refactor: restructure inventory, split roles and add new services
This commit is contained in:
@@ -35,6 +35,9 @@ chain forward {
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 ct state new flow add @ft
|
||||
iifname { eth0, eth0.2, eth0.3, eth0.4, eth0.10, eth0.11, eth0.12 } oifname eth1 accept
|
||||
|
||||
iifname "zt*" oifname "eth0" accept
|
||||
iifname "eth0" oifname "zt*" accept
|
||||
|
||||
tcp flags syn tcp option maxseg size set rt mtu
|
||||
|
||||
include "/etc/nftables.d/90-forward.nft"
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
---
|
||||
- name: install nftables
|
||||
ansible.builtin.package:
|
||||
ansible.builtin.apt:
|
||||
name: nftables
|
||||
state: present
|
||||
state: latest
|
||||
update_cache: true
|
||||
|
||||
@@ -2,5 +2,5 @@
|
||||
- name: include nftables install
|
||||
ansible.builtin.include_tasks: install.yml
|
||||
|
||||
- name: include nftables configurure
|
||||
- name: include nftables configure
|
||||
ansible.builtin.include_tasks: configure.yml
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{% for item in groups[nft_managed_group] | sort %}
|
||||
{% for item in nft_managed_group | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% if 'nft_dst' in client and client.nft_dst is not none %}
|
||||
{% set target_ip = client.container_ip %}
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
#jinja2: trim_blocks: True, lstrip_blocks: True
|
||||
{% for item in groups[nft_managed_group] | sort %}
|
||||
{% for item in nft_managed_group | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% if 'nft_to' in client and client.nft_to is not none %}
|
||||
{% set rules = client.nft_to if (client.nft_to is iterable and client.nft_to is not string) else [client.nft_to] %}
|
||||
@@ -27,7 +27,7 @@ iifname "{{ client.zone_iface }}" ip saddr {{ client.container_ip }} oifname "{{
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% for item in groups[nft_managed_group] | sort %}
|
||||
{% for item in nft_managed_group | sort %}
|
||||
{% set client = hostvars[item] %}
|
||||
{% if 'nft_from' in client and client.nft_from is not none %}
|
||||
{% set rules = client.nft_from if (client.nft_from is iterable and client.nft_from is not string) else [client.nft_from] %}
|
||||
|
||||
Reference in New Issue
Block a user