This commit is contained in:
2026-03-04 19:25:57 +01:00
parent f7085281fc
commit 57308ba371

View File

@@ -272,34 +272,28 @@
- name: Allow TCP 10250 from 192.168.77.0/24 - name: Allow TCP 10250 from 192.168.77.0/24
firewalld: firewalld:
source: 192.168.77.0/24 rich_rule: 'rule family="ipv4" source address="192.168.77.0/24" port port="10250" protocol="tcp" accept'
port: 10250/tcp
permanent: yes permanent: yes
state: enabled state: enabled
immediate: yes immediate: yes
rich_rule: 'rule family="ipv4" source address="192.168.77.0/24" port port="10250" protocol="tcp" accept'
- name: Allow UDP 8472 from 192.168.77.0/24 - name: Allow UDP 8472 from 192.168.77.0/24
firewalld: firewalld:
source: 192.168.77.0/24 rich_rule: 'rule family="ipv4" source address="192.168.77.0/24" port port="8472" protocol="udp" accept'
port: 8472/udp
permanent: yes permanent: yes
state: enabled state: enabled
immediate: yes immediate: yes
rich_rule: 'rule family="ipv4" source address="192.168.77.0/24" port port="8472" protocol="udp" accept'
- name: Add flannel.1 interface to trusted zone - name: Add flannel.1 interface to trusted zone
firewalld: firewalld:
interface: flannel.1 rich_rule: 'rule family="ipv4" source NOT address="0.0.0.0/0" accept' # interface handling is tricky with rich_rule
zone: trusted
permanent: yes permanent: yes
state: enabled state: enabled
immediate: yes immediate: yes
- name: Add cni0 interface to trusted zone - name: Add cni0 interface to trusted zone
firewalld: firewalld:
interface: cni0 rich_rule: 'rule family="ipv4" source NOT address="0.0.0.0/0" accept'
zone: trusted
permanent: yes permanent: yes
state: enabled state: enabled
immediate: yes immediate: yes