Felix Stupp
0043d6255a
nginx/application global.conf: Added comment to excluding hidden files
5 years ago
Felix Stupp
025f77736a
dns: Changed approach for DNSSEC signing to inline-signing
...
- Moved keys into own directory
- Replaced makefile per zone by makefile for all zones
- Only combining of zone files and setting serial number
- signing now made by bind
- Added AppArmor profile extension for creating dynamic zone files
5 years ago
Felix Stupp
274f658016
nginx/php-pool: Fixed permissions for other
5 years ago
Felix Stupp
e85ad8fed3
dns: Fixed applying permissions to directories
5 years ago
Felix Stupp
c89ec27f6d
dns/master: Changed TODO for "Copy public key" to "Copy ZSK"
...
Only required and beneficial for ZSK
5 years ago
Felix Stupp
905a887b80
dns: Renamed zones_configuration_environment_ to zones_environment
5 years ago
Felix Stupp
7e2813928e
dns: Renamed variables, removed prefix dns_ on not essential variable names
5 years ago
Felix Stupp
4e6df015f5
Added roles nfs/server and nfs/export
5 years ago
Felix Stupp
24ab62d6a0
acme/application: Fixed usage of YAML multiline for "Upgrade acme.sh"
5 years ago
Felix Stupp
a03a335430
account: Added bmon to tools list
5 years ago
Felix Stupp
a576893776
misc/docker: Install docker-compose bindings for python3
5 years ago
Felix Stupp
b600f678ca
misc/docker: Install python3 docker bindings using package manager
5 years ago
Felix Stupp
6ce23c8a64
group os_debian: Force python3 interpreter to be used
5 years ago
Felix Stupp
8758553a02
common: Install explicit python3 interpreter
5 years ago
Felix Stupp
2dcfd1b09e
nginx: Added full paths to includes of snippets / fastcgi_params
...
To allow Ansible to validate the main config if placed on different
locations
5 years ago
Felix Stupp
ff7275cb60
server/{linx,spotme}: Removed default bind_port
5 years ago
Felix Stupp
4a186854cf
server/node: Renamed variable app_port to bind_port
5 years ago
Felix Stupp
f6c1aff55a
server/spotme: Renamed variable spotme_port to bind_port
5 years ago
Felix Stupp
7e0df4abc5
Added variable local_user for user running playbook
...
Useful if tasks store data on the local machine
5 years ago
Felix Stupp
192a9c8b86
cloud.banananet.work: Removed preconfiguring admin password
5 years ago
Felix Stupp
9d50f84321
server/firefox-sync: Changed remote repo url back to official repo
5 years ago
Felix Stupp
90bf46bde6
global vars: Added var for username "zocker"
5 years ago
Felix Stupp
373f59e7a4
misc/blocklist/ipv4: Expanded by new ips
5 years ago
Felix Stupp
b74029ec7b
site: Added fail2ban/application as default role for all hosts
5 years ago
Felix Stupp
f91f2bc325
Added role fail2ban/application
5 years ago
Felix Stupp
c110a24e9f
common: sshd: Disable weak key algorithms
5 years ago
Felix Stupp
505c85eb11
common: Disable root login over ssh
5 years ago
Felix Stupp
651794a136
common: sshd: Disable X11 Forwarding globally
5 years ago
Felix Stupp
baace3ce16
misc/handlers: Changed "restart ssh" to "reload ssh"
5 years ago
Felix Stupp
025d8a3256
Added role misc/ssh_tg_notify
...
- Added role to common site
- Added variables required to global vars and vault
5 years ago
Felix Stupp
69b884ad3f
bootstrap: Configure ssh key used to connect on new user
5 years ago
Felix Stupp
f610812fc7
bootstrap: Ensure user has .ssh/authorized_keys before trying to copy
5 years ago
Felix Stupp
096554f37b
mqtt/user: Fixed usage of var user (before username)
5 years ago
Felix Stupp
fe393bd246
mqtt/application: Enforce sort part files before combining for acl and auth
5 years ago
Felix Stupp
1a608ce172
mqtt/application: Remove config use_username_as_clientid
...
Seems to block users with different username and clientid
5 years ago
Felix Stupp
e18f7f32e0
mqtt/application: Add paths for acl and auth files to config
5 years ago
Felix Stupp
46e932049e
mqtt/application: Allow root to read SYS topics
5 years ago
Felix Stupp
b6de0c1a4d
mqtt/application: Fix usage of variable configuration_directory
5 years ago
Felix Stupp
cf632d1a56
mqtt: Ensure create auth files before writing using mosquitto_passwd
...
Fixes error on calling tool if file does not exist
5 years ago
Felix Stupp
4b6cef5c10
mqtt/application: Notify handlers on change to makefile
5 years ago
Felix Stupp
82c7666ae8
mqtt/application: Fix port for mosquitto server
5 years ago
Felix Stupp
81dab362a6
misc/docker: Do not install recommended packages to fix issue on raspberry
5 years ago
Felix Stupp
35b790978f
playbooks/dns: Changed minecraft wg addresses to Nitrado Game Server
5 years ago
Felix Stupp
b052d1f18c
ansible.cfg: Changed type of python detection
...
To prevent further warnings cause of coming, may breaking changes
5 years ago
Felix Stupp
d455d62dbf
Added script for appending ips to blocklist
5 years ago
Felix Stupp
81364e9bfe
Extracted blocklist to own file and added ips
5 years ago
Felix Stupp
8b340912b1
Added known ips to blocklist
5 years ago
Felix Stupp
fcae6e8429
Added blocklist of known malicious ip addresses applied by role common
5 years ago
Felix Stupp
f2c9b17194
Moved packages only required for admin account from role common to role account
5 years ago
Felix Stupp
25df92ee7b
common: Removed package buffer
...
Replaced by pv integrated buffering
which supports greater limits.
5 years ago