Compare commits

..

4 Commits

Author SHA1 Message Date
Jenkins
d069da5c79 Merge branch 'jenkins-build-2' into 'master'
Auto-merge for build 2

See merge request puppet/confdroid_ssh!2
2026-04-05 15:21:41 +02:00
Jenkins Server
dfec1a2790 Merge remote-tracking branch 'origin/master' into jenkins-build-2 2026-04-05 15:17:07 +02:00
1d2e0097ba OP#561 add firewall 2026-04-05 15:16:48 +02:00
Jenkins
f980cb2260 Merge branch 'jenkins-build-1' into 'master'
Auto-merge for build 1

See merge request puppet/confdroid_ssh!1
2026-04-05 12:40:35 +00:00
5 changed files with 37 additions and 4 deletions

View File

@@ -23,6 +23,11 @@
## Features
- install required binaries
- manage configuration based on parameters
- manage service
- (optional) manage firewall
## Support
- Rocky 9

View File

@@ -0,0 +1,17 @@
## confdroid_ssh::firewall::iptables.pp
# Module name: confdroid_ssh
# Author: 12ww1160 (12ww1160@confdroid.com)
# @summary Class manages firewall rules for SSH
##############################################################################
class confdroid_ssh::firewall::iptables (
) inherits confdroid_ssh::params {
if $ssh_use_firewall {
firewall { "${ssh_fw_order}${ssh_fw_port} allow SSH on port ${ssh_fw_port}":
ensure => 'present',
jump => 'accept',
proto => 'tcp',
dport => $ssh_fw_port,
}
}
}

View File

@@ -5,7 +5,7 @@
##############################################################################
class confdroid_ssh::main::install (
) inherits confdroid_ssh::params {
package { $reqpackages:
package { $ssh_reqpackages:
ensure => $pkg_ensure,
}
}

View File

@@ -6,6 +6,9 @@
class confdroid_ssh::main::service (
) inherits confdroid_ssh::params {
require confdroid_ssh::main::files
if $ssh_use_firewall {
require confdroid_ssh::firewall::iptables
}
service { $sshd_service:
ensure => running,

View File

@@ -2,13 +2,21 @@
# Module name: confdroid_ssh
# Author: 12ww1160 (12ww1160@confdroid.com)
# @summary Class contains all class parameters for confdroid_ssh
# @param [Array] reqpackages packages to install
# @param [Array] ssh_reqpackages packages to install
# @param [String] pkg_ensure version to install: 'present' or 'latest'
# @param [Boolean] ssh_use_firewall whether to manage firewall settings
# @param [String] ssh_fw_port port to use for SSHD and in fw
# @param [String] ssh_fw_order order of firewall rule
##############################################################################
class confdroid_ssh::params (
Array $reqpackages = ['openssh','openssh-clients','openssh-server'],
String $pkg_ensure = 'present',
Array $ssh_reqpackages = ['openssh','openssh-clients','openssh-server'],
String $pkg_ensure = 'present',
# firewall settings
Boolean $ssh_use_firewall = true,
String $ssh_fw_port = '22',
String $ssh_fw_order = '50',
) {
# default facts