diff --git a/aws/bootnode.yml b/aws/bootnode.yml index 78ceeee..09cdadd 100644 --- a/aws/bootnode.yml +++ b/aws/bootnode.yml @@ -12,6 +12,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 22 diff --git a/aws/explorer.yml b/aws/explorer.yml index 46faf51..d7b6d53 100644 --- a/aws/explorer.yml +++ b/aws/explorer.yml @@ -12,6 +12,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 22 diff --git a/aws/group_vars/all.yml.example b/aws/group_vars/all.yml.example index 3e472b0..55a32d7 100644 --- a/aws/group_vars/all.yml.example +++ b/aws/group_vars/all.yml.example @@ -49,6 +49,7 @@ secret_key: XXXX awskeypair_name: "keypairname" region: "us-east-1" +vpc_id: "vpc-ID-number" vpc_subnet_id: "subnet-ID-number" MAIN_REPO_FETCH: "poanetwork" diff --git a/aws/moc.yml b/aws/moc.yml index e130831..81d44b0 100644 --- a/aws/moc.yml +++ b/aws/moc.yml @@ -12,6 +12,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 22 diff --git a/aws/netstat.yml b/aws/netstat.yml index 8e1b4ae..0e44f23 100644 --- a/aws/netstat.yml +++ b/aws/netstat.yml @@ -12,6 +12,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 22 diff --git a/aws/roles/bootnode-access/tasks/ec2.yml b/aws/roles/bootnode-access/tasks/ec2.yml index 92aed30..e80bdcc 100644 --- a/aws/roles/bootnode-access/tasks/ec2.yml +++ b/aws/roles/bootnode-access/tasks/ec2.yml @@ -8,6 +8,7 @@ description: "Default security group" region: "{{ region }}" purge_rules: true + vpc_id: "{{ vpc_id }}" - name: Allow outbound traffic delegate_to: localhost @@ -19,6 +20,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules_egress: - proto: all from_port: all @@ -35,6 +37,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -54,6 +57,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 443 @@ -70,6 +74,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -90,6 +95,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" diff --git a/aws/roles/explorer-access/tasks/ec2.yml b/aws/roles/explorer-access/tasks/ec2.yml index 5b24ef3..8e4bc70 100644 --- a/aws/roles/explorer-access/tasks/ec2.yml +++ b/aws/roles/explorer-access/tasks/ec2.yml @@ -8,6 +8,7 @@ description: "Default security group" region: "{{ region }}" purge_rules: true + vpc_id: "{{ vpc_id }}" - name: Allow outbound traffic delegate_to: localhost @@ -19,6 +20,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules_egress: - proto: all from_port: all @@ -35,6 +37,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -54,6 +57,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 443 @@ -70,6 +74,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -93,6 +98,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" diff --git a/aws/roles/moc-access/tasks/ec2.yml b/aws/roles/moc-access/tasks/ec2.yml index 916cfbc..0bdd4df 100644 --- a/aws/roles/moc-access/tasks/ec2.yml +++ b/aws/roles/moc-access/tasks/ec2.yml @@ -8,6 +8,7 @@ description: "Default security group" region: "{{ region }}" purge_rules: true + vpc_id: "{{ vpc_id }}" - name: Allow outbound traffic delegate_to: localhost @@ -19,6 +20,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules_egress: - proto: all from_port: all @@ -35,6 +37,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -54,6 +57,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" diff --git a/aws/roles/netstat-access/tasks/ec2.yml b/aws/roles/netstat-access/tasks/ec2.yml index 8772216..9ad584a 100644 --- a/aws/roles/netstat-access/tasks/ec2.yml +++ b/aws/roles/netstat-access/tasks/ec2.yml @@ -8,6 +8,7 @@ description: "Default security group" region: "{{ region }}" purge_rules: true + vpc_id: "{{ vpc_id }}" - name: Allow outbound traffic delegate_to: localhost @@ -19,6 +20,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules_egress: - proto: all from_port: all @@ -35,6 +37,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -54,6 +57,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 443 @@ -70,6 +74,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" diff --git a/aws/roles/validator-access/tasks/ec2.yml b/aws/roles/validator-access/tasks/ec2.yml index 810f95b..f89cef2 100644 --- a/aws/roles/validator-access/tasks/ec2.yml +++ b/aws/roles/validator-access/tasks/ec2.yml @@ -8,6 +8,7 @@ description: "Default security group" region: "{{ region }}" purge_rules: true + vpc_id: "{{ vpc_id }}" - name: Allow outbound traffic delegate_to: localhost @@ -19,6 +20,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules_egress: - proto: all from_port: all @@ -35,6 +37,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" @@ -54,6 +57,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: "{{ item }}" diff --git a/aws/validator.yml b/aws/validator.yml index 0a365d1..87d7900 100644 --- a/aws/validator.yml +++ b/aws/validator.yml @@ -12,6 +12,7 @@ region: "{{ region }}" purge_rules_egress: false purge_rules: false + vpc_id: "{{ vpc_id }}" rules: - proto: tcp from_port: 22