X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;ds=inline;f=modules%2Froles%2Fmanifests%2Fsnapshot_web.pp;h=6a6414f8168f9cc86706500fadc6c6a9179c11f7;hb=0b90b9722d512bc8e6bc0a90995b3ace1b1b68ed;hp=ee9ab949f033ac67db73e0f99a4650604cdf83ab;hpb=8d38f75440f0a903a4e2630b076a8d090a59b47e;p=mirror%2Fdsa-puppet.git diff --git a/modules/roles/manifests/snapshot_web.pp b/modules/roles/manifests/snapshot_web.pp index ee9ab949f..6a6414f81 100644 --- a/modules/roles/manifests/snapshot_web.pp +++ b/modules/roles/manifests/snapshot_web.pp @@ -2,6 +2,13 @@ class roles::snapshot_web { include apache2 include apache2::rewrite + # snapshot abusers + # 61.69.254.110 - 20180705, mirroring with wget + @ferm::rule { 'dsa-nat-snapshot-varnish-v4': + prio => "000", + rule => "saddr (61.69.254.110) DROP", + } + ensure_packages ( [ "libapache2-mod-wsgi", ], { @@ -31,9 +38,6 @@ class roles::snapshot_web { # varnish cache ############### - @ferm::rule { 'dsa-snapshot-varnish-v4': - rule => '&SERVICE(tcp, 6081)', - } @ferm::rule { 'dsa-nat-snapshot-varnish-v4': table => 'nat', chain => 'PREROUTING',