binet, babin, brahms on jessie
[mirror/dsa-nagios.git] / config / nagios-master.cfg
index 81dc1fb..ce5ee58 100644 (file)
@@ -33,6 +33,10 @@ servers:
     address: 130.239.18.97
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-aql:
+    address: 141.170.2.17
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-bytemark:
     address: 89.16.160.116
     parents: gw-ubcece
@@ -74,8 +78,8 @@ servers:
     address: 62.104.23.249
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
-  gw-ftcollins:
-    address: 192.25.206.1
+  gw-gatech:
+    address: 128.61.240.1
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-grnet:
@@ -90,6 +94,14 @@ servers:
     address: 129.143.57.177
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-leaseweb:
+    address: 185.17.185.190
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
+  gw-linaro:
+    address: 64.28.108.36
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-man-da:
     address: 82.195.75.126
     parents: gw-ubcece
@@ -106,6 +118,10 @@ servers:
     address: 193.201.200.129
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-sakura:
+    address: 133.242.99.65
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-sanger:
     address: 193.62.202.20
     parents: gw-ubcece
@@ -135,6 +151,10 @@ servers:
     address: 128.101.240.222
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-unicamp:
+    address: 143.106.167.234
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-utwente:
     address: 130.89.149.1
     parents: gw-ubcece
@@ -163,7 +183,12 @@ servers:
   babin:
     address: 213.165.95.6
     parents: powell
-    hostgroups: computers, buildd, hassrvfs, kvmdomains, wheezy
+    hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie
+  piu-slave-1und1-01:
+    address: 213.165.95.7
+    parents: powell
+    hostgroups: computers, service, kvmdomains, jessie
+    contacts: holger
   # }}}
   # {{{ gw-1und1-sec
   schumann:
@@ -173,11 +198,7 @@ servers:
   chopin:
     address: 195.20.242.124
     parents: schumann
-    hostgroups: computers, service, apache2-hosts, hassrvfs, hasbootfs, rsyncd-hosts, uploadqueue, kvmdomains, heavy-exim, xinetd-hosts, apache-https, postgres91-hosts, wheezy
-  geo3:
-    address: 195.20.242.125
-    parents: schumann
-    hostgroups: computers, service, hasbootfs, bind9-hosts, kvmdomains, wheezy
+    hostgroups: computers, service, apache2-hosts, hassrvfs, hasbootfs, rsyncd-hosts, uploadqueue, kvmdomains, xinetd-hosts, apache-https, postgres91-hosts, wheezy
   soler:
     address: 195.20.242.126
     parents: schumann
@@ -185,65 +206,83 @@ servers:
   wieck:
     address: 195.20.242.89
     parents: gw-1und1-sec
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, acpid-hosts, xinetd-hosts, wheezy, security_mirror, hasvarlogfs, no-bacula
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, acpid-hosts, xinetd-hosts, jessie, security_mirror, hasvarlogfs, no-bacula
   # }}}
   # {{{ gw-accumu
   pettersson:
     address: 130.239.18.123
     parents: gw-accumu
-    hostgroups: computers, hasbootfs, aacraid, nfs-client, acpid-hosts, service, apache2-hosts, wheezy, autofs
+    hostgroups: computers, hasbootfs, aacraid, nfs-client, acpid-hosts, service, apache2-hosts, jessie, autofs, sw-raid
   praetorius:
     address: 130.239.18.121
     parents: gw-accumu
     hostgroups: computers, buildd, hassrvfs, wheezy
   # }}}
+  # {{{ gw-aql
+  mips-aql-01:
+    address: 141.170.6.149
+    parents: gw-aql
+    hostgroups: computers, buildd, jessie, nfs-client
+  mips-aql-02:
+    address: 141.170.6.150
+    parents: gw-aql
+    hostgroups: computers, buildd, wheezy, nfs-client
+  minkus:
+    address: 141.170.6.151
+    parents: gw-aql
+    hostgroups: computers, porterbox, jessie, nfs-client
+  mipsel-aql-01:
+    address: 141.170.6.152
+    parents: gw-aql
+    hostgroups: computers, buildd, jessie, hassrvfs, hasbootfs, sw-raid
+  mipsel-aql-02:
+    address: 141.170.6.153
+    parents: gw-aql
+    hostgroups: computers, buildd, jessie, hassrvfs, hasbootfs, sw-raid
+  # }}}
   # {{{ gw-arm
   abel:
     address: 217.140.96.56
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, porterbox, wheezy, deadslow
-  alain:
+    hostgroups: computers, hasbootfs, hassrvfs, porterbox, jessie, broken_mq
+  arnold:
+    address: 217.140.96.57
+    parents: gw-arm
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+  arm-arm-01:
     address: 217.140.96.58
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, deadslow
-  alwyn:
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+  arm-arm-02:
     address: 217.140.96.59
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, deadslow
-  antheil:
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+  arm-arm-03:
     address: 217.140.96.60
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, deadslow
-  arne:
-    address: 217.140.96.61
-    parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, deadslow
-  arnold:
-    address: 217.140.96.57
-    parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, deadslow
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
   harris:
     address: 217.140.96.66
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, wheezy, armhf, porterbox, deadslow
-  hasse:
-    address: 217.140.96.68
-    parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, wheezy, armhf, buildd, deadslow
-  henze:
-    address: 217.140.96.70
+    hostgroups: computers, hasbootfs, hassrvfs, jessie, armhf, porterbox, broken_mq
+  hartmann:
+    address: 217.140.96.67
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, wheezy, armhf, buildd, deadslow
+    hostgroups: computers, hasbootfs, hassrvfs, jessie, armhf, buildd, broken_mq
   hoiby:
     address: 217.140.96.71
     parents: gw-arm
-    hostgroups: computers, hasbootfs, hassrvfs, armhf, wheezy, buildd, deadslow
+    hostgroups: computers, hasbootfs, hassrvfs, armhf, jessie, buildd, broken_mq
+  ia64-arm-01:
+    address: 217.140.96.61
+    parents: gw-arm
+    hostgroups: computers, hasbootfs, hassrvfs, wheezy, buildd, broken_mq, sw-raid, acpid-hosts
   # }}}
   # {{{ gw-brown
   franck:
     address: 138.16.160.12
     parents: gw-brown
-    hostgroups: computers, service, apache2-hosts, dl380, rsyncd-hosts, postgres91-hosts, spamd, heavy-exim, acpid-hosts, uploadqueue, xinetd-hosts, apache-https, hassrvfs, wheezy
+    hostgroups: computers, service, apache2-hosts, dl380, rsyncd-hosts, postgres91-hosts, spamd, acpid-hosts, uploadqueue, xinetd-hosts, apache-https, hassrvfs, wheezy
   # }}}
   # {{{ gw-bytemark
   bm-bl1:
@@ -278,11 +317,27 @@ servers:
     address: 5.153.231.248
     parents: gw-bytemark
     hostgroups: computers, bm-bl, acpid-hosts, service, wheezy
+  bm-bl9:
+    address: 5.153.231.249
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+  bm-bl10:
+    address: 5.153.231.250
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+  bm-bl11:
+    address: 5.153.231.251
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
+  bm-bl12:
+    address: 5.153.231.252
+    parents: gw-bytemark
+    hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq
 
   milanollo:
     address: 5.153.231.2
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-server, xinetd-hosts
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, nfs-server, xinetd-hosts
   milanollo2:
     address: 5.153.231.9
     parents: milanollo
@@ -302,17 +357,17 @@ servers:
   pejacevic:
     address: 5.153.231.6
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, apache-https
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, nfs-client, autofs, apache-https
     contacts: holger
   piu-slave-bm-a:
     address: 5.153.231.7
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, nfs-client, autofs
+    hostgroups: computers, service, kvmdomains, jessie, nfs-client, autofs
     contacts: holger
   binet:
     address: 5.153.231.8
     parents: gw-bytemark
-    hostgroups: computers, buildd, hassrvfs, kvmdomains, wheezy
+    hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie
   bmdb1:
     address: 5.153.231.10
     parents: gw-bytemark
@@ -324,35 +379,27 @@ servers:
   coccia:
     address: 5.153.231.11
     parents: ganeti-bytemark
-    hostgroups: computers, hassrvfs, kvmdomains, wheezy, autofs, nfs-client
-  backuphost:
-    address: 5.153.231.12
-    parents: ganeti-bytemark
-    hostgroups: computers, hassrvfs, kvmdomains, wheezy
+    hostgroups: computers, hassrvfs, kvmdomains, wheezy, autofs, nfs-client, uploadqueue, xinetd-hosts, apache-https, apache2-hosts
   philp:
     address: 5.153.231.13
     parents: ganeti-bytemark
     hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts
-  petrova:
-    address: 5.153.231.25
-    parents: ganeti-bytemark
-    hostgroups: computers, kvmdomains, wheezy, apache2-hosts
   couper:
     address: 5.153.231.14
     parents: ganeti-bytemark
     hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs
   rainier:
-    address: 5.153.231.15
+    address: 5.153.231.16
     parents: ganeti-bytemark
     hostgroups: computers, kvmdomains, wheezy, no-bacula
   rapoport:
-    address: 5.153.231.16
+    address: 5.153.231.15
     parents: ganeti-bytemark
     hostgroups: computers, kvmdomains, wheezy, no-bacula
   delfin:
     address: 5.153.231.17
     parents: ganeti-bytemark
-    hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts
+    hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs
   wuiet:
     address: 5.153.231.18
     parents: ganeti-bytemark
@@ -360,7 +407,7 @@ servers:
   dinis:
     address: 5.153.231.19
     parents: ganeti-bytemark
-    hostgroups: computers, general, kvmdomains, wheezy
+    hostgroups: computers, general, kvmdomains, wheezy, hassrvfs
   donizetti:
     address: 5.153.231.20
     parents: ganeti-bytemark
@@ -369,26 +416,73 @@ servers:
     address: 5.153.231.21
     parents: ganeti-bytemark
     contact_groups: alioth-admins
-    hostgroups: computers, general, wheezy, postgres91-hosts, apache2-hosts, acpid-hosts, apache-https, brokensamhain, no-bacula, bind9-hosts, xinetd-hosts
+    hostgroups: computers, general, wheezy, postgres91-hosts, apache2-hosts, acpid-hosts, apache-https, brokensamhain, no-bacula, bind9-hosts, xinetd-hosts, alioth, heavy-exim, spamd
     no-servicegroups: true
   dillon:
     address: 5.153.231.22
     parents: ganeti-bytemark
-    hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs, hassrvfs
+    hostgroups: computers, general, kvmdomains, jessie, nfs-client, autofs, hassrvfs
   ticharich:
     address: 5.153.231.23
     parents: ganeti-bytemark
-    hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs, apache2-hosts, apache-https, service
-  diamond:
-    address: 5.153.231.24
+    hostgroups: computers, general, kvmdomains, jessie, nfs-client, autofs, apache2-hosts, apache-https, service, broken_https_default_vhost
+  petrova:
+    address: 5.153.231.25
+    parents: ganeti-bytemark
+    hostgroups: computers, kvmdomains, wheezy, apache2-hosts
+  oyens:
+    address: 5.153.231.26
+    parents: ganeti-bytemark
+    hostgroups: computers, kvmdomains, jessie, apache2-hosts, openstack-controller, apache-https, broken_mq
+  barriere:
+    address: 5.153.231.27
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, porterbox
+  quantz:
+    address: 5.153.231.28
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, nfs-client, xinetd-hosts, heavy-exim, apache2-hosts, autofs, apache-https
+  portman:
+    address: 5.153.231.29
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts
+  paradis:
+    address: 5.153.231.30
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, apache-https
+  x86-bm-01:
+    address: 5.153.231.32
+    parents: ganeti-bytemark
+    hostgroups: computers, kvmdomains, wheezy, acpid-hosts, no-bacula
+  gideon:
+    address: 5.153.231.34
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, apache-https
+  httpredir-bm-01:
+    address: 5.153.231.35
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts
+  lindsay:
+    address: 5.153.231.36
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, jessie, autofs, nfs-client
+  fede:
+    address: 5.153.231.37
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs
+  sor:
+    address: 5.153.231.38
     parents: ganeti-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, bind9-hosts, no-bacula
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts, autofs, nfs-client
+  jerea:
+    address: 5.153.231.39
+    parents: ganeti-bytemark
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts
   # }}}
   # {{{ gw-c3sl
   santoro:
     address: 200.17.202.197
     parents: gw-c3sl
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, xinetd-hosts, hassrvfs, wheezy, high-RTT, security_mirror, no-bacula, apache-https
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, xinetd-hosts, hassrvfs, jessie, high-RTT, security_mirror, no-bacula, apache-https
     contacts: faw
   # }}}
   # {{{ gw-carnet
@@ -418,83 +512,149 @@ servers:
     hostgroups: computers, buildd, hassrvfs, sw-raid, wheezy, sparc
   # }}}
   # {{{ gw-csail
-  senfl:
-    address: 128.31.0.51
-    parents: gw-csail
-    hostgroups: computers, service, dl360, acpid-hosts, hassrvfs, apache2-hosts, rsyncd-hosts, bind9-hosts, xinetd-hosts, squeeze, apache-https
   steffani:
     address: 128.31.0.36
     parents: gw-csail
     hostgroups: computers, service, apache2-hosts, rsyncd-hosts, sw-raid, acpid-hosts, hasbootfs, hasorgfs, xinetd-hosts, wheezy, security_mirror, no-bacula
+
+  csail-node01:
+    address: 128.31.0.16
+    parents: gw-csail
+    hostgroups: computers, service, dl360, acpid-hosts, wheezy, drbd-hosts
+  csail-node02:
+    address: 128.31.0.46
+    parents: gw-csail
+    hostgroups: computers, service, dl360, acpid-hosts, wheezy, drbd-hosts
+  ganeti-csail:
+    address: 128.31.0.49
+    parents: gw-bytemark
+    hostgroups: notacomputer
+
+  falla:
+    address: 128.31.0.65
+    parents: ganeti-csail
+    hostgroups: computers, freebsd, hassrvfs, porterbox, wheezy
+  fischer:
+    address: 128.31.0.35
+    parents: ganeti-csail
+    hostgroups: computers, freebsd, hassrvfs, porterbox, wheezy
+  mirror-csail:
+    address: 128.31.0.62
+    parents: ganeti-csail
+    hostgroups: computers, service, hassrvfs, kvmdomains, jessie, apache2-hosts, rsyncd-hosts, xinetd-hosts, apache-https
+  x86-csail-01:
+    address: 128.31.0.50
+    parents: ganeti-csail
+    hostgroups: computers, buildd, hassrvfs, kvmdomains, wheezy
+  httpredir-csail-01:
+    address: 128.31.0.66
+    parents: ganeti-csail
+    hostgroups: computers, service, kvmdomains, jessie, apache2-hosts
   # }}}
   # {{{ gw-dgi
-  argento:
-    address: 93.94.130.160
+  storace:
+    address: 93.94.130.161
     parents: gw-dgi
-    hostgroups: computers, sw-raid, hassrvfs, wheezy
-  # }}}
-  # {{{ gw-ftcollins
-  #alkman:
-  #  address: 192.25.206.63
-  #  parents: gw-ftcollins
-  #  hostgroups: computers, buildd, acpid-hosts, wheezy
-  #merulo:
-  #  address: 192.25.206.58
-  #  parents: gw-ftcollins
-  #  hostgroups: computers, porterbox, hasusrfs, wheezy
-  #mundy:
-  #  address: 192.25.206.62
-  #  parents: gw-ftcollins
-  #  hostgroups: computers, buildd, hassrvfs, sw-raid, acpid-hosts, wheezy
-  spohr:
-    address: 192.25.206.33
-    parents: gw-ftcollins
-    hostgroups: computers, service, dl380, apache2-hosts, wheezy, no-bacula
+    hostgroups: computers, acpid-hosts, wheezy, dl380, nfs-client, hassrvfs
+  # }}}
+  # {{{ gw-gatech
+  sechter:
+    address: 128.61.240.73
+    parents: gw-gatech
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, sw-raid, acpid-hosts, hasbootfs, hassrvfs, xinetd-hosts, jessie, security_mirror
   # }}}
   # {{{ gw-grnet
-  barber:
-    address: 194.177.211.203
-    parents: gw-grnet
-    hostgroups: computers, acpid-hosts, buildd, hassrvfs, mptraid, wheezy
-  biber:
-    address: 194.177.211.204
+  ganeti-grnet:
+    address: 194.177.211.194
     parents: gw-grnet
-    hostgroups: computers, acpid-hosts, buildd, hassrvfs, mptraid, wheezy
-  cilea:
-    address: 194.177.211.205
+    hostgroups: notacomputer
+  grnet-node01:
+    address: 194.177.211.195
     parents: gw-grnet
-    hostgroups: computers, acpid-hosts, mptraid, hassrvfs, service, squeeze
-  orff:
-    address: 194.177.211.209
+    hostgroups: computers, service, dl380, acpid-hosts, wheezy, drbd-hosts
+  grnet-node02:
+    address: 194.177.211.196
     parents: gw-grnet
-    hostgroups: computers, acpid-hosts, bind9-hosts, mptraid, service, hassrvfs, apache2-hosts, squeeze
+    hostgroups: computers, service, dl380, acpid-hosts, wheezy, drbd-hosts
   rautavaara:
     address: 194.177.211.199
     parents: gw-grnet
-    hostgroups: computers, acpid-hosts, megaraid, service, squeeze, nfs-server
-  vitry:
-    address: 194.177.211.206
+    hostgroups: computers, acpid-hosts, megaraid, service, wheezy
+  loghost-grnet-01:
+    address: 194.177.211.200
+    parents: gw-grnet
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs
+  geo3:
+    address: 194.177.211.201
+    parents: gw-grnet
+    hostgroups: computers, service, bind9-hosts, kvmdomains, jessie
+  cgi-grnet-01:
+    address: 194.177.211.202
     parents: gw-grnet
-    hostgroups: computers, acpid-hosts, mptraid, no-bacula, wheezy
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts, apache-https
+  x86-grnet-01:
+    address: 194.177.211.203
+    parents: ganeti-grnet
+    hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie
   # }}}
   # {{{ gw-isc
   schein:
     address: 149.20.20.6
     parents: gw-isc
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, acpid-hosts, dl360, hasorgfs, xinetd-hosts, wheezy, security_mirror, no-bacula
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, acpid-hosts, dl360, hasorgfs, xinetd-hosts, jessie, security_mirror, no-bacula
+  # }}}
+  # {{{ gw-leaseweb
+  lw01:
+    address: 185.17.185.177
+    parents: gw-leaseweb
+    hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server
+  lw02:
+    address: 185.17.185.178
+    parents: gw-leaseweb
+    hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server
+  lw03:
+    address: 185.17.185.179
+    parents: gw-leaseweb
+    hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server
+  lw04:
+    address: 185.17.185.180
+    parents: gw-leaseweb
+    hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server
+  lw07:
+    address: 185.17.185.187
+    parents: gw-leaseweb
+    hostgroups: computers,  service, acpid-hosts, wheezy, dl180, nfs-client, autofs, hassrvfs, postgres91-hosts, apache2-hosts
+  lw08:
+    address: 185.17.185.189
+    parents: gw-leaseweb
+    hostgroups: computers,  service, acpid-hosts, jessie, dl180, nfs-client, autofs, hassrvfs, apache2-hosts
+  # }}}
+  # {{{ gw-linaro
+  arm-linaro-01:
+    address: 64.28.108.83
+    parents: gw-linaro
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+  arm-linaro-03:
+    address: 64.28.108.85
+    parents: gw-linaro
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie, broken_mq
+  asachi:
+    address: 64.28.108.84
+    parents: gw-linaro
+    hostgroups: computers, hasbootfs, hassrvfs, porterbox, wheezy, broken_mq
   # }}}
   # {{{ gw-karlsruhe
   zemlinsky:
     address: 129.143.160.6
     parents: gw-karlsruhe
-    hostgroups: computers, buildd, hassrvfs, wheezy
+    hostgroups: computers, buildd, wheezy
     contacts: pkern
   # }}}
   # {{{ gw-man-da
   ball:
     address: 82.195.75.70
     parents: gw-man-da
-    hostgroups: computers, buildd, hasbootfs, wheezy
+    hostgroups: computers, buildd, hasbootfs, wheezy, sw-raid
   # bartok TODO
   czerny:
     address: 82.195.75.109
@@ -512,6 +672,14 @@ servers:
     address: 82.195.75.110
     parents: ganeti3
     hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, spamd, heavy-exim, highload
+  mipsel-manda-01:
+    address: 82.195.75.72
+    parents: gw-man-da
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy
+  mipsel-manda-02:
+    address: 82.195.75.74
+    parents: gw-man-da
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy
   fils:
     address: 82.195.75.89
     parents: ganeti3
@@ -530,14 +698,6 @@ servers:
     address: 82.195.75.99
     parents: ganeti3
     hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, hasvarlogfs
-  rem:
-    address: 82.195.75.68
-    parents: gw-man-da
-    hostgroups: computers, buildd, hasbootfs, hassrvfs, wheezy
-  unger:
-    address: 82.195.75.102
-    parents: gw-man-da
-    hostgroups: computers, service, dl360, acpid-hosts, wheezy
   draghi:
     address: 82.195.75.106
     parents: ganeti3
@@ -545,7 +705,7 @@ servers:
   geo1:
     address: 82.195.75.105
     parents: ganeti3
-    hostgroups: computers, service, bind9-hosts, kvmdomains, wheezy
+    hostgroups: computers, service, bind9-hosts, kvmdomains, jessie
   handel:
     address: 82.195.75.104
     parents: ganeti3
@@ -553,11 +713,11 @@ servers:
   kaufmann:
     address: 82.195.75.107
     parents: ganeti3
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, kvmdomains, xinetd-hosts, wheezy
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, kvmdomains, xinetd-hosts, jessie
   stockhausen:
     address: 82.195.75.108
     parents: ganeti3
-    hostgroups: computers, service, kvmdomains, wheezy, acpid-hosts, jetty-hosts
+    hostgroups: computers, service, kvmdomains, jessie, acpid-hosts
   ganeti3:
     address: 82.195.75.111
     parents: gw-man-da
@@ -566,10 +726,6 @@ servers:
     address: 82.195.75.112
     parents: ganeti3
     hostgroups: computers, service, hassrvfs, apache2-hosts, kvmdomains, wheezy, acpid-hosts, apache-https, rsyncd-hosts, xinetd-hosts
-  vieuxtemps:
-    address: 82.195.75.113
-    parents: ganeti3
-    hostgroups: computers, service, kvmdomains, wheezy, varnish-hosts
   mailly:
     address: 82.195.75.114
     parents: ganeti3
@@ -582,18 +738,30 @@ servers:
     address: 82.195.75.92
     parents: ganeti3
     hostgroups: computers, service, kvmdomains, wheezy
+  wolkenstein:
+    address: 82.195.75.65
+    parents: ganeti3
+    hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, rsyncd-hosts, apache2-hosts, wheezy
+  mipsel-manda-01:
+    address: 82.195.75.72
+    parents: gw-man-da
+    hostgroups: computers, buildd, wheezy, hassrvfs, sw-raid
+  mipsel-manda-02:
+    address: 82.195.75.74
+    parents: gw-man-da
+    hostgroups: computers, buildd, wheezy, hassrvfs, sw-raid
   # }}}
   # {{{ gw-marist
   zani:
     address: 148.100.88.22
     parents: gw-marist
-    hostgroups: computers, buildd, hassrvfs, wheezy, incomingmailrelayed, ping-suckers
+    hostgroups: computers, buildd, hassrvfs, jessie, incomingmailrelayed
   # }}}
   # {{{ gw-osuosl
   busoni:
     address: 140.211.15.34
     parents: gw-osuosl
-    hostgroups: computers, service, dl360, hassrvfs, acpid-hosts, wheezy, hasvarlogfs, apache2-hosts, no-bacula, apache-https
+    hostgroups: computers, service, dl360, hassrvfs, acpid-hosts, jessie, hasvarlogfs, apache2-hosts, no-bacula, apache-https
   byrd:
     address: 140.211.166.20
     parents: gw-osuosl
@@ -601,7 +769,7 @@ servers:
   buxtehude:
     address: 140.211.166.26
     parents: byrd
-    hostgroups: computers, service, hassrvfs, acpid-hosts, apache2-hosts, heavy-exim, postgres91-hosts, wheezy, hasvarlogfs, apache-https
+    hostgroups: computers, service, hassrvfs, acpid-hosts, apache2-hosts, heavy-exim, postgres91-hosts, wheezy, hasvarlogfs, apache-https, spamd
   # malo TODO
   mayer:
     address: 140.211.166.78
@@ -611,14 +779,18 @@ servers:
 #    address: 140.211.166.58
 #    parents: gw-osuosl
 #    hostgroups: computers, buildd, hasbootfs
+  merulo:
+    address: 140.211.166.46
+    parents: gw-osuosl
+    hostgroups: computers, porterbox, hasusrfs, wheezy
   parry:
     address: 140.211.15.153
     parents: gw-osuosl
-    hostgroups: computers, wheezy, buildd, hassrvfs
+    hostgroups: computers, wheezy, buildd, hassrvfs, sw-raid
   partch:
     address: 140.211.15.152
     parents: gw-osuosl
-    hostgroups: computers, wheezy, hassrvfs, porterbox
+    hostgroups: computers, jessie, hassrvfs, porterbox, sw-raid
   rietz:
     address: 140.211.166.43
     parents: gw-osuosl
@@ -640,7 +812,7 @@ servers:
   sibelius:
     address: 193.62.202.28
     parents: gw-sanger
-    hostgroups: computers, acpid-hosts, postgres91-hosts, service, apache2-hosts, sw-raid, squeeze, rsyncd-hosts, xinetd-hosts, hasvarlogfs
+    hostgroups: computers, acpid-hosts, postgres91-hosts, service, apache2-hosts, sw-raid, wheezy, rsyncd-hosts, xinetd-hosts, hasvarlogfs
     contacts: tjrc1, dave
   smetana:
     address: 193.62.202.29
@@ -656,13 +828,9 @@ servers:
   villa:
     address: 212.211.132.32
     parents: gw-scanplus-villa
-    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl380, hasvarfs, hasusrfs, hasorgfs, xinetd-hosts, wheezy, security_mirror, no-bacula
+    hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl360, hassrvfs, xinetd-hosts, jessie, security_mirror, acpid-hosts
