feat: add routed UFW rules for pod traffic and open NFS/SMB on nik-debian
Some checks failed
validate / lint (push) Failing after 1s

Adds explicit UFW routed-allow rules (10.42.0.0/16 pod-to-pod, pod-to-Technitium
DNS) since these nodes default their routed/FORWARD policy to DROP. Also brings
nik-debian's NFS (2049) and SMB (445) ports under Ansible-managed UFW rules via
the existing nfs-server role, scoped to the Lab/Trusted networks that need them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Nik Afiq 2026-08-23 15:00:45 +09:00
parent 53d02b7522
commit 939a7c6ed1
4 changed files with 53 additions and 6 deletions

View File

@ -1,10 +1,13 @@
---
# Vars for: K3s cluster-wide DNS resolver
# Applied by: ansible/roles/k3s-server, ansible/roles/k3s-agent
# Vars for: K3s cluster-wide DNS resolver and pod network
# Applied by: ansible/roles/k3s-server, ansible/roles/k3s-agent, ansible/roles/common
# Description: Single source of truth for the resolver IP written into
# /etc/rancher/k3s/resolv.conf on every K3s node, so CoreDNS's
# "forward . /etc/resolv.conf" always reaches Technitium regardless of
# which node CoreDNS is scheduled on, or that node's own (possibly stale)
# host resolvers.
# host resolvers. k3s_pod_cidr backs the routed UFW rules in the common
# role that allow Flannel pod-to-pod and pod-to-Technitium traffic through
# each node's routed/FORWARD chain.
k3s_dns_resolver: 10.10.40.53
k3s_pod_cidr: 10.42.0.0/16

View File

@ -1,7 +1,7 @@
---
# Part of role: common
# Called by: ansible/playbooks/bootstrap-minisforum.yaml
# Description: Sets timezone, installs base packages, creates user, hardens SSH, configures UFW, and creates data directories.
# Description: Sets timezone, installs base packages, creates user, hardens SSH, configures UFW (including routed pod-to-pod/pod-to-Technitium rules), and creates data directories.
- name: Set timezone
community.general.timezone:
@ -64,6 +64,27 @@
comment: "{{ item.comment }}"
loop: "{{ ufw_allowed_ports }}"
- name: Allow routed pod-to-pod traffic (Flannel)
community.general.ufw:
rule: allow
route: true
src: "{{ k3s_pod_cidr }}"
dest: "{{ k3s_pod_cidr }}"
comment: K3s pod-to-pod (Flannel)
- name: Allow routed pod traffic to Technitium DNS
community.general.ufw:
rule: allow
route: true
src: "{{ k3s_pod_cidr }}"
dest: "{{ k3s_dns_resolver }}"
port: "53"
proto: "{{ item }}"
comment: K3s pod DNS to Technitium
loop:
- tcp
- udp
- name: Enable UFW
community.general.ufw:
state: enabled

View File

@ -1,7 +1,11 @@
---
# Part of role: nfs-server
# Called by: ansible/playbooks/setup-nfs-debian.yaml
# Description: Default variables for the nfs-server role including export path and allowed client IP.
# Description: Default variables for the nfs-server role including export path, allowed client IP, and UFW-allowed SMB source networks.
nfs_export_path: /mnt/storage
nfs_allowed_ip: 10.10.40.53
smb_allowed_subnets:
- 10.10.10.0/24
- 10.10.40.0/24

View File

@ -1,7 +1,7 @@
---
# Part of role: nfs-server
# Called by: ansible/playbooks/setup-nfs-debian.yaml
# Description: Installs NFS server, configures exports, and ensures the backup directory exists.
# Description: Installs NFS server, configures exports, allows NFS/SMB through UFW, and ensures the backup directory exists.
- name: Install NFS server
ansible.builtin.apt:
@ -29,6 +29,25 @@
enabled: true
become: true
- name: Allow NFS access through UFW from the k3s server
community.general.ufw:
rule: allow
port: "2049"
proto: tcp
src: "{{ nfs_allowed_ip }}"
comment: NFS from k3s server
become: true
- name: Allow SMB access through UFW from trusted networks
community.general.ufw:
rule: allow
port: "445"
proto: tcp
src: "{{ item }}"
comment: SMB (Samba)
loop: "{{ smb_allowed_subnets }}"
become: true
- name: Ensure backup directory exists with correct ownership
ansible.builtin.file:
path: /home/nik/backups/gitea