[mas01] Fix iptables pillar compatibility format 25/65925/1
authorAlexandru Avadanii <Alexandru.Avadanii@enea.com>
Mon, 17 Dec 2018 18:17:59 +0000 (19:17 +0100)
committerAlexandru Avadanii <Alexandru.Avadanii@enea.com>
Mon, 17 Dec 2018 18:17:59 +0000 (19:17 +0100)
Sync our reclass pillar data for mas01's iptables with latest formula
changes [1].

[1] https://github.com/salt-formulas/salt-formula-iptables/commit/e353ce3c

Change-Id: I66b2a75066ed512ab5ab4cc213d13d15c5c8cc7f
Signed-off-by: Alexandru Avadanii <Alexandru.Avadanii@enea.com>
mcp/reclass/classes/cluster/all-mcp-arch-common/infra/maas.yml.j2

index ee1d247..4b11478 100644 (file)
@@ -148,21 +148,29 @@ parameters:
           netmask: ${_param:opnfv_net_admin_mask}
           type: eth
   iptables:
+    schema:
+      epoch: 1
     service:
-      enabled: True
-      chain:
-        POSTROUTING:
-          rules:
-            - table: nat
-              source_network: '${_param:single_address}/${_param:opnfv_net_admin_mask}'
-              jump: MASQUERADE
-        INPUT:
-          rules:
-            - table: filter
-              source_network: '${_param:single_address}/${_param:opnfv_net_admin_mask}'
-              jump: ACCEPT
-        INPUT:
-          rules:
-            - table: filter
-              destination_network: '${_param:single_address}/${_param:opnfv_net_admin_mask}'
-              jump: ACCEPT
+      v4:
+        enabled: true
+        persistent_config: /etc/iptables/rules.v4
+      v6:
+        enabled: false
+    tables:
+      v4:
+        filter:
+          chains:
+            INPUT:
+              ruleset:
+                10:
+                  rule: -s ${_param:single_address}/${_param:opnfv_net_admin_mask}
+                11:
+                  rule: -d ${_param:single_address}/${_param:opnfv_net_admin_mask}
+        nat:
+          chains:
+            POSTROUTING:
+              policy: ACCEPT
+              ruleset:
+                10:
+                  rule: -s ${_param:single_address}/${_param:opnfv_net_admin_mask}
+                  action: MASQUERADE