more db ip fix test
This commit is contained in:
@@ -14,14 +14,17 @@ in {
|
|||||||
services.postgresql = {
|
services.postgresql = {
|
||||||
enable = true;
|
enable = true;
|
||||||
enableTCPIP = true; # Required to listen on network interfaces
|
enableTCPIP = true; # Required to listen on network interfaces
|
||||||
authentication = pkgs.lib.mkOverride 10 ''
|
settings = {
|
||||||
# TYPE DATABASE USER ADDRESS METHOD
|
listen_addresses = lib.mkForce "*";
|
||||||
local all all trust
|
};
|
||||||
host all all 127.0.0.1/32 trust
|
# authentication = pkgs.lib.mkOverride 10 ''
|
||||||
host all all 10.0.0.0/8 scram-sha-256
|
# # TYPE DATABASE USER ADDRESS METHOD
|
||||||
host all all 169.254.0.0/16 scram-sha-256
|
# local all all trust
|
||||||
host all all ::1/128 trust
|
# host all all 127.0.0.1/32 trust
|
||||||
'';
|
# host all all 10.0.0.0/8 scram-sha-256
|
||||||
|
# host all all 169.254.0.0/16 scram-sha-256
|
||||||
|
# host all all ::1/128 trust
|
||||||
|
# '';
|
||||||
ensureDatabases = map (name: "${name}_db") allApps;
|
ensureDatabases = map (name: "${name}_db") allApps;
|
||||||
ensureUsers = map (name: { name = "${name}_user"; }) allApps;
|
ensureUsers = map (name: { name = "${name}_user"; }) allApps;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,7 +12,7 @@
|
|||||||
table inet filter {
|
table inet filter {
|
||||||
chain input {
|
chain input {
|
||||||
type filter hook input priority filter; policy accept;
|
type filter hook input priority filter; policy accept;
|
||||||
tcp dport 5432 ip saddr { 10.0.0.0/8 } accept
|
tcp dport 5432 ip saddr { 10.0.0.0/8 169.254.0.0/16 } accept
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
table inet nat {
|
table inet nat {
|
||||||
|
|||||||
Reference in New Issue
Block a user