mirror/dsa-puppet.git
6 years agoDrop alioth zone from named config
Julien Cristau [Tue, 27 Feb 2018 10:07:45 +0000 (11:07 +0100)]
Drop alioth zone from named config

6 years agoFix /etc/repro/radius-servers more
Julien Cristau [Mon, 26 Feb 2018 20:46:01 +0000 (21:46 +0100)]
Fix /etc/repro/radius-servers more

6 years agoFix /etc/repro/radius-servers
Julien Cristau [Mon, 26 Feb 2018 20:43:29 +0000 (21:43 +0100)]
Fix /etc/repro/radius-servers

6 years agoConfiguration item "hashsize" is deprecated
Julien Cristau [Mon, 26 Feb 2018 20:33:55 +0000 (21:33 +0100)]
Configuration item "hashsize" is deprecated

6 years agoConfiguration item "allowmultiplekeys" is deprecated
Julien Cristau [Mon, 26 Feb 2018 20:32:07 +0000 (21:32 +0100)]
Configuration item "allowmultiplekeys" is deprecated

6 years agoConfiguration item "ignorenislike" is deprecated
Julien Cristau [Mon, 26 Feb 2018 20:30:41 +0000 (21:30 +0100)]
Configuration item "ignorenislike" is deprecated

6 years agoAnd fixup another path
Julien Cristau [Mon, 26 Feb 2018 20:28:56 +0000 (21:28 +0100)]
And fixup another path

6 years agoFix path to template
Julien Cristau [Mon, 26 Feb 2018 20:12:55 +0000 (21:12 +0100)]
Fix path to template

6 years agoDisable default freeradius sites I don't think we want
Julien Cristau [Mon, 26 Feb 2018 20:09:25 +0000 (21:09 +0100)]
Disable default freeradius sites I don't think we want

6 years agoAttempt to pull in some of the freeradius config from rtc.d.o
Julien Cristau [Mon, 26 Feb 2018 20:06:07 +0000 (21:06 +0100)]
Attempt to pull in some of the freeradius config from rtc.d.o

6 years agoAlso put bacula messages into syslog
Peter Palfrader [Mon, 26 Feb 2018 09:26:52 +0000 (10:26 +0100)]
Also put bacula messages into syslog

6 years agoDisable scheduling for backup jobs in preparation of deploying our own scheduler
Peter Palfrader [Sat, 24 Feb 2018 12:53:16 +0000 (13:53 +0100)]
Disable scheduling for backup jobs in preparation of deploying our own scheduler

6 years agoOnly add host to bacula dsa client list if we do backups for it
Peter Palfrader [Sat, 24 Feb 2018 11:20:35 +0000 (12:20 +0100)]
Only add host to bacula dsa client list if we do backups for it

6 years agoUpdate (c) year
Peter Palfrader [Sat, 24 Feb 2018 09:18:34 +0000 (10:18 +0100)]
Update (c) year

6 years agoBe more defensive when removing potentially obsolete pools
Peter Palfrader [Sat, 24 Feb 2018 09:16:09 +0000 (10:16 +0100)]
Be more defensive when removing potentially obsolete pools

6 years agocollect backup client list in a plain text file
Peter Palfrader [Sat, 24 Feb 2018 08:59:30 +0000 (09:59 +0100)]
collect backup client list in a plain text file

6 years agobacula: remove obsolete pools
Peter Palfrader [Fri, 23 Feb 2018 23:11:22 +0000 (00:11 +0100)]
bacula: remove obsolete pools

6 years agoRedirect all of *.pages to https (re: RT#7072)
Peter Palfrader [Fri, 23 Feb 2018 22:00:47 +0000 (23:00 +0100)]
Redirect all of *.pages to https (re: RT#7072)

6 years agomirror-health: set User-Agent http header
Julien Cristau [Fri, 23 Feb 2018 15:21:06 +0000 (16:21 +0100)]
mirror-health: set User-Agent http header

6 years agoRevert "Make security -> security-cdn redirect global, not just for the linux package"
Julien Cristau [Fri, 23 Feb 2018 15:06:26 +0000 (16:06 +0100)]
Revert "Make security -> security-cdn redirect global, not just for the linux package"

I need to update the mirror health check to account for this.

