]> Frank Brehm's Git Trees - pixelpark/hiera.git/commitdiff
pfizer - rewrite vhosts
authorPhilipp Dallig <philipp.dallig@pixelpark.com>
Wed, 8 Mar 2017 10:04:07 +0000 (11:04 +0100)
committerPhilipp Dallig <philipp.dallig@pixelpark.com>
Wed, 8 Mar 2017 10:04:07 +0000 (11:04 +0100)
customer/pfizer/dev-web01-pfizer-de.pixelpark.net.yaml

index 807f6e83961f0acd7c4de707c22eae9dc6ceb47f..ad9af9c1fc77bbd5f63b3ac957fb5ef401f037ca 100644 (file)
@@ -531,14 +531,19 @@ site::profile::typo3::projects:
         rewrite_rule:
           - ^(.*)$ https://dev-www-pfizer-de.pixelpark.net [L,R=301]
 
-site::profile::apache::vhosts:
+site::profile::apache::pp_vhosts:
   dev-pfizer-berlin:
     servername: dev-www-pfizer-berlin.pixelpark.net
     docroot: '/srv/www/mspfizerberlin'
-    port: 80
+    ssl: false
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -547,7 +552,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -563,10 +568,15 @@ site::profile::apache::vhosts:
   dev-ich-beim-arzt:
     servername: dev-ich-beim-arzt-de.pixelpark.net
     docroot: '/srv/www/dev-www.ich-beim-arzt.de'
-    port: 80
+    ssl: false
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -575,7 +585,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -591,10 +601,15 @@ site::profile::apache::vhosts:
   dev-lungenkrebs-testen-at:
     servername: dev-www-lungenkrebs-testen-at.pixelpark.net
     docroot: '/srv/www/dev-www.lungenkrebs-testen.at'
-    port: 80
+    ssl: false
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -603,7 +618,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -619,41 +634,17 @@ site::profile::apache::vhosts:
   dev-lungenkrebs-testen-de:
     servername: dev-www-lungenkrebs-testen-de.pixelpark.net
     docroot: '/srv/www/dev-www.lungenkrebs-testen.de'
-    port: 80
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    directories:
-      - directory_root:
-        provider: directory
-        path: '/srv/www/dev-www.lungenkrebs-testen.de'
-        options:
-          - FollowSymLinks
-          - MultiViews
-        allow_override:
-          - All
-      - location_root:
-        provider: locationmatch
-        path: '^/(?!(server-status|server-info))'
-        auth_type: Digest
-        auth_name: pixelrealm
-        auth_digest_provider: file
-        auth_digest_algorithm: MD5
-        auth_user_file: '/etc/httpd/htdigest'
-        auth_require: 'valid-user'
-        require:
-          - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-  dev-lungenkrebs-testen-de_ssl:
-    servername: dev-www-lungenkrebs-testen-de.pixelpark.net
-    docroot: '/srv/www/dev-www.lungenkrebs-testen.de'
-    port: 443
-    docroot_owner: apache
-    docroot_group: apache
-    docroot_mode: '0770'
-    ssl: true
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -662,7 +653,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -674,7 +665,6 @@ site::profile::apache::vhosts:
         auth_require: 'valid-user'
         require:
           - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-
   dev-impf2ab60:
     servername: dev-www-impf2ab60-de.pixelpark.net
     serveraliases:
@@ -687,10 +677,15 @@ site::profile::apache::vhosts:
       - dev-www-impf-2-ab-60-de.pixelpark.net
       - dev-www-impf2-ab-60-de.pixelpark.net
     docroot: '/srv/www/dev-www.impf2ab60.de'
-    port: 80
+    ssl: false
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -699,7 +694,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -716,10 +711,12 @@ site::profile::apache::vhosts:
     servername: dev-www-wegweiser-rheuma-psoriasis-de.pixelpark.net
     docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
     manage_docroot: false
-    port: 80
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
+    ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
+    ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
+    ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
     directories:
       - directory_root:
         provider: directory
@@ -728,7 +725,7 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -759,15 +756,13 @@ site::profile::apache::vhosts:
           - '%%{ich-trickse}{REQUEST_URI} ^/psoriasis.html$'
         rewrite_rule:
           - ^/psoriasis.html$ https://dev-www-wegweiser-psoriasis-de.pixelpark.net [R=301,L]
