lucatelli: decomission
[mirror/dsa-nagios.git] / config / nagios-master.cfg
index 5d39a5a..092416a 100644 (file)
@@ -46,7 +46,7 @@ servers:
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-cecsit:
-    address: 150.203.164.38
+    address: 150.203.164.1
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-arm:
@@ -57,10 +57,6 @@ servers:
     address: 138.16.160.1
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
-  gw-carnet:
-    address: 161.53.160.1
-    parents: gw-ubcece
-    hostgroups: layer3-infrastructure
   gw-conova:
     address: 217.196.149.238
     parents: gw-ubcece
@@ -105,6 +101,10 @@ servers:
     address: 82.195.75.126
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-man-da2:
+    address: 82.195.78.116
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-marist:
     address: 148.100.88.1
     parents: gw-ubcece
@@ -142,16 +142,12 @@ servers:
     address: 206.12.19.254
     hostgroups: layer3-infrastructure
     contacts: lfilipoz
-  gw-ugent:
-    address: 193.191.17.50
-    parents: gw-ubcece
-    hostgroups: layer3-infrastructure
   gw-umn:
     address: 128.101.240.222
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-unicamp:
-    address: 177.220.10.65
+    address: 177.220.10.129
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-utwente:
@@ -230,6 +226,10 @@ servers:
     address: 141.170.6.155
     parents: gw-aql
     hostgroups: computers, buildd, jessie, nfs-client
+  mips-aql-06:
+    address: 141.170.6.157
+    parents: gw-aql
+    hostgroups: computers, buildd, jessie, hassrvfs
   minkus:
     address: 141.170.6.151
     parents: gw-aql
@@ -242,6 +242,10 @@ servers:
     address: 141.170.6.153
     parents: gw-aql
     hostgroups: computers, buildd, jessie, hassrvfs, hasbootfs, sw-raid
+  mipsel-aql-03:
+    address: 141.170.6.158
+    parents: gw-aql
+    hostgroups: computers, buildd, jessie, hassrvfs
   # }}}
   # {{{ gw-arm
   abel:
@@ -255,15 +259,15 @@ servers:
   arm-arm-01:
     address: 217.140.96.58
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
-  arm-arm-02:
-    address: 217.140.96.59
-    parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+    hostgroups: computers, hassrvfs, buildd, jessie, broken_mq
   arm-arm-03:
     address: 217.140.96.60
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+    hostgroups: computers, hassrvfs, buildd, jessie, broken_mq
+  arm-arm-04:
+    address: 217.140.96.61
+    parents: gw-arm
+    hostgroups: computers, hassrvfs, buildd, jessie, broken_mq
   harris:
     address: 217.140.96.66
     parents: gw-arm
@@ -276,71 +280,79 @@ servers:
     address: 217.140.96.71
     parents: gw-arm
     hostgroups: computers, hasbootfs, hassrvfs, armhf, jessie, buildd, broken_mq
-  ia64-arm-01:
-    address: 217.140.96.61
-    parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, wheezy, buildd, broken_mq, sw-raid, acpid-hosts
   # }}}
   # {{{ gw-brown
   franck:
     address: 138.16.160.12
     parents: gw-brown
     hostgroups: computers, service, apache2-hosts, dl380, rsyncd-hosts, postgres94-hosts, uploadqueue, xinetd-hosts, apache-https, hassrvfs, jessie
+  fasolo:
+    address: 138.16.160.17
+    parents: gw-brown
+    hostgroups: computers, service, dl380, hpnewraid, jessie
   # }}}
   # {{{ gw-bytemark
   bm-bl1:
     address: 5.153.231.241
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl2:
     address: 5.153.231.242
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl3:
     address: 5.153.231.243
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl4:
     address: 5.153.231.244
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl5:
     address: 5.153.231.245
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl6:
     address: 5.153.231.246
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl7:
     address: 5.153.231.247
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl8:
     address: 5.153.231.248
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, service, jessie
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl9:
     address: 5.153.231.249
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl10:
     address: 5.153.231.250
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl11:
     address: 5.153.231.251
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
   bm-bl12:
     address: 5.153.231.252
     parents: gw-bytemark
-    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
+  bm-bl13:
+    address: 5.153.231.253
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
+  bm-bl14:
+    address: 5.153.231.254
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, service, jessie, multipath-hosts
 
   milanollo:
     address: 5.153.231.2
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, nfs-server, xinetd-hosts
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, apache-https, nfs-server, xinetd-hosts
   milanollo2:
     address: 5.153.231.9
     parents: milanollo
@@ -352,7 +364,7 @@ servers:
   senfter:
     address: 5.153.231.4
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, no-bacula, apache-https
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, no-bacula, apache-https, nfs-server
   adayevskaya:
     address: 5.153.231.5
     parents: gw-bytemark
@@ -390,7 +402,7 @@ servers:
   philp:
     address: 5.153.231.13
     parents: ganeti-bytemark
-    hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts
+    hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, apache-https
   rainier:
     address: 5.153.231.16
     parents: ganeti-bytemark
@@ -402,7 +414,7 @@ servers:
   delfin:
     address: 5.153.231.17
     parents: ganeti-bytemark
-    hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, nfs-client, autofs
+    hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, apache-https, nfs-client, autofs
   wuiet:
     address: 5.153.231.18
     parents: ganeti-bytemark
@@ -432,7 +444,7 @@ servers:
   petrova:
     address: 5.153.231.25
     parents: ganeti-bytemark
-    hostgroups: computers, kvmdomains, jessie, apache2-hosts
+    hostgroups: computers, kvmdomains, jessie, apache2-hosts, apache-https
   oyens:
     address: 5.153.231.26
     parents: ganeti-bytemark
@@ -445,10 +457,10 @@ servers:
     address: 5.153.231.28
     parents: ganeti-bytemark
     hostgroups: computers, service, kvmdomains, jessie, hassrvfs, nfs-client, xinetd-hosts, heavy-exim, apache2-hosts, autofs, apache-https
-  portman:
+  respighi:
     address: 5.153.231.29
     parents: ganeti-bytemark
-    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, nfs-client, autofs
   paradis:
     address: 5.153.231.30
     parents: ganeti-bytemark
@@ -457,6 +469,10 @@ servers:
     address: 5.153.231.32
     parents: ganeti-bytemark
     hostgroups: computers, kvmdomains, jessie, no-bacula
+  tate:
+    address: 5.153.231.33
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, jessie, autofs, nfs-client, apache2-hosts, apache-https
   gideon:
     address: 5.153.231.34
     parents: ganeti-bytemark
@@ -464,7 +480,7 @@ servers:
   httpredir-bm-01:
     address: 5.153.231.35
     parents: ganeti-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, hassrvfs
   lindsay:
     address: 5.153.231.36
     parents: ganeti-bytemark
@@ -484,10 +500,6 @@ servers:
     address: 5.153.231.40
     parents: ganeti-bytemark
     hostgroups: computers, service, kvmdomains, jessie, hassrvfs, nfs-client, autofs
-  pittar:
-    address: 5.153.231.41
-    parents: ganeti-bytemark
-    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, nfs-client, autofs #, apache2-hosts
   pinel:
     address: 5.153.231.42
     parents: ganeti-bytemark
@@ -496,6 +508,10 @@ servers:
     address: 5.153.231.43
     parents: ganeti-bytemark
     hostgroups: computers, service, kvmdomains, jessie, hassrvfs
+  manziarly:
+    address: 5.153.231.44
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, jessie, autofs, nfs-client, apache2-hosts, apache-https
   # }}}
   # {{{ gw-c3sl
   santoro:
@@ -504,16 +520,6 @@ servers:
     hostgroups: computers, service, apache2-hosts, rsyncd-hosts, xinetd-hosts, hassrvfs, jessie, high-RTT, security_mirror, no-bacula, apache-https
     contacts: faw
   # }}}
-  # {{{ gw-carnet
-  lebrun:
-    address: 193.198.184.10
-    parents: gw-carnet
-    hostgroups: computers, buildd, sw-raid, hasorgfs, sparc, wheezy
-  schroeder:
-    address: 193.198.184.11
-    parents: gw-carnet
-    hostgroups: computers, buildd, sw-raid, hassrvfs, sparc, wheezy
-  # }}}
   # {{{ gw-cecsit
   gluck:
     address: 150.203.164.38
@@ -522,7 +528,19 @@ servers:
   mirror-anu:
     address: 150.203.164.39
     parents: gw-cecsit
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl360, hassrvfs, xinetd-hosts, jessie, security_mirror, no-bacula, apache-https
+    hostgroups: computers, service, apache2-hosts, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror, apache-https
+  mirror-anu2:
+    address: 150.203.164.60
+    parents: mirror-anu
+    hostgroups: secondary-IPs
+  mirror-anu3:
+    address: 150.203.164.61
+    parents: mirror-anu
+    hostgroups: secondary-IPs
+  mirror-anu4:
+    address: 150.203.164.62
+    parents: mirror-anu
+    hostgroups: secondary-IPs
   # }}}
   # {{{ gw-conova
   sompek:
@@ -635,6 +653,14 @@ servers:
     address: 194.177.211.205
     parents: ganeti-grnet
     hostgroups: computers, service, hassrvfs, kvmdomains, jessie, postgres94-hosts, apache2-hosts, apache-https
+  boott:
+    address: 194.177.211.206
+    parents: ganeti-grnet
+    hostgroups: computers, service, hassrvfs, kvmdomains, jessie
+  porta:
+    address: 194.177.211.207
+    parents: ganeti-grnet
+    hostgroups: computers, service, hassrvfs, kvmdomains, jessie, rsyncd-hosts, xinetd-hosts
   # }}}
   # {{{ gw-isc
   schein:
@@ -644,7 +670,19 @@ servers:
   mirror-isc:
     address: 149.20.20.7
     parents: gw-isc
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl360, hassrvfs, xinetd-hosts, jessie, security_mirror, no-bacula
+    hostgroups: computers, service, apache2-hosts, apache-https, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror
+  mirror-isc2:
+    address: 149.20.20.19
+    parents: mirror-isc
+    hostgroups: secondary-IPs
+  mirror-isc3:
+    address: 149.20.20.22
+    parents: mirror-isc
+    hostgroups: secondary-IPs
+  mirror-isc-syncproxy:
+    address: 149.20.20.21
+    parents: mirror-isc
+    hostgroups: secondary-IPs
   # }}}
   # {{{ gw-leaseweb
   lw01:
@@ -697,11 +735,11 @@ servers:
   czerny:
     address: 82.195.75.109
     parents: gw-man-da
-    hostgroups: computers, service, dl380, acpid-hosts, wheezy, drbd-hosts
+    hostgroups: computers, service, dl380, acpid-hosts, jessie, drbd-hosts
   clementi:
     address: 82.195.75.103
