]> git.donarmstrong.com Git - dsa-puppet.git/commitdiff
handel gets a firewall
authorStephen Gran <steve@lobefin.net>
Sun, 7 Mar 2010 23:28:25 +0000 (23:28 +0000)
committerStephen Gran <steve@lobefin.net>
Sun, 7 Mar 2010 23:28:25 +0000 (23:28 +0000)
Signed-off-by: Stephen Gran <steve@lobefin.net>
manifests/site.pp

index 7a8565dbde89fa7a956cee860d1b85c78e35bb3c..7219eca2aa68129122ab9aa431b25bdd3a6ae62c 100644 (file)
@@ -91,7 +91,7 @@ node default {
     }
 
     case $hostname {
-        logtest01,geo1,geo2,geo3,bartok,senfl,beethoven,piatti,saens,villa,lobos,raff,gluck,schein,wieck,steffani,ball: { include ferm }
+        logtest01,geo1,geo2,geo3,bartok,senfl,beethoven,piatti,saens,villa,lobos,raff,gluck,schein,wieck,steffani,ball,handel: { include ferm }
     }
     case $hostname {
         piatti: {
@@ -125,6 +125,16 @@ node default {
                    rule            => "&SERVICE_RANGE(tcp, time, \$HOST_NAGIOS_V4)"
           }
         }
+        handel: {
+          @ferm::rule { "dsa-puppet":
+                   description     => "Allow puppet access",
+                   rule            => "&SERVICE_RANGE(tcp, 8140, \$HOST_DEBIAN_V4)"
+          }
+          @ferm::rule { "dsa-puppet-v6":
+                   description     => "Allow puppet access",
+                   rule            => "&SERVICE_RANGE(tcp, 8140, \$HOST_DEBIAN_V6)"
+          }
+        }
 
     }
     case $brokenhosts {