5a0a49a9c8
Multi-provider (Linode/AWS/FlokiNET) scan orchestration: - Flatten all country CIDRs, chunk by IP count (sprint/balanced/economy presets) - Assign chunks round-robin across providers - Cost+time estimate table before deploy - Ansible provisions N nodes in parallel, runs masscan/nmap/probe per node - Results fetched back and merged into unified JSON report - Scanner IPs logged per engagement for client IR reporting - Operator IP whitelisting, enhanced OPSEC mode, YAML targets.yaml support
93 lines
2.8 KiB
YAML
93 lines
2.8 KiB
YAML
---
|
|
# WEBRUNNER — Distributed geo-targeted recon
|
|
# Multi-provider: Linode, AWS, FlokiNET
|
|
# Controller: ~/tools/c2itall/ (CWD when ansible-playbook runs)
|
|
|
|
- name: WEBRUNNER — Provision scan nodes
|
|
hosts: localhost
|
|
connection: local
|
|
gather_facts: false
|
|
vars:
|
|
ansible_python_interpreter: "{{ ansible_playbook_python }}"
|
|
ssh_key_name: "{{ ssh_key_path | basename | regex_replace('\\.pub$', '') }}"
|
|
all_node_chunks: "{{ lookup('file', node_chunks_file) | from_json }}"
|
|
|
|
tasks:
|
|
- name: Ensure results directory
|
|
file:
|
|
path: "{{ results_dir }}"
|
|
state: directory
|
|
mode: '0755'
|
|
|
|
- name: Initialize scanner IP log
|
|
copy:
|
|
content: "# WEBRUNNER scanner IPs — {{ webrunner_name }}\n"
|
|
dest: "{{ scanner_ip_log }}"
|
|
mode: '0644'
|
|
force: false
|
|
|
|
- name: Provision Linode nodes
|
|
include_tasks: "Linode/webrunner_provision_tasks.yml"
|
|
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'linode') | list }}"
|
|
loop_var: node_chunk
|
|
|
|
- name: Provision AWS nodes
|
|
include_tasks: "AWS/webrunner_provision_tasks.yml"
|
|
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'aws') | list }}"
|
|
loop_var: node_chunk
|
|
|
|
- name: Provision FlokiNET nodes
|
|
include_tasks: "FlokiNET/webrunner_provision_tasks.yml"
|
|
loop: "{{ all_node_chunks | selectattr('provider', 'equalto', 'flokinet') | list }}"
|
|
loop_var: node_chunk
|
|
|
|
|
|
- name: WEBRUNNER — Configure and scan
|
|
hosts: webrunner_nodes
|
|
gather_facts: false
|
|
become: true
|
|
|
|
tasks:
|
|
- name: Wait for SSH
|
|
wait_for_connection:
|
|
delay: 20
|
|
timeout: 300
|
|
|
|
- name: Configure node
|
|
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/configure_node.yml"
|
|
|
|
- name: Run scan
|
|
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/run_scan.yml"
|
|
|
|
- name: Collect results
|
|
include_tasks: "{{ playbook_dir }}/../modules/webrunner/tasks/collect_results.yml"
|
|
|
|
|
|
- name: WEBRUNNER — Merge and report
|
|
hosts: localhost
|
|
connection: local
|
|
gather_facts: false
|
|
|
|
tasks:
|
|
- name: Merge per-node results
|
|
command: >
|
|
python3 {{ playbook_dir }}/../modules/webrunner/tasks/merge_results.py
|
|
--results-dir {{ results_dir }}
|
|
--output {{ results_dir }}/merged_results.json
|
|
--deployment-id {{ deployment_id }}
|
|
register: merge_out
|
|
ignore_errors: true
|
|
|
|
- name: Show merge output
|
|
debug:
|
|
var: merge_out.stdout_lines
|
|
when: merge_out.stdout_lines is defined and merge_out.stdout_lines | length > 0
|
|
|
|
- name: Summary
|
|
debug:
|
|
msg:
|
|
- "WEBRUNNER complete — {{ webrunner_name }}"
|
|
- "Results: {{ results_dir }}/merged_results.json"
|
|
- "Scanner IPs: {{ scanner_ip_log }}"
|
|
- "Log: logs/deployment_{{ deployment_id }}.log"
|