SaltStack Formula to set up and configure Firewalld, dynamically managed firewall with support for network/firewall zones to define the trust level of network connections or interfaces https://github.com/saltstack-formulas/firewalld-formula/
Go to file
Gino Naumann 8d5c0c9410
fix(debian10 iptables): install iptables from buster-backports
* fix(debian10 iptables): install iptables from buster-backports

* fix(debian 10 iptables): Arch Linux test

Co-authored-by: Imran Iqbal <myii@users.noreply.github.com>
2021-06-22 22:09:38 +01:00
.github/workflows ci(workflows/commitlint): add to repo [skip ci] 2020-05-04 09:28:06 +01:00
bin ci(pre-commit): add to formula [skip ci] 2020-10-03 10:22:12 +01:00
docs chore(release): 1.3.0 [skip ci] 2021-06-18 18:45:51 +00:00
firewalld fix(debian10 iptables): install iptables from buster-backports 2021-06-22 22:09:38 +01:00
test/integration feat(rich-rules): add priority to rich rules 2021-06-18 13:11:06 -04:00
.gitignore chore: standardise structure (.gitignore & _mapdata.rb) [skip ci] 2021-02-11 11:48:04 +00:00
.gitlab-ci.yml ci(kitchen+gitlab): remove Ubuntu 16.04 & Fedora 32 (EOL) [skip ci] 2021-06-21 20:42:59 +01:00
.pre-commit-config.yaml chore(pre-commit): use info report level for rstcheck [skip ci] 2021-05-20 14:05:40 +01:00
.rstcheck.cfg chore(pre-commit): use info report level for rstcheck [skip ci] 2021-05-20 14:05:40 +01:00
.rubocop.yml test: standardise use of share suite & _mapdata state [skip ci] 2021-03-23 21:26:54 +00:00
.salt-lint feat(semantic-release): implement for this formula 2019-11-09 08:24:55 +00:00
.travis.yml ci(kitchen+gitlab): remove Ubuntu 16.04 & Fedora 32 (EOL) [skip ci] 2021-06-21 20:42:59 +01:00
.yamllint chore: update CODEOWNERS & .yamllint re: kitchen-vagrant [skip ci] 2021-04-05 18:17:16 +01:00
AUTHORS.md chore(release): 1.3.0 [skip ci] 2021-06-18 18:45:51 +00:00
CHANGELOG.md chore(release): 1.3.0 [skip ci] 2021-06-18 18:45:51 +00:00
CODEOWNERS chore: update CODEOWNERS & .yamllint re: kitchen-vagrant [skip ci] 2021-04-05 18:17:16 +01:00
commitlint.config.js chore(commitlint): add {body,footer,header}-max(-line)-length [skip ci] 2020-10-07 09:04:28 +01:00
FORMULA chore(release): 1.3.0 [skip ci] 2021-06-18 18:45:51 +00:00
Gemfile test: standardise use of share suite & _mapdata state [skip ci] 2021-03-23 21:26:54 +00:00
Gemfile.lock ci(gemfile+lock): use ssf customised kitchen-docker repo [skip ci] 2021-02-17 13:48:18 +00:00
kitchen.yml ci(kitchen+gitlab): remove Ubuntu 16.04 & Fedora 32 (EOL) [skip ci] 2021-06-21 20:42:59 +01:00
LICENSE feat: standardize license and hand over to saltstack formulas 2020-02-12 14:41:48 +00:00
pillar.example feat(rich-rules): add priority to rich rules 2021-06-18 13:11:06 -04:00
pre-commit_semantic-release.sh ci(gitlab-ci): use GitLab CI as Travis CI replacement 2020-12-16 06:30:40 +00:00
release-rules.js feat(semantic-release): implement for this formula 2019-11-09 08:24:55 +00:00
release.config.js ci(gitlab-ci): use GitLab CI as Travis CI replacement 2020-12-16 06:30:40 +00:00
VERSION Update pillar.example 2018-08-25 19:05:21 -03:00

firewalld-formula

Travis CI Build Status Semantic Release

A SaltStack Formula to set up and configure Firewalld, a dynamically managed firewall with support for network/firewall zones to define the trust level of network connections or interfaces.

Table of Contents

General notes

See the full SaltStack Formulas installation and usage instructions.

If you are interested in writing or contributing to formulas, please pay attention to the Writing Formula Section.

If you want to use this formula, please pay attention to the FORMULA file and/or git tag, which contains the currently released version. This formula is versioned according to Semantic Versioning.

See Formula Versioning Section for more details.

If you need (non-default) configuration, please pay attention to the pillar.example file and/or Special notes section.

Contributing to this repo

Commit message formatting is significant!!

Please see How to contribute for more details.

Special notes

None

TODO

  • configure local pre-commit hooks (code syntax check based on file extension, check for ugly utf-8 mac os white space)

Instructions

  1. Add this repository as a GitFS backend in your Salt master config.
  2. Configure your Pillar top file (/srv/pillar/top.sls), see pillar.example
  3. Include this Formula within another Formula or simply define your needed states within the Salt top file (/srv/salt/top.sls).

Additional resources

None

Formula Dependencies

None

Contributions

Contributions are always welcome. All development guidelines you have to know are

  • write clean code (proper YAML+Jinja syntax, no trailing whitespaces, no empty lines with whitespaces, LF only)
  • set sane default settings
  • test your code
  • update README.rst doc

Salt Compatibility

Tested with:

  • 2018.3.x (will probably work too with 2017.x.x)

OS Compatibility

Tested with:

  • CentOS 7
  • Debian 9
  • Ubuntu 18.04

Available states

firewalld

Manage firewalld

Testing

Linux testing is done with kitchen-salt.

Requirements

  • Ruby
  • Docker
$ gem install bundler
$ bundle install
$ bin/kitchen test [platform]

Where [platform] is the platform name defined in kitchen.yml, e.g. debian-9-2019-2-py3.

bin/kitchen converge

Creates the docker instance and runs the firewalld main state, ready for testing.

bin/kitchen verify

Runs the inspec tests on the actual instance.

bin/kitchen destroy

Removes the docker instance.

bin/kitchen test

Runs all of the stages above in one go: i.e. destroy + converge + verify + destroy.

bin/kitchen login

Gives you SSH access to the instance for manual testing.