From 4d92340f9b47ddab76442fc441e17f43cccc9a65 Mon Sep 17 00:00:00 2001 From: Christoph Date: Tue, 28 Jul 2026 21:24:03 +0200 Subject: [PATCH] chore(ansible): clean up host_vars YAML and normalize mail text blocks --- .vscode/settings.json | 5 +- host_vars/a.mx.oopen.de/a.mx-common.yml | 116 ++++++------------ host_vars/a.mx.oopen.de/a.mx-ipt-server.yml | 2 +- host_vars/a.ns.oopen.de/a.ns-common.yml | 89 +++++++------- host_vars/ak-plan.oopen.de/ak-plan-common.yml | 25 ++-- host_vars/anita.wf.netz/anita-common.yml | 8 +- .../at-10-neu.ak.netz/at-10-neu-common.yml | 13 +- host_vars/b.mx.oopen.de/b.mx-common.yml | 25 ++-- host_vars/b.ns.oopen.de/b.ns-common.yml | 88 ++++++------- host_vars/backup.oopen.de/backup-common.yml | 25 ++-- .../backup.warenform.de/backup-common.yml | 3 - .../bbb-server-common.yml | 17 ++- host_vars/c.mx.oopen.de/c.mx-common.yml | 114 ++++++----------- host_vars/cl-01.oopen.de/cl-01-common.yml | 25 ++-- host_vars/cl-02.oopen.de/cl-02-common.yml | 5 +- .../cl-dissens.oopen.de/cl-dissens-common.yml | 25 ++-- host_vars/cl-flr.oopen.de/cl-flr-common.yml | 25 ++-- host_vars/cl-fm.oopen.de/cl-fm-common.yml | 25 ++-- .../cl-irights.oopen.de/cl-irights-common.yml | 5 +- .../cl-lubax.oopen.de/cl-lubax-common.yml | 27 ++-- .../cl-lubax.oopen.de/cl-lubax-ipt-server.yml | 2 +- host_vars/cl-nd.oopen.de/cl-nd-common.yml | 25 ++-- host_vars/cl-ndm.oopen.de/cl-ndm-common.yml | 25 ++-- host_vars/cl-opp.oopen.de/cl-opp-common.yml | 25 ++-- host_vars/cl-test.oopen.de/cl-test-common.yml | 25 ++-- host_vars/cl-vbrg.oopen.de/cl-vbrg-common.yml | 1 - .../cloud-giz-common.yml | 1 - host_vars/cloud.akweb.de/cloud-common.yml | 5 +- host_vars/cp-01.oopen.de/cp-01-common.yml | 25 ++-- host_vars/cp-flr.oopen.de/cp-flr-common.yml | 25 ++-- host_vars/d.mx.oopen.de/d.mx-common.yml | 25 ++-- host_vars/dc-opp.oopen.de/dc-opp-common.yml | 25 ++-- .../devel-cloud-common.yml | 8 +- .../devel-db.wf.netz/devel-db-common.yml | 7 +- .../devel-php.wf.netz/devel-php-common.yml | 7 +- .../devel-repos-common.yml | 7 +- .../devel-root.wf.netz/devel-root-common.yml | 7 +- .../devel-wiki.wf.netz/devel-wiki-common.yml | 7 +- host_vars/dns0.warenform.de/dns0-common.yml | 19 ++- host_vars/dns1.warenform.de/dns1-common.yml | 25 ++-- host_vars/e.mx.oopen.de/e.mx-common.yml | 95 +++++--------- .../file-ah-common.yml | 20 ++- .../file-blkr-alt-common.yml | 13 +- .../file-blkr.blkr.netz/file-blkr-common.yml | 45 ++++--- .../file-dissens-common.yml | 48 ++++---- .../file-ebs.ebs.netz/file-ebs-common.yml | 39 +++--- .../file-fhxb.fhxb.netz/file-fhxb-common.yml | 101 ++++++++------- host_vars/file-fm.fm.netz/file-fm-common.yml | 48 ++++---- .../file-ipa.local.netz/file-ipa-common.yml | 3 +- .../file-kb.anw-kb.netz/file-kb-common.yml | 5 +- .../file-km-alt-common.yml | 19 ++- .../file-km.anw-km.netz/file-km-common.yml | 13 +- .../formbricks-nd-common.yml | 26 ++-- host_vars/g.mx.oopen.de/g.mx-common.yml | 72 +++-------- .../ga-al-gw.oopen.de/ga-al-gw-common.yml | 38 +++--- .../ga-al-kvm2.ga.netz/ga-al-kvm2-common.yml | 1 - .../ga-al-kvm3.ga.netz/ga-al-kvm3-common.yml | 1 - .../ga-al-relay-common.yml | 25 ++-- .../ga-campus-gw-temp-common.yml | 33 +++-- .../ga-gh-gw.oopen.de/ga-gh-gw-common.yml | 29 +++-- .../ga-nh-gw.oopen.de/ga-nh-gw-common.yml | 33 +++-- .../ga-st-gw-ersatz-common.yml | 28 ++--- .../ga-st-gw.ga.netz/ga-st-gw-common.yml | 36 +++--- .../ga-st-kvm1.ga.netz/ga-st-kvm1-common.yml | 1 - .../ga-st-kvm5.ga.netz/ga-st-kvm5-common.yml | 5 +- .../ga-st-lxc1.ga.netz/ga-st-lxc1-common.yml | 21 ++-- .../ga-st-mail.ga.netz/ga-st-mail-common.yml | 17 ++- .../ga-st-mm.ga.netz/ga-st-mm-common.yml | 5 +- .../ga-st-services-common.yml | 9 +- host_vars/git.oopen.de/git-common.yml | 25 ++-- host_vars/git.warenform.de/git-common.yml | 2 - host_vars/gitea.so36.net/gitea-common.yml | 20 +-- host_vars/gw-123.oopen.de/gw-123-common.yml | 5 +- host_vars/gw-ah.oopen.de/gw-ah-common.yml | 21 ++-- host_vars/gw-ak.oopen.de/gw-ak-common.yml | 15 ++- host_vars/gw-akb.oopen.de/gw-akb-common.yml | 7 +- host_vars/gw-b3.oopen.de/gw-b3-common.yml | 7 +- host_vars/gw-blkr.oopen.de/gw-blkr-common.yml | 19 ++- .../gw-campus.oopen.de/gw-campus-common.yml | 35 +++--- .../gw-ckubu.local.netz/gw-ckubu-common.yml | 6 +- host_vars/gw-d11.oopen.de/gw-d11-common.yml | 5 +- .../gw-dissens.oopen.de/gw-dissens-common.yml | 25 ++-- host_vars/gw-ebs.oopen.de/gw-ebs-common.yml | 27 ++-- .../gw-elster.oopen.de/gw-elster-common.yml | 36 +++--- host_vars/gw-fhxb.oopen.de/gw-fhxb-common.yml | 15 ++- host_vars/gw-flr.oopen.de/gw-flr-common.yml | 19 ++- host_vars/gw-fm.oopen.de/gw-fm-common.yml | 11 +- .../gw-irights.oopen.de/gw-irights-common.yml | 15 ++- host_vars/gw-kb.oopen.de/gw-kb-common.yml | 13 +- host_vars/gw-km.oopen.de/gw-km-common.yml | 13 +- host_vars/gw-mbr.oopen.de/gw-mbr-common.yml | 27 ++-- .../gw-opp-neu.opp.netz/gw-opp-neu-common.yml | 15 ++- host_vars/gw-opp.oopen.de/gw-opp-common.yml | 15 ++- .../gw-replacement4-common.yml | 5 +- .../gw-replacment-common.yml | 7 +- .../gw-replacment2-common.yml | 7 +- .../gw-replacment3-common.yml | 7 +- host_vars/gw-spr.oopen.de/gw-spr-common.yml | 5 +- host_vars/iam-nd.oopen.de/iam-nd-common.yml | 26 ++-- .../initiativenserver-common.yml | 6 +- .../keycloak-nd-common.yml | 26 ++-- .../lists.mx.warenform.de/lists.mx-common.yml | 50 +++----- .../lxc-host-kb-common.yml | 8 +- .../mail-neu.cadus.org/mail-neu-common.yml | 11 +- host_vars/mail.cadus.org/mail-common.yml | 53 ++++---- .../mail.faire-mobilitaet.de/mail-common.yml | 106 ++++++---------- .../matomo-01.oopen.de/matomo-01-common.yml | 25 ++-- host_vars/meet.akweb.de/meet-common.yml | 25 ++-- host_vars/meet.oopen.de/meet-common.yml | 48 ++++---- .../mm-irights.oopen.de/mm-irights-common.yml | 25 ++-- .../mm-migration-common.yml | 25 ++-- host_vars/mm-rav.oopen.de/mm-rav-common.yml | 25 ++-- host_vars/mm.oopen.de/mm-common.yml | 25 ++-- host_vars/moodle.oopen.de/moodle-common.yml | 15 ++- host_vars/munin.oopen.de/munin-common.yml | 25 ++-- host_vars/mx.warenform.de/mx-common.yml | 102 +++++---------- host_vars/nc-gw.oopen.de/nc-gw-common.yml | 1 - .../nd-archiv-common.yml | 8 +- .../nd-live.warenform.de/nd-live-common.yml | 8 +- host_vars/nd.warenform.de/nd-common.yml | 8 +- host_vars/nscache.oopen.de/nscache-common.yml | 1 - host_vars/o12.oopen.de/o12-common.yml | 40 +++--- .../o13-cryptpad-common.yml | 7 +- .../o13-mail.oopen.de/o13-mail-common.yml | 53 +------- .../o13-mumble.oopen.de/o13-mumble-common.yml | 7 +- host_vars/o13-pad.oopen.de/o13-pad-common.yml | 7 +- .../o13-staging-board-common.yml | 8 +- host_vars/o13-web.oopen.de/o13-web-common.yml | 7 +- host_vars/o13.oopen.de/o13-common.yml | 11 +- host_vars/o17.oopen.de/o17-common.yml | 35 +++--- host_vars/o18.oopen.de/o18-common.yml | 32 +++-- host_vars/o19.oopen.de/o19-common.yml | 33 +++-- host_vars/o20.oopen.de/o20-common.yml | 7 +- host_vars/o21.oopen.de/o21-common.yml | 34 +++-- host_vars/o22.oopen.de/o22-common.yml | 35 +++--- host_vars/o23.oopen.de/o23-common.yml | 21 ++-- host_vars/o24.oopen.de/o24-common.yml | 19 ++- host_vars/o25.oopen.de/o25-common.yml | 39 +++--- host_vars/o26.oopen.de/o26-common.yml | 44 +++---- host_vars/o27.oopen.de/o27-common.yml | 15 ++- host_vars/o28.oopen.de/o28-common.yml | 32 +++-- host_vars/o29.oopen.de/o29-common.yml | 18 ++- host_vars/o30.oopen.de/o30-common.yml | 14 +-- host_vars/o31.oopen.de/o31-common.yml | 15 +-- host_vars/o32.oopen.de/o32-common.yml | 16 ++- host_vars/o33-neu.oopen.de/o33-neu-common.yml | 4 +- host_vars/o34.oopen.de/o34-common.yml | 18 ++- host_vars/o35.oopen.de/o35-common.yml | 19 ++- host_vars/o36.oopen.de/o36-common.yml | 32 +++-- host_vars/o38.oopen.de/o38-common.yml | 34 +++-- host_vars/o39.oopen.de/o39-common.yml | 35 +++--- host_vars/o40.oopen.de/o40-common.yml | 11 +- host_vars/o41.oopen.de/o41-common.yml | 28 ++--- host_vars/o42.oopen.de/o42-common.yml | 33 +++-- host_vars/o43.oopen.de/o43-common.yml | 37 +++--- host_vars/o44.oopen.de/o44-common.yml | 33 +++-- host_vars/oolm-db.oopen.de/oolm-db-common.yml | 5 +- .../oolm-shop-dev-common.yml | 30 ++--- .../oolm-shop.oopen.de/oolm-shop-common.yml | 10 +- .../oolm-web.oopen.de/oolm-web-common.yml | 6 +- host_vars/piwik.warenform.de/piwik-common.yml | 5 +- .../prometheus-nd-common.yml | 26 ++-- .../psono-ndm.oopen.de/psono-ndm-common.yml | 29 +++-- host_vars/rage.so36.net/rage-common.yml | 60 +-------- .../server16.warenform.de/server16-common.yml | 10 +- .../server18.warenform.de/server18-common.yml | 18 ++- .../server20.warenform.de/server20-common.yml | 10 +- .../server22.warenform.de/server22-common.yml | 16 ++- .../server23.warenform.de/server23-common.yml | 36 +++--- .../server24.warenform.de/server24-common.yml | 19 ++- .../server25.warenform.de/server25-common.yml | 16 ++- .../server26.warenform.de/server26-common.yml | 18 ++- .../server27.warenform.de/server27-common.yml | 18 ++- .../server28.warenform.de/server28-common.yml | 19 ++- .../shop-dev-common.yml | 28 ++--- .../stolpersteine-common.yml | 29 +++-- .../test.mariadb-common.yml | 4 +- host_vars/test.mx.oopen.de/test.mx-common.yml | 8 +- .../verdi-django-common.yml | 5 +- .../vvn-shop.warenform.de/vvn-shop-common.yml | 5 +- .../vvn-www.warenform.de/vvn-www-common.yml | 5 +- host_vars/web-01.oopen.de/web-01-common.yml | 6 +- host_vars/web-02.oopen.de/web-02-common.yml | 5 +- host_vars/web-03.oopen.de/web-03-common.yml | 6 +- host_vars/web-04.oopen.de/web-04-common.yml | 6 +- host_vars/web-05.oopen.de/web-05-common.yml | 6 +- host_vars/web-06.oopen.de/web-06-common.yml | 6 +- host_vars/web-07.oopen.de/web-07-common.yml | 6 +- host_vars/web-08.oopen.de/web-08-common.yml | 6 +- host_vars/web-09.oopen.de/web-09-common.yml | 8 +- host_vars/web-nd.oopen.de/web-nd-common.yml | 26 ++-- .../web-test.oopen.de/web-test-common.yml | 5 +- host_vars/web.cadus.org/web-common.yml | 27 ++-- host_vars/web0.warenform.de/web0-common.yml | 17 +-- host_vars/web1.warenform.de/web1-common.yml | 5 +- host_vars/web2.warenform.de/web2-common.yml | 5 +- host_vars/wiki.cadus.org/wiki-common.yml | 27 ++-- host_vars/www.oopen.de/www-common.yml | 1 - .../zapata-alt.opp.netz/zapata-alt-common.yml | 17 ++- host_vars/zapata.opp.netz/zapata-common.yml | 19 ++- .../postfwd.bl-recipient-exeeds-msg-size-20mb | 0 .../etc/postfix/postfwd.wl-user | 0 .../root/.ssh/a.mx-id_rsa-dehydrated | 0 .../root/.ssh/a.mx-id_rsa-dehydrated.pub | 0 .../root/.ssh/a.mx-id_rsa-opendkim | 0 .../root/.ssh/a.mx-id_rsa-opendkim.pub | 0 .../conf/check_cert_for_dovecot.conf | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../postfix/conf/postfix_add_mailboxes.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../root/bin/bind/conf/bind.conf | 2 + .../bind/conf/bind_add_dkim_zone_slave.conf | 2 + .../bind/conf/create_master_zone_file.conf | 82 +++++++++++++ .../etc/postfix/postfwd.wl-nets | 0 .../etc/postfix/postfwd.wl-sender | 0 .../etc/postfix/relay_domains | 0 .../root/.ssh/b.mx-id_rsa-dehydrated | 0 .../root/.ssh/b.mx-id_rsa-dehydrated.pub | 0 .../root/.ssh/b.mx-id_rsa-opendkim | 0 .../root/.ssh/b.mx-id_rsa-opendkim.pub | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../bind/conf/bind_add_dkim_zone_master.conf | 2 + .../root/.ssh/c.mx-id_rsa | 0 .../root/.ssh/c.mx-id_rsa-dehydrated | 0 .../root/.ssh/c.mx-id_rsa-dehydrated.pub | 0 .../root/.ssh/c.mx-id_rsa-opendkim | 0 .../root/.ssh/c.mx-id_rsa-opendkim.pub | 0 .../root/.ssh/c.mx-id_rsa.pub | 0 .../conf/check_cert_for_dovecot.conf | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../postfix/conf/postfix_add_mailboxes.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../root/.ssh/d.mx-id_rsa-dehydrated | 0 .../root/.ssh/d.mx-id_rsa-dehydrated.pub | 0 .../root/.ssh/d.mx-id_rsa-opendkim | 0 .../root/.ssh/d.mx-id_rsa-opendkim.pub | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../local/src/sympa/conf/install_sympa.conf | 0 .../etc/postfix/postfwd.wl-nets | 0 .../etc/postfix/relay_domains | 0 .../root/.ssh/g.mx-id_ed25519-dehydrated | 0 .../root/.ssh/g.mx-id_ed25519-dehydrated.pub | 0 .../root/.ssh/g.mx-id_ed25519-opendkim | 0 .../root/.ssh/g.mx-id_ed25519-opendkim.pub | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../etc/postfix/relay_domains | 0 .../root/.ssh/ga-st-mail-id_rsa-dehydrated | 0 .../.ssh/ga-st-mail-id_rsa-dehydrated.pub | 0 .../root/.ssh/ga-st-mail-id_rsa-opendkim | 0 .../root/.ssh/ga-st-mail-id_rsa-opendkim.pub | 0 .../etc/postfix/postfwd.cf | 0 .../root/.ssh/ga-st-mail-id_rsa-dehydrated | 49 ++++++++ .../.ssh/ga-st-mail-id_rsa-dehydrated.pub | 1 + .../root/.ssh/ga-st-mail-id_rsa-opendkim | 49 ++++++++ .../root/.ssh/ga-st-mail-id_rsa-opendkim.pub | 1 + .../conf/check_cert_for_dovecot.conf | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../postfix/conf/postfix_add_mailboxes.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../.ssh/lists.mx.warenform-id_rsa-opendkim | 0 .../lists.mx.warenform-id_rsa-opendkim.pub | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../local/src/sympa/conf/install_sympa.conf | 0 .../postfix/postfwd.high-rate-number-messages | 0 .../etc/postfix/postfwd.wl-nets | 0 .../etc/postfix/postfwd.wl-sender | 0 .../etc/postfix/postfwd.wl-user | 0 .../root/.ssh/mail.cadus-id_rsa-dehydrated | 0 .../.ssh/mail.cadus-id_rsa-dehydrated.pub | 0 .../root/.ssh/mail.cadus-id_rsa-opendkim | 0 .../root/.ssh/mail.cadus-id_rsa-opendkim.pub | 0 .../conf/check_cert_for_dovecot.conf | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../postfix/conf/postfix_add_mailboxes.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../mail.faire-mobilitaet-id_rsa-dehydrated | 0 ...ail.faire-mobilitaet-id_rsa-dehydrated.pub | 0 .../mail.faire-mobilitaet-id_rsa-opendkim | 0 .../mail.faire-mobilitaet-id_rsa-opendkim.pub | 0 .../conf/check_cert_for_dovecot.conf | 0 .../bin/postfix/conf/create_opendkim_key.conf | 0 .../postfix/conf/postfix_add_mailboxes.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 .../bin/postfix/conf/whitelist_mb_sigs.conf | 0 .../etc/postfix/postfwd.wl-hosts | 0 .../etc/postfix/postfwd.wl-nets | 0 .../etc/postfix/postfwd.wl-sender | 0 .../etc/postfix/postfwd.wl-user | 0 .../conf/check_cert_for_dovecot.conf | 0 .../conf/check-postfix-fatal-errors.conf | 0 .../etc/postfix/postfwd.wl-hosts | 0 .../etc/postfix/postfwd.wl-nets | 0 .../etc/postfix/postfwd.wl-sender | 0 .../etc/postfix/postfwd.wl-user | 0 .../conf/check_cert_for_dovecot.conf | 0 .../conf/check-postfix-fatal-errors.conf | 0 .../get_number_of_deferred_mailqueue.conf | 0 .../postfix/conf/sent_userinfo_postfix.conf | 0 306 files changed, 2049 insertions(+), 2484 deletions(-) rename roles/common/files/{a.mx => a.mx.oopen.de}/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/etc/postfix/postfwd.wl-user (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/.ssh/a.mx-id_rsa-dehydrated (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/.ssh/a.mx-id_rsa-dehydrated.pub (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/.ssh/a.mx-id_rsa-opendkim (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/.ssh/a.mx-id_rsa-opendkim.pub (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/bin/postfix/conf/postfix_add_mailboxes.conf (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) rename roles/common/files/{a.mx => a.mx.oopen.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{a.ns => a.ns.oopen.de}/root/bin/bind/conf/bind.conf (96%) rename roles/common/files/{a.ns => a.ns.oopen.de}/root/bin/bind/conf/bind_add_dkim_zone_slave.conf (92%) create mode 100644 roles/common/files/a.ns.oopen.de/root/bin/bind/conf/create_master_zone_file.conf rename roles/common/files/{b.mx => b.mx.oopen.de}/etc/postfix/postfwd.wl-nets (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/etc/postfix/postfwd.wl-sender (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/etc/postfix/relay_domains (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/.ssh/b.mx-id_rsa-dehydrated (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/.ssh/b.mx-id_rsa-dehydrated.pub (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/.ssh/b.mx-id_rsa-opendkim (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/.ssh/b.mx-id_rsa-opendkim.pub (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{b.mx => b.mx.oopen.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{b.ns => b.ns.oopen.de}/root/bin/bind/conf/bind_add_dkim_zone_master.conf (94%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa-dehydrated (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa-dehydrated.pub (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa-opendkim (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa-opendkim.pub (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/.ssh/c.mx-id_rsa.pub (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/bin/postfix/conf/postfix_add_mailboxes.conf (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) rename roles/common/files/{c.mx => c.mx.oopen.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/.ssh/d.mx-id_rsa-dehydrated (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/.ssh/d.mx-id_rsa-dehydrated.pub (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/.ssh/d.mx-id_rsa-opendkim (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/.ssh/d.mx-id_rsa-opendkim.pub (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{d.mx => d.mx.oopen.de}/usr/local/src/sympa/conf/install_sympa.conf (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/etc/postfix/postfwd.wl-nets (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/etc/postfix/relay_domains (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/.ssh/g.mx-id_ed25519-dehydrated (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/.ssh/g.mx-id_ed25519-dehydrated.pub (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/.ssh/g.mx-id_ed25519-opendkim (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/.ssh/g.mx-id_ed25519-opendkim.pub (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{g.mx => g.mx.oopen.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{ga-al-relay => ga-al-relay.ga.netz}/etc/postfix/relay_domains (100%) rename roles/common/files/{ga-st-mail => ga-al-relay.ga.netz}/root/.ssh/ga-st-mail-id_rsa-dehydrated (100%) rename roles/common/files/{ga-st-mail => ga-al-relay.ga.netz}/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub (100%) rename roles/common/files/{ga-st-mail => ga-al-relay.ga.netz}/root/.ssh/ga-st-mail-id_rsa-opendkim (100%) rename roles/common/files/{ga-st-mail => ga-al-relay.ga.netz}/root/.ssh/ga-st-mail-id_rsa-opendkim.pub (100%) rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/etc/postfix/postfwd.cf (100%) create mode 100644 roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated create mode 100644 roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub create mode 100644 roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim create mode 100644 roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/root/bin/postfix/conf/postfix_add_mailboxes.conf (100%) rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) rename roles/common/files/{ga-st-mail => ga-st-mail.ga.netz}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{lists.mx.warenform => lists.mx.warenform.de}/root/.ssh/lists.mx.warenform-id_rsa-opendkim (100%) rename roles/common/files/{lists.mx.warenform => lists.mx.warenform.de}/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub (100%) rename roles/common/files/{lists.mx.warenform => lists.mx.warenform.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{lists.mx.warenform => lists.mx.warenform.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{lists.mx.warenform => lists.mx.warenform.de}/usr/local/src/sympa/conf/install_sympa.conf (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/etc/postfix/postfwd.high-rate-number-messages (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/etc/postfix/postfwd.wl-nets (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/etc/postfix/postfwd.wl-sender (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/etc/postfix/postfwd.wl-user (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/.ssh/mail.cadus-id_rsa-dehydrated (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/.ssh/mail.cadus-id_rsa-dehydrated.pub (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/.ssh/mail.cadus-id_rsa-opendkim (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/.ssh/mail.cadus-id_rsa-opendkim.pub (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/bin/postfix/conf/postfix_add_mailboxes.conf (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) rename roles/common/files/{mail.cadus => mail.cadus.org}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/bin/postfix/conf/create_opendkim_key.conf (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/bin/postfix/conf/postfix_add_mailboxes.conf (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) rename roles/common/files/{mail.faire-mobilitaet => mail.faire-mobilitaet.de}/root/bin/postfix/conf/whitelist_mb_sigs.conf (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/etc/postfix/postfwd.wl-hosts (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/etc/postfix/postfwd.wl-nets (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/etc/postfix/postfwd.wl-sender (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/etc/postfix/postfwd.wl-user (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{o13-mail => o13-mail.oopen.de}/root/bin/postfix/conf/check-postfix-fatal-errors.conf (100%) rename roles/common/files/{rage => rage.so36.net}/etc/postfix/postfwd.wl-hosts (100%) rename roles/common/files/{rage => rage.so36.net}/etc/postfix/postfwd.wl-nets (100%) rename roles/common/files/{rage => rage.so36.net}/etc/postfix/postfwd.wl-sender (100%) rename roles/common/files/{rage => rage.so36.net}/etc/postfix/postfwd.wl-user (100%) rename roles/common/files/{rage => rage.so36.net}/root/bin/monitoring/conf/check_cert_for_dovecot.conf (100%) rename roles/common/files/{rage => rage.so36.net}/root/bin/postfix/conf/check-postfix-fatal-errors.conf (100%) rename roles/common/files/{rage => rage.so36.net}/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf (100%) rename roles/common/files/{rage => rage.so36.net}/root/bin/postfix/conf/sent_userinfo_postfix.conf (100%) diff --git a/.vscode/settings.json b/.vscode/settings.json index dcb168d..4deca0f 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -14,5 +14,8 @@ "ansible.ansible.path": "/home/chris/devel/git/git.oopen.de/ansible/oopen-server/.venv/bin/ansible", "ansible.python.interpreterPath": "${workspaceFolder}/.venv/bin/python3", "ansible.validation.lint.path": "/home/chris/devel/git/git.oopen.de/ansible/oopen-server/.venv/bin/ansible-lint", - "ansible.ansibleNavigator.path": "/home/chris/devel/git/git.oopen.de/ansible/oopen-server/.venv/bin/ansible-navigator" + "ansible.ansibleNavigator.path": "/home/chris/devel/git/git.oopen.de/ansible/oopen-server/.venv/bin/ansible-navigator", + "yaml.customTags": [ + "!vault scalar" + ] } diff --git a/host_vars/a.mx.oopen.de/a.mx-common.yml b/host_vars/a.mx.oopen.de/a.mx-common.yml index f2ab5a2..98c12c8 100644 --- a/host_vars/a.mx.oopen.de/a.mx-common.yml +++ b/host_vars/a.mx.oopen.de/a.mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 185.12.64.2 + - 185.12.64.2 # --- @@ -107,14 +107,14 @@ insert_root_ssh_keypair: true root_ssh_keypair: - name: id-rsa-dehydrated - priv_key_src: a.mx/root/.ssh/a.mx-id_rsa-dehydrated + priv_key_src: a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated priv_key_dest: /root/.ssh/id_rsa-dehydrated - pub_key_src: a.mx/root/.ssh/a.mx-id_rsa-dehydrated.pub + pub_key_src: a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated.pub pub_key_dest: /root/.ssh/id_rsa-dehydrated.pub - name: id-rsa-opendkim - priv_key_src: a.mx/root/.ssh/a.mx-id_rsa-opendkim + priv_key_src: a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim priv_key_dest: /root/.ssh/id_rsa-opendkim - pub_key_src: a.mx/root/.ssh/a.mx-id_rsa-opendkim.pub + pub_key_src: a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim.pub pub_key_dest: /root/.ssh/id_rsa-opendkim.pub @@ -151,53 +151,6 @@ root_ssh_keypair: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: a.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_create_opendkim_key.conf - src_path: a.mx/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_postfix_add_mailboxes.conf - src_path: a.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf - dest_path: /root/bin/postfix/conf/postfix_add_mailboxes.conf - - - name: postfix_sent_userinfo_postfix.conf - src_path: a.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf - dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: a.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - -copy_plain_files_postfwd_host_specific: - - # Postfix Firewall postfwd - # - - name: postfwd.wl-user - src_path: a.mx/etc/postfix/postfwd.wl-user - dest_path: /etc/postfix/postfwd.wl-user - - - name: postfwd.bl-recipient-exeeds-msg-size-20mb - src_path: a.mx/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb - dest_path: /etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb - - -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml @@ -219,7 +172,7 @@ db_in_use: !!str "true" postfix_db_type: PostgreSQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: /run/postgresql +# postfix_db_host: /run/postgresql postfix_db_pass: FKt4z55FxMZp # install_amavis.conf @@ -228,33 +181,34 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.oopen.de -email_welcome_message: "\n -Hallo,\n +email_welcome_message: | -Ihre/Deine neue E-Mail Adresse ist eingerichtet.\n + Hallo, -O.OPEN\n + Ihre/Deine neue E-Mail Adresse ist eingerichtet. ---\n -O.OPEN | Phone: +49 30 / 290 484 91\n -Erkelenzdamm 21 | Fax: +49 30 / 290 484 99\n -D-10999 Berlin | E-MAIL: oo@oopen.de\n -" + O.OPEN + + -- + O.OPEN | Phone: +49 30 / 290 484 91 + Erkelenzdamm 21 | Fax: +49 30 / 290 484 99 + D-10999 Berlin | E-MAIL: oo@oopen.de # install_update_dovecot.conf # dovecot_from_address: "o.open " dovecot_reply_to: "oo@oopen.de" webmailer_address: "https://webmail.oopen.de" -salutation: "O.OPEN\n +salutation: | + O.OPEN ---\n -O.OPEN | Phone: +49 30 / 290 484 91\n -Erkelenzdamm 21 | Fax: +49 30 / 290 484 99\n -D-10999 Berlin | http://oopen.de\n" + -- + O.OPEN | Phone: +49 30 / 290 484 91 + Erkelenzdamm 21 | Fax: +49 30 / 290 484 99 + D-10999 Berlin | http://oopen.de # install_upgrade_roundcube-webmail.conf # @@ -265,7 +219,7 @@ autoreply_hostname: autoreply.oopen.de roundcube_db_type: pgsql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: localhost +# roundcube_db_host: localhost roundcube_db_pass: '3Dsz3j5R' roundcube_acl_plugin: true @@ -281,7 +235,7 @@ autoreply_2_hostname: autoreply.oopen.de roundcube_2_db_type: pgsql roundcube_2_db_name: roundcubemail2 roundcube_2_db_user: roundcube -#roundcube_2_db_host: localhost +# roundcube_2_db_host: localhost roundcube_2_db_pass: '3Dsz3j5R' roundcube2_acl_plugin: true diff --git a/host_vars/a.mx.oopen.de/a.mx-ipt-server.yml b/host_vars/a.mx.oopen.de/a.mx-ipt-server.yml index 96258b3..780bd37 100644 --- a/host_vars/a.mx.oopen.de/a.mx-ipt-server.yml +++ b/host_vars/a.mx.oopen.de/a.mx-ipt-server.yml @@ -42,4 +42,4 @@ fw_jitsi_dovecot_auth: true fw_rsync_out_ips: $ext_1_ip # --- Protection / limits -fw_per_IP_connection_limit: 250 +fw_per_IP_connection_limit: 250 # noqa: var-naming[pattern] diff --git a/host_vars/a.ns.oopen.de/a.ns-common.yml b/host_vars/a.ns.oopen.de/a.ns-common.yml index 284889b..fada2b8 100644 --- a/host_vars/a.ns.oopen.de/a.ns-common.yml +++ b/host_vars/a.ns.oopen.de/a.ns-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -86,8 +87,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -98,20 +99,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -129,10 +130,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -142,7 +143,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -198,45 +199,45 @@ copy_plain_files: # --- symlink_files: - - name: bind_get_domain_by_hostname - src_path: /root/bin/bind/bind_get_domain_by_hostname.sh - dest_path: /usr/local/bin/bind_get_domain_by_hostname.sh + - name: bind_get_domain_by_hostname + src_path: /root/bin/bind/bind_get_domain_by_hostname.sh + dest_path: /usr/local/bin/bind_get_domain_by_hostname.sh - - name: bind_get_zonefile_by_hostname - src_path: /root/bin/bind/bind_get_zonefile_by_hostname.sh - dest_path: /usr/local/bin/bind_get_zonefile_by_hostname.sh + - name: bind_get_zonefile_by_hostname + src_path: /root/bin/bind/bind_get_zonefile_by_hostname.sh + dest_path: /usr/local/bin/bind_get_zonefile_by_hostname.sh - - name: bind_rndc_sync_clean - src_path: /root/bin/bind/bind_rndc_sync_clean.sh - dest_path: /usr/local/bin/bind_rndc_sync_clean.sh + - name: bind_rndc_sync_clean + src_path: /root/bin/bind/bind_rndc_sync_clean.sh + dest_path: /usr/local/bin/bind_rndc_sync_clean.sh - - name: /bind_set_new_serial - src_path: /root/bin/bind/bind_set_new_serial.sh - dest_path: /usr/local/bin/bind_set_new_serial.sh + - name: /bind_set_new_serial + src_path: /root/bin/bind/bind_set_new_serial.sh + dest_path: /usr/local/bin/bind_set_new_serial.sh - - name: bind_set_renew_tlsa - src_path: /root/bin/bind/bind_set_renew_tlsa.sh - dest_path: /usr/local/bin/bind_set_renew_tlsa.sh + - name: bind_set_renew_tlsa + src_path: /root/bin/bind/bind_set_renew_tlsa.sh + dest_path: /usr/local/bin/bind_set_renew_tlsa.sh - - name: bind_add_dkim_zone_master - src_path: /root/bin/bind/bind_add_dkim_zone_master.sh - dest_path: /usr/local/bin/bind_add_dkim_zone_master.sh + - name: bind_add_dkim_zone_master + src_path: /root/bin/bind/bind_add_dkim_zone_master.sh + dest_path: /usr/local/bin/bind_add_dkim_zone_master.sh - - name: bind_add_dkim_zone_slave - src_path: /root/bin/bind/bind_add_dkim_zone_slave.sh - dest_path: /usr/local/bin/bind_add_dkim_zone_slave.sh + - name: bind_add_dkim_zone_slave + src_path: /root/bin/bind/bind_add_dkim_zone_slave.sh + dest_path: /usr/local/bin/bind_add_dkim_zone_slave.sh - - name: bind_reload_all_zones - src_path: /root/bin/bind/bind_reload_all_zones.sh - dest_path: /usr/local/bin/bind_reload_all_zones.sh + - name: bind_reload_all_zones + src_path: /root/bin/bind/bind_reload_all_zones.sh + dest_path: /usr/local/bin/bind_reload_all_zones.sh - - name: bind_remove_domain_on_master - src_path: /root/bin/bind/bind_remove_domain_on_master.sh - dest_path: /usr/local/bin/bind_remove_domain_on_master.sh + - name: bind_remove_domain_on_master + src_path: /root/bin/bind/bind_remove_domain_on_master.sh + dest_path: /usr/local/bin/bind_remove_domain_on_master.sh - - name: bind_remove_domain_on_slave - src_path: /root/bin/bind/bind_remove_domain_on_slave.sh - dest_path: /usr/local/bin/bind_remove_domain_on_slave.sh + - name: bind_remove_domain_on_slave + src_path: /root/bin/bind/bind_remove_domain_on_slave.sh + dest_path: /usr/local/bin/bind_remove_domain_on_slave.sh # --- @@ -244,13 +245,9 @@ symlink_files: # --- - - - # ============================== # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/ak-plan.oopen.de/ak-plan-common.yml b/host_vars/ak-plan.oopen.de/ak-plan-common.yml index da22fd8..8d89f6d 100644 --- a/host_vars/ak-plan.oopen.de/ak-plan-common.yml +++ b/host_vars/ak-plan.oopen.de/ak-plan-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -139,4 +139,3 @@ resolved_fallback_nameserver: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/anita.wf.netz/anita-common.yml b/host_vars/anita.wf.netz/anita-common.yml index 8eb986d..ee395f2 100644 --- a/host_vars/anita.wf.netz/anita-common.yml +++ b/host_vars/anita.wf.netz/anita-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -29,7 +30,7 @@ # vars used by roles/common/tasks/users.yml # --- -extra_user: +extra_user: - name: kaya user_id: 1002 @@ -121,7 +122,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -131,7 +132,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -290,4 +291,3 @@ samba_shares: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/at-10-neu.ak.netz/at-10-neu-common.yml b/host_vars/at-10-neu.ak.netz/at-10-neu-common.yml index 598cfe5..1dc65a7 100644 --- a/host_vars/at-10-neu.ak.netz/at-10-neu-common.yml +++ b/host_vars/at-10-neu.ak.netz/at-10-neu-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -120,7 +120,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ak.local @@ -130,7 +130,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.0.254 + - 172.16.0.254 # --- @@ -145,7 +145,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -279,7 +278,7 @@ samba_homes_virusfilter: true # - name: name2 # remove_samba_users: [] -#remove_samba_users: +# remove_samba_users: # - name: evren samba_shares: @@ -306,7 +305,7 @@ samba_shares: recycle_path: '@Recycle' - name: redakteure - comment: Verzeichnis für Redakteure + comment: Verzeichnis für Redakteure path: /data/samba/shares/redakteure group_valid_users: redakteure group_write_list: redakteure diff --git a/host_vars/b.mx.oopen.de/b.mx-common.yml b/host_vars/b.mx.oopen.de/b.mx-common.yml index 70cb3b5..286fbe0 100644 --- a/host_vars/b.mx.oopen.de/b.mx-common.yml +++ b/host_vars/b.mx.oopen.de/b.mx-common.yml @@ -43,8 +43,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -55,20 +55,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -81,10 +81,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -94,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -189,7 +189,6 @@ copy_template_files: [] # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/b.ns.oopen.de/b.ns-common.yml b/host_vars/b.ns.oopen.de/b.ns-common.yml index 6197a5a..25a9c9c 100644 --- a/host_vars/b.ns.oopen.de/b.ns-common.yml +++ b/host_vars/b.ns.oopen.de/b.ns-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -34,7 +35,7 @@ extra_user: - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCv2rDahAeQBR9NcQkHG5VHbMNGlOzHJPbh5V34ogloAtW0VVO7xnes3Ak3Q/eM0tFbFMG4MRti1M3Un0GJzTV9H2bqN02TmUp5MnDVDcHNfG4L7hqLH2KtwniKeB41IKIeJUdhpKxdFFqM8Z78Xn5EASO5Fu33lQcH+RTbmoYikEr1WrSbQB3wcqtXS+lNveyFUlJD9XJ0MLzanBePQh9boc93CfOa3yFTb90grfB5QjnpL7167MpSH6Oq/DVh5NcnMzvoYjZf9gsMTHuOAUyUKGeUdg2K89gFjkBq2r3S3ouKpDQxPSRXHuNDBSeHJEHy8DP6rOd+0qZVOaPEv3Qi/BRPO9LWcc2aUg8ydI7w1oMd/STaK54PaUJJ7uXV3ZTQsxGyziwZlx+Gq0PNAMjKFdYXAcuGPnlYxDGhVcJJElEuu7DJQqpWfzofov2VEniQQ8Ekknpxd5MFYka0NP038lpIZyMzy13DFJ6KUchbTGfzkHcwKmFX+3vZFEBqq5rZWOuY303qe5gP7eKhsBV/iu47Ne1OtTS2N0QFPTElshk3CLbZKerQo+XLxo3Z15cRDxDsgkdAHtY1PiMjXeX8ZahwXC2vs1ZfBoN4kK2iIH1Gtor4QG+g7chjKa+kZDKqFd4y0EZzeR0IjYCyWt2mNd3hMbEjBtZp75drYmRlqQ== root@ga-st-mail-opendkim' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDF7Sx0YJlLjjg3Sm8uiXJyBeKKmZFum3D8Mw2VQZrXJgYOrVB/SVDXO4N5I6NOT5bvxs8c5DLV/4J4ewGP5dGSYiepRnkrRSBUUS6ICwkYfyXremHJ31uREfODRBA4Vnsmpw0SlbQ2I9IpYwsaD3/IDZehDgaCKu4D0/LIprZh0/u+WX7kOGb8Tkm/PBu2SSbAzURaMXn/UtGsUyrickAmEK9qXZDsNYgcwOqZaPtkMZP3mAdix/gKaWV07oU49zxBrouD8gRWAs/yOLvxOe1JDcH2ZExXl81jJYlUffKarBHsWNNE79hUInnH9YTfxP1AEC+MyFXxqKwz3Lk1dQyUo1TFtJTYY+/IHsXT/6KhbOi6twhj7U7uZEqaIWyo6N+WVL9fFhgmbSoVIE6KrBM5VtOdr33A3a+XeNAQGjW6mqOcv3iNUDipTnDTKkEAWQWWnK5YRuaJw1eUCoii/FDp0hRTWIqn+RVCgkOGgEjMIRC8tiQouCXxwfukfcq9zD8S8UCyyQY0uWRHm3uM5GHTmvIJHBXfXBSX/B+PgesSZVwICCiS/6ZSWT+6D5ObBdKGkz12A797YyaMsN7RtJn6OBhPRrGfqQLCIM7lpxJHAoQmTSMiuQp/TjHLedjAm3FvxET2ZvqPWg9QtvSzIoz2JOdKysZHGgbBdC7q6Cssvw== root@ga-st-mail-dehydrated' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQClupkurU+acJRtp2s9GgiC+rANqlup8SfhtulV0a/8z6nobjcpQWrfVq+MNjM7VghnlMAwMjz7tccFGyCmJoSS11RcnFtPmqnSNj0/TI8zyYOZUvZCczPBSeqs/IxawyYz91e3RlPWbpv71Nj+/EHUZApZkkdTkpYHduSJYWtKYA2l2Glzmjd2d2u/IFIkqXhvl1bT3RUMLZJqYdEwYAvlW2JB84EIWNf4ytcGcu6rakXCRP9o62BbRza3AfMgSfa45PLodPi5VpqDiTHSCIBll+VOuLqTgQCBYeANRPClMLbueVXXcMrmEwrDXeC0dpqTdgaF2Tz3xYsrAzTe6bcNJsGgGCQyTtDKpsAgoKb31agsyy68CoZto13Ea4WYsNVx0T3KaRlaDm98KqnUJXHJvXnLegqfXiURL5BpxXmAnFvZ0duHrtRkVpzeu5n5vz41RLnFHyLln2VE6a+IYdiLlPl2hC+7pswb+nBP9yNn6T4WQZNtHp4YssANuYKO+/gJaHpMJ1TqgL/Ip66erK+372M1T/6ibiU3+qHbwW7FbXVfn3Dz2abJGyNkoaZGpQIXtx0UxWYZHF8E35Z0ll9NQo1CnDvV3jA1aMnYVTv9DuSYxqLY34oHWXEFzMyStCRWup4Tfrp3pT61GRhb2h8kZi5dqQur9KrqWmA6HF9D+Q== root@lists.mx' - - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC82aW3qFetvOZSBJFCBnSONurzqAtkZT7cNA+0OuXgYmKXjsOaBlA2pm2a+rKS1Rs2VOzQFAHJMGaR/JGRYTU060jZaZmJhNgNbtqBicDeiEE0p1HfQCm/HSN5vf4Q8CRMDHxkaRxkWOIxvouxn2dkbZklZ+SZCNh42ZMMVC/q0UJmgTV2A5RCbd6eARs9u6lnix+PAhTYYLjsnyNSorr0g6FLb4367dg1klyyHuCNb0rjTZxnYTNDHGHTrYQUXIaZt16iWaxzmnSQi4fivmunGc2Xafhkea+lfxbSwtG68zeJC4D3QBGKZu8xtjyipj9v2LyBrXONgBXfBKs8b9dmhL/Qr4cIhaUdl0IDYaQ/UEBmy3z6CeUxrUsWoQP6st8299ndj1ul7sW2Q5QPH2hLX2PSLOoMygV0cho6oh1XEAkTsAgTXnqhp5G0vZF/2VFYyu2QP+0/yJawOSUE2TMJmA5yU7TMx5koDZL51Rj9XVFqouzRG+6gOOAnhHICfvQUYpS+WW/nqNYl1MI+9Gk29Em2YoBwb1zlep6gC5EyjTzx4h13ldSFSmHcEn9vptZeZv78Es/bT9ib8IdUS9oRatw9IEmA9xnWgHxcrTn1+QYJkbjc1cS2lFVR9wmm3/4It/RyWuxAf3k4qlzHzIS/F4St7MLjviPAWRxqyvroQQ== root@test.mx' + - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC82aW3qFetvOZSBJFCBnSONurzqAtkZT7cNA+0OuXgYmKXjsOaBlA2pm2a+rKS1Rs2VOzQFAHJMGaR/JGRYTU060jZaZmJhNgNbtqBicDeiEE0p1HfQCm/HSN5vf4Q8CRMDHxkaRxkWOIxvouxn2dkbZklZ+SZCNh42ZMMVC/q0UJmgTV2A5RCbd6eARs9u6lnix+PAhTYYLjsnyNSorr0g6FLb4367dg1klyyHuCNb0rjTZxnYTNDHGHTrYQUXIaZt16iWaxzmnSQi4fivmunGc2Xafhkea+lfxbSwtG68zeJC4D3QBGKZu8xtjyipj9v2LyBrXONgBXfBKs8b9dmhL/Qr4cIhaUdl0IDYaQ/UEBmy3z6CeUxrUsWoQP6st8299ndj1ul7sW2Q5QPH2hLX2PSLOoMygV0cho6oh1XEAkTsAgTXnqhp5G0vZF/2VFYyu2QP+0/yJawOSUE2TMJmA5yU7TMx5koDZL51Rj9XVFqouzRG+6gOOAnhHICfvQUYpS+WW/nqNYl1MI+9Gk29Em2YoBwb1zlep6gC5EyjTzx4h13ldSFSmHcEn9vptZeZv78Es/bT9ib8IdUS9oRatw9IEmA9xnWgHxcrTn1+QYJkbjc1cS2lFVR9wmm3/4It/RyWuxAf3k4qlzHzIS/F4St7MLjviPAWRxqyvroQQ== root@test.mx' - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDIf2ahqowiUbP4f3/qtdC1JmbjIdlF+i+TiWpxWam0yjiGuTPDjI1ud5vj0of2+P4DJy2dkDvF3yK7/Np7qpxIJgsj9HNiwIlGtfrwNCzqGlyPovjNpAr8cCR1P34K9CgHz4BInc//vjxlUXZpK17omOJ4KaVY1f/Eit0G5Y2TJ38BY6MztuUfou8PdJqITM3GM/YOk4iz2OnObDjHAbd6VTSn4yrYTkGT30axiCHdSy0XhvfUgB1yO08PIcOOogGkxRLYkvUAxwhDsFSpGzQBhUb1O5RqGnBs/aR4sxwjTaeO8mP6lpQMp2pz//I6448N3k5P1CwcJAqrkUuOk4o+jHWr5rSO+eKm4SQ74RBnAAM9bA0tpvCmO8kV2tsdbS4Yw94H4GfTgOPZ5Fe6Y8ciTR+bkGdp7sqm5DNtjZNZuwiFmoe2vj7RJlCNDIXhwVEGAWf+lFYCQKp05A13QoRYGg2aebaLSjw9XYBghNtwnmYkSb84xIoELmPKYrvdodO2uHgGxHBls1mFTz8m01kn+A49L3yY+cFZtSua/+YYoZLh1tNLAL4rBRCRVpZs+VHrmz0GCxwYMHkm9ti0SRPrb7jtH9DYwLUdci4pL8z/G4D2M92A66OZqIybgAJkkdl4H4mv9n05FPJ8RxPniD58x3AMTZNtkxGxn8UkTCSSGQ== root@web-01-opendkim' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICCvag/r50Dxfsh3fcG3fZSZ+vbsCwbV+WDoJ++zNSHl root@web-01-dns' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFpQyckVQMI2YMbIQ9Gqf2JyGyM2JufIPf0lv7jvMxLI root@web-02-dns' @@ -80,8 +81,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -92,20 +93,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -123,10 +124,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -136,7 +137,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -188,45 +189,45 @@ copy_plain_files: # --- symlink_files: - - name: bind_get_domain_by_hostname - src_path: /root/bin/bind/bind_get_domain_by_hostname.sh - dest_path: /usr/local/bin/bind_get_domain_by_hostname.sh + - name: bind_get_domain_by_hostname + src_path: /root/bin/bind/bind_get_domain_by_hostname.sh + dest_path: /usr/local/bin/bind_get_domain_by_hostname.sh - - name: bind_get_zonefile_by_hostname - src_path: /root/bin/bind/bind_get_zonefile_by_hostname.sh - dest_path: /usr/local/bin/bind_get_zonefile_by_hostname.sh + - name: bind_get_zonefile_by_hostname + src_path: /root/bin/bind/bind_get_zonefile_by_hostname.sh + dest_path: /usr/local/bin/bind_get_zonefile_by_hostname.sh - - name: bind_rndc_sync_clean - src_path: /root/bin/bind/bind_rndc_sync_clean.sh - dest_path: /usr/local/bin/bind_rndc_sync_clean.sh + - name: bind_rndc_sync_clean + src_path: /root/bin/bind/bind_rndc_sync_clean.sh + dest_path: /usr/local/bin/bind_rndc_sync_clean.sh - - name: /bind_set_new_serial - src_path: /root/bin/bind/bind_set_new_serial.sh - dest_path: /usr/local/bin/bind_set_new_serial.sh + - name: /bind_set_new_serial + src_path: /root/bin/bind/bind_set_new_serial.sh + dest_path: /usr/local/bin/bind_set_new_serial.sh - - name: bind_set_renew_tlsa - src_path: /root/bin/bind/bind_set_renew_tlsa.sh - dest_path: /usr/local/bin/bind_set_renew_tlsa.sh + - name: bind_set_renew_tlsa + src_path: /root/bin/bind/bind_set_renew_tlsa.sh + dest_path: /usr/local/bin/bind_set_renew_tlsa.sh - - name: bind_add_dkim_zone_master - src_path: /root/bin/bind/bind_add_dkim_zone_master.sh - dest_path: /usr/local/bin/bind_add_dkim_zone_master.sh + - name: bind_add_dkim_zone_master + src_path: /root/bin/bind/bind_add_dkim_zone_master.sh + dest_path: /usr/local/bin/bind_add_dkim_zone_master.sh - - name: bind_add_dkim_zone_slave - src_path: /root/bin/bind/bind_add_dkim_zone_slave.sh - dest_path: /usr/local/bin/bind_add_dkim_zone_slave.sh + - name: bind_add_dkim_zone_slave + src_path: /root/bin/bind/bind_add_dkim_zone_slave.sh + dest_path: /usr/local/bin/bind_add_dkim_zone_slave.sh - - name: bind_reload_all_zones - src_path: /root/bin/bind/bind_reload_all_zones.sh - dest_path: /usr/local/bin/bind_reload_all_zones.sh + - name: bind_reload_all_zones + src_path: /root/bin/bind/bind_reload_all_zones.sh + dest_path: /usr/local/bin/bind_reload_all_zones.sh - - name: bind_remove_domain_on_master - src_path: /root/bin/bind/bind_remove_domain_on_master.sh - dest_path: /usr/local/bin/bind_remove_domain_on_master.sh + - name: bind_remove_domain_on_master + src_path: /root/bin/bind/bind_remove_domain_on_master.sh + dest_path: /usr/local/bin/bind_remove_domain_on_master.sh - - name: bind_remove_domain_on_slave - src_path: /root/bin/bind/bind_remove_domain_on_slave.sh - dest_path: /usr/local/bin/bind_remove_domain_on_slave.sh + - name: bind_remove_domain_on_slave + src_path: /root/bin/bind/bind_remove_domain_on_slave.sh + dest_path: /usr/local/bin/bind_remove_domain_on_slave.sh # --- @@ -240,4 +241,3 @@ symlink_files: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/backup.oopen.de/backup-common.yml b/host_vars/backup.oopen.de/backup-common.yml index 9260977..1df8884 100644 --- a/host_vars/backup.oopen.de/backup-common.yml +++ b/host_vars/backup.oopen.de/backup-common.yml @@ -70,8 +70,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -82,20 +82,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -109,10 +109,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -122,7 +122,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -410,4 +410,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/backup.warenform.de/backup-common.yml b/host_vars/backup.warenform.de/backup-common.yml index 93fe044..3e5adf9 100644 --- a/host_vars/backup.warenform.de/backup-common.yml +++ b/host_vars/backup.warenform.de/backup-common.yml @@ -188,8 +188,6 @@ cron_user_entries: insert_ssh_keypair_backup_server: false - - default_user: - name: chris @@ -308,4 +306,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/bbb-server.b3-bornim.netz/bbb-server-common.yml b/host_vars/bbb-server.b3-bornim.netz/bbb-server-common.yml index ec6c8aa..c53e9a5 100644 --- a/host_vars/bbb-server.b3-bornim.netz/bbb-server-common.yml +++ b/host_vars/bbb-server.b3-bornim.netz/bbb-server-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.42.1 - #search: b3-bornim.netz + # search: b3-bornim.netz # --- @@ -131,7 +131,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - b3-bornim.netz @@ -141,7 +141,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.42.254 + - 172.16.42.254 # --- @@ -156,7 +156,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -236,7 +235,7 @@ samba_user: groups: - praktikant password: '20-b3_praktikant-22%' - + - name: caroline groups: - praktikant @@ -394,7 +393,7 @@ samba_shares: recycle_path: '@Recycle' - name: gs - comment: Gesellschafter + comment: Gesellschafter path: /data/samba/share/gesellschafter group_valid_users: gs group_write_list: gs diff --git a/host_vars/c.mx.oopen.de/c.mx-common.yml b/host_vars/c.mx.oopen.de/c.mx-common.yml index e450c9f..a791b0c 100644 --- a/host_vars/c.mx.oopen.de/c.mx-common.yml +++ b/host_vars/c.mx.oopen.de/c.mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -107,19 +107,19 @@ insert_root_ssh_keypair: true root_ssh_keypair: - name: id-rsa-dehydrated - priv_key_src: c.mx/root/.ssh/c.mx-id_rsa-dehydrated + priv_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated priv_key_dest: /root/.ssh/id_rsa-dehydrated - pub_key_src: c.mx/root/.ssh/c.mx-id_rsa-dehydrated.pub + pub_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated.pub pub_key_dest: /root/.ssh/id_rsa-dehydrated.pub - name: id-rsa-opendkim - priv_key_src: c.mx/root/.ssh/c.mx-id_rsa-opendkim + priv_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim priv_key_dest: /root/.ssh/id_rsa-opendkim - pub_key_src: c.mx/root/.ssh/c.mx-id_rsa-opendkim.pub + pub_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim.pub pub_key_dest: /root/.ssh/id_rsa-opendkim.pub - name: id-rsa - priv_key_src: c.mx/root/.ssh/c.mx-id_rsa + priv_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa priv_key_dest: /root/.ssh/id_rsa - pub_key_src: c.mx/root/.ssh/c.mx-id_rsa.pub + pub_key_src: c.mx.oopen.de/root/.ssh/c.mx-id_rsa.pub pub_key_dest: /root/.ssh/id_rsa.pub @@ -156,49 +156,6 @@ root_ssh_keypair: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: c.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_create_opendkim_key.conf - src_path: c.mx/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_postfix_add_mailboxes.conf - src_path: c.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf - dest_path: /root/bin/postfix/conf/postfix_add_mailboxes.conf - - - name: postfix_sent_userinfo_postfix.conf - src_path: c.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf - dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: c.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - -copy_plain_files_postfwd_host_specific: [] - - # Postfix Firewall postfwd - # - #- name: postfwd.wl-user - # src_path: c.mx/etc/postfix/postfwd.wl-user - # dest_path: /etc/postfix/postfwd.wl-user - - -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml @@ -218,7 +175,7 @@ db_in_use: !!str "true" postfix_db_type: MySQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: +# postfix_db_host: postfix_db_pass: AeB4kohyie5rahJ7 # install_amavis.conf @@ -227,33 +184,33 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.initiativenserver.de -email_welcome_message: "\n -Hallo,\n +email_welcome_message: | + Hallo, -Ihre/Deine neue E-Mail Adresse ist eingerichtet.\n + Ihre/Deine neue E-Mail Adresse ist eingerichtet. -Aktionsbündnis gegen Gewalt, Rechtsextremismus und Fremdenfeindlichkeit + Aktionsbündnis gegen Gewalt, Rechtsextremismus und Fremdenfeindlichkeit ---\n -Initiativenserver | phone: 0331 505824-28\n -Mittelstraße 38/39 | fax: 0331 505824-29\n -14467 Potsdam | email: kontakt@initiativenserver.de\n -" + -- + Initiativenserver | phone: 0331 505824-28 + Mittelstraße 38/39 | fax: 0331 505824-29 + 14467 Potsdam | email: kontakt@initiativenserver.de # install_update_dovecot.conf # dovecot_from_address: "Admin Initiativenserver " dovecot_reply_to: "admin@initiativenserver.de" webmailer_address: "https://webmail.initiativenserver.de" -salutation: "Aktionsbündnis gegen Gewalt, Rechtsextremismus und FremdenfeindlichkeitN\n +salutation: | + Aktionsbündnis gegen Gewalt, Rechtsextremismus und Fremdenfeindlichkeit ---\n -Initiativenserver | phone: 0331 505824-28\n -Mittelstraße 38/39 | fax: 0331 505824-29\n -14467 Potsdam | email: kontakt@initiativenserver.de\n" + -- + Initiativenserver | phone: 0331 505824-28 + Mittelstraße 38/39 | fax: 0331 505824-29 + 14467 Potsdam | email: kontakt@initiativenserver.de # install_upgrade_roundcube-webmail.conf # @@ -264,7 +221,7 @@ autoreply_hostname: autoreply.initiativenserver.de roundcube_db_type: mysql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: +# roundcube_db_host: roundcube_db_pass: 're6Xe8Fereejai3D' roundcube_acl_plugin: false @@ -295,4 +252,3 @@ template_files_mailsystem_script: - name: mailsystem_install_upgrade_roundcube-webmail.conf src_path: usr/local/src/mailsystem/conf/install_upgrade_roundcube-webmail.conf.j2 dest_path: /usr/local/src/mailsystem/conf/install_upgrade_roundcube-webmail.conf - diff --git a/host_vars/cl-01.oopen.de/cl-01-common.yml b/host_vars/cl-01.oopen.de/cl-01-common.yml index a774e07..42ea8de 100644 --- a/host_vars/cl-01.oopen.de/cl-01-common.yml +++ b/host_vars/cl-01.oopen.de/cl-01-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -85,10 +85,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -98,7 +98,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -163,4 +163,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-02.oopen.de/cl-02-common.yml b/host_vars/cl-02.oopen.de/cl-02-common.yml index 3028782..e72e551 100644 --- a/host_vars/cl-02.oopen.de/cl-02-common.yml +++ b/host_vars/cl-02.oopen.de/cl-02-common.yml @@ -88,7 +88,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -98,7 +98,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -150,4 +150,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-dissens.oopen.de/cl-dissens-common.yml b/host_vars/cl-dissens.oopen.de/cl-dissens-common.yml index 7aabdf0..663a7ca 100644 --- a/host_vars/cl-dissens.oopen.de/cl-dissens-common.yml +++ b/host_vars/cl-dissens.oopen.de/cl-dissens-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -148,4 +148,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-flr.oopen.de/cl-flr-common.yml b/host_vars/cl-flr.oopen.de/cl-flr-common.yml index 7aabdf0..663a7ca 100644 --- a/host_vars/cl-flr.oopen.de/cl-flr-common.yml +++ b/host_vars/cl-flr.oopen.de/cl-flr-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -148,4 +148,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-fm.oopen.de/cl-fm-common.yml b/host_vars/cl-fm.oopen.de/cl-fm-common.yml index bf6660e..0d9b2e7 100644 --- a/host_vars/cl-fm.oopen.de/cl-fm-common.yml +++ b/host_vars/cl-fm.oopen.de/cl-fm-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -232,4 +232,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-irights.oopen.de/cl-irights-common.yml b/host_vars/cl-irights.oopen.de/cl-irights-common.yml index eff9024..31d1456 100644 --- a/host_vars/cl-irights.oopen.de/cl-irights-common.yml +++ b/host_vars/cl-irights.oopen.de/cl-irights-common.yml @@ -86,7 +86,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -232,4 +232,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-lubax.oopen.de/cl-lubax-common.yml b/host_vars/cl-lubax.oopen.de/cl-lubax-common.yml index aa249da..05255dd 100644 --- a/host_vars/cl-lubax.oopen.de/cl-lubax-common.yml +++ b/host_vars/cl-lubax.oopen.de/cl-lubax-common.yml @@ -19,7 +19,7 @@ # vars used by roles/common/tasks/sshd.yml # --- -#sshd_permit_root_login: !!str "prohibit-password" +# sshd_permit_root_login: !!str "prohibit-password" sshd_permit_root_login: !!str "no" # --- @@ -43,8 +43,8 @@ systemd_resolved: false # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -55,20 +55,20 @@ systemd_resolved: false # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -84,10 +84,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -149,4 +149,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-lubax.oopen.de/cl-lubax-ipt-server.yml b/host_vars/cl-lubax.oopen.de/cl-lubax-ipt-server.yml index 3768a0d..8751119 100644 --- a/host_vars/cl-lubax.oopen.de/cl-lubax-ipt-server.yml +++ b/host_vars/cl-lubax.oopen.de/cl-lubax-ipt-server.yml @@ -24,4 +24,4 @@ fw_http_server_ips: $ext_1_ip fw_mail_client_ips: $ext_1_ip # --- Block -#fw_blocked_ips: 222.184.0.0/13 61.160.0.0/16 116.8.0.0/14 +# fw_blocked_ips: 222.184.0.0/13 61.160.0.0/16 116.8.0.0/14 diff --git a/host_vars/cl-nd.oopen.de/cl-nd-common.yml b/host_vars/cl-nd.oopen.de/cl-nd-common.yml index f2c263a..2d2f852 100644 --- a/host_vars/cl-nd.oopen.de/cl-nd-common.yml +++ b/host_vars/cl-nd.oopen.de/cl-nd-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -232,4 +232,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-ndm.oopen.de/cl-ndm-common.yml b/host_vars/cl-ndm.oopen.de/cl-ndm-common.yml index 928617c..5dd4a46 100644 --- a/host_vars/cl-ndm.oopen.de/cl-ndm-common.yml +++ b/host_vars/cl-ndm.oopen.de/cl-ndm-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -232,4 +232,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-opp.oopen.de/cl-opp-common.yml b/host_vars/cl-opp.oopen.de/cl-opp-common.yml index 7e3b817..d5e558c 100644 --- a/host_vars/cl-opp.oopen.de/cl-opp-common.yml +++ b/host_vars/cl-opp.oopen.de/cl-opp-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -143,4 +143,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-test.oopen.de/cl-test-common.yml b/host_vars/cl-test.oopen.de/cl-test-common.yml index e7edf06..c92a3d6 100644 --- a/host_vars/cl-test.oopen.de/cl-test-common.yml +++ b/host_vars/cl-test.oopen.de/cl-test-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -81,10 +81,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - oopen.de @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -140,4 +140,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cl-vbrg.oopen.de/cl-vbrg-common.yml b/host_vars/cl-vbrg.oopen.de/cl-vbrg-common.yml index a7c1f06..04a442e 100644 --- a/host_vars/cl-vbrg.oopen.de/cl-vbrg-common.yml +++ b/host_vars/cl-vbrg.oopen.de/cl-vbrg-common.yml @@ -70,4 +70,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cloud-giz.warenform.de/cloud-giz-common.yml b/host_vars/cloud-giz.warenform.de/cloud-giz-common.yml index a7c1f06..04a442e 100644 --- a/host_vars/cloud-giz.warenform.de/cloud-giz-common.yml +++ b/host_vars/cloud-giz.warenform.de/cloud-giz-common.yml @@ -70,4 +70,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cloud.akweb.de/cloud-common.yml b/host_vars/cloud.akweb.de/cloud-common.yml index 83adbf9..a33a1f0 100644 --- a/host_vars/cloud.akweb.de/cloud-common.yml +++ b/host_vars/cloud.akweb.de/cloud-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -144,4 +144,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cp-01.oopen.de/cp-01-common.yml b/host_vars/cp-01.oopen.de/cp-01-common.yml index 159ac0a..6366d14 100644 --- a/host_vars/cp-01.oopen.de/cp-01-common.yml +++ b/host_vars/cp-01.oopen.de/cp-01-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -85,10 +85,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -98,7 +98,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -158,4 +158,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/cp-flr.oopen.de/cp-flr-common.yml b/host_vars/cp-flr.oopen.de/cp-flr-common.yml index 2cd795c..8a899b7 100644 --- a/host_vars/cp-flr.oopen.de/cp-flr-common.yml +++ b/host_vars/cp-flr.oopen.de/cp-flr-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -156,4 +156,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/d.mx.oopen.de/d.mx-common.yml b/host_vars/d.mx.oopen.de/d.mx-common.yml index 45e9a0c..251c1a9 100644 --- a/host_vars/d.mx.oopen.de/d.mx-common.yml +++ b/host_vars/d.mx.oopen.de/d.mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -173,7 +173,6 @@ copy_template_files: [] # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/dc-opp.oopen.de/dc-opp-common.yml b/host_vars/dc-opp.oopen.de/dc-opp-common.yml index da22fd8..8d89f6d 100644 --- a/host_vars/dc-opp.oopen.de/dc-opp-common.yml +++ b/host_vars/dc-opp.oopen.de/dc-opp-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -139,4 +139,3 @@ resolved_fallback_nameserver: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/devel-cloud.wf.netz/devel-cloud-common.yml b/host_vars/devel-cloud.wf.netz/devel-cloud-common.yml index 615eb5a..b7f3d82 100644 --- a/host_vars/devel-cloud.wf.netz/devel-cloud-common.yml +++ b/host_vars/devel-cloud.wf.netz/devel-cloud-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -81,7 +82,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -91,14 +92,14 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- # vars used by roles/common/tasks/users.yml # --- -extra_user: +extra_user: - name: kaya password: $6$t9gheUvd$hFTJ5mp0bdu4Hc5zGmS6HuSAfFOc4QRROLX4wnCauLjwTxUtvhgeLDlL5YkjGfiWOCEe84krH4op0DdKjTJWG/ @@ -150,4 +151,3 @@ sudo_users: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/devel-db.wf.netz/devel-db-common.yml b/host_vars/devel-db.wf.netz/devel-db-common.yml index 097c1a8..9681da3 100644 --- a/host_vars/devel-db.wf.netz/devel-db-common.yml +++ b/host_vars/devel-db.wf.netz/devel-db-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,15 +142,12 @@ resolved_fallback_nameserver: # --- - # --- # vars used by roles/common/tasks/samba-config-server.yml # vars used by roles/common/tasks/samba-user.yml # --- - - # ============================== diff --git a/host_vars/devel-php.wf.netz/devel-php-common.yml b/host_vars/devel-php.wf.netz/devel-php-common.yml index 1770fde..eda97e2 100644 --- a/host_vars/devel-php.wf.netz/devel-php-common.yml +++ b/host_vars/devel-php.wf.netz/devel-php-common.yml @@ -94,7 +94,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -104,7 +104,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -149,15 +149,12 @@ resolved_fallback_nameserver: # --- - # --- # vars used by roles/common/tasks/samba-config-server.yml # vars used by roles/common/tasks/samba-user.yml # --- - - # ============================== diff --git a/host_vars/devel-repos.wf.netz/devel-repos-common.yml b/host_vars/devel-repos.wf.netz/devel-repos-common.yml index 097c1a8..9681da3 100644 --- a/host_vars/devel-repos.wf.netz/devel-repos-common.yml +++ b/host_vars/devel-repos.wf.netz/devel-repos-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,15 +142,12 @@ resolved_fallback_nameserver: # --- - # --- # vars used by roles/common/tasks/samba-config-server.yml # vars used by roles/common/tasks/samba-user.yml # --- - - # ============================== diff --git a/host_vars/devel-root.wf.netz/devel-root-common.yml b/host_vars/devel-root.wf.netz/devel-root-common.yml index 097c1a8..9681da3 100644 --- a/host_vars/devel-root.wf.netz/devel-root-common.yml +++ b/host_vars/devel-root.wf.netz/devel-root-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,15 +142,12 @@ resolved_fallback_nameserver: # --- - # --- # vars used by roles/common/tasks/samba-config-server.yml # vars used by roles/common/tasks/samba-user.yml # --- - - # ============================== diff --git a/host_vars/devel-wiki.wf.netz/devel-wiki-common.yml b/host_vars/devel-wiki.wf.netz/devel-wiki-common.yml index 097c1a8..9681da3 100644 --- a/host_vars/devel-wiki.wf.netz/devel-wiki-common.yml +++ b/host_vars/devel-wiki.wf.netz/devel-wiki-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,15 +142,12 @@ resolved_fallback_nameserver: # --- - # --- # vars used by roles/common/tasks/samba-config-server.yml # vars used by roles/common/tasks/samba-user.yml # --- - - # ============================== diff --git a/host_vars/dns0.warenform.de/dns0-common.yml b/host_vars/dns0.warenform.de/dns0-common.yml index 13fda17..8d48a8e 100644 --- a/host_vars/dns0.warenform.de/dns0-common.yml +++ b/host_vars/dns0.warenform.de/dns0-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -121,4 +121,3 @@ git_firewall_repository: {} # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/dns1.warenform.de/dns1-common.yml b/host_vars/dns1.warenform.de/dns1-common.yml index 8d8ed30..1fb4fdf 100644 --- a/host_vars/dns1.warenform.de/dns1-common.yml +++ b/host_vars/dns1.warenform.de/dns1-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -81,10 +81,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -94,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -138,4 +138,3 @@ git_firewall_repository: {} # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/e.mx.oopen.de/e.mx-common.yml b/host_vars/e.mx.oopen.de/e.mx-common.yml index 0fcfd6a..1726684 100644 --- a/host_vars/e.mx.oopen.de/e.mx-common.yml +++ b/host_vars/e.mx.oopen.de/e.mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -105,16 +105,16 @@ resolved_fallback_nameserver: insert_root_ssh_keypair: true -#root_ssh_keypair: +# root_ssh_keypair: # - name: id-rsa-dehydrated -# priv_key_src: e.mx/root/.ssh/e.mx-id_rsa-dehydrated +# priv_key_src: e.mx.oopen.de/root/.ssh/e.mx-id_rsa-dehydrated # priv_key_dest: /root/.ssh/id_rsa-dehydrated -# pub_key_src: e.mx/root/.ssh/e.mx-id_rsa-dehydrated.pub +# pub_key_src: e.mx.oopen.de/root/.ssh/e.mx-id_rsa-dehydrated.pub # pub_key_dest: /root/.ssh/id_rsa-dehydrated.pub # - name: id-rsa-opendkim -# priv_key_src: e.mx/root/.ssh/e.mx-id_rsa-opendkim +# priv_key_src: e.mx.oopen.de/root/.ssh/e.mx-id_rsa-opendkim # priv_key_dest: /root/.ssh/id_rsa-opendkim -# pub_key_src: e.mx/root/.ssh/e.mx-id_rsa-opendkim.pub +# pub_key_src: e.mx.oopen.de/root/.ssh/e.mx-id_rsa-opendkim.pub # pub_key_dest: /root/.ssh/id_rsa-opendkim.pub @@ -151,36 +151,6 @@ insert_root_ssh_keypair: true # vars used by roles/common/tasks/copy_files.yml # --- -#copy_plain_files: -# -# - name: monitoring_check_cert_for_dovecot.conf -# src_path: e.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf -# dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf -# -# - name: postfix_create_opendkim_key.conf -# src_path: e.mx/root/bin/postfix/conf/create_opendkim_key.conf -# dest_path: /root/bin/postfix/conf/create_opendkim_key.conf -# -# - name: postfix_postfix_add_mailboxes.conf -# src_path: e.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf -# dest_path: /root/bin/postfix/conf/postfix_add_mailboxes.conf -# -# - name: postfix_sent_userinfo_postfix.conf -# src_path: e.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf -# dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf -# -# - name: postfix_whitelist_mb_sigs.conf -# src_path: e.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf -# dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf -# -# -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml @@ -208,33 +178,34 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm-e.oopen.de -email_welcome_message: "\n -Hallo,\n +email_welcome_message: | -Ihre/Deine neue E-Mail Adresse ist eingerichtet.