@@ -89,7 +89,7 @@ stackhpc_controller_firewalld_rules_template:
89
89
- service: ssh
90
90
network: "{{ public_net_name }}"
91
91
state: disabled
92
- enabled: "{{ public_net_name | net_zone != provision_oc_net_name | net_zone }}"
92
+ enabled: "{{ public_net_name | net_zone != admin_oc_net_name | net_zone }}"
93
93
# Designate
94
94
- rules:
95
95
- port: 53/tcp
@@ -128,7 +128,7 @@ stackhpc_controller_firewalld_rules_template:
128
128
- port: 8089/tcp
129
129
network: "{{ provision_wl_net_name }}"
130
130
state: enabled
131
- enabled: "{{ kolla_enable_octavia | bool }}"
131
+ enabled: "{{ kolla_enable_ironic | bool }}"
132
132
133
133
stackhpc_controller_firewalld_rules_extra: []
134
134
@@ -164,7 +164,7 @@ stackhpc_compute_firewalld_rules_template:
164
164
- service: ssh
165
165
network: "{{ public_net_name }}"
166
166
state: disabled
167
- enabled: "{{ public_net_name | net_zone != provision_oc_net_name | net_zone }}"
167
+ enabled: "{{ public_net_name | net_zone != admin_oc_net_name | net_zone }}"
168
168
# GENEVE
169
169
- rules:
170
170
- port: 6081/udp
@@ -204,24 +204,25 @@ stackhpc_storage_firewalld_rules_template:
204
204
- service: ssh
205
205
network: "{{ admin_oc_net_name }}"
206
206
state: enabled
207
+ enabled: true
208
+ # Ceph Prometheus exporter
209
+ - rules:
207
210
- port: 9283/tcp
208
211
network: "{{ provision_oc_net_name }}"
209
212
state: enabled
210
- enabled: true
211
- - rules:
212
- - service: ssh
213
- network: "{{ storage_net_name }}"
214
- state: disabled
215
- enabled: "{{ storage_net_name | net_zone != provision_oc_net_name | net_zone }}"
213
+ enabled: "{{ kolla_enable_prometheus_ceph_mgr_exporter and 'mgrs' in group_names }}"
216
214
# Ceph
217
215
- rules:
218
216
- service: ceph
219
217
network: "{{ storage_net_name }}"
220
218
state: enabled
219
+ - service: ceph
220
+ network: "{{ storage_mgmt_net_name }}"
221
+ state: enabled
221
222
- service: ceph-mon
222
223
network: "{{ storage_net_name }}"
223
224
state: "{{ 'enabled' if 'mons' in group_names else 'disabled' }}"
224
- enabled: "{{ stackhpc_enable_ceph | default(false) | bool }}"
225
+ enabled: "{{ 'ceph' in group_names }}"
225
226
226
227
stackhpc_storage_firewalld_rules_extra: []
227
228
@@ -369,14 +370,10 @@ stackhpc_seed_firewalld_rules_template:
369
370
- service: ssh
370
371
state: disabled
371
372
network: "{{ public_net_name }}"
372
- enabled: "{{ public_net_name | net_zone != provision_oc_net_name | net_zone }}"
373
+ enabled: "{{ public_net_name | net_zone != admin_oc_net_name | net_zone }}"
373
374
# Pulp server
374
375
- rules:
375
- - service: http
376
- network: "{{ provision_oc_net_name }}"
377
- state: enabled
378
- # nginx
379
- - port: 8080/tcp
376
+ - service: "{{ pulp_port }}/tcp"
380
377
network: "{{ provision_oc_net_name }}"
381
378
state: enabled
382
379
enabled: "{{ seed_pulp_container_enabled | bool }}"
@@ -388,6 +385,10 @@ stackhpc_seed_firewalld_rules_template:
388
385
enabled: "{{ seed_squid_container_enabled | bool }}"
389
386
# Ironic
390
387
- rules:
388
+ # nginx
389
+ - port: 8080/tcp
390
+ network: "{{ provision_oc_net_name }}"
391
+ state: enabled
391
392
# Ironic inspector API
392
393
- port: 5050/tcp
393
394
network: "{{ provision_oc_net_name }}"
0 commit comments