From 6b106cce38106e7beb9db623a9d98784cb8bbc86 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Romain=20Gon=C3=A7alves?= Date: Thu, 30 Dec 2021 15:39:08 +0000 Subject: ansible_port: Add ssh port switch to network roles --- roles/pf/tasks/main.yml | 2 +- roles/pf/templates/pf.conf.j2 | 2 +- roles/sshd/tasks/main.yml | 2 +- roles/sshd/templates/sshd_config.j2 | 3 +++ roles/workstation/templates/ssh.config.j2 | 6 ++++++ 5 files changed, 12 insertions(+), 3 deletions(-) (limited to 'roles') diff --git a/roles/pf/tasks/main.yml b/roles/pf/tasks/main.yml index 3924a89..e5b8af8 100644 --- a/roles/pf/tasks/main.yml +++ b/roles/pf/tasks/main.yml @@ -12,6 +12,6 @@ - name: test ssh connection on new pf rule wait_for: - port: 22 + port: "{{ ansible_port }}" delay: 2 state: started diff --git a/roles/pf/templates/pf.conf.j2 b/roles/pf/templates/pf.conf.j2 index 6bc936a..1b51fe7 100644 --- a/roles/pf/templates/pf.conf.j2 +++ b/roles/pf/templates/pf.conf.j2 @@ -8,7 +8,7 @@ set skip on { lo wg0 } block all # force ssh if not present below -pass in quick on egress proto tcp to port 22 +pass in quick on egress proto tcp to port {{ ansible_port }} # host services {% for service in __services %} diff --git a/roles/sshd/tasks/main.yml b/roles/sshd/tasks/main.yml index 54ef9c2..f1af386 100644 --- a/roles/sshd/tasks/main.yml +++ b/roles/sshd/tasks/main.yml @@ -17,6 +17,6 @@ - name: check ssh connection wait_for: - port: 22 + port: "{{ ansible_port }}" delay: 1 state: started diff --git a/roles/sshd/templates/sshd_config.j2 b/roles/sshd/templates/sshd_config.j2 index 534ea39..f40e160 100644 --- a/roles/sshd/templates/sshd_config.j2 +++ b/roles/sshd/templates/sshd_config.j2 @@ -1,5 +1,8 @@ # managed by Ansible +# network +Port {{ ansible_port }} + # security PermitRootLogin yes MaxAuthTries 6 diff --git a/roles/workstation/templates/ssh.config.j2 b/roles/workstation/templates/ssh.config.j2 index 2915a1a..2a3a903 100644 --- a/roles/workstation/templates/ssh.config.j2 +++ b/roles/workstation/templates/ssh.config.j2 @@ -5,7 +5,13 @@ {% set command = "pgrep wg && ! ping -c 1 -w 1 %s" % h.__ip.external %} Match originalHost {{ h.inventory_hostname }} exec "{{ command }}" HostName {{ h.__ip.internal }} +{% if h.ansible_port is defined %} + Port {{ h.ansible_port }} +{% endif %} Match originalHost {{ h.inventory_hostname }} HostName {{ h.__ip.external }} +{% if h.ansible_port is defined %} + Port {{ h.ansible_port }} +{% endif %} {% endcall %} -- cgit v1.2.3