summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGeorg Pfuetzenreuter2023-02-05 14:29:25 +0100
committerGeorg Pfuetzenreuter2023-02-05 14:29:25 +0100
commit5e02090bc6037ac2e30190d97c3717c3fee01f96 (patch)
tree490a8c08970378cc4c1bd783e52ea7df0a7c5439
parent785986d2acc45ddb5451dffc1840b13accdd871c (diff)
downloadsalt-5e02090bc6037ac2e30190d97c3717c3fee01f96.tar.gz
salt-5e02090bc6037ac2e30190d97c3717c3fee01f96.tar.bz2
salt-5e02090bc6037ac2e30190d97c3717c3fee01f96.zip
web-proxy: add firewall configuration
Allow internal http and https to pass on web proxies. To-do: logic for web proxies directly attached to the internet. Signed-off-by: Georg Pfuetzenreuter <mail@georg-pfuetzenreuter.net>
-rw-r--r--pillar/role/web-proxy.sls7
1 files changed, 6 insertions, 1 deletions
diff --git a/pillar/role/web-proxy.sls b/pillar/role/web-proxy.sls
index 1b7497c..2adc81c 100644
--- a/pillar/role/web-proxy.sls
+++ b/pillar/role/web-proxy.sls
@@ -28,4 +28,9 @@ nginx:
{%- endfor %}
{%- endif %}
-
+firewalld:
+ zones:
+ internal:
+ services:
+ - http
+ - https