--- # Install VPN client(s). - name: Workstation | Software | VPN | Mullvad block: # https://mullvad.net/en/help/install-mullvad-app-linux - name: Workstation | Software | VPN | Mullvad | Add Repo [apt] shell: "{{ item }}" loop: - sudo curl -fsSLo /usr/share/keyrings/mullvad-keyring.asc https://repository.mullvad.net/deb/mullvad-keyring.asc - echo "deb [signed-by=/usr/share/keyrings/mullvad-keyring.asc arch=$( dpkg --print-architecture )] https://repository.mullvad.net/deb/stable $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/mullvad.list - apt update when: ansible_pkg_mgr == "apt" - name: Workstation | Software | VPN | Mullvad | Add Repo [dnf] shell: "{{ item }}" loop: - sudo dnf config-manager --add-repo https://repository.mullvad.net/rpm/stable/mullvad.repo when: ansible_pkg_mgr == "dnf" - name: Workstation | Software | VPN | Install package: name: - mullvad-vpn state: present - name: Workstation | Software | VPN | Install (Artix, runit) package: name: - mullvad-vpn-runit state: present when: ansible_pkg_mgr == "pacman" and ansible_service_mgr == "runit" when: ansible_distribution in ("Debian", "Ubuntu") or ansible_pkg_mgr in ("pacman", "dnf") ## Specific Distros ## - name: Workstation | Software | VPN | Mullvad | Devuan (runit) block: - name: Workstation | Software | VPN | Mullvad | Devuan | Facts 01 set_fact: devuan_mullvad_dir: "{{ global_src }}/mullvad-installer" mullvad_deb_url: https://mullvad.net/en/download/app/deb/latest mullvad_repack_url: https://github.com/sys-fs/mullvad-repack - name: Workstation | Software | VPN | Mullvad | Devuan | Facts 02 set_fact: mullvad_repack_dir: "{{ devuan_mullvad_dir }}/mullvad_repack" - name: Workstation | Software | VPN | Mullvad | Devuan | Check stat: path: '/opt/Mullvad VPN' register: mullvad_installed - name: Workstation | Software | VPN | Mullvad | Devuan | Install shell: "{{ item }}" loop: - "mkdir -pv {{ devuan_mullvad_dir }}" - "curl -L -o {{ devuan_mullvad_dir }}/Mullvad.deb {{ mullvad_deb_url }}" - "rm -rfv {{ mullvad_repack_dir }}" - "git clone {{ mullvad_repack_url }} {{ mullvad_repack_dir }}" - "cd {{ mullvad_repack_dir }} && ./repack.sh ../Mullvad.deb" - "apt-get install -y --reinstall {{ devuan_mullvad_dir }}/Mullvad_repack.deb" when: not mullvad_installed.stat.exists when: ansible_pkg_mgr == "apt" and ansible_service_mgr != "systemd" ## Link & Enable ## - name: Workstation | Software | VPN | Mullvad | PATH | Facts 01 set_fact: mullvad_exe: 'mullvad-vpn' mullvad_exe_dir: '/opt/Mullvad\ VPN' - name: Workstation | Software | VPN | Mullvad | PATH | Facts 02 set_fact: mullvad_exe_new: "{{ global_bin }}/{{ mullvad_exe }}" - name: Workstation | Software | VPN | Mullvad | PATH | Facts (pacman) set_fact: mullvad_exe_dir: '/usr/bin' when: ansible_pkg_mgr == "pacman" - name: Workstation | Software | VPN | Mullvad | PATH | Install shell: "{{ item }}" loop: - rm {{ mullvad_exe_new }} || echo "File does not exist." - echo "#!/usr/bin/env sh" > {{ mullvad_exe_new }} - echo "cd {{ mullvad_exe_dir }}" >> {{ mullvad_exe_new }} - echo "./{{ mullvad_exe }}" >> {{ mullvad_exe_new }} - chmod +x {{ mullvad_exe_new }} - name: Workstation | Software | VPN | Mullvad | runit | Enable Service (mullvad-daemon) file: src: "{{ runit_script_dir }}/mullvad-daemon" dest: "{{ runit_service_dir }}/mullvad-daemon" state: link force: true when: ansible_service_mgr == "runit" - name: Workstation | Software | VPN | Mullvad | runit | Remove Old Service (mullvad) file: path: "{{ runit_service_dir }}/mullvad" state: absent when: ansible_service_mgr == "runit" - name: Workstation | Software | VPN | Mullvad | PATH | Enable Lockdown shell: "{{ item }}" loop: - mullvad lan set block - mullvad tunnel set ipv6 on - mullvad dns set default --block-ads --block-trackers --block-malware --block-gambling --block-adult-content --block-social-media - mullvad auto-connect set on - mullvad lockdown-mode set on - mullvad beta-program set off become_user: "{{ user }}"