diff --git a/ansible/bootstrap.yml b/ansible/bootstrap.yml index 18b8e8b..892944e 100644 --- a/ansible/bootstrap.yml +++ b/ansible/bootstrap.yml @@ -35,6 +35,8 @@ yum install -y sudo elif command -v apk >/dev/null 2>&1; then apk add --no-cache sudo + elif command -v pkg >/dev/null 2>&1; then + pkg bootstrap -y && pkg install -y sudo else echo "Unsupported package manager for sudo installation" >&2 exit 1 @@ -57,6 +59,8 @@ yum install -y python3 elif command -v apk >/dev/null 2>&1; then apk add --no-cache python3 py3-pip + elif command -v pkg >/dev/null 2>&1; then + pkg install -y python3 else echo "Unsupported package manager for python3 installation" >&2 exit 1 diff --git a/ansible/group_vars/all/all.yml b/ansible/group_vars/all/all.yml index 94151a7..9b53b2b 100644 --- a/ansible/group_vars/all/all.yml +++ b/ansible/group_vars/all/all.yml @@ -32,6 +32,8 @@ managed_users: authorized_keys: - type: github value: gmcintire + - type: string + value: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEEKtgXwoW8HZGqC+KJok9iNpI/lK4glvoryL4Ng/AL+" - name: andy shell: /bin/bash home: /home/andy diff --git a/ansible/group_vars/all/vault.yml b/ansible/group_vars/all/vault.yml index 05be873..5fb054b 100644 --- a/ansible/group_vars/all/vault.yml +++ b/ansible/group_vars/all/vault.yml @@ -1,94 +1,173 @@ $ANSIBLE_VAULT;1.1;AES256 -63333633326264363332366339613466666634616166363235326436326461366164333634393335 -6138666135333630313231613038653464613963323634650a303636356364316532653431386630 -61616239666337393065363537613536663061666437656333623162623265666332333539666264 -6366373632373833620a323837313065386632323137643233363132373762373765646264656239 -39646562623566343737623539636134393166326563303030643765336165626437626436343266 -30363264303661646230613865633439373730333861656333383531656439303733326234373364 -35663063396664396662653236363838373139353732343536376431396465633537333265396565 -38373630383237623665323461633062343734653334373362366139656434633662613038643934 -34656232353330663063356563323738396337313737373232363735633238653865366137656365 -39663738643239343762353633663434653837663963376537386563393264643630656433316265 -33323365333261623564656561383137313934623563333931636564346633383239333936626232 -66366636333435616331323633643835353338383235306665373336386138616137396564333666 -63393966323030353363663165346463366335643336366139303664616332363938333461373532 -66653461343635313834306239326639376238386137343336356366616131656632363237623233 -37656262393639393237613362363136643465633665636161356163373136666163373936383938 -63346263383836613662623265393732336335316261326335633935343437343731363435626130 -66633130626266663934383133313462366264636637646666343762303139663665333732353866 -62623936633862623330316165376130386337343730623263623861383462376466333961303234 -34356336323638386634656233616236666335376335373163663263303337346630373464643764 -66383764333839353266323666343532666238666663386432633932333836643163323835353461 -35663137326532616135313138653132303564346265336566613664316533306161393431346131 -33333163613432326330386539323636663838313361643366396530643536336534666638303335 -37343134616530336436333737396533363533306235353465633938373535366565323962383238 -63326361653732373262366234623038653936623236346361666532346335353939636162386663 -34373430363162323431636430666662383262343531653064333864653063666430306465336264 -34663435383538303166303231313261313137366162623961303337653461306339653530373865 -30353637633839656165393931613530323763613130363965386533386363383761613461393238 -65376333646230613764636565626333663031646231613631323734383562316437313133376637 -61373663326162313166646663396232333462623163323763303837303862393930373564643565 -31623965316630326666663037613133356539386462353563303437343335313835636231663630 -63373830303638323431323138333733383131643938663064613261353031663133646230613535 -36376536396366643034343837613463346465383234383637383763336363366433386461356665 -36363131353462356165376261613130653035616232626137666265363535346539666136663037 -64373966306136613133326138383766343164613031386132373832313865393962663437383936 -31626664646432396666646231386261383838393738346639393865363338326264633662653131 -39323161366431353831383235653465383364373532613865616361336162343830613734663139 -33363764333465666364303763656238646565393163383661643532383262616362653737343735 -61383430306139336461313035633534363131613033373864656264396232303933346639636236 -61313731343065626161363531303161356134653234666634363836333762393935613931613334 -66363431613564346464613165383434626532656166333435363034633463386239663933333037 -31613135633163383438623536616362666133653465666532653237633962633632663132393164 -66343536633262363861633534363737373432353962383061396232306363623765363761346463 -39633735336633663131346234376338616662336539343031333839373439653966633165383434 -61316465633663646165376237353638613162643661396466623638346163336632663065653538 -66313835343062336663653531323534316236313534336232386565373465333361323137313830 -31376662373830373237646131646665653266643064376336336663306563323066653238386564 -34306433623538333561663930333237313836656538656133663364313035393930326635303833 -34363832356663323537343562383265626432386365383236646531303432363138366537303533 -63393132623530393931643961646364336364346432336431646237633430313233613262333763 -30626631336465666662616136326366643965303261346665616631323330373333613739343161 -63636538306563386132613731613933326637363338643666396336313961366363653365356537 -36386666656634366235313032326363616166326236366462663233323234366564343232396366 -62313339626336343031626138373233373636623532343662343561633635636435383566373363 -64353566323438363132616238633133396337313564613261303666616163613766333261636436 -38393633313931613232303963313035626533373731646563653062386335303663636235623830 -31663339346131303963316562626233313832613138633466306335386363333731373661326232 -63303338356564356639303336626564323265653533616665623339623935303463353838623364 -38386236373165386439356566323932646339656261653638313665326438393561396261656465 -36366432396462666435626161383434333561383830336337613432363431336161656439346130 -38393465633030383763323936656564303063333561663930363930353534303863373538333636 -36363234386337626137316335646536336533383338316536386434316561616436356562366235 -34326134393237313266666536363364323931353633663930616330663933313136336234613338 -64366139313132636337323837663430373932663839663531353338363261393062363733393039 -33623831396531666263653136313037376462346633376434396232396163346138663736363833 -63663165353230393562623233623739313861626437323032616333393161353765636436666130 -38323266393138326666333066343161646336353564363965613565663362346663393838323731 -39303763643062653262653537636332366266363365336534663261373237363932336664663730 -61343038363062313561633639316139326537633866623538383666393863356439303433326634 -65623861343963323232613963613662353765623437623761333239646361356265663634653136 -63306637306639316138383838653738303136613465633765666665346134383235626234366535 -37376436313532303432306436356534663031373539323532663939346236646463363631613561 -63356436343064393435643666636130353231633566343438346233323137663434643263616439 -36323833346364636433616562646335376339336435316639643837363866663861643937383930 -32383037623262646334306337333735653137326362386439376439383538373130353862336638 -35643336613361663838626634626239333337666361653339623636313838666636323837666333 -31356132396239396632616233666638393231333964336533336130393565383739653232663935 -64373766353738646263316630326534653131613636666362376434363265616232636134383264 -62613037646463366164393830623630376132333232373137383337303134363662386230323331 -36326532623337393563646438396332396635303632636661396237636535383834343235356361 -37663431636339343630303462636331373134613664356162366236323930393562343436646236 -64363131616238373131653137303132633831303634323062663939373835613437636566303563 -66616634623766323937323031346233633563613333643261306264393761313232653065373465 -34653136376335663163623764356465383265366366333334353032663436383037333662323439 -66386630323939666163633636346665663564616263393431363762333930346461336538616538 -31666432326331663535626335643233616663323166313635363362316430356531646361653837 -35343230626666343033316562396233333830663563393632626230656166663461323136353831 -62383134363834313730326434636364303764633239666434313238316438656438626530333630 -62373264653863383939303439323362393266636663623931646339366165323038643864363834 -66383636363937306365653063653436303966616232383065663834383335393935666231613266 -30343562663632346663666332343735613933303462633334386632336230356461336638323737 -62653034616464356461633331376638396161626531373662613762333562373436316166323838 -65386335636334353735333438336635643630636166373934386430316438393965623235333731 -36363634643765373232626239356665316663313263306334643033656166346333 +33303162376164613464623864323932616634653932343066383263356564396232336531613039 +6662663537373133373963353638363261613066343064340a366662633237333633376266616561 +39383563343339373833323131336633333564613161633334633662326331396461623261313966 +3535373432666430340a343138656237633133636634333562343539663765303361613032306663 +61653165656562306162613536623936326465326132323034306361326138376336343438623430 +34383230396333366338643535666530353734343864376233313730343365613962386438646439 +33393062346136303631656635316337353937663330633463623537613531336463316665636132 +35626531393332336532323332393933316434653366633830666130333636303066623561663637 +64366566656366643563666337383835303733653261373032633066383730336136346665303833 +65346662373062373836333430306163663535373665386334353235313464623330336363326165 +39386361363039356166303133353739626162613637633930343131643030386463663537366361 +66626538663836646532636134346230623637626233633866346165396566383731313137303265 +31386632656466313864626235393434626638646564646162356365333530633536356436373436 +32313932323632663438343330636264373365336139616536343332623830616537663030316535 +36393238323465636533353832303264616438626630343963303032623763393533376161633138 +33653864363663633730333864303636333733653562323264323937363738656664343830386566 +30326163646338323334303937653739613238663661643132616665653031373832366135363864 +61623338343963636165373535306266646338656266643539383037656566663961336333643739 +33373332353334373035386438353232333661653961653465646231616264633738663064643738 +34616632663265343630626262646237363864373262396239353538623534643762333934383561 +39383931383161373965623337386430633762643366323965366439666263313833353561356232 +32353238336139343161356130343034393366353138346130666339376633333734393365383666 +65396430373664336562323438626136623633326561303630383038336539396262653032636335 +30656138373064663934663035323163313332333433306430313963393539306362623539393034 +64376238386230336138633137653662636262323561386564346538313564366636613866623836 +33623134333166313164623739383832666666396461656438616635376331623563376363623965 +32616537363861623262366437663637636563353034353932363264656263393035373461666162 +65633235643438393362323164393736363665643335326234323633613335323166616539633639 +39333338343338613766353735643266366130306462663433363163386635393639633539616633 +34393036366432333966366261313938613835373932303166336433623835316237353161616438 +36383066393732666638313461363133356561353537643663373834333733376432353337386163 +61633662643930313565326635663363656633316166383563643435616335633162376339336339 +33373265623837626436393335396133653764376232353564396161386365366538663331613538 +32363762376463623665373339663635356131616239333265343934353666323731623230343137 +62313437346531323966663163393562366336393937636137353666363631346333303631356132 +63613338383463386232313862613731663730376130366332323131343133363666353331653434 +61343839393333663766363530313362386534393166643062303633333834643838633837336263 +34663764373766376539373031663032303732356461303663366562646665366237313732613239 +30333235316630653134343437343939336631666538623264353765636332323763396535386535 +36363030346632346461643934306634616232336631343435313564396466336539376238393233 +63663939343838383739393433366239656663373464333337626530643262663432333465623437 +64656534623563653930333462393038303230643335646630326334653837346433303639326265 +34323337633338336464613163666534616335643462333234316630656230346161653338333961 +64643166633939393630643439313461313463383065663932323132343033376562666231326432 +39616530666435326366353532376536333564383166323232646133373134616335666566306133 +38336336336138363332343731396535633031626561643232623265336333653136623936323235 +36303730626530633261653031633563336237363339616536353738623564666666313762653564 +32663265323562336563613230653334303662663265346338303032646337653937363866663566 +64336663663164363036303466643739333238396164396631333163383365613830623430373062 +38343930363331636133376232333766323338666334333939323136333139623061646437343539 +34323538643030663432343937656438313962623730343330646664393933326463343565313434 +66353366326463363235613233623364646638346539653938336163643766373537383762643563 +65373537393666653039363965363362663264356536653263663133613265646431663738633662 +61303730363132643832393731373062613266363432633338343133633565653437663366323839 +65633335346564383638656362373436663031316539663339616366326432383436613765616561 +31633363623762343932663165366563656264343039313761616266653535646662356131336665 +30346637663165396465346662316537336238343838373566633563313039346633373937663166 +36393233353165376232613739376463306663343136643633643733336163316663393632396565 +65336261353766393166613561623332376366346366623135353964343564373763393739646463 +63383365366265656537303466663437633931343331613163303261363239666531663936623230 +61636432613861396562376138313161316239653862646533653133653162326664653265393239 +32333162656339343939616165303966626633333130643739336235633064626661633130316263 +65393263396131623964373065383839663136623332346637383734356433656539663334376238 +30636236353738626264336561663564333333613538343938353231633262663733653933666233 +62663135363061343233333061313530386634376638303238333239303636376331373730613961 +30333639653765313161666636376631373666393564353532313834336433373734353137646462 +37613263653338383566366461373362363431356336626630663031336532396333306137353233 +37636233303631623031663765333466636364653531363430663931306637633966336430353132 +32626461613736653430663337633136663435663732346330643663653730363939383430363534 +32366433613464613662303539333238613438346564336462623739393036393733623762643930 +65623937393437373538656239363166373339303036653638633932373061353165356361666438 +64333066343564323535646632326130626636393538356437623635313664653030393637613934 +61663966383134636264373664333666363936346337323661316138353231643035666238623866 +34303961353631323838346264383338656131346130363135333237353766353634303133373333 +37623665633731303537326661633332303764343366613339353365623536643961626365343765 +30386363376161616235623136336237326364356133383036663832333566656234313239353462 +31336638666563303031333931643766343036373831326433633135376630656233363661343264 +31346166666332666430656335653338353330383136373932356166633930643932616261626233 +35663835336138363864356464373265373464653438353637373163343030336364336163663364 +38653432636366393737633565663464623136326638663437373765373737633038393566333865 +31393132376238303862656539623737643937643135316563343866353738373232356434356330 +34623162666563383035343262303232656433363265313238373132363334653034363961623138 +30316264343831393466393234313035663265643233663532333961653932383565373731313566 +35323732386161366536366337396665303437346230323438396463623734346537346436376430 +62336337383530313331386565386334303639333761663032613666306235616134396339633864 +39633335623038393138666566396565303339326639346362366336306437376366626231356335 +30633932303963633931303332333630333438653765656237643966383138333963346138396135 +30363161366364613534666162376334313439303864626233623539653430353464633633353263 +66633161376564393962363935313932306165653437646661383238626338306430393566633362 +31663264633734316133323366633439383532303333333033336433333738653037373130643862 +32343030666631666531393335613932373536343263616565373632626138616537343266326537 +64333131663162623161353138633132623336653731313032313437656165303461613035653562 +34613234643364346539363931393837613766313938626132353139626534393865393363633430 +66333835363834303038613066626638333766333865333032636661353030633363363563393761 +35333034346337653862376136323064656237343563383832303335303535663238303665666233 +65613238643333653537643132373033393138313539346465376565663465383561346138356464 +65626431396532633638613463343264303037336162316634373937626665303363396137643837 +62643061326132663265383862353330636630653464356336613935396431663531386261376137 +64323937386334376332343064623639373461366166666136656436623333353738346662613638 +35626137323162373637663966663863353437323261366232633237636265663531376632373062 +35343839393134313836313464333631373364366338386637396364653462316430643235353134 +36386663383236386533316237663364653362653662643237633964663130343633336137326334 +35363934343239653836303333373862363436393736306231613263353064303338343136373363 +62353931336536663766646632663365323435373733343462343136616664396363623736613564 +36363364343761366337393563663532393531353062343266653734363364613839356237626338 +37616234636137363461323136313034316134306162663136633663653132363465643533313437 +37373536376262626565653033333662626637393565393235306165333362303530663463386364 +38353032636237623535386466623939633738303233383963653735333734336132336663383235 +38346231636565656163613234626464333634323166346534633233326562383166636366306663 +63633433623539323364316365613235363830336339653962653764633236653862316663353066 +30386139316266666336653633353633613139633036623037366563323861333632336334336131 +65386261313834343735636265306363613838373935313963376163396634653134323334643962 +36613030623834313331366633303766333136633866623235323065393665666535373861376634 +65393033613333626335376161373435303335633163356364353433313333643639313235396637 +62663137343835656532336366663839353831396563393162306134623731653763316231376432 +39386361623838376231356532633232383733663265363434396130646130323734363365663865 +63386266633539366336653565663063323365396362373631663363326362376361623133633336 +61396661336236316461333537333038656638313562356461353931323835316531653762613765 +63343934626161646365353263356434323338653863383333343431393634633933346539323531 +37306235313731663464393237396262633738363166333330623430663462633963356362646234 +34623361633731626335643335323336613636356630653532356331633132663739613630663964 +64626462383062306433303135323538336237623432613030326638633530313539363164313134 +35663066363337386163356438613939643830623830383761616330323136616339386333626132 +61363030353966616461646435333137336538343533643831303935373638393834383265343831 +61326331653835623935373330333138643634366432336464336563616238396138623131333434 +65663636656331643432333865336330343631623738656561323139633138333434373063656166 +31393735666232646536636131366137323432366530386135333530303734313539623465343739 +36343865663535336230343830343864623462376631626466613966346137633966333863623262 +33653739616261616136376533336135353635333839373438316364383131326434366534353532 +63316165623230623738633664633764613133633730383337336233616364356637313062343064 +65613232363331356139316161633639383963353666633430633635373033306532386236313665 +37323533383265373162313662656430623233613936353832653634303835656662373937633361 +63613866356663383939393434326530643234366462316230666134363530646631326465393865 +36633035323030663765626332363633626265633738353139663434356663303136643232633238 +65366335383961653865653636383036346135643064343765333863376666326135303233373163 +39653463386133326664363031396264363866303337323438616339393461393366643362393238 +62303735353738383135303939363437333062343437343030663265313632306132303461323431 +35356261333265313562373939616536383162363666666666326131306165343037313530393565 +61346430613064656231373161396163626461333830636338303232386537616363336361363763 +62613530343339336662326630633337336635643865663536323936316638313031343734326364 +34636130356335626662656462343238626564316131333566346661383438393830386162633765 +63393838616466353335646639366164666135646563383861383833623637303461643265666266 +63353233373936636565653539666264656438633330646665613266643064386437313362356236 +64613362653638306635393166356439656239303861666633616262396437353364383237333764 +65316465326536346636643836386363383365663765366431393031616134656438326436393636 +31663466633537393337386363353938303131373531376364656535356166646439653665366138 +36356339313739636431613730373931646264633461363735336534396264313363633864613464 +39383835636234386662303339303937383339323834383534633136316666383966343238303137 +39633536653035376335666265663731646164633835386666313361366231383933656332386639 +39353432326137663430643066666639636530353038326632333861653063326561396230323336 +36633766326364636131316333623461333436383561386231323565333431336266626230393536 +65353736366533663132376636323133386563636637386431323332373838663339346566663536 +38373964316537343263353338346438303733333062626232366139316162326434656462616437 +62323532383036343839396431366566323338383534343862343932333361343066653261633935 +30666634333161376432323266316339303062636562326638376166613862346465343663663365 +35336366313861626264383635613261663332356534343036666232386635363363623062323138 +34363038666564333565616261333532346663376263313630303934616331383761323037353066 +32656230393361373837346632656432306134333536326330663832633535373830653265633533 +37613137633634616639396666396430363831303463653238333163343433646639653436376233 +39623937653539653532393134333930303866626464303236653337393865313338356234363235 +34373962636239626533383062306638386333313166633439396630393233326461396464363135 +36633934333765653135633032656138333939323931666131623261626331633339353838346566 +39633238336337623936623639353465626437356630613436383536373137396465363765343634 +30326362613334323538323432643738303961626331623665306533386235646532313661396362 +62343136313836636335343565633537643563376463633565633834323861356637356261646436 +61353461623531653066363835353531373731356263306136646463653336313238623430333565 +30386338333335363530343535383965633161373465653231646565393930646436313438333535 +65643131636264303566613263346332636531626461353733353863313663316236366662303966 +61643736666631323465656562633637323061346539363938666663376363366561306166646565 +65633234356430643233313434663537623937323137623561363836313738353766653064383564 +39666563613638346136306433396631643762633630316164393131393264383965343439326436 +35313436363039663734 diff --git a/ansible/host_vars/ca.manero.org.yml b/ansible/host_vars/ca.manero.org.yml new file mode 100644 index 0000000..8458dc5 --- /dev/null +++ b/ansible/host_vars/ca.manero.org.yml @@ -0,0 +1,18 @@ +--- +# Debian IRC server — reachable via Tailscale MagicDNS +ansible_ssh_common_args: '-o StrictHostKeyChecking=accept-new' +ansible_python_interpreter: /usr/bin/python3 + +# Override the hostname derived from inventory_hostname (ca.manero.org → "ca"), +# since this box's actual hostname is manero-ca. +hostname_override: manero-ca + +inspircd_config_files: + - inspircd.conf + - modules.conf + - opers.conf + - links.conf + - irccloud.conf + - thelounge.conf + - motd.txt + - help.txt diff --git a/ansible/host_vars/us.manero.org.yml b/ansible/host_vars/us.manero.org.yml new file mode 100644 index 0000000..42a5a33 --- /dev/null +++ b/ansible/host_vars/us.manero.org.yml @@ -0,0 +1,25 @@ +--- +# FreeBSD IRC server — reachable via Tailscale MagicDNS +ansible_ssh_common_args: '-o StrictHostKeyChecking=accept-new' +ansible_python_interpreter: /usr/local/bin/python3 + +# This box's hostname is manero-us; the general role's Debian-only hostname +# tasks won't run here, so it stays as-is. +hostname_override: manero-us +network: + skip: true + +inspircd_config_files: + - inspircd.conf + - modules.conf + - opers.conf + - links.conf + - irccloud.conf + - help.conf + - filter.conf + - iso-8859-1.conf + - iso-8859-2.conf + - motd.txt + - opermotd.txt + - help.txt + - quotes.txt diff --git a/ansible/hosts b/ansible/hosts index 738a713..15085f7 100755 --- a/ansible/hosts +++ b/ansible/hosts @@ -24,7 +24,6 @@ skippy.w5isp.com mail.mcintire.me ansible_host=107.174.178.20 dokku.w5isp.com aprs.w5isp.com -staging.towerops.net prom.w5isp.com ansible_host=10.0.15.31 [prometheus_servers] @@ -34,7 +33,6 @@ prom.w5isp.com prometheus_servers [dokku_servers] -staging.towerops.net [aprsc_servers] aprs.w5isp.com @@ -61,3 +59,7 @@ node3 ansible_host=node3 [postgresql_servers] db.w5isp.com + +[irc_servers] +us.manero.org ansible_host=manero-us +ca.manero.org ansible_host=manero-ca diff --git a/ansible/playbook.yml b/ansible/playbook.yml index c58dc6a..3a2ee5c 100644 --- a/ansible/playbook.yml +++ b/ansible/playbook.yml @@ -267,3 +267,13 @@ tags: loki - role: grafana tags: grafana + +- name: Configure IRC servers + hosts: irc_servers + become: true + gather_facts: true + tags: + - irc + - inspircd + roles: + - inspircd diff --git a/ansible/roles/base/defaults/main.yml b/ansible/roles/base/defaults/main.yml index 44dbd77..d67875d 100644 --- a/ansible/roles/base/defaults/main.yml +++ b/ansible/roles/base/defaults/main.yml @@ -5,9 +5,34 @@ managed_users: [] admin_group_map: Debian: sudo RedHat: wheel + FreeBSD: wheel admin_group: "{{ admin_group_map.get(ansible_facts['os_family'], 'sudo') }}" +sudoers_dir_map: + Debian: /etc/sudoers.d + RedHat: /etc/sudoers.d + FreeBSD: /usr/local/etc/sudoers.d + Alpine: /etc/sudoers.d + +sudoers_dir: "{{ sudoers_dir_map.get(ansible_facts['os_family'], '/etc/sudoers.d') }}" + +sudoers_path_map: + Debian: /etc/sudoers + RedHat: /etc/sudoers + FreeBSD: /usr/local/etc/sudoers + Alpine: /etc/sudoers + +sudoers_path: "{{ sudoers_path_map.get(ansible_facts['os_family'], '/etc/sudoers') }}" + +visudo_path_map: + Debian: /usr/sbin/visudo + RedHat: /usr/sbin/visudo + FreeBSD: /usr/local/sbin/visudo + Alpine: /usr/sbin/visudo + +visudo_path: "{{ visudo_path_map.get(ansible_facts['os_family'], '/usr/sbin/visudo') }}" + base_common_packages: - git - vim @@ -35,6 +60,9 @@ base_packages_by_os_family: - smartmontools - lm_sensors - python3 + FreeBSD: + - sudo + - python3 base_packages_by_distribution: Ubuntu: diff --git a/ansible/roles/base/tasks/main.yml b/ansible/roles/base/tasks/main.yml index cc08499..f9ce482 100644 --- a/ansible/roles/base/tasks/main.yml +++ b/ansible/roles/base/tasks/main.yml @@ -44,4 +44,9 @@ name: debian when: ansible_facts['os_family'] == "Debian" +- name: Apply FreeBSD-specific configuration + ansible.builtin.include_role: + name: freebsd + when: ansible_facts['os_family'] == "FreeBSD" + diff --git a/ansible/roles/base/tasks/system.yml b/ansible/roles/base/tasks/system.yml index 4cfbcf1..85a6544 100644 --- a/ansible/roles/base/tasks/system.yml +++ b/ansible/roles/base/tasks/system.yml @@ -52,6 +52,16 @@ when: ansible_facts['os_family'] == "Alpine" notify: restart ssh + - name: Regenerate SSH host keys (FreeBSD) + ansible.builtin.shell: + ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key -N '' + ssh-keygen -t ecdsa -b 521 -f /etc/ssh/ssh_host_ecdsa_key -N '' + ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key -N '' + args: + creates: /etc/ssh/ssh_host_ed25519_key + when: ansible_facts['os_family'] == "FreeBSD" + notify: restart ssh + - name: Create marker file to prevent re-running ansible.builtin.file: path: /etc/ssh/.host_keys_regenerated diff --git a/ansible/roles/base/tasks/users.yml b/ansible/roles/base/tasks/users.yml index 2188c80..3a0a879 100644 --- a/ansible/roles/base/tasks/users.yml +++ b/ansible/roles/base/tasks/users.yml @@ -44,6 +44,10 @@ loop_control: label: "{{ item.name }}" when: item.state | default('present') != 'absent' + register: user_result + failed_when: + - user_result is failed + - '"currently used by process" not in user_result.msg' - name: Remove managed users marked absent ansible.builtin.user: @@ -83,24 +87,38 @@ - item.1.type | default('github') == 'file' - item.0.state | default('present') != 'absent' +- name: Install authorized keys from inline strings + ansible.posix.authorized_key: + user: "{{ item.0.name }}" + state: "{{ item.1.state | default('present') }}" + key: "{{ item.1.value }}" + manage_dir: "{{ item.1.manage_dir | default(true) }}" + exclusive: "{{ item.1.exclusive | default(false) }}" + loop: "{{ managed_users | default([]) | subelements('authorized_keys', skip_missing=True) }}" + loop_control: + label: "{{ item.0.name }} (string key)" + when: + - item.1.type | default('github') == 'string' + - item.0.state | default('present') != 'absent' + - name: Configure sudo for ansible user ansible.builtin.template: src: sudoers_ansible.j2 - dest: /etc/sudoers.d/ansible + dest: "{{ sudoers_dir }}/ansible" mode: '0440' - validate: 'visudo -cf %s' + validate: "{{ visudo_path }} -cf %s" - name: Configure sudo for graham user ansible.builtin.template: src: sudoers_graham.j2 - dest: /etc/sudoers.d/graham + dest: "{{ sudoers_dir }}/graham" mode: '0440' - validate: 'visudo -cf %s' + validate: "{{ visudo_path }} -cf %s" -- name: Enable passwordless sudo for %sudo +- name: Enable passwordless sudo for admin group ansible.builtin.lineinfile: - path: /etc/sudoers + path: "{{ sudoers_path }}" state: present - regexp: '^%sudo' - line: '%sudo ALL=(ALL) NOPASSWD: ALL' - validate: 'visudo -cf %s' + regexp: '^%{{ admin_group }}' + line: '{{ admin_group }} ALL=(ALL) NOPASSWD: ALL' + validate: "{{ visudo_path }} -cf %s" diff --git a/ansible/roles/freebsd/tasks/main.yml b/ansible/roles/freebsd/tasks/main.yml new file mode 100644 index 0000000..4f01366 --- /dev/null +++ b/ansible/roles/freebsd/tasks/main.yml @@ -0,0 +1,10 @@ +--- +- name: Update pkg repository catalog + ansible.builtin.command: pkg update + register: pkg_update + changed_when: "'up-to-date' not in pkg_update.stdout" + +- name: Upgrade installed packages + ansible.builtin.command: pkg upgrade -y + register: pkg_upgrade + changed_when: "'Your packages are up to date' not in pkg_upgrade.stdout" diff --git a/ansible/roles/general/handlers/main.yml b/ansible/roles/general/handlers/main.yml index 4f0ea41..c866d57 100644 --- a/ansible/roles/general/handlers/main.yml +++ b/ansible/roles/general/handlers/main.yml @@ -1,3 +1,6 @@ --- - name: Re-export NFS shares ansible.builtin.command: exportfs -ra + +- name: apply hostname + ansible.builtin.command: hostnamectl set-hostname {{ short_hostname }} diff --git a/ansible/roles/general/tasks/debian/hostname.yml b/ansible/roles/general/tasks/debian/hostname.yml new file mode 100644 index 0000000..666f914 --- /dev/null +++ b/ansible/roles/general/tasks/debian/hostname.yml @@ -0,0 +1,29 @@ +- name: Compute short hostname + ansible.builtin.set_fact: + short_hostname: "{{ hostname_override | default(inventory_hostname | split('.') | first) }}" + tags: + - network_hostname + - hostname + +- name: "Set hostname (/etc/hosts)" + ansible.builtin.template: + src: templates/etc/hosts.j2 + dest: "/etc/hosts" + owner: root + group: root + mode: '0644' + tags: + - network_hostname + - hostname + +- name: "Set hostname (/etc/hostname)" + ansible.builtin.template: + src: templates/etc/hostname.j2 + dest: "/etc/hostname" + owner: root + group: root + mode: '0644' + notify: apply hostname + tags: + - network_hostname + - hostname diff --git a/ansible/roles/general/tasks/debian/network.yml b/ansible/roles/general/tasks/debian/network.yml index 609153e..4cb34e5 100644 --- a/ansible/roles/general/tasks/debian/network.yml +++ b/ansible/roles/general/tasks/debian/network.yml @@ -86,28 +86,6 @@ tags: - network_interfaces -- name: "Set hostname (/etc/hosts)" - ansible.builtin.template: - src: templates/etc/hosts.j2 - dest: "/etc/hosts" - owner: root - group: root - mode: '0644' - when: network.skip | default(False) != True - tags: - - network_hostname - -- name: "Set hostname (/etc/hostname)" - ansible.builtin.template: - src: templates/etc/hostname.j2 - dest: "/etc/hostname" - owner: root - group: root - mode: '0644' - when: network.skip | default(False) != True - tags: - - network_hostname - - name: "Restart networking" ansible.builtin.systemd: name: networking diff --git a/ansible/roles/general/tasks/main.yml b/ansible/roles/general/tasks/main.yml index 93aa2e5..7073afc 100644 --- a/ansible/roles/general/tasks/main.yml +++ b/ansible/roles/general/tasks/main.yml @@ -11,6 +11,12 @@ tags: - motd +- name: Configure hostname + ansible.builtin.import_tasks: debian/hostname.yml + when: ansible_facts['os_family'] == "Debian" + tags: + - hostname + - name: Configure networking ansible.builtin.import_tasks: debian/network.yml when: ansible_facts['os_family'] == "Debian" diff --git a/ansible/roles/general/templates/etc/hostname.j2 b/ansible/roles/general/templates/etc/hostname.j2 index c68c883..3dc88e6 100644 --- a/ansible/roles/general/templates/etc/hostname.j2 +++ b/ansible/roles/general/templates/etc/hostname.j2 @@ -1 +1 @@ -{{ inventory_hostname | split(".") | first }} +{{ short_hostname }} diff --git a/ansible/roles/general/templates/etc/hosts.j2 b/ansible/roles/general/templates/etc/hosts.j2 index d47426b..8e5168c 100644 --- a/ansible/roles/general/templates/etc/hosts.j2 +++ b/ansible/roles/general/templates/etc/hosts.j2 @@ -1,8 +1,8 @@ 127.0.0.1 localhost {% if network.loopback_in_hosts | default(True) %} -127.0.1.1 {{ inventory_hostname }} {{ inventory_hostname | split(".") | first }} +127.0.1.1 {{ inventory_hostname }} {{ short_hostname }} {% else %} -{{ "%-15s" | format(ansible_facts['default_ipv4'].address) }} {{ inventory_hostname }} {{ inventory_hostname | split(".") | first }} +{{ "%-15s" | format(ansible_facts['default_ipv4'].address) }} {{ inventory_hostname }} {{ short_hostname }} {% endif %} # The following lines are desirable for IPv6 capable hosts diff --git a/ansible/roles/inspircd/defaults/main.yml b/ansible/roles/inspircd/defaults/main.yml new file mode 100644 index 0000000..de58644 --- /dev/null +++ b/ansible/roles/inspircd/defaults/main.yml @@ -0,0 +1,6 @@ +--- +inspircd_config_dir_map: + Debian: /etc/inspircd + FreeBSD: /usr/local/etc/inspircd + +inspircd_config_dir: "{{ inspircd_config_dir_map.get(ansible_facts['os_family'], '/etc/inspircd') }}" diff --git a/ansible/roles/inspircd/handlers/main.yml b/ansible/roles/inspircd/handlers/main.yml new file mode 100644 index 0000000..a2c4b9b --- /dev/null +++ b/ansible/roles/inspircd/handlers/main.yml @@ -0,0 +1,5 @@ +--- +- name: restart inspircd + ansible.builtin.service: + name: inspircd + state: restarted diff --git a/ansible/roles/inspircd/tasks/main.yml b/ansible/roles/inspircd/tasks/main.yml new file mode 100644 index 0000000..584fdb9 --- /dev/null +++ b/ansible/roles/inspircd/tasks/main.yml @@ -0,0 +1,55 @@ +--- +- name: Assert required vault variables are set + ansible.builtin.assert: + that: + - vault_inspircd_ca_oper_graham_password is defined + - vault_inspircd_ca_oper_andys_password is defined + - vault_inspircd_ca_link_us_sendpass is defined + - vault_inspircd_ca_link_us_recvpass is defined + - vault_inspircd_us_oper_graham_password is defined + - vault_inspircd_us_oper_andys_password is defined + - vault_inspircd_us_link_ca_sendpass is defined + - vault_inspircd_us_link_ca_recvpass is defined + - vault_inspircd_us_link_services_sendpass is defined + - vault_inspircd_us_link_services_recvpass is defined + fail_msg: >- + Missing one or more inspircd vault variables. See roles/inspircd/README.md + for the full list. + +- name: Install inspircd (Debian) + ansible.builtin.apt: + name: inspircd + state: present + when: ansible_facts['os_family'] == "Debian" + notify: restart inspircd + +- name: Install inspircd (FreeBSD) + community.general.pkgng: + name: inspircd + state: present + when: ansible_facts['os_family'] == "FreeBSD" + notify: restart inspircd + +- name: Ensure inspircd config directory exists + ansible.builtin.file: + path: "{{ inspircd_config_dir }}" + state: directory + owner: root + group: root + mode: '0755' + +- name: Deploy inspircd config files + ansible.builtin.template: + src: "{{ inventory_hostname }}/{{ item }}" + dest: "{{ inspircd_config_dir }}/{{ item }}" + owner: root + group: root + mode: '0644' + loop: "{{ inspircd_config_files }}" + notify: restart inspircd + +- name: Ensure inspircd is started and enabled + ansible.builtin.service: + name: inspircd + state: started + enabled: true diff --git a/ansible/roles/inspircd/templates/ca.manero.org/help.txt b/ansible/roles/inspircd/templates/ca.manero.org/help.txt new file mode 100644 index 0000000..bea8b9e --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/help.txt @@ -0,0 +1,20 @@ +Thanks for installing InspIRCd! + +In order to get your server running you need to create config files. Examples +can be found at `/usr/share/doc/inspircd/examples`. + +If you need any help with this then you can visit our support channel at +ircs://irc.teranova.net/inspircd, open a support discussion at +https://git.io/JIuYv, or refer to the the docs site: + + https://docs.inspircd.org/4/configuration + https://docs.inspircd.org/4/modules + +When you are done you can run the following command to start InspIRCd: + + /usr/bin/inspircd + +If you have installed from an official package you may need to prefix this +command with `sudo -g irc -u irc` to run as the correct group/user. + +You can also use one of the helper scripts in `/usr/share/inspircd`. diff --git a/ansible/roles/inspircd/templates/ca.manero.org/inspircd.conf b/ansible/roles/inspircd/templates/ca.manero.org/inspircd.conf new file mode 100644 index 0000000..12feb23 --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/inspircd.conf @@ -0,0 +1,183 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/inspircd.example.conf b/ansible/roles/inspircd/templates/ca.manero.org/inspircd.example.conf new file mode 100644 index 0000000..badc60b --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/inspircd.example.conf @@ -0,0 +1,1079 @@ +######################################################################## +# # +# ___ ___ ____ ____ _ # +# |_ _|_ __ ___ _ __|_ _| _ \ / ___|__| | # +# | || '_ \/ __| '_ \| || |_) | | / _` | # +# | || | | \__ \ |_) | || _ <| |__| (_| | # +# |___|_| |_|___/ .__/___|_| \_\\____\__,_| # +# |_| # +# ____ __ _ _ _ # +# / ___|___ _ __ / _(_) __ _ _ _ _ __ __ _| |_(_) ___ _ __ # +# | | / _ \| '_ \| |_| |/ _` | | | | '__/ _` | __| |/ _ \| '_ \ # +# | |__| (_) | | | | _| | (_| | |_| | | | (_| | |_| | (_) | | | | # +# \____\___/|_| |_|_| |_|\__, |\__,_|_| \__,_|\__|_|\___/|_| |_| # +# |___/ # +# # +##################################||#################################### + #||# +##################################||#################################### +# # +# This is an example of the config file for InspIRCd. # +# Change the options to suit your network. # +# # +# # +# ____ _ _____ _ _ ____ _ _ _ # +# | _ \ ___ __ _ __| | |_ _| |__ (_)___ | __ )(_) |_| | # +# | |_) / _ \/ _` |/ _` | | | | '_ \| / __| | _ \| | __| | # +# | _ < __/ (_| | (_| | | | | | | | \__ \ | |_) | | |_|_| # +# |_| \_\___|\__,_|\__,_| |_| |_| |_|_|___/ |____/|_|\__(_) # +# # +# Lines prefixed with READ THIS BIT, as shown above, are IMPORTANT # +# lines, and you REALLY SHOULD READ THEM. Yes, THIS MEANS YOU. Even # +# if you've configured InspIRCd before, these probably indicate # +# something new or different to this version and you SHOULD READ IT. # +# # +######################################################################## + +#-#-#-#-#-#-#-#-#-# INCLUDE CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# This optional tag allows you to include another config file # +# allowing you to keep your configuration tidy. The configuration # +# file you include will be treated as part of the configuration file # +# which includes it, in simple terms the inclusion is transparent. # +# # +# All paths to config files are relative to the config directory. # +# # +# You may also include an executable file, in which case if you do so # +# the output of the executable on the standard output will be added # +# to your config at the point of the include tag. # +# # +# Syntax is as follows: # +# # +# # +# # +# # +# Executable include example: # +# +# # + + +#-#-#-#-#-#-#-#-#-#-#-# VARIABLE DEFINITIONS -#-#-#-#-#-#-#-#-#-#-#-# +# # +# You can define variables that will be substituted later in the # +# configuration file. This can be useful to allow settings to be # +# easily changed, or to parameterize a remote includes. # +# # +# Variables may be redefined and may reference other variables. # +# Value expansion happens at the time the tag is read. # +# # +# See https://docs.inspircd.org/4/configuration/#define for a list of # +# predefined config variables. # + + + +#-#-#-#-#-#-#-#-#-#-#-#- SERVER DESCRIPTION -#-#-#-#-#-#-#-#-#-#-#-#- +# # +# Here is where you enter the information about your server. # +# # + + + + +#-#-#-#-#-#-#-#-#-#-#-#- ADMIN INFORMATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# Configures the name and email of the server admin. # +# # + + + + +#-#-#-#-#-#-#-#-#-#-#-#- PORT CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#- +# # +# Configure the port and address bindings here. # +# # + +# TLS listener that binds on a TCP/IP endpoint: + tag that you have defined. See the + # docs page for the TLS module you are using for more details: + # + # GnuTLS: https://docs.inspircd.org/4/modules/ssl_gnutls#sslprofile + # OpenSSL: https://docs.inspircd.org/4/modules/ssl_openssl#sslprofile + # + # You will need to load the ssl_openssl module for OpenSSL and ssl_gnutls + # for GnuTLS. + sslprofile="Clients" + + # defer: When this is non-zero, connections will not be handed over to + # the daemon from the operating system before data is ready. + # In Linux, the value indicates the time period we'll wait for a + # connection to come up with data. Don't set it too low! + # In BSD the value is ignored; only zero and non-zero is possible. + # Windows ignores this parameter completely. + # Note: This does not take effect on rehash. + # To change it on a running bind, you'll have to comment it out, + # rehash, comment it in and rehash again. + defer="0" + + # free: When this is enabled the listener will be created regardless of + # whether the interface that provides the bind address is available. This + # is useful for if you are starting InspIRCd on boot when the server may + # not have brought the network interfaces up yet. + free="no"> + +# Plaintext listener that binds on a TCP/IP endpoint: + + + +# Listener that binds on a UNIX endpoint (not supported on Windows): +# + + +# Listener accepting WebSocket connections. +# Requires the websocket module and SHA-1 hashing support (provided by the sha1 +# module). +# + +# You must define a custom tag which defines the TLS configuration +# for this listener. See the docs page for the TLS module you are using for +# more details. +# +# When linking servers, the OpenSSL and GnuTLS implementations are completely +# link-compatible and can be used alongside each other on each end of the link +# without any significant issues. + + +#-#-#-#-#-#-#-#-#-#- CONNECTIONS CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# This is where you can configure which connections are allowed # +# and denied access onto your server. The password is optional. # +# You may have as many of these as you require. To allow/deny all # +# connections, use a '*' or 0.0.0.0/0. # +# # +# -- It is important to note that connect tags are read from the -- # +# TOP DOWN. This means that you should have more specific deny # +# and allow tags at the top, progressively more general, followed # +# by a (should you wish to have one). # +# # +# Connect blocks are searched twice for each user - once when the TCP # +# connection is accepted, and once when the user completes their # +# connection. Most of the information (hostname, ident response, # +# password, TLS when using STARTTLS, etc) is only available during # +# the second search. If you are trying to make a closed server you # +# will probably need a connect block just for user connection. This # +# can be done by using # + +# To enable IRCCloud on your network uncomment this: +# + +# A connect class with set denies connections from the specified host/IP range. + + +# A connect class with set allows c from the specified host/IP range. + + #hash="bcrypt" + + # password: Password to use for this block/user(s) + password="secret" + + # maxchans: Maximum number of channels a user in this class + # can be in at one time. + maxchans="20" + + # timeout: How long the server will wait before disconnecting + # a user if they do not do anything on connect. + # (Note, this is a client-side thing, if the client does not + # send /NICK, /USER or /PASS) + timeout="20" + + # localmax: Maximum local connections per IP (or CIDR mask, see below). + localmax="3" + + # globalmax: Maximum global (network-wide) connections per IP (or CIDR mask, see below). + globalmax="3" + + # maxconnwarn: Enable warnings when localmax or globalmax are reached (defaults to yes) + maxconnwarn="no" + + # resolvehostnames: If disabled, no DNS lookups will be performed on connecting users + # in this class. This can save a lot of resources on very busy servers. + resolvehostnames="yes" + + # useconnectban: Defines if users in this class should be exempt from connectban limits. + # This setting only has effect when the connectban module is loaded. + #useconnectban="yes" + + # useconnflood: Defines if users in this class should be exempt from connflood limits. + # This setting only has effect when the connflood module is loaded. + #useconnflood="yes" + + # usednsbl: Defines whether or not users in this class are subject to DNSBL. Default is yes. + # This setting only has effect when the dnsbl module is loaded. + #usednsbl="yes" + + # useident: Whether to try to look up the real username of users in this class using + # the RFC 1413 identification protocol. + # This setting only has effect when the ident module is loaded. + useident="no" + + # usests: Whether a STS policy should be advertised to users in this class. + # This setting only has effect when the ircv3_sts module is loaded. + #usests="no" + + # webirc: Restricts usage of this class to the specified WebIRC gateway. + # This setting only has effect when the gateway module is loaded. + #webirc="name" + + # limit: How many users are allowed in this class + limit="5000" + + # modes: The modes to set on users in this class when they connect to + # the server. See https://docs.inspircd.org/4/user-modes/ for a list of + # user modes. The example below sets user modes c (deaf_commonchans) + # and x (cloak) which require the commonchans and cloak modules. + # This setting only has effect when the conn_umodes module is loaded. + modes="+cx" + + # requireident: Require that users of this block have a valid ident response. + # Requires the ident module to be loaded. + #requireident="yes" + + # requiressl: Require that users of this block use a TLS connection. + # This can also be set to "trusted", as to only accept client certificates + # issued by a certificate authority that you can configure in the + # settings of the TLS module that you're using. + # Requires the sslinfo module to be loaded. + #requiressl="yes" + + # requireaccount: Require that users of this block have authenticated to a + # user account. + # NOTE: You must complete the signon prior to full connection. Currently, + # this is only possible by using SASL authentication; passforward + # and PRIVMSG NickServ happen after your final connect block has been found. + # You can also set this to "nick" to require that users are logged into their + # current nickname. + # Requires the account module to be loaded. + #requireaccount="yes" + + # Alternate MOTD file for this connect class. The contents of this file are + # specified using <files secretmotd="filename"> or <execfiles ...> + # + # NOTE: the following escape sequences for IRC formatting characters can be + # used in your MOTD: + # Bold: \b + # Color: \c<fg>[,<bg>] + # Color (alt): \c{<fg>[,<bg>]} + # Hex Color: \h<fg>[,<bg>] + # Italic: \i + # Monospace: \m (not widely supported) + # Reset: \x + # Reverse: \r + # Strikethrough: \s (not widely supported) + # Underline: \u + # + # When using the alternate color syntax the following colors can be used: + # black, blue, brown, cyan, default, green, grey, light blue, + # light cyan, light green, light grey, magenta orange, pink, + # red, white, yellow. + # + # See https://defs.ircdocs.horse/info/formatting.html for more information + # on client support for formatting characters. + motd="secretmotd" + + # port: What port range this user is allowed to connect on. (optional) + # The ports MUST be set to listen in the bind blocks above. + port="6697,9999"> + +<connect + # name: Name to use for this connect block. Mainly used for + # connect class inheriting. + name="main" + + # allow: The IP address or hostname of clients that can use this + # class. You can specify either an exact match, a glob match, or + # a CIDR range here. + allow="*" + + # maxchans: Maximum number of channels a user in this class + # can be in at one time. + maxchans="20" + + # timeout: How long the server will wait before disconnecting + # a user if they do not do anything on connect. + # (Note, this is a client-side thing, if the client does not + # send /NICK, /USER or /PASS) + timeout="20" + + # pingfreq: How often the server tries to ping connecting clients. + pingfreq="2m" + + # hardsendq: maximum amount of data allowed in a client's send queue + # before they are dropped. Keep this value higher than the length of + # your network's /LIST or /WHO output, or you will have lots of + # disconnects from sendq overruns! + # Setting this to "1M" is equivalent to "1048576", "8K" is 8192, etc. + hardsendq="1M" + + # softsendq: amount of data in a client's send queue before the server + # begins delaying their commands in order to allow the sendq to drain + softsendq="10240" + + # recvq: amount of data allowed in a client's queue before they are dropped. + # Entering "10K" is equivalent to "10240", see above. + recvq="10K" + + # threshold: This specifies the amount of command penalty a user is allowed to have + # before being quit or fakelagged due to flood. Normal commands have a penalty of 1, + # ones such as /OPER have penalties up to 10. + # + # If you are not using fakelag, this should be at least 20 to avoid excess flood kills + # from processing some commands. + threshold="10" + + # commandrate: This specifies the maximum rate that commands can be processed. + # If commands are sent more rapidly, the user's penalty will increase and they will + # either be fakelagged or killed when they reach the threshold + # + # Units are millicommands per second, so 1000 means one line per second. + commandrate="1000" + + # fakelag: Use fakelag instead of killing users for excessive flood + # + # Fake lag stops command processing for a user when a flood is detected rather than + # immediately killing them; their commands are held in the recvq and processed later + # as the user's command penalty drops. Note that if this is enabled, flooders will + # quit with "RecvQ exceeded" rather than "Excess Flood". + fakelag="yes" + + # localmax: Maximum local connections per IP. + localmax="3" + + # globalmax: Maximum global (network-wide) connections per IP. + globalmax="3" + + # resolvehostnames: If disabled, no DNS lookups will be performed on connecting users + # in this class. This can save a lot of resources on very busy servers. + resolvehostnames="yes" + + # useident: Whether to try to look up the real username of users in this class using + # the RFC 1413 identification protocol. + # This setting only has effect when the ident module is loaded. + useident="no" + + # usests: Whether a STS policy should be advertised to users in this class. + # This setting only has effect when the ircv3_sts module is loaded. + #usests="no" + + # limit: How many users are allowed in this class + limit="5000" + + # modes: The modes to set on users in this class when they connect to + # the server. See https://docs.inspircd.org/4/user-modes/ for a list of + # user modes. The example below sets user modes c (deaf_commonchans) + # and x (cloak) which require the commonchans and cloak modules. + # This setting only has effect when the conn_umodes module is loaded. + modes="+cx"> + + + +#-#-#-#-#-#-#-#-#-#-#-#- CIDR CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#- +# # +# CIDR configuration allows detection of clones and applying of # +# throttle limits across a CIDR range. (A CIDR range is a group of # +# IPs, for example, the CIDR range 192.168.1.0-192.168.1.255 may be # +# represented as 192.168.1.0/24). This means that abuse across an ISP # +# is detected and curtailed much easier. Here is a good chart that # +# shows how many IPs the different CIDRs correspond to: # +# https://en.wikipedia.org/wiki/IPv4_subnetting_reference # +# https://en.wikipedia.org/wiki/IPv6_subnetting_reference # +# # + +<cidr + # ipv4clone: specifies how many bits of an IP address should be + # looked at for clones. The default only looks for clones on a + # single IP address of a user. You do not want to set this + # extremely low. (Values are 0-32). + ipv4clone="32" + + # ipv6clone: specifies how many bits of an IP address should be + # looked at for clones. The default only looks for clones on a + # single IP address of a user. You do not want to set this + # extremely low. (Values are 0-128). + ipv6clone="128"> + +# This file has all the information about oper classes, types and o:lines. +# You *MUST* edit it. +#<include file="&dir.example;/opers.example.conf"> + +#-#-#-#-#-#-#-#-#-#- MISCELLANEOUS CONFIGURATION -#-#-#-#-#-#-#-#-#-# +# # + +# Files block - contains files whose contents are used by the ircd +# +# motd - displayed on connect and when a user executes /MOTD +# Modules can also define their own files +<files motd="&dir.example;/motd.example.txt"> + +# Example of an executable file include. Note this will be read on rehash, +# not when the command is run. +#<execfiles motd="wget -O - https://www.example.com/motd.txt"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-# DNS SERVER -#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# If these values are not defined, InspIRCd uses the default DNS resolver +# of your system. + +<dns + # server: DNS server to use to attempt to resolve IP's to hostnames. + # in most cases, you won't need to change this, as inspircd will + # automatically detect the nameserver depending on /etc/resolv.conf + # (or, on Windows, your set nameservers in the registry.) + # Note that this must be an IP address and not a hostname, because + # there is no resolver to resolve the name until this is defined! + # + # server="127.0.0.1" + + # timeout: time to wait to try to resolve DNS/hostname. + timeout="5"> + +# An example of using an IPv6 nameserver +#<dns server="::1" timeout="5"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-# PID FILE -#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# Define the path to the PID file here. The PID file can be used to # +# rehash the ircd from the shell or to terminate the ircd from the # +# shell using shell scripts, perl scripts, etc... and to monitor the # +# ircd's state via cron jobs. If this is a relative path, it will be # +# relative to the runtime directory, and if it is not defined, the # +# default of 'inspircd.pid' is used. # +# # + +#<pid file="inspircd.pid"> + +#-#-#-#-#-#-#-#-#-#-#-#-#- LIST MODE LIMITS #-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# The <maxlist> tag is used customise the maximum number of each list # +# mode