Vendor the external cookbooks
Knife-Zero doesn't include Berkshelf support, so vendoring everything in the repo is convenient again
This commit is contained in:
12
cookbooks/firewall/attributes/ufw.rb
Normal file
12
cookbooks/firewall/attributes/ufw.rb
Normal file
@@ -0,0 +1,12 @@
|
||||
default['firewall']['ufw']['defaults'] = {
|
||||
ipv6: 'yes',
|
||||
manage_builtins: 'no',
|
||||
ipt_sysctl: '/etc/ufw/sysctl.conf',
|
||||
ipt_modules: 'nf_conntrack_ftp nf_nat_ftp nf_conntrack_netbios_ns',
|
||||
policy: {
|
||||
input: 'DROP',
|
||||
output: 'ACCEPT',
|
||||
forward: 'DROP',
|
||||
application: 'SKIP',
|
||||
},
|
||||
}
|
||||
Reference in New Issue
Block a user