From 05e189a039dada5edc4f9afb700b594c4dea4c9b Mon Sep 17 00:00:00 2001 From: Russell Teague Date: Mon, 28 Nov 2016 14:43:47 -0500 Subject: Enable firewalld by default --- roles/os_firewall/defaults/main.yml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) (limited to 'roles/os_firewall/defaults') diff --git a/roles/os_firewall/defaults/main.yml b/roles/os_firewall/defaults/main.yml index c870a301a..4c544122f 100644 --- a/roles/os_firewall/defaults/main.yml +++ b/roles/os_firewall/defaults/main.yml @@ -1,9 +1,7 @@ --- os_firewall_enabled: True -# TODO: Upstream kubernetes only supports iptables currently -# TODO: it might be possible to still use firewalld if we wire up the created -# chains with the public zone (or the zone associated with the correct -# interfaces) -os_firewall_use_firewalld: False +# firewalld is not supported on Atomic Host +# https://bugzilla.redhat.com/show_bug.cgi?id=1403331 +os_firewall_use_firewalld: "{{ False if openshift.common.is_atomic | bool else True }}" os_firewall_allow: [] os_firewall_deny: [] -- cgit v1.2.1