如何通过Ansible Playbook在Debian 11中安装并配置UFW
解决Debian 11中Ansible Playbook配置UFW失败的问题
Debian 11默认未预装UFW,导致原Playbook中UFW相关任务执行失败。你只需在UFW配置步骤前添加安装和启用UFW的任务即可,修改后的完整Playbook如下:
--- - name: Install prerequisites apt: name={{ item }} update_cache=yes state=latest force_apt_get=yes loop: [ 'aptitude' ] # Apache Configuration - name: Install Apache and PHP Packages apt: name={{ item }} update_cache=yes state=latest loop: [ 'apache2', 'php', 'php-mysql', 'libapache2-mod-php' ] - name: Create document root file: path: "/var/www/{{ http_host }}" state: directory owner: "{{ app_user }}" mode: '0755' - name: Set up Apache virtualhost template: src: "files/apache.conf.j2" dest: "/etc/apache2/sites-available/{{ http_conf }}" - name: Enable new site shell: /usr/sbin/a2ensite {{ http_conf }} - name: Disable default Apache site shell: /usr/sbin/a2dissite 000-default.conf when: disable_default notify: Reload Apache # UFW 安装与基础配置 - name: Install UFW apt: name=ufw update_cache=yes state=latest - name: Enable and start UFW service service: name: ufw state: started enabled: yes - name: Set UFW default policies(可选,增强安全性) ufw: default: "{{ item.policy }}" direction: "{{ item.direction }}" loop: - { policy: deny, direction: incoming } - { policy: allow, direction: outgoing } # UFW Configuration - name: "UFW - Allow HTTP on port {{ http_port }}" ufw: rule: allow port: "{{ http_port }}" proto: tcp # PHP Info Page - name: Sets Up PHP Info Page template: src: "files/info.php.j2" dest: "/var/www/{{ http_host }}/info.php" - name: Reload Apache service: name: apache2 state: reloaded - name: Restart Apache service: name: apache2 state: restarted
关键修改说明:
- 安装UFW:新增
Install UFW任务,通过apt模块完成ufw包的安装 - 启用UFW服务:确保UFW服务启动并设置开机自启,避免系统重启后防火墙失效
- 默认策略配置(可选):设置默认拒绝入站、允许出站,这是UFW的推荐安全配置,不需要的话可直接删除该部分
内容的提问来源于stack exchange,提问作者Chezzers
相关产品推荐
相关产品推荐

