X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=config%2Fnagios-master.cfg;h=4a489186945d31d0ddb82979d4f027cb311e48fd;hb=6be6eb31d20b7554653a17c90b88f41b470f9878;hp=7a49490fa171bb466d9b6ca90303ad11a65acdfa;hpb=df8246a7262c29e4d284adedc6f8fc03754953b9;p=mirror%2Fdsa-nagios.git diff --git a/config/nagios-master.cfg b/config/nagios-master.cfg index 7a49490..4a48918 100644 --- a/config/nagios-master.cfg +++ b/config/nagios-master.cfg @@ -435,7 +435,7 @@ servers: oyens: address: 5.153.231.26 parents: ganeti-bytemark - hostgroups: computers, kvmdomains, jessie, openstack-controller, broken_mq #, apache2-hosts, apache-https + hostgroups: computers, kvmdomains, jessie, openstack-controller, broken_mq, apache2-hosts # apache-https barriere: address: 5.153.231.27 parents: ganeti-bytemark @@ -551,7 +551,7 @@ servers: fischer: address: 128.31.0.35 parents: ganeti-csail - hostgroups: computers, freebsd, hassrvfs, porterbox, wheezy + hostgroups: computers, freebsd, hassrvfs, porterbox, jessie mirror-csail: address: 128.31.0.62 parents: ganeti-csail @@ -560,6 +560,10 @@ servers: address: 128.31.0.50 parents: ganeti-csail hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie + x86-csail-02: + address: 128.31.0.68 + parents: ganeti-csail + hostgroups: computers, buildd, hassrvfs, kvmdomains, jessie httpredir-csail-01: address: 128.31.0.66 parents: ganeti-csail @@ -567,7 +571,7 @@ servers: soriano: address: 128.31.0.67 parents: ganeti-csail - hostgroups: computers, service, kvmdomains, hassrvfs, jessie, apache2-hosts + hostgroups: computers, service, kvmdomains, hassrvfs, jessie, apache2-hosts, apache-https # }}} # {{{ gw-dgi storace: @@ -609,7 +613,7 @@ servers: cgi-grnet-01: address: 194.177.211.202 parents: gw-grnet - hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts, apache-https + hostgroups: computers, service, kvmdomains, jessie, hassrvfs, apache2-hosts, apache-https, xinetd-hosts x86-grnet-01: address: 194.177.211.203 parents: ganeti-grnet @@ -625,19 +629,19 @@ servers: lw01: address: 185.17.185.177 parents: gw-leaseweb - hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server + hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server, rsyncd-hosts, xinetd-hosts lw02: address: 185.17.185.178 parents: gw-leaseweb - hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server + hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server, rsyncd-hosts, xinetd-hosts lw03: address: 185.17.185.179 parents: gw-leaseweb - hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server + hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server, rsyncd-hosts, xinetd-hosts lw04: address: 185.17.185.180 parents: gw-leaseweb - hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server + hostgroups: computers, service, acpid-hosts, jessie, dl180, nfs-server, rsyncd-hosts, xinetd-hosts lw07: address: 185.17.185.187 parents: gw-leaseweb @@ -665,7 +669,7 @@ servers: zemlinsky: address: 129.143.160.6 parents: gw-karlsruhe - hostgroups: computers, buildd, wheezy + hostgroups: computers, buildd, jessie contacts: pkern # }}} # {{{ gw-man-da @@ -681,28 +685,20 @@ servers: bendel: address: 82.195.75.100 parents: ganeti3 - hostgroups: computers, service, hasbootfs, kvmdomains, hassrvfs, apache2-hosts, wheezy, postfix-hosts, heavy-postfix, acpid-hosts, apache-https, amavis-hosts, hasvarlogfs + hostgroups: computers, service, hasbootfs, kvmdomains, hassrvfs, apache2-hosts, jessie, postfix-hosts, heavy-postfix, acpid-hosts, apache-https, amavis-hosts, hasvarlogfs master: address: 82.195.75.110 parents: ganeti3 hostgroups: computers, service, kvmdomains, jessie, hassrvfs, spamd, heavy-exim, highload - mipsel-manda-01: - address: 82.195.75.72 - parents: gw-man-da - hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy - mipsel-manda-02: - address: 82.195.75.74 - parents: gw-man-da - hostgroups: computers, hasbootfs, hassrvfs, buildd, wheezy fils: address: 82.195.75.89 parents: ganeti3 - hostgroups: computers, freebsd, wheezy, buildd, hassrvfs + hostgroups: computers, freebsd, jessie, buildd, hassrvfs contacts: christoph fayrfax: address: 82.195.75.82 parents: ganeti3 - hostgroups: computers, freebsd, wheezy, buildd, hassrvfs + hostgroups: computers, freebsd, jessie, buildd, hassrvfs contacts: christoph vento: address: 82.195.75.98 @@ -759,11 +755,15 @@ servers: mipsel-manda-01: address: 82.195.75.72 parents: gw-man-da - hostgroups: computers, buildd, wheezy, hassrvfs, sw-raid + hostgroups: computers, buildd, jessie, hassrvfs, sw-raid, hasbootfs mipsel-manda-02: address: 82.195.75.74 parents: gw-man-da - hostgroups: computers, buildd, wheezy, hassrvfs, sw-raid + hostgroups: computers, buildd, jessie, hassrvfs, sw-raid, hasbootfs + seger: + address: 82.195.75.93 + parents: ganeti3 + hostgroups: computers, service, apache2-hosts, hassrvfs, hasbootfs, rsyncd-hosts, uploadqueue, kvmdomains, xinetd-hosts, apache-https, postgres94-hosts, jessie # }}} # {{{ gw-marist zani: @@ -796,11 +796,15 @@ servers: address: 140.211.166.197 parents: pieta