diff options
author | Jhon Honce <jhonce@redhat.com> | 2015-02-20 14:29:02 -0700 |
---|---|---|
committer | Jhon Honce <jhonce@redhat.com> | 2015-02-20 14:29:02 -0700 |
commit | 551dccac66421664a87de523c0e3cc2a6392beb9 (patch) | |
tree | 4e4ab1aa7d6ee4d4425b0a126f028f69b62c9c67 /roles/openshift_master | |
parent | ff402ef719a74a76407fef2569a11ee85dfb1093 (diff) | |
parent | dcd84a6c524c217432f4b529b66da165bf4ff3e9 (diff) | |
download | openshift-551dccac66421664a87de523c0e3cc2a6392beb9.tar.gz openshift-551dccac66421664a87de523c0e3cc2a6392beb9.tar.bz2 openshift-551dccac66421664a87de523c0e3cc2a6392beb9.tar.xz openshift-551dccac66421664a87de523c0e3cc2a6392beb9.zip |
Merge pull request #74 from detiber/ssl2
Additional changes for SSL enabling the api and console ports
Diffstat (limited to 'roles/openshift_master')
-rw-r--r-- | roles/openshift_master/tasks/main.yml | 25 |
1 files changed, 14 insertions, 11 deletions
diff --git a/roles/openshift_master/tasks/main.yml b/roles/openshift_master/tasks/main.yml index 9f28a3469..96b889804 100644 --- a/roles/openshift_master/tasks/main.yml +++ b/roles/openshift_master/tasks/main.yml @@ -13,21 +13,24 @@ regexp: "{{ item.regex }}" line: "{{ item.line }}" with_items: - - { regex: '^OPTIONS=', line: 'OPTIONS=\"--public-master={{ oo_public_ip }} --nodes={{ oo_node_ips | join(",") }} --loglevel=5\"' } + - { regex: '^OPTIONS=', line: "OPTIONS=\"--public-master={{ oo_public_ip }} --nodes={{ oo_node_ips | join(",") }} --loglevel=5\"" } notify: - restart openshift-master -- name: Open firewalld port for etcd embedded in OpenShift - firewalld: port=4001/tcp permanent=false state=enabled +# Open etcd embedded, etcd embedded peer, openshift api, and +# openshift client ports +- name: Open firewalld ports for openshift-master + firewalld: port={{ item[0] }} permanent={{ item[1] }} state=enabled + with_nested: + - [ 4001/tcp, 7001/tcp, 8443/tcp, 8444/tcp ] + - [ true, false ] -- name: Save firewalld port for etcd embedded in - firewalld: port=4001/tcp permanent=true state=enabled - -- name: Open firewalld port for OpenShift - firewalld: port=8080/tcp permanent=false state=enabled - -- name: Save firewalld port for OpenShift - firewalld: port=8080/tcp permanent=true state=enabled +# Disable previously exposed ports that are no longer needed +- name: Close firewalld ports for openshift-master that are no longer needed + firewalld: port={{ item[0] }} permanent={{ item[1] }} state=enabled + with_nested: + - [ 8080/tcp ] + - [ true, false ] - name: Enable OpenShift service: name=openshift-master enabled=yes state=started |