Kernel network namespaces explained
blogs.igalia.com
blogs.igalia.com
Stick them in a netns with only a site-local address and that attack surface reduces massively. Much easier and more performant than trying to close the open doors with iptables.
<rant>
The article and the docs make it pretty clear that this can be accomplished with a couple shell commands. I don't understand why everyone begs for handouts these days. We now have an entire generation of "sysadmins" who refuse the read documentation and can't produce original work. This is not complicated. You do not need a Master's to figure this out.
</rant>
That said, I'm quite certain that Ansible does not support IP namespaces natively, so you'll have to manage this with custom "command:" statements. This means these will fire every time you run the Ansible playbook and they will be listed as an item that changed because Ansible does not internally know how to validate whether or not it needs to take action.
tl;dr read the docs, write a shell script, and/or figure out the most sane way to do this with ansible/salt/puppet/chef/cfengine/whatever because it's 2016 and I'm tired of people begging for someone else to do their work for them.
SubgraphOS uses network namespaces to isolate individual processes (and route all connections over Tor). As a proof-of-concept, I wrote a small binary that wraps arbitrary binaries in customized namespaces and forwards all traffic over tor instead of masquerading: https://github.com/squeed/torbox
Right now, the torsocks command captures all network syscalls via a LD_PRELOAD shim. My goal was to avoid that sort of hackery.
I have services where >30% of my users access the service over IPv6.