+ rsync::site { 'security':
+ source => 'puppet:///modules/roles/security_mirror/rsyncd.conf',
+ max_clients => 100,
+ binds => $binds,
+ }
+
+ $onion_v4_addr = hiera('roles.security_mirror', {})
+ .dig($::fqdn, 'onion_v4_address')
+ if $onion_v4_addr {
+ onion::service { 'security.debian.org':
+ port => 80,
+ target_port => 80,
+ target_address => $onion_v4_addr,
+ }
+ }
+
+ Ferm::Rule::Simple <<| tag == 'ssh::server::from::security_master' |>>