From 917a2f074fd474562dea1dc8733aa86f0520fe53 Mon Sep 17 00:00:00 2001 From: Claudio Maradonna Date: Tue, 3 Jan 2023 16:27:41 +0100 Subject: [PATCH] add iptables-kdeconnect role --- handbook.yml | 1 + roles/iptables-kdeconnect/.travis.yml | 29 ++++++++++++ roles/iptables-kdeconnect/README.md | 34 ++++++++++++++ roles/iptables-kdeconnect/defaults/main.yml | 5 ++ roles/iptables-kdeconnect/handlers/main.yml | 2 + roles/iptables-kdeconnect/meta/main.yml | 52 +++++++++++++++++++++ roles/iptables-kdeconnect/tasks/main.yml | 24 ++++++++++ roles/iptables-kdeconnect/tests/inventory | 2 + roles/iptables-kdeconnect/tests/test.yml | 5 ++ roles/iptables-kdeconnect/vars/main.yml | 2 + 10 files changed, 156 insertions(+) create mode 100644 roles/iptables-kdeconnect/.travis.yml create mode 100644 roles/iptables-kdeconnect/README.md create mode 100644 roles/iptables-kdeconnect/defaults/main.yml create mode 100644 roles/iptables-kdeconnect/handlers/main.yml create mode 100644 roles/iptables-kdeconnect/meta/main.yml create mode 100644 roles/iptables-kdeconnect/tasks/main.yml create mode 100644 roles/iptables-kdeconnect/tests/inventory create mode 100644 roles/iptables-kdeconnect/tests/test.yml create mode 100644 roles/iptables-kdeconnect/vars/main.yml diff --git a/handbook.yml b/handbook.yml index feb2f90..53cb9f7 100644 --- a/handbook.yml +++ b/handbook.yml @@ -12,6 +12,7 @@ - { role: fail2ban-basic, tags: [fail2ban, ips, ids] } - { role: auditd, tags: [auditd] } - { role: iptables-webserver, tags: [firewall, webserver] } + - { role: iptables-kdeconnect, tags: [firewall] } # --- Sysadmin --- - { role: sysadmin-tools, tags: [sysadmin] } diff --git a/roles/iptables-kdeconnect/.travis.yml b/roles/iptables-kdeconnect/.travis.yml new file mode 100644 index 0000000..36bbf62 --- /dev/null +++ b/roles/iptables-kdeconnect/.travis.yml @@ -0,0 +1,29 @@ +--- +language: python +python: "2.7" + +# Use the new container infrastructure +sudo: false + +# Install ansible +addons: + apt: + packages: + - python-pip + +install: + # Install ansible + - pip install ansible + + # Check ansible version + - ansible --version + + # Create ansible.cfg with correct roles_path + - printf '[defaults]\nroles_path=../' >ansible.cfg + +script: + # Basic role syntax check + - ansible-playbook tests/test.yml -i tests/inventory --syntax-check + +notifications: + webhooks: https://galaxy.ansible.com/api/v1/notifications/ \ No newline at end of file diff --git a/roles/iptables-kdeconnect/README.md b/roles/iptables-kdeconnect/README.md new file mode 100644 index 0000000..5a45c9f --- /dev/null +++ b/roles/iptables-kdeconnect/README.md @@ -0,0 +1,34 @@ +iptables-kdeconnect +========= + +This role setup iptables for kdeconnect + +Requirements +------------ + +. + +Role Variables +-------------- + +- **kdeconnect_ports** (array): List of ports to enable for TCP/UDP + +Dependencies +------------ + +. + +Example Playbook +---------------- + + + +License +------- + +GPLv3 + +Author Information +------------------ + +- [Claudio Maradonna](https://social.unitoo.it/claudio) diff --git a/roles/iptables-kdeconnect/defaults/main.yml b/roles/iptables-kdeconnect/defaults/main.yml new file mode 100644 index 0000000..e0544fe --- /dev/null +++ b/roles/iptables-kdeconnect/defaults/main.yml @@ -0,0 +1,5 @@ +--- +# defaults file for iptables-kdeconnect + +kdeconnect_enabled: false +kdeconnect_ports: "1714:1764" diff --git a/roles/iptables-kdeconnect/handlers/main.yml b/roles/iptables-kdeconnect/handlers/main.yml new file mode 100644 index 0000000..5732e8a --- /dev/null +++ b/roles/iptables-kdeconnect/handlers/main.yml @@ -0,0 +1,2 @@ +--- +# handlers file for iptables-kdeconnect diff --git a/roles/iptables-kdeconnect/meta/main.yml b/roles/iptables-kdeconnect/meta/main.yml new file mode 100644 index 0000000..c572acc --- /dev/null +++ b/roles/iptables-kdeconnect/meta/main.yml @@ -0,0 +1,52 @@ +galaxy_info: + author: your name + description: your role description + company: your company (optional) + + # If the issue tracker for your role is not on github, uncomment the + # next line and provide a value + # issue_tracker_url: http://example.com/issue/tracker + + # Choose a valid license ID from https://spdx.org - some suggested licenses: + # - BSD-3-Clause (default) + # - MIT + # - GPL-2.0-or-later + # - GPL-3.0-only + # - Apache-2.0 + # - CC-BY-4.0 + license: license (GPL-2.0-or-later, MIT, etc) + + min_ansible_version: 2.1 + + # If this a Container Enabled role, provide the minimum Ansible Container version. + # min_ansible_container_version: + + # + # Provide a list of supported platforms, and for each platform a list of versions. + # If you don't wish to enumerate all versions for a particular platform, use 'all'. + # To view available platforms and versions (or releases), visit: + # https://galaxy.ansible.com/api/v1/platforms/ + # + # platforms: + # - name: Fedora + # versions: + # - all + # - 25 + # - name: SomePlatform + # versions: + # - all + # - 1.0 + # - 7 + # - 99.99 + + galaxy_tags: [] + # List tags for your role here, one per line. A tag is a keyword that describes + # and categorizes the role. Users find roles by searching for tags. Be sure to + # remove the '[]' above, if you add tags to this list. + # + # NOTE: A tag is limited to a single word comprised of alphanumeric characters. + # Maximum 20 tags per role. + +dependencies: [] + # List your role dependencies here, one per line. Be sure to remove the '[]' above, + # if you add dependencies to this list. diff --git a/roles/iptables-kdeconnect/tasks/main.yml b/roles/iptables-kdeconnect/tasks/main.yml new file mode 100644 index 0000000..cb14eb1 --- /dev/null +++ b/roles/iptables-kdeconnect/tasks/main.yml @@ -0,0 +1,24 @@ +--- +# tasks file for iptables-kdeconnect +- name: Setup iptables for kdeconnect + when: 'kdeconnect_enabled is true' + block: + - name: Allow new, established packets on TCP Kdeconnect ports + ansible.builtin.iptables: + chain: INPUT + protocol: tcp + destination_port: "{{ kdeconnect_ports }}" + ctstate: NEW,ESTABLISHED + jump: ACCEPT + + - name: Allow new, established packets on UDP Kdeconnect ports + ansible.builtin.iptables: + chain: INPUT + protocol: udp + destination_port: "{{ kdeconnect_ports }}" + ctstate: NEW,ESTABLISHED + jump: ACCEPT + + - name: iptables-persistent + ansible.builtin.include_role: + name: iptables-persistent diff --git a/roles/iptables-kdeconnect/tests/inventory b/roles/iptables-kdeconnect/tests/inventory new file mode 100644 index 0000000..878877b --- /dev/null +++ b/roles/iptables-kdeconnect/tests/inventory @@ -0,0 +1,2 @@ +localhost + diff --git a/roles/iptables-kdeconnect/tests/test.yml b/roles/iptables-kdeconnect/tests/test.yml new file mode 100644 index 0000000..8ab43d6 --- /dev/null +++ b/roles/iptables-kdeconnect/tests/test.yml @@ -0,0 +1,5 @@ +--- +- hosts: localhost + remote_user: root + roles: + - iptables-kdeconnect diff --git a/roles/iptables-kdeconnect/vars/main.yml b/roles/iptables-kdeconnect/vars/main.yml new file mode 100644 index 0000000..c226775 --- /dev/null +++ b/roles/iptables-kdeconnect/vars/main.yml @@ -0,0 +1,2 @@ +--- +# vars file for iptables-kdeconnect