126 lines
7 KiB
YAML
126 lines
7 KiB
YAML
|
|
---
|
||
|
|
# Domain expiry, DNS correctness, and public endpoint reachability.
|
||
|
|
#
|
||
|
|
# These are the first checks in the estate that PULL rather than push, and that
|
||
|
|
# is the right way round for them: all three are about how the outside world
|
||
|
|
# sees us, so they must be measured from outside. Gatus polls from the
|
||
|
|
# observability host and needs nothing installed anywhere else - there is no
|
||
|
|
# script, no timer and no token, because nothing is reporting in.
|
||
|
|
#
|
||
|
|
# That also means these have no heartbeat. A heartbeat answers "did the thing
|
||
|
|
# that was supposed to report in do so"; when Gatus does the checking itself,
|
||
|
|
# failure is immediate and self-evident.
|
||
|
|
|
||
|
|
- name: Register the public-facing checks with Gatus
|
||
|
|
hosts: observability
|
||
|
|
become: yes
|
||
|
|
|
||
|
|
vars:
|
||
|
|
# Expected A records, derived from inventory rather than written down again.
|
||
|
|
# The estate's recurring bug is an address recorded in a second place and
|
||
|
|
# then left behind when the machine moved, so the check asserts against
|
||
|
|
# ansible_host - if a box is renumbered, inventory is the one edit.
|
||
|
|
dns_records:
|
||
|
|
- {sub: "{{ subdomains.gatus }}", host: monitoring}
|
||
|
|
- {sub: "{{ subdomains.ntfy }}", host: watchtower}
|
||
|
|
- {sub: "{{ subdomains.headscale }}", host: spacey}
|
||
|
|
- {sub: "{{ subdomains.vaultwarden }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.forgejo }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.lnbits }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.ntfy_emergency_app }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.personal_blog }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.memos }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.mempool }}", host: vipy}
|
||
|
|
- {sub: "{{ subdomains.datum_gateway }}", host: vipy}
|
||
|
|
|
||
|
|
# A public resolver on purpose: this must test what the internet sees, not
|
||
|
|
# what a local cache or the tailnet's MagicDNS happens to answer.
|
||
|
|
dns_resolver: "1.1.1.1"
|
||
|
|
|
||
|
|
# Expected status per site, checked live before being written down.
|
||
|
|
# 401 is the CORRECT answer for the two behind basic auth - asserting 200
|
||
|
|
# there would go green precisely when the auth broke.
|
||
|
|
public_sites:
|
||
|
|
- {name: gatus, sub: "{{ subdomains.gatus }}", path: "/", status: 401}
|
||
|
|
- {name: ntfy, sub: "{{ subdomains.ntfy }}", path: "/", status: 200}
|
||
|
|
- {name: headscale, sub: "{{ subdomains.headscale }}", path: "/health", status: 200}
|
||
|
|
- {name: vaultwarden, sub: "{{ subdomains.vaultwarden }}", path: "/", status: 200}
|
||
|
|
- {name: forgejo, sub: "{{ subdomains.forgejo }}", path: "/", status: 200}
|
||
|
|
- {name: lnbits, sub: "{{ subdomains.lnbits }}", path: "/", status: 200}
|
||
|
|
- {name: avisame, sub: "{{ subdomains.ntfy_emergency_app }}", path: "/", status: 200}
