Auto-update blog content from Obsidian: 2026-07-19 21:21:41
All checks were successful
Blog Deployment / Check-Rebuild (push) Successful in 13s
Blog Deployment / Build (push) Has been skipped
Blog Deployment / Deploy-Staging (push) Successful in 49s
Blog Deployment / Test-Staging (push) Successful in 2s
Blog Deployment / Merge (push) Successful in 14s
Blog Deployment / Deploy-Production (push) Successful in 47s
Blog Deployment / Test-Production (push) Successful in 2s
Blog Deployment / Clean (push) Has been skipped
Blog Deployment / Notify (push) Successful in 3s
All checks were successful
Blog Deployment / Check-Rebuild (push) Successful in 13s
Blog Deployment / Build (push) Has been skipped
Blog Deployment / Deploy-Staging (push) Successful in 49s
Blog Deployment / Test-Staging (push) Successful in 2s
Blog Deployment / Merge (push) Successful in 14s
Blog Deployment / Deploy-Production (push) Successful in 47s
Blog Deployment / Test-Production (push) Successful in 2s
Blog Deployment / Clean (push) Has been skipped
Blog Deployment / Notify (push) Successful in 3s
This commit is contained in:
@@ -30,7 +30,8 @@ For the Proxmox hosted node, I also use the [community.proxmox Ansible collectio
|
|||||||
|
|
||||||
The important detail is that both OPNsense nodes are not treated exactly the same. The backup node runs on TrueNAS, so the playbook updates it without taking a hypervisor snapshot. The master node runs on Proxmox, so the playbook takes a snapshot before starting the firmware operation.
|
The important detail is that both OPNsense nodes are not treated exactly the same. The backup node runs on TrueNAS, so the playbook updates it without taking a hypervisor snapshot. The master node runs on Proxmox, so the playbook takes a snapshot before starting the firmware operation.
|
||||||
|
|
||||||
## Creating an automation user in OPNsense
|
---
|
||||||
|
## Creating an API User in OPNsense
|
||||||
|
|
||||||
To let Ansible interact with OPNsense, I create a dedicated user on the master node.
|
To let Ansible interact with OPNsense, I create a dedicated user on the master node.
|
||||||
|
|
||||||
@@ -54,9 +55,9 @@ I first test the API calls with Bruno from VS Code. Once the basic calls are wor
|
|||||||
|
|
||||||
## Preparing Semaphore
|
## Preparing Semaphore
|
||||||
|
|
||||||
In Semaphore, I created a key store entry named `OPNsense automation`, containing the API key and secret.
|
In Semaphore, I create a key store entry named `OPNsense automation`, containing the API key and secret.
|
||||||
|
|
||||||
Then I created an inventory for the OPNsense nodes:
|
Then I create an inventory for the OPNsense nodes:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
@@ -70,17 +71,20 @@ all:
|
|||||||
hosts:
|
hosts:
|
||||||
cerbere-head2:
|
cerbere-head2:
|
||||||
ansible_host: 192.168.88.3
|
ansible_host: 192.168.88.3
|
||||||
|
main_role: BACKUP
|
||||||
hypervisor: TrueNAS
|
hypervisor: TrueNAS
|
||||||
opnsense_master:
|
opnsense_master:
|
||||||
hosts:
|
hosts:
|
||||||
cerbere-head1:
|
cerbere-head1:
|
||||||
ansible_host: 192.168.88.2
|
ansible_host: 192.168.88.2
|
||||||
|
main_role: MASTER
|
||||||
hypervisor: Proxmox
|
hypervisor: Proxmox
|
||||||
|
proxmox_vmid: 122
|
||||||
```
|
```
|
||||||
|
|
||||||
The playbook runs locally from Semaphore and talks to each firewall through the OPNsense API.
|
The playbook runs locally from Semaphore and talks to each firewall through the OPNsense API.
|
||||||
|
|
||||||
I also created a variable group named `OPNsense automation API` with the API credentials and a few shared variables:
|
I also create a variable group named `OPNsense automation API` with the API credentials and a few shared variables:
|
||||||
|
|
||||||
- `OPNSENSE_API_KEY`
|
- `OPNSENSE_API_KEY`
|
||||||
- `OPNSENSE_API_SECRET`
|
- `OPNSENSE_API_SECRET`
|
||||||
@@ -91,12 +95,12 @@ I also created a variable group named `OPNsense automation API` with the API cre
|
|||||||
|
|
||||||
The HTTPS port is set to `4443`, and the host is built from the inventory address and this port.
|
The HTTPS port is set to `4443`, and the host is built from the inventory address and this port.
|
||||||
|
|
||||||
Finally, I created the Semaphore task template.
|
Finally, I create the Semaphore task template.
|
||||||
|
|
||||||

|

|
||||||
The Semaphore task template used to run the OPNsense HA update playbook.
|
The Semaphore task template used to run the OPNsense HA update playbook.
|
||||||
|
|
||||||
Before going further, I validated that Ansible could query both nodes:
|
Before going further, I validate that Ansible could query both nodes:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
- name: Check node availability
|
- name: Check node availability
|
||||||
@@ -109,7 +113,7 @@ Before going further, I validated that Ansible could query both nodes:
|
|||||||
validate_certs: false
|
validate_certs: false
|
||||||
```
|
```
|
||||||
|
|
||||||
At that point, the automation could reach both nodes and authenticate against the API.
|
At that point, the automation can reach both nodes and authenticate against the API.
|
||||||
|
|
||||||
## Making CARP maintenance usable from the API
|
## Making CARP maintenance usable from the API
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user