|
|
|
@ -2,35 +2,52 @@
|
|
|
|
|
---
|
|
|
|
|
# Set up DHCP servers.
|
|
|
|
|
- hosts: dhcp-*.adm.auro.re
|
|
|
|
|
vars:
|
|
|
|
|
update_motd:
|
|
|
|
|
unbound: isc-dhcp-server est déployé.
|
|
|
|
|
roles:
|
|
|
|
|
- isc_dhcp_server
|
|
|
|
|
|
|
|
|
|
- update_motd
|
|
|
|
|
|
|
|
|
|
# Deploy unbound DNS server (recursive).
|
|
|
|
|
- hosts: dns-*.adm.auro.re,!dns-aurore*.adm.auro.re
|
|
|
|
|
vars:
|
|
|
|
|
update_motd:
|
|
|
|
|
unbound: Unbound est déployé.
|
|
|
|
|
roles:
|
|
|
|
|
- unbound
|
|
|
|
|
|
|
|
|
|
- update_motd
|
|
|
|
|
|
|
|
|
|
# Déploiement du service re2o aurore-firewall et keepalived
|
|
|
|
|
# radvd: IPv6 SLAAC (/64 subnets, private IPs).
|
|
|
|
|
# Must NOT be on routeur-aurore-*, or will with DHCPv6!
|
|
|
|
|
- hosts: ~routeur-(pacaterie|edc|fleming|gs|rives).*\.adm\.auro\.re
|
|
|
|
|
vars:
|
|
|
|
|
router:
|
|
|
|
|
unbound: Le routage (avec radvd) est déployé.
|
|
|
|
|
roles:
|
|
|
|
|
- router
|
|
|
|
|
- radvd
|
|
|
|
|
- update_motd
|
|
|
|
|
|
|
|
|
|
# No radvd here
|
|
|
|
|
- hosts: ~routeur-aurore.*\.adm\.auro\.re
|
|
|
|
|
vars:
|
|
|
|
|
router:
|
|
|
|
|
unbound: Le routage (avec DHCPv6) est déployé.
|
|
|
|
|
roles:
|
|
|
|
|
- router
|
|
|
|
|
- ipv6_edge_router
|
|
|
|
|
- update_motd
|
|
|
|
|
|
|
|
|
|
# Radius (backup only for now)
|
|
|
|
|
- hosts: radius-*.adm.auro.re
|
|
|
|
|
vars:
|
|
|
|
|
router:
|
|
|
|
|
unbound: FreeRADIUS est déployé.
|
|
|
|
|
roles:
|
|
|
|
|
- radius
|
|
|
|
|
|
|
|
|
|
- update_motd
|
|
|
|
|
|
|
|
|
|
# WIP: Deploy authoritative DNS servers
|
|
|
|
|
# - hosts: authoritative_dns
|
|
|
|
|