- Sep 30, 2018
-
-
Jelle van der Waa authored
-
- Sep 23, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Sep 21, 2018
-
-
Phillip Smith (fukawi2) authored
-
- Sep 19, 2018
-
-
Jelle van der Waa authored
Remove eric's pubkey and addition of it['s user account.
-
- Sep 14, 2018
-
-
Jelle van der Waa authored
Enable pacache timer to cleanup old packages and keeps the lsat three version of a package.
-
- Sep 12, 2018
-
-
Phillip Smith (fukawi2) authored
-
- Sep 05, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Aug 31, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Aug 28, 2018
-
-
Jan Alexander Steffens (heftig) authored
-
Jan Alexander Steffens (heftig) authored
-
Jelle van der Waa authored
-
Jelle van der Waa authored
-
Florian Pritz authored
- firewall tag so that the facts exist when only firewall is run - extract IPs from our host vars all the time. no need to query autodetected facts - remove empty elements from the list with select(). not all hosts have ipv6 - fix the subnetmask for v6 - fix the postgres role configuring a v4 rule instead of v6 for a v6 address - hardcode netmask for orion addresses too Little bit much for one commit, but splitting it doesn't make a whole lot of sense. Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Aug 24, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Aug 22, 2018
-
-
Jelle van der Waa authored
The ipv6 configuration from hetzner was copied while specific nymeria settings where reqired.
-
- Aug 18, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Aug 17, 2018
-
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
we have to use rich rules in firewalld to restict a specific port to a list of specific ip addresses. when using rich rules, you have to specify the address family (ipv4 or ipv6) which we can't do in an automated fashion with the ipv4 and ipv6 addresses of the clients dynamically generated into a single variable. so this commit creates 2 variables; one for ipv4 clients and one for ipv6 clients which can be referred to as required when creating the rich rules.
-
Phillip Smith (fukawi2) authored
none of our hosts are configured using dhcpv6 so no need to allow this default firewall hole to remain in place.
-
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
-
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
Signed-off-by:
Christian Rebischke <Chris.Rebischke@posteo.de>
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
other roles with firewalld tasks will fail if firewalld is not installed, enabled and started prior to them trying to run.
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
-
Phillip Smith (fukawi2) authored
we have to use rich rules in firewalld to restict a specific port to a list of specific ip addresses. when using rich rules, you have to specify the address family (ipv4 or ipv6) which we can't do in an automated fashion with the ipv4 and ipv6 addresses of the clients dynamically generated into a single variable. so this commit creates 2 variables; one for ipv4 clients and one for ipv6 clients which can be referred to as required when creating the rich rules.
-
Phillip Smith (fukawi2) authored
none of our hosts are configured using dhcpv6 so no need to allow this default firewall hole to remain in place.
-
- Aug 16, 2018
-
-
Jelle van der Waa authored
-
- Aug 15, 2018
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-