LAN/local deployment support, OS compat, Cloudflare Tunnel

- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN,
  HSTS max-age=0 for self-signed certs, split LAN vs public messages
- Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact
- Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream)
- Module prompts: accept IPs for matrix/cloud/vault/media, hard error
  on email with IP, all_in_one skips certbot email for LAN
- Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name
- OS family guards: ansible_os_family == Debian on all apt tasks
- SSH key path: expanduser().resolve() on user-provided key paths
- Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API
  token — no browser auth needed, creates tunnel + credentials + DNS + systemd

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
n0mad1k
2026-03-10 13:27:12 -04:00
parent 040fa12705
commit 3542913689
22 changed files with 466 additions and 52 deletions
+9
View File
@@ -1,10 +1,15 @@
"""Mail-in-a-Box deployment module — native installer script."""
import re
CYAN = "\033[38;5;51m"
WHITE = "\033[38;5;255m"
GREY = "\033[38;5;244m"
RED = "\033[38;5;196m"
RESET = "\033[0m"
_IP_RE = re.compile(r'^\d+\.\d+\.\d+\.\d+$')
def gather_config(config):
"""Gather Mail-in-a-Box configuration."""
@@ -15,6 +20,10 @@ def gather_config(config):
f" {CYAN}{RESET} Mail domain (e.g. mail.example.com): "
).strip()
if _IP_RE.match(config.get("domain", "")):
print(f" {CYAN}{RESET} {RED}ERROR: Email requires a real domain — bare IPs cannot receive mail (no MX records).{RESET}")
return None
config["email_first_user"] = input(
f" {CYAN}{RESET} First email user (e.g. admin@example.com): "
).strip()