Felix Stupp
|
d40a8cee92
|
server/nextcloud: Fixed changing configuration of nextcloud instance
- Fixes configuring APCu cache
|
4 years ago |
Felix Stupp
|
5c374bc977
|
nginx/application: Added security relevant HTTP headers to global config
Duplicates removed from server/nextcloud
|
4 years ago |
Felix Stupp
|
fc2a098ff2
|
server/nextcloud: Fixed disallowing well-known as dot file
|
4 years ago |
Felix Stupp
|
7889e10385
|
nginx/php-pool: Fixed default disabling of status_page_path
|
4 years ago |
Felix Stupp
|
788d259f85
|
all/vars: nginx_status_page_acl: Added public addresses of host
|
4 years ago |
Felix Stupp
|
8f25d008a9
|
var: nginx_status_page_acl: Fixed localhost ipv4 address range
|
4 years ago |
Felix Stupp
|
b7d34b28ee
|
nginx/php: Made name of task more descriptive
|
4 years ago |
Felix Stupp
|
9d8d041241
|
nginx/application: Fixed typo of "unnecessary"
|
4 years ago |
Felix Stupp
|
28d49be899
|
server/nextcloud: Added support for php-fpm status page
|
4 years ago |
Felix Stupp
|
458babf82c
|
nginx/php: Added support for php-fpm status page
|
4 years ago |
Felix Stupp
|
2a672cb597
|
nginx/default_server: Extracted status_page_acl var
|
4 years ago |
Felix Stupp
|
ce55e33fda
|
nginx/php-pool: Added support for enabling status page
|
4 years ago |
Felix Stupp
|
e91f9d1a81
|
nginx/default_server: Hide status page by answering 403 always
|
4 years ago |
Felix Stupp
|
74a62e861f
|
Added role nginx/default_server
To prevent circular dependencies, role must be included manually on
required servers
|
4 years ago |
Felix Stupp
|
7a33ceffb8
|
nginx/application: Removed configuring trusted certificate for OCSP
Can be derived by given certificate for host
|
4 years ago |
Felix Stupp
|
48588ee0dd
|
server/spotme: Removed not required dependencies
|
4 years ago |
Felix Stupp
|
647f112c2b
|
nginx/server: Extracted special pre directives into configurable vars
|
4 years ago |
Felix Stupp
|
11814fe236
|
nginx/server: Added explicit dependency to nginx/application
|
4 years ago |
Felix Stupp
|
61c7f72422
|
nginx/server: Removed ssl on directive
Should no longer be used, listen + ssl marker is working as expected
|
4 years ago |
Felix Stupp
|
fbca70f81f
|
dns/master: Create keys directory writeable for bind
To apply KASP later
|
4 years ago |
Felix Stupp
|
d73e250b36
|
dns/master: Changed owner and adapted permissions of zone directory
|
4 years ago |
Felix Stupp
|
22fde40ac5
|
dns/application: Changed bind9 source to official source
|
4 years ago |
Felix Stupp
|
415b107bbc
|
vscode configuration: Fixed path to python3 executable for syntax check
|
4 years ago |
Felix Stupp
|
a51225ccc8
|
dns/application: Allowed bind using AppArmor to write temporary journal files
|
4 years ago |
Felix Stupp
|
3932501d54
|
playbooks/dns: Fixed mx records for secondary domains
|
4 years ago |
Felix Stupp
|
646e6d5c75
|
dns: Configured service name using global variable
|
4 years ago |
Felix Stupp
|
77d1e84117
|
dns: Fixed variable structure of var domain_environment_directory
|
4 years ago |
Felix Stupp
|
be8418d546
|
misc/backup_files: Added variable backup_name as alternative of name by domain
|
4 years ago |
Felix Stupp
|
12e47c19c9
|
all/vars: Added var global_log_directory
Added usage in role nginx/application
|
4 years ago |
Felix Stupp
|
95db4cad65
|
nvak: Configured turnips.banananet.work
|
4 years ago |
Felix Stupp
|
51404e3a3d
|
misc/system_user: Added output var system_user_info
|
4 years ago |
Felix Stupp
|
08a37c6dab
|
nginx/application: Configure dhparams for SSL
|
4 years ago |
Felix Stupp
|
586163c9d0
|
Added role misc/dhparams
|
4 years ago |
Felix Stupp
|
69a0b5fd69
|
nvak: Added forwarding of www.banananet.work to main site
|
4 years ago |
Felix Stupp
|
ab13a1272f
|
playbooks/group_bwcloud: Configure preserve hostname for cloud-kernel
|
5 years ago |
Felix Stupp
|
6fbf62cddd
|
dns/application: Added zone.db.jnl files to allowed files for bind to write
|
5 years ago |
Felix Stupp
|
f2e669734b
|
common: Readd package acl
Required for ansible temporary files if becoming an unprivileged user, see
https://docs.ansible.com/ansible/latest/user_guide/become.html#risks-of-becoming-an-unprivileged-user
This reverts commit 3c7fb65ac9 .
|
5 years ago |
Felix Stupp
|
c258a5d1bb
|
server/minecraft: Add SRV dns entry
|
5 years ago |
Felix Stupp
|
c3f85bc8e0
|
playbooks/dns: Removed test mail dns records
can be added by specific mail roles
|
5 years ago |
Felix Stupp
|
8c0e34729a
|
playbooks/dns: Add main server addresses now using dns/server_entries
|
5 years ago |
Felix Stupp
|
55b27c041b
|
dns: Extracted role entries from server_entries
|
5 years ago |
Felix Stupp
|
39771c907f
|
dns/server_entries: Renamed var all_entries to entries
|
5 years ago |
Felix Stupp
|
f2b4540f1f
|
playbooks/dns: Removed manual configured dns entries for servers
Not required due to automatic configuration by role dns/server_entries
|
5 years ago |
Felix Stupp
|
9d23e12a16
|
dns/master: Now considered vars for nameserver and mail to be absolute
Meaning the var itself must not have a dot at the end of the name,
but an usage of the variable may need to append a dot.
|
5 years ago |
Felix Stupp
|
40c6a3ab0f
|
dns/server_entries: Allow duplicate execution of role
|
5 years ago |
Felix Stupp
|
1958c4df54
|
dns: Renamed role entries to server_entries
To distinguish between simple entries role (coming in the future) and
entries role bundled with server-related entries (A, AAAA, SSHFP)
|
5 years ago |
Felix Stupp
|
08fafbf98f
|
dns/entries: Fixed SYNC comment to role dns/master
|
5 years ago |
Felix Stupp
|
a4ec44c9e4
|
playbooks/dns: Removed non-existent ns2 from nameserver list
|
5 years ago |
Felix Stupp
|
cf2529bf05
|
playbooks/dns: Fixed typo "resposible" to "responsible"
|
5 years ago |
Felix Stupp
|
891ec640c7
|
playbooks: Changed repo urls to https if project is public
|
5 years ago |