diff options
author | Jason DeTiberus <jdetiber@redhat.com> | 2015-02-17 22:33:33 -0500 |
---|---|---|
committer | Jason DeTiberus <jdetiber@redhat.com> | 2015-02-24 23:10:37 -0500 |
commit | 4ac06057c9a77626bb181c22a5f1adc8014b13d2 (patch) | |
tree | c8ab69e2e65de32d2f29771fb47fcce78fe5dd04 /roles/openshift_common/tasks/firewall.yml | |
parent | 114fcaac2a8f8e3d68baf8945f8991b1da9763ee (diff) | |
download | openshift-4ac06057c9a77626bb181c22a5f1adc8014b13d2.tar.gz openshift-4ac06057c9a77626bb181c22a5f1adc8014b13d2.tar.bz2 openshift-4ac06057c9a77626bb181c22a5f1adc8014b13d2.tar.xz openshift-4ac06057c9a77626bb181c22a5f1adc8014b13d2.zip |
create openshift_common role
- move common openshift logic into openshift_common
- set openshift_common as a dependency for openshift_node and openshift_master
- rename role variables to openshift_* to be more descriptive
- start recording local_facts on the openshift hosts
- clean up firewalld config to be a bit more dry
- Update firewall ports for https, make sure http rules are removed
- Replace references to ansible_eth0.ipv4.address with
ansible_default_ipv4.address
Diffstat (limited to 'roles/openshift_common/tasks/firewall.yml')
-rw-r--r-- | roles/openshift_common/tasks/firewall.yml | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/roles/openshift_common/tasks/firewall.yml b/roles/openshift_common/tasks/firewall.yml new file mode 100644 index 000000000..514466769 --- /dev/null +++ b/roles/openshift_common/tasks/firewall.yml @@ -0,0 +1,34 @@ +--- +# TODO: Ansible 1.9 will eliminate the need for separate firewalld tasks for +# enabling rules and making them permanent with the immediate flag +- name: "Add firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: false + state: enabled + with_items: allow + when: allow is defined + +- name: "Persist firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: true + state: enabled + with_items: allow + when: allow is defined + +- name: "Remove firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: false + state: disabled + with_items: deny + when: deny is defined + +- name: "Persist removal of firewalld allow rules" + firewalld: + port: "{{ item.port }}" + permanent: true + state: disabled + with_items: deny + when: deny is defined |