Andrew Bogott has uploaded a new change for review.

  https://gerrit.wikimedia.org/r/257796

Change subject: Add labs_baremetal_servers hiera item.
......................................................................

Add labs_baremetal_servers hiera item.

This is a list of IPs which will allow us to open firewalls
appropriately for labs bare metal servers.

Bug: T120262
Change-Id: Ib45203c49f51555e0be833978ec19ecf84428343
---
M hieradata/eqiad.yaml
M modules/role/manifests/labs/openstack/nova.pp
2 files changed, 9 insertions(+), 1 deletion(-)


  git pull ssh://gerrit.wikimedia.org:29418/operations/puppet 
refs/changes/96/257796/1

diff --git a/hieradata/eqiad.yaml b/hieradata/eqiad.yaml
index 672bc36..523433d 100644
--- a/hieradata/eqiad.yaml
+++ b/hieradata/eqiad.yaml
@@ -117,3 +117,6 @@
   pdns_db_name: 'pdns'
   rabbit_host:  *labsnovacontroller
   controller_hostname: *labsnovacontroller
+
+labs_baremetal_servers:
+  - '10.64.20.12'
diff --git a/modules/role/manifests/labs/openstack/nova.pp 
b/modules/role/manifests/labs/openstack/nova.pp
index 2bdac0d..7405588 100644
--- a/modules/role/manifests/labs/openstack/nova.pp
+++ b/modules/role/manifests/labs/openstack/nova.pp
@@ -130,6 +130,11 @@
 
     # TOBE: hiera'd
     $labs_vms = '10.68.16.0/21'
+    $labs_metal = hiera(
+        'labs_baremetal_servers',
+        []
+    )
+
     $wikitech = '208.80.154.136'
     $horizon = '208.80.154.147'
     $api_host = ipresolve(hiera('labs_nova_api_host'),4)
@@ -195,7 +200,7 @@
             rule => "saddr ${labs_nodes} proto tcp dport 9292 ACCEPT;",
         },
         puppetmaster => {
-            rule => "saddr (${labs_vms} ${monitoring}) proto tcp dport 8140 
ACCEPT;",
+            rule => "saddr (${labs_vms} ${labs_metal} ${monitoring}) proto tcp 
dport 8140 ACCEPT;",
         },
         salt => {
             rule => "saddr (${labs_vms} ${monitoring}) proto tcp dport (4505 
4506) ACCEPT;",

-- 
To view, visit https://gerrit.wikimedia.org/r/257796
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: Ib45203c49f51555e0be833978ec19ecf84428343
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Andrew Bogott <[email protected]>

_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits

Reply via email to