Commit graph

390 commits

Author SHA1 Message Date
Franzi 3088ae0ba0
bundles/sshmon: add key, add to all nodes 2020-11-10 09:15:51 +01:00
Franzi ca922ef5f7
scripts: add encrypt_file and passwords-for 2020-11-10 09:15:28 +01:00
Franzi 2e2c504111
groups/ovh: make sure default user is gone 2020-11-10 08:59:54 +01:00
Franzi 6ca0d863b1
bundles/sudo: use sudoers.d
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 20:39:35 +01:00
Franzi c7362df6c4
bundles/sshmon: import from work repository 2020-11-09 20:31:06 +01:00
Franzi eaf268aea9
libs/tools: change resolve_identifier() to return ipv4 and ipv6 separately
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 18:46:37 +01:00
Franzi 67386d9efa
bundles/cron: provide some environment, also manage /etc/crontab
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 18:24:01 +01:00
Franzi 1ffe8bd23e
nodes/htz.ex42-1048908: update travelynx to 1.18.8 2020-11-09 17:03:13 +01:00
Franzi a58c5877bf
bundles/gce-workaround: uninstall gce-disk-expand, too
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 16:48:28 +01:00
Franzi 4921e0b74f
bundles/systemd-networkd: use correct syntax for resolv.conf 2020-11-09 16:47:56 +01:00
Franzi 2e56feb27d
nodes/ovh.icinga2: introduce
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 16:40:15 +01:00
Franzi bd89cd4cb5
groups/locations: sort groups, add nameservers for google and home, add ovh 2020-11-09 16:39:57 +01:00
Franzi 6f87a1d240
bundles/systemd-networkd: also deploy resolv.conf 2020-11-09 16:38:59 +01:00
Franzi 394424951f
bundles/systemd-networkd: fix naming of GatewayOnlink 2020-11-09 16:38:35 +01:00
Franzi 78047da04a
bundles/postgresql: only install packages after we have a zfs dataset 2020-11-09 16:37:00 +01:00
Franzi 5bd642236c
bundles/postfix: only call newaliases if we already have postfix installed 2020-11-09 16:36:26 +01:00
Franzi 607da9d39b
bundles/powerdns: user resolve_identifier() for node-dns-entries 2020-11-09 15:37:48 +01:00
kunsi 5ffaa9b1c8 Merge pull request 'bundle/systemd-networkd' (#4) from interface-configuration into main
All checks were successful
bundlewrap/pipeline/head This commit looks good
Reviewed-on: https://git.kunsmann.eu/kunsi/bundlewrap/pulls/4
2020-11-09 14:27:51 +00:00
Franzi 44414f2375
libs/tools: adjust resolve_identifier() to new interface config 2020-11-09 15:23:44 +01:00
Franzi d90c9edc22
nodes: fix interface config 2020-11-09 15:16:29 +01:00
Franzi 91fd33cfa0
bundles/systemd-networkd: better dhcp support 2020-11-09 14:58:09 +01:00
Franzi 5e7c7671e0
bundles/systemd-networkd: proper config 2020-11-09 14:48:19 +01:00
Franzi fbb4e2f7a5
systemd-networkd: first draft 2020-11-09 14:08:32 +01:00
Franzi aa477322ac
dns: deploy TLS-RPT for domains we're doing mail for
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 13:18:09 +01:00
Franzi c3c510c609
bundles/mautrix-telegram: disable parallel file transfers for now 2020-11-09 13:17:38 +01:00
Franzi f96c53ee8a
nodes/htz.ex42-1048908: fix matrix.franzi.business nginx config 2020-11-09 13:06:03 +01:00
Franzi 835da4db4d
dns: remove wildcard entries
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 12:37:58 +01:00
Franzi ea10ed96e5
dns: fix DMARC records, fix SPF
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 12:17:26 +01:00
Franzi af97226512
nodes/htz.ex42-1048908: update mautrix-telegram to 0.9.2-rc2
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 12:16:06 +01:00
Franzi 06e30cf23c
bundles/mautrix-telegram: also upgrade pip when upgrading bridge 2020-11-09 12:15:37 +01:00
Franzi 90e3bb7fb2
bundles/mautrix-telegram: no need to provide our own alembic.ini 2020-11-09 12:12:04 +01:00
Franzi c0986eb956
bundles/mautrix-telegram: fix database migration
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 12:09:17 +01:00
Franzi 614b920890
bundles/mautrix-telegram: pin version until database migration is fixed
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 11:27:34 +01:00
Franzi 3ff5d8a7dd
bundles/postfix: add alias database
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-09 10:52:24 +01:00
Franzi d39cb5bd82
PORT_MAP: add new mail bundles
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-08 15:59:51 +01:00
Franzi 6a6a9748b4
nodes/rx300: add info about grub configuration
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-08 15:05:17 +01:00
Franzi 64cffad6a7
bundles/rspamd: silence clamav cronjob 2020-11-08 15:03:26 +01:00
Franzi 0eca42d188
bundles/dovecot: fix home directory for virtual mailboxes
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-08 13:00:44 +01:00
Franzi b4b988e5f2
bundles/postfix: disable TLS1.0 and 1.1, disable weak ciphers
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-08 12:24:37 +01:00
Franzi eddabb0043
dns: activate DMARC 2020-11-08 12:23:41 +01:00
Franzi f85349f0c5
bundles/postfixadmin: fix apt packages
All checks were successful
bundlewrap/pipeline/head This commit looks good
2020-11-08 11:53:51 +01:00
Franzi 0647a8203d
nodes/htz.ex42-1048908: add another ip to spamcheck bypass 2020-11-08 11:06:30 +01:00
Franzi 4ef9b119ef
nodes/htz.ex42-1048908: bump php to 7.4
Some checks failed
bundlewrap/pipeline/head There was a failure building this commit
2020-11-08 10:57:01 +01:00
Franzi 15428b03be
bundles/rspamd: introduce, add to htz.ex42-1048908
Some checks failed
bundlewrap/pipeline/head There was a failure building this commit
2020-11-08 10:43:51 +01:00
Franzi a236444fe5
bundles/dovecot: make sure to reload dovecot after letsencrypt 2020-11-08 10:42:08 +01:00
Franzi e36dbf0222
libs/tools: fix missing default in resolve_identifier() 2020-11-08 10:41:41 +01:00
Franzi b00b2aa245
bundles/dovecot: autoexpunge Junk folder
Some checks failed
bundlewrap/pipeline/head There was a failure building this commit
2020-11-07 22:46:15 +01:00
Franzi 1b5ac55033
install postfix on all nodes, configure ex42-1048908 for incoming mail 2020-11-07 22:32:47 +01:00
Franzi 7080b0d89e
bundles/rspamd: create dummy bundle 2020-11-07 22:32:08 +01:00
Franzi 18b573a9c6
bundles/dovecot: introduce 2020-11-07 22:31:47 +01:00