remove weak ssh keys check
[mirror/dsa-nagios.git] / config / nagios-master.cfg
index 026f61c..5e8a1a9 100644 (file)
@@ -77,17 +77,21 @@ servers:
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-karlsruhe:
-    address: 129.143.166.229
+    address: 129.143.57.177
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-man-da:
     address: 82.195.75.126
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
-  gw-marist:
+  gw-marist0:
     address: 148.100.96.1
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
+  gw-marist:
+    address: 148.100.88.1
+    parents: gw-ubcece
+    hostgroups: layer3-infrastructure
   gw-osuosl:
     address: 140.211.166.1
     parents: gw-ubcece
@@ -113,12 +117,6 @@ servers:
     address: 86.59.118.145
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
-  gw-telegraaf2:
-    address: 217.196.40.15
-    parents: gw-ubcece
-    hostgroups: layer3-infrastructure
-    contact_groups: +alioth-admins
-    no-servicegroups: true
   gw-ubcece:
     address: 206.12.19.254
     hostgroups: layer3-infrastructure
@@ -137,7 +135,8 @@ servers:
     hostgroups: layer3-infrastructure
   gw-ynic:
     # really janet, because ynic is stupid about firewalling
-    address: 146.97.42.26
+    #address: 146.97.42.26
+    address: 146.97.41.66
     parents: gw-ubcece
     hostgroups: layer3-infrastructure
   gw-zivit:
@@ -241,10 +240,6 @@ servers:
     address: 138.16.160.12
     parents: gw-brown
     hostgroups: computers, service, apache2-hosts, dl380, rsyncd-hosts, postgres91-hosts, spamd, heavy-exim, acpid-hosts, uploadqueue, xinetd-hosts, apache-https, hassrvfs, wheezy
-  ries:
-    address: 138.16.160.9
-    parents: gw-brown
-    hostgroups: computers, service, dl385, acpid-hosts, xinetd-hosts, hassrvfs, wheezy, postgres91-hosts
   # }}}
   # {{{ gw-bytemark
   bm-bl1:
@@ -303,7 +298,7 @@ servers:
   pejacevic:
     address: 5.153.231.6
     parents: gw-bytemark
-    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs
+    hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, apache-https
     contacts: holger
   piu-slave-bm-a:
     address: 5.153.231.7
@@ -330,6 +325,50 @@ servers:
     address: 5.153.231.13
     parents: gw-bytemark
     hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts
+  petrova:
+    address: 5.153.231.25
+    parents: gw-bytemark
+    hostgroups: computers, kvmdomains, wheezy, apache2-hosts
+  couper:
+    address: 5.153.231.14
+    parents: gw-bytemark
+    hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs
+  rainier:
+    address: 5.153.231.15
+    parents: gw-bytemark
+    hostgroups: computers, kvmdomains, wheezy, no-bacula
+  rapoport:
+    address: 5.153.231.16
+    parents: gw-bytemark
+    hostgroups: computers, kvmdomains, wheezy, no-bacula
+  delfin:
+    address: 5.153.231.17
+    parents: gw-bytemark
+    hostgroups: computers, hassrvfs, kvmdomains, wheezy, apache2-hosts
+  wuiet:
+    address: 5.153.231.18
+    parents: gw-bytemark
+    hostgroups: computers, general, kvmdomains, wheezy, service, apache-https, apache2-hosts, heavy-exim, xinetd-hosts
+  dinis:
+    address: 5.153.231.19
+    parents: gw-bytemark
+    hostgroups: computers, general, kvmdomains, wheezy
+  donizetti:
+    address: 5.153.231.20
+    parents: gw-bytemark
+    hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs
+  dillon:
+    address: 5.153.231.22
+    parents: gw-bytemark
+    hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs
+  ticharich:
+    address: 5.153.231.23
+    parents: gw-bytemark
+    hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs, apache2-hosts, apache-https, service
+  diamond:
+    address: 5.153.231.24
+    parents: gw-bytemark
+    hostgroups: computers, service, kvmdomains, wheezy, bind9-hosts, no-bacula
   # }}}
   # {{{ gw-c3sl
   santoro:
@@ -411,10 +450,6 @@ servers:
     address: 194.177.211.205
     parents: gw-grnet