   # }}}
   # {{{ gw-sil
-  beethoven:
-    address: 86.59.118.146
-    parents: gw-sil
-    hostgroups: computers, hasbootfs, aacraid, service, acpid-hosts, wheezy
   eder:
     address: 86.59.118.151
     parents: gw-sil
@@ -674,7 +842,7 @@ servers:
   eberlin:
     address: 86.59.118.155
     parents: gw-sil
-    hostgroups: computers, buildd, wheezy
+    hostgroups: computers, buildd, wheezy, sw-raid
   # }}}
   # {{{ gw-ubcece
   sw-ubcece:
@@ -702,7 +870,7 @@ servers:
   ravel:
     address: 206.12.19.5
     parents: sw-ubcece-kais
-    hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, hasbootfs, nfs-client, rsyncd-hosts, bind9-hosts, uploadqueue, hasorgfs, heavy-exim, xinetd-hosts, wheezy, autofs
+    hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, hasbootfs, nfs-client, hasorgfs, wheezy, autofs
   dijkstra:
     address: 206.12.19.218
     parents: sw-ubcece-kais
@@ -735,38 +903,22 @@ servers:
     address: 206.12.19.118
     parents: ganeti2
     hostgroups: computers, general, apache2-hosts, hasbootfs, kvmdomains, apache-https, wheezy
-  wolkenstein:
-    address: 206.12.19.116
-    parents: ganeti2
-    hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, rsyncd-hosts, apache2-hosts, wheezy
   brahms:
     address: 206.12.19.115
     parents: ganeti2
-    hostgroups: computers, buildd, hassrvfs, kvmdomains, wheezy
+    hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie
   geo2:
     address: 206.12.19.113
     parents: ganeti2
-    hostgroups: computers, service, bind9-hosts, kvmdomains, wheezy
-  stabile:
-    address: 206.12.19.13
-    parents: sw-ubcece-kais
-    hostgroups: computers, hashomefs, sw-raid, rsyncd-hosts, apache2-hosts, xinetd-hosts, service, nfs-server, squeeze, hassrvfs
-  respighi:
-    address: 206.12.19.11
-    parents: sw-ubcece-kais
-    hostgroups: computers, hasbootfs, aacraid, hassrvfs, service, apache2-hosts, squeeze
+    hostgroups: computers, service, bind9-hosts, kvmdomains, jessie
   # MSA 2000 (2012i)
   giustini:
     address: 192.168.2.6
-    parents: dijkstra
+    parents: sw-ubcece-kais
     hostgroups: notacomputer
     # unless we implement runfrom for host alive checks
     pingable: false
     check_command: dsa_check_always_ok
-  falla:
-    address: 206.12.19.117
-    parents: ganeti2
-    hostgroups: computers, freebsd, hassrvfs, porterbox, wheezy
   fano:
     address: 206.12.19.110
     parents: ganeti2
@@ -777,10 +929,6 @@ servers:
     parents: ganeti2
     hostgroups: computers, freebsd, wheezy, buildd, hassrvfs
     contacts: christoph
-  fischer:
-    address: 206.12.19.112
-    parents: ganeti2
-    hostgroups: computers, freebsd, hassrvfs, porterbox, wheezy
   gabrielli:
     address: 206.12.19.17
     parents: sw-ubcece-kais
@@ -793,14 +941,6 @@ servers:
     address: 206.12.19.15
     parents: sw-ubcece-kais
     hostgroups: computers, buildd, wheezy
-  rossini:
-    address: 206.12.19.19
-    parents: sw-ubcece-kais
-    hostgroups: computers, dl585, acpid-hosts, service, wheezy
-  salieri:
-    address: 206.12.19.20
-    parents: sw-ubcece-kais
-    hostgroups: computers, dl585, acpid-hosts, service, wheezy
   traetta:
     address: 206.12.19.21
     parents: sw-ubcece-kais
@@ -811,15 +951,11 @@ servers:
 #    hostgroups: computers, service, hasbootfs, kvmdomains, squeeze, hasvicepa
   lotti:
     address: 206.12.19.121
-    parents: sw-ubcece-kais
+    parents: ganeti2
     hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, hassrvfs
-  quantz:
-    address: 206.12.19.122
-    parents: traetta
-    hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, hassrvfs, nfs-client, xinetd-hosts, heavy-exim, apache2-hosts, autofs
   nono:
     address: 206.12.19.123
-    parents: traetta
+    parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, xinetd-hosts, apache2-hosts, apache-https, broken_https_default_vhost
   reger:
     address: 206.12.19.124
@@ -831,7 +967,7 @@ servers:
     hostgroups: computers, service, kvmdomains, wheezy, postgres91-hosts, xinetd-hosts
   glinka:
     address: 206.12.19.126
-    parents: traetta
+    parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, xinetd-hosts
   tye:
     address: 206.12.19.129
@@ -839,36 +975,28 @@ servers:
     hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, apache2-hosts, nfs-client, autofs, hassrvfs
   elgar:
     address: 206.12.19.130
-    parents: salieri
+    parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy
   gombert:
     address: 206.12.19.132
     parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, apache2-hosts
+    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts
   jenkins:
     address: 206.12.19.133
-    parents: salieri
+    parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy
   blavet:
     address: 206.12.19.134
     parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy, xinetd-hosts, nfs-client, autofs
-  barriere:
-    address: 206.12.19.135
-    parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, porterbox
   diabelli:
     address: 206.12.19.136
-    parents: traetta
+    parents: ganeti2
     hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, apache2-hosts, apache-https, broken_https_default_vhost
   bizet:
     address: 206.12.19.137
     parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, no-bacula
-  lilburn:
-    address: 206.12.19.138
-    parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, nfs-client, autofs
+    hostgroups: computers, service, kvmdomains, jessie, hassrvfs, no-bacula
   popov:
     address: 206.12.19.119
     parents: ganeti2
@@ -895,11 +1023,6 @@ servers:
     hostgroups: computers, service, kvmdomains, wheezy, spamd, heavy-exim, mail-relay
   # }}}
   # {{{ gw-ugent
-  ancina:
-    address: 157.193.39.13
-    parents: gw-ugent
-    hostgroups: computers, buildd, hassrvfs, hasbootfs, incomingmailrelayed2025, xinetd-hosts, wheezy
-    contacts: luk
   # }}}
   # {{{ gw-umn
   saens:
@@ -907,6 +1030,28 @@ servers:
     parents: gw-umn
     hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl380, hasvarfs, hasusrfs, hasorgfs, xinetd-hosts, wheezy, security_mirror, no-bacula
   # }}}
+  # {{{ gw-unicamp
+  asgard:
+    address: 143.106.167.145
+    parents: gw-unicamp
+    hostgroups: layer3-infrastructure
+  prokofiev:
+    address: 143.106.167.147
+    parents: gw-unicamp
+    hostgroups: computers, jessie, service
+  powerpc-unicamp-01:
+    address: 143.106.167.149
+    parents: prokofiev
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie
+  ppc64el-unicamp-01:
+    address: 143.106.167.135
+    parents: prokofiev
+    hostgroups: computers, hasbootfs, hassrvfs, buildd, jessie
+  plummer:
+    address: 143.106.167.146
+    parents: prokofiev
+    hostgroups: computers, porterbox, hassrvfs, jessie
+  # }}}
   # {{{ gw-utwente
   klecker:
     address: 130.89.148.10
@@ -926,18 +1071,18 @@ servers:
     hostgroups: secondary-IPs
   # }}}
   # {{{ gw-ynic
-  hildegard:
+  henze:
     address: 144.32.168.74
     parents: gw-ynic
-    hostgroups: computers, hasbootfs, hassrvfs, armhf, wheezy, deadslow, buildd
-  howells:
+    hostgroups: computers, hasbootfs, hassrvfs, armhf, jessie, buildd
+  hasse:
     address: 144.32.168.75
     parents: gw-ynic
-    hostgroups: computers, hasbootfs, hassrvfs, armhf, wheezy, deadslow, buildd
-  hummel:
+    hostgroups: computers, hasbootfs, hassrvfs, armhf, jessie, buildd
+  antheil:
     address: 144.32.168.76
     parents: gw-ynic
-    hostgroups: computers, hasbootfs, hassrvfs, armhf, wheezy, deadslow, buildd
+    hostgroups: computers, hasbootfs, hassrvfs, armhf, wheezy, buildd
   porpora:
     address: 144.32.168.78
     parents: gw-ynic
@@ -946,6 +1091,18 @@ servers:
     address: 144.32.168.77
     parents: gw-ynic
     hostgroups: computers, buildd, sw-raid, hassrvfs, wheezy
+  #antheil:
+  #  address: 217.140.96.60
+  #  parents: gw-arm
+  #  hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy, broken_mq
+  #hasse:
+  #  address: 217.140.96.68
+  #  parents: gw-arm
+  #  hostgroups: computers, hasbootfs, hassrvfs, wheezy, armhf, buildd, broken_mq
+  #henze:
+  #  address: 217.140.96.70
+  #  parents: gw-arm
+  #  hostgroups: computers, hasbootfs, hassrvfs, wheezy, armhf, buildd, broken_mq
   # }}}
   # {{{ gw-zivit
   zandonai:
@@ -957,19 +1114,21 @@ servers:
     parents: gw-zivit
     hostgroups: computers, porterbox, hassrvfs, wheezy
   # }}}
+  # {{{ gw-sakura
+  setoguchi:
+    address: 133.242.99.74
+    parents: gw-sakura
+    hostgroups: computers, service, wheezy, no-bacula, hassrvfs, apache2-hosts, rsyncd-hosts, xinetd-hosts, security_mirror, acpid-hosts
   # }}}
 
-
-#############################
-# host groups
-#
-# hostgroups ircd and all are automatically defined
-#
-#############################
+# {{{ ############################# host groups #############################
 hostgroups:
   computers:
     alias: computers
     private: 1
+    extinfo-icon_image: base/debian.png
+    extinfo-icon_image_alt: Debian GNU/Linux
+    extinfo-notes_url: https://db.debian.org/machines.cgi?host=%s
   layer2-infrastructure:
     alias: Layer 2 Devices
     extinfo-icon_image: base/switch40.png
@@ -981,11 +1140,10 @@ hostgroups:
   notacomputer:
     alias: Systems that are not really systems.  Yeah :)
     private: 1
-  deadslow:
-    alias: Systems too slow to run any real checks
   freebsd:
     alias: freebsd
     private: 1
+    extinfo-icon_image_alt: Debian GNU/kFreeBSD
   armhf:
     alias: armhf
     private: 1
@@ -995,24 +1153,12 @@ hostgroups:
 
   porterbox:
     alias: developer accessible porter machines
-    extinfo-icon_image: base/debian.png
-    extinfo-icon_image_alt: Debian GNU/Linux
-    extinfo-notes_url: http://db.debian.org/machines.cgi?host=%s
   service:
     alias: machines running services
-    extinfo-icon_image: base/debian.png
-    extinfo-icon_image_alt: Debian GNU/Linux
-    extinfo-notes_url: http://db.debian.org/machines.cgi?host=%s
   buildd:
     alias: buildd systems
-    extinfo-icon_image: base/debian.png
-    extinfo-icon_image_alt: Debian GNU/Linux
-    extinfo-notes_url: http://db.debian.org/machines.cgi?host=%s
   general:
     alias: general purpose developer accessible machines
-    extinfo-icon_image: base/debian.png
-    extinfo-icon_image_alt: Debian GNU/Linux
-    extinfo-notes_url: http://db.debian.org/machines.cgi?host=%s
 
   dl380:
     alias: HP DL380 hosts
@@ -1032,26 +1178,26 @@ hostgroups:
   dl585:
     alias: HP DL385 hosts
     private: 1
+  dl180:
+    alias: HP DL180
+    private: 1
+  dl120:
+    alias: HP DL120
+    private: 1
   sw-raid:
     alias: Hosts with Linux software raid
     private: 1
   aacraid:
     alias: Hosts with Adaptec AACraid
     private: 1
-#  megactl:
-#    alias: Hosts with LSI Logic MegaRAID, but not usable with megaraid check
-#    private: 1
   megaraid:
     alias: Hosts with LSI Logic MegaRAID
     private: 1
-  mptraid:
-    alias: Hosts with LSI Logic Fusion-MPT
-    private: 1
 
-  squeeze:
-    alias: Hosts running squeeze
   wheezy:
     alias: Hosts running wheezy
+  jessie:
+    alias: Hosts running jessie
 
   kvmdomains:
     alias: Hosts that are KVM domains
@@ -1077,34 +1223,19 @@ hostgroups:
   apache2-hosts:
     alias: hosts running apache2
     private: 1
-  jetty-hosts:
-    alias: hosts running jetty
-    private: 1
-  varnish-hosts:
-    alias: hosts running varnish
-    private: 1
   bind9-hosts:
     alias: hosts running bind9
     private: 1
   # once every host runs unbound, do away with this group and check "computers" instead
-  unbound-hosts:
-    alias: hosts running unbound
-    private: 1
   amavis-hosts:
     alias: hosts running amavis
     private: 1
-  #tftpd-hosts:
-  #  alias: hosts running a tftpd (tftpd-hpa as a daemon)
-  #  private: 1
   rsyncd-hosts:
     alias: hosts providing rsync services via xinetd
     private: 1
   xinetd-hosts:
     alias: hosts providing services via xinetd
     private: 1
-  #postgres81-hosts:
-  #  alias: hosts running postgres81
-  #  private: 1
   postgres91-hosts:
     alias: hosts running postgres91
     private: 1
@@ -1158,9 +1289,6 @@ hostgroups:
   hasorgfs:
     alias: hosts with a /org filesystem
     private: 1
-  hashomefs:
-    alias: hosts with a /home filesystem
-    private: 1
   hasvarfs:
     alias: hosts with a /var filesystem
     private: 1
@@ -1170,9 +1298,6 @@ hostgroups:
   hasusrfs:
     alias: hosts with a /usr filesystem
     private: 1
-#  hasvicepa:
