Commit Graph

331 Commits

Author SHA1 Message Date
staticsafe
83fcf86900 POSTROUTING should be in nat chain 2019-08-21 23:20:41 -04:00
staticsafe
e86367ed83 add firewall rulesets for demonreach.asininetech.net. 2019-08-21 23:18:16 -04:00
staticsafe
ab7979ce01 add firewall rulesets for grevane.asininetech.net. 2019-08-21 22:46:53 -04:00
staticsafe
135e9bd008 add firewall rulesets for erlking.asininetech.net. 2019-08-21 22:37:20 -04:00
staticsafe
d411bc74dd add firewall rulesets for deirdre.asininetech.net. 2019-08-21 22:26:34 -04:00
staticsafe
ee1e6fb76f add firewall rulesets for catsith.asininetech.net 2019-08-21 22:23:10 -04:00
staticsafe
8b77463939 turn off backups in firewall-ruleset-deploy/tasks/main.yml 2019-08-21 22:15:34 -04:00
staticsafe
985895c082 add firewall rulesets for waldo.asininetech.net. 2019-08-21 22:12:42 -04:00
staticsafe
df3044c9f3 fix another error in gard.asininetech.net.rules.v6 2019-08-21 22:07:24 -04:00
staticsafe
ecda411031 fix syntax error in gard.asininetech.net.rules.v6 2019-08-21 22:02:55 -04:00
staticsafe
70fb7c8212 maybe fully enclosed? 2019-08-21 22:00:48 -04:00
staticsafe
62530669c9 double quotes maybe? 2019-08-21 21:58:10 -04:00
staticsafe
89e35f402b add quotes around ansible_fqdn 2019-08-21 21:56:43 -04:00
staticsafe
7705504cf7 add firewall-ruleset-deploy to site.yml 2019-08-21 21:53:38 -04:00
staticsafe
f1623be2e9 add firewall-ruleset-deploy playbook and gard's ruleset 2019-08-21 21:52:12 -04:00
staticsafe
de780e0254 make sure iptables-persistent and netfilter-persistent is installed via common playbook 2019-08-21 18:45:56 -04:00
staticsafe
a4b94b8ded add char.packet.cat conf 2019-07-27 11:57:05 -04:00
staticsafe
c074a6bb0a add wiki.tenforward.social configs 2019-07-27 11:28:12 -04:00
staticsafe
b7f3e9b2c2 removed erroneous block 2019-07-26 23:42:18 -04:00
staticsafe
74d3a686a5 add as393949.net vhost 2019-07-26 23:39:26 -04:00
staticsafe
7b42ceeca2 Remove warn=false in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:43:43 -04:00
staticsafe
8d6bcde072 set warn=False for non-module apt task 2019-07-21 20:43:06 -04:00
staticsafe
32190262bc stop using with_items for apt in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:34:13 -04:00
staticsafe
26d749a670 make sure PATH is set in ubuntu/roles/apt-maintenance/files/apt-maintenance.sh 2019-07-14 08:18:44 -04:00
staticsafe
c82b4f2ccf remove MAILTO from apt-maintenance.sh 2019-07-12 23:42:20 -04:00
staticsafe
c1e39c3f73 remove insertafter from ubuntu/roles/apt-maintenance/tasks/main.yml 2019-07-12 23:40:21 -04:00
staticsafe
e7865d16c9 Add MAILTO variable addition into apt-maintenance/tasks/main.yml 2019-07-12 23:39:01 -04:00
staticsafe
616b5c1a83 make sure /root/scripts exists 2019-07-12 23:13:48 -04:00
staticsafe
1ca719c43f Copy script to dif location and add cronjob to root 2019-07-12 23:11:51 -04:00
staticsafe
e698c4a809 Change permission of script to 755 2019-07-12 11:30:46 -04:00
staticsafe
cd6efefd3f turn off backups for apt-maintenance/tasks/main.yml 2019-07-10 10:15:54 -04:00
staticsafe
d0452a3e95 modify apt-maintenance.sh to add a mailto addr 2019-07-10 10:13:44 -04:00
staticsafe
4761744224 add apt-maintenance defs in ubuntu/site.yml 2019-07-07 20:04:04 -04:00
staticsafe
acdb50458f Add apt-maintenance role 2019-07-07 20:00:42 -04:00
Sadiq Saif
785924e5ba
Update dev-glitch nginx to use TLSv1.3 2019-07-03 21:11:04 -04:00
Sadiq Saif
178a01cba2
Delete mercy.sickstack.com.yml
server terminated
2019-07-03 21:07:42 -04:00
Sadiq Saif
06ddcd9929
Delete mei.sickstack.com.yml
server terminated
2019-07-03 21:07:06 -04:00
Sadiq Saif
ebfc8eff5c
