From b572bc6df7d0fb29ca500fb1bc2ab1498b1b8632 Mon Sep 17 00:00:00 2001 From: Erin Sims Date: Mon, 26 Sep 2022 06:26:39 -0400 Subject: [PATCH] working on changes, and debugging --- playbooks/sshfs.service.j2 | 39 ++++ playbooks/sshfs.yaml | 36 +++- roles/ansible_sshfs/LICENSE | 201 ------------------ roles/ansible_sshfs/README.md | 31 --- roles/ansible_sshfs/meta/main.yml | 15 -- roles/ansible_sshfs/tasks/main.yml | 43 ---- roles/ansible_sshfs/templates/fuse.conf | 1 - roles/ansible_sshfs/templates/ssh_config | 53 ----- roles/ansible_sshfs/templates/sshfs_script.j2 | 2 - 9 files changed, 66 insertions(+), 355 deletions(-) create mode 100644 playbooks/sshfs.service.j2 delete mode 100644 roles/ansible_sshfs/LICENSE delete mode 100644 roles/ansible_sshfs/README.md delete mode 100644 roles/ansible_sshfs/meta/main.yml delete mode 100644 roles/ansible_sshfs/tasks/main.yml delete mode 100644 roles/ansible_sshfs/templates/fuse.conf delete mode 100644 roles/ansible_sshfs/templates/ssh_config delete mode 100644 roles/ansible_sshfs/templates/sshfs_script.j2 diff --git a/playbooks/sshfs.service.j2 b/playbooks/sshfs.service.j2 new file mode 100644 index 0000000..a82ac33 --- /dev/null +++ b/playbooks/sshfs.service.j2 @@ -0,0 +1,39 @@ +[Unit] +Description=Music Player Daemon +Documentation=man:mpd(1) man:mpd.conf(5) +Documentation=file:///usr/share/doc/mpd/html/user.html +After=network.target sound.target + +[Service] +Type=notify +EnvironmentFile=/etc/default/mpd +ExecStart=/usr/bin/mpd --no-daemon /etc/mpdf{{ item }}.conf + +# Enable this setting to ask systemd to watch over MPD, see +# systemd.service(5). This is disabled by default because it causes +# periodic wakeups which are unnecessary if MPD is not playing. +#WatchdogSec=120 + +# allow MPD to use real-time priority 40 +LimitRTPRIO=40 +LimitRTTIME=infinity + +# for io_uring +LimitMEMLOCK=64M + +# disallow writing to /usr, /bin, /sbin, ... +ProtectSystem=yes + +# more paranoid security settings +NoNewPrivileges=yes +ProtectKernelTunables=yes +ProtectControlGroups=yes +ProtectKernelModules=yes +# AF_NETLINK is required by libsmbclient, or it will exit() .. *sigh* +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK +RestrictNamespaces=yes + +[Install] +WantedBy=multi-user.target +Also=mpd.socket + diff --git a/playbooks/sshfs.yaml b/playbooks/sshfs.yaml index c80e0d6..8ca473d 100644 --- a/playbooks/sshfs.yaml +++ b/playbooks/sshfs.yaml @@ -1,16 +1,34 @@ --- - hosts: mpdb tasks: + vars: + share: + - 'MUSIC' + - 'MOVIES' + localpath: '/mnt/' + remotepath: '/pool/' + + hostname: home.thrace-lan.info + username: sshfs + sshfsport: 2200 + - name: sshfs ansible.builtin.user: name: ssfs - - name: SSHFS - import_role: - name: ansible_sshfs - vars: - remote_media_directory: Directory where disk is mounted on the remote machine - ssh_username: sshfs - ssh_server: home.thrace-lan.info:2200 - ssh_media_directory: /mnt/music/ - server_loc: sshfs@home.thrace-lan.info:/pool/MUSIC/ + - name: setup service sshfs + template: + src: sshfs.service.j2 + dest: "/usr/lib/systemd/system/sshfs{{ item }}.service" + mode: 0644 + owner: root + group: root + loop: "{{ share }}" + - name: "Sshfs {{ item }} service start" + systemd: + name: "Share {{ item }}" + state: started + enabled: yes + masked: no + daemon_reload: yes + loop: "{{ share }}" diff --git a/roles/ansible_sshfs/LICENSE b/roles/ansible_sshfs/LICENSE deleted file mode 100644 index 8dada3e..0000000 --- a/roles/ansible_sshfs/LICENSE +++ /dev/null @@ -1,201 +0,0 @@ - Apache License - Version 2.0, January 2004 - http://www.apache.org/licenses/ - - TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION - - 1. Definitions. - - "License" shall mean the terms and conditions for use, reproduction, - and distribution as defined by Sections 1 through 9 of this document. - - "Licensor" shall mean the copyright owner or entity authorized by - the copyright owner that is granting the License. - - "Legal Entity" shall mean the union of the acting entity and all - other entities that control, are controlled by, or are under common - control with that entity. For the purposes of this definition, - "control" means (i) the power, direct or indirect, to cause the - direction or management of such entity, whether by contract or - otherwise, or (ii) ownership of fifty percent (50%) or more of the - outstanding shares, or (iii) beneficial ownership of such entity. - - "You" (or "Your") shall mean an individual or Legal Entity - exercising permissions granted by this License. - - "Source" form shall mean the preferred form for making modifications, - including but not limited to software source code, documentation - source, and configuration files. - - "Object" form shall mean any form resulting from mechanical - transformation or translation of a Source form, including but - not limited to compiled object code, generated documentation, - and conversions to other media types. - - "Work" shall mean the work of authorship, whether in Source or - Object form, made available under the License, as indicated by a - copyright notice that is included in or attached to the work - (an example is provided in the Appendix below). - - "Derivative Works" shall mean any work, whether in Source or Object - form, that is based on (or derived from) the Work and for which the - editorial revisions, annotations, elaborations, or other modifications - represent, as a whole, an original work of authorship. For the purposes - of this License, Derivative Works shall not include works that remain - separable from, or merely link (or bind by name) to the interfaces of, - the Work and Derivative Works thereof. - - "Contribution" shall mean any work of authorship, including - the original version of the Work and any modifications or additions - to that Work or Derivative Works thereof, that is intentionally - submitted to Licensor for inclusion in the Work by the copyright owner - or by an individual or Legal Entity authorized to submit on behalf of - the copyright owner. For the purposes of this definition, "submitted" - means any form of electronic, verbal, or written communication sent - to the Licensor or its representatives, including but not limited to - communication on electronic mailing lists, source code control systems, - and issue tracking systems that are managed by, or on behalf of, the - Licensor for the purpose of discussing and improving the Work, but - excluding communication that is conspicuously marked or otherwise - designated in writing by the copyright owner as "Not a Contribution." - - "Contributor" shall mean Licensor and any individual or Legal Entity - on behalf of whom a Contribution has been received by Licensor and - subsequently incorporated within the Work. - - 2. Grant of Copyright License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - copyright license to reproduce, prepare Derivative Works of, - publicly display, publicly perform, sublicense, and distribute the - Work and such Derivative Works in Source or Object form. - - 3. Grant of Patent License. Subject to the terms and conditions of - this License, each Contributor hereby grants to You a perpetual, - worldwide, non-exclusive, no-charge, royalty-free, irrevocable - (except as stated in this section) patent license to make, have made, - use, offer to sell, sell, import, and otherwise transfer the Work, - where such license applies only to those patent claims licensable - by such Contributor that are necessarily infringed by their - Contribution(s) alone or by combination of their Contribution(s) - with the Work to which such Contribution(s) was submitted. If You - institute patent litigation against any entity (including a - cross-claim or counterclaim in a lawsuit) alleging that the Work - or a Contribution incorporated within the Work constitutes direct - or contributory patent infringement, then any patent licenses - granted to You under this License for that Work shall terminate - as of the date such litigation is filed. - - 4. Redistribution. You may reproduce and distribute copies of the - Work or Derivative Works thereof in any medium, with or without - modifications, and in Source or Object form, provided that You - meet the following conditions: - - (a) You must give any other recipients of the Work or - Derivative Works a copy of this License; and - - (b) You must cause any modified files to carry prominent notices - stating that You changed the files; and - - (c) You must retain, in the Source form of any Derivative Works - that You distribute, all copyright, patent, trademark, and - attribution notices from the Source form of the Work, - excluding those notices that do not pertain to any part of - the Derivative Works; and - - (d) If the Work includes a "NOTICE" text file as part of its - distribution, then any Derivative Works that You distribute must - include a readable copy of the attribution notices contained - within such NOTICE file, excluding those notices that do not - pertain to any part of the Derivative Works, in at least one - of the following places: within a NOTICE text file distributed - as part of the Derivative Works; within the Source form or - documentation, if provided along with the Derivative Works; or, - within a display generated by the Derivative Works, if and - wherever such third-party notices normally appear. The contents - of the NOTICE file are for informational purposes only and - do not modify the License. You may add Your own attribution - notices within Derivative Works that You distribute, alongside - or as an addendum to the NOTICE text from the Work, provided - that such additional attribution notices cannot be construed - as modifying the License. - - You may add Your own copyright statement to Your modifications and - may provide additional or different license terms and conditions - for use, reproduction, or distribution of Your modifications, or - for any such Derivative Works as a whole, provided Your use, - reproduction, and distribution of the Work otherwise complies with - the conditions stated in this License. - - 5. Submission of Contributions. Unless You explicitly state otherwise, - any Contribution intentionally submitted for inclusion in the Work - by You to the Licensor shall be under the terms and conditions of - this License, without any additional terms or conditions. - Notwithstanding the above, nothing herein shall supersede or modify - the terms of any separate license agreement you may have executed - with Licensor regarding such Contributions. - - 6. Trademarks. This License does not grant permission to use the trade - names, trademarks, service marks, or product names of the Licensor, - except as required for reasonable and customary use in describing the - origin of the Work and reproducing the content of the NOTICE file. - - 7. Disclaimer of Warranty. Unless required by applicable law or - agreed to in writing, Licensor provides the Work (and each - Contributor provides its Contributions) on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or - implied, including, without limitation, any warranties or conditions - of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A - PARTICULAR PURPOSE. You are solely responsible for determining the - appropriateness of using or redistributing the Work and assume any - risks associated with Your exercise of permissions under this License. - - 8. Limitation of Liability. In no event and under no legal theory, - whether in tort (including negligence), contract, or otherwise, - unless required by applicable law (such as deliberate and grossly - negligent acts) or agreed to in writing, shall any Contributor be - liable to You for damages, including any direct, indirect, special, - incidental, or consequential damages of any character arising as a - result of this License or out of the use or inability to use the - Work (including but not limited to damages for loss of goodwill, - work stoppage, computer failure or malfunction, or any and all - other commercial damages or losses), even if such Contributor - has been advised of the possibility of such damages. - - 9. Accepting Warranty or Additional Liability. While redistributing - the Work or Derivative Works thereof, You may choose to offer, - and charge a fee for, acceptance of support, warranty, indemnity, - or other liability obligations and/or rights consistent with this - License. However, in accepting such obligations, You may act only - on Your own behalf and on Your sole responsibility, not on behalf - of any other Contributor, and only if You agree to indemnify, - defend, and hold each Contributor harmless for any liability - incurred by, or claims asserted against, such Contributor by reason - of your accepting any such warranty or additional liability. - - END OF TERMS AND CONDITIONS - - APPENDIX: How to apply the Apache License to your work. - - To apply the Apache License to your work, attach the following - boilerplate notice, with the fields enclosed by brackets "{}" - replaced with your own identifying information. (Don't include - the brackets!) The text should be enclosed in the appropriate - comment syntax for the file format. We also recommend that a - file or class name and description of purpose be included on the - same "printed page" as the copyright notice for easier - identification within third-party archives. - - Copyright {yyyy} {name of copyright owner} - - Licensed under the Apache License, Version 2.0 (the "License"); - you may not use this file except in compliance with the License. - You may obtain a copy of the License at - - http://www.apache.org/licenses/LICENSE-2.0 - - Unless required by applicable law or agreed to in writing, software - distributed under the License is distributed on an "AS IS" BASIS, - WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - See the License for the specific language governing permissions and - limitations under the License. diff --git a/roles/ansible_sshfs/README.md b/roles/ansible_sshfs/README.md deleted file mode 100644 index 9575581..0000000 --- a/roles/ansible_sshfs/README.md +++ /dev/null @@ -1,31 +0,0 @@ -# ansible_sshfs -Ansible role for mounting SSHFS - -Role Variables --------------- - -Following variables need to be defined: - -- remote_media_directory: Directory where disk is mounted on the remote machine -- ssh_username -- ssh_server: IP of the remote machine -- ssh_media_directory: Directory where SSHFS will be mounted -- server_loc: eg. @:<"directory where disk is mounted on the remote machine"> - -Note: There