diff --git a/merge.sh b/merge.sh index dcd158b..0ffba61 100644 --- a/merge.sh +++ b/merge.sh @@ -1,9 +1,18 @@ -git checkout dev -git merge master -git push +read -p "Commit message? " cm; +git fetch --all; -git checkout master -git merge --squash dev -git commit -git push -git checkout dev +#copy dev to history to ensure we don't lose changes if something goes wrong +git checkout history; +git reset --hard dev; +git push --force; + +#merge to master +git checkout -B master origin/master; +git merge --squash dev; +git commit -am "$cm"; +git push; + +#clean dev +git checkout dev; +git reset --hard master; +git push --force; diff --git a/pillars/roles/backup/init.sls b/pillars/roles/backup/init.sls old mode 100755 new mode 100644 diff --git a/pillars/roles/backup/radarr.sls b/pillars/roles/backup/radarr.sls old mode 100755 new mode 100644 diff --git a/pillars/roles/ca/init.sls b/pillars/roles/ca/init.sls new file mode 100644 index 0000000..3584c6d --- /dev/null +++ b/pillars/roles/ca/init.sls @@ -0,0 +1,21 @@ +{% set states = salt['cp.list_states'](saltenv) %} +include: + - roles.ca.none +{%- if grains['roles'] is defined -%} + {%- if grains['roles'] is not none -%} + {%- if 'ca' in grains['roles'] -%} + {%- for state in states %} + {%- if state.startswith("pillars.roles.ca.") -%} + {%- set role = state.split('.')[3] %} + - roles.ca.{{ role }} + {%- endif -%} + {%- endfor -%} + {%- else -%} + {%- for role in grains['roles'] %} + {%- if 'pillars.roles.ca.'+role in states %} + - roles.ca.{{ role }} + {%- endif -%} + {%- endfor -%} + {%- endif -%} + {%- endif -%} +{%- endif -%} diff --git a/pillars/roles/ca/none.sls b/pillars/roles/ca/none.sls new file mode 100644 index 0000000..e69de29 diff --git a/pillars/roles/ca/vpnserver.sls b/pillars/roles/ca/vpnserver.sls new file mode 100644 index 0000000..d608dfb --- /dev/null +++ b/pillars/roles/ca/vpnserver.sls @@ -0,0 +1,13 @@ +ca: + vpn.actcur.com: + type: server + priv-locations: + /etc/openvpn/server/vpn.actcur.com.key: + user: root + group: root + mode: 400 + cert-locations: + /etc/openvpn/server/vpn.actcur.com.crt: + user: root + group: root + mode: 400 diff --git a/pillars/roles/firewalld/nginx-proxy.sls b/pillars/roles/firewalld/nginx-proxy.sls old mode 100755 new mode 100644 diff --git a/pillars/roles/init.sls b/pillars/roles/init.sls index ebe1dd8..b5da08b 100644 --- a/pillars/roles/init.sls +++ b/pillars/roles/init.sls @@ -6,3 +6,4 @@ include: - roles.mount - roles.git - roles.backup + - roles.ca diff --git a/pillars/roles/mount/saltmaster.sls b/pillars/roles/mount/saltmaster.sls index bb83aa5..7497990 100644 --- a/pillars/roles/mount/saltmaster.sls +++ b/pillars/roles/mount/saltmaster.sls @@ -8,3 +8,11 @@ mount: host: host.actcur.com directory: /mnt/butter/backups/configurations user: backups + /secure/ca/issued: + host: ca.actcur.com + directory: /etc/easy-rsa/pki/issued + user: ca + /secure/ca/private: + host: ca.actcur.com + directory: /etc/easy-rsa/pki/private + user: ca diff --git a/pillars/servers/env/server/archca.sls b/pillars/servers/env/server/archca.sls new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archca.sls @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archgitlab.sls~HEAD b/pillars/servers/env/server/archgitlab.sls~HEAD new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archgitlab.sls~HEAD @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archgitlab.sls~HEAD_0 b/pillars/servers/env/server/archgitlab.sls~HEAD_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archgitlab.sls~HEAD_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archgitlab.sls~history b/pillars/servers/env/server/archgitlab.sls~history new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archgitlab.sls~history @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archgitlab.sls~history_0 b/pillars/servers/env/server/archgitlab.sls~history_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archgitlab.sls~history_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archhost1.sls~HEAD b/pillars/servers/env/server/archhost1.sls~HEAD new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archhost1.sls~HEAD @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archhost1.sls~HEAD_0 b/pillars/servers/env/server/archhost1.sls~HEAD_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archhost1.sls~HEAD_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archhost1.sls~history b/pillars/servers/env/server/archhost1.sls~history new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archhost1.sls~history @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archhost1.sls~history_0 b/pillars/servers/env/server/archhost1.sls~history_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archhost1.sls~history_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/archvpn.sls b/pillars/servers/env/server/archvpn.sls new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/archvpn.sls @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/debiangitlab.sls~HEAD b/pillars/servers/env/server/debiangitlab.sls~HEAD new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/debiangitlab.sls~HEAD @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/debiangitlab.sls~HEAD_0 b/pillars/servers/env/server/debiangitlab.sls~HEAD_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/debiangitlab.sls~HEAD_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/debiangitlab.sls~history b/pillars/servers/env/server/debiangitlab.sls~history new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/debiangitlab.sls~history @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/env/server/debiangitlab.sls~history_0 b/pillars/servers/env/server/debiangitlab.sls~history_0 new file mode 100644 index 0000000..2fdef9a --- /dev/null +++ b/pillars/servers/env/server/debiangitlab.sls~history_0 @@ -0,0 +1 @@ +env: prod diff --git a/pillars/servers/maintainer/server/archca.sls b/pillars/servers/maintainer/server/archca.sls new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archca.sls @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archgitlab.sls~HEAD b/pillars/servers/maintainer/server/archgitlab.sls~HEAD new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archgitlab.sls~HEAD @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archgitlab.sls~HEAD_0 b/pillars/servers/maintainer/server/archgitlab.sls~HEAD_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archgitlab.sls~HEAD_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archgitlab.sls~history b/pillars/servers/maintainer/server/archgitlab.sls~history new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archgitlab.sls~history @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archgitlab.sls~history_0 b/pillars/servers/maintainer/server/archgitlab.sls~history_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archgitlab.sls~history_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archhost1.sls~HEAD b/pillars/servers/maintainer/server/archhost1.sls~HEAD new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archhost1.sls~HEAD @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archhost1.sls~HEAD_0 b/pillars/servers/maintainer/server/archhost1.sls~HEAD_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archhost1.sls~HEAD_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archhost1.sls~history b/pillars/servers/maintainer/server/archhost1.sls~history new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archhost1.sls~history @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archhost1.sls~history_0 b/pillars/servers/maintainer/server/archhost1.sls~history_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archhost1.sls~history_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/archvpn.sls b/pillars/servers/maintainer/server/archvpn.sls new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/archvpn.sls @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/debiangitlab.sls~HEAD b/pillars/servers/maintainer/server/debiangitlab.sls~HEAD new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/debiangitlab.sls~HEAD @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/debiangitlab.sls~HEAD_0 b/pillars/servers/maintainer/server/debiangitlab.sls~HEAD_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/debiangitlab.sls~HEAD_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/debiangitlab.sls~history b/pillars/servers/maintainer/server/debiangitlab.sls~history new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/debiangitlab.sls~history @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/maintainer/server/debiangitlab.sls~history_0 b/pillars/servers/maintainer/server/debiangitlab.sls~history_0 new file mode 100644 index 0000000..c0b416d --- /dev/null +++ b/pillars/servers/maintainer/server/debiangitlab.sls~history_0 @@ -0,0 +1,3 @@ +maintainer: + - masaufuku + diff --git a/pillars/servers/roles/server/archca.sls b/pillars/servers/roles/server/archca.sls new file mode 100644 index 0000000..22ce80c --- /dev/null +++ b/pillars/servers/roles/server/archca.sls @@ -0,0 +1,6 @@ +grains: + roles: + - server + - ssh + - saltminion + - ca diff --git a/pillars/servers/roles/server/archvpn.sls b/pillars/servers/roles/server/archvpn.sls new file mode 100644 index 0000000..fad59ee --- /dev/null +++ b/pillars/servers/roles/server/archvpn.sls @@ -0,0 +1,7 @@ +grains: + roles: + - server + - ssh + - saltminion + - vpnserver + - ca-cert diff --git a/states/roles/build/ca/init.sls b/states/roles/build/ca/init.sls new file mode 100644 index 0000000..c6339a6 --- /dev/null +++ b/states/roles/build/ca/init.sls @@ -0,0 +1,15 @@ +ca-easy-rsa-build: + pkg.installed: + - name: easy-rsa + +#temporary - easy-rsa package is broken and uses wrong working direcotry +easy-rsa-vars-build: + file.managed: + - name: "/etc/easy-rsa/vars" + - source: salt://roles/maintain/ca/vars + +#--vars=./vars is temporary until package is fixed +gen-ca-key: + cmd.run: + - name: "easyrsa --vars=./vars init-pki;easyrsa --batch --vars=./vars build-ca nopass batch" + - cwd: "/etc/easy-rsa" diff --git a/states/roles/maintain/ca-cert/init.sls b/states/roles/maintain/ca-cert/init.sls new file mode 100644 index 0000000..eb1cfdd --- /dev/null +++ b/states/roles/maintain/ca-cert/init.sls @@ -0,0 +1,29 @@ +{##ensure that ca pillar exists##} +{%- if pillar['ca'] is defined -%} + {##copy certs and private keys for machine##} + {%- for name in pillar['ca'] %} + {%- if pillar['ca'][name]['priv-locations'] is defined -%} + {%- for plocation in pillar['ca'][name]['priv-locations'] %} +priv_location_{{plocation}}: + file.managed: + - name: {{plocation}} + - source: salt://secure/ca/private/{{name}}.key + - user: {{pillar['ca'][name]['priv-locations'][plocation]['user']}} + - group: {{pillar['ca'][name]['priv-locations'][plocation]['group']}} + - mode: {{pillar['ca'][name]['priv-locations'][plocation]['mode']}} + {%- endfor %} + {%- endif %} + + {%- if pillar['ca'][name]['cert-locations'] is defined -%} + {%- for clocation in pillar['ca'][name]['cert-locations'] %} +cert_location{{clocation}}: + file.managed: + - name: {{clocation}} + - source: salt://secure/ca/issued/{{name}}.crt + - user: {{pillar['ca'][name]['cert-locations'][clocation]['user']}} + - group: {{pillar['ca'][name]['cert-locations'][clocation]['group']}} + - mode: {{pillar['ca'][name]['cert-locations'][clocation]['mode']}} + {%- endfor %} + {%- endif %} + {%- endfor %} +{%- endif %} diff --git a/states/roles/maintain/ca/init.sls b/states/roles/maintain/ca/init.sls new file mode 100644 index 0000000..cb2e0c3 --- /dev/null +++ b/states/roles/maintain/ca/init.sls @@ -0,0 +1,56 @@ +ca-easy-rsa-maint: + pkg.installed: + - name: easy-rsa + +#temporary - easy-rsa package is broken and uses wrong working direcotry +easy-rsa-vars-maint: + file.managed: + - name: "/etc/easy-rsa/vars" + - source: salt://roles/maintain/ca/vars + +#initialize ca if necessary +#--vars=./vars is temporary until package is fixed +gen-ca-key: + cmd.run: + - name: "easyrsa --vars=./vars init-pki;easyrsa --batch --vars=./vars build-ca nopass batch" + - cwd: "/etc/easy-rsa" + - onlyif: 'test ! -e /etc/easy-rsa/pki/ca.crt' + +#generate keys if needed +#--vars=./vars is temporary until package is fixed +{%- if pillar['ca'] is defined -%} +{%- for name in pillar['ca'] %} +gen-{{name}}-cert: + cmd.run: + - name: "easyrsa --batch --vars=./vars gen-req {{name}} nopass;easyrsa --batch --vars=./vars sign-req {{pillar['ca'][name]['type']}} {{name}};" + - cwd: "/etc/easy-rsa" + - onlyif: 'test ! -e /etc/easy-rsa/pki/reqs/{{name}}.req' +#set ownership to root:ca and mod to 640 +{{name}}-cert-perms: + file.managed: + - name: /etc/easy-rsa/pki/issued/{{name}}.crt + - group: ca + - mode: 640 +{{name}}-key-perms: + file.managed: + - name: /etc/easy-rsa/pki/private/{{name}}.key + - group: ca + - mode: 640 +{%- endfor %} +{%- endif %} +#set directory perms +pki-perms: + file.directory: + - name: /etc/easy-rsa/pki/ + - group: ca + - mode: 750 +issued-perms: + file.directory: + - name: /etc/easy-rsa/pki/issued/ + - group: ca + - mode: 750 +private-perms: + file.directory: + - name: /etc/easy-rsa/pki/private + - group: ca + - mode: 750 diff --git a/states/roles/maintain/ca/vars b/states/roles/maintain/ca/vars new file mode 100644 index 0000000..778210b --- /dev/null +++ b/states/roles/maintain/ca/vars @@ -0,0 +1,198 @@ +# Easy-RSA 3 parameter settings + +# NOTE: If you installed Easy-RSA from your distro's package manager, don't edit +# this file in place -- instead, you should copy the entire easy-rsa directory +# to another location so future upgrades don't wipe out your changes. + +# HOW TO USE THIS FILE +# +# vars.example contains built-in examples to Easy-RSA settings. You MUST name +# this file 'vars' if you want it to be used as a configuration file. If you do +# not, it WILL NOT be automatically read when you call easyrsa commands. +# +# It is not necessary to use this config file unless you wish to change +# operational defaults. These defaults should be fine for many uses without the +# need to copy and edit the 'vars' file. +# +# All of the editable settings are shown commented and start with the command +# 'set_var' -- this means any set_var command that is uncommented has been +# modified by the user. If you're happy with a default, there is no need to +# define the value to its default. + +# NOTES FOR WINDOWS USERS +# +# Paths for Windows *MUST* use forward slashes, or optionally double-esscaped +# backslashes (single forward slashes are recommended.) This means your path to +# the openssl binary might look like this: +# "C:/Program Files/OpenSSL-Win32/bin/openssl.exe" + +# A little housekeeping: DON'T EDIT THIS SECTION +# +# Easy-RSA 3.x doesn't source into the environment directly. +# Complain if a user tries to do this: +if [ -z "$EASYRSA_CALLER" ]; then + echo "You appear to be sourcing an Easy-RSA 'vars' file." >&2 + echo "This is no longer necessary and is disallowed. See the section called" >&2 + echo "'How to use this file' near the top comments for more details." >&2 + return 1 +fi + +# DO YOUR EDITS BELOW THIS POINT + +# This variable should point to the top level of the easy-rsa tree. By default, +# this is taken to be the directory you are currently in. + +set_var EASYRSA "$PWD" + +# If your OpenSSL command is not in the system PATH, you will need to define the +# path to it here. Normally this means a full path to the executable, otherwise +# you could have left it undefined here and the shown default would be used. +# +# Windows users, remember to use paths with forward-slashes (or escaped +# back-slashes.) Windows users should declare the full path to the openssl +# binary here if it is not in their system PATH. + +#set_var EASYRSA_OPENSSL "openssl" +# +# This sample is in Windows syntax -- edit it for your path if not using PATH: +#set_var EASYRSA_OPENSSL "C:/Program Files/OpenSSL-Win32/bin/openssl.exe" + +# Edit this variable to point