Delete ivy.asininetech.com.yml
server terminated
2019-07-03 21:06:48 -04:00
Sadiq Saif
b1e6c25fbf
Delete aphrodite.selfie.town config
Server terminated
2019-07-03 21:06:26 -04:00
Sadiq Saif
6241b2e321
Update tfmain nginx to use TLSv1.3 2019-07-03 21:06:03 -04:00
Sadiq Saif
075c8cd1ec
Update mastodon.zombocloud.com's nginx config to use TLSv1.3 2019-07-03 21:05:08 -04:00
Sadiq Saif
b21cf6176c
Update webserver1 nginx config to use TLSv1.3 2019-07-03 21:04:35 -04:00
staticsafe
c76ff142ab Rename the yml file for ivy 2019-03-23 19:42:51 -04:00
staticsafe
ad9cc8af24 remove invalid variables in grafana 2019-03-23 16:42:01 -04:00
staticsafe
8c4b104f35 Change grafana listen to localhost 2019-03-23 16:37:13 -04:00
staticsafe
e4563e9c30 add webserver config to ubuntu/prometheus.sickstack.com.yml 2019-03-23 15:45:38 -04:00
staticsafe
07c937e944 remove include from ubuntu/prometheus.sickstack.com.yml 2019-03-23 13:13:58 -04:00
staticsafe
a6b4f8fafc include should in vars? 2019-03-23 12:59:59 -04:00
staticsafe
be0c6f6c32 include secrets.yml for ubuntu/prometheus.sickstack.com.yml 2019-03-23 12:54:10 -04:00
staticsafe
7992363f14 add grafana to ubuntu/prometheus.sickstack.com.yml 2019-03-23 12:48:55 -04:00
staticsafe
49f6e93d96 add netdata.internal.sickstack.com to server_name
in ubuntu/mei.sickstack.com.yml
2019-03-23 11:51:59 -04:00
staticsafe
e94bc70c6d eh? 2019-03-23 11:28:49 -04:00
staticsafe
d63b44bc6f okay maybe this one? 2019-03-23 11:22:49 -04:00
staticsafe
9aae6acae5 okay I think this is the right format? 2019-03-23 11:20:55 -04:00
staticsafe
19250e5b21 let's try a different format 2019-03-23 11:17:52 -04:00
staticsafe
89c3f8d997 complete prometheus.sickstack.com.yml 2019-03-23 11:16:03 -04:00
staticsafe
faa099e917 add ubuntu/prometheus.sickstack.com.yml 2019-03-23 11:07:06 -04:00
staticsafe
6540d059d7 turn off access logging in netdata 2019-03-19 13:05:44 -04:00
staticsafe
2f54131368 Add ubuntu/mei.sickstack.com.yml 2019-03-19 11:11:14 -04:00
staticsafe
e0f2bedf62 Use variable method for listing package installs in ubuntu/roles/icinga-client/tasks/main.yml 2019-02-03 13:35:19 -05:00
staticsafe
279b4e10f0 Modify icinga-client role to add some systemd options 2019-02-03 13:11:39 -05:00
staticsafe
aa14f2f64f Merge branch 'nextgen' of github.com:staticsafe/ansible-playbooks into nextgen 2019-01-19 18:31:01 -05:00
staticsafe
aff6f703ed Add ubuntu/dev.glitch.social.yml 2019-01-19 18:30:53 -05:00
Sadiq Saif
94ae12002a
Update package removal list
add snapd and lxcfs to removal list
2019-01-15 21:22:27 -05:00
staticsafe
1f81721ab6 Remove letsencrypt from packages list. 2019-01-12 15:13:10 -05:00
staticsafe
040efa346f Add ubuntu/aphrodite.selfie.town.yml 2018-12-29 11:43:19 -05:00
staticsafe
d6dd8b95c3 Add ubuntu/aphrodite.selfie.town.yml and remove selfie.town config from mercy.sickstack.com.yml 2018-12-29 11:42:36 -05:00
staticsafe
f27f5135a4 common configuration should include turning off MOTD 2018-09-25 21:02:34 -04:00
staticsafe
df28d10f01 hosts group should be myubuntunodes 2018-09-25 20:40:33 -04:00
staticsafe
482bbc8cf1 add turn-off-motd-news role 2018-09-25 20:38:53 -04:00
Sadiq Saif
eb4ca4c8fe
Update PHP upstream to 7.2 2018-08-26 12:04:52 -04:00
staticsafe
3ff719370f Remove pixelfed upstream from nginx config 2018-08-25 22:29:30 -04:00
staticsafe
05f8b1a1a0 client_max_body_size 0 for selfie.town 2018-08-25 21:47:01 -04:00
staticsafe
f5a495818f Switch back to default pool for pixelfed 2018-08-25 21:38:28 -04:00
staticsafe
c011cc7485 Use separate PHP upstream for pixelfed 2018-08-25 21:29:48 -04:00
staticsafe
