нужно создать несколько SG в aws
- name: sg for ext
ec2_group:
name: "{{ project_name }}-ext"
description: "{{ project_name }} policy for web"
region: "{{ region }}"
rules:
- proto: tcp # https
from_port: 443
to_port: 443
cidr_ip:
0.0.0.0/0 rules_egress:
- proto: all
cidr_ip:
0.0.0.0/0 register: fw-ext
name: "{{ project_name }}-int"
description: "{{ project_name }} pol for int, allow all traf"
region: "{{ region }}"
rules:
- proto: all
cidr_ip:
10.0.0.0/8 register: fw-int