This reverts commit d8b6b760a99f36fc6bf6088b8e998c1d67d46ab6.

6 years agoMake security -> security-cdn redirect global, not just for the linux package
Julien Cristau [Fri, 23 Feb 2018 14:58:23 +0000 (15:58 +0100)]
Make security -> security-cdn redirect global, not just for the linux package

6 years agoDrop security-cdn.d.o on stretch
Aurelien Jarno [Thu, 22 Feb 2018 22:24:26 +0000 (23:24 +0100)]
Drop security-cdn.d.o on stretch

Now that security.d.o as a SRV record basically pointing to
security-cdn.d.o, there is no point to have both in the sources.list
for stretch hosts.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agostorace also makes ACPI noises about power_meter
Julien Cristau [Thu, 22 Feb 2018 22:04:10 +0000 (23:04 +0100)]
storace also makes ACPI noises about power_meter

6 years agowe do not need to backup clamav-unofficial-sigs files
Martin Zobel-Helas [Wed, 21 Feb 2018 21:32:39 +0000 (22:32 +0100)]
we do not need to backup clamav-unofficial-sigs files

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agopush empty /var/lib/varnish/.nobackup
Martin Zobel-Helas [Wed, 21 Feb 2018 21:05:21 +0000 (22:05 +0100)]
push empty /var/lib/varnish/.nobackup

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agomirror-conova also does lots of ACPI power-meter dmesg noise
Julien Cristau [Wed, 21 Feb 2018 08:13:57 +0000 (09:13 +0100)]
mirror-conova also does lots of ACPI power-meter dmesg noise

6 years agoDecommission mirror-bytemark
Aurelien Jarno [Mon, 19 Feb 2018 18:56:52 +0000 (19:56 +0100)]
Decommission mirror-bytemark

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoFix check url for security mirror health
Julien Cristau [Mon, 19 Feb 2018 10:03:51 +0000 (11:03 +0100)]
Fix check url for security mirror health

It's still not ideal because an oldstable-only update won't be picked
up, but at least it exists.

6 years agoRun dsa-check-openmanage on schumann and wieck
Julien Cristau [Sun, 18 Feb 2018 12:27:05 +0000 (13:27 +0100)]
Run dsa-check-openmanage on schumann and wieck

6 years agomirror-bytemark no longer a fastly backend for /debian/
Julien Cristau [Sat, 17 Feb 2018 14:41:19 +0000 (15:41 +0100)]
mirror-bytemark no longer a fastly backend for /debian/

6 years agomake schumann a fastly backend for security
Julien Cristau [Sat, 17 Feb 2018 09:18:43 +0000 (10:18 +0100)]
make schumann a fastly backend for security

6 years agoRemove /srv/ftp.root from security mirrors
Aurelien Jarno [Fri, 16 Feb 2018 20:23:25 +0000 (21:23 +0100)]
Remove /srv/ftp.root from security mirrors

They do not serve FTP anymore so the archive can be located directly
in /srv/mirrors/debian-security like for other archive.

