Disks and firewall
Add storage that moves between servers, and open or close ports, from the command line.
Disks
A disk is extra storage with its own prepaid term. It keeps its data when it is detached or its server ends, and can move to another server in the same zone. See Disks for prices and rules.
layerbeat volume prices --region sgp # public prices, no sign-in
layerbeat volume options --region sgp # sizes, steps, terms and zones
layerbeat volume new data --server agent-01 --size 50 --max-price 5 --waitBuying or renewing a disk asks for a yes in a terminal; scripts add --yes.
With --server the disk is created in that server's zone, attached and mounted at /mnt/data (Windows: C:\mnt\data). Without a server, give --region and --zone to buy an unattached disk.
layerbeat volume ls
layerbeat volume get data
layerbeat volume detach data --wait # unmounts first; data is kept
layerbeat volume attach data agent-02 --wait # same zone only
layerbeat volume rename data postgres-data
layerbeat volume renew data --term 3 --max-price 15
layerbeat volume rm data --confirm data # deletes the disk and its data
layerbeat volume system-disks # each server's own disk, included in its priceFirewall
Each server has its own firewall in front of it. New servers start with the usual rules for SSH, web traffic and ping; layerbeat fw ls shows exactly what is open.
layerbeat fw ls agent-01
layerbeat fw add agent-01 --port 8080
layerbeat fw add agent-01 --port 5432 --cidr 203.0.113.7/32 --description "office"
layerbeat fw add agent-01 --port 3000-3100 --protocol udp
layerbeat fw rm agent-01 fw_...| Flag | Default | Meaning |
|---|---|---|
--port | A port or range, for example 443 or 8000-8100 (not for icmp) | |
--protocol | tcp | tcp, udp, icmp or all |
--cidr | 0.0.0.0/0 | Who may connect |
--action | accept | accept or drop |
See Networking.