Merge "Don't manage iptables if we're in a choot"
This commit is contained in:
commit
9cb87817fc
@ -23,12 +23,21 @@ class iptables(
|
|||||||
name => $::iptables::params::package_name,
|
name => $::iptables::params::package_name,
|
||||||
}
|
}
|
||||||
|
|
||||||
service { 'iptables':
|
if ($::in_chroot) {
|
||||||
name => $::iptables::params::service_name,
|
notify { 'iptables in chroot':
|
||||||
require => Package['iptables'],
|
message => 'Iptables not refreshed, running in chroot',
|
||||||
hasstatus => $::iptables::params::service_has_status,
|
}
|
||||||
status => $::iptables::params::service_status_cmd,
|
$notify_iptables = []
|
||||||
hasrestart => $::iptables::params::service_has_restart,
|
}
|
||||||
|
else {
|
||||||
|
service { 'iptables':
|
||||||
|
name => $::iptables::params::service_name,
|
||||||
|
require => Package['iptables'],
|
||||||
|
hasstatus => $::iptables::params::service_has_status,
|
||||||
|
status => $::iptables::params::service_status_cmd,
|
||||||
|
hasrestart => $::iptables::params::service_has_restart,
|
||||||
|
}
|
||||||
|
$notify_iptables = Service['iptables']
|
||||||
}
|
}
|
||||||
|
|
||||||
file { $::iptables::params::rules_dir:
|
file { $::iptables::params::rules_dir:
|
||||||
@ -49,7 +58,7 @@ class iptables(
|
|||||||
File[$::iptables::params::rules_dir],
|
File[$::iptables::params::rules_dir],
|
||||||
],
|
],
|
||||||
# When this file is updated, make sure the rules get reloaded.
|
# When this file is updated, make sure the rules get reloaded.
|
||||||
notify => Service['iptables'],
|
notify => $notify_iptables,
|
||||||
}
|
}
|
||||||
|
|
||||||
file { $::iptables::params::ipv4_rules:
|
file { $::iptables::params::ipv4_rules:
|
||||||
@ -59,7 +68,7 @@ class iptables(
|
|||||||
mode => '0640',
|
mode => '0640',
|
||||||
target => "${::iptables::params::rules_dir}/rules",
|
target => "${::iptables::params::rules_dir}/rules",
|
||||||
require => File["${::iptables::params::rules_dir}/rules"],
|
require => File["${::iptables::params::rules_dir}/rules"],
|
||||||
notify => Service['iptables'],
|
notify => $notify_iptables,
|
||||||
}
|
}
|
||||||
|
|
||||||
file { $::iptables::params::ipv6_rules:
|
file { $::iptables::params::ipv6_rules:
|
||||||
@ -73,7 +82,7 @@ class iptables(
|
|||||||
File[$::iptables::params::rules_dir],
|
File[$::iptables::params::rules_dir],
|
||||||
],
|
],
|
||||||
# When this file is updated, make sure the rules get reloaded.
|
# When this file is updated, make sure the rules get reloaded.
|
||||||
notify => Service['iptables'],
|
notify => $notify_iptables,
|
||||||
replace => true,
|
replace => true,
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user