Do not create the /srv/mirrors/debian-security, as it might still be a
symlink, and ftpsync will create it. This actually matches what is done
for the other archive.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoServe security mirrors from /srv/mirrors/debian-security
Aurelien Jarno [Fri, 16 Feb 2018 20:07:56 +0000 (21:07 +0100)]
Serve security mirrors from /srv/mirrors/debian-security

In preparation for the /srv/ftp.root removal

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoImport facts from schumann
Julien Cristau [Fri, 16 Feb 2018 08:27:23 +0000 (09:27 +0100)]
Import facts from schumann

6 years agoDrop m68k@buildd.debian.org -> m68k-build@nocrew.org rewrite
Aurelien Jarno [Thu, 15 Feb 2018 19:33:24 +0000 (20:33 +0100)]
Drop m68k@buildd.debian.org -> m68k-build@nocrew.org rewrite

I have no idea why this is done, but we don't want that.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoAdd schumann to the security_mirror role
Julien Cristau [Thu, 15 Feb 2018 16:34:05 +0000 (17:34 +0100)]
Add schumann to the security_mirror role

6 years agoMerge remote-tracking branch 'zobel-salsa/zobel-salsa'
Martin Zobel-Helas [Thu, 15 Feb 2018 07:40:55 +0000 (08:40 +0100)]
Merge remote-tracking branch 'zobel-salsa/zobel-salsa'

6 years agoMerge branch 'zobel-salsa'
Martin Zobel-Helas [Thu, 15 Feb 2018 07:39:47 +0000 (08:39 +0100)]
Merge branch 'zobel-salsa'

6 years agoRemove lobos from fastly security backends for now
Julien Cristau [Thu, 15 Feb 2018 07:25:24 +0000 (08:25 +0100)]
Remove lobos from fastly security backends for now

We want to see how it does with 2 dedicated backends (villa and wieck).

6 years agodupload.conf: fix a thinko in the security upload hostname
Aurelien Jarno [Thu, 15 Feb 2018 07:11:16 +0000 (08:11 +0100)]
dupload.conf: fix a thinko in the security upload hostname

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agobuildd: do security uploads using SSH
Aurelien Jarno [Wed, 14 Feb 2018 18:23:21 +0000 (19:23 +0100)]
buildd: do security uploads using SSH

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agorsync-ssh-wrap: force the permissions of uploaded files
Aurelien Jarno [Wed, 14 Feb 2018 16:33:17 +0000 (17:33 +0100)]
rsync-ssh-wrap: force the permissions of uploaded files

dupload calls rsync with -p, causing the uploaded files to be world
readable, despite the ACL of the upload directory (see bug#876900).
This is an issue for security uploads.

This has been fixed in sid, but not yet in stretch. In the meantime
force the permissions to 0640 at the wrapper level.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoplanet-master.d.o: fix a thinko in my previous commit
Aurelien Jarno [Wed, 14 Feb 2018 11:49:38 +0000 (12:49 +0100)]
planet-d.o: fix a thinko in my previous commit

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoplanet-master.d.o: only allow access from localhost and local IP
Aurelien Jarno [Wed, 14 Feb 2018 11:43:27 +0000 (12:43 +0100)]
planet-d.o: only allow access from localhost and local IP

This way it's possible to access planet-master.d.o using SSH as a socks
proxy. It requires to connect to planet-master.d.o aka philp.d.o instead
of any debian machine.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years ago99builddsourceslist: access the security archive using https
Aurelien Jarno [Tue, 13 Feb 2018 13:33:55 +0000 (14:33 +0100)]
99builddsourceslist: access the security archive using https

Let's try again!

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agolintian.d.o: fix deflate output filter
Aurelien Jarno [Wed, 14 Feb 2018 09:52:25 +0000 (10:52 +0100)]
lintian.d.o: fix deflate output filter

It appears that AddOutputFilterByType options also apply to the
subdirectories. However this directive overwrites the default value or
the one defined in the parent directory.

