2016-03-26 17:54:31 +01:00
|
|
|
---
|
|
|
|
|
2021-01-04 22:34:08 +01:00
|
|
|
- name: Ensure resolved stays down
|
|
|
|
systemd:
|
|
|
|
enabled: false
|
|
|
|
state: stopped
|
|
|
|
masked: yes
|
|
|
|
name: systemd-resolved
|
2016-03-26 17:54:31 +01:00
|
|
|
|
|
|
|
- name: Create primary zone directory
|
2021-01-04 22:34:08 +01:00
|
|
|
file:
|
|
|
|
path: "{{ nsd_primary_zones_dir }}"
|
|
|
|
state: directory
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0711
|
2016-03-26 17:54:31 +01:00
|
|
|
|
2021-01-04 22:34:08 +01:00
|
|
|
- name: Create control dir
|
|
|
|
file:
|
|
|
|
path: /etc/nsd/control
|
|
|
|
state: directory
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0700
|
2016-03-26 17:54:31 +01:00
|
|
|
|
2021-01-04 22:34:08 +01:00
|
|
|
- name: Create subdirectories
|
|
|
|
file:
|
|
|
|
path: "{{ nsd_primary_zones_dir }}/{{ item }}"
|
|
|
|
state: directory
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0700
|
|
|
|
when: nsd_zone_subdirs is defined
|
|
|
|
loop: "{{ nsd_zone_subdirs }}"
|
|
|
|
|
|
|
|
- name: Create secondary zone directory
|
|
|
|
file:
|
|
|
|
path: "{{ nsd_secondary_zones_dir }}"
|
|
|
|
state: directory
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0755
|
2016-03-26 17:54:31 +01:00
|
|
|
|
2017-09-01 10:55:03 +02:00
|
|
|
- name: Configure nsd zones
|
2021-01-04 22:34:08 +01:00
|
|
|
template:
|
|
|
|
src: zones_config.j2
|
|
|
|
dest: "{{ nsd_zones_config_file }}"
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0600
|
|
|
|
validate: 'nsd-checkconf %s'
|
2016-03-26 17:54:31 +01:00
|
|
|
|
2017-09-01 10:55:03 +02:00
|
|
|
- name: Create base nsd configuration file
|
2021-01-04 22:34:08 +01:00
|
|
|
template:
|
|
|
|
src: config.j2
|
|
|
|
dest: "{{ nsd_config_dir }}/nsd.conf"
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0644
|
|
|
|
validate: 'nsd-checkconf %s'
|
2016-03-28 12:49:04 +02:00
|
|
|
notify:
|
2017-09-01 10:55:03 +02:00
|
|
|
- restart nsd
|
2016-03-28 12:49:04 +02:00
|
|
|
|
2021-01-04 22:34:08 +01:00
|
|
|
- name: Copy content of subdirs
|
|
|
|
copy:
|
|
|
|
src: '{{ playbook_dir }}/files/nsd/{{ item }}'
|
|
|
|
dest: "{{ nsd_primary_zones_dir }}"
|
|
|
|
owner: nsd
|
|
|
|
group: nsd
|
|
|
|
mode: 0600
|
|
|
|
directory_mode: 0711
|
|
|
|
when: nsd_zone_subdirs is defined
|
|
|
|
loop: "{{ nsd_zone_subdirs }}"
|
2016-03-27 17:39:55 +02:00
|
|
|
|
2016-03-27 18:17:51 +02:00
|
|
|
- name: Copy content of primary zones
|
2021-01-04 22:34:08 +01:00
|
|
|
copy:
|
|
|
|
src: "{{ playbook_dir }}/files/nsd/{{ item.zone_filename }}"
|
|
|
|
dest: "{{ nsd_primary_zones_dir }}/{{ item.zone_filename }}"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: 0644
|
2016-03-26 17:54:31 +01:00
|
|
|
with_items: "{{ nsd_primary_zones }}"
|
|
|
|
notify:
|
2017-09-01 10:55:03 +02:00
|
|
|
- rebuild nsd database
|
|
|
|
- reload nsd database
|
2016-03-26 19:36:03 +01:00
|
|
|
- notify slaves
|
2021-01-04 22:34:08 +01:00
|
|
|
|
|
|
|
- name: Add dnssec renewal crons
|
|
|
|
cron:
|
|
|
|
special_time: monthly
|
|
|
|
user: nsd
|
|
|
|
job: "bash {{ nsd_primary_zones_dir }}/{{ item }}/source.sh"
|
|
|
|
loop: "{{ nsd_zone_subdirs }}"
|