Age | Commit message (Collapse) | Author | |
---|---|---|---|
2017-02-23 | Cleanup modified Gemfile.lock before pulling nickserver vcsrepo | varac | |
Resolves: #8492 | |||
2017-02-23 | Dont apply specific ssh parameters for wheezy | varac | |
2017-02-23 | [feat] always set smtpd_relay_restrictions | varac | |
now that we deprecate wheezy, we can always set smtpd_relay_restrictions | |||
2017-02-23 | no build_essential packages for wheeyz anymore | varac | |
2017-02-23 | assume systemd is always present now | varac | |
2017-02-23 | [feat] only care for apache >= 2.4 | varac | |
2017-02-23 | [feat] dont use backports for rsyslog anymore | varac | |
2017-02-23 | [feat] dont use backports for passenger anymore | varac | |
2017-02-23 | Remove old leap-keyring package | varac | |
2017-01-18 | Use systemd unit file for nickserver [#8578] | varac | |
2017-01-17 | Ensure the directory exists before creating the file | Tulio Casagrande | |
with @aarni | |||
2017-01-17 | Change autorestart to use systemd::unit_file | Tulio Casagrande | |
2017-01-17 | Rename extensions module to autorestart | Tulio Casagrande | |
2017-01-17 | Remove spec_helper | Tulio Casagrande | |
2017-01-17 | Update how exec is run | Tulio Casagrande | |
2017-01-17 | Add apache auto-restart extension file | Tulio Casagrande | |
2017-01-16 | git subrepo clone --force https://leap.se/git/puppet_systemd ↵ | varac | |
puppet/modules/systemd subrepo: subdir: "puppet/modules/systemd" merged: "f3c4059" upstream: origin: "https://leap.se/git/puppet_systemd" branch: "master" commit: "f3c4059" git-subrepo: version: "0.3.0" origin: "https://github.com/ingydotnet/git-subrepo.git" commit: "841aa43" | |||
2017-01-16 | Revert "Add systemd::enable define" | varac | |
This commit was moved to the systemd puppet repo. This reverts commit f5db49cf6b3ca0a5830b849c0aac074e371b95d9. | |||
2016-12-31 | Couchdb service should not require on soledad | varac | |
- Resolves: #8693 | |||
2016-12-21 | Merge branch 'bugfix/sans-soledad' into 'master' | Varac | |
bugfix: couchdb nodes should not require soledad. closes #8693 See merge request !60 | |||
2016-12-20 | [Vagrant] Install leap_cli gem dependencies | varac | |
2016-12-20 | bugfix: couchdb nodes should not require soledad. closes #8693 | elijah | |
2016-12-08 | Lint site_config::files | varac | |
2016-10-24 | Set X-XSS-Protection HTTP response header to '1'. | Micah Anderson | |
This HTTP response header enables the Cross-site scripting (XSS) filter built into some modern web browsers. This header is usually enabled by default anyway, so the role of this header is to re-enable the filter if it was disabled maliciously, or by accident. | |||
2016-10-24 | Set X-Content-Type-Options nosniff. | Micah Anderson | |
Setting this header will prevent the browser from interpreting files as something else than declared by the content type in the HTTP headers. This will prevent the browser from MIME-sniffing a response away from the declared content-type. When this is not set, older versions of Internet Explorer and Chrome perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the declared content type. | |||
2016-10-20 | Merge branch 'twisted_backports' into develop | varac | |
2016-10-18 | Setup couch for soledad before starting soledad | varac | |
When the soledad couch user is not present, soledad-server refuses to start, so we need to ensure that couch is setup correctly before starting soledad-server. see https://leap.se/code/issues/8535 | |||
2016-10-18 | Lint site_couchdb::setup | varac | |
2016-10-18 | [feat] Use twisted 16.2 from jessie-backports | varac | |
New soledad packages now depend on Twisted 16.2.0 (see https://leap.se/code/issues/8412), so we need to pin twisted to get installed from jessie-backports. - Resolves: #8418 | |||
2016-10-18 | lint site_mx class | varac | |
2016-09-13 | [bugfix] static sites: only enable hidden service by default if one domain ↵ | elijah | |
is configured The problem is that we have a single onion address per server, so if more than one domain is configured we need to make sure they don't both try to use the same onion address. | |||
2016-09-08 | Merge branch 'clamd_dependencies' into develop | varac | |
2016-09-08 | Merge branch 'ensure_clamav_running' into develop | varac | |
2016-09-08 | start clamav after definitions are downloaded | Christoph Kluenter | |
freshclam might not be able to start clamav via the socket because the socket might not be there. This systemd unit watches for the definitions and then starts clamav. Resolves: #8431 | |||
2016-09-08 | Add systemd::enable define | varac | |
2016-09-07 | Fix dependencies for clamd service | varac | |
Sometimes, after a deploy from scratch `leap test` fails because clamd could not get started (even when the deploy log says so). This fixes the dependencies of all resources needed in order to let clamd start reliable. Resolves: #8431 | |||
2016-09-06 | [feat] Add check_mk config values, dont set them | varac | |
When setting values like ignored_services = [...] this will override other `ignored_services` that might get parsed before. Instead, we use `+=` so multiple files can add sth to this config value. | |||
2016-09-05 | [style] lint ::site_static class | varac | |
2016-09-01 | added support for Let's Encrypt | elijah | |
2016-09-01 | moved infrastructure tests run by `leap run` to tests/server-tests | elijah | |
2016-08-31 | Merge remote-tracking branch 'varac/remove_soledad_procs_check' into develop | Micah Anderson | |
2016-08-31 | [bug] Remove Nagios soledad procs check | varac | |
leap_cli already checks for running procs - Resolves: #8380 | |||
2016-08-31 | [style] lint soledad::server | varac | |
2016-08-31 | Document site_check_mk::agent::soledad | varac | |
2016-08-30 | lint site_webapp/manifests/init.pp | varac | |
2016-08-30 | [feat] Use twisted 16.2 from jessie-backports | varac | |
New soledad packages now depend on Twisted 16.2.0 (see https://leap.se/code/issues/8412), so we need to pin twisted to get installed from jessie-backports. - Resolves: #8418 | |||
2016-08-23 | syslog: remove duplicate messages (#8405). | Micah | |
Change-Id: I90f8d160d2293288066847bcc199f480d06d877d | |||
2016-08-20 | Fix rsyslog auth.log entries (#8381). | Micah | |
The auth.log rsyslog entry was accidentally removed in #7863. Change-Id: I4ebffeafedbca5df902041ddd2bcb80d3f68b230 | |||
2016-08-20 | ignore noisy 401 errors from soledad log. | Micah | |
Change-Id: Ia1764cb28e263353856523c11f351a39774bf3b4 | |||
2016-08-08 | Stricter VPN egress firewall (#8289) | Micah | |
Change-Id: Ie09a6a34dfa8fe3d72568d2de0b208e7d947412f |