pkgmirror-1and1:
address: 213.165.95.4
parents: powell
- hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, no-bacula
+ hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, no-bacula, apache-https
babin:
address: 213.165.95.6
parents: powell
picconi:
address: 5.153.231.3
parents: gw-bytemark
- hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, heavy-exim, spamd
+ hostgroups: computers, service, kvmdomains, wheezy, apache2-hosts, nfs-client, autofs, heavy-exim, spamd, apache-https
senfter:
address: 5.153.231.4
parents: gw-bytemark
dillon:
address: 5.153.231.22
parents: ganeti-bytemark
- hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs
+ hostgroups: computers, general, kvmdomains, wheezy, nfs-client, autofs, hassrvfs
ticharich:
address: 5.153.231.23
parents: ganeti-bytemark
hostgroups: computers, sw-raid, hassrvfs, wheezy
# }}}
# {{{ gw-ftcollins
- alkman:
- address: 192.25.206.63
- parents: gw-ftcollins
- hostgroups: computers, buildd, acpid-hosts, wheezy
- merulo:
- address: 192.25.206.58
- parents: gw-ftcollins
- hostgroups: computers, porterbox, hasusrfs, wheezy
- mundy:
- address: 192.25.206.62
- parents: gw-ftcollins
- hostgroups: computers, buildd, hassrvfs, sw-raid, acpid-hosts, wheezy
+ #alkman:
+ # address: 192.25.206.63
+ # parents: gw-ftcollins
+ # hostgroups: computers, buildd, acpid-hosts, wheezy
+ #merulo:
+ # address: 192.25.206.58
+ # parents: gw-ftcollins
+ # hostgroups: computers, porterbox, hasusrfs, wheezy
+ #mundy:
+ # address: 192.25.206.62
+ # parents: gw-ftcollins
+ # hostgroups: computers, buildd, hassrvfs, sw-raid, acpid-hosts, wheezy
spohr:
address: 192.25.206.33
parents: gw-ftcollins
address: 86.59.118.152
parents: gw-sil
hostgroups: computers, buildd, wheezy
+ eberlin:
+ address: 86.59.118.155
+ parents: gw-sil
+ hostgroups: computers, buildd, wheezy
# }}}
# {{{ gw-ubcece
sw-ubcece:
address: 206.12.19.13
parents: sw-ubcece-kais
hostgroups: computers, hashomefs, sw-raid, rsyncd-hosts, apache2-hosts, xinetd-hosts, service, nfs-server, squeeze, hassrvfs
- paganini:
- address: 206.12.19.10
- parents: sw-ubcece-kais
- hostgroups: computers, hasbootfs, aacraid, hassrvfs, nfs-client, service, squeeze, autofs
respighi:
address: 206.12.19.11
parents: sw-ubcece-kais
nono:
address: 206.12.19.123
parents: traetta
- hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, xinetd-hosts, apache2-hosts, apache-https
+ hostgroups: computers, service, kvmdomains, wheezy, heavy-exim, xinetd-hosts, apache2-hosts, apache-https, broken_https_default_vhost
reger:
address: 206.12.19.124
parents: ganeti2
diabelli:
address: 206.12.19.136
parents: traetta
- hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, apache2-hosts, apache-https
+ hostgroups: computers, service, hasbootfs, kvmdomains, wheezy, apache2-hosts, apache-https, broken_https_default_vhost
bizet:
address: 206.12.19.137
parents: ganeti2
address: 206.12.19.143
parents: ganeti2
hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, apache-https
- stanley:
- address: 206.12.19.145
- parents: ganeti2
- hostgroups: computers, service, kvmdomains, wheezy, hassrvfs, apache2-hosts, no-bacula
muffat:
address: 206.12.19.146
parents: ganeti2
apache-https:
alias: hosts with https services
private: 1
+ broken_https_default_vhost:
+ alias: https default vhost does not say 200 OK
+ private: 1
no-bacula:
alias: hosts which are not being backed up with bacula
# i.e. no port 25
private: 1
- ntpsuckers:
- alias: "hosts who's ntp offset is often unknown"
- private: 1
-
brokensamhain:
alias: machines that can not run samhain
private: 1
nrpe: "/usr/lib/nagios/plugins/dsa-check-uptime"
hostgroups: computers
####
+ -
+ name: processes - samhain zombies
+ nrpe: "/usr/lib/nagios/plugins/check_procs 3 6 -s Z -u root -a samhain"
+ event_handler: dsa_event_handler_restart_samhain
+ hostgroups: computers
+ excludehostgroups: brokensamhain
-
name: processes - zombies
nrpe: "/usr/lib/nagios/plugins/check_procs 5 10 -s Z"
hostgroups: computers
depends: process - ntpd
excludehosts: ancina
- excludehostgroups: ntpsuckers, deadslow
+ excludehostgroups: deadslow
servicegroups: time
#
-
nrpe: 'if getent ahosts `hostname` | grep -q 127.0; then echo "Warning: local hostname resolves to 127/8 address"; exit 1; else echo "OK: Hostname resolves to non-127/8 address."; exit 0; fi'
hostgroups: computers
normal_check_interval: 60
- -
- name: setup - ud-ldap freshness
- nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness"
- hostgroups: computers
-
name: system - available entropy
nrpe: "/usr/lib/nagios/plugins/dsa-check-entropy"
check: check_https
hostgroups: apache-https
excludehosts: handel,menotti
+ excludehostgroups: broken_https_default_vhost
depends: "process - apache2 - master"
normal_check_interval: 120
-
hosts: handel,menotti
depends: "process - apache2 - master"
normal_check_interval: 120
+ -
+ name: network service - https
+ check: dsa_check_https_any_status
+ hostgroups: broken_https_default_vhost
+ depends: "process - apache2 - master"
+ normal_check_interval: 120
-
name: network service - https cert
check: dsa_check_cert!443
hostgroups: computers
-
name: process - postgresql91 - master
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:4 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/9.1/bin/postgres'"
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/9.1/bin/postgres'"
hostgroups: postgres91-hosts
-
name: postgresql backups
############ MISC OTHER Stuff ############
#####
+ -
+ name: puppetmaster cert
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem"
+ hosts: handel
+ normal_check_interval: 60
+ max_check_attempts: 2
+ retry_check_interval: 5
-
name: mirror sync - bugs
check: "dsa_check_mirrorsync_skew!bugs.debian.org!project/trace/bugs-master.debian.org!120:600"
remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=7778 $HOSTADDRESS$ public"
runfrom: dijkstra
hosts: giustini
+ ############
+ -
+ name: current chroots
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-dchroots-current"
+ hostgroups: porterbox
+ normal_check_interval: 60
+ retry_check_interval: 15
# vim: set ts=2 sw=2 et ai si fdm=marker: