--- # PURPOSE: Apply customer Sophos configuration # DESCRIPTION: Apply this customer profile using hostname, network_objects and vlan_interfaces from inventory. # TARGETS: sophosxgs # REQUIRED NETWORK KEYS: drucker, guest, office, wlan # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Changes customer firewall configuration. VLAN parent remains Port1 as in the supplied playbooks. Only this customer profile is selected. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/customers/gebhardt_stahl/sophos_apply_customer.yml --limit --vault-id @prompt --ask-pass - name: Sophos | Apply customer configuration | gebhardt_stahl hosts: sophosxgs gather_facts: false any_errors_fatal: false tasks: - name: Apply customer firewall policy ansible.builtin.import_role: name: sophos_customer_gebhardt_stahl pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool - name: Sophos | Require customer host configuration ansible.builtin.assert: that: - hostname is defined - hostname is string - hostname | length > 0 - network_objects is defined - network_objects is mapping - vlan_interfaces is defined - vlan_interfaces is mapping fail_msg: Set hostname, network_objects and vlan_interfaces in this host inventory. AIM can prepare these fields. quiet: true - name: Sophos | Require profile network keys ansible.builtin.assert: that: - item in network_objects fail_msg: A customer-required network_objects key is missing. See the loop item. quiet: true loop: - drucker - guest - office - wlan - name: Sophos | Validate network object shape ansible.builtin.assert: that: - item.value is mapping - item.value.name is defined - item.value.network is defined - item.value.subnetmask is defined fail_msg: Every network object requires name, network and subnetmask. quiet: true loop: '{{ network_objects | dict2items }}' loop_control: label: '{{ item.key }}' - name: Sophos | Validate VLAN shape ansible.builtin.assert: that: - item.value is mapping - item.value.name is defined - item.value.ip_address is defined - item.value.subnetmask is defined - item.value.vlan_id is defined - item.value.zone_name is defined - item.value.zone_type is defined - item.value.zone_description is defined fail_msg: Each VLAN requires its full interface and zone mapping. quiet: true loop: '{{ vlan_interfaces | dict2items }}' loop_control: label: '{{ item.key }}'