The authz.mech option in configuration is no longer used.
[invirt/packages/xvm-prodconfig.git] / master.yaml
index 2114b4e..b967ce0 100644 (file)
@@ -1,46 +1,51 @@
-authn:
- - type: kerberos
-   realm: ATHENA.MIT.EDU
+contact: &contact xvm@mit.edu
+adminacl: &adminacl system:xvm-root
+priv_contact: &priv_contact xvm-root@mit.edu
+
+apt:
+ keyid: 35AE3C4F
 
 authz:
 
 authz:
- - type: afs
-   cell: athena.mit.edu
+ afs:
+  cells:
+  - cell: athena.mit.edu
+    auth: yes
+  - cell: sipb.mit.edu
+    auth: yes
+  - cell: zone.mit.edu
+    auth: yes
+  - cell: ops.mit.edu
+    auth: no
+  - cell: net.mit.edu
+    auth: no
+  - cell: dev.mit.edu
+    auth: no
 
 
-hosts: # hosts on which VMs run
- - hostname: citadel-station.mit.edu
-   ip: 18.181.0.221
- - hostname: aperture-science.mit.edu
-   ip: 18.181.0.222
- - hostname: shadow-moses.mit.edu
-   ip: 18.181.0.223
- - hostname: arklay-mansion.mit.edu
-   ip: 18.181.0.224
+build:
+ pockets:
+  prod:
+   acl: *adminacl
+   apt: stable
+  dev:
+   acl: system:xvm-dev
+   apt: unstable
+   allow_backtracking: yes
+ tagger:
+  name: Invirt Build Server
+  email: invirt@mit.edu
 
 
-apt:
- keyid: 35AE3C4F
+console:
+ hostname: xvm-console.mit.edu
+ ip: 18.181.0.134
 
 db:
 
 db:
- uri: postgres://invirt@xvm-dev.mit.edu/invirt
- host: xvm-dev.mit.edu
- ip: 18.181.0.80
+ uri: postgres://invirt@xvm.mit.edu/invirt
+ host: xvm.mit.edu
+ ip: 18.181.0.62
  port: 5432
  user: invirt
  dbname: invirt
 
  port: 5432
  user: invirt
  dbname: invirt
 
-remote:
- hostname: xvm-remote-dev.mit.edu
- ip: 18.181.0.231
-
-dns:
- contact: xvm@mit.edu
- domains: # first one is advertised
-  - prod.xvm.mit.edu
- nameservers:
-  - hostname: xvm-dev.mit.edu
-    ip: 18.181.0.80
- zone_files:
-  - /etc/invirt/zone
-
 dhcp:
  gateway: 18.181.0.1
  netmask: 255.255.0.0
 dhcp:
  gateway: 18.181.0.1
  netmask: 255.255.0.0
@@ -50,28 +55,64 @@ dhcp:
   - 18.72.0.3
  search_domain: mit.edu
 
   - 18.72.0.3
  search_domain: mit.edu
 
-web:
- baseuri: https://xvm-dev.mit.edu/
- hostname: xvm-dev.mit.edu
- errormail: xvm@mit.edu
- adminacl: system:xvm-webacl
- errormail_exclude:
-  - '*'
-  - price
-  - ecprice
-  - andersk
+dns:
+ contact: *contact
+ domains: # first one is advertised
+  - xvm.mit.edu
+  - 2.181.18.in-addr.arpa
+ nameservers:
+  - hostname: xvm.mit.edu
+    ip: 18.181.0.62
+ zone_files:
+  - /etc/invirt/zone
 
 
-console:
- hostname: xvm-console-dev.mit.edu
- ip: 18.181.0.230
+hosts: # hosts on which VMs run
+ - hostname: citadel-station.mit.edu
+   ip: 18.181.0.221
+ - hostname: aperture-science.mit.edu
+   ip: 18.181.0.222
+ - hostname: shadow-moses.mit.edu
+   ip: 18.181.0.223
+ - hostname: arklay-mansion.mit.edu
+   ip: 18.181.0.224
+
+kerberos:
+ realm: ATHENA.MIT.EDU
+
+mail:
+ forward: *priv_contact
+
+monitoring:
+ - hostname: syn.mit.edu
+   ip: 18.181.0.65
+
+remote:
+ hostname: xvm-remote.mit.edu
+ ip: 18.181.0.188
 
 svn:
  repopath: /afs/sipb.mit.edu/project/xvm/svn
 
 svn:
  repopath: /afs/sipb.mit.edu/project/xvm/svn
- uri: https://xvm-dev.mit.edu:1111
+ uri: https://xvm.mit.edu:1111
 
 trac:
 
 trac:
- uri: https://xvm.mit.edu/trac/wiki
+ uri: https://xvm.scripts.mit.edu
 
 vnc:
  base_port: 10003
 
 vnc:
  base_port: 10003
- proxy_ip: 18.181.0.80
+ proxy_ip: 18.181.0.62
+
+web:
+ baseuri: https://xvm.mit.edu/
+ hostname: xvm.mit.edu
+ errormail: *contact
+ errormail_exclude:
+  - broder
+  - price
+  - ecprice
+  - andersk
+  - quentin
+  - hartmans
+
+xen:
+ network:
+  iface: eth2