blob: 4b2979887dabda769200c4e29d2cb347419386ae (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
|
---
- name: Install firewalld packages
package:
name: firewalld
state: present
- name: Ensure iptables services are not enabled
systemd:
name: "{{ item }}"
state: stopped
enabled: no
masked: yes
with_items:
- iptables
- ip6tables
register: task_result
failed_when: "task_result|failed and 'could not' not in task_result.msg|lower"
- name: Wait 10 seconds after disabling iptables
pause:
seconds: 10
when: task_result | changed
- name: Start and enable firewalld service
systemd:
name: firewalld
state: started
enabled: yes
masked: no
daemon_reload: yes
register: result
- name: need to pause here, otherwise the firewalld service starting can sometimes cause ssh to fail
pause: seconds=10
when: result | changed
- name: Restart polkitd
systemd:
name: polkit
state: restarted
when: result | changed
# Fix suspected race between firewalld and polkit BZ1436964
- name: Wait for polkit action to have been created
command: pkaction --action-id=org.fedoraproject.FirewallD1.config.info
ignore_errors: true
register: pkaction
changed_when: false
until: pkaction.rc == 0
retries: 6
delay: 10
- name: Add firewalld allow rules
firewalld:
port: "{{ item.port }}"
permanent: true
immediate: true
state: enabled
with_items: "{{ os_firewall_allow }}"
- name: Remove firewalld allow rules
firewalld:
port: "{{ item.port }}"
permanent: true
immediate: true
state: disabled
with_items: "{{ os_firewall_deny }}"
|