Therefore we only want to add this directive to the root directory and
with all the mime types.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoMerge remote-tracking branch 'waldi-salsa/godard-apache' into HEAD
Martin Zobel-Helas [Tue, 13 Feb 2018 21:50:36 +0000 (22:50 +0100)]
Merge remote-tracking branch 'waldi-salsa/godard-apache' into HEAD

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoMock more certificates
Bastian Blank [Tue, 13 Feb 2018 21:37:55 +0000 (22:37 +0100)]
Mock more certificates

6 years agoRT#7092: Apache on godard adds an additional X-Xss-Protection
Martin Zobel-Helas [Fri, 9 Feb 2018 17:18:36 +0000 (18:18 +0100)]
RT#7092: Apache on godard adds an additional X-Xss-Protection

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoImport facts from godard
Bastian Blank [Tue, 13 Feb 2018 19:45:51 +0000 (20:45 +0100)]
Import facts from godard

6 years agooctocatalog: add dummy file for LE service certs
Martin Zobel-Helas [Sat, 10 Feb 2018 08:47:33 +0000 (09:47 +0100)]
octocatalog: add dummy file for LE service certs

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoMock ldapinfo during octocatalog runs
Bastian Blank [Tue, 13 Feb 2018 21:09:51 +0000 (22:09 +0100)]
Mock ldapinfo during octocatalog runs

6 years agoMerge branch 'lintian.d.o-tweaks' of https://salsa.debian.org/nthykier/dsa-puppet
Aurelien Jarno [Tue, 13 Feb 2018 21:18:25 +0000 (22:18 +0100)]
Merge branch 'lintian.d.o-tweaks' of https://salsa.debian.org/nthykier/dsa-puppet

6 years agostatic_mirror: enable deflate and filter modules
Aurelien Jarno [Tue, 13 Feb 2018 21:16:29 +0000 (22:16 +0100)]
static_mirror: enable deflate and filter modules

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoInstall ca-certificates in the buildd chroots
Aurelien Jarno [Tue, 13 Feb 2018 20:30:52 +0000 (21:30 +0100)]
Install ca-certificates in the buildd chroots

This is need in addition of apt-transport-https.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agolintian.d.o: Move svg compression to the resources directory
Niels Thykier [Tue, 13 Feb 2018 19:25:41 +0000 (19:25 +0000)]
lintian.d.o: Move svg compression to the resources directory

It does not appear to propogate on its own, so move it from the root
to the "resources" directory section.  There are no SVG images outside
that directory anyway.

Signed-off-by: Niels Thykier <niels@thykier.net>
6 years agolintian.d.o: Remove redundant + incorrect IfModule mod_userdir
Niels Thykier [Tue, 13 Feb 2018 19:25:02 +0000 (19:25 +0000)]
lintian.d.o: Remove redundant + incorrect IfModule mod_userdir

Signed-off-by: Niels Thykier <niels@thykier.net>
6 years agoRevert "99builddsourceslist: access the security archive using https"
Aurelien Jarno [Tue, 13 Feb 2018 14:17:33 +0000 (15:17 +0100)]
Revert "99builddsourceslist: access the security archive using https"

This reverts commit f77a22de23c38230527be61375482971dea55fef.

This doesn't work, we also need ca-certificate in the chroot :-(

6 years ago99builddsourceslist: access the security archive using https
Aurelien Jarno [Tue, 13 Feb 2018 13:33:55 +0000 (14:33 +0100)]
99builddsourceslist: access the security archive using https

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoFully retire spontini.d.o
Aurelien Jarno [Tue, 13 Feb 2018 11:54:26 +0000 (12:54 +0100)]
Fully retire spontini.d.o

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoAlso drop security anycast-test mirrors
Aurelien Jarno [Tue, 13 Feb 2018 11:11:22 +0000 (12:11 +0100)]
Also drop security anycast-test mirrors

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agosnapshot storage nodes want the toolchain to build the snapshot fsck utility
Peter Palfrader [Tue, 13 Feb 2018 10:26:15 +0000 (11:26 +0100)]
snapshot storage nodes want the toolchain to build the snapshot fsck utility

6 years agosetup-dchroot: fix a typo
Aurelien Jarno [Tue, 13 Feb 2018 09:30:53 +0000 (10:30 +0100)]
setup-dchroot: fix a typo

