Enable and run all basic roles
This commit is contained in:
parent
23166bc220
commit
71f927e732
4 changed files with 19 additions and 69 deletions
|
|
@ -13,9 +13,9 @@
|
||||||
become: true
|
become: true
|
||||||
- role: geerlingguy.docker
|
- role: geerlingguy.docker
|
||||||
become: true
|
become: true
|
||||||
# - role: hostname
|
- role: hostname
|
||||||
# - role: basic-intalls
|
- role: packages
|
||||||
# - role: user
|
- role: user
|
||||||
# - role: cloudflare-ddns
|
# - role: cloudflare-ddns
|
||||||
# - role: cloudflared
|
# - role: cloudflared
|
||||||
# - role: nginx
|
# - role: nginx
|
||||||
|
|
|
||||||
|
|
@ -1,6 +0,0 @@
|
||||||
---
|
|
||||||
- name: Restart ufw
|
|
||||||
become: true
|
|
||||||
ansible.builtin.systemd:
|
|
||||||
name: ufw.service
|
|
||||||
state: restarted
|
|
||||||
|
|
@ -1,60 +0,0 @@
|
||||||
---
|
|
||||||
- name: Install basic packages
|
|
||||||
become: true
|
|
||||||
ansible.builtin.apt:
|
|
||||||
pkg:
|
|
||||||
- git
|
|
||||||
- vim
|
|
||||||
- dnsutils
|
|
||||||
- rsyslog
|
|
||||||
# - ufw
|
|
||||||
- podman
|
|
||||||
- snapd
|
|
||||||
state: present
|
|
||||||
- name: Install Snap Core
|
|
||||||
become: true
|
|
||||||
community.general.snap:
|
|
||||||
name: core
|
|
||||||
state: present
|
|
||||||
# - name: Set default policy (incoming)
|
|
||||||
# become: true
|
|
||||||
# community.general.ufw:
|
|
||||||
# direction: incoming
|
|
||||||
# policy: deny
|
|
||||||
# notify: Restart ufw
|
|
||||||
# - name: Set default policy (outgoing)
|
|
||||||
# become: true
|
|
||||||
# community.general.ufw:
|
|
||||||
# direction: outgoing
|
|
||||||
# policy: allow
|
|
||||||
# notify: Restart ufw
|
|
||||||
# - name: Set default policy (routed)
|
|
||||||
# become: true
|
|
||||||
# community.general.ufw:
|
|
||||||
# direction: routed
|
|
||||||
# policy: allow
|
|
||||||
# notify: Restart ufw
|
|
||||||
# - name: Allow forwarding in ufw
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.lineinfile:
|
|
||||||
# path: /etc/ufw/sysctl.conf
|
|
||||||
# regexp: '^#net/ipv4/ip_forward=1$'
|
|
||||||
# line: 'net/ipv4/ip_forward=1'
|
|
||||||
# notify: Restart ufw
|
|
||||||
# - name: Allow forwarding in sysctl
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.lineinfile:
|
|
||||||
# path: /etc/sysctl.conf
|
|
||||||
# regexp: '^#net\.ipv4\.ip_forward=1$'
|
|
||||||
# line: net.ipv4.ip_forward=1
|
|
||||||
# - name: Allow all access to ssh
|
|
||||||
# become: true
|
|
||||||
# community.general.ufw:
|
|
||||||
# rule: allow
|
|
||||||
# port: ssh
|
|
||||||
# proto: tcp
|
|
||||||
# notify: Restart ufw
|
|
||||||
# - name: Enable ufw
|
|
||||||
# become: true
|
|
||||||
# community.general.ufw:
|
|
||||||
# state: enabled
|
|
||||||
16
roles/packages/tasks/main.yml
Normal file
16
roles/packages/tasks/main.yml
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
---
|
||||||
|
- name: Install basic packages
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- git
|
||||||
|
- vim
|
||||||
|
- dnsutils
|
||||||
|
- rsyslog
|
||||||
|
- snapd
|
||||||
|
state: present
|
||||||
|
- name: Install Snap Core
|
||||||
|
become: true
|
||||||
|
community.general.snap:
|
||||||
|
name: core
|
||||||
|
state: present
|
||||||
Loading…
Add table
Add a link
Reference in a new issue