Jérémy Lecour
ce0d61bcbd
certbot: detect HAProxy cert directory
2020-06-14 12:37:04 +02:00
Jérémy Lecour
a8887aaa8e
update changelog
2020-06-09 11:45:19 +02:00
Jérémy Lecour
4c71ea2012
haproxy: enable stats frontend with access lists
2020-06-09 11:41:33 +02:00
Patrick Marchand
c9daa8ba35
evobackup-client: Fix ssh connection test in zzz_evobackup.sh
...
When I made the ssh key name a variable and defaulted it to id_ed25519,
I forgot to change the hardcoded value for the ssh test in
evobackup-client/templates/zzz_evobackup.default.sh.j2
2020-06-08 17:22:18 -04:00
Jérémy Lecour
1ade990526
mongodb: fix logrotate patterm on Debian buster
2020-06-05 11:02:54 +02:00
Jérémy Lecour
7f0931510f
evoacme: upstream release 20.06.1
2020-06-05 11:01:42 +02:00
Ludovic Poujol
ebffccae59
lxc-php: Do --no-install-recommends for ssmtp/opensmtpd
2020-06-05 11:01:22 +02:00
Ludovic Poujol
186f3d90b9
lxc-php: Install opensmtpd as intended
2020-06-05 10:57:49 +02:00
Ludovic Poujol
0dfb92360f
php: Don't disable putenv() by default in PHP settings
2020-06-04 11:52:04 +02:00
Ludovic Poujol
90704dc712
lxc-php: Don't disable putenv() by default in PHP settings
2020-06-04 11:51:25 +02:00
Ludovic Poujol
ead0b7fd88
lxc-php: Install php-sqlite by default
2020-06-04 11:42:17 +02:00
Ludovic Poujol
8c883c44dd
php: Install php-sqlite by default
2020-06-04 11:39:51 +02:00
Ludovic Poujol
c7d456471b
packweb-apache: Install zip & unzip by default
2020-06-04 11:34:26 +02:00
Jérémy Lecour
3bd0a4ffb3
certbot: restore compatibility with old Nginx
2020-06-04 11:22:58 +02:00
Jérémy Lecour
9aed38b637
certbot: install certbot dependencies non-interactively for jessie
2020-06-04 11:22:58 +02:00
Jérémy Lecour
1d5a30b144
evoacme: upstream release 20.06
2020-06-03 12:09:58 +02:00
Patrick Marchand
c8cd119a18
Merge pull request 'Make it possible to setup mysql replication' ( #102 ) from mysql_replication into unstable
2020-06-02 17:31:13 +02:00
Jérémy Lecour
4cf438c8ff
redis: raise an error is port 6379 is used in "instance" mode
2020-06-02 11:22:56 +02:00
Jérémy Lecour
8a87fecbe4
redis: new syntax for match filter
2020-06-02 11:00:06 +02:00
Jérémy Lecour
47d11308ba
redis: create sudoers file if missing
2020-06-02 10:59:51 +02:00
Jérémy Lecour
86cab2ab94
haproxy: chroot and socket path are configurable
2020-06-02 10:58:10 +02:00
Patrick Marchand
8c1e40c1a9
Add option to make a mysql install read only
...
Rebased on unstable
2020-06-01 12:03:23 -04:00
Ludovic Poujol
09371b095f
packweb-apache: Don't turn on mod-evasive emails by default
2020-05-18 12:03:34 +02:00
Jérémy Lecour
4016387ca8
Release 10.0.0
2020-05-13 11:20:45 +02:00
Jérémy Lecour
ac7ee86a9c
minifirewall: /bin/true command doesn't report "changed" anymore
2020-05-11 15:23:52 +02:00
Jérémy Lecour
849ec405d5
evocheck: upstream version 20.04.4
2020-04-28 16:00:45 +02:00
Jérémy Lecour
57e5791728
networkd-to-ifconfig: add variables for configuration by variables
2020-04-26 18:39:25 +02:00
Jérémy Lecour
2f77100b47
evocheck: upstream version 20.04.3
2020-04-26 10:54:49 +02:00
Jérémy Lecour
d013a65cf6
Merge branch 'unstable' into lpoujol/better-multiphp
2020-04-17 12:23:56 +02:00
Jérémy Lecour
6764418e75
evocheck: upstream release 20.04.2
2020-04-15 18:01:55 +02:00
Jérémy Lecour
257a3476f1
evocheck: upstream release 20.04.1
2020-04-12 22:30:07 +02:00
Jérémy Lecour
f2613e91aa
evolinux-base: configure cciss-vol-statusd in the proper file
...
The default file should be used for configuration instead of the init
script.
2020-04-10 11:36:03 +02:00
Ludovic Poujol
93c043c8e0
(fix) lxc: Fix container existance check to be able to run in check_mode
2020-04-08 17:57:46 +02:00
Ludovic Poujol
bd63e7037f
packweb-apache: Do the install & conffigure phpContainer script (instead of evoadmin-web role)
2020-04-08 17:54:43 +02:00
Ludovic Poujol
f135f67cd0
(change) php: Cleanup CLI Settings. Also, allow url fopen and don't disable functions (in CLI only)
...
Closes #98
2020-04-01 18:22:46 +02:00
Ludovic Poujol
7fc260a17b
(fix) php: update surry_post.yml to match current latest PHP release
2020-04-01 18:08:57 +02:00
Ludovic Poujol
f442239cec
(fix) packweb-apache: Don't try to install PHPMyAdmin on Buster as it's not available
2020-04-01 18:05:20 +02:00
Ludovic Poujol
135a089341
(change) lxc-php: Use OpenSMTPD for Stretch/Buster containers, and ssmtp for Jessie containers
2020-04-01 17:23:39 +02:00
Ludovic Poujol
a21fcaf663
(fix) php: Chose the debian version repo archive for packages.sury.org
2020-04-01 17:23:39 +02:00
Ludovic Poujol
a680399608
packweb-apache: Add missing dependency to evoacme role
2020-04-01 17:23:39 +02:00
Ludovic Poujol
9b80db3772
lxc: Don't stop the container if it already exists
2020-04-01 17:17:00 +02:00
Jérémy Lecour
5b5b8944c5
java: add Java 11 as possible version to install
2020-03-21 19:07:26 +01:00
Patrick Marchand
d5731f90e0
Merge branch 'bind9_evocheck_fix' into unstable
2020-03-10 13:48:52 -04:00
Jérémy Lecour
ac98aa2d18
evolinux-base: install Evocheck (default: True
)
2020-03-09 17:02:23 +01:00
Jérémy Lecour
92dcbf1ab5
rbenv: change default Ruby version to 2.7.0
2020-03-09 17:02:23 +01:00
Jérémy Lecour
ac6414076c
nodejs: change default version to 12 (new LTS)
2020-03-09 17:02:23 +01:00
Jérémy Lecour
ec54af596c
evolinux-base: Don't customize the logcheck recipient by default.
...
By default the package sends its messages to the logcheck user.
By default we alias the "logcheck" user to "root" which is redirected to
our custom address.
2020-03-04 14:03:18 +01:00
Jérémy Lecour
783dcb9890
evomaintenance: upstream release 0.6.3
2020-03-02 22:12:58 +01:00
Jérémy Lecour
68a1d4eb27
update changelog
2020-03-02 20:53:54 +01:00
Jérémy Lecour
af53a6b2ec
evomaintenance: upstream release 0.6.2
2020-03-02 14:45:41 +01:00
Jérémy Lecour
eb74bda22a
nagios-nrpe: check_mode per cpu dynamically
2020-02-28 12:14:20 +01:00
Jérémy Lecour
1b29f2d793
update listupgrade from upstream
2020-02-27 13:41:04 +01:00
Jérémy Lecour
d31dddc9aa
evocheck: upstream verison 20.02.1
2020-02-27 11:37:01 +01:00
Jérémy Lecour
65bc2c657d
certbot: commit hook must be executed at the end
2020-02-25 10:46:21 +01:00
Jérémy Lecour
7283e34077
Replace version_compare() with version()
2020-02-25 10:45:35 +01:00
Jérémy Lecour
ff7f8669ef
evomaintenance: install PG dependencies only when needed
2020-02-25 10:43:23 +01:00
Ludovic Poujol
704b76e6de
minifirewall: Properly detect alert5.sh to turn on firewall at boot
2020-02-17 16:02:48 +01:00
Ludovic Poujol
02e8754d75
minifirewall: Backport changes from minifirewall (properly open outgoing smtp(s))
2020-02-17 10:56:38 +01:00
Jérémy Lecour
f57af13349
minifirewall: better alert5 activation
2020-02-10 10:36:00 +01:00
Jérémy Lecour
68b7a88e63
apt: added buster backports prerferences
2020-02-10 10:35:18 +01:00
Patrick Marchand
896b8bd7e4
Merge branch 'evobackup-client' into unstable
...
Import evobackup client code into mainline.
2020-02-06 16:29:02 -05:00
Jérémy Lecour
72f5dc70f8
apt: hold packages only if package is installed
2020-02-04 18:14:57 +01:00
Jérémy Lecour
dc7358bc4c
nagios-nrpe: change default haproxy socket path
2020-01-23 15:04:25 +01:00
Jérémy Lecour
02858692bb
evomaintenance: don't configure firewall for database if not necessary
2020-01-23 14:34:03 +01:00
Jérémy Lecour
71a2a19847
apache: the default VHost doesn't redirect to https for ".well-known" paths
2020-01-23 14:34:03 +01:00
Ludovic Poujol
31df2d2fbc
php: Add a task to remove Debian's default FPM pool file (off by default)
...
