Dzahn has uploaded a new change for review. (
https://gerrit.wikimedia.org/r/370498 )
Change subject: phabricator: open firewall holes only on active_server
......................................................................
phabricator: open firewall holes only on active_server
Only open the ferm/firewall holes when on the active server,
if on the standby server, block access to http/https/smtp/git-ssh.
This is, at least for now, to block access to the Apache on phab2001
to prevent cross-dc traffic, since it doesn't use a codfw db backend yet.
Change-Id: I3be7ae71db282d134e5ed0dc22d2edc721317abd
---
M modules/profile/manifests/phabricator/main.pp
1 file changed, 9 insertions(+), 2 deletions(-)
git pull ssh://gerrit.wikimedia.org:29418/operations/puppet
refs/changes/98/370498/1
diff --git a/modules/profile/manifests/phabricator/main.pp
b/modules/profile/manifests/phabricator/main.pp
index dfa48db..0fea91c 100644
--- a/modules/profile/manifests/phabricator/main.pp
+++ b/modules/profile/manifests/phabricator/main.pp
@@ -34,10 +34,12 @@
$logmail_ensure = 'present'
$dump_rsync_ensure = 'present'
$dump_enabled = true
+ $ferm_ensure = 'present'
} else {
$logmail_ensure = 'absent'
$dump_rsync_ensure ='absent'
$dump_enabled = false
+ $ferm_ensure = 'absent'
}
# todo: change the password for app_user
@@ -225,23 +227,27 @@
}
ferm::service { 'phabmain_http':
- proto => 'tcp',
- port => '80',
+ ensure => $ferm_ensure,
+ proto => 'tcp',
+ port => '80',
}
ferm::service { 'phabmain_https':
+ ensure => $ferm_ensure,
proto => 'tcp',
port => '443',
}
# receive mail from mail smarthosts
ferm::service { 'phabmain-smtp':
+ ensure => $ferm_ensure,
port => '25',
proto => 'tcp',
srange => inline_template('(<%= @mail_smarthost.map{|x|
"@resolve(#{x})" }.join(" ") %>)'),
}
ferm::service { 'phabmain-smtp_ipv6':
+ ensure => $ferm_ensure,
port => '25',
proto => 'tcp',
srange => inline_template('(<%= @mail_smarthost.map{|x|
"@resolve(#{x}, AAAA)" }.join(" ") %>)'),
@@ -250,6 +256,7 @@
# ssh between phabricator servers for clustering support
$phabricator_servers_ferm = join(hiera('phabricator_servers'), ' ')
ferm::service { 'ssh_cluster':
+ ensure => $ferm_ensure,
port => '22',
proto => 'tcp',
srange => "@resolve((${phabricator_servers_ferm}))",
--
To view, visit https://gerrit.wikimedia.org/r/370498
To unsubscribe, visit https://gerrit.wikimedia.org/r/settings
Gerrit-MessageType: newchange
Gerrit-Change-Id: I3be7ae71db282d134e5ed0dc22d2edc721317abd
Gerrit-PatchSet: 1
Gerrit-Project: operations/puppet
Gerrit-Branch: production
Gerrit-Owner: Dzahn <[email protected]>
_______________________________________________
MediaWiki-commits mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/mediawiki-commits