52 コミット (master)

作成者 SHA1 メッセージ 日付
  Niels Abspoel 70071baf9b
fix(config): update firewalld.conf to be inline with 1.2.1 version 2年前
  Imran Iqbal 3a61e7de16
chore(salt-lint): ignore violation [skip ci] 2年前
  Gino Naumann 8d5c0c9410
fix(debian10 iptables): install iptables from buster-backports 3年前
  Steven Daniele 9c2b41d0f9 feat(rich-rules): add priority to rich rules 3年前
  Gino Naumann 194cb99f16 fix(zone.xml): fix jinja error in rule.reject 3年前
  Gino Naumann 88f9fd4687 fix(zone.xml): fix XML error 3年前
  Arnaud Patard a2f4f3b36e feat(zone.xml): allow to rate limit 'accept' in rich rules 3年前
  Daniel Dehennin a29e81bac6
fix(_mapdata): ensure map data is directly under `values` 3年前
  Imran Iqbal 22869e0c7f
test(map): verify `map.jinja` dump using `_mapdata` state 3年前
  Imran Iqbal 0ff53ffb27
feat(firewalld.conf): support configuration of `AllowZoneDrifting` 4年前
  Steven Daniele afcf5e7700
refactor: split default maps into separate files 4年前
  Steven Daniele 94d2b0b97c
fix: do not error on unknown os_family grain 4年前
  Imran Iqbal 69df9a62d6
test: verify map output using `yaml_dump` 4年前
  Imran Iqbal 204efe5fc7
style(zone.xml): remove all trailing whitespaces 4年前
  Imran Iqbal d8f0f47a54
fix(zone.xml): adjust whitespacing to pass tests & macro at top of file 4年前
  Steven Daniele cd4cec0089 feat: allow rich_rules to be specified as a dict 4年前
  Michal Hrusecky 8d0172f5c7
feat(zone.xml): allow more services definition inside zone 4年前
  Imran Iqbal 0f808d6afb
fix(yamllint): fix all errors 5年前
  Imran Iqbal de4e1915fb
fix(map.jinja): fix `salt-lint` errors 5年前
  Steven Daniele 12b696a8fe Remove name attribute in icmp-block-inversion 5年前
  Steven Daniele 64825e20ab Fix typo in icmp block inversion key name 5年前
  Niels Abspoel ae1f2453d3 add updated firewalld.conf from 0.7.1 5年前
  N ad37448038
feat(linux): archlinux support (no osfinger grain) 5年前
  Niels Abspoel a438f30f50 fix spacing in closing tags 5年前
  Niels Abspoel 18fc482853 update service and zones with more options 5年前
  Valentin Bud d1d7a9186c Add support for inet6 ipsets. 6年前
  Javier Bértoli 15a48462f0 Refactor backend format, add backward compatibility, simple pkg testing 6年前
  Javier Bértoli d3928d1be0 Refactor ipset format, add backward compatibility 6年前
  Javier Bértoli 7bc3a9cdd4 Use mapped data instead of pillar.get data 6年前
  Niels Abspoel 7c0b6aeb55 fix whitespacing 6年前
  Niels Abspoel 36da1094b7 update firewalld formula for firewalld > 0.6 6年前
  N 1ba51b8583 notify nosupport if SLES version < 15 6年前
  Niels Abspoel c7f4b3a611
Revert "Fix ipset:type colon handling error" 6年前
  Javier Bértoli 2fc03fbd70 Fix ipset:type colon handling error 6年前
  Angelo Verona b1d6b52307 Default file permission for firewalld.conf is 644 not 640 (CentOS). Even if I think that "others" don't need to read that, it always shows up as file with non-default permissions from default rpm package in security scans. e.g. "rpm -Va |grep ^.M" or more salty way: "salt '*' pkg.verify" / salt '*' pkg.modified firewalld mode=True; manual fix e.g. rpm --setperms firewalld-*.el7.noarch 7年前
  Paul Williams 2fd70c9f41
Add support for using ipsets as sources in a zone 7年前
  Javier Bértoli 141d8a4781 Add warning header to salt-generated files 7年前
  Niels Abspoel 5904c75875 add suse_support 7年前
  Adam Mendlik 103afc0a18 Reload, rather than restart, the FirewallD service 7年前
  Matthew Hoover cc617a97ef Added comment option for zone sources. 8年前
  hoonetorg 25cdfe3bbe firewalld 0.4 settings 8年前
  hoonetorg 9dc0a77167 implement direct rules 8年前
  hoonetorg b91d65d135 fix data type in zone and service template, which broke formula for 2016.3 8年前
  Niels Abspoel c5a01c837e add ipset support for firewalld 8年前
  Clément Mercier 588bf5efcf change the restart, it was not effective before 8年前
  Niels Abspoel 5fc2f58b0c improvements to formula with defaults.yaml 8年前
  David Bezuidenhout d55b767b91 [remove] clean-up some code, mostly code commented out 8年前
  Niels Abspoel e77a52cf27 fix newline to make service.xml files more readable 9年前
  David Bezuidenhout 8afeae049f [fix] mising bracket at endfor loop at <destination ipv6 9年前
  David Bezuidenhout 941b2768b1 [fix] service definition in rich rules - thx jdreese on Github 9年前