rule => '&SERVICE_RANGE(tcp, 5452, ( 2001:41c8:1000:21::21:28/128 2001:41b8:202:deb:216:36ff:fe40:4001/128 2001:41c8:1000:21::21:11/32 2001:41c8:1000:21::21:21/128 ))'
}
}
+ fasolo: {
+ @ferm::rule { 'dsa-postgres-fasolo':
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5433, ( 5.153.231.10/32 ))'
+ }
+ @ferm::rule { 'dsa-postgres-fasolo6':
+ domain => 'ip6',
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5433, ( 2001:41c8:1000:21::21:10/128 ))'
+ }
+
+ @ferm::rule { 'dsa-postgres-backup':
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5433, ( $HOST_PGBACKUPHOST_V4 ))'
+ }
+ @ferm::rule { 'dsa-postgres-backup6':
+ domain => 'ip6',
+ description => 'Allow postgress access',
+ rule => '&SERVICE_RANGE(tcp, 5433, ( $HOST_PGBACKUPHOST_V6 ))'
+ }
+ }
franck: {
@ferm::rule { 'dsa-postgres-franck':
description => 'Allow postgress access',
Host_Alias VOIPHOSTS = vogler
Host_Alias WEBHOSTS = wolkenstein
Host_Alias SECHOSTS = seger
-Host_Alias FTPHOSTS = franck
+Host_Alias FTPHOSTS = franck, fasolo
Host_Alias ZIVITHOSTS = zelenka, zandonai
Host_Alias AACRAIDHOSTS = pettersson
Host_Alias MEGARAIDHOSTS = rautavaara, sibelius
buildd ALL=(ALL) NOPASSWD: ALL
%appstream mekeel=(staticsync) NOPASSWD: /usr/local/bin/static-update-component appstream.debian.org
-%backports franck,coccia=(staticsync) NOPASSWD: /usr/local/bin/static-update-component backports.debian.org
+%backports FTPHOSTS,coccia=(staticsync) NOPASSWD: /usr/local/bin/static-update-component backports.debian.org
%bootstrap boott=(staticsync) NOPASSWD: /usr/local/bin/static-update-component bootstrap.debian.net
d-i dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component d-i.debian.org
lucas dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debaday.debian.net
dsa dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component dsa.debian.org
-dak franck=(staticsync) NOPASSWD: /usr/local/bin/static-update-component incoming.debian.org
-dak franck=(staticsync) NOPASSWD: /usr/local/bin/static-update-component metadata.ftp-master.debian.org
+dak FTPHOSTS=(staticsync) NOPASSWD: /usr/local/bin/static-update-component incoming.debian.org
+dak FTPHOSTS=(staticsync) NOPASSWD: /usr/local/bin/static-update-component metadata.ftp-master.debian.org
%publicity dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component bits.debian.org
%publicity dillon=(staticsync) NOPASSWD: /usr/local/bin/static-update-component micronews.debian.org
%debdelta donizetti=(staticsync) NOPASSWD: /usr/local/bin/static-update-component debdeltas.debian.net
%wbadm BUILDD_MASTER=(root) /usr/local/bin/update-buildd-sshkeys
# mirror push
dak FTPHOSTS,SECHOSTS=(archvsync) NOPASSWD:/home/archvsync/runmirrors
-dak franck=(backports) NOPASSWD: /home/backports/bin/update-archive
+dak FTHOSTS=(backports) NOPASSWD: /home/backports/bin/update-archive
# archvsync triggers snapshot
archvsync sibelius=(snapshot) NOPASSWD: /srv/snapshot.debian.org/bin/update-trigger
archvsync sibelius=(snapshot) NOPASSWD: /srv/2ndsnapshot/bin/update-trigger