Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | use correct group name | Kevin Fenzi | 2016-10-17 | 1 | -1/+1 | |
| | ||||||
* | Attempt to limit pg access to clients that need it only. | Kevin Fenzi | 2016-10-17 | 1 | -0/+85 | |
| | ||||||
* | Set domain realm for krb5 | Patrick Uiterwijk | 2016-10-14 | 1 | -0/+7 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Put krb5.conf in base role | Patrick Uiterwijk | 2016-10-13 | 2 | -0/+38 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | tweak base role interfaces for docker networks | Kevin Fenzi | 2016-10-10 | 1 | -1/+1 | |
| | ||||||
* | remove the entries to noc02 that wont work because that hostnmae doesnt exist | Stephen Smoogen | 2016-09-30 | 1 | -3/+0 | |
| | ||||||
* | Install complete.crt into .crt | Patrick Uiterwijk | 2016-09-27 | 1 | -1/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Install gateway cert with intermediate cert | Patrick Uiterwijk | 2016-09-27 | 1 | -1/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | push the tls change out to the smtp-mm boxes | Stephen Smoogen | 2016-09-27 | 2 | -3/+40 | |
| | ||||||
* | Fix the order of this handler | Kevin Fenzi | 2016-09-27 | 1 | -1/+1 | |
| | ||||||
* | Swap the order of these handlers so it does the map, then the postfix restart. | Kevin Fenzi | 2016-09-27 | 1 | -1/+1 | |
| | ||||||
* | too much email still requires ipv4 only and our ipv6 reverse doesnt work here | Stephen Smoogen | 2016-09-27 | 1 | -1/+1 | |
| | ||||||
* | rebuild then restart | Stephen Smoogen | 2016-09-27 | 1 | -2/+2 | |
| | ||||||
* | tls_ssl_options not implemented in our postfix | Stephen Smoogen | 2016-09-27 | 1 | -1/+1 | |
| | ||||||
* | call it a crt not a csr | Stephen Smoogen | 2016-09-27 | 2 | -3/+3 | |
| | ||||||
* | and we need to have a trigger | Stephen Smoogen | 2016-09-27 | 1 | -0/+3 | |
| | ||||||
* | and put in the items kevin asked for. | Stephen Smoogen | 2016-09-27 | 2 | -5/+10 | |
| | ||||||
* | lets try another go at patching | Stephen Smoogen | 2016-09-27 | 2 | -21/+16 | |
| | ||||||
* | try this patch set on for size to get tls working with smtp | Stephen Smoogen | 2016-09-27 | 2 | -0/+68 | |
| | ||||||
* | Also delivery master.cf to noc02 | Patrick Uiterwijk | 2016-09-24 | 1 | -1/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | why? | Stephen Smoogen | 2016-09-24 | 1 | -1/+1 | |
| | ||||||
* | I broke it so I need to buy it. | Stephen Smoogen | 2016-09-24 | 3 | -0/+0 | |
| | ||||||
* | try to put in place smtp files for noc02 to use smtp-ipv4 vs ipv6 for google | Stephen Smoogen | 2016-09-23 | 3 | -0/+828 | |
| | ||||||
* | Fix a bunch of places that didn't use the full correct mode | Kevin Fenzi | 2016-08-08 | 2 | -12/+12 | |
| | ||||||
* | Death to all trailing whitespace. | Kevin Fenzi | 2016-08-08 | 1 | -4/+4 | |
| | ||||||
* | Make this really norelay | Patrick Uiterwijk | 2016-07-23 | 1 | -1/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | remove debugging, set base to always set hostname | Kevin Fenzi | 2016-07-18 | 1 | -4/+1 | |
| | ||||||
* | drop no longer existant download-rdus from this script | Kevin Fenzi | 2016-07-13 | 1 | -2/+0 | |
| | ||||||
* | osbs-stg will use the normal iptables, and will get docker iptables via a script | Patrick Uiterwijk | 2016-07-05 | 1 | -104/+0 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Until I can figure out this nameserver thing, don't track dns requests to ↵ | Kevin Fenzi | 2016-06-30 | 2 | -0/+248 | |
