Nik Afiq 939a7c6ed1
Some checks failed
validate / lint (push) Failing after 1s
feat: add routed UFW rules for pod traffic and open NFS/SMB on nik-debian
Adds explicit UFW routed-allow rules (10.42.0.0/16 pod-to-pod, pod-to-Technitium
DNS) since these nodes default their routed/FORWARD policy to DROP. Also brings
nik-debian's NFS (2049) and SMB (445) ports under Ansible-managed UFW rules via
the existing nfs-server role, scoped to the Lab/Trusted networks that need them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-23 15:00:45 +09:00

110 lines
2.8 KiB
YAML

---
# Part of role: common
# Called by: ansible/playbooks/bootstrap-minisforum.yaml
# Description: Sets timezone, installs base packages, creates user, hardens SSH, configures UFW (including routed pod-to-pod/pod-to-Technitium rules), and creates data directories.
- name: Set timezone
community.general.timezone:
name: "{{ timezone }}"
- name: Install base packages
ansible.builtin.apt:
name: "{{ base_packages }}"
state: present
update_cache: true
- name: Create primary user
ansible.builtin.user:
name: "{{ username }}"
groups: sudo
shell: /bin/bash
create_home: true
state: present
- name: Set up authorized SSH key for user
ansible.posix.authorized_key:
user: "{{ username }}"
state: present
key: "{{ lookup('file', '~/.ssh/id_ed25519-nik-macbookair.pub') }}"
- name: Harden SSH — disable password auth
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: "{{ item.regexp }}"
line: "{{ item.line }}"
state: present
loop:
- { regexp: "^#?PasswordAuthentication", line: "PasswordAuthentication no" }
- { regexp: "^#?PermitRootLogin", line: "PermitRootLogin no" }
- { regexp: "^#?PubkeyAuthentication", line: "PubkeyAuthentication yes" }
- { regexp: "^#?Port ", line: "Port 430" }
notify: Restart sshd
- name: Install UFW
ansible.builtin.apt:
name: ufw
state: present
- name: Set UFW default deny incoming
community.general.ufw:
default: deny
direction: incoming
- name: Set UFW default allow outgoing
community.general.ufw:
default: allow
direction: outgoing
- name: Allow required ports
community.general.ufw:
rule: allow
port: "{{ item.port }}"
proto: "{{ item.proto }}"
src: "{{ item.src | default('any') }}"
comment: "{{ item.comment }}"
loop: "{{ ufw_allowed_ports }}"
- name: Allow routed pod-to-pod traffic (Flannel)
community.general.ufw:
rule: allow
route: true
src: "{{ k3s_pod_cidr }}"
dest: "{{ k3s_pod_cidr }}"
comment: K3s pod-to-pod (Flannel)
- name: Allow routed pod traffic to Technitium DNS
community.general.ufw:
rule: allow
route: true
src: "{{ k3s_pod_cidr }}"
dest: "{{ k3s_dns_resolver }}"
port: "53"
proto: "{{ item }}"
comment: K3s pod DNS to Technitium
loop:
- tcp
- udp
- name: Enable UFW
community.general.ufw:
state: enabled
- name: Create persistent data directories
ansible.builtin.file:
path: "{{ item }}"
state: directory
owner: "{{ username }}"
group: "{{ username }}"
mode: "0755"
loop: "{{ data_dirs }}"
- name: Set inotify limits
ansible.posix.sysctl:
name: "{{ item.name }}"
value: "{{ item.value }}"
sysctl_file: /etc/sysctl.d/99-inotify.conf
reload: true
loop:
- { name: fs.inotify.max_user_instances, value: 512 }
- { name: fs.inotify.max_user_watches, value: 524288 }