-#    alias: hosts with a /vicepa
-#    private: 1
 
   incomingmailrelayed:
     alias: incoming mail needs to go through a mail relay
@@ -1189,16 +1314,25 @@ hostgroups:
   high-RTT:
     alias: machines with high round trip times
     private: 1
-  ping-suckers:
-    alias: machines that just suck at icmp
+  alioth:
+    alias: machines that just are just awkward
+    private: 1
+  openstack-compute:
+    alias: nodes that run OpenStack compute
+    private: 1
+  openstack-controller:
+    alias: nodes that run OpenStack controller
     private: 1
 
   security_mirror:
     alias: hosts that are security mirrors
     private: 1
-#############################
-# servicegroups
-#############################
+
+  broken_mq:
+    alias: hosts whose MQ is broken
+    private: 1
+# }}}
+# {{{ ############################# servicegroups #############################
 servicegroups:
   diskspace:
     alias: diskusage checks
@@ -1219,16 +1353,17 @@ servicegroups:
   security:
     alias: security
     servicegroup_members: apt, kernel, samhain
-
-#############################
-# services
-#############################
+  MQ:
+    alias: rabbitMQ stuff
+# }}}
+# {{{ ############################# services #############################
 services:
+  # {{{ ### basic networking
   -
     name: PING
     check: "check_ping!350.0,20%!600.0,40%"
     hostgroups: pingable
-    excludehostgroups: layer3-infrastructure, high-RTT, ping-suckers
+    excludehostgroups: layer3-infrastructure, high-RTT
     normal_check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
@@ -1239,13 +1374,6 @@ services:
     normal_check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
-  -
-    name: PING
-    check: "check_ping!600.0,90%!900.0,95%"
-    hostgroups: ping-suckers
-    normal_check_interval: 5
-    max_check_attempts: 4
-    retry_check_interval: 1
   -
     name: PING
     check: "check_ping!2000.0,60%!3000.0,80%"
@@ -1253,28 +1381,18 @@ services:
     normal_check_interval: 5
     max_check_attempts: 4
     retry_check_interval: 1
-
- ############ Services ############
- ###
-
- ############ Disk Usage ############
- ####
-
+  # }}}
+  # {{{ ### disk usage
   -
     name: disk usage - all
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk -w 5% -c 2%  -A -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs --ignore-eregi-path='/home/buildd/build-tr|/var/lib/schroot/mount'"
     hostgroups: computers
-    excludehosts: sibelius,stabile
-  -
-    name: disk usage - all
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk -w 5% -c 3%  -A -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs --ignore-eregi-path=/srv/snapshot.debian.org"
-    hosts: stabile
+    excludehosts: sibelius
   -
     name: disk usage - all
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs 95 98"
+    nrpe: "/usr/lib/nagios/plugins/check_disk -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs -x /srv/farm-snapshot/farm-misc 95 98"
     hosts: sibelius
 
   -
@@ -1282,12 +1400,6 @@ services:
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /"
     hostgroups: computers
-    excludehosts: spohr
-  -
-    name: disk usage on /
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 90 93 /"
-    hosts: spohr
   -
     name: disk usage on /boot
     servicegroups: diskspace
@@ -1318,16 +1430,11 @@ services:
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /usr"
     hostgroups: hasusrfs
-  -
-    name: disk usage on /home
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /home"
-    hostgroups: hashomefs
   -
     name: disk usage on /var/lib/postgresql
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /var/lib/postgresql"
-    hosts: sibelius, busoni, buxtehude
+    hosts: sibelius, busoni, buxtehude, lw07
   -
     name: disk usage on /var/log
     servicegroups: diskspace
@@ -1342,21 +1449,31 @@ services:
     name: disk usage on /srv/mirrors
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 95 98 /srv/mirrors"
-    hosts: beethoven, sibelius
+    hosts: sibelius
   -
     name: disk usage on /srv/snapshot.debian.org
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 98 99 /srv/snapshot.debian.org"
-    hosts: stabile
+    nrpe: "/usr/lib/nagios/plugins/check_disk 90 94 /srv/snapshot.debian.org"
+    hosts: sibelius
   -
-    name: disk usage on /srv/snapshot.debian.org
+    name: disk usage on /srv/farm-snapshot/farm-1
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 90 94 /srv/snapshot.debian.org"
+    nrpe: "/usr/lib/nagios/plugins/check_disk 97 95 /srv/farm-snapshot/farm-1"
     hosts: sibelius
   -
-    name: disk usage on /srv/farm-snapshot/farm-misc
+    name: disk usage on /srv/farm-snapshot/farm-2
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 97 95 /srv/farm-snapshot/farm-misc"
+    nrpe: "/usr/lib/nagios/plugins/check_disk 97 95 /srv/farm-snapshot/farm-2"
+    hosts: sibelius
+  -
+    name: disk usage on /srv/farm-snapshot/farm-3
+    servicegroups: diskspace
+    nrpe: "/usr/lib/nagios/plugins/check_disk 97 95 /srv/farm-snapshot/farm-3"
+    hosts: sibelius
+  -
+    name: disk usage on /srv/farm-snapshot/farm-4
+    servicegroups: diskspace
+    nrpe: "/usr/lib/nagios/plugins/check_disk 97 95 /srv/farm-snapshot/farm-4"
     hosts: sibelius
   -
     name: disk usage on /var/lib/postgresql/9.1
@@ -1369,89 +1486,164 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_disk 85 95 /srv/ftp-master.debian.org"
     hosts: franck
   -
-    name: disk usage on /srv/pgbackup
+    name: disk usage on /storage/snapshot-farm-1
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 75 85 /srv/pgbackup"
-    hosts: franck
+    nrpe: "/usr/lib/nagios/plugins/check_disk 98 92 /storage/snapshot-farm-1"
+    hosts: lw01
   -
-    name: disk usage on /srv/pgbackup
+    name: disk usage on /storage/snapshot-farm-2
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 85 95 /srv/pgbackup"
-    hosts: beethoven
+    nrpe: "/usr/lib/nagios/plugins/check_disk 98 92 /storage/snapshot-farm-2"
+    hosts: lw02
   -
-    name: disk usage on /srv/git-backup
+    name: disk usage on /storage/snapshot-farm-3
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 85 95 /srv/git-backup"
-    hosts: beethoven
+    nrpe: "/usr/lib/nagios/plugins/check_disk 98 92 /storage/snapshot-farm-3"
+    hosts: lw03
   -
-    name: disk usage on /srv/da-backup
+    name: disk usage on /storage/snapshot-farm-4
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 85 95 /srv/da-backup"
-    hosts: beethoven
+    nrpe: "/usr/lib/nagios/plugins/check_disk 98 92 /storage/snapshot-farm-4"
+    hosts: lw04
   -
-    name: disk usage on /srv/bacula
+    name: disk usage on /srv/morgue.debian.org/
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 85 95 /srv/bacula"
-    hosts: beethoven
-
- ############ All Computers ############
- ####
+    nrpe: "/usr/lib/nagios/plugins/check_disk 95 90 /srv/morgue.debian.org"
+    hosts: lw03
+  # }}}
+  # {{{ ### system
+  # {{{ setup
   -
-    name: apt - security updates
-    servicegroups: apt
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/apt"
+    name: setup - dsa config
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
     hostgroups: computers
-    normal_check_interval:  60
-    retry_check_interval: 15
- ####
+    normal_check_interval: 60
+    excludehostgroups: alioth
   -
-    name: backup
-    servicegroups: backup
-    nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup"
+    name: setup - local hostname etc-hosts
+    nrpe: 'if getent ahosts `hostname` | grep -q 127.0; then echo "Warning: local hostname resolves to 127/8 address"; exit 1; else echo "OK: Hostname resolves to non-127/8 address."; exit 0; fi'
     hostgroups: computers
-    excludehosts: backuphost
     normal_check_interval: 60
-    max_check_attempts: 2
-    retry_check_interval: 5
+  # }}}
+  # {{{ os health
+  ####
   -
-    name: backup server config
-    servicegroups: backup
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server"
-    hosts: beethoven, backuphost
-    normal_check_interval: 60
-    max_check_attempts: 2
-    retry_check_interval: 5
+    name: users
+    nrpe: "/usr/lib/nagios/plugins/check_users 30 35"
+    hostgroups: computers
   -
-    name: backup - bacula - last backup
-    servicegroups: backup
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula $HOSTNAME$.debian.org"
-    runfrom: dinis
+    name: load
+    nrpe: "/usr/lib/nagios/plugins/check_load -w 30,28,26 -c 50,45,50"
     hostgroups: computers
-    excludehostgroups: buildd, porterbox, no-bacula
-    normal_check_interval:  60
-    retry_check_interval: 15
+    excludehostgroups: highload
   -
-    name: backup - bacula - last full backup
-    servicegroups: backup
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula -w 1080 -c 1560 $HOSTNAME$.debian.org F"
-    runfrom: dinis
+    name: load
+    nrpe: "/usr/lib/nagios/plugins/check_load -w 140,120,100 -c 240,220,200"
+    hostgroups: highload
+  -
+    name: uptime check
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-uptime"
     hostgroups: computers
-    excludehostgroups: buildd, porterbox, no-bacula
-    normal_check_interval:  60
-    retry_check_interval: 15
   -
-    name: process - bacula-fd
-    servicegroups: backup
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u bacula -C bacula-fd -a '/usr/sbin/bacula-fd -c /etc/bacula/bacula-fd.conf'"
+    name: processes - total
+    nrpe: "/usr/lib/nagios/plugins/check_procs 620 700"
     hostgroups: computers
-    excludehostgroups: freebsd
+    excludehosts: prokofiev
   -
-    name: process - bacula-fd
+    name: processes - total
+    nrpe: "/usr/lib/nagios/plugins/check_procs 1500 1700"
+    hosts: prokofiev
+  -
+    name: swap usage - percent
+    nrpe: "/usr/lib/nagios/plugins/check_swap -w 20% -c 10%"
+    hostgroups: computers
+  -
+    name: swap usage - mb
+    nrpe: "/usr/lib/nagios/plugins/check_swap -w 20000 -c 5000"
+    hostgroups: computers
+  -
+    name: process - getty
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -C getty -a /sbin/getty"
+    hostgroups: computers
+    excludehosts: zelenka, zandonai
+    excludehostgroups: jessie
+  -
+    name: process - getty
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -C agetty -a /sbin/agetty"
+    hostgroups: computers
+    hostgroups: jessie
+  -
+    name: processes - zombies
+    nrpe: "/usr/lib/nagios/plugins/check_procs 5 10 -s Z"
+    hostgroups: computers
+  -
+    name: system - available entropy
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-entropy"
+    event_handler: dsa_event_handler_restart_ekey
+    hostgroups: computers
+    excludehostgroups: freebsd
+  -
+    name: system - filesystem check
+    nrpe: "/usr/bin/sudo /usr/lib/nagios/plugins/dsa-check-filesystems"
+    normal_check_interval:  60
+    retry_check_interval: 15
+    hostgroups: computers
+  # }}}
+  # {{{ backup
+  -
+    name: backup
+    servicegroups: backup
+    nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup"
+    hostgroups: computers
+    excludehosts: storace
+    normal_check_interval: 60
+    max_check_attempts: 2
+    retry_check_interval: 5
+  -
+    name: backup server config
+    servicegroups: backup
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server"
+    hosts: storace
+    normal_check_interval: 60
+    max_check_attempts: 2
+    retry_check_interval: 5
+  -
+    name: backup - bacula - last backup
+    servicegroups: backup
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula $HOSTNAME$.debian.org"
+    runfrom: dinis
+    hostgroups: computers
+    excludehostgroups: buildd, porterbox, no-bacula
+    normal_check_interval:  60
+    retry_check_interval: 15
+  -
+    name: backup - bacula - last full backup
+    servicegroups: backup
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula -w 1080 -c 1560 $HOSTNAME$.debian.org F"
+    runfrom: dinis
+    hostgroups: computers
+    excludehostgroups: buildd, porterbox, no-bacula
+    normal_check_interval:  60
+    retry_check_interval: 15
+  -
+    name: process - bacula-fd
+    servicegroups: backup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u bacula -C bacula-fd -a '/usr/sbin/bacula-fd -c /etc/bacula/bacula-fd.conf'"
+    hostgroups: computers
+    excludehostgroups: freebsd, alioth
+  -
+    name: process - bacula-fd
     servicegroups: backup
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C bacula-fd -a '/usr/sbin/bacula-fd -c /etc/bacula/bacula-fd.conf'"
     hostgroups: freebsd
 
- ####
+  ####
+  -
+    name: process - acc.umu.se backup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -a 'dsmc'"
+    hosts: sibelius
+  # }}}
+  # {{{ security
   -
     name: running kernel
     servicegroups: kernel
@@ -1459,43 +1651,23 @@ services:
     hostgroups: computers
     normal_check_interval: 60
     retry_check_interval: 5
-
- ####
-#  - name: afs - space
-#    hostgroups: bosserver
-#    nrpe: "/usr/lib/nagios/plugins/dsa-check-afs-space -H localhost"
-#    normal_check_interval: 60
-#    max_check_attempts: 2
-#    retry_check_interval: 5
-#
-#  - name: afs - bos
-#    hostgroups: bosserver
-#    nrpe: "/usr/lib/nagios/plugins/dsa-check-afs-bos -H localhost"
-#    normal_check_interval: 60
-#    max_check_attempts: 2
-#    retry_check_interval: 5
-#
-#  - name: afs - waiting connections
-#    hostgroups: bosserver
-#    nrpe: "/usr/lib/nagios/plugins/dsa-check-afs-rxdebug -H localhost"
-#    normal_check_interval: 60
-#    max_check_attempts: 2
-#    retry_check_interval: 5
-#
-  #- name: afs - udebug
-  #  hostgroups: bosserver
-  #  nrpe: "/usr/lib/nagios/plugins/dsa-check-afs-udebug -H localhost"
-  #  normal_check_interval: 60
-  #  max_check_attempts: 2
-  #  retry_check_interval: 5
-
- ####
-  #-
-  #  name: puppet
-  #  nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -i 540 -f /var/lib/puppet/state/state.yaml"
-  #  hostgroups: computers
-
- ####
+  -
+    name: apt - security updates
+    servicegroups: apt
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/apt"
+    hostgroups: computers
+    normal_check_interval:  60
+    retry_check_interval: 15
+  -
+    name: upgraded libraries
+    servicegroups: security
+    nrpe: "sudo /usr/local/sbin/dsa-check-libs"
+    #nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-libs"
+    hostgroups: computers
+    excludehostgroups: freebsd
+    normal_check_interval:  60
+    retry_check_interval: 15
+    notification_interval: 10080
   -
     name: installed firewall
     nrpe: "/usr/lib/nagios/plugins/dsa-check-file -w -f /etc/ferm/ferm.conf"
@@ -1506,11 +1678,21 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-file -w -f /etc/ferm/conf.d/defs.conf"
     hostgroups: computers
     excludehostgroups: freebsd
- ####
-  - name: ganeti - job watcher paused
-    nrpe: "/usr/lib/nagios/plugins/negate /usr/lib/nagios/plugins/dsa-check-file -f /var/lib/ganeti/watcher.pause"
+  -
+    name: process - ulogd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C ulogd -a '/usr/sbin/ulogd -d'"
     hostgroups: computers
- ####
+    excludehostgroups: freebsd, sparc, jessie
+  -
+    name: process - ulogd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u ulog -C ulogd -a '/usr/sbin/ulogd --daemon --uid ulog'"
+    hostgroups: jessie
+    excludehostgroups: freebsd
+  -
+    name: unexpected process - ulogd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C ulogd"
+    hostgroups: freebsd, sparc
+  ####
   -
     name: process - samhain
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -C samhain -a '/usr/sbin/samhain'"
@@ -1525,64 +1707,49 @@ services:
     normal_check_interval: 60
     retry_check_interval: 5
     excludehostgroups: brokensamhain
- ####
-  -
-    name: process - acc.umu.se backup
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -a 'dsmc'"
-    hosts: sibelius
- ####
-  -
-    name: users
-    nrpe: "/usr/lib/nagios/plugins/check_users 30 35"
-    hostgroups: computers
- ####
-  -
-    name: load
-    nrpe: "/usr/lib/nagios/plugins/check_load -w 30,28,26 -c 50,45,50"
-    hostgroups: computers
-    excludehostgroups: highload
-  -
-    name: load
-    nrpe: "/usr/lib/nagios/plugins/check_load -w 140,120,100 -c 240,220,200"
-    hostgroups: highload
- ####
-  -
-    name: uptime check
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-uptime"
-    hostgroups: computers
- ####
   -
     name: processes - samhain zombies
     nrpe: "/usr/lib/nagios/plugins/check_procs 3 6 -s Z -u root -a samhain"
     event_handler: dsa_event_handler_restart_samhain
     hostgroups: computers
     excludehostgroups: brokensamhain
+  # }}}
+  # {{{ logging
   -
-    name: processes - zombies
-    nrpe: "/usr/lib/nagios/plugins/check_procs 5 10 -s Z"
+    name: process - syslog-ng
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
     hostgroups: computers
- ####
+    excludehostgroups: freebsd, jessie
+
   -
-    name: processes - total
-    nrpe: "/usr/lib/nagios/plugins/check_procs 620 700"
-    hostgroups: computers
- ####
+    name: process - syslog-ng
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:2 -c 2: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
+    hostgroups: freebsd
   -
-    name: swap usage - percent
-    nrpe: "/usr/lib/nagios/plugins/check_swap -w 20% -c 10%"
+    name: process - syslog-ng
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng  -a '/sbin/syslog-ng -F'"
+    hostgroups: jessie
+
+  -
+    name: remote logging on lotti
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
+    runfrom: lotti
     hostgroups: computers
- ####
+    excludehostgroups: alioth
   -
-    name: swap usage - mb
-    nrpe: "/usr/lib/nagios/plugins/check_swap -w 20000 -c 5000"
+    name: remote logging on lully
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
+    runfrom: lully
     hostgroups: computers
- ####
+    excludehostgroups: alioth
   -
-    name: process - getty
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -C getty -a /sbin/getty"
+    name: remote logging on loghost-grnet-01
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
+    runfrom: loghost-grnet-01
     hostgroups: computers
-    excludehosts: zelenka, zandonai
- ####
+    excludehostgroups: alioth
+  # }}}
+  # {{{ base service
   -
     name: process - sshd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:20 -c 1: -u root -C sshd -a '/usr/sbin/sshd'"
@@ -1594,7 +1761,7 @@ services:
     depends: process - sshd
     normal_check_interval:  60
     notification_interval: 1440
- ####
 ####
   -
     name: network service - nrpe
     check: check_tcp!5666
@@ -1607,7 +1774,7 @@ services:
     hostgroups: computers
     max_check_attempts: -1
     depends: network service - nrpe
- ###
 ###
   -
     name: process - munin-node
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a '/usr/sbin/munin-node'"
@@ -1620,14 +1787,14 @@ services:
   -
     name: process - munin-node
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a 'munin-node'"
-    hostgroups: wheezy
+    hostgroups: wheezy, jessie
     excludehostgroups: freebsd
   -
     name: network service - munin-node
     check: check_tcp!4949
     hostgroups: computers
     depends: process - munin-node
- ###
 ###
   -
     name: process - ntpd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -p 1 -C ntpd -a '/usr/sbin/ntpd -p /var/run/ntpd.pid'"
@@ -1638,435 +1805,193 @@ services:
     check: dsa_check_ntp
     hostgroups: computers
     depends: process - ntpd
-    excludehosts: ancina
-    excludehostgroups: deadslow
-    servicegroups: time
-  #
-  -
-    name: network service - time
-    check: dsa_check_time
-    hosts: ancina
-    depends: process - xinetd
     servicegroups: time
-
- ###
+  ###
   -
     name: process - atd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u daemon -C atd -a /usr/sbin/atd"
     hostgroups: computers
- ###
 ###
   -
     name: process - cron
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C cron -a /usr/sbin/cron"
     hostgroups: computers
-
- ###
+  ###
   -
-    name: process - syslog-ng
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
+    name: process - ud-replicated
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C ud-replicated -a '/usr/bin/python /usr/bin/ud-replicated'"
     hostgroups: computers
-    excludehostgroups: freebsd
-
+    excludehostgroups: freebsd, alioth
   -
-    name: process - syslog-ng
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:2 -c 2: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
+    name: process - ud-replicated
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C python2.7 -a '/usr/bin/python /usr/bin/ud-replicated'"
     hostgroups: freebsd
-
+  ###
   -
-    name: remote logging on lotti
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
-    runfrom: lotti
-    hostgroups: computers
-  -
-    name: remote logging on lully
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
-    runfrom: lully
+    name: process - monit
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/bin/monit -d 300 -I -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
     hostgroups: computers
+    excludehostgroups: alioth, jessie
+  ###
   -
     name: MQ connection on rainier
+    servicegroups: MQ
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-mq-connection $HOSTNAME$ ud dsa"
     runfrom: rainier
     hostgroups: computers
     normal_check_interval:  60
     retry_check_interval: 15
+    excludehostgroups: alioth, broken_mq
   -
     name: MQ connection on rapoport
+    servicegroups: MQ
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-mq-connection $HOSTNAME$ ud dsa"
     runfrom: rapoport
     hostgroups: computers
     normal_check_interval:  60
     retry_check_interval: 15
- ### MAIL STUFF
- ###
+    excludehostgroups: alioth, broken_mq
 ###
   -
-    name: process - exim
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u Debian-exim -C exim4 -a '/usr/sbin/exim4 -bd -q'"
+    name: local resolver
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-resolver www.debian.org www.google.com"
     hostgroups: computers
-    excludehostgroups: postfix-hosts, mail-relay
-    excludehosts: master, busoni, quantz, buxtehude
-  -
-    name: process - exim
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:25 -c 1: -u Debian-exim -C exim4 -a '/usr/sbin/exim4 -bd -q'"
-    hostgroups: mail-relay
+    normal_check_interval: 60
   -
-    name: process - exim - total
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:50 -c 1: -C exim4"
+    name: process - unbound
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u unbound -C unbound -a '/usr/sbin/unbound'"
     hostgroups: computers
-    excludehostgroups: postfix-hosts
-    excludehosts: master, busoni, quantz, buxtehude
+    excludehostgroups: alioth
+  ###
   -
-    name: process - exim
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:300 -c 1:500 -C exim4 -a '/usr/sbin/exim4'"
-    hosts: master, busoni, quantz, buxtehude
+    name: process - uptimed
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u daemon -C uptimed -a '/usr/sbin/uptimed'"
+    hostgroups: computers
+  ###
   -
-    name: mail queue
-    nrpe: "/usr/lib/nagios/plugins/check_mailq -M exim -w 1000 -c 2000"
-    hostgroups: heavy-exim
- ###
+    name: process - udevd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -p 1 -C udevd -a 'udevd'"
+    hostgroups: computers
+    excludehostgroups: freebsd, jessie
   -
-    name: process - clamav - clamd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:2 -c 1: -u clamav -C clamd -a '/usr/sbin/clamd'"
-    hostgroups: heavy-exim, heavy-postfix
+    name: process - udevd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -p 1 -C systemd-udevd -a '/lib/systemd/systemd-udevd'"
+    hostgroups: jessie
   -
-    name: service - clamav
-    nrpe: "/usr/lib/nagios/plugins/check_clamd -H /var/run/clamav/clamd.ctl"
-    hostgroups: heavy-exim, heavy-postfix
-    depends: process - clamav - clamd
+    name: unexpected process - udev
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C udevd"
+    hostgroups: freebsd
+  ###
   -
-    name: process - clamav - freshclam
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u clamav -C freshclam -a '/usr/bin/freshclam -d --quiet'"
-    hostgroups: heavy-exim, heavy-postfix
+    name: process - acpid
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C acpid -a '/usr/sbin/acpid'"
+    hostgroups: acpid-hosts
   -
-    name: unwanted process - clamav
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C clamd"
+    name: unexpected process - acpid
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C acpid"
     hostgroups: computers
-    excludehostgroups: heavy-exim, heavy-postfix, deadslow
+    excludehostgroups: acpid-hosts, kvmdomains
+  ###
   -
-    name: unwanted process - freshclam
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C freshclam"
+    name: process - xinetd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C xinetd -a '/usr/sbin/xinetd '"
