ansible/roles/firewall/tasks/main.yml

73 lines
1.5 KiB
YAML
Raw Permalink Normal View History

2023-09-11 01:58:32 +02:00
---
- name: Install required packages
apt:
name:
- python3-nftables
- python3-pydantic
2023-09-16 01:52:35 +02:00
- python3-yaml
2023-09-11 01:58:32 +02:00
- nftables
- name: Install script
copy:
src: "{{ item.src }}"
dest: "{{ item.dest }}/{{ item.src }}"
owner: root
group: root
mode: "{{ item.mode }}"
loop:
- src: firewall
dest: /usr/local/sbin
mode: u=rwx,g=rx,o=rx
- src: nft.py
dest: /usr/lib/python3/dist-packages
mode: u=rw,g=r,o=r
- name: Install systemd unit
template:
src: firewall.service.j2
dest: /etc/systemd/system/firewall.service
owner: root
group: root
mode: u=rw,g=r,o=r
- name: Create /etc/firewall
file:
path: /etc/firewall
state: directory
owner: root
group: root
mode: u=rwx,g=rx,o=rx
- name: Configure firewall
template:
src: rules.yml.j2
dest: /etc/firewall/rules.yml
owner: root
group: root
mode: u=rw,g=r,o=r
vars:
firewall__rules:
zones: "{{ firewall__zones }}"
reverse_path_filter:
interfaces: "{{ firewall__rp_filter_disabled }}"
filter:
input: "{{ firewall__input }}"
forward: "{{ firewall__forward }}"
output: "{{ firewall__output }}"
nat: "{{ firewall__nat }}"
notify:
- Reload firewall
2023-09-16 01:52:35 +02:00
- name: Mask nftables service
2023-09-11 01:58:32 +02:00
systemd:
name: nftables.service
2023-09-16 01:52:35 +02:00
masked: true
2023-09-11 01:58:32 +02:00
- name: Enable firewall service
systemd:
name: firewall.service
daemon_reload: true
state: started
enabled: true
...