12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485 |
- ---
- - name: Install firewalld
- package:
- name: firewalld
- state: present
- tags: firewalld
- - name: Start and enable firewalld
- service:
- name: firewalld
- state: started
- enabled: yes
- tags: firewalld
- - name: Configure firewalld on master nodes
- firewalld:
- port: "{{ item }}/tcp"
- permanent: yes
- state: enabled
- with_items: '{{ k8s_master_ports }}'
- when: "'manager' in group_names"
- tags: firewalld
- - name: Configure firewalld on compute nodes
- firewalld:
- port: "{{ item }}/tcp"
- permanent: yes
- state: enabled
- with_items: '{{ k8s_worker_ports }}'
- when: "'compute' in group_names"
- tags: firewalld
- - name: Open flannel ports on the firewall
- firewalld:
- port: "{{ item }}/udp"
- permanent: yes
- state: enabled
- with_items: "{{ flannel_udp_ports }}"
- when: k8s_cni == "flannel"
- tags: firewalld
- - name: Open calico UDP ports on the firewall
- firewalld:
- port: "{{ item }}/udp"
- permanent: yes
- state: enabled
- with_items: "{{ calico_udp_ports }}"
- when: k8s_cni == "calico"
- tags: firewalld
- - name: Open calico TCP ports on the firewall
- firewalld:
- port: "{{ item }}/tcp"
- permanent: yes
- state: enabled
- with_items: "{{ calico_tcp_ports }}"
- when: k8s_cni == "calico"
- tags: firewalld
- - name: Reload firewalld
- command: firewall-cmd --reload
- changed_when: true
- tags: firewalld
- - name: Stop and disable firewalld
- service:
- name: firewalld
- state: stopped
- enabled: no
- tags: firewalld
|