diff --git a/group_vars/testing.yml b/group_vars/testing.yml index c5cb1d3..2ec9f62 100644 --- a/group_vars/testing.yml +++ b/group_vars/testing.yml @@ -14,5 +14,6 @@ traggo_use_https: no monica_use_https: no nextcloud_use_https: no shaarli_use_https: no +landingpage_use_https: no #server_domain: mytest.com diff --git a/roles/landingpage/README.md b/roles/landingpage/README.md new file mode 100644 index 0000000..d649b50 --- /dev/null +++ b/roles/landingpage/README.md @@ -0,0 +1,37 @@ +# landingpage + +The public face of my server. +Not much to see here honestly, +just a few simple lines of html explaining what this server is about and how to contact me. + +I don't see anybody else benefiting massively from this role but me, +but if you want the same web presence go for it I suppose 😉 + +## Defaults + +``` +landingpage_upstream_file_dir: "{{ docker_stack_files_dir }}/{{ stack_name }}" +``` + +The on-target directory where the proxy configuration file should be stashed. + +``` +landingpage_use_https: true +``` + +Whether the service should be reachable through http (port 80) or through https (port 443) and provision an https certificate. Usually you will want this to stay `true`. + +``` +landingpage_version: latest +``` + +The docker image version to be used in stack creation. + +``` +subdomain_alias: www +``` + +If the deployed container should be served over a uri that is not the stack name. +By default, it will be set to `www.yourdomain.com` - +if this option is not set it will be served on `landingpage.yourdomain.com` instead. + diff --git a/roles/landingpage/defaults/main.yml b/roles/landingpage/defaults/main.yml new file mode 100644 index 0000000..2c47345 --- /dev/null +++ b/roles/landingpage/defaults/main.yml @@ -0,0 +1,11 @@ +--- + +# never got around to removing the master tag from the images +landingpage_version: master + +landingpage_upstream_file_dir: "{{ docker_stack_files_dir }}/{{ stack_name }}" + +landingpage_use_https: true + +# the subdomain link landingpage will be reachable under +subdomain_alias: www diff --git a/roles/landingpage/handlers/main.yml b/roles/landingpage/handlers/main.yml new file mode 100644 index 0000000..869b074 --- /dev/null +++ b/roles/landingpage/handlers/main.yml @@ -0,0 +1,53 @@ +## Register reverse proxy +- name: Ensure upstream directory exists + ansible.builtin.file: + path: "{{ landingpage_upstream_file_dir }}" + state: directory + mode: '0755' + become: yes + listen: "update landingpage upstream" + +- name: Update upstream template + ansible.builtin.template: + src: upstream.json.j2 + dest: "{{ landingpage_upstream_file_dir }}/upstream.json" + become: yes + listen: "update landingpage upstream" + +# figure out if upstream id exists +- name: check {{ stack_name }} upstream + community.docker.docker_container_exec: + container: "{{ caddy_container_id }}" + command: > + curl localhost:2019/id/{{ stack_name }}_upstream/ + changed_when: False + register: result + become: yes + listen: "update landingpage upstream" + +# upstream already exists, patch it +- name: remove old {{ stack_name }} upstream + community.docker.docker_container_exec: + container: "{{ caddy_container_id }}" + command: > + curl -X DELETE localhost:2019/id/{{ stack_name }}_upstream/ + become: yes + when: (result.stdout | from_json)['error'] is not defined + listen: "update landingpage upstream" + +# upstream has to be created +- name: add {{ stack_name }} upstream + community.docker.docker_container_exec: + container: "{{ caddy_container_id }}" + command: > + curl -X POST -H "Content-Type: application/json" -d @{{ landingpage_upstream_file_dir }}/upstream.json localhost:2019/config/apps/http/servers/{{ (landingpage_use_https == True) | ternary(caddy_https_server_name, caddy_http_server_name) }}/routes/0/ + become: yes + listen: "update landingpage upstream" + +- name: Ensure upstream directory is gone again + ansible.builtin.file: + path: "{{ landingpage_upstream_file_dir }}" + state: absent + become: yes + listen: "update landingpage upstream" + diff --git a/roles/landingpage/meta/main.yml b/roles/landingpage/meta/main.yml new file mode 100644 index 0000000..fbb1340 --- /dev/null +++ b/roles/landingpage/meta/main.yml @@ -0,0 +1,14 @@ +--- + +galaxy_info: + author: Marty Oehme + description: Installs my personal public facing landing page as a docker stack service + license: GPL-3.0-only + min_ansible_version: 2.9 + galaxy_tags: [] + + +dependencies: + - docker + - docker-swarm + - caddy diff --git a/roles/landingpage/tasks/main.yml b/roles/landingpage/tasks/main.yml new file mode 100644 index 0000000..02a9d2a --- /dev/null +++ b/roles/landingpage/tasks/main.yml @@ -0,0 +1,24 @@ +--- +## install landingpage container +- name: Check upstream status + community.docker.docker_container_exec: + container: "{{ caddy_container_id }}" + command: > + curl localhost:2019/id/{{ stack_name }}_upstream/ + register: result + changed_when: (result.stdout | from_json) != (lookup('template', 'upstream.json.j2') | from_yaml) + become: yes + notify: "update landingpage upstream" + +- name: Deploy landingpage to swarm + community.general.docker_stack: + name: "{{ stack_name }}" + state: present + prune: yes + compose: + - "{{ stack_compose }}" + become: yes + tags: + - docker-swarm + notify: "update landingpage upstream" + diff --git a/roles/landingpage/templates/docker-stack.yml.j2 b/roles/landingpage/templates/docker-stack.yml.j2 new file mode 100644 index 0000000..b2525ab --- /dev/null +++ b/roles/landingpage/templates/docker-stack.yml.j2 @@ -0,0 +1,20 @@ +version: '3.4' + +services: + app: + image: "{{ stack_image }}:{{ landingpage_version }}" + healthcheck: + test: ["CMD", "wget", "--spider", "-q", "localhost"] + interval: 1m + timeout: 10s + retries: 3 + start_period: 1m + entrypoint: sh -c "/docker-entrypoint.sh nginx -g 'daemon off;'" + networks: + - "{{ docker_swarm_public_network_name }}" + +networks: + "{{ docker_swarm_public_network_name }}": + external: true + + diff --git a/roles/landingpage/templates/upstream.json.j2 b/roles/landingpage/templates/upstream.json.j2 new file mode 100644 index 0000000..6c6c59d --- /dev/null +++ b/roles/landingpage/templates/upstream.json.j2 @@ -0,0 +1,42 @@ +{ + "@id": "{{ stack_name }}_upstream", +{% if server_domain is not undefined and not none %} + "match": [ + { + "host": [ +{% if subdomain_alias is not undefined and not none %} + "{{ subdomain_alias }}.{{ server_domain }}" +{% else %} + "{{ stack_name }}.{{ server_domain }}" +{% endif %} + , + "{{ server_domain }}" + ] + } + ], +{% else %} + "match": [ + { + "path": [ +{% if subdomain_alias is not undefined and not none %} + "/{{ subdomain_alias }}*" +{% else %} + "/{{ stack_name }}*" +{% endif %} + , + "/" + ] + } + ], +{% endif %} + "handle": [ + { + "handler": "reverse_proxy", + "upstreams": [ + { + "dial": "{{ stack_name }}_app:80" + } + ] + } + ] +} diff --git a/roles/landingpage/vars/main.yml b/roles/landingpage/vars/main.yml new file mode 100644 index 0000000..e3616a9 --- /dev/null +++ b/roles/landingpage/vars/main.yml @@ -0,0 +1,7 @@ +--- + +stack_name: landingpage + +stack_image: "registry.gitlab.com/cloud-serve/landing" + +stack_compose: "{{ lookup('template', 'docker-stack.yml.j2') | from_yaml }}" diff --git a/site-dev.yml b/site-dev.yml index ee75718..b08c965 100644 --- a/site-dev.yml +++ b/site-dev.yml @@ -10,3 +10,4 @@ - monica - nextcloud - shaarli + - landingpage diff --git a/site.yml b/site.yml index 3a4ef7f..94d344e 100644 --- a/site.yml +++ b/site.yml @@ -17,3 +17,4 @@ - monica - nextcloud - shaarli + - landingpage