Commit Graph

780 Commits

Author SHA1 Message Date
Gregory Colpart b801c883ac minor fix: true -> True 2017-08-31 03:23:07 +02:00
Gregory Colpart d72cd0184d minor fix. true -> True 2017-08-31 03:21:57 +02:00
Victor LABORIE 4e4cbdb3c9 ntpd: listen only on localhost by default 2017-08-30 14:26:57 +02:00
Gregory Colpart 1524146f10 force own:group for config.local.php 2017-08-30 04:07:26 +02:00
Gregory Colpart ca4b0d5b1d log2mail need to be started and not restarted each time 2017-08-30 04:07:26 +02:00
Gregory Colpart 251d323662 Fix: forgot an include in main squid config file 2017-08-30 04:07:26 +02:00
Gregory Colpart 859822709d Revert "Fix: openssl req -subj arg need to be "/CN="" because bad var during test
This reverts commit 8cfa0a6ef2.
2017-08-30 04:07:26 +02:00
Daniel Jakots 03f4eaf269 fix example 2017-08-29 11:22:21 -04:00
Gregory Colpart 4a81d12d03 Delete OpenBSD stuff (mv to another repo), ansible-roles is now Linux-specific (even Debian-specific) 2017-08-29 03:09:57 +02:00
Gregory Colpart 8cfa0a6ef2 Fix: openssl req -subj arg need to be "/CN=" 2017-08-29 02:32:20 +02:00
Gregory Colpart aca83c50a9 need libssl1.0.0 backport for haproxy in jessie-backports 2017-08-29 00:05:36 +02:00
Gregory Colpart df6170404f typo in include file 2017-08-29 00:01:26 +02:00
Gregory Colpart b02e49073a don't crash when use in root (no SUDO_USER) 2017-08-29 00:01:26 +02:00
Daniel Jakots 1b80956043 remove OpenBSD tentacles, requested by gcolpart 2017-08-28 14:05:27 -04:00
Romain Dessort 58bc7940ac Add LimitUIDRange. Fix sudo calls from evoadmin 2017-08-24 12:56:12 -04:00
Romain Dessort 8ed1aaf160 Fix multiple bugs in lxc role after testing 2017-08-24 12:09:41 -04:00
Gregory Colpart 9aec7c8891 First step to use new evoadmin / FPM 2017-08-23 04:28:21 +02:00
Gregory Colpart 5bbec8f829 first step to improve userlogrotate in Debian 9 2017-08-23 04:27:34 +02:00
Gregory Colpart e10e971dbe move FHS restrictions to a new file 2017-08-23 03:23:16 +02:00
Gregory Colpart 453b78a59b do not remove old log files 2017-08-23 03:17:07 +02:00
Gregory Colpart f480ae461c add main.cf hash for stretch 2017-08-23 03:13:04 +02:00
Gregory Colpart 8e0aa59e47 download gpg in repo, we want to be independant from network as possible 2017-08-23 02:50:17 +02:00
Gregory Colpart 41d6fa4df2 test jenkins role on Debian 8 and 9 2017-08-23 02:00:42 +02:00
Gregory Colpart 207a2f6011 Improve distribution verification 2017-08-23 01:49:27 +02:00
Gregory Colpart a5db321717 quick review of mongodb role, few improvments and disable it for stretch because not ready 2017-08-23 01:44:07 +02:00
Gregory Colpart 41329af173 Remove dynamic add of whitelist Squid proxy 2017-08-23 01:26:57 +02:00
Gregory Colpart 32bcec3cc8 review squid role whith https://wiki.evolix.org/HowtoSquid 2017-08-23 01:17:45 +02:00
Gregory Colpart 6526e88b9c install phpmailer by default (now in HowtoPHP) + fix name of package for ssh module in jessie 2017-08-22 20:58:57 +02:00
Romain Dessort 5ba32d4c5f Add README to lxc role 2017-08-22 12:58:13 -04:00
Romain Dessort 39bc3d27fb Add role for LXC 2017-08-22 11:32:32 -04:00
Victor LABORIE 1af13e40c1 nginx: disable spdy in default vhost 2017-08-22 15:00:14 +02:00
Gregory Colpart 9832284050 Merge branch 'php' into unstable 2017-08-22 06:32:34 +02:00
Gregory Colpart 84d39d7121 mv evoadmin to webapps/evoadmin-web 2017-08-22 06:30:41 +02:00
Gregory Colpart 43e0f7589f use now PHP role 2017-08-22 06:30:41 +02:00
Gregory Colpart 2e1deb3e93 write php role with https://wiki.evolix.org/HowtoPHP 2017-08-22 06:30:41 +02:00
Gregory Colpart 30d9e826b8 rename php-fpm -> php 2017-08-22 06:30:41 +02:00
Gregory Colpart 9c406cc9bd Fix "Unable to reload service munin-node: Failed to reload munin-node.service: Job type reload is not applicable for unit munin-node.service.\n" 2017-08-22 06:30:04 +02:00
Gregory Colpart 2d17c60f39 continuation of new policy for sudo in Debian 9 2017-08-22 02:58:38 +02:00
Gregory Colpart bbdbd53cca Avoid using vars not well defined in src file name AND be compatible with Debian 10 2017-08-22 01:37:12 +02:00
Gregory Colpart 5226082db0 evolinux-base and admin-users are only compatible Debian >=8, declare once in main.yml and that's all
(will be probably generalized to others modules if needed)
2017-08-22 01:37:04 +02:00
Gregory Colpart 606f3a14f5 Move sudo stuff to sudo.yml 2017-08-22 01:36:56 +02:00
Gregory Colpart ab08969cfb We decided a new policy for sudo in stretch because our previous stretch policy is buggy 2017-08-22 01:35:36 +02:00
Gregory Colpart f0ced31efa review default vars 2017-08-18 15:18:33 +02:00
Benoît S. a95d7893c5 Add a comment about AcceptEnv 2017-08-18 14:37:34 +02:00
Gregory Colpart 8dbe8bf4ac Quick fix because MySQL install doesn't work anymore on Stretch 2017-08-18 05:06:23 +02:00
Gregory Colpart 2fd165a465 fix error in handler call 2017-08-18 04:18:52 +02:00
Gregory Colpart d82b12b614 fail when evolinux_ssh_password_auth_addresses is empty instead of Ansible crash (like for minifirewall) 2017-08-18 04:13:56 +02:00
Gregory Colpart 2bb7367edf standardization for Debian versions : we use "jessie" or "9 or later" to prepare buster smoothly as possible 2017-08-18 03:50:30 +02:00
Gregory Colpart bcd333aaa9 ansible-roles is now only-Linux compatible, and add precision for compatibility (Debian 9 and accidentally Debian 8) 2017-08-18 02:58:26 +02:00
Gregory Colpart e5e44d5bc1 standard Evolix name is /etc/apache2/ipaddr_whitelist.conf cf https://wiki.evolix.org/HowtoApache 2017-08-18 02:31:41 +02:00