root / CHANGELOG.md @ master
Historique | Voir | Annoter | Télécharger (31,2 ko)
1 | ece9be27 | tr | # Changelog |
---|---|---|---|
2 | |||
3 | All notable changes to this project will be documented in this file. |
||
4 | bc1b0f1a | Steve Traylen | Each new release typically also includes the latest modulesync defaults. |
5 | These should not affect the functionality of the module. |
||
6 | ece9be27 | tr | |
7 | 83506792 | Release Automation | ## [v4.2.0](https://github.com/voxpupuli/puppet-nftables/tree/v4.2.0) (2025-02-28) |
8 | 898da61a | Release Automation | |
9 | 83506792 | Release Automation | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v4.1.0...v4.2.0) |
10 | 898da61a | Release Automation | |
11 | **Implemented enhancements:** |
||
12 | |||
13 | - Add firewall rule for incoming rsync requests [\#272](https://github.com/voxpupuli/puppet-nftables/pull/272) ([bastelfreak](https://github.com/bastelfreak)) |
||
14 | |||
15 | 90296648 | Release Automation | ## [v4.1.0](https://github.com/voxpupuli/puppet-nftables/tree/v4.1.0) (2025-02-18) |
16 | |||
17 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v4.0.0...v4.1.0) |
||
18 | |||
19 | **Implemented enhancements:** |
||
20 | |||
21 | - Add Ubuntu 24.04 support [\#270](https://github.com/voxpupuli/puppet-nftables/pull/270) ([bastelfreak](https://github.com/bastelfreak)) |
||
22 | - Install netbase for /etc/services on Ubuntu 20.04 [\#269](https://github.com/voxpupuli/puppet-nftables/pull/269) ([traylenator](https://github.com/traylenator)) |
||
23 | - Allow puppet-systemd 8.x [\#266](https://github.com/voxpupuli/puppet-nftables/pull/266) ([jay7x](https://github.com/jay7x)) |
||
24 | - add icinga2 rule for outgoing traffic [\#260](https://github.com/voxpupuli/puppet-nftables/pull/260) ([SimonHoenscheid](https://github.com/SimonHoenscheid)) |
||
25 | |||
26 | e8dd4ad3 | Tim Meusel | ## [v4.0.0](https://github.com/voxpupuli/puppet-nftables/tree/v4.0.0) (2024-08-05) |
27 | |||
28 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.7.1...v4.0.0) |
||
29 | |||
30 | **Breaking changes:** |
||
31 | |||
32 | - Drop EOL CentOS 8 support [\#245](https://github.com/voxpupuli/puppet-nftables/pull/245) ([traylenator](https://github.com/traylenator)) |
||
33 | |||
34 | **Implemented enhancements:** |
||
35 | |||
36 | - add support for conntrack helpers [\#207](https://github.com/voxpupuli/puppet-nftables/issues/207) |
||
37 | - New parameter purge\_unmanaged\_rules to reload nftables if configuration does not match reality [\#253](https://github.com/voxpupuli/puppet-nftables/pull/253) ([canihavethisone](https://github.com/canihavethisone)) |
||
38 | - Add support Arrays of source/destination IP addresses for nftables::simplerule [\#252](https://github.com/voxpupuli/puppet-nftables/pull/252) ([phaedriel](https://github.com/phaedriel)) |
||
39 | - New clobber\_default\_config paramater [\#247](https://github.com/voxpupuli/puppet-nftables/pull/247) ([traylenator](https://github.com/traylenator)) |
||
40 | - update puppet-systemd upper bound to 8.0.0 [\#242](https://github.com/voxpupuli/puppet-nftables/pull/242) ([TheMeier](https://github.com/TheMeier)) |
||
41 | - rules::llmnr: Allow interface filtering [\#235](https://github.com/voxpupuli/puppet-nftables/pull/235) ([bastelfreak](https://github.com/bastelfreak)) |
||
42 | - rules::ospf3 & rules::out::ospf3: Allow filtering on outgoing interfaces [\#234](https://github.com/voxpupuli/puppet-nftables/pull/234) ([bastelfreak](https://github.com/bastelfreak)) |
||
43 | - rules::out::mdns & rules::mdns: Allow interface filtering [\#233](https://github.com/voxpupuli/puppet-nftables/pull/233) ([bastelfreak](https://github.com/bastelfreak)) |
||
44 | |||
45 | **Merged pull requests:** |
||
46 | |||
47 | - Run default destroying acceptance tests at end [\#249](https://github.com/voxpupuli/puppet-nftables/pull/249) ([traylenator](https://github.com/traylenator)) |
||
48 | - Accept on Debian 11 nftables::set will fail [\#246](https://github.com/voxpupuli/puppet-nftables/pull/246) ([traylenator](https://github.com/traylenator)) |
||
49 | |||
50 | f2ae9eda | Tim Meusel | ## [v3.7.1](https://github.com/voxpupuli/puppet-nftables/tree/v3.7.1) (2023-12-29) |
51 | |||
52 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.7.0...v3.7.1) |
||
53 | |||
54 | **Fixed bugs:** |
||
55 | |||
56 | - rules::icmp: Allow ICMP packets with extensions [\#231](https://github.com/voxpupuli/puppet-nftables/pull/231) ([bastelfreak](https://github.com/bastelfreak)) |
||
57 | - out::icmp: simplify filtering/fix ICMP bug [\#230](https://github.com/voxpupuli/puppet-nftables/pull/230) ([bastelfreak](https://github.com/bastelfreak)) |
||
58 | |||
59 | af0bf18a | Tim Meusel | ## [v3.7.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.7.0) (2023-12-27) |
60 | |||
61 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.6.0...v3.7.0) |
||
62 | |||
63 | **Implemented enhancements:** |
||
64 | |||
65 | - simplerule: Allow multiple oifname/iifname [\#228](https://github.com/voxpupuli/puppet-nftables/pull/228) ([bastelfreak](https://github.com/bastelfreak)) |
||
66 | |||
67 | 47ef2987 | Tim Meusel | ## [v3.6.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.6.0) (2023-12-20) |
68 | |||
69 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.5.0...v3.6.0) |
||
70 | |||
71 | **Implemented enhancements:** |
||
72 | |||
73 | - Make "dropping invalid packets" configureable [\#225](https://github.com/voxpupuli/puppet-nftables/pull/225) ([bastelfreak](https://github.com/bastelfreak)) |
||
74 | - simplerule: Add support for outgoing interface filtering [\#224](https://github.com/voxpupuli/puppet-nftables/pull/224) ([bastelfreak](https://github.com/bastelfreak)) |
||
75 | - simplerule: Add support for incoming interface filtering [\#221](https://github.com/voxpupuli/puppet-nftables/pull/221) ([bastelfreak](https://github.com/bastelfreak)) |
||
76 | |||
77 | **Merged pull requests:** |
||
78 | |||
79 | - rules::out:dns: refactor for better readability [\#222](https://github.com/voxpupuli/puppet-nftables/pull/222) ([bastelfreak](https://github.com/bastelfreak)) |
||
80 | - Document what the 'auto\_merge' set parameter does. [\#219](https://github.com/voxpupuli/puppet-nftables/pull/219) ([Tamerz](https://github.com/Tamerz)) |
||
81 | |||
82 | f301ff5e | Steve Traylen | ## [v3.5.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.5.0) (2023-11-27) |
83 | |||
84 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.4.0...v3.5.0) |
||
85 | |||
86 | **Implemented enhancements:** |
||
87 | |||
88 | - Support input interface specification to dns server [\#215](https://github.com/voxpupuli/puppet-nftables/pull/215) ([traylenator](https://github.com/traylenator)) |
||
89 | - Additional rules for podman root containers [\#214](https://github.com/voxpupuli/puppet-nftables/pull/214) ([traylenator](https://github.com/traylenator)) |
||
90 | - nftables::simplerule::dport - takes port ranges as part of the array [\#189](https://github.com/voxpupuli/puppet-nftables/pull/189) ([tskirvin](https://github.com/tskirvin)) |
||
91 | |||
92 | **Merged pull requests:** |
||
93 | |||
94 | - Example how to redirect one port to another [\#183](https://github.com/voxpupuli/puppet-nftables/pull/183) ([traylenator](https://github.com/traylenator)) |
||
95 | |||
96 | 54b5cf0b | Tim Meusel | ## [v3.4.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.4.0) (2023-11-17) |
97 | |||
98 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.3.0...v3.4.0) |
||
99 | |||
100 | **Implemented enhancements:** |
||
101 | |||
102 | - allow puppet/systemd v6 [\#213](https://github.com/voxpupuli/puppet-nftables/pull/213) ([vchepkov](https://github.com/vchepkov)) |
||
103 | - Add Debian 12 support [\#211](https://github.com/voxpupuli/puppet-nftables/pull/211) ([bastelfreak](https://github.com/bastelfreak)) |
||
104 | - provide an option to disable logging rejected packets [\#209](https://github.com/voxpupuli/puppet-nftables/pull/209) ([vchepkov](https://github.com/vchepkov)) |
||
105 | - add ftp helper [\#208](https://github.com/voxpupuli/puppet-nftables/pull/208) ([vchepkov](https://github.com/vchepkov)) |
||
106 | |||
107 | c723df84 | Tim Meusel | ## [v3.3.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.3.0) (2023-08-28) |
108 | |||
109 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.2.0...v3.3.0) |
||
110 | |||
111 | **Implemented enhancements:** |
||
112 | |||
113 | - samba: Add option to drop traffic [\#204](https://github.com/voxpupuli/puppet-nftables/pull/204) ([bastelfreak](https://github.com/bastelfreak)) |
||
114 | - Add nftables rules for ws-discovery [\#203](https://github.com/voxpupuli/puppet-nftables/pull/203) ([bastelfreak](https://github.com/bastelfreak)) |
||
115 | - Add rule for incoming SSDP [\#202](https://github.com/voxpupuli/puppet-nftables/pull/202) ([bastelfreak](https://github.com/bastelfreak)) |
||
116 | - Add rule for incoming LLMNR [\#201](https://github.com/voxpupuli/puppet-nftables/pull/201) ([bastelfreak](https://github.com/bastelfreak)) |
||
117 | |||
118 | 3e3f3c50 | Tim Meusel | ## [v3.2.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.2.0) (2023-08-19) |
119 | |||
120 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.1.0...v3.2.0) |
||
121 | |||
122 | **Implemented enhancements:** |
||
123 | |||
