summaryrefslogtreecommitdiffstats
path: root/roles/docker
diff options
context:
space:
mode:
authorScott Dodson <sdodson@redhat.com>2017-05-10 15:10:32 -0400
committerScott Dodson <sdodson@redhat.com>2017-05-10 15:10:32 -0400
commitcc18aa0edf3a55954c2227c01eee25d12766702a (patch)
treecba62c28f1adde14072599bf4023ee6db3c99818 /roles/docker
parent5a4365e765e16a4401d10f0bd42a7d3e194d4ab0 (diff)
downloadopenshift-cc18aa0edf3a55954c2227c01eee25d12766702a.tar.gz
openshift-cc18aa0edf3a55954c2227c01eee25d12766702a.tar.bz2
openshift-cc18aa0edf3a55954c2227c01eee25d12766702a.tar.xz
openshift-cc18aa0edf3a55954c2227c01eee25d12766702a.zip
Default to iptables on master
We did this in 3.5 but never on master and we never came back to add migration support. So we'll revert this on master and if/when we add migration support we'll switch the default.
Diffstat (limited to 'roles/docker')
-rw-r--r--roles/docker/tasks/package_docker.yml2
-rw-r--r--roles/docker/templates/systemcontainercustom.conf.j22
2 files changed, 2 insertions, 2 deletions
diff --git a/roles/docker/tasks/package_docker.yml b/roles/docker/tasks/package_docker.yml
index 10fb5772c..e101730d2 100644
--- a/roles/docker/tasks/package_docker.yml
+++ b/roles/docker/tasks/package_docker.yml
@@ -46,7 +46,7 @@
template:
dest: "{{ docker_systemd_dir }}/custom.conf"
src: custom.conf.j2
- when: not os_firewall_use_firewalld | default(True) | bool
+ when: not os_firewall_use_firewalld | default(False) | bool
- stat: path=/etc/sysconfig/docker
register: docker_check
diff --git a/roles/docker/templates/systemcontainercustom.conf.j2 b/roles/docker/templates/systemcontainercustom.conf.j2
index a4fb01d2b..1faad506a 100644
--- a/roles/docker/templates/systemcontainercustom.conf.j2
+++ b/roles/docker/templates/systemcontainercustom.conf.j2
@@ -10,7 +10,7 @@ ENVIRONMENT=HTTPS_PROXY={{ docker_http_proxy }}
{%- if "no_proxy" in openshift.common %}
ENVIRONMENT=NO_PROXY={{ docker_no_proxy }}
{%- endif %}
-{%- if os_firewall_use_firewalld|default(true) %}
+{%- if os_firewall_use_firewalld|default(false) %}
[Unit]
Wants=iptables.service
After=iptables.service