summaryrefslogtreecommitdiff
path: root/ansible/roles/mox/tasks/main.yml
diff options
context:
space:
mode:
authorJoe Carstairs <me@joeac.net>2026-08-02 09:36:16 +0100
committerJoe Carstairs <me@joeac.net>2026-08-02 09:36:28 +0100
commite6bbca473453a8d797060d97fe8ad3e729719b53 (patch)
tree3224306c4bf061acdaaaeca889f4881eab28bc54 /ansible/roles/mox/tasks/main.yml
parent7b75d7532e7b549efbe15c306f91ea67f2a5a4eb (diff)
move mox and ln from make to ansible
Diffstat (limited to 'ansible/roles/mox/tasks/main.yml')
-rw-r--r--ansible/roles/mox/tasks/main.yml168
1 files changed, 168 insertions, 0 deletions
diff --git a/ansible/roles/mox/tasks/main.yml b/ansible/roles/mox/tasks/main.yml
new file mode 100644
index 0000000..8044262
--- /dev/null
+++ b/ansible/roles/mox/tasks/main.yml
@@ -0,0 +1,168 @@
+- name: Add mox group
+ ansible.builtin.group:
+ name: mox
+
+- name: Add mox user
+ ansible.builtin.user:
+ name: mox
+ group: mox
+ groups:
+ - tls
+ append: false
+
+- name: Assign mox as owner of ~mox home directory
+ register: mox_home_dir
+ ansible.builtin.file:
+ path: ~mox
+ owner: mox
+ group: mox
+ mode: "750"
+
+- name: Create mox configuration directory
+ register: mox_conf_dir
+ ansible.builtin.file:
+ path: ~mox/config/
+ owner: mox
+ group: mox
+ mode: "770"
+
+- name: Create DKIM private keys directory
+ register: mox_dkim_dir
+ ansible.builtin.file:
+ path: ~mox/config/dkim
+ owner: mox
+ group: mox
+ mode: "770"
+
+- name: Install DKIM private key A
+ register: mox_dkim_a
+ ansible.builtin.copy:
+ src: dkim/2026a._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem
+ dest: ~mox/config/dkim/2026a._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem
+ owner: mox
+ group: mox
+ mode: "660"
+
+- name: Install DKIM private key B
+ register: mox_dkim_b
+ ansible.builtin.copy:
+ src: dkim/2026b._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem
+ dest: ~mox/config/dkim/2026b._domainkey.mail.joeac.net.20260705T163220.rsa2048.privatekey.pkcs8.pem
+ owner: mox
+ group: mox
+ mode: "660"
+
+- name: Install adminpasswd
+ register: mox_adminpasswd
+ ansible.builtin.copy:
+ src: adminpasswd
+ dest: ~mox/config/adminpasswd
+ owner: mox
+ group: mox
+ mode: "660"
+
+- name: Install mox configuration
+ register: mox_conf
+ ansible.builtin.template:
+ src: mox.conf
+ dest: ~mox/config/mox.conf
+ owner: mox
+ group: mox
+ mode: "660"
+
+- name: Install mox domain configuration
+ register: mox_domain_conf
+ ansible.builtin.template:
+ src: domains.conf
+ dest: ~mox/config/domains.conf
+ owner: mox
+ group: mox
+ mode: "660"
+
+- name: Create mox data directory
+ ansible.builtin.file:
+ path: ~mox/data
+ state: directory
+ owner: mox
+ group: mox
+ mode: "770"
+
+- name: Create unbound configuration directory
+ ansible.builtin.file:
+ path: /etc/unbound/unbound.conf.d
+ state: directory
+ mode: "444"
+
+- name: Install DNSSEC configuration
+ register: dnssec_conf
+ ansible.builtin.template:
+ src: dnssec.conf
+ dest: /etc/unbound/unbound.conf.d/dnssec.conf
+
+- name: Install unbound binary
+ community.general.apk:
+ name: unbound
+ state: present
+
+- name: Restart unbound service and configure to start on boot
+ when: dnssec_conf is changed
+ ansible.builtin.service:
+ name: unbound
+ enabled: true
+ state: restarted
+
+- name: Start unbound service and configure to start on boot
+ when: not ( dnssec_conf is changed )
+ ansible.builtin.service:
+ name: unbound
+ enabled: true
+ state: started
+
+- name: Configure networking to point at unbound DNS resolver
+ ansible.builtin.copy:
+ content: "nameserver: 127.0.0.1"
+ dest: /etc/resolv.conf
+ backup: true
+ mode: "444"
+
+- name: Install mox binary
+ ansible.builtin.get_url:
+ dest: /usr/bin/mox
+ mode: "755"
+ url: "{{ mox_url }}"
+
+- name: Install mox service
+ ansible.builtin.copy:
+ src: openrc/mox
+ dest: /etc/init.d/mox
+ mode: "755"
+
+- name: Restart mox service and configure to start on boot
+ when:
+ mox_home_dir is changed
+ or mox_conf_dir is changed
+ or mox_dkim_dir is change
+ or mox_dkim_a is change
+ or mox_dkim_b is change
+ or mox_adminpasswd is change
+ or mox_conf is change
+ or mox_domain_conf is changed
+ ansible.builtin.service:
+ name: mox
+ enabled: true
+ state: started
+
+- name: Start mox service and configure to start on boot
+ when: not (
+ mox_home_dir is changed
+ or mox_conf_dir is changed
+ or mox_dkim_dir is change
+ or mox_dkim_a is change
+ or mox_dkim_b is change
+ or mox_adminpasswd is change
+ or mox_conf is change
+ or mox_domain_conf is changed )
+ ansible.builtin.service:
+ name: mox
+ enabled: true
+ state: started