forked from infra/ansible
When `nftables=True` the base role deploys nftables rules and enables the nftables service, but never disables the iptables service. On freshly provisioned hosts the iptables service can be left running from cloud-init, overwriting nftables rules and silently dropping traffic on ports defined in `tcp_ports`. Stop and disable the iptables service explicitly when nftables is the intended firewall backend. |
||
|---|---|---|
| .. | ||
| crypto-policies.yml | ||
| keytab.yml | ||
| lmdb.yml | ||
| main.yml | ||
| mdraid-monitoring.yml | ||
| monitoring.yml | ||
| motd.yml | ||
| postfix-monitoring.yml | ||
| postfix.yml | ||
| process-monitoring.yml | ||
| watchdog.yml | ||