]>
git.donarmstrong.com Git - dsa-puppet.git/log
Stephen Gran [Wed, 18 Aug 2010 21:29:34 +0000 (22:29 +0100)]
only add limit rules where they are going to be used
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Mon, 16 Aug 2010 10:29:20 +0000 (12:29 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
* 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet:
slow down some more search spiders
move all files to explicit new-style module/ paths
and apache module
convert exim module to new syntax - why it needs to change, I don't know
these settings seem to break samhain on wolkenstein - how odd
ignore bind stuff on geo servers as well
libdns66 can be ignored as well - pesky sonames
The geo's no longer have a local geoip set of packages
Peter Palfrader [Mon, 16 Aug 2010 10:29:09 +0000 (12:29 +0200)]
varnish for snapshot on stabile
Stephen Gran [Mon, 16 Aug 2010 07:12:10 +0000 (08:12 +0100)]
slow down some more search spiders
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 15 Aug 2010 15:45:39 +0000 (16:45 +0100)]
move all files to explicit new-style module/ paths
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 15 Aug 2010 15:36:34 +0000 (16:36 +0100)]
and apache module
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 15 Aug 2010 15:34:34 +0000 (15:34 +0000)]
convert exim module to new syntax - why it needs to change, I don't know
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 15 Aug 2010 11:41:16 +0000 (12:41 +0100)]
these settings seem to break samhain on wolkenstein - how odd
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 14 Aug 2010 13:12:41 +0000 (14:12 +0100)]
ignore bind stuff on geo servers as well
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 14 Aug 2010 12:35:00 +0000 (13:35 +0100)]
libdns66 can be ignored as well - pesky sonames
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 14 Aug 2010 12:34:25 +0000 (13:34 +0100)]
The geo's no longer have a local geoip set of packages
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Sat, 14 Aug 2010 11:01:22 +0000 (13:01 +0200)]
Add 2607:f8f0:0610:4000::/64 reverse zone
Peter Palfrader [Fri, 13 Aug 2010 20:29:14 +0000 (22:29 +0200)]
copy/paste error
Peter Palfrader [Fri, 13 Aug 2010 20:27:54 +0000 (22:27 +0200)]
names must be unique
Peter Palfrader [Fri, 13 Aug 2010 20:27:30 +0000 (22:27 +0200)]
syntax
Peter Palfrader [Fri, 13 Aug 2010 20:27:03 +0000 (22:27 +0200)]
Try some nat/redirect magic on sibelius
Peter Palfrader [Fri, 13 Aug 2010 20:16:00 +0000 (22:16 +0200)]
ferm: support more than just the filter table
Martin Zobel-Helas [Thu, 12 Aug 2010 20:03:32 +0000 (22:03 +0200)]
typo?
Martin Zobel-Helas [Thu, 12 Aug 2010 20:02:01 +0000 (22:02 +0200)]
add cilea
Martin Zobel-Helas [Thu, 12 Aug 2010 16:30:42 +0000 (18:30 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Thu, 12 Aug 2010 16:30:17 +0000 (18:30 +0200)]
remove purcell
Peter Palfrader [Tue, 10 Aug 2010 18:25:31 +0000 (20:25 +0200)]
the dl585 hosts have their smartarray in slot9
Peter Palfrader [Tue, 10 Aug 2010 18:16:48 +0000 (20:16 +0200)]
add contrib and non-free to sources.list
Peter Palfrader [Tue, 10 Aug 2010 18:03:26 +0000 (20:03 +0200)]
Dedication and mailroute for rossini, salieri, traetta
Peter Palfrader [Tue, 10 Aug 2010 15:38:39 +0000 (17:38 +0200)]
nagios also gets to contact mail and munin on freebsd hosts
Peter Palfrader [Tue, 10 Aug 2010 15:35:10 +0000 (17:35 +0200)]
tidy up http related ferm rules
Peter Palfrader [Tue, 10 Aug 2010 15:29:37 +0000 (17:29 +0200)]
Try to tidy up forward ferm rules
Peter Palfrader [Tue, 10 Aug 2010 15:27:00 +0000 (17:27 +0200)]
ferm on rautavaara
Peter Palfrader [Tue, 10 Aug 2010 15:25:24 +0000 (17:25 +0200)]
nagios gets to port 22 on freebsd hosts
Peter Palfrader [Tue, 10 Aug 2010 15:23:13 +0000 (17:23 +0200)]
Different quote chars, II
Peter Palfrader [Tue, 10 Aug 2010 15:21:07 +0000 (17:21 +0200)]
Different quote chars
Peter Palfrader [Tue, 10 Aug 2010 15:19:20 +0000 (17:19 +0200)]
Try to limit forward
Peter Palfrader [Tue, 10 Aug 2010 15:08:56 +0000 (17:08 +0200)]
ferm on luchesi
Peter Palfrader [Tue, 10 Aug 2010 14:20:06 +0000 (16:20 +0200)]
Add kibi and aurel ssh client hosts for freebsd
Stephen Gran [Fri, 6 Aug 2010 16:27:10 +0000 (17:27 +0100)]
add master to carnet hosts
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Thu, 5 Aug 2010 13:32:38 +0000 (15:32 +0200)]
remove non-existing hosts
Martin Zobel-Helas [Thu, 5 Aug 2010 12:17:59 +0000 (14:17 +0200)]
try if we can have hightraffic rules
Peter Palfrader [Wed, 4 Aug 2010 23:23:42 +0000 (01:23 +0200)]
sudoers: update archvsync->snapshot triggers
Peter Palfrader [Sun, 1 Aug 2010 17:34:01 +0000 (19:34 +0200)]
krenek/vitry are buildds for archive rebuilds
Peter Palfrader [Fri, 30 Jul 2010 21:38:51 +0000 (23:38 +0200)]
alain, alwyn, antheil, arna are buildds
Peter Palfrader [Fri, 30 Jul 2010 16:35:52 +0000 (18:35 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
* 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet:
sibelius gets ferm
Peter Palfrader [Fri, 30 Jul 2010 16:18:15 +0000 (18:18 +0200)]
porter sudo for abel
Stephen Gran [Fri, 30 Jul 2010 08:09:06 +0000 (09:09 +0100)]
sibelius gets ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Thu, 29 Jul 2010 19:12:54 +0000 (21:12 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
* 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet:
make the range slightly more readable
maybe that works better with correct syntax
ensure correct path permissions, so nagios can read from it
Peter Palfrader [Thu, 29 Jul 2010 19:12:46 +0000 (21:12 +0200)]
etc/motd dedication fu works better if one spells the name right
Stephen Gran [Thu, 29 Jul 2010 08:23:58 +0000 (09:23 +0100)]
make the range slightly more readable
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Wed, 28 Jul 2010 20:52:30 +0000 (22:52 +0200)]
maybe that works better with correct syntax
Martin Zobel-Helas [Wed, 28 Jul 2010 20:42:32 +0000 (22:42 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Wed, 28 Jul 2010 20:41:41 +0000 (22:41 +0200)]
ensure correct path permissions, so nagios can read from it
Peter Palfrader [Wed, 28 Jul 2010 11:45:14 +0000 (13:45 +0200)]
Add arm machines to smarthost
Peter Palfrader [Wed, 28 Jul 2010 11:44:33 +0000 (13:44 +0200)]
Add dedications
Peter Palfrader [Wed, 28 Jul 2010 11:14:13 +0000 (13:14 +0200)]
Try something for syslog fu, IV
Peter Palfrader [Wed, 28 Jul 2010 11:12:52 +0000 (13:12 +0200)]
Try something for syslog fu, III
Peter Palfrader [Wed, 28 Jul 2010 09:31:21 +0000 (11:31 +0200)]
Try something for syslog fu, II
Peter Palfrader [Wed, 28 Jul 2010 09:29:11 +0000 (11:29 +0200)]
Try something for syslog fu
Stephen Gran [Wed, 28 Jul 2010 08:13:57 +0000 (09:13 +0100)]
merikanto gets a firewall
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 28 Jul 2010 08:09:32 +0000 (09:09 +0100)]
now that nfs ports are locked down we no longer need this
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 28 Jul 2010 08:00:52 +0000 (09:00 +0100)]
beethoven is an nfs server
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 28 Jul 2010 07:56:40 +0000 (08:56 +0100)]
Change security's sudo entries
https://rt.debian.org/Ticket/Display.html?id=2420
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Tue, 27 Jul 2010 20:45:37 +0000 (22:45 +0200)]
security-master does rsync too..
Stephen Gran [Tue, 27 Jul 2010 09:29:05 +0000 (10:29 +0100)]
stabile seems to have rsync
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 27 Jul 2010 09:14:12 +0000 (10:14 +0100)]
ravel has rsync
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 27 Jul 2010 08:01:43 +0000 (09:01 +0100)]
copy and waste error
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 27 Jul 2010 08:00:39 +0000 (09:00 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Tue, 27 Jul 2010 08:00:33 +0000 (09:00 +0100)]
put nfs-server in main manifest
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 27 Jul 2010 07:59:23 +0000 (08:59 +0100)]
Add nfs-server module. Still needs menu.lst modification manually for
moduleless kernels.
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Tue, 27 Jul 2010 07:57:58 +0000 (09:57 +0200)]
%fossy to fossy ALL on vivaldi
Stephen Gran [Tue, 27 Jul 2010 07:45:26 +0000 (08:45 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Tue, 27 Jul 2010 07:44:55 +0000 (08:44 +0100)]
spohr has nfs that is able to be firewalled now
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Mon, 26 Jul 2010 23:49:09 +0000 (01:49 +0200)]
the fossy group may run /etc/init.d/fossology as root on vivaldi
Stephen Gran [Mon, 26 Jul 2010 20:20:01 +0000 (21:20 +0100)]
allow paganini to serve dhcp and tftp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 26 Jul 2010 11:08:39 +0000 (12:08 +0100)]
samosa gets udd-stunnel
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 26 Jul 2010 07:22:20 +0000 (08:22 +0100)]
samosa gets recursor
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 26 Jul 2010 06:50:17 +0000 (07:50 +0100)]
kassia has rsync
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 26 Jul 2010 06:20:01 +0000 (07:20 +0100)]
ravel and kassia have ftp
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 22:38:16 +0000 (23:38 +0100)]
ravel gets ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 22:34:29 +0000 (23:34 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sun, 25 Jul 2010 22:33:39 +0000 (23:33 +0100)]
add ferm::nfs-server module
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 25 Jul 2010 22:13:02 +0000 (00:13 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Sun, 25 Jul 2010 22:12:28 +0000 (00:12 +0200)]
make spohr recursor
Stephen Gran [Sun, 25 Jul 2010 22:07:04 +0000 (23:07 +0100)]
alphabetize
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 25 Jul 2010 22:03:32 +0000 (00:03 +0200)]
add chopin back
Martin Zobel-Helas [Sun, 25 Jul 2010 21:58:12 +0000 (23:58 +0200)]
draghi does ldap and ldaps
Martin Zobel-Helas [Sun, 25 Jul 2010 21:47:41 +0000 (23:47 +0200)]
remove chopin
Martin Zobel-Helas [Sun, 25 Jul 2010 21:37:38 +0000 (23:37 +0200)]
add dns and finger rules for draghi
Martin Zobel-Helas [Sun, 25 Jul 2010 21:29:19 +0000 (23:29 +0200)]
spohr without firewall for now!
Martin Zobel-Helas [Sun, 25 Jul 2010 21:17:26 +0000 (23:17 +0200)]
chopin does ftp
Stephen Gran [Sun, 25 Jul 2010 20:18:13 +0000 (21:18 +0100)]
nor these two
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 20:15:10 +0000 (21:15 +0100)]
nor paganini
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 20:12:55 +0000 (21:12 +0100)]
ravel not ready yet
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 20:02:24 +0000 (21:02 +0100)]
and use new module layout
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 19:59:50 +0000 (20:59 +0100)]
try to start breaking up firewall rules into something not quite as messy
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 19:36:06 +0000 (20:36 +0100)]
bellini has ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 19:30:02 +0000 (20:30 +0100)]
petterson has ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 25 Jul 2010 19:27:32 +0000 (21:27 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Martin Zobel-Helas [Sun, 25 Jul 2010 19:26:05 +0000 (21:26 +0200)]
add master
Stephen Gran [Sun, 25 Jul 2010 19:25:21 +0000 (20:25 +0100)]
cimarosa has ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 19:23:41 +0000 (20:23 +0100)]
no longer need to double include ferm
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 25 Jul 2010 19:22:24 +0000 (20:22 +0100)]
Make ferm list exclusive rather than inclusive
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Sun, 25 Jul 2010 18:30:46 +0000 (20:30 +0200)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet