]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/ferm/manifests/per-host.pp
we now use elasticsearch, so adjust ports
[dsa-puppet.git] / modules / ferm / manifests / per-host.pp
index 643ec2ff2b8a4b3b4b17b05a2ea52ac5a22a1b5e..232aa12e98cfed04966a2969479da62f16e22246 100644 (file)
@@ -263,12 +263,18 @@ class ferm::per-host {
                default: {}
        }
 
-       # solr stuff
+       # elasticsearch stuff
        case $::hostname {
                stockhausen: {
-                       @ferm::rule { 'dsa-solr-jetty':
-                               description     => 'Allow jetty access',
-                               rule            => '&SERVICE_RANGE(tcp, 8080, ( 82.195.75.100/32 ))'
+                       @ferm::rule { 'dsa-elasticsearch-bendel':
+                               domain          => '(ip)',
+                               description     => 'Allow elasticsearch access from bendel',
+                               rule            => '&SERVICE_RANGE(tcp, 9200:9300, ( 82.195.75.100/32 ))'
+                       }
+                       @ferm::rule { 'dsa-elasticsearch-bendel6':
+                               domain          => '(ip6)',
+                               description     => 'Allow elasticsearch access from bendel',
+                               rule            => '&SERVICE_RANGE(tcp, 9200:9300, ( 2001:41b8:202:deb:216:36ff:fe40:4002/128 ))'
                        }
                }
        }