LAN/local deployment support, OS compat, Cloudflare Tunnel

- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN,
  HSTS max-age=0 for self-signed certs, split LAN vs public messages
- Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact
- Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream)
- Module prompts: accept IPs for matrix/cloud/vault/media, hard error
  on email with IP, all_in_one skips certbot email for LAN
- Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name
- OS family guards: ansible_os_family == Debian on all apt tasks
- SSH key path: expanduser().resolve() on user-provided key paths
- Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API
  token — no browser auth needed, creates tunnel + credentials + DNS + systemd

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
n0mad1k
2026-03-10 13:27:12 -04:00
parent 040fa12705
commit 3542913689
22 changed files with 466 additions and 52 deletions
@@ -1,6 +1,11 @@
---
# Vaultwarden binary installation from GitHub releases
- name: Check for unsupported 32-bit ARM architecture
fail:
msg: "Vaultwarden does not support 32-bit ARM (armv7l). Use a 64-bit OS (aarch64) or x86_64 system."
when: ansible_architecture == "armv7l"
- name: Install prerequisites
apt:
name:
@@ -13,6 +18,7 @@
- ca-certificates
state: present
update_cache: true
when: ansible_os_family == "Debian"
- name: Create vaultwarden system user
user:
+4
View File
@@ -59,7 +59,11 @@
ssl_prefer_server_ciphers on;
server_tokens off;
{% if _is_selfsigned | default(false) | bool %}
add_header Strict-Transport-Security "max-age=0" always;
{% else %}
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains" always;
{% endif %}
add_header X-Content-Type-Options nosniff always;
add_header X-Frame-Options DENY always;