LAN/local deployment support, OS compat, Cloudflare Tunnel

- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN,
  HSTS max-age=0 for self-signed certs, split LAN vs public messages
- Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact
- Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream)
- Module prompts: accept IPs for matrix/cloud/vault/media, hard error
  on email with IP, all_in_one skips certbot email for LAN
- Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name
- OS family guards: ansible_os_family == Debian on all apt tasks
- SSH key path: expanduser().resolve() on user-provided key paths
- Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API
  token — no browser auth needed, creates tunnel + credentials + DNS + systemd

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
n0mad1k
2026-03-10 13:27:12 -04:00
parent 040fa12705
commit 3542913689
22 changed files with 466 additions and 52 deletions
+42 -20
View File
@@ -4,6 +4,8 @@ Composes multiple services onto a single server with nginx reverse proxy
and TLS via Certbot. Includes clear warnings about single-server risks.
"""
import re
CYAN = "\033[38;5;51m"
WHITE = "\033[38;5;255m"
GREY = "\033[38;5;244m"
@@ -11,6 +13,9 @@ YELLOW = "\033[38;5;214m"
RED = "\033[38;5;196m"
RESET = "\033[0m"
_IP_RE = re.compile(r'^\d+\.\d+\.\d+\.\d+$')
_LOCAL_RE = re.compile(r'\.(local|lan|home|internal|test)$')
SERVICES = [
("matrix", "Matrix + Element", "Encrypted messaging"),
("vpn", "WireGuard VPN", "Private VPN server"),
@@ -69,37 +74,54 @@ def gather_config(config):
config["services"] = selected_services
config["all_in_one"] = True
# Base domain for nginx vhosts
# Base domain or IP for nginx vhosts
config["domain"] = input(
f"\n {CYAN}Base domain (e.g. example.com):{RESET} "
f"\n {CYAN}Base domain or IP (e.g. example.com or 192.168.1.100):{RESET} "
).strip()
if not config["domain"]:
print(f" {RED}Domain is required for reverse proxy.{RESET}")
print(f" {RED}Domain or IP is required for reverse proxy.{RESET}")
return None
config["certbot_email"] = input(
f" {CYAN}Email for Let's Encrypt [{GREY}optional{RESET}]: "
).strip()
base_domain = config["domain"]
is_ip = bool(_IP_RE.match(base_domain))
is_local = bool(_LOCAL_RE.search(base_domain))
if is_ip:
# Warn about multiple web services on a single IP
web_services = [s for s in selected_services if s not in ("vpn", "dns")]
if len(web_services) > 1:
print(f"\n {YELLOW}WARNING: Multiple web services on a single IP.{RESET}")
print(f" {YELLOW}Only the last nginx config on port 443 wins.{RESET}")
print(f" {YELLOW}Consider using different ports or a reverse proxy with path-based routing.{RESET}")
# Skip certbot email for IPs / .local domains
if is_ip or is_local:
config["certbot_email"] = ""
else:
config["certbot_email"] = input(
f" {CYAN}Email for Let's Encrypt [{GREY}optional{RESET}]: "
).strip()
# Gather per-service configs
# Save base domain — each service stores config under its own prefixed keys
base_domain = config["domain"]
for svc in selected_services:
try:
mod = __import__(f"modules.{svc}", fromlist=[svc])
if hasattr(mod, "gather_config"):
# Set per-service subdomain default
svc_subdomains = {
"matrix": f"matrix.{base_domain}",
"cloud": f"cloud.{base_domain}",
"vault": f"vault.{base_domain}",
"media": f"media.{base_domain}",
"email": f"mail.{base_domain}",
"dns": f"dns.{base_domain}",
"vpn": base_domain,
}
if svc in svc_subdomains:
config["domain"] = svc_subdomains[svc]
# Set per-service domain: use same IP for all when base is IP
if is_ip:
config["domain"] = base_domain
else:
svc_subdomains = {
"matrix": f"matrix.{base_domain}",
"cloud": f"cloud.{base_domain}",
"vault": f"vault.{base_domain}",
"media": f"media.{base_domain}",
"email": f"mail.{base_domain}",
"dns": f"dns.{base_domain}",
"vpn": base_domain,
}
if svc in svc_subdomains:
config["domain"] = svc_subdomains[svc]
config = mod.gather_config(config)
if config is None:
return None
+1 -1
View File
@@ -12,7 +12,7 @@ def gather_config(config):
print(f" {CYAN}{RESET} {GREY}PHP-FPM + MariaDB + Redis + nginx{RESET}")
config["domain"] = config.get("domain") or input(
f" {CYAN}{RESET} Domain (e.g. cloud.example.com): "
f" {CYAN}{RESET} Domain or IP (e.g. cloud.example.com or 192.168.1.100): "
).strip()
config["cloud_admin_user"] = input(
+9
View File
@@ -1,10 +1,15 @@
"""Mail-in-a-Box deployment module — native installer script."""
import re
CYAN = "\033[38;5;51m"
WHITE = "\033[38;5;255m"
GREY = "\033[38;5;244m"
RED = "\033[38;5;196m"
RESET = "\033[0m"
_IP_RE = re.compile(r'^\d+\.\d+\.\d+\.\d+$')
def gather_config(config):
"""Gather Mail-in-a-Box configuration."""
@@ -15,6 +20,10 @@ def gather_config(config):
f" {CYAN}{RESET} Mail domain (e.g. mail.example.com): "
).strip()
if _IP_RE.match(config.get("domain", "")):
print(f" {CYAN}{RESET} {RED}ERROR: Email requires a real domain — bare IPs cannot receive mail (no MX records).{RESET}")
return None
config["email_first_user"] = input(
f" {CYAN}{RESET} First email user (e.g. admin@example.com): "
).strip()
+18 -3
View File
@@ -1,25 +1,36 @@
"""Matrix + Element homeserver deployment module."""
import getpass
import re
import secrets
CYAN = "\033[38;5;51m"
WHITE = "\033[38;5;255m"
GREY = "\033[38;5;244m"
YELLOW = "\033[38;5;214m"
RESET = "\033[0m"
_IP_RE = re.compile(r'^\d+\.\d+\.\d+\.\d+$')
def gather_config(config):
"""Gather Matrix/Synapse + Element configuration."""
print(f"\n{CYAN} ┌─ Matrix Homeserver Configuration ─────────────────┐{RESET}")
config["domain"] = config.get("domain") or input(
f" {CYAN}{RESET} Domain (e.g. matrix.example.com): "
f" {CYAN}{RESET} Domain or IP (e.g. matrix.example.com or 192.168.1.100): "
).strip()
if not config["domain"]:
print(f" {CYAN}{RESET} Domain is required.")
return None
is_ip = bool(_IP_RE.match(config["domain"]))
if is_ip:
print(f" {CYAN}{RESET} {YELLOW}WARNING: Deploying with an IP as server_name.{RESET}")
print(f" {CYAN}{RESET} {YELLOW}Synapse server_name is immutable after first federation.{RESET}")
print(f" {CYAN}{RESET} {YELLOW}Migrating to a domain later requires a fresh database.{RESET}")
config["matrix_admin_user"] = input(
f" {CYAN}{RESET} Admin username [{WHITE}admin{RESET}]: "
).strip() or "admin"
@@ -38,8 +49,12 @@ def gather_config(config):
).strip().lower()
config["matrix_element_web"] = config["matrix_element_web"] not in ("no", "n", "false")
config["matrix_server_name"] = config["domain"].replace("matrix.", "", 1) \
if config["domain"].startswith("matrix.") else config["domain"]
# Skip matrix. prefix stripping for IPs
if is_ip:
config["matrix_server_name"] = config["domain"]
else:
config["matrix_server_name"] = config["domain"].replace("matrix.", "", 1) \
if config["domain"].startswith("matrix.") else config["domain"]
config["matrix_signing_key"] = secrets.token_hex(32)
config["matrix_form_secret"] = secrets.token_hex(32)
+1 -1
View File
@@ -12,7 +12,7 @@ def gather_config(config):
print(f" {CYAN}{RESET} {GREY}Official apt repo + nginx reverse proxy{RESET}")
config["domain"] = config.get("domain") or input(
f" {CYAN}{RESET} Domain (e.g. media.example.com): "
f" {CYAN}{RESET} Domain or IP (e.g. media.example.com or 192.168.1.100): "
).strip()
config["media_library_path"] = input(
+1 -1
View File
@@ -14,7 +14,7 @@ def gather_config(config):
print(f" {CYAN}{RESET} {GREY}Pre-built binary + systemd + nginx{RESET}")
config["domain"] = config.get("domain") or input(
f" {CYAN}{RESET} Domain (e.g. vault.example.com): "
f" {CYAN}{RESET} Domain or IP (e.g. vault.example.com or 192.168.1.100): "
).strip()
config["vault_admin_token"] = input(