prole/infrastructure/roles/samba_ad_dc/defaults/main.yml
chrisfu 9b0005aa4c fix(samba_ad_dc): bind to LAN IP only so the DC stops registering junk DNS
The AD DC's smb.conf set no `interfaces` / `bind interfaces only`, so Samba
bound to — and samba_dnsupdate registered into DNS — every interface on the
host. On myrddin that meant the Docker bridge (172.17.0.1) and k3s/flannel
CNI addresses (10.42.0.0, 10.42.0.1) were published as A records for both the
prole.org apex and `myrddin`, alongside the real 10.0.0.3. Clients then
round-robined onto unroutable addresses, producing the long-standing
"resolves, then doesn't" internal DNS flakiness.

Confine Samba to loopback + the LAN service IP:

  interfaces = lo 10.0.0.3
  bind interfaces only = yes

This scopes both service binding and DNS self-registration to the real
address, so the junk records stop being (re)created on restart.

  - smb.conf.j2: emit the two directives, gated on bind-interfaces-only being
    enabled AND a non-loopback IP being present (empty -> directives omitted,
    never binds loopback-only by accident).
  - defaults: samba_ad_dc_lan_ip ("" by default), samba_ad_dc_bind_interfaces_only
    (true), samba_ad_dc_interfaces (lo + lan_ip), all documented.
  - tasks: assert samba_ad_dc_lan_ip is non-empty before deploying smb.conf
    when bind-interfaces-only is on, so a missing value fails fast instead of
    rendering the DC unreachable.
  - group_vars/ad_dc: set samba_ad_dc_lan_ip=10.0.0.3 (myrddin's LAN address).

Deploying notifies the existing Restart samba-ad-dc handler. Pre-existing junk
records must be deleted once by hand; they will not be re-registered after the
restart. Template rendering verified for both the set and empty-IP cases.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-10 00:43:28 -07:00

60 lines
2.3 KiB
YAML

---
# roles/samba_ad_dc_defaults/defaults/main.yml
# DNS
samba_ad_dc_dns_forwarders:
- 10.0.0.5
- 10.0.0.4
# --- Interface / DNS-registration scoping ---
# A Samba AD DC runs samba_dnsupdate on startup (and periodically), which
# registers an A record for the DC hostname and the realm apex for EVERY IP it
# is bound to. On a multi-homed host (Docker bridge 172.17.0.1, k3s/flannel
# 10.42.0.0 / 10.42.0.1, etc.) those junk IPs land in the prole.org zone and
# get round-robined to clients, producing intermittent "resolves, then doesn't"
# DNS failures. Binding Samba to loopback + the LAN IP only confines both
# service binding and DNS registration to the real service address.
#
# samba_ad_dc_lan_ip MUST be the DC's stable LAN service address. It is left
# empty here and set per host (see inventory/group_vars/ad_dc/vars.yml); the
# role asserts it is non-empty before enabling bind-interfaces-only, so a
# missing value can never silently bind the DC to loopback alone (unreachable).
samba_ad_dc_lan_ip: ""
samba_ad_dc_bind_interfaces_only: true
samba_ad_dc_interfaces: "{{ ['lo'] + ([samba_ad_dc_lan_ip] if (samba_ad_dc_lan_ip | length > 0) else []) }}"
# Identity
# When samba_ad_dc_child_id is set (e.g., A000001), the realm/workgroup/netbios
# will be derived automatically as a child of samba_ad_dc_parent_realm.
samba_ad_dc_parent_realm: "PROLE.ORG"
samba_ad_dc_parent_netbios: "{{ samba_ad_dc_parent_realm.split('.')[0] | upper }}"
samba_ad_dc_child_id: ""
samba_ad_dc_realm: >-
{{ (samba_ad_dc_child_id | length > 0)
| ternary((samba_ad_dc_child_id | upper) ~ '.' ~ samba_ad_dc_parent_realm, samba_ad_dc_parent_realm) }}
samba_ad_dc_workgroup: >-
{{ (samba_ad_dc_child_id | length > 0)
| ternary((samba_ad_dc_child_id | upper), "PROLE") }}
samba_ad_dc_netbios_name: "{{ inventory_hostname_short | upper }}"
samba_ad_dc_server_string: "{{ samba_ad_dc_realm }} AD DC"
# Role/services
samba_ad_dc_server_role: "active directory domain controller"
samba_ad_dc_server_services: "-smb -winbind"
# RFC2307
samba_ad_dc_rfc2307: true
# Homes
samba_ad_dc_template_homedir: "/prole/home/%U"
samba_ad_dc_template_shell: "/bin/bash"
# Shares
samba_ad_dc_sysvol_path: "/var/lib/samba/sysvol"
samba_ad_dc_netlogon_path: "/var/lib/samba/sysvol/{{ samba_ad_dc_realm | lower }}/scripts"
# K3s/Kubeadm access group
samba_kubeadm_group: "kubeadm"
samba_kubeadm_members:
- chrisfu