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoInstall apt-transport-https in the buildd chroots
Aurelien Jarno [Tue, 13 Feb 2018 08:54:39 +0000 (09:54 +0100)]
Install apt-transport-https in the buildd chroots

This will be used to access the security archive in a more private way.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoDrop anycast-test mirrors from apt
Aurelien Jarno [Tue, 13 Feb 2018 08:44:03 +0000 (09:44 +0100)]
Drop anycast-test mirrors from apt

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoMore kfreebsd removal
Aurelien Jarno [Tue, 13 Feb 2018 08:15:10 +0000 (09:15 +0100)]
More kfreebsd removal

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agosetup-all-dchroots: get rid of kfreebsd and ppc64
Aurelien Jarno [Tue, 13 Feb 2018 07:47:40 +0000 (08:47 +0100)]
setup-all-dchroots: get rid of kfreebsd and ppc64

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agonagios: use dsa-check-systemd-services instead of systemctl is-system-running
Peter Palfrader [Sun, 11 Feb 2018 10:20:27 +0000 (11:20 +0100)]
nagios: use dsa-check-systemd-services instead of systemctl is-system-running

6 years agoAlso systemctl reset-failed failed session-nnn.scope
Peter Palfrader [Sun, 11 Feb 2018 10:02:25 +0000 (11:02 +0100)]
Also systemctl reset-failed failed session-nnn.scope

6 years agoMove failed rsync cleanup into systemd module
Peter Palfrader [Sun, 11 Feb 2018 09:58:08 +0000 (10:58 +0100)]
Move failed rsync cleanup into systemd module

6 years agooctocatalog: add dummy file for LE service certs
Martin Zobel-Helas [Sat, 10 Feb 2018 08:47:33 +0000 (09:47 +0100)]
octocatalog: add dummy file for LE service certs

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoMerge remote-tracking branch 'origin/master' into zobel-salsa
Martin Zobel-Helas [Sat, 10 Feb 2018 08:42:16 +0000 (09:42 +0100)]
Merge remote-tracking branch 'origin/master' into zobel-salsa

6 years agoFixup local-mirror.cdbuilder sites-enabled symlink name
Julien Cristau [Sat, 10 Feb 2018 07:59:40 +0000 (08:59 +0100)]
Fixup local-mirror.cdbuilder sites-enabled symlink name

6 years agoAdd {deb,security}.d.o aliases to local-mirror.cdbuilder
Julien Cristau [Sat, 10 Feb 2018 07:58:52 +0000 (08:58 +0100)]
Add {deb,security}.d.o aliases to local-mirror.cdbuilder

6 years agouse ttyS1 for the serial console on casulana
Peter Palfrader [Fri, 9 Feb 2018 20:23:28 +0000 (21:23 +0100)]
use ttyS1 for the serial console on casulana

6 years agoGet trailing slashes right for aliases
Peter Palfrader [Fri, 9 Feb 2018 19:49:14 +0000 (20:49 +0100)]
Get trailing slashes right for aliases

6 years agoFirst go at cdbuilder local mirror export (re: RT##7101)
Peter Palfrader [Fri, 9 Feb 2018 19:41:56 +0000 (20:41 +0100)]
First go at cdbuilder local mirror export (re: RT##7101)

6 years agoAdd a apache_not_public role where we do not add ferm allow rules and put casulana...
Peter Palfrader [Fri, 9 Feb 2018 19:03:17 +0000 (20:03 +0100)]
Add a apache_not_public role where we do not add ferm allow rules and put casulana into it

6 years agono more experimental_apache (previously cgi-grnet-01, pejacevic, petrova)
Peter Palfrader [Fri, 9 Feb 2018 19:00:00 +0000 (20:00 +0100)]
no more experimental_apache (previously cgi-grnet-01, pejacevic, petrova)

