diff --git a/01_AnsibleAzure.yaml b/01_AnsibleAzure.yaml index e69de29..d273650 100644 --- a/01_AnsibleAzure.yaml +++ b/01_AnsibleAzure.yaml @@ -0,0 +1,113 @@ +Créer le fichier infra_azure.yml : +- name: Déployer une infrastructure Azure complète + hosts: localhost + gather_facts: no + vars: + location: "eastus" + resource_group: "ResourceGroup_Genthon_Fayard" + virtual_network: "VNet_Genthon_Fayard" + subnet: "Subnet_Genthon_Fayard" + IP_publique: "PublicIP_Genthon_Fayard" + NSG: "NSG_Genthon_Fayard" + VM: "UbuntuVMGenthonFayard" + network_interface: "VMNic_Genthon_Fayard" + vm_size: "Standard_DS1_v2" + os_type: "Linux" + offer: "UbuntuServer" + publisher: "Canonical" + sku: "18.04-LTS" + version: "latest" + admin_username: "azureuser" + admin_password: "{{ lookup('community.general.random_string', length=20, special=True) }}" + vars_files: + - secrets.yml # Charger le fichier Vault contenant les variables sensibles + tasks: + # Créer un Resource Group + - name: Créer un Resource Group + azure.azcollection.azure_rm_resourcegroup: + name: "{{ resource_group }}" + location: "{{ location }}" + # Créer un Virtual Network + - name: Créer un Virtual Network + azure.azcollection.azure_rm_virtualnetwork: + name: "{{ virtual_network }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + address_prefixes: + - "10.0.0.0/16" + # Créer un Subnet + - name: Créer un Subnet + azure.azcollection.azure_rm_subnet: + name: "{{ subnet }}" + resource_group: "{{ resource_group }}" + virtual_network: "{{ virtual_network }}" + address_prefix: "10.0.1.0/24" + # Créer une IP publique + - name: Créer une IP publique + azure.azcollection.azure_rm_publicipaddress: + name: "{{ IP_publique }}" + resource_group: "{{ resource_group }}" + allocation_method: Static + location: "{{ location }}" + # Créer un Network Security Group + - name: Créer un Network Security Group (NSG) + azure.azcollection.azure_rm_securitygroup: + name: "{{ NSG }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + rules: + - name: Allow-SSH + protocol: Tcp + destination_port_range: 22 + access: Allow + direction: Inbound + priority: 100 + source_address_prefix: '*' + destination_address_prefix: '*' + - name: Allow-RDP + protocol: Tcp + destination_port_range: 3389 + access: Allow + direction: Inbound + priority: 110 + source_address_prefix: '*' + destination_address_prefix: '*' + - name: AllowICMP + priority: 1002 + direction: Inbound + access: Allow + protocol: ICMP + source_port_range: '*' + destination_port_range: '*' + source_address_prefix: '*' + destination_address_prefix: '*' + # Créer une interface réseau (NIC) + - name: Créer une interface réseau pour la VM + azure.azcollection.azure_rm_networkinterface: + name: "{{ network_interface }}" + resource_group: "{{ resource_group }}" + ANSIBLE Page 3 + resource_group: "{{ resource_group }}" + location: "{{ location }}" + security_group: "{{ NSG }}" + virtual_network: "{{ virtual_network }}" + subnet_name: "{{ subnet }}" + ip_configurations: + - name: "ipconfig" + public_ip_address_name: "{{ IP_publique }}" + # Créer une VM Linux (exemple avec Ubuntu) + - name: Créer une VM Linux Ubuntu + azure.azcollection.azure_rm_virtualmachine: + name: "{{ VM }}" + resource_group: "{{ resource_group }}" + location: "{{ location }}" + vm_size: "{{ vm_size }}" + admin_username: "{{ admin_username }}" + admin_password: "{{ admin_password }}" + network_interfaces: "{{ network_interface }}" + os_type: "{{ os_type }}" + image: + offer: "{{ offer }}" + publisher: "{{ publisher }}" + sku: "{{ sku }}" + version: "{{ version }}" \ No newline at end of file