mirror of
https://github.com/telekom-security/tpotce.git
synced 2025-04-29 03:38:51 +00:00
Merge pull request #592 from shaderecker/master
Ansible: Use clouds.yaml
This commit is contained in:
commit
f73ca5b328
8 changed files with 34 additions and 68 deletions
|
@ -18,7 +18,7 @@ This example showcases the deployment on our own OpenStack based Public Cloud Of
|
||||||
- [Import Key Pair](#key-pair)
|
- [Import Key Pair](#key-pair)
|
||||||
- [Clone Git Repository](#clone-git)
|
- [Clone Git Repository](#clone-git)
|
||||||
- [Settings and recommended values](#settings)
|
- [Settings and recommended values](#settings)
|
||||||
- [OpenStack authentication variables](#os-auth)
|
- [Clouds.yaml](#clouds-yaml)
|
||||||
- [Ansible remote user](#remote-user)
|
- [Ansible remote user](#remote-user)
|
||||||
- [Instance settings](#instance-settings)
|
- [Instance settings](#instance-settings)
|
||||||
- [User password](#user-password)
|
- [User password](#user-password)
|
||||||
|
@ -97,25 +97,27 @@ Import your SSH public key.
|
||||||
# Clone Git Repository
|
# Clone Git Repository
|
||||||
Clone the `tpotce` repository to your Ansible Master:
|
Clone the `tpotce` repository to your Ansible Master:
|
||||||
`git clone https://github.com/dtag-dev-sec/tpotce.git`
|
`git clone https://github.com/dtag-dev-sec/tpotce.git`
|
||||||
All Ansible related files are located in the [`cloud/ansible/openstack`](../../cloud/ansible/openstack) folder.
|
All Ansible related files are located in the [`cloud/ansible/openstack`](openstack) folder.
|
||||||
|
|
||||||
<a name="settings"></a>
|
<a name="settings"></a>
|
||||||
# Settings and recommended values
|
# Settings and recommended values
|
||||||
You can configure all aspects of your Elastic Cloud Server and T-Pot before using the Playbook.
|
You can configure all aspects of your Elastic Cloud Server and T-Pot before using the Playbook:
|
||||||
The settings are located in the following Ansible vars files:
|
|
||||||
|
|
||||||
<a name="os-auth"></a>
|
<a name="clouds-yaml"></a>
|
||||||
## OpenStack authentication variables
|
## Clouds.yaml
|
||||||
Located at [`openstack/roles/deploy/vars/os_auth.yaml`](openstack/roles/deploy/vars/os_auth.yaml).
|
Located at [`openstack/clouds.yaml`](openstack/clouds.yaml).
|
||||||
Enter your Open Telekom Cloud API user credentials here (username, password, project name, user domain name):
|
Enter your Open Telekom Cloud API user credentials here (username, password, project name, user domain name):
|
||||||
```
|
```
|
||||||
auth_url: https://iam.eu-de.otc.t-systems.com/v3
|
clouds:
|
||||||
username: your_api_user
|
open-telekom-cloud:
|
||||||
password: your_password
|
profile: otc
|
||||||
project_name: eu-de_your_project
|
auth:
|
||||||
os_user_domain_name: OTC-EU-DE-000000000010000XXXXX
|
project_name: eu-de_your_project
|
||||||
|
username: your_api_user
|
||||||
|
password: your_password
|
||||||
|
user_domain_name: OTC-EU-DE-000000000010000XXXXX
|
||||||
```
|
```
|
||||||
You can also perform different authentication methods like sourcing your `.ostackrc` file or using the OpenStack `clouds.yaml` file.
|
You can also perform different authentication methods like sourcing OpenStack OS_* environment variables or providing an inline dictionary.
|
||||||
For more information have a look in the [os_server](https://docs.ansible.com/ansible/latest/modules/os_server_module.html) Ansible module documentation.
|
For more information have a look in the [os_server](https://docs.ansible.com/ansible/latest/modules/os_server_module.html) Ansible module documentation.
|
||||||
|
|
||||||
<a name="remote-user"></a>
|
<a name="remote-user"></a>
|
||||||
|
@ -126,17 +128,15 @@ You may have to adjust the `remote_user` in the Ansible Playbook under [`opensta
|
||||||
## Instance settings
|
## Instance settings
|
||||||
Located at [`openstack/roles/deploy/vars/main.yaml`](openstack/roles/deploy/vars/main.yaml).
|
Located at [`openstack/roles/deploy/vars/main.yaml`](openstack/roles/deploy/vars/main.yaml).
|
||||||
Here you can customize your virtual machine specifications:
|
Here you can customize your virtual machine specifications:
|
||||||
- Specify the region name
|
|
||||||
- Choose an availability zone. For Open Telekom Cloud reference see [here](https://docs.otc.t-systems.com/en-us/endpoint/index.html).
|
- Choose an availability zone. For Open Telekom Cloud reference see [here](https://docs.otc.t-systems.com/en-us/endpoint/index.html).
|
||||||
- Change the OS image (For T-Pot we need Debian)
|
- Change the OS image (For T-Pot we need Debian)
|
||||||
- (Optional) Change the volume size
|
- (Optional) Change the volume size
|
||||||
- Specify your key pair (:warning: Mandatory)
|
- Specify your key pair (:warning: Mandatory)
|
||||||
- (Optional) Change the instance type (flavor)
|
- (Optional) Change the instance type (flavor)
|
||||||
`s2.medium.8` corresponds to 1 vCPU and 8GB of RAM and is the minimum required flavor.
|
`s2.medium.8` corresponds to 1 vCPU and 8GB of RAM and is the minimum required flavor.
|
||||||
A full list of Open telekom Cloud flavors can be found [here](https://docs.otc.t-systems.com/en-us/usermanual/ecs/en-us_topic_0035470096.html).
|
A full list of Open Telekom Cloud flavors can be found [here](https://docs.otc.t-systems.com/en-us/usermanual/ecs/en-us_topic_0177512565.html).
|
||||||
|
|
||||||
```
|
```
|
||||||
region_name: eu-de
|
|
||||||
availability_zone: eu-de-03
|
availability_zone: eu-de-03
|
||||||
image: Standard_Debian_10_latest
|
image: Standard_Debian_10_latest
|
||||||
volume_size: 128
|
volume_size: 128
|
||||||
|
@ -154,7 +154,7 @@ user_password: LiNuXuSeRPaSs#
|
||||||
|
|
||||||
<a name="tpot-conf"></a>
|
<a name="tpot-conf"></a>
|
||||||
## Configure `tpot.conf.dist`
|
## Configure `tpot.conf.dist`
|
||||||
The file is located in [`iso/installer/tpot.conf.dist`](../../iso/installer/tpot.conf.dist).
|
The file is located in [`iso/installer/tpot.conf.dist`](/iso/installer/tpot.conf.dist).
|
||||||
Here you can choose:
|
Here you can choose:
|
||||||
- between the various T-Pot editions
|
- between the various T-Pot editions
|
||||||
- a username for the web interface
|
- a username for the web interface
|
||||||
|
|
8
cloud/ansible/openstack/clouds.yaml
Normal file
8
cloud/ansible/openstack/clouds.yaml
Normal file
|
@ -0,0 +1,8 @@
|
||||||
|
clouds:
|
||||||
|
open-telekom-cloud:
|
||||||
|
profile: otc
|
||||||
|
auth:
|
||||||
|
project_name: eu-de_your_project
|
||||||
|
username: your_api_user
|
||||||
|
password: your_password
|
||||||
|
user_domain_name: OTC-EU-DE-000000000010000XXXXX
|
|
@ -1,6 +1,6 @@
|
||||||
- name: Copy ews configuration file
|
- name: Copy ews configuration file
|
||||||
template:
|
template:
|
||||||
src: ../templates/ews.cfg
|
src: ews.cfg
|
||||||
dest: /data/ews/conf
|
dest: /data/ews/conf
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
|
|
|
@ -1,6 +1,6 @@
|
||||||
- name: Copy hpfeeds configuration file
|
- name: Copy hpfeeds configuration file
|
||||||
copy:
|
copy:
|
||||||
src: ../files/hpfeeds.cfg
|
src: hpfeeds.cfg
|
||||||
dest: /data/ews/conf
|
dest: /data/ews/conf
|
||||||
owner: tpot
|
owner: tpot
|
||||||
group: tpot
|
group: tpot
|
||||||
|
|
|
@ -2,51 +2,26 @@
|
||||||
shell: echo t-pot-ansible-$(pwgen -ns 6 -1)
|
