The authz.mech option in configuration is no longer used.
[invirt/packages/xvm-prodconfig.git] / master.yaml
index 029624a..b967ce0 100644 (file)
@@ -1,23 +1,42 @@
-authn:
- - type: kerberos
-   realm: ATHENA.MIT.EDU
+contact: &contact xvm@mit.edu
+adminacl: &adminacl system:xvm-root
+priv_contact: &priv_contact xvm-root@mit.edu
+
+apt:
+ keyid: 35AE3C4F
 
 authz:
 
 authz:
- - type: afs
-   cell: athena.mit.edu
+ afs:
+  cells:
+  - cell: athena.mit.edu
+    auth: yes
+  - cell: sipb.mit.edu
+    auth: yes
+  - cell: zone.mit.edu
+    auth: yes
+  - cell: ops.mit.edu
+    auth: no
+  - cell: net.mit.edu
+    auth: no
+  - cell: dev.mit.edu
+    auth: no
 
 
-hosts: # hosts on which VMs run
- - hostname: citadel-station.mit.edu
-   ip: 18.181.0.221
- - hostname: aperture-science.mit.edu
-   ip: 18.181.0.222
- - hostname: shadow-moses.mit.edu
-   ip: 18.181.0.223
- - hostname: arklay-mansion.mit.edu
-   ip: 18.181.0.224
+build:
+ pockets:
+  prod:
+   acl: *adminacl
+   apt: stable
+  dev:
+   acl: system:xvm-dev
+   apt: unstable
+   allow_backtracking: yes
+ tagger:
+  name: Invirt Build Server
+  email: invirt@mit.edu
 
 
-apt:
- keyid: 35AE3C4F
+console:
+ hostname: xvm-console.mit.edu
+ ip: 18.181.0.134
 
 db:
  uri: postgres://invirt@xvm.mit.edu/invirt
 
 db:
  uri: postgres://invirt@xvm.mit.edu/invirt
@@ -27,45 +46,49 @@ db:
  user: invirt
  dbname: invirt
 
  user: invirt
  dbname: invirt
 
-remote:
- hostname: xvm-remote.mit.edu
- ip: 18.181.0.188
+dhcp:
+ gateway: 18.181.0.1
+ netmask: 255.255.0.0
+ dns:
+  - 18.70.0.160
+  - 18.71.0.151
+  - 18.72.0.3
+ search_domain: mit.edu
 
 dns:
 
 dns:
- contact: xvm@mit.edu
+ contact: *contact
  domains: # first one is advertised
   - xvm.mit.edu
  domains: # first one is advertised
   - xvm.mit.edu
+  - 2.181.18.in-addr.arpa
  nameservers:
   - hostname: xvm.mit.edu
     ip: 18.181.0.62
  zone_files:
   - /etc/invirt/zone
 
  nameservers:
   - hostname: xvm.mit.edu
     ip: 18.181.0.62
  zone_files:
   - /etc/invirt/zone
 
-dhcp:
- gateway: 18.181.0.1
- netmask: 255.255.0.0
- dns:
-  - 18.70.0.160
-  - 18.71.0.151
-  - 18.72.0.3
- search_domain: mit.edu
+hosts: # hosts on which VMs run
+ - hostname: citadel-station.mit.edu
+   ip: 18.181.0.221
+ - hostname: aperture-science.mit.edu
+   ip: 18.181.0.222
+ - hostname: shadow-moses.mit.edu
+   ip: 18.181.0.223
+ - hostname: arklay-mansion.mit.edu
+   ip: 18.181.0.224
 
 
-web:
- baseuri: https://xvm.mit.edu/
- hostname: xvm.mit.edu
-. errormail: xvm@mit.edu
- adminacl: system:xvm-root
- errormail_exclude:
-  - broder
-  - price
-  - ecprice
-  - andersk
-  - quentin
-  - hartmans
+kerberos:
+ realm: ATHENA.MIT.EDU
 
 
-console:
- hostname: xvm-console.mit.edu
- ip: 18.181.0.134
+mail:
+ forward: *priv_contact
+
+monitoring:
+ - hostname: syn.mit.edu
+   ip: 18.181.0.65
+
+remote:
+ hostname: xvm-remote.mit.edu
+ ip: 18.181.0.188
 
 svn:
  repopath: /afs/sipb.mit.edu/project/xvm/svn
 
 svn:
  repopath: /afs/sipb.mit.edu/project/xvm/svn
@@ -77,3 +100,19 @@ trac:
 vnc:
  base_port: 10003
  proxy_ip: 18.181.0.62
 vnc:
  base_port: 10003
  proxy_ip: 18.181.0.62
+
+web:
+ baseuri: https://xvm.mit.edu/
+ hostname: xvm.mit.edu
+ errormail: *contact
+ errormail_exclude:
+  - broder
+  - price
+  - ecprice
+  - andersk
+  - quentin
+  - hartmans
+
+xen:
+ network:
+  iface: eth2