l monitoring: open ports

This commit is contained in:
lassulus 2018-04-28 09:41:43 +02:00
parent 82e465bcfc
commit dabd9f0f02
2 changed files with 10 additions and 2 deletions

View File

@ -1,7 +1,9 @@
{ config, lib, pkgs, ... }: { config, lib, pkgs, ... }:
{ {
networking.firewall.allowedTCPPorts = [ 9100 ]; krebs.iptables.tables.filter.INPUT.rules = [
{ predicate = "-i retiolum -p tcp --dport 9100 -s ${config.krebs.hosts.prism.nets.retiolum.ip4.addr}"; target = "ACCEPT"; v6 = false; }
{ predicate = "-i retiolum -p tcp --dport 9100 -s ${config.krebs.hosts.prism.nets.retiolum.ip6.addr}"; target = "ACCEPT"; v4 = false; }
];
services.prometheus.exporters = { services.prometheus.exporters = {
node = { node = {
enable = true; enable = true;

View File

@ -9,6 +9,12 @@
# useDHCP = true; # useDHCP = true;
#}; #};
krebs.iptables.tables.filter.INPUT.rules = [
{ predicate = "-i retiolum -p tcp --dport 3000"; target = "ACCEPT"; }
{ predicate = "-i retiolum -p tcp --dport 9090"; target = "ACCEPT"; }
{ predicate = "-i retiolum -p tcp --dport 9093"; target = "ACCEPT"; }
];
services = { services = {
prometheus = { prometheus = {
enable = true; enable = true;