Commit Graph

5 Commits

Author SHA1 Message Date
n0mad1k 1eff254a66 Fix tunnel script overwriting credentials for existing tunnels
When an existing Cloudflare tunnel was found, the script would overwrite
the credentials file with an empty TunnelSecret, breaking the service.
Now validates existing credentials and only recreates the tunnel if the
credentials file is missing or invalid.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 13:37:20 -04:00
n0mad1k 3542913689 LAN/local deployment support, OS compat, Cloudflare Tunnel
- Smart TLS: skip certbot for IPs/.local/.lan, self-signed with SAN,
  HSTS max-age=0 for self-signed certs, split LAN vs public messages
- Dynamic PHP: versionless meta-packages, runtime detection via php_ver fact
- Vaultwarden: fail-fast on armv7l (32-bit ARM not supported upstream)
- Module prompts: accept IPs for matrix/cloud/vault/media, hard error
  on email with IP, all_in_one skips certbot email for LAN
- Matrix: skip matrix. prefix strip for IPs, warn about immutable server_name
- OS family guards: ansible_os_family == Debian on all apt tasks
- SSH key path: expanduser().resolve() on user-provided key paths
- Cloudflare Tunnel: post-deploy script (setup-tunnel.sh) using CF API
  token — no browser auth needed, creates tunnel + credentials + DNS + systemd

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-10 13:27:12 -04:00
n0mad1k 040fa12705 Split base hardening packages into required and optional
software-properties-common removed — dropped from Debian 13 (trixie).
unattended-upgrades and apt-listchanges moved to optional task with
ignore_errors so missing packages don't fail the entire deployment.
2026-03-10 10:59:06 -04:00
n0mad1k 7484a0e034 Phantom v2: dual-mode architecture, security hardening, deployment management
- Dual-mode operation: standalone + c2itall integrated (env var detection)
- SSH keys moved to ~/.ssh/c2deploy_ph-{id} with per-deployment known_hosts
- Ansible output streaming with filtered console + full log capture
- Deployment management menu: discover, SSH, teardown existing deployments
- Cert setup script (setup-cert.sh) deployed to servers for post-DNS LE certs
- Matrix hardening: unique secrets, SSRF protection, rate limits, nginx security headers
- Base hardening: fail2ban systemd backend (Debian 12), SSH limits, nginx jails
- Add-matrix-user helper script deployed to all Matrix servers
- .env support for standalone credential storage
- Config key rename: deploy_id → deployment_id (with backward compat)
- Provider cleanup playbooks for teardown
- Test suite with 50 tests

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-09 15:45:24 -04:00
ghost 973cede31f Initial release: ghost_protocol privacy toolkit 2026-03-04 09:13:16 -05:00