     hostgroups: computers, acpid-hosts, mptraid, hassrvfs, service, squeeze
-  grieg:
-    address: 194.177.211.200
-    parents: gw-grnet
-    hostgroups: computers, apache2-hosts, acpid-hosts, megaraid, heavy-exim, postgres84-hosts, service, apache-https, squeeze
   orff:
     address: 194.177.211.209
     parents: gw-grnet
@@ -442,16 +477,6 @@ servers:
     contacts: pkern
   # }}}
   # {{{ gw-man-da
-  agricola:
-    address: 82.195.75.86
-    parents: gw-man-da
-    hostgroups: computers, porterbox, sw-raid, hassrvfs, wheezy
-    contacts: bzed
-  arcadelt:
-    address: 82.195.75.87
-    parents: gw-man-da
-    hostgroups: computers, buildd, sw-raid, hassrvfs, wheezy
-    contacts: bzed
   ball:
     address: 82.195.75.70
     parents: gw-man-da
@@ -468,7 +493,7 @@ servers:
   bendel:
     address: 82.195.75.100
     parents: ganeti3
-    hostgroups: computers, service, hasbootfs, kvmdomains, hassrvfs, apache2-hosts, squeeze, postfix-hosts, heavy-postfix, acpid-hosts, apache-https, amavis-hosts, hasvarlogfs
+    hostgroups: computers, service, hasbootfs, kvmdomains, hassrvfs, apache2-hosts, wheezy, postfix-hosts, heavy-postfix, acpid-hosts, apache-https, amavis-hosts, hasvarlogfs
   master:
     address: 82.195.75.110
     parents: ganeti3
@@ -499,10 +524,6 @@ servers:
     address: 82.195.75.102
     parents: gw-man-da
     hostgroups: computers, service, dl360, acpid-hosts, wheezy
-  diamond:
-    address: 82.195.75.108
-    parents: ganeti3
-    hostgroups: computers, service, kvmdomains, wheezy, bind9-hosts, no-bacula
   draghi:
     address: 82.195.75.106
     parents: ganeti3
@@ -519,6 +540,10 @@ servers:
     address: 82.195.75.107
     parents: ganeti3
     hostgroups: computers, service, apache2-hosts, rsyncd-hosts, kvmdomains, xinetd-hosts, wheezy
+  stockhausen:
+    address: 82.195.75.108
+    parents: ganeti3
+    hostgroups: computers, service, kvmdomains, wheezy, acpid-hosts, jetty-hosts
   ganeti3:
     address: 82.195.75.111
     parents: gw-man-da
@@ -526,7 +551,7 @@ servers:
   wilder:
     address: 82.195.75.112
     parents: ganeti3
-    hostgroups: computers, service, hassrvfs, apache2-hosts, kvmdomains, wheezy, acpid-hosts, apache2-hosts, apache-https, rsyncd-hosts, xinetd-hosts
+    hostgroups: computers, service, hassrvfs, apache2-hosts, kvmdomains, wheezy, acpid-hosts, apache-https, rsyncd-hosts, xinetd-hosts
   vieuxtemps:
     address: 82.195.75.113
     parents: ganeti3
@@ -535,12 +560,20 @@ servers:
     address: 82.195.75.114
     parents: ganeti3
     hostgroups: computers, service, kvmdomains, wheezy, spamd, heavy-exim, mail-relay
+  denis:
+    address: 82.195.75.91
+    parents: ganeti3
+    hostgroups: computers, service, kvmdomains, wheezy, bind9-hosts
   # }}}
   # {{{ gw-marist
   zappa:
     address: 148.100.96.103
-    parents: gw-marist
+    parents: gw-marist0
     hostgroups: computers, buildd, hassrvfs, squeeze, incomingmailrelayed
+  zani:
+    address: 148.100.88.22
+    parents: gw-marist
+    hostgroups: computers, buildd, hassrvfs, wheezy
   # }}}
   # {{{ gw-osuosl
   busoni:
@@ -587,7 +620,7 @@ servers:
   caballero:
     address: 193.201.200.200
     parents: gw-rapidswitch
-    hostgroups: computers, buildd, sw-raid, squeeze
+    hostgroups: computers, buildd, sw-raid, wheezy, hassrvfs, acpid-hosts
   # }}}
   # {{{ gw-sanger
   sibelius:
@@ -625,26 +658,6 @@ servers:
     parents: gw-sil
     hostgroups: computers, buildd, wheezy
   # }}}
-  # {{{ gw-telegraaf2
-  vasks:
-    address: 217.196.43.140
-    parents: gw-telegraaf2
-    hostgroups: computers, nfs-server, postgres91-hosts, apache2-hosts, acpid-hosts, apache-https, brokensamhain
-    contact_groups: alioth-admins
-    no-servicegroups: true
-  wagner:
-    address: 217.196.43.132
-    parents: gw-telegraaf2
-    hostgroups: computers, bind9-hosts, apache2-hosts, nfs-client, xinetd-hosts, postgres91-hosts, apache-https, dl385, brokensamhain
-    contact_groups: alioth-admins
-    no-servicegroups: true
-  anonscm:
-    address: 217.196.43.132
-    parents: wagner
-    contact_groups: alioth-admins
-    hostgroups: secondary-IPs
-    no-servicegroups: true
-  # }}}
   # {{{ gw-ubcece
   sw-ubcece:
     hostgroups: layer2-infrastructure
@@ -704,10 +717,6 @@ servers:
     address: 206.12.19.118
     parents: ganeti2
     hostgroups: computers, general, apache2-hosts, hasbootfs, kvmdomains, apache-https, wheezy
-  dinis:
-    address: 206.12.19.139 
-    parents: ganeti2
-    hostgroups: computers, general, kvmdomains, wheezy
   wolkenstein:
     address: 206.12.19.116
     parents: ganeti2
@@ -727,7 +736,7 @@ servers:
   paganini:
     address: 206.12.19.10
     parents: sw-ubcece-kais
-    hostgroups: computers, hasbootfs, aacraid, hassrvfs, xinetd-hosts, nfs-client, service, apache2-hosts, squeeze, autofs
+    hostgroups: computers, hasbootfs, aacraid, hassrvfs, nfs-client, service, squeeze, autofs
   respighi:
     address: 206.12.19.11
     parents: sw-ubcece-kais
@@ -793,7 +802,7 @@ servers:
   quantz:
     address: 206.12.19.122
     parents: traetta
-    hostgroups: computers, service, hasbootfs, kvmdomains, squeeze, hassrvfs, nfs-client, xinetd-hosts, heavy-exim, apache2-hosts, autofs
+    hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, hassrvfs, nfs-client, xinetd-hosts, heavy-exim, apache2-hosts, autofs
   nono:
     address: 206.12.19.123
     parents: traetta
@@ -810,10 +819,6 @@ servers:
     address: 206.12.19.126
     parents: traetta
     hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, xinetd-hosts
-  dukas:
-    address: 206.12.19.128
-    parents: traetta
-    hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, heavy-exim, apache2-hosts, nfs-client, autofs, hassrvfs, apache-https
   tye:
     address: 206.12.19.129
     parents: ganeti2
@@ -822,10 +827,6 @@ servers:
     address: 206.12.19.130
     parents: salieri
     hostgroups: computers, service, kvmdomains, wheezy
-  berlioz:
-    address: 206.12.19.131
-    parents: traetta
-    hostgroups: computers, service, hasbootfs, kvmdomains, squeeze, apache2-hosts, hassrvfs, apache-https
   gombert:
     address: 206.12.19.132
     parents: ganeti2
@@ -874,10 +875,6 @@ servers:
     address: 206.12.19.143
     parents: ganeti2
     hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, apache-https
-  coincy:
-    address: 206.12.19.144
-    parents: ganeti2
-    hostgroups: computers, service, kvmdomains, wheezy
   stanley:
     address: 206.12.19.145
     parents: ganeti2
@@ -936,11 +933,11 @@ servers:
   zandonai:
     address: 80.245.147.46
     parents: gw-zivit
-    hostgroups: computers, buildd, hassrvfs, squeeze
+    hostgroups: computers, buildd, hassrvfs, wheezy
   zelenka:
     address: 80.245.147.40
     parents: gw-zivit
-    hostgroups: computers, porterbox, hassrvfs, squeeze
+    hostgroups: computers, porterbox, hassrvfs, wheezy
   # }}}
   # }}}
 
@@ -1062,6 +1059,9 @@ hostgroups:
   apache2-hosts:
     alias: hosts running apache2
     private: 1
+  jetty-hosts:
+    alias: hosts running jetty
+    private: 1
   varnish-hosts:
     alias: hosts running varnish
     private: 1
@@ -1087,9 +1087,6 @@ hostgroups:
   #postgres81-hosts:
   #  alias: hosts running postgres81
   #  private: 1
-  postgres84-hosts:
-    alias: hosts running postgres84
-    private: 1
   postgres91-hosts:
     alias: hosts running postgres91
     private: 1
@@ -1193,8 +1190,6 @@ servicegroups:
     alias: backup checks
   kernel:
     alias: kernel checks
-  weaksshkeys:
-    alias: weak ssh keys
   apt:
     alias: apt upgrade status
   samhain:
@@ -1203,7 +1198,7 @@ servicegroups:
     alias: time stuff
   security:
     alias: security
-    servicegroup_members: apt, weaksshkeys, kernel, samhain
+    servicegroup_members: apt, kernel, samhain
 
 #############################
