]> git.openstreetmap.org Git - chef.git/blobdiff - roles/backup.rb
nftables: allow 169.254.169.0/24 and set log level to notice
[chef.git] / roles / backup.rb
index 5b58145d0c2ed5eb03bf20b6ac8aefbb2723acb0..00c73fd820301427e1b7742d74656e6ff491989e 100644 (file)
@@ -2,11 +2,6 @@ name "backup"
 description "Role applied to backup.openstreetmap.org"
 
 default_attributes(
 description "Role applied to backup.openstreetmap.org"
 
 default_attributes(
-  :accounts => {
-    :users => {
-      :osmbackup => { :status => :role }
-    }
-  },
   :rsyncd => {
     :modules => {
       :backup => {
   :rsyncd => {
     :modules => {
       :backup => {
@@ -20,17 +15,48 @@ default_attributes(
         :transfer_logging => false,
         :hosts_allow => [
           "193.60.236.0/24",                     # ucl external
         :transfer_logging => false,
         :hosts_allow => [
           "193.60.236.0/24",                     # ucl external
-          "146.179.159.160/27",                  # ic internal
-          "193.63.75.96/27",                     # ic external
-          "2001:630:12:500::/64",                # ic external
+          "10.0.48.0/20",                        # amsterdam internal
+          "184.104.179.128/27",                  # amsterdam external
+          "2001:470:1:fa1::/64",                 # amsterdam external
+          "10.0.64.0/20",                        # dublin internal
+          "184.104.226.96/27",                   # dublin external
+          "2001:470:1:b3b::/64",                 # dublin external
           "10.0.32.0/20",                        # bytemark internal
           "89.16.162.16/28",                     # bytemark external
           "2001:41c9:2:d6::/64",                 # bytemark external
           "212.110.172.32",                      # shenron
           "2001:41c9:1:400::32",                 # shenron
           "10.0.32.0/20",                        # bytemark internal
           "89.16.162.16/28",                     # bytemark external
           "2001:41c9:2:d6::/64",                 # bytemark external
           "212.110.172.32",                      # shenron
           "2001:41c9:1:400::32",                 # shenron
+          "140.211.167.99",                      # osuosl
+          "140.211.167.100",                     # osuosl
+          "2605:bc80:3010:700::8cd3:a763",       # osuosl
+          "2605:bc80:3010:700::8cd3:a764",       # osuosl
           "127.0.0.0/8",                         # localhost
           "::1"                                  # localhost
         ]
           "127.0.0.0/8",                         # localhost
           "::1"                                  # localhost
         ]
+      },
+      :logs => {
+        :comment => "Log files",
+        :path => "/store/logs",
+        :read_only => false,
+        :write_only => true,
+        :list => false,
+        :uid => "osmbackup",
+        :gid => "osmbackup",
+        :transfer_logging => false,
+        :hosts_allow => [
+          "193.60.236.0/24",          # ucl external
+          "10.0.48.0/20",             # amsterdam internal
+          "184.104.179.128/27",       # amsterdam external
+          "2001:470:1:fa1::/64",      # amsterdam external
+          "10.0.64.0/20",             # dublin internal
+          "184.104.226.96/27",        # dublin external
+          "2001:470:1:b3b::/64",      # dublin external
+          "10.0.32.0/20",             # bytemark internal
+          "89.16.162.16/28",          # bytemark external
+          "2001:41c9:2:d6::/64",      # bytemark external
+          "127.0.0.0/8",              # localhost
+          "::1"                       # localhost
+        ]
       }
     }
   }
       }
     }
   }