syncproxy ssh firewalling
authorPeter Palfrader <peter@palfrader.org>
Sat, 21 Sep 2019 10:21:37 +0000 (12:21 +0200)
committerPeter Palfrader <peter@palfrader.org>
Sat, 21 Sep 2019 10:24:37 +0000 (12:24 +0200)
modules/roles/manifests/syncproxy.pp

index 158b872..26e1c5a 100644 (file)
@@ -1,3 +1,4 @@
+# a syncproxy
 class roles::syncproxy {
   include roles::archvsync_base
 
@@ -66,4 +67,19 @@ class roles::syncproxy {
       binds   => $binds,
     }
   }
+
+  @@ferm::rule::simple { "dsa-ssh-from-syncproxy-${::fqdn}":
+    tag         => 'ssh::server::allow::syncproxy',
+    description => 'Allow ssh access from a syncproxy',
+    port        => '22',
+    saddr       => $base::public_addresses,
+  }
+
+  # syncproxies should be accessible from various role hosts
+  Ferm::Rule::Simple <<|
+    tag == 'ssh::server::allow::archvsync' or
+    tag == 'ssh::server::allow::ftp-master' or
+    tag == 'ssh::server::allow::ports-master' or
+    tag == 'ssh::server::allow::security-master'
+    |>>
 }