summaryrefslogtreecommitdiffstats
path: root/roles/network/tasks/main.yml
blob: d0cadaa3fbf3168cde536bfa3703eb2d7674ebec (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
---
- name: "Include OS-specific variables"
  ansible.builtin.include_vars: "{{ ansible_facts['distribution'] | lower }}.yml"

- name: "Include OS-specific tasks"
  ansible.builtin.include_tasks: "install-{{ ansible_facts['os_family'] | lower }}.yml"

- name: "Validate network_ipv4_* params"
  ansible.builtin.assert:
    that:
      - network_ipv4_address is defined
      - network_ipv4_gateway is defined
    fail_msg: "network_ipv4_address and network_ipv4_gateway are required together"
  when: network_ipv4_address is defined or network_ipv4_gateway is defined

- name: "Validate network_ipv6_* params"
  ansible.builtin.assert:
    that:
      - network_ipv6_address is defined
      - network_ipv6_gateway is defined
    fail_msg: "network_ipv6_address and network_ipv6_gateway are required together"
  when: network_ipv6_address is defined or network_ipv6_gateway is defined

- name: "Ensure network enabled services are enabled"
  become: true
  ansible.builtin.systemd_service:
    name: "{{ item }}"
    enabled: true
    state: "started"
  loop: "{{ network_enabled_services }}"
  when: not ansible_facts['is_chroot']

- name: "(chroot): Ensure network enabled services are enabled"
  ansible.builtin.command:
    cmd: "systemctl enable {{ item }}"
  changed_when: true
  loop: "{{ network_enabled_services }}"
  when: ansible_facts['is_chroot']
  # noqa: command-instead-of-module module doesn't work inside chroot

- name: "Ensure network disabled services are masked"
  become: true
  ansible.builtin.systemd_service:
    name: "{{ item }}"
    masked: true
    state: "stopped"
  loop: "{{ network_disabled_services }}"
  when: not ansible_facts['is_chroot']

- name: "(chroot): Ensure network disabled services are masked"
  ansible.builtin.command:
    cmd: "systemctl mask {{ item }}"
  changed_when: true
  loop: "{{ network_disabled_services }}"
  when: ansible_facts['is_chroot']
  # noqa: command-instead-of-module module doesn't work inside chroot

- name: "Compute hex-encoded SSID for iwd filename"
  # noqa: risky-shell-pipe since this is used early before bash configuration
  # it is the exception and needed to ensure that iwd is working on Mac machines
  # that only work with broadcom-wl and iwd
  # od is part of coreutils which is available by default on Arch/Debian but
  # added as role dependency for safty
  ansible.builtin.shell:
    cmd: "printf '%s' '{{ network_wifi_ssid }}' | od -A n -t x1 | tr -d ' \\n'"
  register: network_wifi_hex_ssid
  changed_when: false
  when: network_wifi_ssid != ""

- name: "Configure NetworkManager"
  become: true
  notify:
    - "Reload systemd"
    - "Restart NetworkManager"
    - "Restart systemd-resolved"
  block:
    - name: "Configure systemd-resolved"
      ansible.builtin.template:
        src: "resolved.conf.j2"
        dest: "/etc/systemd/resolved.conf"
        mode: "0644"

    - name: "Configure NetworkManager"
      ansible.builtin.template:
        src: "NetworkManager.conf.j2"
        dest: "/etc/NetworkManager/NetworkManager.conf"
        mode: "0644"

    - name: "Configure ethernet connection"
      ansible.builtin.template:
        src: "eth0-connection.nmconnection.j2"
        dest: "/etc/NetworkManager/system-connections/ethernet.nmconnection"
        mode: "0600"
        owner: "root"
        group: "root"

    - name: "Configure wifi connection"
      ansible.builtin.template:
        src: "wifi-connection.nmconnection.j2"
        dest: "/etc/NetworkManager/system-connections/{{ network_wifi_ssid }}.nmconnection"
        mode: "0600"
        owner: "root"
        group: "root"
      when: network_wifi_ssid != ""

    - name: "Ensure /var/lib/iwd directory exists"
      ansible.builtin.file:
        path: "/var/lib/iwd"
        state: "directory"
        mode: "0700"
        owner: "root"
        group: "root"
      when: network_wifi_ssid != ""

    - name: "Configure iwd known network for wifi auto-connect"
      community.general.ini_file:
        path: "/var/lib/iwd/={{ network_wifi_hex_ssid.stdout }}.psk"
        section: "Security"
        option: "Passphrase"
        value: "{{ network_wifi_pass }}"
        mode: "0600"
      when: network_wifi_ssid != ""