Browse Source

ufw tasks shall have the ufw tag

resolves #453
Sebastian Kriems 9 years ago
parent
commit
968abba197

+ 8
- 0
roles/common/tasks/ufw.yml View File

6
   apt: pkg=ufw state=present
6
   apt: pkg=ufw state=present
7
   tags:
7
   tags:
8
     - dependencies
8
     - dependencies
9
+    - ufw
9
 
10
 
10
 - name: Deny everything
11
 - name: Deny everything
11
   ufw: policy=deny
12
   ufw: policy=deny
13
+  tags: ufw
12
 
14
 
13
 - name: Set firewall rule for DNS
15
 - name: Set firewall rule for DNS
14
   ufw: rule=allow port=domain
16
   ufw: rule=allow port=domain
17
+  tags: ufw
15
 
18
 
16
 - name: Set firewall rule for mosh
19
 - name: Set firewall rule for mosh
17
   ufw: rule=allow port=60000:61000 proto=udp
20
   ufw: rule=allow port=60000:61000 proto=udp
21
+  tags: ufw
18
 
22
 
19
 - name: Set firewall rules for web traffic and SSH
23
 - name: Set firewall rules for web traffic and SSH
20
   ufw: rule=allow port={{ item }} proto=tcp
24
   ufw: rule=allow port={{ item }} proto=tcp
22
     - http
26
     - http
23
     - https
27
     - https
24
     - ssh
28
     - ssh
29
+  tags: ufw
25
 
30
 
26
 - name: Enable UFW
31
 - name: Enable UFW
27
   ufw: state=enabled
32
   ufw: state=enabled
33
+  tags: ufw
28
 
34
 
29
 - name: Check config of ufw
35
 - name: Check config of ufw
30
   command: cat /etc/ufw/ufw.conf
36
   command: cat /etc/ufw/ufw.conf
31
   register: ufw_config
37
   register: ufw_config
32
   changed_when: False  # never report as "changed"
38
   changed_when: False  # never report as "changed"
39
+  tags: ufw
33
 
40
 
34
 - name: Disable logging (workaround for known bug in Debian 7)
41
 - name: Disable logging (workaround for known bug in Debian 7)
35
   ufw: logging=off
42
   ufw: logging=off
36
   when: "ansible_lsb['codename'] == 'wheezy' and 'LOGLEVEL=off' not in ufw_config.stdout"
43
   when: "ansible_lsb['codename'] == 'wheezy' and 'LOGLEVEL=off' not in ufw_config.stdout"
44
+  tags: ufw

+ 1
- 0
roles/ircbouncer/tasks/znc.yml View File

64
 
64
 
65
 - name: Set firewall rule for znc
65
 - name: Set firewall rule for znc
66
   ufw: rule=allow port=6697 proto=tcp
66
   ufw: rule=allow port=6697 proto=tcp
67
+  tags: ufw
67
 
68
 
68
 - name: Ensure znc is a system service
69
 - name: Ensure znc is a system service
69
   service: name=znc state=started enabled=true
70
   service: name=znc state=started enabled=true

+ 1
- 0
roles/mailserver/tasks/dovecot.yml View File

93
   with_items:
93
   with_items:
94
     - imaps
94
     - imaps
95
     - pop3s
95
     - pop3s
96
+  tags: ufw

+ 1
- 0
roles/mailserver/tasks/postfix.yml View File

74
   with_items:
74
   with_items:
75
     - smtp
75
     - smtp
76
     - ssmtp
76
     - ssmtp
77
+  tags: ufw

+ 1
- 0
roles/vpn/tasks/openvpn.yml View File

135
 
135
 
136
 - name: Allow OpenVPN through ufw
136
 - name: Allow OpenVPN through ufw
137
   ufw: rule=allow port={{ openvpn_port }} proto={{ openvpn_protocol }}
137
   ufw: rule=allow port={{ openvpn_port }} proto={{ openvpn_protocol }}
138
+  tags: ufw
138
 
139
 
139
 - name: Copy OpenVPN configuration file into place
140
 - name: Copy OpenVPN configuration file into place
140
   template: src=etc_openvpn_server.conf.j2 dest=/etc/openvpn/server.conf
141
   template: src=etc_openvpn_server.conf.j2 dest=/etc/openvpn/server.conf

+ 1
- 0
roles/xmpp/tasks/prosody.yml View File

46
   with_items:
46
   with_items:
47
     - 5222  # xmpp c2s
47
     - 5222  # xmpp c2s
48
     - 5269  # xmpp s2s
48
     - 5269  # xmpp s2s
49
+  tags: ufw

Loading…
Cancel
Save