Hi widehat Admins
You might know that we lost the dark fiber to widehat.o.o when the SUSE
office got the new 1Gb line.
So there was a small problem with the push of content from pontifex
(aka stage.o.o) and the OBS to the machine, as they used the line that
is not connected any longer.
I changed the configuration on widehat now to:
* use 62.146.92.203 as new "internal" IP
* limit external access to rsync and http only
* ssh and nrpe only reachable from NUE and PRG offices
Important changes:
* I reworked the rsync modules a bit (unifying user/group, listen,
compress and logging options) and splitted between:
** 62.146.92.202 => external modules
** 62.146.92.203 => internal modules (push)
* ifcfg-eth0 contains now also the public IPv6 address
2a01:138:a004:0:230:48ff:fe80:9a32/64 - I hope this will avoid the
problem of "xinetd not listening on IPv6" in the future. I added a
default route entry via fe80::2d0:3ff:fed0:8400 (as this is pushed
atm) - but did not test the setup yet. => waiting for reboot
* /etc/sysctl.d/ contains tuning.conf and widehat.conf containing some
security and tuning options for the kernel
Please check the changes and ping me back if this should go into some
GIT or similar repository, as it seems to me like this got lost somehow.
with kind regards,
Lars
--
To unsubscribe, e-mail: heroes+unsubscribe(a)opensuse.org
To contact the owner, e-mail: heroes+owner(a)opensuse.org