add ufw settings
Some checks failed
Linting / YAML Lint (push) Successful in 10s
Linting / Ansible Lint (push) Failing after 46s

This commit is contained in:
2026-01-05 21:00:32 +03:00
parent 2e56cc97d9
commit a44e3d6766
2 changed files with 59 additions and 0 deletions

58
playbook-ufw.yml Normal file
View File

@@ -0,0 +1,58 @@
---
- name: "Configure UFW firewall"
hosts: all
vars_files:
- vars/secrets.yml
tasks:
- name: "Ensure UFW is installed"
ansible.builtin.apt:
name: ufw
state: present
update_cache: true
- name: "Set default incoming policy to deny"
community.general.ufw:
direction: incoming
policy: deny
- name: "Set default outgoing policy to allow"
community.general.ufw:
direction: outgoing
policy: allow
- name: "Allow SSH on port 22"
community.general.ufw:
rule: allow
port: "22"
proto: tcp
- name: "Allow Gitea SSH on port 2222"
community.general.ufw:
rule: allow
port: "2222"
proto: tcp
- name: "Allow HTTP on port 80/tcp"
community.general.ufw:
rule: allow
port: "80"
proto: tcp
- name: "Allow HTTPS on port 443/tcp"
community.general.ufw:
rule: allow
port: "443"
proto: tcp
- name: "Allow HTTPS QUIC on port 443/udp"
community.general.ufw:
rule: allow
port: "443"
proto: udp
- name: "Enable UFW"
community.general.ufw:
state: enabled
logging: true

View File

@@ -11,3 +11,4 @@ roles:
collections: collections:
- name: 'community.docker' - name: 'community.docker'
- name: 'community.general'