diff options
| author | Joe Carstairs <me@joeac.net> | 2026-08-02 09:36:16 +0100 |
|---|---|---|
| committer | Joe Carstairs <me@joeac.net> | 2026-08-02 09:36:28 +0100 |
| commit | e6bbca473453a8d797060d97fe8ad3e729719b53 (patch) | |
| tree | 3224306c4bf061acdaaaeca889f4881eab28bc54 /ansible/roles/mox/tasks/main.yml | |
| parent | 7b75d7532e7b549efbe15c306f91ea67f2a5a4eb (diff) | |
move mox and ln from make to ansible
Diffstat (limited to 'ansible/roles/mox/tasks/main.yml')
| -rw-r--r-- | ansible/roles/mox/tasks/main.yml | 168 |
1 files changed, 168 insertions, 0 deletions
diff --git a/ansible/roles/mox/tasks/main.yml b/ansible/roles/mox/tasks/main.yml new file mode 100644 index 0000000..8044262 --- /dev/null +++ b/ansible/roles/mox/tasks/main.yml @@ -0,0 +1,168 @@ +- name: Add mox group + ansible.builtin.group: + name: mox + +- name: Add mox user + ansible.builtin.user: + name: mox + group: mox + groups: + - tls + append: false + +- name: Assign mox as owner of ~mox home directory + register: mox_home_dir + ansible.builtin.file: + path: ~mox + owner: mox + group: mox + mode: "750" + +- name: Create mox configuration directory + register: mox_conf_dir + ansible.builtin.file: + path: ~mox/config/ + owner: mox + group: mox + mode: "770" + +- name: Create DKIM private keys directory + register: mox_dkim_dir + ansible.builtin.file: + path: ~mox/config/dkim + owner: mox + group: mox + mode: "770" + +- name: Install DKIM private key A + register: mox_dkim_a + ansible.builtin.copy: + src: dkim/2026a._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem + dest: ~mox/config/dkim/2026a._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem + owner: mox + group: mox + mode: "660" + +- name: Install DKIM private key B + register: mox_dkim_b + ansible.builtin.copy: + src: dkim/2026b._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem + dest: ~mox/config/dkim/2026b._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem + owner: mox + group: mox + mode: "660" + +- name: Install adminpasswd + register: mox_adminpasswd + ansible.builtin.copy: + src: adminpasswd + dest: ~mox/config/adminpasswd + owner: mox + group: mox + mode: "660" + +- name: Install mox configuration + register: mox_conf + ansible.builtin.template: + src: mox.conf + dest: ~mox/config/mox.conf + owner: mox + group: mox + mode: "660" + +- name: Install mox domain configuration + register: mox_domain_conf + ansible.builtin.template: + src: domains.conf + dest: ~mox/config/domains.conf + owner: mox + group: mox + mode: "660" + +- name: Create mox data directory + ansible.builtin.file: + path: ~mox/data + state: directory + owner: mox + group: mox + mode: "770" + +- name: Create unbound configuration directory + ansible.builtin.file: + path: /etc/unbound/unbound.conf.d + state: directory + mode: "444" + +- name: Install DNSSEC configuration + register: dnssec_conf + ansible.builtin.template: + src: dnssec.conf + dest: /etc/unbound/unbound.conf.d/dnssec.conf + +- name: Install unbound binary + community.general.apk: + name: unbound + state: present + +- name: Restart unbound service and configure to start on boot + when: dnssec_conf is changed + ansible.builtin.service: + name: unbound + enabled: true + state: restarted + +- name: Start unbound service and configure to start on boot + when: not ( dnssec_conf is changed ) + ansible.builtin.service: + name: unbound + enabled: true + state: started + +- name: Configure networking to point at unbound DNS resolver + ansible.builtin.copy: + content: "nameserver: 127.0.0.1" + dest: /etc/resolv.conf + backup: true + mode: "444" + +- name: Install mox binary + ansible.builtin.get_url: + dest: /usr/bin/mox + mode: "755" + url: "{{ mox_url }}" + +- name: Install mox service + ansible.builtin.copy: + src: openrc/mox + dest: /etc/init.d/mox + mode: "755" + +- name: Restart mox service and configure to start on boot + when: + mox_home_dir is changed + or mox_conf_dir is changed + or mox_dkim_dir is change + or mox_dkim_a is change + or mox_dkim_b is change + or mox_adminpasswd is change + or mox_conf is change + or mox_domain_conf is changed + ansible.builtin.service: + name: mox + enabled: true + state: started + +- name: Start mox service and configure to start on boot + when: not ( + mox_home_dir is changed + or mox_conf_dir is changed + or mox_dkim_dir is change + or mox_dkim_a is change + or mox_dkim_b is change + or mox_adminpasswd is change + or mox_conf is change + or mox_domain_conf is changed ) + ansible.builtin.service: + name: mox + enabled: true + state: started |
