diff --git a/README.md b/README.md index e04c1e1..2e5fc74 100644 --- a/README.md +++ b/README.md @@ -3,38 +3,54 @@ ZeroTier ========= -This Ansible role installs the `zerotier-one` package, adds and authorizes new members to (existing) ZeroTier networks, and tells the new member to join the network. +This Ansible role adds the ZeroTier repository and installs the `zerotier-one` package using your system's package manager. Depending on the provided variables this role can also add and authorize new members to (existing) ZeroTier networks, and tell the new member to join the network. Requirements ------------ -This role has an optional access token variable to authorize the member using the ZeroTier API. The role also takes the ID of the ZeroTier network to automatically join the new member. +Technically this role has no requirements. If it's ran without any variables set it will only run the installation tasks. The following variables impact the role's behavior: -Role Variables --------------- - -### zerotier_api_url -The url where the Zerotier API lives. Must use HTTPS protocol. -Default: https://my.zerotier.com - -### zerotier_accesstoken -The access token needed to authorize with the ZeroTier API. You can generate one in your account settings at https://my.zerotier.com/. If this is left out then the newly joined member will not be automatically authorized. +[**zerotier_network_id**](#zerotier_network_id): when set hosts are told to join this network. +[**zerotier_api_accesstoken**](#zerotier_api_accesstoken): when set the role can handle member authentication and configuration using the ZeroTier API. -### zerotier_network_id -The 16 character network ID of the network the new members should join. The node will not join any network if omitted. -### zerotier_register_short_hostname -Used to register the short hostname (without the FQDN) on the network instead of the long one. -Default: `false` - -### zerotier_member_ip_assignments -A list of IP addresses to assign this member. The member will be automatically assigned an address on the network if left out. - -### zerotier_member_description -Optional desription for a member. +Role Variables +-------------- -### zerotier_api_delegate -Option to delegate tasks for Zerotier API calls. By default the API calls are made from the machine running the role. +#### zerotier_network_id +*Type*: string +*Default value*: +*Description*: The 16 character network ID of the network the new members should join. The node will not join any network if omitted. + +#### zerotier_member_register_short_hostname +*Type*: boolean +*Default value*: `false` +*Description*: Used to register the short hostname (without the FQDN) on the network instead of the long one. + +#### zerotier_member_ip_assignments +*Type*: list +*Default value*: `[]` +*Description*: A list of IP addresses to assign this member. The member will be automatically assigned an address on the network if left out. + +#### zerotier_member_description +*Type*: string +*Default value*: +*Description*: Optional desription for a member. + +#### zerotier_api_accesstoken +*Type*: string +*Default value*: +*Description*: The access token needed to authorize with the ZeroTier API. You can generate one in your account settings at https://my.zerotier.com/. If this is left out then the newly joined member will not be automatically authorized. + +#### zerotier_api_url +*Type*: string +*Default value*: `https://my.zerotier.com` +*Description*: The url where the Zerotier API lives. Must use HTTPS protocol. + +#### zerotier_api_delegate +*Type*: string +*Default value*: `localhost` +*Description*: Option to delegate tasks for Zerotier API calls. By default the API calls are made from the machine running the role. Example Playbook ---------------- diff --git a/defaults/main.yml b/defaults/main.yml index 64c3ab0..ae8b479 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -1,7 +1,8 @@ --- # defaults file for ansible-role-zerotier +zerotier_api_accesstoken: "{{ zerotier_accesstoken | default() }}" # For backwards compatibility zerotier_api_url: https://my.zerotier.com zerotier_api_delegate: localhost zerotier_apt_state: present -zerotier_register_short_hostname: false +zerotier_member_register_short_hostname: "{{ zerotier_register_short_hostname | default(false) }}" # For backwards compatibility zerotier_authorize_member: true diff --git a/tasks/authorize_node.yml b/tasks/authorize_node.yml index d114e25..62c7308 100644 --- a/tasks/authorize_node.yml +++ b/tasks/authorize_node.yml @@ -5,7 +5,7 @@ url: "{{ zerotier_api_url }}/api/network/{{ zerotier_network_id }}/member/{{ ansible_local.zerotier.node_id }}" method: POST headers: - Authorization: bearer {{ zerotier_accesstoken }} + Authorization: bearer {{ zerotier_api_accesstoken }} body: hidden: false config: @@ -21,9 +21,9 @@ url: "{{ zerotier_api_url }}/api/network/{{ zerotier_network_id }}/member/{{ ansible_local.zerotier.node_id }}" method: POST headers: - Authorization: bearer {{ zerotier_accesstoken }} + Authorization: bearer {{ zerotier_api_accesstoken }} body: - name: "{{ zerotier_register_short_hostname | ternary(inventory_hostname_short, inventory_hostname) }}" + name: "{{ zerotier_member_register_short_hostname | ternary(inventory_hostname_short, inventory_hostname) }}" description: "{{ zerotier_member_description | default() }}" config: ipAssignments: "{{ zerotier_member_ip_assignments | default([]) | list }}" diff --git a/tasks/main.yml b/tasks/main.yml index a498ec8..25f1c62 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -15,7 +15,7 @@ - import_tasks: authorize_node.yml when: - - zerotier_accesstoken is defined + - zerotier_api_accesstoken | length > 0 - ansible_local.zerotier.node_id is defined - import_tasks: join_network.yml