Luca Filipozzi [Sun, 12 Jan 2014 07:50:42 +0000 (07:50 +0000)]
enable ipv6 rules for sip
Luca Filipozzi [Sat, 11 Jan 2014 17:49:11 +0000 (17:49 +0000)]
remove mod state
Luca Filipozzi [Sat, 11 Jan 2014 17:16:07 +0000 (17:16 +0000)]
add another rule
Luca Filipozzi [Sat, 11 Jan 2014 17:06:19 +0000 (17:06 +0000)]
use standardized names for rules
Luca Filipozzi [Sat, 11 Jan 2014 17:05:21 +0000 (17:05 +0000)]
must ACCEPT the connections, silly
Luca Filipozzi [Sat, 11 Jan 2014 16:59:28 +0000 (16:59 +0000)]
add ferm rules for sip
Luca Filipozzi [Sat, 11 Jan 2014 16:15:49 +0000 (16:15 +0000)]
initial set up of role:sip
Peter Palfrader [Sat, 11 Jan 2014 14:58:17 +0000 (15:58 +0100)]
new debian.org DSset
Peter Palfrader [Sat, 11 Jan 2014 14:42:36 +0000 (15:42 +0100)]
Add vogler
Stephen Gran [Sat, 11 Jan 2014 11:53:02 +0000 (11:53 +0000)]
add ssl auth support
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Fri, 10 Jan 2014 20:18:16 +0000 (21:18 +0100)]
another MAG2 IP range
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Stephen Gran [Fri, 10 Jan 2014 19:57:46 +0000 (19:57 +0000)]
we never want to remove ~debian
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Fri, 10 Jan 2014 12:35:10 +0000 (13:35 +0100)]
add MAG2 range as per whois -h whois.nic.ad.jp
Network Information:
a. [Network Number] 115.125.152.0/24
b. [Network Name] MAG2-PORTAL
g. [Organization] INFOCOM CORPORATION
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Luca Filipozzi [Fri, 10 Jan 2014 07:12:21 +0000 (07:12 +0000)]
renew security-master certificate
Peter Palfrader [Thu, 9 Jan 2014 22:59:05 +0000 (23:59 +0100)]
make it 2 years
Peter Palfrader [Thu, 9 Jan 2014 18:48:30 +0000 (19:48 +0100)]
Allow queries from 82.195.75.64/26
Peter Palfrader [Thu, 9 Jan 2014 18:47:11 +0000 (19:47 +0100)]
own recursors at man-da
Peter Palfrader [Thu, 9 Jan 2014 12:46:35 +0000 (13:46 +0100)]
Forward 29.172.in-addr.arpa to ns[1234] even if we are not recursive and would usually use a forwarder upstream
Peter Palfrader [Thu, 9 Jan 2014 12:41:38 +0000 (13:41 +0100)]
new key for 29.172.in-addr.arpa
Martin Zobel-Helas [Thu, 9 Jan 2014 07:30:12 +0000 (08:30 +0100)]
add more of mag2.com to blacklist
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 8 Jan 2014 21:55:30 +0000 (22:55 +0100)]
push the cert to bugs
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 8 Jan 2014 21:34:24 +0000 (22:34 +0100)]
add bugs.d.o
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Stephen Gran [Wed, 8 Jan 2014 20:29:28 +0000 (20:29 +0000)]
admin should be able to see pet as well
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 8 Jan 2014 20:01:40 +0000 (20:01 +0000)]
duplicate name
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 8 Jan 2014 20:00:43 +0000 (20:00 +0000)]
change to rules by ip
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 8 Jan 2014 19:54:30 +0000 (19:54 +0000)]
change username
Signed-off-by: Stephen Gran <steve@lobefin.net>
