mirror of
https://github.com/k3s-io/k3s-ansible.git
synced 2025-12-25 00:12:37 +01:00
Set firewall rules for custom CIDR ranges (#293)
Signed-off-by: laszlojau <49835454+laszlojau@users.noreply.github.com>
This commit is contained in:
@@ -57,9 +57,7 @@
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
src: '{{ item }}'
|
||||
loop:
|
||||
- 10.42.0.0/16 # Pods
|
||||
- 10.43.0.0/16 # Services
|
||||
loop: "{{ (cluster_cidr + ',' + service_cidr) | split(',') }}"
|
||||
|
||||
- name: Allow Firewalld Exceptions
|
||||
when:
|
||||
@@ -90,9 +88,7 @@
|
||||
state: enabled
|
||||
permanent: true
|
||||
immediate: true
|
||||
loop:
|
||||
- 10.42.0.0/16 # Pods
|
||||
- 10.43.0.0/16 # Services
|
||||
loop: "{{ (cluster_cidr + ',' + service_cidr) | split(',') }}"
|
||||
|
||||
- name: Add br_netfilter to /etc/modules-load.d/
|
||||
ansible.builtin.copy:
|
||||
|
||||
3
roles/prereq/vars/main.yml
Normal file
3
roles/prereq/vars/main.yml
Normal file
@@ -0,0 +1,3 @@
|
||||
---
|
||||
cluster_cidr: "{{ (server_config_yaml | from_yaml)['cluster-cidr'] | default('10.42.0.0/16') }}"
|
||||
service_cidr: "{{ (server_config_yaml | from_yaml)['service-cidr'] | default('10.43.0.0/16') }}"
|
||||
Reference in New Issue
Block a user