Commits on Source (20)
-
Evangelos Foutras authored
-
Evangelos Foutras authored
The default login shell for the svntogit user (/sbin/nologin) breaks the Match Exec directives in /srv/svntogit/.ssh/config and prohibits Git from using the correct SSH key. While we're at it, add --set-upstream to the git pull command so the task is more likely to accomplish its intended purpose.
-
Kristian Klausen authored
-
Kristian Klausen authored
It simplifies it a bit.
-
Kristian Klausen authored
-
Kristian Klausen authored
-
Kristian Klausen authored
-
Evangelos Foutras authored
No functional change; the "restrict" key option is a shorthand for: - no-agent-forwarding - no-port-forwarding - no-X11-forwarding - no-pty - no-user-rc It was added in OpenSSH 7.2 (2016-02-29) as a convenient way to specify an authorized key should have "all current and future key restrictions" applied to it.
-
Evangelos Foutras authored
The official backup tool for GitLab takes many hours to run because it puts everything inside tarballs and then gzips each one. It seems safe and much more efficient to skip this step for the offsite backup while reusing the tarballs generated by the first backup to the Storage Box. Should save ~5 hours from the borg-backup-offsite.service execution.
-
Evangelos Foutras authored
Avoid running backup-gitlab twice; reuse tarballs See merge request !451
-
Kristian Klausen authored
The port was removed in: 4729ba40 ("postfix: Remove special "fast-path" smtpd")
-
Kristian Klausen authored
It confuses the users that the browser is caching them (due to heuristic[1]). [1] https://developer.mozilla.org/en-US/docs/Web/HTTP/Caching#heuristic_freshness_checking
-
Closes #358
-
Kristian Klausen authored
archweb: Add robots.txt Closes #358 See merge request !452
-
Add number of pacnew/pacsave files and print non explicit installed optdepends as orphans as well.
-
Kristian Klausen authored
prometheus_exporters: Improve arch-textcollector See merge request !453
-
David Runge authored
.gitlab/issue_templates/Onboarding.md: Create the ticket as confidential by default (using a short action). Make the required information in the Details section more explicit and add entries that are relevant when creating an SSO and/or archweb account. Add a note for sponsors of new users, so that they also add a clearsigned version of the data they provide. Add a dot at the end of each sentence. Make the entries for mailing list operations more generic and rely on the *communication e-mail address*, which may be the user's personal mail address or a newly created @archlinux.org mail address. Add warning message about creating a confidential ticket when providing personal data. Add checkbox to remind about the removal of personal information, removal of description history and setting the ticket to be non-confidential (if it has been confidential due to personal data). Add checkbox that reminds setting the Team member username to the @-prefixed username on gitlab (after the user has logged in).
-
Kristian Klausen authored
Extend onboarding by more explicit information See merge request !418
-
Evangelos Foutras authored
Mark "Free Space (Hetzner)" metric as instant for faster updates.
-
Jelle van der Waa authored
Add a default rate limit for 20 req/s for the uwsgi endpoint and automatically ban users who reach this limit. The nginx-limit-req rule does not ban users who reach the rss limit as these are not likely DoS attempts.
Showing
- .gitlab/issue_templates/Onboarding.md 37 additions, 15 deletions.gitlab/issue_templates/Onboarding.md
- docs/email.md 0 additions, 3 deletionsdocs/email.md
- docs/fail2ban.md 3 additions, 0 deletionsdocs/fail2ban.md
- group_vars/all/vault_loki.yml 7 additions, 9 deletionsgroup_vars/all/vault_loki.yml
- host_vars/archlinux.org/misc 1 addition, 1 deletionhost_vars/archlinux.org/misc
- roles/archweb/files/robots.txt 6 additions, 0 deletionsroles/archweb/files/robots.txt
- roles/archweb/tasks/main.yml 6 additions, 0 deletionsroles/archweb/tasks/main.yml
- roles/archweb/templates/nginx.d.conf.j2 6 additions, 0 deletionsroles/archweb/templates/nginx.d.conf.j2
- roles/borg_client/templates/borg-backup.service.j2 5 additions, 0 deletionsroles/borg_client/templates/borg-backup.service.j2
- roles/borg_client/templates/borg-backup.sh.j2 2 additions, 1 deletionroles/borg_client/templates/borg-backup.sh.j2
- roles/dbscripts/tasks/main.yml 5 additions, 3 deletionsroles/dbscripts/tasks/main.yml
- roles/dbscripts/templates/authorized_keys-group.j2 1 addition, 1 deletionroles/dbscripts/templates/authorized_keys-group.j2
- roles/fail2ban/templates/nginx-limit-req.jail.j2 3 additions, 1 deletionroles/fail2ban/templates/nginx-limit-req.jail.j2
- roles/grafana/files/dashboards/backups.json 4 additions, 4 deletionsroles/grafana/files/dashboards/backups.json
- roles/grafana/templates/grafana.ini.j2 1 addition, 1 deletionroles/grafana/templates/grafana.ini.j2
- roles/loki/defaults/main.yml 0 additions, 1 deletionroles/loki/defaults/main.yml
- roles/loki/tasks/main.yml 1 addition, 13 deletionsroles/loki/tasks/main.yml
- roles/loki/templates/nginx.d.conf.j2 3 additions, 2 deletionsroles/loki/templates/nginx.d.conf.j2
- roles/mailman/files/aliases 4 additions, 0 deletionsroles/mailman/files/aliases
- roles/mailman/tasks/main.yml 2 additions, 0 deletionsroles/mailman/tasks/main.yml
roles/archweb/files/robots.txt
0 → 100644
roles/loki/defaults/main.yml
deleted
100644 → 0
roles/mailman/files/aliases
0 → 100644