     parents: gw-man-da
-    hostgroups: computers, service, dl380, acpid-hosts, wheezy, drbd-hosts
+    hostgroups: computers, service, dl380, acpid-hosts, jessie, drbd-hosts
   bendel:
     address: 82.195.75.100
     parents: ganeti3
@@ -731,7 +769,7 @@ servers:
   draghi:
     address: 82.195.75.106
     parents: ganeti3
-    hostgroups: computers, service, hasbootfs, hassrvfs, apache2-hosts, spamd, heavy-exim, kvmdomains, xinetd-hosts, apache-https, wheezy
+    hostgroups: computers, service, hasbootfs, hassrvfs, apache2-hosts, spamd, heavy-exim, kvmdomains, xinetd-hosts, apache-https, jessie
   geo1:
     address: 82.195.75.105
     parents: ganeti3
@@ -743,7 +781,7 @@ servers:
   kaufmann:
     address: 82.195.75.107
     parents: ganeti3
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, kvmdomains, xinetd-hosts, jessie
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, kvmdomains, xinetd-hosts, jessie, apache-https
   stockhausen:
     address: 82.195.75.108
     parents: ganeti3
@@ -771,7 +809,11 @@ servers:
   wolkenstein:
     address: 82.195.75.65
     parents: ganeti3
-    hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, rsyncd-hosts, apache2-hosts, jessie
+    hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, apache2-hosts, jessie, apache-https
+  mips-manda-01:
+    address: 82.195.75.66
+    parents: gw-man-da
+    hostgroups: computers, buildd, jessie, hassrvfs
   mipsel-manda-01:
     address: 82.195.75.72
     parents: gw-man-da
@@ -780,6 +822,10 @@ servers:
     address: 82.195.75.74
     parents: gw-man-da
     hostgroups: computers, buildd, jessie, hassrvfs, sw-raid, hasbootfs
+  mipsel-manda-03:
+    address: 82.195.75.67
+    parents: gw-man-da
+    hostgroups: computers, buildd, jessie, hassrvfs
   seger:
     address: 82.195.75.93
     parents: ganeti3
@@ -796,14 +842,16 @@ servers:
     address: 140.211.15.34
     parents: gw-osuosl
     hostgroups: computers, service, dl360, hassrvfs, jessie, hasvarlogfs, apache2-hosts, no-bacula, apache-https
+
   byrd:
-    address: 140.211.166.20
+    address: 140.211.166.200
     parents: gw-osuosl
     hostgroups: computers, service, dl380, jessie
-  buxtehude:
-    address: 140.211.166.26
+  beach:
+    address: 140.211.166.201
     parents: byrd
-    hostgroups: computers, service, hassrvfs, apache2-hosts, heavy-exim, postgres94-hosts, jessie, hasvarlogfs, apache-https, spamd
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, xinetd-hosts, hassrvfs, rsyncd-hosts, apache-https
+
   pieta:
     address: 140.211.166.195
     parents: gw-osuosl
@@ -820,23 +868,10 @@ servers:
     address: 140.211.166.198
     parents: pieta
     hostgroups: computers, jessie, hassrvfs, porterbox
-  merulo:
-    address: 140.211.166.46
-    parents: gw-osuosl
-    hostgroups: computers, porterbox, hasusrfs, wheezy
   partch:
     address: 140.211.15.152
     parents: gw-osuosl
     hostgroups: computers, jessie, hassrvfs, porterbox, sw-raid
-  rietz:
-    address: 140.211.166.43
-    parents: gw-osuosl
-    hostgroups: computers, service, rsyncd-hosts, dl385, hassrvfs, xinetd-hosts, jessie
-    #, bosserver
-  rietz2:
-    address: 140.211.166.44
-    parents: rietz
-    hostgroups: secondary-IPs
   # }}}
   # {{{ gs-rapidswitch
   caballero:
@@ -848,12 +883,12 @@ servers:
   sibelius:
     address: 193.62.202.28
     parents: gw-sanger
-    hostgroups: computers, postgres94-hosts, service, apache2-hosts, sw-raid, jessie, rsyncd-hosts, xinetd-hosts, hasvarlogfs
+    hostgroups: computers, postgres94-hosts, service, apache2-hosts, sw-raid, jessie, rsyncd-hosts, xinetd-hosts, hasvarlogfs, multipath-hosts
     contacts: tjrc1, dave
   smetana:
     address: 193.62.202.29
     parents: gw-sanger
-    hostgroups: computers, porterbox, sw-raid, sparc, wheezy
+    hostgroups: computers, sw-raid, sparc, wheezy, no-bacula
     contacts: tjrc1, dave
   # }}}
   # {{{ gw-scanplus
@@ -871,6 +906,14 @@ servers:
     address: 86.59.118.155
     parents: gw-sil
     hostgroups: computers, buildd, jessie, sw-raid
+  mips-sil-01:
+    address: 86.59.118.146
+    parents: gw-sil
+    hostgroups: computers, buildd, jessie, hassrvfs
+  mipsel-sil-01:
+    address: 86.59.118.147
+    parents: gw-sil
+    hostgroups: computers, buildd, jessie, hassrvfs
   # }}}
   # {{{ gw-ubcece
   sw-ubcece:
@@ -898,27 +941,27 @@ servers:
   ubc-bl7:
     address: 206.12.19.217
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ubc-bl6:
     address: 206.12.19.216
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ubc-bl2:
     address: 206.12.19.212
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ubc-bl3:
     address: 206.12.19.213
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ubc-bl4:
     address: 206.12.19.214
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ubc-bl8:
     address: 206.12.19.218
     parents: sw-ubcece-kais
-    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts
+    hostgroups: computers, bl460, acpid-hosts, service, jessie, drbd-hosts, multipath-hosts
   ganeti2:
     address: 206.12.19.23
     parents: sw-ubcece-kais
@@ -949,14 +992,6 @@ servers:
     parents: ganeti2
     hostgroups: computers, freebsd, jessie, buildd, hassrvfs
     contacts: christoph
-  lucatelli:
-    address: 206.12.19.15
-    parents: sw-ubcece-kais
-    hostgroups: computers, buildd, jessie
-  traetta:
-    address: 206.12.19.21
-    parents: sw-ubcece-kais
-    hostgroups: computers, dl585, service, jessie
 #  locke:
 #    address: 206.12.19.120
 #    parents: sw-ubcece-kais
@@ -980,11 +1015,11 @@ servers:
   glinka:
     address: 206.12.19.126
     parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, xinetd-hosts
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, apache-https, nfs-client, autofs, xinetd-hosts
   tye:
     address: 206.12.19.129
     parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, apache2-hosts, nfs-client, autofs, hassrvfs
+    hostgroups: computers, service, kvmdomains, jessie, heavy-exim, apache2-hosts, apache-https, nfs-client, autofs, hassrvfs
   elgar:
     address: 206.12.19.130
     parents: ganeti2
@@ -1001,14 +1036,6 @@ servers:
     address: 206.12.19.136
     parents: ganeti2
     hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, apache-https, broken_https_default_vhost
-  bizet:
-    address: 206.12.19.137
-    parents: ganeti2
-    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, no-bacula
-  beach:
-    address: 206.12.19.140
-    parents: ganeti2
-    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, xinetd-hosts, hassrvfs, nfs-server, rsyncd-hosts, no-bacula, apache-https
   ullmann:
     address: 206.12.19.141
     parents: ganeti2
@@ -1016,7 +1043,7 @@ servers:
   sonntag:
     address: 206.12.19.142
     parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, nfs-client, autofs
+    hostgroups: computers, service, kvmdomains, jessie, nfs-client, autofs
   menotti:
     address: 206.12.19.143
     parents: ganeti2
@@ -1025,8 +1052,10 @@ servers:
     address: 206.12.19.146
     parents: ganeti2
     hostgroups: computers, service, kvmdomains, jessie, spamd, heavy-exim, mail-relay
-  # }}}
-  # {{{ gw-ugent
+  buxtehude:
+    address: 206.12.19.147
+    parents: ganeti2
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts, heavy-exim, postgres94-hosts, hasvarlogfs, apache-https, spamd, nfs-server
   # }}}
   # {{{ gw-umn
   #saens:
@@ -1036,23 +1065,35 @@ servers:
   mirror-umn:
     address: 128.101.240.212
     parents: gw-umn
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl360, hassrvfs, xinetd-hosts, jessie, security_mirror
+    hostgroups: computers, service, apache2-hosts, apache-https, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror
+  mirror-umn2:
+    address: 128.101.240.215
+    parents: mirror-umn
+    hostgroups: secondary-IPs
+  mirror-umn3:
+    address: 128.101.240.216
+    parents: mirror-umn
+    hostgroups: secondary-IPs
+  mirror-umn4:
+    address: 128.101.240.217
+    parents: mirror-umn
+    hostgroups: secondary-IPs
   # }}}
   # {{{ gw-unicamp
   prokofiev:
-    address: 177.220.10.78
+    address: 177.220.10.140
     parents: gw-unicamp
     hostgroups: computers, jessie, service
   powerpc-unicamp-01:
-    address: 177.220.10.79
+    address: 177.220.10.141
     parents: prokofiev
     hostgroups: computers, hassrvfs, buildd, jessie
   ppc64el-unicamp-01:
-    address: 177.220.10.80
+    address: 177.220.10.142
     parents: prokofiev
     hostgroups: computers, hassrvfs, buildd, jessie
   plummer:
-    address: 177.220.10.81
+    address: 177.220.10.143
     parents: prokofiev
     hostgroups: computers, porterbox, hassrvfs, jessie
   # }}}
@@ -1060,7 +1101,7 @@ servers:
   klecker:
     address: 130.89.148.10
     parents: gw-utwente
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl380, xinetd-hosts, jessie, incomingmailrelayed2025, hassrvfs
+    hostgroups: computers, service, apache2-hosts, apache-https, rsyncd-hosts, dl380, xinetd-hosts, jessie, incomingmailrelayed2025, hassrvfs
   klecker-ftp:
     address: 130.89.148.12
     parents: klecker
@@ -1164,12 +1205,12 @@ hostgroups:
   general:
     alias: general purpose developer accessible machines
 
+  hpnewraid:
+    alias: new (2015+) machines where we need hpssacli instead of hpacucli
+    private: 1
   dl380:
     alias: HP DL380 hosts
     private: 1
-  dl385:
-    alias: HP DL385 hosts
-    private: 1
   dl360:
     alias: HP DL360 hosts
     private: 1
@@ -1179,9 +1220,6 @@ hostgroups:
   bm-bl:
     alias: HP blades at bytemark
     private: 1
-  dl585:
-    alias: HP DL385 hosts
-    private: 1
   dl180:
     alias: HP DL180
     private: 1
@@ -1211,6 +1249,8 @@ hostgroups:
 
   drbd-hosts:
     alias: hosts running drbd
+  multipath-hosts:
+    alias: hosts running multipathd
   postfix-hosts:
     alias: hosts running postfix instead of exim
     private: 1
@@ -1301,9 +1341,6 @@ hostgroups:
   hasvarlogfs:
     alias: hosts with a /var/log filesystem
     private: 1
-  hasusrfs:
-    alias: hosts with a /usr filesystem
-    private: 1
 
   incomingmailrelayed:
     alias: incoming mail needs to go through a mail relay
@@ -1323,9 +1360,9 @@ hostgroups:
   alioth:
     alias: machines that just are just awkward
     private: 1
-  openstack-compute:
-    alias: nodes that run OpenStack compute
-    private: 1
+  #openstack-compute:
+  #  alias: nodes that run OpenStack compute
+  #  private: 1
   openstack-controller:
     alias: nodes that run OpenStack controller
     private: 1
@@ -1359,6 +1396,8 @@ servicegroups:
   security:
     alias: security
     servicegroup_members: apt, kernel, samhain
+  mirror:
+    alias: mirror stuff
   MQ:
     alias: rabbitMQ stuff
 # }}}
@@ -1370,21 +1409,21 @@ services:
     check: "check_ping!350.0,20%!600.0,40%"
     hostgroups: pingable
     excludehostgroups: layer3-infrastructure, high-RTT
-    normal_check_interval: 5
+    check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
   -
     name: PING
     check: "check_ping!600.0,20%!900.0,40%"
     hostgroups: high-RTT
-    normal_check_interval: 5
+    check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
   -
     name: PING
     check: "check_ping!2000.0,60%!3000.0,80%"
     hostgroups: layer3-infrastructure
-    normal_check_interval: 5
+    check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
   # }}}
@@ -1421,11 +1460,6 @@ services:
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 95 98 /srv"
     hostgroups: hassrvfs
-  -
-    name: disk usage on /usr
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /usr"
-    hostgroups: hasusrfs
   -
     name: disk usage on /var/lib/postgresql
     servicegroups: diskspace
@@ -1513,13 +1547,13 @@ services:
     name: setup - dsa config
     nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
     hostgroups: computers
-    normal_check_interval: 60
+    check_interval: 60
     excludehostgroups: alioth
   -
     name: setup - local hostname etc-hosts
     nrpe: 'if getent ahosts `hostname` | grep -q 127.0; then echo "Warning: local hostname resolves to 127/8 address"; exit 1; else echo "OK: Hostname resolves to non-127/8 address."; exit 0; fi'
     hostgroups: computers
-    normal_check_interval: 60
+    check_interval: 60
   # }}}
   # {{{ os health
   ####
@@ -1586,7 +1620,7 @@ services:
   -
     name: system - filesystem check
     nrpe: "/usr/bin/sudo /usr/lib/nagios/plugins/dsa-check-filesystems"
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
     hostgroups: computers
   # }}}
@@ -1596,8 +1630,8 @@ services:
     servicegroups: backup
     nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup"
     hostgroups: computers
-    excludehosts: backuphost, storace, backuphost
-    normal_check_interval: 60
+    excludehosts: backuphost, storace
+    check_interval: 60
     max_check_attempts: 2
     retry_check_interval: 5
   -
@@ -1605,7 +1639,7 @@ services:
     servicegroups: backup
     nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server"
     hosts: storace
-    normal_check_interval: 60
+    check_interval: 60
     max_check_attempts: 2
     retry_check_interval: 5
   -
@@ -1615,7 +1649,7 @@ services:
     runfrom: dinis
     hostgroups: computers
     excludehostgroups: buildd, porterbox, no-bacula
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
   -
     name: backup - bacula - last full backup
@@ -1624,8 +1658,13 @@ services:
     runfrom: dinis
     hostgroups: computers
     excludehostgroups: buildd, porterbox, no-bacula
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
+  -
+    name: process - bacula-dir
+    servicegroups: backup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u bacula -C bacula-dir -a '/usr/sbin/bacula-dir -c /etc/bacula/bacula-dir.conf'"
+    hosts: dinis
   -
     name: process - bacula-fd
     servicegroups: backup
@@ -1650,14 +1689,14 @@ services:
     servicegroups: kernel
     nrpe: "/usr/lib/nagios/plugins/dsa-check-running-kernel"
     hostgroups: computers
-    normal_check_interval: 60
+    check_interval: 60
     retry_check_interval: 5
   -
     name: apt - security updates
     servicegroups: apt
     nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/apt"
     hostgroups: computers
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
   -
     name: unexpected file - apt sources.list
@@ -1671,7 +1710,7 @@ services:
     #nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-libs"
     hostgroups: computers
     excludehostgroups: freebsd
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
     notification_interval: 10080
   -
@@ -1710,7 +1749,7 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/samhain"
     hostgroups: computers
     depends: process - samhain
-    normal_check_interval: 60
+    check_interval: 60
     retry_check_interval: 5
     excludehostgroups: brokensamhain
   -
@@ -1765,7 +1804,7 @@ services:
     check: dsa_check_ssh
     hostgroups: computers
     depends: process - sshd
-    normal_check_interval:  60
+    check_interval:  60
     notification_interval: 1440
   ####
   -
@@ -1783,18 +1822,13 @@ services:
   ###
   -
     name: process - munin-node
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a '/usr/sbin/munin-node'"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a 'munin-node'"
     hostgroups: computers
-    excludehostgroups: freebsd, armhf
+    excludehostgroups: freebsd
   -
     name: process - munin-node
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C perl -a '/usr/bin/perl -wT /usr/sbin/munin-node'"
     hostgroups: freebsd
-  -
-    name: process - munin-node
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a 'munin-node'"
-    hostgroups: wheezy, jessie
-    excludehostgroups: freebsd
   -
     name: network service - munin-node
     check: check_tcp!4949
@@ -1845,7 +1879,7 @@ services:
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-mq-connection $HOSTNAME$ ud dsa"
     runfrom: rainier
     hostgroups: computers
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
     excludehostgroups: alioth, broken_mq
   -
@@ -1854,7 +1888,7 @@ services:
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-mq-connection $HOSTNAME$ ud dsa"
     runfrom: rapoport
     hostgroups: computers
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
     excludehostgroups: alioth, broken_mq
   ###
@@ -1862,7 +1896,7 @@ services:
     name: local resolver
     nrpe: "/usr/lib/nagios/plugins/dsa-check-resolver www.debian.org www.google.com"
     hostgroups: computers
-    normal_check_interval: 60
+    check_interval: 60
   -
     name: process - unbound
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u unbound -C unbound -a '/usr/sbin/unbound'"
@@ -1921,6 +1955,11 @@ services:
     hostgroups: computers
     excludehostgroups: freebsd, alioth
     excludehosts: czerny, grnet-node01, storace, ubc-bl2
+  ###
+  -
+    name: process - rngd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rngd -a '/usr/sbin/rngd -r /dev/hwrng'"
+    hostgroups: kvmdomains
   # }}}
   # {{{ anti-services
   -
@@ -1935,7 +1974,7 @@ services:
     name: unwanted process - openvpn
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C openvpn"
     hostgroups: computers
-    normal_check_interval: 120
+    check_interval: 120
   -
     name: unwanted process - gkrellmd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C gkrellmd"
@@ -1972,6 +2011,16 @@ services:
     name: "sso CRL"
     nrpe: "if [ -e /var/lib/dsa/sso/ca.crl ]; then /usr/lib/nagios/plugins/dsa-check-crl-expire -w 129600 -c 86400 /var/lib/dsa/sso/ca.crl; else echo 'No sso/ca.crl on this host.'; fi"
     hostgroups: computers
+  -
+    name: SSL certs - puppet
+    hosts: global
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-cert-expire-dir /etc/puppet/modules/ssl/files/servicecerts"
+    runfrom: handel
+  -
+    name: SSL certs - LE
+    hosts: global
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-cert-expire-dir /etc/puppet/modules/ssl/files/from-letsencrypt"
+    runfrom: handel
   # }}}
   # {{{ HW health/raid
   -
@@ -2002,76 +2051,71 @@ services:
     name: HW - hpacucli status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli"
-    normal_check_interval: 120
-    hostgroups: dl385, dl380, dl360, bl460, dl180
-    excludehosts: schein, rietz, mirror-anu, mirror-isc, mirror-umn
+    check_interval: 120
+    hostgroups: dl380, dl360, bl460, dl180
+    excludehosts: schein
+    excludehostgroups: hpnewraid
   -
     name: HW - hpacucli status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli --no-controller-ok --ignore-controller='P700m'"
-    normal_check_interval: 120
+    check_interval: 120
     hostgroups: bm-bl
   -
     name: HW - hpacucli status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli --no-battery"
-    normal_check_interval: 120
-    hosts: schein, rietz
+    check_interval: 120
+    hosts: schein
   -
     name: HW - hpacucli enclosure status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli-enclosure 1 1E:1"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: franck
-  -
-    name: HW - hpacucli status
-    servicegroups: raid
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli --ignore-transfer-speed=1I:1:1 --ignore-transfer-speed=1I:1:2"
-    normal_check_interval: 120
-    hostgroups: dl585
   -
     name: HW - hpssacli status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpssacli"
-    normal_check_interval: 120
-    hosts: mirror-anu, mirror-isc, mirror-umn
+    check_interval: 120
+    hostgroups: hpnewraid
   ###
 #  -
 #    name: HW - edac status
 #    nrpe: "/usr/lib/nagios/plugins/dsa-check-edac"
-#    normal_check_interval: 120
+#    check_interval: 120
     #hostgroups: computers
     #excludehosts: villa, lobos, schein
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm"
-    normal_check_interval: 120
-    hostgroups: dl385, dl380, dl360, bl460, dl585, bm-bl
+    check_interval: 120
+    hostgroups: dl380, dl360, bl460, bm-bl
     excludehosts: villa, lobos, schein, storace, mirror-anu
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --ps-no-redundant"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: villa
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --ps-no-redundant  --ignore-failed='PS2'"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: lobos
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --fan-no-redundant"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: schein
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --fan-ignore-not-present"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: storace
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --fan-ignore-not-present --ps-no-redundant --ignore-failed='PS1'"
-    normal_check_interval: 120
+    check_interval: 120
     hosts: mirror-anu
   ###
   -
@@ -2097,6 +2141,12 @@ services:
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-drbd -d All"
     hostgroups: drbd-hosts
+    excludehosts: ubc-bl8
+  -
+    name: RAID - DRBD
+    servicegroups: raid
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-drbd -d All --ok-no-devices"
+    hosts: ubc-bl8
   # }}}
   # }}}
   # {{{ ### mail stuff
@@ -2304,7 +2354,7 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 465 -S -C 14 -t 45"
     hostgroups: postfix-hosts
     depends: process - postfix - master
-    normal_check_interval: 120
+    check_interval: 120
   # }}}
   # {{{ mail - network service
   -
@@ -2381,31 +2431,31 @@ services:
     excludehosts: menotti
     excludehostgroups: broken_https_default_vhost
     depends: "process - apache2 - master"
-    normal_check_interval: 120
+    check_interval: 120
   -
     name: network service - https
     check: dsa_check_https_want_auth
     hosts: menotti
     depends: "process - apache2 - master"
-    normal_check_interval: 120
+    check_interval: 120
   -
     name: network service - https
     check: dsa_check_https_any_status
     hostgroups: broken_https_default_vhost
     depends: "process - apache2 - master"
-    normal_check_interval: 120
+    check_interval: 120
   -
     name: network service - https cert
     check: dsa_check_cert!443
     hostgroups: apache-https
     depends: network service - https
-    normal_check_interval: 60
+    check_interval: 60
   -
     name: unwanted network service - https
     check: dsa_check_port_closed!443
     hostgroups: apache2-hosts
     excludehostgroups: apache-https
-    normal_check_interval: 60
+    check_interval: 60
   # }}}
   # {{{ FTP
   -
@@ -2485,7 +2535,7 @@ services:
     nrpe: "(/usr/lib/nagios/plugins/check_procs -a schroot -s Zs -c 0 > /dev/null || /usr/lib/nagios/plugins/check_procs -a schroot -s Zs -c 0) && /usr/lib/nagios/plugins/check_procs -a schroot -s ZNs -c 0"
     hostgroups: buildd
     contact_groups: +buildd
-    normal_check_interval: 5
+    check_interval: 5
     max_check_attempts: 24
     retry_check_interval: 5
   -
@@ -2527,24 +2577,205 @@ services:
     name: mirror sync - bugs
     check: "dsa_check_mirrorsync_skew!bugs.debian.org!project/trace/bugs-master.debian.org!120:600"
     hosts: global
+    servicegroups: mirror
   -
     name: mirror sync - security
     check: "dsa_check_mirrorsync_skew!security-nagios.debian.org!project/trace/security-master.debian.org!150:3600"
     hosts: global
+    servicegroups: mirror
   -
     name: mirror sync - packages
     check: "dsa_check_mirrorsync_skew!packages.debian.org!Pics/.trace!3600:57600"
     hosts: global
-    normal_check_interval: 15
+    check_interval: 15
     max_check_attempts: 5
     retry_check_interval: 5
+    servicegroups: mirror
   -
     name: mirror sync - snapshot
     check: "dsa_check_mirrorsync_skew!snapshot.debian.org!project/trace/snapshot-master.debian.org!3600:28800"
     hosts: global
-    normal_check_interval: 15
+    check_interval: 15
     max_check_attempts: 5
     retry_check_interval: 5
+    servicegroups: mirror
+
+  -
+    name: mirror static sync - bits
+    check: "dsa_check_staticsync!bits.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - network-test
+    check: "dsa_check_staticsync!network-test.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - appstream
+    check: "dsa_check_staticsync!appstream.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - blends
+    check: "dsa_check_staticsync!blends.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - d-i
+    check: "dsa_check_staticsync!d-i.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debaday
+    check: "dsa_check_staticsync!debaday.debian.net"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debdeltas
+    check: "dsa_check_staticsync!debdeltas.debian.net"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - dsa
+    check: "dsa_check_staticsync!dsa.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - lintian
+    check: "dsa_check_staticsync!lintian.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - mozilla
+    check: "dsa_check_staticsync!mozilla.debian.net"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - news
+    check: "dsa_check_staticsync!news.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - incoming.ports
+    check: "dsa_check_staticsync!incoming.ports.debian.org"
+    hosts: global
+    servicegroups: mirror
+ # -
+ #   name: mirror static sync - release
+ #   check: "dsa_check_staticsync!release.debian.org"
+ #   hosts: global
+ #   servicegroups: mirror
+  -
+    name: mirror static sync - rtc
+    check: "dsa_check_staticsync!rtc.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - security-team
+    check: "dsa_check_staticsync!security-team.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - wnpp-by-tags
+    check: "dsa_check_staticsync!wnpp-by-tags.debian.net"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - www.ports
+    check: "dsa_check_staticsync!www.ports.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - timeline
+    check: "dsa_check_staticsync!timeline.debian.net"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - backports
+    check: "dsa_check_staticsync!backports.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - incoming
+    check: "dsa_check_staticsync!incoming.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - metadata.ftp-master
+    check: "dsa_check_staticsync!metadata.ftp-master.debian.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - deb
+    check: "dsa_check_staticsync!deb.debian.org"
+    hosts: global
+    servicegroups: mirror
+
+  -
+    name: mirror static sync - 10years
+    check: "dsa_check_staticsync!10years.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf0
+    check: "dsa_check_staticsync!debconf0.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf1
+    check: "dsa_check_staticsync!debconf1.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf2
