diff --git a/roles/dns/tasks/main.yml b/roles/dns/tasks/main.yml index 0a361856..46ec7bac 100644 --- a/roles/dns/tasks/main.yml +++ b/roles/dns/tasks/main.yml @@ -26,17 +26,16 @@ - meta: flush_handlers +- name: Ubuntu | Stop and disable dnscrypt-proxy socket before starting service + systemd: + name: dnscrypt-proxy.socket + state: stopped + enabled: false + failed_when: false + when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' + - name: dnscrypt-proxy enabled and started service: name: dnscrypt-proxy state: started enabled: true - -- name: Ubuntu | Disable dnscrypt-proxy socket activation after service start - systemd: - name: dnscrypt-proxy.socket - state: stopped - enabled: false - masked: true - failed_when: false - when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu' diff --git a/roles/dns/tasks/ubuntu.yml b/roles/dns/tasks/ubuntu.yml index 6f3d8781..a3068f22 100644 --- a/roles/dns/tasks/ubuntu.yml +++ b/roles/dns/tasks/ubuntu.yml @@ -58,8 +58,6 @@ [Unit] After=systemd-resolved.service Requires=systemd-resolved.service - # Remove socket dependency to allow direct binding - TriggeredBy= [Service] AmbientCapabilities=CAP_NET_BIND_SERVICE