to your soon-to-be-created key directory. +# +# WARNING: init-pki will do a rm -rf on this directory so make sure you define +# it correctly! (Interactive mode will prompt before acting.) + +#set_var EASYRSA_PKI "$EASYRSA/pki" + +# Define X509 DN mode. +# This is used to adjust what elements are included in the Subject field as the DN +# (this is the "Distinguished Name.") +# Note that in cn_only mode the Organizational fields further below aren't used. +# +# Choices are: +# cn_only - use just a CN value +# org - use the "traditional" Country/Province/City/Org/OU/email/CN format + +#set_var EASYRSA_DN "cn_only" + +# Organizational fields (used with 'org' mode and ignored in 'cn_only' mode.) +# These are the default values for fields which will be placed in the +# certificate. Don't leave any of these fields blank, although interactively +# you may omit any specific field by typing the "." symbol (not valid for +# email.) + +#set_var EASYRSA_REQ_COUNTRY "US" +#set_var EASYRSA_REQ_PROVINCE "California" +#set_var EASYRSA_REQ_CITY "San Francisco" +#set_var EASYRSA_REQ_ORG "Copyleft Certificate Co" +#set_var EASYRSA_REQ_EMAIL "me@example.net" +#set_var EASYRSA_REQ_OU "My Organizational Unit" + +# Choose a size in bits for your keypairs. The recommended value is 2048. Using +# 2048-bit keys is considered more than sufficient for many years into the +# future. Larger keysizes will slow down TLS negotiation and make key/DH param +# generation take much longer. Values up to 4096 should be accepted by most +# software. Only used when the crypto alg is rsa (see below.) + +#set_var EASYRSA_KEY_SIZE 2048 + +# The default crypto mode is rsa; ec can enable elliptic curve support. +# Note that not all software supports ECC, so use care when enabling it. +# Choices for crypto alg are: (each in lower-case) +# * rsa +# * ec + +#set_var EASYRSA_ALGO rsa + +# Define the named curve, used in ec mode only: + +#set_var EASYRSA_CURVE secp384r1 + +# In how many days should the root CA key expire? + +#set_var EASYRSA_CA_EXPIRE 3650 + +# In how many days should certificates expire? + +#set_var EASYRSA_CERT_EXPIRE 3650 + +# How many days until the next CRL publish date? Note that the CRL can still be +# parsed after this timeframe passes. It is only used for an expected next +# publication date. + +#set_var EASYRSA_CRL_DAYS 180 + +# Support deprecated "Netscape" extensions? (choices "yes" or "no".) The default +# is "no" to discourage use of deprecated extensions. If you require this +# feature to use with --ns-cert-type, set this to "yes" here. This support +# should be replaced with the more modern --remote-cert-tls feature. If you do +# not use --ns-cert-type in your configs, it is safe (and recommended) to leave +# this defined to "no". When set to "yes", server-signed certs get the +# nsCertType=server attribute, and also get any NS_COMMENT defined below in the +# nsComment field. + +#set_var EASYRSA_NS_SUPPORT "no" + +# When NS_SUPPORT is set to "yes", this field is added as the nsComment field. +# Set this blank to omit it. With NS_SUPPORT set to "no" this field is ignored. + +#set_var EASYRSA_NS_COMMENT "Easy-RSA Generated Certificate" + +# A temp file used to stage cert extensions during signing. The default should +# be fine for most users; however, some users might want an alternative under a +# RAM-based FS, such as /dev/shm or /tmp on some systems. + +#set_var EASYRSA_TEMP_FILE "$EASYRSA_PKI/extensions.temp" + +# !! +# NOTE: ADVANCED OPTIONS BELOW THIS POINT +# PLAY WITH THEM AT YOUR OWN RISK +# !! + +# Broken shell command aliases: If you have a largely broken shell that is +# missing any of these POSIX-required commands used by Easy-RSA, you will need +# to define an alias to the proper path for the command. The symptom will be +# some form of a 'command not found' error from your shell. This means your +# shell is BROKEN, but you can hack around it here if you really need. These +# shown values are not defaults: it is up to you to know what you're doing if +# you touch these. +# +#alias awk="/alt/bin/awk" +#alias cat="/alt/bin/cat" + +# X509 extensions directory: +# If you want to customize the X509 extensions used, set the directory to look +# for extensions here. Each cert type you sign must have a matching filename, +# and an optional file named 'COMMON' is included first when present. Note that +# when undefined here, default behaviour is to look in $EASYRSA_PKI first, then +# fallback to $EASYRSA for the 'x509-types' dir. You may override this +# detection with an explicit dir here. +# +#set_var EASYRSA_EXT_DIR "$EASYRSA/x509-types" + +# OpenSSL config file: +# If you need to use a specific openssl config file, you can reference it here. +# Normally this file is auto-detected from a file named openssl-1.0.cnf from the +# EASYRSA_PKI or EASYRSA dir (in that order.) NOTE that this file is Easy-RSA +# specific and you cannot just use a standard config file, so this is an +# advanced feature. + +#set_var EASYRSA_SSL_CONF "$EASYRSA/openssl-1.0.cnf" + +# Default CN: +# This is best left alone. Interactively you will set this manually, and BATCH +# callers are expected to set this themselves. + +#set_var EASYRSA_REQ_CN "ChangeMe" + +# Cryptographic digest to use. +# Do not change this default unless you understand the security implications. +# Valid choices include: md5, sha1, sha256, sha224, sha384, sha512 + +#set_var EASYRSA_DIGEST "sha256" + +# Batch mode. Leave this disabled unless you intend to call Easy-RSA explicitly +# in batch mode without any user input, confirmation on dangerous operations, +# or most output. Setting this to any non-blank string enables batch mode. + +#set_var EASYRSA_BATCH "" diff --git a/states/roles/maintain/gitlab/conf_files/database.yml b/states/roles/maintain/gitlab/conf_files/database.yml index c5b2214..6633c0d 100644 --- a/states/roles/maintain/gitlab/conf_files/database.yml +++ b/states/roles/maintain/gitlab/conf_files/database.yml @@ -9,7 +9,7 @@ production: database: gitlab pool: 10 username: gitlab - password: "{%- include 'secure/gitlab_db_password.txt' -%}" + password: "{%- include 'secure/passwords/gitlab_db_password.txt' -%}" host: sql.actcur.com # socket: /tmp/mysql.sock diff --git a/states/roles/maintain/gitlab/conf_files/smtp_settings.rb b/states/roles/maintain/gitlab/conf_files/smtp_settings.rb index 1f28a51..ebc93e9 100644 --- a/states/roles/maintain/gitlab/conf_files/smtp_settings.rb +++ b/states/roles/maintain/gitlab/conf_files/smtp_settings.rb @@ -16,7 +16,7 @@ if Rails.env.production? address: "smtp.zoho.com", port: 587, user_name: "notifications@actcur.com", - password: "{%- include 'secure/gitlab_smtp_password.txt' -%}", + password: "{%- include 'secure/passwords/gitlab_smtp_password.txt' -%}", domain: "smtp.zoho.com", enable_starttls_auto: true, } diff --git a/states/roles/maintain/gitlab/init.sls b/states/roles/maintain/gitlab/init.sls old mode 100755 new mode 100644 diff --git a/states/roles/maintain/gitlabarch/conf_files/config.yml b/states/roles/maintain/gitlabarch/conf_files/config.yml new file mode 100644 index 0000000..0c802a8 --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/config.yml @@ -0,0 +1,73 @@ +# +# If you change this file in a Merge Request, please also create +# a Merge Request on https://gitlab.com/gitlab-org/omnibus-gitlab/merge_requests +# + +# GitLab user. git by default +user: gitlab + +# URL to GitLab instance, used for API calls. Default: http://localhost:8080. +# For relative URL support read http://doc.gitlab.com/ce/install/relative_url.html +# You only have to change the default if you have configured Unicorn +# to listen on a custom port, or if you have configured Unicorn to +# only listen on a Unix domain socket. For Unix domain sockets use +# "http+unix://", e.g. +# "http+unix://%2Fpath%2Fto%2Fsocket" +gitlab_url: "http://localhost:8080" + +# See installation.md#using-https for additional HTTPS configuration details. +http_settings: +# read_timeout: 300 +# user: someone +# password: somepass +# ca_file: /etc/ssl/cert.pem +# ca_path: /etc/pki/tls/certs + self_signed_cert: false + +# File used as authorized_keys for gitlab user +auth_file: "/var/lib/gitlab/.ssh/authorized_keys" + +# File that contains the secret key for verifying access to GitLab. +# Default is .gitlab_shell_secret in the gitlab-shell directory. +# secret_file: "/var/lib/gitlab/gitlab-shell/.gitlab_shell_secret" + +# Parent directory for global custom hook directories (pre-receive.d, update.d, post-receive.d) +# Default is hooks in the gitlab-shell directory. +# custom_hooks_dir: "/var/lib/gitlab/gitlab-shell/hooks" + +# Redis settings used for pushing commit notices to gitlab +redis: + bin: /usr/bin/redis-cli + host: 127.0.0.1 + port: 6379 + # pass: redispass # Allows you to specify the password for Redis + database: 5 + socket: /run/redis/redis.sock # Comment out this line if you want to use TCP or Sentinel + namespace: resque:gitlab + # sentinels: + # - + # host: 127.0.0.1 + # port: 26380 + # - + # host: 127.0.0.1 + # port: 26381 + + +# Log file. +# Default is gitlab-shell.log in the root directory. +log_file: "/var/log/gitlab/gitlab-shell.log" + +# Log level. INFO by default +log_level: INFO + +# Audit usernames. +# Set to true to see real usernames in the logs instead of key ids, which is easier to follow, but +# incurs an extra API call on every gitlab-shell command. +audit_usernames: false + +# Git trace log file. +# If set, git commands receive GIT_TRACE* environment variables +# See https://git-scm.com/book/es/v2/Git-Internals-Environment-Variables#Debugging for documentation +# An absolute path starting with / – the trace output will be appended to that file. +# It needs to exist so we can check permissions and avoid to throwing warnings to the users. +git_trace_log_file: diff --git a/states/roles/maintain/gitlabarch/conf_files/database.yml b/states/roles/maintain/gitlabarch/conf_files/database.yml new file mode 100644 index 0000000..6633c0d --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/database.yml @@ -0,0 +1,44 @@ +# +# PRODUCTION +# +production: + adapter: mysql2 + encoding: utf8 + collation: utf8_general_ci + reconnect: false + database: gitlab + pool: 10 + username: gitlab + password: "{%- include 'secure/passwords/gitlab_db_password.txt' -%}" + host: sql.actcur.com + # socket: /tmp/mysql.sock + +# +# Development specific +# +development: + adapter: mysql2 + encoding: utf8 + collation: utf8_general_ci + reconnect: false + database: gitlabhq_development + pool: 5 + username: root + password: "secure password" + # host: localhost + # socket: /tmp/mysql.sock + +# Warning: The database defined as "test" will be erased and +# re-generated from your development database when you run "rake". +# Do not set this db to the same as development or production. +test: &test + adapter: mysql2 + encoding: utf8mb4 + collation: utf8mb4_general_ci + reconnect: false + database: gitlabhq_test + pool: 5 + username: root + password: + # host: localhost + # socket: /tmp/mysql.sock diff --git a/states/roles/maintain/gitlabarch/conf_files/gitlab.conf b/states/roles/maintain/gitlabarch/conf_files/gitlab.conf new file mode 100644 index 0000000..cda4f4e --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/gitlab.conf @@ -0,0 +1,69 @@ +## GitLab +## +## Lines starting with two hashes (##) are comments with information. +## Lines starting with one hash (#) are configuration parameters that can be uncommented. +## +################################## +## CONTRIBUTING ## +################################## +## +## If you change this file in a Merge Request, please also create +## a Merge Request on https://gitlab.com/gitlab-org/omnibus-gitlab/merge_requests +## +################################### +## configuration ## +################################### +## +## See installation.md#using-https for additional HTTPS configuration details. + +upstream gitlab-workhorse { + server unix:/run/gitlab/gitlab-workhorse.socket fail_timeout=0; +} + +## Normal HTTP host +server { + ## Either remove "default_server" from the listen line below, + ## or delete the /etc/nginx/sites-enabled/default file. This will cause gitlab + ## to be served if you visit any address that your server responds to, eg. + ## the ip address of the server (http://x.x.x.x/)n 0.0.0.0:80 default_server; + listen 0.0.0.0:8000; + listen [::]:8000; + server_name git2.actcur.com; ## Replace this with something like gitlab.example.com + server_tokens off; ## Don't show the nginx version number, a security best practice + + ## See app/controllers/application_controller.rb for headers set + + ## Individual nginx logs for this GitLab vhost + access_log /var/log/nginx/gitlab_access.log; + error_log /var/log/nginx/gitlab_error.log; + + location / { + client_max_body_size 0; + gzip off; + + ## https://github.com/gitlabhq/gitlabhq/issues/694 + ## Some requests take more than 30 seconds. + proxy_read_timeout 300; + proxy_connect_timeout 300; + proxy_redirect off; + + proxy_http_version 1.1; + + proxy_set_header Host $http_host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Proto $scheme; + + proxy_pass http://gitlab-workhorse; + } + + error_page 404 /404.html; + error_page 422 /422.html; + error_page 500 /500.html; + error_page 502 /502.html; + location ~ ^/(404|422|500|502)\.html$ { + root /usr/share/webapps/gitlab/public; + internal; + } + +} diff --git a/states/roles/maintain/gitlabarch/conf_files/gitlab.yml b/states/roles/maintain/gitlabarch/conf_files/gitlab.yml new file mode 100644 index 0000000..233d4e8 --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/gitlab.yml @@ -0,0 +1,627 @@ +# # # # # # # # # # # # # # # # # # +# GitLab application config file # +# # # # # # # # # # # # # # # # # # +# +########################### NOTE ##################################### +# This file should not receive new settings. All configuration options # +# * are being moved to ApplicationSetting model! # +# If a setting requires an application restart say so in that screen. # +# If you change this file in a Merge Request, please also create # +# a MR on https://gitlab.com/gitlab-org/omnibus-gitlab/merge_requests # +######################################################################## +# +# +# How to use: +# 1. Copy file as gitlab.yml +# 2. Update gitlab -> host with your fully qualified domain name +# 3. Update gitlab -> email_from +# 4. If you installed Git from source, change git -> bin_path to /usr/local/bin/git +# IMPORTANT: If Git was installed in a different location use that instead. +# You can check with `which git`. If a wrong path of Git is specified, it will +# result in various issues such as failures of GitLab CI builds. +# 5. Review this configuration file for other settings you may want to adjust + +production: &base + # + # 1. GitLab app settings + # ========================== + + ## GitLab settings + gitlab: + ## Web server settings (note: host is the FQDN, do not include http://) + host: git.actcur.com + port: 443 # Set to 443 if using HTTPS, see installation.md#using-https for additional HTTPS configuration details + https: true # Set to true if using HTTPS, see installation.md#using-https for additional HTTPS configuration details + + # Uncommment this line below if your ssh host is different from HTTP/HTTPS one + # (you'd obviously need to replace ssh.host_example.com with your own host). + # Otherwise, ssh host will be set to the `host:` value above + # ssh_host: ssh.host_example.com + + # Relative URL support + # WARNING: We recommend using an FQDN to host GitLab in a root path instead + # of using a relative URL. + # Documentation: http://doc.gitlab.com/ce/install/relative_url.html + # Uncomment and customize the following line to run in a non-root path + # + # relative_url_root: /gitlab + + # Trusted Proxies + # Customize if you have GitLab behind a reverse proxy which is running on a different machine. + # Add the IP address for your reverse proxy to the list, otherwise users will appear signed in from that address. + trusted_proxies: + # Examples: + #- 192.168.1.0/24 + #- 192.168.2.1 + #- 2001:0db8::/32 + + # Uncomment and customize if you can't use the default user to run GitLab (default: 'git') + user: gitlab + + ## Date & Time settings + # Uncomment and customize if you want to change the default time zone of GitLab application. + # To see all available zones, run `bundle exec rake time:zones:all RAILS_ENV=production` + # time_zone: 'UTC' + + ## Email settings + # Uncomment and set to false if you need to disable email sending from GitLab (default: true) + # email_enabled: true + # Email address used in the "From" field in mails sent by GitLab + email_from: notifications@actcur.com + email_display_name: Actcur Git + email_reply_to: noreply@actcur.com + email_subject_suffix: '' + + # Email server smtp settings are in config/initializers/smtp_settings.rb.sample + + # default_can_create_group: false # default: true + # username_changing_enabled: false # default: true - User can change her username/namespace + + ## Automatic issue closing + # If a commit message matches this regular expression, all issues referenced from the matched text will be closed. + # This happens when the commit is pushed or merged into the default branch of a project. + # When not specified the default issue_closing_pattern as specified below will be used. + # Tip: you can test your closing pattern at http://rubular.com. + # issue_closing_pattern: '((?:[Cc]los(?:e[sd]?|ing)|[Ff]ix(?:e[sd]|ing)?|[Rr]esolv(?:e[sd]?|ing))(:?) +(?:(?:issues? +)?%{issue_ref}(?:(?:, *| +and +)?)|([A-Z][A-Z0-9_]+-\d+))+)' + + ## Default project features settings + default_projects_features: + issues: true + merge_requests: true + wiki: true + snippets: true + builds: true + container_registry: true + + ## Webhook settings + # Number of seconds to wait for HTTP response after sending webhook HTTP POST request (default: 10) + # webhook_timeout: 10 + + ## Repository downloads directory + # When a user clicks e.g. 'Download zip' on a project, a temporary zip file is created in the following directory. + # The default is 'shared/cache/archive/' relative to the root of the Rails app. + # repository_downloads_path: shared/cache/archive/ + + ## Reply by email + # Allow users to comment on issues and merge requests by replying to notification emails. + # For documentation on how to set this up, see http://doc.gitlab.com/ce/administration/reply_by_email.html + incoming_email: + enabled: false + + # The email address including the `%{key}` placeholder that will be replaced to reference the item being replied to. + # The placeholder can be omitted but if present, it must appear in the "user" part of the address (before the `@`). + address: "gitlab-incoming+%{key}@gmail.com" + + # Email account username + # With third party providers, this is usually the full email address. + # With self-hosted email servers, this is usually the user part of the email address. + user: "gitlab-incoming@gmail.com" + # Email account password + password: "[REDACTED]" + + # IMAP server host + host: "imap.gmail.com" + # IMAP server port + port: 993 + # Whether the IMAP server uses SSL + ssl: true + # Whether the IMAP server uses StartTLS + start_tls: false + + # The mailbox where incoming mail will end up. Usually "inbox". + mailbox: "inbox" + # The IDLE command timeout. + idle_timeout: 60 + + ## Build Artifacts + artifacts: + enabled: true + # The location where build artifacts are stored (default: shared/artifacts). + # path: shared/artifacts + + ## Git LFS + lfs: + enabled: true + # The location where LFS objects are stored (default: shared/lfs-objects). + # storage_path: shared/lfs-objects + + ## GitLab Pages + pages: + enabled: false + # The location where pages are stored (default: shared/pages). + # path: shared/pages + + # The domain under which the pages are served: + # http://group.example.com/project + # or project path can be a group page: group.example.com + host: example.com + port: 80 # Set to 443 if you serve the pages with HTTPS + https: false # Set to true if you serve the pages with HTTPS + # external_http: ["1.1.1.1:80", "[2001::1]:80"] # If defined, enables custom domain support in GitLab Pages + # external_https: ["1.1.1.1:443", "[2001::1]:443"] # If defined, enables custom domain and certificate support in GitLab Pages + + ## Mattermost + ## For enabling Add to Mattermost button + mattermost: + enabled: false + host: 'https://mattermost.example.com' + + ## Gravatar + ## For Libravatar see: http://doc.gitlab.com/ce/customization/libravatar.html + gravatar: + # gravatar urls: possible placeholders: %{hash} %{size} %{email} %{username} + # plain_url: "http://..." # default: http://www.gravatar.com/avatar/%{hash}?s=%{size}&d=identicon + # ssl_url: "https://..." # default: https://secure.gravatar.com/avatar/%{hash}?s=%{size}&d=identicon + + ## Auxiliary jobs + # Periodically executed jobs, to self-heal Gitlab, do external synchronizations, etc. + # Please read here for more information: https://github.com/ondrejbartas/sidekiq-cron#adding-cron-job + cron_jobs: + # Flag stuck CI jobs as failed + stuck_ci_jobs_worker: + cron: "0 * * * *" + # Execute scheduled triggers + pipeline_schedule_worker: + cron: "19 * * * *" + # Remove expired build artifacts + expire_build_artifacts_worker: + cron: "50 * * * *" + # Periodically run 'git fsck' on all repositories. If started more than + # once per hour you will have concurrent 'git fsck' jobs. + repository_check_worker: + cron: "20 * * * *" + # Send admin emails once a week + admin_email_worker: + cron: "0 0 * * 0" + + # Remove outdated repository archives + repository_archive_cache_worker: + cron: "0 * * * *" + + registry: + # enabled: true + # host: registry.example.com + # port: 5005 + # api_url: http://localhost:5000/ # internal address to the registry, will be used by GitLab to directly communicate with API + # key: config/registry.key + # path: shared/registry + # issuer: gitlab-issuer + + # + # 2. GitLab CI settings + # ========================== + + gitlab_ci: + # Default project notifications settings: + # + # Send emails only on broken builds (default: true) + # all_broken_builds: true + # + # Add pusher to recipients list (default: false) + # add_pusher: true + + # The location where build traces are stored (default: builds/). Relative paths are relative to Rails.root + # builds_path: builds/ + + # + # 3. Auth settings + # ========================== + + ## LDAP settings + # You can inspect a sample of the LDAP users with login access by running: + # bundle exec rake gitlab:ldap:check RAILS_ENV=production + ldap: + enabled: false + servers: + ########################################################################## + # + # Since GitLab 7.4, LDAP servers get ID's (below the ID is 'main'). GitLab + # Enterprise Edition now supports connecting to multiple LDAP servers. + # + # If you are updating from the old (pre-7.4) syntax, you MUST give your + # old server the ID 'main'. + # + ########################################################################## + main: # 'main' is the GitLab 'provider ID' of this LDAP server + ## label + # + # A human-friendly name for your LDAP server. It is OK to change the label later, + # for instance if you find out it is too large to fit on the web page. + # + # Example: 'Paris' or 'Acme, Ltd.' + label: 'LDAP' + + host: '_your_ldap_server' + port: 389 + uid: 'sAMAccountName' + method: 'plain' # "tls" or "ssl" or "plain" + bind_dn: '_the_full_dn_of_the_user_you_will_bind_with' + password: '_the_password_of_the_bind_user' + + # Set a timeout, in seconds, for LDAP queries. This helps avoid blocking + # a request if the LDAP server becomes unresponsive. + # A value of 0 means there is no timeout. + timeout: 10 + + # This setting specifies if LDAP server is Active Directory LDAP server. + # For non AD servers it skips the AD specific queries. + # If your LDAP server is not AD, set this to false. + active_directory: true + + # If allow_username_or_email_login is enabled, GitLab will ignore everything + # after the first '@' in the LDAP username submitted by the user on login. + # + # Example: + # - the user enters 'jane.doe@example.com' and 'p@ssw0rd' as LDAP credentials; + # - GitLab queries the LDAP server with 'jane.doe' and 'p@ssw0rd'. + # + # If you are using "uid: 'userPrincipalName'" on ActiveDirectory you need to + # disable this setting, because the userPrincipalName contains an '@'. + allow_username_or_email_login: false + + # To maintain tight control over the number of active users on your GitLab installation, + # enable this setting to keep new users blocked until they have been cleared by the admin + # (default: false). + block_auto_created_users: false + + # Base where we can search for users + # + # Ex. ou=People,dc=gitlab,dc=example + # + base: '' + + # Filter LDAP users + # + # Format: RFC 4515 http://tools.ietf.org/search/rfc4515 + # Ex. (employeeType=developer) + # + # Note: GitLab does not support omniauth-ldap's custom filter syntax. + # + user_filter: '' + + # LDAP attributes that GitLab will use to create an account for the LDAP user. + # The specified attribute can either be the attribute name as a string (e.g. 'mail'), + # or an array of attribute names to try in order (e.g. ['mail', 'email']). + # Note that the user's LDAP login will always be the attribute specified as `uid` above. + attributes: + # The username will be used in paths for the user's own projects + # (like `gitlab.example.com/username/project`) and when mentioning + # them in issues, merge request and comments (like `@username`). + # If the attribute specified for `username` contains an email address, + # the GitLab username will be the part of the email address before the '@'. + username: ['uid', 'userid', 'sAMAccountName'] + email: ['mail', 'email', 'userPrincipalName'] + + # If no full name could be found at the attribute specified for `name`, + # the full name is determined using the attributes specified for + # `first_name` and `last_name`. + name: 'cn' + first_name: 'givenName' + last_name: 'sn' + + # GitLab EE only: add more LDAP servers + # Choose an ID made of a-z and 0-9 . This ID will be stored in the database + # so that GitLab can remember which LDAP server a user belongs to. + # uswest2: + # label: + # host: + # .... + + + ## OmniAuth settings + omniauth: + # Allow login via Twitter, Google, etc. using OmniAuth providers + enabled: false + + # Uncomment this to automatically sign in with a specific omniauth provider's without + # showing GitLab's sign-in page (default: show the GitLab sign-in page) + # auto_sign_in_with_provider: saml + + # Sync user's email address from the specified Omniauth provider every time the user logs + # in (default: nil). And consequently make this field read-only. + # sync_email_from_provider: cas3 + + # CAUTION! + # This allows users to login without having a user account first. Define the allowed providers + # using an array, e.g. ["saml", "twitter"], or as true/false to allow all providers or none. + # User accounts will be created automatically when authentication was successful. + allow_single_sign_on: ["saml"] + + # Locks down those users until they have been cleared by the admin (default: true). + block_auto_created_users: true + # Look up new users in LDAP servers. If a match is found (same uid), automatically + # link the omniauth identity with the LDAP account. (default: false) + auto_link_ldap_user: false + + # Allow users with existing accounts to login and auto link their account via SAML + # login, without having to do a manual login first and manually add SAML + # (default: false) + auto_link_saml_user: false + + # Set different Omniauth providers as external so that all users creating accounts + # via these providers will not be able to have access to internal projects. You + # will need to use the full name of the provider, like `google_oauth2` for Google. + # Refer to the examples below for the full names of the supported providers. + # (default: []) + external_providers: [] + + ## Auth providers + # Uncomment the following lines and fill in the data of the auth provider you want to use + # If your favorite auth provider is not listed you can use others: + # see https://github.com/gitlabhq/gitlab-public-wiki/wiki/Custom-omniauth-provider-configurations + # The 'app_id' and 'app_secret' parameters are always passed as the first two + # arguments, followed by optional 'args' which can be either a hash or an array. + # Documentation for this is available at http://doc.gitlab.com/ce/integration/omniauth.html + providers: + # See omniauth-cas3 for more configuration details + # - { name: 'cas3', + # label: 'cas3', + # args: { + # url: 'https://sso.example.com', + # disable_ssl_verification: false, + # login_url: '/cas/login', + # service_validate_url: '/cas/p3/serviceValidate', + # logout_url: '/cas/logout'} } + # - { name: 'authentiq', + # # for client credentials (client ID and secret), go to https://www.authentiq.com/ + # app_id: 'YOUR_CLIENT_ID', + # app_secret: 'YOUR_CLIENT_SECRET', + # args: { + # scope: 'aq:name email~rs address aq:push' + # # redirect_uri parameter is optional except when 'gitlab.host' in this file is set to 'localhost' + # # redirect_uri: 'YOUR_REDIRECT_URI' + # } + # } + # - { name: 'github', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET', + # url: "https://github.com/", + # verify_ssl: true, + # args: { scope: 'user:email' } } + # - { name: 'bitbucket', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET' } + # - { name: 'gitlab', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET', + # args: { scope: 'api' } } + # - { name: 'google_oauth2', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET', + # args: { access_type: 'offline', approval_prompt: '' } } + # - { name: 'facebook', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET' } + # - { name: 'twitter', + # app_id: 'YOUR_APP_ID', + # app_secret: 'YOUR_APP_SECRET' } + # + # - { name: 'saml', + # label: 'Our SAML Provider', + # groups_attribute: 'Groups', + # external_groups: ['Contractors', 'Freelancers'], + # args: { + # assertion_consumer_service_url: 'https://gitlab.example.com/users/auth/saml/callback', + # idp_cert_fingerprint: '43:51:43:a1:b5:fc:8b:b7:0a:3a:a9:b1:0f:66:73:a8', + # idp_sso_target_url: 'https://login.example.com/idp', + # issuer: 'https://gitlab.example.com', + # name_identifier_format: 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient' + # } } + # + # - { name: 'crowd', + # args: { + # crowd_server_url: 'CROWD SERVER URL', + # application_name: 'YOUR_APP_NAME', + # application_password: 'YOUR_APP_PASSWORD' } } + # + # - { name: 'auth0', + # args: { + # client_id: 'YOUR_AUTH0_CLIENT_ID', + # client_secret: 'YOUR_AUTH0_CLIENT_SECRET', + # namespace: 'YOUR_AUTH0_DOMAIN' } } + + # SSO maximum session duration in seconds. Defaults to CAS default of 8 hours. + # cas3: + # session_duration: 28800 + + # Shared file storage settings + shared: + path: /var/lib/gitlab/shared # Default: shared + + # Gitaly settings + gitaly: + # This setting controls whether GitLab uses Gitaly (new component + # introduced in 9.0). Eventually Gitaly use will become mandatory and + # this option will disappear. + enabled: true + + # + # 4. Advanced settings + # ========================== + + ## Repositories settings + repositories: + # Paths where repositories can be stored. Give the canonicalized absolute pathname. + # IMPORTANT: None of the path components may be symlink, because + # gitlab-shell invokes Dir.pwd inside the repository path and that results + # real path not the symlink. + storages: # You must have at least a `default` storage path. + default: + path: /var/lib/gitlab/repositories/ + gitaly_address: unix:/var/lib/gitlab/sockets/gitlab-gitaly.socket # TCP connections are supported too (e.g. tcp://host:port) + + ## Backup settings + backup: + path: "/var/lib/gitlab/backups" # Relative paths are relative to Rails.root (default: tmp/backups/) + # archive_permissions: 0640 # Permissions for the resulting backup.tar file (default: 0600) + # keep_time: 604800 # default: 0 (forever) (in seconds) + # pg_schema: public # default: nil, it means that all schemas will be backed up + # upload: + # # Fog storage connection settings, see http://fog.io/storage/ . + # connection: + # provider: AWS + # region: eu-west-1 + # aws_access_key_id: AKIAKIAKI + # aws_secret_access_key: 'secret123' + # # The remote 'directory' to store your backups. For S3, this would be the bucket name. + # remote_directory: 'my.s3.bucket' + # # Use multipart uploads when file size reaches 100MB, see + # # http://docs.aws.amazon.com/AmazonS3/latest/dev/uploadobjusingmpu.html + # multipart_chunk_size: 104857600 + # # Turns on AWS Server-Side Encryption with Amazon S3-Managed Keys for backups, this is optional + # # encryption: 'AES256' + # # Specifies Amazon S3 storage class to use for backups, this is optional + # # storage_class: 'STANDARD' + + ## GitLab Shell settings + gitlab_shell: + path: /usr/share/webapps/gitlab-shell/ + hooks_path: /usr/share/webapps/gitlab-shell/hooks/ + + # File that contains the secret key for verifying access for gitlab-shell. + # Default is '.gitlab_shell_secret' relative to Rails.root (i.e. root of the GitLab app). + # secret_file: /home/git/gitlab/.gitlab_shell_secret + + # Git over HTTP + upload_pack: true + receive_pack: true + + # Git import/fetch timeout + # git_timeout: 800 + + # If you use non-standard ssh port you need to specify it + # ssh_port: 22 + + workhorse: + # File that contains the secret key for verifying access for gitlab-workhorse. + # Default is '.gitlab_workhorse_secret' relative to Rails.root (i.e. root of the GitLab app). + # secret_file: /home/git/gitlab/.gitlab_workhorse_secret + + ## Git settings + # CAUTION! + # Use the default values unless you really know what you are doing + git: + bin_path: /usr/bin/git + # The next value is the maximum memory size grit can use + # Given in number of bytes per git object (e.g. a commit) + # This value can be increased if you have very large commits + max_size: 20971520 # 20.megabytes + # Git timeout to read a commit, in seconds + timeout: 10 + + ## Webpack settings + # If enabled, this will tell rails to serve frontend assets from the webpack-dev-server running + # on a given port instead of serving directly from /assets/webpack. This is only indended for use + # in development. + webpack: + # dev_server: + # enabled: true + # host: localhost + # port: 3808 + + # + # 5. Extra customization + # ========================== + + extra: + ## Google analytics. Uncomment if you want it + # google_analytics_id: '_your_tracking_id' + + ## Piwik analytics. + # piwik_url: '_your_piwik_url' + # piwik_site_id: '_your_piwik_site_id' + + rack_attack: + git_basic_auth: + # Rack Attack IP banning enabled + # enabled: true + # + # Whitelist requests from 127.0.0.1 for web proxies (NGINX/Apache) with incorrect headers + # ip_whitelist: ["127.0.0.1"] + # + # Limit the number of Git HTTP authentication attempts per IP + # maxretry: 10 + # + # Reset the auth attempt counter per IP after 60 seconds + # findtime: 60 + # + # Ban an IP for one hour (3600s) after too many auth attempts + # bantime: 3600 + +development: + <<: *base + +test: + <<: *base + gravatar: + enabled: true + lfs: + enabled: false + gitlab: + host: localhost + port: 80 + + # When you run tests we clone and setup gitlab-shell + # In order to setup it correctly you need to specify + # your system username you use to run GitLab + # user: YOUR_USERNAME + pages: + path: tmp/tests/pages + repositories: + storages: + default: + path: tmp/tests/repositories/ + gitaly_address: unix:tmp/tests/gitaly/gitaly.socket + gitaly: + enabled: true + backup: + path: tmp/tests/backups + gitlab_shell: + path: tmp/tests/gitlab-shell/ + hooks_path: tmp/tests/gitlab-shell/hooks/ + issues_tracker: + redmine: + title: "Redmine" + project_url: "http://redmine/projects/:issues_tracker_id" + issues_url: "http://redmine/:project_id/:issues_tracker_id/:id" + new_issue_url: "http://redmine/projects/:issues_tracker_id/issues/new" + jira: + title: "JIRA" + url: https://sample_company.atlassian.net + project_key: PROJECT + ldap: + enabled: false + servers: + main: + label: ldap + host: 127.0.0.1 + port: 3890 + uid: 'uid' + method: 'plain' # "tls" or "ssl" or "plain" + base: 'dc=example,dc=com' + user_filter: '' + group_base: 'ou=groups,dc=example,dc=com' + admin_group: '' + +staging: + <<: *base diff --git a/states/roles/maintain/gitlabarch/conf_files/production.rb b/states/roles/maintain/gitlabarch/conf_files/production.rb new file mode 100644 index 0000000..0b88842 --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/production.rb @@ -0,0 +1,83 @@ +Rails.application.configure do + # Settings specified here will take precedence over those in config/application.rb + + # Code is not reloaded between requests + config.cache_classes = true + + # Full error reports are disabled and caching is turned on + config.consider_all_requests_local = false + config.action_controller.perform_caching = true + + # Disable Rails's static asset server (Apache or nginx will already do this) + config.serve_static_files = false + + # Compress JavaScripts and CSS. + config.assets.js_compressor = :uglifier + # config.assets.css_compressor = :sass + + # Don't fallback to assets pipeline if a precompiled asset is missed + config.assets.compile = false + + # Generate digests for assets URLs + config.assets.digest = true + + # Enable compression of compiled assets using gzip. + config.assets.compress = true + + # Defaults to nil and saved in location specified by config.assets.prefix + # config.assets.manifest = YOUR_PATH + + # Specifies the header that your server uses for sending files + # config.action_dispatch.x_sendfile_header = "X-Sendfile" # for apache + # config.action_dispatch.x_sendfile_header = 'X-Accel-Redirect' # for nginx + + # Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies. + # config.force_ssl = true + + # See everything in the log (default is :info) + config.log_level = :info + + # Suppress 'Rendered template ...' messages in the log + # source: http://stackoverflow.com/a/16369363 + %w{render_template render_partial render_collection}.each do |event| + ActiveSupport::Notifications.unsubscribe "#{event}.action_view" + end + + # Prepend all log lines with the following tags + # config.log_tags = [ :subdomain, :uuid ] + + # Use a different logger for distributed setups + # config.logger = ActiveSupport::TaggedLogging.new(SyslogLogger.new) + + # Enable serving of images, stylesheets, and JavaScripts from an asset server + config.action_controller.asset_host = ENV['GITLAB_CDN_HOST'] if ENV['GITLAB_CDN_HOST'].present? + + # Precompile additional assets (application.js, application.css, and all non-JS/CSS are already added) + # config.assets.precompile += %w( search.js ) + + # Disable delivery errors, bad email addresses will be ignored + # config.action_mailer.raise_delivery_errors = false + + # Enable threaded mode + # config.threadsafe! unless $rails_rake_task + + # Enable locale fallbacks for I18n (makes lookups for any locale fall back to + # the I18n.default_locale when a translation can not be found) + config.i18n.fallbacks = true + + # Send deprecation notices to registered listeners + config.active_support.deprecation = :notify + + config.action_mailer.delivery_method = :smtp + # Defaults to: + # # config.action_mailer.sendmail_settings = { + # # location: '/usr/sbin/sendmail', + # # arguments: '-i -t' + # # } + config.action_mailer.perform_deliveries = true + config.action_mailer.raise_delivery_errors = true + + config.eager_load = true + + config.allow_concurrency = false +end diff --git a/states/roles/maintain/gitlabarch/conf_files/redis.conf b/states/roles/maintain/gitlabarch/conf_files/redis.conf new file mode 100644 index 0000000..e79c9b5 --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/redis.conf @@ -0,0 +1,1293 @@ +# Redis configuration file example. +# +# Note that in order to read the configuration file, Redis must be +# started with the file path as first argument: +# +# ./redis-server /path/to/redis.conf + +# Note on units: when memory size is needed, it is possible to specify +# it in the usual form of 1k 5GB 4M and so forth: +# +# 1k => 1000 bytes +# 1kb => 1024 bytes +# 1m => 1000000 bytes +# 1mb => 1024*1024 bytes +# 1g => 1000000000 bytes +# 1gb => 1024*1024*1024 bytes +# +# units are case insensitive so 1GB 1Gb 1gB are all the same. + +################################## INCLUDES ################################### + +# Include one or more other config files here. This is useful if you +# have a standard template that goes to all Redis servers but also need +# to customize a few per-server settings. Include files can include +# other files, so use this wisely. +# +# Notice option "include" won't be rewritten by command "CONFIG REWRITE" +# from admin or Redis Sentinel. Since Redis always uses the last processed +# line as value of a configuration directive, you'd better put includes +# at the beginning of this file to avoid overwriting config change at runtime. +# +# If instead you are interested in using includes to override configuration +# options, it is better to use include as the last line. +# +# include /path/to/local.conf +# include /path/to/other.conf + +################################## MODULES ##################################### + +# Load modules at startup. If the server is not able to load modules +# it will abort. It is possible to use multiple loadmodule directives. +# +# loadmodule /path/to/my_module.so +# loadmodule /path/to/other_module.so + +################################## NETWORK ##################################### + +# By default, if no "bind" configuration directive is specified, Redis listens +# for connections from all the network interfaces available on the server. +# It is possible to listen to just one or multiple selected interfaces using +# the "bind" configuration directive, followed by one or more IP addresses. +# +# Examples: +# +# bind 192.168.1.100 10.0.0.1 +# bind 127.0.0.1 ::1 +# +# ~~~ WARNING ~~~ If the computer running Redis is directly exposed to the +# internet, binding to all the interfaces is dangerous and will expose the +# instance to everybody on the internet. So by default we uncomment the +# following bind directive, that will force Redis to listen only into +# the IPv4 lookback interface address (this means Redis will be able to +# accept connections only from clients running into the same computer it +# is running). +# +# IF YOU ARE SURE YOU WANT YOUR INSTANCE TO LISTEN TO ALL THE INTERFACES +# JUST COMMENT THE FOLLOWING LINE. +# ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ +bind 127.0.0.1 + +# Protected mode is a layer of security protection, in order to avoid that +# Redis instances left open on the internet are accessed and exploited. +# +# When protected mode is on and if: +# +# 1) The server is not binding explicitly to a set of addresses using the +# "bind" directive. +# 2) No password is configured. +# +# The server only accepts connections from clients connecting from the +# IPv4 and IPv6 loopback addresses 127.0.0.1 and ::1, and from Unix domain +# sockets. +# +# By default protected mode is enabled. You should disable it only if +# you are sure you want clients from other hosts to connect to Redis +# even if no authentication is configured, nor a specific set of interfaces +# are explicitly listed using the "bind" directive. +protected-mode yes + +# Accept connections on the specified port, default is 6379 (IANA #815344). +# If port 0 is specified Redis will not listen on a TCP socket. +port 6379 + +# TCP listen() backlog. +# +# In high requests-per-second environments you need an high backlog in order +# to avoid slow clients connections issues. Note that the Linux kernel +# will silently truncate it to the value of /proc/sys/net/core/somaxconn so +# make sure to raise both the value of somaxconn and tcp_max_syn_backlog +# in order to get the desired effect. +tcp-backlog 511 + +# Unix socket. +# +# Specify the path for the Unix socket that will be used to listen for +# incoming connections. There is no default, so Redis will not listen +# on a unix socket when not specified. +# +unixsocket /run/redis/redis.sock +unixsocketperm 770 + +# Close the connection after a client is idle for N seconds (0 to disable) +timeout 0 + +# TCP keepalive. +# +# If non-zero, use SO_KEEPALIVE to send TCP ACKs to clients in absence +# of communication. This is useful for two reasons: +# +# 1) Detect dead peers. +# 2) Take the connection alive from the point of view of network +# equipment in the middle. +# +# On Linux, the specified value (in seconds) is the period used to send ACKs. +# Note that to close the connection the double of the time is needed. +# On other kernels the period depends on the kernel configuration. +# +# A reasonable value for this option is 300 seconds, which is the new +# Redis default starting with Redis 3.2.1. +tcp-keepalive 300 + +################################# GENERAL ##################################### + +# By default Redis does not run as a daemon. Use 'yes' if you need it. +# Note that Redis will write a pid file in /var/run/redis.pid when daemonized. +daemonize no + +# If you run Redis from upstart or systemd, Redis can interact with your +# supervision tree. Options: +# supervised no - no supervision interaction +# supervised upstart - signal upstart by putting Redis into SIGSTOP mode +# supervised systemd - signal systemd by writing READY=1 to $NOTIFY_SOCKET +# supervised auto - detect upstart or systemd method based on +# UPSTART_JOB or NOTIFY_SOCKET environment variables +# Note: these supervision methods only signal "process is ready." +# They do not enable continuous liveness pings back to your supervisor. +supervised no + +# If a pid file is specified, Redis writes it where specified at startup +# and removes it at exit. +# +# When the server runs non daemonized, no pid file is created if none is +# specified in the configuration. When the server is daemonized, the pid file +# is used even if not specified, defaulting to "/var/run/redis.pid". +# +# Creating a pid file is best effort: if Redis is not able to create it +# nothing bad happens, the server will start and run normally. +pidfile /var/run/redis_6379.pid + +# Specify the server verbosity level. +# This can be one of: +# debug (a lot of information, useful for development/testing) +# verbose (many rarely useful info, but not a mess like the debug level) +# notice (moderately verbose, what you want in production probably) +# warning (only very important / critical messages are logged) +loglevel notice + +# Specify the log file name. Also the empty string can be used to force +# Redis to log on the standard output. Note that if you use standard +# output for logging but daemonize, logs will be sent to /dev/null +logfile "" + +# To enable logging to the system logger, just set 'syslog-enabled' to yes, +# and optionally update the other syslog parameters to suit your needs. +# syslog-enabled no + +# Specify the syslog identity. +# syslog-ident redis + +# Specify the syslog facility. Must be USER or between LOCAL0-LOCAL7. +# syslog-facility local0 + +# Set the number of databases. The default database is DB 0, you can select +# a different one on a per-connection basis using SELECT where +# dbid is a number between 0 and 'databases'-1 +databases 16 + +# By default Redis shows an ASCII art logo only when started to log to the +# standard output and if the standard output is a TTY. Basically this means +# that normally a logo is displayed only in interactive sessions. +# +# However it is possible to force the pre-4.0 behavior and always show a +# ASCII art logo in startup logs by setting the following option to yes. +always-show-logo yes + +################################ SNAPSHOTTING ################################ +# +# Save the DB on disk: +# +# save +# +# Will save the DB if both the given number of seconds and the given +# number of write operations against the DB occurred. +# +# In the example below the behaviour will be to save: +# after 900 sec (15 min) if at least 1 key changed +# after 300 sec (5 min) if at least 10 keys changed +# after 60 sec if at least 10000 keys changed +# +# Note: you can disable saving completely by commenting out all "save" lines. +# +# It is also possible to remove all the previously configured save +# points by adding a save directive with a single empty string argument +# like in the following example: +# +# save "" + +save 900 1 +save 300 10 +save 60 10000 + +# By default Redis will stop accepting writes if RDB snapshots are enabled +# (at least one save point) and the latest background save failed. +# This will make the user aware (in a hard way) that data is not persisting +# on disk properly, otherwise chances are that no one will notice and some +# disaster will happen. +# +# If the background saving process will start working again Redis will +# automatically allow writes again. +# +# However if you have setup your proper monitoring of the Redis server +# and persistence, you may want to disable this feature so that Redis will +# continue to work as usual even if there are problems with disk, +# permissions, and so forth. +stop-writes-on-bgsave-error yes + +# Compress string objects using LZF when dump .rdb databases? +# For default that's set to 'yes' as it's almost always a win. +# If you want to save some CPU in the saving child set it to 'no' but +# the dataset will likely be bigger if you have compressible values or keys. +rdbcompression yes + +# Since version 5 of RDB a CRC64 checksum is placed at the end of the file. +# This makes the format more resistant to corruption but there is a performance +# hit to pay (around 10%) when saving and loading RDB files, so you can disable it +# for maximum performances. +# +# RDB files created with checksum disabled have a checksum of zero that will +# tell the loading code to skip the check. +rdbchecksum yes + +# The filename where to dump the DB +dbfilename dump.rdb + +# The working directory. +# +# The DB will be written inside this directory, with the filename specified +# above using the 'dbfilename' configuration directive. +# +# The Append Only File will also be created inside this directory. +# +# Note that you must specify a directory here, not a file name. +dir /var/lib/redis/ + +################################# REPLICATION ################################# + +# Master-Slave replication. Use slaveof to make a Redis instance a copy of +# another Redis server. A few things to understand ASAP about Redis replication. +# +# 1) Redis replication is asynchronous, but you can configure a master to +# stop accepting writes if it appears to be not connected with at least +# a given number of slaves. +# 2) Redis slaves are able to perform a partial resynchronization with the +# master if the replication link is lost for a relatively small amount of +# time. You may want to configure the replication backlog size (see the next +# sections of this file) with a sensible value depending on your needs. +# 3) Replication is automatic and does not need user intervention. After a +# network partition slaves automatically try to reconnect to masters +# and resynchronize with them. +# +# slaveof + +# If the master is password protected (using the "requirepass" configuration +# directive below) it is possible to tell the slave to authenticate before +# starting the replication synchronization process, otherwise the master will +# refuse the slave request. +# +# masterauth + +# When a slave loses its connection with the master, or when the replication +# is still in progress, the slave can act in two different ways: +# +# 1) if slave-serve-stale-data is set to 'yes' (the default) the slave will +# still reply to client requests, possibly with out of date data, or the +# data set may just be empty if this is the first synchronization. +# +# 2) if slave-serve-stale-data is set to 'no' the slave will reply with +# an error "SYNC with master in progress" to all the kind of commands +# but to INFO and SLAVEOF. +# +slave-serve-stale-data yes + +# You can configure a slave instance to accept writes or not. Writing against +# a slave instance may be useful to store some ephemeral data (because data +# written on a slave will be easily deleted after resync with the master) but +# may also cause problems if clients are writing to it because of a +# misconfiguration. +# +# Since Redis 2.6 by default slaves are read-only. +# +# Note: read only slaves are not designed to be exposed to untrusted clients +# on the internet. It's just a protection layer against misuse of the instance. +# Still a read only slave exports by default all the administrative commands +# such as CONFIG, DEBUG, and so forth. To a limited extent you can improve +# security of read only slaves using 'rename-command' to shadow all the +# administrative / dangerous commands. +slave-read-only yes + +# Replication SYNC strategy: disk or socket. +# +# ------------------------------------------------------- +# WARNING: DISKLESS REPLICATION IS EXPERIMENTAL CURRENTLY +# ------------------------------------------------------- +# +# New slaves and reconnecting slaves that are not able to continue the replication +# process just receiving differences, need to do what is called a "full +# synchronization". An RDB file is transmitted from the master to the slaves. +# The transmission can happen in two different ways: +# +# 1) Disk-backed: The Redis master creates a new process that writes the RDB +# file on disk. Later the file is transferred by the parent +# process to the slaves incrementally. +# 2) Diskless: The Redis master creates a new process that directly writes the +# RDB file to slave sockets, without touching the disk at all. +# +# With disk-backed replication, while the RDB file is generated, more slaves +# can be queued and served with the RDB file as soon as the current child producing +# the RDB file finishes its work. With diskless replication instead once +# the transfer starts, new slaves arriving will be queued and a new transfer +# will start when the current one terminates. +# +# When diskless replication is used, the master waits a configurable amount of +# time (in seconds) before starting the transfer in the hope that multiple slaves +# will arrive and the transfer can be parallelized. +# +# With slow disks and fast (large bandwidth) networks, diskless replication +# works better. +repl-diskless-sync no + +# When diskless replication is enabled, it is possible to configure the delay +# the server waits in order to spawn the child that transfers the RDB via socket +# to the slaves. +# +# This is important since once the transfer starts, it is not possible to serve +# new slaves arriving, that will be queued for the next RDB transfer, so the server +# waits a delay in order to let more slaves arrive. +# +# The delay is specified in seconds, and by default is 5 seconds. To disable +# it entirely just set it to 0 seconds and the transfer will start ASAP. +repl-diskless-sync-delay 5 + +# Slaves send PINGs to server in a predefined interval. It's possible to change +# this interval with the repl_ping_slave_period option. The default value is 10 +# seconds. +# +# repl-ping-slave-period 10 + +# The following option sets the replication timeout for: +# +# 1) Bulk transfer I/O during SYNC, from the point of view of slave. +# 2) Master timeout from the point of view of slaves (data, pings). +# 3) Slave timeout from the point of view of masters (REPLCONF ACK pings). +# +# It is important to make sure that this value is greater than the value +# specified for repl-ping-slave-period otherwise a timeout will be detected +# every time there is low traffic between the master and the slave. +# +# repl-timeout 60 + +# Disable TCP_NODELAY on the slave socket after SYNC? +# +# If you select "yes" Redis will use a smaller number of TCP packets and +# less bandwidth to send data to slaves. But this can add a delay for +# the data to appear on the slave side, up to 40 milliseconds with +# Linux kernels using a default configuration. +# +# If you select "no" the delay for data to appear on the slave side will +# be reduced but more bandwidth will be used for replication. +# +# By default we optimize for low latency, but in very high traffic conditions +# or when the master and slaves are many hops away, turning this to "yes" may +# be a good idea. +repl-disable-tcp-nodelay no + +# Set the replication backlog size. The backlog is a buffer that accumulates +# slave data when slaves are disconnected for some time, so that when a slave +# wants to reconnect again, often a full resync is not needed, but a partial +# resync is enough, just passing the portion of data the slave missed while +# disconnected. +# +# The bigger the replication backlog, the longer the time the slave can be +# disconnected and later be able to perform a partial resynchronization. +# +# The backlog is only allocated once there is at least a slave connected. +# +# repl-backlog-size 1mb + +# After a master has no longer connected slaves for some time, the backlog +# will be freed. The following option configures the amount of seconds that +# need to elapse, starting from the time the last slave disconnected, for +# the backlog buffer to be freed. +# +# Note that slaves never free the backlog for timeout, since they may be +# promoted to masters later, and should be able to correctly "partially +# resynchronize" with the slaves: hence they should always accumulate backlog. +# +# A value of 0 means to never release the backlog. +# +# repl-backlog-ttl 3600 + +# The slave priority is an integer number published by Redis in the INFO output. +# It is used by Redis Sentinel in order to select a slave to promote into a +# master if the master is no longer working correctly. +# +# A slave with a low priority number is considered better for promotion, so +# for instance if there are three slaves with priority 10, 100, 25 Sentinel will +# pick the one with priority 10, that is the lowest. +# +# However a special priority of 0 marks the slave as not able to perform the +# role of master, so a slave with priority of 0 will never be selected by +# Redis Sentinel for promotion. +# +# By default the priority is 100. +slave-priority 100 + +# It is possible for a master to stop accepting writes if there are less than +# N slaves connected, having a lag less or equal than M seconds. +# +# The N slaves need to be in "online" state. +# +# The lag in seconds, that must be <= the specified value, is calculated from +# the last ping received from the slave, that is usually sent every second. +# +# This option does not GUARANTEE that N replicas will accept the write, but +# will limit the window of exposure for lost writes in case not enough slaves +# are available, to the specified number of seconds. +# +# For example to require at least 3 slaves with a lag <= 10 seconds use: +# +# min-slaves-to-write 3 +# min-slaves-max-lag 10 +# +# Setting one or the other to 0 disables the feature. +# +# By default min-slaves-to-write is set to 0 (feature disabled) and +# min-slaves-max-lag is set to 10. + +# A Redis master is able to list the address and port of the attached +# slaves in different ways. For example the "INFO replication" section +# offers this information, which is used, among other tools, by +# Redis Sentinel in order to discover slave instances. +# Another place where this info is available is in the output of the +# "ROLE" command of a master. +# +# The listed IP and address normally reported by a slave is obtained +# in the following way: +# +# IP: The address is auto detected by checking the peer address +# of the socket used by the slave to connect with the master. +# +# Port: The port is communicated by the slave during the replication +# handshake, and is normally the port that the slave is using to +# list for connections. +# +# However when port forwarding or Network Address Translation (NAT) is +# used, the slave may be actually reachable via different IP and port +# pairs. The following two options can be used by a slave in order to +# report to its master a specific set of IP and port, so that both INFO +# and ROLE will report those values. +# +# There is no need to use both the options if you need to override just +# the port or the IP address. +# +# slave-announce-ip 5.5.5.5 +# slave-announce-port 1234 + +################################## SECURITY ################################### + +# Require clients to issue AUTH before processing any other +# commands. This might be useful in environments in which you do not trust +# others with access to the host running redis-server. +# +# This should stay commented out for backward compatibility and because most +# people do not need auth (e.g. they run their own servers). +# +# Warning: since Redis is pretty fast an outside user can try up to +# 150k passwords per second against a good box. This means that you should +# use a very strong password otherwise it will be very easy to break. +# +# requirepass foobared + +# Command renaming. +# +# It is possible to change the name of dangerous commands in a shared +# environment. For instance the CONFIG command may be renamed into something +# hard to guess so that it will still be available for internal-use tools +# but not available for general clients. +# +# Example: +# +# rename-command CONFIG b840fc02d524045429941cc15f59e41cb7be6c52 +# +# It is also possible to completely kill a command by renaming it into +# an empty string: +# +# rename-command CONFIG "" +# +# Please note that changing the name of commands that are logged into the +# AOF file or transmitted to slaves may cause problems. + +################################### CLIENTS #################################### + +# Set the max number of connected clients at the same time. By default +# this limit is set to 10000 clients, however if the Redis server is not +# able to configure the process file limit to allow for the specified limit +# the max number of allowed clients is set to the current file limit +# minus 32 (as Redis reserves a few file descriptors for internal uses). +# +# Once the limit is reached Redis will close all the new connections sending +# an error 'max number of clients reached'. +# +# maxclients 10000 + +############################## MEMORY MANAGEMENT ################################ + +# Set a memory usage limit to the specified amount of bytes. +# When the memory limit is reached Redis will try to remove keys +# according to the eviction policy selected (see maxmemory-policy). +# +# If Redis can't remove keys according to the policy, or if the policy is +# set to 'noeviction', Redis will start to reply with errors to commands +# that would use more memory, like SET, LPUSH, and so on, and will continue +# to reply to read-only commands like GET. +# +# This option is usually useful when using Redis as an LRU or LFU cache, or to +# set a hard memory limit for an instance (using the 'noeviction' policy). +# +# WARNING: If you have slaves attached to an instance with maxmemory on, +# the size of the output buffers needed to feed the slaves are subtracted +# from the used memory count, so that network problems / resyncs will +# not trigger a loop where keys are evicted, and in turn the output +# buffer of slaves is full with DELs of keys evicted triggering the deletion +# of more keys, and so forth until the database is completely emptied. +# +# In short... if you have slaves attached it is suggested that you set a lower +# limit for maxmemory so that there is some free RAM on the system for slave +# output buffers (but this is not needed if the policy is 'noeviction'). +# +# maxmemory + +# MAXMEMORY POLICY: how Redis will select what to remove when maxmemory +# is reached. You can select among five behaviors: +# +# volatile-lru -> Evict using approximated LRU among the keys with an expire set. +# allkeys-lru -> Evict any key using approximated LRU. +# volatile-lfu -> Evict using approximated LFU among the keys with an expire set. +# allkeys-lfu -> Evict any key using approximated LFU. +# volatile-random -> Remove a random key among the ones with an expire set. +# allkeys-random -> Remove a random key, any key. +# volatile-ttl -> Remove the key with the nearest expire time (minor TTL) +# noeviction -> Don't evict anything, just return an error on write operations. +# +# LRU means Least Recently Used +# LFU means Least Frequently Used +# +# Both LRU, LFU and volatile-ttl are implemented using approximated +# randomized algorithms. +# +# Note: with any of the above policies, Redis will return an error on write +# operations, when there are no suitable keys for eviction. +# +# At the date of writing these commands are: set setnx setex append +# incr decr rpush lpush rpushx lpushx linsert lset rpoplpush sadd +# sinter sinterstore sunion sunionstore sdiff sdiffstore zadd zincrby +# zunionstore zinterstore hset hsetnx hmset hincrby incrby decrby +# getset mset msetnx exec sort +# +# The default is: +# +# maxmemory-policy noeviction + +# LRU, LFU and minimal TTL algorithms are not precise algorithms but approximated +# algorithms (in order to save memory), so you can tune it for speed or +# accuracy. For default Redis will check five keys and pick the one that was +# used less recently, you can change the sample size using the following +# configuration directive. +# +# The default of 5 produces good enough results. 10 Approximates very closely +# true LRU but costs more CPU. 3 is faster but not very accurate. +# +# maxmemory-samples 5 + +############################# LAZY FREEING #################################### + +# Redis has two primitives to delete keys. One is called DEL and is a blocking +# deletion of the object. It means that the server stops processing new commands +# in order to reclaim all the memory associated with an object in a synchronous +# way. If the key deleted is associated with a small object, the time needed +# in order to execute th DEL command is very small and comparable to most other +# O(1) or O(log_N) commands in Redis. However if the key is associated with an +# aggregated value containing millions of elements, the server can block for +# a long time (even seconds) in order to complete the operation. +# +# For the above reasons Redis also offers non blocking deletion primitives +# such as UNLINK (non blocking DEL) and the ASYNC option of FLUSHALL and +# FLUSHDB commands, in order to reclaim memory in background. Those commands +# are executed in constant time. Another thread will incrementally free the +# object in the background as fast as possible. +# +# DEL, UNLINK and ASYNC option of FLUSHALL and FLUSHDB are user-controlled. +# It's up to the design of the application to understand when it is a good +# idea to use one or the other. However the Redis server sometimes has to +# delete keys or flush the whole database as a side effect of other operations. +# Specifically Redis deletes objects independently of an user call in the +# following scenarios: +# +# 1) On eviction, because of the maxmemory and maxmemory policy configurations, +# in order to make room for new data, without going over the specified +# memory limit. +# 2) Because of expire: when a key with an associated time to live (see the +# EXPIRE command) must be deleted from memory. +# 3) Because of a side effect of a command that stores data on a key that may +# already exist. For example the RENAME command may delete the old key +# content when it is replaced with another one. Similarly SUNIONSTORE +# or SORT with STORE option may delete existing keys. The SET command +# itself removes any old content of the specified key in order to replace +# it with the specified string. +# 4) During replication, when a slave performs a full resynchronization with +# its master, the content of the whole database is removed in order to +# load the RDB file just transfered. +# +# In all the above cases the default is to delete objects in a blocking way, +# like if DEL was called. However you can configure each case specifically +# in order to instead release memory in a non-blocking way like if UNLINK +# was called, using the following configuration directives: + +lazyfree-lazy-eviction no +lazyfree-lazy-expire no +lazyfree-lazy-server-del no +slave-lazy-flush no + +############################## APPEND ONLY MODE ############################### + +# By default Redis asynchronously dumps the dataset on disk. This mode is +# good enough in many applications, but an issue with the Redis process or +# a power outage may result into a few minutes of writes lost (depending on +# the configured save points). +# +# The Append Only File is an alternative persistence mode that provides +# much better durability. For instance using the default data fsync policy +# (see later in the config file) Redis can lose just one second of writes in a +# dramatic event like a server power outage, or a single write if something +# wrong with the Redis process itself happens, but the operating system is +# still running correctly. +# +# AOF and RDB persistence can be enabled at the same time without problems. +# If the AOF is enabled on startup Redis will load the AOF, that is the file +# with the better durability guarantees. +# +# Please check http://redis.io/topics/persistence for more information. + +appendonly no + +# The name of the append only file (default: "appendonly.aof") + +appendfilename "appendonly.aof" + +# The fsync() call tells the Operating System to actually write data on disk +# instead of waiting for more data in the output buffer. Some OS will really flush +# data on disk, some other OS will just try to do it ASAP. +# +# Redis supports three different modes: +# +# no: don't fsync, just let the OS flush the data when it wants. Faster. +# always: fsync after every write to the append only log. Slow, Safest. +# everysec: fsync only one time every second. Compromise. +# +# The default is "everysec", as that's usually the right compromise between +# speed and data safety. It's up to you to understand if you can relax this to +# "no" that will let the operating system flush the output buffer when +# it wants, for better performances (but if you can live with the idea of +# some data loss consider the default persistence mode that's snapshotting), +# or on the contrary, use "always" that's very slow but a bit safer than +# everysec. +# +# More details please check the following article: +# http://antirez.com/post/redis-persistence-demystified.html +# +# If unsure, use "everysec". + +# appendfsync always +appendfsync everysec +# appendfsync no + +# When the AOF fsync policy is set to always or everysec, and a background +# saving process (a background save or AOF log background rewriting) is +# performing a lot of I/O against the disk, in some Linux configurations +# Redis may block too long on the fsync() call. Note that there is no fix for +# this currently, as even performing fsync in a different thread will block +# our synchronous write(2) call. +# +# In order to mitigate this problem it's possible to use the following option +# that will prevent fsync() from being called in the main process while a +# BGSAVE or BGREWRITEAOF is in progress. +# +# This means that while another child is saving, the durability of Redis is +# the same as "appendfsync none". In practical terms, this means that it is +# possible to lose up to 30 seconds of log in the worst scenario (with the +# default Linux settings). +# +# If you have latency problems turn this to "yes". Otherwise leave it as +# "no" that is the safest pick from the point of view of durability. + +no-appendfsync-on-rewrite no + +# Automatic rewrite of the append only file. +# Redis is able to automatically rewrite the log file implicitly calling +# BGREWRITEAOF when the AOF log size grows by the specified percentage. +# +# This is how it works: Redis remembers the size of the AOF file after the +# latest rewrite (if no rewrite has happened since the restart, the size of +# the AOF at startup is used). +# +# This base size is compared to the current size. If the current size is +# bigger than the specified percentage, the rewrite is triggered. Also +# you need to specify a minimal size for the AOF file to be rewritten, this +# is useful to avoid rewriting the AOF file even if the percentage increase +# is reached but it is still pretty small. +# +# Specify a percentage of zero in order to disable the automatic AOF +# rewrite feature. + +auto-aof-rewrite-percentage 100 +auto-aof-rewrite-min-size 64mb + +# An AOF file may be found to be truncated at the end during the Redis +# startup process, when the AOF data gets loaded back into memory. +# This may happen when the system where Redis is running +# crashes, especially when an ext4 filesystem is mounted without the +# data=ordered option (however this can't happen when Redis itself +# crashes or aborts but the operating system still works correctly). +# +# Redis can either exit with an error when this happens, or load as much +# data as possible (the default now) and start if the AOF file is found +# to be truncated at the end. The following option controls this behavior. +# +# If aof-load-truncated is set to yes, a truncated AOF file is loaded and +# the Redis server starts emitting a log to inform the user of the event. +# Otherwise if the option is set to no, the server aborts with an error +# and refuses to start. When the option is set to no, the user requires +# to fix the AOF file using the "redis-check-aof" utility before to restart +# the server. +# +# Note that if the AOF file will be found to be corrupted in the middle +# the server will still exit with an error. This option only applies when +# Redis will try to read more data from the AOF file but not enough bytes +# will be found. +aof-load-truncated yes + +# When rewriting the AOF file, Redis is able to use an RDB preamble in the +# AOF file for faster rewrites and recoveries. When this option is turned +# on the rewritten AOF file is composed of two different stanzas: +# +# [RDB file][AOF tail] +# +# When loading Redis recognizes that the AOF file starts with the "REDIS" +# string and loads the prefixed RDB file, and continues loading the AOF +# tail. +# +# This is currently turned off by default in order to avoid the surprise +# of a format change, but will at some point be used as the default. +aof-use-rdb-preamble no + +################################ LUA SCRIPTING ############################### + +# Max execution time of a Lua script in milliseconds. +# +# If the maximum execution time is reached Redis will log that a script is +# still in execution after the maximum allowed time and will start to +# reply to queries with an error. +# +# When a long running script exceeds the maximum execution time only the +# SCRIPT KILL and SHUTDOWN NOSAVE commands are available. The first can be +# used to stop a script that did not yet called write commands. The second +# is the only way to shut down the server in the case a write command was +# already issued by the script but the user doesn't want to wait for the natural +# termination of the script. +# +# Set it to 0 or a negative value for unlimited execution without warnings. +lua-time-limit 5000 + +################################ REDIS CLUSTER ############################### +# +# ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +# WARNING EXPERIMENTAL: Redis Cluster is considered to be stable code, however +# in order to mark it as "mature" we need to wait for a non trivial percentage +# of users to deploy it in production. +# ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ +# +# Normal Redis instances can't be part of a Redis Cluster; only nodes that are +# started as cluster nodes can. In order to start a Redis instance as a +# cluster node enable the cluster support uncommenting the following: +# +# cluster-enabled yes + +# Every cluster node has a cluster configuration file. This file is not +# intended to be edited by hand. It is created and updated by Redis nodes. +# Every Redis Cluster node requires a different cluster configuration file. +# Make sure that instances running in the same system do not have +# overlapping cluster configuration file names. +# +# cluster-config-file nodes-6379.conf + +# Cluster node timeout is the amount of milliseconds a node must be unreachable +# for it to be considered in failure state. +# Most other internal time limits are multiple of the node timeout. +# +# cluster-node-timeout 15000 + +# A slave of a failing master will avoid to start a failover if its data +# looks too old. +# +# There is no simple way for a slave to actually have an exact measure of +# its "data age", so the following two checks are performed: +# +# 1) If there are multiple slaves able to failover, they exchange messages +# in order to try to give an advantage to the slave with the best +# replication offset (more data from the master processed). +# Slaves will try to get their rank by offset, and apply to the start +# of the failover a delay proportional to their rank. +# +# 2) Every single slave computes the time of the last interaction with +# its master. This can be the last ping or command received (if the master +# is still in the "connected" state), or the time that elapsed since the +# disconnection with the master (if the replication link is currently down). +# If the last interaction is too old, the slave will not try to failover +# at all. +# +# The point "2" can be tuned by user. Specifically a slave will not perform +# the failover if, since the last interaction with the master, the time +# elapsed is greater than: +# +# (node-timeout * slave-validity-factor) + repl-ping-slave-period +# +# So for example if node-timeout is 30 seconds, and the slave-validity-factor +# is 10, and assuming a default repl-ping-slave-period of 10 seconds, the +# slave will not try to failover if it was not able to talk with the master +# for longer than 310 seconds. +# +# A large slave-validity-factor may allow slaves with too old data to failover +# a master, while a too small value may prevent the cluster from being able to +# elect a slave at all. +# +# For maximum availability, it is possible to set the slave-validity-factor +# to a value of 0, which means, that slaves will always try to failover the +# master regardless of the last time they interacted with the master. +# (However they'll always try to apply a delay proportional to their +# offset rank). +# +# Zero is the only value able to guarantee that when all the partitions heal +# the cluster will always be able to continue. +# +# cluster-slave-validity-factor 10 + +# Cluster slaves are able to migrate to orphaned masters, that are masters +# that are left without working slaves. This improves the cluster ability +# to resist to failures as otherwise an orphaned master can't be failed over +# in case of failure if it has no working slaves. +# +# Slaves migrate to orphaned masters only if there are still at least a +# given number of other working slaves for their old master. This number +# is the "migration barrier". A migration barrier of 1 means that a slave +# will migrate only if there is at least 1 other working slave for its master +# and so forth. It