Commit graph

63 commits

Author SHA1 Message Date
Marius Melzer
389b171401 Apply review comments 2024-04-24 20:03:44 +02:00
e70ab02fed Apply 6 suggestion(s) to 2 file(s) 2024-04-24 17:38:11 +00:00
882286e1a7 Apply 1 suggestion(s) to 1 file(s) 2024-04-24 17:33:35 +00:00
Marius Melzer
65b00c8840 Add ufw role
- Enable ufw and by default deny incoming traffic
- in other roles: if ufw (role) is enabled, then allow necessary ports
2024-04-20 17:08:39 +02:00
Marius Melzer
fcad5b9354 Add unattended upgrades
Enable unattended upgrades and triggers unattended reboots (23:55 after an
upgrade which needs reboot).

Attention: this is specific to debian-style linux systems (Debian, Ubuntu,...).
2024-04-20 15:24:38 +02:00
Marius Melzer
139ba7504a Add system-basics role
- set time zone
- limit journal size
- set vim as editor
- limit ssh login to pubkey
2024-04-20 15:23:38 +02:00
Marius Melzer
dcc52b04cc Generate dhparams instead of using a checked in file 2024-04-20 13:11:26 +02:00
Marius Melzer
a03e50c933 Harden nginx ssl/tls config
According to https://ssl-config.mozilla.org/
2024-04-19 00:28:45 +02:00
7f555a86c3 [mod] role:gitlab:SMTP-Anbindung hinzugefügt 2024-04-14 11:23:32 +02:00
a209387e20 [add] role:synapse:vardef 2024-04-12 20:19:57 +02:00
6c4e68298b [mod] role:synapse:Schalter für federation 2024-04-05 13:39:26 +02:00
00049a180d [fix] role:dokuwiki 2024-04-05 13:31:43 +02:00
59211fba86 [int] 2024-03-29 17:21:05 +01:00