Can be triggered by switching php_fpm_remove_default_pool to True.
2020-01-16 15:55:35 +01:00
Ludovic Poujol
ef5ed6911e
php: Change the default pool names to something more explicit (and same for the variables names)
...
Because it's more than just pure configuration, but a fpm pool
definition, I've changed the following variables in Ansible :
- php_fpm_defaults_conf_file to replaced by php_fpm_default_pool_file
- php_fpm_custom_conf_file to php_fpm_default_pool_custom_file.
On the FPM side, I've also changed the files names of the pool to make
them more explicit. No more z and zzz. It's the www pool, so let's put
www in the file name for coherence :
- z-evolinux-defaults.conf changes to www-evolinux-defaults.conf
- zzz-evolinux-custom.conf changes to www-evolinux-zcustom.conf
2020-01-16 15:55:25 +01:00
Ludovic Poujol
c9d3635cf8
php: Make sure the default pool we define can be fully functionnal witout debian's default pool file
2020-01-16 15:55:17 +01:00
Jérémy Lecour
80081aa26e
evolinux-base: remove the chrony package
2020-01-16 10:57:47 +01:00
Jérémy Lecour
e7952dc3c8
etc-git: fix warnings ansible-lint
2020-01-08 17:19:36 +01:00
Jérémy Lecour
bf7de332ea
minifirewall: fix warnings ansible-lint
2020-01-08 17:19:13 +01:00
Jérémy Lecour
f79b30eeb4
update changelog
2020-01-03 16:40:53 +01:00
Jérémy Lecour
3b258cc43e
tomcat: package version derived from Debian version if missing
2019-12-31 16:43:51 +01:00
Patrick Marchand
20191c8873
Fixed regression introduced by commit 276177900b
...
The default behavior for ansible template is to overwrite the
targeted file. Since we dont always want to overwrite a file when
we play this role, we set `force` to `False` by default. This means
that if the `dest` already exists, ansible will not overwrite it
with it's given template.
This is fine for most of the tasks in this role, but in the case
of `{{ evoadmin_scripts_dir }}/web-mail.tpl`,the file is created
by a task that runs prior to the template task, so setting it to
`False` by default means it never gets updated and clients dont get
notified when they create new websites.
2019-12-24 14:10:24 -05:00
Victor LABORIE
2a1e0b7ef6
evolinux-base: install ssacli for HP Smart Array
2019-12-13 11:00:20 +01:00
Jérémy Lecour
e557a3eaae
apache: improve permissions in save_apache_status script
2019-12-13 10:44:44 +01:00
Ludovic Poujol
6e918d166e
evolinux-base: Don't make alert5.service executable
...
Every 3 mins, systemd complain that the service file is marked as
executable, and asks the executable bit to be remove.
Nov 27 01:35:11 foo systemd[1]: Configuration file /etc/systemd/system/alert5.service is marked executable. Please remove executable permission bits. Proceeding anyway.
2019-11-28 10:59:29 +01:00
Ludovic Poujol
0e58f34e18
certbot: Properly evaluate when apache is installed
...
Checking the existence of /etc/apache2 is not enough as a condition to
validate the presence of apache.
Indeed, some packages (including certbot!!!), put some files in
/etc/apache2/conf-available even if apache isn't installed.
In those cases, the check is not correct, and we'll enter in the apache
block, and fail when we try to enable the configuration.
With this commit, we now validate the presence apache with the presence
of /usr/sbin/apachectl
2019-11-26 11:58:52 +01:00
Ludovic Poujol
dc1c78e08a
evolinux-base: Fix our zsyslog rotate config that doesn't work on Debian 10
...
I've noticed that some log files, especially /var/log/syslog were empty.
After investigating, I've realized that it was happening after a log
rotation by logrotate.
The old mechanism, `invoke-rc.d rsyslog rotate` isn't working anymore on
Debian 10. It will fail with a not so explicit message :
[FAIL] Closing open files: rsyslogd failed!
Long story short, it seems that the pid file (`/run/rsyslogd.pid`) isn't
created any more, so start-stop-daemon as used by /etc/init.d/rsyslog
will fail. Explaining the error message.
Debian 10 rsyslog now brings `/usr/lib/rsyslog/rsyslog-rotate` that is
used by logrotate. It will send the signal HUP the 'right' way, so
rsyslog will be aware of the log rotation.
Sadly, this script isn't present in Debian 9 nor 8, so the logrotate
configuration for rsyslog is now a template, using the right command for
the right version.
2019-11-22 16:48:19 +01:00
Jérémy Lecour
473bcb4cd6
apt: verify that /etc/evolinux is present
2019-11-20 11:34:47 +01:00
Jérémy Lecour
26dd244ae0
nagios-nrpe: update check_redis_instances
2019-11-13 09:47:23 +01:00
Jérémy Lecour
7f6ad406a5
evocheck: upstream version 19.11.2
2019-11-07 10:38:32 +01:00
Jérémy Lecour
767760cbe0
evocheck: upstream version 19.11.1
2019-11-06 07:50:45 +01:00
Jérémy Lecour
049d36ab8f
etc-git: add versioning for /usr/share/scripts on Debian 10+
...
The repository.yml task file is generic and can be called for vrious
repositories.
On Debian 10, /usr/share/scripts is versioned
2019-11-05 17:00:22 +01:00
Jérémy Lecour
6b77372f24
evocheck: upstream version 19.11
2019-11-05 16:20:07 +01:00
Jérémy Lecour
a55e29186f
evomaintenance: upstream version 0.6.0
2019-11-05 14:52:59 +01:00
Jérémy Lecour
ab8c6b13b8
evoacme: upstream version 19.11
2019-11-05 14:08:02 +01:00
Jérémy Lecour
7e50a460a8
minifirewall: add a variable to force the check scripts update
2019-11-05 10:52:14 +01:00
Jérémy Lecour
5476538eb1
minifirewall: no http filtering by default
2019-10-30 14:37:22 +01:00
Jérémy Lecour
f2dacac139
evolinux-base: add /usr/share/scripts in root's PATH (Debian 10+)
2019-10-30 14:32:32 +01:00
Jérémy Lecour
8679da4cb6
evolinux-base: install /sbin/deny
2019-10-30 14:32:32 +01:00
Jérémy Lecour
772c333623
apt: remove jessie/buster sources from Gandi servers
2019-10-30 14:32:32 +01:00
Jérémy Lecour
e80e4197c2
evocheck: upstream version 19.10
2019-10-25 13:17:16 +02:00
Jérémy Lecour
d5a6487315
Merge branch 'mongodb-buster' into unstable
2019-10-24 17:23:53 +02:00
Jérémy Lecour
27adad616f
squid: compatibility wit Debian 10
2019-10-24 16:23:48 +02:00
Jérémy Lecour
85b0e36f33
CHANGELOG: sort alphabetically
2019-10-24 15:37:58 +02:00
Jérémy Lecour
76864f226e
WIP mongodb: compatibility with Debian 10
2019-10-24 15:36:51 +02:00
Jérémy Lecour
ee72dd07ff
rbenv: install Ruby 2.6.5 by default
2019-10-22 15:03:45 +02:00
Jérémy Lecour
2ea88dc385
mysql-oracle: backport tasks from mysql role
2019-10-21 16:32:59 +02:00
Jérémy Lecour
12cebfa71c
lxc-php: refactor tasks for better maintainability
2019-10-21 15:26:03 +02:00
Ludovic Poujol
2d2889ac16
php: Don't set a chroot for the default fpm pool
2019-10-16 15:59:33 +02:00
Ludovic Poujol
0a7262081a
php: add missing handler for php7.3-fpm
2019-10-16 15:17:35 +02:00
Jérémy Lecour
edb5ace762
haproxy: add a variable to keep the existing configuration
2019-10-10 11:27:39 +02:00
Patrick Marchand
c6804e73e7
Adapted the bind role to respect the evocheck warnings
...
The required munin plugins and the logging necessary for them to work is
now activated depending on the type of resolver and the logrotate file is
changed from bind to bind9.
