aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,63 @@
|
||||
---
|
||||
# PURPOSE: Apply bitformer pfSense baseline
|
||||
# DESCRIPTION: Apply the supplied pfSense baseline without changing its firewall/VPN policy.
|
||||
# TARGETS: pfsense
|
||||
# INPUTS (omitted values inherit inventory / role defaults):
|
||||
# aim_debug [bool]: false
|
||||
# AUTH: existing inventory / Vault credentials; no embedded passwords.
|
||||
# CHANGES: Contains the original any-source WAN management rule for ports 22/80/443. The original CA, VPN endpoint and client certificate reference are unchanged; verify them before execution. Requires separately approved pfsensible.core installation.
|
||||
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
|
||||
# playbooks/pfsense_apply_baseline.yml --limit <host> --vault-id <customer>@prompt
|
||||
- name: Install pfSense sudo package
|
||||
hosts: pfsense
|
||||
tasks:
|
||||
- name: Apply supplied firewall policy
|
||||
ansible.builtin.import_role:
|
||||
name: pfsense_install_prerequisites
|
||||
pre_tasks:
|
||||
- name: AIM | Validate diagnostics option
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
|
||||
'false']
|
||||
fail_msg: aim_debug must be a YAML/JSON boolean.
|
||||
quiet: true
|
||||
- name: AIM | Reject mixed platform membership
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
||||
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
||||
quiet: true
|
||||
- name: AIM | Execution context
|
||||
ansible.builtin.debug:
|
||||
msg:
|
||||
host: '{{ inventory_hostname }}'
|
||||
diagnostics: Enabled; secret values are never included by this task.
|
||||
when: aim_debug | default(false) | bool
|
||||
- name: Initial pfSense bitformer config
|
||||
hosts: pfsense
|
||||
become: true
|
||||
tasks:
|
||||
- name: Apply supplied firewall policy
|
||||
ansible.builtin.import_role:
|
||||
name: pfsense_apply_baseline
|
||||
pre_tasks:
|
||||
- name: AIM | Validate diagnostics option
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
|
||||
'false']
|
||||
fail_msg: aim_debug must be a YAML/JSON boolean.
|
||||
quiet: true
|
||||
- name: AIM | Reject mixed platform membership
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
|
||||
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
|
||||
quiet: true
|
||||
- name: AIM | Execution context
|
||||
ansible.builtin.debug:
|
||||
msg:
|
||||
host: '{{ inventory_hostname }}'
|
||||
diagnostics: Enabled; secret values are never included by this task.
|
||||
when: aim_debug | default(false) | bool
|
||||
Reference in New Issue
Block a user