aboutsummaryrefslogtreecommitdiffstats
path: root/manifests/nodes/alamut.pp
blob: 176da1cf67fdfa641d41569e5e023fb02ce9bbb9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
# web apps
node alamut {
# Location: IELO datacenter (marseille)
#
# TODO:
# - Review board
# - api
# - pastebin
# - LDAP slave
#
    include common::default_mageia_server_no_smtp
    include postgresql::server
    postgresql::tagged { 'old': }

    timezone::timezone { 'Europe/Paris': }

    class {'epoll::var':
        db_password => extlookup('epoll_pgsql','x'),
    }
    include epoll
    include epoll::create_db

    include sympa::server
    include postfix::server::primary

    include lists

    # temporary, just the time the vm is running there
    host { 'friteuse':
        ensure       => 'present',
        ip           => '192.168.122.131',
        host_aliases => [ "friteuse.${::domain}", "forums.${::domain}" ],
    }

    # to create all phpbb database on alamut
    phpbb::databases { $fqdn: }

    apache::vhost::redirect_ssl { "forums.${::domain}": }
    apache::vhost_redirect { "forum.${::domain}":
        url => "https://forums.${::domain}/",
    }
    apache::vhost_redirect { "ssl_forum.${::domain}":
        url     => "https://forums.${::domain}/",
        vhost   => "forum.${::domain}",
        use_ssl => true,
    }

    # connect to ssl so the proxy do not shoke if trying to
    # enforce ssl ( note that this has not been tested, maybe this
    # is uneeded )
    apache::vhost::reverse_proxy { "ssl_forums.${::domain}":
        url     => "https://forums.${::domain}/",
        vhost   => "forums.${::domain}",
        use_ssl => true,
        content => '
        RewriteEngine On
        RewriteCond %{QUERY_STRING} mode=register
        RewriteRule .*ucp.php - [forbidden]
        ',
    }

    include tld_redirections

    include libvirtd::kvm

    include wikis

    # Forward ports to arm1 and arm2 ssh, to access them from outside
    xinetd::port_forward {'forward_arm1':
        target_ip   => "arm1.${::domain}",
        target_port => '22',
        port        => '4251',
        proto       => 'tcp',
    }
    xinetd::port_forward {'forward_arm2':
        target_ip   => "arm2.${::domain}",
        target_port => '22',
        port        => '4252',
        proto       => 'tcp',
    }
}