]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
And produce an xinetd snippet
authorPeter Palfrader <peter@palfrader.org>
Sun, 21 Feb 2010 14:15:28 +0000 (15:15 +0100)
committerPeter Palfrader <peter@palfrader.org>
Sun, 21 Feb 2010 14:15:28 +0000 (15:15 +0100)
modules/portforwarder/manifests/init.pp
modules/portforwarder/templates/xinetd.erb [new file with mode: 0644]

index 54dedb8542cfbe4d6daa2eac6c681ac2182017a5..cf83ba593a4d9f2633f2e13acd3126f44cc8c5cc 100644 (file)
@@ -12,10 +12,10 @@ class portforwarder {
             group   => root,
             mode    => 755,
             ;
-        #"/etc/xinetd.d/dsa-portforwader":
-        #    content => template("portforwarder/xinetd.erb"),
-        #    notify  => Exec["xinetd reload"]
-        #    ;
+        "/etc/xinetd.d/dsa-portforwader":
+            content => template("portforwarder/xinetd.erb"),
+            notify  => Exec["xinetd reload"]
+            ;
     }
 
     exec {
diff --git a/modules/portforwarder/templates/xinetd.erb b/modules/portforwarder/templates/xinetd.erb
new file mode 100644 (file)
index 0000000..6d65e5c
--- /dev/null
@@ -0,0 +1,42 @@
+<%=
+lines = []
+
+template = 'service @@TARGET_HOST@@@@TARGET_PORT@@
+{
+        protocol        = tcp
+        port            = @@LOCAL_BIND@@
+        type            = UNLISTED
+
+        bind            = 127.0.0.1
+        socket_type     = stream
+        wait            = no
+        user            = portforwarder
+        group           = portforwarder
+        instances       = 10
+        server          = /usr/bin/ssh
+        server_args     = -o PreferredAuthentications=publickey -o EscapeChar=none -C @@TARGET_HOST@@ : nothing
+        cps             = 0 0
+}
+'
+
+config = YAML.load(File.open('/etc/puppet/modules/portforwarder/misc/config.yaml').read)
+if config[fqdn]
+       config[fdqn].each do |service|
+               target_port = service['target_port']
+               target_host = service['target_host']
+               local_bind = service['source_bind_port']
+
+               lines << "# from #{sourcehost} on local port #{service['source_bind_port']}"
+               if target_port.nil? or target_host.nil? or local_bind.nil?
+                       lines << "# insufficient config values"
+               else
+                       p = template.clone
+                       p.gsub!('@@TARGET_HOST@@', target_host)
+                       p.gsub!('@@TARGET_PORT@@', target_port)
+                       p.gsub!('@@LOCLA_BIND@@', local_bind)
+                       lines << p
+               end
+       end
+end
+lines.join("\n")
+%>