main.yml 1.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940
  1. ---
  2. openshift_node_ips: []
  3. # TODO: update setting these values based on the facts
  4. os_firewall_allow:
  5. - service: etcd embedded
  6. port: 4001/tcp
  7. - service: api server https
  8. port: "{{ openshift.master.api_port }}/tcp"
  9. - service: api controllers https
  10. port: "{{ openshift.master.controllers_port }}/tcp"
  11. - service: skydns tcp
  12. port: "{{ openshift.master.dns_port }}/tcp"
  13. - service: skydns udp
  14. port: "{{ openshift.master.dns_port }}/udp"
  15. # On HA masters version_gte facts are not properly set so open port 53
  16. # whenever we're not certain of the need
  17. - service: legacy skydns tcp
  18. port: "53/tcp"
  19. when: "{{ 'version' not in openshift.common or openshift.common.version == None }}"
  20. - service: legacy skydns udp
  21. port: "53/udp"
  22. when: "{{ 'version' not in openshift.common or openshift.common.version == None }}"
  23. - service: Fluentd td-agent tcp
  24. port: 24224/tcp
  25. - service: Fluentd td-agent udp
  26. port: 24224/udp
  27. - service: pcsd
  28. port: 2224/tcp
  29. - service: Corosync UDP
  30. port: 5404/udp
  31. - service: Corosync UDP
  32. port: 5405/udp
  33. os_firewall_deny:
  34. - service: api server http
  35. port: 8080/tcp
  36. - service: former etcd peer port
  37. port: 7001/tcp
  38. openshift_version: "{{ openshift_pkg_version | default(openshift_image_tag | default(openshift.docker.openshift_image_tag | default(''))) }}"