summaryrefslogtreecommitdiffstats
path: root/roles/os_firewall/defaults
diff options
context:
space:
mode:
authorAndrew Butcher <abutcher@redhat.com>2016-05-02 14:20:36 -0400
committerAndrew Butcher <abutcher@redhat.com>2016-05-02 14:58:00 -0400
commit507a69ed1d1bb3f19ed49d21685840fbd95d1465 (patch)
tree0ecd3c126eca737110dbc31572a3b6836c992e8a /roles/os_firewall/defaults
parent7a6fae4d524dd89b7098debe5bf428b144f66f46 (diff)
downloadopenshift-507a69ed1d1bb3f19ed49d21685840fbd95d1465.tar.gz
openshift-507a69ed1d1bb3f19ed49d21685840fbd95d1465.tar.bz2
openshift-507a69ed1d1bb3f19ed49d21685840fbd95d1465.tar.xz
openshift-507a69ed1d1bb3f19ed49d21685840fbd95d1465.zip
Default os_firewall_use_firewalld to false in os_firewall and remove overrides.
Diffstat (limited to 'roles/os_firewall/defaults')
-rw-r--r--roles/os_firewall/defaults/main.yml6
1 files changed, 5 insertions, 1 deletions
diff --git a/roles/os_firewall/defaults/main.yml b/roles/os_firewall/defaults/main.yml
index 20413d563..c870a301a 100644
--- a/roles/os_firewall/defaults/main.yml
+++ b/roles/os_firewall/defaults/main.yml
@@ -1,5 +1,9 @@
---
os_firewall_enabled: True
-os_firewall_use_firewalld: True
+# TODO: Upstream kubernetes only supports iptables currently
+# TODO: it might be possible to still use firewalld if we wire up the created
+# chains with the public zone (or the zone associated with the correct
+# interfaces)
+os_firewall_use_firewalld: False
os_firewall_allow: []
os_firewall_deny: []