| | | | | keep conntrack tables not full | |||||
* | ppc8-04 is a hw builder | Kevin Fenzi | 2016-06-27 | 1 | -1/+1 | |
| | ||||||
* | drop bodhost01 and proxy07 | Kevin Fenzi | 2016-05-31 | 1 | -1/+0 | |
| | ||||||
* | Update ip address for ppc hub. | Kevin Fenzi | 2016-05-20 | 1 | -2/+2 | |
| | ||||||
* | Switch mm-smtp servers to send to mailman01 instead of relaying via collab03. | Kevin Fenzi | 2016-05-18 | 2 | -6/+4 | |
| | | | | Also, remove the old transports file which as far as I can tell is not used by anything. | |||||
* | Try this and see if it works any differently. | Kevin Fenzi | 2016-05-14 | 1 | -1/+1 | |
| | ||||||
* | Bypass spam checking for emails from Mailman | Aurélien Bompard | 2016-05-12 | 1 | -0/+5 | |
| | ||||||
* | Fixup activation of SpamAssassin on Mailman | Aurélien Bompard | 2016-05-12 | 1 | -1/+1 | |
| | ||||||
* | Add Spamassassin to Mailman | Aurélien Bompard | 2016-05-12 | 1 | -0/+97 | |
| | ||||||
* | Change ansible_fqdn to inventory_hostname. This fixes some few hosts that ↵ | Kevin Fenzi | 2016-05-11 | 2 | -7/+6 | |
| | | | | | | have incorrect reverse dns and shouldn't break any others since we always use fully qualified in our inventory. | |||||
* | OSBS needs prod kojipkgs | Patrick Uiterwijk | 2016-05-10 | 1 | -1/+5 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Osbs needs access to kojipkgs | Patrick Uiterwijk | 2016-05-10 | 1 | -0/+4 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Nobody asked docker to override dns servers, yet it does | Patrick Uiterwijk | 2016-05-09 | 1 | -0/+4 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Allow all traffic over the docker0 interface | Patrick Uiterwijk | 2016-05-09 | 1 | -0/+2 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Seems it tries to use koji stg over http... | Patrick Uiterwijk | 2016-05-09 | 1 | -0/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Allow https clone from pkgs.stg | Patrick Uiterwijk | 2016-05-09 | 1 | -0/+1 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Prod != stg | Patrick Uiterwijk | 2016-05-09 | 1 | -7/+3 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | Add iptables for osbs build | Patrick Uiterwijk | 2016-05-09 | 1 | -0/+92 | |
| | | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com> | |||||
* | openqa/worker: give up on GRE, single tap host instead | Adam Williamson | 2016-05-05 | 1 | -0/+0 | |
| | | | | | | | OK, this GRE crap ain't working. Let's give up! Instead let's have one tap-capable host per openQA deployment, so all the tap jobs will go to it. This...should achieve that. Let's see what blows up. | |||||
* | openqa: fix iptables stuff | Adam Williamson | 2016-04-27 | 1 | -0/+0 | |
| | | | | apparently host_group is not the same thing as inventory group. | |||||
* | add an 'ansible_ifcfg_whitelist' feature and use it for openqa | Adam Williamson | 2016-04-27 | 1 | -1/+1 | |
| | | | | | | | | | | | semi-acked by nirik (but he'll deny it furiously and it's all my fault if everything blows up): for openQA's openvswitch stuff I need a 'br0' and a 'tap0' that I don't want the base role to mess with, but I *do* want the base role to configure eth0 for me. ansible_ifcfg_blacklist isn't granular enough. So let's invent ansible_ifcfg_whitelist, which if defined is a list of interface names you want the base role to configure. Any interface not in the list is left alone. |