Commit graph

233 commits

Author SHA1 Message Date
8ca459430c nsd: Restart nsd after certificate update 2020-09-04 06:37:53 +00:00
e10d84305a base: Install curl to all hosts 2020-09-03 20:24:25 +00:00
7de9a9a6ae nsd: Remove secondary dns servers
We run all as masters at the moment.
2020-09-03 20:04:17 +00:00
b4e260b1e1 nsd: Fix typo 2020-09-03 20:04:05 +00:00
c9f3b7d0b7 Add ns02.home.foo.sh host 2020-09-03 17:59:43 +00:00
69c17d7e12 nsd: Initial version of role (WIP) 2020-09-03 17:58:53 +00:00
c1c74dc5c4 network: Fix type warning from net.inet.carp.preempt 2020-09-03 16:09:18 +00:00
35b1487d2a postfix: Verify peer certificate for stunnel 2020-09-03 07:48:42 +00:00
63890bcb72 opensmtpd: Redirect all local mails to relay 2020-09-03 07:34:20 +00:00
108660e297 network: Require proto=static for static ip address 2020-09-03 06:51:07 +00:00
2312e0b038 ldap_netdb: Fix typo 2020-09-03 06:07:33 +00:00
5b24509081 postfix: Fix email sending to local addresses
CentOS 7 sendmail and postfix doesn't have support for sending to SMTPs
server on port 465 so use stunnel for those.
2020-09-02 21:07:21 +00:00
574916dfaf postfix: Fix local mail delivery to relayhost 2020-09-02 17:13:13 +00:00
8d1fed8695 pf: Fix indentation from pf.conf 2020-09-01 20:37:00 +00:00
6d63bda3ff network: Fix OpenBSD interface with empty settings 2020-09-01 20:22:48 +00:00
bec7f3a84d base: Use copy instead of file 2020-09-01 20:18:14 +00:00
f1468b0f1f base: Use explicit package names for OpenBSD 2020-09-01 20:16:33 +00:00
51aa0a709e selinux: lint fixes 2020-09-01 19:21:18 +00:00
55d7d954b3 ldap_netdb: Initial version of role 2020-09-01 18:12:21 +00:00
7b201b31da collab: Add missing srcdir and remove swap file 2020-08-31 00:21:37 +00:00
9dd83a8146 Lint fixes 2020-08-31 00:20:22 +00:00
c9b21a3286 Add ansible_certificate custom fact 2020-08-29 15:55:51 +00:00
aac14db657 ansible-host: Publish ansible facts with nginx 2020-08-29 13:43:21 +00:00
88157dcc91 collab: Initial version of role 2020-08-28 16:09:53 +00:00
dd2b5c6a69 apache: Remove Procotols option
CentOS 7 doesn't support Protocols definition at all. Also as we
are running Apache only behind proxies all requests are HTTP/1.1
anyway.
2020-08-28 10:57:39 +00:00
e7aa1c9b73 apache: Drop back to Mozilla intermediate
Looks like our proxies don't support modern settings yet.
2020-08-28 10:13:29 +00:00
47da9470a6 apache: Allow access to web root 2020-08-28 10:10:57 +00:00
bace8a39b4 apache: Just use Mozilla recommended settings
Removed all RedHat default settings and just added Mozilla recommended
modern settings.
2020-08-28 10:05:44 +00:00
affeddd2cc apache: Require client certificate authentication 2020-08-28 09:58:36 +00:00
480822619d apache: Initial version of module 2020-08-28 09:52:02 +00:00
9532fa165e ansible-host: Add missing bashrc file 2020-08-28 07:32:56 +00:00
18919643d9 base: Really disable rsa key and not just say so 2020-08-28 07:29:59 +00:00
526a192018 ansible-host: Make sure that ssh-agent is running for root 2020-08-27 18:47:49 +00:00
8ecbc19c75 ansible-host: Remove some packages not related to ansible 2020-08-27 18:26:57 +00:00
602cc4dfc6 certbot: Add missing config file and lint fixes 2020-08-27 21:14:36 +03:00
b81950c5b2 ansible-host: Don't update local ansible repo 2020-08-27 21:13:31 +03:00
5e1f521eb6 certbot: Initial version of role 2020-08-27 20:50:57 +03:00
cb51dc186c network: Fix default network_interfaces variable 2020-08-27 17:47:09 +00:00
c80eca3d85 New implementation of network interfaces
Combine interfaces and network_ether_interfaces into one common
variable network_interfaces. Provisioning uses format:

network_interfaces:
  - device: device name eg. vio0 or eth0
    vlan: vlan id for this interface
    mac: mac address for interface (optional)

Additionally network role will use more settings to configure
interface.
2020-08-27 17:42:07 +00:00
ee03bd3cb7 ansible-host: More fixes to support out of box install 2020-08-27 14:43:19 +03:00
00bdcfb7de selinux: Fix python package name for EL8 2020-08-27 14:35:31 +03:00
f14bb25ade nginx/site: Add support for self signed certs 2020-08-27 13:45:19 +03:00
e672015a1f nginx: Use alias for certbot host 2020-08-27 12:00:28 +03:00
ee23e2120b ansible-host: Add missing virt-install 2020-08-26 23:46:18 +03:00
398bbf5a32 ansible-host: Install more tools 2020-08-26 23:40:52 +03:00
d09ad303dc ansible-host: Fix private directory link 2020-08-26 23:31:20 +03:00
f05112b125 ansible-host: Initial version of role 2020-08-26 23:25:20 +03:00
858a7d30d7 epel-repo: Initial version of role 2020-08-26 23:11:51 +03:00
964b70f978 base: Add more base packages 2020-08-26 23:04:16 +03:00
74edead676 base: Remove all depencies to other than base packages 2020-08-26 22:54:47 +03:00