One of the last changes broke dbmaster role based ferm rules
[mirror/dsa-puppet.git] / modules / ferm / templates /
2019-09-15 Peter PalfraderOne of the last changes broke dbmaster role based ferm...
2019-09-15 Peter Palfraderdo not use role-based ssh restrict
2019-09-13 Peter PalfraderTry to avoid reserved site keyword
2019-09-11 Peter PalfraderRetire unused ferm varible definitions for HOST_STATIC*
2019-09-11 Peter Palfraderssh between static hosts should be handled by the ssh...
2019-09-11 Peter Palfraderrestrict ssh to static-master-ubc-01 by default. we...
2019-09-11 Peter Palfraderrestrict ssh to static-master-grnet-01 by default....
2019-09-07 Peter Palfraderssh restrict dns geo and dns primary hosts
2019-09-07 Peter Palfraderno longer need to manually whitelist adayevskaya on...
2019-09-07 Peter Palfradergitolite pushes puppetmaster
2019-09-07 Peter Palfradermake puppetmaster a role included via hiera
2019-09-07 Peter PalfraderMove adayevskaya from bm to manda
2019-08-28 Aurelien JarnoFix CSAIL IPv6 subnet
2019-08-28 Aurelien Jarnoferm: drop FREEBSD_SSH_ACCESS
2019-08-28 Aurelien Jarnoferm: add syncproxy.na.debian.org IPv6
2019-07-07 Peter Palfradergeo ferm
2019-07-07 Peter Palfradergeo ferm
2019-07-07 Peter Palfraderfw on kaufmann
2019-07-07 Peter Palfraderunify v4 and v6 rules in named::primary
2019-01-02 Tollef Fog HeenOpen up some IPs for tfheen
2018-11-18 Peter PalfraderAlso restrict "ganeti/kvm host" purpose
2018-10-30 Peter PalfraderMove logging and related/established out of ferm.conf...
2018-10-30 Peter Palfradermove munin rules from conf.d to the rules dir
2018-10-30 Peter Palfraderrename interfaces to 50-munin-interfaces
2018-10-30 Peter Palfradermerge munin_ip v4 and v6 into one rule
2018-10-23 Peter PalfraderAdd a second easydns ipv4 address
2018-10-16 Peter Palfraderallow ssh from ftpmaster to debug_mirrors
2018-07-31 Peter Palfraderferm/munin: use already split v[46]addrs for munin...
2018-07-17 Julien CristauRemove wheezy-supporting cruft
2018-06-18 Julien CristauUpdate my home ip ranges yet again
2018-05-06 Julien CristauNew IP ranges for jcristau
2018-03-06 Peter Palfraderstart ferm config with a 00-init and start SSH*SOURCES...
2018-02-08 Martin Zobel-Helasremove sgran IP range. he can hop via master if needed
2018-01-06 Peter PalfraderAllow adayevskaya to ssh trigger puppetmaster/handel
2017-11-23 Julien CristauAdd extra netnod servers to ferm
2017-10-18 Luca Filipozzialways a typo
2017-10-18 Luca Filipozziprune ssh ACLs for luca
2017-10-03 Julien CristauAdd syncproxy addresses to ssh whitelist
2017-10-03 Julien CristauRestrict ssh to mirrors
2017-09-27 Julien CristauRevert "Restrict ssh to anycast and static mirrors"
2017-09-27 Julien CristauRestrict ssh to anycast and static mirrors
2017-09-10 Aurelien Jarnoferm: restrict access to all buildds
2017-08-13 Peter PalfraderAdd 62.46.0.0/15 to weasel's networks
2017-08-06 Julien CristauFix getfastlyranges harder
2017-08-06 Tollef Fog HeenUpdate IPs for tfheen
2017-08-06 Julien CristauFix template syntax
2017-08-06 Julien CristauHandle exceptions from reading fastly IP ranges
2017-08-06 Julien Cristauferm: accept syslog from fastly IPs
2017-07-22 Peter Palfradernew network space for weasel
2017-04-26 Martin Zobel-HelasMerge branch 'master' of git+ssh://puppet.debian.org...
