-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[postfix] virtual machines allow list #4980
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This is a huge step forward. I see a couple of places where we could make it even better:
This PR updates 6 group_vars files, but we currently configure a postfix server in 7 group_vars files:
openbooks )staging and prod)
oawaiver (staging and prod)
ojs (staging and prod)
orangelight (prod only)
Do we want to change them all in this PR? Also, as mentioned below, we should document what we are using the staging ponyexpress for - my vote would be that we assign staging servers to the staging ponyexpress.
Finally, four playbooks refer in their documentation sections to the pul-the-hard-way docs on greenlisting servers for ponyexpress - it would be great to update those as well:
libwww.yml
friends_of_pul.yml
special_collections.yml
byzantine.yml
Thanks, @kayiwa! Writing down some notes from my testing, so we can look at them later. From catalog3, when I run the following in the rails console (with thanks to @carolyncole for the example that inspired this):
I get:
And /var/log/mail on lib-ponyexpr-prod says:
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks, @kayiwa !
For anyone following along, @kayiwa found the issue that was causing the tls error in the above catalog test, we needed to make sure that |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'd add a change to the ojs staging config. Once that's in, this looks great. Thanks @kayiwa.
Add the list of virtual machines that can relay messages
related to #4992 Co-authored-by: Beck Davis <beck-davis@users.noreply.github.com> Co-authored-by: Vickie Karasic <vickiekarasic@users.noreply.github.com>
Added at this commit 1445c3a |
Add the list of virtual machines that can relay messages
Initial machines that we believe need to send messages