改由 cloud-init 声明 Ayatori 容器静态地址
terraform / validate (pull_request) Failing after 10m47s
yaml / yaml (pull_request) Failing after 10m49s
ansible / lint (pull_request) Successful in 12m6s
ansible / collection-test (pull_request) Successful in 12m35s

- Terraform 写 cloud-init.network-config,地址从 records.yml 读取,与 AD DNS 同源
- 撤销 Ansible 直接改 netplan 的做法;镜像模板只在 create/copy 渲染 seed,
  故两台空容器已用 -replace 重建
- 固定指纹已从上游 images: 下架,改从 local: 缓存创建
- sshd -t 前预建 /run/sshd:新装 24.04 只有 ssh.socket 运行,目录尚不存在

Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
2026-10-01 17:11:42 +00:00
co-authored by Claude Opus 5.5
parent 5dcfcad098
commit 094b38b4b5
6 changed files with 40 additions and 73 deletions
@@ -1,52 +0,0 @@
---
# 地址必须在 NEC IX DHCP 池(.128–.250)之外;池由路由器手工维护,没有 reservation 可声明。
# 用 incus exec 而非 SSH 执行,切换地址不会断开 Ansible 自身的连接。
- name: 读取容器的 AD DNS 地址
ansible.builtin.set_fact:
container_ipv4: >-
{{ (homelab_dns.samba.records
| selectattr('zone', 'equalto', 'ad.ddupan.top')
| selectattr('name', 'equalto', incus_container)
| first)['values'] | first }}
# cloud-init 网络模块每次启动都会重写 50-cloud-init.yaml,必须先禁用它,静态配置才能持久。
# 网关与 resolver 照搬原 DHCP 下发值(.1 网关;Blocky .127 优先、路由器 .1 兜底)。
- name: 声明静态网络
ansible.builtin.command:
argv:
- incus
- exec
- "local:{{ incus_container }}"
- --env
- "CLOUD_CFG={{ container_cloud_cfg }}"
- --env
- "NETPLAN={{ container_netplan }}"
- --
- sh
- -euc
- |
changed=0
put() {
if [ "$(cat "$1" 2>/dev/null)" != "$2" ]; then
printf '%s\n' "$2" > "$1"; chmod 600 "$1"; changed=1
fi
}
put /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg "$CLOUD_CFG"
put /etc/netplan/60-static.yaml "$NETPLAN"
if [ -e /etc/netplan/50-cloud-init.yaml ]; then
rm /etc/netplan/50-cloud-init.yaml; changed=1
fi
if [ "$changed" = 1 ]; then netplan apply; echo CHANGED; fi
vars:
container_cloud_cfg: "network: {config: disabled}"
container_netplan: |-
network:
version: 2
ethernets:
eth0:
dhcp4: false
addresses: [{{ container_ipv4 }}/24]
routes: [{to: default, via: 192.168.10.1}]
nameservers: {addresses: [192.168.10.127, 192.168.10.1]}
register: container_network
changed_when: "'CHANGED' in container_network.stdout"
@@ -55,9 +55,11 @@
register: container_sshd_write
changed_when: true
# 24.04 新装时只有 ssh.socket 运行,/run/sshd 要等 ssh.service 的 RuntimeDirectory 才创建,
# 缺它时 sshd -t 直接失败;按同样的 0755 预建(/run 为 tmpfs,不留持久状态)。
- name: 校验 SSH 配置
ansible.builtin.command:
argv: [incus, exec, "local:{{ incus_container }}", --, /usr/sbin/sshd, -t]
argv: [incus, exec, "local:{{ incus_container }}", --, sh, -c, install -d -m 0755 /run/sshd && exec /usr/sbin/sshd -t]
changed_when: false
- name: 更新运行中的 SSH 配置