make $dnsapiport dynamic

This commit is contained in:
pettai 2024-06-14 10:20:46 +02:00
parent 4605f00aa2
commit c077fa4405
No known key found for this signature in database
GPG key ID: CDF2C381E9A751BD
3 changed files with 6 additions and 3 deletions

View file

@ -19,6 +19,7 @@ dns-rest-api1.sunet.se:
dns:
dns::knotdns:
dns::apache2:
dnsapiport = '8443'
sunet::certbot::acmed:
sunet::baas2:
nodename: 7B9DBFE1F4D1

View file

@ -1,4 +1,6 @@
class dns::apache2 {
class dns::apache2 (
$dnsapiport = '8443',
){
package { ['apache2', 'libapache2-mod-qos', 'python3-certbot-apache']:
ensure => installed,
@ -34,6 +36,6 @@ class dns::apache2 {
rule => "add rule inet filter input tcp dport 80 counter accept comment \"allow-apache2-http\""
}
sunet::nftables::rule { 'apache-https':
rule => "add rule inet filter input tcp dport 443 counter accept comment \"allow-apache2-https\""
rule => "add rule inet filter input tcp dport $dnsapiport counter accept comment \"allow-apache2-https\""
}
}

View file

@ -6,7 +6,7 @@
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
<IfModule mod_ssl.c>
<VirtualHost *:443>
<VirtualHost *:<%= @dnsapiport %>>
ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined