diff --git a/quantum_support/conductor/data/templates/cf/ADSecurity.template b/quantum_support/conductor/data/templates/cf/ADSecurity.template new file mode 100644 index 00000000..f8e85650 --- /dev/null +++ b/quantum_support/conductor/data/templates/cf/ADSecurity.template @@ -0,0 +1,107 @@ +{ + "Resources": { + "$port-{instanceName}": { + "Properties": { + "security_groups" : [ {"Ref" : "ADSecurityGroup"} ] + } + }, + "ADSecurityGroup": { + "Type": "AWS::EC2::SecurityGroup", + "Properties": { + "SecurityGroupIngress": [ + { + "IpProtocol": "udp", + "FromPort" : "123", + "ToPort": "123", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "135", + "ToPort": "135", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "464", + "ToPort": "464", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "udp", + "FromPort" : "464", + "ToPort": "464", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "49152", + "ToPort": "65535", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "389", + "ToPort": "389", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "udp", + "FromPort" : "389", + "ToPort": "389", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "636", + "ToPort": "636", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "3268", + "ToPort": "3268", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "3269", + "ToPort": "3269", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "53", + "ToPort": "53", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "udp", + "FromPort" : "53", + "ToPort": "53", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "88", + "ToPort": "88", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "udp", + "FromPort" : "88", + "ToPort": "88", + "CidrIp": "10.0.0.0/24" + }, + { + "IpProtocol": "tcp", + "FromPort" : "445", + "ToPort": "445", + "CidrIp": "10.0.0.0/24" + } + ], + "GroupDescription": "Enable access for AD/SMB protocols" + } + } + } +} diff --git a/quantum_support/conductor/data/templates/cf/Linux.template b/quantum_support/conductor/data/templates/cf/Linux.template index f095e259..2edc7cd0 100644 --- a/quantum_support/conductor/data/templates/cf/Linux.template +++ b/quantum_support/conductor/data/templates/cf/Linux.template @@ -58,18 +58,6 @@ "IpProtocol": "icmp", "FromPort": "-1", "CidrIp": "0.0.0.0/0" - }, - { - "IpProtocol": "tcp", - "FromPort" : "1", - "ToPort": "65535", - "CidrIp": "10.0.0.0/24" - }, - { - "IpProtocol": "udp", - "FromPort" : "1", - "ToPort": "65535", - "CidrIp": "10.0.0.0/24" } ], "GroupDescription": "Default security group for Linux Murano Environments" diff --git a/quantum_support/conductor/data/templates/cf/SQLCluster.template b/quantum_support/conductor/data/templates/cf/SQLCluster.template index 1d81fec0..48bdc471 100644 --- a/quantum_support/conductor/data/templates/cf/SQLCluster.template +++ b/quantum_support/conductor/data/templates/cf/SQLCluster.template @@ -25,16 +25,22 @@ "CidrIp": "0.0.0.0/0" }, { - "ToPort": "1433", - "IpProtocol": "tcp", "FromPort": "1433", + "ToPort": "1434", + "IpProtocol": "tcp", "CidrIp": "0.0.0.0/0" }, { - "ToPort": "1434", + "FromPort": "445", + "ToPort": "445", "IpProtocol": "tcp", - "FromPort": "1434", - "CidrIp": "0.0.0.0/0" + "CidrIp": "10.0.0.0/24" + }, + { + "FromPort": "1024", + "ToPort": "65535", + "IpProtocol": "tcp", + "CidrIp": "10.0.0.0/24" } ], "GroupDescription": "Enable MS SQL access" diff --git a/quantum_support/conductor/data/templates/cf/Windows.template b/quantum_support/conductor/data/templates/cf/Windows.template index 591a1462..357864d7 100644 --- a/quantum_support/conductor/data/templates/cf/Windows.template +++ b/quantum_support/conductor/data/templates/cf/Windows.template @@ -47,12 +47,6 @@ "FromPort": "3389", "CidrIp": "0.0.0.0/0" }, - { - "ToPort": "22", - "IpProtocol": "tcp", - "FromPort": "22", - "CidrIp": "0.0.0.0/0" - }, { "ToPort": "-1", "IpProtocol": "icmp", @@ -60,15 +54,9 @@ "CidrIp": "0.0.0.0/0" }, { + "FromPort": "5985", + "ToPort": "5986", "IpProtocol": "tcp", - "FromPort" : "1", - "ToPort": "65535", - "CidrIp": "10.0.0.0/24" - }, - { - "IpProtocol": "udp", - "FromPort" : "1", - "ToPort": "65535", "CidrIp": "10.0.0.0/24" } ],