Luca Filipozzi [Wed, 8 Jan 2014 19:09:04 +0000 (19:09 +0000)]
fix sed command
Stephen Gran [Wed, 8 Jan 2014 17:13:25 +0000 (17:13 +0000)]
add pet vhost
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 8 Jan 2014 17:13:05 +0000 (17:13 +0000)]
They don't need to be admins
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Wed, 8 Jan 2014 15:43:54 +0000 (15:43 +0000)]
mess with motd wrappig/spacing
Peter Palfrader [Wed, 8 Jan 2014 15:17:39 +0000 (16:17 +0100)]
change wrap in motd
Martin Zobel-Helas [Wed, 8 Jan 2014 08:15:59 +0000 (09:15 +0100)]
add bugs.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Tue, 7 Jan 2014 23:03:28 +0000 (00:03 +0100)]
Update list of geozones
Peter Palfrader [Tue, 7 Jan 2014 22:22:22 +0000 (23:22 +0100)]
Try to allow nagios access to denis
Peter Palfrader [Tue, 7 Jan 2014 21:57:24 +0000 (21:57 +0000)]
Fixes
Peter Palfrader [Tue, 7 Jan 2014 21:53:05 +0000 (22:53 +0100)]
denis: llow ssh from geo[123]
Peter Palfrader [Tue, 7 Jan 2014 21:46:50 +0000 (22:46 +0100)]
update firewalls regarding dns
Peter Palfrader [Tue, 7 Jan 2014 21:20:21 +0000 (22:20 +0100)]
Update geodns trigger keys
Luca Filipozzi [Tue, 7 Jan 2014 11:23:35 +0000 (11:23 +0000)]
augment the security-master role
Luca Filipozzi [Tue, 7 Jan 2014 11:09:21 +0000 (11:09 +0000)]
adding security-master's certificate
Peter Palfrader [Mon, 6 Jan 2014 11:46:32 +0000 (12:46 +0100)]
tlsa record for lists
Peter Palfrader [Sun, 5 Jan 2014 14:13:50 +0000 (15:13 +0100)]
restore sso role
Peter Palfrader [Sun, 5 Jan 2014 14:10:33 +0000 (15:10 +0100)]
try has_role
Luca Filipozzi [Sat, 4 Jan 2014 10:39:42 +0000 (10:39 +0000)]
restoring a deleted command entry
Luca Filipozzi [Sat, 4 Jan 2014 03:26:01 +0000 (03:26 +0000)]
resolve exec dependency and rename
Luca Filipozzi [Sat, 4 Jan 2014 03:14:39 +0000 (03:14 +0000)]
restore external dependency on exec
Luca Filipozzi [Sat, 4 Jan 2014 03:09:13 +0000 (03:09 +0000)]
ensure that links and hashes are properly created
Luca Filipozzi [Fri, 3 Jan 2014 23:02:06 +0000 (23:02 +0000)]
do markdown right
Luca Filipozzi [Fri, 3 Jan 2014 22:50:40 +0000 (22:50 +0000)]
delete old README
Luca Filipozzi [Fri, 3 Jan 2014 21:08:06 +0000 (21:08 +0000)]
markdown styling
Luca Filipozzi [Fri, 3 Jan 2014 20:57:25 +0000 (20:57 +0000)]
fix typo
Stephen Gran [Fri, 3 Jan 2014 19:37:41 +0000 (19:37 +0000)]
sigh, crucial one character
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Fri, 3 Jan 2014 19:36:34 +0000 (19:36 +0000)]
clean up Makefile a bit
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Fri, 3 Jan 2014 19:28:54 +0000 (19:28 +0000)]
Add some basic documentation
Signed-off-by: Stephen Gran <steve@lobefin.net>
Luca Filipozzi [Fri, 3 Jan 2014 16:36:56 +0000 (16:36 +0000)]
manage /etc/ca-certificates.conf because gandi
Stephen Gran [Fri, 3 Jan 2014 15:01:53 +0000 (15:01 +0000)]
Revert "Add a new puppet face"
This reverts commit
b75862abf9f8001f671f5fc603ffcfb981797231.
