## cd_haproxy::firewall::iptables.pp # Module name: cd_haproxy # Author: Arne Teuke (arne_teuke@confdroid.com) # License: # This file is part of cd_haproxy. # # cd_haproxy is used for providing automatic configuration of HA proxy. # Copyright (C) 2017 confdroid (copyright@confdroid.com) # This program is free software: you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation, either version 3 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program. If not, see . # @summary manage firewall settings through cd_firewall or puppetlabs-firewall ############################################################################### class cd_haproxy::firewall::iptables ( ) inherits cd_haproxy::params { if ($fqdn == $hy_host_fqdn) and ($hy_manage_fw == true) { require cd_haproxy::main::files firewall { "${hy_fw_order_no}${hy_http_port} tcp port ${hy_http_port}": proto => 'tcp', dport => $hy_http_port, action => 'accept', } firewall { "${hy_fw_order_no}${hy_https_port} tcp port ${hy_https_port}": proto => 'tcp', dport => $hy_https_port, action => 'accept', } } }