Commit graph ansible-infra/inventories/chaosknoten
Author SHA1 Message Date
4ffb5c18a1
use jtbx SSH key instead of PGP key and use SOPS merge for admin keys
Use jtbx SSH key instead of his PGP key and re-organize .sops.yaml
around the SOPS merge feature to accommodate admin age/SSH keys.
2026-09-24 20:11:54 +02:00
5925b22bf5
setup cccfr secondary DNS 2026-09-11 10:52:37 +02:00
4bdd36b8f7
update knot role to support more operational variety
Now secondary zones, dynamic zones, interpeted catalog zones, etc.
are supported by our knot role
2026-09-11 10:52:33 +02:00
f7c3e2146d
migrate mjolnir to draupnir 2026-09-06 14:40:45 +02:00
53c1801eba Change confirmation lifetime to 7d 2026-08-16 09:28:42 +02:00
f749ed436c Use fixed port range to allow for better fw rules 2026-08-02 17:25:30 +02:00
6eafc47773 jitsi dazu
Erstmal nur der Host, die eigentliche Config muss später passieren
2026-07-29 22:52:13 +02:00
685646c697 Set up Keycloak to Mailman sync for chaos@
DRY_RUN=true, so no changes to Mailman are performed yet.
2026-07-26 16:19:41 +02:00
647058f6ad ccchoir: stick to major version and cronjob update 2026-07-26 13:21:41 +02:00
283bc80b41 Update wordpress image 2026-07-26 00:47:54 +02:00
70b1039f95 Upgrade Hedgdedoc to 1.11.1
Closes #130

Also add appropriate config for renovate to upgrade Hedgedoc.
2026-07-24 23:26:23 +02:00
374e8f981a Update git.hamburg.ccc.de/ccchh/oci-images/nextcloud Docker tag to v34 2026-07-23 20:16:22 +00:00
1ae4a39f57 Update all stable non-major dependencies 2026-07-08 00:16:11 +00:00
9ae16363c5
forgejo-runner-external(host): configure forgejo-runner setup
Configure connection for the DI-Day/website repo.
2026-07-08 00:42:50 +02:00
dd1cd6f529
forgejo-runner-external(host): basic setup 2026-07-08 00:20:02 +02:00
d44d84ae2a
forgejo-runner(host): configure forgejo-runner setup 2026-07-03 03:42:18 +02:00
7d7cf455eb
forgejo_runner(role): create role for setting up Forgejo Runner install 2026-07-03 03:42:18 +02:00
94120337aa
forgejo-runner(host): basic setup 2026-07-03 03:42:17 +02:00
431aaefb36
dns: remove ns.vie.ccc.de from already migrated zones 2026-06-10 16:05:51 +02:00
6d922b7c8b
dns: also notify erfadns.ber.ccc.de for catalog zone changes 2026-06-10 13:12:00 +02:00
b283089b06
readd ns.vie.ccc.de to our zones because zones are not delegated yet 2026-06-09 21:27:33 +02:00
471012928a auth-dns: configure nameserver secondary solely to erfadns.ber.ccc.de 2026-06-09 10:31:32 +02:00
5f94d7f284
remove ns-intern.hamburg.ccc.de from notify targets of our domains 2026-06-06 16:26:47 +02:00
66e0095070
add zone diday.org. to authoritative DNS 2026-06-06 16:25:18 +02:00
fa6e280594
www2/www3(host): remove hosts as they got removed 2026-06-04 00:54:55 +02:00
4574dbf4ba
secrets(role): introduce secrets role for storing secrets
Allows storage of secrets to then be referenced in other places.
The motivation was storing WireGuard secrets for systemd-networkd.
2026-05-23 22:40:17 +02:00
ec27b52820
cloud: bump nextcloud to 33 and postgres 15.18 2026-05-20 19:49:53 +02:00
292c626629
add ns2.vie.ccc.de as dns secondary 2026-05-20 15:44:47 +02:00
0c83fcc2b2
sops: darios key expired, so remove for now 2026-05-20 04:09:28 +02:00
8a8ce7206d
add infrastructure-authorized-keys to lists host 2026-05-19 16:27:59 +02:00
6bb09901a0
add ns.vie.ccc.de. as direct secondary for authoritative DNS zones 2026-05-19 11:00:03 +02:00
a76f01aea7 Move secrets to SOPS, add REST_USER 2026-05-16 13:06:19 +02:00
164f784957
remove errornously added irz42 reverse-dns secondaries 2026-05-15 14:50:15 +02:00
18ffa42358
remove actually unused reverse-dns zones 2026-05-13 15:14:37 +02:00
d2f95237a0
add wieskes nameservers for reverse-dns zone transfers from auth-dns 2026-05-13 15:11:29 +02:00
50beedbc62
configure metric scraping from knot on auth-dns 2026-05-06 15:51:38 +02:00
f7306b91a6
remove unused dns zones 2026-05-06 14:37:53 +02:00
021843b5ce
migrate reverse dns zones to new auth-dns server 2026-05-06 14:33:04 +02:00
46b0a49eb8
migrate dns zone eh22.easterhegg.eu to new auth-dns server 2026-05-06 12:34:23 +02:00
d535607ae6
migrate dns zone eh20.easterhegg.eu. to new auth-dns server 2026-05-06 12:31:55 +02:00
04a6c685d1
migrate dns zone hamburg.ccc.de. to new auth-dns server 2026-05-06 12:17:51 +02:00
fa021fb737
migrate dns zone ccchh.net. to new auth-dns server 2026-05-06 12:12:54 +02:00
9ca4eb14e1
configure hh.ccc.de on auth-dns 2026-05-06 11:47:10 +02:00
becee70ab9
disable systemd-resolved on auth-dns 2026-05-06 11:47:10 +02:00
fa94d59df6
add barebones knot config
This configuration does not yet do much but it provisions a knot
server that runs.
2026-05-06 11:47:10 +02:00
d9fc1ef401
add host auth-dns.hamburg.ccc.de 2026-04-29 21:24:59 +02:00
5d16c7781c
Revert "deploy alerta on grafana.hosts.hamburg.ccc.de"
This reverts commit b10d7d1592.
2026-04-29 19:05:15 +02:00
d7811f249a
diday-staging-runner(host): deploy host runner for diday staging deploy 2026-04-28 20:12:27 +02:00
b10d7d1592
deploy alerta on grafana.hosts.hamburg.ccc.de 2026-04-24 19:05:08 +02:00
26fbbc9035
sops: use fis new key 2026-04-19 00:36:37 +02:00