ansible/roles/unbound/tasks/main.yml

65 lines
1.5 KiB
YAML
Raw Normal View History

2020-04-13 16:35:09 +02:00
---
# This is used to let unbound bind to the right IP addresses.
2020-04-18 17:36:25 +02:00
- name: set dns_host_suffix (main)
set_fact:
dns_host_suffix: "{{ dns_host_suffix_main }}"
when: "'backup' not in inventory_hostname"
2020-04-18 17:36:25 +02:00
- name: set dns_host_suffix (backup)
set_fact:
dns_host_suffix: "{{ dns_host_suffix_backup }}"
when: "'backup' in inventory_hostname"
2020-04-13 16:35:09 +02:00
- name: install unbound
apt:
update_cache: true
name: unbound
state: present
2020-04-28 20:21:47 +02:00
register: unbound_install
- name: ensure unbound log directory exists
file:
path: /var/log/unbound
state: directory
mode: '0755'
owner: unbound
group: unbound
notify: restart unbound
2020-04-28 20:21:47 +02:00
- name: add unbound-control configuration
template:
src: unbound-control.conf.j2
dest: /etc/unbound/unbound.conf.d/unbound-control.conf
mode: 0644
notify: restart unbound
2020-04-13 16:35:09 +02:00
- name: setup main unbound config file
template:
src: unbound.conf.j2
dest: /etc/unbound/unbound.conf
mode: 0644
notify: restart unbound
2020-04-13 16:35:09 +02:00
- name: ask apparmor to allow unbound to write to log file
template:
src: unbound-apparmor-config
dest: /etc/apparmor.d/local/usr.sbin.unbound
mode: '0644'
notify: read unbound apparmor config
- name: setup unbound log rotation
template:
src: unbound-logrotate.j2
dest: /etc/logrotate.d/unbound
mode: 0644
2020-04-13 16:35:09 +02:00
- name: setup recursive DNS server config
template:
src: recursive.conf.j2
dest: /etc/unbound/unbound.conf.d/recursive.conf
mode: 0644
notify: restart unbound