mirror of
https://github.com/clearlinux/docker.git
synced 2026-09-28 00:50:11 +00:00
Merge pull request #9397 from jpopelka/9395-firewalld
Firewalld support
This commit is contained in:
@@ -226,13 +226,18 @@ func InitDriver(config *Config) error {
|
||||
bridgeIPv6Addr = networkv6.IP
|
||||
}
|
||||
|
||||
if config.EnableIptables {
|
||||
iptables.FirewalldInit()
|
||||
}
|
||||
|
||||
// Configure iptables for link support
|
||||
if config.EnableIptables {
|
||||
if err := setupIPTables(addrv4, config.InterContainerCommunication, config.EnableIpMasq); err != nil {
|
||||
logrus.Errorf("Error configuing iptables: %s", err)
|
||||
return err
|
||||
}
|
||||
|
||||
// call this on Firewalld reload
|
||||
iptables.OnReloaded(func() { setupIPTables(addrv4, config.InterContainerCommunication, config.EnableIpMasq) })
|
||||
}
|
||||
|
||||
if config.EnableIpForward {
|
||||
@@ -262,10 +267,16 @@ func InitDriver(config *Config) error {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// call this on Firewalld reload
|
||||
iptables.OnReloaded(func() { iptables.NewChain("DOCKER", bridgeIface, iptables.Nat) })
|
||||
|
||||
chain, err := iptables.NewChain("DOCKER", bridgeIface, iptables.Filter)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// call this on Firewalld reload
|
||||
iptables.OnReloaded(func() { iptables.NewChain("DOCKER", bridgeIface, iptables.Filter) })
|
||||
|
||||
portMapper.SetIptablesChain(chain)
|
||||
}
|
||||
|
||||
@@ -310,6 +321,10 @@ func InitDriver(config *Config) error {
|
||||
// Block BridgeIP in IP allocator
|
||||
ipAllocator.RequestIP(bridgeIPv4Network, bridgeIPv4Network.IP)
|
||||
|
||||
if config.EnableIptables {
|
||||
iptables.OnReloaded(portMapper.ReMapAll) // call this on Firewalld reload
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
@@ -132,6 +132,18 @@ func (pm *PortMapper) Map(container net.Addr, hostIP net.IP, hostPort int) (host
|
||||
return m.host, nil
|
||||
}
|
||||
|
||||
// re-apply all port mappings
|
||||
func (pm *PortMapper) ReMapAll() {
|
||||
logrus.Debugln("Re-applying all port mappings.")
|
||||
for _, data := range pm.currentMappings {
|
||||
containerIP, containerPort := getIPAndPort(data.container)
|
||||
hostIP, hostPort := getIPAndPort(data.host)
|
||||
if err := pm.forward(iptables.Append, data.proto, hostIP, hostPort, containerIP.String(), containerPort); err != nil {
|
||||
logrus.Errorf("Error on iptables add: %s", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func (pm *PortMapper) Unmap(host net.Addr) error {
|
||||
pm.lock.Lock()
|
||||
defer pm.lock.Unlock()
|
||||
|
||||
Reference in New Issue
Block a user