Skip to content

Commit 0afc42b

Browse files
committed
Merge remote-tracking branch 'origin/block-egress' into snapshot-restore
2 parents 03e6636 + 5a85b11 commit 0afc42b

File tree

8 files changed

+12
-11
lines changed

8 files changed

+12
-11
lines changed

roles/aws_controllers/defaults/main.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ vbond_port: 12346
3232
default_vbond_ip: 192.168.1.199 # default ips from official Cisco guides
3333
ipv6_strict_control: true
3434
# vpn0_interface_color: default
35+
aws_sg_block_egress: false
3536

3637

3738
###############################

roles/aws_controllers/tasks/aws_vbond_ec2_instance.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -197,10 +197,6 @@
197197
purge_rules_egress: false
198198
rules: "{{ sg_rules_vbond }}"
199199
rules_egress: "{{ sg_rules_vbond if aws_sg_block_egress else [] }}"
200-
register: allow_traffic
201-
retries: 3
202-
delay: 3
203-
until: allow_traffic is succeeded
204200
vars:
205201
sg_rules_vbond:
206202
- proto: all
@@ -215,6 +211,10 @@
215211
- proto: all
216212
cidr_ipv6: "{{ instance.transport_public_ipv6 }}/128"
217213
rule_desc: "{{ hostname }} - transport IPv6 (VPN 0)"
214+
register: allow_traffic
215+
retries: 3
216+
delay: 3
217+
until: allow_traffic is succeeded
218218

219219
- name: Create record in internal DNS zone
220220
amazon.aws.route53:

roles/azure_controllers/defaults/main.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ az_subnets: |
5555
5656
# Security group
5757
az_network_security_group: "{{ az_resources_prefix }}-nsg"
58-
az_nsg_block_edgess: false
58+
az_nsg_block_egress: false
5959

6060

6161
# Private DNS zone

roles/azure_controllers/tasks/azure_vbond_vm.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@
5757
azure.azcollection.azure_rm_securitygroup:
5858
resource_group: "{{ az_resource_group }}"
5959
name: "{{ az_network_security_group }}"
60-
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_edgess else [inbound_rule] }}"
60+
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_egress else [inbound_rule] }}"
6161
tags:
6262
Name: "{{ az_network_security_group }}"
6363
Creator: "{{ az_tag_creator }}"

roles/azure_controllers/tasks/azure_vmanage_vm.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@
6060
azure.azcollection.azure_rm_securitygroup:
6161
resource_group: "{{ az_resource_group }}"
6262
name: "{{ az_network_security_group }}"
63-
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_edgess else [inbound_rule] }}"
63+
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_egress else [inbound_rule] }}"
6464
tags:
6565
Name: "{{ az_network_security_group }}"
6666
Creator: "{{ az_tag_creator }}"
@@ -159,7 +159,7 @@
159159
azure.azcollection.azure_rm_securitygroup:
160160
resource_group: "{{ az_resource_group }}"
161161
name: "{{ az_network_security_group }}"
162-
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_edgess else [inbound_rule] }}"
162+
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_egress else [inbound_rule] }}"
163163
tags:
164164
Name: "{{ az_network_security_group }}"
165165
Creator: "{{ az_tag_creator }}"

roles/azure_controllers/tasks/azure_vsmart_vm.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@
5757
azure.azcollection.azure_rm_securitygroup:
5858
resource_group: "{{ az_resource_group }}"
5959
name: "{{ az_network_security_group }}"
60-
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_edgess else [inbound_rule] }}"
60+
rules: "{{ [inbound_rule, outbound_rule] if az_nsg_block_egress else [inbound_rule] }}"
6161
tags:
6262
Name: "{{ az_network_security_group }}"
6363
Creator: "{{ az_tag_creator }}"

roles/azure_network_infrastructure/defaults/main.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ az_subnets: |
5858
5959
# Security group
6060
az_network_security_group: "{{ az_resources_prefix }}-nsg"
61-
az_nsg_block_edgess: false
61+
az_nsg_block_egress: false
6262

6363

6464
# Private DNS zone

roles/azure_network_infrastructure/tasks/azure_network_infrastructure.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -124,7 +124,7 @@
124124
Name: "{{ az_network_security_group }}"
125125
Creator: "{{ az_tag_creator }}"
126126
Organization: "{{ organization_name }}"
127-
when: az_nsg_block_edgess
127+
when: az_nsg_block_egress
128128

129129
- name: Create a private DNS zone
130130
azure.azcollection.azure_rm_privatednszone:

0 commit comments

Comments
 (0)