- Jun 16, 2021
-
-
Kristian Klausen authored
Fix #325
-
- Jun 11, 2021
-
-
Kristian Klausen authored
-
- Jun 10, 2021
-
-
Leonidas Spyropoulos authored
Ansible complains if the fail2ban_jails dictionary is missing the nginx_limit_req key. Adding this as default failse. Bugfix from: e5773374 Signed-off-by:
Leonidas Spyropoulos <artafinde@gmail.com>
-
- Jun 07, 2021
-
-
Kristian Klausen authored
Fix #193
-
- May 25, 2021
-
-
Jelle van der Waa authored
-
- May 23, 2021
-
-
Jelle van der Waa authored
To negate high cpu spikes from abusers/bots who scan our services, we now fail2ban them.
-
- May 13, 2021
-
-
Jelle van der Waa authored
-
Co-authored-by:
Kristian Klausen <kristian@klausen.dk>
-
- Apr 18, 2021
-
-
Jelle van der Waa authored
Gitlab can show our alertmanager alerts only for > reporter and create issues from alerts on gitlab.
-
- Apr 07, 2021
-
-
For spam checking it is recommend to use our own recursive resolver[1] to avoid rate limiting by using a public resolver. unbound is already installed but the system wasn't configured to use it. [1] https://rspamd.com/doc/faq.html#resolver-setup
-
- Mar 12, 2021
-
-
Jelle van der Waa authored
-
- Mar 01, 2021
-
-
Jelle van der Waa authored
Previously we configured our network conf to all interfaces, which shouldn't be done as not all our routed to the internet and this causes systemd-network-online target to fail.
-
- Feb 25, 2021
-
-
Sven-Hendrik Haase authored
-
- Feb 01, 2021
-
-
Jelle van der Waa authored
This adds a collaborative markdown editor as newly offered service which is available via login for all Arch Linux Staff with an option to allow anonymous edits by users (not default). Users are managed via keycloak and require the Staff role to be allowed in, non staff keycloak users currently will receive an internal server error due to an upstream issue.
-
- Jan 31, 2021
-
-
- Jan 26, 2021
-
-
Sven-Hendrik Haase authored
-
Jelle van der Waa authored
Closes: #231
-
- Jan 23, 2021
-
-
Jelle van der Waa authored
This host is special and only allows demize to login as user to administer phrik and no other users/groups should be created on the machine.
-
- Jan 11, 2021
-
-
Sven-Hendrik Haase authored
-
- Dec 30, 2020
-
-
Frederik Schwan authored
The former approach to export a maildir and iterate over it with a script broke when the mail server and the web server got on their own hosts. This will use IMAP IDLE to check for new mails and pass them instantly to the djange manage.py script without storing the mail locally.
-
- Dec 29, 2020
-
-
Giancarlo Razzolini authored
Removed the host_vars file for apollo.
-
- Dec 25, 2020
-
-
Giancarlo Razzolini authored
Added security.archlinux.org to the relevant groups on hosts and created a host_vars so we can run the all-hosts-basic.
-
- Dec 24, 2020
-
-
-
-
-
Giancarlo Razzolini authored
Added patchwork to the relevant groups on hosts and created a new host_vars file for it.
-
- Dec 22, 2020
-
-
Sven-Hendrik Haase authored
-
- Dec 21, 2020
-
-
Giancarlo Razzolini authored
Added a host_vars file for the new wiki.archlinux.org machine, with the required variables, specially the memcached_socket, for the prometheus exporter.
-
- Dec 20, 2020
-
-
Frederik Schwan authored
-
-
- Dec 15, 2020
-
-
Giancarlo Razzolini authored
Add the ip addresses for mirror.pkgbuild.com, otherwise the apollo and archlinux.org playbooks won't run
-
Giancarlo Razzolini authored
Added a host_var file for archlinux.org as well as the playbook for archlinux.org machine. It it's a stripped down version of apollo's playbook, only containing the roles pertaining archweb.
-
- Dec 12, 2020
-
-
Frederik Schwan authored
Do not use asterisk on network devices to prevent IP address collisions on networks. Also use the right network mask for the assigned network. For runner1 we need to ignore RAs since those routes don't work.
-
To simplify the archive role, split it up in the web serving part for the archive-mirrors, gemini and keep the archive role for only the archive operation. This simplifies the new role as only two lines are required to setup the the archive mirror website.
-
-
- Dec 11, 2020
-
-
- Dec 07, 2020
-
-
Jelle van der Waa authored
Setup Kape servers as archive mirrors (asia,europe,america), Gitlab runner and Rebuilderd worker. All machines except runner1 are EFI machines with grub setup and a EFI parition which is not supported by our ansible install role and is manually rolled out.
-
- Dec 03, 2020
-
-
The repro3.pkgbuild.com machine was a packet.net box with an Ubuntu installation. Now converted to an Arch Linux installation managed by ansible with a new rebuilderd_worker role.
-
- Nov 21, 2020
-
-
Jelle van der Waa authored
Zabbix has been replaced by Prometheus for monitoring our services.
-
Orion has been replaced by gemini and for mail by mail.archlinux.org
-