Commit Graph

56 Commits

Author SHA1 Message Date
Patrick Uiterwijk
8c9fcd56d1 Add mirrorlist-ibiblio02 vpn ccd 2015-10-25 00:54:36 +00:00
Patrick Uiterwijk
b1db3bafd8 Disable persist-tun for openvpn
This should solve the issue where RHEL7 machines that get a network
hiccup need an OpenVPN restart to restore their routes.

The code is broken in the current upstream OpenVPN release, such that
it does tear down some of the routes during a ping-restart (when the
connection is dropped due to network hiccups), but the reconnection
code does not restore the routes.
I am working on an upstream patch to fix this, but in the meantime
disabling persist-tun will make sure that OpenVPN does the entire
initialization upon reconnection, which makes sure that all routes
are created.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-10-21 18:26:32 +00:00
Kevin Fenzi
301a9cea82 Add first cut at a infinote server (config to come) 2015-10-09 19:03:59 +00:00
Ralph Bean
c891127d1a Add CCD files for statscache-web. 2015-10-09 18:17:21 +00:00
Patrick Uiterwijk
9533446335 Add proxy12 on ibiblio05 2015-10-09 17:00:14 +00:00
Kevin Fenzi
4b8b54b795 Add ccd file too 2015-10-06 16:52:44 +00:00
Stephen Smoogen
2322011063 add a batcave ccd 2015-09-28 20:38:41 +00:00
Kevin Fenzi
2873cdd427 Move all puppet_private stuff to ansible private so we can stop using puppet private. 2015-09-25 18:16:23 +00:00
Ralph Bean
824875d592 ccd files for new autocloud prod web nodes. 2015-09-24 19:44:10 +00:00
Kevin Fenzi
bd5bb2d1ed add ccd file for mm-crawler03 2015-09-03 18:55:23 +00:00
Kevin Fenzi
5160b13c2c Rename ccd file correctly this time. 2015-08-31 20:39:22 +00:00
Kevin Fenzi
9442b2d4b7 Initial cut of new darkserver02 instance. 2015-08-31 18:17:16 +00:00
Stephen Smoogen
75c212c169 more removal of ibiblio01 2015-08-19 17:45:50 +00:00
Patrick Uiterwijk
a45f18bfd7 Add mm-frontend02
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-07-28 17:45:29 +00:00
Kevin Fenzi
09448c2d2b Add openvpn file for ibiblio05 2015-07-27 22:44:33 +00:00
Kevin Fenzi
9ce6b3fdf9 Add a pile of bodhi2 production instances. 2015-07-21 18:39:02 +00:00
Patrick Uiterwijk
26e04d0b58 Add ipsilon0* ccd files...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-07-15 08:17:06 +00:00
Kevin Fenzi
2ea34c01d6 Add vpn on koschei01 2015-06-24 17:13:03 +00:00
Kevin Fenzi
db5b67207d First rough cut at a people01. Many bugfixes ahead I am sure. 2015-06-16 19:06:24 +00:00
Kevin Fenzi
120a8183f6 Helps if you put these in the right directory. ;( Oops 2015-05-11 17:40:05 +00:00
Kevin Fenzi
a07b4a796e Add ccd openvpn files for pagure 2015-05-11 17:34:41 +00:00
Kevin Fenzi
e30df424d2 Finish moving backup03->backup01 2015-05-08 20:46:57 +00:00
Kevin Fenzi
b664cccdef Add vpn ccd file for torrent01 2015-05-01 21:07:10 +00:00
Stephen Smoogen
7a0536d0f6 add backup01 files 2015-05-01 20:39:49 +00:00
Kevin Fenzi
81a26fad8d mirrormanager 2 production instances. 2015-04-24 18:53:40 +00:00
Stephen Smoogen
c184c66f73 and we have more nagios 2015-03-23 23:02:59 +00:00
Kevin Fenzi
5a3362eba6 Add ccd file for proxy10 2015-02-18 22:32:56 +00:00
Ricky Elrod
11fefae70a Make dedicatedsolutions01 use its right vpn address
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2015-01-07 23:41:11 +00:00
Ricky Elrod
2e21cc6c3f ccd for mirrorlist-dedicatedsolutions
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2015-01-07 13:02:01 +00:00
Kevin Fenzi
3a91b15c3e We aren't in phx2 anymore toto. 2014-11-14 18:02:15 +00:00
Kevin Fenzi
7efee52e6f Add mirrorlist-host1plus to the mix 2014-11-14 18:00:18 +00:00
Ricky Elrod
b36cf52a4c add ccd file *here* instead
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2014-11-11 22:34:13 +00:00
Praveen Kumar
4b1e5162d7 Update state from installed/removed to present/absent for yum module as per latest documents -> http://docs.ansible.com/yum_module.html 2014-11-05 15:32:11 +00:00
Kevin Fenzi
325d8e6a7e Sync openvpn ccd files from puppet -> ansible 2014-10-09 22:37:14 +00:00
Kevin Fenzi
a3222e0097 Fix typo in filename 2014-10-08 23:25:37 +00:00
Kevin Fenzi
d7693328eb No need for recurse here. 2014-10-08 23:22:53 +00:00
Kevin Fenzi
837ae4ef1e Correct path here 2014-10-08 23:20:28 +00:00
Kevin Fenzi
8b32c6129c Here too 2014-10-08 23:17:45 +00:00
Kevin Fenzi
bf67428a23 Try copy here 2014-10-08 23:15:09 +00:00
Kevin Fenzi
a50758d90e A basic first cut at a bastion role. Going to use on bastion02 2014-10-08 22:37:24 +00:00
Tim Flink
4cad62833a fixing typo in restart notification 2014-09-24 17:35:59 +00:00
Tim Flink
d6195c2c33 changing openvpn restart notifications to work on sysvinit and systemd style machines 2014-09-24 17:32:41 +00:00
Pierre-Yves Chibon
6e0e238f10 OpenVPN server needs the crl.pem file 2014-08-01 18:37:25 +02:00
Pierre-Yves Chibon
54764c5e41 File works 2014-08-01 17:10:13 +02:00
Pierre-Yves Chibon
d26ae5df9f Use copy instead of file 2014-08-01 17:04:34 +02:00
Pierre-Yves Chibon
b818538962 Y'all get quotes 2014-08-01 16:48:16 +02:00
Pierre-Yves Chibon
27913def24 More quotes for the handler names 2014-08-01 16:45:57 +02:00
Pierre-Yves Chibon
8de71b59e3 Tag all the openvpn tasks as 'openvpn' 2014-08-01 16:41:55 +02:00
Pierre-Yves Chibon
8a89bd9fff Fix accessing the mode 2014-08-01 16:34:21 +02:00
Pierre-Yves Chibon
8185a415d2 And we put directly the destination, no location set 2014-08-01 16:30:08 +02:00