add ufw role

This commit is contained in:
Sergey Malyuk
2025-12-11 10:28:32 +03:00
parent 41c7747d3b
commit 0b9ba8964f
17 changed files with 248 additions and 0 deletions

View File

@@ -0,0 +1,17 @@
---
- name: Converge
hosts: all
vars:
custom_rules:
- port: 80
- port: 9080
src: "10.2.1.0/24"
- interface: eth0@if288
direction: in
comment: "Allow all incoming traffic on eth0@if288"
roles:
- role: genlab.ufw
disable_ipv6: true
limit_ssh: true
rules: "{{ custom_rules }}"

View File

@@ -0,0 +1,27 @@
---
dependency:
name: galaxy
driver:
name: docker
platforms:
- name: ubuntu
image: geerlingguy/docker-${MOLECULE_DISTRO:-ubuntu2204}-ansible:latest
pre_build_image: true
command: ${MOLECULE_DOCKER_COMMAND:-""}
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup:rw
cgroupns_mode: host
privileged: true
provisioner:
name: ansible
verifier:
name: ansible
lint: |
set -e
yamllint .
ansible-lint .

View File

@@ -0,0 +1,28 @@
---
- name: Verify
hosts: all
gather_facts: false
any_errors_fatal: true
tasks:
- name: "Get the UFW status"
register: ufw_status
changed_when: false
ansible.builtin.command:
cmd: ufw status
- name: "Verify expected UFW status"
vars:
expected:
- "Status: active"
- ""
- "To Action From"
- "-- ------ ----"
- "22/tcp LIMIT Anywhere "
- "80 ALLOW Anywhere "
- "9080 ALLOW 10.2.1.0/24 "
- "Anywhere on eth0@if288 ALLOW Anywhere # Allow all incoming traffic on eth0@if288"
ansible.builtin.assert:
that: ufw_status.stdout_lines == expected
success_msg: "UFW has the expected state"
fail_msg: "Unexpected UFW state (some rules may have not been applied correctly)"