- add dmz acl - add common acl - add loopback/ceph/physical subnets to main acl Reviewed-on: https://git.query.consul/unkinben/puppet-prod/pulls/246
103 lines
2.3 KiB
YAML
103 lines
2.3 KiB
YAML
---
|
|
profiles::dns::resolver::acls:
|
|
acl-main.unkin.net:
|
|
addresses:
|
|
- 10.10.8.1/32
|
|
- 198.18.21.160/27
|
|
- 198.18.21.192/27
|
|
- 198.18.13.0/24
|
|
- 198.18.14.0/24
|
|
- 198.18.15.0/24
|
|
- 198.18.16.0/24
|
|
- 198.18.17.0/24
|
|
- 198.18.18.0/24
|
|
- 198.18.19.0/24
|
|
- 198.18.20.0/24
|
|
- 198.18.21.0/24
|
|
- 198.18.22.0/24
|
|
- 198.18.23.0/24
|
|
acl-dmz:
|
|
addresses:
|
|
- 198.18.24.0/24
|
|
acl-common:
|
|
addresses:
|
|
- 198.18.25.0/24
|
|
- 198.18.26.0/24
|
|
- 198.18.27.0/24
|
|
- 198.18.28.0/24
|
|
- 198.18.29.0/24
|
|
acl-nomad-jobs:
|
|
addresses:
|
|
- 198.18.64.0/24
|
|
- 198.18.65.0/24
|
|
- 198.18.66.0/24
|
|
- 198.18.67.0/24
|
|
- 198.18.68.0/24
|
|
- 198.18.69.0/24
|
|
|
|
profiles::dns::resolver::zones:
|
|
8.10.10.in-addr.arpa-forward:
|
|
domain: '8.10.10.in-addr.arpa'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
16.10.10.in-addr.arpa-forward:
|
|
domain: '16.10.10.in-addr.arpa'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
20.10.10.in-addr.arpa-forward:
|
|
domain: '20.10.10.in-addr.arpa'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
dmz.unkin.net-forward:
|
|
domain: 'dmz.unkin.net'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
network.unkin.net-forward:
|
|
domain: 'network.unkin.net'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
prod.unkin.net-forward:
|
|
domain: 'prod.unkin.net'
|
|
zone_type: 'forward'
|
|
forwarders:
|
|
- 10.10.16.32
|
|
- 10.10.16.33
|
|
forward: 'only'
|
|
|
|
profiles::dns::resolver::views:
|
|
openforwarder:
|
|
recursion: true
|
|
zones:
|
|
- main.unkin.net-forward
|
|
- dmz.unkin.net-forward
|
|
- network.unkin.net-forward
|
|
- prod.unkin.net-forward
|
|
- consul-forward
|
|
- 13.18.198.in-addr.arpa-forward
|
|
- 14.18.198.in-addr.arpa-forward
|
|
- 15.18.198.in-addr.arpa-forward
|
|
- 16.18.198.in-addr.arpa-forward
|
|
- 17.18.198.in-addr.arpa-forward
|
|
- 8.10.10.in-addr.arpa-forward
|
|
- 16.10.10.in-addr.arpa-forward
|
|
- 20.10.10.in-addr.arpa-forward
|
|
match_clients:
|
|
- acl-main.unkin.net
|
|
- acl-nomad-jobs
|
|
- acl-common
|