mirror of
https://github.com/dredx/prole.git
synced 2026-09-28 09:24:30 +00:00
The AD DC's smb.conf set no `interfaces` / `bind interfaces only`, so Samba
bound to — and samba_dnsupdate registered into DNS — every interface on the
host. On myrddin that meant the Docker bridge (172.17.0.1) and k3s/flannel
CNI addresses (10.42.0.0, 10.42.0.1) were published as A records for both the
prole.org apex and `myrddin`, alongside the real 10.0.0.3. Clients then
round-robined onto unroutable addresses, producing the long-standing
"resolves, then doesn't" internal DNS flakiness.
Confine Samba to loopback + the LAN service IP:
interfaces = lo 10.0.0.3
bind interfaces only = yes
This scopes both service binding and DNS self-registration to the real
address, so the junk records stop being (re)created on restart.
- smb.conf.j2: emit the two directives, gated on bind-interfaces-only being
enabled AND a non-loopback IP being present (empty -> directives omitted,
never binds loopback-only by accident).
- defaults: samba_ad_dc_lan_ip ("" by default), samba_ad_dc_bind_interfaces_only
(true), samba_ad_dc_interfaces (lo + lan_ip), all documented.
- tasks: assert samba_ad_dc_lan_ip is non-empty before deploying smb.conf
when bind-interfaces-only is on, so a missing value fails fast instead of
rendering the DC unreachable.
- group_vars/ad_dc: set samba_ad_dc_lan_ip=10.0.0.3 (myrddin's LAN address).
Deploying notifies the existing Restart samba-ad-dc handler. Pre-existing junk
records must be deleted once by hand; they will not be re-registered after the
restart. Template rendering verified for both the set and empty-IP cases.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
60 lines
2.3 KiB
YAML
60 lines
2.3 KiB
YAML
---
|
|
# roles/samba_ad_dc_defaults/defaults/main.yml
|
|
|
|
# DNS
|
|
samba_ad_dc_dns_forwarders:
|
|
- 10.0.0.5
|
|
- 10.0.0.4
|
|
|
|
# --- Interface / DNS-registration scoping ---
|
|
# A Samba AD DC runs samba_dnsupdate on startup (and periodically), which
|
|
# registers an A record for the DC hostname and the realm apex for EVERY IP it
|
|
# is bound to. On a multi-homed host (Docker bridge 172.17.0.1, k3s/flannel
|
|
# 10.42.0.0 / 10.42.0.1, etc.) those junk IPs land in the prole.org zone and
|
|
# get round-robined to clients, producing intermittent "resolves, then doesn't"
|
|
# DNS failures. Binding Samba to loopback + the LAN IP only confines both
|
|
# service binding and DNS registration to the real service address.
|
|
#
|
|
# samba_ad_dc_lan_ip MUST be the DC's stable LAN service address. It is left
|
|
# empty here and set per host (see inventory/group_vars/ad_dc/vars.yml); the
|
|
# role asserts it is non-empty before enabling bind-interfaces-only, so a
|
|
# missing value can never silently bind the DC to loopback alone (unreachable).
|
|
samba_ad_dc_lan_ip: ""
|
|
samba_ad_dc_bind_interfaces_only: true
|
|
samba_ad_dc_interfaces: "{{ ['lo'] + ([samba_ad_dc_lan_ip] if (samba_ad_dc_lan_ip | length > 0) else []) }}"
|
|
|
|
# Identity
|
|
# When samba_ad_dc_child_id is set (e.g., A000001), the realm/workgroup/netbios
|
|
# will be derived automatically as a child of samba_ad_dc_parent_realm.
|
|
samba_ad_dc_parent_realm: "PROLE.ORG"
|
|
samba_ad_dc_parent_netbios: "{{ samba_ad_dc_parent_realm.split('.')[0] | upper }}"
|
|
samba_ad_dc_child_id: ""
|
|
samba_ad_dc_realm: >-
|
|
{{ (samba_ad_dc_child_id | length > 0)
|
|
| ternary((samba_ad_dc_child_id | upper) ~ '.' ~ samba_ad_dc_parent_realm, samba_ad_dc_parent_realm) }}
|
|
samba_ad_dc_workgroup: >-
|
|
{{ (samba_ad_dc_child_id | length > 0)
|
|
| ternary((samba_ad_dc_child_id | upper), "PROLE") }}
|
|
samba_ad_dc_netbios_name: "{{ inventory_hostname_short | upper }}"
|
|
samba_ad_dc_server_string: "{{ samba_ad_dc_realm }} AD DC"
|
|
|
|
# Role/services
|
|
samba_ad_dc_server_role: "active directory domain controller"
|
|
samba_ad_dc_server_services: "-smb -winbind"
|
|
|
|
# RFC2307
|
|
samba_ad_dc_rfc2307: true
|
|
|
|
# Homes
|
|
samba_ad_dc_template_homedir: "/prole/home/%U"
|
|
samba_ad_dc_template_shell: "/bin/bash"
|
|
|
|
# Shares
|
|
samba_ad_dc_sysvol_path: "/var/lib/samba/sysvol"
|
|
samba_ad_dc_netlogon_path: "/var/lib/samba/sysvol/{{ samba_ad_dc_realm | lower }}/scripts"
|
|
|
|
# K3s/Kubeadm access group
|
|
samba_kubeadm_group: "kubeadm"
|
|
samba_kubeadm_members:
|
|
- chrisfu
|