Install with Firewalld Enabled
By default, the installer requires that Firewalld is disabled before continuing. If you need to leave Firewalld enabled you can add a flag (under the firewalldConfig spec) to the installer-override.yaml patch file spec: section.
For example:
Configuring Firewalld
The required ports for cluster node communication need to be open in the Firewalld config on each node in the cluster. For more information see System Requirements for an Embedded Cluster InstallSystem Requirements for an Embedded Cluster Install.
Here is an example script for configuring Firewalld in CentOS 7/RHEL 7 environments:
If you wish to open additional ports after the Swimlane deployment (e.g. Syslog Receiver, External Mongo ports) see below:
kubectl get svc -o wide
The ports from the example output above will be different for every deployment. Run these commands to create firewall exceptions:
TCP ports 35246, 6239, 36278 have been assigned to our MongoDB service for external access:
UDP port 42750 has been assigned to our Swimlane Syslog Receiver service:
Restart firewalld:
See Overriding Installer SettingsOverriding Installer Settings for instructions on how to specify the installer override file during the install and join node commands.