|
6 | 6 | when: ansible_facts.os_family == 'Debian'
|
7 | 7 |
|
8 | 8 | # TODO(inc0): Gates don't seem to have ufw executable, check for it instead of ignore errors
|
9 |
| -- name: Set firewall default policy |
10 |
| - become: True |
11 |
| - ufw: |
12 |
| - state: disabled |
13 |
| - policy: allow |
14 |
| - when: ansible_facts.os_family == 'Debian' |
15 |
| - ignore_errors: yes |
16 |
| - |
17 |
| -- name: Check if firewalld is installed |
18 |
| - command: rpm -q firewalld |
19 |
| - register: firewalld_check |
20 |
| - changed_when: false |
21 |
| - failed_when: firewalld_check.rc > 1 |
22 |
| - args: |
23 |
| - warn: false |
24 |
| - when: ansible_facts.os_family == 'RedHat' |
| 9 | +- block: |
| 10 | + - name: Set firewall default policy |
| 11 | + become: True |
| 12 | + ufw: |
| 13 | + state: disabled |
| 14 | + policy: allow |
| 15 | + when: ansible_facts.os_family == 'Debian' |
| 16 | + ignore_errors: yes |
| 17 | + |
| 18 | + - name: Check if firewalld is installed |
| 19 | + command: rpm -q firewalld |
| 20 | + register: firewalld_check |
| 21 | + changed_when: false |
| 22 | + failed_when: firewalld_check.rc > 1 |
| 23 | + args: |
| 24 | + warn: false |
| 25 | + when: ansible_facts.os_family == 'RedHat' |
25 | 26 |
|
26 |
| -- name: Disable firewalld |
27 |
| - become: True |
28 |
| - service: |
29 |
| - name: "{{ item }}" |
30 |
| - enabled: false |
31 |
| - state: stopped |
32 |
| - with_items: |
33 |
| - - firewalld |
34 |
| - when: |
35 |
| - - ansible_facts.os_family == 'RedHat' |
36 |
| - - firewalld_check.rc == 0 |
| 27 | + - name: Disable firewalld |
| 28 | + become: True |
| 29 | + service: |
| 30 | + name: "{{ item }}" |
| 31 | + enabled: false |
| 32 | + state: stopped |
| 33 | + with_items: |
| 34 | + - firewalld |
| 35 | + when: |
| 36 | + - ansible_facts.os_family == 'RedHat' |
| 37 | + - firewalld_check.rc == 0 |
| 38 | + when: disable_firewall | bool |
37 | 39 |
|
38 | 40 | # Upgrading docker engine may cause containers to stop. Take a snapshot of the
|
39 | 41 | # running containers prior to a potential upgrade of Docker.
|
|
0 commit comments