diff --git a/config.cfg b/config.cfg index ae579ad2..3e43c1a4 100644 --- a/config.cfg +++ b/config.cfg @@ -88,7 +88,10 @@ dns_servers: # Store PKI in RAM disk when not retaining (MacOS/Linux only) pki_in_tmpfs: true -# Regenerate ALL user certs on update-users (not just new users) +# Regenerate ALL user credentials on update-users (not just new users) +# When false: existing WireGuard keys and IPsec certs are preserved, new users added +# When true: all credentials deleted and regenerated - ALL CLIENTS MUST RECONFIGURE +# Use true after: suspected key compromise, removing untrusted users, or security audit keys_clean_all: false ### VPN Network Configuration ### diff --git a/roles/common/tasks/main.yml b/roles/common/tasks/main.yml index 2aed7abe..02bc73e0 100644 --- a/roles/common/tasks/main.yml +++ b/roles/common/tasks/main.yml @@ -11,10 +11,12 @@ - include_tasks: ubuntu.yml when: '"Ubuntu" in OS.stdout or "Linux" in OS.stdout' + +# Include facts separately for update-users (skips apt upgrade/reboot in ubuntu.yml) +- include_tasks: facts.yml tags: - update-users - - name: Sysctl tuning sysctl: name="{{ item.item }}" value="{{ item.value }}" when: item.item is defined and item.item != none diff --git a/roles/wireguard/tasks/keys.yml b/roles/wireguard/tasks/keys.yml index 74f380e9..78dabd9c 100644 --- a/roles/wireguard/tasks/keys.yml +++ b/roles/wireguard/tasks/keys.yml @@ -1,4 +1,21 @@ --- +- name: Ensure the WireGuard pki directory does not exist + file: + dest: "{{ wireguard_pki_path }}" + state: absent + when: keys_clean_all | bool + +- name: Ensure the WireGuard pki directories exist + file: + dest: "{{ wireguard_pki_path }}/{{ item }}" + state: directory + recurse: true + mode: "0700" + with_items: + - preshared + - private + - public + - name: Generate raw private keys community.crypto.openssl_privatekey: type: X25519 diff --git a/roles/wireguard/tasks/main.yml b/roles/wireguard/tasks/main.yml index 307dc357..e982b377 100644 --- a/roles/wireguard/tasks/main.yml +++ b/roles/wireguard/tasks/main.yml @@ -1,13 +1,11 @@ --- -- name: Ensure the required directories exist +- name: Ensure the required config directories exist file: dest: "{{ item }}" state: directory recurse: true + mode: "0755" with_items: - - "{{ wireguard_pki_path }}/preshared" - - "{{ wireguard_pki_path }}/private" - - "{{ wireguard_pki_path }}/public" - "{{ wireguard_config_path }}/apple/ios" - "{{ wireguard_config_path }}/apple/macos" delegate_to: localhost diff --git a/server.yml b/server.yml index a5f89abc..d6234ad6 100644 --- a/server.yml +++ b/server.yml @@ -205,6 +205,8 @@ IP_subject_alt_name: {{ IP_subject_alt_name }} ipsec_enabled: {{ ipsec_enabled }} wireguard_enabled: {{ wireguard_enabled }} + local_service_ip: {{ local_service_ip }} + local_service_ipv6: {{ local_service_ipv6 }} {% if tests | default(false) | bool %} ca_password: '{{ CA_password }}' p12_password: '{{ p12_export_password }}' diff --git a/users.yml b/users.yml index 83588aeb..cf6ebf92 100644 --- a/users.yml +++ b/users.yml @@ -24,7 +24,7 @@ - name: Build list of installed servers set_fact: - server_list: "{{ server_list | default([]) + [ {'server': config.server, 'IP_subject_alt_name': config.IP_subject_alt_name} ] }}" + server_list: "{{ server_list | default([]) + [{'server': config.server, 'IP_subject_alt_name': config.IP_subject_alt_name}] }}" loop: "{{ _configs_list.files }}" loop_control: label: "{{ item.path }}" @@ -51,6 +51,41 @@ include_vars: file: configs/{{ algo_server }}/.config.yml + - name: Validate users list is not empty + fail: + msg: | + NO USERS DEFINED + + The 'users' list in config.cfg is empty. At least one user is required. + Add users to config.cfg before running update-users. + when: users | default([]) | length == 0 + + - name: Local deployment permission validation + block: + - name: Get config directory owner + stat: + path: configs/{{ algo_server }} + register: config_dir_stat + + - name: Fail on permission mismatch + fail: + msg: | + PERMISSION MISMATCH DETECTED + + Config directory owner: {{ config_dir_stat.stat.pw_name }} + Current user: {{ ansible_user_id }} + + Running update-users with mismatched permissions will create + files with inconsistent ownership, breaking future operations. + + TO FIX: Run this command, then retry update-users: + sudo chown -R {{ ansible_user_id }} configs/{{ algo_server }}/ + + PREVENT: Always run update-users the same way as initial deployment + (both with sudo, or both without sudo). + when: config_dir_stat.stat.pw_name != ansible_user_id + when: algo_server == 'localhost' or algo_provider | default('') == 'local' + - name: Test SSH connectivity to server wait_for: host: "{{ algo_server }}"