feat: Manage ipforwarding

This commit is contained in:
2026-09-17 11:57:38 +02:00
parent 1982bb584d
commit 4b6c7219aa
4 changed files with 27 additions and 0 deletions
+3
View File
@@ -7,5 +7,8 @@ nftables_conf_template: nftables.conf.j2
# Default configuration path # Default configuration path
nftables_conf_path: /etc/nftables.conf nftables_conf_path: /etc/nftables.conf
# Path of sysctl ipforwarding file
nftables_ip_forwarding_path: ""
# List of rules to deploy # List of rules to deploy
nftables_rules: [] nftables_rules: []
+9
View File
@@ -8,3 +8,12 @@
enabled: true enabled: true
masked: false masked: false
become: true become: true
- name: Enable 100-ip_forwarding.conf
ansible.builtin.command:
argv:
- sysctl
- -p
- "{{ nftables_ip_forwarding_path }}"
removes: "{{ nftables_ip_forwarding_path }}"
become: true
+11
View File
@@ -18,3 +18,14 @@
mode: u=rw,g=,o= mode: u=rw,g=,o=
become: true become: true
notify: Restart nftables.service notify: Restart nftables.service
- name: Enable IP forwarding
ansible.builtin.template:
src: 100-ip_forwarding.conf.j2
dest: "{{ nftables_ip_forwarding_path }}"
owner: root
group: root
mode: u=rw,g=r,o=r
when: nftables_ip_forwarding_path | length > 0
become: true
notify: Enable 100-ip_forwarding.conf
+4
View File
@@ -0,0 +1,4 @@
# {{ ansible_managed }}
net.ipv4.conf.all.forwarding = 1
net.ipv6.conf.all.forwarding = 1