- name: Install nftables
  package:
    name: nftables

- name: Copy firewall config
  template:
    src: files/nftables.conf
    dest: /etc/nftables.conf
    validate: nft -c -f %s
    mode: "644"
  notify: reload nftables

- name: Enable nftables
  service:
    name: nftables
    enabled: true
    state: started