diff --git a/proposals/draft_infrastructure_security_concept.drawio.svg b/proposals/draft_infrastructure_security_concept.drawio.svg new file mode 100644 index 00000000..4051f65f --- /dev/null +++ b/proposals/draft_infrastructure_security_concept.drawio.svg @@ -0,0 +1,833 @@ + + + + + + + + + + +
+
+
+ https/443 +
+ 8140 +
+
+
+
+ + https/443... + +
+
+ + + + + +
+
+
+ 443 +
+ 22 +
+
+
+
+ + 443... + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + + + +
+
+
+ Puppet +
+
+
+
+ + Puppet + +
+
+ + + + + +
+
+
+ https/443 +
+
+
+
+ + https/443 + +
+
+ + + + + + +
+
+
+ YUM Repos +
+
+
+
+ + YUM Repos + +
+
+ + + + + +
+
+
+ tftp +
+ http/80 +
+ https/443 +
+
+
+
+ + tftp... + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + +
+
+
+ - PXE +
+ - Sysdb +
+
+
+
+ + - PXE... + +
+
+ + + + + + + + + +
+
+
+ Git +
+
+
+
+ + Git + +
+
+ + + + + + + + + +
+
+
+ NFS +
+
+
+
+ + NFS + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + + + +
+
+
+ Icinga Master +
+
+
+
+ + Icinga Master + +
+
+ + + + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ Elastic +
+
+
+
+ + Elastic + +
+
+ + + + + +
+
+
+ ???? +
+
+
+
+ + ???? + +
+
+ + + + +
+
+
+ Icinga Satellites +
+
+
+
+ + Icinga Satellites + +
+
+ + + + + +
+
+
+ + nrpe + +
+ + ns-client++ + +
+ + snmp + +
+ + other ports + +
+
+
+
+ + nrpe... + +
+
+ + + + +
+
+
+ agent(s) +
+
+
+
+ + agent(s) + +
+
+ + + + + + + + +
+
+
+ AD +
+
+
+
+ + AD + +
+
+ + + + +
+
+
+ ETH RedHat Satellite +
+
+
+
+ + ETH RedHat Satellite + +
+
+ + + + + +
+
+
+ https +
+
+
+
+ + https + +
+
+ + + + +
+
+
+ Other content provider +
+
+
+
+ + Other content provid... + +
+
+ + + + +
+
+
+ introduction of content scanning +
+
+
+
+ + introduction of content scanning + +
+
+ + + + + +
+
+
+ ... +
+
+
+
+ + ... + +
+
+ + + + +
+
+
+ any supported system in + + ANY + + zone !!!! +
+
+
+
+ + any supported system in... + +
+
+ + + + + + + +
+
+
+ security level +
+
+
+
+ + security l... + +
+
+ + + + + + +
+
+
+ https/443 +
+ 8140 +
+
+
+
+ + https/443... + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + + + + +
+
+
+ https/443 +
+
+
+
+ + https/443 + +
+
+ + + + + + +
+
+
+ (specific) managed Linux machines +
+
+
+
+ + (specific) managed Linux machines + +
+
+ + + + + + +
+
+
+ Icinga Satellite +
+ (DMZ) +
+
+
+
+ + Icinga Satellite... + +
+
+ + + + +
+
+
+ + DMZ + +
+ - DMZ responsible ? +
+ - Periodic reviews +
+
+
+
+ + DMZ... + +
+
+ + + + +
+
+
+
+ - Systems are installed in the DMZ + +
+
+
+
+ + - Firewall rules for specific systems on request - template what ports need to be opened + +
+
+ + - System (will) have static DHCP address + +
+
+
+
+
+
+
+
+ + - Systems are installed in the DMZ... + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ Icinga Satellites +
+
+
+
+ + Icinga Satellites + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ agent(s)/beat(s) +
+
+
+
+ + agent(s)/b... + +
+
+ + + + +
+
+
+ logstash +
+
+
+
+ + logstash + +
+
+ + + + + +
+
+
+ ???? +
+
+
+
+ + ???? + +
+
+ + + + + +
+
+
+ + nrpe + +
+ + ns-client++ + +
+ + snmp + +
+ + other ports + +
+
+
+
+ + nrpe... + +
+
+
+ + + + + Viewer does not support full SVG 1.1 + + + +
\ No newline at end of file diff --git a/proposals/draft_infrastructure_security_concept.md b/proposals/draft_infrastructure_security_concept.md new file mode 100644 index 00000000..047fcd81 --- /dev/null +++ b/proposals/draft_infrastructure_security_concept.md @@ -0,0 +1,3 @@ +# [DRAFT] Core Infrastructure Security Concept + +![](draft_infrastructure_security_concept.drawio.svg) \ No newline at end of file diff --git a/proposals/draft_naming_conventions.md b/proposals/draft_naming_conventions.md index 07476d10..3e8069ab 100644 --- a/proposals/draft_naming_conventions.md +++ b/proposals/draft_naming_conventions.md @@ -1,4 +1,4 @@ -# Naming Conventions Infrastructure Servers +# [DRAFT] Naming Conventions Infrastructure Servers To be able to easily identify all Linux core infrastructure servers they should follow the same naming convention.