47e3bdc8f5
prodnxsr0020 runs FRR/OSPF hand-configured; bring its routing config under puppet without touching interfaces, firewall or dnsmasq. - add roles::infra::network::router (base + frrouting + frr_exporter) - enable ip_forward and disable rp_filter via sysctl::base - add prodnxsr0020 OSPF config (dum0, dum1, bond0.201; src 198.18.21.160) - pin dns, consul and router-id to dum0 instead of the WAN-facing primary IP - listen sshd on 127.0.0.1 and dum0 only, knocking out the common WAN primary IP - keep resolv.conf on the local dnsmasq (127.0.0.1) Reviewed-on: #536 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
27 lines
477 B
YAML
27 lines
477 B
YAML
---
|
|
hiera_include:
|
|
- frrouting
|
|
- exporters::frr_exporter
|
|
|
|
# routing
|
|
sysctl::base::values:
|
|
net.ipv4.ip_forward:
|
|
value: '1'
|
|
net.ipv4.conf.all.rp_filter:
|
|
value: '0'
|
|
net.ipv4.conf.default.rp_filter:
|
|
value: '0'
|
|
|
|
# frrouting
|
|
exporters::frr_exporter::enable: true
|
|
frrouting::ospfd_redistribute:
|
|
- connected
|
|
frrouting::daemons:
|
|
ospfd: true
|
|
|
|
# consul
|
|
profiles::consul::client::node_rules:
|
|
- resource: service
|
|
segment: frr_exporter
|
|
disposition: write
|