Files
deploy_home/ansible/roles/labelprint/templates/cupsd.conf.j2
T
Bastian de BylandClaude Opus 5 6cd4d56de1 feat(labelprint): 4x6 label print proxy on a Raspberry Pi
A Pi 3B+ (stickah.local) shares a Phomemo PM246 to the LAN as a plain CUPS
queue, so any machine can print 4x6 labels -- fulfillr-site's shipping labels
in particular -- without installing the vendor driver, which is x86-64 only.
The role builds the TSPL CUPS driver from source instead.

It is Debian, not Fedora, so it lives in its own inventory and playbook
(make deploy-labelprint / check-labelprint) and the home.debyl.io roles can
never run against it. make bootfs renders its cloud-init first-boot files onto
a freshly imaged SD card from the same templates the role uses. The Wi-Fi
credentials for the home and rescue networks are in the vault.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 23:14:45 -04:00

98 lines
3.2 KiB
Django/Jinja

# {{ ansible_managed }}
#
# CUPS on the label print proxy. The Pi does all the rendering, so macOS,
# Windows and Linux clients add the queue driverless over IPP Everywhere /
# AirPrint and never install a Phomemo driver.
#
# Reachable from the LAN and from the rescue access point only. Everything else
# is refused here and dropped again at nftables.
LogLevel warn
PageLogFormat
MaxLogSize 1m
# A label job is worth retrying: the printer is often powered off or out of
# stock when the job is submitted, and the default is to bin the job outright.
ErrorPolicy retry-job
# Only trusted, local networks reach this port -- see the Location blocks below
# and roles/labelprint/templates/nftables.conf.j2. Listening on all interfaces
# rather than a fixed address so the queue is still reachable at
# {{ labelprint_ap_addr }} when the Pi has fallen back to its rescue AP.
Listen 631
Listen /run/cups/cups.sock
# Advertise over Bonjour/mDNS so clients discover the queue by themselves.
Browsing On
BrowseLocalProtocols dnssd
# Dropping the _cups subtype is what makes macOS and iOS offer a driverless
# "AirPrint" add instead of guessing at a Generic PostScript driver.
BrowseDNSSDSubTypes _print,_universal
DefaultAuthType Basic
WebInterface Yes
<Location />
Order allow,deny
Allow from {{ labelprint_lan_cidr }}
Allow from {{ labelprint_ap_cidr }}
Allow from localhost
</Location>
<Location /admin>
AuthType Default
Require user @SYSTEM
Order allow,deny
Allow from {{ labelprint_lan_cidr }}
Allow from {{ labelprint_ap_cidr }}
</Location>
<Location /admin/conf>
AuthType Default
Require user @SYSTEM
Order allow,deny
Allow from {{ labelprint_lan_cidr }}
Allow from {{ labelprint_ap_cidr }}
</Location>
<Location /admin/log>
AuthType Default
Require user @SYSTEM
Order allow,deny
Allow from {{ labelprint_lan_cidr }}
Allow from {{ labelprint_ap_cidr }}
</Location>
<Policy default>
JobPrivateAccess default
JobPrivateValues default
SubscriptionPrivateAccess default
SubscriptionPrivateValues default
# Anyone on the LAN may print and manage their own jobs -- this is a label
# printer in a workshop, not a shared office device with quotas.
<Limit Create-Job Print-Job Print-URI Validate-Job>
Order deny,allow
</Limit>
<Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-Jobs CUPS-Authenticate-Job Close-Job CUPS-Move-Job Cancel-My-Jobs CUPS-Get-Document>
Order deny,allow
</Limit>
# Changing the printer itself needs a local admin.
<Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After Cancel-Job CUPS-Accept-Jobs CUPS-Reject-Jobs>
AuthType Default
Require user @SYSTEM
Order deny,allow
</Limit>
<Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default>
AuthType Default
Require user @SYSTEM
Order deny,allow
</Limit>
<Limit All>
Order deny,allow
</Limit>
</Policy>