usually reflects the number of slaves you want for every +# master in your cluster. +# +# Default is 1 (slaves migrate only if their masters remain with at least +# one slave). To disable migration just set it to a very large value. +# A value of 0 can be set but is useful only for debugging and dangerous +# in production. +# +# cluster-migration-barrier 1 + +# By default Redis Cluster nodes stop accepting queries if they detect there +# is at least an hash slot uncovered (no available node is serving it). +# This way if the cluster is partially down (for example a range of hash slots +# are no longer covered) all the cluster becomes, eventually, unavailable. +# It automatically returns available as soon as all the slots are covered again. +# +# However sometimes you want the subset of the cluster which is working, +# to continue to accept queries for the part of the key space that is still +# covered. In order to do so, just set the cluster-require-full-coverage +# option to no. +# +# cluster-require-full-coverage yes + +# In order to setup your cluster make sure to read the documentation +# available at http://redis.io web site. + +########################## CLUSTER DOCKER/NAT support ######################## + +# In certain deployments, Redis Cluster nodes address discovery fails, because +# addresses are NAT-ted or because ports are forwarded (the typical case is +# Docker and other containers). +# +# In order to make Redis Cluster working in such environments, a static +# configuration where each node known its public address is needed. The +# following two options are used for this scope, and are: +# +# * cluster-announce-ip +# * cluster-announce-port +# * cluster-announce-bus-port +# +# Each instruct the node about its address, client port, and cluster message +# bus port. The information is then published in the header of the bus packets +# so that other nodes will be able to correctly map the address of the node +# publishing the information. +# +# If the above options are not used, the normal Redis Cluster auto-detection +# will be used instead. +# +# Note that when remapped, the bus port may not be at the fixed offset of +# clients port + 10000, so you can specify any port and bus-port depending +# on how they get remapped. If the bus-port is not set, a fixed offset of +# 10000 will be used as usually. +# +# Example: +# +# cluster-announce-ip 10.1.1.5 +# cluster-announce-port 6379 +# cluster-announce-bus-port 6380 + +################################## SLOW LOG ################################### + +# The Redis Slow Log is a system to log queries that exceeded a specified +# execution time. The execution time does not include the I/O operations +# like talking with the client, sending the reply and so forth, +# but just the time needed to actually execute the command (this is the only +# stage of command execution where the thread is blocked and can not serve +# other requests in the meantime). +# +# You can configure the slow log with two parameters: one tells Redis +# what is the execution time, in microseconds, to exceed in order for the +# command to get logged, and the other parameter is the length of the +# slow log. When a new command is logged the oldest one is removed from the +# queue of logged commands. + +# The following time is expressed in microseconds, so 1000000 is equivalent +# to one second. Note that a negative number disables the slow log, while +# a value of zero forces the logging of every command. +slowlog-log-slower-than 10000 + +# There is no limit to this length. Just be aware that it will consume memory. +# You can reclaim memory used by the slow log with SLOWLOG RESET. +slowlog-max-len 128 + +################################ LATENCY MONITOR ############################## + +# The Redis latency monitoring subsystem samples different operations +# at runtime in order to collect data related to possible sources of +# latency of a Redis instance. +# +# Via the LATENCY command this information is available to the user that can +# print graphs and obtain reports. +# +# The system only logs operations that were performed in a time equal or +# greater than the amount of milliseconds specified via the +# latency-monitor-threshold configuration directive. When its value is set +# to zero, the latency monitor is turned off. +# +# By default latency monitoring is disabled since it is mostly not needed +# if you don't have latency issues, and collecting data has a performance +# impact, that while very small, can be measured under big load. Latency +# monitoring can easily be enabled at runtime using the command +# "CONFIG SET latency-monitor-threshold " if needed. +latency-monitor-threshold 0 + +############################# EVENT NOTIFICATION ############################## + +# Redis can notify Pub/Sub clients about events happening in the key space. +# This feature is documented at http://redis.io/topics/notifications +# +# For instance if keyspace events notification is enabled, and a client +# performs a DEL operation on key "foo" stored in the Database 0, two +# messages will be published via Pub/Sub: +# +# PUBLISH __keyspace@0__:foo del +# PUBLISH __keyevent@0__:del foo +# +# It is possible to select the events that Redis will notify among a set +# of classes. Every class is identified by a single character: +# +# K Keyspace events, published with __keyspace@__ prefix. +# E Keyevent events, published with __keyevent@__ prefix. +# g Generic commands (non-type specific) like DEL, EXPIRE, RENAME, ... +# $ String commands +# l List commands +# s Set commands +# h Hash commands +# z Sorted set commands +# x Expired events (events generated every time a key expires) +# e Evicted events (events generated when a key is evicted for maxmemory) +# A Alias for g$lshzxe, so that the "AKE" string means all the events. +# +# The "notify-keyspace-events" takes as argument a string that is composed +# of zero or multiple characters. The empty string means that notifications +# are disabled. +# +# Example: to enable list and generic events, from the point of view of the +# event name, use: +# +# notify-keyspace-events Elg +# +# Example 2: to get the stream of the expired keys subscribing to channel +# name __keyevent@0__:expired use: +# +# notify-keyspace-events Ex +# +# By default all notifications are disabled because most users don't need +# this feature and the feature has some overhead. Note that if you don't +# specify at least one of K or E, no events will be delivered. +notify-keyspace-events "" + +############################### ADVANCED CONFIG ############################### + +# Hashes are encoded using a memory efficient data structure when they have a +# small number of entries, and the biggest entry does not exceed a given +# threshold. These thresholds can be configured using the following directives. +hash-max-ziplist-entries 512 +hash-max-ziplist-value 64 + +# Lists are also encoded in a special way to save a lot of space. +# The number of entries allowed per internal list node can be specified +# as a fixed maximum size or a maximum number of elements. +# For a fixed maximum size, use -5 through -1, meaning: +# -5: max size: 64 Kb <-- not recommended for normal workloads +# -4: max size: 32 Kb <-- not recommended +# -3: max size: 16 Kb <-- probably not recommended +# -2: max size: 8 Kb <-- good +# -1: max size: 4 Kb <-- good +# Positive numbers mean store up to _exactly_ that number of elements +# per list node. +# The highest performing option is usually -2 (8 Kb size) or -1 (4 Kb size), +# but if your use case is unique, adjust the settings as necessary. +list-max-ziplist-size -2 + +# Lists may also be compressed. +# Compress depth is the number of quicklist ziplist nodes from *each* side of +# the list to *exclude* from compression. The head and tail of the list +# are always uncompressed for fast push/pop operations. Settings are: +# 0: disable all list compression +# 1: depth 1 means "don't start compressing until after 1 node into the list, +# going from either the head or tail" +# So: [head]->node->node->...->node->[tail] +# [head], [tail] will always be uncompressed; inner nodes will compress. +# 2: [head]->[next]->node->node->...->node->[prev]->[tail] +# 2 here means: don't compress head or head->next or tail->prev or tail, +# but compress all nodes between them. +# 3: [head]->[next]->[next]->node->node->...->node->[prev]->[prev]->[tail] +# etc. +list-compress-depth 0 + +# Sets have a special encoding in just one case: when a set is composed +# of just strings that happen to be integers in radix 10 in the range +# of 64 bit signed integers. +# The following configuration setting sets the limit in the size of the +# set in order to use this special memory saving encoding. +set-max-intset-entries 512 + +# Similarly to hashes and lists, sorted sets are also specially encoded in +# order to save a lot of space. This encoding is only used when the length and +# elements of a sorted set are below the following limits: +zset-max-ziplist-entries 128 +zset-max-ziplist-value 64 + +# HyperLogLog sparse representation bytes limit. The limit includes the +# 16 bytes header. When an HyperLogLog using the sparse representation crosses +# this limit, it is converted into the dense representation. +# +# A value greater than 16000 is totally useless, since at that point the +# dense representation is more memory efficient. +# +# The suggested value is ~ 3000 in order to have the benefits of +# the space efficient encoding without slowing down too much PFADD, +# which is O(N) with the sparse encoding. The value can be raised to +# ~ 10000 when CPU is not a concern, but space is, and the data set is +# composed of many HyperLogLogs with cardinality in the 0 - 15000 range. +hll-sparse-max-bytes 3000 + +# Active rehashing uses 1 millisecond every 100 milliseconds of CPU time in +# order to help rehashing the main Redis hash table (the one mapping top-level +# keys to values). The hash table implementation Redis uses (see dict.c) +# performs a lazy rehashing: the more operation you run into a hash table +# that is rehashing, the more rehashing "steps" are performed, so if the +# server is idle the rehashing is never complete and some more memory is used +# by the hash table. +# +# The default is to use this millisecond 10 times every second in order to +# actively rehash the main dictionaries, freeing memory when possible. +# +# If unsure: +# use "activerehashing no" if you have hard latency requirements and it is +# not a good thing in your environment that Redis can reply from time to time +# to queries with 2 milliseconds delay. +# +# use "activerehashing yes" if you don't have such hard requirements but +# want to free memory asap when possible. +activerehashing yes + +# The client output buffer limits can be used to force disconnection of clients +# that are not reading data from the server fast enough for some reason (a +# common reason is that a Pub/Sub client can't consume messages as fast as the +# publisher can produce them). +# +# The limit can be set differently for the three different classes of clients: +# +# normal -> normal clients including MONITOR clients +# slave -> slave clients +# pubsub -> clients subscribed to at least one pubsub channel or pattern +# +# The syntax of every client-output-buffer-limit directive is the following: +# +# client-output-buffer-limit +# +# A client is immediately disconnected once the hard limit is reached, or if +# the soft limit is reached and remains reached for the specified number of +# seconds (continuously). +# So for instance if the hard limit is 32 megabytes and the soft limit is +# 16 megabytes / 10 seconds, the client will get disconnected immediately +# if the size of the output buffers reach 32 megabytes, but will also get +# disconnected if the client reaches 16 megabytes and continuously overcomes +# the limit for 10 seconds. +# +# By default normal clients are not limited because they don't receive data +# without asking (in a push way), but just after a request, so only +# asynchronous clients may create a scenario where data is requested faster +# than it can read. +# +# Instead there is a default limit for pubsub and slave clients, since +# subscribers and slaves receive data in a push fashion. +# +# Both the hard or the soft limit can be disabled by setting them to zero. +client-output-buffer-limit normal 0 0 0 +client-output-buffer-limit slave 256mb 64mb 60 +client-output-buffer-limit pubsub 32mb 8mb 60 + +# Redis calls an internal function to perform many background tasks, like +# closing connections of clients in timeout, purging expired keys that are +# never requested, and so forth. +# +# Not all tasks are performed with the same frequency, but Redis checks for +# tasks to perform according to the specified "hz" value. +# +# By default "hz" is set to 10. Raising the value will use more CPU when +# Redis is idle, but at the same time will make Redis more responsive when +# there are many keys expiring at the same time, and timeouts may be +# handled with more precision. +# +# The range is between 1 and 500, however a value over 100 is usually not +# a good idea. Most users should use the default of 10 and raise this up to +# 100 only in environments where very low latency is required. +hz 10 + +# When a child rewrites the AOF file, if the following option is enabled +# the file will be fsync-ed every 32 MB of data generated. This is useful +# in order to commit the file to the disk more incrementally and avoid +# big latency spikes. +aof-rewrite-incremental-fsync yes + +# Redis LFU eviction (see maxmemory setting) can be tuned. However it is a good +# idea to start with the default settings and only change them after investigating +# how to improve the performances and how the keys LFU change over time, which +# is possible to inspect via the OBJECT FREQ command. +# +# There are two tunable parameters in the Redis LFU implementation: the +# counter logarithm factor and the counter decay time. It is important to +# understand what the two parameters mean before changing them. +# +# The LFU counter is just 8 bits per key, it's maximum value is 255, so Redis +# uses a probabilistic increment with logarithmic behavior. Given the value +# of the old counter, when a key is accessed, the counter is incremented in +# this way: +# +# 1. A random number R between 0 and 1 is extracted. +# 2. A probability P is calculated as 1/(old_value*lfu_log_factor+1). +# 3. The counter is incremented only if R < P. +# +# The default lfu-log-factor is 10. This is a table of how the frequency +# counter changes with a different number of accesses with different +# logarithmic factors: +# +# +--------+------------+------------+------------+------------+------------+ +# | factor | 100 hits | 1000 hits | 100K hits | 1M hits | 10M hits | +# +--------+------------+------------+------------+------------+------------+ +# | 0 | 104 | 255 | 255 | 255 | 255 | +# +--------+------------+------------+------------+------------+------------+ +# | 1 | 18 | 49 | 255 | 255 | 255 | +# +--------+------------+------------+------------+------------+------------+ +# | 10 | 10 | 18 | 142 | 255 | 255 | +# +--------+------------+------------+------------+------------+------------+ +# | 100 | 8 | 11 | 49 | 143 | 255 | +# +--------+------------+------------+------------+------------+------------+ +# +# NOTE: The above table was obtained by running the following commands: +# +# redis-benchmark -n 1000000 incr foo +# redis-cli object freq foo +# +# NOTE 2: The counter initial value is 5 in order to give new objects a chance +# to accumulate hits. +# +# The counter decay time is the time, in minutes, that must elapse in order +# for the key counter to be divided by two (or decremented if it has a value +# less <= 10). +# +# The default value for the lfu-decay-time is 1. A Special value of 0 means to +# decay the counter every time it happens to be scanned. +# +# lfu-log-factor 10 +# lfu-decay-time 1 + +########################### ACTIVE DEFRAGMENTATION ####################### +# +# WARNING THIS FEATURE IS EXPERIMENTAL. However it was stress tested +# even in production and manually tested by multiple engineers for some +# time. +# +# What is active defragmentation? +# ------------------------------- +# +# Active (online) defragmentation allows a Redis server to compact the +# spaces left between small allocations and deallocations of data in memory, +# thus allowing to reclaim back memory. +# +# Fragmentation is a natural process that happens with every allocator (but +# less so with Jemalloc, fortunately) and certain workloads. Normally a server +# restart is needed in order to lower the fragmentation, or at least to flush +# away all the data and create it again. However thanks to this feature +# implemented by Oran Agra for Redis 4.0 this process can happen at runtime +# in an "hot" way, while the server is running. +# +# Basically when the fragmentation is over a certain level (see the +# configuration options below) Redis will start to create new copies of the +# values in contiguous memory regions by exploiting certain specific Jemalloc +# features (in order to understand if an allocation is causing fragmentation +# and to allocate it in a better place), and at the same time, will release the +# old copies of the data. This process, repeated incrementally for all the keys +# will cause the fragmentation to drop back to normal values. +# +# Important things to understand: +# +# 1. This feature is disabled by default, and only works if you compiled Redis +# to use the copy of Jemalloc we ship with the source code of Redis. +# This is the default with Linux builds. +# +# 2. You never need to enable this feature if you don't have fragmentation +# issues. +# +# 3. Once you experience fragmentation, you can enable this feature when +# needed with the command "CONFIG SET activedefrag yes". +# +# The configuration parameters are able to fine tune the behavior of the +# defragmentation process. If you are not sure about what they mean it is +# a good idea to leave the defaults untouched. + +# Enabled active defragmentation +# activedefrag yes + +# Minimum amount of fragmentation waste to start active defrag +# active-defrag-ignore-bytes 100mb + +# Minimum percentage of fragmentation to start active defrag +# active-defrag-threshold-lower 10 + +# Maximum percentage of fragmentation at which we use maximum effort +# active-defrag-threshold-upper 100 + +# Minimal effort for defrag in CPU percentage +# active-defrag-cycle-min 25 + +# Maximal effort for defrag in CPU percentage +# active-defrag-cycle-max 75 + diff --git a/states/roles/maintain/gitlabarch/conf_files/resque.yml b/states/roles/maintain/gitlabarch/conf_files/resque.yml new file mode 100644 index 0000000..6c7944f --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/resque.yml @@ -0,0 +1,34 @@ +# If you change this file in a Merge Request, please also create +# a Merge Request on https://gitlab.com/gitlab-org/omnibus-gitlab/merge_requests +# +development: + url: unix:/run/redis/redis.sock + # sentinels: + # - + # host: localhost + # port: 26380 # point to sentinel, not to redis port + # - + # host: slave2 + # port: 26381 # point to sentinel, not to redis port +test: + url: unix:/run/redis/redis.sock +production: + # Redis (single instance) + url: unix:/run/redis/redis.sock + ## + # Redis + Sentinel (for HA) + # + # Please read instructions carefully before using it as you may lose data: + # http://redis.io/topics/sentinel + # + # You must specify a list of a few sentinels that will handle client connection + # please read here for more information: https://docs.gitlab.com/ce/administration/high_availability/redis.html + ## + # url: redis://master:6379 + # sentinels: + # - + # host: slave1 + # port: 26379 # point to sentinel, not to redis port + # - + # host: slave2 + # port: 26379 # point to sentinel, not to redis port diff --git a/states/roles/maintain/gitlabarch/conf_files/smtp_settings.rb b/states/roles/maintain/gitlabarch/conf_files/smtp_settings.rb new file mode 100644 index 0000000..ebc93e9 --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/smtp_settings.rb @@ -0,0 +1,23 @@ +# To enable smtp email delivery for your GitLab instance do the following: +# 1. Rename this file to smtp_settings.rb +# 2. Edit settings inside this file +# 3. Restart GitLab instance +# +# For full list of options and their values see http://api.rubyonrails.org/classes/ActionMailer/Base.html +# +# If you change this file in a Merge Request, please also create a Merge Request on https://gitlab.com/gitlab-org/omnibus-gitlab/merge_requests + +if Rails.env.production? + Rails.application.config.action_mailer.delivery_method = :smtp + + ActionMailer::Base.delivery_method = :smtp + ActionMailer::Base.smtp_settings = { + authentication: :plain, + address: "smtp.zoho.com", + port: 587, + user_name: "notifications@actcur.com", + password: "{%- include 'secure/passwords/gitlab_smtp_password.txt' -%}", + domain: "smtp.zoho.com", + enable_starttls_auto: true, + } +end diff --git a/states/roles/maintain/gitlabarch/conf_files/tmp_redis.conf b/states/roles/maintain/gitlabarch/conf_files/tmp_redis.conf new file mode 100644 index 0000000..773b8ea --- /dev/null +++ b/states/roles/maintain/gitlabarch/conf_files/tmp_redis.conf @@ -0,0 +1 @@ +d /run/redis 0755 redis redis - diff --git a/states/roles/maintain/gitlabarch/init.sls b/states/roles/maintain/gitlabarch/init.sls new file mode 100644 index 0000000..2351299 --- /dev/null +++ b/states/roles/maintain/gitlabarch/init.sls @@ -0,0 +1,175 @@ +gitlab: + pkg.installed +mariadb: + pkg.installed +gitlab_nginx: + pkg.installed: + - name: nginx + +#managed files +/etc/webapps/gitlab/gitlab.yml: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/gitlab.yml + - user: root + - group: root + - mode: 644 +/etc/webapps/gitlab/database.yml: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/database.yml + - user: gitlab + - group: gitlab + - mode: 600 + - template: jinja +/etc/webapps/gitlab/resque.yml: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/resque.yml + - user: root + - group: root + - mode: 644 +/etc/webapps/gitlab-shell/config.yml: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/config.yml + - user: gitlab + - group: gitlab + - mode: 600 +/usr/share/webapps/gitlab/config/initializers/smtp_settings.rb: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/smtp_settings.rb + - user: root + - group: root + - mode: 644 + - template: jinja +/usr/share/webapps/gitlab/config/environments/production.rb: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/production.rb + - user: root + - group: root + - mode: 644 +/etc/redis.conf: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/redis.conf + - user: root + - group: root + - mode: 644 +/etc/tempfiles.d/redis.conf: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/tmp_redis.conf + - user: root + - group: root + - mode: 644 + - makedirs: true +/etc/nginx/conf.d/gitlab.conf: + file.managed: + - source: salt://roles/maintain/gitlab/conf_files/gitlab.conf + - user: root + - group: root + - makedirs: true + - dir_mode: 755 + - mode: 644 + +#add users git and gitlab to redis group +git_user: + user.present: + - name: git + - groups: + - redis +gitlab_user: + user.present: + - name: gitlab + - groups: + - redis + +#migrate redis database as gitlab user if necessary +redis-running: + service.running: + - name: redis + - enable: true + - watch: + - file: /etc/redis.conf + - file: /etc/tempfiles.d/redis.conf +gitlab_rake_db: + cmd.run: + - name: "bundle-2.3 exec rake db:migrate RAILS_ENV=production" + - cwd: "/usr/share/webapps/gitlab" + - runas: gitlab + - watch: + - pkg: gitlab + +#global git configuration +gitlab_git_name: + git.config_set: + - name: user.name + - value: "Actaeus Curabitur" + - user: gitlab + - global: true +gitlab_git_email: + git.config_set: + - name: user.email + - value: "actcur@actcur.com" + - user: gitlab + - global: true +gitlab_git_crlf: + git.config_set: + - name: core.autocrlf + - value: "input" + - user: gitlab + - global: true + +#create symlink +symlink_repos: + file.symlink: + - name: /var/lib/gitlab/repositories + - target: /mnt/repos + - force: true +#verify perms for repos are right +/var/lib/gitlab/repositories/: + file.directory: + - user: gitlab + - group: gitlab + - dir_mode: 4770 + +#start services +gitlab.target: + service.running: + - enable: true + - watch: + - file: /etc/webapps/gitlab/gitlab.yml + - file: /etc/webapps/gitlab/database.yml + - file: /etc/webapps/gitlab/resque.yml + - file: /etc/webapps/gitlab-shell/config.yml + - file: /etc/nginx/conf.d/gitlab.conf + - file: /usr/share/webapps/gitlab/config/initializers/smtp_settings.rb + - file: /usr/share/webapps/gitlab/config/environments/production.rb +gitlab-workhorse: + service.running: + - enable: true + - watch: + - file: /etc/webapps/gitlab/gitlab.yml + - file: /etc/webapps/gitlab/database.yml + - file: /etc/webapps/gitlab/resque.yml + - file: /etc/webapps/gitlab-shell/config.yml + - file: /etc/nginx/conf.d/gitlab.conf + - file: /usr/share/webapps/gitlab/config/initializers/smtp_settings.rb + - file: /usr/share/webapps/gitlab/config/environments/production.rb +gitlab-unicorn: + service.running: + - enable: true + - watch: + - file: /etc/webapps/gitlab/gitlab.yml + - file: /etc/webapps/gitlab/database.yml + - file: /etc/webapps/gitlab/resque.yml + - file: /etc/webapps/gitlab-shell/config.yml + - file: /etc/nginx/conf.d/gitlab.conf + - file: /usr/share/webapps/gitlab/config/initializers/smtp_settings.rb + - file: /usr/share/webapps/gitlab/config/environments/production.rb +gitlab-sidekiq: + service.running: + - enable: true + - watch: + - file: /etc/webapps/gitlab/gitlab.yml + - file: /etc/webapps/gitlab/database.yml + - file: /etc/webapps/gitlab/resque.yml + - file: /etc/webapps/gitlab-shell/config.yml + - file: /etc/nginx/conf.d/gitlab.conf + - file: /usr/share/webapps/gitlab/config/initializers/smtp_settings.rb + - file: /usr/share/webapps/gitlab/config/environments/production.rb diff --git a/states/roles/maintain/glances/certs b/states/roles/maintain/glances/certs deleted file mode 120000 index 1f4d9d6..0000000 --- a/states/roles/maintain/glances/certs +++ /dev/null @@ -1 +0,0 @@ -/etc/letsencrypt/live/ \ No newline at end of file diff --git a/states/roles/maintain/glances/init.sls b/states/roles/maintain/glances/init.sls index 233123c..77b9290 100644 --- a/states/roles/maintain/glances/init.sls +++ b/states/roles/maintain/glances/init.sls @@ -31,7 +31,7 @@ nginx: {%- for name in pillar['nginx'] %} "/etc/nginx/certs/{{name}}.actcur.com/": file.recurse: - - source: salt://roles/maintain/nginx-proxy/certs/{{name}}.actcur.com/ + - source: salt://secure/certs/{{name}}.actcur.com/ {%- if os=="CentOS" or os=="RedHat" %} - user: nginx - user: nginx @@ -76,7 +76,7 @@ nginx: "/etc/nginx/certs/portal.actcur.com/": file.recurse: - - source: salt://roles/maintain/nginx-proxy/certs/portal.actcur.com/ + - source: salt://secure/certs/portal.actcur.com/ - user: http - group: http - dir_mode: 755 diff --git a/states/roles/maintain/ldap/certs b/states/roles/maintain/ldap/certs deleted file mode 120000 index 1f4d9d6..0000000 --- a/states/roles/maintain/ldap/certs +++ /dev/null @@ -1 +0,0 @@ -/etc/letsencrypt/live/ \ No newline at end of file diff --git a/states/roles/maintain/ldap/init.sls b/states/roles/maintain/ldap/init.sls index a6cd60a..9ee2ef3 100644 --- a/states/roles/maintain/ldap/init.sls +++ b/states/roles/maintain/ldap/init.sls @@ -9,7 +9,7 @@ openldap: /etc/openldap/certs/: file.recurse: - - source: salt://roles/maintain/nginx-proxy/certs/ldap.actcur.com/ + - source: salt://secure/certs/ldap.actcur.com/ - user: ldap - group: ldap - dir_mode: 755 @@ -92,4 +92,3 @@ own_data: - user: ldap - group: ldap - mode: 644 - diff --git a/states/roles/maintain/nginx-proxy/certs b/states/roles/maintain/nginx-proxy/certs deleted file mode 120000 index 1f4d9d6..0000000 --- a/states/roles/maintain/nginx-proxy/certs +++ /dev/null @@ -1 +0,0 @@ -/etc/letsencrypt/live/ \ No newline at end of file diff --git a/states/roles/maintain/nginx-proxy/init.sls b/states/roles/maintain/nginx-proxy/init.sls index 78cea2d..319a0f3 100644 --- a/states/roles/maintain/nginx-proxy/init.sls +++ b/states/roles/maintain/nginx-proxy/init.sls @@ -35,7 +35,7 @@ nginx: {%- for name in pillar['nginx'] %} "/etc/nginx/certs/{{name}}.actcur.com/": file.recurse: - - source: salt://roles/maintain/nginx-proxy/certs/{{name}}.actcur.com/ + - source: salt://secure/certs/{{name}}.actcur.com/ {%- if os=="CentOS" or os=="RedHat" %} - user: nginx - user: nginx @@ -44,7 +44,7 @@ nginx: - group: http {%- endif %} - dir_mode: 755 - - file:mode: 400 + - file_mode: 400 - clean: true /etc/nginx/conf.d/{{ name }}.conf: @@ -80,10 +80,10 @@ nginx: "/etc/nginx/certs/portal.actcur.com/": file.recurse: - - source: salt://roles/maintain/nginx-proxy/certs/portal.actcur.com/ + - source: salt://secure/certs/portal.actcur.com/ - user: http - group: http - dir_mode: 755 - - file:mode: 400 + - file_mode: 400 - clean: true {%- endif -%} diff --git a/states/roles/maintain/vpnserver/init.sls b/states/roles/maintain/vpnserver/init.sls new file mode 100644 index 0000000..0c8c55d --- /dev/null +++ b/states/roles/maintain/vpnserver/init.sls @@ -0,0 +1,17 @@ +vpn-server: + pkg.installed: + - name: openvpn + +#generate diff-hellman param files +#build only +gen-dh-param: + cmd.run: + - name: "openssl dhparam -out /etc/openvpn/server/dh.pem 2048" + - onlyif: 'test ! -e /etc/openvpn/server/dh.pem' + +#generate hmac key +#build only +gen-hmac-key: + cmd.run: + - name: "openvpn --genkey --secret /etc/openvpn/server/ta.key" + - onlyif: 'test ! -e /etc/openvpn/server/ta.key' diff --git a/states/systems/core/backup/init.sls b/states/systems/core/backup/init.sls index 5da37b2..eea95e9 100644 --- a/states/systems/core/backup/init.sls +++ b/states/systems/core/backup/init.sls @@ -11,7 +11,7 @@ {{ name }}_key: file.managed: - name: /root/.ssh/{{ pillar['backup'][name]['key'] }} - - source: salt://systems/core/backup/keys/{{ pillar['backup'][name]['key'] }} + - source: salt://secure/keys/backup/{{ pillar['backup'][name]['key'] }} - user: root - group: root - mode: 600 diff --git a/states/systems/core/git/init.sls b/states/systems/core/git/init.sls index 8b5f1c2..f074c27 100644 --- a/states/systems/core/git/init.sls +++ b/states/systems/core/git/init.sls @@ -12,7 +12,7 @@ git_pkg: {{ repo }}_key: file.managed: - name: /root/.ssh/{{ pillar['git'][repo]['key'] }} - - source: salt://systems/core/git/keys/{{ pillar['git'][repo]['key'] }} + - source: salt://secure/keys/git/{{ pillar['git'][repo]['key'] }} - user: root - group: root - mode: 600 diff --git a/states/systems/core/git/keys b/states/systems/core/git/keys deleted file mode 120000 index 2feebc4..0000000 --- a/states/systems/core/git/keys +++ /dev/null @@ -1 +0,0 @@ -/keys/git/ \ No newline at end of file diff --git a/states/systems/core/mount/init.sls b/states/systems/core/mount/init.sls old mode 100755 new mode 100644 index d54378c..0b72676 --- a/states/systems/core/mount/init.sls +++ b/states/systems/core/mount/init.sls @@ -45,7 +45,7 @@ mount_host.actcur.com: {{ mount }}_key: file.managed: - name: /root/.ssh/{{user}}_key - - source: salt://systems/core/mount/keys/{{user}}_key + - source: salt://secure/keys/mount/{{user}}_key - user: root - group: root - mode: 600 diff --git a/states/systems/core/mount/keys b/states/systems/core/mount/keys deleted file mode 120000 index e0ecba1..0000000 --- a/states/systems/core/mount/keys +++ /dev/null @@ -1 +0,0 @@ -/keys/mount/ \ No newline at end of file diff --git a/states/top.sls b/states/top.sls old mode 100755 new mode 100644 diff --git a/test b/test old mode 100755 new mode 100644