<feed xmlns='http://www.w3.org/2005/Atom'>
<title>leap_platform.git/puppet/modules/site_config/templates, branch master</title>
<subtitle>[leap_platform] 
</subtitle>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/'/>
<entry>
<title>testing: adds mx delivery tests</title>
<updated>2016-04-05T16:52:01+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2016-03-29T20:27:01+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=eac3056c237d523f4786593922fe8f88eb65dff7'/>
<id>eac3056c237d523f4786593922fe8f88eb65dff7</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>allow all outgoing traffic</title>
<updated>2014-09-25T14:01:37+00:00</updated>
<author>
<name>Christoph Kluenter</name>
<email>ckluente@thoughtworks.com</email>
</author>
<published>2014-09-25T14:01:37+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=343572ab04686c65c10fd49a5d09314ca99b3d75'/>
<id>343572ab04686c65c10fd49a5d09314ca99b3d75</id>
<content type='text'>
as discussed on #leap
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
as discussed on #leap
</pre>
</div>
</content>
</entry>
<entry>
<title>allow outgoing port 3142 for apt-cacher proxy</title>
<updated>2014-09-17T15:30:38+00:00</updated>
<author>
<name>Christoph</name>
<email>chris@inferno.nadir.org</email>
</author>
<published>2014-09-17T15:30:38+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=63783c1dc0a1e1749810162af169f0ffc0a237d5'/>
<id>63783c1dc0a1e1749810162af169f0ffc0a237d5</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>clean up how /etc/hosts is generated so it doesn't require custom behavior depending on the services.</title>
<updated>2014-06-04T21:19:55+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-06-04T21:19:55+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=f991e8a4c877cff1d274fd1cac26488f8c3fda84'/>
<id>f991e8a4c877cff1d274fd1cac26488f8c3fda84</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Change the initial firewall to subscribe to the rule file to be able to</title>
<updated>2014-05-06T20:37:01+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-06T20:37:01+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=0eff66a4bcf68b51c57493c0a80e0f3813476733'/>
<id>0eff66a4bcf68b51c57493c0a80e0f3813476733</id>
<content type='text'>
trigger changes, make the default ipv6 firewall subscribe to shorewall6,
if it exists, and finally reject all outgoing IPv6 packets.

All of this will complete the platform-side of route IPv6 through
OpenVPN gateway, and block it. (Feature #4163)

Change-Id: Icf6d582063ed01d304658b740a565057ee4e6810
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
trigger changes, make the default ipv6 firewall subscribe to shorewall6,
if it exists, and finally reject all outgoing IPv6 packets.

All of this will complete the platform-side of route IPv6 through
OpenVPN gateway, and block it. (Feature #4163)

Change-Id: Icf6d582063ed01d304658b740a565057ee4e6810
</pre>
</div>
</content>
</entry>
<entry>
<title>initial firewall: allow port 22 by default. This is the most common port</title>
<updated>2014-04-24T18:59:33+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-04-24T18:55:46+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=640c63ef377abe7a4461ab417c27057313613830'/>
<id>640c63ef377abe7a4461ab417c27057313613830</id>
<content type='text'>
that sshd will be listening to in a default setup. This needs to be
allowed so that you can have a different port configured in the
hiera and not get locked out during deployment (#5119)

Change-Id: Ie101eaaf440415ddb276621c369da7f67f409c2b
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
that sshd will be listening to in a default setup. This needs to be
allowed so that you can have a different port configured in the
hiera and not get locked out during deployment (#5119)

Change-Id: Ie101eaaf440415ddb276621c369da7f67f409c2b
</pre>
</div>
</content>
</entry>
<entry>
<title>include "127.0.1.1 @domain_public @api['domain']"  in /etc/hosts for nagios webapp log check</title>
<updated>2014-02-27T17:28:54+00:00</updated>
<author>
<name>varac</name>
<email>varacanero@zeromail.org</email>
</author>
<published>2014-02-27T15:41:05+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=2887bbbac9f350c0912e3b2bf8fd643994eaee84'/>
<id>2887bbbac9f350c0912e3b2bf8fd643994eaee84</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>fix initial firewall to allow outgoing lo traffic and outgoing port 443 (#3736)</title>
<updated>2013-09-05T02:46:56+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2013-09-05T02:46:56+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=f9ee40f2fca2396c1ef7d85a9c44b97fe834671a'/>
<id>f9ee40f2fca2396c1ef7d85a9c44b97fe834671a</id>
<content type='text'>
this allows nameserver queries to the local resolver to work and clones to the
leap https repository to work

Change-Id: I575d08405a0c28e12c8d201a8dbc79585a5a9a48
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
this allows nameserver queries to the local resolver to work and clones to the
leap https repository to work

Change-Id: I575d08405a0c28e12c8d201a8dbc79585a5a9a48
</pre>
</div>
</content>
</entry>
<entry>
<title>install a preliminary firewall that blocks everything, except ssh for the cases when shorewall doesn't properly come up, ensuring that it fails safe (#3339)</title>
<updated>2013-08-22T13:43:20+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2013-08-20T23:45:56+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=3cdebf3ebe73cb2859dc852dcc73a8ee2d60e976'/>
<id>3cdebf3ebe73cb2859dc852dcc73a8ee2d60e976</id>
<content type='text'>
Change-Id: Id4f0bf6cf25f420aa2ad67635b37ae95f54e3d38
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: Id4f0bf6cf25f420aa2ad67635b37ae95f54e3d38
</pre>
</div>
</content>
</entry>
<entry>
<title>ensure that /etc/hosts is output deterministically, so that content does not change each time you deploy.</title>
<updated>2013-07-11T04:45:51+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2013-07-11T04:45:51+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=0e7b47380edb2af6683a0cdc871eaa60a4101f5c'/>
<id>0e7b47380edb2af6683a0cdc871eaa60a4101f5c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
