Commit graph ansible-infra/resources
Author SHA1 Message Date
012bceeabb public-reverse-proxy(host): Increase nginx worker fd limit
All checks were successful
/ build (pull_request) Successful in 29s
/ Ansible Lint (push) Successful in 2m34s
/ Ansible Lint (pull_request) Successful in 2m37s
By default the limit on file descriptors is at a 1024 hard limit and 520k hard limit.
Unsure how this affects nginx, but each client connection needs two file descriptors.
So let's try to set the limit of open files explicitly.
2026-08-28 12:11:03 +02:00
4540dc5516 Update to current version, open up fully again.
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 3m9s
2026-08-25 19:04:44 +02:00
bd71738df3 Temporary block until we can update Keycloak
All checks were successful
/ build (push) Successful in 32s
/ Ansible Lint (push) Successful in 2m44s
2026-08-25 18:41:40 +02:00
ae314ea9b3 Configure manual subscriber lists
All checks were successful
/ build (push) Successful in 50s
/ Ansible Lint (push) Successful in 4m18s
2026-08-24 10:01:16 +02:00
a2eba1ac70 fixed IP for Retro Sun SparcStation 4
All checks were successful
/ build (push) Successful in 29s
/ Ansible Lint (push) Successful in 2m24s
2026-08-21 23:34:10 +02:00
5ae8a3b186 Re-add IP for waybackproxy
All checks were successful
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m51s
2026-08-21 23:28:21 +02:00
a87c27b3d5
keycloak(host): allow right ipv4 of z9 router
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m38s
2026-08-17 21:39:00 +02:00
e9a5b711ae Start migrating config to Ansible
All checks were successful
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m31s
The real file still lives in /opt/mailman on the host for now, need to migrate whole config into Ansible.
2026-08-17 09:25:23 +02:00
548d761def Migrate officemail away
All checks were successful
/ build (push) Successful in 50s
/ Ansible Lint (push) Successful in 2m59s
2026-08-17 09:20:13 +02:00
53c1801eba Change confirmation lifetime to 7d
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 3m2s
2026-08-16 09:28:42 +02:00
e668c44273 Enable list subscription management for intern@
All checks were successful
/ build (push) Successful in 49s
/ Ansible Lint (push) Successful in 2m52s
2026-08-16 09:01:57 +02:00
73760a9995
fix ansible-lint warnings
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 4m35s
2026-08-11 17:38:51 +02:00
39d8ff4ef8
update wireguard publicKey for lilly
Some checks failed
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m26s
2026-08-11 17:33:57 +02:00
938a913094
z9-router(host): add firewall rule chaosknoten to z9 pbs
Some checks failed
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 2m20s
2026-08-09 17:32:36 +02:00
6a402aa544
z9-router(host): fix dhcp6 config, wrong interface
Some checks failed
/ build (push) Successful in 51s
/ Ansible Lint (push) Failing after 2m50s
2026-08-09 17:09:40 +02:00
35381d5bb9
z9-router and auth-dns(host): add static dhcp lease and dns entry for wled-eh22 2026-08-09 17:09:15 +02:00
f5d1c6deee
z9-router(host): add firewall rule staubis to club assistant
Some checks failed
/ build (push) Successful in 27s
/ Ansible Lint (push) Failing after 2m32s
2026-08-07 23:50:57 +02:00
stb
8f3cd75a46 Merge branch 'main' into renovate/docker.io-pretalx-standalone-2026.x
Some checks failed
/ cleanup-staging (pull_request) Successful in 3s
/ build (pull_request) Successful in 29s
/ build (push) Successful in 26s
/ Ansible Lint (pull_request) Failing after 2m33s
/ Ansible Lint (push) Failing after 2m28s
2026-08-07 23:47:09 +02:00
stb
cf18c8e633 Merge branch 'main' into renovate/docker.io-pretix-standalone-2026.x
Some checks failed
/ build (pull_request) Successful in 31s
/ cleanup-staging (pull_request) Successful in 4s
/ build (push) Successful in 28s
/ Ansible Lint (pull_request) Failing after 2m54s
/ Ansible Lint (push) Has been cancelled
2026-08-07 23:44:45 +02:00
3ab9f83039
z9-router(host): fix nftables
Some checks failed
/ build (pull_request) Successful in 30s
/ Ansible Lint (pull_request) Failing after 2m39s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 27s
/ Ansible Lint (push) Has been cancelled
2026-08-07 23:36:56 +02:00
5378c3f360
auth-dns(host): ccchh.net remove unused 2026-08-07 22:56:07 +02:00
51b2cac907
z9-router(host): remove netwan, vlan55 untagged, add and fix DNS, fix formatting 2026-08-07 22:56:07 +02:00
82760d2bc2
light(host): remove resolver from nginx conf 2026-08-07 22:55:56 +02:00
c2130adbb5
auth-dns(host): remove unused unfi ipv6 and specify comments 2026-08-07 22:55:56 +02:00
49f07b0872
z9-router(host): move yate from vlan 55 to 52 2026-08-07 22:55:56 +02:00
1452c85b9d
z9-router(host): change mac address of yate in dhcp 2026-08-07 22:55:56 +02:00
8043198569
z9-router(host): add dhcp and dns for dooris-legacy 2026-08-07 22:55:56 +02:00
ffb88164ee
z9-router(host): change vlan 54 to 55 and remove netwan move vlan 400 to netlan 2026-08-07 22:55:56 +02:00
58ea3ef7a3
z9-router(host): update host kea config
- edit config to work with update kea role
- fix ipv6 addresses
2026-08-07 22:55:55 +02:00
6006dbca27
z9-router(host): nftables conf fix indent and allow dhcpv6 2026-08-07 22:55:55 +02:00
4ec4c1f942
z9-router(host): fix systemd-networkd configs 2026-08-07 22:55:34 +02:00
04d24ccb6f
z9(group): remove all old ip references and change them to new ones 2026-08-07 22:55:33 +02:00
9e92a3c390
z9(group): remove all z9 references as subdomain 2026-08-07 22:55:33 +02:00
ebc6c8a9b8
z9-router(host): fix some spelling and a wireguard peer address 2026-08-07 22:55:31 +02:00
1dff022146
z9-router(host): rename rt1 to z9-router 2026-08-07 22:55:31 +02:00
010b8d1224
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-08-07 22:55:31 +02:00
aeaa80d2c4
rt1(z9 host): create host and configure networkd and nftables 2026-08-07 22:55:31 +02:00
54b0d83451 Update docker.io/pretalx/standalone Docker tag to v2026
All checks were successful
/ build (pull_request) Successful in 30s
/ Ansible Lint (push) Successful in 2m44s
/ Ansible Lint (pull_request) Successful in 2m26s
2026-08-04 21:31:22 +00:00
e32d3734e4 Update docker.io/pretix/standalone Docker tag to v2026.7
All checks were successful
/ build (pull_request) Successful in 33s
/ Ansible Lint (push) Successful in 2m47s
/ Ansible Lint (pull_request) Successful in 2m47s
2026-08-04 21:31:00 +00:00
7f421b2409 Update to current version
All checks were successful
/ build (push) Successful in 33s
/ Ansible Lint (push) Successful in 2m41s
2026-08-04 23:16:39 +02:00
849f63cd1b Activate sync
All checks were successful
/ build (push) Successful in 28s
/ Ansible Lint (push) Successful in 3m21s
2026-08-04 09:13:50 +02:00
f749ed436c Use fixed port range to allow for better fw rules
Some checks failed
/ build (push) Successful in 45s
/ Ansible Lint (push) Failing after 2m38s
2026-08-02 17:25:30 +02:00
5ecf70ade3 Activate old address for yate for now
Some checks failed
/ Ansible Lint (push) Failing after 5s
/ build (push) Failing after 17s
2026-07-31 19:43:37 +02:00
de8daaf56c
add dooris role for setup of dooris interaction on the node itself
Some checks failed
/ build (pull_request) Successful in 28s
/ Ansible Lint (pull_request) Failing after 3m49s
/ cleanup-staging (pull_request) Successful in 6s
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m35s
2026-07-29 14:16:04 +02:00
685646c697 Set up Keycloak to Mailman sync for chaos@
All checks were successful
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m23s
DRY_RUN=true, so no changes to Mailman are performed yet.
2026-07-26 16:19:41 +02:00
283bc80b41 Update wordpress image
All checks were successful
/ build (push) Successful in 50s
/ Ansible Lint (push) Successful in 2m53s
2026-07-26 00:47:54 +02:00
70b1039f95 Upgrade Hedgdedoc to 1.11.1
All checks were successful
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m38s
Closes #130

Also add appropriate config for renovate to upgrade Hedgedoc.
2026-07-24 23:26:23 +02:00
9a876e12a8
fix CNAME for club-assistant acme challenge
All checks were successful
/ build (push) Successful in 47s
/ Ansible Lint (push) Successful in 3m52s
2026-07-23 14:33:19 +02:00
b3fe097421
re-enable club-assistant dns record
All checks were successful
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 3m27s
2026-07-22 21:44:03 +02:00
28a22e4476 pad: disable external link warning
All checks were successful
/ build (pull_request) Successful in 29s
/ Ansible Lint (pull_request) Successful in 3m10s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 4m20s
closes #130
2026-07-22 00:04:05 +02:00