 # services
@@ -1240,7 +1235,7 @@ services:
   -
     name: disk usage - all
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk -w 5% -c 2%  -A -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs --ignore-eregi-path=/home/buildd/build-trees"
+    nrpe: "/usr/lib/nagios/plugins/check_disk -w 5% -c 2%  -A -X devpts -X proc -X linprocfs -X devfs -X fdescfs -X sysfs -X nfs --ignore-eregi-path='/home/buildd/build-tr|/var/lib/schroot/mount'"
     hostgroups: computers
     excludehosts: sibelius,stabile
   -
@@ -1300,11 +1295,6 @@ services:
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /home"
     hostgroups: hashomefs
-  -
-    name: disk usage on /x
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /x"
-    hosts: caballero
   -
     name: disk usage on /var/lib/postgresql
     servicegroups: diskspace
@@ -1415,7 +1405,7 @@ services:
   -
     name: backup - bacula - last full backup
     servicegroups: backup
-    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula -w 840 -c 1560 $HOSTNAME$.debian.org F"
+    remotecheck: "/usr/lib/nagios/plugins/dsa-check-bacula -w 1080 -c 1560 $HOSTNAME$.debian.org F"
     runfrom: dinis
     hostgroups: computers
     excludehostgroups: buildd, porterbox, no-bacula
@@ -1427,7 +1417,6 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u bacula -C bacula-fd -a '/usr/sbin/bacula-fd -c /etc/bacula/bacula-fd.conf'"
     hostgroups: computers
     excludehostgroups: freebsd
-    excludehosts: wagner, vasks
   -
     name: process - bacula-fd
     servicegroups: backup
@@ -1477,7 +1466,6 @@ services:
   #  name: puppet
   #  nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -i 540 -f /var/lib/puppet/state/state.yaml"
   #  hostgroups: computers
-  #  excludehosts: wagner, vasks
 
  ####
   -
@@ -1485,14 +1473,15 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-file -w -f /etc/ferm/ferm.conf"
     hostgroups: computers
     excludehostgroups: freebsd
-    excludehosts: vasks, wagner
   -
     name: puppetized firewall
     nrpe: "/usr/lib/nagios/plugins/dsa-check-file -w -f /etc/ferm/conf.d/defs.conf"
     hostgroups: computers
     excludehostgroups: freebsd
-    excludehosts: vasks, wagner
-
+ ####
+  - name: ganeti - job watcher paused
+    nrpe: "/usr/lib/nagios/plugins/negate /usr/lib/nagios/plugins/dsa-check-file -f /var/lib/ganeti/watcher.pause"
+    hostgroups: computers
  ####
   -
     name: process - samhain
@@ -1508,7 +1497,11 @@ services:
     normal_check_interval: 60
     retry_check_interval: 5
     excludehostgroups: brokensamhain
-
+ ####
+  -
+    name: process - acc.umu.se backup
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -a 'dsmc'"
+    hosts: sibelius
  ####
   -
     name: users
@@ -1567,14 +1560,6 @@ services:
     depends: process - sshd
     normal_check_interval:  60
     notification_interval: 1440
-
-  -
-    name: ssh - weak keys
-    servicegroups: weaksshkeys
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/weak-ssh-keys"
-    hostgroups: computers
-    excludehosts: wagner, vasks
-    normal_check_interval:  60
  ####
   -
     name: network service - nrpe
@@ -1594,7 +1579,6 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C munin-node -a '/usr/sbin/munin-node'"
     hostgroups: computers
     excludehostgroups: freebsd, armhf
-    excludehosts: vasks, wagner
   -
     name: process - munin-node
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:3 -c 1: -u root -C perl -a '/usr/bin/perl -wT /usr/sbin/munin-node'"
@@ -1609,7 +1593,6 @@ services:
     check: check_tcp!4949
     hostgroups: computers
     depends: process - munin-node
-    excludehosts: vasks, wagner
  ###
   -
     name: process - ntpd
@@ -1649,7 +1632,6 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
     hostgroups: computers
     excludehostgroups: freebsd
-    excludehosts: vasks, wagner
 
   -
     name: process - syslog-ng
@@ -1661,13 +1643,11 @@ services:
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
     runfrom: lotti
     hostgroups: computers
-    excludehosts: vasks, wagner
   -
     name: remote logging on lully
     remotecheck: "/usr/lib/nagios/plugins/dsa-check-log-age-loghost $HOSTNAME$"
     runfrom: lully
     hostgroups: computers
-    excludehosts: vasks, wagner
  ### MAIL STUFF
  ###
   -
@@ -1699,40 +1679,36 @@ services:
     name: process - clamav - clamd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:2 -c 1: -u clamav -C clamd -a '/usr/sbin/clamd'"
     hostgroups: heavy-exim, heavy-postfix
-    hosts: wagner
   -
     name: service - clamav
     nrpe: "/usr/lib/nagios/plugins/check_clamd -H /var/run/clamav/clamd.ctl"
     hostgroups: heavy-exim, heavy-postfix
-    hosts: wagner
     depends: process - clamav - clamd
   -
     name: process - clamav - freshclam
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u clamav -C freshclam -a '/usr/bin/freshclam -d --quiet'"
-    hosts: wagner
     hostgroups: heavy-exim, heavy-postfix
   -
     name: unwanted process - clamav
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C clamd"
     hostgroups: computers
     excludehostgroups: heavy-exim, heavy-postfix, deadslow
-    excludehosts: wagner
   -
     name: unwanted process - freshclam
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C freshclam"
     hostgroups: computers
     excludehostgroups: heavy-exim, heavy-postfix, deadslow
-    excludehosts: wagner
+ ###
   -
     name: process - spamd - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
     hostgroups: spamd
-    excludehosts: wagner, picconi
+    excludehosts: picconi
     excludehostgroups: deadslow
   -
     name: process - spamd - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
-    hosts: wagner, picconi
+    hosts: picconi
   -
     name: process - spamd - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 10 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
@@ -1740,7 +1716,7 @@ services:
   -
     name: process - spamd - child
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:11 -c 1: -C spamd -a 'spamd child'"
-    hosts: wagner, bendel
+    hosts: bendel
     hostgroups: spamd
     depends: process - spamd - master
   #
@@ -1758,7 +1734,7 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd"
     hostgroups: computers
     excludehostgroups: spamd, deadslow
-    excludehosts: bendel, busoni, wagner, buxtehude
+    excludehosts: bendel, busoni, buxtehude
 
  ###
   #-
@@ -1773,19 +1749,13 @@ services:
     excludehostgroups: deadslow
 
  ###
-  -
-    name: process - postgrey
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -C postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --unix=/var/run/postgrey/socket --retry-window=4 --auto-whitelist-clients=10 --exim'"
-    hostgroups: heavy-exim
-    excludehostgroups: wheezy
   -
     name: process - postgrey
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --unix=/var/run/postgrey/socket --retry-window=4 --auto-whitelist-clients=10 --exim'"
     hostgroups: heavy-exim
-    excludehostgroups: squeeze
   -
     name: process - postgrey
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -C postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'"
     hostgroups: heavy-postfix
   #
   -
@@ -1796,11 +1766,11 @@ services:
  ###
   -
     name: process - amavis - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u amavis -C amavisd-new -a 'amavisd-new (master)'"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u amavis -a 'amavisd-new (master)'"
     hostgroups: amavis-hosts
   -
     name: process - amavis - all
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1:10 -u amavis -C amavisd-new -a 'amavisd-new '"
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1:10 -u amavis -a 'amavisd-new '"
     hostgroups: amavis-hosts
     depends: process - amavis - master
   #
@@ -1824,7 +1794,7 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:50 -c 1: -u polw -a 'policyd-weight (child)'"
     hostgroups: heavy-postfix
     depends: process - weightd - master
 #
###
   -
     name: unwanted process - policyd-weight
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C policyd-weight"
@@ -1832,7 +1802,6 @@ services:
     excludehostgroups: heavy-postfix, deadslow
 
 
-
  ###
   -
     name: process - postfix - master
@@ -1920,51 +1889,43 @@ services:
     name: setup - dsa config
     nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
     hostgroups: computers
-    excludehosts: wagner, vasks
     normal_check_interval: 60
   -
     name: setup - local hostname etc-hosts
     nrpe: 'if getent ahosts `hostname` | grep -q 127.0; then echo "Warning: local hostname resolves to 127/8 address"; exit 1; else echo "OK: Hostname resolves to non-127/8 address."; exit 0; fi'
     hostgroups: computers
-    excludehosts: wagner, vasks
     normal_check_interval: 60
   -
     name: setup - ud-ldap freshness
     nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness"
-    excludehosts: wagner, vasks
     hostgroups: computers
   -
     name: system - available entropy
     nrpe: "/usr/lib/nagios/plugins/dsa-check-entropy"
     event_handler: dsa_event_handler_restart_ekey
     hostgroups: computers
-    excludehosts: vasks, wagner
     excludehostgroups: freebsd
   -
     name: system - filesystem check
     nrpe: "/usr/bin/sudo /usr/lib/nagios/plugins/dsa-check-filesystems"
     normal_check_interval:  60
     retry_check_interval: 15
-    excludehosts: wagner, vasks
     hostgroups: computers
  ###
   -
     name: local resolver
     nrpe: "/usr/lib/nagios/plugins/dsa-check-resolver www.debian.org www.google.com"
     hostgroups: computers
-    excludehosts: vasks, wagner
     normal_check_interval: 60
   -
     name: process - unbound
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u unbound -C unbound -a '/usr/sbin/unbound'"
-    excludehosts: vasks, wagner
     hostgroups: unbound-hosts, squeeze, wheezy
  ###
   -
     name: process - uptimed
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u daemon -C uptimed -a '/usr/sbin/uptimed'"
     hostgroups: computers
-    excludehosts: vasks, wagner
  ###
   -
     name: unwanted process - irqbalance
@@ -1996,7 +1957,7 @@ services:
     name: unwanted process - inetd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C inetd"
     hostgroups: computers
-    excludehosts: grieg, abel, alwyn, vasks
+    excludehosts: abel, alwyn
     excludehostgroups: deadslow
   -
     name: unwanted process - snmpd
@@ -2045,13 +2006,12 @@ services:
   -
     name: process - monit
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/sbin/monit -d 300 -I -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
-    hostgroups: computers
-    excludehosts: vasks, wagner
-    excludehostgroups: armhf
+    hostgroups: squeeze
   -
     name: process - monit
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C monit -a '/usr/bin/monit -d 300 -I -c /etc/monit/monitrc -s /var/lib/monit/monit.state'"
-    hostgroups: wheezy
+    hostgroups: computers
+    excludehostgroups: squeeze
   -
     name: HW - hpacucli status
     servicegroups: raid
@@ -2160,7 +2120,6 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C ulogd -a '/usr/sbin/ulogd -d'"
     hostgroups: computers
     excludehostgroups: freebsd, sparc
-    excludehosts: vasks, wagner
   -
     name: unexpected process - ulogd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C ulogd"
@@ -2192,11 +2151,6 @@ services:
 #    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C bosserver -a '/usr/sbin/bosserver'"
 #    hostgroups: bosserver
 #
- ###
-  -
-    name: process - inetd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C inetd -a '/usr/sbin/inetd'"
-    hosts: grieg, vasks
  ###
   -
     name: process - xinetd
@@ -2237,6 +2191,16 @@ services:
     # there is always one extra process per check currently running..
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:30 -c 1: -u nagios -C icinga -a '/usr/sbin/icinga -d /etc/icinga/icinga.cfg'"
     hosts: tchaikovsky
+ ###
+  -
+    name: process - jetty - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -a 'jsvc.exec'"
+    hostgroups: jetty-hosts
+  -
+    name: process - jetty - worker
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:50 -c 1:100 -u jetty -a 'jsvc.exec -user jetty'"
+    hostgroups: jetty-hosts
+    depends: process - jetty - master
 
  ###
   -
@@ -2320,15 +2284,6 @@ services:
 
 ###
 
-# Alioth web URLs
-
-  -
-    name: network service - loggerhead
-    remotecheck: "/usr/lib/nagios/plugins/check_http -H anonscm.debian.org -u /loggerhead/"
-    hosts: anonscm
-    runfrom: tchaikovsky
-    depends: wagner:process - apache2 - master
-
  ####
   -
     name: process - named
@@ -2392,7 +2347,7 @@ services:
     name: unwanted process - postgresql
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0 -C postgres"
     hostgroups: computers
-    excludehostgroups: postgres84-hosts, postgres91-hosts, deadslow
+    excludehostgroups: postgres91-hosts, deadslow
   -
     name: unwanted process - postgresql 9.0
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0 -C postgres -a '9.0/bin/postgres'"
@@ -2401,10 +2356,6 @@ services:
     name: process - postgresql91 - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:4 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/9.1/bin/postgres'"
     hostgroups: postgres91-hosts
-  -
-    name: process - postgresql84 - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:4 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres'"
-    hostgroups: postgres84-hosts
   -
     name: postgresql backups
     nrpe: "/usr/bin/sudo -u debbackup /usr/lib/nagios/plugins/dsa-check-backuppg"
@@ -2440,10 +2391,6 @@ services:
     nrpe: "/usr/lib/nagios/plugins/dsa-check-ups"
     hosts: franck
     depends: process - UPS - nut upsd
-  -
-    name: process - pglistener
-    nrpe: "/usr/lib/nagios/plugins/check_procs -u pglisten -C python -a '/usr/bin/python /usr/share/pglistener/starter.py /etc/pglistener/pglistener.cfg /etc/pglistener/conf.d' -w 1: -c 1:"
-    hosts: wagner, vasks
  ###
   -
     name: process - buildd
@@ -2478,8 +2425,7 @@ services:
     check: check_tcp!6523
     hosts: gombert
     contact_groups: gobby
-
- ###
+ ####
   #-
   #  name: process - tftpd
   #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C in.tftpd -a '/usr/sbin/in.tftpd -l -B 1450 -s /var/lib/tftpboot'"
@@ -2505,8 +2451,8 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rpc.mountd -a '/sbin/rpc.mountd'"
     hostgroups: nfs-server
   -
-    name: nfs server stabile reachable
-    nrpe: "/usr/lib/nagios/plugins/check_ping -H 192.168.2.13 -w 50,10% -c 200,30%"
+    name: nfs server glinka reachable
+    nrpe: "/usr/lib/nagios/plugins/check_ping -H 192.168.2.76 -w 50,10% -c 200,30%"
     hosts: quantz
   #
   -
@@ -2545,32 +2491,28 @@ services:
     retry_check_interval: 5
   -
     name: DNS SOA sync - debian.org
-    check: "dsa_check_soas_add!draghi.debian.org!debian.org"
+    check: "dsa_check_soas_add!denis.debian.org!debian.org"
     hosts: global
   -
     name: DNS SOA sync - debian.net
-    check: "dsa_check_soas_add!draghi.debian.org!debian.net"
+    check: "dsa_check_soas_add!denis.debian.org!debian.net"
     hosts: global
   -
     name: DNS SOA sync - debian.com
-    check: "dsa_check_soas_add!draghi.debian.org!debian.com"
+    check: "dsa_check_soas_add!denis.debian.org!debian.com"
     hosts: global
   -
     name: DNS SOA sync - mirror.debian.net
-    check: "dsa_check_soas_add!draghi.debian.org!mirror.debian.net"
+    check: "dsa_check_soas_add!denis.debian.org!mirror.debian.net"
     hosts: global
   -
     name: DNS SOA sync - 144-28.118.59.86.in-addr.arpa
-    check: "dsa_check_soas_add!draghi.debian.org!144-28.118.59.86.in-addr.arpa"
+    check: "dsa_check_soas_add!denis.debian.org!144-28.118.59.86.in-addr.arpa"
     hosts: global
   -
     name: DNS SOA sync - alioth.debian.org
     check: "dsa_check_soas_add!alioth.debian.org!alioth.debian.org"
     hosts: global
-  -
-    name: DNS SOA sync - 2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa
-    check: "dsa_check_soas!2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
-    hosts: global
   -
     name: DNS SEC - signature expiry
     hosts: global