X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fferm%2Ftemplates%2Fme.conf.erb;h=8ed108462262a00ae590b07875e9036cd75226a0;hb=75786fffb824d4fe6c78b0ae5f19685c6ce077cf;hp=0ed5c0f07d2c25489f9497dae95973cb0ea8635f;hpb=167d6174e2c588d46666bae9545c114d3da1903a;p=mirror%2Fdsa-puppet.git diff --git a/modules/ferm/templates/me.conf.erb b/modules/ferm/templates/me.conf.erb index 0ed5c0f07..8ed108462 100644 --- a/modules/ferm/templates/me.conf.erb +++ b/modules/ferm/templates/me.conf.erb @@ -4,9 +4,70 @@ ## -@def $SSH_SOURCES = <% -ssh_allowed = case hostname - when 'logtest01' then '0.0.0.0/0' +@def $SSH_SOURCES = (<%= + +sshallowed = [] + +case hostname + when 'logtest01', 'geo1', 'geo2', 'geo3', 'bartok', 'beethoven' then sshallowed << [ '$DSA_IPS', '$HOST_NAGIOS_V4', '$HOST_DB_V4' ] +end + +case hostname + when 'bartok', 'beethoven' then sshallowed << '$HOST_DEBIAN_V4' +end + +if sshallowed.length == 0 + sshallowed = [ '0.0.0.0/0' ] +end + +sshallowed.join(' ') +%>); + +@def $SSH_V6_SOURCES = (<%= + +sshallowed = [] + +case hostname + when 'logtest01', 'geo1', 'geo2', 'geo3', 'bartok', 'beethoven' then sshallowed << [ '$DSA_V6_IPS', '$HOST_NAGIOS_V6', '$HOST_DB_V6' ] +end + +case hostname + when 'bartok', 'beethoven' then sshallowed << '$HOST_DEBIAN_V6' +end + +if sshallowed.length == 0 + sshallowed = [ '::' ] end -ssh_allowed -%> + +sshallowed.join(' ') +%>); + +def $SMTP_SOURCES =(<%= + +smtpallowed = [] + +if not nodeinfo['smarthost'].empty? + smtpallowed = [ '$HOST_MAILRELAY_V4', '$HOST_NAGIOS_V4' ] +end + +if smtpallowed.length == 0 + smtpallowed = [ '0.0.0.0/0' ] +end + +smtpallowed.join(' ') +%>); + +def $SMTP_V6_SOURCES =(<%= + +smtpallowed = [] + +if not nodeinfo['smarthost'].empty? + smtpallowed = [ '$HOST_MAILRELAY_V6', '$HOST_NAGIOS_V6' ] +end + +if smtpallowed.length == 0 + smtpallowed = [ '::' ] +end + +smtpallowed.join(' ') +%>);