rule => '&SERVICE_RANGE(tcp, 5671, $HOST_DEBIAN)'
}
- if $::hostname == $cc_master {
- $other = join(getfromhash($deprecated::allnodeinfo, "${cc_secondary}.debian.org", 'ipHostNumber'), ' ')
- } else {
- $other = join(getfromhash($deprecated::allnodeinfo, "${cc_master}.debian.org", 'ipHostNumber'), ' ')
- }
-
- ferm::rule { 'rabbitmq_cluster':
- domain => '(ip ip6)',
- description => 'rabbitmq cluster connections',
- rule => "proto tcp mod state state (NEW) saddr (${other}) ACCEPT"
+ @@ferm::rule::simple { "pubsub-cluster-from-${::fqdn}":
+ tag => 'roles::pubsub::intra-cluster',
+ saddr => $base::public_addresses,
}
+ Ferm::Rule::Simple <<| tag == 'roles::pubsub::intra-cluster' |>>
}