浏览代码

Issue #502: Updated firewalld ports

Signed-off-by: blesson-james <blesson_james@Dellteam.com>
blesson-james 3 年之前
父节点
当前提交
ec0b0d0c2f
共有 1 个文件被更改,包括 7 次插入2 次删除
  1. 7 2
      control_plane/roles/control_plane_k8s/tasks/k8s_firewalld.yml

+ 7 - 2
control_plane/roles/control_plane_k8s/tasks/k8s_firewalld.yml

@@ -26,7 +26,7 @@
 
 - name: Configure firewalld on master nodes
   firewalld:
-    port: "{{ item }}/tcp"
+    port: "{{ item }}"
     permanent: yes
     state: enabled
   with_items: '{{ k8s_master_ports }}'
@@ -45,6 +45,11 @@
     state: enabled
   with_items: "{{ calico_tcp_ports }}"
 
+- name: Masquerade the firewall
+  command: firewall-cmd --add-masquerade --permanent
+  changed_when: true
+  tags: firewalld
+
 - name: Reload firewalld
   command: firewall-cmd --reload
   changed_when: true
@@ -53,4 +58,4 @@
   service:
     name: firewalld
     state: stopped
-    enabled: no
+    enabled: no