webdav: add config

This commit is contained in:
Jef Roosens 2025-04-14 14:21:00 +02:00
parent ee7ee2b19d
commit 4b5ed5c8a5
Signed by: Jef Roosens
GPG key ID: 21FD3D77D56BAF49
13 changed files with 260 additions and 39 deletions

View file

@ -0,0 +1,3 @@
---
dependencies:
- role: caddy

View file

@ -0,0 +1,9 @@
---
- name: Ensure Caddyfile is present
template:
src: 'webdav.Caddyfile.j2'
dest: '/etc/caddy/webdav.Caddyfile'
owner: root
group: root
mode: '0644'
notify: caddy-reload

View file

@ -0,0 +1,5 @@
webdav.roosens.me {
reverse_proxy {{ hostvars[groups['webdav'][0]].static_ip }}:8018 {
header_down +X-Robots-Tag "none"
}
}

View file

@ -0,0 +1,12 @@
#!/usr/bin/env bash
data_dir='/mnt/data1/webdav/data'
snapshot_dir="${data_dir}.snapshot"
# Read-only snapshot for atomic backup
btrfs subvolume snapshot -r "$data_dir" "$snapshot_dir" || exit $?
/usr/local/bin/restic backup "$snapshot_dir"
# Always remove snapshot subvolume, even if restic fails
btrfs subvolume delete "$snapshot_dir"

View file

@ -0,0 +1,15 @@
[Unit]
Description=WebDAV
After=network.target network-online.target
Requires=network-online.target
[Service]
Type=exec
User=webdav
Group=webdav
ExecStart=/usr/local/bin/webdav --config /etc/webdav/config.toml
Restart=always
[Install]
WantedBy=multi-user.target

View file

@ -0,0 +1,5 @@
---
- name: 'restart webdav'
ansible.builtin.service:
name: 'webdav'
state: 'restarted'

117
roles/webdav/tasks/main.yml Normal file
View file

@ -0,0 +1,117 @@
---
# Download latest version of binary
- name: Ensure download directory is present
ansible.builtin.file:
path: "/home/debian/webdav/{{ webdav_version }}"
state: directory
mode: '0755'
- name: Ensure compressed binary is downloaded
ansible.builtin.get_url:
url: "https://github.com/hacdias/webdav/releases/download/v{{ webdav_version }}/linux-arm64-webdav.tar.gz"
dest: "/home/debian/webdav/{{ webdav_version }}/webdav-{{ webdav_version }}.tar.gz"
register: res
- name: Ensure binary is decompressed
ansible.builtin.shell:
chdir: "/home/debian/webdav/{{ webdav_version }}"
cmd: "tar --extract --gzip --file webdav-{{ webdav_version }}.tar.gz"
when: 'res.changed'
- name: Ensure binary is copied to correct location
ansible.builtin.copy:
src: "/home/debian/webdav/{{ webdav_version }}/webdav"
remote_src: true
dest: '/usr/local/bin/webdav'
owner: 'root'
group: 'root'
mode: '0755'
when: 'res.changed'
notify: 'restart webdav'
# Set up system user and data directories
- name: Ensure system group exists
ansible.builtin.group:
name: 'webdav'
gid: 5000
system: true
state: present
- name: Ensure system user exists
ansible.builtin.user:
name: 'webdav'
group: 'webdav'
uid: 5000
system: true
create_home: false
- name: Ensure data directory is present
ansible.builtin.file:
path: '/mnt/data1/webdav'
state: directory
mode: '0755'
owner: 'webdav'
group: 'webdav'
- name: Ensure data subvolumes are present
community.general.btrfs_subvolume:
name: '/webdav/{{ item }}'
loop:
- 'data'
- name: Ensure subvolume permissions are correct
ansible.builtin.file:
path: "/mnt/data1/webdav/{{ item }}"
state: directory
mode: '0755'
owner: 'webdav'
group: 'webdav'
loop:
- 'data'
# Set up configuration, backup scripts and systemd service
- name: Ensure configuration directory is present
ansible.builtin.file:
path: '/etc/webdav'
state: directory
mode: '0755'
- name: Ensure config file is present
ansible.builtin.template:
src: 'config.toml.j2'
dest: '/etc/webdav/config.toml'
mode: '0644'
owner: 'root'
group: 'root'
notify: 'restart webdav'
- name: Ensure backup scripts are present
ansible.builtin.copy:
src: "webdav.{{ item }}.backup.sh"
dest: "/etc/backups/webdav.{{ item }}.backup.sh"
owner: 'root'
group: 'root'
mode: '0644'
loop:
- 'data'
- name: Ensure service file is present
ansible.builtin.copy:
src: 'webdav.service'
dest: '/lib/systemd/system/webdav.service'
owner: 'root'
group: 'root'
mode: '0644'
register: res
- name: systemd-reload
ansible.builtin.systemd_service:
daemon_reload: true
when: 'res.changed'
- name: Ensure webdav service is enabled
ansible.builtin.service:
name: 'webdav'
enabled: true

View file

@ -0,0 +1,31 @@
address = '0.0.0.0'
port = 8018
# Handled by reverse proxy
tls = false
prefix = '/'
debug = false
noSniff = false
behindProxy = true
directory = '/mnt/data1/webdav/data'
permissions = 'R'
rulesBehavior = 'overwrite'
[log]
format = 'console'
# Color output isn't useful when ingested via systemd
colors = false
outputs = ['stdout']
[cors]
enabled = false
[[users]]
username = '{{ webdav_user }}'
password = '{bcrypt}{{ webdav_password_bcrypt }}'
permissions = 'CRUD'
# vim: ft=toml