BBB-via-ansible/README.md

69 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# bbb-vps-prep (Ubuntu 22.04) — nftables + hardening + Docker (BBB 3.x ready)
Ce dépôt prépare un VPS **Ubuntu 22.04** pour BigBlueButton (BBB 3.x) avec :
- SSH durci (clés seulement, root interdit, allowlist utilisateurs)
- **nftables** comme firewall (pas UFW, pas iptables en gestion humaine)
- Docker CE (repo officiel) requis par BBB 3.x
- compatibilité Docker : on **nefface jamais** le ruleset global, on applique une **table nftables dédiée** (`inet hostfilter`)
- fail2ban avec action nftables
- journald persistant + rotation
- sysctl hardening (inclut ip_forward pour Docker)
- swapfile (utile avec 12 Go RAM)
## Mise en route
1) Éditer `inventory.ini` (IP du VPS)
2) Éditer `group_vars/all.yml` (clé publique, CIDR SSH, FQDN)
3) Exécuter :
```bash
make check
make run
```
Mode dry-run :
```bash
make dry-run
```
## Ports ouverts (par défaut)
- SSH: 22/TCP (restreignable par CIDR)
- BBB: 80/TCP, 443/TCP, 1638432768/UDP
- TURN (cohab): 3478/TCP+UDP, 5349/TCP, 3276965535/UDP
## Notes
- Docker gardera ses règles nécessaires au bridge/NAT; ce dépôt ajoute une couche “policy” via nftables.
- TURN sur 443 “exclusif” nest pas compatible cohabitation 1 IP avec nginx/BBB (on utilise 5349/TLS).
## Installation BBB + TURN (suite)
1) Renseigne `letsencrypt_email` dans `group_vars/all.yml`.
2) Applique uniquement l'installation BBB :
```bash
make bbb
```
Pour un dry-run (vérification) :
```bash
make bbb-dry-run
```
> Note: BBB 3.x installe un TURN local + HAProxy pour partager le port 443 avec HTTPS. Le firewall `hostfilter` doit donc autoriser **UDP/443** en plus de TCP/443.
## Greenlight v3 (portail principal)
Installation sur le domaine racine (remplace la page daccueil BBB) :
```bash
make greenlight
```
Créer un compte admin :
```bash
sudo docker exec -it greenlight-v3 bundle exec rake admin:create
```