]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ferm/manifests/init.pp
add log/drop rule
[dsa-puppet.git] / modules / ferm / manifests / init.pp
index 0fa60634d3f0004f8d33a099b60b24b212e23418..f5dd60f73fb68cb54f7e1d92bc9c8ff2951ce416 100644 (file)
@@ -10,15 +10,49 @@ class ferm {
                }
        }
 
+        # realize (i.e. enable) all @ferm::rule virtual resources
+        Ferm::Rule <| |>
+
+        package { ferm: ensure => installed }
+
         file { 
-                "/etc/ferm": 
-                        ensure => directory;
-                "/etc/ferm/dsa.d": 
-                        ensure => directory;
+                "/etc/ferm/dsa.d":
+                        ensure => directory,
+                        purge   => true,
+                        force   => true,
+                        recurse => true,
+                        source  => "puppet:///files/empty/",
+                        require => Package["ferm"];
+                "/etc/ferm/conf.d":
+                        ensure => directory,
+                        require => Package["ferm"];
+                "/etc/ferm/ferm.conf":
+                        source  => "puppet:///ferm/ferm.conf",
+                        require => Package["ferm"],
+                        mode    => 0400,
+                        notify  => Exec["ferm restart"];
+                "/etc/ferm/conf.d/me.conf":
+                        content => template("ferm/me.conf.erb"),
+                        require => Package["ferm"],
+                        mode    => 0400,
+                        notify  => Exec["ferm restart"];
+                "/etc/ferm/conf.d/defs.conf":
+                        source  => "puppet:///ferm/defs.conf",
+                        require => Package["ferm"],
+                        mode    => 0400,
+                        notify  => Exec["ferm restart"];
         }
 
+        ferm::rule {
+                domain          => "(ip ip6)",
+                description     => "Drop everything else",
+                prio            => "99",
+                rule            => "jump log_or_drop"
+        }
+
+
         exec { "ferm restart":
-                command     => "/bin/true",
+                command     => "/etc/init.d/ferm restart",
                 refreshonly => true,
         }