Forge Home

knockd

Knockd Module

460 downloads

460 latest version

5.0 quality score

We run a couple of automated
scans to help you access a
module's quality. Each module is
given a score based on how well
the author has formatted their
code and documentation and
modules are also checked for
malware using VirusTotal.

Please note, the information below
is for guidance only and neither of
these methods should be considered
an endorsement by Puppet.

Version information

  • 1.0.1 (latest)
released Jun 16th 2022
This version is compatible with:
  • Puppet Enterprise 2023.2.x, 2023.1.x, 2023.0.x, 2021.7.x, 2021.6.x, 2021.5.x, 2021.4.x, 2021.3.x, 2021.2.x, 2021.1.x, 2021.0.x, 2019.8.x
  • Puppet >= 6.21.0 < 8.0.0

Start using this module

  • r10k or Code Manager
  • Bolt
  • Manual installation
  • Direct download

Add this module to your Puppetfile:

mod 'puppetfinland-knockd', '1.0.1'
Learn more about managing modules with a Puppetfile

Add this module to your Bolt project:

bolt module add puppetfinland-knockd
Learn more about using this module with an existing project

Manually install this module globally with Puppet module tool:

puppet module install puppetfinland-knockd --version 1.0.1

Direct download is not typically how you would use a Puppet module to manage your infrastructure, but you may want to download the module in order to inspect the code.

Download

Documentation

puppetfinland/knockd — version 1.0.1 Jun 16th 2022

puppet-knockd

This module manages knockd.

Examples

Open SSH port to any IP that provides the correct knock sequence, then close it automatically after 30 seconds:

class { 'knockd':
  interface => $facts['networking']['primary'],
}

knockd::sequence { 'openCloseSSH':
  sequence      => '2222,3333,4444',
  seq_timeout   => 15,
  start_command => '/sbin/iptables -A INPUT -s %IP% -p tcp --dport ssh -j ACCEPT',
  cmd_timeout   => 30,
  stop_command  => '/sbin/iptables -D INPUT -s %IP% -p tcp --dport ssh -j ACCEPT',
}

The stop_command is not mandatory, but required for automatic cleanup. See class documentation for additional options. Use two knockd::sequence resources without a stop_command if you want one sequence to open a port, and another one to close a port.

Copyright

  • Copyright 2015 Alessio Cassibba (X-Drum), unless otherwise noted.
  • Copyright 2022 OpenVPN Inc.