Stephen Gran [Fri, 3 Jan 2014 14:56:14 +0000 (14:56 +0000)]
Add a new puppet face
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Fri, 3 Jan 2014 12:11:53 +0000 (12:11 +0000)]
whitespace cleanup
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Fri, 3 Jan 2014 12:10:21 +0000 (12:10 +0000)]
use a puppet builtin for this
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Fri, 3 Jan 2014 09:07:32 +0000 (09:07 +0000)]
fix regexp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 22:40:04 +0000 (22:40 +0000)]
move over dns_primary/seconday
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 22:26:39 +0000 (22:26 +0000)]
This comes from LDAP
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 22:16:13 +0000 (22:16 +0000)]
In ruby, this must be an array
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 21:58:52 +0000 (21:58 +0000)]
try this on
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 21:37:23 +0000 (21:37 +0000)]
move more to roles
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 21:33:26 +0000 (21:33 +0000)]
template breakage
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 20:17:19 +0000 (20:17 +0000)]
try to fix nagios template
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 19:55:19 +0000 (19:55 +0000)]
we are passed a string
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 19:54:54 +0000 (19:54 +0000)]
puppet math is primitive
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Thu, 2 Jan 2014 19:52:10 +0000 (19:52 +0000)]
try to fix errors
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Thu, 2 Jan 2014 18:12:01 +0000 (19:12 +0100)]
A chain for www
Tollef Fog Heen [Thu, 2 Jan 2014 18:07:39 +0000 (19:07 +0100)]
More workarounds
Peter Palfrader [Thu, 2 Jan 2014 17:57:26 +0000 (18:57 +0100)]
Make denis an extra nrpe client
Tollef Fog Heen [Thu, 2 Jan 2014 17:56:07 +0000 (18:56 +0100)]
More workarounds
Tollef Fog Heen [Thu, 2 Jan 2014 17:53:57 +0000 (18:53 +0100)]
err, not error. Maybe
Tollef Fog Heen [Thu, 2 Jan 2014 17:49:34 +0000 (18:49 +0100)]
More workarounds
Tollef Fog Heen [Thu, 2 Jan 2014 17:47:12 +0000 (18:47 +0100)]
Add workaround for buildd not being a real role yet
Tollef Fog Heen [Thu, 2 Jan 2014 17:44:31 +0000 (18:44 +0100)]
Log error rather than exploding unhelpfully
Tollef Fog Heen [Thu, 2 Jan 2014 17:39:15 +0000 (18:39 +0100)]
Ruby is not python
Tollef Fog Heen [Thu, 2 Jan 2014 17:22:58 +0000 (18:22 +0100)]
Simply exim config slightly by checking for roles in manifest
Tollef Fog Heen [Wed, 1 Jan 2014 15:12:14 +0000 (16:12 +0100)]
Move all roles from local.yaml to hiera
Hopefully this won't break anything.
Peter Palfrader [Wed, 1 Jan 2014 21:58:40 +0000 (22:58 +0100)]
And put the ssl cert out
Peter Palfrader [Wed, 1 Jan 2014 21:55:40 +0000 (22:55 +0100)]
Try new www vhost config
Peter Palfrader [Wed, 1 Jan 2014 21:53:42 +0000 (22:53 +0100)]
Move volatile vhost from www to static
Peter Palfrader [Wed, 1 Jan 2014 21:08:45 +0000 (21:08 +0000)]
Checking for classes in templates is not reliable
Peter Palfrader [Wed, 1 Jan 2014 21:00:23 +0000 (22:00 +0100)]
no RRL on the primary
Peter Palfrader [Wed, 1 Jan 2014 20:58:49 +0000 (21:58 +0100)]
maybe these firewall rules are better
Peter Palfrader [Wed, 1 Jan 2014 20:45:52 +0000 (21:45 +0100)]
remove another hardcoding of hostnames
Peter Palfrader [Wed, 1 Jan 2014 20:43:12 +0000 (20:43 +0000)]
syntax fix
Peter Palfrader [Wed, 1 Jan 2014 20:41:15 +0000 (21:41 +0100)]
try to rolify dns
Peter Palfrader [Wed, 1 Jan 2014 20:29:32 +0000 (21:29 +0100)]
master is now denis
Peter Palfrader [Wed, 1 Jan 2014 20:29:26 +0000 (21:29 +0100)]
new way to update zones
Peter Palfrader [Wed, 1 Jan 2014 19:56:42 +0000 (20:56 +0100)]
put release cert onto franck - we have no release service yet
Peter Palfrader [Wed, 1 Jan 2014 19:55:08 +0000 (20:55 +0100)]
put nagios cert onto nagios host by role
Martin Zobel-Helas [Wed, 1 Jan 2014 19:51:18 +0000 (20:51 +0100)]
add nagios.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 1 Jan 2014 19:45:12 +0000 (20:45 +0100)]
add nagios.debian.org and release.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 1 Jan 2014 19:41:26 +0000 (20:41 +0100)]
add ftp-master.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Wed, 1 Jan 2014 17:52:32 +0000 (18:52 +0100)]
remove zappa
Peter Palfrader [Wed, 1 Jan 2014 17:52:06 +0000 (18:52 +0100)]
Use submission for mail to zani
Peter Palfrader [Wed, 1 Jan 2014 16:20:25 +0000 (17:20 +0100)]
Add vhost_listen_443