summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2013-07-10added tls support, including smtp auth via client certvarac
2013-07-09re-add mx servicevarac
2013-07-09updated submodule apachevarac
2013-07-09updated submodule couchdbvarac
2013-07-09updated submodule aptvarac
2013-07-09beginning of smtp_auth config with client certsvarac
2013-07-09smtpd_recipient_restrictions: +permit_tls_all_clientcertsvarac
2013-07-09smtpd_checks: smtpd_delay_rejectvarac
2013-07-09smtpd_checks: smtpd_data_restrictionsvarac
2013-07-09using alias resolvervarac
2013-07-09fixed provider_base/services/mx.json syntaxvarac
2013-07-09update postfix module to new shared version for parameterized classes, and otherMicah Anderson
2.7 updates update site_postfix::mx to use parameterized classes
2013-07-09initial mx couchdb stunnel configurationMicah Anderson
2013-07-09no need to import common anymorevarac
2013-07-09Configure Postfix for incoming mails (Feature #2269)varac
2013-07-09hiera variable mx.contact -> postfix $root_mail_recipientvarac
2013-07-09initial mx couchdb stunnel configurationMicah Anderson
2013-07-09added provider_base/services/mx.jsonvarac
2013-07-09added site_mx::haproxyvarac
2013-07-09added basic site_postfix::mx configvarac
2013-07-09include shorewall rules for site_mxvarac
2013-07-09shorewall rules for site_mxvarac
2013-07-09added site_mxvarac
2013-07-09added submodule postfix from git://labs.riseup.net/shared-postfixvarac
2013-07-09include site_mxvarac
2013-07-06site_webapp -- make bundler not install test-only or development-only gems.elijah
2013-07-04bugfix - properly generate provider.json file.elijah
2013-07-04more robust openvpn restartingMicah Anderson
this ensures that an actual restart is run on the service when config files are added or removed, instead of relying on the status parameter of the initscript, which can be confused if config files are removed out from under it Change-Id: I1c69fff26933338b707acf7dc4593547f32f92e3
2013-07-04make sure webapps have the full domain suffix as an alias (fixes problems ↵elijah
generating zone file).
2013-07-04couchdb.json should not set service_type, since internal_service is the default.elijah
2013-07-04remove stupid bandwidth limit from default provider.jsonelijah
2013-07-03Merge branch 'feature/documentation_update' into leapMicah Anderson
2013-07-03Copy the current state of the platform documentation into the doc directory.Micah Anderson
Originally I thought it would be better to add the leap_doc git repository as a submodule, but I decided against that: . it requires that the user has to start off by initializing submodules, something that the leap_cli does for you . it would result in more up-to-date documentation than was targeted for this release . it would result in an unfortunate directory structure (doc/doc/platform). For these reasons it seemed to me better to put a snapshot of our current platform documentation into the doc directory right before release. This just means a step in our release process of refreshing these docs once we have reviewed them and updated the known-issues for this release. Change-Id: Ib395ea30553772fd195dd50315f026a2576feedd
2013-07-03Update README to guide a user through a basic understanding, and where to go ↵Micah Anderson
next to get started or report problems Change-Id: I254e73db7bdbf181bd993d2e9d73e864a62d1112
2013-07-03Merge branch 'bug/1983' into leapMicah Anderson
2013-07-03Merge branch 'bug/1983' of /home/git/repositories/micah/leap_platform into ↵micah
develop
2013-07-02update stunnel submodule to fix refresh bug #3013Micah Anderson
Change-Id: I9ed218d9353c05b34d34c363a6a3f10d54b3a60a
2013-07-03Merge branch 'bug/3013' of /home/git/repositories/micah/leap_platform into ↵micah
develop
2013-07-02update stunnel submodule to fix refresh bug #3013Micah Anderson
Change-Id: I9ed218d9353c05b34d34c363a6a3f10d54b3a60a
2013-07-02create a site_config subclass for package installation and removal add ↵Micah Anderson
packages that we want to make sure are installed remove packages that were found on vagrant and PC installations that have no business being there Change-Id: I4887a327ca89eb60945ad817a75ff199859824d3
2013-07-02deleted bind9 purging, it was only needed for the transition from bind to ↵varac
unbound
2013-07-01Merge branch 'bug/hosts_restart_stunnels' of ↵micah
/home/git/repositories/micah/leap_platform into develop
2013-07-01restart stunnels if /etc/hosts is changed (#3031)Micah Anderson
Due to the fact that /etc/hosts is modified in the early stage setup.pp run and the stunnel service is not deployed on an initial puppet run, we cannot simply override the Service['stunnel'] but instead need to trigger a restart through an exec calling the init script that first tests to see if it is present. Change-Id: I6bf5dfece9ecbdb8319747774185dec50d5a55f6
2013-07-01Merge branch 'bug/3019' of /home/git/repositories/micah/leap_platform into ↵micah
develop
2013-06-30Fix 'Failed to call refresh: /usr/local/sbin/reload_dhclient returned 2 insteadMicah Anderson
of one of [0]' by putting in the missing closing single quote. Change-Id: I86feb5d06dd25e28ea67da0b5627e7be4174e01e
2013-07-01Merge branch 'feature/authorized_keys' of ↵micah
/home/git/repositories/micah/leap_platform into develop
2013-06-30switch to own define for managing ssh keysvarac
The problem with puppet's built-in ssh_authorized_key is that you can purge unmanaged keys in a authorized_keys file. see https://leap.se/code/issues/3010 for details. Conflicts: puppet/modules/site_sshd/manifests/authorized_keys.pp Change-Id: I640bf7ebc0f0f7fb19cc46feb4cb2702d6561a9b
2013-06-30modularize and standardize site_sshd:Micah Anderson
. move the setting of the xterm title to site_config::shell . change the xterm file resource to use standard source lines, switch to single quotes, quote mode, and line up parameters . move the mosh pieces into a site_ssh::mosh class and only include it if the right mosh variable is enabled, passing into the class the necessary hiera parameters . lint the site_ssh::mosh resources . change the authorized_keys class to accept the key parameter which is passed in from the main ssh class (but allow for out of scope variable lookup when the tag is passed) Change-Id: Ieec5a3932de9bad1b98633032b28f88e91e46604
2013-06-28added site_sshd::authorized_keysvarac
2013-06-27Merge branch 'develop' into leapMicah Anderson