openstack-infrastructure-te.../s2i2s/dmarc-reports/README.md

2.0 KiB

DMARC reports service of the S2I2S project

One VM, m1.large (RAM 8 - VCPUs 4), Ubuntu 24.04, 20 GB of root disk, on the main private network only (10.10.0.166), and one 50 GB SSD volume (CephSSD, enable_online_resize) on /dev/vdb, for the OpenSearch indexes.

It runs parsedmarc, OpenSearch and OpenSearch Dashboards. parsedmarc reads the aggregate and failure reports sent to dmarc-reports@isti.cnr.it (the rua and ruf of _dmarc.isti.cnr.it) over IMAP, through the router of the project: no floating IP.

The resources live in ../../modules/dmarc_reports, which carries the sizing and the service port as defaults. Only the address on the main private network, from the address plan in ../variables (basic_services_ip.dmarc_reports), and the IDs read from the other workspaces are set in main.tf.

Security groups on the port:

  • default_for_all;
  • traffic_to_dmarc_reports_from_the_main_load_balancers: 5601 (OpenSearch Dashboards, TLS with the certificate of the internal CA) from each L7 load balancer.

OpenSearch itself (9200) is not reachable from outside the VM. The Grafana server that will read the indexes (public_grafana_server_cidr in ../variables) is a separate activity: it will need either a rule here or a service on the load balancers.

Names

Name Type
opensearch-dmarc.s2i2s.cloud.isti.cnr.it A → 10.10.0.166, used by the playbooks and by the load balancer
dmarc.s2i2s.cloud.isti.cnr.it CNAME → main-lb.s2i2s.cloud.isti.cnr.it.

The public name is served by the L7 load balancers: the dmarc_reports entry of haproxy_l7_services in group_vars/main_haproxy_l7/main_haproxy_l7.yml of infrastructure-playbooks.

Order of the applies

main_net_dns_router  ->  project-setup  ->  dmarc-reports
tofu init
tofu plan -out=dmarc-reports.plan
tofu apply dmarc-reports.plan

Then regenerate the ansible inventory in infrastructure-playbooks:

ansible-playbook tofu-inventory.yml --diff