aboutsummaryrefslogtreecommitdiff
path: root/manifests/config.pp
diff options
context:
space:
mode:
authorTim Meusel <tim@bastelfreak.de>2017-09-18 15:23:36 +0200
committerTim Meusel <tim@bastelfreak.de>2018-03-15 17:06:08 +0100
commit2d355a4c1baadc761d6b12645d0274da8866f722 (patch)
treee6d1a78f9719397ed9ce9144bf4706a3ccd46c48 /manifests/config.pp
downloadpuppet-ferm-2d355a4c1baadc761d6b12645d0274da8866f722.tar.gz
puppet-ferm-2d355a4c1baadc761d6b12645d0274da8866f722.tar.bz2
initial commit
Diffstat (limited to 'manifests/config.pp')
-rw-r--r--manifests/config.pp46
1 files changed, 46 insertions, 0 deletions
diff --git a/manifests/config.pp b/manifests/config.pp
new file mode 100644
index 0000000..43c68ee
--- /dev/null
+++ b/manifests/config.pp
@@ -0,0 +1,46 @@
+# @api private
+# This class handles the configuration file. Avoid modifying private classes.
+class ferm::config {
+
+ # this is a private class
+ assert_private("You're not supposed to do that!")
+
+ # copy static files to ferm
+ # on a long term point of view, we want to package this
+ file{'/etc/ferm.d':
+ ensure => 'directory',
+ }
+ -> file{'/etc/ferm.d/definitions':
+ ensure => 'directory',
+ }
+ -> file{'/etc/ferm.d/chains':
+ ensure => 'directory',
+ }
+
+ if $ferm::manage_configfile {
+ concat{$ferm::configfile:
+ ensure => 'present',
+ }
+ concat::fragment{'ferm_header.conf':
+ target => $ferm::configfile,
+ content => epp("${module_name}/ferm_header.conf.epp"),
+ order => '01',
+ }
+
+ concat::fragment{'ferm.conf':
+ target => $ferm::configfile,
+ content => epp("${module_name}/ferm.conf.epp"),
+ order => '50',
+ }
+ }
+
+ ferm::chain{'INPUT':
+ policy => $ferm::input_policy,
+ }
+ ferm::chain{'FORWARD':
+ policy => $ferm::forward_policy,
+ }
+ ferm::chain{'OUTPUT':
+ policy => $ferm::output_policy,
+ }
+}