Phantom v2: dual-mode architecture, security hardening, deployment management
- Dual-mode operation: standalone + c2itall integrated (env var detection)
- SSH keys moved to ~/.ssh/c2deploy_ph-{id} with per-deployment known_hosts
- Ansible output streaming with filtered console + full log capture
- Deployment management menu: discover, SSH, teardown existing deployments
- Cert setup script (setup-cert.sh) deployed to servers for post-DNS LE certs
- Matrix hardening: unique secrets, SSRF protection, rate limits, nginx security headers
- Base hardening: fail2ban systemd backend (Debian 12), SSH limits, nginx jails
- Add-matrix-user helper script deployed to all Matrix servers
- .env support for standalone credential storage
- Config key rename: deploy_id → deployment_id (with backward compat)
- Provider cleanup playbooks for teardown
- Test suite with 50 tests
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -7,10 +7,11 @@
|
||||
connection: local
|
||||
gather_facts: false
|
||||
vars:
|
||||
deploy_id: "{{ deployment_id }}"
|
||||
aws_region: "{{ region | default('us-east-1') }}"
|
||||
ec2_instance_type: "{{ instance_type | default('t3.micro') }}"
|
||||
ec2_ami: "{{ ami | default('') }}"
|
||||
ec2_key_name: "phantom-{{ deploy_id }}"
|
||||
ec2_key_name: "ph-{{ deployment_id }}"
|
||||
ssh_key_path: "{{ ssh_key }}.pub"
|
||||
|
||||
environment:
|
||||
@@ -48,7 +49,7 @@
|
||||
|
||||
- name: Create security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "phantom-{{ deploy_id }}"
|
||||
name: "ph-{{ deploy_id }}"
|
||||
description: "phantom deployment {{ deploy_id }}"
|
||||
region: "{{ aws_region }}"
|
||||
rules:
|
||||
@@ -68,7 +69,7 @@
|
||||
|
||||
- name: Launch EC2 instance
|
||||
amazon.aws.ec2_instance:
|
||||
name: "phantom-{{ deploy_id }}"
|
||||
name: "ph-{{ deploy_id }}"
|
||||
key_name: "{{ ec2_key_name }}"
|
||||
instance_type: "{{ ec2_instance_type }}"
|
||||
image_id: "{{ ec2_ami }}"
|
||||
@@ -97,6 +98,12 @@
|
||||
dest: "{{ _host_output_file }}"
|
||||
when: _host_output_file is defined
|
||||
|
||||
- name: Write instance ID for teardown
|
||||
copy:
|
||||
content: "{{ ec2_result.instances[0].instance_id }}"
|
||||
dest: "{{ _host_output_file | dirname }}/instance_id"
|
||||
when: _host_output_file is defined
|
||||
|
||||
- name: Wait for SSH
|
||||
wait_for:
|
||||
host: "{{ target_host }}"
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
---
|
||||
# Tear down a Phantom AWS EC2 instance
|
||||
# Matches c2itall cleanup pattern
|
||||
|
||||
- name: Teardown Phantom EC2 Instance
|
||||
hosts: localhost
|
||||
connection: local
|
||||
gather_facts: false
|
||||
|
||||
environment:
|
||||
AWS_ACCESS_KEY_ID: "{{ aws_access_key }}"
|
||||
AWS_SECRET_ACCESS_KEY: "{{ aws_secret_key }}"
|
||||
AWS_DEFAULT_REGION: "{{ region | default('us-east-1') }}"
|
||||
|
||||
tasks:
|
||||
- name: Find instance by name tag
|
||||
amazon.aws.ec2_instance_info:
|
||||
filters:
|
||||
"tag:Name": "{{ instance_label }}"
|
||||
instance-state-name: ["running", "stopped", "pending"]
|
||||
region: "{{ region | default('us-east-1') }}"
|
||||
register: ec2_info
|
||||
|
||||
- name: Terminate instance
|
||||
amazon.aws.ec2_instance:
|
||||
instance_ids: "{{ ec2_info.instances | map(attribute='instance_id') | list }}"
|
||||
state: absent
|
||||
region: "{{ region | default('us-east-1') }}"
|
||||
when: ec2_info.instances | length > 0
|
||||
register: deletion
|
||||
ignore_errors: true
|
||||
|
||||
- name: Delete security group
|
||||
amazon.aws.ec2_security_group:
|
||||
name: "{{ instance_label }}"
|
||||
state: absent
|
||||
region: "{{ region | default('us-east-1') }}"
|
||||
ignore_errors: true
|
||||
|
||||
- name: Delete key pair
|
||||
amazon.aws.ec2_key:
|
||||
name: "{{ instance_label }}"
|
||||
state: absent
|
||||
region: "{{ region | default('us-east-1') }}"
|
||||
ignore_errors: true
|
||||
|
||||
- name: Report teardown result
|
||||
debug:
|
||||
msg: "Instance {{ instance_label }}: {{ (ec2_info.instances | length > 0) | ternary('Terminated', 'Not found') }}"
|
||||
@@ -7,11 +7,12 @@
|
||||
connection: local
|
||||
gather_facts: false
|
||||
vars:
|
||||
deploy_id: "{{ deployment_id }}"
|
||||
linode_token: "{{ api_token }}"
|
||||
linode_region: "{{ region | default('us-east') }}"
|
||||
linode_plan: "{{ plan | default('g6-nanode-1') }}"
|
||||
linode_image: "{{ image | default('linode/debian12') }}"
|
||||
linode_label: "phantom-{{ deploy_id }}"
|
||||
linode_label: "ph-{{ deployment_id }}"
|
||||
ssh_key_path: "{{ ssh_key }}.pub"
|
||||
|
||||
tasks:
|
||||
@@ -20,6 +21,10 @@
|
||||
src: "{{ ssh_key_path }}"
|
||||
register: ssh_pubkey
|
||||
|
||||
- name: Generate root password (required by API, SSH key auth used instead)
|
||||
command: openssl rand -base64 32
|
||||
register: root_pass_gen
|
||||
|
||||
- name: Create Linode instance
|
||||
uri:
|
||||
url: https://api.linode.com/v4/linode/instances
|
||||
@@ -33,6 +38,7 @@
|
||||
region: "{{ linode_region }}"
|
||||
image: "{{ linode_image }}"
|
||||
label: "{{ linode_label }}"
|
||||
root_pass: "{{ root_pass_gen.stdout }}"
|
||||
authorized_keys:
|
||||
- "{{ ssh_pubkey.content | b64decode | trim }}"
|
||||
booted: true
|
||||
@@ -58,6 +64,12 @@
|
||||
dest: "{{ _host_output_file }}"
|
||||
when: _host_output_file is defined
|
||||
|
||||
- name: Write instance ID for teardown
|
||||
copy:
|
||||
content: "{{ linode_result.json.id }}"
|
||||
dest: "{{ _host_output_file | dirname }}/instance_id"
|
||||
when: _host_output_file is defined
|
||||
|
||||
- name: Wait for SSH
|
||||
wait_for:
|
||||
host: "{{ target_host }}"
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
---
|
||||
# Tear down a Phantom Linode instance by label using raw API calls
|
||||
# No extra collections needed — uses uri module (same as provisioning)
|
||||
|
||||
- name: Teardown Phantom Linode Instance
|
||||
hosts: localhost
|
||||
connection: local
|
||||
gather_facts: false
|
||||
|
||||
tasks:
|
||||
- name: Validate required variables
|
||||
assert:
|
||||
that:
|
||||
- api_token is defined and api_token != ""
|
||||
- instance_label is defined and instance_label != ""
|
||||
fail_msg: "api_token and instance_label are required for teardown"
|
||||
|
||||
- name: List all Linode instances
|
||||
uri:
|
||||
url: https://api.linode.com/v4/linode/instances
|
||||
method: GET
|
||||
headers:
|
||||
Authorization: "Bearer {{ api_token }}"
|
||||
return_content: true
|
||||
register: linode_list
|
||||
|
||||
- name: Find instance by label
|
||||
set_fact:
|
||||
target_instance: "{{ linode_list.json.data | selectattr('label', 'equalto', instance_label) | list | first | default(None) }}"
|
||||
|
||||
- name: Delete instance
|
||||
uri:
|
||||
url: "https://api.linode.com/v4/linode/instances/{{ target_instance.id }}"
|
||||
method: DELETE
|
||||
headers:
|
||||
Authorization: "Bearer {{ api_token }}"
|
||||
status_code: 200
|
||||
when: target_instance is not none and target_instance != None
|
||||
register: deletion
|
||||
|
||||
- name: Report result
|
||||
debug:
|
||||
msg: "{{ (target_instance is not none and target_instance != None) | ternary('Instance ' ~ instance_label ~ ' (ID ' ~ target_instance.id | default('?') ~ ') deleted', 'No instance found with label ' ~ instance_label) }}"
|
||||
Reference in New Issue
Block a user