-  dev-wegweiser-rheuma-psoriasis_ssl:
-    servername: dev-www-wegweiser-rheuma-psoriasis-de.pixelpark.net
+  dev-wegweiser-rheuma:
+    servername: dev-www-wegweiser-rheuma-de.pixelpark.net
     docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
     manage_docroot: false
-    port: 443
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    ssl: true
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
@@ -779,50 +774,8 @@ site::profile::apache::vhosts:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
-      - location_root:
-        provider: locationmatch
-        path: '^/(?!(server-status|server-info))'
-        auth_type: Digest
-        auth_name: pixelrealm
-        auth_digest_provider: file
-        auth_digest_algorithm: MD5
-        auth_user_file: '/etc/httpd/htdigest'
-        auth_require: 'valid-user'
-        require:
-          - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-    rewrites:
-      - rheuma:
-        comment: 'Redirect to rheuma domain'
-        rewrite_cond:
-          - '%%{ich-trickse}{REQUEST_URI} ^/rheuma.html$'
-        rewrite_rule:
-          - ^/rheuma.html$ https://dev-www-wegweiser-rheuma-de.pixelpark.net [R=301,L]
-      - psoriasis:
-        comment: 'Redirect to psoriasis domain'
-        rewrite_cond:
-          - '%%{ich-trickse}{REQUEST_URI} ^/psoriasis.html$'
-        rewrite_rule:
-          - ^/psoriasis.html$ https://dev-www-wegweiser-psoriasis-de.pixelpark.net [R=301,L]
-
-  dev-wegweiser-rheuma:
-    servername: dev-www-wegweiser-rheuma-de.pixelpark.net
-    docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
-    manage_docroot: false
-    port: 80
-    docroot_owner: apache
-    docroot_group: apache
-    docroot_mode: '0770'
-    directoryindex: rheuma.html
-    directories:
-      - directory_root:
-        provider: directory
-        path: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
-        options:
-          - FollowSymLinks
-          - MultiViews
-        allow_override:
-          - All
+          - None
+        directoryindex: rheuma.html
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -841,19 +794,21 @@ site::profile::apache::vhosts:
           - '%%{ich-trickse}{REQUEST_URI} ^/rheuma.html$'
         rewrite_rule:
           - ^/rheuma.html$ http://dev-www-wegweiser-rheuma-de.pixelpark.net [R=301,L]
-  dev-wegweiser-rheuma_ssl:
-    servername: dev-www-wegweiser-rheuma-de.pixelpark.net
+  dev-wegweiser-psoriasis:
+    servername: dev-www-wegweiser-psoriasis-de.pixelpark.net
     docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
     manage_docroot: false
-    port: 443
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    ssl: true
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
-    directoryindex: rheuma.html
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
@@ -863,6 +818,7 @@ site::profile::apache::vhosts:
           - MultiViews
         allow_override:
           - All
+        directoryindex: psoriasis.html
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -878,28 +834,30 @@ site::profile::apache::vhosts:
       - rheuma:
         comment: 'Redirect to rheuma domain'
         rewrite_cond:
-          - '%%{ich-trickse}{REQUEST_URI} ^/rheuma.html$'
+          - '%%{ich-trickse}{REQUEST_URI} ^/psoriasis.html'
         rewrite_rule:
-          - ^/rheuma.html$ https://dev-www-wegweiser-rheuma-de.pixelpark.net [R=301,L]
-
-  dev-wegweiser-psoriasis:
-    servername: dev-www-wegweiser-psoriasis-de.pixelpark.net
-    docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
-    manage_docroot: false
-    port: 80
+          - ^/psoriasis.html(.*)$ http://dev-www-wegweiser-psoriasis-de.pixelpark.net$1 [R=301,L]
+  dev-static.pfizer:
+    servername: dev-static-pfizer-de.pixelpark.net
+    docroot: '/srv/www/dev-static.pfizer.de'
+    ssl: false
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    directoryindex: psoriasis.html
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
-        path: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
+        path: '/srv/www/dev-static.pfizer.de'
         options:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -911,64 +869,24 @@ site::profile::apache::vhosts:
