summaryrefslogtreecommitdiff
path: root/puppet
diff options
context:
space:
mode:
authorvarac <varacanero@zeromail.org>2013-02-12 13:26:42 +0100
committervarac <varacanero@zeromail.org>2013-02-12 13:26:42 +0100
commit102af94df02decef888bac09748dbac6773dedd6 (patch)
treee4f92fd7390f02745d576f5573acc7bf88adba0a /puppet
parentb754c9f3412441c58e90fa57dc236fab74cee167 (diff)
fixed shorewall is blocking api port (Bug #1735)
Diffstat (limited to 'puppet')
-rw-r--r--puppet/modules/site_shorewall/manifests/service/webapp_api.pp21
-rw-r--r--puppet/modules/site_shorewall/manifests/webapp.pp1
2 files changed, 22 insertions, 0 deletions
diff --git a/puppet/modules/site_shorewall/manifests/service/webapp_api.pp b/puppet/modules/site_shorewall/manifests/service/webapp_api.pp
new file mode 100644
index 00000000..9d4296e5
--- /dev/null
+++ b/puppet/modules/site_shorewall/manifests/service/webapp_api.pp
@@ -0,0 +1,21 @@
+class site_shorewall::service::webapp_api {
+
+ $api = hiera('api')
+ $api_port = $api['port']
+
+ # define macro for incoming services
+ file { '/etc/shorewall/macro.leap_webapp_api':
+ content => "PARAM - - tcp $api_port ",
+ notify => Service['shorewall']
+ }
+
+
+ shorewall::rule {
+ 'net2fw-webapp_api':
+ source => 'net',
+ destination => '$FW',
+ action => 'leap_webapp_api(ACCEPT)',
+ order => 200;
+ }
+
+}
diff --git a/puppet/modules/site_shorewall/manifests/webapp.pp b/puppet/modules/site_shorewall/manifests/webapp.pp
index 31a65b1b..d12bbc8f 100644
--- a/puppet/modules/site_shorewall/manifests/webapp.pp
+++ b/puppet/modules/site_shorewall/manifests/webapp.pp
@@ -2,4 +2,5 @@ class site_shorewall::webapp {
include site_shorewall::defaults
include site_shorewall::service::https
+ include site_shorewall::service::webapp_api
}