first_commit

This commit is contained in:
2026-05-31 11:58:36 +03:00
commit 32667c657d
21 changed files with 338 additions and 0 deletions
+10
View File
@@ -0,0 +1,10 @@
services:
garage:
image: dxflrs/garage:v2.1.0
container_name: garage
restart: unless-stopped
network_mode: "host"
volumes:
- ./garage.toml:/etc/garage.toml:ro
- ./meta:/var/lib/garage/meta
- ./data:/var/lib/garage/data
+28
View File
@@ -0,0 +1,28 @@
metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"
db_engine = "lmdb"
replication_factor = 2
read_quorum = 1
write_quorum = 2
compression_level = 2
# RPC слушает на WG интерфейсе
rpc_bind_addr = "{{ wg_ip }}:3901"
rpc_public_addr = "{{ wg_ip }}:3901"
rpc_secret = "{{ garage_rpc_secret }}"
[s3_api]
s3_region = "garage"
# S3 API доступно везде (для простоты отладки), но можно ограничить
api_bind_addr = "0.0.0.0:3900"
[admin]
admin_token = "{{ garage_admin_token }}"
[kademlia]
bootstrap_peers = [
{% for peer in wireguard_peers %}
"{{ peer.pubkey }}@{{ peer.ip }}:3901"{% if not loop.last %},{% endif %}
{% endfor %}
]
+5
View File
@@ -0,0 +1,5 @@
---
- name: Restart Garage
community.docker.docker_compose_v2:
project_src: /opt/garage
state: restarted
+96
View File
@@ -0,0 +1,96 @@
---
- name: Install prerequisites for Docker
apt:
name:
- apt-transport-https
- ca-certificates
- curl
- gnupg
- lsb-release
state: present
update_cache: yes
ignore_errors: yes # Игнорируем ошибки, если старые репо битые
- name: Install software-properties-common on Ubuntu
apt:
name: software-properties-common
state: present
when: ansible_distribution == "Ubuntu"
ignore_errors: yes
- name: Create keyrings directory
file:
path: /etc/apt/keyrings
state: directory
mode: '0755'
# --- Логика для UBUNTU ---
- name: Download Docker GPG key for Ubuntu
shell: |
curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
args:
creates: /etc/apt/keyrings/docker.asc
when: ansible_distribution == "Ubuntu"
- name: Add Docker repository for Ubuntu
copy:
# Используем переменную Ansible для архитектуры, чтобы избежать shell-синтаксиса в файле
content: "deb [arch={{ ansible_architecture }} signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu {{ ansible_distribution_release }} stable\n"
dest: /etc/apt/sources.list.d/docker.list
mode: '0644'
when: ansible_distribution == "Ubuntu"
# --- Логика для DEBIAN ---
- name: Download and convert Docker GPG key for Debian
shell: |
curl -fsSL https://download.docker.com/linux/debian/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
args:
creates: /usr/share/keyrings/docker-archive-keyring.gpg
when: ansible_distribution == "Debian"
- name: Add Docker repository for Debian
copy:
content: "deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/debian {{ ansible_distribution_release }} stable\n"
dest: /etc/apt/sources.list.d/docker.list
mode: '0644'
when: ansible_distribution == "Debian"
- name: Update apt cache after adding Docker repo
apt:
update_cache: yes
- name: Install Docker packages
apt:
name:
- docker-ce
- docker-ce-cli
- containerd.io
- docker-buildx-plugin
- docker-compose-plugin
state: present
update_cache: yes
- name: Ensure Garage directory exists
file:
path: /opt/garage
state: directory
mode: '0755'
- name: Deploy Garage docker-compose.yml
template:
src: docker-compose.yml.j2
dest: /opt/garage/docker-compose.yml
mode: '0644'
- name: Deploy Garage configuration (garage.toml)
template:
src: garage.toml.j2
dest: /opt/garage/garage.toml
mode: '0644'
notify: Restart Garage
- name: Start Garage services
community.docker.docker_compose_v2:
project_src: /opt/garage
state: present
@@ -0,0 +1,10 @@
services:
garage:
image: dxflrs/garage:{{ garage_version }}
container_name: garage
restart: unless-stopped
network_mode: "host"
volumes:
- ./garage.toml:/etc/garage.toml:ro
- ./meta:/var/lib/garage/meta
- ./data:/var/lib/garage/data
+29
View File
@@ -0,0 +1,29 @@
metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"
db_engine = "lmdb"
replication_factor = {{ garage_replication_factor }}
read_quorum = {{ garage_read_quorum }}
write_quorum = {{ garage_write_quorum }}
compression_level = 2
metadata_auto_snapshot_interval = "6h"
# RPC привязан к WG интерфейсу для безопасности
rpc_bind_addr = "{{ wireguard_ip }}:3901"
rpc_public_addr = "{{ wireguard_ip }}:3901"
rpc_secret = "{{ garage_rpc_secret }}"
[s3_api]
s3_region = "garage"
# S3 API доступно на всех интерфейсах (для доступа из LAN и через WG)
api_bind_addr = "0.0.0.0:3900"
[admin]
admin_token = "{{ garage_admin_token }}"
[kademlia]
bootstrap_peers = [
{% for peer in wireguard_peers %}
"{{ peer.pubkey }}@{{ peer.ip }}:3901"{% if not loop.last %},{% endif %}
{% endfor %}
]
+5
View File
@@ -0,0 +1,5 @@
---
- name: Restart WireGuard
systemd:
name: wg-quick@wg0
state: restarted
+34
View File
@@ -0,0 +1,34 @@
---
- name: Remove any broken Docker repository files to prevent apt errors
file:
path: "{{ item }}"
state: absent
with_fileglob:
- "/etc/apt/sources.list.d/*docker*"
ignore_errors: yes
- name: Install WireGuard
apt:
name: wireguard
state: present
update_cache: yes
ignore_errors: yes
- name: Ensure WireGuard directory exists
file:
path: /etc/wireguard
state: directory
mode: '0700'
- name: Deploy WireGuard configuration
template:
src: wg0.conf.j2
dest: /etc/wireguard/wg0.conf
mode: '0600'
notify: Restart WireGuard
- name: Enable and start WireGuard service
systemd:
name: wg-quick@wg0
enabled: yes
state: started
+17
View File
@@ -0,0 +1,17 @@
[Interface]
PrivateKey = {{ wireguard_private_key }}
Address = {{ wireguard_ip }}/24
ListenPort = {{ wireguard_port }}
{% for peer in wireguard_peers %}
{% if peer.ip != wireguard_ip %}
[Peer]
# {{ peer.name }}
PublicKey = {{ peer.pubkey }}
AllowedIPs = {{ peer.ip }}/32
{% if peer.endpoint %}
Endpoint = {{ peer.endpoint }}
PersistentKeepalive = 25
{% endif %}
{% endif %}
{% endfor %}
+16
View File
@@ -0,0 +1,16 @@
[Interface]
PrivateKey = {{ host_private_key }}
Address = {{ wg_ip }}/24
ListenPort = {{ wg_port }}
{% for peer in wireguard_peers %}
{% if peer.ip != wg_ip %}
[Peer]
PublicKey = {{ peer.pubkey }}
AllowedIPs = {{ peer.ip }}/32
{% if peer.endpoint %}
Endpoint = {{ peer.endpoint }}
PersistentKeepalive = 25
{% endif %}
{% endif %}
{% endfor %}