ansible-infra/collections/ansible_collections/nullified/infrastructure/roles/security/defaults/main.yml

30 lines
539 B
YAML

---
security:
apt:
force_https: true
https_ignore_list: []
clamav:
version: 1.2.1
firewall:
enable: true
nat:
policy:
prerouting: accept
input: accept
output: accept
postrouting: accept
mangle:
drop_privatenets: true
policy:
prerouting: accept
output: accept
forward: drop
postrouting: accept
filter:
policy:
input: drop
output: drop
forward: drop
custom_security: {}
recursive_combine: true