mariadb: do not open holes in the firewall for mariadb

We always run mariadb on the host where the service is located which
requires a mariadb database.
......@@ -46,12 +46,3 @@
- name: install zabbix mysql config
template: dest=/etc/zabbix/ owner=zabbix-agent group=zabbix-agent mode=0600
# the source addresses here could be tightened up more, but it's far better
# than having mariadb open to the world
- name: open firewall holes to other infrastructure hosts
firewalld: service=mysql permanent=true state="{{'disabled' if mariadb_skip_networking else 'enabled'}}" source={{item}} immediate=yes
with_items: "{{ groups['all'] }}"
when: configure_firewall
- firewall
