]> git.donarmstrong.com Git - dsa-puppet.git/log
dsa-puppet.git
13 years agokrb class installs heimdal-clients
Peter Palfrader [Tue, 14 Sep 2010 21:45:22 +0000 (23:45 +0200)]
krb class installs heimdal-clients

13 years agobartok basic afs client. not much magic happening
Peter Palfrader [Tue, 14 Sep 2010 21:44:22 +0000 (23:44 +0200)]
bartok basic afs client.  not much magic happening

13 years agoport forward pagnini->samosa
Peter Palfrader [Tue, 14 Sep 2010 21:20:14 +0000 (23:20 +0200)]
port forward pagnini->samosa

13 years agoThis means we will install the openafs-client package automatically
Peter Palfrader [Tue, 14 Sep 2010 17:27:49 +0000 (19:27 +0200)]
This means we will install the openafs-client package automatically

13 years agoShip CellServDB and ThisCell in puppet
Peter Palfrader [Tue, 14 Sep 2010 17:26:32 +0000 (19:26 +0200)]
Ship CellServDB and ThisCell in puppet

13 years agoRevert "some gratuitous whitespace changes"
Stephen Gran [Mon, 13 Sep 2010 17:40:09 +0000 (18:40 +0100)]
Revert "some gratuitous whitespace changes"

This reverts commit 9ea1140c359d4bf3c513f34f8f311b911649ceef.

13 years agosome gratuitous whitespace changes
Stephen Gran [Mon, 13 Sep 2010 17:39:05 +0000 (18:39 +0100)]
some gratuitous whitespace changes

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agomake new syslog-ng module
Stephen Gran [Mon, 13 Sep 2010 17:30:51 +0000 (18:30 +0100)]
make new syslog-ng module

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agorautavaara does afs
Peter Palfrader [Mon, 13 Sep 2010 12:24:46 +0000 (14:24 +0200)]
rautavaara does afs

13 years agotry to break syslog
Stephen Gran [Mon, 13 Sep 2010 07:22:29 +0000 (08:22 +0100)]
try to break syslog

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoTry to appease anal ferm
Peter Palfrader [Sun, 12 Sep 2010 20:57:11 +0000 (22:57 +0200)]
Try to appease anal ferm

13 years agomove rautavaara to squeeze
Peter Palfrader [Sun, 12 Sep 2010 20:42:14 +0000 (22:42 +0200)]
move rautavaara to squeeze

13 years agoi was never too good in math
Martin Zobel-Helas [Sun, 12 Sep 2010 17:36:45 +0000 (19:36 +0200)]
i was never too good in math
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agolotti for president^Wloghost
Martin Zobel-Helas [Sun, 12 Sep 2010 17:11:09 +0000 (19:11 +0200)]
lotti for president^Wloghost
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agoadd lotti
Martin Zobel-Helas [Sun, 12 Sep 2010 16:51:21 +0000 (18:51 +0200)]
add lotti
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agoadd locke
Peter Palfrader [Sun, 12 Sep 2010 10:12:30 +0000 (12:12 +0200)]
add locke

13 years agoTry to allow some ports to afs hosts
Peter Palfrader [Sun, 12 Sep 2010 08:41:19 +0000 (10:41 +0200)]
Try to allow some ports to afs hosts

13 years agofix typo
Martin Zobel-Helas [Sat, 11 Sep 2010 21:27:55 +0000 (23:27 +0200)]
fix typo
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agomove krb firewalling to modules/krb
Peter Palfrader [Sat, 11 Sep 2010 18:40:55 +0000 (20:40 +0200)]
move krb firewalling to modules/krb

13 years agolibheimdal-kadm5-perl is a local package on draghi
Peter Palfrader [Fri, 10 Sep 2010 20:10:20 +0000 (22:10 +0200)]
libheimdal-kadm5-perl is a local package on draghi

13 years agokrb5.conf on lamb
Peter Palfrader [Fri, 10 Sep 2010 17:15:41 +0000 (19:15 +0200)]
krb5.conf on lamb

13 years agoadd basic krb module
Peter Palfrader [Fri, 10 Sep 2010 15:20:04 +0000 (17:20 +0200)]
add basic krb module

13 years agofix domain
Peter Palfrader [Fri, 10 Sep 2010 11:17:06 +0000 (13:17 +0200)]
fix domain

13 years agokerberos kadmind access from draghi
Peter Palfrader [Fri, 10 Sep 2010 11:15:56 +0000 (13:15 +0200)]
kerberos kadmind access from draghi

13 years agoAdd lamb
Peter Palfrader [Thu, 9 Sep 2010 20:06:38 +0000 (22:06 +0200)]
Add lamb

13 years agokerberos is also a udp service
Peter Palfrader [Thu, 9 Sep 2010 16:08:53 +0000 (18:08 +0200)]
kerberos is also a udp service

13 years agoUse service names instead of port numbers
Peter Palfrader [Thu, 9 Sep 2010 15:46:07 +0000 (17:46 +0200)]
Use service names instead of port numbers

13 years agoTry to add byrd/schuetz special ports
Peter Palfrader [Thu, 9 Sep 2010 15:43:20 +0000 (17:43 +0200)]
Try to add byrd/schuetz special ports

13 years agoIndenting clean-up for ferm/per-host
Peter Palfrader [Thu, 9 Sep 2010 15:37:19 +0000 (17:37 +0200)]
Indenting clean-up for ferm/per-host

13 years agoAdd schuetz
Peter Palfrader [Thu, 9 Sep 2010 15:03:33 +0000 (17:03 +0200)]
Add schuetz

13 years agomake templates produce properly aligned output
Peter Palfrader [Thu, 9 Sep 2010 12:40:19 +0000 (14:40 +0200)]
make templates produce properly aligned output

13 years agoferm now officially sucks
Peter Palfrader [Thu, 9 Sep 2010 12:35:11 +0000 (14:35 +0200)]
ferm now officially sucks

13 years agoAdd ntp.grnet.gr to orff
Peter Palfrader [Wed, 8 Sep 2010 22:53:35 +0000 (00:53 +0200)]
Add ntp.grnet.gr to orff

13 years agoadd byrd
Peter Palfrader [Wed, 8 Sep 2010 22:10:44 +0000 (00:10 +0200)]
add byrd

13 years agoupdate package ignorelist for draghi and orff
Peter Palfrader [Wed, 8 Sep 2010 12:42:11 +0000 (14:42 +0200)]
update package ignorelist for draghi and orff

13 years agomininag now runs on orff
Peter Palfrader [Tue, 7 Sep 2010 21:02:12 +0000 (23:02 +0200)]
mininag now runs on orff

13 years agoUpdate the script that geo* servers run upon being triggered
Peter Palfrader [Tue, 7 Sep 2010 20:42:02 +0000 (22:42 +0200)]
Update the script that geo* servers run upon being triggered

13 years agoallow ssh to geo[123] from orff
Peter Palfrader [Tue, 7 Sep 2010 20:31:42 +0000 (22:31 +0200)]
allow ssh to geo[123] from orff

13 years agogeo nameservers are ssh triggered from orff now
Peter Palfrader [Tue, 7 Sep 2010 20:19:32 +0000 (22:19 +0200)]
geo nameservers are ssh triggered from orff now

13 years agoI think this ferm rule is no longer needed
Peter Palfrader [Tue, 7 Sep 2010 20:11:14 +0000 (22:11 +0200)]
I think this ferm rule is no longer needed

13 years agos/secondary/authoritative/
Peter Palfrader [Tue, 7 Sep 2010 19:53:47 +0000 (21:53 +0200)]
s/secondary/authoritative/

13 years agoconfigure orff as master too
Peter Palfrader [Tue, 7 Sep 2010 19:49:28 +0000 (21:49 +0200)]
configure orff as master too

13 years agoUpdate sudoers for move of dns master
Peter Palfrader [Tue, 7 Sep 2010 17:18:38 +0000 (19:18 +0200)]
Update sudoers for move of dns master

13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Tue, 7 Sep 2010 08:07:59 +0000 (09:07 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agoupdate apt preferences for new name
Stephen Gran [Tue, 7 Sep 2010 08:07:54 +0000 (09:07 +0100)]
update apt preferences for new name

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoallow dak on morricone to trigger archvsync
Peter Palfrader [Sun, 5 Sep 2010 19:20:01 +0000 (21:20 +0200)]
allow dak on morricone to trigger archvsync

13 years agoadd security@ rbllist
Stephen Gran [Sat, 4 Sep 2010 14:01:47 +0000 (15:01 +0100)]
add security@ rbllist

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agofix rbl and rhsbl list handling
Stephen Gran [Sat, 4 Sep 2010 13:47:39 +0000 (14:47 +0100)]
fix rbl and rhsbl list handling

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agono more non-us
Stephen Gran [Sat, 4 Sep 2010 11:13:38 +0000 (12:13 +0100)]
no more non-us

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoImprove on nodeinfo (i.e. make it work)
Peter Palfrader [Fri, 3 Sep 2010 12:58:10 +0000 (14:58 +0200)]
Improve on nodeinfo (i.e. make it work)

13 years ago$fqdn is not defined in functions
Peter Palfrader [Fri, 3 Sep 2010 12:47:47 +0000 (14:47 +0200)]
$fqdn is not defined in functions

13 years agoTry to enable ntp keying
Peter Palfrader [Fri, 3 Sep 2010 12:33:51 +0000 (14:33 +0200)]
Try to enable ntp keying

13 years agoSometimes this ruby puppet thing is weird
Peter Palfrader [Fri, 3 Sep 2010 12:17:18 +0000 (14:17 +0200)]
Sometimes this ruby puppet thing is weird

13 years agoTry to make extractnodeinfo accept more than one level of hash keys
Peter Palfrader [Fri, 3 Sep 2010 12:03:06 +0000 (14:03 +0200)]
Try to make extractnodeinfo accept more than one level of hash keys

13 years agoFind out if we are natted
Peter Palfrader [Fri, 3 Sep 2010 10:10:44 +0000 (12:10 +0200)]
Find out if we are natted

13 years agoRevert "We use "keyinfo" in all kinda of places. Rename it to something more generic"
Peter Palfrader [Thu, 2 Sep 2010 15:05:37 +0000 (17:05 +0200)]
Revert "We use "keyinfo" in all kinda of places.  Rename it to something more generic"

This reverts commit d7475f90c56697e9589e1386ced135498df68c81.

13 years agoRevert "We use "keyinfo" in all kinda of places. Rename it to something more generic...
Peter Palfrader [Thu, 2 Sep 2010 15:05:34 +0000 (17:05 +0200)]
Revert "We use "keyinfo" in all kinda of places.  Rename it to something more generic, II"

This reverts commit e6859bc74154e89b4996313992cc58c1f002be5e.

13 years agoWe use "keyinfo" in all kinda of places. Rename it to something more generic, II
Peter Palfrader [Thu, 2 Sep 2010 15:01:14 +0000 (17:01 +0200)]
We use "keyinfo" in all kinda of places.  Rename it to something more generic, II

13 years agoWe use "keyinfo" in all kinda of places. Rename it to something more generic
Peter Palfrader [Thu, 2 Sep 2010 14:59:44 +0000 (16:59 +0200)]
We use "keyinfo" in all kinda of places.  Rename it to something more generic

13 years agoSlightly modify ldapinfo, let's see what blows up
Peter Palfrader [Thu, 2 Sep 2010 14:48:43 +0000 (16:48 +0200)]
Slightly modify ldapinfo, let's see what blows up

13 years agoA reordering that should not matter
Peter Palfrader [Thu, 2 Sep 2010 14:25:36 +0000 (16:25 +0200)]
A reordering that should not matter

13 years agoNo point in giving albeniz and goetz a local ntp server too - they are too broken...
Peter Palfrader [Thu, 2 Sep 2010 14:05:21 +0000 (16:05 +0200)]
No point in giving albeniz and goetz a local ntp server too - they are too broken to keep proper time anyway

13 years agofix whitelist macro
Stephen Gran [Tue, 31 Aug 2010 07:30:09 +0000 (08:30 +0100)]
fix whitelist macro

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agothis should make whitelist, greylist and callout work as expected for virtual domains
Stephen Gran [Tue, 31 Aug 2010 00:31:59 +0000 (01:31 +0100)]
this should make whitelist, greylist and callout work as expected for virtual domains

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoMerge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa...
Martin Zobel-Helas [Mon, 30 Aug 2010 07:11:56 +0000 (09:11 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agoAdd njabl.org list for a set of addresses
Joerg Jaspert [Sun, 29 Aug 2010 22:20:32 +0000 (00:20 +0200)]
Add njabl.org list for a set of addresses

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agoRemove dsbl.org, its dead
Joerg Jaspert [Sun, 29 Aug 2010 22:19:12 +0000 (00:19 +0200)]
Remove dsbl.org, its dead

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agories not a recursor
Stephen Gran [Fri, 27 Aug 2010 08:28:06 +0000 (09:28 +0100)]
ries not a recursor

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Fri, 27 Aug 2010 07:40:10 +0000 (08:40 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agories no longer heavy exim
Stephen Gran [Fri, 27 Aug 2010 07:40:03 +0000 (08:40 +0100)]
ries no longer heavy exim

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoRevert "Revert "byebye ries""
Martin Zobel-Helas [Thu, 26 Aug 2010 23:04:01 +0000 (01:04 +0200)]
Revert "Revert "byebye ries""

This reverts commit 92457b979065ae6bd02ddde3f001db2cb7f74b43.

13 years agoRevert "byebye ries"
Martin Zobel-Helas [Thu, 26 Aug 2010 22:55:50 +0000 (00:55 +0200)]
Revert "byebye ries"

This reverts commit 6218c7c72655ea8a332fc634727efc3188d5502b.

13 years agoMerge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa...
Martin Zobel-Helas [Thu, 26 Aug 2010 22:10:54 +0000 (00:10 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agobyebye ries
Martin Zobel-Helas [Thu, 26 Aug 2010 22:10:37 +0000 (00:10 +0200)]
byebye ries
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agoTry adding more stuff to the motd
Peter Palfrader [Wed, 25 Aug 2010 09:35:08 +0000 (11:35 +0200)]
Try adding more stuff to the motd

13 years agoDo not prevent paganini from getting updated firewall configs
Peter Palfrader [Tue, 24 Aug 2010 12:31:08 +0000 (14:31 +0200)]
Do not prevent paganini from getting updated firewall configs

13 years agoMerge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Peter Palfrader [Tue, 24 Aug 2010 11:05:13 +0000 (13:05 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet

* 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet:
  no more puccini here
  bye bye byrd(ie)
  make http_limit opt-in rather than out
  actually reload ferm when the Ferm::Rules change
  only add limit rules where they are going to be used

13 years agoallow enclosure check on franck
Peter Palfrader [Tue, 24 Aug 2010 11:04:57 +0000 (13:04 +0200)]
allow enclosure check on franck

13 years agono more puccini here
Stephen Gran [Mon, 23 Aug 2010 09:04:37 +0000 (10:04 +0100)]
no more puccini here

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agobye bye byrd(ie)
Stephen Gran [Wed, 18 Aug 2010 22:13:24 +0000 (23:13 +0100)]
bye bye byrd(ie)

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agomake http_limit opt-in rather than out
Stephen Gran [Wed, 18 Aug 2010 21:50:31 +0000 (22:50 +0100)]
make http_limit opt-in rather than out

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoactually reload ferm when the Ferm::Rules change
Stephen Gran [Wed, 18 Aug 2010 21:46:03 +0000 (22:46 +0100)]
actually reload ferm when the Ferm::Rules change

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Wed, 18 Aug 2010 21:29:51 +0000 (22:29 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agoonly add limit rules where they are going to be used
Stephen Gran [Wed, 18 Aug 2010 21:29:34 +0000 (22:29 +0100)]
only add limit rules where they are going to be used

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoMerge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Peter Palfrader [Mon, 16 Aug 2010 10:29:20 +0000 (12:29 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet

* 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet:
  slow down some more search spiders
  move all files to explicit new-style module/ paths
  and apache module
  convert exim module to new syntax - why it needs to change, I don't know
  these settings seem to break samhain on wolkenstein - how odd
  ignore bind stuff on geo servers as well
  libdns66 can be ignored as well - pesky sonames
  The geo's no longer have a local geoip set of packages

13 years agovarnish for snapshot on stabile
Peter Palfrader [Mon, 16 Aug 2010 10:29:09 +0000 (12:29 +0200)]
varnish for snapshot on stabile

13 years agoslow down some more search spiders
Stephen Gran [Mon, 16 Aug 2010 07:12:10 +0000 (08:12 +0100)]
slow down some more search spiders

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agomove all files to explicit new-style module/ paths
Stephen Gran [Sun, 15 Aug 2010 15:45:39 +0000 (16:45 +0100)]
move all files to explicit new-style module/ paths

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoand apache module
Stephen Gran [Sun, 15 Aug 2010 15:36:34 +0000 (16:36 +0100)]
and apache module

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoconvert exim module to new syntax - why it needs to change, I don't know
Stephen Gran [Sun, 15 Aug 2010 15:34:34 +0000 (15:34 +0000)]
convert exim module to new syntax - why it needs to change, I don't know

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agothese settings seem to break samhain on wolkenstein - how odd
Stephen Gran [Sun, 15 Aug 2010 11:41:16 +0000 (12:41 +0100)]
these settings seem to break samhain on wolkenstein - how odd

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoignore bind stuff on geo servers as well
Stephen Gran [Sat, 14 Aug 2010 13:12:41 +0000 (14:12 +0100)]
ignore bind stuff on geo servers as well

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agolibdns66 can be ignored as well - pesky sonames
Stephen Gran [Sat, 14 Aug 2010 12:35:00 +0000 (13:35 +0100)]
libdns66 can be ignored as well - pesky sonames

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoThe geo's no longer have a local geoip set of packages
Stephen Gran [Sat, 14 Aug 2010 12:34:25 +0000 (13:34 +0100)]
The geo's no longer have a local geoip set of packages
Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoAdd 2607:f8f0:0610:4000::/64 reverse zone
Peter Palfrader [Sat, 14 Aug 2010 11:01:22 +0000 (13:01 +0200)]
Add 2607:f8f0:0610:4000::/64 reverse zone

13 years agocopy/paste error
Peter Palfrader [Fri, 13 Aug 2010 20:29:14 +0000 (22:29 +0200)]
copy/paste error

13 years agonames must be unique
Peter Palfrader [Fri, 13 Aug 2010 20:27:54 +0000 (22:27 +0200)]
names must be unique

13 years agosyntax
Peter Palfrader [Fri, 13 Aug 2010 20:27:30 +0000 (22:27 +0200)]
syntax

13 years agoTry some nat/redirect magic on sibelius
Peter Palfrader [Fri, 13 Aug 2010 20:27:03 +0000 (22:27 +0200)]
Try some nat/redirect magic on sibelius

13 years agoferm: support more than just the filter table
Peter Palfrader [Fri, 13 Aug 2010 20:16:00 +0000 (22:16 +0200)]
ferm: support more than just the filter table