# vim: ft=yaml.ansible
---
- name: Allow necessary ports in UFW
community.general.ufw:
rule: allow
port: "{{ item.port }}"
proto: "{{ item.proto | default('tcp') }}"
loop:
- port: '22' # SSH
- port: '80' # HTTP
- port: '443' # HTTPS
- port: '5223' # SimpleXMQ
- port: '10000' # Jitsi Videobridge
proto: udp
- name: Enable UFW
state: enabled
policy: deny