ansible/172-ansible-linux-hardening.yml

- hosts: all
  become: true
  tasks:
    - apt:
        name: [ufw, fail2ban, unattended-upgrades]
        state: present
        update_cache: true
    - ufw:
        rule: allow
        name: OpenSSH
    - ufw:
        state: enabled