<feed xmlns='http://www.w3.org/2005/Atom'>
<title>salt.git/pillar/cluster, branch nsd</title>
<subtitle>Work in progress effort to automate the LibertaCasa infrastructure configuration using SaltStack </subtitle>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/'/>
<entry>
<title>denc-webcluster: add ModSecurity adjustments</title>
<updated>2023-02-12T22:46:22+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T22:46:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=c75e31c14542cd8db89e9b7616adb82e22e945ea'/>
<id>c75e31c14542cd8db89e9b7616adb82e22e945ea</id>
<content type='text'>
With the rollout of our Salted configuration, ModSecurity came enforced.
This adds necessary rules to PrivateBin and BookStack for correct
operation.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
With the rollout of our Salted configuration, ModSecurity came enforced.
This adds necessary rules to PrivateBin and BookStack for correct
operation.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>denc-webcluster: nginx listen on HA addresses</title>
<updated>2023-02-12T16:42:31+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T16:42:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=37a1ec433ac588e864de89e245bb84308d6ed4da'/>
<id>37a1ec433ac588e864de89e245bb84308d6ed4da</id>
<content type='text'>
Accidentally configured to listen only internally.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Accidentally configured to listen only internally.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>denc-webcluster: nginx AppArmor rules</title>
<updated>2023-02-12T15:39:49+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T15:28:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=2d5da24ce5d695b3f934ec06c654f7ae754b3fbf'/>
<id>2d5da24ce5d695b3f934ec06c654f7ae754b3fbf</id>
<content type='text'>
Allow access to client trust certificate and to static content.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Allow access to client trust certificate and to static content.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>denc-webcluster: nginx config fixup</title>
<updated>2023-02-12T14:48:44+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T14:48:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=eac227d1204f7ab149c98360994951cdd94771b0'/>
<id>eac227d1204f7ab149c98360994951cdd94771b0</id>
<content type='text'>
- remove keys duplicated by include
- repair wrong snippets include directory
- repair wrong ip_hash option syntax

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- remove keys duplicated by include
- repair wrong snippets include directory
- repair wrong ip_hash option syntax

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>denc-webcluster: enable keepalived script security</title>
<updated>2023-02-12T13:37:45+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T13:37:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=533aedd864fce377ee4cc543bad5edcf4ef6acf3'/>
<id>533aedd864fce377ee4cc543bad5edcf4ef6acf3</id>
<content type='text'>
Prevent script tampering.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Prevent script tampering.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>denc-webcluster: allow http(s) publicly</title>
<updated>2023-02-12T13:33:34+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-12T13:33:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=7481741f95e591727b2dee0e58c31d68f58c5359'/>
<id>7481741f95e591727b2dee0e58c31d68f58c5359</id>
<content type='text'>
Public firewall rules were missing from initial import.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Public firewall rules were missing from initial import.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>nemesis/hubris: import keepalived configuration</title>
<updated>2023-02-12T04:21:43+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-08T19:52:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=303b06ae8cae4167bca6bafca71d226b32379941'/>
<id>303b06ae8cae4167bca6bafca71d226b32379941</id>
<content type='text'>
Add shared configuration to cluster.denc.web-proxy.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add shared configuration to cluster.denc.web-proxy.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>nemesis/hubris: import nginx configuration</title>
<updated>2023-02-12T04:21:39+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-07T23:10:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=eed4945a9f6981041260a593fde7bc54150c0740'/>
<id>eed4945a9f6981041260a593fde7bc54150c0740</id>
<content type='text'>
Add shared configuration to cluster.denc.web-proxy.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Add shared configuration to cluster.denc.web-proxy.

Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Add cluster pillar</title>
<updated>2023-02-05T08:36:23+00:00</updated>
<author>
<name>Georg Pfuetzenreuter</name>
</author>
<published>2023-02-05T08:36:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.casa/salt.git/commit/?id=3f2b8d2ee79ba53027b60c932c0dc41a1a5cd3f5'/>
<id>3f2b8d2ee79ba53027b60c932c0dc41a1a5cd3f5</id>
<content type='text'>
Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Signed-off-by: Georg Pfuetzenreuter &lt;mail@georg-pfuetzenreuter.net&gt;
</pre>
</div>
</content>
</entry>
</feed>
