diff --git a/files/wireguard/default/preshared-thinkpad.psk b/files/wireguard/default/preshared-thinkpad.psk new file mode 100644 index 0000000..97bc195 --- /dev/null +++ b/files/wireguard/default/preshared-thinkpad.psk @@ -0,0 +1,7 @@ +$ANSIBLE_VAULT;1.1;AES256 +34643535393664343461666562656166373165313335356663353265623065386163383133373534 +3262623130653739353461353838343433303766643436340a373365613736643539323331623363 +30366161623566663066376531343361336332333238333236376266313566643961346336653933 +3933623933626231650a326632353837386630666265343238616333303765636666646665663839 +38393961633066626431653561386136376564643237653939383938386161613037333436353865 +6533316130613366616663633830656530383466333664383532 diff --git a/host_vars/fudiggity/vpn.yml b/host_vars/fudiggity/vpn.yml index ab4a583..91adff4 100644 --- a/host_vars/fudiggity/vpn.yml +++ b/host_vars/fudiggity/vpn.yml @@ -6,11 +6,11 @@ vpn_server_key_path: "{{ vpn_config_dir }}/keys/private/server.key" copy_vpn_configurations: false vpn_peers: - laptop: - ip: "10.0.0.2" - public_key: "EbWLf2+7x/RymeeiVuX72nZOBqPvdhu2V9pYhszpQEw=" - preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-laptop.psk" - preshared_key_source_path: "files/wireguard/default/preshared-laptop.psk" + thinkpad: + ip: "10.0.0.5" + public_key: "MOdt0GmrJWOAsL78TcHRNrBMF2jC9mviJrP5gqFzKxo=" + preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-thinkpad.psk" + preshared_key_source_path: "files/wireguard/default/preshared-thinkpad.psk" desktop: ip: "10.0.0.3" diff --git a/host_vars/fudiggity/vpn_media.yml b/host_vars/fudiggity/vpn_media.yml index 7598b16..b6867a9 100644 --- a/host_vars/fudiggity/vpn_media.yml +++ b/host_vars/fudiggity/vpn_media.yml @@ -8,18 +8,27 @@ copy_vpn_media_configurations: false # private_key_source_path keys are required for clients which get their configuration # generated. vpn_media_peers: - laptop: - ip: 10.0.1.2 - public_key: "hI4rqlv2afs4RJkt5xR+dYxQODSd6lR0OqWJRlnQdjM=" - preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-media-laptop.psk" - preshared_key_source_path: files/wireguard/media/preshared-laptop.psk - desktop: ip: 10.0.1.3 public_key: "YDH5lZcxUHM4AU2ZxQrFqjDIV2Z7PSUQKMcYXLExV0E=" preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-media-desktop.psk" preshared_key_source_path: files/wireguard/media/preshared-desktop.psk + thinkpad: + ip: 10.0.1.9 + public_key: "znOvNe+KL6R/mE1OkjuTRcGDpgU8JLWBe5bNc027nWE=" + preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-media-thinkpad.psk" + preshared_key_source_path: files/wireguard/media/preshared-thinkpad.psk + + htpc: + ip: 10.0.1.8 + allowed_ips: + - "{{ vpn_media_subnet }}" + - "{{ jellyfin_subnet }}" + public_key: "XcWpmGrkSQJUEADrDTUmcA7/dm8HQffbdC03rQ/3fwg=" + preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-htpc.psk" + preshared_key_source_path: files/wireguard/media/preshared-htpc.psk + mobile_peer_1: ip: 10.0.1.4 allowed_ips: @@ -59,12 +68,3 @@ vpn_media_peers: preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-media-tv-2.psk" preshared_key_source_path: files/wireguard/media/preshared-tv-2.psk private_key_source_path: files/wireguard/media/tv-2.key - - htpc: - ip: 10.0.1.8 - allowed_ips: - - "{{ vpn_media_subnet }}" - - "{{ jellyfin_subnet }}" - public_key: "XcWpmGrkSQJUEADrDTUmcA7/dm8HQffbdC03rQ/3fwg=" - preshared_key_path: "{{ vpn_config_dir }}/keys/private/preshared-htpc.psk" - preshared_key_source_path: files/wireguard/media/preshared-htpc.psk diff --git a/tasks/wireguard.yml b/tasks/wireguard.yml index e49b709..62b75ce 100644 --- a/tasks/wireguard.yml +++ b/tasks/wireguard.yml @@ -12,7 +12,7 @@ dest: "/etc/systemd/network/wg0.netdev" - src: "templates/network/wireguard/default/wg0.network.j2" dest: "/etc/systemd/network/wg0.network" - notify: restart systemd-networkd + notify: Restart systemd-networkd - name: Create Wireguard directories become: true @@ -41,7 +41,7 @@ dest: "{{ vpn_server_public_key_path }}" - src: "files/wireguard/default/server.key" dest: "{{ vpn_server_key_path }}" - notify: restart systemd-networkd + notify: Restart systemd-networkd - name: Copy Wireguard mobile credentials become: true @@ -56,7 +56,7 @@ dest: "{{ vpn_config_dir }}/keys/public/mobile.pub" - src: "files/wireguard/default/mobile.key" dest: "{{ vpn_config_dir }}/keys/private/mobile.key" - notify: restart systemd-networkd + notify: Restart systemd-networkd - name: Copy Wireguard preshared keys become: true @@ -67,7 +67,7 @@ group: systemd-network mode: "0640" with_dict: "{{ vpn_peers }}" - notify: restart systemd-networkd + notify: Restart systemd-networkd - name: Copy Wireguard mobile configuration become: true diff --git a/tasks/wireguard_media.yml b/tasks/wireguard_media.yml index c7046d7..3eff19b 100644 --- a/tasks/wireguard_media.yml +++ b/tasks/wireguard_media.yml @@ -12,7 +12,7 @@ dest: /etc/systemd/network/wg1.netdev - src: templates/network/wireguard/media/wg1.network.j2 dest: /etc/systemd/network/wg1.network - notify: restart systemd-networkd + notify: Restart systemd-networkd - name: Create Wireguard media directories become: true