Compare commits

...

3 commits

Author SHA1 Message Date
Franzi d6bb5e973e
voc.infobeamer-cms: add gpn20 people
All checks were successful
kunsi/bundlewrap/pipeline/head This commit looks good
2022-05-16 14:37:35 +02:00
Franzi 51c9506a19
move pacman/no_extract to bundle metadata defaults 2022-05-16 10:52:14 +02:00
Franzi 9730a2be13
bundles/wireguard: fix permissions for wireguard netdev files 2022-05-16 10:48:26 +02:00
5 changed files with 10 additions and 2 deletions

View file

@ -5,6 +5,7 @@ defaults = {
'pacman', 'pacman',
}, },
'no_extract': { 'no_extract': {
'etc/cron.d/0hourly',
# don't install systemd-homed pam module. It produces a lot of spam in # don't install systemd-homed pam module. It produces a lot of spam in
# journal about systemd-homed not being active, so just get rid of it. # journal about systemd-homed not being active, so just get rid of it.
# Requires reinstall of systemd package, though # Requires reinstall of systemd package, though

View file

@ -18,6 +18,8 @@ for number, (peer, config) in enumerate(sorted(node.metadata.get('wireguard/peer
files[f'/etc/systemd/network/wg{number}.netdev'] = { files[f'/etc/systemd/network/wg{number}.netdev'] = {
'content_type': 'mako', 'content_type': 'mako',
'source': 'wg.netdev', 'source': 'wg.netdev',
'owner': 'systemd-network',
'mode': '0600',
'context': { 'context': {
'endpoint': config.get('endpoint'), 'endpoint': config.get('endpoint'),
'number': number, 'number': number,

View file

@ -49,6 +49,9 @@ defaults = {
}, },
}, },
'pacman': { 'pacman': {
'no_extract': {
'etc/sudoers.d/zfs',
},
'packages': { 'packages': {
'zfs-utils': { 'zfs-utils': {
'needed_by': { 'needed_by': {

View file

@ -71,9 +71,7 @@ nodes['kunsi-p14s'] = {
}, },
'pacman': { 'pacman': {
'no_extract': { 'no_extract': {
'etc/cron.d/0hourly',
'etc/sudoers.d/ctdb', # samba junk 'etc/sudoers.d/ctdb', # samba junk
'etc/sudoers.d/zfs',
}, },
'packages': { 'packages': {
# for hardware support # for hardware support

View file

@ -32,6 +32,10 @@ nodes['voc.infobeamer-cms'] = {
'ADMIN_USERS': [ 'ADMIN_USERS': [
'kunsi', 'kunsi',
'sophieschi', 'sophieschi',
# GPN20
'hexchen',
'twiddau',
], ],
'GITHUB_CLIENT_ID': vault.decrypt('encrypt$gAAAAABiNwHfIu9PYFfJrF7qirn_9vdvvUlEhJnadoNSS5XlCDbI_aMyj21_ZYQxaCkc6_eVX6Cj1jEHZ7Vs6wM-XyQdW0nUOahtqG4uvnYCiM3GFKHW_wQ='), 'GITHUB_CLIENT_ID': vault.decrypt('encrypt$gAAAAABiNwHfIu9PYFfJrF7qirn_9vdvvUlEhJnadoNSS5XlCDbI_aMyj21_ZYQxaCkc6_eVX6Cj1jEHZ7Vs6wM-XyQdW0nUOahtqG4uvnYCiM3GFKHW_wQ='),
'GITHUB_CLIENT_SECRET': vault.decrypt('encrypt$gAAAAABiNwHtdZC2XQ8IjosL7vsmrxZMwDIM6AD5dUlLo996tJs4qV7KJETHgYYZil2aMzClwhcE6JmxdhARRp7IJQ4rQQibelTNmyYSzj_V4puVpvma7SU0UZkTIG95SdPpoHY--Zba'), 'GITHUB_CLIENT_SECRET': vault.decrypt('encrypt$gAAAAABiNwHtdZC2XQ8IjosL7vsmrxZMwDIM6AD5dUlLo996tJs4qV7KJETHgYYZil2aMzClwhcE6JmxdhARRp7IJQ4rQQibelTNmyYSzj_V4puVpvma7SU0UZkTIG95SdPpoHY--Zba'),