Add router role for prodnxsr0020 (#536)
prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq. - add roles::infra::network::router (base + frrouting + frr_exporter) - enable ip_forward and disable rp_filter via sysctl::base - add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160) - pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP - listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP - keep resolv.conf on the local dnsmasq (127.0.0.1) Reviewed-on: #536 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #536.
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
---
|
||||
hiera_include:
|
||||
- frrouting
|
||||
- exporters::frr_exporter
|
||||
|
||||
# routing
|
||||
sysctl::base::values:
|
||||
net.ipv4.ip_forward:
|
||||
value: '1'
|
||||
net.ipv4.conf.all.rp_filter:
|
||||
value: '0'
|
||||
net.ipv4.conf.default.rp_filter:
|
||||
value: '0'
|
||||
|
||||
# frrouting
|
||||
exporters::frr_exporter::enable: true
|
||||
frrouting::ospfd_redistribute:
|
||||
- connected
|
||||
frrouting::daemons:
|
||||
ospfd: true
|
||||
|
||||
# consul
|
||||
profiles::consul::client::node_rules:
|
||||
- resource: service
|
||||
segment: frr_exporter
|
||||
disposition: write
|
||||
Reference in New Issue
Block a user