]> git.openstreetmap.org Git - chef.git/blobdiff - roles/ironbelly.rb
Fix permissions
[chef.git] / roles / ironbelly.rb
index a3a94fc636041ab2c817341e05787f36f6cc2215..273a74a0ebc9004437e6d11cc6a9ef58e325db22 100644 (file)
@@ -35,11 +35,56 @@ default_attributes(
         }
       }
     }
+  },
+  :rsyncd => {
+    :modules => {
+      :hosts => {
+        :comment => "Host data",
+        :path => "/home/hosts",
+        :read_only => true,
+        :write_only => false,
+        :list => false,
+        :uid => "tomh",
+        :gid => "tomh",
+        :transfer_logging => false,
+        :hosts_allow => [ 
+          "89.16.179.150",                       # shenron
+          "2001:41c8:10:996:21d:7dff:fec3:df70", # shenron
+          "212.159.112.221"                      # grant
+        ]
+      },
+      :logs => {
+        :comment => "Log files",
+        :path => "/store/logs",
+        :read_only => false,
+        :write_only => true,
+        :list => false,
+        :uid => "www-data",
+        :gid => "www-data",
+        :transfer_logging => false,
+        :hosts_allow => [
+          "128.40.168.0/24",      # ucl external
+          "146.179.159.160/27",   # ic internal
+          "193.63.75.96/27",      # ic external
+          "2001:630:12:500::/64", # ic external
+          "127.0.0.0/8",          # localhost
+          "::1"                   # localhost
+        ]
+      }
+    }
   }
 );
 
 run_list(
   "role[ic]",
   "role[gateway]",
+  "role[chef-server]",
+  "role[chef-repository]",
+  "role[web-storage]",
+  "role[supybot]",
+  "role[backup]",
+  "role[stats]",
+  "role[planet]",
+  "recipe[rsyncd]",
   "recipe[openvpn]"
 )