openstack-infrastructure-te.../s2i2s/dmarc-reports/README.md

58 lines
2.0 KiB
Markdown

# DMARC reports service of the S2I2S project
One VM, `m1.large` (RAM 8 - VCPUs 4), Ubuntu 24.04, 20 GB of root disk, on the
main private network only (`10.10.0.166`), and **one 50 GB SSD volume**
(`CephSSD`, `enable_online_resize`) on `/dev/vdb`, for the OpenSearch indexes.
It runs parsedmarc, OpenSearch and OpenSearch Dashboards. parsedmarc reads the
aggregate and failure reports sent to `dmarc-reports@isti.cnr.it` (the `rua`
and `ruf` of `_dmarc.isti.cnr.it`) over IMAP, through the router of the
project: no floating IP.
The resources live in [`../../modules/dmarc_reports`](../../modules/dmarc_reports),
which carries the sizing and the service port as defaults. Only the address on
the main private network, from the address plan in [`../variables`](../variables)
(`basic_services_ip.dmarc_reports`), and the IDs read from the other
workspaces are set in `main.tf`.
Security groups on the port:
* `default_for_all`;
* `traffic_to_dmarc_reports_from_the_main_load_balancers`: **5601**
(OpenSearch Dashboards, TLS with the certificate of the internal CA) from
each L7 load balancer.
OpenSearch itself (9200) is not reachable from outside the VM. The Grafana
server that will read the indexes (`public_grafana_server_cidr` in
`../variables`) is a separate activity: it will need either a rule here or a
service on the load balancers.
## Names
| Name | Type |
|---|---|
| `opensearch-dmarc.s2i2s.cloud.isti.cnr.it` | A → `10.10.0.166`, used by the playbooks and by the load balancer |
| `dmarc.s2i2s.cloud.isti.cnr.it` | CNAME → `main-lb.s2i2s.cloud.isti.cnr.it.` |
The public name is served by the L7 load balancers: the `dmarc_reports` entry
of `haproxy_l7_services` in `group_vars/main_haproxy_l7/main_haproxy_l7.yml` of
`infrastructure-playbooks`.
## Order of the applies
```
main_net_dns_router -> project-setup -> dmarc-reports
```
```bash
tofu init
tofu plan -out=dmarc-reports.plan
tofu apply dmarc-reports.plan
```
Then regenerate the ansible inventory in `infrastructure-playbooks`:
```bash
ansible-playbook tofu-inventory.yml --diff
```