2019-10-09 11:54:30 -04:00
Ludovic Poujol
4aaeb4590b
lxc: rely on lxc_container module instead of command module
2019-10-02 16:32:20 +02:00
Ludovic Poujol
e985f5778c
evoadmin-web: Put the php config at the right place for Buster
2019-10-02 15:48:03 +02:00
Ludovic Poujol
a5378c783e
lxc: update our default template to be compatible with Debian 10
2019-10-01 17:54:13 +02:00
Ludovic Poujol
ae97276e13
lxc: remove useless loop in apt execution
2019-10-01 17:54:13 +02:00
Jérémy Lecour
a478c773eb
apt: check if cron is installed before adding a cron job
2019-09-30 14:12:38 +02:00
Jérémy Lecour
394e28b815
WIP: new certbot role
2019-09-27 00:21:29 +02:00
Jérémy Lecour
e3e908dd4c
Merge branch 'redis-instances' into unstable
2019-09-25 22:25:42 +02:00
Gregory Colpart
6fe86a76c5
remove reload-vcl.sh (Custom Varnish ExecReload script) when Debian >= 10
2019-09-24 14:00:22 +02:00
Jérémy Lecour
f09a405d84
mongodb: still incompatible with Debian 10
2019-09-23 22:18:52 +02:00
Jérémy Lecour
bea11352be
Merge branch 'buster' into unstable
2019-09-23 18:34:35 +02:00
Jérémy Lecour
45d48eedb0
changelog cleanup
2019-09-23 13:47:19 +02:00
Jérémy Lecour
3999e7d4f8
listupgrade: install old-kernel-autoremoval script
2019-09-23 13:46:29 +02:00
Jérémy Lecour
0829efc8a6
evocheck: upstream version 19.09
2019-09-23 09:22:58 +02:00
Jérémy Lecour
9f619adf68
evocheck: cron jobs execute in verbose
2019-09-23 09:22:40 +02:00
Jérémy Lecour
1a647d0546
evocheck : update (version 19.09) from upstream
2019-09-22 22:41:03 +02:00
Jérémy Lecour
b31159c9d2
evolinux-base: use "evolinux_internal_group" for SSH authentication
2019-09-22 22:26:21 +02:00
Jérémy Lecour
8f868b8612
evolinux-base: default value for "evolinux_ssh_group"
2019-09-22 22:25:30 +02:00
Jérémy Lecour
2d249f1815
squid: split systemd tasks into own file
2019-09-22 22:18:09 +02:00
Patrick Marchand
a358db065b
Merge branch 'htpasswd_evoadmin' into unstable
2019-09-20 10:06:20 -04:00
Patrick Marchand
0009272462
Allow setting a custom mysql server_id
2019-09-12 11:46:12 -04:00
Patrick Marchand
109191ccd8
Added mysql_log_bin variable to enable binary logs
2019-09-12 08:54:18 -04:00
Jérémy Lecour
442353ce73
Update changelog
2019-09-06 16:04:47 +02:00
Jérémy Lecour
4acd61a072
generate-ldif: support MariaDB 10.3
2019-09-02 10:39:49 +02:00
Patrick Marchand
1c12827c9c
Added evobackup-client role
2019-08-30 14:43:52 -04:00
Patrick Marchand
d75846ed28
Make it possible to add an htpasswd file to evoadmin
2019-08-30 10:32:44 -04:00
Jérémy Lecour
5925a12b3d
evocheck: upstream version 19.08
2019-08-30 14:23:35 +02:00
Jérémy Lecour
6db519c2b0
redis: max clients is configurable
2019-08-30 08:53:12 +02:00
Jérémy Lecour
2c2f13e17f
update CHANGELOG
2019-08-30 08:52:08 +02:00
Patrick Marchand
276177900b
Merge branch 'evoadmin-web-template-override' into unstable
...
I had to apply some of the yamllint fixes to the new multi-php tasks
as well. Notably it removes the need to explicitely check for the
truthy "True"
2019-08-27 10:23:04 -04:00
Ludovic Poujol
8d71965ec9
nginx: fix munin fcgi not working (missing chmod 660 on logs)
2019-08-22 14:47:32 +02:00
Ludovic Poujol
e2fd56bdcd
php: By default, allow 128M for OpCache (instead of 64M)
2019-08-21 15:56:35 +02:00
Jérémy Lecour
f5f4a82114
evomaintenance: upstream version 0.5.1
2019-08-21 15:40:15 +02:00
Ludovic Poujol
b116c47b58
packweb-apache: Deploy opcache.php to give some insights on PHP's opcache status
2019-08-21 15:24:58 +02:00
Jérémy Lecour
c0ed2fa620
php: variable to install the mysqlnd module instead of the default mysql module
2019-08-16 10:11:23 +02:00
Ludovic Poujol
6d2db1341f
evomaintenance: Turn on API by default (instead of DB)
2019-08-07 15:42:23 +02:00
Ludovic Poujol
b7844dd804
squid: Remove wait time when we turn off squid
2019-08-06 10:26:47 +02:00
Ludovic Poujol
f630d93587
evolinux-base: On debian 10 and later, add noexec on /dev/shm
2019-07-23 18:18:29 +02:00
Victor LABORIE
cb8116fff0
tomcat: fix typo for default tomcat_version
2019-07-12 15:29:05 +02:00
Victor LABORIE
031c4c29b9
roundcube: fix typo for roundcube vhost
2019-07-08 15:35:05 +02:00
Jérémy Lecour
11a039bfac
elasticsearch: listen on local interface only by default
2019-07-01 17:17:32 +02:00
Ludovic Poujol
e13543bf07
lxc-php: Don't remove the default pool - That's making PHP-FPM sad :(
2019-06-26 11:10:23 +02:00
Jérémy Lecour
16bdd6893d
Release 9.10.1
2019-06-21 14:36:20 +02:00
Jérémy Lecour
a5ee2771ca
evocheck : update (version 19.06) from upstream
2019-06-21 14:35:59 +02:00
Jérémy Lecour
39d0167408
Release 9.10.0
2019-06-21 10:46:08 +02:00
Jérémy Lecour
bb0189e5a4
rbenv: install Ruby 2.6.3 by default
2019-06-21 10:43:20 +02:00
Jérémy Lecour
8420791224
fluentd: store gpg key locally
2019-06-21 10:29:18 +02:00
Jérémy Lecour
ce12e32375
evocheck : update from upstream
2019-06-21 09:42:02 +02:00
Jérémy Lecour
49d90fff09
apache: add a variable to customize the server-status host
2019-06-20 17:29:48 +02:00
Jérémy Lecour
a8ef97fcde
Revert "evolinux-base: install "spectre-meltdown-checker" (Debian 9 and later)"
...
