- create classes for each class of in/out traffic - use hier_include to add firewall rules to each role
8 lines
185 B
Puppet
8 lines
185 B
Puppet
class firewall::rules::out::mysql (
|
|
String $ipset = 'sql_galera',
|
|
){
|
|
nftables::rule { 'default_out-mysql_tcp_3306':
|
|
content => "tcp dport 3306 ip daddr @${ipset} accept",
|
|
}
|
|
}
|