Documentation by YARD 0.9.26
-Alphabetic Index
- -Puppet Class Listing A-Z
- - -
-
-
-
|
-
File Listing
--
-
-
-
- README - - -
diff --git a/.mdl_style.rb b/.mdl_style.rb deleted file mode 100644 index 5d4d3b9..0000000 --- a/.mdl_style.rb +++ /dev/null @@ -1,3 +0,0 @@ -all -rule 'MD013', :line_length => 1000 -exclude_rule 'MD036' diff --git a/.mdlrc b/.mdlrc deleted file mode 100644 index e5c563a..0000000 --- a/.mdlrc +++ /dev/null @@ -1,2 +0,0 @@ -style '.mdl_style.rb' - diff --git a/.spelling b/.spelling deleted file mode 100644 index 3935583..0000000 --- a/.spelling +++ /dev/null @@ -1,43 +0,0 @@ -# markdown-spellcheck spelling configuration file -# Format - lines begining # are comments -# global dictionary is at the start, file overrides afterwards -# one word per line, to define a file override use ' - filename' -# where filename is relative to this configuration file -Readme.md -httpd -sudo -selinux -site.pp -nodes.pp -cd_apache -:: -params -Foreman -cd_resources -CentOS -Puppet -ConfDroid -nagios -vHosts -vHost -phpMyAdmin -phpPgAdmin -parameterized -erb -Confdroid.com -UTF_Files -Elasticsearch -cd_firewall -puppetlabs -cd_elasticsearch -fail2ban_cd -Fail2Ban -intrusion -fail2ban -firewalld -prevention -management -CentOS7 -auto-installed -ipv4 -ipv6 diff --git a/Jenkinsfile b/Jenkinsfile index c4762f7..5ff6855 100644 --- a/Jenkinsfile +++ b/Jenkinsfile @@ -51,16 +51,9 @@ pipeline { stage('puppet-lint') { steps { - sh '''find . -iname *.pp -exec /usr/local/rvm/gems/ruby-2.5.0/wrappers/puppet-lint \\ - --no-class_inherits_from_params_class-check \\ - --no-variable_scope-check \\ - --no-80chars-check \\ - --no-arrow_alignment-check \\ - --no-autoloader_layout-check \\ - --no-140chars-check \\ - --log-format "%{path}:%{line}:%{check}:%{KIND}:%{message}" {} \\; + sh '''/usr/local/bin/puppet-lint . \\ + --no-variable_scope-check \\ ''' - recordIssues aggregatingResults: true, tool: puppetLint() } } diff --git a/README.md b/README.md index 8c90b9f..39f8f52 100644 --- a/README.md +++ b/README.md @@ -75,13 +75,9 @@ All files and directories are configured with correct selinux context. If selinu * Puppet Lint * excluded tests: - * `--no-class_inherits_from_params_class-check`:relevant only to non-supported outdated puppet versions * `--no-variable_scope-check`: not applicable as we are inheriting parameters from params class. the lint check does not distinguish between facts and inherited parameters. - * `--no-80chars-check`: it is not always possible to stay within 80 characters, although typically only occurring on the parameter vault `params.pp`. - * `--no-arrow_alignment-check`: this check leads to actually not having am easily readable arrow alignment, as this checks `per block`, not per class. * Puppet Parser * ERB Template Parser -* Test for unwanted UTF8 files in the Puppet code (see tests/UTF_Files) * Sonar Quality Gate ## Contact Us diff --git a/doc/_index.html b/doc/_index.html deleted file mode 100644 index 6ab762e..0000000 --- a/doc/_index.html +++ /dev/null @@ -1,143 +0,0 @@ - - -
- - -
-
-
-
|
-
| t |
- - - -6 -7 -8- |
-
- # File 'manifests/init.pp', line 6
-
-class fail2ban_cd {
- include fail2ban_cd::params
-}
- |
-
fail2ban_cd::main::config.pp Module name: fail2ban_cd Author: Arne Teuke -(arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10- |
-
- # File 'manifests/main/config.pp', line 6
-
-class fail2ban_cd::main::config (
-
-) inherits fail2ban_cd::params {
- include fail2ban_cd::main::service
-}
- |
-
fail2ban_cd::main::dirs.pp Module name: fail2ban_cd Author: Arne Teuke -(arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30 -31 -32 -33 -34 -35 -36 -37 -38 -39 -40 -41 -42 -43 -44 -45 -46 -47 -48 -49 -50 -51 -52 -53 -54 -55 -56 -57 -58 -59 -60 -61 -62 -63 -64 -65 -66 -67 -68 -69 -70 -71 -72 -73 -74 -75 -76 -77 -78 -79 -80 -81 -82 -83 -84 -85 -86 -87 -88 -89 -90 -91 -92 -93 -94 -95 -96 -97 -98 -99 -100 -101 -102 -103 -104 -105 -106 -107 -108- |
-
- # File 'manifests/main/dirs.pp', line 6
-
-class fail2ban_cd::main::dirs (
-
-) inherits fail2ban_cd::params {
- require fail2ban_cd::main::install
-
- # manage main dir
-
- file { $fn_main_dir:
- ensure => directory,
- path => $fn_main_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # manage action.d dir
-
- file { $fn_action_d_dir:
- ensure => directory,
- path => $fn_action_d_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # manage fail2ban.d dir
-
- file { $fn_fail2ban_d_dir:
- ensure => directory,
- path => $fn_fail2ban_d_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # manage filter.d dir
-
- file { $fn_filter_d_dir:
- ensure => directory,
- path => $fn_filter_d_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # manage jail.d dir
-
- file { $fn_jail_d_dir:
- ensure => directory,
- path => $fn_jail_d_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- }
-
- # manage /var/lib/fail2ban
-
- file { $fn_var_lib_dir:
- ensure => directory,
- path => $fn_var_lib_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => fail2ban_var_lib_t,
- seluser => system_u,
- }
-
- # manage /var/run/fail2bam
-
- file { $fn_var_run_dir:
- ensure => directory,
- path => $fn_var_run_dir,
- owner => 'root',
- group => 'root',
- mode => '0755',
- selrange => s0,
- selrole => object_r,
- seltype => fail2ban_var_run_t,
- seluser => system_u,
- }
-}
- |
-
fail2ban_cd::main::files.pp Module name: fail2ban_cd Author: Arne Teuke -(arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17 -18 -19 -20 -21 -22 -23 -24 -25 -26 -27 -28 -29 -30 -31 -32 -33 -34 -35 -36 -37 -38 -39 -40 -41 -42 -43 -44 -45 -46 -47 -48 -49 -50 -51 -52 -53 -54 -55 -56 -57 -58 -59 -60 -61 -62 -63 -64 -65 -66 -67 -68 -69 -70 -71 -72 -73 -74 -75 -76 -77 -78 -79 -80 -81 -82 -83 -84 -85 -86 -87 -88 -89 -90 -91 -92- |
-
- # File 'manifests/main/files.pp', line 6
-
-class fail2ban_cd::main::files (
-
-) inherits fail2ban_cd::params {
- require fail2ban_cd::main::dirs
-
- if $fn_manage_config == true {
- # manage fail2ban.conf
-
- file { $fn_fail2ban_conf_file:
- ensure => file,
- path => $fn_fail2ban_conf_file,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($fn_fail2ban_conf_erb),
- notify => Service[$fn_service],
- }
-
- # manage fail2ban.local
-
- file { $fn_fail2ban_local_file:
- ensure => file,
- path => $fn_fail2ban_local_file,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($fn_fail2ban_local_erb),
- notify => Service[$fn_service],
- }
-
- # manage jail.conf
-
- file { $fn_jail_conf_file:
- ensure => file,
- path => $fn_jail_conf_file,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($fn_jail_conf_erb),
- notify => Service[$fn_service],
- }
-
- # manage jail.local
-
- file { $fn_jail_local_file:
- ensure => file,
- path => $fn_jail_local_file,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($fn_jail_local_erb),
- notify => Service[$fn_service],
- }
-
- # manage paths-common.conf
-
- file { $fn_paths_common_file:
- ensure => file,
- path => $fn_paths_common_file,
- owner => 'root',
- group => 'root',
- mode => '0640',
- selrange => s0,
- selrole => object_r,
- seltype => etc_t,
- seluser => system_u,
- content => template($fn_paths_common_erb),
- notify => Service[$fn_service],
- }
- }
-}
- |
-
fail2ban_cd::main::install.pp Module name: fail2ban_cd Author: Arne Teuke -(arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14- |
-
- # File 'manifests/main/install.pp', line 6
-
-class fail2ban_cd::main::install (
-
-) inherits fail2ban_cd::params {
-# require cd_resources
-
- package { $reqpackages:
- ensure => $pkg_ensure,
- }
-}
- |
-
fail2ban_cd::main::service.pp Module name: fail2ban_cd Author: Arne Teuke -(arne_teuke@confdroid.com)
- -
- - - -6 -7 -8 -9 -10 -11 -12 -13 -14 -15 -16 -17- |
-
- # File 'manifests/main/service.pp', line 6
-
-class fail2ban_cd::main::service (
-
-) inherits fail2ban_cd::params {
- require fail2ban_cd::main::files
-
- service { $fn_service:
- ensure => $fn_enable_service,
- hasstatus => true,
- hasrestart => true,
- enable => true,
- }
-}
- |
-
fail2ban_cd::params.pp Module name: fail2ban_cd Author: Arne Teuke
-(arne_teuke@confdroid.com)
-CRITICAL,ERROR,WARNING,NOTICE,INFO
-and DEBUG.
- - - -105 -106 -107 -108 -109 -110 -111 -112 -113 -114 -115 -116 -117 -118 -119 -120 -121 -122 -123 -124 -125 -126 -127 -128 -129 -130 -131 -132 -133 -134 -135 -136 -137 -138 -139 -140 -141 -142 -143 -144 -145 -146 -147 -148 -149 -150 -151 -152 -153 -154 -155 -156 -157 -158 -159 -160 -161 -162 -163 -164 -165 -166 -167 -168 -169 -170 -171 -172 -173 -174 -175 -176 -177 -178 -179 -180 -181 -182 -183 -184 -185 -186 -187 -188 -189 -190 -191 -192 -193- |
-
- # File 'manifests/params.pp', line 105
-
-class fail2ban_cd::params (
-
-# installation
- String $pkg_ensure = 'latest',
- Array $reqpackages = ['fail2ban','fail2ban-firewalld',
- 'fail2ban-sendmail','fail2ban-server.noarch','whois'],
-
- Boolean $fn_manage_config = true,
- String $fn_enable_service = 'running',
-
-# fail2ban.conf/local
-
- String $fn_loglevel = 'INFO',
- String $fn_logtarget = 'SYSLOG',
- String $fn_syslogsocket = 'auto',
- String $fn_socket = '/var/run/fail2ban/fail2ban.sock',
- String $fn_pidfile = '/var/run/fail2ban/fail2ban.pid',
- String $fn_dbfile = '/var/lib/fail2ban/fail2ban.sqlite3',
- String $fn_dbpurgeage = '86400',
-
-# jail.conf/local
- String $fn_ignoreip = '127.0.0.1/8',
- String $fn_ignorecommand = '',
- String $fn_bantime = '600',
- String $fn_findtime = '600',
- String $fn_maxretry = '5',
