]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ferm/manifests/per-host.pp
retire ravel
[dsa-puppet.git] / modules / ferm / manifests / per-host.pp
index 00537576cd87d947bb827faa4b961f5e3f201caa..0e14027023fea5bb1c8a308540f96dc65c65215a 100644 (file)
@@ -3,7 +3,7 @@ class ferm::per-host {
                include ferm::zivit
        }
 
-       if $::hostname in [glinka,klecker,ravel,rietz,senfl,sibelius] {
+       if $::hostname in [glinka,klecker,rietz,sibelius] {
                ferm::rule { 'dsa-rsync':
                        domain      => '(ip ip6)',
                        description => 'Allow rsync access',
@@ -263,12 +263,18 @@ class ferm::per-host {
                default: {}
        }
 
-       # solr stuff
+       # elasticsearch stuff
        case $::hostname {
                stockhausen: {
-                       @ferm::rule { 'dsa-solr-jetty':
-                               description     => 'Allow jetty access',
-                               rule            => '&SERVICE_RANGE(tcp, 8080, ( 82.195.75.100/32 ))'
+                       @ferm::rule { 'dsa-elasticsearch-bendel':
+                               domain          => '(ip)',
+                               description     => 'Allow elasticsearch access from bendel',
+                               rule            => '&SERVICE_RANGE(tcp, 9200:9300, ( 82.195.75.100/32 ))'
+                       }
+                       @ferm::rule { 'dsa-elasticsearch-bendel6':
+                               domain          => '(ip6)',
+                               description     => 'Allow elasticsearch access from bendel',
+                               rule            => '&SERVICE_RANGE(tcp, 9200:9300, ( 2001:41b8:202:deb:216:36ff:fe40:4002/128 ))'
                        }
                }
        }