do not run an authority on draghi
authorPeter Palfrader <peter@palfrader.org>
Mon, 30 Dec 2013 22:56:00 +0000 (23:56 +0100)
committerPeter Palfrader <peter@palfrader.org>
Mon, 30 Dec 2013 22:56:00 +0000 (23:56 +0100)
manifests/site.pp
modules/ferm/manifests/per-host.pp
modules/sudo/files/sudoers

index 24f330a..ab6fd7d 100644 (file)
@@ -86,7 +86,7 @@ node default {
                include apache2
        }
 
-       if $::hostname in [ravel,senfl,orff,draghi,diamond,rietz,denis] {
+       if $::hostname in [ravel,senfl,orff,diamond,rietz,denis] {
                include named::authoritative
        } elsif $::hostname in [geo1,geo2,geo3] {
                include named::geodns
index 2a48908..818c2aa 100644 (file)
@@ -74,11 +74,6 @@ class ferm::per-host {
                        }
                }
                draghi: {
-                       #@ferm::rule { 'dsa-bind':
-                       #    domain          => '(ip ip6)',
-                       #    description     => 'Allow nameserver access',
-                       #    rule            => '&TCP_UDP_SERVICE(53)'
-                       #}
                        @ferm::rule { 'dsa-finger':
                                domain          => '(ip ip6)',
                                description     => 'Allow finger access',
index 18eea46..71b7245 100644 (file)
@@ -155,10 +155,9 @@ debwww             wolkenstein=(staticsync)        NOPASSWD: /usr/local/bin/static-update-componen
 piupartss      PIUPARTS_SLAVE_HOSTS=(ALL)              NOPASSWD: ALL
 # trigger of mirror run for packages
 #pkg_user      powell=(archvsync)      NOPASSWD: /home/archvsync/bin/pushpdo
-# on draghi, the domains git thing will run bind9 reload afterwards
 dnsadm         denis=(root)                    NOPASSWD: /usr/sbin/service bind9 reload
-%dnsadm                draghi,orff=(root)              NOPASSWD: /etc/init.d/bind9 reload
-%dnsadm                draghi,orff=(geodnssync)        NOPASSWD: /usr/bin/make -C /srv/dns.debian.org/geo
+%dnsadm                orff=(root)             NOPASSWD: /etc/init.d/bind9 reload
+%dnsadm                orff=(geodnssync)       NOPASSWD: /usr/bin/make -C /srv/dns.debian.org/geo
 %adm           draghi=(puppet)                 NOPASSWD: /usr/bin/make -s -C /srv/db.debian.org/var/gitnagios/dsa-nagios/config install
 # wbadm can update all buildd* users' keys on buildd.d.o
 %wbadm         BUILDD_MASTER=(wb-buildd)       ALL