This reverts commit 65414d8ae7
.
2019-06-20 17:29:48 +02:00
Jérémy Lecour
8cb604aa93
etc-git: gitignore /etc/letsencrypt/.certbot.lock
2019-06-17 15:02:17 +02:00
Ludovic Poujol
7b9cc7c2b1
apt: Add Debian Buster repositories
2019-06-17 14:24:09 +02:00
Jérémy Lecour
65414d8ae7
evolinux-base: install "spectre-meltdown-checker" (Debian 9 and later)
2019-06-17 14:22:00 +02:00
Jérémy Lecour
a643c96cca
evomaintenance: make hooks configurable
2019-06-17 14:17:30 +02:00
Ludovic Poujol
8413fa137c
nagios-nrpe: Replace the dummy packages nagios-plugins-* with monitoring-plugins-*
2019-06-17 10:25:46 +02:00
Ludovic Poujol
890055753e
evolinux-users: Validate sshd config with "-t" instead of "-T"
...
See #52
2019-06-17 10:23:56 +02:00
Ludovic Poujol
75a8c90258
evolinux-base: Ensure rename is present
2019-06-17 09:58:10 +02:00
Ludovic Poujol
20a4c082d7
php: Stop enforcing /var/www/html as chroot while we use /var/www.....
2019-06-06 13:45:53 +02:00
Victor LABORIE
e2ae37fa3d
nagios-nrpe: check_load is now based on ansible_processor_vcpus
2019-06-05 11:09:52 +02:00
Victor LABORIE
08ae9d73c4
redmine: fix 500 error on logging
2019-05-29 11:49:10 +02:00
Victor LABORIE
490708c76d
redmine: use custom errors-pages in Nginx vhost
2019-05-22 12:07:51 +02:00
Victor LABORIE
360150d57b
nagios-nrpe: fix redis_instances check when Redis port equal 0
2019-05-20 14:28:52 +02:00
Victor LABORIE
6c1991196a
nagios-nrpe: change required status code for http and https check
2019-05-14 14:29:50 +02:00
Jérémy Lecour
7cc1777cf5
apt: add a script to manage packages with "hold" mark
2019-05-13 17:48:55 +02:00
Victor LABORIE
e40aefb4e0
redmine: enable gzip compression in nginx vhost
2019-05-13 12:06:22 +02:00
Victor LABORIE
0dd7b26ade
redmine: update default version to 4.0.3
2019-05-13 11:21:32 +02:00
Victor LABORIE
c2ed7faeb7
rbenv: update defaults rbenv version to 1.1.2 and ruby version to 2.5.5
2019-05-13 11:21:32 +02:00
Victor LABORIE
4a703978a8
rbenv: add check_mode for versions checking
2019-05-13 11:21:32 +02:00
Patrick Marchand
d8385bff84
Make it possible to overwrite the default evoadmin-web templates
...
The templates can also be forced to update if so desired.
2019-05-06 22:00:45 +02:00
Jérémy Lecour
4394d795e0
update changelog
2019-04-26 11:09:36 +02:00
Jérémy Lecour
b6499671fa
apache/nginx: add server status suffix in default site if missing
2019-04-26 11:02:02 +02:00
Jérémy Lecour
8e618ce70a
apache/nginx: add server status suffix in VHost if missing
2019-04-25 17:12:19 +02:00
Jérémy Lecour
afea232858
evocheck : version 19.04 from upstream
2019-04-25 13:34:28 +02:00
Jérémy Lecour
daae099aef
Release 9.9.0
2019-04-16 16:41:28 +02:00
Jérémy Lecour
69e45dab84
update CHANGELOG for lxc changes
2019-04-16 16:36:27 +02:00
Jérémy Lecour
c61e40bdf8
clean CHANGELOG
2019-04-16 16:27:10 +02:00
Jérémy Lecour
7bb15e7b70
evocheck : add "x-frame-options: sameorigin" for Munin
2019-04-16 10:47:26 +02:00
Jérémy Lecour
6b52f89ad3
evocheck : update script from upstream
2019-04-16 10:46:44 +02:00
Ludovic Poujol
48226ff7b6
apt: Ensure jessie-backport from archives.debian.org is accepted
2019-04-08 16:11:10 +02:00
Ludovic Poujol
b185012469
apt: Remove jessie-update suite as it's no longer exists
2019-04-08 15:40:03 +02:00
Eric Morino
48becaecf4
Replace mirror.evolix.org by archives.debian.org for jessie-backport
2019-04-03 15:08:06 +02:00
Eric Morino
36515c9c89
aligning roles with our conventions, major changes in opendkim-add.sh
2019-03-27 11:01:11 +01:00
Jérémy Lecour
66381ae454
evomaintenance: embed version 0.5.0
2019-03-26 15:06:20 +01:00
Jérémy Lecour
de0a4c2ca8
update README
2019-03-21 15:38:36 +01:00
Ludovic Poujol
6e36b54adb
webapps/evoadmin-web: add dbadmin.sh to sudoers file
2019-03-18 11:50:46 +01:00
Jérémy Lecour
f3b54188d3
redis: higher limit of open files
2019-03-08 13:44:12 +01:00
Jérémy Lecour
02723ba0f3
redis: set variables on nclusion, not with set_facts
2019-03-08 13:44:12 +01:00
Victor LABORIE
aebd46e4d7
tomcat-instance: deploy correct version of config files
2019-03-06 15:52:56 +01:00
Jérémy Lecour
3e37800994
evolinux-base: remove apt-listchanges on Stretch and later
2019-03-05 11:10:12 +01:00
Jérémy Lecour
70f5504382
etc-git: ignore evobackup/.keep-* files
2019-02-22 10:25:27 +01:00
Victor LABORIE
346e556049
tomcat-instance: deploy correct version of server.xml
2019-02-20 11:29:11 +01:00
Victor LABORIE
49dc437880
tomcat: better tomcat version management
2019-02-20 11:28:59 +01:00
Victor LABORIE
c1d727bb5d
spamassasin: fix sa-update.sh and ensure service is started and enabled
2019-01-31 14:37:41 +01:00
Jérémy Lecour
c296dd94c2
Release 9.8.0
2019-01-31 10:22:50 +01:00
Jérémy Lecour
eb0879f3c2
New "percona" role to install Percona repositories and tools
2019-01-31 10:22:13 +01:00
Jérémy Lecour
c8e7675a49
metricbeat: disable cloud_metadata processor by default
2019-01-31 10:15:02 +01:00
Jérémy Lecour
ff275efd95
filebeat: disable cloud_metadata processor by default
2019-01-31 10:14:13 +01:00
Victor LABORIE
0794e6f620
redmine: refactoring of redmine role with use of rbenv
2019-01-28 14:29:01 +01:00
Victor LABORIE
fabac07210
redis: add variable for configure unixsocketperm
2019-01-28 14:26:13 +01:00
Victor LABORIE
2c874afb3c
proftpd: add FTPS and SFTP support
2019-01-24 11:47:03 +01:00
Ludovic Poujol
af896fe1fc
* ntpd: Update the restrictions to follow wiki.evolix.org/HowtoNTP client config
...
- Ensure the client won't respond to anybody but accept the timeserver
answers
- Should work on both Jessie and Stretch
2019-01-18 15:32:45 +01:00
Jérémy Lecour
87860d5b7f
Release 9.7.0
2019-01-17 18:11:46 +01:00
Jérémy Lecour
fc0b1d6968
update changelog
2019-01-17 17:42:18 +01:00
Patrick Marchand
59c479582e
Adds ips tag to fail2ban/tasks/ip_whitelist.yml
...
You can already skip nginx and apache ip_whitelist tasks with this
tags, it makes sense for fail2ban to follow suite.
2019-01-10 17:03:14 -05:00
Ludovic Poujol
40b2654141
php: added php-zip in the installed package list for debian 9 (and later)
2019-01-10 19:12:53 +01:00
Ludovic Poujol
c4c091b362
squid: added packagist.org in the whitelist
2019-01-10 18:12:03 +01:00
Victor LABORIE
f6ca2279bf
java: update Oracle java package to 8u192
2019-01-10 16:16:35 +01:00
Jérémy Lecour
df308b0396
fail2ban: fix "ignoreip" update
2019-01-09 16:44:16 +01:00
Ludovic Poujol
67d7458ba6
nodejs: Update yarn repo GPG key (current key expired)
...
Ref: https://github.com/yarnpkg/yarn/issues/6865
2019-01-09 10:49:20 +01:00
Jérémy Lecour
7c2feea561
metricbeat: add a variable for the protocol to use with Elasticsearch
2019-01-08 11:05:27 +01:00
Victor LABORIE
719e9b35b2
evocheck: update evocheck.sh for source install
2019-01-08 10:25:10 +01:00
Jérémy Lecour
921c92fd5b
redis: add a variable for renamed/disabled commands
2019-01-08 10:04:27 +01:00
Jérémy Lecour
ebd65b2395
metricbeat: fix username/password replacement
2019-01-08 10:02:04 +01:00
Jérémy Lecour
1118486993
rbenv: add pkg-config to the list of packages to install
...
