Peter Palfrader [Sat, 20 Mar 2010 23:25:18 +0000 (00:25 +0100)]
I wonder if that makes puppet work
Peter Palfrader [Thu, 18 Mar 2010 13:53:00 +0000 (14:53 +0100)]
%debian-cd gets sudo to debian-cd
Peter Palfrader [Thu, 18 Mar 2010 13:09:19 +0000 (14:09 +0100)]
Move logrotate dependency from apache to debian-org
Peter Palfrader [Thu, 18 Mar 2010 12:59:20 +0000 (13:59 +0100)]
puppet does not like requiring the same package twice, apparently
Peter Palfrader [Thu, 18 Mar 2010 12:58:16 +0000 (13:58 +0100)]
ulogd logs: Rotate daily, compress them (delayed), and keep 10, but do not rotate empty files
Peter Palfrader [Thu, 18 Mar 2010 12:56:08 +0000 (13:56 +0100)]
puppet header
Peter Palfrader [Thu, 18 Mar 2010 12:55:49 +0000 (13:55 +0100)]
Add logrotate.d/ulogd
Stephen Gran [Thu, 18 Mar 2010 12:06:24 +0000 (12:06 +0000)]
add nixon key for pettersson
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 16 Mar 2010 23:48:14 +0000 (23:48 +0000)]
stupid net-lsearch type
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Tue, 16 Mar 2010 11:46:54 +0000 (12:46 +0100)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Tue, 16 Mar 2010 11:46:23 +0000 (12:46 +0100)]
disable dns_ipv4_lookup upon sgrans request
Stephen Gran [Mon, 15 Mar 2010 13:12:04 +0000 (13:12 +0000)]
allow local_part_suffixes in procmail router
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 23:54:50 +0000 (23:54 +0000)]
enable the nf_ftp_conntrack hook
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 17:59:51 +0000 (17:59 +0000)]
stop serving a broken file for now
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 17:55:49 +0000 (17:55 +0000)]
and let's try pointing at the right file
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 17:53:35 +0000 (17:53 +0000)]
and the inevitable syntax error
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 17:52:03 +0000 (17:52 +0000)]
a stab at auto loading conntrack modules
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Mon, 8 Mar 2010 13:34:57 +0000 (14:34 +0100)]
Revert "lets load nf_conntrack_ftp on buildds"
This reverts commit
1689c9c9a7ca632ec433fd952ce19b9bd254a3bb.
Martin Zobel-Helas [Mon, 8 Mar 2010 13:32:21 +0000 (14:32 +0100)]
lets load nf_conntrack_ftp on buildds
Stephen Gran [Mon, 8 Mar 2010 00:07:08 +0000 (00:07 +0000)]
add ferm to tchaikovsky
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 8 Mar 2010 00:01:43 +0000 (00:01 +0000)]
restrict ssh to tchaikovsky
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 23:35:26 +0000 (23:35 +0000)]
v6 rule is v6
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 23:28:25 +0000 (23:28 +0000)]
handel gets a firewall
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 23:21:49 +0000 (23:21 +0000)]
try not to double include rietz when we do puppetize it
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 22:44:38 +0000 (22:44 +0000)]
add rietz back into munin
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 21:59:00 +0000 (21:59 +0000)]
match subnets that might exist
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 21:38:56 +0000 (21:38 +0000)]
add https ferm rule to apache class for now
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:52:24 +0000 (20:52 +0000)]
munin must run ip6 plugin as root as well
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:40:54 +0000 (20:40 +0000)]
make v6ips fail more gracefully
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:36:01 +0000 (20:36 +0000)]
get package name right
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:34:19 +0000 (20:34 +0000)]
reshuffle where template is served from
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:29:38 +0000 (20:29 +0000)]
bandwidth graphs for v6
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:28:18 +0000 (20:28 +0000)]
alphabetize
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:25:03 +0000 (20:25 +0000)]
some whitespace cleanup and move template to base class
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 20:24:16 +0000 (20:24 +0000)]
handle lack of v6 addresses nicely
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 15:30:45 +0000 (15:30 +0000)]
some more no_munin hosts
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 13:00:11 +0000 (13:00 +0000)]
more whitespace
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 12:36:47 +0000 (12:36 +0000)]
whitespace nazi
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 11:57:04 +0000 (11:57 +0000)]
get rid of way too many munin subclasses
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 11:23:26 +0000 (11:23 +0000)]
confine ip addr fact to linux
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:57:39 +0000 (10:57 +0000)]
yes, picky pain
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:56:52 +0000 (10:56 +0000)]
since we log to ulog, we should probably install it
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:43:29 +0000 (10:43 +0000)]
erm, time is tcp, ntp is udp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:41:25 +0000 (10:41 +0000)]
sigh
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:39:19 +0000 (10:39 +0000)]
picky picky
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 10:37:41 +0000 (10:37 +0000)]
allow time for ancina and zelenka
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 09:39:57 +0000 (09:39 +0000)]
some more ferm fixups
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 09:25:30 +0000 (09:25 +0000)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sun, 7 Mar 2010 09:25:20 +0000 (09:25 +0000)]
buildd get minimal firewalls
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 7 Mar 2010 09:22:42 +0000 (10:22 +0100)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Sun, 7 Mar 2010 09:20:19 +0000 (10:20 +0100)]
lets try the first buildd: ball
Stephen Gran [Sun, 7 Mar 2010 09:00:53 +0000 (09:00 +0000)]
this should be cool
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 08:35:56 +0000 (08:35 +0000)]
Revert "we want counters"
This reverts commit
f2f9d3efab7262bbdfb4e51feebfa6bd8aebc9a8.
