diff --git a/playbooks/check-etc.yml b/playbooks/check-etc.yml index 899b06d924..506a6b8ae0 100644 --- a/playbooks/check-etc.yml +++ b/playbooks/check-etc.yml @@ -8,18 +8,37 @@ vars: # Add files here for things that store data in /etc/ known_prefixes: + - /etc/builder-keytabs + - /etc/containers/systemd/ipatuura.container - /etc/dnf/modules.d + - /etc/dirsrv/slapd-FEDORAPROJECT-ORG + - /etc/dirsrv/slapd-STG-FEDORAPROJECT-ORG + - /etc/gconf/gconf.xml.defaults + - /etc/ipa-tuura + - /etc/ipatuura-container-config + - /etc/java/java-11-openjdk # rpm:*.aarch64/lib/security/blacklisted.certs + - /etc/letsencrypt/accounts + - /etc/letsencrypt/archive + - /etc/letsencrypt/csr + - /etc/letsencrypt/keys + - /etc/letsencrypt/live # ? + - /etc/letsencrypt/renewal # ? - /etc/lvm/archive - /etc/lvm/backup - /etc/lvm/devices/backup - - /etc/dirsrv/slapd-STG-FEDORAPROJECT-ORG - /etc/libvirt/storage - /etc/libvirt/qemu + - /etc/mailman3/__pycache__ + - /etc/mock/koji - /etc/NetworkManager/system-connections + - /etc/nagios # Getting rid of nagios and there are 666 files. + - /etc/nrpe.d # Getting rid of nagios and there are 666 files. + - /etc/openshift_apps # FIXME: ? + - /etc/openvpn/server/ccd # ? + - /etc/openvpn/server/ccd.bad + - /etc/pki/ca-trust/extracted/pem/directory-hash # ? lots of files. + - /etc/pki/pki-tomcat/ca/archives - /etc/udev/rules.d - - /etc/ipatuura-container-config - - /etc/containers/systemd/ipatuura.container - - /etc/ipa-tuura # Add files here that you know are safe but aren't from an RPM known_filenames: @@ -30,21 +49,118 @@ # Email aliases files: - /etc/aliases.db - /etc/aliases.lmdb + - /etc/aliases.static # Ansible files: - /etc/ansible/facts.d/install_date.fact + # Ansubis files: + - /etc/anubis/policies.yaml + + # AWstats files: + - /etc/awstats/awstats.log01.rdu3.fedoraproject.org.conf + + # Bodhi files: + - /etc/bodhi/celeryconfig.py + - /etc/bodhi/createrepo_c.ini + - /etc/bodhi/logging.yaml + - /etc/bodhi/pungi_general.conf + - /etc/bodhi/pungi_multilib.conf + # Dracut files: + - /etc/dracut.conf.d/local.conf - /etc/dracut.conf.d/nbde_client.conf + - /etc/dracut.conf.d/sgdisk.conf + - /etc/dracut.conf.d/xen.conf # CollectD files: + - /etc/collectd.d/bind.conf + - /etc/collectd.d/fmn.conf + - /etc/collectd.d/memcached.conf - /etc/collectd.d/network.conf - /etc/collectd.d/nfs.conf + - /etc/collectd.d/postgres.conf + - /etc/collectd.d/unixsock.conf + - /etc/collectd.d/vfive-upgrade.conf # Our crond conf files: + - /etc/cron.daily/cleanup-stage-users - /etc/cron.daily/data-only-backup.sh - /etc/cron.daily/freshclam + - /etc/cron.daily/grab-daily-logs + - /etc/cron.daily/rotatelogs-cleanup. + - /etc/cron.daily/sync-http-logs-and-merge.sh + # prod, roughly + - /etc/cron.d/ansible-make-git-checkout-seed + - /etc/cron.d/bodhi-automated-pushes + - /etc/cron.d/branched + - /etc/cron.d/bz-review-report.cron + - /etc/cron.d/cgit-clean-lock.cron + - /etc/cron.d/check-broken-planet.cron + - /etc/cron.d/cloud-image-stat.cron + - /etc/cron.d/cloud-updates + - /etc/cron.d/compress-log.cron + - /etc/cron.d/condense-mirrorlogs.cron + - /etc/cron.d/container-updates + - /etc/cron.d/countme-update.cron + - /etc/cron.d/cron-backup-anitya-public + - /etc/cron.d/cron-backup-database-anitya + - /etc/cron.d/cron-backup-database-blockerbugs + - /etc/cron.d/cron-backup-database-bodhi2 + - /etc/cron.d/cron-backup-database-datanommer2 + - /etc/cron.d/cron-backup-database-elections + - /etc/cron.d/cron-backup-database-fedocal + - /etc/cron.d/cron-backup-database-fpo-mediawiki + - /etc/cron.d/cron-backup-database-hyperkitty + - /etc/cron.d/cron-backup-database-ipsilon + - /etc/cron.d/cron-backup-database-kerneltest + - /etc/cron.d/cron-backup-database-koji + - /etc/cron.d/cron-backup-database-koschei + - /etc/cron.d/cron-backup-database-mailman + - /etc/cron.d/cron-backup-database-mirrormanager2 + - /etc/cron.d/cron-backup-database-notifications + - /etc/cron.d/cron-backup-database-openqa + - /etc/cron.d/cron-backup-database-openqa-stg + - /etc/cron.d/cron-backup-database-pagure + - /etc/cron.d/cron-backup-database-postgres + - /etc/cron.d/cron-backup-database-resultsdb + - /etc/cron.d/cron-backup-database-tahrir + - /etc/cron.d/cron-backup-database-testdays + - /etc/cron.d/cron-backup-database-testdays_resultsdb + - /etc/cron.d/cron-backup-database-transtats + - /etc/cron.d/cron-backup-database-waiverdb + - /etc/cron.d/cron-backup-database-webhook2fedmsg + - /etc/cron.d/cron-backup-database-zezere + - /etc/cron.d/cron-docs-translation-update + - /etc/cron.d/cron-weblate-backup + - /etc/cron.d/directory-sizes-update + - /etc/cron.d/download-sync + - /etc/cron.d/eln + - /etc/cron.d/f42-bootc + - /etc/cron.d/f43-compose + - /etc/cron.d/f44-compose + - /etc/cron.d/fasjson-aliases + - /etc/cron.d/grokfsck.cron + - /etc/cron.d/grokmirror.cron + - /etc/cron.d/koji-directory-cleanup + - /etc/cron.d/koji-gc + - /etc/cron.d/koji-prune-signed-copies + - /etc/cron.d/koji-sidetag-cleanup + - /etc/cron.d/linuxsystemroles-logs-clean + - /etc/cron.d/make-people-git + - /etc/cron.d/make-people-page.cron + - /etc/cron.d/package-owner-aliases + - /etc/cron.d/rawhide + - /etc/cron.d/rawhide-compose + - /etc/cron.d/run-rdiff-backups + - /etc/cron.d/sig_policy + - /etc/cron.d/torrent-hash.cron + - /etc/cron.d/torrent-web-generate + - /etc/cron.d/updates-sync + - /etc/cron.d/update-fullfiletimelist + - /etc/cron.d/update-koji-owner + # stg, roughly - /etc/cron.d/ansible-check-update-hooks - /etc/cron.d/ansible-clamscan - /etc/cron.d/budget-sync @@ -76,6 +192,11 @@ - /etc/cron.d/sync-mirrors - /etc/cron.d/sync-start + - /etc/cron.d/cron-backup-database-fas2 + - /etc/cron.d/sa-update + + - /etc/cron.weekly/ftbfs.cron + # dconf files: - /etc/dconf/db/distro - /etc/dconf/db/local @@ -84,19 +205,34 @@ # dnf plugin files: - /etc/dnf/libdnf5-plugins/actions.d/mod_wsgi.actions + # docker! files: + - /etc/docker/certs.d/registry.fedoraproject.org/client.cert + - /etc/docker/certs.d/registry.fedoraproject.org/client.key + - /etc/docker/certs.d/registry.stg.fedoraproject.org/client.cert + - /etc/docker/certs.d/registry.stg.fedoraproject.org/client.key + - /etc/fedora-gather-easyfix/template.html # fedora-messaging files: - /etc/fedora-messaging/config.toml + - /etc/fedora-messaging/faf/ca.crt # These should be under /etc/pki? + - /etc/fedora-messaging/faf/faf.crt + - /etc/fedora-messaging/faf/faf.key - /etc/fedora-messaging/git-hooks-messaging.toml + - /etc/fedora-messaging/koji_sync_listener.toml - /etc/fedora-messaging/ursabot.toml + - /etc/fedora-messaging/zodbot.toml + + # ftbfs files: + - /etc/ftbfs.cfg # gitconfig files: - /etc/gitconfig - /etc/gssproxy/10-ipa.conf - # haproxy files: + # HAproxy files: + - /etc/haproxy/503.http - /etc/haproxy/ipa.pem - /etc/haproxy/ocp-stg.pem - /etc/haproxy/ocp-stg-rdu3.pem @@ -899,27 +1035,26 @@ - /etc/httpd/conf.d/zabbix.stg.fedoraproject.org/securityheaders.conf - /etc/httpd/conf.d/zabbix.stg.fedoraproject.org/zabbix.conf + - /etc/httpd/conf.d/compose.conf - /etc/httpd/conf.d/fp.conf + - /etc/httpd/conf.d/freemedia-app.conf + - /etc/httpd/conf.d/geoip-city-wsgi.conf + - /etc/httpd/conf.d/ipa-tuura.conf - /etc/httpd/conf.d/infrastructure.fedoraproject.org.conf + - /etc/httpd/conf.d/kojiweb-stg.conf + - /etc/httpd/conf.d/mailmanweb.conf - /etc/httpd/conf.d/meetbot.conf - /etc/httpd/conf.d/nss.conf + - /etc/httpd/conf.d/pager-app.conf - /etc/httpd/conf.d/referer-override.conf + - /etc/httpd/conf.d/rel-eng.conf + - /etc/httpd/conf.d/repo.conf - /etc/httpd/conf.d/testproxy.conf + - /etc/httpd/conf.d/wsgi.conf - /etc/httpd/conf/cacert.pem - /etc/httpd/conf/pkgs.fedoraproject.org_key_and_cert.pem - - /etc/httpd/conf.d/freemedia-app.conf - - /etc/httpd/conf.d/geoip-city-wsgi.conf - - /etc/httpd/conf.d/pager-app.conf - - /etc/httpd/conf.d/wsgi.conf - - - /etc/httpd/conf.d/kojiweb-stg.conf - - /etc/httpd/conf.d/rel-eng.conf - - /etc/httpd/conf.d/repo.conf - - - /etc/httpd/conf.d/ipa-tuura.conf - - /etc/httpd/ticketkey_staging.tkey # IPA files: @@ -928,89 +1063,120 @@ - /etc/ipa/custodia/custodia.conf - /etc/ipa/custodia/server.keys + # ipsilon files: + - /etc/ipsilon/root/configuration.conf + - /etc/ipsilon/root/idp.conf + - /etc/ipsilon/root/install_changes + - /etc/ipsilon/root/ipsilon.conf + - /etc/ipsilon/root/openidc.key + - /etc/ipsilon/root/openidc.static.cfg + - /etc/ipsilon/root/saml2/idp.crt + - /etc/ipsilon/root/saml2/idp.key + - /etc/ipsilon/root/saml2/metadata.xml + # Kerberos keytab files: - /etc/dirsrv/ds.keytab - - /etc/httpd.keytab + - /etc/httpd.keytab # Move to below? + - /etc/httpd/conf/http.keytab - /etc/kojid/kojid.keytab + - /etc/koji-hub/koji-hub.keytab - /etc/krb5.keytab + - /etc/krb5.releng.keytab - /etc/pkgs.keytab + - /etc/krb5.HTTP_admin.fedoraproject.org.keytab + - /etc/krb5.HTTP_id.fedoraproject.org.keytab + - /etc/krb5.HTTP_id.fedoraproject.org.keytab.combined + - /etc/krb5.HTTP_koji.fedoraproject.org.keytab + - /etc/krb5.HTTP_nagios.fedoraproject.org.keytab + - /etc/krb5.HTTP_nagios-external.fedoraproject.org.keytab + - /etc/krb5.HTTP_riscv-koji.fedoraproject.org.keytab + - /etc/krb5.bodhi_bodhi.fedoraproject.org.keytab + - /etc/krb5.compose_koji.fedoraproject.org.keytab + - /etc/krb5.compose_riscv-koji.fedoraproject.org.keytab + - /etc/krb5.kojira_koji.fedoraproject.org.keytab + - /etc/krb5.kojira_koji.stg.fedoraproject.org.keytab + - /etc/krb5.kojira_riscv-koji.fedoraproject.org.keytab + - /etc/krb5.koji-gc_koji.fedoraproject.org.keytab + - /etc/krb5.koji-gc_koji.stg.fedoraproject.org.keytab + - /etc/krb5.koji-gc_riscv-koji.fedoraproject.org.keytab + - /etc/krb5.mash_koji.fedoraproject.org.keytab + - /etc/krb5.mash_koji.stg.fedoraproject.org.keytab + - /etc/krb5.monitoring_ipa01.rdu3.fedoraproject.org.keytab + - /etc/krb5.stage-users_ipa01.rdu3.fedoraproject.org.keytab + - /etc/krb5.zodbot_value01.rdu3.fedoraproject.org.keytab - /etc/krb5.HTTP_id.stg.fedoraproject.org.keytab - /etc/krb5.HTTP_id.stg.fedoraproject.org.keytab.combined + - /etc/krb5.HTTP_ipatuura01.stg.rdu3.fedoraproject.org.keytab + - /etc/krb5.HTTP_koji.stg.fedoraproject.org.keytab + - /etc/krb5.bodhi_bodhi.stg.fedoraproject.org.keytab + - /etc/krb5.compose_compose-x86-01.stg.rdu3.fedoraproject.org.keytab + - /etc/krb5.compose_koji.stg.fedoraproject.org.keytab - /etc/krb5.monitoring_ipa01.stg.rdu3.fedoraproject.org.keytab - /etc/krb5.stage-users_ipa01.stg.rdu3.fedoraproject.org.keytab - /etc/krb5.ursabot_value01.stg.rdu3.fedoraproject.org.keytab # Kerberos files: - /etc/krb5.conf.d/freeipa + - /etc/krb5.conf.d/freeipa-realm - /etc/krb5.conf.d/freeipa-server # Kernel/init files: - /etc/kernel/cmdline + - /etc/modprobe.d/blacklist-nouveau.conf + - /etc/modprobe.d/disable-cdc_ether.conf + - /etc/modprobe.d/i40e.conf + - /etc/modprobe.d/kvm_intel.conf + - /etc/modules-load.d/nf_conntrack.conf # KOJI files: - - /etc/kojid/plugins/flatpak.conf - /etc/kojira/extras_cacert.pem - /etc/kojira/kojira_cert_key.pem - /etc/koji-hub/gssapi.keytab - /etc/koji-osbuild/builder.conf + - /etc/koji.conf.d/bodhi.conf + - /etc/koji.conf.d/compose.conf + - /etc/kojid/plugins/flatpak.conf - # FIXME: ? + # FIXME: Seem sus bad name files: - /etc/pki/tls/certs/extras_cacert.pem - /etc/pki/tls/certs/extras_upload_cacert.pem - /etc/pki/tls/certs/localhost.crt - /etc/pki/tls/certs/upload_cacert.pem - /etc/pki/tls/private/localhost.key - # logrotate files: + - /etc/logrotate.d/bittorrent + - /etc/logrotate.d/merged-rsyslog - /etc/logrotate.d/mirrormanager + - /etc/logrotate.d/rsync-fedora - /etc/logrotate.d/rsyslog + - /etc/logrotate.d/spamassassin + - /etc/logrotate.d/syslog # LVM files: - /etc/lvm/devices/system.devices + # Spam files: + - /etc/mail/spamassassin/sa-update-keys/pubring.kbx + - /etc/mail/spamassassin/sa-update-keys/trustdb.gpg + + # Mailman files: + - /etc/mailman3/django_fedora_nosignup.py + - /etc/mailman3/gunicorn.conf.py + - /etc/mailman3/initial-data.json + - /etc/mailman3/settings_admin.py + - /etc/mailman3/urls.py + # MDADM files: - /etc/mdadm.conf - - /etc/modprobe.d/kvm_intel.conf + # Named files: + - /etc/named/zones.conf # NF Tables files: - /etc/nftables/fedora-infra-ipv4.nft - /etc/nftables/fedora-infra-ipv6.nft - # Nagios files: - - /etc/nrpe.d/check_basset.cfg - - /etc/nrpe.d/check_celery_redis_queue.cfg - - /etc/nrpe.d/check_countme.cfg - - /etc/nrpe.d/check_cron.cfg - - /etc/nrpe.d/check_datanommer_history.cfg - - /etc/nrpe.d/check_disk.cfg - - /etc/nrpe.d/check_fedmsg_composer_proc.cfg - - /etc/nrpe.d/check_fedmsg_consumers.cfg - - /etc/nrpe.d/check_fedmsg_gateway_proc.cfg - - /etc/nrpe.d/check_fedmsg_hub_proc.cfg - - /etc/nrpe.d/check_fedmsg_irc_proc.cfg - - /etc/nrpe.d/check_fedmsg_relay_proc.cfg - - /etc/nrpe.d/check_fmn.cfg - - /etc/nrpe.d/check_happroxy_conns.cfg - - /etc/nrpe.d/check_ipa.cfg - - /etc/nrpe.d/check_lock.cfg - - /etc/nrpe.d/check_lock_file_age.cfg - - /etc/nrpe.d/check_memcache.cfg - - /etc/nrpe.d/check_mirrorlist_cache.cfg - - /etc/nrpe.d/check_mirrorlist_docker_proxy.cfg - - /etc/nrpe.d/check_postfix_queue.cfg - - /etc/nrpe.d/check_postfix_redhat.cfg - - /etc/nrpe.d/check_proxies.cfg - - /etc/nrpe.d/check_raid.cfg - - /etc/nrpe.d/check_readonly_fs.cfg - - /etc/nrpe.d/check_redis_proc.cfg - - /etc/nrpe.d/check_rsyslogd_proc.cfg - - /etc/nrpe.d/check_swap.cfg - - /etc/nrpe.d/check_testcloud.cfg - - /etc/nrpe.d/check_websites_buildtime.cfg - - /etc/nrpe.d/check_varnish_proc.cfg - # NVME files: - /etc/nvme/hostid - /etc/nvme/hostnqn @@ -1022,24 +1188,32 @@ # OpenVPN files: - /etc/openvpn/client/ca.crt + - /etc/openvpn/client/client.crt + - /etc/openvpn/client/client.key - /etc/openvpn/client/openvpn.conf - /etc/openvpn/fix-routes.sh - /etc/openvpn/server/ca.crt + # PAM files: + - /etc/pam.d/mock + # Pagure files: - /etc/pagure/client_secrets.json - /etc/pagure/pagure_hook.cfg - /etc/pagure/pagure_plugins.cfg # PKI files: - - /etc/pki/ca-trust/extracted/pem/directory-hash/STG.FEDORAPROJECT.ORG_IPA_CA.pem - - /etc/pki/fedora-messaging/cacert.pem - - /etc/pki/fedora-messaging/mediawiki.stg-cert.pem - - /etc/pki/fedora-messaging/mediawiki.stg-key.pem + - /etc/pki/fedora-messaging/bodhi-cert.pem + - /etc/pki/fedora-messaging/bodhi-key.pem - /etc/pki/fedora-messaging/ca.crt + - /etc/pki/fedora-messaging/cacert.pem - /etc/pki/fedora-messaging/ipa.stg.crt - /etc/pki/fedora-messaging/ipa.stg.key + - /etc/pki/fedora-messaging/mediawiki.stg-cert.pem + - /etc/pki/fedora-messaging/mediawiki.stg-key.pem - /etc/pki/fedora-messaging/rabbitmq-ca.crt + - /etc/pki/fedora-messaging/rabbitmq-pungi.crt + - /etc/pki/fedora-messaging/rabbitmq-pungi.key - /etc/pki/fedora-messaging/ursabot.crt - /etc/pki/fedora-messaging/ursabot.key @@ -1269,13 +1443,21 @@ - /etc/pki/tls/certs/wildcard-2025.id.fedoraproject.org.intermediate.cert - /etc/pki/tls/certs/wildcard-2025.id.stg.fedoraproject.org.cert - /etc/pki/tls/certs/wildcard-2025.id.stg.fedoraproject.org.intermediate.cert + - /etc/pki/tls/certs/wildcard-2025.fedorapeople.org.cert + - /etc/pki/tls/certs/wildcard-2025.fedorapeople.org.intermediate.cert - /etc/pki/tls/certs/wildcard-2025.stg.fedoraproject.org.cert - /etc/pki/tls/certs/wildcard-2025.stg.fedoraproject.org.intermediate.cert - /etc/pki/tls/certs/wildcard-2026.stg.fedoraproject.org.cert - /etc/pki/tls/certs/wildcard-2026.stg.fedoraproject.org.intermediate.cert + - /etc/pki/tls/private/br.fedoracommunity.org.key - /etc/pki/tls/private/coreos.stg.fedoraproject.org.key - /etc/pki/tls/private/epel.io.key - /etc/pki/tls/private/fedora.im.key + - /etc/pki/tls/private/fedoracommunity.org.key + - /etc/pki/tls/private/fedorahosted.org.key + - /etc/pki/tls/private/fedoramagazine.org.key + - /etc/pki/tls/private/flocktofedora.org.key + - /etc/pki/tls/private/fpaste.org.key - /etc/pki/tls/private/fedoraloveskde.org.key - /etc/pki/tls/private/fedoraplanet.org.key - /etc/pki/tls/private/getfedora.org.key @@ -1296,6 +1478,7 @@ - /etc/pki/tls/private/wildcard-2025.apps.ocp-rdu3.fedoraproject.org.key - /etc/pki/tls/private/wildcard-2025.apps.ocp-rdu3.stg.fedoraproject.org.key - /etc/pki/tls/private/wildcard-2025.apps.ocp.stg.fedoraproject.org.key + - /etc/pki/tls/private/wildcard-2025.fedorapeople.org.key - /etc/pki/tls/private/wildcard-2025.fedoraproject.org.key - /etc/pki/tls/private/wildcard-2025.id.fedoraproject.org.key - /etc/pki/tls/private/wildcard-2025.id.stg.fedoraproject.org.key @@ -1308,15 +1491,38 @@ - /etc/pki/rabbitmq/kojicert/koji.ca - /etc/pki/rabbitmq/kojicert/koji.crt - /etc/pki/rabbitmq/kojicert/koji.key + - /etc/pki/rabbitmq/mailman/mailman.ca + - /etc/pki/rabbitmq/mailman/mailman.crt + - /etc/pki/rabbitmq/mailman/mailman.key - /etc/pki/rabbitmq/pagurecert/src.fp.o.ca - /etc/pki/rabbitmq/pagurecert/src.fp.o.crt - /etc/pki/rabbitmq/pagurecert/src.fp.o.key + - /etc/pki/releng # ? + - /etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-SIG-Messaging + - /etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-9 + # Profile files: + - /etc/profile.d/cudapath.sh + - /etc/profile.d/externalcaches.sh + - /etc/profile.d/history_off.sh + - /etc/profile.d/models.sh + - /etc/profile.d/setprodps1.sh - /etc/profile.d/setprodiad2ps1.sh # FIXME ? - /etc/profile.d/setprodrdu3ps1.sh - /etc/profile.d/setstgps1.sh + # RabbitMQ files: + - /etc/rabbitmq/ca.crt + - /etc/rabbitmq/enabled_plugins + - /etc/rabbitmq/inter_node_tls.config + - /etc/rabbitmq/nodecert.combined.pem + - /etc/rabbitmq/nodecert/node.crt + - /etc/rabbitmq/nodecert/node.key + - /etc/rabbitmq/pubsub_federation/client_cert.pem + - /etc/rabbitmq/pubsub_federation/client_key.pem + - /etc/rabbitmq/rabbitmq-env.conf + # Resolve files: - /etc/resolv.conf @@ -1326,10 +1532,17 @@ - /etc/rsyslog.d/rsyslog-audit.conf - /etc/rsyslog.d/rsyslog-disablerate.conf - /etc/rsyslog.d/rsyslog-imjournal-limits.conf + - /etc/rsyslog.d/rsyslog-limits.conf - /etc/rsyslog.d/rsyslog-log01.conf # SSH files: - /etc/ssh/sshd_config.d/04-ipa.conf + - /etc/ssh/sshd_config.d/50-cloud-init.conf + - /etc/ssh/ssh_config.d/04-ipa.conf + - /etc/ssh/ssh_config.d/99-x11.conf + - /etc/ssh/ssh_host_dsa_key + - /etc/ssh/ssh_host_dsa_key.pub + - /etc/ssh/ssh_host_dsa_key-cert.pub - /etc/ssh/ssh_host_ecdsa_key - /etc/ssh/ssh_host_ecdsa_key.pub - /etc/ssh/ssh_host_ed25519_key @@ -1345,13 +1558,26 @@ - /etc/sssd/conf.d/fedora-nss-ignore.conf # sudoers files: + - /etc/sudoers.d/01-sysadmin-main + - /etc/sudoers.d/90-cloud-init-users + - /etc/sudoers.d/arm-packager-sudoers + - /etc/sudoers.d/arm-retrace-sudoers + - /etc/sudoers.d/default - /etc/sudoers.d/norequiretty + - /etc/sudoers.d/pkgs01_rdu3_fedoraproject_org-sudoers # Sysconfig files: - /etc/sysconfig/anaconda - /etc/sysconfig/authconfig + - /etc/sysconfig/bittorrent + - /etc/sysconfig/bootloader + - /etc/sysconfig/firstboot + - /etc/sysconfig/global-update-applied # FIXME: ? + - /etc/sysconfig/freshclam + - /etc/sysconfig/ipv4-br-aggregated.zone + - /etc/sysconfig/ipv6-br.zone - /etc/sysconfig/ipv4-cu-aggregated.zone - /etc/sysconfig/ipv4-ir-aggregated.zone - /etc/sysconfig/ipv4-kp-aggregated.zone @@ -1374,37 +1600,95 @@ - /etc/sysconfig/sshd-permitrootlogin + # Sysctl.d files: + - /etc/sysctl.d/10-tcp-socket-buffers.conf + # SystemD files: + - /etc/systemd/system/anubis.service + - /etc/systemd/system/bodhi-celery.service - /etc/systemd/system/btrfs-balance.timer.d/schedule.conf + - /etc/systemd/system/collectd.service.d/timeout.conf + - /etc/systemd/system/debuginfod.service.d/override.conf + - /etc/systemd/system/dirsrv@FEDORAPROJECT-ORG.service.d/ipa-env.conf - /etc/systemd/system/dirsrv@STG-FEDORAPROJECT-ORG.service.d/ipa-env.conf - /etc/systemd/system/dnf-automatic.timer.d/weekdays.conf - /etc/systemd/system/dnf5-automatic.timer.d/weekdays.conf - /etc/systemd/system/dnf-automatic-install.timer.d/weekdays.conf + - /etc/systemd/system/fm-consumer@.service.d/local.conf - /etc/systemd/system/git@.service + - /etc/systemd/system/haproxy.service.d/postvpn.conf + - /etc/systemd/system/httpd.service - /etc/systemd/system/httpd.service.d/env.conf - /etc/systemd/system/httpd.service.d/httpdoverride.conf - /etc/systemd/system/httpd.service.d/ipa.conf + - /etc/systemd/system/httpd.service.d/override.conf + - /etc/systemd/system/hyperkitty.target + - /etc/systemd/system/hyperkitty-daily.service + - /etc/systemd/system/hyperkitty-daily.timer + - /etc/systemd/system/hyperkitty-hourly.service + - /etc/systemd/system/hyperkitty-hourly.timer + - /etc/systemd/system/hyperkitty-minutely.service + - /etc/systemd/system/hyperkitty-minutely.timer + - /etc/systemd/system/hyperkitty-monthly.service + - /etc/systemd/system/hyperkitty-monthly.timer + - /etc/systemd/system/hyperkitty-quarter_hourly.service + - /etc/systemd/system/hyperkitty-quarter_hourly.timer + - /etc/systemd/system/hyperkitty-weekly.service + - /etc/systemd/system/hyperkitty-weekly.timer + - /etc/systemd/system/hyperkitty-yearly.service + - /etc/systemd/system/hyperkitty-yearly.timer - /etc/systemd/system/kojid.service + - /etc/systemd/system/machine-.scope.d/80-infra.conf + - /etc/systemd/system/mailman3.service.d/mailman3.conf + - /etc/systemd/system/mailmanweb.service - /etc/systemd/system/mirrorlist1.service - /etc/systemd/system/mirrorlist2.service - /etc/systemd/system/pagure_ev.service + - /etc/systemd/system/pagure_fast_worker.service - /etc/systemd/system/pagure_logcom.service + - /etc/systemd/system/pagure_medium_worker.service + - /etc/systemd/system/pagure_mirror.service + - /etc/systemd/system/pagure_slow_worker.service - /etc/systemd/system/pagure_webhook.service - /etc/systemd/system/pagure_worker.service - /etc/systemd/system/pki-tomcatd@pki-tomcat.service.d/ipa.conf + - /etc/systemd/system/rabbitmq-server.service.d/override.conf + - /etc/systemd/system/rsyslog.service.d/limits.conf + - /etc/systemd/system/send-rabbitmq-queue.service + - /etc/systemd/system/send-rabbitmq-queue.timer - /etc/systemd/system/ursabot.service - /etc/systemd/system/varnish.service - + - /etc/systemd/system/varnish.service.d/postvpn.conf + - /etc/systemd/system/varnish.service.d/restart-on-fail.conf + - /etc/systemd/system/webui-qcluster.service + - /etc/systemd/system/webui-warm-up-cache.service + - /etc/systemd/system/zodbot.service # tmpfiles files: - /etc/tmpfiles.d/dirsrv-STG-FEDORAPROJECT-ORG.conf + # Varnish files: + - /etc/varnish/secret + # YUM files: + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:dvraaij:ada.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_abrt:faf-el8.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_abrt:faf-el8-devel.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:group_osbuild:osbuild.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:hobbes1069:testing.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:packit:abrt-retrace-server-434.repo + - /etc/yum.repos.d/_copr:copr.fedorainfracloud.org:psloboda:mariadb10.11-rebase-to-10.11.13.repo + - /etc/yum.repos.d/centos9s-rabbitmq38.repo + - /etc/yum.repos.d/cuda-fedora41.repo + - /etc/yum.repos.d/epel.repo # FIXME ? - /etc/yum.repos.d/epel8.repo - /etc/yum.repos.d/epel9.repo - /etc/yum.repos.d/epel10.repo + - /etc/yum.repos.d/group_abrt-faf-el8-epel-8.repo - /etc/yum.repos.d/infra-tags.repo - /etc/yum.repos.d/infra-tags-stg.repo + - /etc/yum.repos.d/redhat.repo + - /etc/yum.repos.d/rhel-infra-tags.repo - /etc/yum.repos.d/rhel8.repo - /etc/yum.repos.d/rhel9.repo - /etc/yum.repos.d/rhel10.repo @@ -1415,14 +1699,28 @@ - /etc/zabbix/zabbix_agentd.d/interface-alias.conf - /etc/zabbix/zabbix_agentd.d/ipa-backup.conf - /etc/zabbix/zabbix_agentd.d/postfix.conf + - /etc/zabbix/zabbix_agentd.d/rabbitmq.conf - /etc/zabbix/zabbix_agentd.d/raid.conf - /etc/zabbix/zabbix_agentd.conf + # FIXME: Why this and the above? + - /etc/zabbix_agentd.conf + # FIXME: SELinux BS goes here? + - /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.mod + - /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.pp + - /etc/zabbix/zabbix_agentd.d/zabbix_rabbitmq.te - # Are these known though? - - /etc/firewalld/zones/public.xml - - /etc/modules-load.d/nf_conntrack.conf - - /etc/system_identification - - /etc/varnish/secret + # Misc files: + # FIXME: Are these actually known/good though? + - /etc/crio/crio.conf + - /etc/firewalld/zones/public.xml # everything but s390x has this. + - /etc/grub.d/00_tuned # from 2024 on pkgs01.stg.rdu3 + - /etc/iscsi/initiatorname.iscsi + - /etc/motd_fedora + - /etc/stunnel/stunnel.conf + - /etc/sync-http-logs.yaml + - /etc/system_identification # only bvmhost-s390x-01.stg.s390 + - /etc/systemd/dont-synthesize-nobody # empty file on memcached02.stg.rdu3 + - /etc/xinetd.d/rsync tasks: