From: Justin Wind Date: Fri, 10 Mar 2017 22:04:49 +0000 (-0800) Subject: split infrastructure further X-Git-Url: https://git.squeep.com/?a=commitdiff_plain;h=61529b77d80927786c7459c0776ad036682ceca3;p=awsible split infrastructure further --- diff --git a/roles/aws-management-infrastructure/meta/main.yml b/roles/aws-management-infrastructure/meta/main.yml index f4f0c2a..381b352 100644 --- a/roles/aws-management-infrastructure/meta/main.yml +++ b/roles/aws-management-infrastructure/meta/main.yml @@ -1,3 +1,4 @@ --- dependencies: - { role: aws-management-queues } + - { role: common-infrastructure } diff --git a/roles/aws-management-infrastructure/tasks/main.yml b/roles/aws-management-infrastructure/tasks/main.yml index 512f229..d0edb77 100644 --- a/roles/aws-management-infrastructure/tasks/main.yml +++ b/roles/aws-management-infrastructure/tasks/main.yml @@ -5,24 +5,6 @@ - DEFAULT_AMI != '' tags: ['check_vars'] -- name: sg ssh - ec2_group: - vpc_id: "{{ vpc.vpc.id }}" - region: "{{ vpc_region }}" - state: present - name: ssh - description: "allow ssh from anywhere" - purge_rules: false - rules: - - proto: tcp - from_port: 22 - to_port: 22 - cidr_ip: 0.0.0.0/0 - rules_egress: - - proto: all - cidr_ip: 0.0.0.0/0 - register: sg_ssh - - name: sg management-elb ec2_group: vpc_id: "{{ vpc.vpc.id }}" diff --git a/roles/common-infrastructure/meta/main.yml b/roles/common-infrastructure/meta/main.yml new file mode 100644 index 0000000..279092d --- /dev/null +++ b/roles/common-infrastructure/meta/main.yml @@ -0,0 +1,3 @@ +--- +dependencies: + - { role: aws-vpc } diff --git a/roles/common-infrastructure/tasks/main.yml b/roles/common-infrastructure/tasks/main.yml new file mode 100644 index 0000000..6d40a64 --- /dev/null +++ b/roles/common-infrastructure/tasks/main.yml @@ -0,0 +1,18 @@ +--- +- name: sg ssh + ec2_group: + vpc_id: "{{ vpc.vpc.id }}" + region: "{{ vpc_region }}" + state: present + name: ssh + description: "allow ssh from anywhere" + purge_rules: false + rules: + - proto: tcp + from_port: 22 + to_port: 22 + cidr_ip: 0.0.0.0/0 + rules_egress: + - proto: all + cidr_ip: 0.0.0.0/0 + register: sg_ssh