k8s_firewalld.yml 1.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445
  1. # Copyright 2022 Dell Inc. or its subsidiaries. All Rights Reserved.
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. ---
  15. - name: Configure firewalld on master nodes
  16. firewalld:
  17. port: "{{ item }}"
  18. permanent: yes
  19. state: enabled
  20. with_items: '{{ k8s_master_ports }}'
  21. - name: Open calico UDP ports on the firewall
  22. firewalld:
  23. port: "{{ item }}/udp"
  24. permanent: yes
  25. state: enabled
  26. with_items: "{{ calico_udp_ports }}"
  27. - name: Open calico TCP ports on the firewall
  28. firewalld:
  29. port: "{{ item }}/tcp"
  30. permanent: yes
  31. state: enabled
  32. with_items: "{{ calico_tcp_ports }}"
  33. - name: Masquerade the firewall
  34. command: firewall-cmd --add-masquerade --permanent
  35. changed_when: true
  36. tags: firewalld
  37. - name: Reload firewalld
  38. command: firewall-cmd --reload
  39. changed_when: true