UNPKG

lad

Version:

Lad is the best Node.js framework. Made by a former Express TC and Koa team member.

100 lines (99 loc) 2.45 kB
--- - hosts: web become: true become_user: root tasks: - name: set hostname hostname: name: "{{ lookup('env', 'WEB_HOST') }}" # TODO: deprecate this in Jan 1st 2021 - name: allow legacy api ufw: rule: allow port: 4000 proto: tcp roles: # https://github.com/holms/ansible-fqdn - role: fqdn fqdn: "{{ lookup('env', 'WEB_HOST') }}" - hosts: api become: true become_user: root tasks: - name: set hostname hostname: name: "{{ lookup('env', 'API_HOST') }}" roles: # https://github.com/holms/ansible-fqdn - role: fqdn fqdn: "{{ lookup('env', 'API_HOST') }}" - import_playbook: security.yml hostlist="http" - import_playbook: python.yml hostlist="http" - import_playbook: node.yml hostlist="http" - import_playbook: ssh-keys.yml hostlist="http" - hosts: web:api become: true become_user: root # this was already defined in the ufw role # https://github.com/Oefenweb/ansible-ufw/blob/master/handlers/main.yml handlers: - name: reload ufw ufw: state: reloaded tasks: # ufw - name: enable ufw ufw: state: enabled policy: deny direction: incoming - name: limit ufw ssh ufw: rule: limit port: 22 proto: tcp - name: set UFW default forward policy to ACCEPT lineinfile: dest: /etc/default/ufw line: DEFAULT_FORWARD_POLICY="ACCEPT" regexp: "^DEFAULT_FORWARD_POLICY\\=" - name: allow ssh ufw: rule: allow port: 22 proto: tcp - name: allow http ufw: rule: allow port: 80 proto: tcp - name: allow https ufw: rule: allow port: 443 proto: tcp - name: allow http forwarder ufw: rule: allow port: "{{ lookup('env', 'PROXY_PORT') }}" proto: tcp - name: allow https forwarder ufw: rule: allow port: "{{ lookup('env', 'HTTP_PORT') }}" proto: tcp - name: reload ufw ufw: state: reloaded # # modify ufw setup # https://github.com/Oefenweb/ansible-ufw/issues/21 # - name: 'update ufw before.rules until #21 is resolved' template: src: '{{ playbook_dir }}/templates/before.rules.j2' dest: /etc/ufw/before.rules owner: root group: root mode: 0644 notify: reload ufw