are no default values for the above mentioned variables. - -Dependencies ------------- - -This package has no dependencies on modules not included with Ansible by default. - -License -------- - -Apache - -Author Information ------------------- - -Created by Amrit Singh -https://www.twitter.com/_amrit_ diff --git a/roles/ansible_sshfs/meta/main.yml b/roles/ansible_sshfs/meta/main.yml deleted file mode 100644 index 90a56b5..0000000 --- a/roles/ansible_sshfs/meta/main.yml +++ /dev/null @@ -1,15 +0,0 @@ ---- -galaxy_info: - author: Amrit Singh - description: Ansible role for mounting SSHFS - license: Apache - min_ansible_version: 1.4 - platforms: - - name: Ubuntu - versions: - - all - categories: - - web - - sshfs - - ec2 -dependencies: [] diff --git a/roles/ansible_sshfs/tasks/main.yml b/roles/ansible_sshfs/tasks/main.yml deleted file mode 100644 index cd155ee..0000000 --- a/roles/ansible_sshfs/tasks/main.yml +++ /dev/null @@ -1,43 +0,0 @@ ---- - -- name: Install SSHFS - apt: pkg=sshfs state=latest update_cache=true - become: yes - -- name: Unmount (fusermount) Media Directory - command: fusermount -u {{ remote_media_directory }} - become: yes - ignore_errors: yes - -- name: Unmount (umount) Media Directory - command: umount -l {{ remote_media_directory }} - become: yes - ignore_errors: yes - -- name: Remove Media Directory - command: rmdir {{ remote_media_directory }} - become: yes - ignore_errors: yes - -- name: Copy SSHFS Configuration - template: src={{ item.src }} dest={{ item.dest }} owner={{ item.owner }} group={{ item.group }} mode={{ item.mode }} - with_items: - - {src: fuse.conf, dest: "/etc/fuse.conf", owner: "{{ ssh_username }}", group: "{{ ssh_username }}", mode: "0777"} - - {src: ssh_config, dest: "/etc/ssh/ssh_config", owner: "{{ ssh_username }}", group: "{{ ssh_username }}", mode: "0777"} - - {src: sshfs_script.j2, dest: "/etc/sshfs_script", owner: "{{ ssh_username }}", group: "{{ ssh_username }}", mode: "0777"} - become: yes - -- name: Add User to Fuse Group - command: gpasswd -a $USER fuse - become: yes - -- name: Create Media Directory - command: mkdir {{ remote_media_directory }} - become: yes - -- name: Mount Media Directory - shell: /etc/sshfs_script - args: - executable: /bin/bash - become: yes - diff --git a/roles/ansible_sshfs/templates/fuse.conf b/roles/ansible_sshfs/templates/fuse.conf deleted file mode 100644 index a439ab8..0000000 --- a/roles/ansible_sshfs/templates/fuse.conf +++ /dev/null @@ -1 +0,0 @@ -user_allow_other diff --git a/roles/ansible_sshfs/templates/ssh_config b/roles/ansible_sshfs/templates/ssh_config deleted file mode 100644 index 0cd48a7..0000000 --- a/roles/ansible_sshfs/templates/ssh_config +++ /dev/null @@ -1,53 +0,0 @@ - -# This is the ssh client system-wide configuration file. See -# ssh_config(5) for more information. This file provides defaults for -# users, and the values can be changed in per-user configuration files -# or on the command line. - -# Configuration data is parsed as follows: -# 1. command line options -# 2. user-specific file -# 3. system-wide file -# Any configuration value is only changed the first time it is set. -# Thus, host-specific definitions should be at the beginning of the -# configuration file, and defaults at the end. - -# Site-wide defaults for some commonly used options. For a comprehensive -# list of available options, their meanings and defaults, please see the -# ssh_config(5) man page. - -Host * -# ForwardAgent no -# ForwardX11 no -# ForwardX11Trusted yes -# RhostsRSAAuthentication no -# RSAAuthentication yes -# PasswordAuthentication yes -# HostbasedAuthentication no -# GSSAPIAuthentication no -# GSSAPIDelegateCredentials no -# GSSAPIKeyExchange no -# GSSAPITrustDNS no -# BatchMode no -# CheckHostIP yes -# AddressFamily any -# ConnectTimeout 0 -# IdentityFile ~/.ssh/identity -# IdentityFile ~/.ssh/id_rsa -# IdentityFile ~/.ssh/id_dsa -# Port 22 -# Protocol 2,1 -# Cipher 3des -# Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc -# MACs hmac-md5,hmac-sha1,umac-64@openssh.com,hmac-ripemd160 -# EscapeChar ~ -# Tunnel no -# TunnelDevice any:any -# PermitLocalCommand no -# VisualHostKey no -# ProxyCommand ssh -q -W %h:%p gateway.example.com - SendEnv LANG LC_* - HashKnownHosts yes - GSSAPIAuthentication yes - GSSAPIDelegateCredentials no - StrictHostKeyChecking no diff --git a/roles/ansible_sshfs/templates/sshfs_script.j2 b/roles/ansible_sshfs/templates/sshfs_script.j2 deleted file mode 100644 index b80bccd..0000000 --- a/roles/ansible_sshfs/templates/sshfs_script.j2 +++ /dev/null @@ -1,2 +0,0 @@ -#!/bin/bash -su ubuntu -c "sudo /usr/bin/sshfs {{ ssh_username }}@{{ ssh_server }}:{{ ssh_media_directory }} {{ remote_media_directory }} -F /etc/ssh/ssh_config -o uid=1000 -o gid=105 -o allow_other -o IdentityFile=/home/ubuntu/.ssh/id_rsa -o idmap=user -o sshfs_debug -d > /tmp/x.txt 2>&1 &"