124 | - Add rule for outgoing multicast DNS [\#199](https://github.com/voxpupuli/puppet-nftables/pull/199) ([bastelfreak](https://github.com/bastelfreak)) |
||
125 | - Add rule for multicast listener requests \(MLDv2\) [\#198](https://github.com/voxpupuli/puppet-nftables/pull/198) ([bastelfreak](https://github.com/bastelfreak)) |
||
126 | - Add rules for IGMP [\#194](https://github.com/voxpupuli/puppet-nftables/pull/194) ([bastelfreak](https://github.com/bastelfreak)) |
||
127 | - mDNS: Allow udp port 5353 [\#193](https://github.com/voxpupuli/puppet-nftables/pull/193) ([bastelfreak](https://github.com/bastelfreak)) |
||
128 | - Add rule to allow incoming spotify broadcast [\#192](https://github.com/voxpupuli/puppet-nftables/pull/192) ([bastelfreak](https://github.com/bastelfreak)) |
||
129 | - Add rule to allow multicast DNS [\#191](https://github.com/voxpupuli/puppet-nftables/pull/191) ([bastelfreak](https://github.com/bastelfreak)) |
||
130 | - Add rule to allow incoming multicast traffic [\#190](https://github.com/voxpupuli/puppet-nftables/pull/190) ([bastelfreak](https://github.com/bastelfreak)) |
||
131 | - Declare stdlib v9 support [\#180](https://github.com/voxpupuli/puppet-nftables/pull/180) ([traylenator](https://github.com/traylenator)) |
||
132 | |||
133 | **Fixed bugs:** |
||
134 | |||
135 | - Add missing unit string for timeout,gc-interval [\#187](https://github.com/voxpupuli/puppet-nftables/pull/187) ([javier-angulo](https://github.com/javier-angulo)) |
||
136 | |||
137 | **Merged pull requests:** |
||
138 | |||
139 | - Rewrite mdns rules to limit to multicast and allow IPv6 [\#197](https://github.com/voxpupuli/puppet-nftables/pull/197) ([ekohl](https://github.com/ekohl)) |
||
140 | |||
141 | ## [v3.1.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.1.0) (2023-07-30) |
||
142 | cedfa7db | Tim Meusel | |
143 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.0.1...v3.1.0) |
||
144 | |||
145 | **Implemented enhancements:** |
||
146 | |||
147 | - puppetlabs/stdlib: Allow 9.x [\#182](https://github.com/voxpupuli/puppet-nftables/pull/182) ([bastelfreak](https://github.com/bastelfreak)) |
||
148 | - Declare puppet v8 support [\#181](https://github.com/voxpupuli/puppet-nftables/pull/181) ([traylenator](https://github.com/traylenator)) |
||
149 | |||
150 | **Merged pull requests:** |
||
151 | |||
152 | - puppetlabs/concat: Allow 9.x [\#185](https://github.com/voxpupuli/puppet-nftables/pull/185) ([bastelfreak](https://github.com/bastelfreak)) |
||
153 | |||
154 | b09c1fa4 | Simon Hoenscheid | ## [v3.0.1](https://github.com/voxpupuli/puppet-nftables/tree/v3.0.1) (2023-06-20) |
155 | |||
156 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v3.0.0...v3.0.1) |
||
157 | |||
158 | cedfa7db | Tim Meusel | **Implemented enhancements:** |
159 | |||
160 | - add ldap and active directory rules [\#177](https://github.com/voxpupuli/puppet-nftables/pull/177) ([SimonHoenscheid](https://github.com/SimonHoenscheid)) |
||
161 | |||
162 | b09c1fa4 | Simon Hoenscheid | **Closed issues:** |
163 | |||
164 | - rspec tests fail on docker again. [\#167](https://github.com/voxpupuli/puppet-nftables/issues/167) |
||
165 | |||
166 | **Merged pull requests:** |
||
167 | |||
168 | - Increased puppet/systemd upper limit to \< 6.0.0 [\#176](https://github.com/voxpupuli/puppet-nftables/pull/176) ([canihavethisone](https://github.com/canihavethisone)) |
||
169 | |||
170 | ## [v3.0.0](https://github.com/voxpupuli/puppet-nftables/tree/v3.0.0) (2023-05-25) |
||
171 | 84baa533 | Steve Traylen | |
172 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.6.1...v3.0.0) |
||
173 | |||
174 | **Breaking changes:** |
||
175 | |||
176 | - Drop puppet 6 support [\#173](https://github.com/voxpupuli/puppet-nftables/pull/173) ([traylenator](https://github.com/traylenator)) |
||
177 | |||
178 | **Implemented enhancements:** |
||
179 | |||
180 | - Raise puppetlabs/concat upper limit to \< 9.0.0 [\#170](https://github.com/voxpupuli/puppet-nftables/pull/170) ([canihavethisone](https://github.com/canihavethisone)) |
||
181 | |||
182 | **Merged pull requests:** |
||
183 | |||
184 | - Refresh REFERENCE [\#171](https://github.com/voxpupuli/puppet-nftables/pull/171) ([traylenator](https://github.com/traylenator)) |
||
185 | - Fix typo in icinga2 rule documentation [\#169](https://github.com/voxpupuli/puppet-nftables/pull/169) ([baldurmen](https://github.com/baldurmen)) |
||
186 | |||
187 | ## [v2.6.1](https://github.com/voxpupuli/puppet-nftables/tree/v2.6.1) (2023-03-24) |
||
188 | 2f8b600b | Steve Traylen | |
189 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.6.0...v2.6.1) |
||
190 | |||
191 | **Implemented enhancements:** |
||
192 | |||
193 | - Add bridge as a valid family for chain tables [\#165](https://github.com/voxpupuli/puppet-nftables/pull/165) ([luisfdez](https://github.com/luisfdez)) |
||
194 | - Add Rocky 8 and 9 support [\#161](https://github.com/voxpupuli/puppet-nftables/pull/161) ([bastelfreak](https://github.com/bastelfreak)) |
||
195 | - Declare AlmaLinux8 and AlmaLinux9 support [\#160](https://github.com/voxpupuli/puppet-nftables/pull/160) ([nbarrientos](https://github.com/nbarrientos)) |
||
196 | - bump puppet/systemd to \< 5.0.0 [\#159](https://github.com/voxpupuli/puppet-nftables/pull/159) ([jhoblitt](https://github.com/jhoblitt)) |
||
197 | - Allow netdev as table family in defined type nftables::chain [\#149](https://github.com/voxpupuli/puppet-nftables/pull/149) ([hugendudel](https://github.com/hugendudel)) |
||
198 | |||
199 | **Fixed bugs:** |
||
200 | |||
201 | - Align filemode on RedHat to distro default [\#157](https://github.com/voxpupuli/puppet-nftables/pull/157) ([duritong](https://github.com/duritong)) |
||
202 | |||
203 | **Closed issues:** |
||
204 | |||
205 | - failing to setup a basic firewall [\#158](https://github.com/voxpupuli/puppet-nftables/issues/158) |
||
206 | |||
207 | **Merged pull requests:** |
||
208 | |||
209 | - README improvements [\#162](https://github.com/voxpupuli/puppet-nftables/pull/162) ([anarcat](https://github.com/anarcat)) |
||
210 | |||
211 | 61491646 | Tim Meusel | ## [v2.6.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.6.0) (2022-10-25) |
212 | |||
213 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.5.0...v2.6.0) |
||
214 | |||
215 | **Implemented enhancements:** |
||
216 | |||
217 | - Add class for outgoing HKP firewalling [\#153](https://github.com/voxpupuli/puppet-nftables/pull/153) ([bastelfreak](https://github.com/bastelfreak)) |
||
218 | - Add Ubuntu support [\#152](https://github.com/voxpupuli/puppet-nftables/pull/152) ([bastelfreak](https://github.com/bastelfreak)) |
||
219 | - split conntrack management into dedicated classes [\#148](https://github.com/voxpupuli/puppet-nftables/pull/148) ([duritong](https://github.com/duritong)) |
||
220 | - New nftables::file type to include raw file [\#147](https://github.com/voxpupuli/puppet-nftables/pull/147) ([traylenator](https://github.com/traylenator)) |
||
221 | |||
222 | **Closed issues:** |
||
223 | |||
224 | - Add ability to include completely raw files [\#146](https://github.com/voxpupuli/puppet-nftables/issues/146) |
||
225 | - Add support for Debian [\#65](https://github.com/voxpupuli/puppet-nftables/issues/65) |
||
226 | |||
227 | 3b8f5945 | Steve Traylen | ## [v2.5.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.5.0) (2022-08-26) |
228 | |||
229 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.4.0...v2.5.0) |
||
230 | |||
231 | **Implemented enhancements:** |
||
232 | |||
233 | - Add all nftables families as a valid noflush pattern [\#142](https://github.com/voxpupuli/puppet-nftables/pull/142) ([luisfdez](https://github.com/luisfdez)) |
||
234 | |||
235 | **Fixed bugs:** |
||
236 | |||
237 | - Properly escape bridge in rulename [\#144](https://github.com/voxpupuli/puppet-nftables/pull/144) ([duritong](https://github.com/duritong)) |
||
238 | |||
239 | **Closed issues:** |
||
240 | |||
241 | - nftables::bridges creates invalid rule names when bridge devices have multiple IP addresses [\#143](https://github.com/voxpupuli/puppet-nftables/issues/143) |
||
242 | |||
243 | 60f3e2e6 | Tim Meusel | ## [v2.4.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.4.0) (2022-07-11) |
244 | |||
245 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.3.0...v2.4.0) |
||
246 | |||
247 | **Implemented enhancements:** |
||
248 | |||
249 | - Add rule to allow outgoing whois queries [\#140](https://github.com/voxpupuli/puppet-nftables/pull/140) ([bastelfreak](https://github.com/bastelfreak)) |
||
250 | - chrony: Allow filtering for outgoing NTP servers [\#139](https://github.com/voxpupuli/puppet-nftables/pull/139) ([bastelfreak](https://github.com/bastelfreak)) |
||
251 | - Add class for pxp-agent firewalling [\#138](https://github.com/voxpupuli/puppet-nftables/pull/138) ([bastelfreak](https://github.com/bastelfreak)) |
||
252 | |||
253 | 821ec83a | Tim Meusel | ## [v2.3.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.3.0) (2022-07-06) |
254 | |||
255 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.2.1...v2.3.0) |
||
256 | |||
257 | **Implemented enhancements:** |
||
258 | |||
259 | - systemctl: Use relative path [\#136](https://github.com/voxpupuli/puppet-nftables/pull/136) ([bastelfreak](https://github.com/bastelfreak)) |
||
