[fix] roles with ufw incocation

This commit is contained in:
Christian Fraß 2024-06-01 17:23:42 +02:00
parent 8c7b10f852
commit 35688eddaf
5 changed files with 23 additions and 13 deletions

View file

@ -28,16 +28,18 @@
}
},
{
"name": "check whether enabling UFW would be considered a change",
"name": "ufw | check",
"check_mode": true,
"become": true,
"community.general.ufw": {
"state": "enabled"
},
"register": "ufw_enable_check"
},
{
"name": "allow port 80 in ufw",
"name": "ufw | allow port 80",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "80",
@ -45,8 +47,9 @@
}
},
{
"name": "allow port 443 in ufw",
"name": "ufw | allow port 443",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "443",

View file

@ -26,16 +26,18 @@
}
},
{
"name": "check whether enabling UFW would be considered a change",
"name": "ufw | check",
"check_mode": true,
"become": true,
"community.general.ufw": {
"state": "enabled"
},
"register": "ufw_enable_check"
},
{
"name": "allow port in ufw",
"name": "ufw | allow port",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "{{var_murmur_port | string}}",

View file

@ -29,7 +29,7 @@
}
},
{
"name": "check whether enabling UFW would be considered a change",
"name": "ufw | check",
"become": true,
"check_mode": true,
"community.general.ufw": {
@ -38,7 +38,7 @@
"register": "ufw_enable_check"
},
{
"name": "Allow port 80 in ufw",
"name": "ufw | allow port 80",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
@ -48,7 +48,7 @@
}
},
{
"name": "Allow port 443 in ufw",
"name": "ufw | allow port 443",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {

View file

@ -10,16 +10,18 @@
}
},
{
"name": "check whether enabling UFW would be considered a change",
"name": "ufw | check",
"check_mode": true,
"become": true,
"community.general.ufw": {
"state": "enabled"
},
"register": "ufw_enable_check"
},
{
"name": "allow FTP port 20 in ufw",
"name": "ufw | allow port 20",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "20",
@ -27,8 +29,9 @@
}
},
{
"name": "allow FTP port 21 in ufw",
"name": "ufw | allow port 21",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "21",

View file

@ -59,7 +59,8 @@
}
},
{
"name": "check whether enabling UFW would be considered a change",
"name": "ufw | check",
"become": true,
"check_mode": true,
"community.general.ufw": {
"state": "enabled"
@ -67,8 +68,9 @@
"register": "ufw_enable_check"
},
{
"name": "allow matrix federation port in ufw",
"name": "ufw | allow port",
"when": "not ufw_enable_check.changed",
"become": true,
"community.general.ufw": {
"rule": "allow",
"port": "8448",