Commit graph

93 commits

Author SHA1 Message Date
79c731ccd3 replaced ip addresses with hostnames 2025-04-01 17:14:28 +00:00
7f5496c9c9 populate ip address based on hostname and populate the hostfile with other vm ips 2025-04-01 17:14:28 +00:00
1a819e1ca4
Disable spam checking 2025-03-30 09:04:27 +02:00
daf3a05b4e Alias file update 2025-03-30 07:01:45 +00:00
ef27fda73a Fix syntax error 2025-03-30 07:01:26 +00:00
298864af66
Update SOPS files for new encryption key
Result of `find . -name '*.secrets.yaml' -exec sops updatekeys --yes {} \;`
2025-03-29 13:12:10 +01:00
totallynotadolphin
76324cbec1 remove trailing whitespace 2025-03-29 11:33:06 +01:00
totallynotadolphin
b978c4c71e Create new user and add keys for totallynotadolphin 2025-03-29 11:09:39 +01:00
4aaff89e95
satisfied alejandra 2025-03-26 22:23:37 +01:00
98fe80676d
Fix DKIM config 2025-03-26 14:40:45 +01:00
c078a05ad0 Fix e-mail regex. Apostrophes are allowed in local parts but we use them to deliminate strings in the sieve script. 2025-03-24 19:38:05 +00:00
ee26c2a42a Update alias file 2025-03-24 19:38:05 +00:00
327d4ec34e Move sieve generator script to stalwart-mail service and make all respective /tmp folders private 2025-03-24 19:38:05 +00:00
a469194bce Enable SMTPUTF8. We talk to our own VM that supports it. 2025-03-24 19:38:05 +00:00
3300389ac8 More comments 2025-03-24 19:38:05 +00:00
f7d555471b Rename secret files to have 'secrets.yaml' suffix. 2025-03-24 19:38:05 +00:00
737e66f822 Increase limits for our redirect script to be higher than our number of aliases 2025-03-24 19:38:05 +00:00
b13aa775c8 Only set original sender for MAIL FROM 2025-03-24 19:38:05 +00:00
6acb1aaed5 Alias file update 2025-03-24 19:38:05 +00:00
0e8d4eb121 Group config parameters 2025-03-24 19:38:05 +00:00
9c83e40da6 Enable DKIM signing 2025-03-24 19:38:05 +00:00
0cbc7041b7 Filter out catch-all addresses of the form "@domain.tld" from the allowlist that are not intended for HRZ 2025-03-24 19:38:05 +00:00
3258fbc2e3 Set sender and increase redirect limit for our alias file 2025-03-24 19:38:05 +00:00
3918ca5fec Accept mail from our badly configured VMs 2025-03-24 19:38:05 +00:00
b0268f9d24 Add mathebau.de to certificate 2025-03-24 19:38:05 +00:00
0407561faf Rename config option after update beyond version 0.11.2 2025-03-24 19:38:05 +00:00
00e774edf9 Disable matheball.de forwards and submission to mail allowlist until we actually handle it 2025-03-24 19:38:05 +00:00
60b7eef25e Allow unpacking stalwart's webadmin interface 2025-03-24 19:38:05 +00:00
69c4ccc0d8 Delete directive proxy_interface
This directive is supposed to prevent mail delivery loops that would be caused by portforwarding to itself.
Behind this ip address, however, there is our general mail vm and not immediately the mailinglist setup.
2025-03-24 19:38:05 +00:00
4f3efdf496 Don't fail installer machine if no drives to install on are mounted 2025-03-06 09:49:08 +01:00
064aca1705
renamed secret files so they are easier to shell glob 2025-03-05 21:11:38 +01:00
e5e3fab14d
reencrypted secrets for Daniel 2025-03-05 20:53:01 +01:00
Daniel Simon
638b62591d Add SSH and Nix keys and password for daniel 2025-03-03 23:59:28 +01:00
0472063a76
new ssh key for nerf 2025-03-03 15:21:58 +01:00
753b34592c Increase root file system to make space for /tmp folder which needs lots of space during builds 2025-02-27 16:00:24 +00:00
cc91339f80 Address second round of review 2025-02-27 16:55:14 +01:00
361eed84af Rename machine to Nyarlathotep 2025-02-26 18:04:27 +01:00
70b3a694c4 Submit mailing list mails to correct vm based on port forwarding and run allowlist job less often 2025-02-26 12:34:44 +01:00
f0e584e239 Add patch to allow alias files to redirect to their sender 2025-02-26 12:34:44 +01:00
5a80d86bd3 Post mailaddresses to HRZ allowlist 2025-02-26 12:34:44 +01:00
7796b7aa00 Add mail forwarding based on alias files 2025-02-26 12:34:44 +01:00
d7b8f935cd Add basic mailserver configuration 2025-02-26 12:34:44 +01:00
2aa93c98f5 Add basic machine config for kaalut, a new mail vm 2025-02-26 12:34:44 +01:00
77bdd979b0 Align file system layout to new naming policy 2025-02-20 16:37:46 +01:00
35707122fa Add Nodens, a VM to install NixOS VMs 2025-02-20 16:37:32 +01:00
51c83c8ec0 Pass pkgs to machine configs to enable installation of packages there 2025-02-20 16:31:55 +01:00
ac85711356 Entferne Backupconfig für die Matheballwebseite
Die Bilder, die gesichert wurden, liegen jetzt alle im Git-Repo der Webseite
2024-10-16 16:32:06 +00:00
ec46a28278
nix config to save some space 2024-10-15 13:19:23 +02:00
e7154785dd Disable TLS behind proxies and relays 2024-10-12 14:10:01 +00:00
ace96d5f7c Restrict HRZ allowlist update service privileges 2024-10-12 14:10:01 +00:00