From b0620fbfd1ec55ce813b817a770424786b2ab948 Mon Sep 17 00:00:00 2001 From: Renovate Date: Thu, 17 Sep 2026 08:31:35 +0000 Subject: [PATCH 1/2] Update all stable non-major dependencies --- .forgejo/workflows/lint.yaml | 2 +- inventories/chaosknoten/host_vars/cloud.yaml | 2 +- inventories/chaosknoten/host_vars/netbox.yaml | 2 +- inventories/chaosknoten/host_vars/pad.yaml | 2 +- .../chaosknoten/grafana/docker_compose/compose.yaml.j2 | 8 ++++---- resources/chaosknoten/ntfy/docker_compose/compose.yaml.j2 | 2 +- .../chaosknoten/pretalx/docker_compose/compose.yaml.j2 | 2 +- .../chaosknoten/tickets/docker_compose/compose.yaml.j2 | 2 +- resources/external/status/docker_compose/compose.yaml.j2 | 2 +- 9 files changed, 12 insertions(+), 12 deletions(-) diff --git a/.forgejo/workflows/lint.yaml b/.forgejo/workflows/lint.yaml index 5c1b82ac..6dc4a0c9 100644 --- a/.forgejo/workflows/lint.yaml +++ b/.forgejo/workflows/lint.yaml @@ -24,7 +24,7 @@ jobs: # work in our environmnet. # Rather manually setup python (pip) before instead. - name: Run ansible-lint - uses: https://github.com/ansible/ansible-lint@v26.6.0 + uses: https://github.com/ansible/ansible-lint@v26.8.0 with: setup_python: "false" requirements_file: "requirements.yml" diff --git a/inventories/chaosknoten/host_vars/cloud.yaml b/inventories/chaosknoten/host_vars/cloud.yaml index 8f299b2d..a441ac84 100644 --- a/inventories/chaosknoten/host_vars/cloud.yaml +++ b/inventories/chaosknoten/host_vars/cloud.yaml @@ -1,7 +1,7 @@ # renovate: datasource=docker depName=git.hamburg.ccc.de/ccchh/oci-images/nextcloud nextcloud__version: 34 # renovate: datasource=docker depName=docker.io/library/postgres -nextcloud__postgres_version: 15.18 +nextcloud__postgres_version: 15.19 nextcloud__fqdn: cloud.hamburg.ccc.de nextcloud__data_dir: /data/nextcloud nextcloud__extra_configuration: "{{ lookup('ansible.builtin.template', 'resources/chaosknoten/cloud/nextcloud/extra_configuration.config.php.j2') }}" diff --git a/inventories/chaosknoten/host_vars/netbox.yaml b/inventories/chaosknoten/host_vars/netbox.yaml index 312b1d70..5bcd1d60 100644 --- a/inventories/chaosknoten/host_vars/netbox.yaml +++ b/inventories/chaosknoten/host_vars/netbox.yaml @@ -1,5 +1,5 @@ # renovate: datasource=github-releases depName=netbox packageName=netbox-community/netbox -netbox__version: "v4.6.4" +netbox__version: "v4.7.1" netbox__config: "{{ lookup('ansible.builtin.template', 'resources/chaosknoten/netbox/netbox/configuration.py.j2') }}" netbox__custom_pipeline_oidc_group_and_role_mapping: true diff --git a/inventories/chaosknoten/host_vars/pad.yaml b/inventories/chaosknoten/host_vars/pad.yaml index 0c9b29ea..c2fa834f 100644 --- a/inventories/chaosknoten/host_vars/pad.yaml +++ b/inventories/chaosknoten/host_vars/pad.yaml @@ -13,4 +13,4 @@ nginx__configurations: content: "{{ lookup('ansible.builtin.file', 'resources/chaosknoten/pad/nginx/pad.hamburg.ccc.de.conf') }}" # renovate: datasource=docker depName=quay.io/hedgedoc/hedgedoc -host_pad__docker_compose__hedgedoc_version: 1.11.1 +host_pad__docker_compose__hedgedoc_version: 1.12.0 diff --git a/resources/chaosknoten/grafana/docker_compose/compose.yaml.j2 b/resources/chaosknoten/grafana/docker_compose/compose.yaml.j2 index f08c7994..ddeb43e6 100644 --- a/resources/chaosknoten/grafana/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/grafana/docker_compose/compose.yaml.j2 @@ -2,7 +2,7 @@ services: prometheus: - image: docker.io/prom/prometheus:v3.13.1 + image: docker.io/prom/prometheus:v3.14.0 container_name: prometheus command: - '--config.file=/etc/prometheus/prometheus.yml' @@ -19,7 +19,7 @@ services: - prom_data:/prometheus alertmanager: - image: docker.io/prom/alertmanager:v0.33.1 + image: docker.io/prom/alertmanager:v0.34.1 container_name: alertmanager command: - '--config.file=/etc/alertmanager/alertmanager.yaml' @@ -32,7 +32,7 @@ services: - alertmanager_data:/alertmanager grafana: - image: docker.io/grafana/grafana:13.1.0 + image: docker.io/grafana/grafana:13.2.2 container_name: grafana ports: - 3000:3000 @@ -46,7 +46,7 @@ services: - graf_data:/var/lib/grafana pve-exporter: - image: docker.io/prompve/prometheus-pve-exporter:3.9.0 + image: docker.io/prompve/prometheus-pve-exporter:3.10.0 container_name: pve-exporter ports: - 9221:9221 diff --git a/resources/chaosknoten/ntfy/docker_compose/compose.yaml.j2 b/resources/chaosknoten/ntfy/docker_compose/compose.yaml.j2 index a982bf3a..dcb1669d 100644 --- a/resources/chaosknoten/ntfy/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/ntfy/docker_compose/compose.yaml.j2 @@ -1,7 +1,7 @@ --- services: ntfy: - image: docker.io/binwiederhier/ntfy:v2.26.0 + image: docker.io/binwiederhier/ntfy:v2.28.0 container_name: ntfy command: - serve diff --git a/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 b/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 index 3c6e5daa..d5c4c9fd 100644 --- a/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/pretalx/docker_compose/compose.yaml.j2 @@ -15,7 +15,7 @@ services: - pretalx_net redis: - image: docker.io/library/redis:8.8.0 + image: docker.io/library/redis:8.10.1 restart: unless-stopped volumes: - redis:/data diff --git a/resources/chaosknoten/tickets/docker_compose/compose.yaml.j2 b/resources/chaosknoten/tickets/docker_compose/compose.yaml.j2 index 9eac87ca..df06e559 100644 --- a/resources/chaosknoten/tickets/docker_compose/compose.yaml.j2 +++ b/resources/chaosknoten/tickets/docker_compose/compose.yaml.j2 @@ -13,7 +13,7 @@ services: restart: unless-stopped redis: - image: docker.io/library/redis:8.8.0 + image: docker.io/library/redis:8.10.1 ports: - "6379:6379" volumes: diff --git a/resources/external/status/docker_compose/compose.yaml.j2 b/resources/external/status/docker_compose/compose.yaml.j2 index 638ebbe2..3d3cb7af 100644 --- a/resources/external/status/docker_compose/compose.yaml.j2 +++ b/resources/external/status/docker_compose/compose.yaml.j2 @@ -4,7 +4,7 @@ services: database: - image: docker.io/library/postgres:18.4 + image: docker.io/library/postgres:18.6 restart: always volumes: - ./database:/var/lib/postgresql From ee810bfc16750bce65d05680da1a1bbe9dc18ac5 Mon Sep 17 00:00:00 2001 From: lilly Date: Fri, 18 Sep 2026 17:45:46 +0200 Subject: [PATCH 2/2] update matrix moderation docs to reflect that we now have two ban lists --- docs/concepts-and-configurations/matrix-moderation.md | 7 ++++--- docs/guides/matrix-taking-moderation-action.md | 6 ++++-- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/docs/concepts-and-configurations/matrix-moderation.md b/docs/concepts-and-configurations/matrix-moderation.md index fc307645..b1c16edd 100644 --- a/docs/concepts-and-configurations/matrix-moderation.md +++ b/docs/concepts-and-configurations/matrix-moderation.md @@ -27,9 +27,10 @@ The bot account `@moderation:hamburg.ccc.de` (Draupnir) maintains various intern These can include, for example, user bans or entire server bans. Additionally, certain automatic monitoring measures (so-called "protections") apply in these rooms, which trigger a configured action if violated. For example, a user is not allowed to tag too many other users in a single message, as this is considered spam and results in a kick. -The bot is controlled and configured via a privileged *CCCHH Moderation Management* room using `!mjolnir` commands. +The bot is controlled and configured via a privileged *CCCHH Moderation Management* room using `!draupnir` commands. There, individual actions can also be triggered through the bot as needed, such as redacting messages, kicking users from all or some channels, etc. -It is also possible to make our moderation bot's local lists available to other entities and subscribe our bot to other entities' lists. -Our list is published in `#general-moderation:hamburg.ccc.de` where other moderation bots can freely watch it. +Currently we operate **two policy lists**: One for internal bans like "Hausverbot" or similar and one for general misconduct like harassment and spam. +It is possible to make our general list available to other entities as well as subscribe our bot to other entities' lists. +Our general list is published in `#general-moderation:hamburg.ccc.de` where other moderation bots can freely watch it. diff --git a/docs/guides/matrix-taking-moderation-action.md b/docs/guides/matrix-taking-moderation-action.md index a516989c..2f1e467c 100644 --- a/docs/guides/matrix-taking-moderation-action.md +++ b/docs/guides/matrix-taking-moderation-action.md @@ -18,18 +18,20 @@ All bot actions are triggered through the *CCCHH Moderation Management* room. ## Banning a User ``` -!draupnir ban user general +!draupnir ban user ``` +- `` either `general` for general misconduct or `internal` for CCCHH-internal reasons - `` can be a user ID (e.g. `@example:matrix.org`) but also more sophisticated. Be careful when using actual glob syntax as whole servers can be banned even if just a single user is the intended target. - `` is technically optional but should always be supplied so that we know why a certain user was banned in retrospect. The bot supports parsing quotations so `""` is usually what you want if more than one word is used. ## Banning a Server ``` -!draupnir ban server general +!draupnir ban server ``` +- `` either `general` for general misconduct or `internal` for CCCHH-internal reasons - `` can be used to ban subdomains of a domain too, e.g. `*.example.com`. If used, an additional `--force` is required after the whole command. - `` should be supplied and supports quotation (`"") if more than one word is used - When a domain is banned, we usually also ban all subdomains too. This needs to be done in two separate commands.