2017-04-26 Martin Zobel-Helasadd my other subnet
2017-03-19 Martin Zobel-HelasMerge branch 'master' of git+ssh://puppet.debian.org...
2017-03-18 Julien CristauAttempt to fix version comparisons
2017-03-18 Peter Palfraderfix template
2017-03-18 rootpuppet 4 foo
2017-03-18 rootpuppet 4 foo
2017-01-10 Peter Palfraderother sil network for weasel
2016-10-13 Luca Filipozziadd new host for luca
2016-10-07 Luca Filipozziremove fubar.emyr.net from luca's list of hosts
2016-10-05 Luca Filipozziadd IPv4 address for luca's new jumphost
2016-09-26 Luca Filipozzinew cable modem
2016-06-28 Julien CristauAdd topinambour.cristau.org to DSA_IPS
2016-06-28 Peter PalfraderAdd people.do to DSA_IPs
2016-06-25 Aurelien Jarnobeethoven has been decommissioned for a lot of time...
2016-06-15 Julien CristauDecommission lebrun and schroeder
2016-05-28 Julien Cristaudsa -= paravoid (rt#6248)
2016-04-16 Julien Cristauferm: remove my office addresses
2016-04-15 Martin Zobel-Helasadd new office networks
2016-03-07 Luca Filipozziadd luca's home and work IPv4 since they are fixed...
2016-03-02 Julien Cristauferm: squeeze cleanup
2016-02-18 Luca Filipozziremove linode.emyr.net from ACL for luca
2016-02-08 Luca Filipozziprep for transition away from linode
2015-08-31 Julien Cristauferm: add yet another $work ip
2015-08-25 Peter PalfraderRemove /var/run/iptables-ferm.checksum /var/run/ip6tabl...
2015-08-24 Aurelien Jarnoferm: use NFLOG instead of LOG/ULOG on jessie
2015-08-24 Aurelien Jarnoferm: change ferm.conf to a template
2015-08-24 Aurelien Jarnoferm: drop aurel32's IPs
2015-05-14 Peter Palfraderretire ravel
2015-04-28 Julien Cristauferm: office ip renumbering
2015-02-11 Tollef Fog HeenDrop no longer in use office network
2014-11-19 Luca Filipozziallow netnod to reach denis on 53/tcp and 53/udp
2014-11-06 Peter Palfraderfix function name
2014-11-06 Peter PalfraderHandle hosts that are not in ldap yet
2014-10-25 Peter PalfraderAllow pg connections from pgbackuphost
2014-10-06 Julien Cristauferm: add networks for jcristau
2014-07-11 Martin Zobel-Helasadd ip for mfl
2014-07-09 Héctor Orón Martínezportman: does not need ssh all buildd
2014-07-08 Héctor Orón Martínezferm: update -ports rules
2014-05-31 Luca Filipozzidrop orff from dns_secondary; purge dns_secondary configs
2014-05-14 Luca Filipozziadd rcode0.net to primary nameserver firewall rules
2014-03-07 Luca Filipozziadd xfr0.easydns.com to firewall rules
2014-01-14 Peter Palfraderremove grieg (RT#4393)
2014-01-07 Peter PalfraderFixes
2014-01-07 Peter Palfraderdenis: llow ssh from geo[123]
2014-01-07 Peter Palfraderupdate firewalls regarding dns
2014-01-02 Stephen GranIn ruby, this must be an array
2014-01-02 Stephen Grantemplate breakage
2014-01-02 Stephen Grantry to fix errors
2014-01-02 Tollef Fog HeenMove all roles from local.yaml to hiera
2013-12-30 Peter Palfraderadayevskaya can ssh into denis
next