]> git.donarmstrong.com Git - dsa-puppet.git/blobdiff - modules/samhain/templates/samhainrc.erb
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa...
[dsa-puppet.git] / modules / samhain / templates / samhainrc.erb
index e9ce52fcc6c93855154193ab56dd2d3440df25af..89c341f92a1e18252a1e3a0c5c298e66ad52600c 100644 (file)
@@ -67,6 +67,9 @@
 # RedefIgnoreNone=(no default)
 # RedefUser0=(no default)
 # RedefUser1=(no default)
+<% if nodeinfo['buildd'] -%>
+IgnoreMissing=/etc/lvm/archive/.*.vg
+<% end -%>
 
 [Attributes]
 ##
 file=/etc/mtab
 file=/etc/ssh_random_seed
 file=/etc/asound.conf
+<% case hoster when "ubcece", "darmstadt", "ftcollins", "grnet" then -%>
+<% else -%>
 file=/etc/resolv.conf
+<% end -%>
 file=/etc/localtime
 file=/etc/ioctl.save
 file=/etc/passwd.backup
@@ -89,8 +95,16 @@ file=/etc/network/run/ifstate
 file=/var/state/samhain/samhain_file
 file=/etc/bind/zones/db.debian.net
 file=/etc/exim4/bsmtp
-
-
+<% if classes.include?("named::geodns") -%>
+file=/etc/bind
+file=/etc/bind/named.conf.acl
+file=/etc/bind/named.conf.local
+file=/etc/bind/geodns/named.conf.geo
+file=/etc/bind/geodns/recvconf.files
+<% end -%>
+<% if classes.include?("named") -%>
+file=/etc/bind/named.conf.options
+<% end -%>
 
 #
 # There are files in /etc that might change, thus changing the directory
@@ -100,10 +114,15 @@ file=/etc
 file=/etc/ssh
 file=/etc/network/run
 file=/etc/bind/zones
+file=/etc/spamassassin/sa-update-keys
 
 # These are the directories for the files we handle with puppet
+file=/etc/apache2/conf.d
+files=/etc/apache2/mods-enabled
 file=/etc/samhain
 file=/etc/munin
+file=/etc/munin/plugins
+file=/etc/munin/plugin-conf.d
 file=/etc/exim4
 file=/etc/exim4/ssl
 file=/etc/apt
@@ -113,21 +132,23 @@ file=/etc/default
 file=/etc/logrotate.d
 file=/etc/nagios
 file=/etc/nagios/nrpe.d
-<%= extradir=""
-case fqdn 
-when "spohr.debian.org": extradir="file=/etc/nagios3/puppetconf.d
-file=/etc/puppet"
-else extradir="file=/etc/puppet"
-end
-extradir
-%>
+file=/etc/nagios/obsolete-packages-ignore.d
+file=/etc/bind/geodns
+<% if nodeinfo['nagiosmaster'] -%>
+file=/etc/nagios3/puppetconf.d
+<% end -%>
+file=/etc/puppet
 file=/etc/cron.d
 file=/usr/lib/nagios/plugins
 file=/usr/sbin
 file=/etc/monit
 file=/etc/monit/monit.d
 file=/etc/pam.d
+file=/etc/sysctl.d
 file=/etc/syslog-ng
+file=/etc/ferm/
+file=/etc/ferm/conf.d
+file=/etc/ferm/dsa.d
 
 
 [LogFiles]
@@ -190,6 +211,9 @@ file=/var/log/syslog
 ##
 ## This file might be created or removed by the system sometimes.
 ##
+<% case hoster when "ubcece", "darmstadt", "ftcollins", "grnet" then -%>
+file=/etc/resolv.conf
+<% end -%>
 file=/etc/resolv.conf.pcmcia.save
 file=/etc/nologin
 file=/etc/postfix/debian.db
@@ -207,10 +231,13 @@ file=/etc/resolv.conf.dhclient-new
 # We handle these files with puppet - please to not be bothering us
 file=/etc/timezone
 file=/etc/motd.tail
+file=/etc/ntp.conf
 file=/etc/samhain/samhainrc
 file=/etc/munin/munin-node.conf
+file=/etc/munin/plugin-conf.d/munin-node
 file=/etc/userdir-ldap.confc
 file=/etc/exim4/blacklist
+file=/etc/exim4/host_blacklist
 file=/etc/exim4/callout_users
 file=/etc/exim4/exim4.conf
 file=/etc/exim4/grey_users
@@ -219,16 +246,17 @@ file=/etc/exim4/locals
 file=/etc/exim4/localusers
 file=/etc/exim4/manualroute
 file=/etc/exim4/rbllist
-file=/etc/exim4/rcpthosts
 file=/etc/exim4/rhsbllist
+file=/etc/exim4/submission-domains
 file=/etc/exim4/virtualdomains
 file=/etc/exim4/whitelist
-file=/etc/exim4/local-auto.conf
 file=/etc/exim4/local-settings.conf
 file=/etc/exim4/ssl/ca.crt
 file=/etc/exim4/ssl/ca.crl
 file=/etc/exim4/ssl/thishost.crt
 file=/etc/exim4/ssl/thishost.key
+file=/etc/ssh/ssh_config
+file=/etc/ssh/sshd_config
 <%=
 out=""
 if not nodeinfo['heavy_exim'].empty?
@@ -236,10 +264,53 @@ if not nodeinfo['heavy_exim'].empty?
 file=/etc/exim4/surbl_whitelist.txt
 file=/etc/exim4/exim_surbl.pl
 file=/etc/exim4/ccTLD.txt
+file=/etc/clamav-unofficial-sigs.conf
+file=/etc/clamav-unofficial-sigs.dsa.conf
 '
 end
 out
 %>
+file=/etc/munin/plugins/bind
+file=/etc/munin/plugins/bind_views
+file=/etc/munin/plugins/cpu
+file=/etc/munin/plugins/df
+file=/etc/munin/plugins/df_abs
+file=/etc/munin/plugins/df_inode
+file=/etc/munin/plugins/entropy
+file=/etc/munin/plugins/forks
+file=/etc/munin/plugins/interrupts
+file=/etc/munin/plugins/iostat
+file=/etc/munin/plugins/irqstats
+file=/etc/munin/plugins/load
+file=/etc/munin/plugins/memory
+file=/etc/munin/plugins/ntp_offset
+file=/etc/munin/plugins/ntp_states
+file=/etc/munin/plugins/open_files
+file=/etc/munin/plugins/open_inodes
+file=/etc/munin/plugins/processes
+file=/etc/munin/plugins/ps_apache2
+file=/etc/munin/plugins/ps_exim4
+file=/etc/munin/plugins/ps_vsftpd
+file=/etc/munin/plugins/spamassassin
+file=/etc/munin/plugins/swap
+file=/etc/munin/plugins/uptime
+file=/etc/munin/plugins/vmstat
+file=/etc/munin/plugins/vfstpd
+file=/etc/munin/plugins/apache_accesses
+file=/etc/munin/plugins/apache_processes
+file=/etc/munin/plugins/apache_volume
+file=/etc/munin/plugins/apache_servers
+file=/etc/munin/plugins/exim_mailqueue
+file=/etc/munin/plugins/exim_mailstats
+file=/etc/munin/plugins/postfix_mailqueue
+file=/etc/munin/plugins/postfix_mailvolume
+file=/etc/apache2/conf.d/ressource-limits
+file=/etc/apache2/mods-enabled/info.conf
+file=/etc/apache2/mods-enabled/info.load
+file=/etc/apache2/mods-enabled/server.conf
+file=/etc/apache2/mods-enabled/server.load
+file=/etc/apache2/conf.d/server-status
+file=/etc/apache2/conf.d/local-serverinfo
 file=/etc/apt/preferences
 file=/etc/apt/sources.list.d/volatile.list
 file=/etc/apt/sources.list.d/security.list
@@ -262,6 +333,7 @@ file=/usr/sbin/dsa-update-samhain-status
 file=/etc/nagios/nrpe.d/nrpe_dsa.cfg
 file=/etc/nagios/nrpe.d/debianorg.cfg
 file=/etc/nagios/obsolete-packages-ignore
+file=/etc/nagios/obsolete-packages-ignore.d/hostspecific
 file=/usr/lib/nagios/plugins/dsa-check-packages
 file=/usr/lib/nagios/plugins/dsa-check-soas
 file=/usr/lib/nagios/plugins/dsa-check-mirrorsync
@@ -281,22 +353,46 @@ file=/usr/lib/nagios/plugins/dsa-check-raid-areca
 file=/usr/lib/nagios/plugins/dsa-check-raid-sw
 file=/usr/lib/nagios/plugins/dsa-update-samhain-status
 file=/etc/sudoers
+file=/etc/sysctl.d/mmap_min_addr.conf
 file=/etc/pam.d/sudo
 file=/etc/monit/monitrc
 file=/etc/monit/monit.d/01puppet
 file=/etc/monit/monit.d/00debian.org
-<%= extrafiles=""
-case fqdn 
-when "spohr.debian.org": extrafiles="file=/etc/nagios3/puppetconf.d/auto-hostgroups.cfg
+file=/etc/cron.d/dsa-puppet-stuff
+file=/etc/cron.d/dsa-buildd
+<% if nodeinfo['nagiosmaster'] -%>
+file=/etc/nagios3/puppetconf.d/auto-hostgroups.cfg
 file=/etc/nagios3/puppetconf.d/auto-hosts.cfg
 file=/etc/nagios3/puppetconf.d/auto-services.cfg
 file=/etc/nagios3/puppetconf.d/auto-dependencies.cfg
 file=/etc/nagios3/puppetconf.d/auto-hostextinfo.cfg
-file=/etc/nagios3/puppetconf.d/auto-serviceextinfo.cfg"
-when "handel.debian.org": extrafiles="dir=8/etc/puppet"
-end
-extrafiles
-%>
+file=/etc/nagios3/puppetconf.d/auto-serviceextinfo.cfg
+<% end -%>
+<% if nodeinfo['muninmaster'] -%>
+file=/etc/munin/munin.conf
+<% end -%>
+<% if nodeinfo['puppetmaster'] -%>
+dir=8/etc/puppet
+<% end -%>  
+<% if classes.include?('named::geodns') -%>
+dir=1/etc/bind/geodns
+<% end -%>
+<% if classes.include?('named::secondary') -%>
+dir=1/etc/bind
+file=/etc/bind/named.conf.debian-zones
+<% end -%>
+<% if fqdn == "dijkstra.debian.org" -%>
+dir=4/etc/dsa-kvm
+<% end -%>
+
+<% if nodeinfo['buildd'] -%>
+dir=3/etc/lvm
+<% end -%>
+dir=1/etc/ferm/dsa.d
+file=/etc/ferm/conf.d/me.conf
+file=/etc/ferm/conf.d/defs.conf
+file=/etc/ferm/ferm.conf
+dir=2/etc/ssl/debian
 
 [IgnoreNone]
 ##
@@ -741,19 +837,12 @@ SetMailNum = 10
 SetMailAddress=samhain-reports@debian.org
 
 ## Mail relay (IP address)
-<%=
-out=""
-if not nodeinfo['smarthost'].empty?
-  out = '
-SetMailRelay = localhost
-'
-else
-out = '
+<% if nodeinfo['smarthost'].empty? -%>
 SetMailRelay = master.debian.org
-'
-end
-out
-%>
+<% else -%>
+SetMailRelay = localhost
+<% end -%>
+
 ## Custom subject format
 #
 MailSubject = [Samhain at %H] %T: %S