From dc3a1c9aa1dd2a719bd2651101ae19a718ee2aee Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Tue, 19 Jun 2018 10:43:55 -0400 Subject: [PATCH] Firewall Module - Allow Minions to connect to salt --- pillar/firewall/minions.sls | 2 +- salt/firewall/init.sls | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/pillar/firewall/minions.sls b/pillar/firewall/minions.sls index fd8e03672..233e42904 100644 --- a/pillar/firewall/minions.sls +++ b/pillar/firewall/minions.sls @@ -1,2 +1,2 @@ -minion_ips: +minions: - 127.0.0.1 \ No newline at end of file diff --git a/salt/firewall/init.sls b/salt/firewall/init.sls index 2d1ca8b3f..f82ec8a95 100644 --- a/salt/firewall/init.sls +++ b/salt/firewall/init.sls @@ -52,10 +52,10 @@ enable_reject_policy: # Rules if you are a Master {% if grains['role'] == 'so-master' %} -{% set minions = salt['pillar.get']('firewall.minions', {}) %} -{% for ip in minions.get('minion_ips', []) %} -enable_salt_minions_4505: +{% for ip in pillar.get('minions') %} + +enable_salt_minions_4505_{{ip}}: iptables.append: - table: filter - chain: INPUT @@ -65,7 +65,7 @@ enable_salt_minions_4505: - dport: 4505 - save: True -enable_salt_minions_4506: +enable_salt_minions_4506_{{ip}}: iptables.append: - table: filter - chain: INPUT