shell: echo t-pot-ansible-$(pwgen -ns 6 -1)
|
||||||
register: tpot_name
|
register: tpot_name
|
||||||
|
|
||||||
- name: Import OpenStack authentication variables
|
|
||||||
include_vars:
|
|
||||||
file: roles/deploy/vars/os_auth.yaml
|
|
||||||
no_log: true
|
|
||||||
|
|
||||||
- name: Create security group
|
- name: Create security group
|
||||||
os_security_group:
|
os_security_group:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
name: sg-tpot-any
|
name: sg-tpot-any
|
||||||
description: tpot any-any
|
description: tpot any-any
|
||||||
|
|
||||||
- name: Add rules to security group
|
- name: Add rules to security group
|
||||||
os_security_group_rule:
|
os_security_group_rule:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
security_group: sg-tpot-any
|
security_group: sg-tpot-any
|
||||||
remote_ip_prefix: 0.0.0.0/0
|
remote_ip_prefix: 0.0.0.0/0
|
||||||
|
|
||||||
- name: Create network
|
- name: Create network
|
||||||
os_network:
|
os_network:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
name: network-tpot
|
name: network-tpot
|
||||||
|
|
||||||
- name: Create subnet
|
- name: Create subnet
|
||||||
os_subnet:
|
os_subnet:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
network_name: network-tpot
|
network_name: network-tpot
|
||||||
name: subnet-tpot
|
name: subnet-tpot
|
||||||
cidr: 192.168.0.0/24
|
cidr: 192.168.0.0/24
|
||||||
|
@ -56,26 +31,15 @@
|
||||||
|
|
||||||
- name: Create router
|
- name: Create router
|
||||||
os_router:
|
os_router:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
name: router-tpot
|
name: router-tpot
|
||||||
interfaces:
|
interfaces:
|
||||||
- subnet-tpot
|
- subnet-tpot
|
||||||
|
|
||||||
- name: Launch an instance
|
- name: Launch an instance
|
||||||
os_server:
|
os_server:
|
||||||
auth:
|
cloud: open-telekom-cloud
|
||||||
auth_url: "{{ auth_url }}"
|
|
||||||
username: "{{ username }}"
|
|
||||||
password: "{{ password }}"
|
|
||||||
project_name: "{{ project_name }}"
|
|
||||||
os_user_domain_name: "{{ os_user_domain_name }}"
|
|
||||||
name: "{{ tpot_name.stdout }}"
|
name: "{{ tpot_name.stdout }}"
|
||||||
region_name: "{{ region_name }}"
|
|
||||||
availability_zone: "{{ availability_zone }}"
|
availability_zone: "{{ availability_zone }}"
|
||||||
image: "{{ image }}"
|
image: "{{ image }}"
|
||||||
boot_from_volume: yes
|
boot_from_volume: yes
|
||||||
|
|
|
@ -1,4 +1,3 @@
|
||||||
region_name: eu-de
|
|
||||||
availability_zone: eu-de-03
|
availability_zone: eu-de-03
|
||||||
image: Standard_Debian_10_latest
|
image: Standard_Debian_10_latest
|
||||||
volume_size: 128
|
volume_size: 128
|
||||||
|
|
|
@ -1,5 +0,0 @@
|
||||||
auth_url: https://iam.eu-de.otc.t-systems.com/v3
|
|
||||||
username: your_api_user
|
|
||||||
password: your_password
|
|
||||||
project_name: eu-de_your_project
|
|
||||||
os_user_domain_name: OTC-EU-DE-000000000010000XXXXX
|
|
|
@ -9,7 +9,7 @@
|
||||||
repo: "https://github.com/dtag-dev-sec/tpotce.git"
|
repo: "https://github.com/dtag-dev-sec/tpotce.git"
|
||||||
dest: /root/tpot
|
dest: /root/tpot
|
||||||
|
|
||||||
- name: Prepare to set user password
|
- name: Prepare to set user password
|
||||||
set_fact:
|
set_fact:
|
||||||
user_name: "{{ ansible_user }}"
|
user_name: "{{ ansible_user }}"
|
||||||
user_salt: "s0mew1ck3dTpoT"
|
user_salt: "s0mew1ck3dTpoT"
|
||||||
|
|
Loading…
Reference in a new issue