2022-11-18 18:33:37 +01:00
|
|
|
---
|
|
|
|
# tasks file for iptables-webserver
|
|
|
|
|
2023-01-13 18:01:41 +01:00
|
|
|
- ansible.builtin.debug:
|
|
|
|
msg: "ENABLED = {{ iptables_webserver_enabled }}; PORTS = {{ iptables_webserver_ports }}; iptables-webserver role"
|
|
|
|
|
|
|
|
- when:
|
2022-11-18 18:33:37 +01:00
|
|
|
- "is_docker is not true"
|
|
|
|
block:
|
|
|
|
- name: Allow new, established packets on TCP ports 80/443 (Webserver)
|
|
|
|
ansible.builtin.iptables:
|
|
|
|
chain: INPUT
|
|
|
|
protocol: tcp
|
2023-01-13 18:01:41 +01:00
|
|
|
state: "{{ 'present' if iptables_webserver_enabled is true else 'absent' }}"
|
2022-11-19 11:48:56 +01:00
|
|
|
destination_port: "{{ item }}"
|
2022-11-18 18:33:37 +01:00
|
|
|
ctstate: NEW,ESTABLISHED
|
|
|
|
jump: ACCEPT
|
|
|
|
comment: Webserver dedicated port
|
|
|
|
loop: "{{ iptables_webserver_ports }}"
|
|
|
|
|
|
|
|
- name: iptables-persistent
|
|
|
|
ansible.builtin.include_role:
|
|
|
|
name: iptables-persistent
|