diff --git a/lib/puppet/type/firewalld_rich_rule.rb b/lib/puppet/type/firewalld_rich_rule.rb index 1ae38820..e1486313 100644 --- a/lib/puppet/type/firewalld_rich_rule.rb +++ b/lib/puppet/type/firewalld_rich_rule.rb @@ -165,15 +165,19 @@ def elements self[:policy] if self[:policy] != :unset end - autorequire(:ipset) do + autorequire(:firewalld_ipset) do self[:source]['ipset'] if self[:source].is_a?(Hash) end - autorequire(:ipset) do + autorequire(:firewalld_ipset) do self[:dest]['ipset'] if self[:dest].is_a?(Hash) end autorequire(:service) do ['firewalld'] end + + autorequire(:firewalld_custom_service) do + self[:service]&.gsub(%r{[^\w-]}, '_') + end end diff --git a/manifests/init.pp b/manifests/init.pp index efdc0208..ed3bd8c8 100644 --- a/manifests/init.pp +++ b/manifests/init.pp @@ -182,14 +182,9 @@ enable => $service_enable, } - # create ports - Firewalld_port { - zone => $default_port_zone, - protocol => $default_port_protocol, - } - - $ports.each |String $key, Hash $attrs| { - firewalld_port { $key: + #...ipsets + $ipsets.each | String $key, Hash $attrs| { + firewalld_ipset { $key: * => $attrs, } } @@ -208,22 +203,21 @@ } } - #...services - Firewalld_service { - zone => $default_service_zone, + # create ports + Firewalld_port { + zone => $default_port_zone, + protocol => $default_port_protocol, } - $services.each | String $key, Hash $attrs| { - firewalld_service { $key: + $ports.each |String $key, Hash $attrs| { + firewalld_port { $key: * => $attrs, } } - #...rich rules - $rich_rules.each | String $key, Hash $attrs| { - firewalld_rich_rule { $key: - * => $attrs, - } + #...services + Firewalld_service { + zone => $default_service_zone, } #...custom services @@ -233,9 +227,8 @@ } } - #...ipsets - $ipsets.each | String $key, Hash $attrs| { - firewalld_ipset { $key: + $services.each | String $key, Hash $attrs| { + firewalld_service { $key: * => $attrs, } } @@ -259,6 +252,13 @@ } } + #...rich rules + $rich_rules.each | String $key, Hash $attrs| { + firewalld_rich_rule { $key: + * => $attrs, + } + } + Firewalld_direct_purge { notify => Class['firewalld::reload'], }