085856e318
This adds a new variable for the iptables role that allows us to indicate all members of an ansible inventory group should have iptables rules added. It also removes the unused zuul-executor-opendev group, and some unused variables related to the snmp rule. Also, collect the generated iptables rules for debugging. Change-Id: I48746a6527848a45a4debf62fd833527cc392398 Depends-On: https://review.opendev.org/728952
18 lines
572 B
YAML
18 lines
572 B
YAML
iptables_extra_allowed_hosts:
|
|
- hostname: bridge.openstack.org
|
|
port: 8125
|
|
protocol: udp
|
|
- hostname: opendev.org
|
|
port: 8125
|
|
protocol: udp
|
|
- hostname: mirror-update01.openstack.org
|
|
port: 8125
|
|
protocol: udp
|
|
|
|
iptables_extra_allowed_groups:
|
|
- {'protocol': 'udp', 'port': '8125', 'group': 'firehose'}
|
|
- {'protocol': 'udp', 'port': '8125', 'group': 'mirror-update'}
|
|
- {'protocol': 'udp', 'port': '8125', 'group': 'logstash'}
|
|
- {'protocol': 'udp', 'port': '8125', 'group': 'nodepool'}
|
|
- {'protocol': 'udp', 'port': '8125', 'group': 'zuul'}
|