réinstallation du jitsi komuniki
This commit is contained in:
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
jitsi.komuniki.fr ansible_user=ubuntu ansible_become=true
|
jitsi.komuniki.fr ansible_user=debian ansible_become=true
|
||||||
visio.imio.be ansible_user=debian ansible_become=true
|
visio.imio.be ansible_user=debian ansible_become=true
|
||||||
jitsi.entrouvert.com ansible_user=root
|
jitsi.entrouvert.com ansible_user=root
|
||||||
bbb.komuniki.fr ansible_user=root
|
bbb.komuniki.fr ansible_user=root
|
||||||
@@ -1,42 +1,12 @@
|
|||||||
---
|
---
|
||||||
- name: Installation de fail2ban, nftables, gnupg2, apt-transport-https, ufw
|
- name: Installation de sshguard, ufw
|
||||||
apt:
|
apt:
|
||||||
name:
|
name:
|
||||||
- fail2ban
|
- sshguard
|
||||||
- nftables
|
|
||||||
- gnupg2
|
|
||||||
- apt-transport-https
|
|
||||||
- ufw
|
- ufw
|
||||||
update_cache: true
|
update_cache: true
|
||||||
state: present
|
state: present
|
||||||
|
|
||||||
- name: Appliquation des règles de ban ssh
|
|
||||||
template:
|
|
||||||
src: ../files/jail.conf
|
|
||||||
dest: /etc/fail2ban/jail.d/jail.conf
|
|
||||||
notify:
|
|
||||||
- restart fail2ban
|
|
||||||
|
|
||||||
- name: Création du répertoire pour la surcharge systemd
|
|
||||||
file:
|
|
||||||
name: /etc/systemd/system/fail2ban.service.d
|
|
||||||
state: directory
|
|
||||||
|
|
||||||
- name: Règle de base pour nftables
|
|
||||||
template:
|
|
||||||
src: ../files/fail2ban-override.conf
|
|
||||||
dest: /etc/systemd/system/fail2ban.service.d/override.conf
|
|
||||||
|
|
||||||
- name: Déploiement des règles nftables (base)
|
|
||||||
tags:
|
|
||||||
- nftables
|
|
||||||
template:
|
|
||||||
src: ../files/nftables.conf
|
|
||||||
dest: /etc/nftables.conf
|
|
||||||
notify:
|
|
||||||
- restart nftables
|
|
||||||
- restart fail2ban
|
|
||||||
|
|
||||||
- name: Mise en place des règle firewall tcp et udp
|
- name: Mise en place des règle firewall tcp et udp
|
||||||
#source : https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart#setup-and-configure-your-firewall
|
#source : https://jitsi.github.io/handbook/docs/devops-guide/devops-guide-quickstart#setup-and-configure-your-firewall
|
||||||
ufw:
|
ufw:
|
||||||
@@ -52,6 +22,7 @@
|
|||||||
- ['10000','udp']
|
- ['10000','udp']
|
||||||
- ['3478','tcp']
|
- ['3478','tcp']
|
||||||
- ['5349','udp']
|
- ['5349','udp']
|
||||||
|
- ['5222','tcp'] # XMPP port for recorder
|
||||||
|
|
||||||
- name: Ajout de la clé GPG pour le depot jitsi
|
- name: Ajout de la clé GPG pour le depot jitsi
|
||||||
apt_key:
|
apt_key:
|
||||||
|
|||||||
Reference in New Issue
Block a user