diff --git a/inventories/chaosknoten/host_vars/lists.yaml b/inventories/chaosknoten/host_vars/lists.yaml index 8070d501..e6680f4b 100644 --- a/inventories/chaosknoten/host_vars/lists.yaml +++ b/inventories/chaosknoten/host_vars/lists.yaml @@ -1,7 +1,5 @@ docker_compose__compose_file_content: "{{ lookup('ansible.builtin.template', 'resources/chaosknoten/lists/docker_compose/compose.yaml.j2') }}" docker_compose__configuration_files: - - name: mailman-extra.cfg - content: "{{ lookup('ansible.builtin.file', 'resources/chaosknoten/lists/docker_compose/mailman-extra.cfg') }}" - name: settings_local.py content: "{{ lookup('ansible.builtin.file', 'resources/chaosknoten/lists/docker_compose/settings_local.py') }}" docker_compose__files: resources/chaosknoten/lists/docker_compose/files diff --git a/inventories/z9/hosts.yaml b/inventories/z9/hosts.yaml index 66519db7..ebbab18f 100644 --- a/inventories/z9/hosts.yaml +++ b/inventories/z9/hosts.yaml @@ -15,7 +15,7 @@ all: ansible_host: waybackproxy.ccchh.net ansible_user: chaos yate: - ansible_host: yate.ccchh.net + ansible_host: yate.z9.ccchh.net ansible_user: chaos z9-router: ansible_host: z9-router.ccchh.net diff --git a/resources/chaosknoten/auth-dns/zones/ccchh.net.zone b/resources/chaosknoten/auth-dns/zones/ccchh.net.zone index e5c1d251..c501167f 100644 --- a/resources/chaosknoten/auth-dns/zones/ccchh.net.zone +++ b/resources/chaosknoten/auth-dns/zones/ccchh.net.zone @@ -134,10 +134,6 @@ octopi A 10.89.212.31 ;cisco-slm248p A 10.89.208.27 -waybackproxy A 10.89.212.33 - -alnair A 10.89.210.23 - TXT "Sun SparcStation 4 Retro" ; ; Public Club Services diff --git a/resources/chaosknoten/auth-dns/zones/hh.ccc.de.zone b/resources/chaosknoten/auth-dns/zones/hh.ccc.de.zone index f603a3d1..41b7f26e 100644 --- a/resources/chaosknoten/auth-dns/zones/hh.ccc.de.zone +++ b/resources/chaosknoten/auth-dns/zones/hh.ccc.de.zone @@ -1,7 +1,15 @@ $TTL 7200 +; es wird jetzt der hostname mail.hamburg.ccc.de nicht mehr +; verwendet, sondern statt dessen local-mail.hamburg.ccc.de +; die popeye fuehlt sich immer noch unter mail.hamburg.ccc.de +; angesprochen, und nimmt daher keine mails mit absender-adressen +; die sie nicht kennt an. +; ich hoffe diese aenderung arbeitet um diesen bug herum. +; - haegar 2001.11.14 + @ IN SOA auth-dns.hamburg.ccc.de. noc.hamburg.ccc.de. ( - 2024012601 + 2024012601 10800 3600 3600000 @@ -11,18 +19,16 @@ $TTL 7200 @ NS erfadns.ber.ccc.de. IN MX 5 nomail.ccc.de. +; IN MX 10 local-mail.hamburg.ccc.de. IN MX 23 nomail2.ccc.de. IN MX 42 nomail3.ccc.de. - ; public-reverse-proxy IN A 212.12.48.125 IN AAAA 2a00:14b0:4200:3000:125::1 -; Migration von großem C officemail zu Infra in Berlin, ggf. mit vollkorn/haegar klären -officemail IN CNAME officemail.office.ccc.de. +localhost IN A 127.0.0.1 -; Alter Kram, sollte nach der Netzwerkumstellung auf Chaosknoten überflüssig sein ; DMZ-Server: dmz-net IN A 212.12.50.208 @@ -33,3 +39,35 @@ LAN-212-12-51-128 IN A 212.12.51.128 gate IN A 212.12.51.129 END-212-12-51-143 IN A 212.12.51.143 + +; convience and email + +backup IN A 172.31.16.3 + IN AAAA 2001:6f8:126f:1:16:20:0:3 +; IN MX 5 nomail.ccc.de. + IN MX 10 local-mail.hamburg.ccc.de. + +officemail IN A 172.31.17.131 + IN MX 5 nomail.ccc.de. +; IN MX 10 local-mail.hamburg.ccc.de. + IN MX 23 nomail2.ccc.de. + IN MX 42 