | 
			
		||||
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
 | 
			
		||||
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256
 | 
			
		||||
 | 
			
		||||
{% if ssh_allowed_users is defined and ssh_allowed_users %}
 | 
			
		||||
# Is there a list of allowed users?
 | 
			
		||||
 
 | 
			
		||||
@@ -17,7 +17,7 @@ innodb_buffer_pool_size: 256M
 | 
			
		||||
# Ansible 2.7.x with PyMySQL seems to default to TCP connection so we should
 | 
			
		||||
# force it to use a Unix socket.
 | 
			
		||||
# See: https://github.com/ansible/ansible/issues/47736
 | 
			
		||||
mariadb_login_unix_socket: /var/run/mysqld/mysqld.sock
 | 
			
		||||
mariadb_login_unix_socket: /run/mysqld/mysqld.sock
 | 
			
		||||
 | 
			
		||||
# default is 100 but the max I've seen used is 5, so let's reduce it
 | 
			
		||||
max_connections: 33
 | 
			
		||||
 
 | 
			
		||||
@@ -29,29 +29,27 @@
 | 
			
		||||
    - restart mariadb
 | 
			
		||||
  tags: mariadb
 | 
			
		||||
 | 
			
		||||
# 'localhost' needs to be the last item for idempotency, see
 | 
			
		||||
# https://docs.ansible.com/ansible/latest/mysql_user_module.html
 | 
			
		||||
# See: https://docs.ansible.com/ansible/latest/collections/community/mysql/mysql_user_module.html
 | 
			
		||||
- name: Update MariaDB root password for all root accounts
 | 
			
		||||
  mysql_user: name=root host={{ item }} password={{ mariadb_root_password }} login_unix_socket={{ mariadb_login_unix_socket }}
 | 
			
		||||
  loop:
 | 
			
		||||
    - "{{ inventory_hostname }}"
 | 
			
		||||
    - 127.0.0.1
 | 
			
		||||
    - ::1
 | 
			
		||||
    - localhost
 | 
			
		||||
  tags: mariadb
 | 
			
		||||
 | 
			
		||||
- name: Create .my.conf file with root credentials
 | 
			
		||||
  template: src=.my.cnf.j2 dest=/root/.my.cnf owner=root mode=0600
 | 
			
		||||
  tags: mariadb
 | 
			
		||||
 | 
			
		||||
# See: https://docs.ansible.com/ansible/latest/collections/community/mysql/mysql_db_module.html
 | 
			
		||||
- name: Create MariaDB database(s)
 | 
			
		||||
  mysql_db: db={{ item.name }} state=present encoding=utf8mb4
 | 
			
		||||
  mysql_db: db={{ item.name }} state=present encoding=utf8mb4 login_unix_socket={{ mariadb_login_unix_socket }}
 | 
			
		||||
  loop: "{{ mariadb_databases }}"
 | 
			
		||||
  when: mariadb_databases is defined
 | 
			
		||||
  tags: mariadb
 | 
			
		||||
 | 
			
		||||
- name: Create MariaDB user(s)
 | 
			
		||||
  mysql_user: name={{ item.user }} password={{ item.pass }} priv={{ item.name }}.*:ALL host=127.0.0.1 state=present
 | 
			
		||||
  mysql_user: name={{ item.user }} password={{ item.pass }} priv={{ item.name }}.*:ALL host=127.0.0.1 state=present login_unix_socket={{ mariadb_login_unix_socket }}
 | 
			
		||||
  loop: "{{ mariadb_databases }}"
 | 
			
		||||
  when: mariadb_databases is defined
 | 
			
		||||
  tags: mariadb
 | 
			
		||||
 
 | 
			
		||||
@@ -19,14 +19,14 @@
 | 
			
		||||
# Remember to edit /etc/mysql/debian.cnf when changing the socket location.
 | 
			
		||||
[client]
 | 
			
		||||
port		= 3306
 | 
			
		||||
socket		= /var/run/mysqld/mysqld.sock
 | 
			
		||||
socket		= /run/mysqld/mysqld.sock
 | 
			
		||||
 | 
			
		||||
# Here is entries for some specific programs
 | 
			
		||||
# The following values assume you have at least 32M ram
 | 
			
		||||
 | 
			
		||||
# This was formally known as [safe_mysqld]. Both versions are currently parsed.
 | 
			
		||||
[mysqld_safe]
 | 
			
		||||
socket		= /var/run/mysqld/mysqld.sock
 | 
			
		||||
socket		= /run/mysqld/mysqld.sock
 | 
			
		||||
nice		= 0
 | 
			
		||||
 | 
			
		||||
[mysqld]
 | 
			
		||||
@@ -34,8 +34,8 @@ nice		= 0
 | 
			
		||||
# * Basic Settings
 | 
			
		||||
#
 | 
			
		||||
user		= mysql
 | 
			
		||||
pid-file	= /var/run/mysqld/mysqld.pid
 | 
			
		||||
socket		= /var/run/mysqld/mysqld.sock
 | 
			
		||||
pid-file	= /run/mysqld/mysqld.pid
 | 
			
		||||
socket		= /run/mysqld/mysqld.sock
 | 
			
		||||
port		= 3306
 | 
			
		||||
basedir		= /usr
 | 
			
		||||
datadir		= /var/lib/mysql
 | 
			
		||||
 
 | 
			
		||||
@@ -20,18 +20,25 @@ nginx_ssl_protocols: 'TLSv1.2 TLSv1.3'
 | 
			
		||||
# See: https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_stapling
 | 
			
		||||
nginx_ssl_stapling_resolver: '1.1.1.1 1.0.0.1 [2606:4700:4700::1111] [2606:4700:4700::1001]'
 | 
			
		||||
 | 
			
		||||
# install certbot + dependencies?
 | 
			
		||||
# HTTP Strict-Transport-Security header, recommended by Google to be ~1 year
 | 
			
		||||
# in seconds, see: https://hstspreload.org/
 | 
			
		||||
nginx_hsts_max_age: 31536000
 | 
			
		||||
 | 
			
		||||
# install acme.sh?
 | 
			
		||||
# True unless you're in development and using "localhost" + snakeoil certs
 | 
			
		||||
use_letsencrypt: True
 | 
			
		||||
 | 
			
		||||
# Directory root for Let's Encrypt certs
 | 
			
		||||
letsencrypt_root: /etc/letsencrypt/live
 | 
			
		||||
letsencrypt_root: /etc/ssl
 | 
			
		||||
 | 
			
		||||
# Location of Let's Encrypt's certbot script
 | 
			
		||||
letsencrypt_certbot_dest: /opt/certbot-auto
 | 
			
		||||
# Location where to save initial acme.sh script. After installation the script
 | 
			
		||||
# will automatically create its home in the /root/.acme.sh directory (including
 | 
			
		||||
# a copy of the script itself). The initial script is not needed after.
 | 
			
		||||
letsencrypt_acme_script_temp: /root/acme.sh
 | 
			
		||||
letsencrypt_acme_home: /root/.acme.sh
 | 
			
		||||
 | 
			
		||||
# stable is 1.18.x
 | 
			
		||||
# mainline is 1.19.x
 | 
			
		||||
# stable is 1.20.x
 | 
			
		||||
# mainline is 1.21.x
 | 
			
		||||
nginx_version: mainline
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -15,3 +15,6 @@ add_header X-XSS-Protection "1; mode=block" always;
 | 
			
		||||
# CSP can be quite difficult to configure, and cause real issues if you get it wrong
 | 
			
		||||
# There is website that helps you generate a policy here http://cspisawesome.com/
 | 
			
		||||
# add_header Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' https://www.google-analytics.com;" always;
 | 
			
		||||
 | 
			
		||||
# Opt this site out of Google Chrome's Federated Learning of Cohorts (FLoC)
 | 
			
		||||
add_header Permissions-Policy interest-cohort=() always;
 | 
			
		||||
 
 | 
			
		||||
@@ -1,3 +0,0 @@
 | 
			
		||||
#!/usr/bin/env bash
 | 
			
		||||
 | 
			
		||||
/bin/systemctl start nginx
 | 
			
		||||
@@ -1,3 +0,0 @@
 | 
			
		||||
#!/usr/bin/env bash
 | 
			
		||||
 | 
			
		||||
/bin/systemctl stop nginx
 | 
			
		||||
@@ -1,137 +1,89 @@
 | 
			
		||||
---
 | 
			
		||||
 | 
			
		||||
# Use acme.sh instead of certbot because they only support installation via
 | 
			
