Skip to content

Comments

WIP KP-6954 Add nftables handling for non-vmware hosts#70

Open
Traubert wants to merge 4 commits intomainfrom
KP-6954-iftables
Open

WIP KP-6954 Add nftables handling for non-vmware hosts#70
Traubert wants to merge 4 commits intomainfrom
KP-6954-iftables

Conversation

@Traubert
Copy link
Contributor

@Traubert Traubert commented Apr 1, 2025

This is an attempt to parametrize in the inventories whether we are on a VMWare host, in case we try to stick to their funky processes, or if we're on some other (RH-based) host, in which case we use "normal" nftables rules literally.

firewalld is another option, but it would be even more different from the VMWare stuff.

This is an attempt to parametrize in the inventories whether we are on a
VMWare host, in case we try to stick to their funky processes, or if
we're on some other (RH-based) host, in which case we use "normal"
nftables rules literally.

firewalld is another option, but it would be even more different from
the VMWare stuff.
Comment on lines 4 to 12
- name: Include Pouta iptables configuration
when: not is_vmware
include_tasks:
file: pouta.yml

- name: Include VMWare iptables configuration
when: is_vmware
include_tasks:
file: vmware.yml
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now that these have fully diverged, could we ditch the is_vmware variable and this "shared" task and instead remove the firewall task from korp-software.yml and do the pouta.yml and vmware.yml in corresponding pre/post-processing playbooks for pouta/production?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants