32b5f147bc
Manage the CCCHH browser authentication flow as YAML
...
/ build (pull_request) Successful in 47s
/ Ansible Lint (push) Successful in 5m31s
/ Ansible Lint (pull_request) Successful in 4m35s
Adds a keycloak_auth_flow role that locally validates flow
definitions (structure, nesting depth, known provider IDs, and a set
of Keycloak authentication-flow gotchas: conditions silently ignored
outside a Conditional subflow, keycloak/keycloak#29515's OTP+WebAuthn
sibling bug, conditional-credential config shape/semantics, and more)
before deploying them idempotently via
middleware_automation.keycloak.keycloak_authentication_v2.
Includes the CCCHH realm's actual "browser passkey and token" flow
(the realm's real browserFlow binding, not the untouched built-in
"browser" flow), exported from the live server so it's now reviewable
and redeployable from this repo instead of only editable in the
Keycloak admin console.
2026-09-02 11:07:45 +02:00
233131b612
Use correct hostname
2026-08-18 19:27:54 +02:00
53c1801eba
Change confirmation lifetime to 7d
/ build (push) Successful in 27s
/ Ansible Lint (push) Successful in 3m2s
2026-08-16 09:28:42 +02:00
379aa7c451
add configuration required for dooris -> spaceapid integration
/ build (pull_request) Successful in 28s
/ cleanup-staging (pull_request) Successful in 7s
/ build (push) Successful in 27s
/ Ansible Lint (pull_request) Successful in 2m37s
/ Ansible Lint (push) Successful in 2m34s
2026-08-11 20:54:27 +02:00
d97c22cc8e
z9-router(host): fix dns
2026-08-07 23:36:37 +02:00
22ace3c537
z9-router(host): fix file permissions
/ build (pull_request) Successful in 29s
/ Ansible Lint (pull_request) Failing after 3m13s
/ Ansible Lint (push) Failing after 3m51s
2026-08-07 23:13:44 +02:00
51b2cac907
z9-router(host): remove netwan, vlan55 untagged, add and fix DNS, fix formatting
2026-08-07 22:56:07 +02:00
fa91690485
z9(pve01): change thinkcccore0 to pve01
2026-08-07 22:55:33 +02:00
9e92a3c390
z9(group): remove all z9 references as subdomain
2026-08-07 22:55:33 +02:00
1a0ac38861
unbound(role): use existing deploy_systemd_resolved_config role and some reordering
2026-08-07 22:55:32 +02:00
8351c28cd0
z9-router(host): add ansible pull
2026-08-07 22:55:31 +02:00
1dff022146
z9-router(host): rename rt1 to z9-router
2026-08-07 22:55:31 +02:00
010b8d1224
rt1(z9 host) unbound(role) kea_dhcp(role): create unbound and kea_dhcp role for rt1
...
- create unbound role
- create kea_dhcp role
- configure unbound and keadhcp on rt1(z9 host)
2026-08-07 22:55:31 +02:00
aeaa80d2c4
rt1(z9 host): create host and configure networkd and nftables
2026-08-07 22:55:31 +02:00
f749ed436c
Use fixed port range to allow for better fw rules
/ build (push) Successful in 45s
/ Ansible Lint (push) Failing after 2m38s
2026-08-02 17:25:30 +02:00
0377db2812
Use correct hostname for yate
2026-08-02 17:24:58 +02:00
6eafc47773
jitsi dazu
...
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 2m28s
Erstmal nur der Host, die eigentliche Config muss später passieren
2026-07-29 22:52:13 +02:00
de8daaf56c
add dooris role for setup of dooris interaction on the node itself
/ build (pull_request) Successful in 28s
/ Ansible Lint (pull_request) Failing after 3m49s
/ cleanup-staging (pull_request) Successful in 6s
/ build (push) Successful in 26s
/ Ansible Lint (push) Failing after 3m35s
2026-07-29 14:16:04 +02:00
685646c697
Set up Keycloak to Mailman sync for chaos@
...
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m23s
DRY_RUN=true, so no changes to Mailman are performed yet.
2026-07-26 16:19:41 +02:00
647058f6ad
ccchoir: stick to major version and cronjob update
/ build (push) Successful in 48s
/ Ansible Lint (push) Successful in 2m46s
2026-07-26 13:21:41 +02:00
283bc80b41
Update wordpress image
/ build (push) Successful in 50s
/ Ansible Lint (push) Successful in 2m53s
2026-07-26 00:47:54 +02:00
70b1039f95
Upgrade Hedgdedoc to 1.11.1
...
/ build (push) Successful in 26s
/ Ansible Lint (push) Successful in 2m38s
Closes #130
Also add appropriate config for renovate to upgrade Hedgedoc.
2026-07-24 23:26:23 +02:00
374e8f981a
Update git.hamburg.ccc.de/ccchh/oci-images/nextcloud Docker tag to v34
/ build (pull_request) Successful in 31s
/ Ansible Lint (pull_request) Successful in 2m54s
/ cleanup-staging (pull_request) Successful in 3s
/ build (push) Successful in 25s
/ Ansible Lint (push) Successful in 2m46s
2026-07-23 20:16:22 +00:00
1ae4a39f57
Update all stable non-major dependencies
/ build (pull_request) Successful in 33s
/ Ansible Lint (pull_request) Successful in 3m19s
/ cleanup-staging (pull_request) Successful in 8s
/ build (push) Successful in 45s
/ Ansible Lint (push) Successful in 2m51s
2026-07-08 00:16:11 +00:00
9ae16363c5
forgejo-runner-external(host): configure forgejo-runner setup
...
/ build (push) Successful in 48s
/ Ansible Lint (push) Failing after 2m57s
Configure connection for the DI-Day/website repo.
2026-07-08 00:42:50 +02:00
dd1cd6f529
forgejo-runner-external(host): basic setup
2026-07-08 00:20:02 +02:00
d44d84ae2a
forgejo-runner(host): configure forgejo-runner setup
2026-07-03 03:42:18 +02:00
7d7cf455eb
forgejo_runner(role): create role for setting up Forgejo Runner install
2026-07-03 03:42:18 +02:00
94120337aa
forgejo-runner(host): basic setup
2026-07-03 03:42:17 +02:00
3e0fdb6074
Configure transmission
2026-06-28 17:02:05 +02:00
431aaefb36
dns: remove ns.vie.ccc.de from already migrated zones
/ Ansible Lint (push) Successful in 2m27s
/ build (push) Failing after 2m41s
2026-06-10 16:05:51 +02:00
6d922b7c8b
dns: also notify erfadns.ber.ccc.de for catalog zone changes
/ Ansible Lint (push) Successful in 2m32s
/ build (push) Failing after 2m43s
2026-06-10 13:12:00 +02:00
b283089b06
readd ns.vie.ccc.de to our zones because zones are not delegated yet
/ build (push) Successful in 28s
/ Ansible Lint (push) Successful in 2m21s
2026-06-09 21:27:33 +02:00
471012928a
auth-dns: configure nameserver secondary solely to erfadns.ber.ccc.de
/ Ansible Lint (push) Successful in 2m26s
/ build (push) Failing after 2m42s
2026-06-09 10:31:32 +02:00
5f94d7f284
remove ns-intern.hamburg.ccc.de from notify targets of our domains
/ Ansible Lint (push) Successful in 2m35s
/ build (push) Failing after 2m43s
2026-06-06 16:26:47 +02:00
66e0095070
add zone diday.org. to authoritative DNS
2026-06-06 16:25:18 +02:00
fa6e280594
www2/www3(host): remove hosts as they got removed
/ build (push) Successful in 28s
/ Ansible Lint (push) Successful in 2m19s
2026-06-04 00:54:55 +02:00
fa598c72fc
Add opensourcetorrents
/ Ansible Lint (push) Successful in 2m27s
/ build (push) Failing after 2m42s
2026-06-01 21:15:31 +02:00
0842a51ae0
Merge branch 'main' of git.hamburg.ccc.de:CCCHH/ansible-infra
/ Ansible Lint (push) Successful in 2m21s
/ build (push) Failing after 2m38s
2026-05-24 00:12:52 +02:00
603d3fb6f4
Update machine SMTP mail sending config
2026-05-24 00:12:50 +02:00
4574dbf4ba
secrets(role): introduce secrets role for storing secrets
...
/ Ansible Lint (push) Successful in 2m18s
/ build (push) Failing after 2m40s
Allows storage of secrets to then be referenced in other places.
The motivation was storing WireGuard secrets for systemd-networkd.
2026-05-23 22:40:17 +02:00
ec27b52820
cloud: bump nextcloud to 33 and postgres 15.18
/ build (push) Failing after 2m40s
/ Ansible Lint (push) Successful in 3m2s
2026-05-20 19:49:53 +02:00
292c626629
add ns2.vie.ccc.de as dns secondary
/ build (push) Failing after 2m37s
/ Ansible Lint (push) Successful in 21m28s
2026-05-20 15:44:47 +02:00
0c83fcc2b2
sops: darios key expired, so remove for now
/ Ansible Lint (push) Successful in 2m22s
/ build (push) Successful in 24s
2026-05-20 04:09:28 +02:00
8a8ce7206d
add infrastructure-authorized-keys to lists host
/ Ansible Lint (push) Successful in 2m48s
2026-05-19 16:27:59 +02:00
6bb09901a0
add ns.vie.ccc.de. as direct secondary for authoritative DNS zones
/ Ansible Lint (push) Has been cancelled
2026-05-19 11:00:03 +02:00
a76f01aea7
Move secrets to SOPS, add REST_USER
/ Ansible Lint (push) Successful in 9m15s
2026-05-16 13:06:19 +02:00
164f784957
remove errornously added irz42 reverse-dns secondaries
/ Ansible Lint (push) Successful in 3m0s
2026-05-15 14:50:15 +02:00
18ffa42358
remove actually unused reverse-dns zones
/ Ansible Lint (push) Successful in 3m0s
2026-05-13 15:14:37 +02:00
d2f95237a0
add wieskes nameservers for reverse-dns zone transfers from auth-dns
2026-05-13 15:11:29 +02:00