firewalld:
service: ceph-mon
zone: "{{ ceph_mon_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
service: ceph
zone: "{{ ceph_mgr_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
service: ceph
zone: "{{ ceph_osd_firewall_zone }}"
+ source: "{{ item }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
+ with_items:
+ - "{{ public_network }}"
+ - "{{ cluster_network }}"
notify: restart firewalld
when:
- osd_group_name is defined
firewalld:
port: "{{ radosgw_frontend_port }}/tcp"
zone: "{{ ceph_rgw_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
service: ceph
zone: "{{ ceph_mds_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
service: nfs
zone: "{{ ceph_nfs_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
port: "111/tcp"
zone: "{{ ceph_nfs_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
port: "{{ restapi_port }}/tcp"
zone: "{{ ceph_restapi_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
service: ceph
zone: "{{ ceph_rbdmirror_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled
firewalld:
port: "5001/tcp"
zone: "{{ ceph_iscsi_firewall_zone }}"
+ source: "{{ public_network }}"
permanent: true
immediate: false # if true then fails in case firewalld is stopped
state: enabled