Stephen Gran [Sun, 7 Mar 2010 08:32:59 +0000 (08:32 +0000)]
get the ferm variable right
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 08:31:55 +0000 (08:31 +0000)]
and add a nop rule for munin
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 7 Mar 2010 08:23:48 +0000 (08:23 +0000)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sun, 7 Mar 2010 08:23:42 +0000 (08:23 +0000)]
new ipaddress fact
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 7 Mar 2010 07:15:52 +0000 (08:15 +0100)]
steffani being a recursor
Martin Zobel-Helas [Sat, 6 Mar 2010 21:49:04 +0000 (22:49 +0100)]
add steffani to ferm
Martin Zobel-Helas [Sat, 6 Mar 2010 21:24:28 +0000 (22:24 +0100)]
add wieck to ferm
Martin Zobel-Helas [Sat, 6 Mar 2010 20:36:15 +0000 (21:36 +0100)]
schein runs a local dns
Martin Zobel-Helas [Sat, 6 Mar 2010 20:30:01 +0000 (21:30 +0100)]
add schein
Martin Zobel-Helas [Sat, 6 Mar 2010 20:15:43 +0000 (21:15 +0100)]
add raff+gluck to ferm
Martin Zobel-Helas [Sat, 6 Mar 2010 19:27:54 +0000 (20:27 +0100)]
add lobos to ferm
Martin Zobel-Helas [Sat, 6 Mar 2010 19:24:09 +0000 (20:24 +0100)]
add villa to ferm
Martin Zobel-Helas [Sat, 6 Mar 2010 18:30:55 +0000 (19:30 +0100)]
remove obsolete modules
Martin Zobel-Helas [Sat, 6 Mar 2010 18:30:41 +0000 (19:30 +0100)]
we want counters
Martin Zobel-Helas [Sat, 6 Mar 2010 18:14:34 +0000 (19:14 +0100)]
ah, : missing
Martin Zobel-Helas [Sat, 6 Mar 2010 18:10:37 +0000 (19:10 +0100)]
typo?
Martin Zobel-Helas [Sat, 6 Mar 2010 18:04:50 +0000 (19:04 +0100)]
saens alone
Martin Zobel-Helas [Sat, 6 Mar 2010 18:02:15 +0000 (19:02 +0100)]
move ftp and rsync to site.pp
Martin Zobel-Helas [Sat, 6 Mar 2010 17:41:50 +0000 (18:41 +0100)]
add module ftp
Martin Zobel-Helas [Sat, 6 Mar 2010 17:38:29 +0000 (18:38 +0100)]
weasel is always right
Martin Zobel-Helas [Sat, 6 Mar 2010 17:36:57 +0000 (18:36 +0100)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Conflicts:
manifests/site.pp
Martin Zobel-Helas [Sat, 6 Mar 2010 17:30:55 +0000 (18:30 +0100)]
start ferm'ing security mirrors
Stephen Gran [Sat, 6 Mar 2010 15:33:07 +0000 (15:33 +0000)]
see if global_variables works
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 15:31:59 +0000 (15:31 +0000)]
and not cause a syntax error
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 15:31:14 +0000 (15:31 +0000)]
and actually ship it
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 15:29:49 +0000 (15:29 +0000)]
add first stab at interfaces
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:37:07 +0000 (13:37 +0000)]
try in place array, but with bonus for syntactic correctness
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:36:00 +0000 (13:36 +0000)]
try in place array
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:33:19 +0000 (13:33 +0000)]
restore stunnel rule
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:28:12 +0000 (13:28 +0000)]
humph
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:23:13 +0000 (13:23 +0000)]
first stab at http limit rules - how bad can it go?
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 13:07:50 +0000 (13:07 +0000)]
piatti has ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:57:43 +0000 (12:57 +0000)]
let's see if this works
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:53:53 +0000 (12:53 +0000)]
Revert "first stab at opening firewall for actual mail port"
This reverts commit
8aa9460c4f37da95c931dd25eb2b3ab0512f6afd.
Stephen Gran [Sat, 6 Mar 2010 12:53:47 +0000 (12:53 +0000)]
Revert "er, not a case statement"
This reverts commit
14275a7a8892845f59f12a86945da4c7effc643c.
Stephen Gran [Sat, 6 Mar 2010 12:51:27 +0000 (12:51 +0000)]
er, not a case statement
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:50:48 +0000 (12:50 +0000)]
first stab at opening firewall for actual mail port
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:50:29 +0000 (12:50 +0000)]
add submission for mx machines
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:40:44 +0000 (12:40 +0000)]
nagios also wants to talk smtp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:21:17 +0000 (12:21 +0000)]
convert ssh to new rule format
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:19:39 +0000 (12:19 +0000)]
quoting, maybe
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:17:52 +0000 (12:17 +0000)]
another try
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 12:14:19 +0000 (12:14 +0000)]
restrict smtp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 6 Mar 2010 11:56:37 +0000 (11:56 +0000)]
beethoven has ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Fri, 5 Mar 2010 22:25:56 +0000 (23:25 +0100)]
try with the correct path name
Martin Zobel-Helas [Fri, 5 Mar 2010 22:24:05 +0000 (23:24 +0100)]
does order matter?
Martin Zobel-Helas [Fri, 5 Mar 2010 22:05:34 +0000 (23:05 +0100)]
damn typo