Commit graph

86 commits

Author SHA1 Message Date
Pierre-Yves Chibon
1c183896c8 Install the openvpn client package with dnf on F22+ 2015-11-17 15:29:29 +01:00
Pierre-Yves Chibon
a7e6225b8f Fix indentation 2015-11-17 15:27:42 +01:00
Pierre-Yves Chibon
27910ddaef Install the package with dnf on F22+ 2015-11-17 15:27:05 +01:00
Patrick Uiterwijk
032376de7e Tag the fix-routes.sh play 2015-11-04 23:11:52 +00:00
Patrick Uiterwijk
fe6f551049 Move fix-routes.sh to openvpn base and run it on restart
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-11-04 23:09:43 +00:00
Patrick Uiterwijk
8c9fcd56d1 Add mirrorlist-ibiblio02 vpn ccd 2015-10-25 00:54:36 +00:00
Patrick Uiterwijk
b2b07e8bcd Running the script doesnt work yet. But we still want the script.
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-10-23 03:11:02 +00:00
Patrick Uiterwijk
50511a65e7 Make fix-routes not terminate with status 2 if it fixed it
This will make openvpn think something went wrong and terminate the connection.
I did this to make it easily visible when running with ansible, but in this case
it messes things up.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-10-23 02:41:01 +00:00
Patrick Uiterwijk
d5bdc65887 Add script to OpenVPN for VPN route fixing
This will make sure that always after a start/restart the
VPN routes are created

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-10-23 02:15:43 +00:00
Patrick Uiterwijk
b1db3bafd8 Disable persist-tun for openvpn
This should solve the issue where RHEL7 machines that get a network
hiccup need an OpenVPN restart to restore their routes.

The code is broken in the current upstream OpenVPN release, such that
it does tear down some of the routes during a ping-restart (when the
connection is dropped due to network hiccups), but the reconnection
code does not restore the routes.
I am working on an upstream patch to fix this, but in the meantime
disabling persist-tun will make sure that OpenVPN does the entire
initialization upon reconnection, which makes sure that all routes
are created.

Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-10-21 18:26:32 +00:00
Kevin Fenzi
301a9cea82 Add first cut at a infinote server (config to come) 2015-10-09 19:03:59 +00:00
Ralph Bean
c891127d1a Add CCD files for statscache-web. 2015-10-09 18:17:21 +00:00
Patrick Uiterwijk
9533446335 Add proxy12 on ibiblio05 2015-10-09 17:00:14 +00:00
Kevin Fenzi
4b8b54b795 Add ccd file too 2015-10-06 16:52:44 +00:00
Stephen Smoogen
2322011063 add a batcave ccd 2015-09-28 20:38:41 +00:00
Kevin Fenzi
2873cdd427 Move all puppet_private stuff to ansible private so we can stop using puppet private. 2015-09-25 18:16:23 +00:00
Ralph Bean
824875d592 ccd files for new autocloud prod web nodes. 2015-09-24 19:44:10 +00:00
Kevin Fenzi
bd5bb2d1ed add ccd file for mm-crawler03 2015-09-03 18:55:23 +00:00
Kevin Fenzi
5160b13c2c Rename ccd file correctly this time. 2015-08-31 20:39:22 +00:00
Kevin Fenzi
9442b2d4b7 Initial cut of new darkserver02 instance. 2015-08-31 18:17:16 +00:00
Stephen Smoogen
75c212c169 more removal of ibiblio01 2015-08-19 17:45:50 +00:00
Patrick Uiterwijk
a45f18bfd7 Add mm-frontend02
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-07-28 17:45:29 +00:00
Kevin Fenzi
09448c2d2b Add openvpn file for ibiblio05 2015-07-27 22:44:33 +00:00
Kevin Fenzi
9ce6b3fdf9 Add a pile of bodhi2 production instances. 2015-07-21 18:39:02 +00:00
Patrick Uiterwijk
26e04d0b58 Add ipsilon0* ccd files...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
2015-07-15 08:17:06 +00:00
Kevin Fenzi
2ea34c01d6 Add vpn on koschei01 2015-06-24 17:13:03 +00:00
Kevin Fenzi
db5b67207d First rough cut at a people01. Many bugfixes ahead I am sure. 2015-06-16 19:06:24 +00:00
Kevin Fenzi
275f4b5203 Change all instances of ansible_distribution_major_version to filter to int for comparisons. 2015-05-27 22:27:39 +00:00
Kevin Fenzi
120a8183f6 Helps if you put these in the right directory. ;( Oops 2015-05-11 17:40:05 +00:00
Kevin Fenzi
a07b4a796e Add ccd openvpn files for pagure 2015-05-11 17:34:41 +00:00
Kevin Fenzi
e30df424d2 Finish moving backup03->backup01 2015-05-08 20:46:57 +00:00
Kevin Fenzi
b664cccdef Add vpn ccd file for torrent01 2015-05-01 21:07:10 +00:00
Stephen Smoogen
7a0536d0f6 add backup01 files 2015-05-01 20:39:49 +00:00
Kevin Fenzi
81a26fad8d mirrormanager 2 production instances. 2015-04-24 18:53:40 +00:00
Kevin Fenzi
05e35e953d This is now fixed in a systemd update in rhel7.1 so drop the workaround 2015-04-22 14:40:57 +00:00
Kevin Fenzi
fb1c3a6eeb Work around rhel 7.1 systemd template bug: https://bugzilla.redhat.com/show_bug.cgi?id=1206007 2015-03-26 13:41:48 +00:00
Stephen Smoogen
c184c66f73 and we have more nagios 2015-03-23 23:02:59 +00:00
Kevin Fenzi
5a3362eba6 Add ccd file for proxy10 2015-02-18 22:32:56 +00:00
11fefae70a Make dedicatedsolutions01 use its right vpn address
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2015-01-07 23:41:11 +00:00
2e21cc6c3f ccd for mirrorlist-dedicatedsolutions
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2015-01-07 13:02:01 +00:00
Kevin Fenzi
10b316d114 Does this need quotes? 2014-12-15 19:40:37 +00:00
Kevin Fenzi
1cd3cb534b Try this one. 2014-12-15 19:39:30 +00:00
Kevin Fenzi
aabdcd15d6 Split this out to see if we can debug it some. 2014-12-15 19:37:22 +00:00
Kevin Fenzi
3a91b15c3e We aren't in phx2 anymore toto. 2014-11-14 18:02:15 +00:00
Kevin Fenzi
7efee52e6f Add mirrorlist-host1plus to the mix 2014-11-14 18:00:18 +00:00
b36cf52a4c add ccd file *here* instead
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org>
2014-11-11 22:34:13 +00:00
Praveen Kumar
4b1e5162d7 Update state from installed/removed to present/absent for yum module as per latest documents -> http://docs.ansible.com/yum_module.html 2014-11-05 15:32:11 +00:00
Kevin Fenzi
325d8e6a7e Sync openvpn ccd files from puppet -> ansible 2014-10-09 22:37:14 +00:00
Kevin Fenzi
a3222e0097 Fix typo in filename 2014-10-08 23:25:37 +00:00
Kevin Fenzi
d7693328eb No need for recurse here. 2014-10-08 23:22:53 +00:00