|
@@ -28,7 +28,7 @@
|
|
|
|
|
|
- name: Configure firewalld on master nodes
|
|
|
firewalld:
|
|
|
- port: "{{ item }}/tcp"
|
|
|
+ port: "{{ item }}"
|
|
|
permanent: yes
|
|
|
state: enabled
|
|
|
with_items: '{{ k8s_master_ports }}'
|
|
@@ -71,6 +71,11 @@
|
|
|
when: hostvars['127.0.0.1']['k8s_cni'] == "calico"
|
|
|
tags: firewalld
|
|
|
|
|
|
+- name: Masquerade the firewall
|
|
|
+ command: firewall-cmd --add-masquerade --permanent
|
|
|
+ changed_when: true
|
|
|
+ tags: firewalld
|
|
|
+
|
|
|
- name: Reload firewalld
|
|
|
command: firewall-cmd --reload
|
|
|
changed_when: true
|
|
@@ -81,4 +86,4 @@
|
|
|
name: firewalld
|
|
|
state: stopped
|
|
|
enabled: no
|
|
|
- tags: firewalld
|
|
|
+ tags: firewalld
|