58 lines
2.0 KiB
Markdown
58 lines
2.0 KiB
Markdown
# DMARC reports service of the S2I2S project
|
|
|
|
One VM, `m1.large` (RAM 8 - VCPUs 4), Ubuntu 24.04, 20 GB of root disk, on the
|
|
main private network only (`10.10.0.166`), and **one 50 GB SSD volume**
|
|
(`CephSSD`, `enable_online_resize`) on `/dev/vdb`, for the OpenSearch indexes.
|
|
|
|
It runs parsedmarc, OpenSearch and OpenSearch Dashboards. parsedmarc reads the
|
|
aggregate and failure reports sent to `dmarc-reports@isti.cnr.it` (the `rua`
|
|
and `ruf` of `_dmarc.isti.cnr.it`) over IMAP, through the router of the
|
|
project: no floating IP.
|
|
|
|
The resources live in [`../../modules/dmarc_reports`](../../modules/dmarc_reports),
|
|
which carries the sizing and the service port as defaults. Only the address on
|
|
the main private network, from the address plan in [`../variables`](../variables)
|
|
(`basic_services_ip.dmarc_reports`), and the IDs read from the other
|
|
workspaces are set in `main.tf`.
|
|
|
|
Security groups on the port:
|
|
|
|
* `default_for_all`;
|
|
* `traffic_to_dmarc_reports_from_the_main_load_balancers`: **5601**
|
|
(OpenSearch Dashboards, TLS with the certificate of the internal CA) from
|
|
each L7 load balancer.
|
|
|
|
OpenSearch itself (9200) is not reachable from outside the VM. The Grafana
|
|
server that will read the indexes (`public_grafana_server_cidr` in
|
|
`../variables`) is a separate activity: it will need either a rule here or a
|
|
service on the load balancers.
|
|
|
|
## Names
|
|
|
|
| Name | Type |
|
|
|---|---|
|
|
| `opensearch-dmarc.s2i2s.cloud.isti.cnr.it` | A → `10.10.0.166`, used by the playbooks and by the load balancer |
|
|
| `dmarc.s2i2s.cloud.isti.cnr.it` | CNAME → `main-lb.s2i2s.cloud.isti.cnr.it.` |
|
|
|
|
The public name is served by the L7 load balancers: the `dmarc_reports` entry
|
|
of `haproxy_l7_services` in `group_vars/main_haproxy_l7/main_haproxy_l7.yml` of
|
|
`infrastructure-playbooks`.
|
|
|
|
## Order of the applies
|
|
|
|
```
|
|
main_net_dns_router -> project-setup -> dmarc-reports
|
|
```
|
|
|
|
```bash
|
|
tofu init
|
|
tofu plan -out=dmarc-reports.plan
|
|
tofu apply dmarc-reports.plan
|
|
```
|
|
|
|
Then regenerate the ansible inventory in `infrastructure-playbooks`:
|
|
|
|
```bash
|
|
ansible-playbook tofu-inventory.yml --diff
|
|
```
|