summaryrefslogtreecommitdiffstats
path: root/roles/base
Commit message (Collapse)AuthorAgeFilesLines
* Add missing .stg.phx2.fp.o to krb5.conf. If env will be removed after freezePatrick Uiterwijk2017-09-151-0/+3
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* openqa tap workers: allow masquerade on eth2 also, for ppc64Adam Williamson2017-09-091-0/+3
| | | | Signed-off-by: Adam Williamson <awilliam@redhat.com>
* Add dns1 and dns2 for nm-controlled resolv.confPatrick Uiterwijk2017-08-211-1/+3
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Allow NM-controlled DNS if intendedPatrick Uiterwijk2017-08-212-1/+4
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* move this to a dep instead of including itKevin Fenzi2017-08-192-3/+1
|
* Turns out it was just missing a name=Patrick Uiterwijk2017-08-161-1/+2
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Turns out name: is incompatible with include_rolePatrick Uiterwijk2017-08-161-2/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Move SSH setup to its own rolePatrick Uiterwijk2017-08-1613-1563/+3
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Revert "bypass sshd restart for nowg"Patrick Uiterwijk2017-08-151-1/+1
| | | | This reverts commit ecb03a1093dd4ad6e5e9e0ac5c3a20eeb1ac4ae3.
* Update sshd_config everywhere to present certPatrick Uiterwijk2017-08-156-2/+10
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* We no longer have any <Fedora24 boxesPatrick Uiterwijk2017-08-155-755/+0
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* bypass sshd restart for nowgPatrick Uiterwijk2017-08-151-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Lets just call out to date...Patrick Uiterwijk2017-08-151-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Add sshd_cert tagPatrick Uiterwijk2017-08-151-0/+10
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Open firewall enough from s390x-01 for sshfsPatrick Uiterwijk2017-08-121-0/+4
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Or no quotingPatrick Uiterwijk2017-08-041-2/+2
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Quote this too. Quote all the thingsPatrick Uiterwijk2017-08-041-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Fix EPARSEPatrick Uiterwijk2017-08-041-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Deploy sender_access filePatrick Uiterwijk2017-08-041-0/+17
| | | | Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
* Create a sender_access filePatrick Uiterwijk2017-08-041-0/+3
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* when != henPatrick Uiterwijk2017-07-141-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Teach ansible about the enc900 interface on s390Patrick Uiterwijk2017-07-142-2/+7
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* How beauteous mankind is! O brave new worldStephen Smoogen2017-06-261-4/+0
|
* cut down the list of hosts externalStephen Smoogen2017-06-231-0/+3
|
* add resolv.conf for internetxRicky Elrod2017-06-201-0/+4
| | | | Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
* adding main.cf for upstreamfirst.fedorainfracloud.orgTim Flink2017-05-251-0/+687
|
* oops, == here not isKevin Fenzi2017-05-151-4/+4
|
* clean up iptables in base to not apply to cloud compute/master, osbs or osKevin Fenzi2017-05-151-2/+4
|
* lets try this s390 caching againKevin Fenzi2017-05-141-0/+3
|
* comment in rsyslog-audit module in baseKevin Fenzi2017-05-041-20/+23
|
* Fix up policy source and add EL6 compiled versionPatrick Uiterwijk2017-05-042-9/+4
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* initial selinux module work for rsyslog to read auditKevin Fenzi2017-05-042-0/+38
|
* Revert "ansible tells me not to use {s in when, lets see if this works"Kevin Fenzi2017-04-201-1/+1
| | | | This reverts commit 9b77ca729b3d8ea304d99e795c9aae77006c57a5.
* ansible tells me not to use {s in when, lets see if this worksKevin Fenzi2017-04-201-1/+1
|
* change state=running to start=started as the old one is going away in ↵Kevin Fenzi2017-04-132-2/+2
| | | | ansible 2.7
* and we will try nagios templatesStephen Smoogen2017-04-111-4/+0
|
* kill paste0* instancesKevin Fenzi2017-04-111-3/+0
|
* drop hosted03 from nagios and various other placesKevin Fenzi2017-04-111-1/+0
|
* Configure SSH certificatesPatrick Uiterwijk2017-04-106-0/+6
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Production key is generatedPatrick Uiterwijk2017-04-091-11/+2
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Revert "Make explicitly invalid"Patrick Uiterwijk2017-04-091-1/+1
| | | | This reverts commit b91d69d1ede9d66a7a24d7fe555d33c9ca4d7574.
* Make explicitly invalidPatrick Uiterwijk2017-04-091-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* SSH does not know yearsPatrick Uiterwijk2017-04-091-1/+1
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Combine properlyPatrick Uiterwijk2017-04-091-2/+2
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Allow setting additional hostnamesPatrick Uiterwijk2017-04-091-2/+2
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Use a static dirPatrick Uiterwijk2017-04-091-9/+12
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Fix env testsPatrick Uiterwijk2017-04-091-10/+10
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* Add initial SSH certificatesPatrick Uiterwijk2017-04-092-0/+117
| | | | Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
* do not apply iptables to any fed-cloud machine nowKevin Fenzi2017-04-071-1/+1
|
* put in many changes for new nagios serverStephen Smoogen2017-04-0613-0/+26
|