Merge "Create role and playbook to set default secgroup in infracloud"
This commit is contained in:
commit
c070992791
14
playbooks/allow_all_traffic_default_secgroup.yml
Normal file
14
playbooks/allow_all_traffic_default_secgroup.yml
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
- hosts: localhost
|
||||||
|
connection: local
|
||||||
|
gather_facts: false
|
||||||
|
user: root
|
||||||
|
roles:
|
||||||
|
- { role: allow_all_traffic_default_secgroup, os_client_config_cloud: 'openstackci-infracloud-west' }
|
||||||
|
|
||||||
|
- hosts: localhost
|
||||||
|
connection: local
|
||||||
|
gather_facts: false
|
||||||
|
user: root
|
||||||
|
roles:
|
||||||
|
- { role: allow_all_traffic_default_secgroup, os_client_config_cloud: 'openstackjenkins-infracloud-west' }
|
@ -0,0 +1,21 @@
|
|||||||
|
- name: Delete any previously default security group rules
|
||||||
|
shell: /usr/local/bin/openstack security group rule delete "{{ item }}"
|
||||||
|
environment:
|
||||||
|
OS_CLOUD: "{{ os_client_config_cloud }}"
|
||||||
|
with_lines: OS_CLOUD="{{ os_client_config_cloud }}" /usr/local/bin/openstack security group rule list -f value -c ID default
|
||||||
|
|
||||||
|
- name: Allow all IPv4 traffic on default security group
|
||||||
|
os_security_group_rule:
|
||||||
|
cloud: "{{ os_client_config_cloud }}"
|
||||||
|
security_group: default
|
||||||
|
direction: ingress
|
||||||
|
ethertype: IPv4
|
||||||
|
remote_ip_prefix: 0.0.0.0/0
|
||||||
|
|
||||||
|
- name: Allow all IPv6 traffic on default security group
|
||||||
|
os_security_group_rule:
|
||||||
|
cloud: "{{ os_client_config_cloud }}"
|
||||||
|
security_group: default
|
||||||
|
direction: ingress
|
||||||
|
ethertype: IPv6
|
||||||
|
remote_ip_prefix: ::0/0
|
Loading…
x
Reference in New Issue
Block a user