that can be set on a channel. # +# The tags are read from top to bottom and the list mode limit from # +# the first tag found which matches the channel name and mode type is # +# applied to that channel. # +# It is advisable to put an entry with the channel as '*' at the # +# bottom of the list. If none are specified or no maxlist tag is # +# matched, the banlist size defaults to 100 entries. # +# # + +# Allows #largechan to have up to 200 ban entries. +#<maxlist mode="ban" chan="#largechan" limit="200"> + +# Allows #largechan to have up to 200 ban exception entries. +#<maxlist mode="e" chan="#largechan" limit="200"> + +# Allows all channels and list modes not previously matched to have +# up to 100 entries. +<maxlist chan="*" limit="100"> + +#-#-#-#-#-#-#-#-#-#-#-#-#- SERVER OPTIONS -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# Settings to define which features are usable on your server. # +# # + +<options + # prefixquit: What (if anything) users' quit messages + # should be prefixed with. + prefixquit="Quit: " + + # suffixquit: What (if anything) users' quit messages + # should be suffixed with. + suffixquit="" + + # prefixpart: What (if anything) users' part messages + # should be prefixed with. + prefixpart="&quot;" + + # suffixpart: What (if anything) users' part message + # should be suffixed with. + suffixpart="&quot;" + + # fixedquit: Set all users' quit messages to this value. + #fixedquit="" + + # fixedpart: Set all users' part messages in all channels + # to this value. + #fixedpart="" + + # syntaxhints: If enabled, if a user fails to send the correct parameters + # for a command, the ircd will give back some help text of what + # the correct parameters are. + syntaxhints="no" + + # cyclehostsfromuser: If enabled, the source of the mode change for + # cyclehosts will be the user who cycled. This can look nicer, but + # triggers anti-takeover mechanisms of some obsolete bots. + cyclehostsfromuser="no" + + # announcets: If set to yes, when the timestamp on a channel changes, all users + # in the channel will be sent a NOTICE about it. + announcets="yes" + + # allowmismatch: Setting this option to yes will allow servers to link even + # if they don't have the same "optionally common" modules loaded. Setting this to + # yes may introduce some desyncs and unwanted behaviour. + allowmismatch="no" + + # defaultbind: Sets the default for <bind> tags without an address. Choices are + # ipv4 or ipv6; if not specified, IPv6 will be used if your system has support, + # falling back to IPv4 otherwise. + defaultbind="auto" + + # maskinlist: If enabled then channels will show the nick!user@host of a list + # mode setter in the mode list instead of just the nick of the list mode setter. + maskinlist="yes" + + # maskintopic: If enabled then channels will show the nick!user@host of the topic + # setter in the topic instead of just the nick of the topic setter. + maskintopic="yes" + + # pingwarning: If a server does not respond to a ping within this period, + # it will send a notice to opers with snomask +l informing that the server + # is about to ping timeout. + pingwarning="15" + + # serverpingfreq: How often pings are sent between servers. + serverpingfreq="1m" + + # splitwhois: Whether to split private/secret channels from normal channels + # in WHOIS responses. Possible values for this are: + # 'no' - list all channels together in the WHOIS response regardless of type. + # 'split' - split private/secret channels to a separate WHOIS response numeric. + # 'splitmsg' - the same as split but also send a message explaining the split. + splitwhois="no" + + # defaultmodes: The modes to set on a channel when it is created. See + # https://docs.inspircd.org/4/channel-modes/ for a list of channel + # modes. If a prefix mode is included in this option it will be set on + # the user that created the channel. The example below sets channel + # modes n (noextmsg) and t (topiclock) and grants channel prefix mode + # o (op) to the channel creator. + defaultmodes="not" + + # xlinemessage: This is the text that is sent to a user when they are + # banned from the server. + xlinemessage="You're banned! Email irc@&networkDomain; with the ERROR line below for help." + + # xlinequit: The quit message to show to opers and affected users when + # a user is [KGZ]-lined. The variables you can use in this are: + # + # %created% - The date/time at which the X-line was created. + # %duration% - The duration of the X-line. + # %expiry% - The date/time at which the X-line expires. + # %fulltype% - The type of X-line which was matched, suffixed with + # "-lined" if its name is one or two characters. + # %reason% - The reason the X-line was added. + # %remaining% - The duration remaining on the X-line. + # %setter% - The name of the X-line setter. + # %type% - The type of X-line which was matched. + xlinequit="%fulltype%: %reason%" + + # modesinlist: Whether to show the current channel modes in the /LIST + # output. Can be set to any one of: + # - yes Show the current channel modes to all users. + # - opers Show the current channel modes to server operators with the + # channels/auspex privilege. This is the default. + # - no Do not show the current channel modes in /LIST. + modesinlist="opers" + + # extbanformat: The method to use for normalising extbans. Can be set + # to one of: + # - any Do not perform any extban normalisation. + # - name Normalise extbans to use their name. + # - letter Normalise extbans to use their letter. This is useful for + # if you need to keep compatibility with v3. + # Defaults to "any" if not set. + extbanformat="name" + + # exemptchanops: Allows users with with a status mode to be exempt + # from various channel restrictions. Possible restrictions are: + # - anticaps Channel mode +B - blocks messages with too many capital + # letters (requires the anticaps module). + # - auditorium-see Permission required to see the full user list of + # a +u channel (requires the auditorium module). + # - auditorium-vis Permission required to be visible in a +u channel + # (requires the auditorium module). + # - blockcaps Channel mode +B - blocks messages with too many capital + # letters (requires the blockcaps module). + # - blockcolor Channel mode +c - blocks messages with formatting codes + # (requires the blockcolor module). + # - delaymsg Channel mode +d - blocks sending messages until specified + # seconds have passed since user join + # - filter Channel mode +g - blocks messages containing the given + # glob mask (requires the chanfilter module). + # - flood Channel mode +f - kicks (and bans) on text flood of a + # specified rate (requires the messageflood module). + # - nickflood Channel mode +F - blocks nick changes after a specified + # rate (requires the nickflood module). + # - noctcp Channel mode +C - blocks any CTCPs to the channel + # (requires the noctcp module). + # - nonick Channel mode +N - prevents users on the channel from + # changing nicks (requires the nonicks module). + # - nonotice Channel mode +T - blocks /NOTICEs to the channel + # (requires the nonotice module). + # - regmoderated Channel mode +M - blocks unregistered users from + # speaking (requires the account module). + # - stripcolor Channel mode +S - strips formatting codes from + # messages (requires the stripcolor module). + # - topiclock Channel mode +t - limits changing the topic to (half)ops + # You can also configure this on a per-channel basis with a channel mode and + # even negate the configured exemptions below. + # See exemptchanops in modules.example.conf for more details. + exemptchanops="filter:o nickflood:o nonick:v regmoderated:o" + + # invitebypassmodes: This allows /INVITE to bypass other channel modes. + # (Such as +k, +j, +l, etc.) + invitebypassmodes="yes" + + # nosnoticestack: This prevents snotices from 'stacking' and giving you + # the message saying '(last message repeated X times)'. Defaults to no. + nosnoticestack="no"> + + +#-#-#-#-#-#-#-#-#-#-#-# PERFORMANCE CONFIGURATION #-#-#-#-#-#-#-#-#-#-# +# # + +<performance + # netbuffersize: Size of the buffer used to receive data from clients. + # The ircd may only read this amount of text in 1 go at any time. + netbuffersize="10240" + + # somaxconn: The maximum number of connections that may be waiting + # in the accept queue. This is *NOT* the total maximum number of + # connections per server. Some systems may only allow this to be up + # to 5, while others (such as Linux and *BSD) default to 128. + # Setting this above the limit imposed by your OS can have undesired + # effects. + somaxconn="128" + + # softlimit: This optional feature allows a defined softlimit for + # connections. If defined, it sets a soft max connections value. + softlimit="12800" + + # clonesonconnect: If this is set to no, we won't check for clones + # on initial connection, but only after the DNS check is done. + # This can be useful where your main class is more restrictive + # than some other class a user can be assigned after DNS lookup is complete. + # Turning this option off will make the server spend more time on users we may + # potentially not want. Normally this should be negligible, though. + # Default value is yes + clonesonconnect="yes" + + # timeskipwarn: The time period that a server clock can jump by before + # operators will be warned that the server is having performance issues. + timeskipwarn="2s" + + # quietbursts: When syncing or splitting from a network, a server + # can generate a lot of connect and quit messages to opers with + # +C and +Q snomasks. Setting this to yes squelches those messages, + # which makes it easier for opers, but degrades the functionality of + # bots like BOPM during netsplits. + quietbursts="yes"> + +#-#-#-#-#-#-#-#-#-#-#-# SECURITY CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-# +# # + +<security + # announceinvites: This option controls which members of the channel + # receive an announcement when someone is INVITEd. Available values: + # 'none' - don't send invite announcements + # 'all' - send invite announcements to all members + # 'ops' - send invite announcements to ops and higher ranked users + # 'dynamic' - send invite announcements to halfops (if available) and + # higher ranked users. This is the recommended setting. + announceinvites="dynamic" + + # hideservices: If this value is set to yes, services servers will + # be hidden from non-opers in /LINKS and /MAP. + hideservices="no" + + # flatlinks: If this value is set to yes, /MAP and /LINKS will + # be flattened when shown to non-opers. + flatlinks="no" + + # hideserver: When defined, the given text will be used in place + # of the server name in public messages. As with <server:name> this + # does not need to resolve but does need to be a valid hostname. + # + # NOTE: enabling this will cause users' idle times to only be shown + # when a remote whois (/WHOIS <nick> <nick>) is used. + #hideserver="irc.&networkDomain;" + + # publicxlinequit: The quit message to show to unprivileged users when + # a user is [KGZ]-lined. The variables you can use in this are: + # + # %created% - The date/time at which the X-line was created. + # %duration% - The duration of the X-line. + # %expiry% - The date/time at which the X-line expires. + # %fulltype% - The type of X-line which was matched, suffixed with + # "-lined" if its name is one or two characters. + # %reason% - The reason the X-line was added. + # %remaining% - The duration remaining on the X-line. + # %setter% - The name of the X-line setter. + # %type% - The type of X-line which was matched. + #publicxlinequit="%fulltype%" + + # hidekills: If defined, replaces who executed a /KILL with a custom string. + hidekills="" + + # hideservicekills: Hide kills from clients of services servers from server notices. + hideservicekills="yes" + + # hidesplits: If enabled, non-opers will not be able to see which + # servers split in a netsplit, they will only be able to see that one + # occurred (If their client has netsplit detection). + hidesplits="no" + + # maxtargets: Maximum number of targets per command. + # (Commands like /NOTICE, /PRIVMSG, /KICK, etc) + maxtargets="20" + + # customversion: A custom message to be displayed in the comments field + # of the VERSION command response. This does not hide the InspIRCd version. + customversion="" + + # runasuser: If this is set, InspIRCd will attempt to switch + # to run as this user, which allows binding of ports under 1024. + # You should NOT set this unless you are starting as root. + # NOT SUPPORTED/NEEDED UNDER WINDOWS. + #runasuser="" + + # runasgroup: If this is set, InspIRCd will attempt to switch + # to run as this group, which allows binding of ports under 1024. + # You should NOT set this unless you are starting as root. + # NOT SUPPORTED/NEEDED UNDER WINDOWS. + #runasgroup="" + + # restrictbannedusers: If this is set to yes, InspIRCd will not allow users + # banned on a channel to change nickname or message channels they are + # banned on. This can also be set to silent to restrict the user but not + # notify them. + restrictbannedusers="yes" + + # genericoper: Setting this value to yes makes all opers on this server + # appear as 'is a server operator' in their WHOIS, regardless of their + # oper type, however oper types are still used internally. This only + # affects the display in WHOIS. + genericoper="no" + + # userstats: /STATS commands that users can run (opers can run all). + userstats="Pu"> + +#-#-#-#-#-#-#-#-#-#-#-#-# LIMITS CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-# +# # +# This configuration tag defines the maximum sizes of various types # +# on IRC, such as the maximum length of a channel name, and the # +# maximum length of a channel. These values should match network-wide # +# otherwise issues will occur. # +# # +# The highest safe value you can set any of these options to is 500, # +# but it is recommended that you keep them somewhat # +# near their defaults (or lower). # + +<limits + # maxaway: Maximum length of an away message. + maxaway="200" + + # maxchan: Maximum length of a channel name. + maxchan="60" + + # maxhost: Maximum length of a hostname. + maxhost="64" + + # maxuser: Maximum length of a username. + maxuser="10" + + # maxkey: Maximum length of a channel key. + maxkey="30" + + # maxkick: Maximum length of a kick message. + maxkick="300" + + # maxmodes: Maximum number of mode changes per line. + maxmodes="20" + + # maxnick: Maximum length of a nickname. + maxnick="30" + + # maxquit: Maximum length of a quit message. + maxquit="300" + + # maxreal: Maximum length of a real name. + maxreal="130" + + # maxtopic: Maximum length of a channel topic. + maxtopic="330"> + +#-#-#-#-#-#-#-#-#-#-#-#-# PATHS CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-#-# +# # +# This configuration tag defines the location that InspIRCd stores # +# various types of files such as configuration files, log files and # +# modules. You will probably not need to change these from the values # +# set when InspIRCd was built unless you are using a binary package # +# where you do not have the ability to set build time configuration. # +#<path configdir="conf" datadir="data" logdir="logs" moduledir="modules"> + +#-#-#-#-#-#-#-#-#-#-#-# LOGGING CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-#-# +# # +# The <log> tag allows you to define a list of targets to write log # +# messages to. # +# # +# method - The method to use when logging. This can be set to "file" # +# to log to a file, "stderr" to log to the standard error # +# stream, or "stdout" to log to the standard output stream. # +# You can also set it to a log method provided by a module. # +# # +# level - The level of messages to write to this logger. Can be set # +# to "error", "warning", "normal", or "debug". # +# # +# type - A space-delimited list of log types to write to this logger. # +# See https://docs.inspircd.org/4/configuration/#log for a # +# full list of log types. You can also use * to include every # +# log type and then -TYPE to exclude specific unwanted types. # +# # +# target - If the method is set to "file" then the name of the file # +# to write log messages to. # + +<log method="file" + level="normal" + type="* -USERINPUT -USEROUTPUT" + target="inspircd.log"> + +#<log method="stderr" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> + +#<log method="stdout" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> + +#-#-#-#-#-#-#-#-#-#-#-#-#- WHOWAS OPTIONS -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# This tag lets you define the behaviour of the /WHOWAS command of # +# your server. # +# # +<whowas + # groupsize: Maximum entries per nick shown when performing + # a /WHOWAS <nick>. Defaults to 10. + groupsize="10" + + # maxgroups: Maximum number of nickgroups that can be added to + # the list so that /WHOWAS does not use a lot of resources on + # large networks. Defaults to 10000. + maxgroups="10000" + + # maxkeep: Maximum time a nick is kept in the whowas list + # before being pruned. Time may be specified in seconds, + # or in the following format: 1y2w3d4h5m6s. Minimum is + # 1 hour. Defaults to 7 days. + maxkeep="7d" + + # nickupdate: Whether to update the WHOWAS database on nick + # change as well as quit. This can significantly increase the + # memory usage of your IRC server so it is not recommended + # for large networks. Defaults to yes. + nickupdate="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#- BAN OPTIONS -#-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# The ban tags define nick masks, host masks and ip ranges which are # +# banned from your server. All details in these tags are local to # +# Your server. # +# # + +<badip + # ipmask: IP range to ban. Wildcards and CIDR can be used. + ipmask="192.0.2.69" + + # reason: Reason to display when user is disconnected. + reason="No porn here thanks."> + +<badnick + # nick: Nick to disallow. Wildcards are supported. + nick="Tr0ll123" + + # reason: Reason to display on /NICK. + reason="Don't use this nick."> + +<badhost + # host: username@hostname to ban. + # Wildcards and CIDR (if you specify an IP) can be used. + host="*@banneduser.example.net" + + # reason: Reason to display when user is disconnected + reason="Evading Bans"> + +<badhost host="root@*" reason="Don't IRC as root!"> +<badhost host="*@198.51.100.0/24" reason="This subnet is bad."> + +# exception: Hosts that are exempt from [KGZ]-lines. +<exception + # host: username@hostname to exempt. + # Wildcards and CIDR (if you specify an IP) can be used. + host="*@serverop.example.com" + + # reason: Reason for exception. Only shown in /STATS e. + reason="Oper's hostname"> + +#-#-#-#-#-#-#-#-#-#-#- INSANE BAN OPTIONS -#-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# This optional tag allows you to specify how wide a G-line, E-line, # +# K-line, Z-line or Q-line can be before it is forbidden from being # +# set. By setting hostmasks="yes", you can allow all G-, K-, E-lines, # +# no matter how many users the ban would cover. This is not # +# recommended! By setting ipmasks="yes", you can allow all Z-lines, # +# no matter how many users these cover too. Needless to say we # +# don't recommend you do this, or, set nickmasks="yes", which will # +# allow any Q-line. # +# # + +<insane + # hostmasks: Allow bans with insane hostmasks. (over-reaching bans) + hostmasks="no" + + # ipmasks: Allow bans with insane ipmasks. (over-reaching bans) + ipmasks="no" + + # nickmasks: Allow bans with insane nickmasks. (over-reaching bans) + nickmasks="no" + + # trigger: What percentage of users on the network to trigger + # specifying an insane ban as. The default is 95.5%, which means + # if you have a 1000 user network, a ban will not be allowed if it + # will be banning 955 or more users. + trigger="95.5"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# MODULES #-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# ____ _ _____ _ _ ____ _ _ _ # +# | _ \ ___ __ _ __| | |_ _| |__ (_)___ | __ )(_) |_| | # +# | |_) / _ \/ _` |/ _` | | | | '_ \| / __| | _ \| | __| | # +# | _ < __/ (_| | (_| | | | | | | | \__ \ | |_) | | |_|_| # +# |_| \_\___|\__,_|\__,_| |_| |_| |_|_|___/ |____/|_|\__(_) # +# # +# Well done, you've reached the end of the basic configuration, your # +# ircd should now start if you want to try it out! (./inspircd start) # +# # +# We now suggest you read and edit modules.conf, as modules are what # +# provide almost all the features of InspIRCd. :) # +# # +# The default does nothing -- we include it for simplicity for you. # +#<include file="&dir.example;/modules.example.conf"> + +#-#-#-#-#-#-#-#-#-#-#-# SERVICES CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-# +# # +# If you use services you will probably want to include one of the # +# following files which set up aliases, nick reservations and filter # +# exemptions for services pseudoclients: # +# +# Anope users should uncomment this: +#<include file="&dir.example;/services/anope.example.conf"> +# +# Atheme users should uncomment this: +#<include file="&dir.example;/services/atheme.example.conf"> +# +# Users of other services should uncomment this: +#<include file="&dir.example;/services/generic.example.conf"> + +######################################################################### +# # +# - InspIRCd Development Team - # +# https://www.inspircd.org # +# # +######################################################################### diff --git a/ansible/roles/inspircd/templates/ca.manero.org/irccloud.conf b/ansible/roles/inspircd/templates/ca.manero.org/irccloud.conf new file mode 100644 index 0000000..5e3cdc3 --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/irccloud.conf @@ -0,0 +1,31 @@ +# This file contains connect classes which are used by IRCCloud users. +# See https://www.irccloud.com for more information on IRCCloud and +# https://www.irccloud.com/networks for more information on supporting +# IRCCloud on your network. + +<connect name="IRCCloud" + parent="main" + globalmax="100" + localmax="100" + useconnectban="no" + useconnflood="no" + usednsbl="no"> + +<connect name="IRCCloud (IPv4)" + parent="IRCCloud" + allow="5.254.36.56/29 5.254.36.104/29" + uniqueusername="yes"> + +# This is not typically needed as each user has their own IPv6 but if you have +# <cidr:ipv6clone> set to a value lower than 128 you will need to enable it. +#<connect name="IRCCloud (IPv6)" +# parent="IRCCloud" +# allow="2a03:5180:f::/62 2a03:5180:f:4::/63 2a03:5180:f:6::/64"> + +# IRCCloud IPv4 users use a shared IPv4 address which means that some clients +# may have trouble banning them. To work around this you can use the cloak_user +# module to copy the user identifier from the username to the hostname. +#<cloak method="username" +# class="IRCCloud (IPv4),IRCCloud (IPv6)" +# suffix=".irccloud.com"> + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/links.conf b/ansible/roles/inspircd/templates/ca.manero.org/links.conf new file mode 100644 index 0000000..91eb68a --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/links.conf @@ -0,0 +1,19 @@ +<bind address="" port="7001" type="servers" sslprofile="sslprofile"> + +<link + name="us.manero.org" + ipaddr="100.93.123.98" + port="7001" + allowmask="100.93.123.98/32" + timeout="1m" + sslprofile="sslprofile" + bind="" + statshidden="no" + hidden="no" + sendpass="{{ vault_inspircd_ca_link_us_sendpass }}" + recvpass="{{ vault_inspircd_ca_link_us_recvpass }}"> + + +<uline server="services.manero.org" silent="yes"> +<autoconnect period="1m" server="us.manero.org"> + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/modules.conf b/ansible/roles/inspircd/templates/ca.manero.org/modules.conf new file mode 100644 index 0000000..794ab19 --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/modules.conf @@ -0,0 +1,159 @@ +<module name="alias"> +<module name="allowinvite"> +<module name="chancreate"> +<module name="check"> +<module name="chghost"> +<module name="chgident"> +<module name="chgname"> +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Cloak module: Adds user mode x (cloak) which allows user hostnames to +# be hidden. This module does not provide any cloak methods by itself. +# You should also load another module like cloak_account or cloak_sha256. +# +# In order to have users automatically cloaked on connect you should +# load the conn_umodes module and add "x" to <connect:modes>. +<module name="cloak"> +<module name="cloak_user"> +#<include file="&dir;/codepages/ascii.conf"> +#<include file="&dir;/codepages/iso-8859-1.conf"> +#<include file="&dir;/codepages/iso-8859-2.conf"> +#<include file="&dir;/codepages/rfc1459.conf"> +#<include file="&dir;/codepages/strict-rfc1459.conf"> +<module name="customprefix"> +<module name="hidechans"> + +<module name="cap"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 module: Provides the IRCv3 account-notify, away-notify, +# extended-join, and standard-replies extensions. These are optional +# enhancements to the client-to-server protocol. An extension is only +# active for a client when the client specifically requests it, so this +# module needs the cap module to work. +# +# Further information on these extensions can be found at the IRCv3 +# working group website: +# https://ircv3.net/irc/ +# +<module name="ircv3"> +# The following block can be used to control which extensions are +# enabled. Note that extended-join can be incompatible with delayjoin +# and host cycling. +#<ircv3 accountnotify="yes" +# awaynotify="yes" +# extendedjoin="yes" +<module name="ircv3_accounttag"> +<module name="ircv3_batch"> +<module name="ircv3_capnotify"> +<module name="ircv3_chghost"> +<module name="ircv3_ctctags"> +<module name="ircv3_echomessage"> +<module name="ircv3_invitenotify"> +<module name="ircv3_labeledresponse"> +<module name="ircv3_msgid"> +<module name="ircv3_servertime"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 Strict Transport Security module: Provides the sts IRCv3 +# extension which allows clients connecting insecurely to upgrade their +# connections to TLS. +<module name="ircv3_sts"> +<sts host="ca.manero.org" port="6697" duration="1d"> +# +# If using the ircv3_sts module you MUST define a STS policy to send +# to clients using the <sts> tag. This tag takes the following +# attributes: +# +# host - A glob match for the SNI hostname to apply this policy to. +# duration - The amount of time that the policy lasts for. Defaults to +# five minutes by default. You should raise this to a month +# or two once you know that your config is valid. +# port - The port on which TLS connections to the server are being +# accepted. You MUST have a CA-verified certificate on this +# port. Self signed certificates are not acceptable. +# preload - Whether client developers can include your certificate in +# preload lists. +# +# <sts host="*.com" duration="5m" port="6697" preload="yes"> + +<module name="messageflood"> +# +# The weight to give each message type. TAGMSGs are considered to be +# 1/5 of a NOTICE or PRIVMSG to avoid users being accidentally flooded +# out of a channel by automatic client features such as typing +# notifications. +#<messageflood message="Message flood detected (trigger is %messages% messages in %duration%)" +# extended="yes" +# notice="1.0" +# privmsg="1.0" +# tagmsg="0.2"> + +<module name="monitor"> +<monitor maxentries="30"> +<module name="multiprefix"> +<module name="nokicks"> +<passforward + + # nick: The nick of the service to forward passwords to. + nick="NickServ" + + # forwardmsg: Message to send to users when forwarding their + # password. You can use the following variables in this message: + # + # %nick% The nickname of the authenticating user. + # %nickrequired% The nickname of the service to forward to (see above). + # %pass% The password to forward to services. + # %user% The username of the authenticating user. + forwardmsg="NOTICE %nick% :*** Forwarding password to %nickrequired%" + + # cmd: The message to send to forward passwords to services. + cmd="SQUERY %nickrequired% :IDENTIFY %nick% %pass%"> + +<module name="sajoin"> +<module name="samode"> +<module name="sanick"> +<module name="satopic"> +<module name="services"> +<servicesintegration accountoverrideshold="yes" + disablemodes="no"> +<module name="sethost"> +<module name="setident"> +<module name="setidle"> +<module name="setname"> +<setname notifyopers="yes"> +<module name="sha1"> +<module name="sha2"> +<module name="showfile"> +<module name="showwhois"> +<showwhois opersonly="yes"> +<module name="shun"> +<module name="spanningtree"> +<include file="&dir;/links.conf"> +#<module name="ssl_openssl"> +<module name="stripcolor"> +<module name="vhost"> +<module name="services_account"> +<module name="ssl_gnutls"> + + +<module name="bcrypt"> +<bcrypt rounds="10"> + +<module name="password_hash"> +<mkpasswd operonly="no"> + +<module name="knock"> +<knock notify="notice"> +<module name="swhois"> +<module name="sakick"> +<module name="autoop"> +<module name="sslmodes"> +<module name="sslinfo"> +<module name="override"> +<module name="sasl"> +<sasl requiressl="no" + target="services.manero.org"> +<module name="customprefix"> +<module name="hideoper"> +<hideoper mode="yes"> + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/modules.example.conf b/ansible/roles/inspircd/templates/ca.manero.org/modules.example.conf new file mode 100644 index 0000000..66593af --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/modules.example.conf @@ -0,0 +1,2724 @@ +#-#-#-#-#-#-#-#-#-#-#-#-#- MODULE OPTIONS -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# These tags define which modules will be loaded on startup by your # +# server. Add modules without any paths. When you make your ircd # +# using the 'make' command, all compiled modules will be moved into # +# the folder you specified when you ran ./configure. The module tag # +# automatically looks for modules in this location. # +# If you attempt to load a module outside of this location, either # +# in the config, or via /LOADMODULE, you will receive an error. # +# # +# By default, ALL modules are commented out. You must uncomment them # +# or add lines to your config to load modules. Please refer to # +# https://docs.inspircd.org/4/modules for a list of modules and # +# each modules link for any additional conf tags they require. # +# # +# ____ _ _____ _ _ ____ _ _ _ # +# | _ \ ___ __ _ __| | |_ _| |__ (_)___ | __ )(_) |_| | # +# | |_) / _ \/ _` |/ _` | | | | '_ \| / __| | _ \| | __| | # +# | _ < __/ (_| | (_| | | | | | | | \__ \ | |_) | | |_|_| # +# |_| \_\___|\__,_|\__,_| |_| |_| |_|_|___/ |____/|_|\__(_) # +# # +# To link servers to InspIRCd, you MUST load the spanningtree module. # +# If you don't do this, server links will NOT work at all. # +# This is by design, to allow for the implementation of other linking # +# protocols in modules in the future. This module is at the bottom of # +# this file. # +# # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Abbreviation module: Provides the ability to abbreviate commands a-la +# BBC BASIC keywords. +#<module name="abbreviation"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Account support module: Adds support for user accounts as well as +# several several modes relating to accounts. +#<module name="account"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Alias module: Allows you to define server-side command aliases. +#<module name="alias"> +# +# Set the 'prefix' for in-channel aliases (fantasy commands) to the +# specified character. If not set, the default is "!". +# If 'allowbots' is disabled, +B clients will not be able to use +# fantasy commands. If not set, the default is no. +#<fantasy prefix="!" allowbots="no"> +# +#-#-#-#-#-#-#-#-#-#-#- ALIAS DEFINITIONS -#-#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# If you have the alias module loaded, you may also define aliases as # +# shown below. They are commonly used to provide shortcut commands to # +# services, however they are not limited to just this use. # +# An alias tag requires the following values to be defined in it: # +# # +# text - The text to detect as the actual command line. # +# Can't contain spaces, but case insensitive. # +# You may have multiple aliases with the same # +# command name (text="" value), however the first # +# found will be executed if its format value is # +# matched, or it has no format value. Aliases are # +# read from the top of the file to the bottom. # +# # +# usercommand - If set to yes, the alias can be run simply as # +# /ALIASNAME. Defaults to yes. # +# # +# channelcommand - If set to yes, the alias can be used as an # +# in-channel alias or 'fantasy command', prefixed # +# by the fantasy prefix character, !aliasname by # +# default. Defaults to no. # +# # +# format - If this is defined, the parameters of the alias # +# must match this glob pattern. For example if you # +# want the first parameter to start with a # for # +# the alias to be executed, set format="#*" in the # +# alias definition. Note that the :'s which are # +# part of IRC formatted lines will be preserved # +# for matching of this text. This value is # +# optional. # +# # +# replace - The text to replace 'text' with. Usually this # +# will be "PRIVMSG ServiceName :$2-" or similar. # +# You may use the variables $1 through $9 in the # +# replace string, which refer to the first through # +# ninth word in the original string typed by the # +# user. You may also use $1- through $9- which # +# refer to the first word onwards, through to the # +# ninth word onwards, e.g. if the user types the # +# command "foo bar baz qux quz" then $3- will hold # +# "baz qux quz" and $2 will contain "bar". You may # +# also use the special variables: $nick, $user, # +# $address, $host and $vhost, and you may separate # +# multiple commands with a newline (which can be # +# written in the file literally or encoded as &nl; # +# # +# requires - If you provide a value for 'requires' this means # +# the given nickname MUST be online for the alias # +# to successfully trigger. If they are not, then # +# the user receives a 'no such nick' 401 numeric. # +# # +# stripcolor - If set to yes, the text from the user will be # +# stripped of color and format codes before # +# matching against 'text'. # +# # +# service - Setting this to yes will ensure that the user # +# given in 'requires' is also on a servicesserver, # +# as well as actually being on the network. If the # +# user is online, but not on a services server, # +# then an oper alert is sent out as this is # +# possibly a sign of a user trying to impersonate # +# a service. # +# # +# operonly - If yes, this will make the alias oper only. # +# If a non-oper attempts to use the alias, it will # +# appear to not exist. # +# # +# +# An example of using the format value to create an alias with two +# different behaviours depending on the format of the parameters. +# +#<alias text="ID" format="#*" replace="PRIVMSG ChanServ :IDENTIFY $2 $3" +# requires="ChanServ" service="yes"> +# +#<alias text="ID" replace="PRIVMSG NickServ :IDENTIFY $2" +# requires="NickServ" service="yes"> +# +# You may also add aliases to trigger based on something said in a +# channel, aka 'fantasy' commands, configured in the same manner as any +# other alias, with usercommand="no" and channelcommand="yes" The +# command must be preceded by the fantasy prefix when used. +# +#<alias text="CS" usercommand="no" channelcommand="yes" +# replace="PRIVMSG ChanServ :$1 $chan $2-" requires="ChanServ" service="yes"> +# +# This would be used as "!cs <command> <options>", with the channel +# being automatically inserted after the command in the message to +# ChanServ, assuming the fantasy prefix is "!". + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Allowinvite module: Gives channel mode +A to allow all users to use +# /INVITE, and extban A to deny invite from specific masks. +#<module name="allowinvite"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Alltime module: Shows time on all connected servers at once. +# This module is oper-only and provides /ALLTIME. +# To use, ALLTIME must be in one of your oper class blocks. +#<module name="alltime"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Anticaps module: Adds channel mode +B which allows you to punish +# users that send overly capitalised messages to channels. +#<module name="anticaps"> +# +# You may also configure the characters which anticaps considers to be +# lower case and upper case. Any characters not listed here are assumed +# to be punctuation and will be ignored when counting: +# <anticaps lowercase="abcdefghijklmnopqrstuvwxyz" +# uppercase="ABCDEFGHIJKLMNOPQRSTUVWXYZ"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Argon2 module: Allows other modules to generate Argon2 hashes, +# usually for cryptographic uses and security. +# This module makes the algorithms argon2i, argon2d and argon2id +# available for use. +# Note that this module is extra, and must be enabled explicitly +# to build. It depends on libargon2. +#<module name="argon2"> +# +# memory: Memory hardness, in KiB. E.g. 131072 KiB = 128 MiB. +# iterations: Time hardness in iterations. (def. 3) +# threads: Maximum amount of threads each invocation can spawn. (def. 1) +# length: Output length in bytes. (def. 32) +# saltlength: Salt length in bytes. (def. 16) +# version: Algorithm version, 10 or 13. (def. 13) +# The parameters can be customized as follows: +#<argon2 iterations="3" memory="131074" length="32" saltlength="16"> +# Defines the parameters that are common for all the variants (i/d/id). +# Can be overridden on individual basis, e.g. +#<argon2i iterations="4"> +#<argon2d memory="131074" +#<argon2id iterations="5" memory="262144" length="64" saltlength="32"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Auditorium module: Adds channel mode +u which makes everyone else +# except you in the channel invisible, used for large meetings etc. +#<module name="auditorium"> +# +# Auditorium settings: +# +#<auditorium opvisible="no" opcansee="no" opercansee="yes"> +# +# opvisible (auditorium-vis in exemptchanops): +# Show channel ops to all users +# opcansee (auditorium-see in exemptchanops): +# Allow ops to see all joins/parts/kicks in the channel +# opercansee: +# Allow opers (channels/auspex) to see see all joins/parts/kicks in the channel +# +# Exemptchanops can be used to adjust the level at which users become visible or +# the level at which they can see the full member list of the channel. + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Autoop module: Adds basic channel access controls via the +w listmode. +# For example +w o:*!Attila@127.0.0.1 will op anyone matching that mask +# on join. This can be combined with extbans, for example +w o:R:Brain +# will op anyone identified to the account "Brain". +# Another useful combination is with TLS client certificate +# fingerprints: +w h:z:72db600734bb9546c1bdd02377bc21d2a9690d48 will +# give halfop to the user(s) having the given certificate. +#<module name="autoop"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Ban except module: Adds support for channel ban exceptions (+e). +#<module name="banexception"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Ban redirection module: Allows bans which redirect to a specified +# channel. e.g. +b nick!user@host#channelbanneduserissentto +#<module name="banredirect"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# bcrypt module: Allows other modules to generate bcrypt hashes, +# usually for cryptographic uses and security. +#<module name="bcrypt"> +# +# rounds: Defines how many rounds the bcrypt function will run when +# generating new hashes. +#<bcrypt rounds="10"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Block amsg module: Attempt to block all usage of /amsg and /ame. +#<module name="blockamsg"> +# +#-#-#-#-#-#-#-#-#-#-#- BLOCKAMSG CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# If you have the blockamsg module loaded, you can configure it with # +# the <blockamsg> tag: # +# # +# delay - How much time between two messages to force them # +# to be recognised as unrelated. # +# action - Any of 'notice', 'noticeopers', 'silent', 'kill' # +# or 'killopers'. Define how to take action when # +# a user uses /amsg or /ame. # +# +#<blockamsg delay="3" action="killopers"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Block color module: Blocking color-coded messages with chan mode +c. +#<module name="blockcolor"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Botmode module: Adds the user mode +B. If set on a user, it will +# show that the user is a bot in /WHOIS. +#<module name="botmode"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CallerID module: Adds user mode +g which activates hybrid-style +# callerid: block all private messages unless you /ACCEPT first. +#<module name="callerid"> +# +#-#-#-#-#-#-#-#-#-#-#- CALLERID CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# maxaccepts - Maximum number of entries a user can add to their # +# /ACCEPT list. Default is 30 entries. # +# tracknick - Preserve /ACCEPT entries when a user changes nick? # +# If no (the default), the user is removed from # +# everyone's accept list if their nickname changes. # +# cooldown - Amount of time that must pass since the last # +# notification sent to a user before they can be # +# sent another. Default is 1 minute. # +#<callerid maxaccepts="30" +# tracknick="no" +# cooldown="1m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CAP module: Provides the CAP negotiation mechanism required by many +# other modules. It is strongly recommended that you load this. +#<module name="cap"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CBAN module: Lets you disallow channels from being used at runtime. +# This module is oper-only and provides /CBAN. +# To use, CBAN must be in one of your oper class blocks. +#<module name="cban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel create module: Adds snomask +j, which will notify opers of +# any new channels that are created. +# This module is oper-only. +#<module name="chancreate"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel filter module: Allows channel-op defined message filtering +# using simple string matches (channel mode +g). +#<module name="chanfilter"> +# +# If hidemask is set to yes, the user will not be shown the mask when +# their message is blocked. +# +# If maxlen is set then it defines the maximum length of a filter entry. +# +# If notifyuser is set to no, the user will not be notified when +# their message is blocked. +#<chanfilter hidemask="yes" maxlen="50" notifyuser="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel history module: Displays the last 'X' lines of chat to a user +# joining a channel with +H 'X:T' set; 'T' is the maximum time to keep +# lines in the history buffer. Designed so that the new user knows what +# the current topic of conversation is when joining the channel. +#<module name="chanhistory"> +# +#-#-#-#-#-#-#-#-#-#-#- CHANHISTORY CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# maxduration - The maximum period to keep chat history for. Defaults # +# to 4 weeks. # +# # +# maxlines - The maximum number of lines of chat history to send to a # +# joining users. Defaults to 50. # +# # +# prefixmsg - Whether to send an explanatory message to clients that # +# don't support the chathistory batch type. Defaults to # +# yes. # +# # +# savefrombots - Whether to save messages from users with user mode # +# +B (bot) in the channel history. Defaults to yes. # +# # +# sendtobots - Whether to send channel history to users with user # +# mode +B (bot) enabled. Defaults to yes. # +# +#<chanhistory maxlines="50" +# maxduration="4w" +# prefixmsg="yes" +# savefrombots="yes" +# sendtobots="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel logging module: Used to send snotice output to channels, to +# allow staff to centrally monitor and discuss network activity. +# +# The "channel" field is where you want the messages to go, "snomasks" +# is what snomasks you want to be sent to that channel. Multiple tags +# are allowed. +#<module name="chanlog"> +#<chanlog snomasks="AOcC" channel="#opers"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel names module: Allows disabling channels which have certain +# characters in the channel name such as bold, colorcodes, etc. which +# can be quite annoying and allow users to on occasion have a channel +# that looks like the name of another channel on the network. +#<module name="channames"> + +#<channames + # denyrange: characters or range of characters to deny in channel + # names. + #denyrange="2,3" + + # allowrange: characters or range of characters to specifically allow + # in channel names. + #allowrange=""> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channelban: Implements extended ban j:, which stops anyone already +# in a channel matching a ban like +b j:#channel from joining. +# It is also possible to ban based on their status in that channel, +# like so: +b j:@#channel, this example prevents the ops from joining. +# Note that by default wildcard characters * and ? are allowed in +# channel names. To disallow them, load the channames module and +# add characters 42 and 63 to denyrange (see above). +#<module name="channelban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Check module: Adds the /CHECK command. +# Check is useful for looking up information on channels, users, +# IP addresses and hosts. +# This module is oper-only. +# To use, CHECK must be in one of your oper class blocks. +#<module name="check"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CHGHOST module: Adds the /CHGHOST command. +# This module is oper-only. +# To use, CHGHOST must be in one of your oper class blocks. +# NOTE: Services will not be able to set vhosts on users if this module +# isn't loaded. If you're planning on running services, you probably +# want to load this. +#<module name="chghost"> +# +#-#-#-#-#-#-#-#-# /CHGHOST - /SETHOST CONFIGURATION #-#-#-#-#-#-#-#-# +# Optional - If you want to use special chars for hostnames you can # +# specify your own custom list of chars with the <hostname> tag: # +# # +# charmap - A list of chars accepted as valid by the /CHGHOST # +# and /SETHOST commands. Also note that the list is # +# case-sensitive. # +#<hostname charmap="abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ.-_/0123456789"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CHGIDENT module: Adds the /CHGIDENT command. +# This module is oper-only. +# To use, CHGIDENT must be in one of your oper class blocks. +#<module name="chgident"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# CHGNAME module: Adds the /CHGNAME command. +# This module is oper-only. +# To use, CHGNAME must be in one of your oper class blocks. +#<module name="chgname"> +# +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Connection class ban module: Adds support for extban 'n' which +# matches against the class name of the user's connection. +# This module assumes that connection classes are named in a uniform +# way on all servers of the network. Wildcards are accepted. +#<module name="classban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Clear chan module: Allows opers to masskick, masskill or +# mass G/Z-line all users on a channel using /CLEARCHAN. +#<module name="clearchan"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Cloak module: Adds user mode x (cloak) which allows user hostnames to +# be hidden. This module does not provide any cloak methods by itself. +# You should also load another module like cloak_account or cloak_sha256. +# +# In order to have users automatically cloaked on connect you should +# load the conn_umodes module and add "x" to <connect:modes>. +#<module name="cloak"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# MD5 cloak module: Adds the "half" and "full" cloak methods. These +# methods are deprecated and will be removed in the next major version +# of InspIRCd. They should only be used on a network which is upgrading +# from v3 and wishes to keep ban compatibility. New networks should use +# the "hmac-sha256" method (see below) instead. +# +# IMPORTANT: If you are using this module you should also load the md5 +# module. Failure to do so will result in users not being cloaked. +#<module name="cloak_md5"> +# +#-#-#-#-#-#-#-#-#-#-#- MD5 CLOAK CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# To use the cloak_md5 module you must define a <cloak> tag. This tag # +# tag can have the following fields. # +# # +# key - The secret key to use when hashing hostnames. This # +# MUST be at least 30 characters long. # +# # +# class - If non-empty then a comma-delimited list of connect # +# class names that a user has to be in to get the cloak # +# from this tag. # +# # +# prefix - A freeform value to prefix cloaks with. This must not # +# contain spaces. # +# # +# suffix - A freeform value to suffix cloaks with. This must not # +# contain spaces. # +# # +# domainparts - The maximum number of hostname labels that should be # +# visible on the end of a host. Defaults to 3. # +# # +# ignorecase - Whether to ignore the capitalisation of a hostname # +# when generating the cloak. This prevents users from # +# evading bans by changing the case of their DNS PTR # +# record. Defaults to off. # +# # +# IMPORTANT: Changing these details will break all of your existing # +# bans. If you do not want this to happen you can define multiple # +# cloak tags. The first will be used for hostnames and the rest will # +# be used for checking if a user is banned in a channel. # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +#<cloak method="half" +# key="changeme" +# class="" +# prefix="MyNet-" +# suffix=".IP" +# domainparts="3" +# ignorecase="yes"> +# +#<cloak method="full" +# key="changeme" +# class="" +# prefix="MyNet-" +# suffix=".IP"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# HMAC-SHA256 cloak module: Adds the "hmac-sha256" (hostname or IP) and +# "hmac-sha256-addr" (IP only) cloak methods. This is the recommended +# cloak module for new networks. +# +# IMPORTANT: If you are using this module you should also load the sha2 +# module. Failure to do so will result in users not being cloaked. +#<module name="cloak_sha256"> +# +#-#-#-#-#-#-#-#-#- HMAC-SHA256 CLOAK CONFIGURATION -#-#-#-#-#-#-#-#-#-# +# To use the cloak_sha256 module you must define a <cloak> tag. This # +# tag can have the following fields. # +# # +# key - The secret key to use when hashing hostnames. This # +# MUST be at least 30 characters long. # +# # +# class - If non-empty then a comma-delimited list of connect # +# class names that a user has to be in to get the cloak # +# from this tag. # +# # +# prefix - A freeform value to prefix cloaks with. This must not # +# contain spaces. # +# # +# suffix - A freeform value to suffix IPv4/IPv6 cloaks with. This # +# must not contain spaces. # +# # +# case - The case of the cloak table. Can be set to "upper" or # +# "lower". Defaults to "lower". # +# # +# hostparts - The maximum number of hostname labels that should be # +# visible on the end of a host. Defaults to 3. # +# # +# pathparts - The maximum number of UNIX socket path segments that # +# should be visible on the end of a host. Defaults to 1. # +# # +# psl - If non-empty then the path to a Mozilla Public Suffix # +# List database to use for finding the visible part of a # +# hostname or "system" to use the system database if one # +# exists. This overrides the hostparts (above) field. # +# Only available if libpsl was installed at build time. # +# # +# IMPORTANT: Changing these details will break all of your existing # +# bans. If you do not want this to happen you can define multiple # +# cloak tags. The first will be used for hostnames and the rest will # +# be used for checking if a user is banned in a channel. # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +#<cloak method="hmac-sha256" +# key="changeme" +# class="" +# prefix="MyNet" +# suffix="ip" +# case="lower" +# hostparts="3" +# pathparts="1" +# psl="system"> +# +#<cloak method="hmac-sha256-addr" +# key="changeme" +# class="" +# prefix="MyNet" +# suffix="ip" +# case="lower" +# pathparts="1"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Static cloak module: Adds the "static" (fixed value) cloak method. +#<module name="cloak_static"> +# +#-#-#-#-#-#-#-#-#-#- STATIC CLOAK CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# To use the cloak_static module you must define a <cloak> tag. This # +# tag can have the following fields. # +# # +# class - If non-empty then a comma-delimited list of connect class # +# names that a user has to be in to get the cloak from this tag. # +# # +# cloak - The cloak to give to users. # +# # +# IMPORTANT: Changing these details will break all of your existing # +# bans. If you do not want this to happen you can define multiple # +# cloak tags. The first will be used for hostnames and the rest will # +# be used for checking if a user is banned in a channel. # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +#<cloak method="static" +# class="" +# cloak="some.fixed.value"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# User data cloak module: Adds the "account" (services account name), +# "account-id" (services account id), "nickname" (current nickname), +# "fingerprint" (client certificate fingerprint), and "username" (RFC +# 1413 identification string) cloak methods. +#<module name="cloak_user"> +# +#-#-#-#-#-#-#-#-#-#-#- USER CLOAK CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# To use the cloak_user module you must define a <cloak> tag. This # +# tag can have the following fields. # +# # +# case - The case to transform the cloak value to. Can be set # +# to "upper" to use upper case, "lower" to use lower # +# case, or "preserve" to not change the case. Defaults # +# to "preserve". # +# # +# class - If non-empty then a comma-delimited list of connect # +# class names that a user has to be in to get the # +# cloak from this tag. # +# # +# invalidchar - The action to take when an invalid host character is # +# encountered in the cloak. Can be set to "reject" to # +# not apply the cloak, "strip" to remove the invalid # +# host character, or "truncate" to truncate the cloak # +# at the invalid host character. Defaults to "strip". # +# # +# length - If using the "fingerprint" method them the number of # +# characters of the fingerprint hash to use. Defaults # +# to the value of <limits:maxhost> minus the length of # +# the prefix and suffix fields. # +# # +# prefix - A freeform value to prefix cloaks with. This must # +# not contain spaces. # +# # +# suffix - A freeform value to suffix IPv4/IPv6 cloaks with. # +# This must not contain spaces. # +# # +# IMPORTANT: Changing these details will break all of your existing # +# bans. If you do not want this to happen you can define multiple # +# cloak tags. The first will be used for hostnames and the rest will # +# be used for checking if a user is banned in a channel. # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +#<cloak method="account" +# case="preserve" +# class="" +# invalidchar="strip" +# prefix="" +# suffix=".users.example.com"> +# +#<cloak method="account-id" +# case="preserve" +# class="" +# invalidchar="strip" +# prefix="" +# suffix=".users.example.com"> +# +#<cloak method="fingerprint" +# case="preserve" +# class="" +# invalidchar="strip" +# length="16" +# prefix="" +# suffix=".fp"> +# +#<cloak method="nickname" +# case="preserve" +# class="" +# invalidchar="strip" +# prefix="Users/" +# suffix=""> +# +#<cloak method="username" +# case="preserve" +# class="" +# invalidchar="strip" +# prefix="Users/" +# suffix=""> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Codepage module: Allows using a custom 8-bit codepage for nicknames +# and case mapping. +#<module name="codepage"> +# +# You should include one of the following files to set your codepage: +#<include