hostgroups: computers, hassrvfs, buildd, jessie + pizzetti: + address: 140.211.166.198 + parents: pieta + hostgroups: computers, jessie, hassrvfs, porterbox # malo TODO mayer: address: 140.211.166.78 parents: gw-osuosl - hostgroups: computers, buildd, hasbootfs, wheezy + hostgroups: computers, buildd, hasbootfs, jessie # mayr: # address: 140.211.166.58 # parents: gw-osuosl @@ -860,11 +864,11 @@ servers: eysler: address: 86.59.118.152 parents: gw-sil - hostgroups: computers, buildd, wheezy + hostgroups: computers, buildd, jessie eberlin: address: 86.59.118.155 parents: gw-sil - hostgroups: computers, buildd, wheezy, sw-raid + hostgroups: computers, buildd, jessie, sw-raid # }}} # {{{ gw-ubcece sw-ubcece: @@ -940,12 +944,12 @@ servers: fano: address: 206.12.19.110 parents: ganeti2 - hostgroups: computers, freebsd, wheezy, buildd, hassrvfs + hostgroups: computers, freebsd, jessie, buildd, hassrvfs contacts: christoph finzi: address: 206.12.19.111 parents: ganeti2 - hostgroups: computers, freebsd, wheezy, buildd, hassrvfs + hostgroups: computers, freebsd, jessie, buildd, hassrvfs contacts: christoph gabrielli: address: 206.12.19.17 @@ -999,7 +1003,7 @@ servers: address: 206.12.19.132 parents: ganeti2 hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, apache-https - jenkins: + jenko: address: 206.12.19.133 parents: ganeti2 hostgroups: computers, service, kvmdomains, jessie @@ -1559,11 +1563,11 @@ services: name: processes - total nrpe: "/usr/lib/nagios/plugins/check_procs 620 700" hostgroups: computers - excludehosts: prokofiev + excludehosts: prokofiev, pieta - name: processes - total nrpe: "/usr/lib/nagios/plugins/check_procs 1500 1700" - hosts: prokofiev + hosts: prokofiev, pieta - name: swap usage - percent nrpe: "/usr/lib/nagios/plugins/check_swap -w 20% -c 10%" @@ -1977,6 +1981,10 @@ services: name: "host SSL cert - debian client" nrpe: "if [ -e /etc/ssl/debian/certs/thishost.crt ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/debian/certs/thishost.crt; else echo 'No thishost.crt on this host.'; fi" hostgroups: computers + - + name: "sso CRL" + nrpe: "if [ -e lib/dsa/sso/ca.crl ]; then /usr/lib/nagios/plugins/dsa-check-crl-expire -w 129600 -c 86400 /var/lib/dsa/sso/ca.crl; else echo 'No sso/ca.crl on this host.'; fi" + hostgroups: computers # }}} # {{{ HW health/raid - @@ -2170,7 +2178,7 @@ services: hosts: picconi - name: process - spamd - master - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 10 --helper-home-dir -d --pidfile=/var/run/spamd.pid'" + nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd -d --pidfile=/var/run/spamassassin.pid --create-prefs --max-children 10 --helper-home-dir'" hosts: bendel - name: process - spamd - child @@ -2204,7 +2212,7 @@ services: excludehostgroups: wheezy - name: process - postgrey - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a '/usr/sbin/postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'" + nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgrey -a 'postgrey --pidfile=/var/run/postgrey.pid --daemonize --inet=127.0.0.1:60000'" hostgroups: heavy-postfix # - @@ -2346,7 +2354,7 @@ services: name: network service - http check: check_http hostgroups: apache2-hosts - excludehosts: klecker + excludehosts: klecker, oyens depends: process - apache2 - master - name: network service - http @@ -2366,14 +2374,14 @@ services: name: network service - https check: check_https hostgroups: apache-https - excludehosts: handel,menotti + excludehosts: menotti excludehostgroups: broken_https_default_vhost depends: "process - apache2 - master" normal_check_interval: 120 - name: network service - https check: dsa_check_https_want_auth - hosts: handel,menotti + hosts: menotti depends: "process - apache2 - master" normal_check_interval: 120 - @@ -2570,6 +2578,22 @@ services: name: DNS SOA sync - alioth.debian.org check: "dsa_check_soas_add!denis.debian.org!alioth.debian.org" hosts: global + - + name: DNS SOA sync - debconf.net + check: "dsa_check_soas_add!denis.debian.org!debconf.net" + hosts: global + - + name: DNS SOA sync - debconf.org + check: "dsa_check_soas_add!denis.debian.org!debconf.org" + hosts: global + - + name: DNS SOA sync - debianday.org + check: "dsa_check_soas_add!denis.debian.org!debianday.org" + hosts: global + - + name: DNS SOA sync - dpkg.org + check: "dsa_check_soas_add!denis.debian.org!dpkg.org" + hosts: global - name: DNS - delegation and signature expiry hosts: global @@ -2607,7 +2631,7 @@ services: hosts: giustini - name: event log - remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=10791 $HOSTADDRESS$ public" + remotecheck: "/usr/lib/nagios/plugins/dsa-check-msa-eventlog --start=10867 $HOSTADDRESS$ public" runfrom: ubc-bl8 hosts: giustini # }}} @@ -2736,7 +2760,7 @@ services: #### - name: puppetmaster cert - nrpe: "/usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem" + nrpe: "sudo -u puppet /usr/lib/nagios/plugins/dsa-check-cert-expire /var/lib/puppet/ssl/certs/ca.pem" hosts: handel normal_check_interval: 60 max_check_attempts: 2