Selaa lähdekoodia

ufw tasks shall have the ufw tag

resolves #453
Sebastian Kriems 9 vuotta sitten
vanhempi
commit
968abba197

+ 8
- 0
roles/common/tasks/ufw.yml Näytä tiedosto

@@ -6,15 +6,19 @@
6 6
   apt: pkg=ufw state=present
7 7
   tags:
8 8
     - dependencies
9
+    - ufw
9 10
 
10 11
 - name: Deny everything
11 12
   ufw: policy=deny
13
+  tags: ufw
12 14
 
13 15
 - name: Set firewall rule for DNS
14 16
   ufw: rule=allow port=domain
17
+  tags: ufw
15 18
 
16 19
 - name: Set firewall rule for mosh
17 20
   ufw: rule=allow port=60000:61000 proto=udp
21
+  tags: ufw
18 22
 
19 23
 - name: Set firewall rules for web traffic and SSH
20 24
   ufw: rule=allow port={{ item }} proto=tcp
@@ -22,15 +26,19 @@
22 26
     - http
23 27
     - https
24 28
     - ssh
29
+  tags: ufw
25 30
 
26 31
 - name: Enable UFW
27 32
   ufw: state=enabled
33
+  tags: ufw
28 34
 
29 35
 - name: Check config of ufw
30 36
   command: cat /etc/ufw/ufw.conf
31 37
   register: ufw_config
32 38
   changed_when: False  # never report as "changed"
39
+  tags: ufw
33 40
 
34 41
 - name: Disable logging (workaround for known bug in Debian 7)
35 42
   ufw: logging=off
36 43
   when: "ansible_lsb['codename'] == 'wheezy' and 'LOGLEVEL=off' not in ufw_config.stdout"
44
+  tags: ufw

+ 1
- 0
roles/ircbouncer/tasks/znc.yml Näytä tiedosto

@@ -64,6 +64,7 @@
64 64
 
65 65
 - name: Set firewall rule for znc
66 66
   ufw: rule=allow port=6697 proto=tcp
67
+  tags: ufw
67 68
 
68 69
 - name: Ensure znc is a system service
69 70
   service: name=znc state=started enabled=true

+ 1
- 0
roles/mailserver/tasks/dovecot.yml Näytä tiedosto

@@ -93,3 +93,4 @@
93 93
   with_items:
94 94
     - imaps
95 95
     - pop3s
96
+  tags: ufw

+ 1
- 0
roles/mailserver/tasks/postfix.yml Näytä tiedosto

@@ -74,3 +74,4 @@
74 74
   with_items:
75 75
     - smtp
76 76
     - ssmtp
77
+  tags: ufw

+ 1
- 0
roles/vpn/tasks/openvpn.yml Näytä tiedosto

@@ -135,6 +135,7 @@
135 135
 
136 136
 - name: Allow OpenVPN through ufw
137 137
   ufw: rule=allow port={{ openvpn_port }} proto={{ openvpn_protocol }}
138
+  tags: ufw
138 139
 
139 140
 - name: Copy OpenVPN configuration file into place
140 141
   template: src=etc_openvpn_server.conf.j2 dest=/etc/openvpn/server.conf

+ 1
- 0
roles/xmpp/tasks/prosody.yml Näytä tiedosto

@@ -46,3 +46,4 @@
46 46
   with_items:
47 47
     - 5222  # xmpp c2s
48 48
     - 5269  # xmpp s2s
49
+  tags: ufw

Loading…
Peruuta
Tallenna