Age | Commit message (Collapse) | Author | |
---|---|---|---|
2021-10-31 | Merge branch 'master' into trainingtraining | Jan Dittberner | |
* master: Manage /etc/network/interfaces of LXC containers only Only perform update-ca-certificates on changes Fix version number for debian-security check | |||
2021-10-31 | Merge commit '500ee63f8027d7d0672c7f0172feaa2401fccf03' into training | Jan Dittberner | |
* commit '500ee63f8027d7d0672c7f0172feaa2401fccf03': | |||
2021-10-31 | Manage /etc/network/interfaces of LXC containers only | Jan Dittberner | |
2021-10-31 | Only perform update-ca-certificates on changes | Jan Dittberner | |
2021-10-31 | Fix version number for debian-security check | Jan Dittberner | |
2021-10-31 | Fix version number for debian-security check | Jan Dittberner | |
2021-10-31 | Marge back changes from training branch | Jan Dittberner | |
* training: Remove dependency on ca-cacert package Fix puppet-lint warnings Add support for Debian 11 security repository Change password for Ed Kapitein Change passwrd for Hamish Gough Revert "Change password for Ed Kapitein" Change password for Ed Kapitein Change password for Dave van der Merwe Add training system account for Hamish Gough Change password for Dirk Meyer Change password for Bruce Schuck Fix yamllint warnings for hiera data Assign Bruce, Dave, Dirk m. and Ed to training systems Add users for infrastructure team volunteers Add training instances | |||
2021-10-31 | Remove dependency on ca-cacert package | Jan Dittberner | |
The ca-cacert package did not make it into bullseye. This change replaces the package dependency with an installation of the root and class3 certificate via Puppet. | |||
2021-10-31 | Merge branch 'master' into training | Jan Dittberner | |
* master: (97 commits) Add ftp.belnet.be Jenkins mirror, remove sun1 rule Allow sun1 access to Debian mirrors Remove ledgersmb Fix user name in hier data Gnupg is now an implicit dependency of the apt module Add role, profile and node config for ledgersmb Add role, profile and node config for pgsql Add user for Wacłav Schiller Move http proxy_pass into location block Move nginx http config to template Remove misleading comment in sniproxy template Fix parameter passing Use correct data types Implement http redirect/proxy support for sniproxy Add host ingress03 Lower critical value for next_update to 60 minutes Switch CRL check to seconds for proper perf data Add cacert_crl CheckCommand definition Do not install monitoring-plugins-contrib on stretch hosts Add check plugin for checking CRL updates ... | |||
2021-10-31 | Fix puppet-lint warnings | Jan Dittberner | |
2021-10-31 | Add support for Debian 11 security repository | Jan Dittberner | |
2021-09-19 | Add ftp.belnet.be Jenkins mirror, remove sun1 rule | Jan Dittberner | |
The sun1 rule is not needed because localnet contains 172.16.0.0/12 ftp.belnet.be has been added to the Jenkins mirror network | |||
2021-09-18 | Allow sun1 access to Debian mirrors | Jan Dittberner | |
2021-09-07 | Remove ledgersmb | Jan Dittberner | |
2021-08-28 | Fix user name in hier data | Jan Dittberner | |
2021-08-28 | Gnupg is now an implicit dependency of the apt module | Jan Dittberner | |
2021-08-28 | Add role, profile and node config for ledgersmb | Jan Dittberner | |
2021-08-28 | Add role, profile and node config for pgsql | Jan Dittberner | |
2021-08-28 | Add user for Wacłav Schiller | Jan Dittberner | |
2021-08-15 | Move http proxy_pass into location block | Jan Dittberner | |
2021-08-15 | Move nginx http config to template | Jan Dittberner | |
2021-08-15 | Remove misleading comment in sniproxy template | Jan Dittberner | |
2021-08-15 | Fix parameter passing | Jan Dittberner | |
2021-08-15 | Use correct data types | Jan Dittberner | |
2021-08-15 | Implement http redirect/proxy support for sniproxy | Jan Dittberner | |
2021-08-11 | Add host ingress03 | Jan Dittberner | |
2021-08-03 | Lower critical value for next_update to 60 minutes | Jan Dittberner | |
2021-08-03 | Switch CRL check to seconds for proper perf data | Jan Dittberner | |
2021-08-03 | Add cacert_crl CheckCommand definition | Jan Dittberner | |
2021-08-03 | Do not install monitoring-plugins-contrib on stretch hosts | Jan Dittberner | |
2021-08-03 | Add check plugin for checking CRL updates | Jan Dittberner | |
2021-08-01 | Add essential packages to base profile | Jan Dittberner | |
2021-08-01 | Add Icinga2 CA tickets for mariadb and nextcloud | Jan Dittberner | |
2021-08-01 | Add configuration stubs for mariadb and nextcloud | Jan Dittberner | |
- Add Sascha Ternes as sat - Add roles and profiles for nextcloud and mariadb - Add basic node configuration in hieradata | |||
2021-08-01 | Remove unwanted linebreaks | Jan Dittberner | |
2021-07-17 | Use renewed certificates | Jan Dittberner | |
2021-07-16 | Ensure external command definition | Jan Dittberner | |
2021-06-19 | Use infra02 as DNS resolver for infra03 | Jan Dittberner | |
Infra02 has information about all infrastructure hosts and can resolve names like puppet, proxyout, emailout. This commit changes the DNS resolver of infra03 to use infra02. | |||
2021-05-24 | Fix type in dnsmasq service name | Jan Dittberner | |
2021-05-24 | Add profile for LXC host for infra03 | Jan Dittberner | |
Setup ntp, dnsmasq and resolv.conf for LXC hosting | |||
2021-05-24 | Make ssl_cert_cacert available on extmon | Jan Dittberner | |
This adds the ssl_cert_cacert CheckCommand definition globally. | |||
2021-05-14 | Rename hiera data file to .yaml | Jan Dittberner | |
Hiera doesn't look for .yml | |||
2021-05-14 | Add base setup for infra03 | Jan Dittberner | |
2021-05-11 | Add vim-nox to base packages | Jan Dittberner | |
2021-05-11 | Fix default file mode for private keys | Jan Dittberner | |
2021-05-08 | Fix Puppet assignment syntax | Jan Dittberner | |
2021-05-08 | Allow cacert_boardvoting user to access private key | Jan Dittberner | |
2021-05-08 | Fix unsupported variable reassignment | Jan Dittberner | |
Use https://forge.puppet.com/modules/puppetlabs/stdlib/7.0.1/reference#pick-1 to workaround unsupported variable reassignment in the Puppet DSL. | |||
2021-05-08 | Add dependencies on certificate files | Jan Dittberner | |
Subscribe the cacert-boardvoting service to the certificate and key files to trigger restarts on changes. | |||
2021-05-08 | Use x509cert_common for cacert_boardvoting | Jan Dittberner | |
- add support for custom owner, group and mode for private key files managed by x509cert_common - use x509cert_common for cacert_boardvoting - remove key and certificate from old locations - add class1 (root) certificate to allowed client certificate roots for cacert_boardvoting |