{"id":19331095,"url":"https://github.com/systemli/ansible-role-onion","last_synced_at":"2025-04-22T23:31:47.388Z","repository":{"id":34098528,"uuid":"160425415","full_name":"systemli/ansible-role-onion","owner":"systemli","description":"Install and configure Tor Onion Services","archived":false,"fork":false,"pushed_at":"2025-03-04T18:18:44.000Z","size":274,"stargazers_count":26,"open_issues_count":0,"forks_count":9,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-04-02T04:47:26.539Z","etag":null,"topics":["ansible-role","hidden-services","onion","onion-services","tor"],"latest_commit_sha":null,"homepage":null,"language":"Jinja","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/systemli.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-12-04T22:11:28.000Z","updated_at":"2025-03-04T18:18:47.000Z","dependencies_parsed_at":"2023-02-14T10:01:09.782Z","dependency_job_id":"b1ea4f3c-4989-44af-89b5-f35742b497ff","html_url":"https://github.com/systemli/ansible-role-onion","commit_stats":null,"previous_names":[],"tags_count":19,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/systemli%2Fansible-role-onion","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/systemli%2Fansible-role-onion/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/systemli%2Fansible-role-onion/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/systemli%2Fansible-role-onion/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/systemli","download_url":"https://codeload.github.com/systemli/ansible-role-onion/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250340292,"owners_count":21414517,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible-role","hidden-services","onion","onion-services","tor"],"created_at":"2024-11-10T02:39:01.573Z","updated_at":"2025-04-22T23:31:47.142Z","avatar_url":"https://github.com/systemli.png","language":"Jinja","funding_links":[],"categories":[],"sub_categories":[],"readme":"ansiblt-role-onion\n===========================\n\n[![Build Status](https://github.com/systemli/ansible-role-onion/workflows/Integration/badge.svg?branch=main)](https://github.com/systemli/ansible-role-onion/actions?query=workflow%3AIntegration)\n[![Ansible Galaxy](http://img.shields.io/badge/ansible--galaxy-onion-blue.svg)](https://galaxy.ansible.com/systemli/onion/)\n\nInstall and configure one or multiple Tor Onion Services (formerly known as Hidden Services).\n\nHostname and private key will be generated if not supplied as variable.\n\nHint: It may take up to one minute, until the service is announced in the tor network and reachable.\n\nBe careful: Using the default 127.0.0.1 as Onion Service IP-address could possibly leak meta data: https://help.riseup.net/en/security/network-security/tor/onionservices-best-practices#be-careful-of-localhost-bypasses\n\nOnly supports Onion Services in version 3 previously known as [Next Gen Onion Services](https://trac.torproject.org/projects/tor/wiki/doc/NextGenOnions#Howtosetupyourownprop224service) only if tor version \u003e= [0.3.2.1](https://blog.torproject.org/tor-0321-alpha-released-support-next-gen-onion-services-and-kist-scheduler)!\n\nRole Variables\n--------------\n\n```\n# defaults file for onion\nonion_active: True\nonion_ipaddr: 127.0.0.1\nonion_tor_apt_state: present\nonion_services:\n  ssh:\n    onion_hostname:\n    onion_ports:\n      - [22, 22]\n    onion_authorized_clients: []\n    onion_private_key:\n\nonions_configuration:\n  SocksPort: 9050\n  SocksPolicy: \"reject *\"\n\n# List of auth cookies for connecting to Authenticated Tor Onion Services.\n#\nonion_hid_serv_auth: []\n\nonion_monit_enabled: False\n```\n\nDownload\n--------\n\nDownload latest release with `ansible-galaxy`\n\n\tansible-galaxy install systemli.onion\n\nExample Playbook\n----------------\n\n```\n    - hosts: servers\n      roles:\n         - { role: systemli.onion }\n```\n\nExtended Variables Example\n--------------------------\n\n```\nonion_active: True\nonion_ipaddr: 192.168.3.12\n\nonion_services:\n  #\n  # nextgeneration onion (v3) only available in tor \u003e= 0.3.2.1\n  # https://trac.torproject.org/projects/tor/wiki/doc/NextGenOnions#Howtosetupyourownprop224service\n  #\n  nextgenonion:\n     onion_hostname: onionv3url.onion\n     onion_ports:\n        - [25, 25]\n        - [587,587]\n     onion_public_key_b64encoded: \"\\nPT0gZWQyNTUxOaYxLXB1YmxpYzogdHlwZTAgPT0AAABADSX6gVbfuClP6aBXz8V00oMw5Sovn0ZU\\nftKei9UWmw==\\n\"\n     onion_secret_key_b64encoded: \"\\nPT0gZWQyNTUxOaYxLXNlY3JldDogdHlwZTAgPT0AAAAYzbVMulElZeorlRoSKWG4VVVwWQN0lHac\\nhpR5jLcqb2iuHQu7K9yrdRUrSUWW42gFUvl7lCDQPV7aGWQcf9TI\\n\"\n\n  absentonion:\n     onion_state: absent\n     onion_hostname: onionv3url.onion\n     onion_ports:\n        - [25, 25]\n        - [587,587]\n     onion_public_key_b64encoded: \"\\nPT0gZWQyNTUxOaYxLXB1YmxpYzogdHlwZTAgPT0AAABADSX6gVbfuClP6aBXz8V00oMw5Sovn0ZU\\nftKei9UWmw==\\n\"\n     onion_secret_key_b64encoded: \"\\nPT0gZWQyNTUxOaYxLXNlY3JldDogdHlwZTAgPT0AAAAYzbVMulElZeorlRoSKWG4VVVwWQN0lHac\\nhpR5jLcqb2iuHQu7K9yrdRUrSUWW42gFUvl7lCDQPV7aGWQcf9TI\\n\"\n\n#\n# Example for torrc with special onion configurations\n# such as Sandboxing, custom data directory, auth cookies ...\n\nonion_services:\n  ssh:\n    onion_ports:\n      - [22, 22]\n    onion_authorized_clients:\n      - admin\n\nonions_configuration:\n  SocksPort: 9050\n  SocksPolicy: \"reject *\"\n  RunAsDaemon: 1\n  # Enabling Sandbox for the first time may prevent\n  # the tor service from restarting. Make sure your\n  # SSH connection is not over Tor when enabling it.\n  Sandbox: 1\n  FetchDirInfoEarly: 1\n  FetchDirInfoExtraEarly: 1\n  DataDirectory: /var/lib/tor\n\n# Hosts that specified `onion_authorized_clients` will generate\n# auth cookies for restricted access. Collect those values from the\n# hostname file and add them to the torrc for intended clients, e.g.\n# the Ansible controller, via the list var below.\nonion_hid_serv_auth:\n  - \"r7w3xdf3r5smxokv.onion p0xMVci7ffeQFA4IWkcBxR # client: admin\"\n```\n\nTests\n-----\n\nFor developing and testing this role we use Github Actions, ansible-lint, Molecule, and Vagrant.\n\nRun local tests with:\n\n```\nmolecule test\n```\n\nLicense\n-------\n\nGPLv3\n\nAuthor Information\n------------------\n\nhttps://www.systemli.org\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsystemli%2Fansible-role-onion","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsystemli%2Fansible-role-onion","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsystemli%2Fansible-role-onion/lists"}