salsa: allow postgresql connections from backuphosts through firewall
authorPeter Palfrader <peter@palfrader.org>
Fri, 1 Sep 2017 11:49:36 +0000 (11:49 +0000)
committerPeter Palfrader <peter@palfrader.org>
Fri, 1 Sep 2017 11:49:36 +0000 (11:49 +0000)
modules/salsa/manifests/database.pp

index b363b79..e2793c1 100644 (file)
@@ -35,4 +35,10 @@ class salsa::database inherits salsa {
                        tag     => "postgresql::server::backup-source-sshkey",
                }
        }
+
+       @ferm::rule { "dsa-postgres-${postgresql::params::port}":
+               description => 'Allow postgress access from backup host',
+               domain      => '(ip ip6)',
+               rule        => "&SERVICE_RANGE(tcp, ${postgresql::params::port}, ( @ipfilter(\$HOST_PGBACKUPHOST) ))",
+       }
 }