a887f9615b Add selfie.town vhost to ubuntu/mercy.sickstack.com.yml 2018-08-25 20:57:09 -04:00
staticsafe
c1ebd44be3 Add HTTP to HTTPS redirect for wiki.sickstack.com 2018-06-10 15:53:16 -04:00
staticsafe
62f285f786 Add wiki.sickstack.com vhost 2018-06-10 15:51:31 -04:00
staticsafe
40e6a57afa Add GD to the PHP extensions list 2018-06-10 15:40:42 -04:00
staticsafe
7d06e18935 add PHP upstream config to ubuntu/mercy.sickstack.com.yml 2018-06-10 13:16:32 -04:00
staticsafe
f5d3828f3c Add some Ubuntu version conditionals to ubuntu/roles/php/tasks/main.yml 2018-06-10 13:11:12 -04:00
staticsafe
4d992b8fc7 Add a LEMP stack combo to ubuntu/site.yml 2018-06-10 13:04:44 -04:00
staticsafe
e0e30edeb0 Add MySQL role to ubuntu/site.yml 2018-06-10 12:47:46 -04:00
staticsafe
02e8237c42 Add MySQL server role 2018-06-10 12:41:02 -04:00
staticsafe
4874d5fcfc proxy_pass for gitea is using localhost now 2018-06-05 10:14:00 -04:00
staticsafe
53d757c46a Change gitea proxy_pass to use HTTPS 2018-06-05 09:47:20 -04:00
staticsafe
180f53774f Remove cryptpad.sickstack.com vhost 2018-06-04 22:53:20 -04:00
staticsafe
eac8443003 Add cryptpad.sickstack.com vhost 2018-06-04 22:39:32 -04:00
staticsafe
f5683efd4b Make the icinga role Ubuntu version agnostic 2018-06-03 18:15:46 -04:00
staticsafe
270497f949 should say git.sickstack.com for nginx config filenames 2018-06-03 18:09:26 -04:00
staticsafe
dad8e5a6a4 Add ubuntu/mercy.sickstack.com.yml 2018-06-03 18:08:41 -04:00
Sadiq Saif
181d95e78e
add client_max_body_size 2018-04-13 15:36:22 -04:00
Sadiq Saif
c7c6806689
Add client_max_body_size 2018-04-13 15:36:01 -04:00
staticsafe
9eb9954845 Add ubuntu/tfmain.tenforward.social.yml 2018-04-08 19:07:09 -04:00
staticsafe
b99eea2a6c Forgot to remove some semi-colons in ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:56:10 -04:00
staticsafe
1128317729 Add ssl config to ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:55:33 -04:00
staticsafe
11f7b2f07e another quotes situation 2018-04-08 18:48:06 -04:00
staticsafe
2d229a436d god I hate this quote situation 2018-04-08 18:45:26 -04:00
staticsafe
6c65f62aa3 remove quotes around referrer-policy and add HSTS back in 2018-04-08 18:42:56 -04:00
staticsafe
829e337ef1 Remove HSTS header add 2018-04-08 18:40:39 -04:00
staticsafe
5828fd6d89 can we escape the semi-colons maybe? 2018-04-08 18:39:15 -04:00
staticsafe
539b844d5a another try 2018-04-08 18:36:39 -04:00
staticsafe
99d70a22af this quote situation is getting out of hand 2018-04-08 18:33:34 -04:00
staticsafe
b1e0d39af1 add some quotes around add_header in ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:30:58 -04:00
staticsafe
d8ebe62efd Remove some semi-colons from ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:28:02 -04:00
staticsafe
8eb16489c8 Remove comment from ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:26:26 -04:00
staticsafe
ff0eee420b add ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:24:13 -04:00
staticsafe
a85dfac3fc Move webserver1's nginx config to its own YAML file 2018-04-08 14:38:42 -04:00
staticsafe
bf36cacc89 Remove LetsEncrypt role, it is no longer useful. 2018-04-08 14:35:06 -04:00
Sadiq Saif
2dd075b853
Check that chrony service is enabled instead of ntpd 2018-02-12 17:21:28 -05:00
Sadiq Saif
0aad55187b
Replace ntpd with chrony 2018-02-12 17:20:52 -05:00
staticsafe
3c428e0781 Replace 8.8.8.8 with [::1] in ubuntu/site.yml 2018-02-12 10:34:16 -05:00
staticsafe
d0814a5657 Use wildcard v4 listeners in nginx 2018-02-06 11:42:11 -05:00
staticsafe
1874de7c22 nginx does not need to bind to a specific address
just bind to all addresses on the required ports
2018-01-14 20:28:16 -05:00
Sadiq Saif
6215dbcfc6
Remove netdata upstream 2017-12-17 23:58:00 -05:00
staticsafe
8174e2d60f Fix missing repo string in ubuntu/roles/icinga-client/tasks/main.yml 2017-11-27 14:26:24 -05:00
staticsafe
508e73ff39 Fix another typo in ubuntu/site.yml 2017-11-27 14:24:02 -05:00
staticsafe
26d4fa21f8 Fix small typo in ubuntu/site.yml 2017-11-27 14:21:49 -05:00
staticsafe
6a74202168 Add icinga-client role. 2017-11-27 14:20:22 -05:00
Sadiq Saif
084ee25fa9
Add some deny blocks to secure cache directories for tt-rss 2017-11-09 16:07:57 -05:00
Sadiq Saif
9bea7f7d08
Add vhosts for ttrss.sadiqsaif.com 2017-11-09 11:27:19 -05:00
Sadiq Saif
4dafe9ee93
Remove netdata vhosts
we are no longer using netdata
2017-11-09 11:10:36 -05:00
Sadiq Saif
760d2fe9df
turns out fastcgi_cache_path didn't need quoting 2017-10-29 14:40:01 -04:00
Sadiq Saif
662051312c
remove inactive parameter from fastcgi_cache_path 2017-10-29 14:32:16 -04:00
Sadiq Saif
310a8373ae
Add fcgicache nginx config block for global use 2017-10-29 14:27:37 -04:00
Sadiq Saif
8a8426e5d4 Remove location block from netdata http 2017-09-16 13:06:13 -04:00
Sadiq Saif
d52252e0d9 Remove root variable from http netdata 2017-09-16 13:03:51 -04:00
Sadiq Saif
becd78336d Update SSL certificates with new acme.sh locations 2017-09-16 13:00:53 -04:00
Sadiq Saif
d2aed3cfae remove ACME location block and add it to http block 2017-09-16 12:21:31 -04:00
Sadiq Saif
1c1002be6e Add ACME location in netdat vhost 2017-09-16 12:17:34 -04:00
Sadiq Saif
62709d3731 Add some custom APT periodic task configuration
Ensure that the periodic APT cron task clears out old kernels and does unattended security upgrades
2017-08-06 16:24:25 -04:00
Sadiq Saif
7969f8908d Add 10periodic file, APT Periodic task config 2017-08-06 16:21:10 -04:00
Sadiq Saif
3f9ab5a693 Add unattended-upgrades to package list
subversion was removed as we don't need it anymore
2017-08-06 16:03:17 -04:00
Sadiq Saif
b85519e0f1 Turn off access log for netdata vhost 2017-07-18 14:52:13 -04:00
Sadiq Saif
5d11eaaf47 fix server_name in netdata https vhost 2017-07-17 23:08:11 -04:00
Sadiq Saif
861b13471b only unsetup hosts need the initial package install 2017-07-17 23:02:32 -04:00
Sadiq Saif
2d6a0a42b3 update netdata proxy pass and add backend 2017-07-17 23:01:33 -04:00
Sadiq Saif
055458219e disable letsencrypt role for now
its broken with webroot method
2017-07-17 22:57:09 -04:00
Sadiq Saif
7bb3478ea7 add netdata LE and change to webroot use 2017-07-17 22:55:15 -04:00
Sadiq Saif
1ca6c8643c add site configurations for netdata.asininetech.net 2017-07-17 22:52:57 -04:00
Sadiq Saif
fb6039aebf Update letsencrypt-renew
changes for webroot renewal
2017-07-16 19:43:34 -04:00
Sadiq Saif
f7b40f6e28 Add "gzip_types" parameter for nginx gzip config 2017-07-07 09:40:20 -04:00
staticsafe
f428fadf2b Typo in error_page configuration variable. 2017-06-28 13:02:53 -04:00
staticsafe
3f15c339ec Add custom 404 page for entropynet.net. 2017-06-28 12:58:34 -04:00
staticsafe
e60c082e78 Add SSL session settings to nginx config. 2017-05-08 23:58:22 -04:00
staticsafe
bc0645c412 We are moving to Mozilla's recommended settings for 'Modern' browsers. 2017-05-08 22:36:52 -04:00
staticsafe
c80fc35887 We redirect all HTTP requests to their HTTPS equivalents. 2017-05-08 21:12:15 -04:00
staticsafe
de8c801cb3 301 staticsafe.ca to sadiqsaif.com. 2017-03-18 18:31:37 +00:00
staticsafe
8130b10d7b lets try that port 80 thing again 2017-03-18 02:06:53 +00:00
staticsafe
9f3efeb9a2 Revert "Add port 80 listens for sadiqsaif.*"
This reverts commit bb2be78f67.
2017-03-18 02:00:25 +00:00
staticsafe
bb2be78f67 Add port 80 listens for sadiqsaif.* 2017-03-18 01:57:01 +00:00
staticsafe
feaa58b5ca Add a 301 return for sadiqsaif.ca. 2017-03-17 02:45:44 +00:00
staticsafe
1b8bb49e03 Add nginx config for sadiqsaif.com 2017-03-17 02:39:11 +00:00
staticsafe
2da2ba0312 add sadiqsaif.com to LE domain list. 2017-03-17 02:34:27 +00:00
staticsafe
ef896a0f2f letsencrypt renew script had invalid arguments 2017-01-14 14:41:07 +00:00
staticsafe
0897a454ae PHP role is now installing required PHP libs.
Close issue #2
2017-01-14 14:17:50 +00:00
staticsafe
f7bdbcd297 add some location directives for dokuwiki 2017-01-14 04:08:03 +00:00
staticsafe
0d09eae129 Add nginx service conditional to LetsEncrypt role.
Resolve issue #1
2017-01-14 03:51:43 +00:00
staticsafe
6b87ad2c87 add ssl_dhparam in nginx config options 2017-01-14 01:59:08 +00:00
staticsafe
7bc7afbb24 Fix error in TSOB's nginx config block 2017-01-14 01:12:37 +00:00
staticsafe
6c077a8f0a Remove rewrite statements now due to some parsing issues 2017-01-14 01:04:53 +00:00
staticsafe
822924ea95 Add all nginx sites to site.yml. 2017-01-14 00:17:51 +00:00
staticsafe
03276432f4 Add LetsEncrypt roles for webserver use. 2017-01-13 22:21:21 +00:00
staticsafe
98d8783038 Remove gzip_types directive 2017-01-13 03:19:08 +00:00
staticsafe
34bb61e026 Oops, wrong nginx variable name. 2017-01-13 03:15:16 +00:00
staticsafe
860dfd2a44 increase nginx's server_names_has_bucket_size to 128 2017-01-13 03:12:32 +00:00
staticsafe
14af637538 Upstream configuration probably doesn't need quotes 2017-01-13 03:05:20 +00:00
staticsafe
25ef8aee95 Add webserver role using jdauphant.nginx 2017-01-13 03:00:01 +00:00
staticsafe
baf710fc32 PHP-FPM daemon should be in a started state. 2017-01-13 02:49:33 +00:00
staticsafe
eb644482c3 Fix YAML syntax error in roles/php/tasks/main.yml 2017-01-13 02:45:22 +00:00
staticsafe
2ed429d06a Add new basic PHP role. 2017-01-13 02:43:11 +00:00
staticsafe
f73a0972f5 Remove unbound from boot check list. 2017-01-12 20:27:22 +00:00
staticsafe
7bfc6267e1 We are no longer modifying host resolvers.
VPS provider defaults are sufficient.
2017-01-12 20:24:45 +00:00
staticsafe
05b4122862 Remove appservers-php and webservers-nginx roles.
We are going to be using Galaxy roles going forward.
2017-01-12 20:20:40 +00:00
staticsafe
01dd5a9491 Update cloudflare.conf with latest set of Cloudflare IPs from their docs. 2016-09-06 19:42:15 -04:00
staticsafe
d0e17c7351 Remove uwsgi role as I don't really need it anymore. 2016-09-06 19:32:11 -04:00
staticsafe
ee8dba40ee Fix indentation from last commit. 2016-09-06 19:25:04 -04:00
staticsafe
4f65a95591 Add letsencrypt to required packages list. 2016-09-06 19:23:38 -04:00
staticsafe
4690ace036 Use "127.0.0.1" instead of "::1" to prevent odd behaviour in mtr. 2016-09-06 19:18:52 -04:00
staticsafe
c924387905 Better cipher settings for nginx. 2015-05-24 13:30:39 -04:00
staticsafe
550c81b78f Add a slightly modified playbook for Ubuntu systems.
- No need for nginx repo anymore.
2015-05-24 13:23:21 -04:00