Lock down postgresql access to koji03/04. Nothing else should need it.
This commit is contained in:
parent
111bb8ba62
commit
71a350daca
1 changed files with 5 additions and 1 deletions
|
@ -24,8 +24,12 @@ host_backup_targets: ['/backups']
|
||||||
lvm_size: 300000
|
lvm_size: 300000
|
||||||
mem_size: 25165
|
mem_size: 25165
|
||||||
num_cpus: 8
|
num_cpus: 8
|
||||||
tcp_ports: [ 5432, 443 ]
|
|
||||||
fas_client_groups: sysadmin-dba,sysadmin-noc
|
fas_client_groups: sysadmin-dba,sysadmin-noc
|
||||||
|
|
||||||
# kernel SHMMAX value
|
# kernel SHMMAX value
|
||||||
kernel_shmmax: 68719476736
|
kernel_shmmax: 68719476736
|
||||||
|
|
||||||
|
#
|
||||||
|
# Only allow postgresql access from the frontend node.
|
||||||
|
#
|
||||||
|
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.125.59 --dport 5432 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 10.5.125.60 --dport 5432 -j ACCEPT' ]
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue