diff --git a/01_AnsibleAzure.yaml b/01_AnsibleAzure.yaml index d273650..e62290e 100644 --- a/01_AnsibleAzure.yaml +++ b/01_AnsibleAzure.yaml @@ -1,113 +1,116 @@ -Créer le fichier infra_azure.yml : - name: Déployer une infrastructure Azure complète - hosts: localhost - gather_facts: no - vars: - location: "eastus" - resource_group: "ResourceGroup_Genthon_Fayard" - virtual_network: "VNet_Genthon_Fayard" - subnet: "Subnet_Genthon_Fayard" - IP_publique: "PublicIP_Genthon_Fayard" - NSG: "NSG_Genthon_Fayard" - VM: "UbuntuVMGenthonFayard" - network_interface: "VMNic_Genthon_Fayard" - vm_size: "Standard_DS1_v2" - os_type: "Linux" - offer: "UbuntuServer" - publisher: "Canonical" - sku: "18.04-LTS" - version: "latest" - admin_username: "azureuser" - admin_password: "{{ lookup('community.general.random_string', length=20, special=True) }}" - vars_files: - - secrets.yml # Charger le fichier Vault contenant les variables sensibles - tasks: - # Créer un Resource Group - - name: Créer un Resource Group - azure.azcollection.azure_rm_resourcegroup: - name: "{{ resource_group }}" - location: "{{ location }}" - # Créer un Virtual Network - - name: Créer un Virtual Network - azure.azcollection.azure_rm_virtualnetwork: - name: "{{ virtual_network }}" - resource_group: "{{ resource_group }}" - location: "{{ location }}" - address_prefixes: - - "10.0.0.0/16" - # Créer un Subnet - - name: Créer un Subnet - azure.azcollection.azure_rm_subnet: - name: "{{ subnet }}" - resource_group: "{{ resource_group }}" - virtual_network: "{{ virtual_network }}" - address_prefix: "10.0.1.0/24" - # Créer une IP publique - - name: Créer une IP publique - azure.azcollection.azure_rm_publicipaddress: - name: "{{ IP_publique }}" - resource_group: "{{ resource_group }}" - allocation_method: Static - location: "{{ location }}" - # Créer un Network Security Group - - name: Créer un Network Security Group (NSG) - azure.azcollection.azure_rm_securitygroup: - name: "{{ NSG }}" - resource_group: "{{ resource_group }}" - location: "{{ location }}" - rules: - - name: Allow-SSH - protocol: Tcp - destination_port_range: 22 - access: Allow - direction: Inbound - priority: 100 - source_address_prefix: '*' - destination_address_prefix: '*' - - name: Allow-RDP - protocol: Tcp - destination_port_range: 3389 - access: Allow - direction: Inbound - priority: 110 - source_address_prefix: '*' - destination_address_prefix: '*' - - name: AllowICMP - priority: 1002 - direction: Inbound - access: Allow - protocol: ICMP - source_port_range: '*' - destination_port_range: '*' - source_address_prefix: '*' - destination_address_prefix: '*' - # Créer une interface réseau (NIC) - - name: Créer une interface réseau pour la VM - azure.azcollection.azure_rm_networkinterface: - name: "{{ network_interface }}" - resource_group: "{{ resource_group }}" - ANSIBLE Page 3 - resource_group: "{{ resource_group }}" - location: "{{ location }}" - security_group: "{{ NSG }}" - virtual_network: "{{ virtual_network }}" - subnet_name: "{{ subnet }}" - ip_configurations: - - name: "ipconfig" - public_ip_address_name: "{{ IP_publique }}" - # Créer une VM Linux (exemple avec Ubuntu) - - name: Créer une VM Linux Ubuntu - azure.azcollection.azure_rm_virtualmachine: - name: "{{ VM }}" - resource_group: "{{ resource_group }}" - location: "{{ location }}" - vm_size: "{{ vm_size }}" - admin_username: "{{ admin_username }}" - admin_password: "{{ admin_password }}" - network_interfaces: "{{ network_interface }}" - os_type: "{{ os_type }}" - image: - offer: "{{ offer }}" - publisher: "{{ publisher }}" - sku: "{{ sku }}" - version: "{{ version }}" \ No newline at end of file + hosts: localhost + gather_facts: no + vars: + location: "eastus" + resource_group: "ResourceGroup_Genthon_Fayard" + virtual_network: "VNet_Genthon_Fayard" + subnet: "Subnet_Genthon_Fayard" + IP_publique: "PublicIP_Genthon_Fayard" + NSG: "NSG_Genthon_Fayard" + VM: "UbuntuVMGenthonFayard" + network_interface: "VMNic_Genthon_Fayard" + vm_size: "Standard_DS1_v2" + os_type: "Linux" + offer: "UbuntuServer" + publisher: "Canonical" + sku: "18.04-LTS" + version: "latest" + admin_username: "azureuser" + admin_password: "{{ lookup('community.general.random_string', length=20, special=True) }}" + vars_files: + - secrets.yml # Charger le fichier Vault contenant les variables sensibles + tasks: + # Créer un Resource Group + - name: Créer un Resource Group + azure.azcollection.azure_rm_resourcegroup: + name: "{{ resource_group }}" + location: "{{ location }}" + + # Créer un Virtual Network + - name: Créer un Virtual Network + azure.azcollection.azure_rm_virtualnetwork: + name: "{{ virtual_network }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + address_prefixes: + - "10.0.0.0/16" + + # Créer un Subnet + - name: Créer un Subnet + azure.azcollection.azure_rm_subnet: + name: "{{ subnet }}" + resource_group: "{{ resource_group }}" + virtual_network: "{{ virtual_network }}" + address_prefix: "10.0.1.0/24" + + # Créer une IP publique + - name: Créer une IP publique + azure.azcollection.azure_rm_publicipaddress: + name: "{{ IP_publique }}" + resource_group: "{{ resource_group }}" + allocation_method: Static + location: "{{ location }}" + + # Créer un Network Security Group + - name: Créer un Network Security Group (NSG) + azure.azcollection.azure_rm_securitygroup: + name: "{{ NSG }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + rules: + - name: Allow-SSH + protocol: Tcp + destination_port_range: 22 + access: Allow + direction: Inbound + priority: 100 + source_address_prefix: '*' + destination_address_prefix: '*' + - name: Allow-RDP + protocol: Tcp + destination_port_range: 3389 + access: Allow + direction: Inbound + priority: 110 + source_address_prefix: '*' + destination_address_prefix: '*' + - name: AllowICMP + priority: 1002 + direction: Inbound + access: Allow + protocol: ICMP + source_port_range: '*' + destination_port_range: '*' + source_address_prefix: '*' + destination_address_prefix: '*' + + # Créer une interface réseau (NIC) + - name: Créer une interface réseau pour la VM + azure.azcollection.azure_rm_networkinterface: + name: "{{ network_interface }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + security_group: "{{ NSG }}" + virtual_network: "{{ virtual_network }}" + subnet_name: "{{ subnet }}" + ip_configurations: + - name: "ipconfig" + public_ip_address_name: "{{ IP_publique }}" + + # Créer une VM Linux (exemple avec Ubuntu) + - name: Créer une VM Linux Ubuntu + azure.azcollection.azure_rm_virtualmachine: + name: "{{ VM }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + vm_size: "{{ vm_size }}" + admin_username: "{{ admin_username }}" + admin_password: "{{ admin_password }}" + network_interfaces: "{{ network_interface }}" + os_type: "{{ os_type }}" + image: + offer: "{{ offer }}" + publisher: "{{ publisher }}" + sku: "{{ sku }}" + version: "{{ version }}" \ No newline at end of file