diff --git a/index.md b/index.md index 24978a14..f00c4332 100644 --- a/index.md +++ b/index.md @@ -65,16 +65,3 @@ Chair: xxx ### Standup Meeting Chair: xxx - - -## AD/Unix Groups -- __unx-linux_support__ - used to give Linux supporters access to systems/services -- __unx-puppet_adm__ - associated with lxdev environment/systems -- __unx-puppet_dev__ - developer of puppet code -- __unx-puppet_usr__ - user of puppet (i.e. need access to linux-infra group/repos) - -There are 2 groups that are used within ServiceNow that are used to dispatch CSS tickets: -- __itsm-linux__ -- __itsm-linux_2nd__ - -_itsm-linux_ is used to assign Linux ticket to the PC-Supporter (i.e. 1st level Linux support). _itsm-linux_2nd_ is used to assign tickets to the second level Linux support. diff --git a/infrastructure-guide/home.md b/infrastructure-guide/home.md index b57636a5..15dc6507 100644 --- a/infrastructure-guide/home.md +++ b/infrastructure-guide/home.md @@ -26,6 +26,8 @@ List of systems and their primary role: * [satint](satint) - 129.129.160.114 - PSI Satellite server +* http://linux.web.psi.ch - YUM Repositories SL6 / RHEL7 + ![](overview_linux.drawio.svg) diff --git a/proposals/draft_infrastructure_security_concept.drawio.svg b/proposals/draft_infrastructure_security_concept.drawio.svg new file mode 100644 index 00000000..4051f65f --- /dev/null +++ b/proposals/draft_infrastructure_security_concept.drawio.svg @@ -0,0 +1,833 @@ + + + + + + + + + + +
+
+
+ https/443 +
+ 8140 +
+
+
+
+ + https/443... + +
+
+ + + + + +
+
+
+ 443 +
+ 22 +
+
+
+
+ + 443... + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + + + +
+
+
+ Puppet +
+
+
+
+ + Puppet + +
+
+ + + + + +
+
+
+ https/443 +
+
+
+
+ + https/443 + +
+
+ + + + + + +
+
+
+ YUM Repos +
+
+
+
+ + YUM Repos + +
+
+ + + + + +
+
+
+ tftp +
+ http/80 +
+ https/443 +
+
+
+
+ + tftp... + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + +
+
+
+ - PXE +
+ - Sysdb +
+
+
+
+ + - PXE... + +
+
+ + + + + + + + + +
+
+
+ Git +
+
+
+
+ + Git + +
+
+ + + + + + + + + +
+
+
+ NFS +
+
+
+
+ + NFS + +
+
+ + + + + +
+
+
+ 443 +
+
+
+
+ + 443 + +
+
+ + + + + + +
+
+
+ Icinga Master +
+
+
+
+ + Icinga Master + +
+
+ + + + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ Elastic +
+
+
+
+ + Elastic + +
+
+ + + + + +
+
+
+ ???? +
+
+
+
+ + ???? + +
+
+ + + + +
+
+
+ Icinga Satellites +
+
+
+
+ + Icinga Satellites + +
+
+ + + + + +
+
+
+ + nrpe + +
+ + ns-client++ + +
+ + snmp + +
+ + other ports + +
+
+
+
+ + nrpe... + +
+
+ + + + +
+
+
+ agent(s) +
+
+
+
+ + agent(s) + +
+
+ + + + + + + + +
+
+
+ AD +
+
+
+
+ + AD + +
+
+ + + + +
+
+
+ ETH RedHat Satellite +
+
+
+
+ + ETH RedHat Satellite + +
+
+ + + + + +
+
+
+ https +
+
+
+
+ + https + +
+
+ + + + +
+
+
+ Other content provider +
+
+
+
+ + Other content provid... + +
+
+ + + + +
+
+
+ introduction of content scanning +
+
+
+
+ + introduction of content scanning + +
+
+ + + + + +
+
+
+ ... +
+
+
+
+ + ... + +
+
+ + + + +
+
+
+ any supported system in + + ANY + + zone !!!! +
+
+
+
+ + any supported system in... + +
+
+ + + + + + + +
+
+
+ security level +
+
+
+
+ + security l... + +
+
+ + + + + + +
+
+
+ https/443 +
+ 8140 +
+
+
+
+ + https/443... + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + + + + +
+
+
+ https/443 +
+
+
+
+ + https/443 + +
+
+ + + + + + +
+
+
+ (specific) managed Linux machines +
+
+
+
+ + (specific) managed Linux machines + +
+
+ + + + + + +
+
+
+ Icinga Satellite +
+ (DMZ) +
+
+
+
+ + Icinga Satellite... + +
+
+ + + + +
+
+
+ + DMZ + +
+ - DMZ responsible ? +
+ - Periodic reviews +
+
+
+
+ + DMZ... + +
+
+ + + + +
+
+
+
+ - Systems are installed in the DMZ + +
+
+
+
+ + - Firewall rules for specific systems on request - template what ports need to be opened + +
+
+ + - System (will) have static DHCP address + +
+
+
+
+
+
+
+
+ + - Systems are installed in the DMZ... + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ Icinga Satellites +
+
+
+
+ + Icinga Satellites + +
+
+ + + + + +
+
+
+ 5665 +
+
+
+
+ + 5665 + +
+
+ + + + +
+
+
+ agent(s)/beat(s) +
+
+
+
+ + agent(s)/b... + +
+
+ + + + +
+
+
+ logstash +
+
+
+
+ + logstash + +
+
+ + + + + +
+
+
+ ???? +
+
+
+
+ + ???? + +
+
+ + + + + +
+
+
+ + nrpe + +
+ + ns-client++ + +
+ + snmp + +
+ + other ports + +
+
+
+
+ + nrpe... + +
+
+
+ + + + + Viewer does not support full SVG 1.1 + + + +
\ No newline at end of file diff --git a/proposals/draft_infrastructure_security_concept.md b/proposals/draft_infrastructure_security_concept.md new file mode 100644 index 00000000..047fcd81 --- /dev/null +++ b/proposals/draft_infrastructure_security_concept.md @@ -0,0 +1,3 @@ +# [DRAFT] Core Infrastructure Security Concept + +![](draft_infrastructure_security_concept.drawio.svg) \ No newline at end of file diff --git a/proposals/draft_naming_conventions.md b/proposals/draft_naming_conventions.md new file mode 100644 index 00000000..3e8069ab --- /dev/null +++ b/proposals/draft_naming_conventions.md @@ -0,0 +1,14 @@ +# [DRAFT] Naming Conventions Infrastructure Servers + +To be able to easily identify all Linux core infrastructure servers they should follow the same naming convention. + +Following pattern should be followed: +__lx-<purpose>-<number>__ + +Usually there should be a DNS alias __lx-<purpose> -> lx-<purpose>-<number>__ that points to the currently active production server. + +Examples: +* lx-repo -> lx-repo-01 +* lx-puppet -> lx-puppet-01 +* lx-puppet-test -> lx-puppet-test-01 +* lx-lc -> lx-lc-01 \ No newline at end of file