By default, inbound connections are not allowed to any of the instances. One way to allow the traffic is by allowing incoming connections to a certain port of instances carrying a particular tag. For example, we can tag all the webservers as http and allow incoming connections to port 80 and 8080 for all the instances carrying the http tag.
Managing network and firewall rules
How to do it...
- We will create a firewall rule with source tag using the gce_net module:
- name: Create Firewall Rule with Source Tags
gce_net:
name: my-network
fwname: "allow-http"
allowed: tcp:80,8080
state: "present"
target_tags: "http"
subnet_region: us-west1
service_account_email: "{{ service_account_email...