diff --git a/apache/tasks/auth.yml b/apache/tasks/auth.yml index f024f9cb..b785c704 100644 --- a/apache/tasks/auth.yml +++ b/apache/tasks/auth.yml @@ -13,18 +13,6 @@ - name: Load IP whitelist task include: ip_whitelist.yml - tags: - - apache - -- name: remove IP addresses from private IP whitelist - lineinfile: - dest: /etc/apache2/ipaddr_whitelist.conf - line: "Require ip {{ item }}" - state: absent - with_items: "{{ apache_ipaddr_whitelist_absent }}" - notify: reload apache - tags: - - apache - name: include private IP whitelist for server-status lineinfile: diff --git a/apache/tasks/ip_whitelist.yml b/apache/tasks/ip_whitelist.yml index c6dd0cc9..ac2b6f87 100644 --- a/apache/tasks/ip_whitelist.yml +++ b/apache/tasks/ip_whitelist.yml @@ -1,4 +1,5 @@ --- + - name: add IP addresses to private IP whitelist lineinfile: dest: /etc/apache2/ipaddr_whitelist.conf @@ -7,4 +8,16 @@ with_items: "{{ apache_ipaddr_whitelist_present }}" notify: reload apache tags: - - apache \ No newline at end of file + - apache + - ips + +- name: remove IP addresses from private IP whitelist + lineinfile: + dest: /etc/apache2/ipaddr_whitelist.conf + line: "Require ip {{ item }}" + state: absent + with_items: "{{ apache_ipaddr_whitelist_absent }}" + notify: reload apache + tags: + - apache + - ips diff --git a/nginx/tasks/ip_whitelist.yml b/nginx/tasks/ip_whitelist.yml index 3b443f65..10cdcc37 100644 --- a/nginx/tasks/ip_whitelist.yml +++ b/nginx/tasks/ip_whitelist.yml @@ -1,4 +1,5 @@ --- + - name: add IP addresses to private IP whitelist lineinfile: dest: /etc/nginx/snippets/ipaddr_whitelist @@ -6,5 +7,17 @@ state: present with_items: "{{ nginx_ipaddr_whitelist_present }}" notify: reload nginx - tags + tags: - nginx + - ips + +- name: remove IP addresses from private IP whitelist + lineinfile: + dest: /etc/nginx/snippets/ipaddr_whitelist + line: "allow {{ item }};" + state: absent + with_items: "{{ nginx_ipaddr_whitelist_absent }}" + notify: reload nginx + tags: + - nginx + - ips diff --git a/nginx/tasks/main_regular.yml b/nginx/tasks/main_regular.yml index 5aff5ae4..f3c31d56 100644 --- a/nginx/tasks/main_regular.yml +++ b/nginx/tasks/main_regular.yml @@ -50,23 +50,9 @@ tags: - nginx - ips - + - name: Include IP address whitelist task include: ip_whitelist.yml - tags: - - nginx - - ips - -- name: remove IP addresses from private IP whitelist - lineinfile: - dest: /etc/nginx/snippets/ipaddr_whitelist - line: "allow {{ item }};" - state: absent - with_items: "{{ nginx_ipaddr_whitelist_absent }}" - notify: reload nginx - tags: - - nginx - - ips - name: Copy private_htpasswd copy: