diff --git a/inventory/group_vars/anitya-backend b/inventory/group_vars/anitya-backend index b641abce69..e2937fb0eb 100644 --- a/inventory/group_vars/anitya-backend +++ b/inventory/group_vars/anitya-backend @@ -11,8 +11,6 @@ custom_rules: [ # Need for rsync from log01 for logs. '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', - # Need so that anitya-backend can talk fedmsg to our relay - '-A INPUT -p tcp -m tcp -s 140.211.169.230 --dport 9939 -j ACCEPT', ] # No other ports open. no web service running here. diff --git a/inventory/group_vars/anitya-frontend b/inventory/group_vars/anitya-frontend index cca63b8f78..43564ac9df 100644 --- a/inventory/group_vars/anitya-frontend +++ b/inventory/group_vars/anitya-frontend @@ -10,8 +10,13 @@ num_cpus: 2 # 9940 is for the anitya public relay tcp_ports: [ 80, 443, 9940 ] -# Neeed for rsync from log01 for logs. -custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ] +custom_rules: [ + # Need for rsync from log01 for logs. + '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', + '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT', + # Need so that anitya-backend can talk fedmsg to our relay + '-A INPUT -p tcp -m tcp -s 140.211.169.230 --dport 9939 -j ACCEPT', + ] fas_client_groups: sysadmin-noc,sysadmin-web