diff options
author | Andrew Butcher <abutcher@redhat.com> | 2016-05-02 14:57:15 -0400 |
---|---|---|
committer | Andrew Butcher <abutcher@redhat.com> | 2016-05-02 14:58:00 -0400 |
commit | 404cf230da83f91a5dd9df1f289da2c6c1b7fee7 (patch) | |
tree | d7a7b30df1f40534f583e1c119f971b3765e6a2e /roles/os_firewall/tasks/firewall/iptables.yml | |
parent | 507a69ed1d1bb3f19ed49d21685840fbd95d1465 (diff) | |
download | openshift-404cf230da83f91a5dd9df1f289da2c6c1b7fee7.tar.gz openshift-404cf230da83f91a5dd9df1f289da2c6c1b7fee7.tar.bz2 openshift-404cf230da83f91a5dd9df1f289da2c6c1b7fee7.tar.xz openshift-404cf230da83f91a5dd9df1f289da2c6c1b7fee7.zip |
Check and unmask iptables/firewalld.
Diffstat (limited to 'roles/os_firewall/tasks/firewall/iptables.yml')
-rw-r--r-- | roles/os_firewall/tasks/firewall/iptables.yml | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/roles/os_firewall/tasks/firewall/iptables.yml b/roles/os_firewall/tasks/firewall/iptables.yml index 070fe6a3a..774916798 100644 --- a/roles/os_firewall/tasks/firewall/iptables.yml +++ b/roles/os_firewall/tasks/firewall/iptables.yml @@ -32,6 +32,24 @@ command: systemctl daemon-reload when: install_result | changed +- name: Determine if iptables service masked + command: > + systemctl is-enabled {{ item }} + with_items: + - iptables + - ip6tables + register: os_firewall_iptables_masked_output + changed_when: false + failed_when: false + +- name: Unmask iptables service + command: > + systemctl unmask {{ item }} + with_items: + - iptables + - ip6tables + when: "'masked' in os_firewall_iptables_masked_output.results | map(attribute='stdout')" + - name: Start and enable iptables service service: name: iptables |