6 years agoAdd cdbuilder-logs static component (re: RT##7101)
Peter Palfrader [Fri, 9 Feb 2018 18:32:09 +0000 (19:32 +0100)]
Add cdbuilder-logs static component (re: RT##7101)

6 years agoAdd casulana as a static source for cdbuilder-logs (re: RT##7101)
Peter Palfrader [Fri, 9 Feb 2018 18:27:21 +0000 (19:27 +0100)]
Add casulana as a static source for cdbuilder-logs (re: RT##7101)

6 years agoMerge branch 'master' into zobel-salsa
Martin Zobel-Helas [Fri, 9 Feb 2018 17:25:45 +0000 (18:25 +0100)]
Merge branch 'master' into zobel-salsa

6 years agoRT#7092: Apache on godard adds an additional X-Xss-Protection
Martin Zobel-Helas [Fri, 9 Feb 2018 17:18:36 +0000 (18:18 +0100)]
RT#7092: Apache on godard adds an additional X-Xss-Protection

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoTest with Puppet 4.8
Bastian Blank [Fri, 9 Feb 2018 13:02:52 +0000 (14:02 +0100)]
Test with Puppet 4.8

6 years agoUpdate facts
Bastian Blank [Fri, 9 Feb 2018 12:58:29 +0000 (13:58 +0100)]
Update facts

6 years agoMove nagios stuff
Bastian Blank [Fri, 9 Feb 2018 12:49:13 +0000 (13:49 +0100)]
Move nagios stuff

6 years agoMove generated cert files to new location
Bastian Blank [Fri, 9 Feb 2018 12:45:03 +0000 (13:45 +0100)]
Move generated cert files to new location

6 years agoUpdate octocatalog job
Bastian Blank [Fri, 9 Feb 2018 12:28:28 +0000 (13:28 +0100)]
Update octocatalog job

6 years agoTest with Puppet 4.8
Bastian Blank [Fri, 9 Feb 2018 13:02:52 +0000 (14:02 +0100)]
Test with Puppet 4.8

6 years agoUpdate facts
Bastian Blank [Fri, 9 Feb 2018 12:58:29 +0000 (13:58 +0100)]
Update facts

6 years agoMove nagios stuff
Bastian Blank [Fri, 9 Feb 2018 12:49:13 +0000 (13:49 +0100)]
Move nagios stuff

6 years agoMove generated cert files to new location
Bastian Blank [Fri, 9 Feb 2018 12:45:03 +0000 (13:45 +0100)]
Move generated cert files to new location

6 years agoUpdate octocatalog job
Bastian Blank [Fri, 9 Feb 2018 12:28:28 +0000 (13:28 +0100)]
Update octocatalog job

6 years agorsync on lw09,lw10
Peter Palfrader [Fri, 9 Feb 2018 09:19:26 +0000 (10:19 +0100)]
rsync on lw09,lw10

6 years agoupdate lw autotab
Peter Palfrader [Fri, 9 Feb 2018 08:38:23 +0000 (09:38 +0100)]
update lw autotab

6 years agoupdate lw autotab
Peter Palfrader [Fri, 9 Feb 2018 08:28:27 +0000 (09:28 +0100)]
update lw autotab

6 years agodo nfs server setup on lw09/lw10
Peter Palfrader [Fri, 9 Feb 2018 08:11:24 +0000 (09:11 +0100)]
do nfs server setup on lw09/lw10

6 years agono more 10/8 network at leaseweb
Peter Palfrader [Fri, 9 Feb 2018 08:10:57 +0000 (09:10 +0100)]
no more 10/8 network at leaseweb

6 years agoremove sgran from root keys
Martin Zobel-Helas [Thu, 8 Feb 2018 16:26:48 +0000 (17:26 +0100)]
remove sgran from root keys

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoremove sgran IP range. he can hop via master if needed
Martin Zobel-Helas [Thu, 8 Feb 2018 16:25:54 +0000 (17:25 +0100)]
remove sgran IP range. he can hop via master if needed

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>