use become

This commit is contained in:
Robert Kaussow 2018-07-06 23:18:11 +02:00
parent c6f2c9c54f
commit 1f36ad2c49
3 changed files with 43 additions and 37 deletions

View File

@ -1,5 +1,5 @@
---
- name: restart iptables
- name: Restart iptables
shell: sleep 2 && systemctl restart iptables
async: 1
poll: 0

View File

@ -1,30 +1,33 @@
---
- name: Set custom iptables rules
iptables_raw:
name: 'iptables_custom_rules_{{ item.name }}'
rules: '{{ item.rules }}'
state: '{{ item.state }}'
weight: '{{ item.weight|default(omit) }}'
table: '{{ item.table|default(omit) }}'
with_items: '{{ iptables_custom_rules }}'
loop_control:
label: "{{item.name}}"
tags: iptables
- name: Setup iptables
block:
- name: Set custom iptables rules
iptables_raw:
name: 'iptables_custom_rules_{{ item.name }}'
rules: '{{ item.rules }}'
state: '{{ item.state }}'
weight: '{{ item.weight|default(omit) }}'
table: '{{ item.table|default(omit) }}'
with_items: '{{ iptables_custom_rules }}'
loop_control:
label: "{{item.name}}"
tags: iptables
- name: Set default iptables head rules
iptables_raw:
name: iptables_default_head
weight: 10
keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: present
rules: '{{ iptables_default_head }}'
tags: iptables
- name: Set default iptables head rules
iptables_raw:
name: iptables_default_head
weight: 10
keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: present
rules: '{{ iptables_default_head }}'
tags: iptables
- name: Set default iptables tail rules
iptables_raw:
name: iptables_default_tail
weight: 99
keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: '{{ (iptables_default_tail != "" ) | ternary("present", "absent") }}'
rules: '{{ iptables_default_tail }}'
tags: iptables
- name: Set default iptables tail rules
iptables_raw:
name: iptables_default_tail
weight: 99
keep_unmanaged: '{{ iptables_keep_unmanaged }}'
state: '{{ (iptables_default_tail != "" ) | ternary("present", "absent") }}'
rules: '{{ iptables_default_tail }}'
tags: iptables
become: True

View File

@ -1,11 +1,14 @@
---
- name: Install package
package:
name: '{{ iptables_package }}'
state: latest
- name: Install iptables
block:
- name: Install packages
package:
name: "{{ iptables_package }}"
state: latest
- name: Enable and start service
service:
name: iptables
enabled: True
state: started
- name: Enable and start service
service:
name: iptables
enabled: True
state: started
become: True