Skip to content
Extraits de code Groupes Projets
Valider 6dd39b70 rédigé par Fanch's avatar Fanch
Parcourir les fichiers

add nftable support

parent 581d803e
Aucune branche associée trouvée
Aucune étiquette associée trouvée
Aucune requête de fusion associée trouvée
......@@ -2,3 +2,4 @@
warn_list:
- git-latest
- risky-file-permissions
......@@ -2,8 +2,9 @@
- name: Converge
hosts: all
vars:
iptables_ip_versions: ['ipv4']
iptables_services: ['iptables']
iptables_ip_versions: ['ipv4', 'ipv6']
iptables_services: ['nftables']
iptables_packages: ['iptables-nft', 'nftables']
iptables_open_port_in: [80, 443]
tasks:
- name: "Include iptables"
......
---
- name: Remove Packages iptables Packages
ansible.builtin.package:
name: iptables
state: absent
force: true # as it is a systemd deps
when:
- '"iptables-nft" in iptables_packages'
- name: Install Packages
ansible.builtin.package:
name: "{{ iptables_packages }}"
......
......@@ -19,3 +19,18 @@
- '"ipv6" in iptables_ip_versions'
- '"ip6tables" in iptables_services'
notify: Restart Iptables Services
- name: Get Nftables rules
command: 'nft -s list ruleset'
register: nft_output
when:
- '"nftables" in iptables_services'
changed_when: false
- name: Save Nftables State
copy:
content: "{{ nft_output.stdout }}"
dest: "/etc/nftables.conf"
backup: 'yes'
when:
- '"nftables" in iptables_services'
0% Chargement en cours ou .
You are about to add 0 people to the discussion. Proceed with caution.
Terminez d'abord l'édition de ce message.
Veuillez vous inscrire ou vous pour commenter