Andrew Bogott has submitted this change and it was merged.
Change subject: Add labs_baremetal_servers hiera item.
......................................................................
Add labs_baremetal_servers hiera item.
This is a list of IPs which will allow us to open firewalls
appropriately for labs bare metal servers.
Bug: T120262
Change-Id: Ib45203c49f51555e0be833978ec19ecf84428343
---
M hieradata/eqiad.yaml
M modules/role/manifests/labs/openstack/nova.pp
2 files changed, 5 insertions(+), 1 deletion(-)
Approvals:
Andrew Bogott: Looks good to me, approved
jenkins-bot: Verified
diff --git a/hieradata/eqiad.yaml b/hieradata/eqiad.yaml
index 672bc36..523433d 100644
--- a/hieradata/eqiad.yaml
+++ b/hieradata/eqiad.yaml
@@ -117,3 +117,6 @@
pdns_db_name: 'pdns'
rabbit_host: *labsnovacontroller
controller_hostname: *labsnovacontroller
+
+labs_baremetal_servers:
+ - '10.64.20.12'
diff --git a/modules/role/manifests/labs/openstack/nova.pp
b/modules/role/manifests/labs/openstack/nova.pp
index 2bdac0d..ff7be94 100644
--- a/modules/role/manifests/labs/openstack/nova.pp
+++ b/modules/role/manifests/labs/openstack/nova.pp
@@ -130,6 +130,7 @@
# TOBE: hiera'd
$labs_vms = '10.68.16.0/21'
+ $labs_metal = join(hiera('labs_baremetal_servers', []), " ")
$wikitech = '208.80.154.136'
$horizon = '208.80.154.147'
$api_host = ipresolve(hiera('labs_nova_api_host'),4)
@@ -195,7 +196,7 @@
rule => "saddr ${labs_nodes} proto tcp dport 9292 ACCEPT;",
},
puppetmaster => {
- rule => "saddr (${labs_vms} ${monitoring}) proto tcp dport 8140
ACCEPT;",
+ rule => "saddr (${labs_vms} ${labs_metal} ${monitoring}) proto tcp
dport 8140 ACCEPT;",
},
salt => {
rule => "saddr (${labs_vms} ${monitoring}) proto tcp dport (4505
4506) ACCEPT;",
--
To view, visit https://gerrit.wikimedia.org/r/257796
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings
Gerrit-MessageType: merged
Gerrit-Change-Id: Ib45203c49f51555e0be833978ec19ecf84428343
Gerrit-PatchSet: 5
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Andrew Bogott <[email protected]>
Gerrit-Reviewer: Andrew Bogott <[email protected]>
Gerrit-Reviewer: Yuvipanda <[email protected]>
Gerrit-Reviewer: jenkins-bot <>
_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits