--- # PURPOSE: Apply bitformer pfSense baseline # DESCRIPTION: Apply the supplied pfSense baseline without changing its firewall/VPN policy. # TARGETS: pfsense # INPUTS (omitted values inherit inventory / role defaults): # aim_debug [bool]: false # AUTH: existing inventory / Vault credentials; no embedded passwords. # CHANGES: Contains the original any-source WAN management rule for ports 22/80/443. The original CA, VPN endpoint and client certificate reference are unchanged; verify them before execution. Requires separately approved pfsensible.core installation. # EXAMPLE: ansible-playbook -i inventories//hosts.yml # playbooks/pfsense_apply_baseline.yml --limit --vault-id @prompt - name: Install pfSense sudo package hosts: pfsense tasks: - name: Apply supplied firewall policy ansible.builtin.import_role: name: pfsense_install_prerequisites pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool - name: Initial pfSense bitformer config hosts: pfsense become: true tasks: - name: Apply supplied firewall policy ansible.builtin.import_role: name: pfsense_apply_baseline pre_tasks: - name: AIM | Validate diagnostics option ansible.builtin.assert: that: - (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true', 'false'] fail_msg: aim_debug must be a YAML/JSON boolean. quiet: true - name: AIM | Reject mixed platform membership ansible.builtin.assert: that: - (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1 fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups. quiet: true - name: AIM | Execution context ansible.builtin.debug: msg: host: '{{ inventory_hostname }}' diagnostics: Enabled; secret values are never included by this task. when: aim_debug | default(false) | bool