forked from Deuxfleurs/infrastructure
Alex Auvolat
351e6f13d5
- Remove nomad interface (unused) - Deactivate systemd-resolved - Add dns_server to production nodes variables - Add recursors option to Consul so that it can resolve outside DNS queries - Use consul as a global DNS server for machines and containers, with the outside DNS as a fallback (see roles/consul/templates/resolv.conf.j2)
31 lines
716 B
YAML
31 lines
716 B
YAML
- name: "Deploy iptablesv4 configuration"
|
|
template: src=rules.v4.j2 dest=/etc/iptables/rules.v4
|
|
notify:
|
|
- reload iptables
|
|
|
|
- name: "Deploy iptablesv6 configuration"
|
|
copy: src=rules.v6 dest=/etc/iptables/rules.v6
|
|
notify:
|
|
- reload ip6tables
|
|
|
|
- name: "Activate IP forwarding"
|
|
sysctl:
|
|
name: net.ipv4.ip_forward
|
|
value: 1
|
|
sysctl_set: yes
|
|
|
|
- name: "Flush handlers"
|
|
meta: flush_handlers
|
|
|
|
|
|
# These two lines are used to undo previous config, remove them once it is done
|
|
- name: "Update nsswitch.conf to not use systemd-resolved"
|
|
copy: src=nsswitch.conf dest=/etc/nsswitch.conf
|
|
|
|
- name: "Disable systemd-resolved"
|
|
systemd:
|
|
name: systemd-resolved
|
|
state: stopped
|
|
enabled: false
|
|
|
|
|