Remove firewall
Yes, really! Docker no like!
This commit is contained in:
parent
7c9df74daf
commit
7e074231bd
1 changed files with 0 additions and 43 deletions
|
@ -24,46 +24,3 @@
|
||||||
dest: "{{ home }}/.ssh/assh.yml"
|
dest: "{{ home }}/.ssh/assh.yml"
|
||||||
mode: 0644
|
mode: 0644
|
||||||
owner: "{{ user }}"
|
owner: "{{ user }}"
|
||||||
|
|
||||||
- name: Install Firewall
|
|
||||||
aur:
|
|
||||||
name: "{{ item }}"
|
|
||||||
become: true
|
|
||||||
become_user: aur_builder
|
|
||||||
loop:
|
|
||||||
- firewalld
|
|
||||||
|
|
||||||
- name: Enable firewalld
|
|
||||||
systemd:
|
|
||||||
name: firewalld
|
|
||||||
enabled: true
|
|
||||||
state: started
|
|
||||||
|
|
||||||
- name: Define firewall ports
|
|
||||||
set_fact:
|
|
||||||
requested_firewall_ports:
|
|
||||||
- 22/tcp # SSH
|
|
||||||
- 80/tcp # Web (crab)
|
|
||||||
|
|
||||||
- name: Get firewall ports
|
|
||||||
shell: firewall-cmd --list-ports
|
|
||||||
become: true
|
|
||||||
register: firewall_ports
|
|
||||||
changed_when: false
|
|
||||||
|
|
||||||
- name: Open firewall ports
|
|
||||||
ansible.posix.firewalld:
|
|
||||||
port: "{{ item }}"
|
|
||||||
permanent: true
|
|
||||||
immediate: true
|
|
||||||
state: enabled
|
|
||||||
loop: "{{ requested_firewall_ports }}"
|
|
||||||
|
|
||||||
- name: Close firewall ports
|
|
||||||
ansible.posix.firewalld:
|
|
||||||
port: "{{ item }}"
|
|
||||||
permanent: true
|
|
||||||
immediate: true
|
|
||||||
state: disabled
|
|
||||||
when: item and item not in requested_firewall_ports
|
|
||||||
loop: "{{ firewall_ports.stdout.split(' ') }}"
|
|
||||||
|
|
Loading…
Reference in a new issue