A Pi 3B+ (stickah.local) shares a Phomemo PM246 to the LAN as a plain CUPS queue, so any machine can print 4x6 labels -- fulfillr-site's shipping labels in particular -- without installing the vendor driver, which is x86-64 only. The role builds the TSPL CUPS driver from source instead. It is Debian, not Fedora, so it lives in its own inventory and playbook (make deploy-labelprint / check-labelprint) and the home.debyl.io roles can never run against it. make bootfs renders its cloud-init first-boot files onto a freshly imaged SD card from the same templates the role uses. The Wi-Fi credentials for the home and rescue networks are in the vault. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
98 lines
3.2 KiB
Django/Jinja
98 lines
3.2 KiB
Django/Jinja
# {{ ansible_managed }}
|
|
#
|
|
# CUPS on the label print proxy. The Pi does all the rendering, so macOS,
|
|
# Windows and Linux clients add the queue driverless over IPP Everywhere /
|
|
# AirPrint and never install a Phomemo driver.
|
|
#
|
|
# Reachable from the LAN and from the rescue access point only. Everything else
|
|
# is refused here and dropped again at nftables.
|
|
|
|
LogLevel warn
|
|
PageLogFormat
|
|
MaxLogSize 1m
|
|
# A label job is worth retrying: the printer is often powered off or out of
|
|
# stock when the job is submitted, and the default is to bin the job outright.
|
|
ErrorPolicy retry-job
|
|
|
|
# Only trusted, local networks reach this port -- see the Location blocks below
|
|
# and roles/labelprint/templates/nftables.conf.j2. Listening on all interfaces
|
|
# rather than a fixed address so the queue is still reachable at
|
|
# {{ labelprint_ap_addr }} when the Pi has fallen back to its rescue AP.
|
|
Listen 631
|
|
Listen /run/cups/cups.sock
|
|
|
|
# Advertise over Bonjour/mDNS so clients discover the queue by themselves.
|
|
Browsing On
|
|
BrowseLocalProtocols dnssd
|
|
# Dropping the _cups subtype is what makes macOS and iOS offer a driverless
|
|
# "AirPrint" add instead of guessing at a Generic PostScript driver.
|
|
BrowseDNSSDSubTypes _print,_universal
|
|
|
|
DefaultAuthType Basic
|
|
WebInterface Yes
|
|
|
|
<Location />
|
|
Order allow,deny
|
|
Allow from {{ labelprint_lan_cidr }}
|
|
Allow from {{ labelprint_ap_cidr }}
|
|
Allow from localhost
|
|
</Location>
|
|
|
|
<Location /admin>
|
|
AuthType Default
|
|
Require user @SYSTEM
|
|
Order allow,deny
|
|
Allow from {{ labelprint_lan_cidr }}
|
|
Allow from {{ labelprint_ap_cidr }}
|
|
</Location>
|
|
|
|
<Location /admin/conf>
|
|
AuthType Default
|
|
Require user @SYSTEM
|
|
Order allow,deny
|
|
Allow from {{ labelprint_lan_cidr }}
|
|
Allow from {{ labelprint_ap_cidr }}
|
|
</Location>
|
|
|
|
<Location /admin/log>
|
|
AuthType Default
|
|
Require user @SYSTEM
|
|
Order allow,deny
|
|
Allow from {{ labelprint_lan_cidr }}
|
|
Allow from {{ labelprint_ap_cidr }}
|
|
</Location>
|
|
|
|
<Policy default>
|
|
JobPrivateAccess default
|
|
JobPrivateValues default
|
|
SubscriptionPrivateAccess default
|
|
SubscriptionPrivateValues default
|
|
|
|
# Anyone on the LAN may print and manage their own jobs -- this is a label
|
|
# printer in a workshop, not a shared office device with quotas.
|
|
<Limit Create-Job Print-Job Print-URI Validate-Job>
|
|
Order deny,allow
|
|
</Limit>
|
|
|
|
<Limit Send-Document Send-URI Hold-Job Release-Job Restart-Job Purge-Jobs Set-Job-Attributes Create-Job-Subscription Renew-Subscription Cancel-Subscription Get-Notifications Reprocess-Job Cancel-Current-Job Suspend-Current-Job Resume-Job Cancel-Jobs CUPS-Authenticate-Job Close-Job CUPS-Move-Job Cancel-My-Jobs CUPS-Get-Document>
|
|
Order deny,allow
|
|
</Limit>
|
|
|
|
# Changing the printer itself needs a local admin.
|
|
<Limit Pause-Printer Resume-Printer Enable-Printer Disable-Printer Pause-Printer-After-Current-Job Hold-New-Jobs Release-Held-New-Jobs Deactivate-Printer Activate-Printer Restart-Printer Shutdown-Printer Startup-Printer Promote-Job Schedule-Job-After Cancel-Job CUPS-Accept-Jobs CUPS-Reject-Jobs>
|
|
AuthType Default
|
|
Require user @SYSTEM
|
|
Order deny,allow
|
|
</Limit>
|
|
|
|
<Limit CUPS-Add-Modify-Printer CUPS-Delete-Printer CUPS-Add-Modify-Class CUPS-Delete-Class CUPS-Set-Default>
|
|
AuthType Default
|
|
Require user @SYSTEM
|
|
Order deny,allow
|
|
</Limit>
|
|
|
|
<Limit All>
|
|
Order deny,allow
|
|
</Limit>
|
|
</Policy>
|