97 lines
2.9 KiB
Puppet
97 lines
2.9 KiB
Puppet
## cd_fail2ban::main::files.pp
|
|
# Module name: cd_fail2ban
|
|
# Author: Arne Teuke (arne_teuke@confdroid.com)
|
|
# License:
|
|
# This file is part of cd_fail2ban.
|
|
#
|
|
# cd_fail2ban is used for providing automatic configuration of Fail2Ban
|
|
# Copyright (C) 2017 confdroid (copyright@confdroid.com)
|
|
# This program is free software: you can redistribute it and/or modify
|
|
# it under the terms of the GNU General Public License as published by
|
|
# the Free Software Foundation, either version 3 of the License, or
|
|
# (at your option) any later version.
|
|
#
|
|
# This program is distributed in the hope that it will be useful,
|
|
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
# GNU General Public License for more details.
|
|
#
|
|
# You should have received a copy of the GNU General Public License
|
|
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
# @summary Class manages all configuration files required for cd_fail2ban.
|
|
##############################################################################
|
|
class cd_fail2ban::main::files (
|
|
|
|
) inherits cd_fail2ban::params {
|
|
|
|
require cd_fail2ban::main::dirs
|
|
|
|
if $fn_manage_config == true {
|
|
|
|
# manage fail2ban.conf
|
|
|
|
file { $fn_fail2ban_conf_file:
|
|
ensure => present,
|
|
path => $fn_fail2ban_conf_file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0640',
|
|
selrange => s0,
|
|
selrole => object_r,
|
|
seltype => etc_t,
|
|
seluser => system_u,
|
|
content => template($fn_fail2ban_conf_erb),
|
|
notify => Service[$fn_service],
|
|
}
|
|
|
|
# manage fail2ban.local
|
|
|
|
file { $fn_fail2ban_local_file:
|
|
ensure => present,
|
|
path => $fn_fail2ban_local_file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0640',
|
|
selrange => s0,
|
|
selrole => object_r,
|
|
seltype => etc_t,
|
|
seluser => system_u,
|
|
content => template($fn_fail2ban_local_erb),
|
|
notify => Service[$fn_service],
|
|
}
|
|
|
|
# manage jail.conf
|
|
|
|
file { $fn_jail_conf_file:
|
|
ensure => present,
|
|
path => $fn_jail_conf_file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0640',
|
|
selrange => s0,
|
|
selrole => object_r,
|
|
seltype => etc_t,
|
|
seluser => system_u,
|
|
content => template($fn_jail_conf_erb),
|
|
notify => Service[$fn_service],
|
|
}
|
|
|
|
# manage jail.local
|
|
|
|
file { $fn_jail_local_file:
|
|
ensure => present,
|
|
path => $fn_jail_local_file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0640',
|
|
selrange => s0,
|
|
selrole => object_r,
|
|
seltype => etc_t,
|
|
seluser => system_u,
|
|
content => template($fn_jail_local_erb),
|
|
notify => Service[$fn_service],
|
|
}
|
|
|
|
}
|
|
}
|