iptables.yml 1016 B

12345678910111213141516171819202122232425262728293031323334353637383940414243444546
  1. ---
  2. - name: Ensure firewalld service is not enabled
  3. systemd:
  4. name: firewalld
  5. state: stopped
  6. enabled: no
  7. masked: yes
  8. register: task_result
  9. failed_when:
  10. - task_result is failed
  11. - ('could not' not in task_result.msg|lower)
  12. - name: Wait 10 seconds after disabling firewalld
  13. pause:
  14. seconds: 10
  15. when: task_result is changed
  16. - name: Install iptables packages
  17. package:
  18. name: "{{ pkg_list | join(',') }}"
  19. state: present
  20. vars:
  21. pkg_list:
  22. - iptables
  23. - iptables-services
  24. when: not openshift_is_atomic | bool
  25. register: result
  26. until: result is succeeded
  27. - name: Start and enable iptables service
  28. systemd:
  29. name: iptables
  30. state: started
  31. enabled: yes
  32. masked: no
  33. daemon_reload: yes
  34. register: result
  35. delegate_to: "{{item}}"
  36. run_once: true
  37. with_items: "{{ ansible_play_batch }}"
  38. - name: need to pause here, otherwise the iptables service starting can sometimes cause ssh to fail
  39. pause:
  40. seconds: 10
  41. when: result is changed