|
|
|
|
|
|
|
|
{% from "iptables/map.jinja" import service with context %} |
|
|
{% from "iptables/map.jinja" import service with context %} |
|
|
|
|
|
{%- if grains.get('virtual_subtype', None) not in ['Docker', 'LXC'] %} |
|
|
|
|
|
|
|
|
{%- for chain_name, chain in service.get('chain', {}).iteritems() %} |
|
|
{%- for chain_name, chain in service.get('chain', {}).iteritems() %} |
|
|
|
|
|
|
|
|
|
|
|
iptables_{{ chain_name }}: |
|
|
|
|
|
iptables.chain_present: |
|
|
|
|
|
- family: ipv4 |
|
|
|
|
|
- name: {{ chain_name }} |
|
|
|
|
|
- table: filter |
|
|
|
|
|
- require: |
|
|
|
|
|
- pkg: iptables_packages |
|
|
|
|
|
|
|
|
|
|
|
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %} |
|
|
|
|
|
iptables_{{ chain_name }}_ipv6: |
|
|
|
|
|
iptables.chain_present: |
|
|
|
|
|
- family: ipv6 |
|
|
|
|
|
- name: {{ chain_name }} |
|
|
|
|
|
- table: filter |
|
|
|
|
|
- require: |
|
|
|
|
|
- pkg: iptables_packages |
|
|
|
|
|
{%- if chain.policy is defined %} |
|
|
|
|
|
- require_in: |
|
|
|
|
|
- iptables: iptables_{{ chain_name }}_ipv6_policy |
|
|
|
|
|
{%- endif %} |
|
|
|
|
|
{%- endif %} |
|
|
|
|
|
|
|
|
{%- if chain.policy is defined %} |
|
|
{%- if chain.policy is defined %} |
|
|
iptables_{{ chain_name }}_policy: |
|
|
iptables_{{ chain_name }}_policy: |
|
|
iptables.set_policy: |
|
|
iptables.set_policy: |
|
|
|
|
|
|
|
|
- chain: {{ chain_name }} |
|
|
- chain: {{ chain_name }} |
|
|
- policy: {{ chain.policy }} |
|
|
- policy: {{ chain.policy }} |
|
|
- table: filter |
|
|
- table: filter |
|
|
|
|
|
- require: |
|
|
|
|
|
- iptables: iptables_{{ chain_name }} |
|
|
|
|
|
|
|
|
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %} |
|
|
{%- if grains.ipv6|default(False) and service.ipv6|default(True) %} |
|
|
iptables_{{ chain_name }}_ipv6_policy: |
|
|
iptables_{{ chain_name }}_ipv6_policy: |
|
|
|
|
|
|
|
|
- chain: {{ chain_name }} |
|
|
- chain: {{ chain_name }} |
|
|
- policy: {{ chain.policy }} |
|
|
- policy: {{ chain.policy }} |
|
|
- table: filter |
|
|
- table: filter |
|
|
|
|
|
- require: |
|
|
|
|
|
- iptables: iptables_{{ chain_name }}_ipv6 |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
{%- endif %} |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
{%- endfor %} |
|
|
{%- endfor %} |
|
|
|
|
|
|
|
|
{%- endfor %} |
|
|
{%- endfor %} |
|
|
|
|
|
{%- endif %} |