Question

Automate Firewall for Private LAN-ish

  • Posted March 11, 2014

I am looking at DO to run a cloud we currently have in AWS VPC, the prices are hard to beat so I am overlooking the fact DO doesn’t have a truly safe private network (only available to a user). However, our cloud uses ZMQ between processing nodes and connects to a Cassandra cluster, which we would all like to have at DO, but none of which is authenticated by default. So I was wondering if DO (or anyone else) has a good way to automate firewall rules across a fleet of droplets. Essentially I would like to use something like SaltStack to automatically propagate new node’s IP addresses and setup the firewall rules only allowing traffic between those, essentially sort of replicating the VPC from AWS here. I’m sure I could do it by hand, but this is just crazy, I want something 100% automated, has this been done by anyone?

Subscribe
Share

Submit an answer
You can type!ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

I think, Digital Ocean is simple cloud hosting, built for developers. You can build your own cloud. <br> <br>“Essentially I would like to use something like SaltStack to automatically propagate new node’s IP addresses and setup the firewall rules only allowing traffic between those…” <br> <br>- Ummm… : <br>http://docs.saltstack.com/en/latest/topics/cloud/digitalocean.html <br> <br>- DO saltstack: <br>https://www.digitalocean.com/community/articles/how-to-install-salt-on-ubuntu-12-04 <br> <br>- Automatic or Manage Infrastructure with Puppet/Chef <br>https://www.digitalocean.com/community/articles/how-to-install-puppet-on-a-digitalocean-vps <br> <br>https://www.digitalocean.com/community/articles/how-to-create-simple-chef-cookbooks-to-manage-infrastructure-on-ubuntu <br> <br>- Puppet Enterprise ?? <br>http://puppetlabs.com/puppet/puppet-enterprise <br> <br>============= <br>Firewall <br>============= <br>- Config Server Firewall (CSF) <br>https://www.digitalocean.com/community/articles/how-to-install-and-configure-config-server-firewall-csf-on-ubuntu <br>* White list all your node IP <br> <br>- Forge firewall with puppet module <br>https://forge.puppetlabs.com/puppetlabs/firewall <br> <br>=========== <br>Migration <br>=========== <br>- Transitioning from Amazon EC2 to DigitalOcean’s Control Panel <br>https://www.digitalocean.com/community/articles/transitioning-from-amazon-ec2-to-digitalocean-s-control-panel <br> <br>“Essentially I would like to use something like SaltStack to automatically propagate new node’s IP addresses…” <br> <br>https://www.digitalocean.com/community/questions/can-i-get-additional-ip-addresses-for-a-droplet <br> <br>… <br>Moisey say: <br> <br>“We currently don’t support multiple IP addresses for the same droplet, but if you give us some more info on what you’re looking to setup we may be able to recommend a solution where we can work around the restriction of 1 IP per droplet.” <br>… <br> <br>End: <br>Click support ticket.