Archived
Initial planning docs and hardening scripts for HA rebuild
Covers node 1 hardware/network layout, LVM-thin -> ZFS migration path, Ceph as the future HA storage upgrade, and baseline SSH/firewall hardening.
This commit is contained in:
@@ -0,0 +1,31 @@
|
||||
# Example cluster-wide firewall rules for /etc/pve/firewall/cluster.fw
|
||||
#
|
||||
# Placeholders to fill in once the network is built:
|
||||
# <MGMT_CIDR> - management VLAN/subnet, e.g. 192.168.10.0/24
|
||||
# <COROSYNC_CIDR> - corosync VLAN/subnet
|
||||
# <CEPH_CIDR> - Ceph public + backend VLAN/subnet (once Ceph is live)
|
||||
#
|
||||
# Copy to /etc/pve/firewall/cluster.fw and edit before enabling.
|
||||
|
||||
[OPTIONS]
|
||||
enable: 1
|
||||
policy_in: DROP
|
||||
policy_out: ACCEPT
|
||||
|
||||
[IPSET mgmt]
|
||||
<MGMT_CIDR>
|
||||
|
||||
[RULES]
|
||||
# Web UI + SSH only from the management network
|
||||
IN ACCEPT -source +mgmt -p tcp -dport 8006 -log nolog
|
||||
IN ACCEPT -source +mgmt -p tcp -dport 22 -log nolog
|
||||
|
||||
# Corosync (cluster quorum) - nodes only, restrict source to the
|
||||
# corosync subnet once it's provisioned
|
||||
IN ACCEPT -source <COROSYNC_CIDR> -p udp -dport 5404:5405 -log nolog
|
||||
|
||||
# Ceph (uncomment once Ceph is live; ports: mon 3300,6789, osd/mgr/mds
|
||||
# 6800-7300)
|
||||
# IN ACCEPT -source <CEPH_CIDR> -p tcp -dport 3300 -log nolog
|
||||
# IN ACCEPT -source <CEPH_CIDR> -p tcp -dport 6789 -log nolog
|
||||
# IN ACCEPT -source <CEPH_CIDR> -p tcp -dport 6800:7300 -log nolog
|
||||
Reference in New Issue
Block a user