Installs and configures knockd.
None
Tested on
- Ubuntu 12.04
- Ubuntu 13.04
- Debian 7.4
Include the knockd::default
recipe to start using knockd.
include_recipe 'knockd'
knockd_sequence 'openHTTP' do
sequence ['7000', '8000', '9000:tcp']
tcpflags :syn
on_open '/sbin/iptables -A INPUT -s %IP% -p tcp --dport 80 -j ACCEPT'
end
knockd_sequence 'https' do
sequence [ '2123', '2124:tcp', '2125:udp' ]
tcpflags [ :syn, :ack ]
on_open 'echo https open'
end
['knockd']['enabled']
- Enables or disables knockd. default true.['knockd']['interface']
- Make knockd listen to a specific interface. default nil.
Provides LWRP for knockd. Note that by default, knockd service is disabled.
Definition that constructs a sequence to be specified in the knockd configuration.
- :enable: adds sequence to configuration
- :disable: removes sequence from configuration
- sequence: list of ports following the [:<tcp|udp>] syntax.
- port: alternative listing of ports.
- tcpflags: list of flags for tcp ports. Defaults to [:syn,:ack]
- seq_timeout: sequence timeout. Defaults to 30 seconds
- auto_close: if specified, causes on_close to be fired after N seconds. Defaults to off value -1.
- on_open: command to run when port is opened.
- on_close: command to run when port is closed. Only works with valid auto_close.
Performs a simple knock. Does this at the start of the resource section.
- :enable: performs knock sequence.
- :nothing: does nothing.
- ip: Destination IP address.
- sequence: list of ports following the [:<tcp|udp>] syntax.
- Author:: Li-Te Chen (datacoda@gmail.com)
Copyright 2014-2016 Nephila Graphic, Li-Te Chen
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.