260 | - Add Debian support [\#134](https://github.com/voxpupuli/puppet-nftables/pull/134) ([bastelfreak](https://github.com/bastelfreak)) |
||
261 | - make path to echo configureable [\#133](https://github.com/voxpupuli/puppet-nftables/pull/133) ([bastelfreak](https://github.com/bastelfreak)) |
||
262 | - make path to `nft` binary configureable [\#132](https://github.com/voxpupuli/puppet-nftables/pull/132) ([bastelfreak](https://github.com/bastelfreak)) |
||
263 | |||
264 | ## [v2.2.1](https://github.com/voxpupuli/puppet-nftables/tree/v2.2.1) (2022-05-02) |
||
265 | f4dcddd6 | Nacho Barrientos | |
266 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.2.0...v2.2.1) |
||
267 | |||
268 | **Merged pull requests:** |
||
269 | |||
270 | - rspec mock systemd process on docker [\#128](https://github.com/voxpupuli/puppet-nftables/pull/128) ([traylenator](https://github.com/traylenator)) |
||
271 | |||
272 | d0a1ffef | hashworks | ## [v2.2.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.2.0) (2022-02-27) |
273 | |||
274 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.1.0...v2.2.0) |
||
275 | |||
276 | **Implemented enhancements:** |
||
277 | |||
278 | - Add support for Arch Linux [\#124](https://github.com/voxpupuli/puppet-nftables/pull/124) ([hashworks](https://github.com/hashworks)) |
||
279 | - Declare support for RHEL9, CentOS9 and OL9 [\#120](https://github.com/voxpupuli/puppet-nftables/pull/120) ([nbarrientos](https://github.com/nbarrientos)) |
||
280 | - Rubocop corrections for rubocop 1.22.3 [\#118](https://github.com/voxpupuli/puppet-nftables/pull/118) ([traylenator](https://github.com/traylenator)) |
||
281 | - Use protocol number instead of label [\#112](https://github.com/voxpupuli/puppet-nftables/pull/112) ([keachi](https://github.com/keachi)) |
||
282 | |||
283 | **Fixed bugs:** |
||
284 | |||
285 | - Ensure that nftables.service remains active after it exits [\#125](https://github.com/voxpupuli/puppet-nftables/pull/125) ([hashworks](https://github.com/hashworks)) |
||
286 | |||
287 | **Merged pull requests:** |
||
288 | |||
289 | - Fix typos in initial reference examples [\#122](https://github.com/voxpupuli/puppet-nftables/pull/122) ([hashworks](https://github.com/hashworks)) |
||
290 | |||
291 | b02d6ea9 | Nacho Barrientos | ## [v2.1.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.1.0) (2021-09-14) |
292 | |||
293 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v2.0.0...v2.1.0) |
||
294 | |||
295 | **Implemented enhancements:** |
||
296 | |||
297 | - nftables::set can only be assigned to 1 table [\#100](https://github.com/voxpupuli/puppet-nftables/issues/100) |
||
298 | - support a different table name for 'nat' [\#107](https://github.com/voxpupuli/puppet-nftables/pull/107) ([figless](https://github.com/figless)) |
||
299 | - Allow declaring the same set in several tables [\#102](https://github.com/voxpupuli/puppet-nftables/pull/102) ([nbarrientos](https://github.com/nbarrientos)) |
||
300 | |||
301 | **Fixed bugs:** |
||
302 | |||
303 | - fix datatype for $table and $dport [\#104](https://github.com/voxpupuli/puppet-nftables/pull/104) ([bastelfreak](https://github.com/bastelfreak)) |
||
304 | |||
305 | **Merged pull requests:** |
||
306 | |||
307 | - Allow stdlib 8.0.0 [\#106](https://github.com/voxpupuli/puppet-nftables/pull/106) ([smortex](https://github.com/smortex)) |
||
308 | - switch from camptocamp/systemd to voxpupuli/systemd [\#103](https://github.com/voxpupuli/puppet-nftables/pull/103) ([bastelfreak](https://github.com/bastelfreak)) |
||
309 | - pull fixtures from git and not forge [\#99](https://github.com/voxpupuli/puppet-nftables/pull/99) ([bastelfreak](https://github.com/bastelfreak)) |
||
310 | |||
311 | ## [v2.0.0](https://github.com/voxpupuli/puppet-nftables/tree/v2.0.0) (2021-06-03) |
||
312 | 683d1049 | Nacho Barrientos | |
313 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v1.3.0...v2.0.0) |
||
314 | |||
315 | **Breaking changes:** |
||
316 | |||
317 | - Drop Puppet 5, puppetlabs/concat 7.x, puppetlabs/stdlib 7.x, camptocamp/systemd: 3.x [\#92](https://github.com/voxpupuli/puppet-nftables/pull/92) ([traylenator](https://github.com/traylenator)) |
||
318 | - Drop Puppet 5 support [\#79](https://github.com/voxpupuli/puppet-nftables/pull/79) ([kenyon](https://github.com/kenyon)) |
||
319 | |||
320 | **Implemented enhancements:** |
||
321 | |||
322 | - Ability to set base chains [\#95](https://github.com/voxpupuli/puppet-nftables/issues/95) |
||
323 | - puppetlabs/concat: Allow 7.x [\#91](https://github.com/voxpupuli/puppet-nftables/pull/91) ([bastelfreak](https://github.com/bastelfreak)) |
||
324 | - puppetlabs/stdlib: Allow 7.x [\#90](https://github.com/voxpupuli/puppet-nftables/pull/90) ([bastelfreak](https://github.com/bastelfreak)) |
||
325 | - camptocamp/systemd: allow 3.x [\#89](https://github.com/voxpupuli/puppet-nftables/pull/89) ([bastelfreak](https://github.com/bastelfreak)) |
||
326 | |||
327 | **Fixed bugs:** |
||
328 | |||
329 | - Fix IPv4 source address type detection [\#93](https://github.com/voxpupuli/puppet-nftables/pull/93) ([nbarrientos](https://github.com/nbarrientos)) |
||
330 | |||
331 | **Closed issues:** |
||
332 | |||
333 | - Class\[Nftables::Bridges\]\['bridgenames'\] contains a Regexp value. It will be converted to the String '/^br.+/' [\#83](https://github.com/voxpupuli/puppet-nftables/issues/83) |
||
334 | |||
335 | **Merged pull requests:** |
||
336 | |||
337 | - Allow creating a totally empty firewall [\#96](https://github.com/voxpupuli/puppet-nftables/pull/96) ([nbarrientos](https://github.com/nbarrientos)) |
||
338 | - Amend link to Yasnippets [\#88](https://github.com/voxpupuli/puppet-nftables/pull/88) ([nbarrientos](https://github.com/nbarrientos)) |
||
339 | |||
340 | 804b96e4 | Nacho Barrientos | ## [v1.3.0](https://github.com/voxpupuli/puppet-nftables/tree/v1.3.0) (2021-03-25) |
341 | |||
342 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v1.2.0...v1.3.0) |
||
343 | |||
344 | **Implemented enhancements:** |
||
345 | |||
346 | - Add rules for QEMU/libvirt guests \(bridged virtual networking\) [\#85](https://github.com/voxpupuli/puppet-nftables/pull/85) ([nbarrientos](https://github.com/nbarrientos)) |
||
347 | - Add nftables.version to structured fact. [\#84](https://github.com/voxpupuli/puppet-nftables/pull/84) ([traylenator](https://github.com/traylenator)) |
||
348 | - Add rules for Apache ActiveMQ [\#82](https://github.com/voxpupuli/puppet-nftables/pull/82) ([nbarrientos](https://github.com/nbarrientos)) |
||
349 | - Add Docker-CE default rules [\#80](https://github.com/voxpupuli/puppet-nftables/pull/80) ([luisfdez](https://github.com/luisfdez)) |
||
350 | |||
351 | b02d6ea9 | Nacho Barrientos | **Closed issues:** |
352 | |||
353 | - Increase puppetlabs/concat version in metadata [\#78](https://github.com/voxpupuli/puppet-nftables/issues/78) |
||
354 | |||
355 | 804b96e4 | Nacho Barrientos | **Merged pull requests:** |
356 | |||
357 | - Fix sections and add a pointer to code snippets for Emacs [\#81](https://github.com/voxpupuli/puppet-nftables/pull/81) ([nbarrientos](https://github.com/nbarrientos)) |
||
358 | |||
359 | ## [v1.2.0](https://github.com/voxpupuli/puppet-nftables/tree/v1.2.0) (2021-03-03) |
||
360 | 05c7f19d | Steve Traylen | |
361 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v1.1.1...v1.2.0) |
||
362 | |||
363 | **Implemented enhancements:** |
||
364 | |||
365 | - start declaring the 'global' chain with module resources [\#73](https://github.com/voxpupuli/puppet-nftables/pull/73) ([lelutin](https://github.com/lelutin)) |
||
366 | |||
367 | **Fixed bugs:** |
||
368 | |||
369 | - nftables service is broken after reboot [\#74](https://github.com/voxpupuli/puppet-nftables/issues/74) |
||
370 | - fix \#74 - ensure table are initialized before flushing them [\#75](https://github.com/voxpupuli/puppet-nftables/pull/75) ([duritong](https://github.com/duritong)) |
||
371 | |||
372 | bd0d7998 | Steve Traylen | ## [v1.1.1](https://github.com/voxpupuli/puppet-nftables/tree/v1.1.1) (2021-01-29) |
373 | |||
374 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v1.1.0...v1.1.1) |
||
375 | |||
376 | **Fixed bugs:** |
||
377 | |||
378 | - Simplerule: wrong IP protocol version filter statement for IPv6 traffic [\#69](https://github.com/voxpupuli/puppet-nftables/issues/69) |
||
379 | - Fix IP version filter for IPv6 traffic [\#70](https://github.com/voxpupuli/puppet-nftables/pull/70) ([nbarrientos](https://github.com/nbarrientos)) |
||
380 | |||
381 | **Merged pull requests:** |
||
382 | |||
383 | - Improve nftables::rule's documentation [\#68](https://github.com/voxpupuli/puppet-nftables/pull/68) ([nbarrientos](https://github.com/nbarrientos)) |
||
384 | |||
385 | afc4dd16 | Steve Traylen | ## [v1.1.0](https://github.com/voxpupuli/puppet-nftables/tree/v1.1.0) (2021-01-25) |
386 | |||
387 | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/v1.0.0...v1.1.0) |
||
388 | |||
389 | **Implemented enhancements:** |
||
390 | |||
391 | - Enable parameter\_documentation lint [\#64](https://github.com/voxpupuli/puppet-nftables/pull/64) ([traylenator](https://github.com/traylenator)) |
||
392 | - Add Samba in rules [\#62](https://github.com/voxpupuli/puppet-nftables/pull/62) ([glpatcern](https://github.com/glpatcern)) |
||
