ansible-role-kubernetes/templates/etc/firewalld/services/kubernetes.xml.j2
2020-04-25 02:23:35 +02:00

26 lines
877 B
Django/Jinja

<?xml version="1.0" encoding="utf-8"?>
<service>
<short>Kubernetes</short>
<description>Open needed Kubernetes ports.</description>
{% if kubernetes_master == false or kubernetes_master_taint == true %}
<port protocol="tcp" port="80"/>
<port protocol="tcp" port="443"/>
{% endif %}
{% if kubernetes_master == true %}
# Kubernetes API server, used by all
<port protocol="tcp" port="6443"/>
# etcd server client API, used by kube-apiserver and etcd
<port protocol="tcp" port="2379"/>
<port protocol="tcp" port="2380"/>
# Kubelet API, used by self and control plane
<port protocol="tcp" port="10250"/>
# kube-scheduler, used by self
<port protocol="tcp" port="10251"/>
# kube-controler-manager, used by self
<port protocol="tcp" port="10252"/>
# ???
<port protocol="tcp" port="10255"/>
{% else %}
<port protocol="tcp" port="10250"/>
{% endif %}
</service>