|
||
|
|
- {name: blog, sub: "{{ subdomains.personal_blog }}", path: "/", status: 200}
|
||
|
|
- {name: memos, sub: "{{ subdomains.memos }}", path: "/", status: 200}
|
||
|
|
- {name: mempool, sub: "{{ subdomains.mempool }}", path: "/", status: 200}
|
||
|
|
- {name: datum, sub: "{{ subdomains.datum_gateway }}", path: "/", status: 401}
|
||
|
|
|
||
|
|
# Ports published from the edge host by socket_proxy.
|
||
|
|
public_tcp:
|
||
|
|
- {name: bitcoin-p2p, host: vipy, port: "{{ hostvars['knots_box_local'].bitcoin_p2p_port }}"}
|
||
|
|
- {name: fulcrum-ssl, host: vipy, port: "{{ hostvars['fulcrum_box_local'].fulcrum_ssl_port }}"}
|
||
|
|
- {name: datum-stratum, host: vipy, port: "{{ hostvars['knots_box_local'].datum_gateway_stratum_port }}"}
|
||
|
|
|
||
|
|
tasks:
|
||
|
|
# ── Domain expiry ────────────────────────────────────────────────────────
|
||
|
|
- name: Build the domain endpoint
|
||
|
|
ansible.builtin.set_fact:
|
||
|
|
domain_endpoints:
|
||
|
|
- name: "{{ root_domain }}"
|
||
|
|
group: domain
|
||
|
|
# Needs a scheme: Gatus derives the endpoint TYPE from the URL prefix
|
||
|
|
# (endpoint.Type()), and a bare domain is UNKNOWN and rejected. The
|
||
|
|
# apex points at the registrar's parking page, which is irrelevant -
|
||
|
|
# the only condition here is the WHOIS expiry, and no status check is
|
||
|
|
# asserted, so what the page serves does not matter.
|
||
|
|
url: "https://{{ root_domain }}"
|
||
|
|
# 24h, and upstream enforces a 5m minimum for DOMAIN_EXPIRATION
|
||
|
|
# anyway because it uses a free whois service that must not be
|
||
|
|
# hammered and whose data updates slowly.
|
||
|
|
interval: 24h
|
||
|
|
# 336h = 14 days. Renewal is manual at the registrar, so this needs
|
||
|
|
# enough runway to act on.
|
||
|
|
conditions:
|
||
|
|
- "[DOMAIN_EXPIRATION] > 336h"
|
||
|
|
|
||
|
|
# ── DNS ──────────────────────────────────────────────────────────────────
|
||
|
|
- name: Build the DNS endpoints
|
||
|
|
ansible.builtin.set_fact:
|
||
|
|
dns_endpoints: "{{ dns_endpoints | default([]) + [{
|
||
|
|
'name': item.sub ~ '.' ~ root_domain,
|
||
|
|
'group': 'dns',
|
||
|
|
'url': dns_resolver,
|
||
|
|
'interval': '24h',
|
||
|
|
'dns': {'query-type': 'A', 'query-name': item.sub ~ '.' ~ root_domain},
|
||
|
|
'conditions': ['[DNS_RCODE] == NOERROR',
|
||
|
|
'[BODY] == ' ~ hostvars[item.host].ansible_host]}] }}"
|
||
|
|
loop: "{{ dns_records }}"
|
||
|
|
|
||
|
|
# ── Public HTTP ──────────────────────────────────────────────────────────
|
||
|
|
- name: Build the public HTTP endpoints
|
||
|
|
ansible.builtin.set_fact:
|
||
|
|
http_endpoints: "{{ http_endpoints | default([]) + [{
|
||
|
|
'name': item.name,
|
||
|
|
'group': 'public',
|
||
|
|
'url': 'https://' ~ item.sub ~ '.' ~ root_domain ~ item.path,
|
||
|
|
'interval': '5m',
|
||
|
|
'conditions': ['[STATUS] == ' ~ item.status,
|
||
|
|
'[CERTIFICATE_EXPIRATION] > 168h']}] }}"
|
||
|
|
loop: "{{ public_sites }}"
|
||
|
|
|
||
|
|
# ── Public TCP ───────────────────────────────────────────────────────────
|
||
|
|
- name: Build the public TCP endpoints
|
||
|
|
ansible.builtin.set_fact:
|
||
|
|
tcp_endpoints: "{{ tcp_endpoints | default([]) + [{
|
||
|
|
'name': item.name,
|
||
|
|
'group': 'public',
|
||
|
|
'url': 'tcp://' ~ hostvars[item.host].ansible_host ~ ':' ~ item.port,
|
||
|
|
'interval': '5m',
|
||
|
|
'conditions': ['[CONNECTED] == true']}] }}"
|
||
|
|
loop: "{{ public_tcp }}"
|
||
|
|
|
||
|
|
- name: Register the public-facing endpoints
|
||
|
|
ansible.builtin.include_role:
|
||
|
|
name: gatus_endpoint
|
||
|
|
vars:
|
||
|
|
gatus_endpoint_name: public
|
||
|
|
gatus_endpoint_pulled: "{{ domain_endpoints + dns_endpoints + http_endpoints + tcp_endpoints }}"
|