https://www.puppet.com/community logo
Join Slack
Powered by
# voxpupuli
  • d

    Dr Bunsen Honeydew

    05/22/2023, 4:27 PM
    See the
    puppetlabs-firewall
    module at https://forge.puppet.com/puppetlabs/firewall?src=slack&channel=voxpupuli
  • l

    Lumiere

    05/22/2023, 4:27 PM
    and I have no idea why (1.9.0)
  • s

    Shaik Ishak

    05/22/2023, 4:30 PM
    Hi Team, we are using this module for puppet-Splunk, in module where we need to give our Splunk details and like heavy forwarder details? https://github.com/voxpupuli/puppet-splunk
  • t

    tskirvin

    05/22/2023, 4:45 PM
    EL9? RedHat wants everybody to use firewalld. It pretty much works but man, the hoops to jump through…
  • b

    bastelfreak

    05/22/2023, 4:45 PM
    one of the worst pieces of software
  • b

    bastelfreak

    05/22/2023, 4:46 PM
    but it supports nftables as backend
  • b

    bastelfreak

    05/22/2023, 4:46 PM
    (and you can use nftables directly if you like)
  • t

    tskirvin

    05/22/2023, 4:46 PM
    Honestly firewalld itself is fine so far, but the fact that the core philosophy behind firewalld is so much more complicated makes it harder to deploy.
  • t

    tskirvin

    05/22/2023, 4:47 PM
    There’s way too many ways to do it.
  • v

    VoxBot

    05/22/2023, 4:47 PM
    Lumiere, ran into similar issues with other modules. i cant recommend enough to write a little monitoring script to monitor latest releases for all puppet forge based modules :P
  • t

    tskirvin

    05/22/2023, 4:47 PM
    (And I’ve got an open firewalld-puppet-module bug that’s holding us back from basic rule purging: https://github.com/voxpupuli/puppet-firewalld/issues/338)
  • b

    bastelfreak

    05/22/2023, 4:48 PM
    https://github.com/voxpupuli/ra10ke
  • b

    bastelfreak

    05/22/2023, 4:48 PM
    our rake tasks to detect outdated/migrated puppet modules 🙂
  • l

    Lumiere

    05/22/2023, 4:48 PM
    the problem is, we don't use a straight puppetfile
  • s

    Slackbot

    05/22/2023, 4:48 PM
    This message was deleted.
    b
    l
    • 3
    • 8
  • v

    VoxBot

    05/22/2023, 4:49 PM
    ok that makes it a little more complex
  • l

    Lumiere

    05/22/2023, 4:49 PM
    we actually tried at one point to contribute it back iirc
  • v

    VoxBot

    05/22/2023, 4:49 PM
    @bastelfreak, thanks for the rake task, will have a look into it. the less i have to maintain manually the better
  • b

    bastelfreak

    05/22/2023, 4:50 PM
    @tskirvin I'm afraid you will probably have to fix it yourself. But I will happily review your PRs
  • b

    bastelfreak

    05/22/2023, 4:51 PM
    Since I don't use firewalld and all customers moved away from it, I won't have the time to fix open issues
  • t

    tskirvin

    05/22/2023, 4:51 PM
    Honestly I don’t even know where to start. That particular bug seems really bad, like core assumptions are broken and I don’t grok the whole module so I can’t fix it.
  • v

    VoxBot

    05/22/2023, 6:00 PM
    bastelfreak: had you seen https://community.theforeman.org/t/automatically-install-arch-linux/33590 already?
  • v

    VoxBot

    05/22/2023, 6:00 PM
    oh neat
  • v

    VoxBot

    05/22/2023, 6:00 PM
    no I haven't
  • v

    VoxBot

    05/22/2023, 7:41 PM
    Even redhat says to use nftables over firewalld for anything other than a desktop https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/securing_networks/getting-started-with-nftables_securing-networks
  • v

    VoxBot

    05/22/2023, 7:42 PM
    \o/
  • v

    VoxBot

    05/22/2023, 7:43 PM
    yeah everybody should use puppet/nftables
  • d

    Dr Bunsen Honeydew

    05/22/2023, 7:43 PM
    See the
    puppet-nftables
    module at https://forge.puppet.com/puppet/nftables?src=slack&channel=voxpupuli
  • v

    VoxBot

    05/22/2023, 7:43 PM
    CERN approved!
  • v

    VoxBot

    05/22/2023, 7:43 PM
    (also please stop using puppetlabs/firewall: https://github.com/puppetlabs/puppetlabs-firewall/issues/1100)
1...483484485...642Latest