Saltstack Official UFW Formula
Nie możesz wybrać więcej, niż 25 tematów Tematy muszą się zaczynać od litery lub cyfry, mogą zawierać myślniki ('-') i mogą mieć do 35 znaków.
Alexandre Anriot b749509eb1 Add kitchen tests 6 lat temu
_modules Handle test mode when enabling ufw 6 lat temu
_states Fix rules logic 6 lat temu
test/integration/ufw Add kitchen tests 6 lat temu
ufw Handle loglevel 6 lat temu
.gitignore Add kitchen tests 6 lat temu
.kitchen.yml Add kitchen tests 6 lat temu
Gemfile Add kitchen tests 6 lat temu
LICENSE Initial commit 10 lat temu
README.md Add kitchen tests 6 lat temu
pillar.example Handle loglevel 6 lat temu

README.md

Ufw Salt Formula

This module manages your firewall using ufw with pillar configured rules.

See the full Salt Formulas installation and usage instructions.

Usage

All the configuration for the firewall is done via pillar (pillar.example).

Enable firewall, applying default configuration:

ufw:
  enabled: True

Allow 80/tcp (http) traffic from only two remote addresses:

ufw:
  services:
    http:
      protocol: tcp
      from_addr:
        - 10.0.2.15
        - 10.0.2.16

Allow 443/tcp (https) traffic from network 10.0.0.0/8 to an specific local ip:

ufw:
  services:
    https:
      protocol: tcp
      from_addr:
        - 10.0.0.0/8
      to_addr: 10.0.2.1

Allow from a service port:

ufw:
  services:
    smtp:
      protocol: tcp

Allow from an specific port, by number:

ufw:
  services:
    139:
      protocol: tcp

Allow from a range of ports, udp:

ufw:
  services:
    "10000:20000":
      protocol: udp

Allow from two specific ports, udp:

ufw:
  services:
    "30000,40000":
      protocol: udp

Allow an application defined at /etc/ufw/applications.d/:

ufw:
  applications:
    - OpenSSH

Run tests

This formula is tested with Kitchen and Inspec in a Docker container.

To run tests you need to

  • install Ruby dependencies : bundle install
  • run Kitchen : kitchen test

Authors

Original state and module based on the work from Yigal Duppen.

Salt formula originally developed by Mario del Pozo.