ansible-role-wireguard/tasks/main.yml
Adrien Reslinger 91ad2ba961
Some checks reported errors
continuous-integration/drone/push Build encountered an error
Fix indentation
2022-11-30 08:44:51 +01:00

89 lines
2.9 KiB
YAML

---
- name: WireGuard setup
block:
- name: Include vars for {{ ansible_os_family }}
ansible.builtin.include_vars: "{{ item }}"
with_first_found:
- "{{ ansible_os_family }}_{{ ansible_distribution_major_version }}.yml"
- "{{ ansible_os_family }}.yml"
- name: Pre-installation
ansible.builtin.include_tasks: "install_{{ ansible_os_family }}.yml"
- name: Install packages for WireGuard
ansible.builtin.package:
name: "{{ wireguard_packages }}"
state: present
update_cache: true
- name: Configure wireguard
block:
- name: Retreive private key
block:
- name: Retreive private key
ansible.builtin.shell: >
cat /etc/wireguard/privatekey
register: wireguard_private_key
changed_when: false
check_mode: false
rescue:
- name: Generate private key
ansible.builtin.shell: >
set -o pipefail && wg genkey | tee /etc/wireguard/privatekey
register: wireguard_private_key
always:
- name: Fix permission on /etc/wireguard/privatekey
ansible.builtin.file:
path: "/etc/wireguard/privatekey"
owner: root
group: root
mode: 0600
- name: Retreive public key
block:
- name: Retreive public key
ansible.builtin.shell: >
cat /etc/wireguard/publickey
register: wireguard_public_key
changed_when: false
check_mode: false
rescue:
- name: Generate public key
ansible.builtin.shell: >
set -o pipefail && cat /etc/wireguard/privatekey | wg pubkey | tee /etc/wireguard/publickey
register: wireguard_public_key
always:
- name: Fix permission on /etc/wireguard/publickey
ansible.builtin.file:
path: "/etc/wireguard/publickey"
owner: root
group: root
mode: 0600
- name: Set keys pair variable
ansible.builtin.set_fact:
wireguard_public_key: '{{ wireguard_public_key.stdout }}'
wireguard_private_key: '{{ wireguard_private_key.stdout }}'
check_mode: false
- name: Install WireGuard configuration files
ansible.builtin.template:
src: "etc/wireguard/wireguard.conf.j2"
dest: "/etc/wireguard/{{ wireguard_interface }}.conf"
owner: root
group: root
mode: 0644
notify: "reconfigure wireguard"
- name: Enable Wireguard service
ansible.builtin.service:
name: "wg-quick@{{ wireguard_interface }}"
enabled: true
state: restarted
when:
- not skip_conf
tags:
- wireguard-conf
tags:
- wireguard