\n + Hallo, -O.OPEN\n + Ihre/Deine neue E-Mail Adresse ist eingerichtet. ---\n -O.OPEN | Phone: +49 30 / 290 484 91\n -Erkelenzdamm 21 | Fax: +49 30 / 290 484 99\n -D-10999 Berlin | E-MAIL: oo@oopen.de\n -" + O.OPEN + + -- + O.OPEN | Phone: +49 30 / 290 484 91 + Erkelenzdamm 21 | Fax: +49 30 / 290 484 99 + D-10999 Berlin | E-MAIL: oo@oopen.de # install_update_dovecot.conf # dovecot_from_address: "o.open " dovecot_reply_to: "oo@oopen.de" webmailer_address: "https://webmail-e.oopen.de" -salutation: "O.OPEN\n +salutation: | + O.OPEN ---\n -O.OPEN | Phone: +49 30 / 290 484 91\n -Erkelenzdamm 21 | Fax: +49 30 / 290 484 99\n -D-10999 Berlin | http://oopen.de" + -- + O.OPEN | Phone: +49 30 / 290 484 91 + Erkelenzdamm 21 | Fax: +49 30 / 290 484 99 + D-10999 Berlin | http://oopen.de # install_upgrade_roundcube-webmail.conf # diff --git a/host_vars/file-ah.kanzlei-kiel.netz/file-ah-common.yml b/host_vars/file-ah.kanzlei-kiel.netz/file-ah-common.yml index d74177b..87ff957 100644 --- a/host_vars/file-ah.kanzlei-kiel.netz/file-ah-common.yml +++ b/host_vars/file-ah.kanzlei-kiel.netz/file-ah-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -45,9 +45,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.100.1 - #search: kanzlei-kiel.netz + # search: kanzlei-kiel.netz # optional bridge parameters bridge: {} # bridge: @@ -66,7 +66,7 @@ network_interfaces: # inline hook scripts pre-up: - !!str "ip link set dev eno1np0 up" # pre-up script lines - up: [] #up script lines + up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) down: [] # down script lines @@ -155,7 +155,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - kanzlei-kiel.netz @@ -165,7 +165,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -233,7 +233,6 @@ default_user: - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIItQLQ7lhBY2USF4Jcp4teF+1NydI73VeHYbQW8q4Mcw root@gw-ah' - # --- # vars used by roles/common/tasks/cron.yml # --- @@ -273,7 +272,7 @@ cron_user_special_time_entries: job: "sleep 10 ; /bin/systemctl restart systemd-resolved" insertafter: PATH -#cron_user_special_time_entries: +# cron_user_special_time_entries: # # - name: "Restart DNS Cache service 'systemd-resolved'" # special_time: reboot @@ -281,7 +280,6 @@ cron_user_special_time_entries: # insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -431,7 +429,7 @@ samba_user: - name: buchholz groups: - - buero + - buero - intern - verwaltung password: '20-buch_holz-20' diff --git a/host_vars/file-blkr-alt.blkr.netz/file-blkr-alt-common.yml b/host_vars/file-blkr-alt.blkr.netz/file-blkr-alt-common.yml index e26d8e0..a5529fa 100644 --- a/host_vars/file-blkr-alt.blkr.netz/file-blkr-alt-common.yml +++ b/host_vars/file-blkr-alt.blkr.netz/file-blkr-alt-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.162.1 - #search: blkr.netz + # search: blkr.netz # --- @@ -152,7 +152,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - blkr.netz @@ -162,7 +162,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -177,7 +177,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- diff --git a/host_vars/file-blkr.blkr.netz/file-blkr-common.yml b/host_vars/file-blkr.blkr.netz/file-blkr-common.yml index 0aead0f..6cf25d1 100644 --- a/host_vars/file-blkr.blkr.netz/file-blkr-common.yml +++ b/host_vars/file-blkr.blkr.netz/file-blkr-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.162.1 - #search: blkr.netz + # search: blkr.netz # --- @@ -152,7 +152,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - blkr.netz @@ -162,7 +162,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -177,7 +177,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -200,14 +199,14 @@ cron_user_special_time_entries: # see: roles/common/tasks/vars sudoers_file_user_aliases: - - name: MAIN_USER - entry: 'josephine, julius, julius-e, leonie, buero1, buero2, buero3, referendariat, refa, ref1, sebastian, buero-05, buero-06, lap-01' + - name: MAIN_USER + entry: 'josephine, julius, julius-e, leonie, buero1, buero2, buero3, referendariat, refa, ref1, sebastian, buero-05, buero-06, lap-01' sudoers_file_cmnd_aliases: - - name: REBOOT - entry: '/sbin/reboot' - - name: MANAGE_SERVICE - entry: '/usr/bin/systemctl' + - name: REBOOT + entry: '/sbin/reboot' + - name: MANAGE_SERVICE + entry: '/usr/bin/systemctl' sudoers_file_user_privileges: @@ -249,16 +248,16 @@ nfs_server: 192.168.162.10 # Take car to increase 'fsid' in case of more than one export # nfs_exports: - - src: 192.168.162.10:/data/samba/shares - path: /data/samba/shares - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.162.0/24 - - 10.0.192.0/24 - - 10.1.192.0/24 - - 192.168.63.0/24 - use_fsid_option: true + - src: 192.168.162.10:/data/samba/shares + path: /data/samba/shares + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.162.0/24 + - 10.0.192.0/24 + - 10.1.192.0/24 + - 192.168.63.0/24 + use_fsid_option: true # --- diff --git a/host_vars/file-dissens.dissens.netz/file-dissens-common.yml b/host_vars/file-dissens.dissens.netz/file-dissens-common.yml index 09f2be5..3bd6705 100644 --- a/host_vars/file-dissens.dissens.netz/file-dissens-common.yml +++ b/host_vars/file-dissens.dissens.netz/file-dissens-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.132.1 - #search: blkr.netz + # search: blkr.netz # --- @@ -130,7 +130,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - dissens.netz @@ -140,7 +140,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -189,7 +189,7 @@ default_user: - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINj0nCdFOZm51AVCfPbZ22QROIEiboXZ7RamHvM2E9IM root@backup.warenform.de' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBZQMCGCyIvs5hoNDoTIkKvKmEbxLf+uCYI1vx//ZQYY root@o26-backup' -#extra_user: +# extra_user: # # - name: borg # user_id: 1065 @@ -272,14 +272,14 @@ cron_user_special_time_entries: # see: roles/common/tasks/vars sudoers_file_user_aliases: - - name: MAIN_USER - entry: 'malte.taeubrich, ulla.wittenzellner, sarah.klemm, bernard.koennecke, elenor.faellgren, mario.freidank ' + - name: MAIN_USER + entry: 'malte.taeubrich, ulla.wittenzellner, sarah.klemm, bernard.koennecke, elenor.faellgren, mario.freidank ' sudoers_file_cmnd_aliases: - - name: REBOOT - entry: '/sbin/reboot' - - name: MANAGE_SERVICE - entry: '/usr/bin/systemctl' + - name: REBOOT + entry: '/sbin/reboot' + - name: MANAGE_SERVICE + entry: '/usr/bin/systemctl' sudoers_file_user_privileges: @@ -330,16 +330,16 @@ nfs_server: 192.168.132.10 # Take car to increase 'fsid' in case of more than one export # nfs_exports: - - src: 192.168.132.10:/data/samba/shares - path: /data/samba/shares - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.132.0/24 - - 10.0.192.0/24 - - 10.1.192.0/24 - - 192.168.63.0/24 - use_fsid_option: true + - src: 192.168.132.10:/data/samba/shares + path: /data/samba/shares + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.132.0/24 + - 10.0.192.0/24 + - 10.1.192.0/24 + - 192.168.63.0/24 + use_fsid_option: true # --- @@ -534,7 +534,7 @@ base_home: /data/home samba_homes_virusfilter: true remove_samba_users: [] -#remove_samba_users: +# remove_samba_users: # - name: sebastian.scheele # - name: rositsa.mahdi # - name: laura.sasse diff --git a/host_vars/file-ebs.ebs.netz/file-ebs-common.yml b/host_vars/file-ebs.ebs.netz/file-ebs-common.yml index 3ce54e1..6ba3181 100644 --- a/host_vars/file-ebs.ebs.netz/file-ebs-common.yml +++ b/host_vars/file-ebs.ebs.netz/file-ebs-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.182.1 - #search: ebs.netz + # search: ebs.netz # optional bridge parameters bridge: {} # bridge: @@ -65,7 +65,7 @@ network_interfaces: # inline hook scripts pre-up: - !!str "ip link set dev eno1 up" # pre-up script lines - up: [] #up script lines + up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) down: [] # down script lines @@ -161,7 +161,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ebs.netz @@ -171,7 +171,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.182.254 + - 172.16.182.254 # --- @@ -247,7 +247,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -293,17 +292,16 @@ nfs_server: 192.168.182.10 # Take car to increase 'fsid' in case of more than one export # nfs_exports: - - src: 192.168.182.10:/data/samba/shares - path: /data/samba/shares - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.182.0/24 - - 10.0.192.0/24 - - 10.1.192.0/24 - - 192.168.63.0/24 - use_fsid_option: true - + - src: 192.168.182.10:/data/samba/shares + path: /data/samba/shares + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.182.0/24 + - 10.0.192.0/24 + - 10.1.192.0/24 + - 192.168.63.0/24 + use_fsid_option: true # --- @@ -318,7 +316,7 @@ samba_workgroup: EBS samba_netbios_name: FILE-EBS -#samba_server_min_protocol: !!str NT1 +# samba_server_min_protocol: !!str NT1 samba_groups: @@ -557,7 +555,6 @@ samba_shares: vfs_object_recycle: false - # ============================== diff --git a/host_vars/file-fhxb.fhxb.netz/file-fhxb-common.yml b/host_vars/file-fhxb.fhxb.netz/file-fhxb-common.yml index a6aa2fb..c6982b1 100644 --- a/host_vars/file-fhxb.fhxb.netz/file-fhxb-common.yml +++ b/host_vars/file-fhxb.fhxb.netz/file-fhxb-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.192.1 - #search: fhxb.netz + # search: fhxb.netz # --- @@ -131,7 +131,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - fhxb.netz @@ -141,7 +141,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.192.254 + - 172.16.192.254 # --- @@ -156,7 +156,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -202,28 +201,27 @@ nfs_server: 192.168.192.10 # Take car to increase 'fsid' in case of more than one export # nfs_exports: - - src: 192.168.192.10:/data/home - path: /data/home - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.192.0/23 - - 10.0.192.0/24 - - 10.1.192.0/24 - - 192.168.63.0/24 - use_fsid_option: true - - - src: 192.168.192.10:/data/samba/shares - path: /data/samba/shares - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.192.0/23 - - 10.0.192.0/24 - - 10.1.192.0/24 - - 192.168.63.0/24 - use_fsid_option: true + - src: 192.168.192.10:/data/home + path: /data/home + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.192.0/23 + - 10.0.192.0/24 + - 10.1.192.0/24 + - 192.168.63.0/24 + use_fsid_option: true + - src: 192.168.192.10:/data/samba/shares + path: /data/samba/shares + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.192.0/23 + - 10.0.192.0/24 + - 10.1.192.0/24 + - 192.168.63.0/24 + use_fsid_option: true # --- @@ -285,7 +283,7 @@ samba_groups: group_id: 1480 - name: vermittlung group_id: 1490 - + - name: altlasten group_id: 1510 @@ -358,7 +356,7 @@ samba_user: password: '5hE-7n.JRQ9Y' # Archiv01 - - name : a.rchiv01 + - name: a.rchiv01 groups: - archiv - ausstellungen @@ -371,7 +369,7 @@ samba_user: password: '45pS2X-rim.e' # Archiv02 - - name : a.rchiv02 + - name: a.rchiv02 groups: - archiv - ausstellungen @@ -384,7 +382,7 @@ samba_user: password: '7gqKY/7-nh3Q' # Astrid Schiemann - - name : a.schiemann + - name: a.schiemann groups: - archiv - ausstellungen @@ -408,7 +406,7 @@ samba_user: password: 'G.u3r.tJ6Qkh' # Babara Schaller - - name : b.schaller + - name: b.schaller groups: - archiv - ausstellungen @@ -421,7 +419,7 @@ samba_user: password: 'ufPmZ.L/63yJ' # Ellen Thieleman - - name : e.thieleman + - name: e.thieleman groups: - ausstellungen - buero @@ -430,14 +428,14 @@ samba_user: password: 'MFS79-tzWA/c' # Erika Hausotter - - name : e.hausotter + - name: e.hausotter groups: - archiv - team password: 'A/pY4-9VvUdo' # Fabian Bovens - - name : f.bovens + - name: f.bovens groups: - archiv - ausstellungen @@ -449,7 +447,7 @@ samba_user: password: 'z/Cw3.IzP2xn' # Florian Helm - - name : f.helm + - name: f.helm groups: - altlasten - archiv @@ -475,7 +473,7 @@ samba_user: password: 'z2FE..fUh4fx' # Frauke Erdmann - - name : f.erdmann + - name: f.erdmann groups: - archiv - ausstellungen @@ -488,7 +486,7 @@ samba_user: password: 'P/yV5N9rxA-Y' # Gerhard Grosche - - name : g.grosche + - name: g.grosche groups: - archiv - ausstellungen @@ -500,7 +498,7 @@ samba_user: password: '6/H-EgRqP9-T' # Heike Müller - - name : h.mueller + - name: h.mueller groups: - administration - buero @@ -508,7 +506,7 @@ samba_user: password: 'VT7/n5hHy-Av' # Jana König - - name : j.koenig + - name: j.koenig groups: - administration - archiv @@ -532,7 +530,7 @@ samba_user: password: 'fE6.2K/HpnuS' # Jorinde Splettstößer - - name : j.splettstoesser + - name: j.splettstoesser groups: - administration - archiv @@ -557,7 +555,7 @@ samba_user: password: '2/octHEm/g5H' # Natalie Bayer - - name : n.bayer + - name: n.bayer groups: - administration - altlasten @@ -584,7 +582,7 @@ samba_user: password: 'AI/.44Jt6rhY' # Natalie Maier - - name : n.maier + - name: n.maier groups: - administration - altlasten @@ -611,7 +609,7 @@ samba_user: password: 'kI25L.pfQI/q' # Norbert Schropp - - name : n.schropp + - name: n.schropp groups: - archiv - ausstellungen @@ -623,7 +621,7 @@ samba_user: password: 'rK/puJ2.7sb4' # Praktikum 01 - - name : p.raktikum01 + - name: p.raktikum01 groups: - ausstellungen - buero @@ -634,7 +632,7 @@ samba_user: password: '2IN.R5HIq-ig' # Praktikum 02 - - name : p.raktikum02 + - name: p.raktikum02 groups: - ausstellungen - buero @@ -645,7 +643,7 @@ samba_user: password: 'NnRYo5-d6i/n' # Volo 01 - - name : v.olo01 + - name: v.olo01 groups: - archiv - ausstellungen @@ -665,7 +663,7 @@ samba_user: password: 'A/pY4-9VvUdo' # Volo 02 - - name : v.olo02 + - name: v.olo02 groups: - archiv - ausstellungen @@ -686,7 +684,7 @@ samba_user: password: 'sp29q-Yn-6PY' # Volo 03 - - name : v.olo03 + - name: v.olo03 groups: - archiv - ausstellungen @@ -716,7 +714,7 @@ samba_homes_virusfilter: true # - name: name1 # - name: name2 # -#remove_samba_users: [] +# remove_samba_users: [] remove_samba_users: - name: evren @@ -963,7 +961,6 @@ samba_shares: recycle_path: '@Recycle' - # ============================== diff --git a/host_vars/file-fm.fm.netz/file-fm-common.yml b/host_vars/file-fm.fm.netz/file-fm-common.yml index 073c1d9..7330be4 100644 --- a/host_vars/file-fm.fm.netz/file-fm-common.yml +++ b/host_vars/file-fm.fm.netz/file-fm-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.222.1 - #search: blkr.netz + # search: blkr.netz # --- @@ -130,7 +130,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - fm.netz @@ -140,7 +140,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -203,7 +203,7 @@ default_user: - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHUvk8+UduCcBbQO1YxXSU8SaGIl8x+TBmIFmPb9JQu8 root@gw-fm' - 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN0ibOee8TvYlrEzKno5J6h3ZQs79i0wPElqYvQxAymK root@file-fm' -#extra_user: +# extra_user: # # - name: borg # user_id: 1065 @@ -296,14 +296,14 @@ cron_user_special_time_entries: # see: roles/common/tasks/vars sudoers_file_user_aliases: - - name: MAIN_USER - entry: 'sysadm' + - name: MAIN_USER + entry: 'sysadm' sudoers_file_cmnd_aliases: - - name: REBOOT - entry: '/sbin/reboot' - - name: MANAGE_SERVICE - entry: '/usr/bin/systemctl' + - name: REBOOT + entry: '/sbin/reboot' + - name: MANAGE_SERVICE + entry: '/usr/bin/systemctl' sudoers_file_user_privileges: @@ -354,16 +354,16 @@ nfs_server: 192.168.222.10 # Take car to increase 'fsid' in case of more than one export # nfs_exports: - - src: 192.168.222.10:/data/samba/shares - path: /data/samba/shares - mount_opts: users,rsize=8192,wsize=8192,hard,intr - export_opt: rw,root_squash,sync,subtree_check - export_networks: - - 192.168.222.0/24 - - 10.0.222.0/24 - - 10.1.222.0/24 - - 192.168.63.0/24 - use_fsid_option: true + - src: 192.168.222.10:/data/samba/shares + path: /data/samba/shares + mount_opts: users,rsize=8192,wsize=8192,hard,intr + export_opt: rw,root_squash,sync,subtree_check + export_networks: + - 192.168.222.0/24 + - 10.0.222.0/24 + - 10.1.222.0/24 + - 192.168.63.0/24 + use_fsid_option: true # --- @@ -480,7 +480,7 @@ samba_homes_virusfilter: true # - name: name2 # remove_samba_users: [] -#remove_samba_users: +# remove_samba_users: # - name: elenor.faellgrem # - name: maiken.schiele diff --git a/host_vars/file-ipa.local.netz/file-ipa-common.yml b/host_vars/file-ipa.local.netz/file-ipa-common.yml index b3111eb..e98373f 100644 --- a/host_vars/file-ipa.local.netz/file-ipa-common.yml +++ b/host_vars/file-ipa.local.netz/file-ipa-common.yml @@ -66,14 +66,13 @@ install_compiler_pkgs: true # --- -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/file-kb.anw-kb.netz/file-kb-common.yml b/host_vars/file-kb.anw-kb.netz/file-kb-common.yml index ecefc47..66e08fb 100644 --- a/host_vars/file-kb.anw-kb.netz/file-kb-common.yml +++ b/host_vars/file-kb.anw-kb.netz/file-kb-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-km.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.122.254 + - 172.16.122.254 # --- @@ -112,7 +112,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- diff --git a/host_vars/file-km-alt.anw-km.netz/file-km-alt-common.yml b/host_vars/file-km-alt.anw-km.netz/file-km-alt-common.yml index 9a107ac..e2e06ea 100644 --- a/host_vars/file-km-alt.anw-km.netz/file-km-alt-common.yml +++ b/host_vars/file-km-alt.anw-km.netz/file-km-alt-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,7 +62,7 @@ network_interfaces: # inline hook scripts pre-up: - !!str "ip link set dev enp97s0 up" # pre-up script lines - up: [] #up script lines + up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) down: [] # down script lines @@ -151,7 +151,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-km.netz @@ -161,7 +161,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.122.254 + - 172.16.122.254 # --- @@ -214,7 +214,6 @@ cron_user_entries: job: /root/bin/monitoring/check_ntpsec_service.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -273,7 +272,7 @@ samba_groups: group_id: 1120 - name: wildvang group_id: 1130 - - name: eibelshaeuser + - name: eibelshaeuser group_id: 1140 - name: stahmann group_id: 1150 @@ -287,7 +286,6 @@ samba_groups: group_id: 1190 - samba_user: - name: advoware @@ -591,7 +589,6 @@ samba_user: password: 'uJ5gF/m53p.P' - - name: aphex2 groups: - alle @@ -767,8 +764,8 @@ remove_samba_users: - name: gerhard - name: laura -#remove_samba_users: [] -#remove_samba_users: +# remove_samba_users: [] +# remove_samba_users: # - name: evren samba_shares: diff --git a/host_vars/file-km.anw-km.netz/file-km-common.yml b/host_vars/file-km.anw-km.netz/file-km-common.yml index b8e8dcc..8caf434 100644 --- a/host_vars/file-km.anw-km.netz/file-km-common.yml +++ b/host_vars/file-km.anw-km.netz/file-km-common.yml @@ -4,10 +4,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -58,7 +58,7 @@ network_interfaces: # inline hook scripts pre-up: - !!str "ip link set dev eno1np0 up" # pre-up script lines - up: [] #up script lines + up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) down: [] # down script lines @@ -148,7 +148,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-km.netz @@ -630,7 +630,6 @@ samba_user: password: "uJ5gF/m53p.P" - - name: aphex2 groups: - alle @@ -806,8 +805,8 @@ remove_samba_users: - name: gerhard - name: laura -#remove_samba_users: [] -#remove_samba_users: +# remove_samba_users: [] +# remove_samba_users: # - name: evren samba_shares: diff --git a/host_vars/formbricks-nd.oopen.de/formbricks-nd-common.yml b/host_vars/formbricks-nd.oopen.de/formbricks-nd-common.yml index 50b3894..c114af6 100644 --- a/host_vars/formbricks-nd.oopen.de/formbricks-nd-common.yml +++ b/host_vars/formbricks-nd.oopen.de/formbricks-nd-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -132,7 +132,6 @@ cron_user_entries: job: /root/bin/monitoring/check_ssh.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -197,4 +196,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/g.mx.oopen.de/g.mx-common.yml b/host_vars/g.mx.oopen.de/g.mx-common.yml index 9f0c134..6beca15 100644 --- a/host_vars/g.mx.oopen.de/g.mx-common.yml +++ b/host_vars/g.mx.oopen.de/g.mx-common.yml @@ -43,8 +43,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -55,20 +55,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -81,10 +81,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -94,25 +94,25 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- # vars used by roles/common/tasks/users.yml # --- -#insert_root_ssh_keypair: true +# insert_root_ssh_keypair: true # -#root_ssh_keypair: +# root_ssh_keypair: # - name: id-rsa-dehydrated -# priv_key_src: b.mx/root/.ssh/b.mx-id_rsa-dehydrated +# priv_key_src: g.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated # priv_key_dest: /root/.ssh/id_rsa-dehydrated -# pub_key_src: b.mx/root/.ssh/b.mx-id_rsa-dehydrated.pub +# pub_key_src: g.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated.pub # pub_key_dest: /root/.ssh/id_rsa-dehydrated.pub # - name: id-rsa-opendkim -# priv_key_src: b.mx/root/.ssh/b.mx-id_rsa-opendkim +# priv_key_src: g.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim # priv_key_dest: /root/.ssh/id_rsa-opendkim -# pub_key_src: b.mx/root/.ssh/b.mx-id_rsa-opendkim.pub +# pub_key_src: g.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim.pub # pub_key_dest: /root/.ssh/id_rsa-opendkim.pub @@ -149,42 +149,6 @@ resolved_fallback_nameserver: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/postfix - # - - name: postfix_create_opendkim_key.conf - src_path: g.mx/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: g.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - -copy_plain_files_postfix_host_specific: - - - name: relay_domains - src_path: g.mx/etc/postfix/relay_domains - dest_path: /etc/postfix/relay_domains - - -copy_plain_files_postfwd_host_specific: - - # Postfix Firewall postfwd - # - - name: postfwd.wl-nets - src_path: g.mx/etc/postfix/postfwd.wl-nets - dest_path: /etc/postfix/postfwd.wl-nets - - -copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml diff --git a/host_vars/ga-al-gw.oopen.de/ga-al-gw-common.yml b/host_vars/ga-al-gw.oopen.de/ga-al-gw-common.yml index 1771bd0..be718a0 100644 --- a/host_vars/ga-al-gw.oopen.de/ga-al-gw-common.yml +++ b/host_vars/ga-al-gw.oopen.de/ga-al-gw-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -28,10 +28,10 @@ network_interfaces: address: 172.16.10.1 netmask: 24 gateway: 172.16.10.254 - #nameservers: + # nameservers: # - 192.168.10.1 # - 192.168.10.3 - #search: ga.netz + # search: ga.netz - device: eth2 @@ -90,7 +90,7 @@ network_interfaces: family: inet method: static - #hwaddress: 0c:c4:7a:7d:51:46 + # hwaddress: 0c:c4:7a:7d:51:46 description: address: 10.221.15.254 netmask: 20 @@ -185,8 +185,8 @@ network_interfaces: - /sbin/ip route add 192.168.11.0/24 via 172.16.111.254 - /sbin/ip route add 192.168.78.0/24 via 172.16.111.254 # User Networks Campus - #- /sbin/ip route add 192.168.72.0/24 via 172.16.111.254 - #- /sbin/ip route add 192.168.73.0/24 via 172.16.111.254 + # - /sbin/ip route add 192.168.72.0/24 via 172.16.111.254 + # - /sbin/ip route add 192.168.73.0/24 via 172.16.111.254 # User Network Novalishaus - /sbin/ip route add 192.168.81.0/24 via 172.16.111.254 # User Network Georgshaus @@ -202,7 +202,7 @@ network_interfaces: # WLAN privat Novalishaus - /sbin/ip route add 10.31.0.0/20 via 172.16.111.254 # Management Netork Campus - #- /sbin/ip route add 10.72.1.0/24 via 172.16.111.254 + # - /sbin/ip route add 10.72.1.0/24 via 172.16.111.254 # WLan Router Stockhausen - /sbin/ip route add 10.112.1.0/24 via 172.16.111.254 # WLan Netz @@ -329,7 +329,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -340,7 +340,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 192.168.11.1 + - 192.168.11.1 # --- @@ -482,30 +482,29 @@ bind9_gateway_acl: - 192.168.10.2 - bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.10.1" +bind9_transfer_source: !!str "192.168.10.1" bind9_notify_source: !!str "192.168.10.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -529,4 +528,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-al-kvm2.ga.netz/ga-al-kvm2-common.yml b/host_vars/ga-al-kvm2.ga.netz/ga-al-kvm2-common.yml index 6cab5bb..2c7d450 100644 --- a/host_vars/ga-al-kvm2.ga.netz/ga-al-kvm2-common.yml +++ b/host_vars/ga-al-kvm2.ga.netz/ga-al-kvm2-common.yml @@ -123,7 +123,6 @@ sshd_permit_root_login: !!str "prohibit-password" # --- - # ============================== diff --git a/host_vars/ga-al-kvm3.ga.netz/ga-al-kvm3-common.yml b/host_vars/ga-al-kvm3.ga.netz/ga-al-kvm3-common.yml index 13f7e17..b1757b9 100644 --- a/host_vars/ga-al-kvm3.ga.netz/ga-al-kvm3-common.yml +++ b/host_vars/ga-al-kvm3.ga.netz/ga-al-kvm3-common.yml @@ -123,7 +123,6 @@ sshd_permit_root_login: !!str "prohibit-password" # --- - # ============================== diff --git a/host_vars/ga-al-relay.ga.netz/ga-al-relay-common.yml b/host_vars/ga-al-relay.ga.netz/ga-al-relay-common.yml index 8ce88b3..aa192ed 100644 --- a/host_vars/ga-al-relay.ga.netz/ga-al-relay-common.yml +++ b/host_vars/ga-al-relay.ga.netz/ga-al-relay-common.yml @@ -133,7 +133,7 @@ systemd_resolved: true # Servername für DNS-over-TLS: dot.ffmuc.net # für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb) resolved_nameserver: - - 192.168.10.1 + - 192.168.10.1 - 192.168.10.3 # search domains @@ -141,7 +141,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -233,30 +233,29 @@ bind9_gateway_acl: - 192.168.10.2 - bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.10.2" +bind9_transfer_source: !!str "192.168.10.2" bind9_notify_source: !!str "192.168.10.2" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -287,21 +286,19 @@ copy_template_files: [] # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- hostname: ga-al-relay.ga.netz ipv4_address: 192.168.10.2 -#ipv6_address: +# ipv6_address: admin_email: it@gemeinschaft-altenschlirf.org is_relay_host: !!str "false" sasl_auth_enable: !!str "yes" - template_files_mailsystem_script: - name: mailsystem_install_postfix_advanced.conf diff --git a/host_vars/ga-campus-gw-temp.ga.netz/ga-campus-gw-temp-common.yml b/host_vars/ga-campus-gw-temp.ga.netz/ga-campus-gw-temp-common.yml index 04ae8a4..5160193 100644 --- a/host_vars/ga-campus-gw-temp.ga.netz/ga-campus-gw-temp-common.yml +++ b/host_vars/ga-campus-gw-temp.ga.netz/ga-campus-gw-temp-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -28,10 +28,10 @@ network_interfaces: address: 172.16.72.1 netmask: 24 gateway: 172.16.72.254 - #nameservers: + # nameservers: # - 192.168.81.1 # - 172.16.81.254 - #search: ga.netz ga.intra + # search: ga.netz ga.intra - device: eno2 headline: eno2 - Uplink Lehrer-und Schülerdatenbank (LUSD) @@ -45,7 +45,6 @@ network_interfaces: - /sbin/ip route add 10.9.131.0/24 via 192.168.100.253 - - device: eno3 family: inet method: manual @@ -76,7 +75,7 @@ network_interfaces: family: inet method: manual post-up: - # VLAN 20 - LAN 2 Campus including UniFi Accesspoints + # VLAN 20 - LAN 2 Campus including UniFi Accesspoints - /sbin/ip link add link eno4 name eno4.20 type vlan id 20 - device: eno4.20 @@ -109,7 +108,6 @@ network_interfaces: netmask: 24 - # --- # vars used by roles/ansible_dependencies # --- @@ -197,7 +195,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - campus.netz @@ -208,7 +206,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -346,28 +344,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.81.1" +bind9_transfer_source: !!str "192.168.81.1" bind9_notify_source: !!str "192.168.81.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -391,4 +389,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-gh-gw.oopen.de/ga-gh-gw-common.yml b/host_vars/ga-gh-gw.oopen.de/ga-gh-gw-common.yml index 39e3214..09f51d6 100644 --- a/host_vars/ga-gh-gw.oopen.de/ga-gh-gw-common.yml +++ b/host_vars/ga-gh-gw.oopen.de/ga-gh-gw-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -31,7 +31,7 @@ network_interfaces: - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -132,7 +132,7 @@ cron_user_entries: job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -208,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -219,7 +219,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -359,28 +359,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.85.1" +bind9_transfer_source: !!str "192.168.85.1" bind9_notify_source: !!str "192.168.85.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -404,4 +404,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-nh-gw.oopen.de/ga-nh-gw-common.yml b/host_vars/ga-nh-gw.oopen.de/ga-nh-gw-common.yml index d9b0fd6..8041d01 100644 --- a/host_vars/ga-nh-gw.oopen.de/ga-nh-gw-common.yml +++ b/host_vars/ga-nh-gw.oopen.de/ga-nh-gw-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -28,10 +28,10 @@ network_interfaces: address: 172.16.80.1 netmask: 24 gateway: 172.16.80.254 - #nameservers: + # nameservers: # - 192.168.81.1 # - 172.16.81.254 - #search: ga.netz ga.intra + # search: ga.netz ga.intra - device: eno2 @@ -45,7 +45,7 @@ network_interfaces: - device: eno5 - headline: eno5 - LAN + headline: eno5 - LAN auto: true family: inet method: static @@ -136,7 +136,7 @@ cron_user_entries: job: /root/bin/manage-gw-config/copy_gateway-config.sh GA-NH -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -212,7 +212,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -223,7 +223,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -363,28 +363,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.81.1" +bind9_transfer_source: !!str "192.168.81.1" bind9_notify_source: !!str "192.168.81.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -408,4 +408,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-st-gw-ersatz.ga.netz/ga-st-gw-ersatz-common.yml b/host_vars/ga-st-gw-ersatz.ga.netz/ga-st-gw-ersatz-common.yml index 9850611..f8fb121 100644 --- a/host_vars/ga-st-gw-ersatz.ga.netz/ga-st-gw-ersatz-common.yml +++ b/host_vars/ga-st-gw-ersatz.ga.netz/ga-st-gw-ersatz-common.yml @@ -79,8 +79,8 @@ systemd_resolved: true # Servername für DNS-over-TLS: dot.ffmuc.net # für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb) resolved_nameserver: - - 192.168.11.1 - - 192.168.10.1 + - 192.168.11.1 + - 192.168.10.1 - 192.168.11.3 # search domains @@ -88,7 +88,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -99,8 +99,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 127.0.0.1 - + - 127.0.0.1 # --- @@ -240,28 +239,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - internaldns + - internaldns -#bind9_transfer_source: !!str "192.168.11.1" -#bind9_notify_source: !!str "192.168.11.1" +# bind9_transfer_source: !!str "192.168.11.1" +# bind9_notify_source: !!str "192.168.11.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -285,4 +284,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-st-gw.ga.netz/ga-st-gw-common.yml b/host_vars/ga-st-gw.ga.netz/ga-st-gw-common.yml index 3cf3995..8e9a640 100644 --- a/host_vars/ga-st-gw.ga.netz/ga-st-gw-common.yml +++ b/host_vars/ga-st-gw.ga.netz/ga-st-gw-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -26,7 +26,7 @@ network_interfaces: family: inet method: static address: 192.168.11.18 - #gateway: 192.168.11.254 + # gateway: 192.168.11.254 netmask: 24 - device: lan4 @@ -81,7 +81,7 @@ network_interfaces: netmask: 24 - - device: lan6 + - device: lan6 headline: lan6 - holds VLAN 211 device for Network Telefons Stockhausen auto: false family: inet @@ -136,7 +136,7 @@ network_interfaces: # ---------- # Note: Install the 'ifenslave' package, necessary to enable bonding: - # + # # apt-get install ifenslave # ---------- - device: bond0 @@ -186,7 +186,7 @@ network_interfaces: # ---------- # Note: Install the 'ifenslave' package, necessary to enable bonding: - # + # # apt-get install ifenslave # ---------- - device: sfp0 @@ -200,7 +200,7 @@ network_interfaces: - 192.168.11.1 - 192.168.10.3 search: ga.netz ga.intra - #bond: + # bond: # slaves: lan3 lan11 # # Mode 4 (802.3ad) # # @@ -382,7 +382,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -393,7 +393,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 192.168.10.1 + - 192.168.10.1 # --- @@ -451,7 +451,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -587,28 +586,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - internaldns + - internaldns -bind9_transfer_source: !!str "192.168.11.1" +bind9_transfer_source: !!str "192.168.11.1" bind9_notify_source: !!str "192.168.11.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -632,4 +631,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/ga-st-kvm1.ga.netz/ga-st-kvm1-common.yml b/host_vars/ga-st-kvm1.ga.netz/ga-st-kvm1-common.yml index cb7cac1..d7e65ef 100644 --- a/host_vars/ga-st-kvm1.ga.netz/ga-st-kvm1-common.yml +++ b/host_vars/ga-st-kvm1.ga.netz/ga-st-kvm1-common.yml @@ -123,7 +123,6 @@ sshd_permit_root_login: !!str "prohibit-password" # --- - # ============================== diff --git a/host_vars/ga-st-kvm5.ga.netz/ga-st-kvm5-common.yml b/host_vars/ga-st-kvm5.ga.netz/ga-st-kvm5-common.yml index 9b67d5a..9138b56 100644 --- a/host_vars/ga-st-kvm5.ga.netz/ga-st-kvm5-common.yml +++ b/host_vars/ga-st-kvm5.ga.netz/ga-st-kvm5-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -195,7 +195,6 @@ sshd_permit_root_login: !!str "prohibit-password" # --- - # ============================== diff --git a/host_vars/ga-st-lxc1.ga.netz/ga-st-lxc1-common.yml b/host_vars/ga-st-lxc1.ga.netz/ga-st-lxc1-common.yml index 23ec706..b8e453d 100644 --- a/host_vars/ga-st-lxc1.ga.netz/ga-st-lxc1-common.yml +++ b/host_vars/ga-st-lxc1.ga.netz/ga-st-lxc1-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -38,7 +38,7 @@ network_interfaces: # - "91.239.100.100" # anycast.censurfridns.dk # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -66,7 +66,7 @@ network_interfaces: - device: eno2 # use only once per device (for the first device entry) - headline: eno2 - LAN Interface VLAN definition + headline: eno2 - LAN Interface VLAN definition auto: true family: inet method: manual @@ -95,10 +95,10 @@ network_interfaces: # nameservers: # - "194.150.168.168" # dns.as250.net # - "91.239.100.100" # anycast.censurfridns.dk - #nameservers: + # nameservers: # - 192.168.11.1 # - 192.168.10.3 - #search: ga.netz ga.intra + # search: ga.netz ga.intra # --- @@ -176,8 +176,8 @@ systemd_resolved: true # Servername für DNS-over-TLS: dot.ffmuc.net # für iOS 14+: DoT-Server-Konfiguration (unsigniert, vom PrHdb) resolved_nameserver: - - 192.168.11.1 - - 192.168.10.1 + - 192.168.11.1 + - 192.168.10.1 - 192.168.11.3 # search domains @@ -185,7 +185,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -196,7 +196,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -311,4 +311,3 @@ sudo_users: # --- root_user: {} - diff --git a/host_vars/ga-st-mail.ga.netz/ga-st-mail-common.yml b/host_vars/ga-st-mail.ga.netz/ga-st-mail-common.yml index b82d709..b75a160 100644 --- a/host_vars/ga-st-mail.ga.netz/ga-st-mail-common.yml +++ b/host_vars/ga-st-mail.ga.netz/ga-st-mail-common.yml @@ -86,7 +86,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 192.168.11.1 + - 192.168.11.1 # --- @@ -242,21 +242,20 @@ copy_plain_files_postfwd_host_specific: dest_path: /etc/postfix/postfwd.cf -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- hostname: mx.gemeinschaft-altenschlirf.de ipv4_address: 192.168.11.2 -#ipv6_address: +# ipv6_address: admin_email: it@gemeinschaft-altenschlirf.org is_relay_host: !!str "false" @@ -270,7 +269,7 @@ db_in_use: !!str "true" postfix_db_type: PostgreSQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: +# postfix_db_host: postfix_db_pass: R_wuKauoTE7+AJg9 # install_amavis.conf @@ -279,7 +278,7 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.gemeinschaft-altenschlirf.de email_welcome_message: "\n @@ -317,10 +316,10 @@ autoreply_hostname: autoreply.gemeinschaft-altenschlirf.de roundcube_db_type: pgsql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: +# roundcube_db_host: roundcube_db_pass: 'K3TbMmTfnCXdj4vz' -#roundcube_acl_plugin: true +# roundcube_acl_plugin: true roundcube_product_name: Gemeinschaft Altenschlirf - Webmailer roundcube_support_url: https://www.gemeinschaft-altenschlirf.de diff --git a/host_vars/ga-st-mm.ga.netz/ga-st-mm-common.yml b/host_vars/ga-st-mm.ga.netz/ga-st-mm-common.yml index e9a9911..8120a1b 100644 --- a/host_vars/ga-st-mm.ga.netz/ga-st-mm-common.yml +++ b/host_vars/ga-st-mm.ga.netz/ga-st-mm-common.yml @@ -88,7 +88,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -99,7 +99,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 192.168.11.3 + - 192.168.11.3 # --- @@ -209,7 +209,6 @@ sudo_users: # --- - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/ga-st-services.ga.netz/ga-st-services-common.yml b/host_vars/ga-st-services.ga.netz/ga-st-services-common.yml index 26d37a9..9d7de31 100644 --- a/host_vars/ga-st-services.ga.netz/ga-st-services-common.yml +++ b/host_vars/ga-st-services.ga.netz/ga-st-services-common.yml @@ -86,7 +86,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ga.netz @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 192.168.10.1 + - 192.168.10.1 - 192.168.10.3 @@ -195,19 +195,18 @@ sudo_users: # Postfix Firewall postfwd # - #- name: postfwd.wl-user + # - name: postfwd.wl-user # src_path: ga-st-mail/etc/postfix/postfwd.wl-user # dest_path: /etc/postfix/postfwd.wl-user -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/git.oopen.de/git-common.yml b/host_vars/git.oopen.de/git-common.yml index edda230..2bd9e80 100644 --- a/host_vars/git.oopen.de/git-common.yml +++ b/host_vars/git.oopen.de/git-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -80,10 +80,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -145,4 +145,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/git.warenform.de/git-common.yml b/host_vars/git.warenform.de/git-common.yml index 24caaa1..3117213 100644 --- a/host_vars/git.warenform.de/git-common.yml +++ b/host_vars/git.warenform.de/git-common.yml @@ -83,7 +83,6 @@ resolved_nameserver: - 2a01:4f8:0:1::add:9999 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -133,4 +132,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gitea.so36.net/gitea-common.yml b/host_vars/gitea.so36.net/gitea-common.yml index 1c8ea13..106925a 100644 --- a/host_vars/gitea.so36.net/gitea-common.yml +++ b/host_vars/gitea.so36.net/gitea-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by role firewall @@ -30,8 +31,8 @@ sshd_ports: - 1036 sshd_listen_address: - - '::' - - '0.0.0.0' + - '::' + - '0.0.0.0' sshd_host_keys: - /etc/ssh/ssh_host_rsa_key @@ -68,7 +69,7 @@ sshd_allowed_users: # - diffie-hellman-group-exchange-sha256 # - diffie-hellman-group14-sha1 # -#sshd_kexalgorithms: {} +# sshd_kexalgorithms: {} sshd_kexalgorithms: - curve25519-sha256 - curve25519-sha256@libssh.org @@ -83,7 +84,7 @@ sshd_kexalgorithms: # - chacha20-poly1305@openssh.com # - aes256-gcm@openssh.com # - aes256-ctr -#sshd_ciphers: {} +# sshd_ciphers: {} sshd_ciphers: - chacha20-poly1305@openssh.com - aes256-gcm@openssh.com @@ -92,13 +93,13 @@ sshd_ciphers: - aes192-ctr - aes128-ctr -#sshd_macs: {} +# sshd_macs: {} sshd_macs: - hmac-sha2-256-etm@openssh.com - hmac-sha2-512-etm@openssh.com - umac-128-etm@openssh.com -#sshd_hostkeyalgorithms: {} +# sshd_hostkeyalgorithms: {} sshd_hostkeyalgorithms: - ssh-ed25519 - ssh-ed25519-cert-v01@openssh.com @@ -107,12 +108,12 @@ sshd_hostkeyalgorithms: - rsa-sha2-256-cert-v01@openssh.com - rsa-sha2-512-cert-v01@openssh.com -#sshd_kexalgorithms: +# sshd_kexalgorithms: # - curve25519-sha256@libssh.org # - diffie-hellman-group-exchange-sha256 # - diffie-hellman-group14-sha1 -#sshd_ciphers: +# sshd_ciphers: # - chacha20-poly1305@openssh.com # - aes256-gcm@openssh.com # - aes256-ctr @@ -220,7 +221,7 @@ default_user: password: $6$GntX81EP$O1GEmQF.BbOQfTMMw/m/BDKSXmANVpqmz0nyzw4O4R2/iK9huGOAjT/2eq8FVdMghvNOvdwrWtwohO.Mg4V9n. shell: /bin/bash ssh_keys: - - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC5IhVprsvVOcFPbZzD9xR0nCjZ/9qVG6RhLJ7QBSts81nRvLwnmvcMBHSf5Rfaigey7Ff5dLHfJnxRE0KDATn6n2yd/5mXpn2GAA8hDVfhdsmsb5U7bROjZNr8MmIUrP7c3msUGx1FtvzhwxtyvIWOFQpWx+W5biBa6hFjIxT1pkUJqe6fclp7xbGYKZiqZRBS4qKG5CpKnisuOYDsqYPND+OkU+PShoxGVzp1JywIVze7qeKv6GyYbRA9SP9Np+5Mit6B21Io4zOI81c2Rz6sPX7mwEAQEs7iCm2hzG8qJws45Lb4ERqDkVEVhGNUyHjHgGebS1sZx1mLExdurXlPm1l/EamkncDFDCutHXtLP7lsFFiym7fKUjSEgiiLmyu5Xm+mwZvesKa1FYNaeiFWfYZpCJrNzIk+ffs+mgg3kmL4Sd4Ooy7jXPX+WJe5Xyh1KLU/+Wj2TVrhN+LbmupYAti/Wgd3DA1v601svmG82aLmyJRtKC0rGMePH3kDbtqU72kYpzI8mXERe1TIQ00Z77kQBR/7BF/9y5/0YmYDcXt1wNCoSie+mzz3xYcEdLAc7T+DhYpd4M6VgWnuz/exzRzhQwoSdEKkEED8CpEoBrEWEiMdrlElGmlkVomLU7P9i9j1rshX/pAq0asnqeSoPdC3vNbU3keiJQnhIHECvw== chris@luna' + - 'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQC5IhVprsvVOcFPbZzD9xR0nCjZ/9qVG6RhLJ7QBSts81nRvLwnmvcMBHSf5Rfaigey7Ff5dLHfJnxRE0KDATn6n2yd/5mXpn2GAA8hDVfhdsmsb5U7bROjZNr8MmIUrP7c3msUGx1FtvzhwxtyvIWOFQpWx+W5biBa6hFjIxT1pkUJqe6fclp7xbGYKZiqZRBS4qKG5CpKnisuOYDsqYPND+OkU+PShoxGVzp1JywIVze7qeKv6GyYbRA9SP9Np+5Mit6B21Io4zOI81c2Rz6sPX7mwEAQEs7iCm2hzG8qJws45Lb4ERqDkVEVhGNUyHjHgGebS1sZx1mLExdurXlPm1l/EamkncDFDCutHXtLP7lsFFiym7fKUjSEgiiLmyu5Xm+mwZvesKa1FYNaeiFWfYZpCJrNzIk+ffs+mgg3kmL4Sd4Ooy7jXPX+WJe5Xyh1KLU/+Wj2TVrhN+LbmupYAti/Wgd3DA1v601svmG82aLmyJRtKC0rGMePH3kDbtqU72kYpzI8mXERe1TIQ00Z77kQBR/7BF/9y5/0YmYDcXt1wNCoSie+mzz3xYcEdLAc7T+DhYpd4M6VgWnuz/exzRzhQwoSdEKkEED8CpEoBrEWEiMdrlElGmlkVomLU7P9i9j1rshX/pAq0asnqeSoPdC3vNbU3keiJQnhIHECvw== chris@luna' sudo_users: - alex @@ -272,4 +273,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-123.oopen.de/gw-123-common.yml b/host_vars/gw-123.oopen.de/gw-123-common.yml index 3683ec4..c869328 100644 --- a/host_vars/gw-123.oopen.de/gw-123-common.yml +++ b/host_vars/gw-123.oopen.de/gw-123-common.yml @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - 123.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -219,4 +219,3 @@ git_firewall_repository: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-ah.oopen.de/gw-ah-common.yml b/host_vars/gw-ah.oopen.de/gw-ah-common.yml index a5d700f..2a9dacb 100644 --- a/host_vars/gw-ah.oopen.de/gw-ah-common.yml +++ b/host_vars/gw-ah.oopen.de/gw-ah-common.yml @@ -93,7 +93,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - kanzlei-kiel.netz @@ -103,7 +103,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -227,28 +227,28 @@ bind9_gateway_acl: - 192.168.100.30 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - internaldns + - internaldns -bind9_transfer_source: !!str "192.168.100.1" +bind9_transfer_source: !!str "192.168.100.1" bind9_notify_source: !!str "192.168.100.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -271,4 +271,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-ak.oopen.de/gw-ak-common.yml b/host_vars/gw-ak.oopen.de/gw-ak-common.yml index 6e64a04..401db02 100644 --- a/host_vars/gw-ak.oopen.de/gw-ak-common.yml +++ b/host_vars/gw-ak.oopen.de/gw-ak-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.0.1 netmask: 24 gateway: 172.16.0.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.0.1 - #search: ebs.netz kanzlei-kiel.netz elster.netz + # search: ebs.netz kanzlei-kiel.netz elster.netz - device: eno2 - headline: eno2 - WLAN + headline: eno2 - WLAN auto: true family: inet method: static @@ -143,7 +143,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ak.netz @@ -153,7 +153,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -244,4 +244,3 @@ bind9_gateway_listen_on: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-akb.oopen.de/gw-akb-common.yml b/host_vars/gw-akb.oopen.de/gw-akb-common.yml index 7d22be2..90f3a54 100644 --- a/host_vars/gw-akb.oopen.de/gw-akb-common.yml +++ b/host_vars/gw-akb.oopen.de/gw-akb-common.yml @@ -26,7 +26,7 @@ copy_additional_plain_files_sysctl: # vars used by roles/common/tasks/sshd.yml # --- -#sshd_hostkeyalgorithms: +# sshd_hostkeyalgorithms: # - ssh-ed25519 # - ssh-ed25519-cert-v01@openssh.com # - rsa-sha2-256 @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - akb.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -214,4 +214,3 @@ bind9_gateway_listen_on: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-b3.oopen.de/gw-b3-common.yml b/host_vars/gw-b3.oopen.de/gw-b3-common.yml index 5938c80..0f163fa 100644 --- a/host_vars/gw-b3.oopen.de/gw-b3-common.yml +++ b/host_vars/gw-b3.oopen.de/gw-b3-common.yml @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - b3-bornim.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -166,8 +166,6 @@ cron_user_special_time_entries: insertafter: PATH - - # --- # vars used by roles/common/tasks/users.yml # --- @@ -204,4 +202,3 @@ git_firewall_repository: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-blkr.oopen.de/gw-blkr-common.yml b/host_vars/gw-blkr.oopen.de/gw-blkr-common.yml index bd5f954..9f0ef88 100644 --- a/host_vars/gw-blkr.oopen.de/gw-blkr-common.yml +++ b/host_vars/gw-blkr.oopen.de/gw-blkr-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.162.1 netmask: 24 gateway: 172.16.162.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.162.1 - #search: blkr.netz + # search: blkr.netz - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -54,7 +54,7 @@ network_interfaces: - device: eno3 - headline: eno3 - WLAN + headline: eno3 - WLAN auto: true family: inet method: static @@ -123,7 +123,7 @@ cron_user_entries: hour: 0-8 job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -208,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - blkr.netz @@ -218,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -287,4 +287,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-campus.oopen.de/gw-campus-common.yml b/host_vars/gw-campus.oopen.de/gw-campus-common.yml index f0bd497..9f9cba0 100644 --- a/host_vars/gw-campus.oopen.de/gw-campus-common.yml +++ b/host_vars/gw-campus.oopen.de/gw-campus-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -28,10 +28,10 @@ network_interfaces: address: 172.16.72.1 netmask: 24 gateway: 172.16.72.254 - #nameservers: + # nameservers: # - 192.168.81.1 # - 172.16.81.254 - #search: ga.netz ga.intra + # search: ga.netz ga.intra - device: eno2 headline: eno2 - Uplink Lehrer-und Schülerdatenbank (LUSD) @@ -45,7 +45,6 @@ network_interfaces: - /sbin/ip route add 10.9.131.0/24 via 192.168.100.253 - - device: eno3 family: inet method: manual @@ -76,7 +75,7 @@ network_interfaces: family: inet method: manual post-up: - # VLAN 20 - LAN 2 Campus including UniFi Accesspoints + # VLAN 20 - LAN 2 Campus including UniFi Accesspoints - /sbin/ip link add link eno4 name eno4.20 type vlan id 20 - device: eno4.20 @@ -105,11 +104,10 @@ network_interfaces: family: inet method: static address: 192.168.11.72 - #gateway: 192.168.11.254 + # gateway: 192.168.11.254 netmask: 24 - # --- # vars used by roles/ansible_dependencies # --- @@ -247,7 +245,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - campus.netz @@ -258,7 +256,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -396,28 +394,28 @@ bind9_gateway_acl: - 192.168.10.2 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - none + - none -bind9_transfer_source: !!str "192.168.81.1" +bind9_transfer_source: !!str "192.168.81.1" bind9_notify_source: !!str "192.168.81.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -441,4 +439,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-ckubu.local.netz/gw-ckubu-common.yml b/host_vars/gw-ckubu.local.netz/gw-ckubu-common.yml index 4b6cc2e..3eda47a 100644 --- a/host_vars/gw-ckubu.local.netz/gw-ckubu-common.yml +++ b/host_vars/gw-ckubu.local.netz/gw-ckubu-common.yml @@ -89,7 +89,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - local.netz @@ -99,7 +99,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -149,7 +149,6 @@ cron_user_entries: job: /root/bin/admin-stuff/speedtest.sh - cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -214,4 +213,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-d11.oopen.de/gw-d11-common.yml b/host_vars/gw-d11.oopen.de/gw-d11-common.yml index 320f903..c82fef5 100644 --- a/host_vars/gw-d11.oopen.de/gw-d11-common.yml +++ b/host_vars/gw-d11.oopen.de/gw-d11-common.yml @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -215,4 +215,3 @@ bind9_gateway_listen_on: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-dissens.oopen.de/gw-dissens-common.yml b/host_vars/gw-dissens.oopen.de/gw-dissens-common.yml index 3ed5895..dea19a5 100644 --- a/host_vars/gw-dissens.oopen.de/gw-dissens-common.yml +++ b/host_vars/gw-dissens.oopen.de/gw-dissens-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -186,7 +186,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - dissens.netz @@ -196,7 +196,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -314,26 +314,26 @@ bind9_gateway_acl: - ::1/128 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} -bind9_transfer_source: !!str "192.168.132.1" +bind9_transfer_source: !!str "192.168.132.1" bind9_notify_source: !!str "192.168.132.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -356,4 +356,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-ebs.oopen.de/gw-ebs-common.yml b/host_vars/gw-ebs.oopen.de/gw-ebs-common.yml index a806161..88991d6 100644 --- a/host_vars/gw-ebs.oopen.de/gw-ebs-common.yml +++ b/host_vars/gw-ebs.oopen.de/gw-ebs-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -139,7 +139,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - ebs.netz @@ -149,7 +149,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -275,28 +275,28 @@ bind9_gateway_acl: - 192.168.182.30 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - internaldns + - internaldns -bind9_transfer_source: !!str "192.168.182.1" +bind9_transfer_source: !!str "192.168.182.1" bind9_notify_source: !!str "192.168.182.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -319,4 +319,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-elster.oopen.de/gw-elster-common.yml b/host_vars/gw-elster.oopen.de/gw-elster-common.yml index e151b0e..68d8d83 100644 --- a/host_vars/gw-elster.oopen.de/gw-elster-common.yml +++ b/host_vars/gw-elster.oopen.de/gw-elster-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.202.1 netmask: 24 gateway: 172.16.202.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.202.1 - #search: elster.netz ebs.netz + # search: elster.netz ebs.netz - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -54,7 +54,7 @@ network_interfaces: - device: eno3 - headline: eno3 - WLAN + headline: eno3 - WLAN auto: true family: inet method: static @@ -124,7 +124,7 @@ cron_user_entries: job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -209,7 +209,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - elster.netz @@ -219,8 +219,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -286,28 +285,28 @@ bind9_gateway_acl: - 192.168.182.1 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} bind9_gateway_allow_transfer: - - internaldns + - internaldns -bind9_transfer_source: !!str "192.168.202.1" +bind9_transfer_source: !!str "192.168.202.1" bind9_notify_source: !!str "192.168.202.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -331,4 +330,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-fhxb.oopen.de/gw-fhxb-common.yml b/host_vars/gw-fhxb.oopen.de/gw-fhxb-common.yml index 1e22ce1..a8fcc34 100644 --- a/host_vars/gw-fhxb.oopen.de/gw-fhxb-common.yml +++ b/host_vars/gw-fhxb.oopen.de/gw-fhxb-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.192.1 netmask: 24 gateway: 172.16.192.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.192.1 - #search: ebs.netz kanzlei-kiel.netz elster.netz + # search: ebs.netz kanzlei-kiel.netz elster.netz - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -143,7 +143,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - fhxb.netz @@ -153,7 +153,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -274,4 +274,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-flr.oopen.de/gw-flr-common.yml b/host_vars/gw-flr.oopen.de/gw-flr-common.yml index 73e1d41..1fa4e0e 100644 --- a/host_vars/gw-flr.oopen.de/gw-flr-common.yml +++ b/host_vars/gw-flr.oopen.de/gw-flr-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -28,14 +28,14 @@ network_interfaces: address: 172.16.102.1 netmask: 24 gateway: 172.16.102.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 172.16.102.254 - #search: flr.netz + # search: flr.netz - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -53,7 +53,7 @@ network_interfaces: - device: eno3 - headline: eno3 - WLAN + headline: eno3 - WLAN auto: true family: inet method: static @@ -122,7 +122,7 @@ cron_user_entries: job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -207,7 +207,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - flr.netz @@ -217,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -286,4 +286,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-fm.oopen.de/gw-fm-common.yml b/host_vars/gw-fm.oopen.de/gw-fm-common.yml index a10ab2b..047143f 100644 --- a/host_vars/gw-fm.oopen.de/gw-fm-common.yml +++ b/host_vars/gw-fm.oopen.de/gw-fm-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -160,7 +160,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - fm.netz @@ -170,7 +170,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.222.254 + - 172.16.222.254 - 194.150.168.168 @@ -295,4 +295,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-irights.oopen.de/gw-irights-common.yml b/host_vars/gw-irights.oopen.de/gw-irights-common.yml index ef6c71a..f0c6b89 100644 --- a/host_vars/gw-irights.oopen.de/gw-irights-common.yml +++ b/host_vars/gw-irights.oopen.de/gw-irights-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -31,7 +31,7 @@ network_interfaces: - device: eno3 - headline: eno3 - LAN + headline: eno3 - LAN auto: true family: inet method: static @@ -49,7 +49,7 @@ network_interfaces: - device: eno4 - headline: eno4 - Uplink DSL via mobile data (Fritzbox 6850 5G) + headline: eno4 - Uplink DSL via mobile data (Fritzbox 6850 5G) auto: true family: inet method: static @@ -119,7 +119,7 @@ cron_user_entries: job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -204,7 +204,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +214,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -282,4 +282,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-kb.oopen.de/gw-kb-common.yml b/host_vars/gw-kb.oopen.de/gw-kb-common.yml index dfeb5b8..4d07d97 100644 --- a/host_vars/gw-kb.oopen.de/gw-kb-common.yml +++ b/host_vars/gw-kb.oopen.de/gw-kb-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -31,7 +31,7 @@ network_interfaces: - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -100,7 +100,7 @@ cron_user_entries: job: /root/bin/manage-gw-config/copy_gateway-config.sh ANW-KB -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Check if Postfix Service is running at boot time" @@ -195,7 +195,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-kb.netz @@ -205,7 +205,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -274,4 +274,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-km.oopen.de/gw-km-common.yml b/host_vars/gw-km.oopen.de/gw-km-common.yml index d3d3827..c7a9050 100644 --- a/host_vars/gw-km.oopen.de/gw-km-common.yml +++ b/host_vars/gw-km.oopen.de/gw-km-common.yml @@ -5,10 +5,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -31,7 +31,7 @@ network_interfaces: - device: eno5 - headline: eno5 - LAN + headline: eno5 - LAN auto: true family: inet method: static @@ -109,7 +109,7 @@ cron_user_entries: hour: 0-8 job: /root/bin/admin-stuff/speedtest.sh -#cron_user_special_time_entries: [] +# cron_user_special_time_entries: [] cron_user_special_time_entries: - name: "Restart NTP service 'ntpsec'" @@ -194,7 +194,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-km.netz @@ -204,7 +204,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -273,4 +273,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-mbr.oopen.de/gw-mbr-common.yml b/host_vars/gw-mbr.oopen.de/gw-mbr-common.yml index fa7f237..0dfbdb1 100644 --- a/host_vars/gw-mbr.oopen.de/gw-mbr-common.yml +++ b/host_vars/gw-mbr.oopen.de/gw-mbr-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -30,7 +30,7 @@ network_interfaces: # gateway: 172.16.112.254 - device: enp0s20f0 - headline: enp0s20f0 - Uplink + headline: enp0s20f0 - Uplink auto: true family: inet method: static @@ -39,7 +39,7 @@ network_interfaces: - device: enp0s20f1 - headline: enp0s20f1 - LAN + headline: enp0s20f1 - LAN auto: true family: inet method: static @@ -207,7 +207,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - mbr-bln.netz @@ -217,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -335,26 +335,26 @@ bind9_gateway_acl: - ::1/128 bind9_gateway_listen_on_v6: - - none + - none bind9_gateway_listen_on: - any -#bind9_gateway_allow_transfer: {} +# bind9_gateway_allow_transfer: {} -bind9_transfer_source: !!str "192.168.112.1" +bind9_transfer_source: !!str "192.168.112.1" bind9_notify_source: !!str "192.168.112.1" -#bind9_gateway_allow_query: {} +# bind9_gateway_allow_query: {} bind9_gateway_allow_query: - local-net -#bind9_gateway_allow_query_cache: {} +# bind9_gateway_allow_query_cache: {} bind9_gateway_allow_query_cache: - local-net -bind9_gateway_recursion: !!str "yes" -#bind9_gateway_allow_recursion: {} +bind9_gateway_recursion: !!str "yes" +# bind9_gateway_allow_recursion: {} bind9_gateway_allow_recursion: - local-net @@ -377,4 +377,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-opp-neu.opp.netz/gw-opp-neu-common.yml b/host_vars/gw-opp-neu.opp.netz/gw-opp-neu-common.yml index 2ad366f..42e96d3 100644 --- a/host_vars/gw-opp-neu.opp.netz/gw-opp-neu-common.yml +++ b/host_vars/gw-opp-neu.opp.netz/gw-opp-neu-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.62.2 netmask: 24 gateway: 172.16.62.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.62.1 - #search: ebs.netz kanzlei-kiel.netz elster.netz + # search: ebs.netz kanzlei-kiel.netz elster.netz - device: eno2 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -143,7 +143,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - opp.netz @@ -153,7 +153,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -233,4 +233,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-opp.oopen.de/gw-opp-common.yml b/host_vars/gw-opp.oopen.de/gw-opp-common.yml index 6c6876c..4203568 100644 --- a/host_vars/gw-opp.oopen.de/gw-opp-common.yml +++ b/host_vars/gw-opp.oopen.de/gw-opp-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -29,14 +29,14 @@ network_interfaces: address: 172.16.62.1 netmask: 24 gateway: 172.16.62.254 - #nameservers: + # nameservers: # - 127.0.0.1 # - 192.168.62.1 - #search: ebs.netz kanzlei-kiel.netz elster.netz + # search: ebs.netz kanzlei-kiel.netz elster.netz - device: eno3 - headline: eno2 - LAN + headline: eno2 - LAN auto: true family: inet method: static @@ -143,7 +143,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - opp.netz @@ -153,7 +153,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -276,4 +276,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/gw-replacement4.local.netz/gw-replacement4-common.yml b/host_vars/gw-replacement4.local.netz/gw-replacement4-common.yml index 6ca8d9c..05b7855 100644 --- a/host_vars/gw-replacement4.local.netz/gw-replacement4-common.yml +++ b/host_vars/gw-replacement4.local.netz/gw-replacement4-common.yml @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - wf.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -172,4 +172,3 @@ bind9_gateway_listen_on: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-replacment.oopen.de/gw-replacment-common.yml b/host_vars/gw-replacment.oopen.de/gw-replacment-common.yml index 3f05f31..609cab3 100644 --- a/host_vars/gw-replacment.oopen.de/gw-replacment-common.yml +++ b/host_vars/gw-replacment.oopen.de/gw-replacment-common.yml @@ -98,17 +98,17 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - -local.netz + - local.netz resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -154,4 +154,3 @@ install_bind_packages: true root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-replacment2.oopen.de/gw-replacment2-common.yml b/host_vars/gw-replacment2.oopen.de/gw-replacment2-common.yml index 3f05f31..609cab3 100644 --- a/host_vars/gw-replacment2.oopen.de/gw-replacment2-common.yml +++ b/host_vars/gw-replacment2.oopen.de/gw-replacment2-common.yml @@ -98,17 +98,17 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - -local.netz + - local.netz resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -154,4 +154,3 @@ install_bind_packages: true root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-replacment3.oopen.de/gw-replacment3-common.yml b/host_vars/gw-replacment3.oopen.de/gw-replacment3-common.yml index 3f05f31..609cab3 100644 --- a/host_vars/gw-replacment3.oopen.de/gw-replacment3-common.yml +++ b/host_vars/gw-replacment3.oopen.de/gw-replacment3-common.yml @@ -98,17 +98,17 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - -local.netz + - local.netz resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -154,4 +154,3 @@ install_bind_packages: true root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/gw-spr.oopen.de/gw-spr-common.yml b/host_vars/gw-spr.oopen.de/gw-spr-common.yml index 07ca5f5..2025ac6 100644 --- a/host_vars/gw-spr.oopen.de/gw-spr-common.yml +++ b/host_vars/gw-spr.oopen.de/gw-spr-common.yml @@ -98,7 +98,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - sprachenatelier.netz @@ -108,7 +108,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -214,4 +214,3 @@ bind9_gateway_listen_on: root_user: name: root password: $y$j9T$IVBTpn.OrI6YiQ9q3fA8b1$Y1bmID5yXJbKfoLFt1VmQs6LezeTj5/1M9ppZBD2Pn4 - diff --git a/host_vars/iam-nd.oopen.de/iam-nd-common.yml b/host_vars/iam-nd.oopen.de/iam-nd-common.yml index 5ceb929..550ed5e 100644 --- a/host_vars/iam-nd.oopen.de/iam-nd-common.yml +++ b/host_vars/iam-nd.oopen.de/iam-nd-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -157,7 +157,6 @@ cron_user_entries: job: /var/lib/dehydrated/tools/update_ssl_directives.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -222,4 +221,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/initiativenserver.oopen.de/initiativenserver-common.yml b/host_vars/initiativenserver.oopen.de/initiativenserver-common.yml index 132043f..5cfff9c 100644 --- a/host_vars/initiativenserver.oopen.de/initiativenserver-common.yml +++ b/host_vars/initiativenserver.oopen.de/initiativenserver-common.yml @@ -83,7 +83,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,8 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -143,4 +142,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/keycloak-nd.oopen.de/keycloak-nd-common.yml b/host_vars/keycloak-nd.oopen.de/keycloak-nd-common.yml index 5ceb929..550ed5e 100644 --- a/host_vars/keycloak-nd.oopen.de/keycloak-nd-common.yml +++ b/host_vars/keycloak-nd.oopen.de/keycloak-nd-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -157,7 +157,6 @@ cron_user_entries: job: /var/lib/dehydrated/tools/update_ssl_directives.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -222,4 +221,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/lists.mx.warenform.de/lists.mx-common.yml b/host_vars/lists.mx.warenform.de/lists.mx-common.yml index 81ff675..43118c9 100644 --- a/host_vars/lists.mx.warenform.de/lists.mx-common.yml +++ b/host_vars/lists.mx.warenform.de/lists.mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -96,7 +96,7 @@ resolved_dnssec: !!str "allow-downgrade" # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -107,9 +107,9 @@ insert_root_ssh_keypair: true root_ssh_keypair: - name: id-rsa-opendkim - priv_key_src: lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim + priv_key_src: lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim priv_key_dest: /root/.ssh/id_rsa-opendkim - pub_key_src: lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub + pub_key_src: lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub pub_key_dest: /root/.ssh/id_rsa-opendkim.pub @@ -146,28 +146,6 @@ root_ssh_keypair: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - - name: postfix_create_opendkim_key.conf - src_path: lists.mx.warenform/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: lists.mx.warenform/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - - name: install_sympa.conf - src_path: lists.mx.warenform/usr/local/src/sympa/conf/install_sympa.conf - dest_path: /usr/local/src/sympa/conf/install_sympa.conf - - -copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml diff --git a/host_vars/lxc-host-kb.anw-kb.netz/lxc-host-kb-common.yml b/host_vars/lxc-host-kb.anw-kb.netz/lxc-host-kb-common.yml index ebc771b..3a2d109 100644 --- a/host_vars/lxc-host-kb.anw-kb.netz/lxc-host-kb-common.yml +++ b/host_vars/lxc-host-kb.anw-kb.netz/lxc-host-kb-common.yml @@ -28,12 +28,11 @@ sshd_pubkey_authentication: !!str "yes" sshd_password_authentication: !!str "yes" - # --- # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -93,7 +92,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - anw-kb.netz @@ -103,7 +102,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.32.254 + - 172.16.32.254 # --- @@ -205,4 +204,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/mail-neu.cadus.org/mail-neu-common.yml b/host_vars/mail-neu.cadus.org/mail-neu-common.yml index e470978..fc0b334 100644 --- a/host_vars/mail-neu.cadus.org/mail-neu-common.yml +++ b/host_vars/mail-neu.cadus.org/mail-neu-common.yml @@ -128,19 +128,18 @@ copy_plain_files_postfwd_host_specific: # Postfix Firewall postfwd # - #- name: postfwd.wl-user + # - name: postfwd.wl-user # src_path: mail.cadus/etc/postfix/postfwd.wl-user # dest_path: /etc/postfix/postfwd.wl-user -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- @@ -159,7 +158,7 @@ db_in_use: !!str "true" postfix_db_type: MySQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: +# postfix_db_host: postfix_db_pass: T3CJnFMJNX9wmhNs mysql_credentials: !!str "-u root -S /run/mysqld/mysqld.sock" @@ -169,7 +168,7 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.cadus.org email_welcome_message: "\n @@ -209,7 +208,7 @@ autoreply_hostname: autoreply.cadus.org roundcube_db_type: mysql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: +# roundcube_db_host: roundcube_db_pass: 'j3vqsK7Ldm7MxNjH' roundcube_acl_plugin: false diff --git a/host_vars/mail.cadus.org/mail-common.yml b/host_vars/mail.cadus.org/mail-common.yml index b44410b..cfc3dbc 100644 --- a/host_vars/mail.cadus.org/mail-common.yml +++ b/host_vars/mail.cadus.org/mail-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 185.12.64.2 + - 185.12.64.2 # --- @@ -198,19 +198,18 @@ copy_plain_files_postfwd_host_specific: # Postfix Firewall postfwd # - #- name: postfwd.wl-user + # - name: postfwd.wl-user # src_path: mail.cadus/etc/postfix/postfwd.wl-user # dest_path: /etc/postfix/postfwd.wl-user -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- @@ -238,7 +237,7 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.cadus.org email_welcome_message: "\n @@ -255,19 +254,19 @@ D-10243 Berlin\n admin@cadus.org\n " -#email_welcome_message: "\n -#Hallo,\n +# email_welcome_message: "\n +# Hallo,\n # -#Ihre/Deine neue E-Mail Adresse ist eingerichtet.\n +# Ihre/Deine neue E-Mail Adresse ist eingerichtet.\n # -#Cadus e.V. - Redefine Global Solidarity\n +# Cadus e.V. - Redefine Global Solidarity\n # -#--\n -#Cadus e.V.\n -#Am Sudhaus 2\n -#D-12053 Berlin\n -#admin@cadus.org\n -#" +# --\n +# Cadus e.V.\n +# Am Sudhaus 2\n +# D-12053 Berlin\n +# admin@cadus.org\n +# " # install_update_dovecot.conf dovecot_msg_language: en @@ -292,7 +291,7 @@ autoreply_hostname: autoreply.cadus.org roundcube_db_type: mysql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: +# roundcube_db_host: roundcube_db_pass: 'j3vqsK7Ldm7MxNjH' roundcube_acl_plugin: false diff --git a/host_vars/mail.faire-mobilitaet.de/mail-common.yml b/host_vars/mail.faire-mobilitaet.de/mail-common.yml index 61c52c2..9cf894b 100644 --- a/host_vars/mail.faire-mobilitaet.de/mail-common.yml +++ b/host_vars/mail.faire-mobilitaet.de/mail-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 185.12.64.1 + - 185.12.64.1 # --- @@ -107,14 +107,14 @@ insert_root_ssh_keypair: true root_ssh_keypair: - name: id-rsa-dehydrated - priv_key_src: mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated + priv_key_src: mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated priv_key_dest: /root/.ssh/id_rsa-dehydrated - pub_key_src: mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub + pub_key_src: mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub pub_key_dest: /root/.ssh/id_rsa-dehydrated.pub - name: id-rsa-opendkim - priv_key_src: mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim + priv_key_src: mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim priv_key_dest: /root/.ssh/id_rsa-opendkim - pub_key_src: mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub + pub_key_src: mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub pub_key_dest: /root/.ssh/id_rsa-opendkim.pub @@ -151,50 +151,14 @@ root_ssh_keypair: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: mail.faire-mobilitaet/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_create_opendkim_key.conf - src_path: mail.faire-mobilitaet/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_postfix_add_mailboxes.conf - src_path: mail.faire-mobilitaet/root/bin/postfix/conf/postfix_add_mailboxes.conf - dest_path: /root/bin/postfix/conf/postfix_add_mailboxes.conf - - - name: postfix_sent_userinfo_postfix.conf - src_path: mail.faire-mobilitaet/root/bin/postfix/conf/sent_userinfo_postfix.conf - dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: mail.faire-mobilitaet/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - -copy_plain_files_postfwd_host_specific: [] - - # Postfix Firewall postfwd - # - #- name: postfwd.wl-user - # src_path: mail.faire-mobilitaet/etc/postfix/postfwd.wl-user - # dest_path: /etc/postfix/postfwd.wl-user - - -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- @@ -213,7 +177,7 @@ db_in_use: !!str "true" postfix_db_type: PostgreSQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: +# postfix_db_host: postfix_db_pass: sp4xMdnXJkdMXnq9 # install_amavis.conf @@ -222,32 +186,32 @@ mp_receipt_number: 106015125438 si_authorisation_signature: abb4ec6b194639f3d123154f1b971843a3b8751d8c1bcdc7d07ed6db26621b11bca0e23d2a42b60aef3f7b7803a1466a964d90c7b1e82d67c7680c8f46b59a4e # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.cadus.org -email_welcome_message: "\n -Hallo,\n +email_welcome_message: | -Projekt Faire Mobilität + Hallo, ---\n -Projekt Faire Mobilität | Phone: +49 30 219653721\n -Paula-Thiede-Ufer 10 | Fax:\n -D-10179 Berlin | E-MAIL: kontakt@faire-mobilitaet.de\n -" + Projekt Faire Mobilität + + -- + Projekt Faire Mobilität | Phone: +49 30 219653721 + Paula-Thiede-Ufer 10 | Fax: + D-10179 Berlin | E-MAIL: kontakt@faire-mobilitaet.de # install_update_dovecot.conf # dovecot_from_address: "Administrator E-Mail " dovecot_reply_to: "admin@faire-mobilitaet.de" webmailer_address: "https://webmail.faire-mobilitaet.de" -salutation: "\Projekt Faire Mobilität\n +salutation: | + Projekt Faire Mobilität ---\n -Projekt Faire Mobilität | Phone: +49 30 219653721\n -Paula-Thiede-Ufer 10 | Fax:\n -D-10179 Berlin | E-MAIL: kontakt@faire-mobilitaet.de\n -" + -- + Projekt Faire Mobilität | Phone: +49 30 219653721 + Paula-Thiede-Ufer 10 | Fax: + D-10179 Berlin | E-MAIL: kontakt@faire-mobilitaet.de # install_upgrade_roundcube-webmail.conf # @@ -258,10 +222,10 @@ autoreply_hostname: autoreply.faire-mobilitaet.de roundcube_db_type: pgsql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: +# roundcube_db_host: roundcube_db_pass: 'gqnzTrfsjnRv4PWW' -#roundcube_acl_plugin: false +# roundcube_acl_plugin: false roundcube_product_name: O.OPEN - Webmailer roundcube_support_url: https://www.faire-mobilitaet.de/ diff --git a/host_vars/matomo-01.oopen.de/matomo-01-common.yml b/host_vars/matomo-01.oopen.de/matomo-01-common.yml index 03a8c80..e4477dd 100644 --- a/host_vars/matomo-01.oopen.de/matomo-01-common.yml +++ b/host_vars/matomo-01.oopen.de/matomo-01-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -85,10 +85,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -146,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/meet.akweb.de/meet-common.yml b/host_vars/meet.akweb.de/meet-common.yml index 483b5b7..1609d5d 100644 --- a/host_vars/meet.akweb.de/meet-common.yml +++ b/host_vars/meet.akweb.de/meet-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -117,17 +117,17 @@ cron_user_entries: - name: "Restart Prosody Servive (used by Jitsi Meet Authentification)" minute: 57 - hour: 05 + hour: '05' job: systemctl restart prosody.service - name: "Check if cert for coTURN service is up-to-date" - minute: 03 - hour: 05 + minute: '03' + hour: '05' job: /root/bin/monitoring/check_cert_for_service.sh - name: "Check if cert(s) for Prosody service are up-to-date" minute: 13 - hour: 07 + hour: '07' job: /root/bin/monitoring/check_cert_for_prosody.sh - name: "Check if SSH service is running. Restart service if needed." @@ -195,13 +195,13 @@ git_firewall_repository: dest: /usr/local/src/ipt-server git_other_repositories: - - name: jitsi - repo: https://git.oopen.de/install/jitsi - dest: /usr/local/src/jitsi + - name: jitsi + repo: https://git.oopen.de/install/jitsi + dest: /usr/local/src/jitsi - - name: etherpad-lite - repo: https://git.oopen.de/install/etherpad-lite - dest: /usr/local/src/etherpad-lite + - name: etherpad-lite + repo: https://git.oopen.de/install/etherpad-lite + dest: /usr/local/src/etherpad-lite # ============================== @@ -210,4 +210,3 @@ git_other_repositories: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/meet.oopen.de/meet-common.yml b/host_vars/meet.oopen.de/meet-common.yml index 85d8011..46c5479 100644 --- a/host_vars/meet.oopen.de/meet-common.yml +++ b/host_vars/meet.oopen.de/meet-common.yml @@ -24,7 +24,7 @@ # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -43,8 +43,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -55,20 +55,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -86,10 +86,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -99,7 +99,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -119,17 +119,17 @@ cron_user_entries: - name: "Restart Prosody Servive (used by Jitsi Meet Authentification)" minute: 57 - hour: 05 + hour: '05' job: systemctl restart prosody.service - name: "Check if cert for coTURN service is up-to-date" - minute: 03 - hour: 05 + minute: '03' + hour: '05' job: /root/bin/monitoring/check_cert_for_service.sh - name: "Check if cert(s) for Prosody service are up-to-date" minute: 13 - hour: 07 + hour: '07' job: /root/bin/monitoring/check_cert_for_prosody.sh - name: "Check if SSH service is running. Restart service if needed." @@ -158,7 +158,6 @@ cron_user_entries: job: /var/lib/dehydrated/tools/update_ssl_directives.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -196,13 +195,13 @@ git_firewall_repository: dest: /usr/local/src/ipt-server git_other_repositories: - - name: jitsi - repo: https://git.oopen.de/install/jitsi - dest: /usr/local/src/jitsi + - name: jitsi + repo: https://git.oopen.de/install/jitsi + dest: /usr/local/src/jitsi - - name: etherpad-lite - repo: https://git.oopen.de/install/etherpad-lite - dest: /usr/local/src/etherpad-lite + - name: etherpad-lite + repo: https://git.oopen.de/install/etherpad-lite + dest: /usr/local/src/etherpad-lite # ============================== @@ -214,4 +213,3 @@ git_other_repositories: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/mm-irights.oopen.de/mm-irights-common.yml b/host_vars/mm-irights.oopen.de/mm-irights-common.yml index 96b3708..0f4a0a4 100644 --- a/host_vars/mm-irights.oopen.de/mm-irights-common.yml +++ b/host_vars/mm-irights.oopen.de/mm-irights-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -82,10 +82,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,7 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -198,4 +198,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/mm-migration.oopen.de/mm-migration-common.yml b/host_vars/mm-migration.oopen.de/mm-migration-common.yml index b6b4b5c..508cfaf 100644 --- a/host_vars/mm-migration.oopen.de/mm-migration-common.yml +++ b/host_vars/mm-migration.oopen.de/mm-migration-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - oopen.de @@ -95,7 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -138,4 +138,3 @@ resolved_fallback_nameserver: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/mm-rav.oopen.de/mm-rav-common.yml b/host_vars/mm-rav.oopen.de/mm-rav-common.yml index f471eeb..d783678 100644 --- a/host_vars/mm-rav.oopen.de/mm-rav-common.yml +++ b/host_vars/mm-rav.oopen.de/mm-rav-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -82,10 +82,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,7 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -203,4 +203,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/mm.oopen.de/mm-common.yml b/host_vars/mm.oopen.de/mm-common.yml index c7bc5cc..58178ad 100644 --- a/host_vars/mm.oopen.de/mm-common.yml +++ b/host_vars/mm.oopen.de/mm-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -84,10 +84,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -149,4 +149,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/moodle.oopen.de/moodle-common.yml b/host_vars/moodle.oopen.de/moodle-common.yml index 5025a82..bd4c2c7 100644 --- a/host_vars/moodle.oopen.de/moodle-common.yml +++ b/host_vars/moodle.oopen.de/moodle-common.yml @@ -24,7 +24,7 @@ # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -64,13 +64,13 @@ git_firewall_repository: dest: /usr/local/src/ipt-server git_other_repositories: - - name: moodle - repo: https://git.oopen.de/install/moodle - dest: /usr/local/src/moodle + - name: moodle + repo: https://git.oopen.de/install/moodle + dest: /usr/local/src/moodle - - name: bigbluebutton - repo: https://git.oopen.de/install/bigbluebutton - dest: /usr/local/src/bigbluebutton + - name: bigbluebutton + repo: https://git.oopen.de/install/bigbluebutton + dest: /usr/local/src/bigbluebutton # ============================== @@ -82,4 +82,3 @@ git_other_repositories: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/munin.oopen.de/munin-common.yml b/host_vars/munin.oopen.de/munin-common.yml index d745bdb..ea6be7d 100644 --- a/host_vars/munin.oopen.de/munin-common.yml +++ b/host_vars/munin.oopen.de/munin-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -84,10 +84,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -149,4 +149,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/mx.warenform.de/mx-common.yml b/host_vars/mx.warenform.de/mx-common.yml index 1230812..b0ec03d 100644 --- a/host_vars/mx.warenform.de/mx-common.yml +++ b/host_vars/mx.warenform.de/mx-common.yml @@ -45,8 +45,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -57,20 +57,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 83.223.66.51 + - 83.223.66.51 # --- @@ -146,49 +146,6 @@ root_ssh_keypair: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: mx.warenform.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_create_opendkim_key.conf - src_path: mx.warenform.de/root/bin/postfix/conf/create_opendkim_key.conf - dest_path: /root/bin/postfix/conf/create_opendkim_key.conf - - - name: postfix_postfix_add_mailboxes.conf - src_path: mx.warenform.de/root/bin/postfix/conf/postfix_add_mailboxes.conf - dest_path: /root/bin/postfix/conf/postfix_add_mailboxes.conf - - - name: postfix_sent_userinfo_postfix.conf - src_path: mx.warenform.de/root/bin/postfix/conf/sent_userinfo_postfix.conf - dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf - - - name: postfix_whitelist_mb_sigs.conf - src_path: mx.warenform.de/root/bin/postfix/conf/whitelist_mb_sigs.conf - dest_path: /root/bin/postfix/conf/whitelist_mb_sigs.conf - - -copy_plain_files_postfwd_host_specific: [] - - # Postfix Firewall postfwd - # - #- name: postfwd.wl-user - # src_path: mx.warenform/etc/postfix/postfwd.wl-user - # dest_path: /etc/postfix/postfwd.wl-user - - -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml @@ -208,7 +165,7 @@ db_in_use: !!str "true" postfix_db_type: PostgreSQL postfix_db_name: postfix postfix_db_user: postfix -#postfix_db_host: /run/postgresql +# postfix_db_host: /run/postgresql postfix_db_pass: CbX8vg347Vvm # install_amavis.conf @@ -217,21 +174,21 @@ mp_receipt_number: 106015125438 si_authorisation_signature: 76ed7ca6670dbee497e1a0397a7e178c4caa25888bc26d7327d1eab0195342a4cfa522dcf10382623d57dbc2a79bd37627b9a52def4d4bfe617d26e35405ce3b # install_postfixadmin.conf -# +# website_name_postfixadmin: adm.warenform.de -email_welcome_message: "\n -Hallo,\n +email_welcome_message: | -Ihre neue E-Mail Adresse ist eingerichtet.\n + Hallo, -Das WARENFORM-Team\n + Ihre neue E-Mail Adresse ist eingerichtet. ---\n -WARENFORM | Phone: +49 30 / 61 65 17 52 -0\n -Schierker Str. 24 | Fax: +49 30 / 61 65 17 52 -66\n -D-10999 Berlin | http://www.warenform.net\n -" + Das WARENFORM-Team + + -- + WARENFORM | Phone: +49 30 / 61 65 17 52 -0 + Schierker Str. 24 | Fax: +49 30 / 61 65 17 52 -66 + D-10999 Berlin | http://www.warenform.net # install_update_dovecot.conf @@ -239,12 +196,13 @@ D-10999 Berlin | http://www.warenform.net\n dovecot_from_address: "warenform gbr " dovecot_reply_to: "hilfe@kunden.warenform.net" webmailer_address: "https://webmail.warenform.de" -salutation: "Das WARENFORM-Team\n +salutation: | + Das WARENFORM-Team -WARENFORM | Phone: +49 30 / 61 65 17 52 -0\n -Schierker Str. 24 | Fax: +49 30 / 61 65 17 52 -66\n -D-10999 Berlin | http://www.warenform.net\n" + WARENFORM | Phone: +49 30 / 61 65 17 52 -0 + Schierker Str. 24 | Fax: +49 30 / 61 65 17 52 -66 + D-10999 Berlin | http://www.warenform.net # install_upgrade_roundcube-webmail.conf @@ -256,10 +214,10 @@ autoreply_hostname: autoreply.warenform.de roundcube_db_type: pgsql roundcube_db_name: roundcubemail roundcube_db_user: roundcube -#roundcube_db_host: localhost +# roundcube_db_host: localhost roundcube_db_pass: 'Hoo5heis' -#roundcube_acl_plugin: false +# roundcube_acl_plugin: false roundcube_product_name: O.OPEN - Webmailer roundcube_support_url: https://www.warenform.net diff --git a/host_vars/nc-gw.oopen.de/nc-gw-common.yml b/host_vars/nc-gw.oopen.de/nc-gw-common.yml index 0e401de..f6bdf1c 100644 --- a/host_vars/nc-gw.oopen.de/nc-gw-common.yml +++ b/host_vars/nc-gw.oopen.de/nc-gw-common.yml @@ -77,4 +77,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/nd-archiv.warenform.de/nd-archiv-common.yml b/host_vars/nd-archiv.warenform.de/nd-archiv-common.yml index 64a5374..01c26e8 100644 --- a/host_vars/nd-archiv.warenform.de/nd-archiv-common.yml +++ b/host_vars/nd-archiv.warenform.de/nd-archiv-common.yml @@ -91,7 +91,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -101,13 +101,13 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- # vars used by roles/common/tasks/users.yml # --- - + create_sftp_group: false insert_ssh_keypair_backup_server: false @@ -129,7 +129,6 @@ ssh_keypair_backup_client: target: backup.warenform.de - # --- # vars used by roles/common/tasks/users-systemfiles.yml # --- @@ -172,4 +171,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/nd-live.warenform.de/nd-live-common.yml b/host_vars/nd-live.warenform.de/nd-live-common.yml index 64a5374..01c26e8 100644 --- a/host_vars/nd-live.warenform.de/nd-live-common.yml +++ b/host_vars/nd-live.warenform.de/nd-live-common.yml @@ -91,7 +91,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -101,13 +101,13 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- # vars used by roles/common/tasks/users.yml # --- - + create_sftp_group: false insert_ssh_keypair_backup_server: false @@ -129,7 +129,6 @@ ssh_keypair_backup_client: target: backup.warenform.de - # --- # vars used by roles/common/tasks/users-systemfiles.yml # --- @@ -172,4 +171,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/nd.warenform.de/nd-common.yml b/host_vars/nd.warenform.de/nd-common.yml index 64a5374..01c26e8 100644 --- a/host_vars/nd.warenform.de/nd-common.yml +++ b/host_vars/nd.warenform.de/nd-common.yml @@ -91,7 +91,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -101,13 +101,13 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- # vars used by roles/common/tasks/users.yml # --- - + create_sftp_group: false insert_ssh_keypair_backup_server: false @@ -129,7 +129,6 @@ ssh_keypair_backup_client: target: backup.warenform.de - # --- # vars used by roles/common/tasks/users-systemfiles.yml # --- @@ -172,4 +171,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/nscache.oopen.de/nscache-common.yml b/host_vars/nscache.oopen.de/nscache-common.yml index 763bbc1..722572e 100644 --- a/host_vars/nscache.oopen.de/nscache-common.yml +++ b/host_vars/nscache.oopen.de/nscache-common.yml @@ -112,4 +112,3 @@ acl_caching_nameserver: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/o12.oopen.de/o12-common.yml b/host_vars/o12.oopen.de/o12-common.yml index fce42ae..0c3ee2a 100644 --- a/host_vars/o12.oopen.de/o12-common.yml +++ b/host_vars/o12.oopen.de/o12-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -33,9 +33,9 @@ network_interfaces: method: manual hwaddress: 52:54:00:2a:b7:76 description: Bridge Interface IPv4 for LXC - address: - netmask: - gateway: + address: + netmask: + gateway: metric: pointopoint: mtu: @@ -66,7 +66,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -111,7 +111,7 @@ network_interfaces: # - !!str "ip route add default via 83.223.86.1" # pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.115/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) @@ -161,8 +161,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -173,20 +173,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -200,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - oopen.de @@ -212,7 +212,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -279,7 +279,6 @@ cron_user_entries: job: /root/bin/LXC/boot-autostart-lx-container.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -326,4 +325,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o13-cryptpad.oopen.de/o13-cryptpad-common.yml b/host_vars/o13-cryptpad.oopen.de/o13-cryptpad-common.yml index 01e9f8d..501e6ad 100644 --- a/host_vars/o13-cryptpad.oopen.de/o13-cryptpad-common.yml +++ b/host_vars/o13-cryptpad.oopen.de/o13-cryptpad-common.yml @@ -1,5 +1,6 @@ --- - +# yamllint disable rule:line-length + # --- # vars used by roles/ansible_dependencies # --- @@ -83,7 +84,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o13-mail.oopen.de/o13-mail-common.yml b/host_vars/o13-mail.oopen.de/o13-mail-common.yml index 328f2f7..a17db7f 100644 --- a/host_vars/o13-mail.oopen.de/o13-mail-common.yml +++ b/host_vars/o13-mail.oopen.de/o13-mail-common.yml @@ -1,5 +1,6 @@ --- - +# yamllint disable rule:line-length + # --- # vars used by roles/ansible_dependencies # --- @@ -82,7 +83,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -92,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -146,52 +147,6 @@ sudo_users: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: o13-mail/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_check-postfix-fatal-errors.conf - src_path: o13-mail/root/bin/postfix/conf/check-postfix-fatal-errors.conf - dest_path: /root/bin/postfix/conf/check-postfix-fatal-errors.conf - - -copy_plain_files_postfwd_host_specific: - - - name: postfwd.wl-hosts - src_path: o13-mail/etc/postfix/postfwd.wl-hosts - dest_path: /etc/postfix/postfwd.wl-hosts - - - name: postfwd.wl-nets - src_path: o13-mail/etc/postfix/postfwd.wl-nets - dest_path: /etc/postfix/postfwd.wl-nets - - - name: postfwd.wl-sender - src_path: o13-mail/etc/postfix/postfwd.wl-sender - dest_path: /etc/postfix/postfwd.wl-sender - - - name: postfwd.wl-user - src_path: o13-mail/etc/postfix/postfwd.wl-user - dest_path: /etc/postfix/postfwd.wl-user - - # Postfix Firewall postfwd - # - #- name: postfwd.wl-user - # src_path: o13-mail/etc/postfix/postfwd.wl-user - # dest_path: /etc/postfix/postfwd.wl-user - - -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/caching-nameserver.yml diff --git a/host_vars/o13-mumble.oopen.de/o13-mumble-common.yml b/host_vars/o13-mumble.oopen.de/o13-mumble-common.yml index 01e9f8d..501e6ad 100644 --- a/host_vars/o13-mumble.oopen.de/o13-mumble-common.yml +++ b/host_vars/o13-mumble.oopen.de/o13-mumble-common.yml @@ -1,5 +1,6 @@ --- - +# yamllint disable rule:line-length + # --- # vars used by roles/ansible_dependencies # --- @@ -83,7 +84,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o13-pad.oopen.de/o13-pad-common.yml b/host_vars/o13-pad.oopen.de/o13-pad-common.yml index 01e9f8d..501e6ad 100644 --- a/host_vars/o13-pad.oopen.de/o13-pad-common.yml +++ b/host_vars/o13-pad.oopen.de/o13-pad-common.yml @@ -1,5 +1,6 @@ --- - +# yamllint disable rule:line-length + # --- # vars used by roles/ansible_dependencies # --- @@ -83,7 +84,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o13-staging-board.oopen.de/o13-staging-board-common.yml b/host_vars/o13-staging-board.oopen.de/o13-staging-board-common.yml index 5839dbb..eba02a5 100644 --- a/host_vars/o13-staging-board.oopen.de/o13-staging-board-common.yml +++ b/host_vars/o13-staging-board.oopen.de/o13-staging-board-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/network_interfaces @@ -28,7 +29,7 @@ # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -89,7 +90,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -99,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -173,4 +174,3 @@ git_firewall_repository: root_user: name: root password: $y$j9T$myZ6f5/klmH0HDN2mb9tv/$s/bBrr6PEXdEgtn9CZYzBNZsA4.r6gWYYeZ4LAYotp9 - diff --git a/host_vars/o13-web.oopen.de/o13-web-common.yml b/host_vars/o13-web.oopen.de/o13-web-common.yml index 01e9f8d..501e6ad 100644 --- a/host_vars/o13-web.oopen.de/o13-web-common.yml +++ b/host_vars/o13-web.oopen.de/o13-web-common.yml @@ -1,5 +1,6 @@ --- - +# yamllint disable rule:line-length + # --- # vars used by roles/ansible_dependencies # --- @@ -83,7 +84,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +94,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o13.oopen.de/o13-common.yml b/host_vars/o13.oopen.de/o13-common.yml index 49b11bb..8c8971c 100644 --- a/host_vars/o13.oopen.de/o13-common.yml +++ b/host_vars/o13.oopen.de/o13-common.yml @@ -1,14 +1,15 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/network_interfaces # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -20,7 +21,7 @@ network_interface_required_packages: network_interfaces: - + # --- # vars used by roles/ansible_dependencies # --- @@ -104,7 +105,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -114,7 +115,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o17.oopen.de/o17-common.yml b/host_vars/o17.oopen.de/o17-common.yml index b9597ca..823cbe2 100644 --- a/host_vars/o17.oopen.de/o17-common.yml +++ b/host_vars/o17.oopen.de/o17-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -66,7 +66,7 @@ network_interfaces: search: oopen.de warenform.de # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -111,7 +111,7 @@ network_interfaces: # - !!str "ip route add default via 83.223.86.1" # pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.85.203/24 dev br0" - !!str "ip route add default via 83.223.85.1" post-up: [] # post-up script lines (alias for up) @@ -119,7 +119,7 @@ network_interfaces: down: [] # down script lines post-down: [] # post-down script lines - + # --- # vars used by roles/ansible_dependencies # --- @@ -161,8 +161,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -173,20 +173,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -200,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - oopen.de @@ -212,7 +212,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -327,7 +327,6 @@ git_firewall_repository: # --- - # ============================== diff --git a/host_vars/o18.oopen.de/o18-common.yml b/host_vars/o18.oopen.de/o18-common.yml index 9bb9cd2..dc7aace 100644 --- a/host_vars/o18.oopen.de/o18-common.yml +++ b/host_vars/o18.oopen.de/o18-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 5.9.97.96 netmask 255.255.255.224 gw 5.9.97.97 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -160,8 +159,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -172,20 +171,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -201,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -322,4 +321,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o19.oopen.de/o19-common.yml b/host_vars/o19.oopen.de/o19-common.yml index 4eebd5a..f8e4491 100644 --- a/host_vars/o19.oopen.de/o19-common.yml +++ b/host_vars/o19.oopen.de/o19-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 37.27.121.192 netmask 255.255.255.192 gw 37.27.121.193 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -164,8 +163,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -176,20 +175,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -205,10 +204,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -218,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -280,7 +279,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -327,4 +325,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o20.oopen.de/o20-common.yml b/host_vars/o20.oopen.de/o20-common.yml index 897927e..3fe944b 100644 --- a/host_vars/o20.oopen.de/o20-common.yml +++ b/host_vars/o20.oopen.de/o20-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -113,7 +113,6 @@ cron_env_entries: insertafter: PATH - cron_user_entries: - name: "Check if webservices sre running. Restart if necessary" @@ -177,7 +176,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -224,4 +222,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o21.oopen.de/o21-common.yml b/host_vars/o21.oopen.de/o21-common.yml index 5fa873a..243b0a3 100644 --- a/host_vars/o21.oopen.de/o21-common.yml +++ b/host_vars/o21.oopen.de/o21-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -69,7 +69,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 46.4.25.192 netmask 255.255.255.192 gw 46.4.25.193 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -165,8 +164,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -177,20 +176,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -206,10 +205,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -219,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -357,4 +356,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o22.oopen.de/o22-common.yml b/host_vars/o22.oopen.de/o22-common.yml index 1c41c6e..24a44e6 100644 --- a/host_vars/o22.oopen.de/o22-common.yml +++ b/host_vars/o22.oopen.de/o22-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -68,7 +68,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -106,14 +106,14 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.120/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) down: [] # down script lines post-down: [] # post-down script lines - + # --- # vars used by roles/ansible_dependencies # --- @@ -140,7 +140,6 @@ copy_additional_plain_files_sysctl: # --- - # --- # vars used by roles/common/tasks/apt.yml # --- @@ -162,8 +161,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -174,20 +173,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -203,10 +202,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -216,7 +215,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o23.oopen.de/o23-common.yml b/host_vars/o23.oopen.de/o23-common.yml index 3f5de17..f2060f7 100644 --- a/host_vars/o23.oopen.de/o23-common.yml +++ b/host_vars/o23.oopen.de/o23-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -33,7 +33,7 @@ network_interfaces: family: inet method: static hwaddress: 30:9c:23:63:40:b5 - description: + description: address: 159.69.74.150 netmask: 26 gateway: 159.69.74.129 @@ -63,13 +63,13 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 195.201.179.131 # - 95.217.204.204 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 159.69.74.128 netmask 255.255.255.192 gw 159.69.74.129 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -207,7 +206,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -217,7 +216,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -289,7 +288,6 @@ cron_user_entries: job: /usr/bin/lxc-stop -n meet ; sleep 5 ; /usr/bin/lxc-start -n meet - # --- # vars used by roles/common/tasks/users.yml # --- @@ -336,4 +334,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o24.oopen.de/o24-common.yml b/host_vars/o24.oopen.de/o24-common.yml index 5fc77fb..47996b3 100644 --- a/host_vars/o24.oopen.de/o24-common.yml +++ b/host_vars/o24.oopen.de/o24-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -63,13 +63,13 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 195.201.179.131 # - 95.217.204.204 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 157.90.140.128 netmask 255.255.255.192 gw 157.90.140.129 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -209,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -219,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -286,7 +285,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -333,4 +331,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o25.oopen.de/o25-common.yml b/host_vars/o25.oopen.de/o25-common.yml index a346ac9..9f5e5ab 100644 --- a/host_vars/o25.oopen.de/o25-common.yml +++ b/host_vars/o25.oopen.de/o25-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -34,7 +34,7 @@ network_interfaces: auto: true family: inet - + # The statisc Mode # Options # address @@ -58,16 +58,16 @@ network_interfaces: # leasetime # vendor # client - # - # The bootp Method + # + # The bootp Method # Options # bootfile: # server: # hwaddr - # + # method: static - - hwaddress: + + hwaddress: description: address: 65.109.28.179 # dotted quad or number of bits @@ -75,10 +75,10 @@ network_interfaces: # the entry will be: address/netmask netmask: 26 gateway: 65.109.28.129 - metric: - pointopoint: - mtu: - scope: + metric: + pointopoint: + mtu: + scope: # additional user by dhcp method # @@ -107,7 +107,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -159,7 +159,7 @@ network_interfaces: # auto & allow are only used for the first device entry allow: [] # array of allow-[stanzas] eg. allow-hotplug - auto: + auto: family: inet6 method: static @@ -196,7 +196,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -224,7 +224,7 @@ network_interfaces: vlan: {} # inline hook scripts - pre-up: []# pre-up script lines + pre-up: [] # pre-up script lines up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -257,7 +257,7 @@ create_sftp_group: true # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -319,7 +319,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -329,7 +329,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -447,4 +447,3 @@ git_firewall_repository: root_user: name: root password: $y$j9T$myZ6f5/klmH0HDN2mb9tv/$s/bBrr6PEXdEgtn9CZYzBNZsA4.r6gWYYeZ4LAYotp9 - diff --git a/host_vars/o26.oopen.de/o26-common.yml b/host_vars/o26.oopen.de/o26-common.yml index 53c2ade..ebdbc88 100644 --- a/host_vars/o26.oopen.de/o26-common.yml +++ b/host_vars/o26.oopen.de/o26-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/network_interfaces @@ -6,10 +7,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -34,7 +35,7 @@ network_interfaces: auto: true family: inet - + # The statisc Mode # Options # address @@ -58,16 +59,16 @@ network_interfaces: # leasetime # vendor # client - # - # The bootp Method + # + # The bootp Method # Options # bootfile: # server: # hwaddr - # + # method: static - - hwaddress: + + hwaddress: description: address: 37.27.129.85 # dotted quad or number of bits @@ -75,10 +76,10 @@ network_interfaces: # the entry will be: address/netmask netmask: 26 gateway: 37.27.129.65 - metric: - pointopoint: - mtu: - scope: + metric: + pointopoint: + mtu: + scope: # additional user by dhcp method # @@ -101,13 +102,13 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 185.12.64.1 # - a01:4ff:ff00::add:2 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -159,7 +160,7 @@ network_interfaces: # auto & allow are only used for the first device entry allow: [] # array of allow-[stanzas] eg. allow-hotplug - auto: + auto: family: inet6 method: static @@ -196,7 +197,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -224,7 +225,7 @@ network_interfaces: vlan: {} # inline hook scripts - pre-up: []# pre-up script lines + pre-up: [] # pre-up script lines up: [] # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -279,7 +280,7 @@ root_ssh_keypair: # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -342,7 +343,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -352,7 +353,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -549,4 +550,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o27.oopen.de/o27-common.yml b/host_vars/o27.oopen.de/o27-common.yml index 13490f3..91445ae 100644 --- a/host_vars/o27.oopen.de/o27-common.yml +++ b/host_vars/o27.oopen.de/o27-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,15 +62,15 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 185.12.64.1 # - 2a01:4ff:ff00::add:2 # - 185.12.64.2 # - 2a01:4ff:ff00::add:1 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -209,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -219,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- diff --git a/host_vars/o28.oopen.de/o28-common.yml b/host_vars/o28.oopen.de/o28-common.yml index be4efe5..85f4612 100644 --- a/host_vars/o28.oopen.de/o28-common.yml +++ b/host_vars/o28.oopen.de/o28-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 88.198.56.192 netmask 255.255.255.224 gw 88.198.56.193 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -160,8 +159,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -172,20 +171,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -201,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -317,4 +316,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o29.oopen.de/o29-common.yml b/host_vars/o29.oopen.de/o29-common.yml index e4df42d..42c31d2 100644 --- a/host_vars/o29.oopen.de/o29-common.yml +++ b/host_vars/o29.oopen.de/o29-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,13 +62,13 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 185.12.64.2 # - 2a01:4ff:ff00::add:1 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -106,7 +106,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 65.21.220.128 netmask 255.255.255.192 gw 65.21.220.129 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -114,7 +114,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -209,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -219,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -327,4 +326,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o30.oopen.de/o30-common.yml b/host_vars/o30.oopen.de/o30-common.yml index 53b5e03..cf53834 100644 --- a/host_vars/o30.oopen.de/o30-common.yml +++ b/host_vars/o30.oopen.de/o30-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -56,7 +56,7 @@ network_interfaces: hwaddr: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -94,7 +94,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 148.251.14.128 netmask 255.255.255.224 gw 148.251.14.129 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -102,7 +102,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -195,7 +194,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -205,7 +204,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -323,4 +322,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o31.oopen.de/o31-common.yml b/host_vars/o31.oopen.de/o31-common.yml index b043b9d..41b9922 100644 --- a/host_vars/o31.oopen.de/o31-common.yml +++ b/host_vars/o31.oopen.de/o31-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -69,7 +69,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 135.181.22.128 netmask 255.255.255.192 gw 135.181.22.129 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -212,7 +211,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -222,7 +221,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -311,7 +310,6 @@ cron_user_entries: # see: roles/common/tasks/vars - # --- # vars used by roles/common/tasks/caching-nameserver.yml # --- @@ -336,4 +334,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o32.oopen.de/o32-common.yml b/host_vars/o32.oopen.de/o32-common.yml index 9b735a3..7c67beb 100644 --- a/host_vars/o32.oopen.de/o32-common.yml +++ b/host_vars/o32.oopen.de/o32-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -70,7 +70,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -103,7 +103,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 95.217.197.64 netmask 255.255.255.192 gw 95.217.197.65 dev enp34s0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -111,7 +111,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: enp34s0 family: inet6 method: static @@ -145,7 +144,7 @@ sshd_login_grace_time: 0 # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -208,7 +207,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -218,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -371,4 +370,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o33-neu.oopen.de/o33-neu-common.yml b/host_vars/o33-neu.oopen.de/o33-neu-common.yml index e545845..1225bba 100644 --- a/host_vars/o33-neu.oopen.de/o33-neu-common.yml +++ b/host_vars/o33-neu.oopen.de/o33-neu-common.yml @@ -27,7 +27,7 @@ sshd_hostkeyalgorithms: [] # vars used by roles/common/tasks/apt.yml # --- -#apt_manage_sources_list: false +# apt_manage_sources_list: false # --- @@ -35,7 +35,6 @@ sshd_hostkeyalgorithms: [] # --- - # --- # vars used by roles/common/tasks/users-systemfiles.yml # --- @@ -77,4 +76,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o34.oopen.de/o34-common.yml b/host_vars/o34.oopen.de/o34-common.yml index df692f1..10adf7f 100644 --- a/host_vars/o34.oopen.de/o34-common.yml +++ b/host_vars/o34.oopen.de/o34-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,14 +62,14 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 127.0.0.1 # - 185.12.64.2 # - 2a01:4ff:ff00::add:1 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - route add -net 65.109.158.64 netmask 255.255.255.192 gw 65.109.158.65 dev enp6s0 post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: enp6s0 family: inet6 method: static @@ -204,7 +203,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -373,4 +372,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o35.oopen.de/o35-common.yml b/host_vars/o35.oopen.de/o35-common.yml index 60f6675..369862c 100644 --- a/host_vars/o35.oopen.de/o35-common.yml +++ b/host_vars/o35.oopen.de/o35-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -63,13 +63,13 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 213.133.100.100 # - 213.133.98.98 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 95.217.204.192 netmask 255.255.255.192 gw 95.217.204.193 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -209,7 +208,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -219,7 +218,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -281,7 +280,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -328,4 +326,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o36.oopen.de/o36-common.yml b/host_vars/o36.oopen.de/o36-common.yml index 997c537..44086ff 100644 --- a/host_vars/o36.oopen.de/o36-common.yml +++ b/host_vars/o36.oopen.de/o36-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 162.55.82.64 netmask 255.255.255.192 gw 162.55.82.65 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -160,8 +159,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -172,20 +171,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -199,10 +198,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -212,7 +211,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -325,4 +324,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o38.oopen.de/o38-common.yml b/host_vars/o38.oopen.de/o38-common.yml index d39a7b8..61e032b 100644 --- a/host_vars/o38.oopen.de/o38-common.yml +++ b/host_vars/o38.oopen.de/o38-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: static - hwaddress: + hwaddress: description: address: 213.133.111.115 netmask: 27 @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 213.133.111.96 netmask 255.255.255.224 gw 213.133.111.97 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -164,8 +163,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -176,20 +175,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -205,10 +204,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -218,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -326,4 +325,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o39.oopen.de/o39-common.yml b/host_vars/o39.oopen.de/o39-common.yml index 5e3f696..615295c 100644 --- a/host_vars/o39.oopen.de/o39-common.yml +++ b/host_vars/o39.oopen.de/o39-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: static - hwaddress: + hwaddress: description: address: 37.27.67.126 netmask: 26 @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 37.27.67.64 netmask 255.255.255.192 gw 37.27.67.65 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -160,8 +159,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -172,20 +171,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -201,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -276,7 +275,6 @@ cron_user_entries: job: /root/bin/monitoring/check_ntpsec_service.sh > /dev/null 2>&1 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -323,4 +321,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o40.oopen.de/o40-common.yml b/host_vars/o40.oopen.de/o40-common.yml index b242ae4..ce35889 100644 --- a/host_vars/o40.oopen.de/o40-common.yml +++ b/host_vars/o40.oopen.de/o40-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -204,7 +203,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -281,7 +280,6 @@ cron_user_entries: job: /root/bin/monitoring/check_ntpsec_service.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -328,4 +326,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o41.oopen.de/o41-common.yml b/host_vars/o41.oopen.de/o41-common.yml index dc5cfce..5cf4cd8 100644 --- a/host_vars/o41.oopen.de/o41-common.yml +++ b/host_vars/o41.oopen.de/o41-common.yml @@ -46,8 +46,8 @@ systemd_resolved: false # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: false # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -116,7 +116,7 @@ cron_env_entries: insertafter: PATH -#cron_user_special_time_entries: +# cron_user_special_time_entries: # # - name: "Restart DNS Cache service 'systemd-resolved'" # special_time: reboot @@ -157,7 +157,6 @@ cron_user_entries: # job: /root/bin/monitoring/check_ntpsec_service.sh > /dev/null 2>&1 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -204,4 +203,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o42.oopen.de/o42-common.yml b/host_vars/o42.oopen.de/o42-common.yml index 1f02bfb..d9bf1ff 100644 --- a/host_vars/o42.oopen.de/o42-common.yml +++ b/host_vars/o42.oopen.de/o42-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 95.217.194.0 netmask 255.255.255.192 gw 95.217.194.1 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -160,8 +159,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -172,20 +171,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -201,10 +200,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -214,7 +213,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -276,7 +275,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -323,4 +321,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o43.oopen.de/o43-common.yml b/host_vars/o43.oopen.de/o43-common.yml index b7be8e0..59fedaf 100644 --- a/host_vars/o43.oopen.de/o43-common.yml +++ b/host_vars/o43.oopen.de/o43-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 176.9.62.64 netmask 255.255.255.224 gw 176.9.62.65 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -198,12 +197,12 @@ network_interfaces: vlan: {} # inline hook scripts - #pre-up: [] # pre-up script lines + # pre-up: [] # pre-up script lines pre-up: - /sbin/ip link add link enp6s0 name enp6s0.4001 type vlan id 4001 - /sbin/ip link set enp6s0.4001 mtu 1400 up: [] # up script lines - #post-up: [] # post-up script lines (alias for up) + # post-up: [] # post-up script lines (alias for up) post-up: # post-up script lines (alias for up) - /sbin/ip route add 172.20.0.0/21 via 172.20.1.1 pre-down: [] # pre-down script lines (alias for down) @@ -252,8 +251,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -264,20 +263,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -293,10 +292,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -306,7 +305,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -368,7 +367,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -415,4 +413,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/o44.oopen.de/o44-common.yml b/host_vars/o44.oopen.de/o44-common.yml index f7d64e2..4b52962 100644 --- a/host_vars/o44.oopen.de/o44-common.yml +++ b/host_vars/o44.oopen.de/o44-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 148.251.194.0 netmask 255.255.255.192 gw 148.251.194.1 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -164,8 +163,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -176,20 +175,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -205,10 +204,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -218,7 +217,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -280,7 +279,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -327,4 +325,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/oolm-db.oopen.de/oolm-db-common.yml b/host_vars/oolm-db.oopen.de/oolm-db-common.yml index 3197b71..816a417 100644 --- a/host_vars/oolm-db.oopen.de/oolm-db-common.yml +++ b/host_vars/oolm-db.oopen.de/oolm-db-common.yml @@ -19,10 +19,10 @@ # vars used by roles/common/tasks/sshd.yml # --- -#sshd_pasword_auth_user: +# sshd_pasword_auth_user: # - chris -#sshd_pasword_auth_ip: +# sshd_pasword_auth_ip: # - 2003:ec:df0c:e7fe:ebb:d93b:1d33:3918 # - 2003:ec:df0c:e7fe:4b3a:a5ba:c661:f7f6 @@ -70,4 +70,3 @@ # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/oolm-shop-dev.oopen.de/oolm-shop-dev-common.yml b/host_vars/oolm-shop-dev.oopen.de/oolm-shop-dev-common.yml index b1b2fee..84de24d 100644 --- a/host_vars/oolm-shop-dev.oopen.de/oolm-shop-dev-common.yml +++ b/host_vars/oolm-shop-dev.oopen.de/oolm-shop-dev-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -19,12 +20,12 @@ # vars used by roles/common/tasks/sshd.yml # --- -#sshd_password_authentication: !!str "yes" +# sshd_password_authentication: !!str "yes" sshd_pasword_auth_ip: - 34.107.7.34 -sshd_pubkey_accepted_algorithms: +sshd_pubkey_accepted_algorithms: - +ssh-rsa @@ -49,8 +50,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -61,20 +62,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -88,10 +89,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -101,7 +102,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -197,4 +198,3 @@ sudo_users: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/oolm-shop.oopen.de/oolm-shop-common.yml b/host_vars/oolm-shop.oopen.de/oolm-shop-common.yml index 1bd081d..a39dadd 100644 --- a/host_vars/oolm-shop.oopen.de/oolm-shop-common.yml +++ b/host_vars/oolm-shop.oopen.de/oolm-shop-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by roles/ansible_dependencies @@ -19,14 +20,14 @@ # vars used by roles/common/tasks/sshd.yml # --- -#sshd_password_authentication: !!str "yes" +# sshd_password_authentication: !!str "yes" -sshd_pubkey_accepted_algorithms: +sshd_pubkey_accepted_algorithms: - +ssh-rsa # This users are allowed to use password authentification -# -#sshd_pasword_auth_user: +# +# sshd_pasword_auth_user: # - nordkurier_live sshd_pasword_auth_ip: @@ -130,4 +131,3 @@ sudo_users: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/oolm-web.oopen.de/oolm-web-common.yml b/host_vars/oolm-web.oopen.de/oolm-web-common.yml index 132043f..5cfff9c 100644 --- a/host_vars/oolm-web.oopen.de/oolm-web-common.yml +++ b/host_vars/oolm-web.oopen.de/oolm-web-common.yml @@ -83,7 +83,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,8 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -143,4 +142,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/piwik.warenform.de/piwik-common.yml b/host_vars/piwik.warenform.de/piwik-common.yml index cce9f02..507c04e 100644 --- a/host_vars/piwik.warenform.de/piwik-common.yml +++ b/host_vars/piwik.warenform.de/piwik-common.yml @@ -94,7 +94,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -104,7 +104,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -182,4 +182,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/prometheus-nd.oopen.de/prometheus-nd-common.yml b/host_vars/prometheus-nd.oopen.de/prometheus-nd-common.yml index ea4d6cc..aed7fbf 100644 --- a/host_vars/prometheus-nd.oopen.de/prometheus-nd-common.yml +++ b/host_vars/prometheus-nd.oopen.de/prometheus-nd-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,7 +142,6 @@ cron_user_entries: job: /root/bin/monitoring/check_postfix.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -207,4 +206,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/psono-ndm.oopen.de/psono-ndm-common.yml b/host_vars/psono-ndm.oopen.de/psono-ndm-common.yml index 69a72df..6531ca1 100644 --- a/host_vars/psono-ndm.oopen.de/psono-ndm-common.yml +++ b/host_vars/psono-ndm.oopen.de/psono-ndm-common.yml @@ -42,8 +42,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -54,20 +54,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -83,10 +83,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -96,7 +96,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -112,7 +112,7 @@ cron_env_entries: insertafter: PATH -#cron_user_special_time_entries: +# cron_user_special_time_entries: # # - name: "Restart DNS Cache service 'systemd-resolved'" # special_time: reboot @@ -120,7 +120,7 @@ cron_env_entries: # insertafter: PATH # # -#cron_user_entries: +# cron_user_entries: # # - name: "Check if webservices sre running. Restart if necessary" # minute: '*/5' @@ -232,4 +232,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/rage.so36.net/rage-common.yml b/host_vars/rage.so36.net/rage-common.yml index d3a724e..35db0b8 100644 --- a/host_vars/rage.so36.net/rage-common.yml +++ b/host_vars/rage.so36.net/rage-common.yml @@ -1,5 +1,5 @@ --- - + # --- # vars used by roles/ansible_dependencies # --- @@ -83,7 +83,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - so36.net @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -122,60 +122,6 @@ resolved_fallback_nameserver: # vars used by roles/common/tasks/copy_files.yml # --- -copy_plain_files: - - # /root/bin/monitoring - # - - name: monitoring_check_cert_for_dovecot.conf - src_path: rage/root/bin/monitoring/conf/check_cert_for_dovecot.conf - dest_path: /root/bin/monitoring/conf/check_cert_for_dovecot.conf - - # /root/bin/postfix - # - - name: postfix_check-postfix-fatal-errors.conf - src_path: rage/root/bin/postfix/conf/check-postfix-fatal-errors.conf - dest_path: /root/bin/postfix/conf/check-postfix-fatal-errors.conf - - - name: postfix_sent_userinfo_postfix.conf - src_path: rage/root/bin/postfix/conf/sent_userinfo_postfix.conf - dest_path: /root/bin/postfix/conf/sent_userinfo_postfix.conf - - - name: postfix_get_number_of_deferred_mailqueue.conf - src_path: rage/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf - dest_path: /root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf - - -copy_plain_files_postfwd_host_specific: - - - name: postfwd.wl-hosts - src_path: rage/etc/postfix/postfwd.wl-hosts - dest_path: /etc/postfix/postfwd.wl-hosts - - - name: postfwd.wl-nets - src_path: rage/etc/postfix/postfwd.wl-nets - dest_path: /etc/postfix/postfwd.wl-nets - - - name: postfwd.wl-sender - src_path: rage/etc/postfix/postfwd.wl-sender - dest_path: /etc/postfix/postfwd.wl-sender - - - name: postfwd.wl-user - src_path: rage/etc/postfix/postfwd.wl-user - dest_path: /etc/postfix/postfwd.wl-user - - # Postfix Firewall postfwd - # - #- name: postfwd.wl-user - # src_path: rage/etc/postfix/postfwd.wl-user - # dest_path: /etc/postfix/postfwd.wl-user - - -#copy_template_files: [] -# -# - name: mailsystem_install_amavis.conf -# src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 -# dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/caching-nameserver.yml diff --git a/host_vars/server16.warenform.de/server16-common.yml b/host_vars/server16.warenform.de/server16-common.yml index 021bc04..32919c5 100644 --- a/host_vars/server16.warenform.de/server16-common.yml +++ b/host_vars/server16.warenform.de/server16-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -67,7 +67,7 @@ network_interfaces: search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -105,7 +105,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.81/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) @@ -114,7 +114,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -209,4 +208,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server18.warenform.de/server18-common.yml b/host_vars/server18.warenform.de/server18-common.yml index ce209ff..e3574b8 100644 --- a/host_vars/server18.warenform.de/server18-common.yml +++ b/host_vars/server18.warenform.de/server18-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,14 +62,14 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 212.42.230.1 # - 83.223.90.90 # - 83.223.66.51 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.80/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) @@ -116,7 +116,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -206,7 +205,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -216,7 +215,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -355,4 +354,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server20.warenform.de/server20-common.yml b/host_vars/server20.warenform.de/server20-common.yml index 3647d2b..7130310 100644 --- a/host_vars/server20.warenform.de/server20-common.yml +++ b/host_vars/server20.warenform.de/server20-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -56,7 +56,7 @@ network_interfaces: hwaddr: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -94,7 +94,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.85.220/24 dev br0" - !!str "ip route add default via 83.223.85.1" post-up: [] # post-up script lines (alias for up) @@ -103,7 +103,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -199,4 +198,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server22.warenform.de/server22-common.yml b/host_vars/server22.warenform.de/server22-common.yml index 2d2c7ec..f070303 100644 --- a/host_vars/server22.warenform.de/server22-common.yml +++ b/host_vars/server22.warenform.de/server22-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: manual hwaddress: 52:54:00:21:68:2f - description: + description: address: netmask: gateway: @@ -56,7 +56,7 @@ network_interfaces: hwaddr: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -94,7 +94,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.83.20/24 dev br0" - !!str "ip route add default via 83.223.83.1" post-up: [] # post-up script lines (alias for up) @@ -103,7 +103,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -193,7 +192,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -203,7 +202,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -342,4 +341,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server23.warenform.de/server23-common.yml b/host_vars/server23.warenform.de/server23-common.yml index 6e7f379..5913b85 100644 --- a/host_vars/server23.warenform.de/server23-common.yml +++ b/host_vars/server23.warenform.de/server23-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: manual hwaddress: 52:54:00:41:af:9b - description: + description: address: netmask: gateway: @@ -56,7 +56,7 @@ network_interfaces: hwaddr: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -94,7 +94,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.110/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) @@ -103,7 +103,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -150,8 +149,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -162,20 +161,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -190,10 +189,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -203,7 +202,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -342,4 +341,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server24.warenform.de/server24-common.yml b/host_vars/server24.warenform.de/server24-common.yml index b8ec5b3..09bbbc0 100644 --- a/host_vars/server24.warenform.de/server24-common.yml +++ b/host_vars/server24.warenform.de/server24-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: manual hwaddress: 52:54:00:6a:7f:8d - description: + description: address: netmask: gateway: @@ -62,10 +62,10 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 212.42.230.1 # - 83.223.66.51 - #search: + # search: # optional bridge parameters bridge: {} # bridge: @@ -101,7 +101,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.86.75/24 dev br0" - !!str "ip route add default via 83.223.86.1" post-up: [] # post-up script lines (alias for up) @@ -110,7 +110,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -200,7 +199,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -210,7 +209,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -272,7 +271,6 @@ cron_user_entries: job: /root/bin/admin-stuff/check-disc-usage.sh -c 85 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -351,4 +349,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server25.warenform.de/server25-common.yml b/host_vars/server25.warenform.de/server25-common.yml index dbe1755..8c3d0be 100644 --- a/host_vars/server25.warenform.de/server25-common.yml +++ b/host_vars/server25.warenform.de/server25-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -32,7 +32,7 @@ network_interfaces: family: inet method: manual hwaddress: 52:54:00:f7:c0:fb - description: + description: address: netmask: gateway: @@ -64,7 +64,7 @@ network_interfaces: # # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -102,7 +102,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "ip addr add 83.223.85.163/24 dev br0" - !!str "ip route add default via 83.223.85.1" post-up: [] # post-up script lines (alias for up) @@ -111,7 +111,6 @@ network_interfaces: post-down: [] # post-down script lines - # --- # vars used by roles/ansible_dependencies # --- @@ -201,7 +200,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -211,7 +210,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -351,4 +350,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server26.warenform.de/server26-common.yml b/host_vars/server26.warenform.de/server26-common.yml index a1a26bc..e12b40c 100644 --- a/host_vars/server26.warenform.de/server26-common.yml +++ b/host_vars/server26.warenform.de/server26-common.yml @@ -5,10 +5,10 @@ # --- # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -62,14 +62,14 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 213.133.100.100 # - 213.133.99.99 # - 213.133.98.98 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -107,7 +107,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 178.63.33.16 netmask 255.255.255.240 gw 178.63.33.17 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -115,7 +115,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -216,7 +215,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -226,7 +225,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -366,4 +365,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server27.warenform.de/server27-common.yml b/host_vars/server27.warenform.de/server27-common.yml index 47d1b00..270a782 100644 --- a/host_vars/server27.warenform.de/server27-common.yml +++ b/host_vars/server27.warenform.de/server27-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -63,14 +63,14 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 213.133.100.100 # - 213.133.99.99 # - 213.133.98.98 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -108,7 +108,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 95.217.44.192 netmask 255.255.255.192 gw 95.217.44.193 dev br0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -116,7 +116,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: br0 family: inet6 method: static @@ -223,7 +222,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -233,7 +232,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -373,4 +372,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/server28.warenform.de/server28-common.yml b/host_vars/server28.warenform.de/server28-common.yml index 9e4b81e..21ac025 100644 --- a/host_vars/server28.warenform.de/server28-common.yml +++ b/host_vars/server28.warenform.de/server28-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -63,14 +63,14 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 213.133.99.99 # - 213.133.98.98 # - 213.133.100.100 - #search: + # search: # optional additional subnets/ips subnets: [] - # subnets: + # subnets: # - '192.168.123.0/24' # - '192.168.124.11/32' @@ -103,7 +103,7 @@ network_interfaces: # inline hook scripts pre-up: [] # pre-up script lines - up: + up: - !!str "route add -net 116.202.161.0 netmask 255.255.255.192 gw 116.202.161.1 dev enp9s0" # up script lines post-up: [] # post-up script lines (alias for up) pre-down: [] # pre-down script lines (alias for down) @@ -111,7 +111,6 @@ network_interfaces: post-down: [] # post-down script lines - - device: enp9s0 family: inet6 method: static @@ -212,7 +211,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -222,7 +221,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 cron_env_entries: - name: PATH @@ -299,7 +298,6 @@ cron_user_entries: job: /var/lib/dehydrated/tools/update_ssl_directives.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -360,4 +358,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/shop-dev.aufstehen-gegen-rassismus.de/shop-dev-common.yml b/host_vars/shop-dev.aufstehen-gegen-rassismus.de/shop-dev-common.yml index dc5cfce..5cf4cd8 100644 --- a/host_vars/shop-dev.aufstehen-gegen-rassismus.de/shop-dev-common.yml +++ b/host_vars/shop-dev.aufstehen-gegen-rassismus.de/shop-dev-common.yml @@ -46,8 +46,8 @@ systemd_resolved: false # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: false # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -116,7 +116,7 @@ cron_env_entries: insertafter: PATH -#cron_user_special_time_entries: +# cron_user_special_time_entries: # # - name: "Restart DNS Cache service 'systemd-resolved'" # special_time: reboot @@ -157,7 +157,6 @@ cron_user_entries: # job: /root/bin/monitoring/check_ntpsec_service.sh > /dev/null 2>&1 - # --- # vars used by roles/common/tasks/users.yml # --- @@ -204,4 +203,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/stolpersteine.oopen.de/stolpersteine-common.yml b/host_vars/stolpersteine.oopen.de/stolpersteine-common.yml index 1ca5af7..48c9b2b 100644 --- a/host_vars/stolpersteine.oopen.de/stolpersteine-common.yml +++ b/host_vars/stolpersteine.oopen.de/stolpersteine-common.yml @@ -36,8 +36,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -48,20 +48,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -75,10 +75,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -88,7 +88,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -118,8 +118,8 @@ resolved_fallback_nameserver: # see: roles/common/tasks/vars sudoers_file_user_privileges: - - name: eike - entry: 'ALL=(www-data) NOPASSWD: ALL' + - name: eike + entry: 'ALL=(www-data) NOPASSWD: ALL' # --- @@ -140,4 +140,3 @@ sudoers_file_user_privileges: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/test.mariadb.oopen.de/test.mariadb-common.yml b/host_vars/test.mariadb.oopen.de/test.mariadb-common.yml index e372b40..4223991 100644 --- a/host_vars/test.mariadb.oopen.de/test.mariadb-common.yml +++ b/host_vars/test.mariadb.oopen.de/test.mariadb-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by role 'firewall' @@ -18,7 +19,7 @@ # vars used by cron.yml # --- -#cron_env_entries: [] +# cron_env_entries: [] cron_env_entries: - name: PATH job: /root/bin/admin-stuff:/root/bin:/usr/local/php/bin:/usr/local/apache2/bin:/sbin:/bin:/usr/local/dovecot/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin @@ -53,4 +54,3 @@ cron_env_entries: # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/test.mx.oopen.de/test.mx-common.yml b/host_vars/test.mx.oopen.de/test.mx-common.yml index 13f17a9..cbcea43 100644 --- a/host_vars/test.mx.oopen.de/test.mx-common.yml +++ b/host_vars/test.mx.oopen.de/test.mx-common.yml @@ -1,4 +1,5 @@ --- +# yamllint disable rule:line-length # --- # vars used by role 'firewall' @@ -30,7 +31,7 @@ dovecot_auth_allowed_network_ipv6: # vars used by cron.yml # --- -#cron_env_entries: [] +# cron_env_entries: [] cron_env_entries: - name: PATH job: /root/bin/admin-stuff:/root/bin:/usr/local/php/bin:/usr/local/apache2/bin:/sbin:/bin:/usr/local/dovecot/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin @@ -59,9 +60,9 @@ create_sftp_group: true # vars used by roles/common/tasks/sudoers.yml # --- -insert_sudoers_back_postgres_privileges: True +insert_sudoers_back_postgres_privileges: true -insert_sudoers_postfixadmin_privileges: True +insert_sudoers_postfixadmin_privileges: true # ============================== @@ -70,4 +71,3 @@ insert_sudoers_postfixadmin_privileges: True # --- # vars used by scripts/reset_root_passwd.yml # --- - diff --git a/host_vars/verdi-django.warenform.de/verdi-django-common.yml b/host_vars/verdi-django.warenform.de/verdi-django-common.yml index 0e8d69c..bc4ca54 100644 --- a/host_vars/verdi-django.warenform.de/verdi-django-common.yml +++ b/host_vars/verdi-django.warenform.de/verdi-django-common.yml @@ -97,7 +97,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -107,7 +107,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -162,4 +162,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/vvn-shop.warenform.de/vvn-shop-common.yml b/host_vars/vvn-shop.warenform.de/vvn-shop-common.yml index 3af1272..474f5d2 100644 --- a/host_vars/vvn-shop.warenform.de/vvn-shop-common.yml +++ b/host_vars/vvn-shop.warenform.de/vvn-shop-common.yml @@ -88,7 +88,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -98,7 +98,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -166,4 +166,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/vvn-www.warenform.de/vvn-www-common.yml b/host_vars/vvn-www.warenform.de/vvn-www-common.yml index 6be2267..e4d6d08 100644 --- a/host_vars/vvn-www.warenform.de/vvn-www-common.yml +++ b/host_vars/vvn-www.warenform.de/vvn-www-common.yml @@ -88,7 +88,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -98,7 +98,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -165,4 +165,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-01.oopen.de/web-01-common.yml b/host_vars/web-01.oopen.de/web-01-common.yml index c310a16..3dfa779 100644 --- a/host_vars/web-01.oopen.de/web-01-common.yml +++ b/host_vars/web-01.oopen.de/web-01-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,8 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -147,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-02.oopen.de/web-02-common.yml b/host_vars/web-02.oopen.de/web-02-common.yml index b5fb4d7..3dfa779 100644 --- a/host_vars/web-02.oopen.de/web-02-common.yml +++ b/host_vars/web-02.oopen.de/web-02-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,7 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -146,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-03.oopen.de/web-03-common.yml b/host_vars/web-03.oopen.de/web-03-common.yml index c310a16..3dfa779 100644 --- a/host_vars/web-03.oopen.de/web-03-common.yml +++ b/host_vars/web-03.oopen.de/web-03-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,8 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -147,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-04.oopen.de/web-04-common.yml b/host_vars/web-04.oopen.de/web-04-common.yml index c310a16..3dfa779 100644 --- a/host_vars/web-04.oopen.de/web-04-common.yml +++ b/host_vars/web-04.oopen.de/web-04-common.yml @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,8 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -147,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-05.oopen.de/web-05-common.yml b/host_vars/web-05.oopen.de/web-05-common.yml index d2d16e6..21462a0 100644 --- a/host_vars/web-05.oopen.de/web-05-common.yml +++ b/host_vars/web-05.oopen.de/web-05-common.yml @@ -85,7 +85,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,8 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -145,4 +144,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-06.oopen.de/web-06-common.yml b/host_vars/web-06.oopen.de/web-06-common.yml index d2d16e6..21462a0 100644 --- a/host_vars/web-06.oopen.de/web-06-common.yml +++ b/host_vars/web-06.oopen.de/web-06-common.yml @@ -85,7 +85,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,8 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -145,4 +144,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-07.oopen.de/web-07-common.yml b/host_vars/web-07.oopen.de/web-07-common.yml index d2d16e6..21462a0 100644 --- a/host_vars/web-07.oopen.de/web-07-common.yml +++ b/host_vars/web-07.oopen.de/web-07-common.yml @@ -85,7 +85,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,8 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -145,4 +144,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-08.oopen.de/web-08-common.yml b/host_vars/web-08.oopen.de/web-08-common.yml index d2d16e6..21462a0 100644 --- a/host_vars/web-08.oopen.de/web-08-common.yml +++ b/host_vars/web-08.oopen.de/web-08-common.yml @@ -85,7 +85,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -95,8 +95,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -145,4 +144,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-09.oopen.de/web-09-common.yml b/host_vars/web-09.oopen.de/web-09-common.yml index 5541b02..56c4214 100644 --- a/host_vars/web-09.oopen.de/web-09-common.yml +++ b/host_vars/web-09.oopen.de/web-09-common.yml @@ -19,7 +19,7 @@ # vars used by roles/common/tasks/sshd.yml # --- -#sshd_login_grace_time: 0 +# sshd_login_grace_time: 0 # --- @@ -87,7 +87,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -97,8 +97,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 - + - 194.150.168.168 # --- @@ -147,4 +146,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-nd.oopen.de/web-nd-common.yml b/host_vars/web-nd.oopen.de/web-nd-common.yml index be1ca53..6978dec 100644 --- a/host_vars/web-nd.oopen.de/web-nd-common.yml +++ b/host_vars/web-nd.oopen.de/web-nd-common.yml @@ -46,8 +46,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -58,20 +58,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -87,10 +87,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,7 +142,6 @@ cron_user_entries: job: /root/bin/monitoring/check_postfix.sh - # --- # vars used by roles/common/tasks/users.yml # --- @@ -235,4 +234,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web-test.oopen.de/web-test-common.yml b/host_vars/web-test.oopen.de/web-test-common.yml index c1a7e6e..e1e0c16 100644 --- a/host_vars/web-test.oopen.de/web-test-common.yml +++ b/host_vars/web-test.oopen.de/web-test-common.yml @@ -83,7 +83,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -142,4 +142,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web.cadus.org/web-common.yml b/host_vars/web.cadus.org/web-common.yml index 2d25d4d..5df1b97 100644 --- a/host_vars/web.cadus.org/web-common.yml +++ b/host_vars/web.cadus.org/web-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -80,10 +80,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 185.12.64.1 + - 185.12.64.1 # --- @@ -140,14 +140,13 @@ git_firewall_repository: # --- -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/web0.warenform.de/web0-common.yml b/host_vars/web0.warenform.de/web0-common.yml index c7d6196..de48dd4 100644 --- a/host_vars/web0.warenform.de/web0-common.yml +++ b/host_vars/web0.warenform.de/web0-common.yml @@ -90,7 +90,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -143,10 +143,10 @@ ssh_keypair_backup_client: # see: roles/common/tasks/vars sudoers_file_user_aliases: - - name: WEB_USER - entry: 'webadmin, axel, chris' - - name: MAIN_USER - entry: 'sysadm, axel, chris' + - name: WEB_USER + entry: 'webadmin, axel, chris' + - name: MAIN_USER + entry: 'sysadm, axel, chris' sudoers_file_cmnd_aliases: - name: REBOOT @@ -161,10 +161,6 @@ sudoers_file_user_privileges: entry: ALL = MANAGE_SERVICE - - - - # --- # vars used by roles/common/tasks/caching-nameserver.yml # --- @@ -190,4 +186,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web1.warenform.de/web1-common.yml b/host_vars/web1.warenform.de/web1-common.yml index 1d78c8d..4991a8b 100644 --- a/host_vars/web1.warenform.de/web1-common.yml +++ b/host_vars/web1.warenform.de/web1-common.yml @@ -90,7 +90,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -168,4 +168,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/web2.warenform.de/web2-common.yml b/host_vars/web2.warenform.de/web2-common.yml index e8caaaa..7840787 100644 --- a/host_vars/web2.warenform.de/web2-common.yml +++ b/host_vars/web2.warenform.de/web2-common.yml @@ -90,7 +90,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - warenform.de @@ -100,7 +100,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 194.150.168.168 + - 194.150.168.168 # --- @@ -167,4 +167,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/wiki.cadus.org/wiki-common.yml b/host_vars/wiki.cadus.org/wiki-common.yml index 2d25d4d..5df1b97 100644 --- a/host_vars/wiki.cadus.org/wiki-common.yml +++ b/host_vars/wiki.cadus.org/wiki-common.yml @@ -41,8 +41,8 @@ systemd_resolved: true # IPv6: 2606:4700:4700::1111 # sekundäre DNS-Adresse # IPv4: 1.0.0.1 -# IPv6: 2606:4700:4700::1001 -# +# IPv6: 2606:4700:4700::1001 +# # Google (USA) Public DNS - Großartige Kombination aus Geschwindigkeit und Sicherheit # primäre DNS-Adresse # IPv4: 8.8.8.8 @@ -53,20 +53,20 @@ systemd_resolved: true # # Quad9 (CH) - Blockiert mühelos schädliche Seiten und verhindert Phishing-Betrug # primäre DNS-Adresse -# IPv4: 9.9.9.9 -# IPv6: 2620:fe::fe +# IPv4: 9.9.9.9 +# IPv6: 2620:fe::fe # sekundäre DNS-Adresse # IPv4: 149.112.112.112 # IPv6: 2620:fe::9 # # OpenNIC - https://www.opennic.org/ -# IPv4: 195.10.195.195 - ns31.de -# IPv4: 94.16.114.254 - ns28.de -# IPv4: 51.254.162.59 - ns9.de +# IPv4: 195.10.195.195 - ns31.de +# IPv4: 94.16.114.254 - ns28.de +# IPv4: 51.254.162.59 - ns9.de # IPv4: 194.36.144.87 - ns29.de # IPv6: 2a00:f826:8:2::195 - ns31.de -# -# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) +# +# Freifunk München (normales DNS, DNS-over-TLS und DNS-over-HTTPS) # IPv4: 5.1.66.255 # IPv6: 2001:678:e68:f000:: # Servername für DNS-over-TLS: dot.ffmuc.net @@ -80,10 +80,10 @@ resolved_nameserver: # search domains # -# If there are more than one search domains, then specify them here in the order in which +# If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - oopen.de @@ -93,7 +93,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 185.12.64.1 + - 185.12.64.1 # --- @@ -140,14 +140,13 @@ git_firewall_repository: # --- -#copy_template_files: [] +# copy_template_files: [] # # - name: mailsystem_install_amavis.conf # src_path: usr/local/src/mailsystem/conf/install_amavis.conf.j2 # dest_path: /usr/local/src/mailsystem/conf/install_amavis.conf - # --- # vars used by roles/common/tasks/config_files_mailsystem_scripts.yml # --- diff --git a/host_vars/www.oopen.de/www-common.yml b/host_vars/www.oopen.de/www-common.yml index 578780c..7ecdad1 100644 --- a/host_vars/www.oopen.de/www-common.yml +++ b/host_vars/www.oopen.de/www-common.yml @@ -73,4 +73,3 @@ git_firewall_repository: root_user: name: root password: $6$J1ssJfdshf/$mknQEPDcW4HN5.wFfawbamamywI7F7fhdZmaR1abNrc4DA7DNRx766lz3ygf9YV3gcmRq3QhJ3fBVlkwGMCvq. - diff --git a/host_vars/zapata-alt.opp.netz/zapata-alt-common.yml b/host_vars/zapata-alt.opp.netz/zapata-alt-common.yml index 554a269..775092c 100644 --- a/host_vars/zapata-alt.opp.netz/zapata-alt-common.yml +++ b/host_vars/zapata-alt.opp.netz/zapata-alt-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.62.1 - #search: opp.netz + # search: opp.netz # --- @@ -131,7 +131,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - opp.netz @@ -141,7 +141,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.62.254 + - 172.16.62.254 # --- @@ -156,7 +156,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -359,7 +358,7 @@ samba_user: - verwaltung password: '' - - name: maria + - name: maria groups: - buero - beratung @@ -396,7 +395,7 @@ samba_user: - buero password: 'praktikant*in_00p' - - name: robin + - name: robin groups: - buero - beratung diff --git a/host_vars/zapata.opp.netz/zapata-common.yml b/host_vars/zapata.opp.netz/zapata-common.yml index 2958192..456b89f 100644 --- a/host_vars/zapata.opp.netz/zapata-common.yml +++ b/host_vars/zapata.opp.netz/zapata-common.yml @@ -6,10 +6,10 @@ # If true, all additional files in /etc/network/interfaces/interfaces.d/ are deleted -network_manage_devices: True +network_manage_devices: true # Should the interfaces be reloaded after config change? -network_interface_reload: False +network_interface_reload: false network_interface_path: /etc/network/interfaces.d network_interface_required_packages: @@ -44,9 +44,9 @@ network_interfaces: # - 91.239.100.100 # anycast.censurfridns.dk # search: warenform.de # - #nameservers: + # nameservers: # - 192.168.62.1 - #search: opp.netz + # search: opp.netz # --- @@ -131,7 +131,7 @@ resolved_nameserver: # If there are more than one search domains, then specify them here in the order in which # the resolver should also search them # -#resolved_domains: [] +# resolved_domains: [] resolved_domains: - ~. - opp.netz @@ -141,7 +141,7 @@ resolved_dnssec: false # dns.as250.net: 194.150.168.168 # resolved_fallback_nameserver: - - 172.16.62.254 + - 172.16.62.254 # --- @@ -156,7 +156,6 @@ cron_user_special_time_entries: insertafter: PATH - # --- # vars used by roles/common/tasks/users.yml # --- @@ -365,7 +364,7 @@ samba_user: - verwaltung password: '1Gdg1btsnL,dgdB' - - name: maria + - name: maria groups: - buero - beratung @@ -402,7 +401,7 @@ samba_user: - buero password: 'praktikant*in_00p' - - name: robin + - name: robin groups: - buero - beratung @@ -420,7 +419,7 @@ samba_user: - beratung - verwaltung password: 'X:0ff3n_' - #password: '20_simon_18!' + # password: '20_simon_18!' - name: ute groups: diff --git a/roles/common/files/a.mx/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb b/roles/common/files/a.mx.oopen.de/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb similarity index 100% rename from roles/common/files/a.mx/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb rename to roles/common/files/a.mx.oopen.de/etc/postfix/postfwd.bl-recipient-exeeds-msg-size-20mb diff --git a/roles/common/files/a.mx/etc/postfix/postfwd.wl-user b/roles/common/files/a.mx.oopen.de/etc/postfix/postfwd.wl-user similarity index 100% rename from roles/common/files/a.mx/etc/postfix/postfwd.wl-user rename to roles/common/files/a.mx.oopen.de/etc/postfix/postfwd.wl-user diff --git a/roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-dehydrated b/roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated similarity index 100% rename from roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-dehydrated rename to roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated diff --git a/roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-dehydrated.pub b/roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-dehydrated.pub rename to roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-dehydrated.pub diff --git a/roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-opendkim b/roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim similarity index 100% rename from roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-opendkim rename to roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim diff --git a/roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-opendkim.pub b/roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/a.mx/root/.ssh/a.mx-id_rsa-opendkim.pub rename to roles/common/files/a.mx.oopen.de/root/.ssh/a.mx-id_rsa-opendkim.pub diff --git a/roles/common/files/a.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/a.mx.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/a.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/a.mx.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/a.mx/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/a.mx/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/a.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf b/roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/postfix_add_mailboxes.conf similarity index 100% rename from roles/common/files/a.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf rename to roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/postfix_add_mailboxes.conf diff --git a/roles/common/files/a.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/a.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/sent_userinfo_postfix.conf diff --git a/roles/common/files/a.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/a.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/a.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/a.ns/root/bin/bind/conf/bind.conf b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind.conf similarity index 96% rename from roles/common/files/a.ns/root/bin/bind/conf/bind.conf rename to roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind.conf index 5e2352c..44498c6 100644 --- a/roles/common/files/a.ns/root/bin/bind/conf/bind.conf +++ b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind.conf @@ -1,3 +1,5 @@ +# *** [ Ansible managed: DO NOT EDIT DIRECTLY ] *** + # ---------------------------------------------------- # --- # - Parameter Settings for bind administration scripts. diff --git a/roles/common/files/a.ns/root/bin/bind/conf/bind_add_dkim_zone_slave.conf b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_slave.conf similarity index 92% rename from roles/common/files/a.ns/root/bin/bind/conf/bind_add_dkim_zone_slave.conf rename to roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_slave.conf index a5a0989..92d7417 100644 --- a/roles/common/files/a.ns/root/bin/bind/conf/bind_add_dkim_zone_slave.conf +++ b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_slave.conf @@ -1,3 +1,5 @@ +# *** [ Ansible managed: DO NOT EDIT DIRECTLY ] *** + # -------------------------------------------------------------- # - Parameter Settings for script 'bind_add_dkim_zone_slave.sh'. # --------------------------------------------------------------- diff --git a/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/create_master_zone_file.conf b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/create_master_zone_file.conf new file mode 100644 index 0000000..46d1022 --- /dev/null +++ b/roles/common/files/a.ns.oopen.de/root/bin/bind/conf/create_master_zone_file.conf @@ -0,0 +1,82 @@ +# *** [ Ansible managed: DO NOT EDIT DIRECTLY ] *** + +# ------------------------------------------------------ +# - Parameter Settings for script 'create_zone_file.sh'. +# ------------------------------------------------------ + +# - ZONE_FILE_MASTER_DIR +# - +# - Directory where all the zonefile love +# - +# - Defaults to: +# - ZONE_FILE_MASTER_DIR=/etc/bind/master +# - +ZONE_FILE_MASTER_DIR="/etc/bind/master" + + +# - NS_HOST_1 +# +# - First Nameserver +# - +# - Example: +# - NS_HOST_1="a.ns.oopen.de" +# - +# - This option is required and has no default value. But +# - option can also set using commandline parameter '--ns-host-1'' +# - +NS_HOST_1="a.ns.oopen.de" + + +# - NS_HOST_2 +# +# - Second Nameserver +# - +# - Example: +# - NS_HOST_2="b.ns.oopen.de" +# - +# - This option is required and has no default value. But +# - option can also set using commandline parameter '--ns-host-2' +# - +NS_HOST_2="b.ns.oopen.de" + + +# - MX_HOST_1 +# - +# - Example: +# - MX_HOST_1="a.mx.oopen.de" +# - +# - This option is required and has no default value. But +# - option can also set using commandline parameter '--mx-host-1' +# - +MX_HOST_1="a.mx.oopen.de" + + +# - MX_HOST_2 +# - +# - Example: +# - MX_HOST_1="b.mx.oopen.de" +# - +# - This option is optinal and has no default value. But +# - option can also set by using commandline parameter '--mx-host-2' +# - +#MX_HOST_2="" + + +# - WEB_SERVER_IP_4 +# - +# - The webservers IPv4 Address +# - +# - Example: +# - WEB_SERVER_IP_4="162.55.82.78" +# - +WEB_SERVER_IP_4="162.55.82.78" + + +# - WEB_SERVER_IP_6 +# - +# - The webservers IPv6 Address +# - +# - Example: +# - WEB_SERVER_IP_6="2a01:4f8:271:1266::78" +# - +WEB_SERVER_IP_6="2a01:4f8:271:1266::78" diff --git a/roles/common/files/b.mx/etc/postfix/postfwd.wl-nets b/roles/common/files/b.mx.oopen.de/etc/postfix/postfwd.wl-nets similarity index 100% rename from roles/common/files/b.mx/etc/postfix/postfwd.wl-nets rename to roles/common/files/b.mx.oopen.de/etc/postfix/postfwd.wl-nets diff --git a/roles/common/files/b.mx/etc/postfix/postfwd.wl-sender b/roles/common/files/b.mx.oopen.de/etc/postfix/postfwd.wl-sender similarity index 100% rename from roles/common/files/b.mx/etc/postfix/postfwd.wl-sender rename to roles/common/files/b.mx.oopen.de/etc/postfix/postfwd.wl-sender diff --git a/roles/common/files/b.mx/etc/postfix/relay_domains b/roles/common/files/b.mx.oopen.de/etc/postfix/relay_domains similarity index 100% rename from roles/common/files/b.mx/etc/postfix/relay_domains rename to roles/common/files/b.mx.oopen.de/etc/postfix/relay_domains diff --git a/roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-dehydrated b/roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated similarity index 100% rename from roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-dehydrated rename to roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated diff --git a/roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-dehydrated.pub b/roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-dehydrated.pub rename to roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-dehydrated.pub diff --git a/roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-opendkim b/roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim similarity index 100% rename from roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-opendkim rename to roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim diff --git a/roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-opendkim.pub b/roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/b.mx/root/.ssh/b.mx-id_rsa-opendkim.pub rename to roles/common/files/b.mx.oopen.de/root/.ssh/b.mx-id_rsa-opendkim.pub diff --git a/roles/common/files/b.mx/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/b.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/b.mx/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/b.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/b.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/b.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/b.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/b.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/b.ns/root/bin/bind/conf/bind_add_dkim_zone_master.conf b/roles/common/files/b.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_master.conf similarity index 94% rename from roles/common/files/b.ns/root/bin/bind/conf/bind_add_dkim_zone_master.conf rename to roles/common/files/b.