+    hostgroups: xinetd-hosts
+  -
+    name: unwanted process - xinetd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C xinetd"
     hostgroups: computers
-    excludehostgroups: heavy-exim, heavy-postfix, deadslow
- ###
+    excludehostgroups: xinetd-hosts
 ###
   -
-    name: process - spamd - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
-    hostgroups: spamd
-    excludehosts: picconi
-    excludehostgroups: deadslow
+    name: process - stunnel4 - puppet-ekeyd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:6 -c 1: -u stunnel4 -C stunnel4 -a '/usr/bin/stunnel4 /etc/stunnel/puppet-ekeyd.conf'"
+    hostgroups: wheezy, jessie
+    excludehostgroups: freebsd, alioth
   -
-    name: process - spamd - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
-    hosts: picconi
+    name: process - stunnel4 - puppet-ekeyd is crazy
+    nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-stunnel-sanity"
+    hostgroups: computers
+    excludehostgroups: freebsd, alioth
+    excludehosts: czerny, grnet-node01, storace
+  # }}}
+  # {{{ anti-services
   -
-    name: process - spamd - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 10 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
-    hosts: bendel
-  -
-    name: process - spamd - child
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:11 -c 1: -C spamd -a 'spamd child'"
-    hosts: bendel
-    hostgroups: spamd
-    depends: process - spamd - master
-  #
-  -
-    name: process - spamd - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u debbugs -C spamd -a '/usr/sbin/spamd -d '"
-    hosts: buxtehude
-  -
-    name: process - spamd - child
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:6 -c 1: -u debbugs -C spamd -a 'spamd child'"
-    hosts: buxtehude
-  #
-  -
-    name: unwanted process - spamd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd"
-    hostgroups: computers
-    excludehostgroups: spamd, deadslow
-    excludehosts: bendel, busoni, buxtehude
-
- ###
-  #-
-  #  name: process - greylistd
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u greylist -C greylistd -a '/usr/bin/python /usr/sbin/greylistd'"
-  #  hostgroups: heavy-exim
-  #
-  -
-    name: unwanted process - greylistd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C greylistd"
-    hostgroups: computers
-    excludehostgroups: deadslow
-
- ###
-  -
-    name: process - postgrey
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --unix=/var/run/postgrey/socket --retry-window=4 --auto-whitelist-clients=10 --exim'"
-    hostgroups: heavy-exim
-  -
-    name: process - postgrey
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'"
-    hostgroups: heavy-postfix
-  #
-  -
-    name: unwanted process - postgrey
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C postgrey"
-    hostgroups: computers
-    excludehostgroups: heavy-postfix, heavy-exim, deadslow
- ###
-  -
-    name: process - amavis - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u amavis -a 'amavisd-new (master)'"
-    hostgroups: amavis-hosts
-  -
-    name: process - amavis - all
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1:10 -u amavis -a 'amavisd-new '"
-    hostgroups: amavis-hosts
-    depends: process - amavis - master
-  #
-  -
-    name: unwanted process - amavis
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C amavisd-new"
+    name: ganeti - job watcher paused
+    nrpe: "/usr/lib/nagios/plugins/negate /usr/lib/nagios/plugins/dsa-check-file -f /var/lib/ganeti/watcher.pause"
     hostgroups: computers
-    excludehostgroups: amavis-hosts, deadslow
- ###
-  -
-    name: process - weightd - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u polw -a 'policyd-weight (master)'"
-    hostgroups: heavy-postfix
-  -
-    name: process - weightd - cache
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u polw -a 'policyd-weight (cache)'"
-    hostgroups: heavy-postfix
-    depends: process - weightd - master
-  -
-    name: process - weightd - child
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:50 -c 1: -u polw -a 'policyd-weight (child)'"
-    hostgroups: heavy-postfix
-    depends: process - weightd - master
- ###
   -
-    name: unwanted process - policyd-weight
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C policyd-weight"
+    name: unwanted process - irqbalance
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C irqbalance"
     hostgroups: computers
-    excludehostgroups: heavy-postfix, deadslow
-
-
- ###
-  -
-    name: process - postfix - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C master -a '/usr/lib/postfix/master'"
-    hostgroups: postfix-hosts
-  -
-    name: process - postfix - qmgr
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C qmgr -a 'qmgr -l -t fifo -u'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  #-
-  #  name: process - postfix - tlsmgr
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C tlsmgr -a 'tlsmgr -l -t fifo -u'"
-  #  hostgroups: postfix-hosts
-  #  depends: process - postfix - master
-  -
-    name: process - postfix - pickup
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C pickup -a 'pickup -l -t fifo -u -c'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  -
-    name: process - postfix - anvil
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:1 -c 0: -u postfix -C anvil -a 'anvil -l -t unix -u'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-
-  -
-    name: process - postfix - trivial-rewrite
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:10 -c 0:15 -u postfix -C trivial-rewrite -a 'trivial-rewrite -n rewrite -t unix -u -c'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  -
-    name: process - postfix - proxymap
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:10 -c 0:15 -u postfix -C proxymap -a 'proxymap -t unix -u'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  -
-    name: process - postfix - cleanup
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:30 -c 0:50 -u postfix -C cleanup -a 'cleanup -z -t unix -u -c'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  -
-    name: process - postfix - local
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:30 -c 0:50 -u postfix -C local -a 'local -t unix'"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
   -
     name: unwanted process - openvpn
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C openvpn"
     hostgroups: computers
     normal_check_interval: 120
-
-
- ###
-  -
-    name: network service - smtp
-    check: dsa_check_smtp
-    hostgroups: computers
-    excludehostgroups: postfix-hosts, incomingmailrelayed, incomingmailrelayed2025
-    depends: process - exim
-
-  -
-    name: network service - smtp
-    check: dsa_check_smtp
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-  -
-    name: network service - submission
-    check: dsa_check_smtp_port!587
-    hostgroups: incomingmailrelayed
-    depends: process - exim
-  -
-    name: network service - smtp 2025
-    check: dsa_check_smtp_port!2025
-    hostgroups: incomingmailrelayed2025
-    depends: process - exim
-  -
-    name: network service local - smtps cert
-    nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 465 -S -C 14 -t 45"
-    hostgroups: postfix-hosts
-    depends: process - postfix - master
-    normal_check_interval: 120
-
-  -
-    name: setup - dsa config
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
-    hostgroups: computers
-    normal_check_interval: 60
-  -
-    name: setup - local hostname etc-hosts
-    nrpe: 'if getent ahosts `hostname` | grep -q 127.0; then echo "Warning: local hostname resolves to 127/8 address"; exit 1; else echo "OK: Hostname resolves to non-127/8 address."; exit 0; fi'
-    hostgroups: computers
-    normal_check_interval: 60
-  -
-    name: system - available entropy
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-entropy"
-    event_handler: dsa_event_handler_restart_ekey
-    hostgroups: computers
-    excludehostgroups: freebsd
-  -
-    name: system - filesystem check
-    nrpe: "/usr/bin/sudo /usr/lib/nagios/plugins/dsa-check-filesystems"
-    normal_check_interval:  60
-    retry_check_interval: 15
-    hostgroups: computers
- ###
-  -
-    name: local resolver
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-resolver www.debian.org www.google.com"
-    hostgroups: computers
-    normal_check_interval: 60
-  -
-    name: process - unbound
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u unbound -C unbound -a '/usr/sbin/unbound'"
-    hostgroups: unbound-hosts, squeeze, wheezy
- ###
-  -
-    name: process - uptimed
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u daemon -C uptimed -a '/usr/sbin/uptimed'"
-    hostgroups: computers
- ###
-  -
-    name: unwanted process - irqbalance
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C irqbalance"
-    hostgroups: computers
-    excludehostgroups: deadslow
-
- ####
- ###
-  #-
-  #  name: unwanted process - system-tools-backends
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C system-tools-ba"
-  #  hostgroups: computers
-  #-
-  #  name: unwanted process - dbus-daemon
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C dbus-daemon"
-  #  hostgroups: computers
   -
     name: unwanted process - gkrellmd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C gkrellmd"
     hostgroups: computers
-    excludehostgroups: deadslow
   -
     name: unwanted process - rpc.statd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C rpc.statd"
     hostgroups: computers
-    excludehostgroups: nfs-client, nfs-server, deadslow
+    excludehostgroups: nfs-client, nfs-server
   -
     name: unwanted process - inetd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C inetd"
     hostgroups: computers
-    excludehosts: abel, alwyn
-    excludehostgroups: deadslow
+    excludehosts: abel
   -
     name: unwanted process - snmpd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C snmpd"
     hostgroups: computers
-    excludehostgroups: deadslow
-
- ####
+  # }}}
+  # {{{ ssl certs
   -
     name: "host SSL cert"
     nrpe: "if [ -e /etc/ssl/certs/thishost.pem ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/certs/thishost.pem; else echo 'No thishost.pem on this host.'; fi"
     hostgroups: computers
-
- ############ Processes/Services that only run on some computers ############
- ####
- ###
   -
-    name: process - rngd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rngd  -a '/usr/sbin/rngd -r /dev/hwrng'"
-    hostgroups: dl385
- ###
+    name: "host SSL cert - debian server"
+    nrpe: "if [ -e /etc/ssl/debian/certs/thishost-server.crt ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/debian/certs/thishost-server.crt; else echo 'No thishost-server.crt on this host.'; fi"
+    hostgroups: computers
+  -
+    name: "host SSL cert - debian client"
+    nrpe: "if [ -e /etc/ssl/debian/certs/thishost.crt ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/debian/certs/thishost.crt; else echo 'No thishost.crt on this host.'; fi"
+    hostgroups: computers
+  # }}}
+  # {{{ HW health/raid
   -
     name: process - mdadm monitor
     servicegroups: raid
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C mdadm -a '/sbin/mdadm --monitor --pid-file /var/run/mdadm/monitor.pid --daemonise --scan'"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C mdadm -a '/sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan'"
     hostgroups: sw-raid
-    excludehostgroups: wheezy
+    excludehostgroups: jessie
   -
-    # wheezy:
     name: process - mdadm monitor
     servicegroups: raid
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C mdadm -a '/sbin/mdadm --monitor --pid-file /run/mdadm/monitor.pid --daemonise --scan'"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C mdadm -a '/sbin/mdadm --monitor --scan'"
     hostgroups: sw-raid
-    excludehostgroups: squeeze
+    excludehostgroups: wheezy
   -
     name: RAID - sw raid
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-sw"
     hostgroups: sw-raid
-
- ###
-  -
-    name: process - ud-replicated
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C ud-replicated -a '/usr/bin/python /usr/bin/ud-replicated'"
-    hostgroups: computers
-    excludehostgroups: squeeze,freebsd
   -
-    name: process - ud-replicated
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C python2.7 -a '/usr/bin/python /usr/bin/ud-replicated'"
-    hostgroups: freebsd
-  -
-    name: process - monit
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/sbin/monit -d 300 -I -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
-    hostgroups: squeeze
-  -
-    name: process - monit
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/bin/monit -d 300 -I -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
+    name: RAID - unexpected sw raid
+    servicegroups: raid
+    nrpe: "if [ -e /proc/mdstat ]; then echo 'Found /proc/mdstat'; exit 1; else echo 'No /proc/mdstat on this host.'; fi"
     hostgroups: computers
-    excludehostgroups: squeeze
+    excludehostgroups: sw-raid
+  ###
   -
     name: HW - hpacucli status
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli"
     normal_check_interval: 120
-    hostgroups: dl385, dl380, dl360, bl460
+    hostgroups: dl385, dl380, dl360, bl460, dl180
     excludehosts: schein, rietz
   -
     name: HW - hpacucli status
@@ -2092,166 +2017,280 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli --ignore-transfer-speed=1I:1:1 --ignore-transfer-speed=1I:1:2"
     normal_check_interval: 120
     hostgroups: dl585
- ###
+  ###
+#  -
+#    name: HW - edac status
+#    nrpe: "/usr/lib/nagios/plugins/dsa-check-edac"
+#    normal_check_interval: 120
+    #hostgroups: computers
+    #excludehosts: villa, lobos, schein
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm"
     normal_check_interval: 120
     hostgroups: dl385, dl380, dl360, bl460, dl585, bm-bl
-    excludehosts: villa, lobos, senfl, schein
+    excludehosts: villa, lobos, schein, storace
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --ps-no-redundant"
     normal_check_interval: 120
-    hosts: villa, lobos
+    hosts: villa
+  -
+    name: HW - hpasmcli status
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --ps-no-redundant  --ignore-failed='PS2'"
+    normal_check_interval: 120
+    hosts: lobos
   -
     name: HW - hpasmcli status
     nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --fan-no-redundant"
     normal_check_interval: 120
-    hosts: senfl, schein
- ###
+    hosts: schein
+  -
+    name: HW - hpasmcli status
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-hpasm --fan-ignore-not-present"
+    normal_check_interval: 120
+    hosts: storace
+  ###
   -
     name: RAID - 3ware
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-3ware"
     hosts: powell
- ###
 ###
   -
     name: RAID - aacraid
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-aacraid"
     hostgroups: aacraid
- ###
 ###
   -
     name: RAID - megaraid
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-megaraid"
     hostgroups: megaraid
- ###
-  #-
-  #  name: RAID - 3ware
-  #  servicegroups: raid
-  #  nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-3ware"
-  #  hosts: puccini
- ###
-  -
-    name: RAID - MPT
-    servicegroups: raid
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-mpt"
-    hostgroups: mptraid
-
- ###
-#  -
-#    name: RAID - megactl
-#    servicegroups: raid
-#    nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-megactl"
-#    hostgroups: megactl
- ###
+  ###
   -
     name: RAID - DRBD
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-drbd -d All"
     hostgroups: drbd-hosts
- ###
+  # }}}
+  # }}}
+  # {{{ ### mail stuff
+  # {{{ exim processes and mailq
   -
-    name: process - slapd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:20 -c 1:50 -u openldap -C slapd -a '/usr/sbin/slapd -h ldap:/// ldaps:/// -g openldap -u openldap'"
-    hosts: draghi
+    name: process - exim
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u Debian-exim -C exim4 -a '/usr/sbin/exim4 -bd -q'"
+    hostgroups: computers
+    excludehostgroups: postfix-hosts, mail-relay
+    excludehosts: master, busoni, quantz, buxtehude
   -
-    name: network service - ldaps cert
-    check: dsa_check_cert!636
-    depends: process - slapd
-    normal_check_interval: 60
-    hosts: draghi
- ###
+    name: process - exim
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:25 -c 1: -u Debian-exim -C exim4 -a '/usr/sbin/exim4 -bd -q'"
+    hostgroups: mail-relay
   -
-    name: process - ulogd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C ulogd -a '/usr/sbin/ulogd -d'"
+    name: process - exim - total
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:50 -c 1: -C exim4"
     hostgroups: computers
-    excludehostgroups: freebsd, sparc
+    excludehostgroups: postfix-hosts
+    excludehosts: master, busoni, quantz, buxtehude
   -
-    name: unexpected process - ulogd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C ulogd"
-    hostgroups: freebsd, sparc
+    name: process - exim
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:300 -c 1:500 -C exim4 -a '/usr/sbin/exim4'"
+    hosts: master, busoni, quantz, buxtehude
+  -
+    name: mail queue
+    nrpe: "/usr/lib/nagios/plugins/check_mailq -M exim -w 1000 -c 2000"
+    hostgroups: heavy-exim
+  # }}}
+  # {{{ clamav
+  -
+    name: process - clamav - clamd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:2 -c 1: -u clamav -C clamd -a '/usr/sbin/clamd'"
+    hostgroups: heavy-exim, heavy-postfix
+  -
+    name: service - clamav
+    nrpe: "/usr/lib/nagios/plugins/check_clamd -H /var/run/clamav/clamd.ctl"
+    hostgroups: heavy-exim, heavy-postfix
+    depends: process - clamav - clamd
+  -
+    name: process - clamav - freshclam
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u clamav -C freshclam -a '/usr/bin/freshclam -d --quiet'"
+    hostgroups: heavy-exim, heavy-postfix
+  -
+    name: unwanted process - clamav
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C clamd"
+    hostgroups: computers
+    excludehostgroups: heavy-exim, heavy-postfix
+  -
+    name: unwanted process - freshclam
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C freshclam"
+    hostgroups: computers
+    excludehostgroups: heavy-exim, heavy-postfix
+  # }}}
+  # {{{ anti-spam
+  -
+    name: process - spamd - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
+    hostgroups: spamd
+    excludehosts: picconi
+  -
+    name: process - spamd - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
+    hosts: picconi
+  -
+    name: process - spamd - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 10 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
+    hosts: bendel
+  -
+    name: process - spamd - child
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:11 -c 1: -C spamd -a 'spamd child'"
+    hosts: bendel
+    hostgroups: spamd
+    depends: process - spamd - master
+  #
+  -
+    name: unwanted process - spamd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd"
+    hostgroups: computers
+    excludehostgroups: spamd
+    excludehosts: bendel, busoni
 
- ###
   -
-    name: process - udevd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -p 1 -C udevd -a 'udevd'"
+    name: unwanted process - greylistd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C greylistd"
     hostgroups: computers
-    excludehostgroups: freebsd
+
+  ###
+  -
+    name: process - postgrey
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --unix=/var/run/postgrey/socket --retry-window=4 --auto-whitelist-clients=10 --exim'"
+    hostgroups: heavy-exim
+  -
+    name: process - postgrey
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'"
+    hostgroups: heavy-postfix
+  #
+  -
+    name: unwanted process - postgrey
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C postgrey"
+    hostgroups: computers
+    excludehostgroups: heavy-postfix, heavy-exim
+  ###
+  -
+    name: process - amavis - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u amavis -a 'amavisd-new (master)'"
+    hostgroups: amavis-hosts
+  -
+    name: process - amavis - all
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1:10 -u amavis -a 'amavisd-new '"
+    hostgroups: amavis-hosts
+    depends: process - amavis - master
+  #
+  -
+    name: unwanted process - amavis
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C amavisd-new"
+    hostgroups: computers
+    excludehostgroups: amavis-hosts
+  ###
+  -
+    name: process - weightd - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u polw -a 'policyd-weight (master)'"
+    hostgroups: heavy-postfix, alioth
+  -
+    name: process - weightd - cache
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u polw -a 'policyd-weight (cache)'"
+    hostgroups: heavy-postfix, alioth
+    depends: process - weightd - master
+  -
+    name: process - weightd - child
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:50 -c 1: -u polw -a 'policyd-weight (child)'"
+    hostgroups: heavy-postfix, alioth
+    depends: process - weightd - master
+  ###
+  -
+    name: unwanted process - policyd-weight
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C policyd-weight"
+    hostgroups: computers
+    excludehostgroups: heavy-postfix, alioth
+  # }}}
+  # {{{ postfix
+  ###
+  -
+    name: process - postfix - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C master -a '/usr/lib/postfix/master'"
+    hostgroups: postfix-hosts
   -
-    name: unexpected process - udev
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C udevd"
-    hostgroups: freebsd
- ###
+    name: process - postfix - qmgr
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C qmgr -a 'qmgr -l -t fifo -u'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: process - acpid
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C acpid -a '/usr/sbin/acpid'"
-    hostgroups: acpid-hosts
+    name: process - postfix - pickup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C pickup -a 'pickup -l -t fifo -u -c'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: unexpected process - acpid
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C acpid"
-    hostgroups: computers
-    excludehostgroups: acpid-hosts, kvmdomains
- ###
-#  -
-#    name: process - bosserver
-#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C bosserver -a '/usr/sbin/bosserver'"
-#    hostgroups: bosserver
-#
- ###
+    name: process - postfix - anvil
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:1 -c 0: -u postfix -C anvil -a 'anvil -l -t unix -u'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
+
   -
-    name: process - xinetd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C xinetd -a '/usr/sbin/xinetd -pidfile /var/run/xinetd.pid -stayalive'"
-    hostgroups: xinetd-hosts
+    name: process - postfix - trivial-rewrite
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:10 -c 0:15 -u postfix -C trivial-rewrite -a 'trivial-rewrite -n rewrite -t unix -u -c'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: unwanted process - xinetd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C xinetd"
-    hostgroups: computers
-    excludehostgroups: xinetd-hosts, deadslow
- ###
+    name: process - postfix - proxymap
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:10 -c 0:15 -u postfix -C proxymap -a 'proxymap -t unix -u'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: network service - finger
-    check: check_tcp!79
-    hosts: draghi
-    depends: process - xinetd
- ###
+    name: process - postfix - cleanup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:30 -c 0:50 -u postfix -C cleanup -a 'cleanup -z -t unix -u -c'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: network service - rsync
-    check: check_tcp!873
-    hostgroups: rsyncd-hosts
-    depends: process - xinetd
-    excludehosts: rietz
+    name: process - postfix - local
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:30 -c 0:50 -u postfix -C local -a 'local -t unix'"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
+
   -
-    name: network service - rsync
-    check: check_tcp!873
-    hosts: rietz2
-    depends: rietz:process - xinetd
+    name: network service local - smtps cert
+    nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 465 -S -C 14 -t 45"
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
+    normal_check_interval: 120
+  # }}}
+  # {{{ mail - network service
   -
-    name: network service - rsync
-    check: check_tcp!873
-    hosts: milanollo2
-    depends: milanollo:process - xinetd
+    name: network service - smtp
+    check: dsa_check_smtp
+    hostgroups: computers
+    excludehostgroups: postfix-hosts, incomingmailrelayed, incomingmailrelayed2025
+    depends: process - exim
 
- ###
   -
-    name: process - icinga
-    # there is always one extra process per check currently running..
