- Jul 30, 2021
-
-
Kristian Klausen authored
en is the prefix for ethernet according to systemd.net-naming-scheme(7)
-
Redundant since this commit: bdd538ec ("Use unbound for rspamd DNS resolving") Signed-off-by:
Leonidas Spyropoulos <artafinde@gmail.com>
-
- Jul 20, 2021
-
-
Kristian Klausen authored
CPU: Intel Xeon E5-2620 -> E-2288G Disk: 2x~1TB -> 2x~500GB
-
- Jul 13, 2021
-
-
Evangelos Foutras authored
It's been running out of swap during borg-backup and seems to get good compression ratios; try upping the zram size to 100% of RAM (from 50%).
-
- Jul 12, 2021
-
-
Jelle van der Waa authored
-
Evangelos Foutras authored
zswap seems like the better choice when a backing swap partition exists.
-
- Jul 11, 2021
-
-
Jelle van der Waa authored
Add a default rate limit for 20 req/s for the uwsgi endpoint and automatically ban users who reach this limit. The nginx-limit-req rule does not ban users who reach the rss limit as these are not likely DoS attempts.
-
- Jul 06, 2021
-
-
Kristian Klausen authored
-
Kristian Klausen authored
This is meant as a internal authenticated and encrypted network which we can use for internal services, we don't want to expose to the internet or when encryption is desired but not easily implementable.
-
- Jun 30, 2021
-
-
Kristian Klausen authored
nginx, certbot, postfix and mailman are still missing and the DNS is still pointing to luna.
-
- Jun 16, 2021
-
-
Kristian Klausen authored
Fix #325
-
- Jun 11, 2021
-
-
Kristian Klausen authored
-
- Jun 10, 2021
-
-
Leonidas Spyropoulos authored
Ansible complains if the fail2ban_jails dictionary is missing the nginx_limit_req key. Adding this as default failse. Bugfix from: e5773374 Signed-off-by:
Leonidas Spyropoulos <artafinde@gmail.com>
-
- Jun 07, 2021
-
-
Kristian Klausen authored
Fix #193
-
- May 25, 2021
-
-
Jelle van der Waa authored
-
- May 23, 2021
-
-
Jelle van der Waa authored
To negate high cpu spikes from abusers/bots who scan our services, we now fail2ban them.
-
- May 13, 2021
-
-
Jelle van der Waa authored
-
Co-authored-by:
Kristian Klausen <kristian@klausen.dk>
-
- Apr 18, 2021
-
-
Jelle van der Waa authored
Gitlab can show our alertmanager alerts only for > reporter and create issues from alerts on gitlab.
-
- Apr 07, 2021
-
-
For spam checking it is recommend to use our own recursive resolver[1] to avoid rate limiting by using a public resolver. unbound is already installed but the system wasn't configured to use it. [1] https://rspamd.com/doc/faq.html#resolver-setup
-
- Mar 12, 2021
-
-
Jelle van der Waa authored
-
- Mar 01, 2021
-
-
Jelle van der Waa authored
Previously we configured our network conf to all interfaces, which shouldn't be done as not all our routed to the internet and this causes systemd-network-online target to fail.
-
- Feb 25, 2021
-
-
Sven-Hendrik Haase authored
-
- Feb 01, 2021
-
-
Jelle van der Waa authored
This adds a collaborative markdown editor as newly offered service which is available via login for all Arch Linux Staff with an option to allow anonymous edits by users (not default). Users are managed via keycloak and require the Staff role to be allowed in, non staff keycloak users currently will receive an internal server error due to an upstream issue.
-
- Jan 31, 2021
-
-
- Jan 26, 2021
-
-
Sven-Hendrik Haase authored
-
Jelle van der Waa authored
Closes: #231
-
- Jan 23, 2021
-
-
Jelle van der Waa authored
This host is special and only allows demize to login as user to administer phrik and no other users/groups should be created on the machine.
-
- Jan 11, 2021
-
-
Sven-Hendrik Haase authored
-
- Dec 30, 2020
-
-
Frederik Schwan authored
The former approach to export a maildir and iterate over it with a script broke when the mail server and the web server got on their own hosts. This will use IMAP IDLE to check for new mails and pass them instantly to the djange manage.py script without storing the mail locally.
-
- Dec 29, 2020
-
-
Giancarlo Razzolini authored
Removed the host_vars file for apollo.
-
- Dec 25, 2020
-
-
Giancarlo Razzolini authored
Added security.archlinux.org to the relevant groups on hosts and created a host_vars so we can run the all-hosts-basic.
-
- Dec 24, 2020
-
-
-
-
-
Giancarlo Razzolini authored
Added patchwork to the relevant groups on hosts and created a new host_vars file for it.
-
- Dec 22, 2020
-
-
Sven-Hendrik Haase authored
-
- Dec 21, 2020
-
-
Giancarlo Razzolini authored
Added a host_vars file for the new wiki.archlinux.org machine, with the required variables, specially the memcached_socket, for the prometheus exporter.
-
- Dec 20, 2020
-
-
Frederik Schwan authored
-
-