nomail3.ccc.de. + +orga IN CNAME orga.hamburg.ccc.de. + + +; Die alte World, aka popeye.crew-gmbh.de +; Legacy-Names, do not delete +world IN A 192.76.134.7 + IN MX 10 world +popeye IN A 192.76.134.7 + IN MX 10 world +uucp IN A 192.76.134.7 + +; ChaosVPN +hack IN NS cvpn-dns.hack +cvpn-dns.hack IN A 172.31.0.5 + + +; tmp test +merz.leck.eier IN TXT "kann er mal" diff --git a/resources/chaosknoten/keycloak/docker_compose/compose.yaml.j2 b/resources/chaosknoten/keycloak/docker_compose/compose.yaml.j2 index 75c94e04..e321b2f3 100644 --- a/resources/chaosknoten/keycloak/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/keycloak/docker_compose/compose.yaml.j2 @@ -22,7 +22,7 @@ services: keycloak: - image: git.hamburg.ccc.de/ccchh/oci-images/keycloak:26.6.3 + image: git.hamburg.ccc.de/ccchh/oci-images/keycloak:26.7.2 pull_policy: always restart: unless-stopped command: start --optimized diff --git a/resources/chaosknoten/keycloak/nginx/keycloak-admin.hamburg.ccc.de.conf b/resources/chaosknoten/keycloak/nginx/keycloak-admin.hamburg.ccc.de.conf index bd819118..1420e43d 100644 --- a/resources/chaosknoten/keycloak/nginx/keycloak-admin.hamburg.ccc.de.conf +++ b/resources/chaosknoten/keycloak/nginx/keycloak-admin.hamburg.ccc.de.conf @@ -41,7 +41,7 @@ server { # Also provide "_hidden" for by, since it's not relevant. proxy_set_header Forwarded "for=$remote_addr;proto=https;host=$host;by=_hidden"; - allow 185.161.129.134/32; # z9 + allow 185.161.129.132/32; # z9 allow 2a07:c480:0:100::/56; # z9 allow 2a07:c481:1::/48; # z9 new ipv6 allow 213.240.180.39/32; # stb home diff --git a/resources/chaosknoten/lists/docker_compose/compose.yaml.j2 b/resources/chaosknoten/lists/docker_compose/compose.yaml.j2 index 2a7ffdd8..b4372c05 100644 --- a/resources/chaosknoten/lists/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/lists/docker_compose/compose.yaml.j2 @@ -77,7 +77,7 @@ services: - KEYCLOAK_CLIENT_SECRET={{ secret__lists__keycloak_client_secret }} - KEYCLOAK_REALM=ccchh - KEYCLOAK_URL=https://id.hamburg.ccc.de - - LIST_ATTRIBUTES=chaos@lists.hamburg.ccc.de:mailinglist-chaos,intern@lists.hamburg.ccc.de:mailinglist-intern + - LIST_ATTRIBUTES=chaos@lists.hamburg.ccc.de:mailinglist-chaos - MAILMAN_API_PASSWORD={{ secret__lists__rest_password }} - MAILMAN_API_URL=http://mailman-core:8001/3.1 image: git.hamburg.ccc.de/ccchh/mailman-subscription-sync:latest diff --git a/resources/chaosknoten/lists/docker_compose/mailman-extra.cfg b/resources/chaosknoten/lists/docker_compose/mailman-extra.cfg deleted file mode 100644 index 29bb00ce..00000000 --- a/resources/chaosknoten/lists/docker_compose/mailman-extra.cfg +++ /dev/null @@ -1,19 +0,0 @@ -# Override Mailman configuration settings -# See https://github.com/maxking/docker-mailman#configuration -# and https://docs.mailman3.org/projects/mailman/en/latest/src/mailman/config/docs/config.html - -[mailman] -pending_request_life: 7d - -# This address is the "site owner" address. Certain messages which must be -# delivered to a human, but which can't be delivered to a list owner (e.g. a -# bounce from a list owner), will be sent to this address. It should point to -# a human. -site_owner: listops@hamburg.ccc.de - -[mta] -# remove any pre-existing DKIM headers from mails being forwarded through a -# list -remove_dkim_headers: yes - -# eof