firewalld-formula/firewalld/zones.sls

43 lines
1.1 KiB
Plaintext
Raw Normal View History

# == State: firewalld.zones
2014-08-23 16:44:48 +02:00
#
# This state ensures that /etc/firewalld/zones/ exists.
#
{% from "firewalld/map.jinja" import firewalld with context %}
directory_firewalld_zones:
2014-08-23 16:44:48 +02:00
file.directory: # make sure this is a directory
- name: /etc/firewalld/zones
2014-08-23 16:44:48 +02:00
- user: root
- group: root
- mode: 750
- require:
- pkg: package_firewalld # make sure package is installed
- listen_in:
- module: service_firewalld # restart service
2014-08-23 16:44:48 +02:00
# == Define: firewalld.zones
2014-08-23 16:44:48 +02:00
#
# This defines a zone configuration, see firewalld.zone (5) man page.
#
{% for k, v in salt['pillar.get']('firewalld:zones', {}).items() %}
{% set z_name = v.name|default(k) %}
/etc/firewalld/zones/{{ z_name }}.xml:
file.managed:
2014-08-23 16:44:48 +02:00
- name: /etc/firewalld/zones/{{ z_name }}.xml
- user: root
- group: root
- mode: 644
- source: salt://firewalld/files/zone.xml
- template: jinja
- require:
- pkg: package_firewalld # make sure package is installed
- file: directory_firewalld_zones
- listen_in:
- module: service_firewalld # restart service
2014-08-23 16:44:48 +02:00
- context:
name: {{ z_name }}
zone: {{ v }}
{% endfor %}