diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 83a18d25e58ca7adc2e526f0ed30b12263cb0c13..233bc80d8f4b0a2ed98f97e33a6269dd6ef0d882 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -8,7 +8,7 @@ - id: check-merge-conflict - id: flake8 - id: check-symlinks -- repo: https://www.shore.co.il/git/ansible-pre-commit +- repo: https://github.com/adarnimrod/ansible-pre-commit.git sha: 0fadd691465b97db8992cfc66650f630e433324b hooks: - id: ansible-syntax-check diff --git a/.travis.yml b/.travis.yml new file mode 100644 index 0000000000000000000000000000000000000000..abc583a44f62a169059b177cabed55bfe3ab9183 --- /dev/null +++ b/.travis.yml @@ -0,0 +1,24 @@ +--- +language: python +python: "2.7" +dist: trusty +sudo: false +group: beta +services: [docker] +cache: + - pip + - directories: + - $HOME/.pre-commit + +install: + - pip install -r tests/requirements.txt | cat + - ansible-galaxy install git+file://$(pwd),$(git rev-parse --abbrev-ref HEAD) -p .molecule/roles + - molecule dependency + +script: + - pre-commit run --all-files + - molecule test --driver docker + +notifications: + webhooks: https://galaxy.ansible.com/api/v1/notifications/ + email: false diff --git a/README.rst b/README.rst index ed5be624a1299f940eeef831ecdff3fdb3c66f13..08feb2803603630e1d4779c14213b3cb791aff8b 100644 --- a/README.rst +++ b/README.rst @@ -1,13 +1,15 @@ UFW ### +.. image:: https://travis-ci.org/adarnimrod/ufw.svg?branch=master + :target: https://travis-ci.org/adarnimrod/ufw + Install UFW, set default policy and allow but limit ssh traffic. Requirements ------------ -See :code:`meta/main.yml`, :code:`tests/requirements.yml` and assertions at -the top of :code:`tasks/main.yml`. +See :code:`meta/main.yml` and assertions at the top of :code:`tasks/main.yml`. Role Variables -------------- @@ -27,21 +29,22 @@ See :code:`tests/playbook.yml`. Testing ------- -Testing requires Virtualbox and Vagrant and Python 2.7. Install the Python -dependencies, add pre-commit hooks by running: +Testing requires Python 2.7 and either Docker or Vagrant and Virtualbox. +Install the Python dependencies, dependent roles and roles required for +testing: .. code:: shell pip install -r tests/requirements.txt - pre-commit install + ansible-galaxy install git+file://$(pwd),$(git rev-parse --abbrev-ref HEAD) -p .molecule/roles + molecule dependency To run the full test suite: .. code:: shell - ansible-galaxy install git+file://$(pwd),$(git rev-parse --abbrev-ref HEAD) -p .molecule/roles - molecule test --platform all pre-commit run --all-files + molecule test --platform all License ------- diff --git a/ansible.cfg b/ansible.cfg index 2bc7613f4df5ddc0fe0f2719df832ddfff4bfe62..905e3c64897217cd1b88acde10920ae04c7c6011 100644 --- a/ansible.cfg +++ b/ansible.cfg @@ -5,6 +5,7 @@ retry_files_enabled = False roles_path = .molecule/roles:.molecule/../roles:../:../../ command_warnings = True deprecation_warnings = True +callback_whitelist = profile_tasks [ssh_connection] pipelining = True diff --git a/defaults/main.yml b/defaults/main.yml index 366ee82e2e64a807228f00df2f7e59fe29271cef..8c01a18287dbec6688e8ffb4e88bb79dcf1c292f 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -1,4 +1,4 @@ --- -# defaults file for ansible-role-ufw +# defaults file for ufw ufw_policy: reject # Default policy, check ufw module for options. diff --git a/handlers/main.yml b/handlers/main.yml index ecb7d31bb12b681666d1cf829aa64f217ec89c18..975db23e285e9052bca5db10b2de846c21f4be03 100644 --- a/handlers/main.yml +++ b/handlers/main.yml @@ -1,2 +1,2 @@ --- -# handlers file for ansible-role-ufw +# handlers file for ufw diff --git a/molecule.yml b/molecule.yml index 1fff18527c43bcf809dbdd2b3ed3cc38dd964a4a..58acadc5a6b78724db7d58b6fb1b7b41be54d288 100644 --- a/molecule.yml +++ b/molecule.yml @@ -5,6 +5,10 @@ ansible: diff: True config_file: ../ansible.cfg +dependency: + name: galaxy + requirements_file: tests/requirements.yml + vagrant: providers: - name: virtualbox @@ -13,7 +17,7 @@ vagrant: - name: debian box: debian/jessie64 instances: - - name: ansible-role-ufw + - name: ufw options: append_platform_to_hostname: yes raw_config_args: @@ -21,3 +25,17 @@ vagrant: - 'vbguest.auto_update = false' - 'landrush.enabled = false' - 'landrush_ip.override = false' + +docker: + containers: + - name: ufw-jessie + image: debian + image_version: jessie + command: /sbin/init + privileged: True + volume_mounts: + - /sys/fs/cgroup:/sys/fs/cgroup + - /var/run/dbus/system_bus_socket:/var/run/dbus/system_bus_socket + environment: + DEBIAN_FRONTEND: noninteractive + container: docker diff --git a/tasks/main.yml b/tasks/main.yml index dc284b4ec6f61c542da250edf20c84357ddad7be..8fa6fe4a68552acbfc23c0f8d36d0c261536a1e6 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -1,5 +1,6 @@ --- -# tasks file for ansible-role-ufw +# tasks file for ufw + - name: Assertions assert: that: ansible_pkg_mgr == 'apt' diff --git a/tests/playbook.yml b/tests/playbook.yml index d8f9993176fd2f18f48877c622b9fbe181880f6a..15f954d92e9cfb5bb683e290f9308640655df80b 100644 --- a/tests/playbook.yml +++ b/tests/playbook.yml @@ -1,4 +1,9 @@ --- +- hosts: ufw-xenial + gather_facts: false + roles: [adarnimrod.debian-bootstrap] + - hosts: all + strategy: free roles: - - role: ansible-role-ufw + - role: ufw diff --git a/tests/requirements.txt b/tests/requirements.txt index 0588c359a06c17f6d8a27f8d19be6cf89b2758b8..70cb7661036d9bd7cc73bfb2f4f8978edce7ea4c 100644 --- a/tests/requirements.txt +++ b/tests/requirements.txt @@ -1,6 +1,8 @@ ansible==2.2.0.0 -testinfra==1.4.3 -molecule==1.13.0 -ansible-lint==3.4.4 -pre-commit==0.9.3 +testinfra==1.4.5 +molecule==1.16.1 +ansible-lint==3.4.8 +pre-commit==0.9.4 piprot==0.9.7 +python-vagrant==0.5.14 +docker-py==1.10.6 diff --git a/tests/requirements.yml b/tests/requirements.yml index 8b9b2bcba3b4459621ff239243ac0375a081f20a..cdc294cd67e8c5b70eed5178580e6edde25e10bb 100644 --- a/tests/requirements.yml +++ b/tests/requirements.yml @@ -1,7 +1,3 @@ --- -- src: https://www.shore.co.il/git/ansible-role-openbsd-bootstrap - scm: git - name: openbsd_bootstrap -- src: https://www.shore.co.il/git/ansible-role-debian-bootstrap - scm: git - name: debian_bootstrap +- src: adarnimrod.openbsd-bootstrap +- src: adarnimrod.debian-bootstrap diff --git a/tests/test_example.py b/tests/test_example.py index 12d4c7a5294fc8128e8ae695e8afaaa62a002f9b..aaea50030b9784f0528df9b936cf1903d3af5994 100644 --- a/tests/test_example.py +++ b/tests/test_example.py @@ -1,7 +1,12 @@ +from testinfra.utils.ansible_runner import AnsibleRunner + +testinfra_hosts = AnsibleRunner('.molecule/ansible_inventory').get_hosts('all') + + def test_example(Command): assert Command('uname').rc == 0 def test_root(Command, Sudo): with Sudo(): - assert Command('whoami').stdout == 'root' + assert Command('whoami').stdout.strip() == 'root' diff --git a/tests/test_ufw.py b/tests/test_ufw.py index 72c7abc204110280432d03b5f7f0e69d5b9eb78b..1e6842661ceb3e7c46aa81de2eae1aebc766dcb6 100644 --- a/tests/test_ufw.py +++ b/tests/test_ufw.py @@ -1,2 +1,7 @@ +from testinfra.utils.ansible_runner import AnsibleRunner + +testinfra_hosts = AnsibleRunner('.molecule/ansible_inventory').get_hosts('all') + + def test_ufw(Command): assert 'Status: active' in Command('ufw status').stdout diff --git a/vars/main.yml b/vars/main.yml index 9f57584a45da6a0f837a3e69211ae17df849911e..7a4698f57cb45f484cbc00d9f16241759c552077 100644 --- a/vars/main.yml +++ b/vars/main.yml @@ -1,2 +1,2 @@ --- -# vars file for ansible-role-ufw +# vars file for ufw