As noted in the invirt.authz.locker._authenticate docstring, if we
[invirt/packages/xvm-prodconfig.git] / master.yaml
index cc03b96..896df3b 100644 (file)
@@ -1,17 +1,25 @@
 contact: &contact xvm@mit.edu
-adminacl: system:xvm-root
+adminacl: &adminacl system:xvm-root
 priv_contact: &priv_contact xvm-root@mit.edu
 
 apt:
  keyid: 35AE3C4F
 
 authz:
- - type: afs
-   cell: athena.mit.edu
+ mech: invirt.authz.locker
+ cells:
+ - cell: athena.mit.edu
    auth: yes
- - type: afs
-   cell: sipb.mit.edu
+ - cell: sipb.mit.edu
    auth: yes
+ - cell: zone.mit.edu
+   auth: yes
+ - cell: ops.mit.edu
+   auth: no
+ - cell: net.mit.edu
+   auth: no
+ - cell: dev.mit.edu
+   auth: no
 
 console:
  hostname: xvm-console.mit.edu
@@ -46,13 +54,17 @@ dns:
   - /etc/invirt/zone
 
 git:
- branches:
+ pockets:
   prod:
    acl: *adminacl
-   component: stable
+   apt: stable
   dev:
    acl: system:xvm-dev
-   component: unstable
+   apt: unstable
+   allow_backtracking: yes
+ tagger:
+  name: Invirt Build Server
+  email: invirt@mit.edu
 
 hosts: # hosts on which VMs run
  - hostname: citadel-station.mit.edu