Commit Graph

382 Commits

Author SHA1 Message Date
50cab2429d raduis: use LE certificate via dns 2019-03-25 21:08:19 +01:00
c6c91d7256 Migrate LDAP from BKCA to Let's Encrypt 2019-03-25 19:58:06 +01:00
c0070e042b acertmgr: update to 0.9.4 2019-03-25 19:25:56 +01:00
606851de76 slapd: use LE certificate via dns 2019-03-25 19:05:31 +01:00
3471c0ca34 bk-dss: update to 0.8.2 2019-03-22 13:09:58 +01:00
e72ee8fb74 acertmgr: update to 0.8.2 2019-03-21 22:33:05 +01:00
218ae6c4dd bk-dss: restart uwsgi on changes (fixes #28) 2019-03-18 22:18:43 +01:00
cefabcaa7f web: no longer server binary-kitchen.space 2019-03-09 18:39:27 +01:00
654c2c0122 cleanup whitespace 2019-03-09 18:38:07 +01:00
e7375cac3e new host: mpcnc 2019-03-09 18:33:00 +01:00
97cb51efbf hackmd: increase max upload size 2019-03-07 21:17:19 +01:00
e1e110e704 acertmgr: update to 0.8.1 2019-03-07 15:01:06 +01:00
56df920ec0 bk-dss: update to 0.8.1 2019-02-28 11:17:08 +01:00
7fb5ac8875 acertmgr: fix typo 2019-02-25 18:10:56 +01:00
476df56fcc acertmgr: rename vars, introduce version 2019-02-25 08:34:21 +01:00
a2e6267ec8 slapd: use base from variables 2019-02-23 23:55:35 +01:00
9bffa36a33 acertmgr: rename from certmgr, run on config change 2019-02-23 23:54:24 +01:00
407409010e bk-dss: use vault for secret, use tagged version, use correct certificate for ldap 2019-02-23 23:34:23 +01:00
845a9f3c76 dss: remove unused role (replaced by bk-dss) 2019-02-19 09:31:33 +01:00
905f86f2df gogs: apt repo key location has changed 2019-02-18 19:15:34 +01:00
f576ebe615 common: forgot to remove gentoo prompt from Debian 2019-02-18 18:39:12 +01:00
d5c98eb13c common: don't use gentoo prompt anymore 2019-02-18 18:35:54 +01:00
41784f514f Cleanup whitespace 2019-02-13 16:01:32 +01:00
b47be3287a librenms & racktables: use LE certificates 2019-02-13 15:57:46 +01:00
766ece5b10 acme-dnskey-generate: fix naming inconsistencies 2019-02-13 15:40:12 +01:00
275b9a6071 Cleanup whitespace 2019-02-13 14:28:16 +01:00
cffa318bea Remove acme.sh client 2019-02-13 14:05:27 +01:00
82b5f9cdf3 dns-intern: sync A/PTR, use RR for radius, fix erx-rz loopback 2019-02-13 13:38:08 +01:00
82181c2eb2 Remove forseti/checkmk 2019-02-13 13:30:16 +01:00
d52b5c0b76 bk-dss: update to current version 2019-02-12 09:45:10 +01:00
fa7fec4a93 certmgr: update to latest version, adjust config 2019-02-11 19:36:35 +01:00
Kishi85
06760bf9f7 Add role to generate dns keys for acme/cermgr 2019-02-11 18:38:41 +01:00
40efa84fcf dovecot: add logrotate config 2019-02-04 20:31:13 +01:00
8b0be8cc6f dns: host ffrgb (offloader) 2019-02-04 18:33:06 +01:00
7b53f00a5e new hosts: maccaroni & spaghetti 2019-01-20 14:47:55 +01:00
Kishi85
3425fdeac9 new host: magnesium (partdb/partkeepr) 2018-12-17 19:25:15 +01:00
5fae8fa02c dns-intern: update loopback addresses 2018-10-30 12:31:34 +01:00
543ffce274 dhcpd: dhcp for Aruba APs 2018-10-26 18:43:18 +02:00
2f1ed864cd dns-extern: update documentation 2018-10-22 21:03:18 +02:00
ae65e438dc dns-extern: role for primary nameserver 2018-10-22 20:58:34 +02:00
Kishi85
e3c7c0cc1b Change updatepolicy.aliases format 2018-10-22 20:30:12 +02:00
267557f068 common: install software on proxmox 2018-10-15 21:47:26 +02:00
65786edf03 common: run apt task to ensure python-apt is installed 2018-10-15 21:47:03 +02:00
e88a6e5691 further updates wrt changed ntp server 2018-10-15 21:46:30 +02:00
Kishi85
271305ad34 Proxmox handling 2018-10-15 21:08:06 +02:00
67d4340ba6 hackmd: fix owner, persistent upload path, allow anon edits 2018-10-15 18:46:34 +02:00
22c1b0d469 bk-dss: new role to be deployed on LDAP host 2018-10-15 18:25:30 +02:00
32f976a163 hackmd: fix when 2018-10-08 21:46:29 +02:00
4a93fab603 hackmd: update database scheme 2018-10-08 20:29:18 +02:00
9b19d93bf9 hackmd: update version to codimd 1.2.1 2018-10-08 20:28:06 +02:00
ebecd957b2 hackmd: reload systemd before restarting hackmd 2018-10-08 20:14:33 +02:00
e2fd44eb53 prometheus: new role 2018-10-06 22:19:37 +02:00
634b952321 common: update zsh path for FreeBSDH 2018-10-06 22:18:40 +02:00
b6605467fa dhcpd: new lock IP 2018-10-06 20:37:41 +02:00
1b25547d97 dns: remove old hosts 2018-10-04 21:38:59 +02:00
ca86d25ed5 Fix dovecot ldaps 2018-10-04 21:29:16 +02:00
59cca157e2 web: new domain makerspace-regensburg.de 2018-10-02 18:35:30 +02:00
d434e9e70d hackmd: only rebuild if changed (properly this time) 2018-09-20 22:57:51 +02:00
9e0e5923a8 dns-intern: renumber RZ 2018-09-20 22:31:12 +02:00
482d67ebb1 Change BKCA to a system CA for migration to Let's Encrypt 2018-09-20 18:55:17 +02:00
1a511a9faf root-keys: new role to set ssh authorized keys for the root user 2018-09-17 22:03:35 +02:00
0a2f85459d common: update FreeBSD zsh location 2018-09-16 11:50:45 +02:00
3be1e06242 hackmd: disable anon usage 2018-09-16 11:49:53 +02:00
9f608c886d Change certificate locations, update powerdns aliases 2018-09-11 13:58:24 +02:00
9dcdbdf983 acme.sh role 2018-09-10 22:52:41 +02:00
b3d3888518 dchpd: don't use global ntp servers 2018-08-27 23:31:29 +02:00
d571ff6827 dns-intern: new hosts 2018-08-27 23:30:49 +02:00
6a73265d79 dhcp: increase lease times 2018-08-21 12:59:41 +02:00
8d7d6f6765 dns-intern: fix typo in hostname 2018-08-21 12:59:22 +02:00
008f64cb08 dns-intern: new host sw03 2018-08-20 15:46:09 +02:00
6c7014e7fc Set sane default for DMARC_MODERATION_ACTION 2018-07-30 21:32:09 +02:00
9baad14c37 Remove, rename and preserve DKIM headers (mode=3) 2018-07-24 12:21:57 +02:00
74aa02420e mail: make mailman work with postfix again 2018-07-23 22:36:54 +02:00
6db9b2eafd dns-intern: new hosts (ap04 and modem) 2018-07-23 21:54:27 +02:00
ede83b43a1 Mailman: Remove (wrong) DKIM headers 2018-07-23 18:47:56 +02:00
bfe0d994d0 common: fix regex 2018-07-17 13:26:45 +02:00
b456e13542 radius: update to freeradius 3 (and no more LDAP) 2018-07-17 10:43:31 +02:00
4204334e3d Clean cmk server 2018-07-16 21:03:25 +02:00
ff98616d94 new agent ver 2018-07-16 21:02:50 +02:00
2876acf4d6 Check_MK for bacon, new cmk version 2018-07-16 20:52:33 +02:00
e4b07bc43b dns/dhcp: reserved host mirror 2018-07-08 16:38:16 +02:00
4aa681ff70 common: udpate zsh prompt path 2018-07-06 12:12:29 +02:00
26ed972c00 Check_MK update p33 to p34 2018-06-27 21:09:12 +02:00
66bdb9ec16 dns-intern: style fix 2018-06-27 20:27:00 +02:00
66c36c4896 common: fix network interfaces names
(ensXX -> ethX) in consistent way with systems upgraded
from debian 8
2018-06-27 20:04:45 +02:00
0622787e0c new host: neon, rename dns to dns-intern 2018-06-27 19:35:30 +02:00
8ae92ce745 Add alias for forseti, checkmk.bk 2018-06-13 17:29:37 +02:00
69edc1d5bf Downloaded file mode 0755 -> 0644 2018-06-13 16:56:19 +02:00
a025bc0301 Merge branch 'master' of git.binary-kitchen.de:moepman/infra 2018-06-13 16:48:27 +02:00
b5b06841d1 Add check_mk tasks and roles 2018-06-13 16:47:18 +02:00
0cafa543aa run unattented updates on non-critial hosts 2018-06-13 15:08:04 +02:00
4ae4cb8b13 member-sw: install ansible 2018-06-13 14:53:59 +02:00
b570b30ad2 common: prevent normal users from running su 2018-06-13 14:43:13 +02:00
2417bf1302 Add forseti check_mk VM 2018-06-11 21:08:37 +02:00
850f813079 hackmd: fix service file (missing working dir) 2018-06-04 15:59:11 +02:00
b68232cea4 hackmd: improve (csp, hsts, version bump) and start to use vault 2018-06-04 14:00:55 +02:00
197af9ee3f dns: update IPs 2018-05-14 20:02:18 +02:00
ce8959a1d2 gogs: use debian stretch packages 2018-05-08 23:15:06 +02:00
cc5611ca37 common: use ansible facts to detect KVM VMs 2018-05-02 12:11:31 +02:00
d3a50a75d6 hackmd: SSL, temporary CSP'fix 2018-05-01 11:49:42 +02:00
e24a9ede41 DNS and DHCP update: obazda, garlic 2018-05-01 11:48:55 +02:00
2bebcc16a3 common: install qemu-agent on VMs 2018-05-01 11:47:57 +02:00
2a15de42cf gogs: style fix 2018-05-01 11:43:51 +02:00
7806c6b9e9 DNS and DHCP updates 2018-05-01 11:43:51 +02:00
95084d6cc6 mail: reduce dovecot logging 2018-04-18 15:07:58 +02:00
b9086690dc hackmd: LDAP and vhost 2018-04-12 18:30:30 +02:00
344139e75c hackmd: new role (not finished yet) 2018-04-09 21:28:36 +02:00
67af76cbda prosody: enable modules to improve user experience (XEP 0065, 0124, 0191, 0352, 0357, 0363) 2018-03-20 12:59:49 +01:00
f13bf4d466 dns: remove host ups2 2018-02-03 22:52:13 +01:00
718657fc15 New host: bowle (punsch replacement) 2018-02-03 22:40:48 +01:00
d281b083bc dns: remove non working update check 2018-01-23 18:29:16 +01:00
42b741a139 common: install psmisc (for killall) 2018-01-14 19:06:25 +01:00
7a004e4d8f certmgr: update to current version 2018-01-14 18:40:19 +01:00
f2dca81c28 Update dns & dhcp (remove sushi) 2018-01-11 19:37:57 +01:00
d975523f4d common: install net-tools (for netstat) 2018-01-10 12:28:20 +01:00
5b5fa52e53 Modify dns for debian stretch. 2017-10-10 09:48:48 +02:00
4db79176e5 Update zsh path for FreeBSD. 2017-10-10 09:46:57 +02:00
bc653331f6 Fix gogs repository url. 2017-10-02 12:15:56 +02:00
19f4984b1b Make sure less is installed (needed by journalctl). 2017-10-02 12:15:17 +02:00
983189fb46 Make snmpd less verbose on debian Stretch. 2017-10-02 12:14:50 +02:00
683acac84e Add DHCP options for VoIP phones. 2017-10-02 12:13:04 +02:00
dba3a3fa71 DHCP for schweinshaxn. 2017-09-30 16:44:19 +02:00
99b0279cac Disable mouse in vim (debian). 2017-09-20 13:24:30 +02:00
47ecaa9a74 New hosts/IPs in dns. 2017-09-18 20:52:22 +02:00
261c053c93 IP, DNS and DHCP for spaghetti (octopi). 2017-09-12 19:41:36 +02:00
b6132e8720 Fetch letsencrypt root cert for certmgr. 2017-09-09 11:25:16 +02:00
008b0efd1b Modify certmgr for Debian stretch. 2017-09-09 11:23:30 +02:00
c43a927779 Modify nginx for Debian stretch. 2017-09-09 11:22:43 +02:00
fef4ea1c13 Fix dovecot ssl config (no longer worked with Debian stretch). 2017-09-04 15:36:55 +02:00
103512faae Add php7.0-xml to web role. 2017-09-03 14:37:23 +02:00
afc6b3f57f Modify librenms and racktables for Debian stretch. 2017-09-03 14:35:56 +02:00
021aa8df96 Add new devices and IPs. 2017-09-03 14:26:05 +02:00
88c23c3693 Clean up, specify eth0 as dhcp interface. 2017-07-07 07:49:17 +02:00
fd6abd2dd2 Modify web role for debian stretch. 2017-07-03 09:49:18 +02:00
313a27e20d Handle incorrectly enabled hibernation/resume. 2017-07-03 09:48:25 +02:00
7e856c2923 Cleanup (mostly apt: state=present). 2017-07-02 22:17:32 +02:00
c7e4dd4173 Forgot to add opcache.ini. 2017-07-01 16:36:41 +02:00
37aef461cf Modify owncloud role for debian stretch. 2017-07-01 16:33:15 +02:00
becadd373f New hosts: nbe-w13b, nbe-tr8, sw01, sw02 2017-07-01 14:25:43 +02:00
438ed4e24e Reserve DNS/IPs for new network equipment. 2017-06-05 21:39:41 +02:00
05e54ced02 Change mac address of lock. 2017-06-05 21:38:47 +02:00
5feacf313f Prosody: enable XEP-0313 (for OMEMO). 2017-04-03 12:25:18 +02:00
fa23c6281b New hosts: ap03, klopi. 2017-03-21 20:45:16 +01:00
1cbb6e7f1d New host: cannelloni. 2017-03-21 20:45:16 +01:00
bc270519b0 Begin work on directory-self-service role. 2017-03-21 20:45:12 +01:00
1b587c0eec Switch to nginx-light. 2017-03-01 09:33:49 +01:00
2978ef8177 Fix certmgr actions for cron usage. 2017-02-28 14:48:03 +01:00
e7e49f356f Use Leti's Encrypt certificates for binary-kitchen.de. 2017-02-28 14:14:33 +01:00
7c01620a0f Enable certificate manager cron job. 2017-02-28 13:20:48 +01:00
c6a563b1bd Add (free)radius role. 2017-02-21 20:20:04 +01:00