Update wuiet IP address
[mirror/dsa-puppet.git] / hieradata / common.yaml
index 71b1519..e3afd79 100644 (file)
@@ -7,8 +7,29 @@ lookup_options:
   apt::sources::debian::location:
     merge: unique
 
+# class parameters
 resolv::nameservers: []
 resolv::searchpaths: ['debian.org']
+staticsync::user: 'staticsync'
+staticsync::basedir: '/srv/static.debian.org'
+
+roles::dns_primary::allow_access:
+  # easydns
+  - '64.68.200.91'
+  - '205.210.42.80'
+  # rcode0
+  - '83.136.34.0/27'
+  - '2a02:850:8::/47'
+  # netnod
+  - '192.71.80.0/24'
+  - '192.36.144.222'
+  - '192.36.144.218'
+  - '194.146.105.24'
+  - '194.146.105.25'
+  - '2a01:3f0:0:27::24'
+  - '2a01:3f0:0:28::25'
+
+# other variables
 allow_dns_query: []
 role_config__mirrors:
   mirror_basedir_prefix: '/srv/mirrors/'
@@ -27,20 +48,10 @@ paths:
   auto_clientcerts_dir: '/srv/puppet.debian.org/ca/RESULT/clientcerts'
 apt::sources::debian::location: 'https://deb.debian.org/debian/'
 
-staticsync::user: 'staticsync'
-staticsync::basedir: '/srv/static.debian.org'
 
 # all of these should be retired in favour of including the class role
 # with the host. weasel, 2019-09
 roles:
-  dns_primary:
-    # XXX - used by ferm templates/defs.conf.erb
-    - denis.debian.org
-  dns_geo:
-    # XXX - used by ferm templates/defs.conf.erb
-    - geo1.debian.org
-    - geo2.debian.org
-    - geo3.debian.org
   extranrpeclient:
     # XXX - used by ferm templates/defs.conf.erb
     - denis.debian.org