modify nodes and bundles for new nftables syntax

This commit is contained in:
Franzi 2021-06-03 13:59:15 +02:00
parent ecb67d012b
commit d569b00960
Signed by: kunsi
GPG key ID: 12E3D2136B818350
30 changed files with 172 additions and 126 deletions

View file

@ -18,7 +18,7 @@ alias_maps = hash:/etc/aliases
relayhost = ${node.metadata['postfix']['relayhost']}
% endif
% if node.has_bundle('postfixadmin') or node.has_bundle('iptables'):
% if node.has_bundle('postfixadmin') or node.has_bundle('nftables'):
inet_interfaces = all
% else:
inet_interfaces = 127.0.0.1

View file

@ -100,11 +100,11 @@ def letsencrypt(metadata):
@metadata_reactor.provides(
'iptables/port_rules/25',
'iptables/port_rules/587',
'iptables/port_rules/2525',
'firewall/port_rules/25',
'firewall/port_rules/587',
'firewall/port_rules/2525',
)
def iptables(metadata):
def firewall(metadata):
if node.has_bundle('postfixadmin'):
default = {'*'}
else:
@ -119,7 +119,7 @@ def iptables(metadata):
rules['2525'] = atomic(metadata.get('postfix/restrict-to', default))
return {
'iptables': {
'firewall': {
'port_rules': rules,
},
}