Update homelab playbook and UFW role
Change hosts target from online to managed Add tags to UFW role tasks Set default UFW policies Allow traffic on Tailscale interface
This commit is contained in:
10
homelab.yml
10
homelab.yml
@@ -1,11 +1,15 @@
|
||||
# yaml-language-server: $schema=https://raw.githubusercontent.com/ansible/ansible-lint/main/src/ansiblelint/schemas/playbook.json
|
||||
---
|
||||
- name: Homelab alignment
|
||||
hosts: online
|
||||
hosts: managed
|
||||
become: true
|
||||
|
||||
roles:
|
||||
- role: repos
|
||||
- role: common
|
||||
- role: ufw
|
||||
tags: ufw
|
||||
|
||||
- role: repos
|
||||
tags: repos
|
||||
|
||||
- role: upgrade
|
||||
tags: upgrade
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
# roles/ufw/defaults/main.yml
|
||||
---
|
||||
ufw_default_incoming_policy: deny
|
||||
ufw_default_outgoing_policy: allow
|
||||
ufw_tailscale_interface: tailscale0
|
||||
ufw_extra_rules: []
|
||||
|
||||
@@ -0,0 +1,5 @@
|
||||
- name: Allow all traffic on Tailscale interface
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
interface: "{{ ufw_tailscale_interface }}"
|
||||
direction: in
|
||||
|
||||
Reference in New Issue
Block a user