summaryrefslogtreecommitdiffstats
path: root/roles/os_firewall/defaults
diff options
context:
space:
mode:
authorScott Dodson <sdodson@redhat.com>2017-01-09 12:49:04 -0500
committerGitHub <noreply@github.com>2017-01-09 12:49:04 -0500
commiteb451532df15b010bd9d26195b93096a8bd20148 (patch)
treeceecd7342c71717830a3a928022196545f08e420 /roles/os_firewall/defaults
parent96fe76dad188610733c87cf80f4e22da34f11fb7 (diff)
parent05e189a039dada5edc4f9afb700b594c4dea4c9b (diff)
downloadopenshift-eb451532df15b010bd9d26195b93096a8bd20148.tar.gz
openshift-eb451532df15b010bd9d26195b93096a8bd20148.tar.bz2
openshift-eb451532df15b010bd9d26195b93096a8bd20148.tar.xz
openshift-eb451532df15b010bd9d26195b93096a8bd20148.zip
Merge pull request #2909 from mtnbikenc/firewalld
Enable firewalld by default
Diffstat (limited to 'roles/os_firewall/defaults')
-rw-r--r--roles/os_firewall/defaults/main.yml8
1 files changed, 3 insertions, 5 deletions
diff --git a/roles/os_firewall/defaults/main.yml b/roles/os_firewall/defaults/main.yml
index c870a301a..4c544122f 100644
--- a/roles/os_firewall/defaults/main.yml
+++ b/roles/os_firewall/defaults/main.yml
@@ -1,9 +1,7 @@
---
os_firewall_enabled: True
-# TODO: Upstream kubernetes only supports iptables currently
-# TODO: it might be possible to still use firewalld if we wire up the created
-# chains with the public zone (or the zone associated with the correct
-# interfaces)
-os_firewall_use_firewalld: False
+# firewalld is not supported on Atomic Host
+# https://bugzilla.redhat.com/show_bug.cgi?id=1403331
+os_firewall_use_firewalld: "{{ False if openshift.common.is_atomic | bool else True }}"
os_firewall_allow: []
os_firewall_deny: []