Puppet Class: conntrackd::config
- Defined in:
- manifests/config.pp
Summary
This class exists to coordinate all configuration for the conntrackd daemonOverview
# conntrackd::config
242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 |
# File 'manifests/config.pp', line 242
class conntrackd::config (
Enum['present', 'absent'] $ensure = $conntrackd::ensure,
Enum['Multicast', 'UDP'] $protocol = $conntrackd::protocol,
Integer[-20,19] $nice = $conntrackd::nice,
Integer $hashsize = $conntrackd::hashsize,
Integer $hashlimit = $conntrackd::_hashlimit,
String $logfile = $conntrackd::logfile,
String $syslog = $conntrackd::syslog,
String $lockfile = $conntrackd::lockfile,
String $sock_path = $conntrackd::sock_path,
Integer $sock_backlog = $conntrackd::sock_backlog,
Array $ignore_ips_ipv4 = $conntrackd::ignore_ips_ipv4,
Array $ignore_ips_ipv6 = $conntrackd::ignore_ips_ipv6,
Array $tcp_flows = $conntrackd::tcp_flows,
Integer $netlinkbuffersize = $conntrackd::netlinkbuffersize,
Integer $netlinkbuffersizemaxgrowth = $conntrackd::netlinkbuffersizemaxgrowth,
String $netlinkoverrunresync = $conntrackd::netlinkoverrunresync,
String $netlinkeventsreliable = $conntrackd::netlinkeventsreliable,
Optional[Integer] $pollsecs = $conntrackd::pollsecs,
Integer $eventiterationlimit = $conntrackd::eventiterationlimit,
Enum['FTFW', 'NOTRACK', 'ALARM'] $sync_mode = $conntrackd::sync_mode,
Integer $resend_queue_size = $conntrackd::resend_queue_size,
Integer $ack_window_size = $conntrackd::ack_window_size,
String $disable_external_cache = $conntrackd::disable_external_cache,
String $disable_internal_cache = $conntrackd::disable_internal_cache,
Integer $refresh_time = $conntrackd::refresh_time,
Integer $cache_timeout = $conntrackd::cache_timeout,
Integer $commit_timeout = $conntrackd::commit_timeout,
Integer $purge_timeout = $conntrackd::purge_timeout,
String $interface = $conntrackd::interface,
String $ipv4_address = $conntrackd::ipv4_address,
String $ipv4_interface = $conntrackd::ipv4_interface,
String $mcast_group = $conntrackd::mcast_group,
Integer $sndsocketbuffer = $conntrackd::sndsocketbuffer,
Integer $rcvsocketbuffer = $conntrackd::rcvsocketbuffer,
String $checksum = $conntrackd::checksum,
Optional[String] $udp_ipv6_address = $conntrackd::udp_ipv6_address,
Optional[String] $udp_ipv4_dest = $conntrackd::udp_ipv4_dest,
Optional[String] $udp_ipv6_dest = $conntrackd::udp_ipv6_dest,
Integer $udp_port = $conntrackd::udp_port,
Array $filter_accept_protocols = $conntrackd::filter_accept_protocols,
String $tcp_window_tracking = $conntrackd::tcp_window_tracking,
Array $track_tcp_states = $conntrackd::track_tcp_states,
String $scheduler_type = $conntrackd::scheduler_type,
String $scheduler_priority = $conntrackd::scheduler_priority,
Optional[String] $stats_logfile = $conntrackd::stats_logfile,
String $stats_netlink_reliable = $conntrackd::stats_netlink_reliable,
Optional[String] $stats_syslog = $conntrackd::stats_syslog,
) {
assert_private()
#### Config management
if $ensure == 'present' {
# set params: in operation
$config_exists = 'present'
$config_dir_exists = 'directory'
} else {
# set params: removal
$config_exists = 'absent'
$config_dir_exists = 'absent'
}
# sanity check some paramaters
if $protocol == 'UDP' {
if $ipv4_address == undef and $udp_ipv6_address == undef {
fail("\"${module_name}\": protocol \"${protocol}\" requires atleast one of: ipv4_address, ipv6_address to be specified")
}
if $ipv4_address and $udp_ipv4_dest == undef {
fail("\"${module_name}\": protocol \"${protocol}\" udp_ipv4_dest must be specified if ipv4_address is specified")
}
if $udp_ipv6_address and $udp_ipv6_dest == undef {
fail("\"${module_name}\": protocol \"${protocol}\" udp_ipv6_dest must be specified if ipv6_address is specified")
}
}
# manage config dir
file { 'conntrackd-confdir':
ensure => $config_dir_exists,
path => $conntrackd::config_dir,
mode => '0755',
}
# configuration file
file { 'conntrackd-config':
ensure => $config_exists,
path => "${conntrackd::config_dir}/${conntrackd::config_filename}",
content => epp('conntrackd/conntrackd.conf.epp'),
mode => '0644',
require => File['conntrackd-confdir'],
notify => Service['conntrackd'],
}
}
|