feat(aegis): harden Fedora IoT services

This commit is contained in:
Fabio Scotto di Santolo
2026-09-05 14:44:14 +02:00
parent 1933ddbe8f
commit f07391c404
13 changed files with 77 additions and 29 deletions

View File

@@ -1,12 +1,12 @@
# One-time bootstrap for Fedora CoreOS on Aegis (Raspberry Pi 4).
# One-time bootstrap for Fedora IoT on Aegis (Raspberry Pi 4).
# Generate only: ./generate-aegis-ign.sh
# Generate and write an SD card: ./generate-aegis-ign.sh --write IMAGE DEVICE
# The write mode uses arm-image-installer with the RPi4 target and embeds
# config.ign; it prompts for Wi-Fi credentials unless supplied through its
# WIFI_SSID and WIFI_PASS environment variables.
# For WiFi, the UEFI 'System Table Selection' must be DeviceTree (Esc at boot).
variant: fcos
version: 1.6.0
variant: fiot
version: 1.0.0
passwd:
users:
- name: pi

View File

@@ -1,2 +0,0 @@
---
# Fedora CoreOS is immutable: do not attach the mutable Fedora package roles.

View File

@@ -0,0 +1,2 @@
---
# Fedora IoT is immutable: do not attach the mutable Fedora package roles.

View File

@@ -4,8 +4,10 @@ ansible_connection: ssh
ansible_user: pi
ansible_become: true
ansible_python_interpreter: /usr/bin/python3
# Avoid PTY framing around module JSON on this remote Fedora IoT host.
ansible_ssh_use_tty: false
aegis_lan_subnet: 192.168.178.0/24
aegis_adguard_web_port: 3000
aegis_adguard_web_port: 80
aegis_icloudpd_apple_id: "{{ vault_aegis_icloudpd_apple_id | default('') }}"

View File

@@ -13,7 +13,7 @@ all:
deadalus:
ansible_connection: local
platform_fedora_coreos:
platform_fedora_iot:
hosts:
aegis:
@@ -28,7 +28,7 @@ all:
fedora:
children:
platform_fedora:
platform_fedora_coreos:
platform_fedora_iot:
rocky:
children:

View File

@@ -10,6 +10,7 @@ aegis_wol_port: 9
aegis_lan_subnet: CHANGEME_LAN_SUBNET
aegis_firewalld_zone: public
aegis_adguard_web_port: 3000
aegis_adguard_web_port: 80
aegis_ssh_allowed_users:
- pi
aegis_ssh_user_home: "/var/home/{{ ansible_user }}"

View File

@@ -1,4 +1,9 @@
---
- name: Restart Aegis systemd-resolved
ansible.builtin.systemd:
name: systemd-resolved.service
state: restarted
- name: Reload Aegis SSH
ansible.builtin.systemd:
name: sshd.service

View File

@@ -64,6 +64,36 @@
no_log: "{{ item.dest == 'icloudpd.container' }}"
notify: Restart Aegis Quadlet services
- name: Create Aegis systemd-resolved configuration directory
tags: [aegis, adguard, dns, services]
ansible.builtin.file:
path: /etc/systemd/resolved.conf.d
state: directory
owner: root
group: root
mode: "0755"
- name: Disable Aegis systemd-resolved DNS stub listener
tags: [aegis, adguard, dns, services]
ansible.builtin.template:
src: 10-adguard-dns.conf.j2
dest: /etc/systemd/resolved.conf.d/10-adguard-dns.conf
owner: root
group: root
mode: "0644"
notify:
- Restart Aegis systemd-resolved
- Restart Aegis Quadlet services
- name: Point Aegis resolver at the full systemd-resolved configuration
tags: [aegis, adguard, dns, services]
ansible.builtin.file:
src: ../run/systemd/resolve/resolv.conf
dest: /etc/resolv.conf
state: link
force: true
notify: Restart Aegis systemd-resolved
- name: Enable Aegis firewalld
tags: [aegis, firewall, services]
ansible.builtin.systemd:
@@ -116,6 +146,7 @@
loop:
- 'rule family="ipv4" source address="{{ aegis_lan_subnet }}" service name="ssh" accept'
- 'rule family="ipv4" source address="{{ aegis_lan_subnet }}" service name="dns" accept'
- 'rule family="ipv4" source address="{{ aegis_lan_subnet }}" port port="853" protocol="tcp" accept'
- 'rule family="ipv4" source address="{{ aegis_lan_subnet }}" service name="aegis-adguard-web" accept'
loop_control:
label: "{{ item }}"
@@ -123,13 +154,13 @@
- name: Check the standard Aegis SSH authorized keys file
tags: [aegis, ssh, services]
ansible.builtin.stat:
path: "{{ ansible_user_dir }}/.ssh/authorized_keys"
path: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys"
register: aegis_authorized_keys
- name: Find Aegis SSH authorized key fragments
tags: [aegis, ssh, services]
ansible.builtin.find:
paths: "{{ ansible_user_dir }}/.ssh/authorized_keys.d"
paths: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys.d"
file_type: file
recurse: false
register: aegis_authorized_key_fragments

View File

@@ -0,0 +1,3 @@
# Managed by Ansible. Do not edit manually.
[Resolve]
DNSStubListener=no

View File

@@ -3,4 +3,5 @@
<short>Aegis AdGuard Home web interface</short>
<description>AdGuard Home administrative web interface on Aegis.</description>
<port protocol="tcp" port="{{ aegis_adguard_web_port }}"/>
<port protocol="tcp" port="443"/>
</service>

View File

@@ -35,7 +35,7 @@
- role: dotfiles_common
when:
- "'platform_rocky' not in group_names"
- "'platform_fedora_coreos' not in group_names"
- "'platform_fedora_iot' not in group_names"
- name: Configure Void platform
hosts: platform_void
@@ -71,7 +71,7 @@
- packages_rocky
- services_systemd
- name: Configure Aegis Fedora CoreOS profile
- name: Configure Aegis Fedora IoT profile
hosts: role_aegis
become: true