Commit Graph

90 Commits

Author SHA1 Message Date
jeltz f45cd77510 Merge branch 'master' into logs-first-phase 2021-03-13 05:02:30 +01:00
otthorn a01a2095d6 Add passwords in all and vault for postgres db for wikijs, gitea, nextcloud, drone 2021-03-13 03:07:35 +01:00
jeltz 69516012a2 Add databases for Grafana and CAS
continuous-integration/drone/push Build is failing Details
continuous-integration/drone/pr Build is failing Details
2021-03-11 19:28:14 +01:00
jeltz df4bee2980 Add kanboard database to bdd-ovh
continuous-integration/drone/push Build is passing Details
continuous-integration/drone/pr Build is passing Details
2021-03-10 20:14:02 +01:00
otthorn b3fa8a455d Add/Update password for postgres db codimd, etherpad and synapse
continuous-integration/drone/push Build is passing Details
continuous-integration/drone/pr Build is passing Details
2021-03-10 17:13:56 +01:00
otthorn 5871e1cfb8 Add/Update password for postgres db codimd, etherpad and synapse 2021-03-10 17:13:13 +01:00
jeltz deb4372588 Merge branch 'master' into add-ssh-keys
continuous-integration/drone/push Build is failing Details
continuous-integration/drone/pr Build is failing Details
2021-03-07 21:29:57 +01:00
jeltz 2e912fc47a Add recovery SSH keys for ynerant and otthorn
continuous-integration/drone/pr Build is failing Details
continuous-integration/drone/push Build is failing Details
2021-03-07 21:23:09 +01:00
jeltz 8ae94fa8f8 Rename vault_snmp_switch{s,}_community 2021-03-06 01:08:51 +01:00
jeltz 5d319cf167 Define rsyslog_{inputs,outputs} for all hosts 2021-03-02 00:52:38 +01:00
jeltz 1fe8d1d28b Remove "Root Aurore" SSH key + add histausse key 2021-03-01 13:28:49 +01:00
jeltz c3d24c1cd0 Add SSH key for Jeltz
continuous-integration/drone/push Build is passing Details
2021-02-28 21:47:42 +01:00
ynerant ae151321db
[nginx/certbot] Clone roles from Crans
continuous-integration/drone/push Build is passing Details
continuous-integration/drone/pr Build is passing Details
Signed-off-by: Yohann D'ANELLO <ynerant@crans.org>
2021-02-24 11:46:37 +01:00
ynerant 4ecb6ed7be
Update re2o-service password
continuous-integration/drone/push Build is failing Details
continuous-integration/drone/pr Build is failing Details
Signed-off-by: ynerant <ynerant@crans.org>
2021-02-05 21:18:26 +01:00
ynerant 7e4a2d20c0
Clone nginx role from Crans
Signed-off-by: Yohann D'ANELLO <ynerant@crans.org>
2021-02-05 20:39:25 +01:00
ynerant 889cb764c1
Clone certbot role from Crans
Signed-off-by: Yohann D'ANELLO <ynerant@crans.org>
2021-02-05 20:39:25 +01:00
otthorn 217b210295 Please the yaml linter for document line start another because it breaks vault 2021-01-07 11:41:08 +01:00
otthorn e68ef218a2 Added yaml document start --- to please yaml linter 2021-01-07 11:20:53 +01:00
otthorn 15ebe0ee4b remove whitespace to please yaml linter 2021-01-07 11:19:57 +01:00
pz2891 88ffd2297f Add residence les rives
continuous-integration/drone/push Build is failing Details
2020-11-08 18:53:07 +01:00
Yohann D'ANELLO f9b7e052b9 Store reverse proxy data in proxy host vars 2020-11-04 22:38:54 +01:00
Yohann D'ANELLO c11b3bc20f Comments must start by a space 2020-11-04 20:08:51 +01:00
Yohann D'ANELLO 9505e87113 Use true instead of yes 2020-11-04 20:00:35 +01:00
chirac 4a43c0f0db Update re2o ip 2020-11-02 17:25:26 +01:00
chirac 68f7fd5b59 Isc-dhcp-server config for banni/accueil vlans 2020-10-17 19:48:34 +02:00
Yohaï-Eliel BERREBY 6dd6168d2a dhcp: upgrade role for dhcp-aurore-backup 2020-09-12 16:03:33 +02:00
Yohaï-Eliel BERREBY 9b07fc9001 dhcp: manage dhcp-aurore 2020-09-11 15:13:11 +02:00
chirac 26743b464d Add Radius-aurore.adm.auro.re to ansible managed radius servers 2020-09-09 23:17:15 +02:00
Yohaï-Eliel BERREBY 646ebd3ba9 router: ansibilize routeur-aurore{,backup} 2020-08-08 20:45:38 +02:00
Yohaï-Eliel BERREBY 3a8112bf0d roll out (private) IPv6 on George Sand 2020-08-01 17:48:39 +02:00
Yohaï-Eliel BERREBY d54da8d2b9 add ipv6_base_prefix variable 2020-08-01 14:31:49 +02:00
Yohaï-Eliel BERREBY a32116131d raise MTU at fleming
already been deployed for a while, forgot to push
2020-08-01 12:02:37 +02:00
Yohaï-Eliel BERREBY 337906c6c0 add gs dhcp, dns, routing
and add thor to inventory
2020-07-06 18:40:54 +02:00
Yohaï-Eliel BERREBY a6b15c0e10 vars: use apartment block id for subnets 2020-05-21 20:06:47 +02:00
Yohaï-Eliel BERREBY 63b4425a27 gs: fix vars 2020-05-21 19:45:35 +02:00
Yohaï-Eliel BERREBY 99070ed5ef radius: step 2 of deployment (WIP) 2020-05-21 18:06:37 +02:00
Yohaï-Eliel BERREBY e2fa1964af radius: change proxy.conf password, use vault
and also actually template it... it wasn't being
uploaded.
2020-05-21 14:19:28 +02:00
Yohaï-Eliel BERREBY 266b0dde6f radius: initial setup 2020-05-16 22:08:22 +02:00
Yohaï-Eliel BERREBY 8355546131 edc: raise DHCP-announced MTU to 1500 2020-05-14 17:50:06 +02:00
Yohaï-Eliel BERREBY 87b2e4f8cf pacaterie: raise MTU to 1500 2020-05-09 16:15:56 +02:00
Yohaï-Eliel BERREBY ba3aec348f keepalived: deploy to fleming w/ proper password 2020-05-09 16:07:04 +02:00
Alexandre Iooss a992612381
Add certbot challenge DNS-01 key 2020-05-09 13:03:31 +02:00
Pierre 3f26e7d4b4 routeur de la pacaterie en ...254 au lieu de ...240 pour keepalived 2020-05-08 18:39:05 +02:00
Yohaï-Eliel BERREBY 4372b21976 dhcp: allow different router IP suffix
This variable is only needed because we're in the process of deploying
keepalived. For now it's only at EDC.
2020-05-08 16:36:07 +02:00
Yohaï-Eliel BERREBY c77ae7f4c3 aurore-firewall: initial setup
group_vars: add apartment_block_id var
dhcp: move vars to role
2020-05-07 19:47:50 +02:00
Yohaï-Eliel BERREBY 3f5e0d0035 edc: add group vars required for dhcp deployment 2020-05-07 13:03:44 +02:00
Alexandre IOOSS 81592fa986 Merge branch 'master' into 'aurore-dev'
# Conflicts:
#   .gitignore
#   hosts
#   network.yml
#   proxmox.yml
2020-05-03 16:11:19 +02:00
Yohaï-Eliel BERREBY a77b2c4f0f unbound: fix MTU settings
That was the root cause of all our DNSSEC issues.
Now that this was fixed, we're not having these anymore,
so the relaxed checks can be restored back to their original state.
2020-05-02 18:59:22 +02:00
Yohaï-Eliel BERREBY 662452065f dhcp: remove Cloudflare from backup DNS
and rename variable, since these are not technically
upstream DNS servers
(unbound will ask the root servers, not these)
2020-04-18 17:06:38 +02:00
Yohaï-Eliel BERREBY a0651d7703 unbound: bind to the right addresses on backup hosts 2020-04-18 16:56:34 +02:00