Mercurial > code > home > repos > infra
view dns.py @ 213:33db4d39e554
filtered dns adjustments
author | drewp@bigasterisk.com |
---|---|
date | Sat, 12 Aug 2023 14:27:14 -0700 |
parents | b63ed77141fd |
children | 075ceead3673 |
line wrap: on
line source
from pyinfra import host from pyinfra.operations import apt, files, systemd def dnsmasq_instance(net_name, house_iface, dhcp_range='10.2.0.10,10.2.0.11', listen_address='reqd', dhcp_hosts_filename='/dev/null'): files.directory(path=f'/opt/dnsmasq/{net_name}') files.template( src='templates/dnsmasq/dnsmasq.conf.j2', dest=f'/opt/dnsmasq/{net_name}/dnsmasq.conf', net=net_name, house_iface=house_iface, dhcp_range=dhcp_range, listen_address=listen_address, dhcp_enabled=net_name == '10.2' and host.name == 'pipe', dns_server=listen_address, router=listen_address, ) files.template(src='templates/dnsmasq/hosts.j2', dest=f'/opt/dnsmasq/{net_name}/hosts', net=net_name) files.template(src=dhcp_hosts_filename, dest=f'/opt/dnsmasq/{net_name}/dhcp_hosts', net=net_name) files.template(src='templates/dnsmasq/dnsmasq.service.j2', dest=f'/etc/systemd/system/dnsmasq_{net_name}.service', net=net_name) if net_name in ['10.2', '10.2-filtered']: systemd.service(service=f'dnsmasq_{net_name}', enabled=True, restarted=True, daemon_reload=True) def standard_host_dns(): files.template(src='templates/hosts.j2', dest='/etc/hosts') files.link(path='/etc/resolv.conf', target='/run/systemd/resolve/resolv.conf', force=True) files.template(src='templates/resolved.conf.j2', dest='/etc/systemd/resolved.conf') systemd.service(service='systemd-resolved.service', running=True, restarted=True) standard_host_dns() if host.name == 'bang': systemd.service(service='dnsmasq', enabled=False, running=False) files.directory(path='/opt/dnsmasq') dnsmasq_instance('10.5', house_iface='unused', dhcp_range='unused', listen_address='unused') # only works after wireguard is up elif host.name == 'ditto': systemd.service(service='dnsmasq', enabled=False, running=False) elif host.name == 'pipe': systemd.service(service='dnsmasq', enabled=False, running=False) files.directory(path='/opt/dnsmasq') dnsmasq_instance('10.2', house_iface='eth1', dhcp_range='10.2.0.101,10.2.0.240', listen_address='10.2.0.3', dhcp_hosts_filename='templates/dnsmasq/dhcp_hosts.j2') out = '/opt/dnsmasq/10.2' # This mtail is for dhcp command counts and errors. Another monitor in lanscape/ reads the leases file. files.template(src='templates/dnsmasq/metrics.mtail.j2', dest=f'{out}/metrics.mtail') files.template(src='templates/dnsmasq/run_mtail.sh', dest=f'{out}/run_mtail.sh') files.template(src='templates/dnsmasq/dnsmasq-mtail.service.j2', dest=f'/etc/systemd/system/dnsmasq-mtail.service') systemd.service(service=f'dnsmasq-mtail', enabled=True, restarted=True, daemon_reload=True) # Serve another dns, no dhcp, and include the dynamic-blocking file written by net_routes. dnsmasq_instance( net_name='10.2-filtered', house_iface='eth1', listen_address='10.2.0.4', )