feat: add option to enable or disable ipv4/ipv6

This commit is contained in:
Adrien Waksberg 2017-10-15 02:23:00 +02:00
parent cf18a2e564
commit 9944b4e2fc
5 changed files with 17 additions and 2 deletions

View file

@ -13,6 +13,8 @@ None
* `bind_role` - the role `master` or `slave`, don't generate dnssec key on `slave` * `bind_role` - the role `master` or `slave`, don't generate dnssec key on `slave`
* `bind_zones` - the dns zones * `bind_zones` - the dns zones
* `bind_listen_ipv4` - enable or disable ip v4 support (default: true)
* `bind_listen_ipv6` - enable or disable ip v6 support (default: true)
## How to use ## How to use

3
defaults/main.yml Normal file
View file

@ -0,0 +1,3 @@
---
bind_listen_ipv4: true
bind_listen_ipv6: true

View file

@ -32,6 +32,15 @@ describe file('/etc/bind/named.conf.local') do
it { should contain '4.2.2.4' } it { should contain '4.2.2.4' }
end end
describe file('/etc/bind/named.conf.options') do
it { should be_file }
it { should be_mode 644 }
it { should be_owned_by 'root' }
it { should be_grouped_into 'root' }
it { should contain 'listen-on { any; };' }
it { should contain 'listen-on-v6 { none; };' }
end
describe port(53) do describe port(53) do
it { should be_listening.with('tcp') } it { should be_listening.with('tcp') }
it { should be_listening.with('udp') } it { should be_listening.with('udp') }

View file

@ -8,8 +8,8 @@ options {
dnssec-lookaside auto; dnssec-lookaside auto;
auth-nxdomain no; # conform to RFC1035 auth-nxdomain no; # conform to RFC1035
listen-on { any; }; listen-on { {% if bind_listen_ipv4 %}any{% else %}none{% endif %}; };
listen-on-v6 { none; }; listen-on-v6 { {% if bind_listen_ipv6 %}any{% else %}none{% endif %}; };
version none; version none;
}; };

View file

@ -1,6 +1,7 @@
- hosts: localhost - hosts: localhost
connection: local connection: local
vars: vars:
bind_listen_ipv6: false
bind_role: master bind_role: master
bind_zones: bind_zones:
test.local: test.local: