2026-07-05 - 2026-08-05
Overview
26 Issues closed from 1 user
Closed
#410 archive wtmptail from salt to a separate repository, and remove it
Closed
#332 Set up prometheus exporters for php-fpm instances
Closed
#401 Use Type=notify for python-http-handlers
Closed
#376 Ingest exim logs into grafana
Closed
#412 Advertise TLS instead of STARTTLS in .well-known/autoconfig/mail
Closed
#318 Extract PVV-specified config from exim
Closed
#452 Firewall gitea runners to only be able to take requests from kommode
Closed
#428 Replace dbus with dbus-broker in salt
Closed
#199 Enable encryption for OpenVPN bridge between PVV and serverroom
Closed
#417 Clean up authorized_keys in salt
Closed
#411 Purge sane config from salt
Closed
#377 Replace promtail with fluentbit in salt
Closed
#186 Ask SoC for SSH exception for kommode
Closed
#408 Close udp 5432 on bicep firewall
Closed
#429 Pure arch/gentoo/redhat config from salt
Closed
#422 Configure fwupd in salt
Closed
#191 Make uptimekuma (or otherwise uptime status of some sort) more accessible to all users
Closed
#395 Run OPTIMIZE <db> on all mysql databases as a timed job
Closed
#384 Replace all nixos postfix instances with nullmailer
Closed
#388 Use better password algorithm for new postgresql password
Closed
#387 Disable atime for postgres/mariadb state directories
Closed
#400 Set up gatus monitoring for mariadb
Closed
#399 Set up gatus monitoring for postgresql
Closed
#390 Fix mojibake in distributed /etc/passwd
Closed
#372 Access logs for postgresql
Closed
#380 Disable irqbalancer on single CPU socket machines
77 Issues created by 4 users
Opened
#398 Fix gatus monitoring for georg/brzęczyszczykiewicz
Opened
#399 Set up gatus monitoring for postgresql
Opened
#400 Set up gatus monitoring for mariadb
Opened
#401 Use Type=notify for python-http-handlers
Opened
#402 Set up matrix alerts for gatus
Opened
#403 PVV-net <--> Openstack VPN
Opened
#404 Add watchdog(s) for drumknotty subprocesses
Opened
#405 PVV PDS
Opened
#406 Remove statedir for uptimekuma and remove host from principal backup script
Opened
#407 Create backups for radicale
Opened
#408 Close udp 5432 on bicep firewall
Opened
#409 replace use of autofs with mount units in salt
Opened
#410 archive wtmptail from salt to a separate repository, and remove it
Opened
#411 Purge sane config from salt
Opened
#412 Advertise TLS instead of STARTTLS in .well-known/autoconfig/mail
Opened
#413 Fix renewal of turn.pvv.ntnu.no ACME cert
Opened
#414 Drop mariadb superusers for yorinad@spikkjeposche and pederbs@spikkjeposche
Opened
#415 Have a matrix bot subscribe to innsida varsler on matrix/discord
Opened
#416 archive detach from salt to a separate repository, replace it
Opened
#417 Clean up authorized_keys in salt
Opened
#418 Install qemu-guest-agent on VMs through salt
Opened
#419 Disable irqbalancer on microbel
Opened
#420 Disable apache2 on microbel
Opened
#421 Exim hardening
Opened
#422 Configure fwupd in salt
Opened
#423 Setup cups on terminals to work with NTNU printing service
Opened
#424 Make /tmp private per user on debian machines
Opened
#425 Migrate iptables rules in salt to use nftables
Opened
#426 Configure cronjobs via the cron salt module
Opened
#427 Create a kernel module banlist in salt
Opened
#428 Replace dbus with dbus-broker in salt
Opened
#429 Pure arch/gentoo/redhat config from salt
Opened
#430 Make use of nullmailer on non-microbel debian servers
Opened
#431 Replace gickup-based software mirrors with a fresh forgejo instance
Opened
#432 Enable wake-on-lan on most of our machines
Opened
#433 Configure debian user umasks to a safer default
Opened
#434 Mount everything except /usr/{sbin,bin,lib} with nosuid set
Opened
#435 Ensure we are using norwegian apt mirrors everywhere
Opened
#436 Set up tea on loginboxes and terminals
Opened
#437 Set up bw-cli on loginboxes and terminals
Opened
#438 Configure plocate in salt
Opened
#439 Add SRV records for coturn
Opened
#440 Add SRV records for SMTP, POP, IMAP
Opened
#441 Share a common APT proxy among all debian machines
Opened
#442 Set up binfmt and qemu+user compat on loginboxes and terminals
Opened
#443 Clean up microbel /etc
Opened
#444 Create better scripts to restore stuff from principal
Opened
#445 Clean up secrets in pillar
Opened
#446 Make sure all salt minions don't have access to each other's secrets
Opened
#447 Use window 0 and 1 or 1 and 2 for drumknoTTY
Opened
#448 Clean up UID/GIDs
Opened
#449 Move prometheus-node-exporter from standard to mandatory in salt
Opened
#450 Add validate-rsync script to salt
Opened
#451 Properly remove promtail from microbel
Opened
#452 Firewall gitea runners to only be able to take requests from kommode
Opened
#453 Remove zabbix from sleipner
Opened
#454 Add /usr/sbin to path on microbel (and possibly other machines)
Opened
#455 Set up firewall on sleipner
Opened
#456 Add dovecot config to salt
Opened
#457 Add spamd config to salt
Opened
#458 Add mailman config to salt
Opened
#459 Remove /home/pvv/t
Opened
#460 Fix renewal of alps.pvv.ntnu.no ACME cert on bekkalokk
Opened
#461 Uninstall distcc on most machines
Opened
#462 Provide aerc and meli on loginboxes
Opened
#463 Replace all use of tcpwrapper with firewall rules
Opened
#464 Disable avahi in salt
Opened
#465 Move fail2ban-mailman rules out of /etc on microbel
Opened
#466 Add fail2ban-mailman setup to salt
Opened
#467 Fix element-call
Opened
#468 File level duplication on pages.pvv.ntnu.no
Opened
#469 Kommode doesnt rebuild due to build error in gitea themes
Opened
#470 Add popularity-contest to salt
Opened
#471 Add gitea-runner healtchecks to gatus
Opened
#472 Explicitly allow broken mail headers on microbel in salt
Opened
#473 Ignore quota email bounces
Opened
#474 Host an iroh relay
22 Unresolved Conversations
Open
#354
Repurpose bukserud
Open
#374
Send NOTIFY to DNS secondaries
Open
#97
Gitea: fix incoming mail
Open
#18
Configure mailman3
Open
#382
Upgrade dovecot on microbel
Open
#86
Move salt repository
Open
#350
Create new debian VM login box
Open
#362
Document Matrix bots under services
Open
#280
Get the bicep hardware running again
Open
#241
Consider mounting nfs mounts with async
Open
#379
Configure auditing
Open
#358
Ephemeral VM runners for gitea
Open
#363
principal-backup-script: only do snapshots when something has changed
Open
#393
Create SRV + TXT records for caldav server
Open
#394
Create .well-known redirects for caldav
Open
#396
nixos-upgrade.service: send notification on failure
Open
#181
Configure robots.txt against scraping
Open
#202
Consider moving software mirrors out of gitea
Open
#370
Create virtualhost for matrix synapse admin endpoints
Open
#385
Ensure hugepages are available to postgresql/mysql on bicep
Open
#192
Set up prometheus exporter for dibbler
Open
#383
Split postgresql/mysql backups into per-db files