mirror of
https://github.com/dredx/prole.git
synced 2026-09-27 01:44:29 +00:00
All samba-tool dns commands were using -P (machine account Kerberos) which
silently failed with no error — tasks reported changed=0 but records were
never written. Switch to -U Administrator --password={{ samba_dns_admin_pass }}
which uses the vault-protected admin credentials that were already defined
but never wired up.
Also fix regex patterns in record parsers: samba-tool output uses `A: IP`
and `PTR: fqdn` format, not `A IP` / `PTR fqdn` (space-separated), so
updated regex_findall patterns to match `TYPE:\s+value`.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
34 lines
1.2 KiB
YAML
34 lines
1.2 KiB
YAML
---
|
|
- name: Assert Samba DNS admin password is set (vault loaded)
|
|
ansible.builtin.assert:
|
|
that:
|
|
- samba_dns_admin_pass is defined
|
|
- samba_dns_admin_pass | length > 0
|
|
fail_msg: "Missing samba_dns_admin_pass. Create inventory/group_vars/ad_dc.vault.yml with vault_samba_dns_admin_pass."
|
|
|
|
- name: List Samba DNS zones
|
|
ansible.builtin.command:
|
|
cmd: samba-tool dns zonelist {{ samba_dns_server }} -U Administrator --password={{ samba_dns_admin_pass }}
|
|
register: samba_zones
|
|
changed_when: false
|
|
tags: [samba, samba_reverse_dns]
|
|
|
|
- name: Build reverse DNS zone list
|
|
ansible.builtin.set_fact:
|
|
samba_reverse_zones: >-
|
|
{{ ([lan_reverse_zone] + (k3s_reverse_zones | default([]))) | unique }}
|
|
|
|
- name: Create reverse DNS zones if missing
|
|
ansible.builtin.command:
|
|
cmd: samba-tool dns zonecreate {{ samba_dns_server }} {{ reverse_zone }} -U Administrator --password={{ samba_dns_admin_pass }}
|
|
loop: "{{ samba_reverse_zones }}"
|
|
loop_control:
|
|
loop_var: reverse_zone
|
|
when: reverse_zone not in samba_zones.stdout
|
|
tags: [samba, samba_reverse_dns]
|
|
|
|
- name: Ensure minimum PTR records (DC + Pi-holes)
|
|
ansible.builtin.include_tasks: ensure_ptr.yml
|
|
loop: "{{ ptr_records | default([]) }}"
|
|
tags: [samba, samba_reverse_dns]
|