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_master.conf index 9344a0c..883b4bc 100644 --- a/roles/common/files/b.ns/root/bin/bind/conf/bind_add_dkim_zone_master.conf +++ b/roles/common/files/b.ns.oopen.de/root/bin/bind/conf/bind_add_dkim_zone_master.conf @@ -1,3 +1,5 @@ +# *** [ Ansible managed: DO NOT EDIT DIRECTLY ] *** + # -------------------------------------------------------------- # - Parameter Settings for script 'bind_add_dkim_zone_master.sh'. # --------------------------------------------------------------- diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-dehydrated b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-dehydrated rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-dehydrated.pub b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-dehydrated.pub rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-dehydrated.pub diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-opendkim b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-opendkim rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-opendkim.pub b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa-opendkim.pub rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa-opendkim.pub diff --git a/roles/common/files/c.mx/root/.ssh/c.mx-id_rsa.pub b/roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa.pub similarity index 100% rename from roles/common/files/c.mx/root/.ssh/c.mx-id_rsa.pub rename to roles/common/files/c.mx.oopen.de/root/.ssh/c.mx-id_rsa.pub diff --git a/roles/common/files/c.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/c.mx.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/c.mx/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/c.mx.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/c.mx/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/c.mx/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/c.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf b/roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/postfix_add_mailboxes.conf similarity index 100% rename from roles/common/files/c.mx/root/bin/postfix/conf/postfix_add_mailboxes.conf rename to roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/postfix_add_mailboxes.conf diff --git a/roles/common/files/c.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/c.mx/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/sent_userinfo_postfix.conf diff --git a/roles/common/files/c.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/c.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/c.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-dehydrated b/roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-dehydrated similarity index 100% rename from roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-dehydrated rename to roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-dehydrated diff --git a/roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-dehydrated.pub b/roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-dehydrated.pub rename to roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-dehydrated.pub diff --git a/roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-opendkim b/roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-opendkim similarity index 100% rename from roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-opendkim rename to roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-opendkim diff --git a/roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-opendkim.pub b/roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/d.mx/root/.ssh/d.mx-id_rsa-opendkim.pub rename to roles/common/files/d.mx.oopen.de/root/.ssh/d.mx-id_rsa-opendkim.pub diff --git a/roles/common/files/d.mx/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/d.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/d.mx/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/d.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/d.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/d.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/d.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/d.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/d.mx/usr/local/src/sympa/conf/install_sympa.conf b/roles/common/files/d.mx.oopen.de/usr/local/src/sympa/conf/install_sympa.conf similarity index 100% rename from roles/common/files/d.mx/usr/local/src/sympa/conf/install_sympa.conf rename to roles/common/files/d.mx.oopen.de/usr/local/src/sympa/conf/install_sympa.conf diff --git a/roles/common/files/g.mx/etc/postfix/postfwd.wl-nets b/roles/common/files/g.mx.oopen.de/etc/postfix/postfwd.wl-nets similarity index 100% rename from roles/common/files/g.mx/etc/postfix/postfwd.wl-nets rename to roles/common/files/g.mx.oopen.de/etc/postfix/postfwd.wl-nets diff --git a/roles/common/files/g.mx/etc/postfix/relay_domains b/roles/common/files/g.mx.oopen.de/etc/postfix/relay_domains similarity index 100% rename from roles/common/files/g.mx/etc/postfix/relay_domains rename to roles/common/files/g.mx.oopen.de/etc/postfix/relay_domains diff --git a/roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-dehydrated b/roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-dehydrated similarity index 100% rename from roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-dehydrated rename to roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-dehydrated diff --git a/roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-dehydrated.pub b/roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-dehydrated.pub similarity index 100% rename from roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-dehydrated.pub rename to roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-dehydrated.pub diff --git a/roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-opendkim b/roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-opendkim similarity index 100% rename from roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-opendkim rename to roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-opendkim diff --git a/roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-opendkim.pub b/roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-opendkim.pub similarity index 100% rename from roles/common/files/g.mx/root/.ssh/g.mx-id_ed25519-opendkim.pub rename to roles/common/files/g.mx.oopen.de/root/.ssh/g.mx-id_ed25519-opendkim.pub diff --git a/roles/common/files/g.mx/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/g.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/g.mx/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/g.mx.oopen.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/g.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/g.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/g.mx/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/g.mx.oopen.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/ga-al-relay/etc/postfix/relay_domains b/roles/common/files/ga-al-relay.ga.netz/etc/postfix/relay_domains similarity index 100% rename from roles/common/files/ga-al-relay/etc/postfix/relay_domains rename to roles/common/files/ga-al-relay.ga.netz/etc/postfix/relay_domains diff --git a/roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-dehydrated b/roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated similarity index 100% rename from roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-dehydrated rename to roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated diff --git a/roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub b/roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub rename to roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub diff --git a/roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-opendkim b/roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim similarity index 100% rename from roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-opendkim rename to roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim diff --git a/roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-opendkim.pub b/roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/ga-st-mail/root/.ssh/ga-st-mail-id_rsa-opendkim.pub rename to roles/common/files/ga-al-relay.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub diff --git a/roles/common/files/ga-st-mail/etc/postfix/postfwd.cf b/roles/common/files/ga-st-mail.ga.netz/etc/postfix/postfwd.cf similarity index 100% rename from roles/common/files/ga-st-mail/etc/postfix/postfwd.cf rename to roles/common/files/ga-st-mail.ga.netz/etc/postfix/postfwd.cf diff --git a/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated new file mode 100644 index 0000000..0a256b5 --- /dev/null +++ b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated @@ -0,0 +1,49 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAACFwAAAAdzc2gtcn +NhAAAAAwEAAQAAAgEAxe0sdGCZS444N0pvLolycgXiipmRbptw/DMNlUGa1yYGDq1Qf0lQ +1zuDeSOjTk+W78bPHOQy1f+CeHsBj+XRkmInqUZ5K0UgVFEuiAsJGH8l63phyd9bkRHzg0 +QQOFZ7JqcNEpW0NiPSKWMLGg9/yA2XoQ4GgiruA9PyyKa2YdP7vll+5Dhm/E5Jvzwbtkkm +wM1EWjF5/1LRrFMq4nJAJhCval2Q7DWIHMDqmWj7ZDGT95gHYsf4CmlldO6FOPc8Qa6Lg/ +IEVgLP8ji78TntSQ3B9mRMV5fNYyWJVH3ymqwR7FjTRO/YVCJ5x/WE38T9QBAvjMhV8ais +M9y5NXUMlKNUxbSU2GPvyB7F0/+ioWzourcIY+1O7mRKmiFsqOjfllS/XxYYJm0qFSBOiq +wTOVbTna99wN2vl3jQEBo1upqjnL94jVA4qU5w0ypBAFkFlpyuWEbmicNXlAqIovxQ6dIU +U1iKp/kVQoJDhoBIzCEQvLYkKLgl8cH7pH3Kvcw/EvFAsskGNLlkR5t7jORh05ryCRwV31 +wUl/wfj4HrEmVcCAgokv+mUlk/ug+TmwXShpM9dgO/e2MmjLDe0bSZ+jgYT0axn6kCwiDO +5acSRwKEJk0jIrkKf04xy3nYwJtxb8RE9mb6j1oPULb0syKM9iTnSsrGRxoGwXQu6ugrLL +8AAAdApTZfwqU2X8IAAAAHc3NoLXJzYQAAAgEAxe0sdGCZS444N0pvLolycgXiipmRbptw +/DMNlUGa1yYGDq1Qf0lQ1zuDeSOjTk+W78bPHOQy1f+CeHsBj+XRkmInqUZ5K0UgVFEuiA +sJGH8l63phyd9bkRHzg0QQOFZ7JqcNEpW0NiPSKWMLGg9/yA2XoQ4GgiruA9PyyKa2YdP7 +vll+5Dhm/E5JvzwbtkkmwM1EWjF5/1LRrFMq4nJAJhCval2Q7DWIHMDqmWj7ZDGT95gHYs +f4CmlldO6FOPc8Qa6Lg/IEVgLP8ji78TntSQ3B9mRMV5fNYyWJVH3ymqwR7FjTRO/YVCJ5 +x/WE38T9QBAvjMhV8aisM9y5NXUMlKNUxbSU2GPvyB7F0/+ioWzourcIY+1O7mRKmiFsqO +jfllS/XxYYJm0qFSBOiqwTOVbTna99wN2vl3jQEBo1upqjnL94jVA4qU5w0ypBAFkFlpyu +WEbmicNXlAqIovxQ6dIUU1iKp/kVQoJDhoBIzCEQvLYkKLgl8cH7pH3Kvcw/EvFAsskGNL +lkR5t7jORh05ryCRwV31wUl/wfj4HrEmVcCAgokv+mUlk/ug+TmwXShpM9dgO/e2MmjLDe +0bSZ+jgYT0axn6kCwiDO5acSRwKEJk0jIrkKf04xy3nYwJtxb8RE9mb6j1oPULb0syKM9i +TnSsrGRxoGwXQu6ugrLL8AAAADAQABAAACAChfUIoMijhXMjBVBoi/kJChkqwi1v9wxYMs +BsFDOIpaPzIPODQ+iDbe9Npo4o6+vVL7gpOqGJR+IebhcFgh0LXDP8PPlDe3Sfjo9kzZs2 +lDxkBaHkhHPy5AMyO7ZnOXcFdaC9iWoMPKWrwGb+VI9A+idiNr8PfsOdCeEw/KsbkSvG7/ +Ylq7BobAkVposF5mXXlGZYLgRLpH8mzsKfs2ws8A6EcR/tWvtavnzfKs71poon4GjLshfv +7gsMlBPft4stnS+LJZU3kX6cLGv89cuYIFRGM14jybwlFO/sw1RJ84Kg/DrpSJN98xiRW4 +hvn9/IpswsY8twssFLQfecflsELlfkzVNE1YR1d2rHdBEHKSa0piNvaUgPuIP9oggDkE/m +pF4Oz/aW71fHLWQVxf3qlCnYfshf86XqJTZvJ8N7edF4XZ+UiOWPl5c8vXBJDFLrydenWF +9z4IExHZafmYygnbLdEP4cFq8fPsb7zbhNr8aLOLfIyLj30brvIE9/gc7VnME0PdK3n2FO +u4GDTYSE0UNpjctw5Fg4+89Yv1xD/onLIA43scw3l3NhCtLI5QHnsO8cckga6/wcdfOG2f +V8kMzICZt3IFnR4EgDlavLMx+FthyYKDE4JYOKM2Qy6xGRg9p6kFyb7SQEFy91JgCN5tpJ +V5ezfJF7bgTW8tuQpBAAABABSvsV4UpatmjpicZChtXMQHuDob/ZUcVwJ3emORxD5vfKd8 +zuySbJxlJBIIUVT2ako8AmUYQBjIU+vPI18CHdhDhL4rDmeletC6Sl1KB089dc2qavIvtC +N0E5+iozCXHGirr79t3UTVGBMGr5UYG9y5nfa7WWY38UqVc63TK2EVT0wrNxgS9hUtZWbk +LsEiIAUEp/8N5wKKv4+uVfzSfg0sEy/JGNU0KNcxFUZNolSEeieQUdmopALD04f/YOdhO5 +mV5oS3lDUC8cnbefQmoK/kszfgOb/qMC76RqLa7IUm91IZbKfA78x81gjSsuiqfPXsE9El +GxqXrnggbHarFG4AAAEBAOwpW++DbYcI3AJn44o3sH6bGVVsNbAualMxFz0XYwdnoD7UUG +aOhlRFWZXqOQEbvt1LOp4SYyT50puwdvg0as6+78FnlwVXVaHKjP0Igh2e8Ls5YYpp8jas +FDcZa0F5JiAFPamxY+ypvaD/Fmc3ha7JBGOGkV67qktOO+Dtd2NSKB6EIt8ShKbjZA6U2i +UAQCp2AC+f3CDL+3vN/Gj4oBI2ysYl3QVG/nuBT8Lxdf+JabEYwPBMlOqYVfjYQj0FL6Ht +/+MCeVyaeww+a0/i+W5RqqBn1ptOw1YlamsOvLG2Z0FL6s2/uTE9+dYfQXto6j6vkAGrIr +yugIYwC0abzxsAAAEBANaNkiXeqKssyYZ14OEfzXyD7M3l2vvfGRvCS0XgqEodvVGbB/A4 +AAWtkuPvOPqSzaOIfdbIcN1dvccJuxU/SPanL33aX7PLROuq7ApIbhzFI5QblvoivUAMST +ND9QjAu8hHiO9K6qRU3evEpJVvN2iOznTuU/A91n5ChJLeQAjqpMhgB45ZlWKmPE+y0kw6 +aCZq7qmqqCRr5nzY1YYFy2UilbOUyeO5wCDa6bN8FXYvKTBWOmTvsoILPjTjiaZbfITmfd +f2n4mNITViGU6kirtZSzjRRqqQRj0Vz9f5Qn2TBZ/uCkTDQEBtr/rdAHL9eBaSXYXWVIpl +RsBCSs/Sny0AAAAHcm9vdEBteAECAwQ= +-----END OPENSSH PRIVATE KEY----- diff --git a/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub new file mode 100644 index 0000000..fe60301 --- /dev/null +++ b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-dehydrated.pub @@ -0,0 +1 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQDF7Sx0YJlLjjg3Sm8uiXJyBeKKmZFum3D8Mw2VQZrXJgYOrVB/SVDXO4N5I6NOT5bvxs8c5DLV/4J4ewGP5dGSYiepRnkrRSBUUS6ICwkYfyXremHJ31uREfODRBA4Vnsmpw0SlbQ2I9IpYwsaD3/IDZehDgaCKu4D0/LIprZh0/u+WX7kOGb8Tkm/PBu2SSbAzURaMXn/UtGsUyrickAmEK9qXZDsNYgcwOqZaPtkMZP3mAdix/gKaWV07oU49zxBrouD8gRWAs/yOLvxOe1JDcH2ZExXl81jJYlUffKarBHsWNNE79hUInnH9YTfxP1AEC+MyFXxqKwz3Lk1dQyUo1TFtJTYY+/IHsXT/6KhbOi6twhj7U7uZEqaIWyo6N+WVL9fFhgmbSoVIE6KrBM5VtOdr33A3a+XeNAQGjW6mqOcv3iNUDipTnDTKkEAWQWWnK5YRuaJw1eUCoii/FDp0hRTWIqn+RVCgkOGgEjMIRC8tiQouCXxwfukfcq9zD8S8UCyyQY0uWRHm3uM5GHTmvIJHBXfXBSX/B+PgesSZVwICCiS/6ZSWT+6D5ObBdKGkz12A797YyaMsN7RtJn6OBhPRrGfqQLCIM7lpxJHAoQmTSMiuQp/TjHLedjAm3FvxET2ZvqPWg9QtvSzIoz2JOdKysZHGgbBdC7q6Cssvw== root@ga-st-mail-dehydrated diff --git a/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim new file mode 100644 index 0000000..59e5e27 --- /dev/null +++ b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim @@ -0,0 +1,49 @@ +-----BEGIN OPENSSH PRIVATE KEY----- +b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAACFwAAAAdzc2gtcn +NhAAAAAwEAAQAAAgEAr9qw2oQHkAUfTXEJBxuVR2zDRpTsxyT24eVd+KIJaALVtFVTu8Z3 +rNwJN0P3jNLRWxTBuDEbYtTN1J9Bic01fR9m6jdNk5lKeTJw1Q3BzXxuC+4aix9ircJ4in +geNSCiHiVHYaSsXRRajPGe/F5+RAEjuRbt95UHB/kU25qGIpBK9Vq0m0Ad8HKrV0vpTb3s +hVJSQ/VydDC82pwXj0IfW6HPdwnzmt8hU2/dIK3weUI56S+9euzKUh+jqvw1YeTXJzM76G +I2X/YLDEx7jgFMlChnlHYNivPYBY5Aatq90t6LiqQ0MT0kVx7jQwUnhyRB8vAz+qznftKm +VTmjxL90IvwUTzvS1nHNmlIPMnSO8NaDHf0k2iueD2lCSe7l1d2U0LMRss4sGZcfhqtDzQ +DIyhXWFwHLhj55WMQxoVXCSRJRLruwyUKqVn86H6L9lRJ4kEPBJJJ6cXeTBWJGtDT9N/Ja +SGcjM8tdwxSeilHIW0xn85B3MCphV/t72RRAaqua2VjrmN9N6nuYD+3iobAVf4ruOzXtTr +U0tjdEBT0xJbIZNwi22Snq0KPly8aN2deXEQ8Q7IJHQB7WNT4jI13l/GWocFwtr7NWXwaD +eJCtoiB9RraK+EBvoO3IYymvpGQyqhXeMtBGc3kdCI2AslrdpjXd4TGxIwbWae+Xa2JkZa +kAAAdAgUVtA4FFbQMAAAAHc3NoLXJzYQAAAgEAr9qw2oQHkAUfTXEJBxuVR2zDRpTsxyT2 +4eVd+KIJaALVtFVTu8Z3rNwJN0P3jNLRWxTBuDEbYtTN1J9Bic01fR9m6jdNk5lKeTJw1Q +3BzXxuC+4aix9ircJ4ingeNSCiHiVHYaSsXRRajPGe/F5+RAEjuRbt95UHB/kU25qGIpBK +9Vq0m0Ad8HKrV0vpTb3shVJSQ/VydDC82pwXj0IfW6HPdwnzmt8hU2/dIK3weUI56S+9eu +zKUh+jqvw1YeTXJzM76GI2X/YLDEx7jgFMlChnlHYNivPYBY5Aatq90t6LiqQ0MT0kVx7j +QwUnhyRB8vAz+qznftKmVTmjxL90IvwUTzvS1nHNmlIPMnSO8NaDHf0k2iueD2lCSe7l1d +2U0LMRss4sGZcfhqtDzQDIyhXWFwHLhj55WMQxoVXCSRJRLruwyUKqVn86H6L9lRJ4kEPB +JJJ6cXeTBWJGtDT9N/JaSGcjM8tdwxSeilHIW0xn85B3MCphV/t72RRAaqua2VjrmN9N6n +uYD+3iobAVf4ruOzXtTrU0tjdEBT0xJbIZNwi22Snq0KPly8aN2deXEQ8Q7IJHQB7WNT4j +I13l/GWocFwtr7NWXwaDeJCtoiB9RraK+EBvoO3IYymvpGQyqhXeMtBGc3kdCI2Aslrdpj +Xd4TGxIwbWae+Xa2JkZakAAAADAQABAAACABJKDFqtoJu57KeBOg8jL0NebHDKzFVp4sNb +t4pET/YhVViMB0lgOtIfkFXPG8/pnRx77Cnb8Z01xLJ4XbiXPxjkSy/Q0KCpMLWqKVH/PE +jCyC81dE1D1l97+k1scLfVzQaVmfbtyX9kvoYqGv7kVP19oNl/KQC23yRVI3Yze//cQe+C +n4YGBRcc1fUeUAVl21OCXEv1GxI6f2m9EjY0Ck7dZVZcEpno2u5yk+zyKjByUtONw4clWW +VxJPSDhonH4xiQm4pvrHgOfteonLEIMY63JQ6ruHzbH3x0bv6uAVANFTY2HbeBRGZLMBeo +UZQckT9S/BT2Jp1qCyKR/BZaUxmkLOAfJl2rW5IfOOOtKEE/q0DVRidfDf2A2ihmsfbCqR +hbhOmf7IbqC4XTGm6W9U3pNyu8Oz4QxRyhwlTWTa3hqvF/xJo6C82yy3p4HYRTX5VfZNbN +iQ7CM/UY0ee69br80MPPdxLetmGX9VvR6g1lsRK8/447DiOD9TZtAXMAiCOf3FUyhwRmRP +qUdGOXHjXsBAjDMWA0OwwdiGFI7dk5zdyQNTpRsM38cctGeBixPs9SOrTKr10zSaf9NzX4 +srsXnoAdm2LHQIa0Awfd1TJydFjC6KIGgtZgXy4UDpPE6RzlDnkY8DO/pLLhXMAgtts+G/ +ZiaRBKY65VYOHKqVoBAAABAHsbFe8LTyYnDhzgKrlLbeGDySEHTeBbVpKbIUhDjkqoyHvc +HzEt7b2idhJtjXsEIcMUO+0ut1A2toY/JHkHOKnyXPpqv1NxXR/4ru6rAXrOGB/LQCUtcl +5Q4StZvvOtcKbt8b0kvvvBMmkFGEtJr5ybDy6K5CFyyROGlUTpXPfjZjuv6YuzqCsLYXXM +o4cWK1ZUQ7Yf1YovZr3zk6VMzd4gHHQzyTVP5iNflSB3k+AQZClLy771bw2caPFgdpu87a +kAvhtW+anGLkFxSCZFRMkv9rXl8tB2ZPKWqQb8jEzAfH0CC7sDkddLE2l45RapGMUtsJ1V +fF8pGpFiHX7FABoAAAEBAN9JT4Tc29Wc5lDVZEqz8IYT+/eRVBAlALmt7jTVwclY+KSZ5g +i+QONIWj+Js+1Z84bzOzcQ6pZIFAZ57+5qkFeUpfVJB+UL7bLqNF2GeBAvtZ+GgguBK5uN +H+uXrnyeEWn8ppcHebA5vi/GxzCebZ29VnUbh/nHn0WmMvOBAFYqtjGNxo1diYyp8vS0k+ +pmhZA5xtgGKzGGwrlAJrWLPzAieFPkNJsDMcY03RkU9u0XI3SkrtlmRqaykSzJpIAtDuT/ +D7gyjrNBH6a8qv57LxaUyeWEBOtlC7C4mtTrWcu/+zS8dkh7Y4ZaNR83Zx24DRzAfbuA/R +04eb6Jd55ATr0AAAEBAMmeXjYdwqh2gbizFgyP8ZgTxXUWp5B0YQ7XUOC8CuQqAL8/HlE3 +gVHLwrUIKAwTUADfqvzyG86IgJOw1byU3DWY9b5dKfrWm1RhcvLWMgIjRHH3sqnVWxIBam +RkfDkRZ/B8236SoAxe5k7yqZ3wQ6BNJstY1Nya+iJG1h6mLPasEzqZH+JOd0Uc9Fsr8uYR +CmvojolkAaa2We44y9oCXTTHCBfpFUZf0gySmG7ZEXA6MqwTCcbFCP599YmRQ2BmdO0SQF +YHIhpmc3xBjKMiNqhNBii2PUejVp7OVqHQBCeWq/GH9yTj00JeX9KoL7DdoyCoCWHG4eB0 +JVW9wg49J10AAAAHcm9vdEBteAECAwQ= +-----END OPENSSH PRIVATE KEY----- diff --git a/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub new file mode 100644 index 0000000..1a1f50d --- /dev/null +++ b/roles/common/files/ga-st-mail.ga.netz/root/.ssh/ga-st-mail-id_rsa-opendkim.pub @@ -0,0 +1 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAACAQCv2rDahAeQBR9NcQkHG5VHbMNGlOzHJPbh5V34ogloAtW0VVO7xnes3Ak3Q/eM0tFbFMG4MRti1M3Un0GJzTV9H2bqN02TmUp5MnDVDcHNfG4L7hqLH2KtwniKeB41IKIeJUdhpKxdFFqM8Z78Xn5EASO5Fu33lQcH+RTbmoYikEr1WrSbQB3wcqtXS+lNveyFUlJD9XJ0MLzanBePQh9boc93CfOa3yFTb90grfB5QjnpL7167MpSH6Oq/DVh5NcnMzvoYjZf9gsMTHuOAUyUKGeUdg2K89gFjkBq2r3S3ouKpDQxPSRXHuNDBSeHJEHy8DP6rOd+0qZVOaPEv3Qi/BRPO9LWcc2aUg8ydI7w1oMd/STaK54PaUJJ7uXV3ZTQsxGyziwZlx+Gq0PNAMjKFdYXAcuGPnlYxDGhVcJJElEuu7DJQqpWfzofov2VEniQQ8Ekknpxd5MFYka0NP038lpIZyMzy13DFJ6KUchbTGfzkHcwKmFX+3vZFEBqq5rZWOuY303qe5gP7eKhsBV/iu47Ne1OtTS2N0QFPTElshk3CLbZKerQo+XLxo3Z15cRDxDsgkdAHtY1PiMjXeX8ZahwXC2vs1ZfBoN4kK2iIH1Gtor4QG+g7chjKa+kZDKqFd4y0EZzeR0IjYCyWt2mNd3hMbEjBtZp75drYmRlqQ== root@ga-st-mail-opendkim diff --git a/roles/common/files/ga-st-mail/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/ga-st-mail.ga.netz/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/ga-st-mail/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/ga-st-mail.ga.netz/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/ga-st-mail/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/ga-st-mail/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/ga-st-mail/root/bin/postfix/conf/postfix_add_mailboxes.conf b/roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/postfix_add_mailboxes.conf similarity index 100% rename from roles/common/files/ga-st-mail/root/bin/postfix/conf/postfix_add_mailboxes.conf rename to roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/postfix_add_mailboxes.conf diff --git a/roles/common/files/ga-st-mail/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/ga-st-mail/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/sent_userinfo_postfix.conf diff --git a/roles/common/files/ga-st-mail/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/ga-st-mail/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/ga-st-mail.ga.netz/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim b/roles/common/files/lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim similarity index 100% rename from roles/common/files/lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim rename to roles/common/files/lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim diff --git a/roles/common/files/lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub b/roles/common/files/lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/lists.mx.warenform/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub rename to roles/common/files/lists.mx.warenform.de/root/.ssh/lists.mx.warenform-id_rsa-opendkim.pub diff --git a/roles/common/files/lists.mx.warenform/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/lists.mx.warenform.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/lists.mx.warenform/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/lists.mx.warenform.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/lists.mx.warenform/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/lists.mx.warenform.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/lists.mx.warenform/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/lists.mx.warenform.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/lists.mx.warenform/usr/local/src/sympa/conf/install_sympa.conf b/roles/common/files/lists.mx.warenform.de/usr/local/src/sympa/conf/install_sympa.conf similarity index 100% rename from roles/common/files/lists.mx.warenform/usr/local/src/sympa/conf/install_sympa.conf rename to roles/common/files/lists.mx.warenform.de/usr/local/src/sympa/conf/install_sympa.conf diff --git a/roles/common/files/mail.cadus/etc/postfix/postfwd.high-rate-number-messages b/roles/common/files/mail.cadus.org/etc/postfix/postfwd.high-rate-number-messages similarity index 100% rename from roles/common/files/mail.cadus/etc/postfix/postfwd.high-rate-number-messages rename to roles/common/files/mail.cadus.org/etc/postfix/postfwd.high-rate-number-messages diff --git a/roles/common/files/mail.cadus/etc/postfix/postfwd.wl-nets b/roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-nets similarity index 100% rename from roles/common/files/mail.cadus/etc/postfix/postfwd.wl-nets rename to roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-nets diff --git a/roles/common/files/mail.cadus/etc/postfix/postfwd.wl-sender b/roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-sender similarity index 100% rename from roles/common/files/mail.cadus/etc/postfix/postfwd.wl-sender rename to roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-sender diff --git a/roles/common/files/mail.cadus/etc/postfix/postfwd.wl-user b/roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-user similarity index 100% rename from roles/common/files/mail.cadus/etc/postfix/postfwd.wl-user rename to roles/common/files/mail.cadus.org/etc/postfix/postfwd.wl-user diff --git a/roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-dehydrated b/roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-dehydrated similarity index 100% rename from roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-dehydrated rename to roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-dehydrated diff --git a/roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-dehydrated.pub b/roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-dehydrated.pub rename to roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-dehydrated.pub diff --git a/roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-opendkim b/roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-opendkim similarity index 100% rename from roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-opendkim rename to roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-opendkim diff --git a/roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-opendkim.pub b/roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/mail.cadus/root/.ssh/mail.cadus-id_rsa-opendkim.pub rename to roles/common/files/mail.cadus.org/root/.ssh/mail.cadus-id_rsa-opendkim.pub diff --git a/roles/common/files/mail.cadus/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/mail.cadus.org/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/mail.cadus/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/mail.cadus.org/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/mail.cadus/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/mail.cadus.org/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/mail.cadus/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/mail.cadus.org/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/mail.cadus/root/bin/postfix/conf/postfix_add_mailboxes.conf b/roles/common/files/mail.cadus.org/root/bin/postfix/conf/postfix_add_mailboxes.conf similarity index 100% rename from roles/common/files/mail.cadus/root/bin/postfix/conf/postfix_add_mailboxes.conf rename to roles/common/files/mail.cadus.org/root/bin/postfix/conf/postfix_add_mailboxes.conf diff --git a/roles/common/files/mail.cadus/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/mail.cadus.org/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/mail.cadus/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/mail.cadus.org/root/bin/postfix/conf/sent_userinfo_postfix.conf diff --git a/roles/common/files/mail.cadus/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/mail.cadus.org/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/mail.cadus/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/mail.cadus.org/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated b/roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated rename to roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated diff --git a/roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub b/roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub rename to roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-dehydrated.pub diff --git a/roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim b/roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim rename to roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim diff --git a/roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub b/roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub rename to roles/common/files/mail.faire-mobilitaet.de/root/.ssh/mail.faire-mobilitaet-id_rsa-opendkim.pub diff --git a/roles/common/files/mail.faire-mobilitaet/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/mail.faire-mobilitaet.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/mail.faire-mobilitaet.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/create_opendkim_key.conf b/roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/create_opendkim_key.conf similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/create_opendkim_key.conf rename to roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/create_opendkim_key.conf diff --git a/roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/postfix_add_mailboxes.conf b/roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/postfix_add_mailboxes.conf similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/postfix_add_mailboxes.conf rename to roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/postfix_add_mailboxes.conf diff --git a/roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/sent_userinfo_postfix.conf diff --git a/roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/whitelist_mb_sigs.conf b/roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/whitelist_mb_sigs.conf similarity index 100% rename from roles/common/files/mail.faire-mobilitaet/root/bin/postfix/conf/whitelist_mb_sigs.conf rename to roles/common/files/mail.faire-mobilitaet.de/root/bin/postfix/conf/whitelist_mb_sigs.conf diff --git a/roles/common/files/o13-mail/etc/postfix/postfwd.wl-hosts b/roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-hosts similarity index 100% rename from roles/common/files/o13-mail/etc/postfix/postfwd.wl-hosts rename to roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-hosts diff --git a/roles/common/files/o13-mail/etc/postfix/postfwd.wl-nets b/roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-nets similarity index 100% rename from roles/common/files/o13-mail/etc/postfix/postfwd.wl-nets rename to roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-nets diff --git a/roles/common/files/o13-mail/etc/postfix/postfwd.wl-sender b/roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-sender similarity index 100% rename from roles/common/files/o13-mail/etc/postfix/postfwd.wl-sender rename to roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-sender diff --git a/roles/common/files/o13-mail/etc/postfix/postfwd.wl-user b/roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-user similarity index 100% rename from roles/common/files/o13-mail/etc/postfix/postfwd.wl-user rename to roles/common/files/o13-mail.oopen.de/etc/postfix/postfwd.wl-user diff --git a/roles/common/files/o13-mail/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/o13-mail.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/o13-mail/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/o13-mail.oopen.de/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/o13-mail/root/bin/postfix/conf/check-postfix-fatal-errors.conf b/roles/common/files/o13-mail.oopen.de/root/bin/postfix/conf/check-postfix-fatal-errors.conf similarity index 100% rename from roles/common/files/o13-mail/root/bin/postfix/conf/check-postfix-fatal-errors.conf rename to roles/common/files/o13-mail.oopen.de/root/bin/postfix/conf/check-postfix-fatal-errors.conf diff --git a/roles/common/files/rage/etc/postfix/postfwd.wl-hosts b/roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-hosts similarity index 100% rename from roles/common/files/rage/etc/postfix/postfwd.wl-hosts rename to roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-hosts diff --git a/roles/common/files/rage/etc/postfix/postfwd.wl-nets b/roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-nets similarity index 100% rename from roles/common/files/rage/etc/postfix/postfwd.wl-nets rename to roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-nets diff --git a/roles/common/files/rage/etc/postfix/postfwd.wl-sender b/roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-sender similarity index 100% rename from roles/common/files/rage/etc/postfix/postfwd.wl-sender rename to roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-sender diff --git a/roles/common/files/rage/etc/postfix/postfwd.wl-user b/roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-user similarity index 100% rename from roles/common/files/rage/etc/postfix/postfwd.wl-user rename to roles/common/files/rage.so36.net/etc/postfix/postfwd.wl-user diff --git a/roles/common/files/rage/root/bin/monitoring/conf/check_cert_for_dovecot.conf b/roles/common/files/rage.so36.net/root/bin/monitoring/conf/check_cert_for_dovecot.conf similarity index 100% rename from roles/common/files/rage/root/bin/monitoring/conf/check_cert_for_dovecot.conf rename to roles/common/files/rage.so36.net/root/bin/monitoring/conf/check_cert_for_dovecot.conf diff --git a/roles/common/files/rage/root/bin/postfix/conf/check-postfix-fatal-errors.conf b/roles/common/files/rage.so36.net/root/bin/postfix/conf/check-postfix-fatal-errors.conf similarity index 100% rename from roles/common/files/rage/root/bin/postfix/conf/check-postfix-fatal-errors.conf rename to roles/common/files/rage.so36.net/root/bin/postfix/conf/check-postfix-fatal-errors.conf diff --git a/roles/common/files/rage/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf b/roles/common/files/rage.so36.net/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf similarity index 100% rename from roles/common/files/rage/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf rename to roles/common/files/rage.so36.net/root/bin/postfix/conf/get_number_of_deferred_mailqueue.conf diff --git a/roles/common/files/rage/root/bin/postfix/conf/sent_userinfo_postfix.conf b/roles/common/files/rage.so36.net/root/bin/postfix/conf/sent_userinfo_postfix.conf similarity index 100% rename from roles/common/files/rage/root/bin/postfix/conf/sent_userinfo_postfix.conf rename to roles/common/files/rage.so36.net/root/bin/postfix/conf/sent_userinfo_postfix.conf