]> git.donarmstrong.com Git - dsa-puppet.git/blob - modules/roles/manifests/sip.pp
try concatenation
[dsa-puppet.git] / modules / roles / manifests / sip.pp
1 class roles::sip {
2         include concat::setup
3
4         ssl::service { 'www.debian.org':
5                 # TODO notify concat
6         }
7
8         # TODO concatate in the ssl module?
9         concat { '/etc/ssl/debian/certs/www.debian.org-chained.crt':
10         }
11         concat::fragment { '/etc/ssl/debian/certs/www.debian.org.crt':
12                 target      => '/etc/ssl/debian/certs/www.debian.org-chained.crt',
13                 source      => 'file:///etc/ssl/debian/certs/www.debian.org.crt',
14                 order       => 00,
15         }
16         concat::fragment { '/etc/ssl/debian/certs/www.debian.org.crt-chain':
17                 target      => '/etc/ssl/debian/certs/www.debian.org-chained.crt',
18                 source      => 'file:///etc/ssl/debian/certs/www.debian.org.crt-chain',
19                 order       => 99,
20         }
21
22         @ferm::rule { 'dsa-sip-ws-ip4':
23                 domain      => 'ip',
24                 description => 'SIP connections (WebSocket; for WebRTC)',
25                 rule        => 'proto tcp dport (443) ACCEPT'
26         }
27         @ferm::rule { 'dsa-sip-ws-ip6':
28                 domain      => 'ip6',
29                 description => 'SIP connections (WebSocket; for WebRTC)',
30                 rule        => 'proto tcp dport (443) ACCEPT'
31         }
32         @ferm::rule { 'dsa-sip-tls-ip4':
33                 domain      => 'ip',
34                 description => 'SIP connections (TLS)',
35                 rule        => 'proto tcp dport (5061) ACCEPT'
36         }
37         @ferm::rule { 'dsa-sip-tls-ip6':
38                 domain      => 'ip6',
39                 description => 'SIP connections (TLS)',
40                 rule        => 'proto tcp dport (5061) ACCEPT'
41         }
42         @ferm::rule { 'dsa-turn-ip4':
43                 domain      => 'ip',
44                 description => 'TURN connections',
45                 rule        => 'proto udp dport (3478) ACCEPT'
46         }
47         @ferm::rule { 'dsa-turn-ip6':
48                 domain      => 'ip6',
49                 description => 'TURN connections',
50                 rule        => 'proto udp dport (3478) ACCEPT'
51         }
52         @ferm::rule { 'dsa-turn-tls-ip4':
53                 domain      => 'ip',
54                 description => 'TURN connections (TLS)',
55                 rule        => 'proto tcp dport (5349) ACCEPT'
56         }
57         @ferm::rule { 'dsa-turn-tls-ip6':
58                 domain      => 'ip6',
59                 description => 'TURN connections (TLS)',
60                 rule        => 'proto tcp dport (5349) ACCEPT'
61         }
62         @ferm::rule { 'dsa-rtp-ip4':
63                 domain      => 'ip',
64                 description => 'RTP streams',
65                 rule        => 'proto udp dport (49152:65535) ACCEPT'
66         }
67         @ferm::rule { 'dsa-rtp-ip6':
68                 domain      => 'ip6',
69                 description => 'RTP streams',
70                 rule        => 'proto udp dport (49152:65535) ACCEPT'
71         }
72 }