dammit. ferm is smarter than me
[mirror/dsa-puppet.git] / modules / ferm / manifests / real.pp
index db7e445..447ab75 100644 (file)
@@ -1,4 +1,4 @@
-class ferm::real {
+class ferm::real inherits ferm {
 
         package { ferm: ensure => installed }
 
@@ -9,37 +9,22 @@ class ferm::real {
                 "/etc/ferm/ferm.conf":
                         source  => "puppet:///ferm/ferm.conf",
                         require => Package["ferm"],
+                        mode    => 0400,
                         notify  => Exec["ferm restart"];
                 "/etc/ferm/conf.d/me.conf":
                         content => template("ferm/me.conf.erb"),
                         require => Package["ferm"],
+                        mode    => 0400,
                         notify  => Exec["ferm restart"];
                 "/etc/ferm/conf.d/defs.conf":
                         source  => "puppet:///ferm/defs.conf",
                         require => Package["ferm"],
+                        mode    => 0400,
                         notify  => Exec["ferm restart"];
         }
 
-        ferm::rule { "dsa-ssh":
-                description     => "Allow SSH from DSA",
-                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_SOURCES) ACCEPT; }"
-        }
-        ferm::rule { "dsa-ssh-v6":
-                description     => "Allow SSH from DSA",
-                domain          => "ip6",
-                rule            => "proto tcp mod state state (NEW) dport (ssh) @subchain 'ssh' { saddr (\$SSH_V6_SOURCES) ACCEPT; }"
-        }
-        ferm::rule { "dsa-munin":
-                description     => "Allow munin from munin master",
-                rule            => "proto tcp mod state state (NEW) dport (munin) @subchain 'munin' { saddr (\$HOST_MUNIN) ACCEPT; }"
-        }
-        ferm::rule { "dsa-nagios":
-                description     => "Allow nrpe from nagios master",
-                rule            => "proto tcp mod state state (NEW) dport (5666) @subchain 'nagios' { saddr (\$HOST_NAGIOS) ACCEPT; }"
-        }
-
         Exec["ferm restart"] {
-                path        => "/etc/init.d:/usr/bin:/usr/sbin:/bin:/sbin",
+                command     => "/etc/init.d/ferm restart",
                 refreshonly => true,
         }
 }