refactor ♻️: Refactor fail2ban tasks for better IPSet management
Some checks failed
ansible-lint / Ansible Lint (push) Failing after 6s
Gitleaks Scan / gitleaks (push) Successful in 5s
Markdown Lint / markdown-lint (push) Successful in 5s

This refactoring removes redundant 'blockinfile' and 'reload' commands in fail2ban tasks, ensuring that IPSet and drop rules are correctly placed. A new handler has been added to reload the PVE firewall after a fail2ban restart.
This commit is contained in:
2026-02-24 18:46:12 +01:00
parent a120b1042b
commit 80b3b82bf6
2 changed files with 12 additions and 15 deletions

View File

@@ -36,3 +36,7 @@
ansible.builtin.systemd:
name: fail2ban
state: restarted
- name: Reload pve firewall
ansible.builtin.command: pve-firewall reload
changed_when: false