diff --git a/defaults/main.yml b/defaults/main.yml index cbcb8c5..04d7ae2 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -39,14 +39,6 @@ nginx_gzip_types: - text/css - application/xml -nginx_iptables_enabled: False -nginx_iptables_rules_default: - - name: allow_nginx_ports - rules: | - -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT - state: present -nginx_iptables_rules_extra: [] - nginx_tls_enabled: False nginx_tls_versions: - TLSv1.2 diff --git a/tasks/install.yml b/tasks/install.yml index 8716f7c..c979a1b 100644 --- a/tasks/install.yml +++ b/tasks/install.yml @@ -76,18 +76,6 @@ validate: /bin/bash -c 'nginx -t -c /dev/stdin <<< "events {worker_connections 10;} http { include %s; }"' notify: __nginx_reload - - name: Open ports in iptables - iptables_raw: - name: "{{ item.name }}" - rules: "{{ item.rules }}" - state: "{{ item.state | default('present') }}" - weight: "{{ item.weight | default(omit) }}" - table: "{{ item.table | default(omit) }}" - loop: "{{ nginx_iptables_rules_default + nginx_iptables_rules_extra }}" - loop_control: - label: "{{ item.name }}" - when: nginx_iptables_enabled | bool - - name: Set selinux booleans seboolean: name: "{{ item.name }}"