Kudos on saving the state and providing locking around that state. As
long as you can ensure that this module is the only thing manipulating
iptables on the hosts you are managing, then there should be no
issues. In the project I work on, we don't have that guarantee, so we
work around it by adding a chain to minimize the possibility of
conflicts with other services managing iptables. It doesn't completely
solve the issue, but it has improved reliability in practice.
--
Jason DeTiberus