# Open ports on corresponding nodes if firewall is installed on it
#ceph_mon_firewall_zone: public
+#ceph_mgr_firewall_zone: public
#ceph_osd_firewall_zone: public
#ceph_rgw_firewall_zone: public
#ceph_mds_firewall_zone: public
# Open ports on corresponding nodes if firewall is installed on it
#ceph_mon_firewall_zone: public
+#ceph_mgr_firewall_zone: public
#ceph_osd_firewall_zone: public
#ceph_rgw_firewall_zone: public
#ceph_mds_firewall_zone: public
tags:
- firewall
+- name: open manager ports
+ firewalld:
+ service: ceph
+ zone: "{{ ceph_mgr_firewall_zone }}"
+ permanent: true
+ immediate: false # if true then fails in case firewalld is stopped
+ state: enabled
+ notify: restart firewalld
+ when:
+ - ceph_release_num[ceph_release] >= ceph_release_num.luminous
+ - mgr_group_name is defined
+ - mgr_group_name in group_names
+ - firewalld_pkg_query.rc == 0
+ tags:
+ - firewall
+
- name: open osd ports
firewalld:
service: ceph
# Open ports on corresponding nodes if firewall is installed on it
ceph_mon_firewall_zone: public
+ceph_mgr_firewall_zone: public
ceph_osd_firewall_zone: public
ceph_rgw_firewall_zone: public
ceph_mds_firewall_zone: public