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:30 -c 1: -u nagios -C icinga -a '/usr/sbin/icinga -d /etc/icinga/icinga.cfg'"
-    hosts: tchaikovsky
- ###
+    name: network service - smtp
+    check: dsa_check_smtp
+    hostgroups: postfix-hosts
+    depends: process - postfix - master
   -
-    name: process - jetty - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -a 'jsvc.exec'"
-    hostgroups: jetty-hosts
+    name: network service - submission
+    check: dsa_check_smtp_port!587
+    hostgroups: incomingmailrelayed
+    depends: process - exim
   -
-    name: process - jetty - worker
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:50 -c 1:100 -u jetty -a 'jsvc.exec -user jetty'"
-    hostgroups: jetty-hosts
-    depends: process - jetty - master
-
- ###
+    name: network service - smtp 2025
+    check: dsa_check_smtp_port!2025
+    hostgroups: incomingmailrelayed2025
+    depends: process - exim
+  # }}}
+  # }}}
+  # {{{ ### host specific services
+  # {{{ HTTP
   -
     name: process - apache2 - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -a /usr/sbin/apache2"
@@ -2265,7 +2304,7 @@ services:
     name: unwanted process - apache2
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C apache2"
     hostgroups: computers
-    excludehostgroups: apache2-hosts, deadslow
+    excludehostgroups: apache2-hosts
 
   -
     name: network service - http
@@ -2317,46 +2356,12 @@ services:
     name: unwanted network service - https
     check: dsa_check_port_closed!443
     hostgroups: apache2-hosts
-    excludehostgroups: apache-https, deadslow
+    excludehostgroups: apache-https
     # ravel does ssh on port 443
     excludehosts: ravel
     normal_check_interval: 60
-
-###
-  -
-    name: process - varnish - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C varnishd -a '/usr/sbin/varnishd -P /var/run/varnishd.pid -a :80 -T localhost:6082 -f /etc/varnish/default.vcl'"
-    hostgroups: varnish-hosts
-  -
-    name: process - varnish - worker
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u nobody -C varnishd -a '/usr/sbin/varnishd -P /var/run/varnishd.pid -a :80 -T localhost:6082 -f /etc/varnish/default.vcl'"
-    hostgroups: varnish-hosts
-    depends: process - varnish - master
-  -
-    name: network service - http
-    check: check_http
-    hostgroups: varnish-hosts
-    depends: process - varnish - master
-
-###
-
- ####
-  -
-    name: process - named
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:15 -c 1: -u bind -C named -a '/usr/sbin/named -u bind'"
-    hostgroups: bind9-hosts
-  -
-    name: network service - dns
-    check: check_dns
-    hostgroups: bind9-hosts
-    depends: process - named
-  -
-    name: unwanted process - named
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C named"
-    hostgroups: computers
-    excludehostgroups: bind9-hosts, deadslow
-
- ####
+  # }}}
+  # {{{ FTP
   -
     name: network service - ftp
     check: check_ftp
@@ -2367,43 +2372,13 @@ services:
     check: check_ftp
     hosts: klecker-ftp
     depends: klecker:process - xinetd
-
- ####
-  #-
-  #  name: process - debianqueued
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u dak -C debianqueued"
-  -
-    name: process - debianqueued
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u dak-unpriv -C debianqueued"
-    hostgroups: uploadqueue
-
-
- ###
-  #-
-  #  name: process - postgresql81 - master
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a '/usr/lib/postgresql/8.1/bin/postmaster -D /var/lib/postgresql/8.1/main -c config_file=/etc/postgresql/8.1/main/postgresql.conf'"
-  #  hostgroups: postgres81-hosts
-  #-
-  #  name: process - postgresql81 - writer
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: writer process'"
-  #  hostgroups: postgres81-hosts
-  #  depends: process - postgresql81 - master
-  #-
-  #  name: process - postgresql81 - buffer
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats buffer process'"
-  #  hostgroups: postgres81-hosts
-  #  depends: process - postgresql81 - master
-  #-
-  #  name: process - postgresql81 - collector
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats collector process'"
-  #  hostgroups: postgres81-hosts
-  #  depends: process - postgresql81 - master
- ####
+  # }}}
+  # {{{ postgres
   -
     name: unwanted process - postgresql
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0 -C postgres"
     hostgroups: computers
-    excludehostgroups: postgres91-hosts, deadslow
+    excludehostgroups: postgres91-hosts
   -
     name: unwanted process - postgresql 9.0
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0 -C postgres -a '9.0/bin/postgres'"
@@ -2415,39 +2390,33 @@ services:
   -
     name: postgresql backups
     nrpe: "/usr/bin/sudo -u debbackup /usr/lib/nagios/plugins/dsa-check-backuppg"
-    #hosts: beethoven
-    hosts: backuphost
- ####
- ####
-  -
-    name: process - stunnel4 - puppet-ekeyd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:6 -c 1: -u stunnel4 -C stunnel4 -a '/usr/bin/stunnel4 /etc/stunnel/puppet-ekeyd.conf'"
-    hostgroups: squeeze, wheezy
-    excludehostgroups: freebsd
- ####
-  -
-    name: process - UPS - nut usbhid-ups - ups1
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C usbhid-ups  -a '/lib/nut/usbhid-ups -a ups1'"
-    hosts: franck
-  -
-    name: process - UPS - nut upsd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C upsd  -a '/sbin/upsd'"
-    hosts: franck
-  -
-    name: process - UPS - nut upsmon master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C upsmon  -a '/sbin/upsmon'"
-    hosts: franck
-  -
-    name: process - UPS - nut upsmon worker
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C upsmon  -a '/sbin/upsmon'"
-    hosts: franck
-    depends: process - UPS - nut upsmon master
-  -
-    name: UPS - on line power
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-ups"
-    hosts: franck
-    depends: process - UPS - nut upsd
- ###
+    hosts: storace
+  # }}}
+  # {{{ power
+#  -
+#    name: process - UPS - nut usbhid-ups - ups1
+#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C usbhid-ups  -a '/lib/nut/usbhid-ups -a ups1'"
+#    hosts: franck
+#  -
+#    name: process - UPS - nut upsd
+#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C upsd  -a '/sbin/upsd'"
+#    hosts: franck
+#  -
+#    name: process - UPS - nut upsmon master
+#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C upsmon  -a '/sbin/upsmon'"
+#    hosts: franck
+#  -
+#    name: process - UPS - nut upsmon worker
+#    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nut -C upsmon  -a '/sbin/upsmon'"
+#    hosts: franck
+#    depends: process - UPS - nut upsmon master
+#  -
+#    name: UPS - on line power
+#    nrpe: "/usr/lib/nagios/plugins/dsa-check-ups"
+#    hosts: franck
+#    depends: process - UPS - nut upsd
+  # }}}
+  # {{{ buildd
   -
     name: process - buildd
     servicegroups: buildd
@@ -2463,7 +2432,6 @@ services:
     contact_groups: buildd
   -
     name: processes - zombie schroot
-    #nrpe: "/usr/lib/nagios/plugins/check_procs -a schroot -s Zs -c 0"
     nrpe: "(/usr/lib/nagios/plugins/check_procs -a schroot -s Zs -c 0 > /dev/null || /usr/lib/nagios/plugins/check_procs -a schroot -s Zs -c 0) && /usr/lib/nagios/plugins/check_procs -a schroot -s ZNs -c 0"
     hostgroups: buildd
     contact_groups: +buildd
@@ -2475,21 +2443,8 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -m 'ELAPSED' -c 500 -C lvcreate -u root -a 'lvcreate'"
     hostgroups: buildd
     contact_groups: +buildd
- ####
-  -
-    name: network service - gobby
-    check: check_tcp!6523
-    hosts: gombert
-    contact_groups: gobby
- ####
-  #-
-  #  name: process - tftpd
-  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C in.tftpd -a '/usr/sbin/in.tftpd -l -B 1450 -s /var/lib/tftpboot'"
-  #  hostgroups: tftpd-hosts
- ###
-
- ############ NFS Stuff ############
- ####
+  # }}}
+  # {{{ NFS Stuff
   -
     name: process - statd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u statd -C rpc.statd -a '/sbin/rpc.statd'"
@@ -2506,10 +2461,6 @@ services:
     name: process - mountd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rpc.mountd -a '/sbin/rpc.mountd'"
     hostgroups: nfs-server
-  -
-    name: nfs server glinka reachable
-    nrpe: "/usr/lib/nagios/plugins/check_ping -H 192.168.2.76 -w 50,10% -c 200,30%"
-    hosts: quantz
   #
   -
     name: process - automount
@@ -2519,17 +2470,9 @@ services:
     name: unwanted process - automount
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0 -C automount"
     hostgroups: computers
-    excludehostgroups: autofs, deadslow
-
- ############ MISC OTHER Stuff ############
- #####
-  -
-    name: puppetmaster cert
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem"
-    hosts: handel
-    normal_check_interval: 60
-    max_check_attempts: 2
-    retry_check_interval: 5
+    excludehostgroups: autofs
+  # }}}
+  # {{{ mirroring
   -
     name: mirror sync - bugs
     check: "dsa_check_mirrorsync_skew!bugs.debian.org!project/trace/bugs-master.debian.org!120:600"
@@ -2552,6 +2495,23 @@ services:
     normal_check_interval: 15
     max_check_attempts: 5
     retry_check_interval: 5
+  # }}}
+  # {{{ DNS
+  -
+    name: process - named
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:15 -c 1: -u bind -C named -a '/usr/sbin/named '"
+    hostgroups: bind9-hosts
+  -
+    name: network service - dns
+    check: check_dns
+    hostgroups: bind9-hosts
+    depends: process - named
+  -
+    name: unwanted process - named
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C named"
+    hostgroups: computers
+    excludehostgroups: bind9-hosts
+  ###
   -
     name: DNS SOA sync - debian.org
     check: "dsa_check_soas_add!denis.debian.org!debian.org"
@@ -2564,17 +2524,13 @@ services:
     name: DNS SOA sync - debian.com
     check: "dsa_check_soas_add!denis.debian.org!debian.com"
     hosts: global
-  -
-    name: DNS SOA sync - mirror.debian.net
-    check: "dsa_check_soas_add!denis.debian.org!mirror.debian.net"
-    hosts: global
   -
     name: DNS SOA sync - 144-28.118.59.86.in-addr.arpa
     check: "dsa_check_soas_add!denis.debian.org!144-28.118.59.86.in-addr.arpa"
     hosts: global
   -
     name: DNS SOA sync - alioth.debian.org
-    check: "dsa_check_soas_add!alioth.debian.org!alioth.debian.org"
+    check: "dsa_check_soas_add!denis.debian.org!alioth.debian.org"
     hosts: global
   -
     name: DNS - delegation and signature expiry
@@ -2596,8 +2552,8 @@ services:
     hosts: global
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-statusfile /srv/dns.debian.org/var/nagios/ds"
     runfrom: denis
-
- ############
+  # }}}
+  # {{{ storage
   -
     name: ping alive check
     remotecheck: "/usr/lib/nagios/plugins/check_ping -H $HOSTADDRESS$ -w 50,10% -c 200,30%"
@@ -2613,15 +2569,143 @@ services:
     hosts: giustini
   -
     name: event log
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=7778 $HOSTADDRESS$ public"
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=9966 $HOSTADDRESS$ public"
     runfrom: dijkstra
     hosts: giustini
- ############
+  # }}}
+  # {{{ porterbox
   -
     name: current chroots
     nrpe: "/usr/lib/nagios/plugins/dsa-check-dchroots-current"
     hostgroups: porterbox
     normal_check_interval:  60
     retry_check_interval: 15
+  # }}}
+  # {{{ openstack
+  -
+    name: process - openstack - memcached
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nobody -C memcached -a '/usr/bin/memcached -m 128 -p 11211 -u nobody -l 0.0.0.0'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - glance-registry
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u glance -C glance-registry -a '/usr/bin/python /usr/bin/glance-registry'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-api
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-api -a '/usr/bin/python /usr/bin/nova-api --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-api.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-compute
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-compute -a '/usr/bin/python /usr/bin/nova-compute --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-compute.log --config-file=/etc/nova/nova-compute.conf'"
+    hostgroups: openstack-compute
+  -
+    name: process - openstack - nova-cert
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-cert -a '/usr/bin/python /usr/bin/nova-cert --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-cert.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-conductor
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -C nova-conductor -a '/usr/bin/python /usr/bin/nova-conductor --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-conductor.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-consoleauth
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -a '/usr/bin/python /usr/bin/nova-consoleauth --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-consoleauth.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-scheduler
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -a '/usr/bin/python /usr/bin/nova-scheduler --config-file=/etc/nova/nova.conf --log-file /var/log/nova/nova-scheduler.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - nova-spicehtml5proxy
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u nova -a '/usr/bin/python /usr/bin/nova-spicehtml5proxy --log-file /var/log/nova/nova-consoleproxy.log'"
+    hostgroups: openstack-controller
+  -
+    name: process - openstack - neutron-server
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u neutron -C neutron-server -a '/usr/bin/python2.7 /usr/bin/neutron-server --config-file=/etc/neutron/neutron.conf --config-file /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini --log-file=/var/log/neutron/neutron-server.log'"
+    hostgroups: openstack-controller
+  # }}}
+  # {{{ misc
+#  -
+#    Disable this check until logind and binfmt_misc issues are fixed
+#    something unknown is triggering mount of binfmt_misc
+#    https://bugs.debian.org/772700
+#    name: system - all services running
+#    nrpe: "/usr/bin/sudo /bin/systemctl is-system-running"
+#    hostgroups: jessie
+  ###
+  -
+    name: process - rngd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rngd  -a '/usr/sbin/rngd -r /dev/hwrng'"
+    hostgroups: dl385
+  ###
+  -
+    name: process - slapd
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:20 -c 1:50 -u openldap -C slapd -a '/usr/sbin/slapd -h ldap:/// ldaps:/// -g openldap -u openldap'"
+    hosts: draghi
+  -
+    name: network service - ldaps cert
+    check: dsa_check_cert!636
+    depends: process - slapd
+    normal_check_interval: 60
+    hosts: draghi
+  ###
+  -
+    name: network service - finger
+    check: check_tcp!79
+    hosts: draghi
+    depends: process - xinetd
+  ###
+  -
+    name: network service - rsync
+    check: check_tcp!873
+    hostgroups: rsyncd-hosts
+    depends: process - xinetd
+    excludehosts: rietz
+  -
+    name: network service - rsync
+    check: check_tcp!873
+    hosts: rietz2
+    depends: rietz:process - xinetd
+  -
+    name: network service - rsync
+    check: check_tcp!873
+    hosts: milanollo2
+    depends: milanollo:process - xinetd
+  ###
+  -
+    name: process - icinga
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:30 -c 1: -u nagios -C icinga -a '/usr/sbin/icinga -d /etc/icinga/icinga.cfg'"
+    hosts: tchaikovsky
+  ###
+  -
+    name: process - debianqueued
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u dak-unpriv -C debianqueued"
+    hostgroups: uploadqueue
+  ####
+  -
+    name: network service - gobby
+    check: check_tcp!6523
+    hosts: gombert
+    contact_groups: gobby
+  ####
+  -
+    name: network service - sip-tls cert - 443
+    check: dsa_check_cert!443
+    normal_check_interval: 60
+    hosts: vogler
+  -
+    name: network service - sip-tls cert - 5061
+    check: dsa_check_cert!5061
+    normal_check_interval: 60
+    hosts: vogler
+  ####
+  -
+    name: puppetmaster cert
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem"
+    hosts: handel
+    normal_check_interval: 60
+    max_check_attempts: 2
+    retry_check_interval: 5
+  # }}}
+# }}}
 
 # vim: set ts=2 sw=2 et ai si fdm=marker: