infra issueshttps://git.fsmpi.rwth-aachen.de/groups/infra/-/issues2017-07-26T22:26:54+02:00https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/5disable ip6 tempaddr2017-07-26T22:26:54+02:00Lars Beckersdisable ip6 tempaddrdisable ip6 tempaddr per sysctl (default, all)disable ip6 tempaddr per sysctl (default, all)https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/2hostname configuration2017-07-26T22:33:45+02:00Lars Beckershostname configurationhostname configuration should be set per variable (fqdn on/off)hostname configuration should be set per variable (fqdn on/off)https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/8shell: sudoers2017-07-26T22:59:38+02:00Lars Beckersshell: sudoersadmin group per default configurable; only if ad-auth?
validate using template/copy moduleadmin group per default configurable; only if ad-auth?
validate using template/copy modulehttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/4rsyslog2017-07-26T23:19:18+02:00Lars Beckersrsyslogconfigure by variable (at least on/off), template target hostconfigure by variable (at least on/off), template target hosthttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/3/tmp noexec2017-07-26T23:27:07+02:00Lars Beckers/tmp noexecIt is a known, reported, and accepted, but yet unsolved bug in debconf, that sometimes for some packages, it tries to write and execute some script in /tmp.
Solution: https://serverfault.com/questions/72356/how-useful-is-mounting-tmp-no...It is a known, reported, and accepted, but yet unsolved bug in debconf, that sometimes for some packages, it tries to write and execute some script in /tmp.
Solution: https://serverfault.com/questions/72356/how-useful-is-mounting-tmp-noexec#72357, https://debian-administration.org/article/57/Making_/tmp_non-executablehttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/1apticron: template config2017-07-26T23:40:11+02:00Lars Beckersapticron: template configconfig is currently copied, but you should be able to set the email addresses via variablesconfig is currently copied, but you should be able to set the email addresses via variableshttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/6ca installation2017-07-26T23:59:07+02:00Lars Beckersca installationcurrent rwth chain deployment, custom ca deployment
isn't it a kind of branding? but then, aren't custom repos another form of branding?current rwth chain deployment, custom ca deployment
isn't it a kind of branding? but then, aren't custom repos another form of branding?https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/1rework apt repository configuration2017-07-27T20:56:48+02:00Lars Beckersrework apt repository configurationneeds to be more flexible: backports on/off, non-free/contrib, proposed-updates, general additional repo (one's own)needs to be more flexible: backports on/off, non-free/contrib, proposed-updates, general additional repo (one's own)https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/8debian-updates role2017-08-03T01:00:43+02:00Lars Beckersdebian-updates rolerole that deploys debian-updates to a mailserver as a complement to the apticron role
this implies that the debian-update repo must be available in some formrole that deploys debian-updates to a mailserver as a complement to the apticron role
this implies that the debian-update repo must be available in some formhttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/7additional packages2017-09-21T23:14:56+02:00Lars Beckersadditional packages- git-extras
- bash-completion
- keychain
- quota
- emacs
- lftp
- aptitude
- python-yaml
- python-jinja2
- python-paramiko
- reptyr
- file
- ipmitool
- squashfs-tools
- facter
- dnsutils
- tree
- *-microcode
- ncurses-term- git-extras
- bash-completion
- keychain
- quota
- emacs
- lftp
- aptitude
- python-yaml
- python-jinja2
- python-paramiko
- reptyr
- file
- ipmitool
- squashfs-tools
- facter
- dnsutils
- tree
- *-microcode
- ncurses-termhttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/5nullmailer: admin address2017-09-21T23:16:18+02:00Lars Beckersnullmailer: admin addresshttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/samba/-/issues/1nfs-client2017-09-21T23:35:22+02:00Lars Beckersnfs-clientadditional packages: cifs-utils, smbclient
written for nfs4 with kerberos, but works also for non-kerberosadditional packages: cifs-utils, smbclient
written for nfs4 with kerberos, but works also for non-kerberoshttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/samba/-/issues/2ad-auth2017-09-21T23:40:29+02:00Lars Beckersad-authvalidate sudo reconfigurationvalidate sudo reconfigurationhttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/3cups-client: remove cups-server (if necessary?)2017-09-21T23:46:00+02:00Lars Beckerscups-client: remove cups-server (if necessary?)https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/7baremetal: microcode2017-09-22T00:13:46+02:00Lars Beckersbaremetal: microcodebaremetal shall install microcode packages
(if clients won't be "baremetal", install it in their role, too)baremetal shall install microcode packages
(if clients won't be "baremetal", install it in their role, too)https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/supplemental/-/issues/6baremetal2017-09-22T00:13:51+02:00Lars Beckersbaremetalcurrently very setup specific
semi-dependence on zabbix monitoringcurrently very setup specific
semi-dependence on zabbix monitoringhttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/client/-/issues/2split client role2017-09-26T21:20:04+02:00Lars Beckerssplit client rolesplit client role into resonable parts
resort all the things insidesplit client role into resonable parts
resort all the things insidehttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/client/-/issues/3new packages2017-09-26T21:21:04+02:00Lars Beckersnew packagesgitk, git-svngitk, git-svnhttps://git.fsmpi.rwth-aachen.de/infra/ansible-shared/client/-/issues/1client issues2017-09-26T22:42:09+02:00Lars Beckersclient issuesspecific libreoffice version, because specific is not updated:
- libreoffice5.2-de
- libreoffice5.2-calc
- libreoffice5.2-writer
- libreoffice5.2-dict-de
- libreoffice5.2-dict-en
- libreoffice5.2-dict-es
- libreoffice5.2-dict-fr
- libre...specific libreoffice version, because specific is not updated:
- libreoffice5.2-de
- libreoffice5.2-calc
- libreoffice5.2-writer
- libreoffice5.2-dict-de
- libreoffice5.2-dict-en
- libreoffice5.2-dict-es
- libreoffice5.2-dict-fr
- libreoffice5.2-draw
- libreoffice5.2-impress
- libreoffice5.2-math
present vs absent:
- gv
- mupdf
- php5-cli (absent only)
additional:
- kmymoney
- xournal
- pdfmod
- lyx
- speedcrunch
- pandoc
- libav-tools
- libavcodec-extra
- smplayer
- pulseaudio
- pavucontrol
- dunst
- rar
- unrar
- emacs
- joe
- c2hs
- default-jdk
- root-system
- octave
- libroot-bindings-python5.34
- mysql-client
- libasound2-dev
- libx11-dev
- libxinerama-dev
- libxext-dev
- libxft-dev
- libxrandr-dev
- cmake
- python-pysnmp4
- python-prettytable
- python3-scipy
- python3-pyqt5
- gdb
- clusterssh
- weechat
- x2goclient
- tnef
- remmina
- remmina-plugin-rdp
- remmina-plugin-vnc
- freerdp-x11
- x11vnc
- lm-sensors
- lldpd
the new mozilla way:
- thunderbird
- firefox-esr
- lightning
- xul-ext-quotecolors
- enigmail
- is there a way to default ad block for everyone?
- new name of iceowl-extension?
- new name of iceweasel-l10n-de?
- new name of icedove-l10n-de?
- alternatives: name=x-www-browser path=/usr/bin/firefox
additional, but needs special repo:
- google-chrome-stable
- flashplugin-nonfree
- seafile
additional configuration:
- kdm theme configurable
- correct printer, configurable template
- lldpd configuration and service
- rsyslog config
- default profile for firefox and thunderbird
- seperate repo
- client administrators
- rdp
does other form of kde unrolling all wished for packages and no un-wished for packages?
is pyxtrlock broken?https://git.fsmpi.rwth-aachen.de/infra/ansible-shared/common/-/issues/9timezone configuration2018-03-21T00:33:20+01:00Lars Beckerstimezone configurationCurrently, timezone is configured via modifying `/etc/timezone` and calling `dpkg-reconfigure tzdata`. This is also the documented how-to according to Debian's own wiki. However `dpkg` then reconfigures to the previously set timezone.Currently, timezone is configured via modifying `/etc/timezone` and calling `dpkg-reconfigure tzdata`. This is also the documented how-to according to Debian's own wiki. However `dpkg` then reconfigures to the previously set timezone.