Davo 3 years ago
parent b79b71763f
commit f1dc1e8e2b
  1. 4
      handlers/main.yml
  2. 37
      tasks/main.yml

@ -2,3 +2,7 @@
- name: daemon reload - name: daemon reload
ansible.builtin.systemd: ansible.builtin.systemd:
daemon_reload: yes daemon_reload: yes
- name: firewalld reload
ansible.builtin.systemd:
state: restarted
name: firewalld

@ -1,11 +1,4 @@
- name: sw-node-exporter | PRE - 1. Install req packages - name: sw-node-exporter | PRE - 1. Stop, disable and mask ufw service
ansible.builtin.apt:
name:
- firewalld
state: present
update_cache: yes
- name: sw-node-exporter | PRE - 2. Stop, disable and mask ufw service
ansible.builtin.systemd: ansible.builtin.systemd:
state: stopped state: stopped
name: ufw name: ufw
@ -13,6 +6,13 @@
masked: yes masked: yes
daemon_reload: yes daemon_reload: yes
- name: sw-node-exporter | PRE - 2. Install firewalld
ansible.builtin.apt:
name:
- firewalld
state: present
update_cache: yes
- name: sw-node-exporter | PRE - 3. Start and enable firewalld service - name: sw-node-exporter | PRE - 3. Start and enable firewalld service
ansible.builtin.systemd: ansible.builtin.systemd:
state: started state: started
@ -20,16 +20,25 @@
enabled: yes enabled: yes
daemon_reload: yes daemon_reload: yes
- name: sw-node-exporter | PRE - 4. Allow traffic in default zone on port 9100/tcp - name: sw-node-exporter | PRE - 4. Allow ports in firewalld
ansible.posix.firewalld: ansible.posix.firewalld:
port: 9100/tcp port: "{{ item }}"
permanent: yes permanent: yes
state: enabled state: enabled
notify: firewalld reload
loop:
- 9100/tcp
- 22/tcp
- name: sw-node-exporter | PRE - 5. Reload firewalld service # Muze byt pridano vice portu pomoci variablu, tedy alespon myslim, ale abych si nic nero*esral, tak je to takto.
ansible.builtin.systemd: #- name: sw-node-exporter | PRE - 4. Allow ports in firewalld
state: restarted # ansible.posix.firewalld:
name: firewalld # port: "{{ item }}"
# permanent: yes
# state: enabled
# notify: reload firewalld
# with_items: "{{ additional_ports }}"
# when: additional_ports is defined
- name: sw-node-exporter | 1. Download and Unarchive node-exporter in /usr/local/bin - name: sw-node-exporter | 1. Download and Unarchive node-exporter in /usr/local/bin
ansible.builtin.unarchive: ansible.builtin.unarchive:

Loading…
Cancel
Save