Files
Ansible/playbooks/customers/hungeling_und_toechter/sophos_apply_customer.yml
T
2026-09-22 19:23:17 +02:00

93 lines
3.7 KiB
YAML

---
# PURPOSE: Apply customer Sophos configuration
# DESCRIPTION: Apply this customer profile using hostname, network_objects and vlan_interfaces from inventory.
# TARGETS: sophosxgs
# REQUIRED NETWORK KEYS: facility, guest, management, office, voip
# INPUTS (omitted values inherit inventory / role defaults):
# aim_debug [bool]: false
# AUTH: existing inventory / Vault credentials; no embedded passwords.
# CHANGES: Changes customer firewall configuration. VLAN parent remains Port1 as in the supplied playbooks. Only this customer profile is selected.
# EXAMPLE: ansible-playbook -i inventories/<customer>/hosts.yml
# playbooks/customers/hungeling_und_toechter/sophos_apply_customer.yml --limit <host> --vault-id <customer>@prompt --ask-pass
- name: Sophos | Apply customer configuration | hungeling_und_toechter
hosts: sophosxgs
gather_facts: false
any_errors_fatal: false
tasks:
- name: Apply customer firewall policy
ansible.builtin.import_role:
name: sophos_customer_hungeling_und_toechter
pre_tasks:
- name: AIM | Validate diagnostics option
ansible.builtin.assert:
that:
- (aim_debug | default(false)) is boolean or (aim_debug | default(false) | string | lower) in ['true',
'false']
fail_msg: aim_debug must be a YAML/JSON boolean.
quiet: true
- name: AIM | Reject mixed platform membership
ansible.builtin.assert:
that:
- (group_names | intersect(['linux', 'windows', 'sophosxgs', 'pfsense']) | length) <= 1
fail_msg: This host belongs to incompatible platform groups. Use globally unique subgroups.
quiet: true
- name: AIM | Execution context
ansible.builtin.debug:
msg:
host: '{{ inventory_hostname }}'
diagnostics: Enabled; secret values are never included by this task.
when: aim_debug | default(false) | bool
- name: Sophos | Require customer host configuration
ansible.builtin.assert:
that:
- hostname is defined
- hostname is string
- hostname | length > 0
- network_objects is defined
- network_objects is mapping
- vlan_interfaces is defined
- vlan_interfaces is mapping
fail_msg: Set hostname, network_objects and vlan_interfaces in this host inventory. AIM can prepare
these fields.
quiet: true
- name: Sophos | Require profile network keys
ansible.builtin.assert:
that:
- item in network_objects
fail_msg: A customer-required network_objects key is missing. See the loop item.
quiet: true
loop:
- facility
- guest
- management
- office
- voip
- name: Sophos | Validate network object shape
ansible.builtin.assert:
that:
- item.value is mapping
- item.value.name is defined
- item.value.network is defined
- item.value.subnetmask is defined
fail_msg: Every network object requires name, network and subnetmask.
quiet: true
loop: '{{ network_objects | dict2items }}'
loop_control:
label: '{{ item.key }}'
- name: Sophos | Validate VLAN shape
ansible.builtin.assert:
that:
- item.value is mapping
- item.value.name is defined
- item.value.ip_address is defined
- item.value.subnetmask is defined
- item.value.vlan_id is defined
- item.value.zone_name is defined
- item.value.zone_type is defined
- item.value.zone_description is defined
fail_msg: Each VLAN requires its full interface and zone mapping.
quiet: true
loop: '{{ vlan_interfaces | dict2items }}'
loop_control:
label: '{{ item.key }}'