- String $fn_backend = 'auto',
- String $fn_usedns = 'warn',
- String $fn_logencoding = 'auto',
- Boolean $fn_enabled = false,
- String $fn_filter = '%(__name__)s',
- String $fn_destemail = 'root@localhost',
- #String $fn_sender = "fail2ban@${fqdn}",
- String $fn_mta = 'sendmail',
- String $fn_protocol = 'tcp',
- String $fn_chain = 'INPUT',
- String $fn_port = '0:65535',
- String $fn_fail2ban_agent = 'Fail2Ban/%(fail2ban_version)s',
- String $fn_banaction = 'iptables-multiport',
- String $fn_banaction_allports = 'iptables-allports',
- String $fn_action_ = '%(banaction)s[name=%(__name__)s, bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"]',
- String $fn_action_mw = '%(banaction)s[name=%(__name__)s, bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"]
- %(mta)s-whois[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", protocol="%(protocol)s", chain="%(chain)s"]',
- String $fn_action_mwl = '%(banaction)s[name=%(__name__)s, bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"]
- %(mta)s-whois-lines[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", logpath=%(logpath)s, chain="%(chain)s"]',
- String $fn_action_xarf = '%(banaction)s[name=%(__name__)s, bantime="%(bantime)s", port="%(port)s", protocol="%(protocol)s", chain="%(chain)s"]
- xarf-login-attack[service=%(__name__)s, sender="%(sender)s", logpath=%(logpath)s, port="%(port)s"]',
- String $fn_action_cf_mwl = 'cloudflare[cfuser="%(cfemail)s", cftoken="%(cfapikey)s"]
- %(mta)s-whois-lines[name=%(__name__)s, sender="%(sender)s", dest="%(destemail)s", logpath=%(logpath)s, chain="%(chain)s"]',
- String $fn_action_blocklist_de = 'blocklist_de[email="%(sender)s", service=%(filter)s, apikey="%(blocklist_de_apikey)s", agent="%(fail2ban_agent)s"]',
- String $fn_action_badips = 'badips.py[category="%(__name__)s", banaction="%(banaction)s", agent="%(fail2ban_agent)s"]',
- String $fn_action_badips_report = 'badips[category="%(__name__)s", agent="%(fail2ban_agent)s"]',
- String $fn_default_action = 'action_',
- String $fn_jail_paths = 'fedora',
-
-) {
-# shortcuts
- $fqdn = $facts['networking']['fqdn']
- $fn_os = $facts['os']
- $fn_sender = "fail2ban@${fqdn}"
-
-# service
- $fn_service = 'fail2ban'
-
-# directories
- $fn_main_dir = '/etc/fail2ban'
- $fn_action_d_dir = "${fn_main_dir}/action.d"
- $fn_fail2ban_d_dir = "${fn_main_dir}/fail2ban.d"
- $fn_filter_d_dir = "${fn_main_dir}/filter.d"
- $fn_jail_d_dir = "${fn_main_dir}/jail.d"
- $fn_var_lib_dir = '/var/lib/fail2ban'
- $fn_var_run_dir = '/var/run/fail2ban'
-
-# files
- $fn_fail2ban_conf_file = "${fn_main_dir}/fail2ban.conf"
- $fn_fail2ban_conf_erb = 'fail2ban_cd/fail2ban_conf.erb'
- $fn_fail2ban_local_file = "${fn_main_dir}/fail2ban.local"
- $fn_fail2ban_local_erb = 'fail2ban_cd/fail2ban_local.erb'
- $fn_jail_conf_file = "${fn_main_dir}/jail.conf"
- $fn_jail_conf_erb = 'fail2ban_cd/jail_conf.erb'
- $fn_jail_local_file = "${fn_main_dir}/jail.local"
- $fn_jail_local_erb = 'fail2ban_cd/jail_local.erb'
- $fn_paths_common_file = "${fn_main_dir}/paths-common.conf"
- $fn_paths_common_erb = 'fail2ban_cd/paths_common_conf.erb'
-
-# includes must be last
-
- include fail2ban_cd::main::config
-}
- |
-