I am currently looking into ansibles to store my configurations and deploy services more easily. I have couple of iptable rules in /etc/iptables/rules.v4, which I can easily restore. Meanwhile, ansible has iptable role for configurations. How do I persist this rules, especially across reboots? Should I rerun ansible every time on each reboot? I am at loss on how to best manage iptables, as other services can interact with it. How do you folks handle this? Thanks in advance!
I second the use of nftables instead. Optimally with a pre-made role like this one: galaxy.ansible.com/ui/…/documentation/
possiblylinux127@lemmy.zip 1 year ago
You want something outside of IPtables like Firewalld. Ansible should only run to make changes to a existing system.
vegetaaaaaaa@lemmy.world 11 months ago
No. Ansible is fine for provisioning and initial deployment.
possiblylinux127@lemmy.zip 11 months ago
I miss phrased this
My existing system I mean some sort of Linux install. Don’t use Ansible to start a service on startup.