From 925289b675bc43ce1d7fbde09f40ed416e09e4c8 Mon Sep 17 00:00:00 2001 From: pgrondek Date: Wed, 24 Feb 2021 02:53:29 +0100 Subject: [PATCH] Add ssh external --- .../docker-cluster/files/etc/ha.d/haresources | 1 + .../files/etc/ha.d/resource.d/ssh-external | 28 +++++++++++++++++++ .../lib/systemd/system/sshd-external.service | 19 +++++++++++++ roles/docker-cluster/tasks/main.yml | 4 ++- roles/docker-cluster/tasks/ssh-external.yml | 24 ++++++++++++++++ 5 files changed, 75 insertions(+), 1 deletion(-) create mode 100755 roles/docker-cluster/files/etc/ha.d/resource.d/ssh-external create mode 100644 roles/docker-cluster/files/lib/systemd/system/sshd-external.service create mode 100644 roles/docker-cluster/tasks/ssh-external.yml diff --git a/roles/docker-cluster/files/etc/ha.d/haresources b/roles/docker-cluster/files/etc/ha.d/haresources index 7ba51bf..babeb30 100644 --- a/roles/docker-cluster/files/etc/ha.d/haresources +++ b/roles/docker-cluster/files/etc/ha.d/haresources @@ -1 +1,2 @@ node-02 IPaddr::192.168.50.100/24/eth0:0 +node-02 ssh-external \ No newline at end of file diff --git a/roles/docker-cluster/files/etc/ha.d/resource.d/ssh-external b/roles/docker-cluster/files/etc/ha.d/resource.d/ssh-external new file mode 100755 index 0000000..cd06592 --- /dev/null +++ b/roles/docker-cluster/files/etc/ha.d/resource.d/ssh-external @@ -0,0 +1,28 @@ +#!/usr/bin/env bash + +SERVICE=sshd-external + +case "$1" in + start) + systemctl start "${SERVICE}" + ;; + stop) + systemctl stop "${SERVICE}" + ;; + reload) + systemctl reload "${SERVICE}" + ;; + force-reload) + systemctl force-reload "${SERVICE}" + ;; + restart) + systemctl restart "${SERVICE}" + ;; + status) + systemctl status "${SERVICE}" + ;; + *) + echo "Usage: /etc/init.d/ssh {start|stop|reload|force-reload|restart|status}" || true + exit 1 + ;; +esac \ No newline at end of file diff --git a/roles/docker-cluster/files/lib/systemd/system/sshd-external.service b/roles/docker-cluster/files/lib/systemd/system/sshd-external.service new file mode 100644 index 0000000..b512af1 --- /dev/null +++ b/roles/docker-cluster/files/lib/systemd/system/sshd-external.service @@ -0,0 +1,19 @@ +[Unit] +Description=OpenBSD Secure Shell server +After=network.target auditd.service +ConditionPathExists=!/etc/ssh/sshd_not_to_be_run + +[Service] +EnvironmentFile=-/etc/default/ssh +ExecStartPre=/usr/sbin/sshd -t +ExecStart=/usr/sbin/sshd -D $SSHD_OPTS -f /etc/ssh/sshd_config_external +ExecReload=/usr/sbin/sshd -t +ExecReload=/bin/kill -HUP $MAINPID +KillMode=process +Restart=on-failure +RestartPreventExitStatus=255 +Type=notify + +[Install] +WantedBy=multi-user.target +Alias=sshd-external.service diff --git a/roles/docker-cluster/tasks/main.yml b/roles/docker-cluster/tasks/main.yml index 6c61c31..0fca0ae 100644 --- a/roles/docker-cluster/tasks/main.yml +++ b/roles/docker-cluster/tasks/main.yml @@ -11,4 +11,6 @@ - import_tasks: hostfile.yml -- import_tasks: docker-watcher.yml \ No newline at end of file +- import_tasks: docker-watcher.yml + +- import_tasks: ssh-external.yml \ No newline at end of file diff --git a/roles/docker-cluster/tasks/ssh-external.yml b/roles/docker-cluster/tasks/ssh-external.yml new file mode 100644 index 0000000..87653bf --- /dev/null +++ b/roles/docker-cluster/tasks/ssh-external.yml @@ -0,0 +1,24 @@ +--- +- become: yes + block: + - name: copy config + copy: + owner: root + group: root + mode: 0600 + directory_mode: yes + src: etc/ssh + dest: /etc + + - name: copy ha.d resource ssh-external + copy: + owner: root + group: root + mode: 0755 + src: etc/ha.d/resource.d/ssh-external + dest: /etc/ha.d/resource.d/ssh-external + + - name: add systemd service + copy: + src: lib/systemd/system/sshd-external.service + dest: /lib/systemd/system/sshd-external.service