2021-12-21 14:56:24 +00:00
|
|
|
from bundlewrap.metadata import atomic
|
|
|
|
|
2022-01-04 12:37:32 +00:00
|
|
|
defaults = {
|
|
|
|
'monit': {
|
|
|
|
'services': {
|
|
|
|
'openssh': {
|
|
|
|
'bin': '/usr/sbin/sshd',
|
|
|
|
'systemd_unit': 'sshd',
|
|
|
|
'ports': {
|
|
|
|
'22': {
|
|
|
|
'protocol': 'ssh',
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
2021-12-21 14:56:24 +00:00
|
|
|
@metadata_reactor.provides(
|
|
|
|
'firewall/port_rules/22',
|
|
|
|
)
|
|
|
|
def firewall(metadata):
|
|
|
|
return {
|
|
|
|
'firewall': {
|
|
|
|
'port_rules': {
|
|
|
|
'22': atomic(metadata.get('openssh/restrict-to', {'*'})),
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|