@@ -36,6 +36,29 @@ func (b *FirewallBuilder) Build(c *fi.NodeupModelBuilderContext) error {
3636 c .AddTask (b .buildFirewallScript ())
3737 c .AddTask (b .buildSystemdService ())
3838
39+ // On distros where Kubernetes CNIs (notably Calico) document firewalld
40+ // as incompatible, stop and mask it. firewalld's default-reject
41+ // filter_INPUT/filter_FORWARD policies and periodic-reload behavior
42+ // conflict with the iptables/nftables rules CNIs install for pod and
43+ // service traffic. Most cloud images in the RHEL family already ship
44+ // firewalld off (AWS RHEL/Rocky AMIs, upstream Rocky GenericCloud); the
45+ // GCE-optimized Rocky 10 image is the known outlier. The disable/mask
46+ // sequence is idempotent and a no-op where firewalld isn't installed.
47+ // See: https://docs.tigera.io/calico/latest/getting-started/kubernetes/requirements
48+ if b .Distribution .ForceNftables () {
49+ c .AddTask (& nodetasks.File {
50+ Path : "/etc/kops/firewalld-disabled" ,
51+ Contents : fi .NewStringResource ("# Marker: firewalld disabled by kops to avoid conflicts with the Kubernetes CNI dataplane.\n " ),
52+ Type : nodetasks .FileType_File ,
53+ OnChangeExecute : [][]string {
54+ // Stop and disable so it can't restart at boot.
55+ {"bash" , "-c" , "systemctl disable --now firewalld.service 2>/dev/null; true" },
56+ // Mask so package updates or preset reloads can't bring it back.
57+ {"bash" , "-c" , "systemctl mask firewalld.service 2>/dev/null; true" },
58+ },
59+ })
60+ }
61+
3962 return nil
4063}
4164
0 commit comments