Skip to content

CentOS firewalld and selinux? #130

Answered by xanmanning
reenberg asked this question in Q&A
Discussion options

You must be logged in to vote

Hi.

Cheers 🍻

I'll look into the k3s-selinux policy package. I am going to be removing the tasks to install Docker in time and these will need to be done using another Ansible role, for example geerlingguy.docker, to separate the concerns of the role. k3s-selinux will eventually be handled by this role.

Firewalld configuration is a tough one to make a call on, because that "fix" is going to make assumptions about networking policy - for the casual hobbyist Rancher's suggestion to disable firewalld is easier to swallow, enterprise users would likely have a more stringent policy where traffic is restricted to specific subnets. It would need to be a carefully considered approach that ultimate…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@reenberg
Comment options

Answer selected by reenberg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants