diff options
| author | Matthieu Pignolet <m@mpgn.dev> | 2025-03-17 14:18:03 +0400 |
|---|---|---|
| committer | Matthieu Pignolet <m@mpgn.dev> | 2025-03-17 14:18:03 +0400 |
| commit | 5098223d5c81fac49ded8e555ba629281b06d425 (patch) | |
| tree | 451988b8a7287735ac98704c5f2b1783fd837666 /host_vars | |
| parent | 63efaaf0ba315a9af837d9e9016d331a1327e5e5 (diff) | |
initial commit: migrate all `MatthieuCoder/pantheon-ansible` files to the oss repo
Diffstat (limited to 'host_vars')
27 files changed, 343 insertions, 0 deletions
diff --git a/host_vars/adguard1.pantheon.lab.mpgn.dev.yml b/host_vars/adguard1.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..f6c6462 --- /dev/null +++ b/host_vars/adguard1.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,19 @@ +--- +nft_input_host_rules: + 400 allow dns: + - tcp dport { 53 } ct state new accept + - udp dport { 53 } ct state new accept + 401 allow adguard webui: + - tcp dport { 80 } ct state new accept + 402 allow adguard-sync webui: + - tcp dport { 8080 } ct state new accept + +# Nmap scan report for adguard1.pantheon.lab.mpgn.dev (10.80.50.111) +# Host is up (0.00014s latency). +# Not shown: 996 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 53/tcp open domain +# 80/tcp open http +# 8080/tcp open http-proxy +# MAC Address: BC:24:11:11:32:49 (Unknown)
\ No newline at end of file diff --git a/host_vars/authelia.pantheon.lab.mpgn.dev.yml b/host_vars/authelia.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..6cb17e7 --- /dev/null +++ b/host_vars/authelia.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,12 @@ +--- +nft_input_host_rules: + 400 allow authelia https: + - tcp dport { 443 } ct state new accept + +# Nmap scan report for authelia.pantheon.lab.mpgn.dev (10.80.50.127) +# Host is up (0.00012s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 443/tcp open https +# MAC Address: BC:24:11:5F:E4:44 (Unknown)
\ No newline at end of file diff --git a/host_vars/bastion-kerberos.pantheon.lab.mpgn.dev.yml b/host_vars/bastion-kerberos.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..822c94e --- /dev/null +++ b/host_vars/bastion-kerberos.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,10 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for bastion-kerberos.pantheon.lab.mpgn.dev (10.80.50.123) +# Host is up (0.000083s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 111/tcp open rpcbind +# MAC Address: BC:24:11:CD:A2:3E (Unknown)
\ No newline at end of file diff --git a/host_vars/factorio.pantheon.lab.mpgn.dev.yml b/host_vars/factorio.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..f276084 --- /dev/null +++ b/host_vars/factorio.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,9 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for factorio.pantheon.lab.mpgn.dev (10.80.50.107) +# Host is up (0.00014s latency). +# Not shown: 999 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# MAC Address: BC:24:11:BE:E3:D8 (Unknown)
\ No newline at end of file diff --git a/host_vars/falco-sidekick.pantheon.lab.mpgn.dev.yml b/host_vars/falco-sidekick.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..06b8145 --- /dev/null +++ b/host_vars/falco-sidekick.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,9 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for falco-sidekick.pantheon.lab.mpgn.dev (10.80.50.126) +# Host is up (0.000050s latency). +# Not shown: 999 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# MAC Address: BC:24:11:6B:82:51 (Unknown)
\ No newline at end of file diff --git a/host_vars/freepbx.pantheon.lab.mpgn.dev.yml b/host_vars/freepbx.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..a866fd3 --- /dev/null +++ b/host_vars/freepbx.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,14 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for freepbx.pantheon.lab.mpgn.dev (10.80.50.131) +# Host is up (0.00013s latency). +# Not shown: 994 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 80/tcp open http +# 443/tcp open https +# 1720/tcp open h323q931 +# 8001/tcp open vcom-tunnel +# 8089/tcp open unknown +# MAC Address: BC:24:11:1A:DD:10 (Unknown)
\ No newline at end of file diff --git a/host_vars/gns3.pantheon.lab.mpgn.dev.yml b/host_vars/gns3.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..c8b5798 --- /dev/null +++ b/host_vars/gns3.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,10 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for gns3.pantheon.lab.mpgn.dev (10.80.50.112) +# Host is up (0.000047s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 179/tcp open bgp +# MAC Address: BC:24:11:0A:CE:00 (Unknown)
\ No newline at end of file diff --git a/host_vars/homarr.pantheon.lab.mpgn.dev.yml b/host_vars/homarr.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..3af1633 --- /dev/null +++ b/host_vars/homarr.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,10 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for homarr.pantheon.lab.mpgn.dev (10.80.50.106) +# Host is up (0.00015s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 443/tcp open https +# MAC Address: BC:24:11:03:8F:A1 (Unknown)
\ No newline at end of file diff --git a/host_vars/influxdb.pantheon.lab.mpgn.dev.yml b/host_vars/influxdb.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..35c6f92 --- /dev/null +++ b/host_vars/influxdb.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,15 @@ +--- +nft_input_host_rules: + 400 librenms web interface: + - tcp dport { 443 } ct state new accept + +# Nmap scan report for influxdb.pantheon.lab.mpgn.dev (10.80.50.108) +# Host is up (0.00014s latency). +# Not shown: 995 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 443/tcp open https +# 8086/tcp open d-s-n +# 9090/tcp open zeus-admin +# 9100/tcp open jetdirect +# MAC Address: BC:24:11:94:27:2E (Unknown)
\ No newline at end of file diff --git a/host_vars/iredmail.pantheon.lab.mpgn.dev.yml b/host_vars/iredmail.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..9219ecb --- /dev/null +++ b/host_vars/iredmail.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,9 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for iredmail.pantheon.lab.mpgn.dev (10.80.50.132) +# Host is up (0.000043s latency). +# Not shown: 999 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# MAC Address: BC:24:11:E3:A3:F3 (Unknown)
\ No newline at end of file diff --git a/host_vars/kali.pantheon.lab.mpgn.dev.yml b/host_vars/kali.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..2ff86d8 --- /dev/null +++ b/host_vars/kali.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,12 @@ +--- +nft_input_host_rules: + 400 allow greenbone: + - tcp dport { 9392 } ct state new accept + +# Nmap scan report for kali.pantheon.lab.mpgn.dev (10.80.50.119) +# Host is up (0.0000050s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 80/tcp open http +# 3389/tcp open ms-wbt-server
\ No newline at end of file diff --git a/host_vars/krb-fs.pantheon.lab.mpgn.dev.yml b/host_vars/krb-fs.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..0dc41ce --- /dev/null +++ b/host_vars/krb-fs.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,11 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for krb-fs.pantheon.lab.mpgn.dev (10.80.50.133) +# Host is up (0.000063s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 111/tcp open rpcbind +# 2049/tcp open nfs +# MAC Address: BC:24:11:FB:94:B8 (Unknown) diff --git a/host_vars/ldap.pantheon.lab.mpgn.dev.yml b/host_vars/ldap.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..b9aa457 --- /dev/null +++ b/host_vars/ldap.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,22 @@ +--- +nft_input_host_rules: + 400 allow kerberos: + - udp dport { 88, 749, 111, 464 } ct state new accept + - tcp dport { 88, 749, 111, 464 } ct state new accept + + 401 allow ldap: + - udp dport { 389, 636 } ct state new accept + - tcp dport { 389, 636 } ct state new accept + +# Nmap scan report for ldap.pantheon.lab.mpgn.dev (10.80.50.104) +# Host is up (0.00013s latency). +# Not shown: 993 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 88/tcp open kerberos-sec +# 111/tcp open rpcbind +# 389/tcp open ldap +# 464/tcp open kpasswd5 +# 636/tcp open ldapssl +# 749/tcp open kerberos-adm +# MAC Address: BC:24:11:D5:84:08 (Unknown) diff --git a/host_vars/librenms-web.pantheon.lab.mpgn.dev.yml b/host_vars/librenms-web.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..9f7ef82 --- /dev/null +++ b/host_vars/librenms-web.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 librenms web interface: + - tcp dport { 80, 443, 42217 } ct state new accept + +# Nmap scan report for librenms-web.pantheon.lab.mpgn.dev (10.80.50.109) +# Host is up (0.00013s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 80/tcp open http +# 443/tcp open https +# MAC Address: BC:24:11:BA:22:D0 (Unknown)
\ No newline at end of file diff --git a/host_vars/librenms.pantheon.lab.mpgn.dev.yml b/host_vars/librenms.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..4984ce4 --- /dev/null +++ b/host_vars/librenms.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 librenms backend services: + - tcp dport { 3306, 11211, 6379 } ct state new accept + +# Nmap scan report for librenms.pantheon.lab.mpgn.dev (10.80.50.105) +# Host is up (0.00013s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 111/tcp open rpcbind +# 3306/tcp open mysql +# MAC Address: BC:24:11:67:B1:2C (Unknown)
\ No newline at end of file diff --git a/host_vars/loki.pantheon.lab.mpgn.dev.yml b/host_vars/loki.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..4981bb8 --- /dev/null +++ b/host_vars/loki.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,16 @@ +--- +nft_input_host_rules: + 400 allow loki api: + - tcp dport { 9080, 3100 } ct state new accept + 401 allow syslog: + - tcp dport { 514 } ct state new accept + - udp dport { 514 } ct state new accept + +# Nmap scan report for loki.pantheon.lab.mpgn.dev (10.80.50.122) +# Host is up (0.00019s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 514/tcp open shell +# 9080/tcp open glrpc +# MAC Address: BC:24:11:34:5A:7D (Unknown)
\ No newline at end of file diff --git a/host_vars/media.pantheon.lab.mpgn.dev.yml b/host_vars/media.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..edd9ca3 --- /dev/null +++ b/host_vars/media.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,17 @@ +--- +nft_input_host_rules: + 400 allow bittorrent access: + - iif "eth0" tcp dport { 8080 } ct state new accept + 400 input torrent accepted: + - udp dport 6881 ct state new accept + 400 allow access to sonarr: + - iif "eth0" tcp dport { 8989 } ct state new accept + +# Nmap scan report for media.pantheon.lab.mpgn.dev (10.80.50.103) +# Host is up (0.000037s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 21/tcp open ftp +# 22/tcp open ssh +# 8080/tcp open http-proxy +# MAC Address: BC:24:11:47:18:60 (Unknown)
\ No newline at end of file diff --git a/host_vars/ollama.pantheon.lab.mpgn.dev.yml b/host_vars/ollama.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..9d0ab1e --- /dev/null +++ b/host_vars/ollama.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 allow ollama access: + - tcp dport { 3000 } ct state new accept + +# Nmap scan report for ollama.pantheon.lab.mpgn.dev (10.80.50.114) +# Host is up (0.000060s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 3000/tcp open ppp +# 8000/tcp open http-alt +# MAC Address: BC:24:11:39:D0:15 (Unknown) diff --git a/host_vars/orion.pantheon.lab.mpgn.dev.yml b/host_vars/orion.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..e1cf35e --- /dev/null +++ b/host_vars/orion.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,12 @@ +--- +nft_input_host_rules: + 400 allow bgp: + - tcp dport { 179 } ct state new accept + +# Nmap scan report for orion.pantheon.lab.mpgn.dev (10.80.50.118) +# Host is up (0.00013s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 179/tcp open bgp +# MAC Address: BC:24:11:C6:A2:70 (Unknown)
\ No newline at end of file diff --git a/host_vars/ovpn.pantheon.lab.mpgn.dev.yml b/host_vars/ovpn.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..dc58141 --- /dev/null +++ b/host_vars/ovpn.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 allow bgp: + - tcp dport { 179 } ct state new accept + +# Nmap scan report for ovpn.pantheon.lab.mpgn.dev (10.80.50.125) +# Host is up (0.00013s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 53/tcp open domain +# 179/tcp open bgp +# MAC Address: BC:24:11:BA:CF:86 (Unknown)
\ No newline at end of file diff --git a/host_vars/pantheon-lb.pantheon.lab.mpgn.dev.yml b/host_vars/pantheon-lb.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..0166125 --- /dev/null +++ b/host_vars/pantheon-lb.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,16 @@ +--- +nft_input_host_rules: + 400 allow loadbalancer access: + - tcp dport { 80, 443 } ct state new accept + 401 allow haproxy stats: + - tcp dport { 8443 } ct state new accept + +# Nmap scan report for pantheon-lb.pantheon.lab.mpgn.dev (10.80.50.102) +# Host is up (0.00013s latency). +# Not shown: 996 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 80/tcp open http +# 443/tcp open https +# 8443/tcp open https-alt +# MAC Address: BC:24:11:C6:8F:6B (Unknown)
\ No newline at end of file diff --git a/host_vars/pdm.pantheon.lab.mpgn.dev.yml b/host_vars/pdm.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..bc19343 --- /dev/null +++ b/host_vars/pdm.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 allow proxmox datacenter manager ui: + - tcp dport { 443, 8443 } ct state new accept + +# Nmap scan report for pdm.pantheon.lab.mpgn.dev (10.80.50.113) +# Host is up (0.00021s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 443/tcp open https +# 8443/tcp open https-alt +# MAC Address: BC:24:11:4D:A1:CA (Unknown)
\ No newline at end of file diff --git a/host_vars/postgresql.pantheon.lab.mpgn.dev.yml b/host_vars/postgresql.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..52578c0 --- /dev/null +++ b/host_vars/postgresql.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,12 @@ +--- +nft_input_host_rules: + 400 allow postgres from other VMs: + - tcp dport { 5432 } ct state new accept + +# Nmap scan report for postgresql.pantheon.lab.mpgn.dev (10.80.50.100) +# Host is up (0.00014s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 5432/tcp open postgresql +# MAC Address: BC:24:11:51:61:34 (Unknown)
\ No newline at end of file diff --git a/host_vars/powerdns-webui.pantheon.lab.mpgn.dev.yml b/host_vars/powerdns-webui.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..55dd0b2 --- /dev/null +++ b/host_vars/powerdns-webui.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,13 @@ +--- +nft_input_host_rules: + 400 allow powerdns ui: + - tcp dport { 80, 443 } ct state new accept + +# Nmap scan report for powerdns-webui.pantheon.lab.mpgn.dev (10.80.50.116) +# Host is up (0.00012s latency). +# Not shown: 997 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 80/tcp open http +# 443/tcp open https +# MAC Address: BC:24:11:66:97:71 (Unknown)
\ No newline at end of file diff --git a/host_vars/pufferpanel.pantheon.lab.mpgn.dev.yml b/host_vars/pufferpanel.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..bf8230b --- /dev/null +++ b/host_vars/pufferpanel.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,12 @@ +--- +nft_input_host_rules: + 400 allow pufferpanel admin interface: + - tcp dport 8080 ct state new accept + +# Nmap scan report for pufferpanel.pantheon.lab.mpgn.dev (10.80.50.110) +# Host is up (0.000048s latency). +# Not shown: 998 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# 8080/tcp open http-proxy +# MAC Address: BC:24:11:FF:DD:3F (Unknown) diff --git a/host_vars/reflector.pantheon.lab.mpgn.dev.yml b/host_vars/reflector.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..970e9a5 --- /dev/null +++ b/host_vars/reflector.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,9 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for reflector.pantheon.lab.mpgn.dev (10.80.50.101) +# Host is up (0.00014s latency). +# Not shown: 999 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# MAC Address: BC:24:11:80:3F:30 (Unknown)
\ No newline at end of file diff --git a/host_vars/toan-box.pantheon.lab.mpgn.dev.yml b/host_vars/toan-box.pantheon.lab.mpgn.dev.yml new file mode 100644 index 0000000..6f98ba6 --- /dev/null +++ b/host_vars/toan-box.pantheon.lab.mpgn.dev.yml @@ -0,0 +1,9 @@ +--- +nft_input_host_rules: [] + +# Nmap scan report for toan-box.pantheon.lab.mpgn.dev (10.80.50.117) +# Host is up (0.000061s latency). +# Not shown: 999 closed tcp ports (reset) +# PORT STATE SERVICE +# 22/tcp open ssh +# MAC Address: BC:24:11:65:1D:A9 (Unknown) |