         auth_require: 'valid-user'
         require:
           - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-    rewrites:
-      - rheuma:
-        comment: 'Redirect to rheuma domain'
-        rewrite_cond:
-          - '%%{ich-trickse}{REQUEST_URI} ^/psoriasis.html'
-        rewrite_rule:
-          - ^/psoriasis.html(.*)$ http://dev-www-wegweiser-psoriasis-de.pixelpark.net$1 [R=301,L]
-  dev-wegweiser-psoriasis_ssl:
-    servername: dev-www-wegweiser-psoriasis-de.pixelpark.net
-    docroot: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
-    manage_docroot: false
-    port: 443
+  dev-www-breastcancer-matters-de:
+    servername: dev-www-breastcancer-matters-de.pixelpark.net
+    docroot: '/srv/www/dev-www-breastcancer-matters-de.pixelpark.net/drupal'
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    ssl: true
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
-    directoryindex: psoriasis.html
-    directories:
-      - directory_root:
-        provider: directory
-        path: '/srv/www/dev-www.wegweiser-rheuma-psoriasis.de/current'
-        options:
-          - FollowSymLinks
-          - MultiViews
-        allow_override:
-          - All
-      - location_root:
-        provider: locationmatch
-        path: '^/(?!(server-status|server-info))'
-        auth_type: Digest
-        auth_name: pixelrealm
-        auth_digest_provider: file
-        auth_digest_algorithm: MD5
-        auth_user_file: '/etc/httpd/htdigest'
-        auth_require: 'valid-user'
-        require:
-          - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-    rewrites:
-      - rheuma:
-        comment: 'Redirect to rheuma domain'
-        rewrite_cond:
-          - '%%{ich-trickse}{REQUEST_URI} ^/psoriasis.html'
-        rewrite_rule:
-          - ^/psoriasis.html(.*)$ http://dev-www-wegweiser-psoriasis-de.pixelpark.net$1 [R=301,L]
-  dev-static.pfizer:
-    servername: dev-static-pfizer-de.pixelpark.net
-    docroot: '/srv/www/dev-static.pfizer.de'
-    port: 80
-    docroot_owner: apache
-    docroot_group: apache
-    docroot_mode: '0770'
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
-        path: '/srv/www/dev-static.pfizer.de'
+        path: '/srv/www/dev-www-breastcancer-matters-de.pixelpark.net/drupal'
         options:
           - FollowSymLinks
           - MultiViews
@@ -985,26 +903,29 @@ site::profile::apache::vhosts:
         auth_require: 'valid-user'
         require:
           - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
-  dev-www-breastcancer-matters-de:
-    servername: dev-www-breastcancer-matters-de.pixelpark.net
-    docroot: '/srv/www/dev-www-breastcancer-matters-de.pixelpark.net/drupal'
-    port: 443
+  dev-pfizer-dtd-preview:
+    servername: dev-pfizer-dtd-preview.pixelpark.net
+    docroot: '/srv/www/dev-pfizer-dtd-preview'
     docroot_owner: apache
     docroot_group: apache
     docroot_mode: '0770'
-    ssl: true
     ssl_cert: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_chain: /etc/pki/tls/certs/wildcard.pixelpark.net-cert.pem
     ssl_key: /etc/pki/tls/private/wildcard.pixelpark.net-key.pem
+    headers:
+      - 'always unset "X-Powered-By"'
+      - 'set X-Content-Type-Options: nosniff'
+      - 'set X-XSS-Protection: "1; mode=block"'
+      - 'set X-Frame-Options: DENY'
     directories:
       - directory_root:
         provider: directory
-        path: '/srv/www/dev-www-breastcancer-matters-de.pixelpark.net/drupal'
+        path: '/srv/www/dev-pfizer-dtd-preview'
         options:
           - FollowSymLinks
           - MultiViews
         allow_override:
-          - All
+          - None
       - location_root:
         provider: locationmatch
         path: '^/(?!(server-status|server-info))'
@@ -1016,3 +937,4 @@ site::profile::apache::vhosts:
         auth_require: 'valid-user'
         require:
           - 'ip 217.66.55 217.66.50 217.66.51 217.66.48.130 168.224.160 10.121.101 204.114.176 204.114.216 148.168.40 202.32.173 204.114.248 168.224.1 168.224.160 148.168.127 204.114.196 193.235.226 212.58.14 204.114.199 155.94.99 155.94.78 155.94.62 218.213.241 155.94.70 155.94.110 222.73.72 155.94.119 155.94.55 68.58.141.20 174.137.32.22 15.213.17 85.183.14'
+          
\ No newline at end of file