LAN/local deployment support, OS compat, Cloudflare Tunnel
- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN, HSTS max-age=0 for self-signed certs, split LAN vs public messages - Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact - Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream) - Module prompts: accept IPs for matrix/cloud/vault/media, hard error on email with IP, all_in_one skips certbot email for LAN - Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name - OS family guards: ansible_os_family == Debian on all apt tasks - SSH key path: expanduser().resolve() on user-provided key paths - Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API token — no browser auth needed, creates tunnel + credentials + DNS + systemd Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -1,6 +1,11 @@
|
||||
---
|
||||
# Vaultwarden binary installation from GitHub releases
|
||||
|
||||
- name: Check for unsupported 32-bit ARM architecture
|
||||
fail:
|
||||
msg: "Vaultwarden does not support 32-bit ARM (armv7l). Use a 64-bit OS (aarch64) or x86_64 system."
|
||||
when: ansible_architecture == "armv7l"
|
||||
|
||||
- name: Install prerequisites
|
||||
apt:
|
||||
name:
|
||||
@@ -13,6 +18,7 @@
|
||||
- ca-certificates
|
||||
state: present
|
||||
update_cache: true
|
||||
when: ansible_os_family == "Debian"
|
||||
|
||||
- name: Create vaultwarden system user
|
||||
user:
|
||||
|
||||
@@ -59,7 +59,11 @@
|
||||
ssl_prefer_server_ciphers on;
|
||||
|
||||
server_tokens off;
|
||||
{% if _is_selfsigned | default(false) | bool %}
|
||||
add_header Strict-Transport-Security "max-age=0" always;
|
||||
{% else %}
|
||||
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
|
||||
{% endif %}
|
||||
add_header X-Content-Type-Options nosniff always;
|
||||
add_header X-Frame-Options DENY always;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user