aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,91 @@
|
||||
---
|
||||
# PURPOSE: Apply customer Sophos configuration
|
||||
# DESCRIPTION: Apply this customer profile using hostname, network_objects and vlan_interfaces from inventory.
|
||||
# TARGETS: sophosxgs
|
||||
# REQUIRED NETWORK KEYS: drucker, guest, office, wlan
|
||||
# INPUTS (omitted values inherit inventory / role defaults):
|
||||
# aim_debug [bool]: false
|
||||
# AUTH: existing inventory / Vault credentials; no embedded passwords.
|
||||
# CHANGES: Changes customer firewall configuration. VLAN parent remains Port1 as in the supplied playbooks. Only this customer profile is selected.
|
||||
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
|
||||
# playbooks/customers/gebhardt_stahl/sophos_apply_customer.yml --limit <host> --vault-id <customer>@prompt --ask-pass
|
||||
- name: Sophos | Apply customer configuration | gebhardt_stahl
|
||||
hosts: sophosxgs
|
||||
gather_facts: false
|
||||
any_errors_fatal: false
|
||||
tasks:
|
||||
- name: Apply customer firewall policy
|
||||
ansible.builtin.import_role:
|
||||
name: sophos_customer_gebhardt_stahl
|
||||
pre_tasks:
|
||||
- name: AIM | Validate diagnostics option
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
|
||||
'false']
|
||||
fail_msg: aim_debug must be a YAML/JSON boolean.
|
||||
quiet: true
|
||||
- name: AIM | Reject mixed platform membership
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
||||
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
||||
quiet: true
|
||||
- name: AIM | Execution context
|
||||
ansible.builtin.debug:
|
||||
msg:
|
||||
host: '{{ inventory_hostname }}'
|
||||
diagnostics: Enabled; secret values are never included by this task.
|
||||
when: aim_debug | default(false) | bool
|
||||
- name: Sophos | Require customer host configuration
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- hostname is defined
|
||||
- hostname is string
|
||||
- hostname | length > 0
|
||||
- network_objects is defined
|
||||
- network_objects is mapping
|
||||
- vlan_interfaces is defined
|
||||
- vlan_interfaces is mapping
|
||||
fail_msg: Set hostname, network_objects and vlan_interfaces in this host inventory. AIM can prepare
|
||||
these fields.
|
||||
quiet: true
|
||||
- name: Sophos | Require profile network keys
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- item in network_objects
|
||||
fail_msg: A customer-required network_objects key is missing. See the loop item.
|
||||
quiet: true
|
||||
loop:
|
||||
- drucker
|
||||
- guest
|
||||
- office
|
||||
- wlan
|
||||
- name: Sophos | Validate network object shape
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- item.value is mapping
|
||||
- item.value.name is defined
|
||||
- item.value.network is defined
|
||||
- item.value.subnetmask is defined
|
||||
fail_msg: Every network object requires name, network and subnetmask.
|
||||
quiet: true
|
||||
loop: '{{ network_objects | dict2items }}'
|
||||
loop_control:
|
||||
label: '{{ item.key }}'
|
||||
- name: Sophos | Validate VLAN shape
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- item.value is mapping
|
||||
- item.value.name is defined
|
||||
- item.value.ip_address is defined
|
||||
- item.value.subnetmask is defined
|
||||
- item.value.vlan_id is defined
|
||||
- item.value.zone_name is defined
|
||||
- item.value.zone_type is defined
|
||||
- item.value.zone_description is defined
|
||||
fail_msg: Each VLAN requires its full interface and zone mapping.
|
||||
quiet: true
|
||||
loop: '{{ vlan_interfaces | dict2items }}'
|
||||
loop_control:
|
||||
label: '{{ item.key }}'
|
||||
Reference in New Issue
Block a user