393 | - Add some mail related outgoing rules [\#60](https://github.com/voxpupuli/puppet-nftables/pull/60) ([duritong](https://github.com/duritong)) |
||
394 | |||
395 | **Fixed bugs:** |
||
396 | |||
397 | - nftables::simplerule should follow the same rules as nftables::rule [\#58](https://github.com/voxpupuli/puppet-nftables/issues/58) |
||
398 | - Align simplerule and rule rulename requirements [\#59](https://github.com/voxpupuli/puppet-nftables/pull/59) ([nbarrientos](https://github.com/nbarrientos)) |
||
399 | |||
400 | **Closed issues:** |
||
401 | |||
402 | - Get it under the voxpupuli umbrella [\#35](https://github.com/voxpupuli/puppet-nftables/issues/35) |
||
403 | |||
404 | **Merged pull requests:** |
||
405 | |||
406 | - Add badges to README [\#63](https://github.com/voxpupuli/puppet-nftables/pull/63) ([traylenator](https://github.com/traylenator)) |
||
407 | - Check that all the predefined rules are declared in the all rules acceptance test [\#53](https://github.com/voxpupuli/puppet-nftables/pull/53) ([nbarrientos](https://github.com/nbarrientos)) |
||
408 | |||
409 | bc1b0f1a | Steve Traylen | ## [v1.0.0](https://github.com/voxpupuli/puppet-nftables/tree/v1.0.0) (2020-12-15) |
410 | ece9be27 | tr | |
411 | bc1b0f1a | Steve Traylen | [Full Changelog](https://github.com/voxpupuli/puppet-nftables/compare/0ba57c66a35ed4e9b570d8a6315a33a1c4ba3181...v1.0.0) |
412 | ece9be27 | tr | |
413 | bc1b0f1a | Steve Traylen | **Breaking changes:** |
414 | ece9be27 | tr | |
415 | bc1b0f1a | Steve Traylen | - switch the server naming [\#42](https://github.com/voxpupuli/puppet-nftables/pull/42) ([duritong](https://github.com/duritong)) |
416 | |||
417 | **Implemented enhancements:** |
||
418 | |||
419 | - Use Stdlib::Port everywhere in place of Integer [\#56](https://github.com/voxpupuli/puppet-nftables/pull/56) ([traylenator](https://github.com/traylenator)) |
||
420 | - Enable Puppet 7 support [\#51](https://github.com/voxpupuli/puppet-nftables/pull/51) ([bastelfreak](https://github.com/bastelfreak)) |
||
421 | - Several fixes for nftables::config [\#48](https://github.com/voxpupuli/puppet-nftables/pull/48) ([nbarrientos](https://github.com/nbarrientos)) |
||
422 | - rubocop corrections [\#41](https://github.com/voxpupuli/puppet-nftables/pull/41) ([traylenator](https://github.com/traylenator)) |
||
423 | - Add basic configuration validation acceptance test [\#38](https://github.com/voxpupuli/puppet-nftables/pull/38) ([traylenator](https://github.com/traylenator)) |
||
424 | - Remove duplicate flush on reload [\#34](https://github.com/voxpupuli/puppet-nftables/pull/34) ([traylenator](https://github.com/traylenator)) |
||
425 | - Add nftables::simplerule [\#33](https://github.com/voxpupuli/puppet-nftables/pull/33) ([nbarrientos](https://github.com/nbarrientos)) |
||
426 | - Add Ceph and NFS rules [\#32](https://github.com/voxpupuli/puppet-nftables/pull/32) ([dvanders](https://github.com/dvanders)) |
||
427 | - New parameter noflush\_tables to selectivly skip flush [\#31](https://github.com/voxpupuli/puppet-nftables/pull/31) ([traylenator](https://github.com/traylenator)) |
||
428 | - Scientific Linux 8 will never exist [\#30](https://github.com/voxpupuli/puppet-nftables/pull/30) ([traylenator](https://github.com/traylenator)) |
||
429 | - Enable conntrack in FORWARD [\#29](https://github.com/voxpupuli/puppet-nftables/pull/29) ([keachi](https://github.com/keachi)) |
||
430 | - Do not test nftables::rules repeatadly [\#28](https://github.com/voxpupuli/puppet-nftables/pull/28) ([traylenator](https://github.com/traylenator)) |
||
431 | - Allow sourcing sets from Hiera [\#26](https://github.com/voxpupuli/puppet-nftables/pull/26) ([nbarrientos](https://github.com/nbarrientos)) |
||
432 | - Allow disabling default NAT tables and chains [\#25](https://github.com/voxpupuli/puppet-nftables/pull/25) ([nbarrientos](https://github.com/nbarrientos)) |
||
433 | - Set a customisable rate limit to the logging rules [\#22](https://github.com/voxpupuli/puppet-nftables/pull/22) ([nbarrientos](https://github.com/nbarrientos)) |
||
434 | - Make masking Service\['firewalld'\] optional [\#20](https://github.com/voxpupuli/puppet-nftables/pull/20) ([nbarrientos](https://github.com/nbarrientos)) |
||
435 | - Move ICMP stuff to separate classes allowing better customisation [\#16](https://github.com/voxpupuli/puppet-nftables/pull/16) ([nbarrientos](https://github.com/nbarrientos)) |
||
436 | - Move conntrack rules from global to INPUT and OUTPUT [\#14](https://github.com/voxpupuli/puppet-nftables/pull/14) ([nbarrientos](https://github.com/nbarrientos)) |
||
437 | - Add comments for all the nftable::rules entries [\#13](https://github.com/voxpupuli/puppet-nftables/pull/13) ([traylenator](https://github.com/traylenator)) |
||
438 | - Allow tables to add comments to $log\_prefix [\#12](https://github.com/voxpupuli/puppet-nftables/pull/12) ([nbarrientos](https://github.com/nbarrientos)) |
||
439 | - Reload rules atomically and verify rules before deploy [\#10](https://github.com/voxpupuli/puppet-nftables/pull/10) ([traylenator](https://github.com/traylenator)) |
||
440 | - Allow raw sets and dashes in set names [\#8](https://github.com/voxpupuli/puppet-nftables/pull/8) ([nbarrientos](https://github.com/nbarrientos)) |
||
441 | - Add a parameter to control the fate of discarded traffic [\#7](https://github.com/voxpupuli/puppet-nftables/pull/7) ([nbarrientos](https://github.com/nbarrientos)) |
||
442 | - Add rules for afs3\_callback in and out rules for kerberos and openafs. [\#6](https://github.com/voxpupuli/puppet-nftables/pull/6) ([traylenator](https://github.com/traylenator)) |
||
443 | - Allow customising the log prefix [\#5](https://github.com/voxpupuli/puppet-nftables/pull/5) ([nbarrientos](https://github.com/nbarrientos)) |
||
444 | - Add classes encapsulating rules for DHCPv6 client traffic \(in/out\) [\#4](https://github.com/voxpupuli/puppet-nftables/pull/4) ([nbarrientos](https://github.com/nbarrientos)) |
||
445 | - Add support for named sets [\#3](https://github.com/voxpupuli/puppet-nftables/pull/3) ([nbarrientos](https://github.com/nbarrientos)) |
||
446 | - New parameter out\_all, default false [\#1](https://github.com/voxpupuli/puppet-nftables/pull/1) ([traylenator](https://github.com/traylenator)) |
||
447 | |||
448 | **Fixed bugs:** |
||
449 | |||
450 | - Correct nfs3 invalid udp /tcp matching rule and more tests [\#50](https://github.com/voxpupuli/puppet-nftables/pull/50) ([traylenator](https://github.com/traylenator)) |
||
451 | - Prefix custom tables with custom- so they're loaded [\#47](https://github.com/voxpupuli/puppet-nftables/pull/47) ([nbarrientos](https://github.com/nbarrientos)) |
||
452 | - Correct bad merge [\#15](https://github.com/voxpupuli/puppet-nftables/pull/15) ([traylenator](https://github.com/traylenator)) |
||
453 | |||
454 | **Closed issues:** |
||
455 | |||
456 | - deploying custom tables is broken [\#45](https://github.com/voxpupuli/puppet-nftables/issues/45) |
||
457 | - Switch to Stdlib::Port everywhere [\#37](https://github.com/voxpupuli/puppet-nftables/issues/37) |
||
458 | - Add set definition from Hiera [\#24](https://github.com/voxpupuli/puppet-nftables/issues/24) |
||
459 | - Add an option to disable NAT [\#23](https://github.com/voxpupuli/puppet-nftables/issues/23) |
||
460 | - Add an option to limit the rate of logged messages [\#19](https://github.com/voxpupuli/puppet-nftables/issues/19) |
||
461 | - Rule API [\#17](https://github.com/voxpupuli/puppet-nftables/issues/17) |
||
462 | - Publish to forge.puppet.com [\#11](https://github.com/voxpupuli/puppet-nftables/issues/11) |
||
463 | - The global chain contains INPUT specific rules [\#9](https://github.com/voxpupuli/puppet-nftables/issues/9) |
||
464 | - The fate of forbidden packets should be configurable [\#2](https://github.com/voxpupuli/puppet-nftables/issues/2) |
||
465 | |||
466 | **Merged pull requests:** |
||
467 | |||
468 | - Docs for nftables::set [\#55](https://github.com/voxpupuli/puppet-nftables/pull/55) ([traylenator](https://github.com/traylenator)) |
||
469 | - Remove a blank separating the doc string and the code [\#52](https://github.com/voxpupuli/puppet-nftables/pull/52) ([nbarrientos](https://github.com/nbarrientos)) |
||
470 | afc4dd16 | Steve Traylen | - Release 1.0.0 [\#49](https://github.com/voxpupuli/puppet-nftables/pull/49) ([traylenator](https://github.com/traylenator)) |
471 | bc1b0f1a | Steve Traylen | - Correct layout of ignore table example [\#44](https://github.com/voxpupuli/puppet-nftables/pull/44) ([traylenator](https://github.com/traylenator)) |
472 | - Fix typos and formatting in the README [\#43](https://github.com/voxpupuli/puppet-nftables/pull/43) ([nbarrientos](https://github.com/nbarrientos)) |
||
473 | - Comment why firewalld\_enable parameter is required [\#40](https://github.com/voxpupuli/puppet-nftables/pull/40) ([traylenator](https://github.com/traylenator)) |
||
474 | - modulesync 4.0.0 [\#36](https://github.com/voxpupuli/puppet-nftables/pull/36) ([traylenator](https://github.com/traylenator)) |
||
475 | - Refresh REFERENCE [\#27](https://github.com/voxpupuli/puppet-nftables/pull/27) ([traylenator](https://github.com/traylenator)) |
||
476 | |||
477 | |||
478 | |||
479 | \* *This Changelog was automatically generated by [github_changelog_generator](https://github.com/github-changelog-generator/github-changelog-generator)* |