aboutsummaryrefslogtreecommitdiffstatshomepage
diff options
context:
space:
mode:
authorEgor Tensin <Egor.Tensin@gmail.com>2023-08-08 22:57:19 +0200
committerEgor Tensin <Egor.Tensin@gmail.com>2023-08-08 22:57:19 +0200
commit3ca728406720da6814f4bcb670639315e3170270 (patch)
treec8eceacd70f019595a262a8fe4a3163a9257189c
parentadd router role (diff)
downloadinfra-ansible-3ca728406720da6814f4bcb670639315e3170270.tar.gz
infra-ansible-3ca728406720da6814f4bcb670639315e3170270.zip
firewall: make SSH port go first in rules
-rw-r--r--roles/firewall/templates/rules.v42
-rw-r--r--roles/firewall/templates/rules.v62
2 files changed, 2 insertions, 2 deletions
diff --git a/roles/firewall/templates/rules.v4 b/roles/firewall/templates/rules.v4
index 7ea1162..38caa43 100644
--- a/roles/firewall/templates/rules.v4
+++ b/roles/firewall/templates/rules.v4
@@ -17,7 +17,7 @@
{% set ssh_port = hostvars[inventory_hostname].ansible_port %}
# Open TCP ports:
-{% set tcp_ports = firewall_ports_tcp + firewall_ports4_tcp + [ssh_port] %}
+{% set tcp_ports = [ssh_port] + firewall_ports_tcp + firewall_ports4_tcp %}
{% set tcp_ports = tcp_ports | unique %}
{% for port in tcp_ports %}
diff --git a/roles/firewall/templates/rules.v6 b/roles/firewall/templates/rules.v6
index 27bf58b..ab1ce6d 100644
--- a/roles/firewall/templates/rules.v6
+++ b/roles/firewall/templates/rules.v6
@@ -17,7 +17,7 @@
{% set ssh_port = hostvars[inventory_hostname].ansible_port %}
# Open TCP ports:
-{% set tcp_ports = firewall_ports_tcp + firewall_ports6_tcp + [ssh_port] %}
+{% set tcp_ports = [ssh_port] + firewall_ports_tcp + firewall_ports6_tcp %}
{% set tcp_ports = tcp_ports | unique %}
{% for port in tcp_ports %}