Limit access to hosts that have sssd running
This commit is contained in:
parent
2c423fc0ca
commit
dc9a3a0725
7 changed files with 22 additions and 2 deletions
|
@ -7,3 +7,6 @@ firewall_in:
|
||||||
- {proto: tcp, port: 80, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 80, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 443, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 443, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- sysadm
|
||||||
|
|
|
@ -2,6 +2,7 @@
|
||||||
datadisks:
|
datadisks:
|
||||||
- {size: 10, type: nvme}
|
- {size: 10, type: nvme}
|
||||||
mem_size: 4192
|
mem_size: 4192
|
||||||
|
|
||||||
firewall_in:
|
firewall_in:
|
||||||
- {proto: tcp, port: 22, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 22, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 25}
|
- {proto: tcp, port: 25}
|
||||||
|
@ -11,3 +12,6 @@ firewall_in:
|
||||||
- {proto: tcp, port: 587}
|
- {proto: tcp, port: 587}
|
||||||
- {proto: tcp, port: 993}
|
- {proto: tcp, port: 993}
|
||||||
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- sysadm
|
||||||
|
|
|
@ -10,3 +10,6 @@ firewall_in:
|
||||||
- {proto: tcp, port: 2049, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 2049, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 2049, from: [172.20.30.0/24]}
|
- {proto: tcp, port: 2049, from: [172.20.30.0/24]}
|
||||||
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- root
|
||||||
|
|
|
@ -33,3 +33,6 @@ firewall_in:
|
||||||
firewall_raw:
|
firewall_raw:
|
||||||
- "-A INPUT -i eth1 -d 224.0.0.0/8 -j ACCEPT"
|
- "-A INPUT -i eth1 -d 224.0.0.0/8 -j ACCEPT"
|
||||||
- "-A INPUT -i eth1 -p vrrp -j ACCEPT"
|
- "-A INPUT -i eth1 -p vrrp -j ACCEPT"
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- sysadm
|
||||||
|
|
|
@ -22,3 +22,6 @@ firewall_in:
|
||||||
firewall_raw:
|
firewall_raw:
|
||||||
- "-A INPUT -i eth1 -d 224.0.0.0/8 -j ACCEPT"
|
- "-A INPUT -i eth1 -d 224.0.0.0/8 -j ACCEPT"
|
||||||
- "-A INPUT -i eth1 -p vrrp -j ACCEPT"
|
- "-A INPUT -i eth1 -p vrrp -j ACCEPT"
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- sysadm
|
||||||
|
|
|
@ -1,6 +1,4 @@
|
||||||
---
|
---
|
||||||
|
|
||||||
# beef up shell hosts
|
|
||||||
dsk_size: 40
|
dsk_size: 40
|
||||||
mem_size: 8192
|
mem_size: 8192
|
||||||
num_cpus: 4
|
num_cpus: 4
|
||||||
|
@ -13,3 +11,6 @@ firewall_in:
|
||||||
|
|
||||||
ssh_hostnames:
|
ssh_hostnames:
|
||||||
- shell.foo.sh
|
- shell.foo.sh
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- foosh
|
||||||
|
|
|
@ -3,3 +3,6 @@ firewall_in:
|
||||||
- {proto: tcp, port: 22, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 22, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 443, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 443, from: [172.20.20.0/22]}
|
||||||
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
- {proto: tcp, port: 9100, from: [172.20.20.0/22]}
|
||||||
|
|
||||||
|
sssd_allow_groups:
|
||||||
|
- root
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue