new-klecker as debian mirror
[mirror/dsa-puppet.git] / hieradata / common.yaml
index 71b1519..864209d 100644 (file)
@@ -7,8 +7,29 @@ lookup_options:
   apt::sources::debian::location:
     merge: unique
 
+# class parameters
 resolv::nameservers: []
 resolv::searchpaths: ['debian.org']
+staticsync::user: 'staticsync'
+staticsync::basedir: '/srv/static.debian.org'
+
+roles::dns_primary::allow_access:
+  # easydns
+  - '64.68.200.91'
+  - '205.210.42.80'
+  # rcode0
+  - '83.136.34.0/27'
+  - '2a02:850:8::/47'
+  # netnod
+  - '192.71.80.0/24'
+  - '192.36.144.222'
+  - '192.36.144.218'
+  - '194.146.105.24'
+  - '194.146.105.25'
+  - '2a01:3f0:0:27::24'
+  - '2a01:3f0:0:28::25'
+
+# other variables
 allow_dns_query: []
 role_config__mirrors:
   mirror_basedir_prefix: '/srv/mirrors/'
@@ -27,23 +48,10 @@ paths:
   auto_clientcerts_dir: '/srv/puppet.debian.org/ca/RESULT/clientcerts'
 apt::sources::debian::location: 'https://deb.debian.org/debian/'
 
-staticsync::user: 'staticsync'
-staticsync::basedir: '/srv/static.debian.org'
 
 # all of these should be retired in favour of including the class role
 # with the host. weasel, 2019-09
 roles:
-  dns_primary:
-    # XXX - used by ferm templates/defs.conf.erb
-    - denis.debian.org
-  dns_geo:
-    # XXX - used by ferm templates/defs.conf.erb
-    - geo1.debian.org
-    - geo2.debian.org
-    - geo3.debian.org
-  extranrpeclient:
-    # XXX - used by ferm templates/defs.conf.erb
-    - denis.debian.org
   ftp_master:
     # XXX - used by ferm templates/defs.conf.erb
     - fasolo.debian.org
@@ -113,8 +121,6 @@ roles:
     # XXX - used by ferm templates/defs.conf.erb
     - backuphost.debian.org
     - storace.debian.org
-  dabackup_client:
-    - lw03.debian.org
   debian_mirror:
     # XXX used also in ferm me.conf.erb
     klecker.debian.org:
@@ -122,6 +128,7 @@ roles:
         - '130.89.148.12:80'
         - '[2001:67c:2564:a119::148:12]:80'
       onion_v4_address: 130.89.148.12
+    new-klecker.debian.org: []
     mirror-accumu.debian.org:
       service-hostname: accumu.debian.backend.mirrors.debian.org
       fastly-backend: true
@@ -165,8 +172,6 @@ roles:
   ports_master:
     # XXX - used by ferm templates/defs.conf.erb
     - porta.debian.org
-  onionbalance:
-    - olin.debian.org
   bgp:
     - mirror-accumu.debian.org
     - mirror-skroutz.debian.org