		||||
# snap now.
 | 
			
		||||
- block:
 | 
			
		||||
  - name: Remove certbot
 | 
			
		||||
    apt:
 | 
			
		||||
      name: certbot
 | 
			
		||||
      state: absent
 | 
			
		||||
 | 
			
		||||
  - name: Remove old certbot post and pre hooks for nginx
 | 
			
		||||
    file:
 | 
			
		||||
      dest: "{{ item }}"
 | 
			
		||||
      state: absent
 | 
			
		||||
    with_items:
 | 
			
		||||
      - /etc/letsencrypt/renewal-hooks/pre/stop-nginx.sh
 | 
			
		||||
      - /etc/letsencrypt/renewal-hooks/post/start-nginx.sh
 | 
			
		||||
 | 
			
		||||
  - name: Check if acme.sh is installed
 | 
			
		||||
    stat:
 | 
			
		||||
      path: "{{ letsencrypt_acme_home }}"
 | 
			
		||||
    register: acme_home
 | 
			
		||||
 | 
			
		||||
  - name: Download acme.sh
 | 
			
		||||
    get_url:
 | 
			
		||||
      url: https://raw.githubusercontent.com/acmesh-official/acme.sh/master/acme.sh
 | 
			
		||||
      dest: "{{ letsencrypt_acme_script_temp }}"
 | 
			
		||||
      mode: 0700
 | 
			
		||||
    register: acme_download
 | 
			
		||||
    when: not acme_home.stat.exists
 | 
			
		||||
 | 
			
		||||
  # Run the "install" for acme.sh so it creates the .acme.sh dir (currently I
 | 
			
		||||
  # have to chdir to the /root directory where the script exists or else it
 | 
			
		||||
  # fails. Ansible runs it, but the script can't find itself...).
 | 
			
		||||
  - name: Install acme.sh
 | 
			
		||||
    ansible.builtin.command:
 | 
			
		||||
      cmd: "{{ letsencrypt_acme_script_temp }} --install --no-profile --no-cron"
 | 
			
		||||
      creates: "{{ letsencrypt_acme_home }}/acme.sh"
 | 
			
		||||
      chdir: /root
 | 
			
		||||
    register: acme_install
 | 
			
		||||
    when: acme_download is changed
 | 
			
		||||
 | 
			
		||||
  - name: Remove temporary acme.sh script
 | 
			
		||||
    file:
 | 
			
		||||
      dest: "{{ letsencrypt_acme_script_temp }}"
 | 
			
		||||
      state: absent
 | 
			
		||||
    when: acme_install.rc is defined and acme_install.rc == 0
 | 
			
		||||
 | 
			
		||||
  - name: Set default certificate authority for acme.sh
 | 
			
		||||
    ansible.builtin.command:
 | 
			
		||||
      cmd: "{{ letsencrypt_acme_home }}/acme.sh --set-default-ca --server letsencrypt"
 | 
			
		||||
 | 
			
		||||
  - name: Prepare Let's Encrypt well-known directory
 | 
			
		||||
    file:
 | 
			
		||||
      state: directory
 | 
			
		||||
      path: /var/lib/letsencrypt/.well-known
 | 
			
		||||
      owner: root
 | 
			
		||||
      group: nginx
 | 
			
		||||
      mode: g+s
 | 
			
		||||
 | 
			
		||||
  - name: Copy systemd service to renew Let's Encrypt certs
 | 
			
		||||
    template: src=renew-letsencrypt.service.j2 dest=/etc/systemd/system/renew-letsencrypt.service mode=0644 owner=root group=root
 | 
			
		||||
    template:
 | 
			
		||||
      src: renew-letsencrypt.service.j2
 | 
			
		||||
      dest: /etc/systemd/system/renew-letsencrypt.service
 | 
			
		||||
      mode: 0644
 | 
			
		||||
      owner: root
 | 
			
		||||
      group: root
 | 
			
		||||
 | 
			
		||||
  - name: Copy systemd timer to renew Let's Encrypt certs
 | 
			
		||||
    copy: src=renew-letsencrypt.timer dest=/etc/systemd/system/renew-letsencrypt.timer mode=0644 owner=root group=root
 | 
			
		||||
    copy:
 | 
			
		||||
      src: renew-letsencrypt.timer
 | 
			
		||||
      dest: /etc/systemd/system/renew-letsencrypt.timer
 | 
			
		||||
      mode: 0644
 | 
			
		||||
      owner: root
 | 
			
		||||
      group: root
 | 
			
		||||
 | 
			
		||||
  # always issues daemon-reload just in case the server/timer changed
 | 
			
		||||
  # always issues daemon-reload just in case the service/timer changed
 | 
			
		||||
  - name: Start and enable systemd timer to renew Let's Encrypt certs
 | 
			
		||||
    systemd: name=renew-letsencrypt.timer state=started enabled=yes daemon_reload=yes
 | 
			
		||||
    systemd:
 | 
			
		||||
      name: renew-letsencrypt.timer
 | 
			
		||||
      state: started
 | 
			
		||||
      enabled: yes
 | 
			
		||||
      daemon_reload: yes
 | 
			
		||||
 | 
			
		||||
  - name: Download certbot
 | 
			
		||||
    get_url: dest={{ letsencrypt_certbot_dest }} url=https://dl.eff.org/certbot-auto mode=700
 | 
			
		||||
 | 
			
		||||
  # Dependencies certbot checks for on its first run. I set them in a fact so that
 | 
			
		||||
  # I can pass the list directly to the apt module to install in one transaction.
 | 
			
		||||
  - name: Set certbot dependencies (Debian 10)
 | 
			
		||||
    when: ansible_distribution == 'Debian' and ansible_distribution_major_version is version('10', '==')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      certbot_dependencies:
 | 
			
		||||
        - augeas-lenses
 | 
			
		||||
        - binutils
 | 
			
		||||
        - binutils-common
 | 
			
		||||
        - binutils-x86-64-linux-gnu
 | 
			
		||||
        - cpp
 | 
			
		||||
        - cpp-8
 | 
			
		||||
        - gcc
 | 
			
		||||
        - gcc-8
 | 
			
		||||
        - libasan5
 | 
			
		||||
        - libatomic1
 | 
			
		||||
        - libaugeas0
 | 
			
		||||
        - libbinutils
 | 
			
		||||
        - libc-dev-bin
 | 
			
		||||
        - libc6-dev
 | 
			
		||||
        - libcc1-0
 | 
			
		||||
        - libexpat1-dev
 | 
			
		||||
        - libffi-dev
 | 
			
		||||
        - libgcc-8-dev
 | 
			
		||||
        - libgomp1
 | 
			
		||||
        - libisl19
 | 
			
		||||
        - libitm1
 | 
			
		||||
        - liblsan0
 | 
			
		||||
        - libmpc3
 | 
			
		||||
        - libmpfr6
 | 
			
		||||
        - libmpx2
 | 
			
		||||
        - libpython-dev
 | 
			
		||||
        - libpython2-dev
 | 
			
		||||
        - libpython2.7
 | 
			
		||||
        - libpython2.7-dev
 | 
			
		||||
        - libquadmath0
 | 
			
		||||
        - libssl-dev
 | 
			
		||||
        - libtsan0
 | 
			
		||||
        - libubsan1
 | 
			
		||||
        - linux-libc-dev
 | 
			
		||||
        - python-dev
 | 
			
		||||
        - python-pip-whl
 | 
			
		||||
        - python-pkg-resources
 | 
			
		||||
        - python-virtualenv
 | 
			
		||||
        - python2-dev
 | 
			
		||||
        - python2.7-dev
 | 
			
		||||
        - python3-distutils
 | 
			
		||||
        - python3-lib2to3
 | 
			
		||||
        - python3-virtualenv
 | 
			
		||||
        - virtualenv
 | 
			
		||||
 | 
			
		||||
  # Dependencies certbot checks for on its first run. I set them in a fact so that
 | 
			
		||||
  # I can pass the list directly to the apt module to install in one transaction.
 | 
			
		||||
  - name: Set certbot dependencies (Ubuntu 18.04)
 | 
			
		||||
    when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('18.04', '==')
 | 
			
		||||
    set_fact:
 | 
			
		||||
      certbot_dependencies:
 | 
			
		||||
        - augeas-lenses
 | 
			
		||||
        - binutils
 | 
			
		||||
        - binutils-common
 | 
			
		||||
        - binutils-x86-64-linux-gnu
 | 
			
		||||
        - cpp
 | 
			
		||||
        - cpp-7
 | 
			
		||||
        - gcc
 | 
			
		||||
        - gcc-7
 | 
			
		||||
        - gcc-7-base
 | 
			
		||||
        - libasan4
 | 
			
		||||
        - libatomic1
 | 
			
		||||
        - libaugeas0
 | 
			
		||||
        - libbinutils
 | 
			
		||||
        - libc-dev-bin
 | 
			
		||||
        - libc6-dev
 | 
			
		||||
        - libcc1-0
 | 
			
		||||
        - libcilkrts5
 | 
			
		||||
        - libexpat1-dev
 | 
			
		||||
        - libffi-dev
 | 
			
		||||
        - libgcc-7-dev
 | 
			
		||||
        - libgomp1
 | 
			
		||||
        - libisl19
 | 
			
		||||
        - libitm1
 | 
			
		||||
        - liblsan0
 | 
			
		||||
        - libmpc3
 | 
			
		||||
        - libmpx2
 | 
			
		||||
        - libpython-dev
 | 
			
		||||
        - libpython2.7
 | 
			
		||||
        - libpython2.7-dev
 | 
			
		||||
        - libquadmath0
 | 
			
		||||
        - libssl-dev
 | 
			
		||||
        - libtsan0
 | 
			
		||||
        - libubsan0
 | 
			
		||||
        - linux-libc-dev
 | 
			
		||||
        - python-dev
 | 
			
		||||
        - python-pip-whl
 | 
			
		||||
        - python-pkg-resources
 | 
			
		||||
        - python-virtualenv
 | 
			
		||||
        - python2.7-dev
 | 
			
		||||
        - python3-virtualenv
 | 
			
		||||
        - virtualenv
 | 
			
		||||
 | 
			
		||||
  - name: Install certbot dependencies
 | 
			
		||||
    apt: name={{ certbot_dependencies }} state=present update_cache=yes
 | 
			
		||||
 | 
			
		||||
  when: ansible_distribution != 'Ubuntu' and ansible_distribution_major_version is version('20.04', '!=')
 | 
			
		||||
  tags: letsencrypt
 | 
			
		||||
 | 
			
		||||
# On Ubuntu 20.04 it is no longer recommended/supported to use the standalone
 | 
			
		||||
# certbot-auto so I guess we need to use the one from the repositories.
 | 
			
		||||
- block:
 | 
			
		||||
  - name: Install certbot (Ubuntu 20.04)
 | 
			
		||||
    apt: name=certbot state=present update_cache=yes
 | 
			
		||||
 | 
			
		||||
  - name: Copy certbot post and pre hooks for nginx
 | 
			
		||||
    copy: src={{ item.src }} dest={{ item.dest }} owner=root group=root mode=0755
 | 
			
		||||
    with_items:
 | 
			
		||||
      - { src: 'stop-nginx.sh', dest: '/etc/letsencrypt/renewal-hooks/pre/stop-nginx.sh' }
 | 
			
		||||
      - { src: 'start-nginx.sh', dest: '/etc/letsencrypt/renewal-hooks/post/start-nginx.sh' }
 | 
			
		||||
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==')
 | 
			
		||||
  when: (ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '=='))
 | 
			
		||||
        or (ansible_distribution == 'Debian' and ansible_distribution_version is version('11', '=='))
 | 
			
		||||
  tags: letsencrypt
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -71,7 +71,6 @@
 | 
			
		||||
 | 
			
		||||
- name: Configure Let's Encrypt
 | 
			
		||||
  include_tasks: letsencrypt.yml
 | 
			
		||||
  when: use_letsencrypt is defined and use_letsencrypt
 | 
			
		||||
  tags: letsencrypt
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -12,11 +12,15 @@
 | 
			
		||||
    notify:
 | 
			
		||||
      - reload nginx
 | 
			
		||||
 | 
			
		||||
  - name: Generate 2048-bit dhparam
 | 
			
		||||
    command: openssl dhparam -out dhparam.pem 2048 chdir=/etc/ssl/certs creates=dhparam.pem
 | 
			
		||||
  - name: Download 4096-bit RFC 7919 dhparams
 | 
			
		||||
    get_url:
 | 
			
		||||
      url: https://raw.githubusercontent.com/internetstandards/dhe_groups/master/ffdhe4096.pem
 | 
			
		||||
      checksum: sha256:64852d6890ff9e62eecd1ee89c72af9af244dfef5b853bcedea3dfd7aade22b3
 | 
			
		||||
      dest: "{{ nginx_ssl_dhparam }}"
 | 
			
		||||
    notify:
 | 
			
		||||
      - reload nginx
 | 
			
		||||
 | 
			
		||||
  # TODO: this could break because we can override the document root in host vars
 | 
			
		||||
  - name: Create vhost document roots
 | 
			
		||||
    file: path={{ nginx_root_prefix }}/{{ item.domain_name }} state=directory mode=0755 owner=nginx group=nginx
 | 
			
		||||
    loop: "{{ nginx_vhosts }}"
 | 
			
		||||
 
 | 
			
		||||
@@ -16,7 +16,7 @@ server {
 | 
			
		||||
    listen [::]:443 ssl http2 default_server;
 | 
			
		||||
    server_name _;
 | 
			
		||||
 | 
			
		||||
    # "snakeoil" certificate (self signed!)
 | 
			
		||||
    # self-signed "snakeoil" certificate
 | 
			
		||||
    ssl_certificate /etc/ssl/certs/nginx-snakeoil.crt;
 | 
			
		||||
    ssl_certificate_key /etc/ssl/private/nginx-snakeoil.key;
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										5
									
								
								roles/nginx/templates/gitea.j2
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										5
									
								
								roles/nginx/templates/gitea.j2
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,5 @@
 | 
			
		||||
 | 
			
		||||
    location / {
 | 
			
		||||
        proxy_pass http://localhost:3000;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -16,8 +16,8 @@
 | 
			
		||||
 | 
			
		||||
    # concatenated key + cert
 | 
			
		||||
    # See: http://nginx.org/en/docs/http/configuring_https_servers.html
 | 
			
		||||
    ssl_certificate {{ letsencrypt_root }}/{{ domain_name }}/fullchain.pem;
 | 
			
		||||
    ssl_certificate_key {{ letsencrypt_root }}/{{ domain_name }}/privkey.pem;
 | 
			
		||||
    ssl_certificate {{ letsencrypt_root }}/certs/{{ domain_name }}.fullchain.pem;
 | 
			
		||||
    ssl_certificate_key {{ letsencrypt_root }}/private/{{ domain_name }}.key.pem;
 | 
			
		||||
 | 
			
		||||
    {% endif %}
 | 
			
		||||
 | 
			
		||||
@@ -51,5 +51,5 @@
 | 
			
		||||
    # Enable this if you want HSTS (recommended, but be careful)
 | 
			
		||||
    # Include all subdomains and indicate to Google that we want this pre-loaded in Chrome's HSTS store
 | 
			
		||||
    # See: https://hstspreload.appspot.com/
 | 
			
		||||
    add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload" always;
 | 
			
		||||
    add_header Strict-Transport-Security "max-age={{ nginx_hsts_max_age }}; includeSubDomains; preload" always;
 | 
			
		||||
    {% endif %}
 | 
			
		||||
 
 | 
			
		||||
@@ -1,7 +1,9 @@
 | 
			
		||||
[Unit]
 | 
			
		||||
Description=Renew Let's Encrypt certificates
 | 
			
		||||
ConditionFileIsExecutable={{ letsencrypt_certbot_dest }}
 | 
			
		||||
ConditionFileIsExecutable={{ letsencrypt_acme_home }}/acme.sh
 | 
			
		||||
 | 
			
		||||
[Service]
 | 
			
		||||
Type=oneshot
 | 
			
		||||
ExecStart={{ letsencrypt_certbot_dest }} renew --standalone --pre-hook "/bin/systemctl stop nginx" --post-hook "/bin/systemctl start nginx"
 | 
			
		||||
ExecStart={{ letsencrypt_acme_home }}/acme.sh --cron --home {{ letsencrypt_acme_home }} --reloadcmd "/bin/systemctl reload nginx" -w /var/lib/letsencrypt
 | 
			
		||||
 | 
			
		||||
SuccessExitStatus=0 2
 | 
			
		||||
 
 | 
			
		||||
@@ -7,6 +7,7 @@
 | 
			
		||||
{% set enable_hsts    = item.enable_hsts | default(False) %}
 | 
			
		||||
{% set has_wordpress  = item.has_wordpress | default(False) %}
 | 
			
		||||
{% set needs_php      = item.needs_php | default(False) %}
 | 
			
		||||
{% set has_gitea      = item.has_gitea | default(False) %}
 | 
			
		||||
 | 
			
		||||
# http -> https vhost
 | 
			
		||||
server {
 | 
			
		||||
@@ -14,6 +15,8 @@ server {
 | 
			
		||||
    listen [::]:80;
 | 
			
		||||
    server_name {{ domain_name }} {{ domain_aliases }};
 | 
			
		||||
 | 
			
		||||
    {% include 'well-known.j2' %}
 | 
			
		||||
 | 
			
		||||
    # redirect http -> https
 | 
			
		||||
    location / {
 | 
			
		||||
        # ? in rewrite makes sure nginx doesn't append query string again
 | 
			
		||||
@@ -47,6 +50,10 @@ server {
 | 
			
		||||
        {% include 'wordpress.j2' %}
 | 
			
		||||
    {% endif %}
 | 
			
		||||
 | 
			
		||||
    {% if has_gitea == True %}
 | 
			
		||||
        {% include 'gitea.j2' %}
 | 
			
		||||
    {% endif %}
 | 
			
		||||
 | 
			
		||||
    error_page 500 502 503 504 /50x.html;
 | 
			
		||||
    location = /50x.html {
 | 
			
		||||
        root /usr/share/nginx/html;
 | 
			
		||||
@@ -75,7 +82,7 @@ server {
 | 
			
		||||
        fastcgi_pass unix:/run/php/php7.2-fpm-{{ domain_name }}.sock;
 | 
			
		||||
        {% elif ansible_distribution == 'Debian' and ansible_distribution_version is version('10', '==') %}
 | 
			
		||||
        fastcgi_pass unix:/run/php/php7.3-fpm-{{ domain_name }}.sock;
 | 
			
		||||
        {% elif ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==') %}
 | 
			
		||||
        {% elif (ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==')) or (ansible_distribution == 'Debian' and ansible_distribution_version is version('11', '==')) %}
 | 
			
		||||
        fastcgi_pass unix:/run/php/php7.4-fpm-{{ domain_name }}.sock;
 | 
			
		||||
        {% else %}
 | 
			
		||||
        fastcgi_pass unix:/var/run/php5-fpm-{{ domain_name }}.sock;
 | 
			
		||||
@@ -96,7 +103,7 @@ server {
 | 
			
		||||
        # Enable this if you want HSTS (recommended, but be careful)
 | 
			
		||||
        # Include all subdomains and indicate to Google that we want this pre-loaded in Chrome's HSTS store
 | 
			
		||||
        # See: https://hstspreload.appspot.com/
 | 
			
		||||
        add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload" always;
 | 
			
		||||
        add_header Strict-Transport-Security "max-age={{ nginx_hsts_max_age }}; includeSubDomains; preload" always;
 | 
			
		||||
        {% endif %}
 | 
			
		||||
 | 
			
		||||
        include extra-security.conf;
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										6
									
								
								roles/nginx/templates/well-known.j2
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										6
									
								
								roles/nginx/templates/well-known.j2
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,6 @@
 | 
			
		||||
location ^~ /.well-known/acme-challenge/ {
 | 
			
		||||
  allow all;
 | 
			
		||||
  root /var/lib/letsencrypt/;
 | 
			
		||||
  default_type "text/plain";
 | 
			
		||||
  try_files $uri =404;
 | 
			
		||||
}
 | 
			
		||||
@@ -9,7 +9,7 @@
 | 
			
		||||
        # Enable this if you want HSTS (recommended, but be careful)
 | 
			
		||||
        # Include all subdomains and indicate to Google that we want this pre-loaded in Chrome's HSTS store
 | 
			
		||||
        # See: https://hstspreload.appspot.com/
 | 
			
		||||
        add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload" always;
 | 
			
		||||
        add_header Strict-Transport-Security "max-age={{ nginx_hsts_max_age }}; includeSubDomains; preload" always;
 | 
			
		||||
        {% endif %}
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -20,7 +20,7 @@
 | 
			
		||||
        # Enable this if you want HSTS (recommended, but be careful)
 | 
			
		||||
        # Include all subdomains and indicate to Google that we want this pre-loaded in Chrome's HSTS store
 | 
			
		||||
        # See: https://hstspreload.appspot.com/
 | 
			
		||||
        add_header Strict-Transport-Security "max-age=15768000; includeSubDomains; preload" always;
 | 
			
		||||
        add_header Strict-Transport-Security "max-age={{ nginx_hsts_max_age }}; includeSubDomains; preload" always;
 | 
			
		||||
        {% endif %}
 | 
			
		||||
    }   
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
@@ -28,7 +28,8 @@
 | 
			
		||||
  - name: Update php.ini
 | 
			
		||||
    template: src=php7.3-php.ini.j2 dest=/etc/php/7.3/fpm/php.ini owner=root group=root mode=0644
 | 
			
		||||
    notify: reload php7.3-fpm
 | 
			
		||||
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
  when: (item.has_wordpress is defined and item.has_wordpress) or (item.needs_php is defined and item.needs_php)
 | 
			
		||||
  when: install_php
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -28,7 +28,8 @@
 | 
			
		||||
  - name: Update php.ini
 | 
			
		||||
    template: src=php7.2-php.ini.j2 dest=/etc/php/7.2/fpm/php.ini owner=root group=root mode=0644
 | 
			
		||||
    notify: reload php7.2-fpm
 | 
			
		||||
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
  when: (item.has_wordpress is defined and item.has_wordpress) or (item.needs_php is defined and item.needs_php)
 | 
			
		||||
  when: install_php
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -4,11 +4,12 @@
 | 
			
		||||
  - name: Set php-fpm packages
 | 
			
		||||
    set_fact:
 | 
			
		||||
      php_fpm_packages:
 | 
			
		||||
        - php-fpm
 | 
			
		||||
        - php7.4-fpm
 | 
			
		||||
        # for WordPress
 | 
			
		||||
        - php-mysql
 | 
			
		||||
        - php-gd
 | 
			
		||||
        - php-curl
 | 
			
		||||
        - php7.4-mysql
 | 
			
		||||
        - php7.4-gd
 | 
			
		||||
        - php7.4-curl
 | 
			
		||||
        - php7.4-xml
 | 
			
		||||
 | 
			
		||||
  - name: Install php-fpm and deps
 | 
			
		||||
    apt: name={{ php_fpm_packages }} state=present update_cache=yes
 | 
			
		||||
@@ -28,7 +29,8 @@
 | 
			
		||||
  - name: Update php.ini
 | 
			
		||||
    template: src=php7.4-php.ini.j2 dest=/etc/php/7.4/fpm/php.ini owner=root group=root mode=0644
 | 
			
		||||
    notify: reload php7.4-fpm
 | 
			
		||||
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
  when: (item.has_wordpress is defined and item.has_wordpress) or (item.needs_php is defined and item.needs_php)
 | 
			
		||||
  when: install_php
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
@@ -2,20 +2,49 @@
 | 
			
		||||
# Ubuntu 18.04 uses php-fpm 7.2
 | 
			
		||||
# Debian 10 uses php-fpm 7.3
 | 
			
		||||
# Ubuntu 20.04 uses PHP 7.4
 | 
			
		||||
# Debian 11 uses PHP 7.4
 | 
			
		||||
 | 
			
		||||
# If any of the vhosts on this host need WordPress then we need to install PHP.
 | 
			
		||||
# This uses selectattr to filter the list of dicts in nginx_vhosts, selecting
 | 
			
		||||
# any that have has_wordpress defined, and has_wordpress set to True.
 | 
			
		||||
#
 | 
			
		||||
# See: https://stackoverflow.com/a/31896249
 | 
			
		||||
- name: Check if any vhost needs WordPress
 | 
			
		||||
  set_fact:
 | 
			
		||||
    install_php: True
 | 
			
		||||
  when: "nginx_vhosts | selectattr('has_wordpress', 'defined') | selectattr('has_wordpress', 'equalto', True) | list | length > 0"
 | 
			
		||||
 | 
			
		||||
# Legacy, was only for Piwik, but leaving for now.
 | 
			
		||||
- name: Check if any vhost needs PHP
 | 
			
		||||
  set_fact:
 | 
			
		||||
    install_php: True
 | 
			
		||||
  when: "nginx_vhosts | selectattr('needs_php', 'defined') | selectattr('needs_php', 'equalto', True) | list | length > 0"
 | 
			
		||||
 | 
			
		||||
# If install_php has not been set, then we assume no vhosts need PHP. This is
 | 
			
		||||
# a bit hacky, but it's the closest we come to an if/then/else.
 | 
			
		||||
- name: Set install_php to False
 | 
			
		||||
  set_fact:
 | 
			
		||||
    install_php: False
 | 
			
		||||
  when: install_php is not defined
 | 
			
		||||
 | 
			
		||||
- name: Configure php-fpm on Ubuntu 18.04
 | 
			
		||||
  include_tasks: Ubuntu_18.04.yml
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('18.04', '==')
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('18.04', '==') and install_php
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
 | 
			
		||||
- name: Configure php-fpm on Debian 10
 | 
			
		||||
  include_tasks: Debian_10.yml
 | 
			
		||||
  when: ansible_distribution == 'Debian' and ansible_distribution_version is version('10', '==')
 | 
			
		||||
  when: ansible_distribution == 'Debian' and ansible_distribution_version is version('10', '==') and install_php
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
 | 
			
		||||
- name: Configure php-fpm on Ubuntu 20.04
 | 
			
		||||
  include_tasks: Ubuntu_20.04.yml
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==')
 | 
			
		||||
  when: ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('20.04', '==') and install_php
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
 | 
			
		||||
- name: Configure php-fpm on Debian 11
 | 
			
		||||
  include_tasks: Ubuntu_20.04.yml
 | 
			
		||||
  when: ansible_distribution == 'Debian' and ansible_distribution_version is version('11', '==') and install_php
 | 
			
		||||
  tags: php-fpm
 | 
			
		||||
 | 
			
		||||
# vim: set ts=2 sw=2:
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user