With Salt, sudo files content are now managed from rOPS.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Mon, Mar 23
Sun, Mar 22
Next: configure DNS records
Sat, Mar 21
Will need to be revisited when we switch to acme.sh.
Fri, Mar 20
Feb 5 2026
Patched it live.
Feb 3 2026
Nov 10 2025
Bruteforce attack scenario possible, so we're only interested by usernames defined in users.sls, not by "root" (can't login by SSH) or generic accounts like "docker" (doesn't exist):
Oct 25 2025
Oct 24 2025
Same issue for rhyne-wyse.log. Configuration was copied from acme.sh one.
Oct 20 2025
Oct 13 2025
Credentials have been hashed directly in Vault, so we don't need to manipulate cleartext password with Salt.
Salt updated the tomcat-users.xml accordingly.
Oct 11 2025
The full /etc/nginx directories on both docker-002 and dwellers use httpd_config_t for every file.
Oct 10 2025
Oct 9 2025
Alternatively, we made a lot of progress on this in T2124.
Oct 6 2025
Sep 23 2025
Sep 22 2025
Sep 18 2025
So, there is a new reason to do the upgrade.
Sep 14 2025
Sep 10 2025
First step is to create a script to renew all needed certificates:
May 18 2025
Apr 5 2025
Une fois que tu as retrouvé les accès SSH pour le web statique:
- WindRiver: automatiquement https://windriver.nasqueron.org/~xcombelle est disponible si tu places des fichiers dans /var/home-wwwroot/xcombelle (je ne sais plus si ça se crée automatiquement avec symlink vers $HOME/public_html, à vérifier)
- Eglide: https://www.eglide.org/~xcombelle pour $HOME/public_html
Nov 2 2024
Oct 27 2024
Oct 23 2024
Oct 13 2024
So, to get routing back:
Oct 12 2024
Not sure of the current benefit to use TC2.
This is still needed for acme.sh if we want to provision different *.nasqueron.org certificates on different servers.
Oct 9 2024
Salt SELinux module issue