aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--manifests/vserver.pp20
1 files changed, 10 insertions, 10 deletions
diff --git a/manifests/vserver.pp b/manifests/vserver.pp
index 67ece43..d59bcd6 100644
--- a/manifests/vserver.pp
+++ b/manifests/vserver.pp
@@ -3,16 +3,6 @@ class nodo::vserver inherits nodo {
include timezone
include syslog-ng::vserver
- # SSL computational DoS mitigation
- # See http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html
- $firewall_ssl_ratelimit = $firewall_ssl_ratelimit ? {
- '' => $firewall_global_ssl_ratelimit ? {
- '' => '-',
- default => $firewall_global_ssl_ratelimit,
- },
- default => $firewall_ssl_ratelimit,
- }
-
backupninja::sys { "sys":
ensure => present,
partitions => false,
@@ -130,6 +120,16 @@ class nodo::vserver inherits nodo {
}
}
+ # SSL computational DoS mitigation
+ # See http://vincent.bernat.im/en/blog/2011-ssl-dos-mitigation.html
+ $firewall_ssl_ratelimit = $firewall_ssl_ratelimit ? {
+ '' => $firewall_global_ssl_ratelimit ? {
+ '' => '-',
+ default => $firewall_global_ssl_ratelimit,
+ },
+ default => $firewall_ssl_ratelimit,
+ }
+
# Apply firewall rules just for running vservers
case $ensure {
'running': {