mirror of
https://github.com/k3s-io/k3s-ansible.git
synced 2025-12-25 00:12:37 +01:00
Set firewall rules for custom CIDR ranges (#293)
Signed-off-by: laszlojau <49835454+laszlojau@users.noreply.github.com>
This commit is contained in:
@@ -57,9 +57,7 @@
|
|||||||
community.general.ufw:
|
community.general.ufw:
|
||||||
rule: allow
|
rule: allow
|
||||||
src: '{{ item }}'
|
src: '{{ item }}'
|
||||||
loop:
|
loop: "{{ (cluster_cidr + ',' + service_cidr) | split(',') }}"
|
||||||
- 10.42.0.0/16 # Pods
|
|
||||||
- 10.43.0.0/16 # Services
|
|
||||||
|
|
||||||
- name: Allow Firewalld Exceptions
|
- name: Allow Firewalld Exceptions
|
||||||
when:
|
when:
|
||||||
@@ -90,9 +88,7 @@
|
|||||||
state: enabled
|
state: enabled
|
||||||
permanent: true
|
permanent: true
|
||||||
immediate: true
|
immediate: true
|
||||||
loop:
|
loop: "{{ (cluster_cidr + ',' + service_cidr) | split(',') }}"
|
||||||
- 10.42.0.0/16 # Pods
|
|
||||||
- 10.43.0.0/16 # Services
|
|
||||||
|
|
||||||
- name: Add br_netfilter to /etc/modules-load.d/
|
- name: Add br_netfilter to /etc/modules-load.d/
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
|
|||||||
3
roles/prereq/vars/main.yml
Normal file
3
roles/prereq/vars/main.yml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
cluster_cidr: "{{ (server_config_yaml | from_yaml)['cluster-cidr'] | default('10.42.0.0/16') }}"
|
||||||
|
service_cidr: "{{ (server_config_yaml | from_yaml)['service-cidr'] | default('10.43.0.0/16') }}"
|
||||||
Reference in New Issue
Block a user