Some Ruby gems (Nokogiri…) need this to detect system libraries.
2019-01-03 10:16:46 +01:00
Jérémy Lecour
41c1ed5a70
apache: add Munin configuration for Apache server-status URL
2019-01-01 21:08:51 +01:00
Jérémy Lecour
92a25a9502
redis: add variables to prevent or force restart
2018-12-21 11:11:15 +01:00
Jérémy Lecour
3b63172532
redis: distinction between main and master password
2018-12-21 11:08:18 +01:00
Ludovic Poujol
effdb4c7eb
redis: Configure munin when working in instance mode
2018-12-17 14:47:07 +01:00
Ludovic Poujol
fa49f249e7
redis: Don't set the owner of /var/{lib,log}/redis to a redis instance account
2018-12-17 14:43:42 +01:00
Ludovic Poujol
f46f5ccbde
nagios-nrpe: check_process now return the error code (making the check more usefull than /bin/true)
2018-12-12 14:58:12 +01:00
Jérémy Lecour
d0b3b6d6b8
evomaintenance: database variables must be set or the task fails
2018-12-11 12:08:04 +01:00
Victor LABORIE
2a6cb3b381
evoadmin-mail: complete refactoring, use Debian Package
2018-12-07 15:26:08 +01:00
Ludovic Poujol
f2f595af13
redis: In instance mode, ensure to replace the nrpe check_redis with the instance check script
2018-12-05 16:37:52 +01:00
Ludovic Poujol
c9ba37614c
nginx: Munin url config is now a template to insert the server-status prefix
2018-12-05 16:25:48 +01:00
Jérémy Lecour
69d9b949e2
Release 9.6.0
2018-12-04 14:51:17 +01:00
Jérémy Lecour
2bcc1133c0
minifirewall: all variables are configurable
...
By default, a Null value keeps the variable current value as-is.
Set an Array (can be empty) to replace the value.
2018-12-04 14:49:50 +01:00
Jérémy Lecour
50e16e0dee
minifirewall: compare config before/after (for restart condition)
2018-12-04 14:46:32 +01:00
Jérémy Lecour
59dd03c91e
squid: better replacement in minifirewall config
2018-12-04 14:46:32 +01:00
Jérémy Lecour
33e29657a7
update changelog
2018-12-04 14:46:32 +01:00
Victor LABORIE
74f25e8183
evolinux-base: deploy custom motd if template are present
2018-11-30 15:14:39 +01:00
Victor LABORIE
6469733d2f
evoacme: fix error handling in sed_cert_path_for_(apache|nginx)
2018-11-22 15:06:23 +01:00
Jérémy Lecour
d5e34a58d2
Release 9.5.0
2018-11-14 17:15:25 +01:00
Jérémy Lecour
b3f9932c4d
evolinux-users: add newaliases handler
2018-11-14 17:04:51 +01:00
Jérémy Lecour
2f8cad3c7c
packweb-apache: mod-security config is already included elsewhere
2018-11-14 17:04:03 +01:00
Jérémy Lecour
5056f93283
mysql: logdir can be customized
2018-11-14 16:13:06 +01:00
Jérémy Lecour
bd1b1a7775
update CHANGELOG
2018-11-14 16:13:06 +01:00
Jérémy Lecour
3425711ecf
redis: update CHANGELOG
2018-11-14 15:35:11 +01:00
Victor LABORIE
cfb87a7b65
haproxy: add vars for tls configuration
...
Permit simply include of TLS configuration, eg. in [global] :
{{ haproxy_ssl_intermediate | indent(width=4) }}
2018-11-13 11:07:06 +01:00
Jérémy Lecour
df48a60684
evocheck: update script from upstream
2018-11-08 09:46:57 +01:00
Victor LABORIE
c6a504c6c5
Add an SSL role for certificates deployment
2018-11-06 16:15:48 +01:00
Jérémy Lecour
4a411685ff
evomaintenance: FROM domain is configurable
2018-11-06 10:39:30 +01:00
Jérémy Lecour
2f9348e3d1
update CHANGELOG
2018-11-02 18:16:29 +01:00
Jérémy Lecour
3d76454984
update CHANGELOG for postfix
2018-11-02 10:14:49 +01:00
Jérémy Lecour
c03be65ed9
evomaintenance: update script from upstream
2018-11-02 10:13:40 +01:00
Victor LABORIE
83e9f12669
evolinux-base: install man package
2018-10-23 11:38:52 +02:00
Victor LABORIE
6e6820805d
nginx: add tag for ips management
2018-10-19 10:31:45 +02:00
Jérémy Lecour
79aceac380
Release 9.4.2
2018-10-12 10:16:40 +02:00