]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
move ftp and rsync to site.pp
authorMartin Zobel-Helas <zobel@debian.org>
Sat, 6 Mar 2010 18:02:15 +0000 (19:02 +0100)
committerMartin Zobel-Helas <zobel@debian.org>
Sat, 6 Mar 2010 18:02:15 +0000 (19:02 +0100)
manifests/site.pp

index a29e9d3543bb27619aaa7e0c9377c45552a7bfa6..14fbc5f0f4b178a14dad807923ad1a22d10d0ed5 100644 (file)
@@ -83,17 +83,6 @@ node default {
         bartok:                   { include named::recursor }
     }
 
-    case extractnodeinfo($nodeinfo, 'apache2_security_mirror') {
-        true: { 
-              include rsync
-              include ftp
-        }
-    }
-
-    case $hostname {
-       senfl: { include rsync }
-    }
-
     case $hostname {
         logtest01,geo1,geo2,geo3,bartok,senfl,beethoven,piatti,saens: { include ferm }
     }
@@ -104,6 +93,20 @@ node default {
                rule         => "&SERVICE_RANGE(tcp, http-alt, ( 192.25.206.16 70.103.162.29 217.196.43.134 ))"
            }
         }
+       senfl,saens: {
+          @ferm::rule { "dsa-rsync":
+                   domain          => "(ip ip6)",
+                   description     => "Allow rsync access",
+                   rule            => "&SERVICE(tcp, 873)"
+          }
+        }
+        saens: {
+           @ferm::rule { "dsa-ftp":
+                   domain          => "(ip ip6)",
+                   description     => "Allow ftp access",
+                   rule            => "&SERVICE(tcp, 21)"
+           }
+        }
 
     }
     case $brokenhosts {