+    check: "dsa_check_staticsync!debconf2.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf3
+    check: "dsa_check_staticsync!debconf3.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf4
+    check: "dsa_check_staticsync!debconf4.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf5
+    check: "dsa_check_staticsync!debconf5.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf6
+    check: "dsa_check_staticsync!debconf6.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf7
+    check: "dsa_check_staticsync!debconf7.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - debconf1
+    check: "dsa_check_staticsync!debconf1.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - es
+    check: "dsa_check_staticsync!es.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - fr
+    check: "dsa_check_staticsync!fr.debconf.org"
+    hosts: global
+    servicegroups: mirror
+  -
+    name: mirror static sync - miniconf10
+    check: "dsa_check_staticsync!miniconf10.debconf.org"
+    hosts: global
+    servicegroups: mirror
   # }}}
   # {{{ DNS
   -
@@ -2625,7 +2856,7 @@ services:
     remotecheck: "/usr/lib/nagios/plugins/check_ping -H $HOSTADDRESS$ -w 50,10% -c 200,30%"
     runfrom: ubc-bl8
     hosts: giustini
-    normal_check_interval: 5
+    check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
   -
@@ -2638,13 +2869,23 @@ services:
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=11298 $HOSTADDRESS$ public"
     runfrom: ubc-bl8
     hosts: giustini
+  ###
+  -
+    name: process - multipathd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:15 -c 1: -u root -C multipathd -a '/sbin/multipathd'"
+    hostgroups: multipath-hosts
+  -
+    name: unwanted process - multipathd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C multipathd"
+    hostgroups: computers
+    excludehostgroups: multipath-hosts
   # }}}
   # {{{ porterbox
   -
     name: current chroots
     nrpe: "/usr/lib/nagios/plugins/dsa-check-dchroots-current"
     hostgroups: porterbox
-    normal_check_interval:  60
+    check_interval:  60
     retry_check_interval: 15
   # }}}
   # {{{ openstack
@@ -2660,10 +2901,10 @@ services:
 #    name: process - openstack - nova-api
 #    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-api -a '/usr/bin/python /usr/bin/nova-api --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-api.log'"
 #    hostgroups: openstack-controller
-  -
-    name: process - openstack - nova-compute
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-compute -a '/usr/bin/python /usr/bin/nova-compute --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-compute.log --config-file=/etc/nova/nova-compute.conf'"
-    hostgroups: openstack-compute
+#  -
+#    name: process - openstack - nova-compute
+#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-compute -a '/usr/bin/python /usr/bin/nova-compute --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-compute.log --config-file=/etc/nova/nova-compute.conf'"
+#    hostgroups: openstack-compute
 #  -
 #    name: process - openstack - nova-cert
 #    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-cert -a '/usr/bin/python /usr/bin/nova-cert --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-cert.log'"
@@ -2696,11 +2937,6 @@ services:
     hostgroups: jessie
     excludehostgroups: freebsd
   ###
-  -
-    name: process - rngd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rngd  -a '/usr/sbin/rngd -r /dev/hwrng'"
-    hostgroups: dl385
-  ###
   -
     name: process - slapd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:20 -c 1:50 -u openldap -C slapd -a '/usr/sbin/slapd -h ldap:/// ldaps:/// -g openldap -u openldap'"
@@ -2709,7 +2945,7 @@ services:
     name: network service - ldaps cert
     check: dsa_check_cert!636
     depends: process - slapd
-    normal_check_interval: 60
+    check_interval: 60
     hosts: draghi
   ###
   -
@@ -2723,17 +2959,26 @@ services:
     check: check_tcp!873
     hostgroups: rsyncd-hosts
     depends: process - xinetd
-    excludehosts: rietz
   -
     name: network service - rsync
     check: check_tcp!873
-    hosts: rietz2
-    depends: rietz:process - xinetd
+    hosts: milanollo2
+    depends: milanollo:process - xinetd
   -
     name: network service - rsync
     check: check_tcp!873
-    hosts: milanollo2
-    depends: milanollo:process - xinetd
+    hosts: mirror-isc2, mirror-isc-syncproxy
+    depends: mirror-isc:process - xinetd
+  -
+    name: network service - rsync
+    check: check_tcp!873
+    hosts: mirror-umn2, mirror-umn3
+    depends: mirror-umn:process - xinetd
+  -
+    name: network service - rsync
+    check: check_tcp!873
+    hosts: mirror-anu2, mirror-anu3
+    depends: mirror-anu:process - xinetd
   ###
   -
     name: process - icinga
@@ -2754,19 +2999,19 @@ services:
   -
     name: network service - sip-tls cert - 443
     check: dsa_check_cert!443
-    normal_check_interval: 60
+    check_interval: 60
     hosts: vogler
   -
     name: network service - sip-tls cert - 5061
     check: dsa_check_cert!5061
-    normal_check_interval: 60
+    check_interval: 60
     hosts: vogler
   ####
   -
     name: puppetmaster cert
     nrpe: "sudo -u puppet /usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem"
     hosts: handel
-    normal_check_interval: 60
+    check_interval: 60
     max_check_attempts: 2
     retry_check_interval: 5
   # }}}