file="&dir.example;/codepages/ascii.example.conf"> +#<include file="&dir.example;/codepages/iso-8859-1.example.conf"> +#<include file="&dir.example;/codepages/iso-8859-2.example.conf"> +#<include file="&dir.example;/codepages/rfc1459.example.conf"> +#<include file="&dir.example;/codepages/strict-rfc1459.example.conf"> +# +# You can also define a custom codepage. For details on how to do this +# please refer to the docs site: +# https://docs.inspircd.org/4/modules/codepage + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Common channels module: Adds user mode +c, which, when set, requires +# that users must share a common channel with you to PRIVMSG, NOTICE, +# TAGMSG, or INVITE you. +#<module name="commonchans"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Connectban: Provides IP connection throttling. Any IP range that +# connects too many times (configurable) in an hour is Z-lined for a +# (configurable) duration, and their count resets to 0. +#<module name="connectban"> +# +# threshold - The number of connections which are allowed before a user +# is connectbanned. Defaults to 10. +# +# banmessage - The message to give users when Z-lining them for connecting +# too much. +# +# banduration - The time period to ban users who connect to much for. Defaults +# to 10 minutes. +# +# ipv4cidr - The IPv4 CIDR mask (1-32) to treat connecting users as coming +# from the same host. Defaults to 32. +# +# ipv6cidr - The IPv6 CIDR mask (1-128) to treat connecting users as coming +# from the same host. Defaults to 128. +# +# bootwait - The time period to wait after starting up before enforcing +# connection bans. Defaults to 2 minutes. +# +# splitwait - The time period to wait after a netsplit before enforcing +# connection bans. Defaults to 2 minutes. +# +#<connectban threshold="10" +# banmessage="Your IP range has been attempting to connect too many times in too short a duration. Wait a while, and you will be able to connect." +# banduration="6h" +# ipv4cidr="32" +# ipv6cidr="128" +# bootwait="2m" +# splitwait="2m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Connection throttle module. +#<module name="connflood"> +# +#-#-#-#-#-#-#-#-#-#-#- CONNTHROTTLE CONFIGURATION -#-#-#-#-#-#-#-#-#-# +# period, maxconns - Amount of connections per <period>. +# +# timeout - Time to wait after the throttle was activated +# before deactivating it. Be aware that the time +# is seconds + timeout. +# +# quitmsg - The message that users get if they attempt to +# connect while the throttle is active. +# +# bootwait - Amount of time in seconds to wait before enforcing +# the throttling when the server just booted. +# +#<connflood period="30" maxconns="3" timeout="30" +# quitmsg="Throttled" bootwait="2m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Auto join on connect module: Allows you to force users to join one +# or more channels automatically upon connecting to the server, or +# join them in case they aren't on any channels after being online +# for X seconds. +#<module name="conn_join"> +# +#-#-#-#-#-#-#-#-#-#-#-#- CONNJOIN CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# +# If you have the conn_join module loaded, you can configure it below +# or set autojoin="#chat,#help" in <connect> blocks. +# +# Join users immediately after connection to #one #two and #three. +#<autojoin channel="#one,#two,#three"> +# Join users to #chat after 15 seconds if they aren't on any channels. +#<autojoin channel="#chat" delay="15"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Set modes on connect module: When this module is loaded <connect> +# blocks may have an optional modes="" value, which contains modes to +# add or remove from users when they connect to the server. +#<module name="conn_umodes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Wait for PONG on connect module: Send a PING to all connecting users +# and don't let them connect until they reply with a PONG. +# This is useful to stop certain kinds of bots and proxies. +#<module name="conn_waitpong"> +# +#-#-#-#-#-#-#-#-#-#-#- WAITPONG CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# If you have the conn_waitpong module loaded, configure it with the # +# <waitpong> tag: # +# # +# sendsnotice - Whether to send a helpful notice to users on # +# connect telling them how to connect, should # +# their client not reply PONG automatically. # +# # +# killonbadreply - Whether to kill the user if they send the wrong # +# PONG reply. # +# # +#<waitpong sendsnotice="no" killonbadreply="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Custom prefixes: Allows for channel prefixes to be configured. +#<module name="customprefix"> +# +# name The name of the mode, must be unique from other modes. +# letter The letter used for this mode. Required. +# prefix The prefix used for nicks with this mode. Not required. +# rank A numeric rank for this prefix, defining what permissions it gives. +# The rank of voice, halfop and op is 10000, 20000, and 30000, +# respectively. +# ranktoset The numeric rank required to set this mode. Defaults to rank. +# ranktounset The numeric rank required to unset this mode. Defaults to ranktoset. +# depriv Can you remove the mode from yourself? Defaults to yes. +#<customprefix name="founder" letter="q" prefix="~" rank="50000" ranktoset="50000"> +#<customprefix name="admin" letter="a" prefix="&amp;" rank="40000" ranktoset="50000"> +#<customprefix name="halfop" letter="h" prefix="%" rank="20000" ranktoset="30000"> +# +# You can also override the configuration of prefix modes added by both the core +# and other modules by adding a customprefix tag with change="yes" specified. +# <customprefix name="op" change="yes" rank="30000" ranktoset="30000"> +# <customprefix name="voice" change="yes" rank="10000" ranktoset="20000" depriv="no"> +# +# Do /RELOADMODULE customprefix after changing the settings of this module. + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Custom title module: Adds the /TITLE command which allows for trusted +# users to gain a custom whois line and an optional vhost can be +# specified. +#<module name="customtitle"> +# +#-#-#-#-#-#-#-#-#-#- CUSTOM TITLE CONFIGURATION -#-#-#-#-#-#-#-#-#-# +# name - The username used to identify. +# password - The password used to identify. +# hash - The hash for the specific user's password (optional). +# password_hash and a hashing module must be loaded +# for this to work. +# host - Allowed hostmask (optional). +# title - Title shown in whois. +# vhost - Displayed host (optional). +# +#<title name="foo" password="bar" title="Official Chat Helper"> +#<title name="bar" password="foo" host="test@test.org" title="Official Chat Helper" vhost="helper.test.org"> +#<title name="foo" password="$2a$10$UYZ4OcO8NNTCCGyCdY9SK.2GHiqGgxZfHFPOPmWuxEVWVQTtoDC7C" hash="bcrypt" title="Official Chat Helper"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Channel cycle module: Adds the /CYCLE command which is a server-side +# /HOP that bypasses restrictive modes. +#<module name="cycle"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# DCCALLOW module: Adds the /DCCALLOW command. +#<module name="dccallow"> +# +#-#-#-#-#-#-#-#-#-#-#- DCCALLOW CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# blockchat - Whether to block DCC CHAT as well as DCC SEND. +# length - Default duration of entries in DCCALLOW list. +# action - Default action to take if no action is +# specified, can be 'block' or 'allow'. +# maxentries - Max number of nicks to allow on a DCCALLOW list. +# +# File configuration: +# pattern - The glob pattern to match against. +# action - Action to take if a user attempts to send a file +# that matches this pattern, can be 'block' or +# 'allow'. +# +#<dccallow blockchat="yes" length="5m" action="block" maxentries="20"> +#<banfile pattern="*.exe" action="block"> +#<banfile pattern="*.txt" action="allow"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Deaf module: Adds support for user modes +d and +D: +# d - deaf to channel messages and notices. +# D - deaf to user messages and notices. +#<module name="deaf"> +# +#-#-#-#-#-#-#-#-#-#-#-#- DEAF CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# bypasschars - Characters that bypass deaf to a regular user. +# servicebypasschars - Characters that bypass deaf to a services users. +# Both of these take a list of characters that must match +# the starting character of a message. +# If 'servicebypasschars' is empty, then 'bypasschars' will +# match for both regular and services users. +# privdeafservice - Whether services users bypass user mode +D (privdeaf). +# +#<deaf bypasschars="" servicebypasschars="!" privdeafservice="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Delay join module: Adds the channel mode +D which delays all JOIN +# messages from users until they speak. If they quit or part before +# speaking, their quit or part message will not be shown to the channel +# which helps cut down noise on large channels in a more friendly way +# than the auditorium mode. Only channel ops may set the +D mode. +#<module name="delayjoin"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Delay message module: Adds the channel mode +d which disallows a user +# from talking in the channel unless they've been joined for X seconds. +# Settable using /MODE #chan +d 30 +#<module name="delaymsg"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Deny channels module: Deny channels from being used by users. +#<module name="denychans"> +# +#-#-#-#-#-#-#-#-#-#-#- DENYCHAN DEFINITIONS -#-#-#-#-#-#-#-#-#-#-#-# +# # +# If you have the denychans module loaded, you need to specify the # +# channels to deny: # +# # +# name - The channel name to deny (glob masks are ok). # +# allowopers - If operators are allowed to override the deny. # +# reason - Reason given for the deny. # +# redirect - Redirect the user to a different channel. # +# # +#<badchan name="#gods*" allowopers="yes" reason="Tortoises!"> # +#<badchan name="#chan1" redirect="#chan2" reason="Chan1 is closed"> # +# # +# Redirects will not work if the target channel is set +L. # +# # +# Additionally, you may specify channels which are allowed, even if # +# a badchan tag specifies it would be denied: # +#<goodchan name="#funtimes"> # +# Glob masks are accepted here also. # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Disable module: Provides support for disabling commands and modes. # +#<module name="disable"> +# +#-#-#-#-#-#-#-#-#-#-#-#- DISABLE CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# If you have the disable module loaded then you need to specify the # +# commands and modes that you want disabled. Users who have not fully # +# connected yet are exempt from this module so you can e.g. disable # +# the NICK command but still allow users to connect to the server. # +# # +# commands - A space-delimited list of commands that can not be used # +# by users. You can exempt server operators from this with # +# the servers/use-disabled-commands privilege. # +# # +# chanmodes - One or more channel modes that can not be added/removed # +# by users. You can exempt server operators from this # +# with the servers/use-disabled-modes privilege. # +# # +# usermodes - One or more user modes that can not be added/removed by # +# users. You can exempt server operators from this with # +# the servers/use-disabled-modes privilege. # +# # +# fakenonexistent - Whether to pretend that a disabled command/mode # +# does not exist when executed/changed by a user. # +# Defaults to no. # +# # +# notifyopers - Whether to send a notice to snomask `a` when a user # +# is prevented from using a disabled command/mode. # +# Defaults to no. # +# # +#<disabled commands="KICK TOPIC" # +# chanmodes="kp" # +# usermodes="iw" # +# fakenonexistent="yes" # +# notifyopers="no"> # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# DNS blacklist module: Provides support for looking up IPs on one or # +# more blacklists. # +#<module name="dnsbl"> +# # +# For configuration options please see the docs page for dnsbl at # +# https://docs.inspircd.org/4/modules/dnsbl. You can also use one or # +# more of the following example configs for popular DNSBLs: # +# # +# DroneBL (https://dronebl.org) # +#<include file="&dir.example;/providers/dronebl.example.conf"> +# # +# EFnet RBL (https://rbl.efnetrbl.org) # +#<include file="&dir.example;/providers/efnet-rbl.example.conf"> +# # +# dan.me.uk Tor exit node DNSBL (https://www.dan.me.uk/dnsbl) # +#<include file="&dir.example;/providers/torexit.example.conf"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Exempt channel operators module: Provides support for allowing # +# users of a specified channel status to be exempt from some channel # +# restriction modes. Supported restrictions are: # +# anticaps, auditorium-see, auditorium-vis, blockcaps, blockcolor, # +# filter, flood, nickflood, noctcp, nonick, nonotice, regmoderated, # +# stripcolor, and topiclock. # +# See <options:exemptchanops> in inspircd.example.conf for a more # +# detailed list of the restriction modes that can be exempted. # +# These are settable using: /MODE #chan +X <restriction>:<status> # +# Furthermore, the exemptions configured in <options:exemptchanops> # +# can also be negated by using: /MODE #chan +X <restriction>:* # +#<module name="exemptchanops"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Filter module: Provides message filtering, similar to SPAMFILTER. # +#<module name="filter"> +# # +# This module depends upon a regex provider such as regex_stdlib or # +# regex_glob to function. You must specify which of these you want # +# the filter module to use via the tag below. # +# # +# Valid engines are: # +# # +# glob - Glob patterns, provided via regex_glob. # +# pcre - PCRE regexps, provided via regex_pcre2, needs libpcre2. # +# posix - POSIX regexps, provided via regex_posix, not available # +# on Windows, no dependencies on other operating systems. # +# stdregex - stdlib regexps, provided via regex_stdlib, see comment # +# at the <module> tag for info on availability. # +# # +# If enableflags is set, you can specify flags that modify matching # +# of the regular expression. # +# # +# If notifyuser is set to no, the user will not be notified when # +# their message is blocked. # +# # +# If warnonselfmsg is set to yes when a user sends a message to # +# themself that matches a filter the filter will be ignored and a # +# warning will be sent to opers instead. This stops spambots which # +# send their spam message to themselves first to check if it is being # +# filtered by the server. # +#<filteropts engine="stdregex" +# enableflags="yes" +# notifyuser="yes" +# warnonselfmsg="no"> +# # +# Your choice of regex engine must match on all servers network-wide. # +# # +# To learn more about the configuration of this module, read # +# examples/filter.example.conf, which covers the various types of # +# filters and shows how to add exemptions. # +# # +#-#-#-#-#-#-#-#-#-#-#- FILTER CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# Optional - If you specify to use the filter module, then # +# specify below the path to the filter.conf file, or define some # +# <keyword> tags. # +# # +#<include file="&dir.example;/filter.example.conf"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Gateway module: Enables forwarding the real IP address of a user from +# a gateway to the IRC server. +#<module name="gateway"> +# +#-#-#-#-#-#-#-#-#-#-#-# GATEWAY CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-#-# +# +# If you use the gateway module then you must specify the gateways which +# are authorised to forward IP/host information to your server. There +# are currently two ways to do this: +# +# The webirc method is the recommended way to allow gateways to forward +# IP/host information. When using this method the gateway sends a WEBIRC +# message to the server on connection. For more details please read the +# IRCv3 WebIRC specification at: https://ircv3.net/specs/extensions/webirc.html +# +# When using this method you must specify one or more wildcard masks +# or CIDR ranges to allow gateway connections from and at least one of +# either a TLS client certificate fingerprint for the gateway or +# a password to be sent in the WEBIRC command. +# +# <gateway type="webirc" +# fingerprint="bd90547b59c1942b85f382bc059318f4c6ca54c5" +# mask="192.0.2.0/24 198.51.100.*"> +# <gateway type="webirc" +# password="$2a$10$WEUpX9GweJiEF1WxBDSkeODBstIBMlVPweQTG9cKM8/Vd58BeM5cW" +# hash="bcrypt" +# mask="*.webirc.gateway.example.com"> +# +# Alternatively if your gateway does not support sending the WEBIRC +# message then you can configure InspIRCd to look for the client IP +# address in the username sent by the user. This is not recommended +# as it only works with IPv4 connections. +# +# When using this method you must specify one or more wildcard masks +# or CIDR ranges to allow gateway connections from. You can also +# optionally configure the static value that replaces the IP in the +# username to avoid leaking the real IP address of gateway clients +# (defaults to "gateway" if not set). +# +# <gateway type="username" +# mask="198.51.100.0/24 203.0.113.*" +# newusername="wibble"> +# <gateway type="username" +# mask="*.username.gateway.example.com" +# newusername="wobble"> +# +# IMPORTANT NOTE: +# --------------- +# +# When you connect gateway clients, there are two connect classes which +# apply to these clients. When the client initially connects, the connect +# class which matches the gateway site's host is checked. Therefore you +# must raise the maximum local/global clients for this IP as high as you +# want to allow gateway clients. After the client has connected and is +# determined to be a gateway client, the class which matches the client's +# real IP is then checked. You may set this class to a lower value, so that +# the real IP of the client can still be restricted to, for example, 3 +# sessions maximum. + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# MaxMindDB geolocation module: Provides geolocation information for # +# other modules that need it using the libMaxMindDB library. # +# # +# This module depends on a third-party library (libmaxminddb) and may # +# need to be manually enabled at build time. If you are building from # +# source you can do this by installing this dependency and running: # +# # +# ./configure --enable-extras geo_maxmind # +# make install # +# # +# Users of binary packages should consult the documentation for their # +# package to find out whether this module is available. # +#<module name="geo_maxmind"> +# # +# If you use the geo_maxmind module you MUST provide a database file # +# to look up geolocation information in. You can either purchase this # +# from MaxMind at https://www.maxmind.com/en/geoip2-country-database # +# or use the free CC-BY-SA licensed GeoLite2 Country database which # +# can be downloaded at https://dev.maxmind.com/geoip/geoip2/geolite2/ # +#<maxmind file="GeoLite2-Country.mmdb"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Geolocation ban module: Adds support for extban 'G' which matches # +# against the ISO 3166-1 alpha-2 codes for the countries that users # +# are connecting from. Users connecting from unknown origins such as # +# internal networks can be matched against using the XX alpha-2 code. # +# A full list of ISO 3166-1 alpha-2 codes can be found at # +# https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2 # +#<module name="geoban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Geolocation connect class module: Adds support for limiting connect # +# classes to users from specific countries. With this module you can # +# specify a space-delimited list of two character the ISO 3166-1 # +# alpha-2 codes in the "country" field of a connect class. e.g. to # +# deny connections from users in Russia or Turkey: # +# # +# <connect deny="*" country="TR RU"> # +# # +# Users connecting from unknown origins such as internal networks can # +# be matched against using the XX alpha-2 code. A full list of ISO # +# 3166-1 alpha-2 codes can be found at # +# https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2 # +#<module name="geoclass"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Global load module: Allows loading and unloading of modules network- +# wide (USE WITH EXTREME CAUTION!) +# This module is oper-only and provides /GLOADMODULE, /GUNLOADMODULE +# and /GRELOADMODULE. +# To use, GLOADMODULE, GUNLOADMODULE and GRELOADMODULE +# must be in one of your oper class blocks. +#<module name="globalload"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Globops module: Provides the /GLOBOPS command and snomask +g. +# This module is oper-only. +# To use, GLOBOPS must be in one of your oper class blocks. +#<module name="globops"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# HAProxy module: Adds support for the HAProxy PROXY v2 protocol. To +# use this module specify hook="haproxy" in the <bind> tag that HAProxy +# has been configured to connect to. +#<module name="haproxy"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Help module: Provides the /HELP command +#<module name="help"> +# +#-#-#-#-#-#-#-#-#-#-#-#- HELP CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# If you specify to use the help module, then specify below the path # +# to the help.conf file. # +# # +#<include file="&dir.example;/help.example.conf"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Help mode module: Provides oper-only user mode `h` (helpop) which +# marks a server operator as available for help. +#<module name="helpmode"> +# +# If you also use the hideoper module you can allow hidden opers with +# the help mode set to to be included in `/STATS P` and mark helpers +# as such to differentiate them from opers. +# <helpmode ignorehideoper="no" +# markhelpers="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Hide chans module: Allows users to hide their channels list from non- +# opers by setting user mode +I on themselves. +#<module name="hidechans"> +# +# affectsopers: Whether server operators with the users/auspex privilege +# are exempt from the hideoper (+I) mode. Defaults to no. +# +# hideservices: Whether to hide the channels of services pseudoclients +# with the hideoper (+I) mode from all users. Defaults +# to yes. +# +# <hidechans affectsopers="no" +# hideservices="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Hide list module: Allows for hiding the list of listmodes from users +# who do not have sufficient channel rank. +#<module name="hidelist"> +# +# Each <hidelist> tag configures one listmode to hide. +# mode: Name of the listmode to hide. +# rank: Minimum rank required to view the list. If set to 0, all +# members of the channel may view the list, but non-members may not. +# The rank of the built-in op and voice mode is 30000 and 10000, +# respectively; the rank of other prefix modes is configurable. +# Defaults to 20000. +# +# Hiding the ban list is not recommended because it may break some +# clients. +# +# Hide filter (+g) list: +#<hidelist mode="filter" rank="30000"> +# Only show invite exceptions (+I) to channel members: +#<hidelist mode="invex" rank="0"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Hide mode module: Allows for hiding mode changes from users who do not +# have sufficient channel privileges. +#<module name="hidemode"> +# +# Hide bans (+b) from people who are not voiced: +#<hidemode mode="ban" rank="10000"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Hide oper module: Allows opers to hide their oper status from non- +# opers by setting user mode +H on themselves. +# This module is oper-only. +#<module name="hideoper"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# hostcycle module: Sends a fake part and join for users when their +# username or hostname changes to update client information caches. +# This module is compatible with the ircv3_chghost module. Clients +# supporting the chghost extension will get the chghost message instead +# of seeing a host cycle. +#<module name="hostcycle"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# httpd module: Provides HTTP server support for InspIRCd. +#<module name="httpd"> +# +#-#-#-#-#-#-#-#-#-#-#-#- HTTPD CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# +# If you choose to use the httpd module, then you will need to add +# a <bind> tag with type "httpd", and load at least one of the other +# httpd_* modules to provide pages to display. +# <bind address="127.0.0.1" port="8067" type="httpd"> +# <bind address="127.0.0.1" port="8097" type="httpd" sslprofile="Clients"> +# +# You can adjust the timeout for HTTP connections below. All HTTP +# connections will be closed after (roughly) this time period. +#<httpd timeout="20"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# HTTP ACL module: Provides access control lists for httpd dependent +# modules. Use this module to restrict pages by IP address and by +# password. +#<module name="httpd_acl"> +# +#-#-#-#-#-#-#-#-#-#-#-#- HTTPD ACL CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# +# Restrict access to the httpd_stats module to all but the local +# network and when the correct password is specified: +# <httpdacl path="/stats*" types="password,whitelist" +# username="secrets" password="mypasshere" whitelist="127.0.0.*,10.*"> +# +# Deny all connections to all but the main index page: +# <httpdacl path="/*" types="blacklist" blacklist="*"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# HTTP config module: Allows the server configuration to be viewed over +# HTTP via the /config path. Requires the httpd module to be loaded for +# it to function. +# +# IMPORTANT: This module exposes extremely sensitive information about +# your server and users so you *MUST* protect it using a local-only +# <bind> tag and/or the httpd_acl module. See above for details. +#<module name="httpd_config"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# HTTP stats module: Provides server statistics over HTTP via the /stats +# path. Requires the httpd module to be loaded for it to function. +# +# IMPORTANT: This module exposes extremely sensitive information about +# your server and users so you *MUST* protect it using a local-only +# <bind> tag and/or the httpd_acl module. See above for details. +#<module name="httpd_stats"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Ident: Provides RFC 1413 ident lookup support. +# When this module is loaded <connect:allow> tags may have an optional +# useident="yes|no" boolean value, determining whether or not to lookup +# usernames on users matching that connect tag. +#<module name="ident"> +# +#-#-#-#-#-#-#-#-#-#-#-#- IDENT CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# Optional - If you are using the ident module, then you can specify # +# the timeout for ident lookups here. If not defined, it will default # +# to 5 seconds. This is a non-blocking timeout which holds the user # +# in a 'connecting' state until the lookup is complete. # +# prefixunqueried: If yes, the usernames of users in a connect class # +# with ident lookups disabled (i.e. <connect useident="no">) will be # +# prefixed with a "~". If no, the username of those users will not be # +# prefixed. Default is no. # +# +#<ident timeout="5" prefixunqueried="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Invite exception module: Adds support for channel invite exceptions +# (+I). +#<module name="inviteexception"> +# bypasskey: If this is enabled, exceptions will bypass +k as well as +i +#<inviteexception bypasskey="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 module: Provides the IRCv3 account-notify, away-notify, +# extended-join, and standard-replies extensions. These are optional +# enhancements to the client-to-server protocol. An extension is only +# active for a client when the client specifically requests it, so this +# module needs the cap module to work. +# +# Further information on these extensions can be found at the IRCv3 +# working group website: +# https://ircv3.net/irc/ +# +#<module name="ircv3"> +# The following block can be used to control which extensions are +# enabled. Note that extended-join can be incompatible with delayjoin +# and host cycling. +#<ircv3 accountnotify="yes" +# awaynotify="yes" +# extendedjoin="yes" +# standardreplies="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 account-tag module. Adds the 'account' tag which contains the +# user account name of the message sender. +#<module name="ircv3_accounttag"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 batch module: Provides the batch IRCv3 extension which allows +# the server to inform a client that a group of messages are related to +# each other. +#<module name="ircv3_batch"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 cap-notify module: Provides the cap-notify IRCv3 extension. +# Required for IRCv3 conformance. +#<module name="ircv3_capnotify"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 chghost module: Provides the chghost IRCv3 extension which +# allows capable clients to learn when the username or hostname of a +# user changes +# This module is compatible with the hostcycle module. If both are +# loaded, clients supporting the chghost extension will get the chghost +# message and won't receive a host cycle. +#<module name="ircv3_chghost"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 client-to-client tags module: Provides the message-tags IRCv3 +# extension which allows clients to add extra data to their messages. +# This is used to support new IRCv3 features such as replies and ids. +#<module name="ircv3_ctctags"> +# +# If you want to only allow client tags that are intended for processing +# by the server you can disable the following setting. Doing this is not +# recommended though as it may break clients. +#<ctctags allowclientonlytags="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 echo-message module: Provides the echo-message IRCv3 +# extension which allows capable clients to get an acknowledgement when +# their messages are delivered and learn what modifications, if any, +# were applied to them. +#<module name="ircv3_echomessage"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 invite-notify module: Provides the invite-notify IRCv3 +# extension which notifies supporting clients when a user invites +# another user into a channel. This respects <security:announceinvites>. +#<module name="ircv3_invitenotify"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 labeled-response module: Provides the labeled-response IRCv3 +# extension which allows server responses to be associated with the +# client message which caused them to be sent. +#<module name="ircv3_labeledresponse"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 message id module: Provides the msgid IRCv3 extension which +# adds a unique identifier to each message when the message-tags cap +# has been requested. This enables support for modern features such as +# reactions and replies. +#<module name="ircv3_msgid"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 server-time module. Adds the 'time' tag which adds a timestamp +# to all messages received from the server. +#<module name="ircv3_servertime"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# IRCv3 Strict Transport Security module: Provides the sts IRCv3 +# extension which allows clients connecting insecurely to upgrade their +# connections to TLS. +#<module name="ircv3_sts"> +# +# If using the ircv3_sts module you MUST define a STS policy to send +# to clients using the <sts> tag. This tag takes the following +# attributes: +# +# host - A glob match for the SNI hostname to apply this policy to. +# duration - The amount of time that the policy lasts for. Defaults to +# five minutes by default. You should raise this to a month +# or two once you know that your config is valid. +# port - The port on which TLS connections to the server are being +# accepted. You MUST have a CA-verified certificate on this +# port. Self signed certificates are not acceptable. +# preload - Whether client developers can include your certificate in +# preload lists. +# +# <sts host="*.example.com" duration="5m" port="6697" preload="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Join flood module: Adds support for join flood protection +j X:Y. +# Closes the channel for N seconds if X users join in Y seconds. +#<module name="joinflood"> +# +# duration: The number of seconds to close a channel for when it is +# being flooded with joins. +# +# bootwait: The number of seconds to disengage joinflood for after +# a server boots. This allows users to reconnect without +# being throttled by joinflood. +# +# splitwait: The number of seconds to disengage joinflood for after +# a server splits. This allows users to reconnect without +# being throttled by joinflood. +# +# notifyrank: The lowest prefix rank that should receive notification +# that the channel is closed to new users. This can be set +# to 0 for all users, 10000 for voiced users (+v) and above, +# 30000 for channel operators (+o), or the value specified +# in <customprefix:rank> for any custom prefix rank. +# +#<joinflood duration="1m" +# bootwait="30s" +# splitwait="30s" +# notifyrank="0"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Anti auto rejoin: Adds support for prevention of auto-rejoin (+J). +#<module name="kicknorejoin"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Knock module: Adds the /KNOCK command and channel mode +K. +#<module name="knock"> +# +# This setting specifies what to do when someone successfully /KNOCKs. +# If set to "notice", then a NOTICE will be sent to the channel. +# This is the default and the compatible setting, as it requires no +# special support from the clients. +# If set to "numeric" then a 710 numeric will be sent to the channel. +# This allows easier scripting but not all clients support it. +# If set to "both" then (surprise!) both will be sent. +#<knock notify="notice"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# LDAP module: Allows other SQL modules to access a LDAP database +# through a unified API. +# +# This module depends on a third-party library (OpenLDAP) and may need +# to be manually enabled at build time. If you are building from source +# you can do this by installing this dependency and running: +# +# ./configure --enable-extras ldap +# make install +# +# Users of binary packages should consult the documentation for their +# package to find out whether this module is available. +#<module name="ldap"> +# +#<database module="ldap" id="ldapdb" server="ldap://localhost" binddn="cn=Manager,dc=inspircd,dc=org" bindauth="mysecretpass" searchscope="subtree"> +# The server parameter indicates the LDAP server to connect to. The # +# ldap:// style scheme before the hostname proper is MANDATORY. # +# # +# The binddn and bindauth indicate the DN to bind to for searching, # +# and the password for the distinguished name. Some LDAP servers will # +# allow anonymous searching in which case these two values do not # +# need defining, otherwise they should be set similar to the examples # +# above. # +# # +# The searchscope value indicates the subtree to search under. On our # +# test system this is 'subtree'. Your mileage may vary. # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# LDAP authentication module: Adds the ability to authenticate users # +# via LDAP. # +#<module name="ldapauth"> +# # +# Configuration: # +# # +# <ldapauth dbid="ldapdb" # +# baserdn="ou=People,dc=brainbox,dc=cc" # +# attribute="uid" # +# killreason="Access denied" # +# verbose="yes" # +# host="$uid.$ou.inspircd.org" # +# field="nickname"> # +# # +# <ldapexemption mask="*!*@10.42.0.0/16"> # +# <ldapexemption mask="Guest*!*@*"> # +# # +# <ldaprequire attribute="attr" value="val"> # +# # +# The baserdn indicates the base DN to search in for users. Usually # +# this is 'ou=People,dc=yourdomain,dc=yourtld'. # +# # +# The attribute value indicates the attribute which is used to locate # +# a user account by name. On POSIX systems this is usually 'uid'. # +# # +# The field setting chooses where to select the LDAP username from. # +# Valid options are "nickname", "username", and "password". # +# # +# Killreason indicates the QUIT reason to give to users if they fail # +# to authenticate. # +# # +# Setting the verbose value causes an oper notice to be sent out for # +# every failed authentication to the server, with an error string. # +# # +# ldapwhitelist indicates that clients connecting from an IP in the # +# provided CIDR do not need to authenticate against LDAP. It can be # +# repeated to whitelist multiple CIDRs. # +# # +# ldaprequire allows further filtering on the LDAP user, by requiring # +# certain LDAP attributes to have a given value. It can be repeated, # +# in which case the list will act as an OR list, that is, the # +# authentication will succeed if any of the requirements in the list # +# is satisfied. # +# # +# host allows you to change the displayed host of users connecting # +# from ldap. The string supplied takes formatters which are replaced # +# from the DN. For instance, if your DN looks like: # +# uid=w00t,ou=people,dc=inspircd,dc=org, then the formatters uid, ou # +# and dc will be available to you. If a key is given multiple times # +# in the DN, the last appearance will take precedence. # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# LDAP oper configuration module: Adds the ability to authenticate # +# opers via LDAP. # +#<module name="ldapoper"> +# # +# Configuration: # +# # +# <ldapoper dbid="ldapdb" +# baserdn="ou=People,dc=brainbox,dc=cc" +# attribute="uid"> +# # +# Available configuration items are identical to the same items in # +# ldapauth above (except for the verbose setting, that is only # +# supported in ldapauth). # +# Please always specify a password in your <oper> tags even if the # +# opers are to be authenticated via LDAP, so in case this module is # +# not loaded the oper accounts are still protected by a password. # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# JSON logging module: Allows writing messages to a JSON file. # +# # +# This module depends on a third-party library (yyjson or RapidJSON) # +# and may need to be manually enabled at build time. If you are # +# building from source you can do this by installing this dependency # +# and running: # +# # +# ./configure --enable-extras log_json # +# make install # +# # +# Users of binary packages should consult the documentation for their # +# package to find out whether this module is available. # +#<module name="log_json"> +# +#<log method="json" +# target="inspircd.json" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> +# +#<log method="json-stderr" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> +# +#<log method="json-stdout" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SQL logging module: Allows writing messages to an SQL database.. # +#<module name="log_sql"> +# +# This module adds the following fields to the <log> tag: +# +# dbid - The id for the <database> tag that defines your database +# connection details. +# query - A custom query to use when inserting logs into the database. +# +#<log method="sql" +# level="normal" +# type="* -USERINPUT -USEROUTPUT" +# dbid="sql-log" +# query="INSERT INTO ircd_log (time, type, message) VALUES (FROM_UNIXTIME($time), '$type', '$message');"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Syslog logging module: Allows writing messages to the system log. # +# # +# This module depends on a POSIX component (syslog) and may need to # +# be manually enabled at build time. If you are building from source # +# you can do this by running: # +# # +# ./configure --enable-extras log_syslog # +# make install # +# # +# Users of binary packages should consult the documentation for their # +# package to find out whether this module is available. # +#<module name="log_syslog"> +# +#<log method="syslog" +# level="normal" +# type="* -USERINPUT -USEROUTPUT"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Map hiding module: replaces /MAP and /LINKS output to users with a # +# message to see a website, set by maphide="https://test.org/map" in # +# the <security> tag, instead. # +#<module name="maphide"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# MD5 module: Allows other modules to generate MD5 hashes, usually for +# cryptographic uses and security. This module is deprecated and will +# be removed in the next major version of InspIRCd. +# +# IMPORTANT: +# Other modules such as cloak_md5 and password_hash may rely on +# this module being loaded to function. +# +#<module name="md5"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Message flood module: Adds message/notice flood protection via +# channel mode +f. +#<module name="messageflood"> +# +# The weight to give each message type. TAGMSGs are considered to be +# 1/5 of a NOTICE or PRIVMSG to avoid users being accidentally flooded +# out of a channel by automatic client features such as typing +# notifications. +#<messageflood message="Message flood detected (trigger is %messages% messages in %duration%)" +# extended="yes" +# notice="1.0" +# privmsg="1.0" +# tagmsg="0.2"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Monitor module: Adds support for MONITOR which is used by clients to +# maintain notify lists. +#<module name="monitor"> +# +# Set the maximum number of entries on a user's monitor list below. +#<monitor maxentries="30"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Multiple prefix module: Provides support for the IRCv3 multi-prefix +# capability which allows clients to see all the prefix modes set on a +# user. +#<module name="multiprefix"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Muteban: Implements extended ban 'm', which stops anyone matching +# a mask like +b m:nick!user@host from speaking on channel. +#<module name="muteban"> +# +# If notifyuser is set to no, the user will not be notified when +# their message is blocked. +#<muteban notifyuser="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# MySQL module: Allows other SQL modules to access MySQL databases +# through a unified API. +# +# This module depends on a third-party library (libmysqlclient) and may +# need to be manually enabled at build time. If you are building from +# source you can do this by installing this dependency and running: +# +# ./configure --enable-extras mysql +# make install +# +# Users of binary packages should consult the documentation for their +# package to find out whether this module is available. +#<module name="mysql"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SQL CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# mysql is more complex than described here, see the docs for more # +# info: https://docs.inspircd.org/4/modules/mysql # +# +#<database module="mysql" name="mydb" user="myuser" pass="mypass" host="localhost" id="my_database2" ssl="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Named modes module: Allows for the display and set/unset of channel +# modes via long-form mode names via +Z and the /PROP command. +# For example, to set a ban, do /MODE #channel +Z ban=foo!bar@baz or +# /PROP #channel ban=foo!bar@baz +#<module name="namedmodes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Nickchange flood protection module: Provides channel mode +F X:Y +# which allows up to X nick changes in Y seconds. +#<module name="nickflood"> +# +# The time period to prevent nick changes for: +#<nickflood duration="1m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Nicklock module: Let opers change a user's nick and then stop that +# user from changing their nick again until unlocked. +# This module is oper-only. +# To use, NICKLOCK and NICKUNLOCK must be in one of your oper class blocks. +#<module name="nicklock"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# No CTCP module: Adds the channel mode +C and user mode +T to block +# CTCPs and extban 'C' to block CTCPs sent by specific users. +#<module name="noctcp"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# No kicks module: Adds the +Q channel mode and the Q: extban to deny +# certain users from kicking. +#<module name="nokicks"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# No nicks module: Adds the +N channel mode, as well as the 'N' extban. +# +N stops all users from changing their nick, the N extban stops +# anyone from matching a +b N:nick!user@host mask from changing their +# nick. +#<module name="nonicks"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# No notice module: Adds the channel mode +T and the extban 'T' to +# block specific users from noticing the channel. +#<module name="nonotice"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Network business join module: +# Allows an oper to join a channel using /OJOIN, giving them +Y on the +# channel which makes them immune to kicks. +#<module name="ojoin"> +# +# Specify the prefix that +Y will grant here. +# Leave 'prefix' empty if you do not wish +Y to grant a prefix. +# If 'notice' is set to on, upon /OJOIN, the server will notice the +# channel saying that the oper is joining on network business. +# If 'op' is set to on, it will give them +o along with +Y. +#<ojoin prefix="!" notice="yes" op="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper channels mode: Adds the +O channel mode which restricts channel +# access to server operators and extbans O:<type> and o:<account> that +# match against an oper type and oper account respectively. +#<module name="operchans"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper join module: Auto-joins opers to a channel upon oper-up. +# This module is oper-only. For the user equivalent, see the conn_join +# module. +#<module name="operjoin"> +# +#-#-#-#-#-#-#-#-#-#-# OPERJOIN CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# If you are using the operjoin module, specify options here: # +# # +# channel - The channel name to join, can also be a comma # +# separated list e.g. "#channel1,#channel2". # +# # +# override - If on, lets the oper join walking thru any modes # +# that might be set, even bans. # +# # +#<operjoin channel="#channel" override="no"> +# +# Alternatively you can use the autojoin="channellist" in a <type> # +# tag to set specific autojoins for a type of oper, for example: # +# +#<type name="Helper" autojoin="#help" classes="..."> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper levels module: Gives each oper a level and prevents actions +# being taken by lower level opers against higher level opers. +# Specify the level as the 'level' parameter of the <type> tag. +# This module is oper-only. +#<module name="operlevels"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper log module: Logs all oper commands to the server log (with log +# type "m_operlog" at default loglevel), and optionally to the 'o' +# snomask. +# This module is oper-only. +#<module name="operlog"> +# +# If the following option is on then all oper commands will be sent to +# the snomask 'r'. The default is no. +#<operlog tosnomask="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper modes module: Allows you to specify modes to add/remove on oper. +# Specify the modes as the 'modes' parameter of the <type> tag +# and/or as the 'modes' parameter of the <oper> tag. +# This module is oper-only. For the user equivalent, see the +# conn_umodes module. +#<module name="opermodes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper MOTD module: Provides support for a separate message of the day +# on oper-up. +# This module is oper-only. +#<module name="opermotd"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Oper prefixing module: Adds a channel prefix mode +y which is given +# to all server operators automatically on all channels they are in. +# This prefix mode is more powerful than channel op and other regular +# prefix modes. +# +# Load this module if you want all your server operators to have +# channel operator powers. +#<module name="operprefix"> +# +# You may additionally customise the prefix character. +#<operprefix prefix="!"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Op moderated module: Adds channel mode +U and extban u: which allow +# making messages from matching unprivileged users only visible to +# channel operators. +#<module name="opmoderated"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Override module: Adds support for oper override. +# This module is oper-only. +#<module name="override"> +# +#-#-#-#-#-#-#-#-#-#-# OVERRIDE CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# Much of override's configuration relates to your oper blocks. # +# For more information on how to allow opers to override, see: # +# https://docs.inspircd.org/4/modules/override # +# # +# noisy - If enabled, all oper overrides will be announced # +# via channel notice. # +# # +# requirekey - If enabled, overriding on join requires a channel # +# key of "override" to be specified. # +# # +# timeout: The time period after which to automatically remove # +# the override user mode. If not set then it will not # +# be removed automatically. # +# # +#<override noisy="yes" +# requirekey="no" +# timeout="30m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Password forwarding module: Allows forwarding passwords to services to +# automatically log users into their account. The password can either be +# specified as the server password or as a second parameter to the /NICK +# command. +#<module name="passforward"> + +<passforward + + # nick: The nick of the service to forward passwords to. + nick="NickServ" + + # forwardmsg: Message to send to users when forwarding their + # password. You can use the following variables in this message: + # + # %nick% The nickname of the authenticating user. + # %nickrequired% The nickname of the service to forward to (see above). + # %pass% The password to forward to services. + # %user% The username of the authenticating user. + forwardmsg="NOTICE %nick% :*** Forwarding password to %nickrequired%" + + # cmd: The message to send to forward passwords to services. + cmd="SQUERY %nickrequired% :IDENTIFY %nick% %pass%"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Password hash module: Allows hashed passwords to be used. +# To be useful, a hashing module like bcrypt also needs to be loaded. +#<module name="password_hash"> +# +#-#-#-#-#-#-#-#-#-# PASSWORD HASH CONFIGURATION #-#-#-#-#-#-#-#-#-#-#-# +# +# To use this module, you must define a hash type for each oper's +# password you want to hash. For example: +# +# <oper name="Brain" +# host="brain@dialup15.isp.test.com" +# hash="bcrypt" +# password="$2a$10$Mss9AtHHslZTLBrXqM0FB.JBwD.UTSu8A48SfrY9exrpxbsRiRTbO" +# type="NetAdmin"> +# +# If you are using a hash algorithm which does not perform salting you can use +# HMAC to salt your passwords in order to prevent them from being looked up in +# a rainbow table. +# +# hash="hmac-sha256" password="lkS1Nbtp$CyLd/WPQXizsbxFUTqFRoMvaC+zhOULEeZaQkUJj+Gg" +# +# Generate hashes using the /MKPASSWD command on the server. +# Don't run it on a server you don't trust with your password. +# +# You can also make the MKPASSWD command oper only by uncommenting this: +#<mkpasswd operonly="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# PBKDF2 module: Allows other modules to generate PBKDF2 hashes, +# usually for cryptographic uses and security. +# This module relies on other hash providers (e.g. SHA2). +#<module name="pbkdf2"> +# +# iterations: Iterations the hashing function runs when generating new +# hashes. +# length: Length in bytes of the derived key. +#<pbkdf2 iterations="12288" length="32"> +# You can override these values with specific values +# for specific providers if you want to. Example given for SHA2. +#<pbkdf2prov hash="sha256" iterations="24576"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Permanent channels module: Channels with the permanent channel mode +# will remain open even after everyone else has left the channel, and +# therefore keep things like modes, ban lists and topic. Permanent +# channels -may- need support from your Services package to function +# properly with them. This adds channel mode +P. +# This module is oper-only. +#<module name="permchannels"> +# +# If you like, this module can write a config file of permanent channels +# whenever +P is set, unset, or the topic/modes on a +P channel is changed. +# If you want to do this, set the filename below, and uncomment the include. +# +# If 'listmodes' is yes then all list modes (+b, +I, +e, +g...) will be +# saved. Defaults to no. +# +# 'saveperiod' determines how often to check if the database needs to be +# saved to disk. Defaults to every five seconds. +# +# 'backoff' is the value to multiply the saveperiod by every time a save +# fails. When the save succeeds the period will be reset. +# +# 'maxbackoff' is the maximum write period that should be allowed even +# if incremental backoff is enabled. +# +# 'operonly' determines whether a server operator or services server is +# needed to enable the permchannels mode. You should generally keep this +# set to yes unless you know what you are doing. +#<permchanneldb filename="permchannels.conf" +# listmodes="yes" +# saveperiod="5s" +# backoff="2" +# maxbackoff="5m" +# operonly="yes"> +#<include file="permchannels.conf" missingokay="yes"> +# +# You may also create channels on startup by using the <permchannels> block. +#<permchannels channel="#opers" modes="isP" topic="Opers only."> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# PostgreSQL module: Allows other SQL modules to access PgSQL databases +# through a unified API. +# +# This module depends on a third-party library (libpq) and may need to +# be manually enabled at build time. If you are building from source +# you can do this by installing this dependency and running: +# +# ./configure --enable-extras pgsql +# make install +# +# Users of binary packages should consult the documentation for their +# package to find out whether this module is available. +#<module name="pgsql"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SQL CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# pgsql is more complex than described here, see the docs for # +# more: https://docs.inspircd.org/4/modules/pgsql # +# +#<database module="pgsql" name="mydb" user="myuser" pass="mypass" host="localhost" id="my_database" tls="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Random quote module: Provides a random quote on connect. +# NOTE: Some of these may mimic fatal errors and confuse users and +# opers alike - BEWARE! +#<module name="randquote"> +# +#-#-#-#-#-#-#-#-#-#- RANDOMQUOTES CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# Optional - If you specify to use the randquote module, then specify # +# below the path to the quotes file. # +# # +#<randquote file="quotes.txt"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Real name ban: Implements two extended bans: # +# 'a', which matches a n!u@h+realname mask like +b a:*!*@host+*real* # +# 'r', which matches a realname mask like +b r:*realname?here* # +#<module name="realnameban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Redirect module: Adds channel mode +L which redirects users to # +# another channel when the channel has reached its user limit and # +# user mode +L which stops redirection. # +#<module name="redirect"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Regular expression provider for glob or wildcard (?/*) matching. +# You must have at least 1 provider loaded to use the filter or R-line +# modules. This module has no additional requirements, as it uses the +# matching already present in InspIRCd core. +#<module name="regex_glob"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Regular expression provider for PCRE2 (Perl-Compatible Regular +# Expressions). You need libpcre2 installed to compile and load this +# module. You must have at least 1 provider loaded to use the filter or +# R-line modules. +#<module name="regex_pcre2"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Regular expression provider for POSIX regular expressions. +# You shouldn't need any additional libraries on a POSIX-compatible +# system (i.e.: any Linux, BSD, but not Windows). You must have at +# least 1 provider loaded to use the filter or R-line modules. +# On POSIX-compliant systems, regex syntax can be found by using the +# command: 'man 7 regex'. +#<module name="regex_posix"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Regular Expression Provider for RE2 Regular Expressions. +# You need libre2 installed and in your include/library paths in order +# to compile and load this module. +#<module name="regex_re2"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Regular expression provider for C++11 std::regex regular expressions. +#<module name="regex_stdlib"> +# +# Specify the regular expression engine to use here. Valid settings are +# bre, ere, awk, grep, egrep, ecmascript (default if not specified). +#<stdregex type="ecmascript"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Remove module: Adds the /REMOVE command which is a peaceful +# alternative to /KICK. +#<module name="remove"> +# +# supportnokicks: If yes, /REMOVE is not allowed on channels where the +# nokicks (+Q) mode is set. Defaults to no. +# protectedrank: Members having this rank or above may not be /REMOVE'd +# by anyone. Set to 0 to disable this feature. Defaults to 50000. +#<remove supportnokicks="yes" protectedrank="50000"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Repeat module: Allows to block, kick or ban upon similar messages +# being uttered several times. Provides channel mode +E. +# +# Syntax: [~|*]<lines>:<duration>[:<difference>][:<backlog>] +# ~ is to block, * is to ban, default is kick. +# lines - In mode 1, the amount of lines that has to match consecutively. +# In mode 2, the size of the backlog to keep for matching. +# seconds - How old the message has to be before it's invalidated. +# difference - Edit distance, in percent, between two strings to trigger on. +# backlog - When set, the function goes into mode 2. In this mode the +# function will trigger if this many of the last <lines> matches. +# +# As this module can be rather CPU-intensive, it comes with some options. +# maxbacklog - Maximum size that can be specified for backlog. 0 disables +# multiline matching. +# maxdistance - Max percentage of difference between two lines we'll allow +# to match. Set to 0 to disable edit-distance matching. +# maxlines - Max lines of backlog to match against. +# maxtime - Maximum period of time a user can set. 0 to allow any. +# size - Maximum number of characters to check for, can be used to +# truncate messages before they are checked, resulting in +# less CPU usage. Increasing this beyond 512 doesn't have +# any effect, as the maximum length of a message on IRC +# cannot exceed that. +# kickmessage - Kick message when * is specified +#<repeat maxbacklog="20" +# maxdistance="50" +# maxlines="20" +# maxtime="0s" +# size="512" +# extended="yes" +# message="Repeat flood detected (trigger is %lines% messages in %duration%)"> +#<module name="repeat"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Restricted channels module: Allows only opers with the +# channels/restricted-create priv and/or registered users to +# create channels. +# +# You probably *DO NOT* want to load this module on a public network. +# +#<module name="restrictchans"> +# +# allowregistered: should registered users be allowed to bypass the restrictions? +#<restrictchans allowregistered="no"> +# +# Allow any channel matching #user-* to be created, bypassing restrictchans checks +#<allowchannel name="#user-*"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Restrict message module: Allows users to only message opers. +# +# You probably *DO NOT* want to load this module on a public network. +# +#<module name="restrictmsg"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# R-line module: Ban users through regular expression patterns. +#<module name="rline"> +# +#-#-#-#-#-#-#-#-#-#-#-#- RLINE CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# +# If you wish to re-check a user when they change nickname (can be +# useful under some situations, but *can* also use CPU with more users +# on a server) then set 'matchonnickchange' to yes. +# If you additionally want Z-lines to be added on matches, then +# set 'zlineonmatch' to yes. +# Also, this is where you set what Regular Expression engine is to be +# used. If you ever change it while running, all of your R-lines will +# be wiped. This is the regex engine used by all R-lines set, and +# regex_<engine> must be loaded, or rline will be non-functional +# until you load it or change the engine to one that is loaded. +# +#<rline matchonnickchange="yes" zlineonmatch="no" engine="stdregex"> +# +# Generally, you will NOT want to use 'glob' here, as this turns an +# R-line into just another G-line. The exceptions are that R-lines will +# always use the full "nick!user@host realname" string, rather than only +# user@host, but beware that only the ? and * wildcards are available, +# and are the only way to specify where the space can occur if you do +# use glob. For this reason, is recommended to use a real regex engine +# so that at least \s or [[:space:]] is available. + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# RMODE module: Adds the /RMODE command. +# Allows channel operators to remove list modes en masse, optionally +# matching a glob-based pattern. +# Syntax: /RMODE <channel> <mode> [<pattern>] +# E.g. '/RMODE #channel b m:*' will remove all mute extbans on the channel. +#<module name="rmode"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SAJOIN module: Adds the /SAJOIN command which forcibly joins a user +# to the given channel. +# This module is oper-only. +# To use, SAJOIN must be in one of your oper class blocks. +# Opers need the users/sajoin-others priv to be able to /SAJOIN users +# other than themselves. +#<module name="sajoin"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SAKICK module: Adds the /SAKICK command which kicks a user from the +# given channel. +# This module is oper-only. +# To use, SAKICK must be in one of your oper class blocks. +#<module name="sakick"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SAMODE module: Adds the /SAMODE command which allows server operators +# to change modes on a channel without requiring them to have any +# channel privileges. Also allows changing user modes for any user. +# This module is oper-only. +# To use, SAMODE must be in one of your oper class blocks. +#<module name="samode"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SANICK module: Adds the /SANICK command which allows opers to change +# users' nicks. +# This module is oper-only. +# To use, SANICK must be in one of your oper class blocks. +#<module name="sanick"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SAPART module: Adds the /SAPART command which forcibly parts a user +# from a channel. +# This module is oper-only. +# To use, SAPART must be in one of your oper class blocks. +#<module name="sapart"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SAQUIT module: Adds the /SAQUIT command which forcibly quits a user. +# This module is oper-only. +# To use, SAQUIT must be in one of your oper class blocks. +#<module name="saquit"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SASL authentication module: Provides support for IRC Authentication +# Layer via AUTHENTICATE. Note: You also need to have cap loaded +# for SASL to work. +#<module name="sasl"> + +# You must define <sasl:target> to the name of your services server so +# that InspIRCd knows where to send SASL authentication messages and +# when it should enable the SASL capability. +# You can also define <sasl:requiressl> to require users to use TLS +# in order to be able to use SASL. +#<sasl target="services.mynetwork.com" +# requiressl="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SATOPIC module: Adds the /SATOPIC command which allows changing the +# topic on a channel without requiring any channel privileges. +# This module is oper-only. +# To use, SATOPIC must be in one of your oper class blocks. +#<module name="satopic"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Secure list module: Prevent users from using the /LIST command until +# a predefined period has passed. This helps protect your network from +# spambots. +#<module name="securelist"> +# +#-#-#-#-#-#-#-#-#-# SECURELIST CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# Securelist can be harmful to some IRC search engines. To prevent # +# securelist blocking these sites from listing, define exception tags # +# as shown below: # +#<securehost exception="*@*.netsplit.de"> +# # +# exemptregistered - Whether the waiting period applies to users who # +# are logged in to a user account. # +# Defaults to no. # +# # +# fakechans - The number of fake channels to show in /LIST. This can # +# be used to break spambots. # +# # +# fakechanprefix - The prefix for the fake channels. A random suffix # +# will be appended to this when generating channels. # +# # +# fakechantopic - The topic for the fake channels. A random format # +# modifier will be inserted into this for randomness. # +# # +# hidesmallchans - The minimum user count for a channel to show up in # +# /LIST after the wait period (see below). If a user # +# is exempt from the wait period this will not apply # +# to them. # +# # +# showmsg - Whether to tell users that they need to wait for a while # +# before they can use the /LIST command. # +# Defaults to no. # +# # +# waittime - The time period that a user must be connected for before # +# they can use the /LIST command. If exemptregistered is # +# enabled you can set this to 0 to disable unauthenticated # +# users from viewing the channel list. # +# Defaults to 1 minute. # +# # +#<securelist exemptregistered="yes" +# fakechans="5" +# fakechanprefix="#spam" +# fakechantopic="Fake channel for confusing spambots" +# hidesmallchans="0" +# showmsg="yes" +# waittime="1m"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# See nicks module: Adds snomask +n and +N which show local and remote +# nick changes. +# This module is oper-only. +#<module name="seenicks"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Serverban: Implements extended ban 's', which stops anyone connected +# to a server matching a mask like +b s:server.mask.here from joining. +# Wildcards are accepted. +#<module name="serverban"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Services integration module: Adds various features which enable +# integrating with a third-party services pseudoserver like Anope or +# Atheme. +#<module name="services"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SERVICES CONFIGURATION -#-#-#-#-#-#-#-#-#-#-# +# # +# accountoverrideshold - Whether to allow users that are logged in # +# to an account that has a services-held nick # +# in their group to override the SVSHOLD. # +# Defaults to no. # +# # +# disablemodes - Whether channel mode `r` (registered) and # +# user mode `r` (u_registered) are disabled. # +# These modes are deprecated in InspIRCd v4 # +# but may still be needed by older services # +# software. Anope 2.1 is known to work with # +# this enabled. Defaults to no. # +# # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +# <servicesintegration accountoverrideshold="yes" +# disablemodes="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Sethost module: Adds the /SETHOST command. +# This module is oper-only. +# To use, SETHOST must be in one of your oper class blocks. +# See the chghost module for how to customise valid chars for hostnames. +#<module name="sethost"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Setident module: Adds the /SETIDENT command. +# This module is oper-only. +# To use, SETIDENT must be in one of your oper class blocks. +#<module name="setident"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Set idle module: Adds a command for opers to change their idle time. +# This module is oper-only. +# To use, SETIDLE must be in one of your oper class blocks. +#<module name="setidle"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SETNAME module: Adds the /SETNAME command. +#<module name="setname"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SETNAME CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# operonly - Whether the SETNAME command should only be usable by # +# server operators. Defaults to no. # +# # +# notifyopers - Whether to send a snotice to snomask `a` when a user # +# changes their real name. Defaults to to yes if # +# oper-only and no if usable by everyone. # +# # +#<setname notifyopers="yes" +# operonly="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SHA1 module: Allows other modules to generate SHA1 hashes. +# Required by the WebSocket module. +#<module name="sha1"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SHA2 module: Allows other modules to generate SHA2 hashes, +# usually for cryptographic uses and security. +# +# IMPORTANT: +# Other modules such as password_hash may rely on this module being +# loaded to function. Certain modules such as spanningtree will +# function without this module but when it is loaded their features will +# be enhanced (for example the addition of HMAC authentication). +# +#<module name="sha2"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Showfile: Provides support for showing a text file to users when # +# they enter a command. # +# This module adds one command for each <showfile> tag that shows the # +# given file to the user as a series of messages or numerics. # +#<module name="showfile"> +# # +#-#-#-#-#-#-#-#-#-#-# SHOWFILE CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# name - The name of the command which displays this file. This is # +# the only mandatory setting, all others are optional. # +# file - The text file to be shown to the user. # +# By default same as the command name. # +# method - How should the file be shown? # +# * numeric: Send contents using a numeric # +# (similar to /MOTD; the default). # +# * notice: Send contents as a series of notices. # +# * msg: Send contents as a series of private messages. # +# # +# When using the method "numeric", the following extra settings are # +# available: # +# # +# introtext - Introductory line, "Showing <name>" by default. # +# intronumeric - Numeric used for the introductory line. # +# numeric - Numeric used for sending the text itself. # +# endtext - Ending line, "End of <name>" by default. # +# endnumeric - Numeric used for the ending line. # +# # +#<showfile name="RULES" +# file="rules.txt" +# introtext="Server rules:" +# endtext="End of server rules."> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Show whois module: Adds the +W user mode which allows opers to see +# when they are /WHOIS'd. +# This module is oper-only by default. +#<module name="showwhois"> +# +# If you wish, you may also let users set this mode. +#<showwhois opersonly="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Shun module: Provides the /SHUN command, which stops a user from +# executing all except configured commands. +# This module is oper-only. +# To use, SHUN must be in one of your oper class blocks. +#<module name="shun"> +# +# Configuration: +# +# allowconnect: Whether to only apply shuns to users who are fully +# connected to the server. +# +# allowtags: Whether to allow client tags to be attached to enabled +# commands. +# +# cleanedcommands: The commands that, if enabled, should be cleaned +# of any message content if a shunned user tries to +# execute them. +# +# enabledcommands: The commands that a shunned user is allowed to +# execute. +# +# notifyuser: Whether to notify shunned users that a command they tried +# to execute has been blocked. +# +#<shun enabledcommands="ADMIN OPER PING PONG QUIT PART JOIN" +# cleanedcommands="AWAY PART QUIT" +# allowconnect="no" +# allowtags="no" +# notifyuser="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Silence module: Adds support for the /SILENCE command, which allows +# users to have a server-side ignore list for their client. +#<module name="silence"> +# +# Set the maximum number of entries allowed on a user's silence list. +#<silence maxentries="32" +# +# Whether messages from services servers will bypass silence masks. +#exemptservice="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# ____ _ _____ _ _ ____ _ _ _ # +# | _ \ ___ __ _ __| | |_ _| |__ (_)___ | __ )(_) |_| | # +# | |_) / _ \/ _` |/ _` | | | | '_ \| / __| | _ \| | __| | # +# | _ < __/ (_| | (_| | | | | | | | \__ \ | |_) | | |_|_| # +# |_| \_\___|\__,_|\__,_| |_| |_| |_|_|___/ |____/|_|\__(_) # +# # +# To link servers to InspIRCd, you MUST load the spanningtree module. # +# If you don't do this, server links will NOT work at all. # +# This is by design, to allow for the implementation of other linking # +# protocols in modules in the future. # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Spanning tree module: Allows linking of servers using the spanning +# tree protocol (see the READ THIS BIT section above). +# You will almost always want to load this. +# +#<module name="spanningtree"> +# +# This file has all the information about server links and services servers. +# You *MUST* edit it if you intend to link servers. +#<include file="&dir.example;/links.example.conf"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SQL authentication module: Allows IRCd connections to be tied into +# a database table (for example a forum). +# +#<module name="sqlauth"> +# +#-#-#-#-#-#-#-#-#-#-#- SQLAUTH CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# sqlauth is too complex to describe here, see the docs: # +# https://docs.inspircd.org/4/modules/sqlauth # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SQLite3 module: Allows other SQL modules to access SQLite3 # +# databases through a unified API. # +# # +# This module depends on a third-party library (SQLite) and may need # +# to be manually enabled at build time. If you are building from # +# source you can do this by installing this dependency and running: # +# # +# ./configure --enable-extras sqlite3 # +# make install # +# # +# Users of binary packages should consult the documentation for their # +# package to find out whether this module is available. # +#<module name="sqlite3"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SQL CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# sqlite is more complex than described here, see the docs for more # +# info: https://docs.inspircd.org/4/modules/sqlite3 # +# +#<database module="sqlite" hostname="/full/path/to/database.db" id="anytext"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SQL oper module: Allows you to store oper credentials in an SQL +# table. You can add additional table columns like you would config +# tags in opers.conf. Opers in opers.conf will override opers from +# this module. +# +#<module name="sqloper"> +# +#-#-#-#-#-#-#-#-#-#-#- SQLOPER CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# dbid - Database ID to use (see SQL modules). # +# # +# See also: https://docs.inspircd.org/4/modules/sqloper # +# # +#<sqloper dbid="1"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# GnuTLS TLS module: Adds support for TLS connections using GnuTLS, +# if enabled. You must answer 'yes' in ./configure when asked or +# manually symlink the source for this module from the directory +# src/modules/extra, if you want to enable this, or it will not load. +#<module name="ssl_gnutls"> +# +#-#-#-#-#-#-#-#-#-#-#- GNUTLS CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# ssl_gnutls is too complex to describe here, see the docs: # +# https://docs.inspircd.org/4/modules/ssl_gnutls # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# OpenSSL TLS module: Adds support for TLS connections using OpenSSL, +# if enabled. You must answer 'yes' in ./configure when asked or symlink +# the source for this module from the directory src/modules/extra, if +# you want to enable this, or it will not load. +#<module name="ssl_openssl"> +# +#-#-#-#-#-#-#-#-#-#-#- OPENSSL CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# ssl_openssl is too complex to describe here, see the docs: # +# https://docs.inspircd.org/4/modules/ssl_openssl # + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# TLS info module: Allows users to retrieve information about other +# users' peer TLS certificates and keys via the SSLINFO command. +# This can be used by client scripts to validate users. For this to +# work either ssl_gnutls or ssl_openssl must be loaded. +# This module also adds the "<user> is using a secure connection" +# and "<user> has TLS client certificate fingerprint <fingerprint>" +# WHOIS lines, the ability for opers to use TLS cert fingerprints to +# verify their identity and the ability to force opers to use TLS +# connections in order to oper up. It is highly recommended to load +# this module if you use TLS on your network. +# For how to use the oper features, please see the first +# example <oper> tag in opers.example.conf. +# +#<module name="sslinfo"> +# +#-#-#-#-#-#-#-#-#-#-#-#- SSLINFO CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-# +# # +# hash - The IANA Hash Function Name of the hash algorithm # +# used for the TLS client fingerprint of WebIRC # +# gateway users (requires the gateway module). This # +# should be the same algorithm you specified in the # +# <sslprofile:hash> field of the TLS profile used for # +# user connections. You can prefix the algorithm name # +# with spki- to use a Subject Public Key Info (SPKI) # +# fingerprint instead of a certificate fingerprint. # +# # +# localsecure - Whether to treat locally-connected plaintext users # +# as if they are connected with TLS. Defaults to yes. # +# # +# operonly - Whether TLS client certificate info is only visible # +# by server operators. Defaults to no. # +# # +# warnexpiring - If specified then the maximum period of validity # +# that can be left on a user's TLS client certificate # +# before users are warned about the imminent expiry. # +# # +# welcomemsg - Whether to send a welcome message to users that are # +# connecting using TLS containing their server name, # +# ciphersuite and client fingerprint. Defaults to no. # +# # +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# +#<sslinfo hash="sha-256" +# localsecure="yes" +# operonly="no" +# warnexpiring="1w" +# welcomemsg="no"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# TLS mode module: Adds support for TLS-only channels via the '+z' +# channel mode, TLS-only private messages via the '+z' user mode and +# the 'z:' extban which matches TLS client certificate fingerprints. +# +# Does not do anything useful without a working TLS module and the +# sslinfo module (see below). +#<module name="sslmodes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# TLS rehash signal module: Allows the TLS modules to be rehashed by +# sending SIGUSR1 to a running InspIRCd process. +# +# This module depends on a POSIX component (SIGUSR1) and may need to be +# manually enabled at build time. If you are building from source you +# can do this by running: +# +# ./configure --enable-extras sslrehashsignal +# make install +# +# Users of binary packages should consult the documentation for their +# package to find out whether this module is available. +#<module name="sslrehashsignal"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# StartTLS module: Adds support for the IRCv3 tls capability which # +# allows clients to upgrade their connection to use TLS. As well as # +# this module you should also load one of ssl_gnutls or ssl_openssl # +# modules. You may also want to consider using the ircv3_sts module. # +#<module name="starttls"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Strip color module: Adds channel mode +S that strips IRC formatting +# characters from all messages sent to the channel. +#<module name="stripcolor"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# SWHOIS module: Allows you to add arbitrary lines to user WHOIS. +# This module is oper-only. +# To use, SWHOIS must be in one of your oper class blocks. +#<module name="swhois"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Timed bans module: Adds timed channel bans with the /TBAN command. +#<module name="timedbans"> +# By default, it sends a notice to channel operators when timed ban is +# set and when it is removed by server. +#<timedbans sendnotice="yes"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Test line module: Adds the /TLINE command, used to test how many +# users a /GLINE or /ZLINE etc. would match. +# This module is oper-only. +# To use, TLINE must be in one of your oper class blocks. +#<module name="tline"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# UHNAMES support module: Adds support for the IRCv3 userhost-in-names +# capability which displays the username and hostname of users in the +# NAMES response. +#<module name="uhnames"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Uninvite module: Adds the /UNINVITE command which lets users remove +# pending invites from channels without waiting for the user to join. +#<module name="uninvite"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Vhost module: Adds the VHOST command which allows for adding virtual +# hosts which are accessible using a username and password in the config. +#<module name="vhost"> +# +#-#-#-#-#-#-#-#-#-#-#- VHOST CONFIGURATION -#-#-#-#-#-#-#-#-#-#-#-#-# +# # +# user - Username for the vhost. # +# # +# pass - Password for the vhost. # +# # +# hash - The hash for the specific user (optional) # +# password_hash and a hashing module must be loaded for # +# this to work. # +# # +# host - Vhost to set. # +# +#<vhost user="some_username" pass="some_password" host="some.host.test.cc"> +#<vhost user="foo" password="$2a$10$iTuYLT6BRhRlOgzfsW9oPe62etW.oXwSpyKw5rJit64SGZanLXghO" hash="bcrypt" host="some.other.host.example.com"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# Watch module: Adds the WATCH command, which is used by clients to +# maintain notify lists. +#<module name="watch"> +# +# Set the maximum number of entries on a user's watch list below. +#<watch maxwatch="32"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# WebSocket module: Adds WebSocket support. +# Specify hook="websocket" in a <bind> tag to make that port accept +# WebSocket connections. Compatible with TLS. +# Requires SHA-1 hash support available in the sha1 module. +#<module name="websocket"> +# +# defaultmode: The default frame mode if a client does not send a +# WebSocket subprotocol. Potential values are "text" to +# encode messages as UTF-8 text frames, "binary" to send +# messages as raw binary frames, or "reject" to close +# connections which do not request a subprotocol. Defaults +# to "text". +# +# proxyranges: A space-delimited list of glob or CIDR matches to trust +# the X-Real-IP or X-Forwarded-For headers from. If enabled +# the server will use the IP address specified by those HTTP +# headers. You should NOT enable this unless you are using +# a HTTP proxy like nginx as it will allow IP spoofing. +# +# allowmissingorigin: Whether to allow connections from clients that +# don't send an origin header. These are probably +# not web clients so it probably safe to allow this. +# Defaults to yes. +# +# nativeping: Whether to check client connectivity using WebSocket ping +# messages instead of IRC ping messages. Defaults to yes. +# +#<websocket defaultmode="text" +# proxyranges="192.0.2.0/24 198.51.100.*" +# allowmissingorigin="yes" +# nativeping="yes"> +# +# If you use the websocket module you MUST specify one or more origins +# which are allowed to connect to the server. You should set this as +# strict as possible to prevent malicious webpages from connecting to +# your server. +# <wsorigin allow="https://*.example.com"> + +#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-#-# +# X-line database: Stores all *-lines (G/Z/K/R/any added by other modules) +# in a file which is re-loaded on restart. This is useful +# for two reasons: it keeps bans so users may not evade them, and on +# bigger networks, server connections will take less time as there will +# be a lot less bans to apply - as most of them will already be there. +#<module name="xline_db"> + +# Specify the filename for the xline database and how often to check whether +# the database needs to be saved here. +#<xlinedb filename="xline.db" +# saveperiod="5s" +# backoff="2" +# maxbackoff="5m"> diff --git a/ansible/roles/inspircd/templates/ca.manero.org/motd.txt b/ansible/roles/inspircd/templates/ca.manero.org/motd.txt new file mode 100644 index 0000000..e172306 --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/motd.txt @@ -0,0 +1,32 @@ +------------------------------------------------------------------- + XWXWXWXWXWXWXWXW WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX A XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW AWA WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX AA AWXWA AA XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW VWXWXWXWXWV WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX AA VWXWXWXWV AA XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW VWXWXWXA VWXWXWV AXWXWXWV WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX XWXWXWXWXWXWXWXWXWXWXWXWX XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW AXWXWXWXWXWXWXWXWXWXWXWXWXWXA WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX VXWXWXWXWXWXWXWXWXWXWXV XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW VXWXWXWXWXWXWXWXV WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX XWXWXWXWXWXWX XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW AXWXWXWXWXWXWXWXA WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX I XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW I WXWXWXWXWXWXWXWX + WXWXWXWXWXWXWXWX I XWXWXWXWXWXWXWXW + XWXWXWXWXWXWXWXW WXWXWXWXWXWXWXWX + ------------------------------------------------------------------- + +This server is hosted in Canada, by andys + + +███╗ ███╗ █████╗ ███╗ ██╗███████╗██████╗ ██████╗ +████╗ ████║██╔══██╗████╗ ██║██╔════╝██╔══██╗██╔═══██╗ +██╔████╔██║███████║██╔██╗ ██║█████╗ ██████╔╝██║ ██║ +██║╚██╔╝██║██╔══██║██║╚██╗██║██╔══╝ ██╔══██╗██║ ██║ +██║ ╚═╝ ██║██║ ██║██║ ╚████║███████╗██║ ██║╚██████╔╝ +╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═════╝ + +Welcome to the manero memorial irc network + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/opers.conf b/ansible/roles/inspircd/templates/ca.manero.org/opers.conf new file mode 100644 index 0000000..da1350c --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/opers.conf @@ -0,0 +1,43 @@ +<class name="SACommands" commands="SAJOIN SAPART SANICK SAQUIT SATOPIC SAKICK SAMODE OJOIN"> +<class name="ServerLink" commands="CONNECT SQUIT RCONNECT RSQUIT MKPASSWD ALLTIME SWHOIS LOCKSERV UNLOCKSERV" usermodes="*" chanmodes="*" privs="servers/auspex" snomasks="Cc"> +<class name="BanControl" commands="KILL GLINE KLINE ZLINE QLINE ELINE TLINE RLINE CHECK NICKLOCK NICKUNLOCK SHUN CLONES CBAN" usermodes="*" chanmodes="*" snomasks="Xx"> +<class name="OperChat" commands="WALLOPS GLOBOPS" usermodes="*" chanmodes="*" privs="users/mass-message" snomasks="Gg"> +<class name="HostCloak" commands="SETHOST SETIDENT SETIDLE CHGNAME CHGHOST CHGIDENT" usermodes="*" chanmodes="*" privs="users/auspex"> +<class + name="Shutdown" + commands="DIE RESTART REHASH LOADMODULE UNLOADMODULE RELOADMODULE GLOADMODULE GUNLOADMODULE GRELOADMODULE" + privs="users/auspex channels/auspex servers/auspex users/mass-message users/flood/no-throttle users/flood/increased-buffers" + usermodes="*" + chanmodes="*" + snomasks="*"> + +<type + # name: Name of the type. Used in actual server operator accounts below. + name="NetAdmin" + + # classes: Classes (blocks above) that this type belongs to. + classes="SACommands OperChat BanControl HostCloak Shutdown ServerLink" # vhost: Host that opers of this type get when they log in (oper up). This is optional. + #vhost="netadmin.omega.example.org" + + # maxchans: Maximum number of channels opers of this type can be in at once. + maxchans="60" + + # modes: User modes besides +o that are set on an oper of this type # when they oper up. Used for snomasks and other things. + # Requires the opermodes module to be loaded. + modes="+s +cCqQ"> + +<oper + name="gmc" + hash="bcrypt" + password="{{ vault_inspircd_ca_oper_graham_password }}" + host="*@*" sslonly="yes" vhost="gmc.texas.ragnar" + type="NetAdmin"> + +<oper + name="andys" + hash="bcrypt" + password="{{ vault_inspircd_ca_oper_andys_password }}" + host="*@*" + sslonly="yes" + type="NetAdmin"> + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/services-atheme.conf b/ansible/roles/inspircd/templates/ca.manero.org/services-atheme.conf new file mode 100644 index 0000000..c65d75a --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/services-atheme.conf @@ -0,0 +1,52 @@ +# This file contains aliases and nickname reservations which are used +# by Atheme. See https://atheme.github.io/atheme.html for more +# information on Atheme. + +# This file inherits from the generic config to avoid repetition. +<include file="&dir.example;/services/generic.example.conf"> + +# Long hand aliases for services pseudoclients. +<alias text="ALIS" replace="PRIVMSG $requirement :$2-" requires="ALIS" service="yes"> +<alias text="CHANFIX" replace="PRIVMSG $requirement :$2-" requires="ChanFix" service="yes"> +<alias text="GAMESERV" replace="PRIVMSG $requirement :$2-" requires="GameServ" service="yes"> +<alias text="GROUPSERV" replace="PRIVMSG $requirement :$2-" requires="GroupServ" service="yes"> +<alias text="HELPSERV" replace="PRIVMSG $requirement :$2-" requires="HelpServ" service="yes"> +<alias text="INFOSERV" replace="PRIVMSG $requirement :$2-" requires="InfoServ" service="yes"> +<alias text="PROXYSCAN" replace="PRIVMSG $requirement :$2-" requires="Proxyscan" service="yes" operonly="yes"> +<alias text="RPGSERV" replace="PRIVMSG $requirement :$2-" requires="RPGServ" service="yes"> + +# Short hand aliases for services pseudoclients. +<alias text="CF" replace="PRIVMSG $requirement :$2-" requires="ChanFix" service="yes"> +<alias text="GS" replace="PRIVMSG $requirement :$2-" requires="GroupServ" service="yes"> +<alias text="IS" replace="PRIVMSG $requirement :$2-" requires="InfoServ" service="yes"> +<alias text="LS" replace="PRIVMSG $requirement :$2-" requires="ALIS" service="yes"> +<alias text="PS" replace="PRIVMSG $requirement :$2-" requires="Proxyscan" service="yes" operonly="yes"> +<alias text="RS" replace="PRIVMSG $requirement :$2-" requires="RPGServ" service="yes"> + +# These short hand aliases conflict with other pseudoclients. You can enable +# them but you will need to comment out the uncommented ones above first, +#<alias text="GS" replace="PRIVMSG $requirement :$2-" requires="GameServ" service="yes"> +#<alias text="HS" replace="PRIVMSG $requirement :$2-" requires="HelpServ" service="yes"> + +# Prevent clients from using the nicknames of services pseudoclients. +<badnick nick="ALIS" reason="Reserved for a network service"> +<badnick nick="ChanFix" reason="Reserved for a network service"> +<badnick nick="GameServ" reason="Reserved for a network service"> +<badnick nick="GroupServ" reason="Reserved for a network service"> +<badnick nick="HelpServ" reason="Reserved for a network service"> +<badnick nick="InfoServ" reason="Reserved for a network service"> +<badnick nick="Proxyscan" reason="Reserved for a network service"> +<badnick nick="RPGServ" reason="Reserved for a network service"> +<badnick nick="SaslServ" reason="Reserved for a network service"> + +# Exempt services pseudoclients from filters. +<exemptfromfilter target="ALIS"> +<exemptfromfilter target="ChanFix"> +<exemptfromfilter target="GameServ"> +<exemptfromfilter target="GroupServ"> +<exemptfromfilter target="HelpServ"> +<exemptfromfilter target="InfoServ"> +<exemptfromfilter target="Proxyscan"> +<exemptfromfilter target="RPGServ"> +<exemptfromfilter target="SaslServ"> + diff --git a/ansible/roles/inspircd/templates/ca.manero.org/thelounge.conf b/ansible/roles/inspircd/templates/ca.manero.org/thelounge.conf new file mode 100644 index 0000000..8d4790e --- /dev/null +++ b/ansible/roles/inspircd/templates/ca.manero.org/thelounge.conf @@ -0,0 +1,33 @@ +# This file contains connect classes which are used by IRCCloud users. +# See https://www.irccloud.com for more information on IRCCloud and +# https://www.irccloud.com/networks for more information on supporting +# IRCCloud on your network. + +<connect name="TheLounge" + parent="main" + globalmax="100" + localmax="100" + useconnectban="no" + useconnflood="no" + usednsbl="no"> + +<connect name="TheLounge (IPv4)" + parent="TheLounge" + allow="167.114.209.151/32 158.69.124.210/32 192.99.44.61/32 172.16.0.0/12" + globalmax="100" + localmax="100" + uniqueusername="yes"> + +# This is not typically needed as each user has their own IPv6 but if you have +# <cidr:ipv6clone> set to a value lower than 128 you will need to enable it. +#<connect name="IRCCloud (IPv6)" +# parent="IRCCloud" +# allow="2a03:5180:f::/62 2a03:5180:f:4::/63 2a03:5180:f:6::/64"> + +# IRCCloud IPv4 users use a shared IPv4 address which means that some clients +# may have trouble banning them. To work around this you can use the cloak_user +# module to copy the user identifier from the username to the hostname. +#<cloak method="username" +# class="IRCCloud (IPv4),IRCCloud (IPv6)" +# suffix=".irccloud.com"> + diff --git a/ansible/roles/inspircd/templates/us.manero.org/filter.conf b/ansible/roles/inspircd/templates/us.manero.org/filter.conf new file mode 100644 index 0000000..fe95687 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/filter.conf @@ -0,0 +1,80 @@ +# Configuration file for the filter module + +# The tags for this module are formatted as follows: +# +# <keyword pattern="any glob pattern here" +# reason="reason for filtering" +# action="action to take" +# flags="filter flags" +# duration="optional duration of the G-line, Z-line or shun"> +# +# Valid actions for 'action' are: +# +# warn This allows the line and sends out a notice to all opers +# with +s. +# +# block This blocks the line, sends out a notice to all opers with +# +s and informs the user that their message was blocked. +# +# silent This blocks the line only, and informs the user that their +# message was blocked, but does not notify opers. +# +# none This action causes nothing to be done except logging. This +# is the default action if none is specified. +# +# kill This disconnects the user, with the 'reason' parameter as +# the kill reason. +# +# gline G-line the user for 'duration' length of time. Durations may +# be specified using the notation 1y2w3d4h5m6s in a similar way to +# other G-lines, omitting the duration or setting it to 0 makes +# any G-lines set by this filter be permanent. +# +# zline Z-line the user for 'duration' length of time. Durations may +# be specified using the notation 1y2w3d4h5m6s in a similar way to +# other Z-lines, omitting the duration or setting it to 0 makes +# any Z-lines set by this filter be permanent. +# +# shun Shun the user for 'duration' length of time. Durations may +# be specified using the notation 1y2w3d4h5m6s in a similar way to +# other X-lines, omitting the duration or setting it to 0 makes +# any shuns set by this filter be permanent. +# Requires the shun module to be loaded. +# +# You can add filters from IRC using the /FILTER command. If you do this, they +# will be set globally to your entire network. +# +# Valid characters for 'flags' are one or more of: +# +# p: Block private and channel messages +# n: Block private and channel notices +# P: Block part messages +# q: Block quit messages +# o: Don't match against opers +# r: Don't match against registered users +# c: Strip color codes from text before trying to match +# *: Represents all of the above flags except r +# -: Does nothing, a no-op for when you do not want to specify any flags + +# Example filters: +# +# <keyword pattern="*qwerty*" reason="You qwertied!" action="block" flags="pn"> +# <keyword pattern="*killmenow*" reason="As you request." action="kill" flags="*"> +# <keyword pattern="*blah*" reason="Don't blah!" action="gline" duration="1d6h" flags="-"> + +# An example regexp filter: +# +# <keyword pattern="^blah.*?$" reason="Don't blah!" action="gline" duration="1d6h" flags="pnPq"> + +# You may specify specific channels that are exempt from being filtered: +#<exemptfromfilter target="#opers"> +#<exemptfromfilter target="#help"> + +# You can also exempt messages from being filtered if they are sent to +# specific nicks. +# Example that exempts all messages sent *to* NickServ: +#<exemptfromfilter target="NickServ"> + +# Note that messages *from* services are never subject to filtering; +# <exemptfromfilter> tags are only for exempting messages sent *to* the +# configured targets. diff --git a/ansible/roles/inspircd/templates/us.manero.org/help.conf b/ansible/roles/inspircd/templates/us.manero.org/help.conf new file mode 100644 index 0000000..d3415cc --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/help.conf @@ -0,0 +1,1137 @@ +# Sample configuration file for the help module. +# You can either copy this into your conf folder and set up the module to use it, +# or you can customize the responses for your network and/or add more. +# +# The way the new help system works is simple. You use one or more helptopic tags. +# <helptopic key="moo" title="something here" value="something here"> +# key is what the user is looking for (i.e. /HELP moo), title is the title, and +# value is what they get back +# (note that it can span multiple lines!). +# -- w00t 16/dec/2006 +# + +<alias text="HELPOP" replace="HELP $2-"> + +<helpmsg nohelp="There is no help for the topic you searched for. Please try again."> + +<helptopic key="start" title="InspIRCd Help System" value=" +This system provides help for commands and modes. +Specify your question or a command name as the +parameter for this command. + +/HELP CUSER - To see a list of user commands +/HELP COPER - To see a list of oper commands +/HELP UMODES - To see a list of user modes +/HELP CHMODES - To see a list of channel modes +/HELP SNOMASKS - To see a list of oper snotice masks +/HELP EXTBANS - To see a list of extended bans +/HELP INDEX - To see a list of help topics +"> + +<helptopic key="cuser" title="User Commands" value=" +ACCEPT ADMIN AWAY COMMANDS CYCLE DCCALLOW +HEXIP INFO INVITE ISON JOIN KICK +KNOCK LINKS LIST LUSERS MAP MKPASSWD +MODE MODULES MONITOR MOTD NAMES NICK +NOTICE OPER PART PASS PING PONG +PRIVMSG QUIT REMOVE SERVLIST SETNAME SILENCE +SQUERY SSLINFO STATS TBAN TIME TITLE +TOPIC UNINVITE USER USERHOST VERSION VHOST +WATCH WHO WHOIS WHOWAS +"> + +<helptopic key="squery" title="/SQUERY <target> :<message>" value=" +Sends a message to the network service specified in <target>. +"> + +<helptopic key="servlist" title="/SERVLIST [<nick> [<oper-type>]]" value=" +List network services that are currently connected to the network and +visible to you. The optional glob-based nick and oper-type parameters +match against the nickname of the network service and the oper type of +the network service. +"> + +<helptopic key="sslinfo" title="/SSLINFO [<chan>|<nick>]" value=" +If a channel is specified then display TLS connection information +for users in the specified channel. + +If a user is specified then display information on the TLS connection +and certificate of the specified user. + +If no target is specified then display information on the TLS +connection and certificate of the executing user. +"> + +<helptopic key="uninvite" title="/UNINVITE <nick> <channel>" value=" +Uninvite a user from a channel, same syntax as INVITE. +"> + +<helptopic key="tban" title="/TBAN <channel> <duration> <banmask>" value=" +Sets a timed ban. The duration of the ban can be specified in the +form of 1y2w3d4h5m6s - meaning one year, two weeks, three days, +four hours, five minutes and six seconds. All fields in this +format are optional. Alternatively, the ban may just be specified +as a number of seconds. All timed bans appear in the banlist as +normal bans and may be safely removed before their time is up. +"> + +<helptopic key="dccallow" title="/DCCALLOW [(+|-)<nick> [<time>]]|[LIST|HELP]" value=" +/DCCALLOW - List allowed nicks +/DCCALLOW LIST - This also lists allowed nicks +/DCCALLOW +<nick> [<duration>] - Add a nick +/DCCALLOW -<nick> - Remove a nick +/DCCALLOW HELP - Display help + +Duration is optional, and may be specified in seconds or in the +form of 1y2w3d4h5m6s - meaning one year, two weeks, three days, +four hours, five minutes and six seconds. All fields in this +format are optional. +"> + +<helptopic key="accept" title="/ACCEPT *|(+|-)<nick>[,(+|-)<nick>]+" value=" +Manages your accept list. This list is used to determine who can +private message you when you have user mode +g set. + +/ACCEPT * - List accepted nicks +/ACCEPT +<nick> - Add a nick +/ACCEPT -<nick> - Remove a nick + +This command accepts multiple nicks like so: +/ACCEPT +<nick>,-<nick>,+<nick> +"> + +<helptopic key="cycle" title="/CYCLE <channel> [:<reason>]" value=" +Cycles a channel (leaving and rejoining), overrides restrictions that +would stop a new user joining, such as user limits and channel keys. +"> + +<helptopic key="title" title="/TITLE <username> <password>" value=" +Authenticate for a WHOIS title line and optionally a vhost using the +specified username and password. +"> + +<helptopic key="watch" title="/WATCH C|L|l|S|(+|-)<nick> [(+|-)<nick>]+" value=" +/WATCH - List watched nicks that are online +/WATCH l - List watched nicks that are online +/WATCH L - List watched nicks, online and offline +/WATCH C - Clear all watched nicks +/WATCH S - Show statistics +/WATCH +<nick> - Add a nick +/WATCH -<nick> - Remove a nick + +This command accepts multiple nicks like so: +/WATCH +<nick> -<nick> +<nick> +"> + +<helptopic key="monitor" title="/MONITOR C|L|S|(+|-) <nick>[,<nick>]+" value=" +/MONITOR L - List all monitored nicks, not differentiating between + online and offline nicks +/MONITOR C - Clear all monitored nicks +/MONITOR S - List all monitored nicks, indicating which are online + and which are offline +/MONITOR + <nick> - Add a nick +/MONITOR - <nick> - Remove a nick + +This command accepts multiple nicks like so: +/MONITOR + <nick>,<nick>,<nick> +/MONITOR - <nick>,<nick>,<nick> +"> + +<helptopic key="vhost" title="/VHOST <username> <password>" value=" +Authenticate for a vhost using the specified username and password. +"> + +<helptopic key="remove" title="/REMOVE <channel> <nick> [:<reason>]" value=" +Removes a user from a channel you specify. You must be at least a +channel halfoperator to remove a user. A removed user will part with +a message stating they were removed from the channel and by whom. +"> + +<helptopic key="rmode" title="/RMODE <channel> <mode> [<pattern>]" value=" +Removes list and prefix modes from the specified channel. If a pattern is +specified then all modes matching the specified pattern will be removed. If +removing a list mode and the pattern is the nick of an online user then all +modes in the list matching the specified user will be removed. +"> + +<helptopic key="hexip" title="/HEXIP <hex-ip|raw-ip>" value=" +If the specified argument is a raw IP address then respond with the +hex encoded equivalent as if sent by a username gateway. Otherwise, if +the specified argument is a hex encoded IP address then respond with +the equivalent raw IP address. +"> + +<helptopic key="silence" title="/SILENCE [(+|-)<mask> [CcdiHNnPpTtx]]" value=" +A server-side ignore of the given n!u@h mask. If the optional flags field is +specified then it must contain one or more flags which specify what kind of +messages should be blocked and how they should be blocked. + +/SILENCE - Shows a list of silenced masks +/SILENCE +<mask> [<flags>] - Add a mask +/SILENCE -<mask> - Remove a mask + +Valid SILENCE Flags +------------------- + C Matches a CTCP targeted at a user. + c Matches a CTCP targeted at a channel. + d Default behaviour; equivalent to CciNnPpTt. + H Hide the contents of messages instead of blocking. + i Matches an invite to a channel. + N Matches a NOTICE targeted at a user. + n Matches a NOTICE targeted at a channel. + P Matches a PRIVMSG targeted at a user. + p Matches a PRIVMSG targeted at a channel. + T Matches a TAGMSG targeted at a user. + t Matches a TAGMSG targeted at a channel. + x Exempt the mask from silence rules. + +Any combination of flags is valid. +"> + +<helptopic key="knock" title="/KNOCK <channel> :<reason>" value=" +Sends a notice to a channel indicating you wish to join. +"> + +<helptopic key="user" title="/USER <username> <unused> <unused> :<realname>" value=" +This command is used by your client to register your +IRC session, providing your username and real name to +the server. + +You should not use it during an established connection. +"> + +<helptopic key="nick" title="/NICK <newnick>" value=" +Change your nickname to <newnick>. +"> + +<helptopic key="quit" title="/QUIT [:<message>]" value=" +Quit from IRC and end your current session. +"> + +<helptopic key="version" title="/VERSION [<servername>]" value=" +Returns the server's version information. +"> + +<helptopic key="ping" title="/PING <cookie> [<servername>]" value=" +Ping a server. The server will answer with a PONG. +"> + +<helptopic key="pong" title="/PONG <cookie> [<servername>]" value=" +Your client should send this to answer server PINGs. You +should not issue this command manually. +"> + +<helptopic key="prop" title="/PROP <target> [(+|-)<name> [<value>]]+" value=" +Allows users to add, remove, and view the modes of a specific target. +"> + +<helptopic key="admin" title="/ADMIN [<servername>]" value=" +Shows the administrative information for the given server. +"> + +<helptopic key="privmsg" title="/PRIVMSG <target>[,<target>]+ :<message>" value=" +Sends a message to a user or channel specified in <target>. +"> + +<helptopic key="notice" title="/NOTICE <target>[,<target>]+ :<message>" value=" +Sends a notice to a user or channel specified in <target>. +"> + +<helptopic key="join" title="/JOIN <channel>[,<channel>]+ [<key>[,<key>]+]" value=" +Joins one or more channels you provide the names for. +"> + +<helptopic key="names" title="/NAMES [<channel>[,<channel>]+]" value=" +Return a list of users on the channel(s) you provide. +"> + +<helptopic key="part" title="/PART <channel>[,<channel>]+ [:<reason>]" value=" +Leaves one or more channels you specify. +"> + +<helptopic key="kick" title="/KICK <channel> <nick>[,<nick>]+ [:<reason>]" value=" +Kicks a user from a channel you specify. You must be +at least a channel halfoperator to kick a user. +"> + +<helptopic key="mode" title="/MODE <target> [[(+|-)]<modes> [<mode-parameters>]]" value=" +Change or view modes of <target>. + +/MODE <target> - Show modes of <target>. + +/MODE <channel> <list mode char> - List bans, exceptions, etc. set on <channel>. + +Sets the mode for a channel or a nickname specified in <target>. +A user may only set modes upon themselves, and may not set the ++o user mode, and a user may only change channel modes of +channels where they are at least a halfoperator. + +For a list of all user and channel modes, enter /HELP UMODES or /HELP CHMODES. +"> + +<helptopic key="topic" title="/TOPIC <channel> [:<topic>]" value=" +Sets or retrieves the channel topic. If a channel topic is +given in the command and either the channel is not +t, or +you are at least a halfoperator, the channel topic will be +changed to the new one you provide. +"> + +<helptopic key="who" title="/WHO <pattern> [<flags>][%[<fields>[,<querytype>]]] <pattern>" value=" +Looks up information about users matching the provided pattern. You can specify +a flag specific pattern, a channel name, user hostname, a user server name, a +user real name, or a user nickname. Matching users will only be included in the +WHO response if: + + 1) The specified pattern is an exact channel name that does not have the + private or secret channel modes set and the user does not have the invisible + user mode set. + 2) The specified pattern is an exact nickname. + 3) You share one or more common channels with the user. + 4) The user does not have the invisible user mode set. + 5) You are a server operator with the users/auspex privilege. + +If you specify any fields the response returned will be a WHOX response rather +than a RFC 1459 WHO response. + +Valid WHO Flags +--------------- + +The following flags use <pattern> to match against the specified user data: + + A Show users who have an away message matching <pattern>. + a Show users who have an account name matching <pattern>. + G Show users who are connecting from a country code matching <pattern>. + Requires the geoban module. + h Show users who have a hostname matching <pattern>. If the 'x' modifier + is specified then this will match against the real hostname instead of + the display hostname. + i Show users who have an IP address matching <pattern>. + m Show users who have the modes listed in <pattern>. The pattern + should be in the same format as a mode change e.g. +ow-i (server + operators only). + n Show users who have a nickname matching <pattern>. + p Show users who are connected to a port in the <pattern> range (server + operators only). + r Show users who have a real name matching <pattern>. + s Show users who are on a server with a name matching <pattern>. If the 'x' + modifier is specified then this will match against the real server name + instead of the masked server name. + t Show users who have connected in the last <pattern> seconds. + u Show users who have a username matching <pattern>. + +The following flags filter users by their status: + + f Only show users on remote (far) servers. + l Only show users on the local server. + o Only show server operators. + +The following flags modify the command output: + + x Show sensitive data like real user hostnames and, when hideserver is + enabled, real server hostnames. + +You may combine one flag from the first group and multiple from the others in +one WHO command. + +Valid WHO Fields +---------------- + + a Include the user's account name in the response. + c Include the first common channel name in the response. + d Include the user's server distance from you in the response. + f Include the user's away status, oper status, and highest channel prefix + in the response. + h Include the user's hostname in the response. If the 'x' flag was + specified then this is the real host rather than the display host. + i Include the user's IP address in the response. + l Include the user's idle time in the response. + n Include the user's nickname in the response. + o Include the user's channel operator rank level in the response. + r Include the user's real name in the response. + s Include the user's server name in the response. If the 'x' flag was + specified then this is the real server name rather than the masked server + name. + t Include the query type in the response. + u Include the user's username in the response. + + +"> + +<helptopic key="motd" title="/MOTD [<servername>]" value=" +Show the message of the day for <server>. Messages of the day often +contain important server rules and notices and should be read prior +to using a server. +"> + +<helptopic key="oper" title="/OPER <username> [<password>]" value=" +Attempts to authenticate as a server operator. + +Both successful and unsuccessful oper attempts are +logged, and sent to online server operators. +"> + +<helptopic key="list" title="/LIST [<pattern>]" value=" +Creates a list of all existing channels matching the glob pattern +<pattern>, e.g. *chat* or bot*. +"> + +<helptopic key="lusers" title="/LUSERS" value=" +Shows a count of local and remote users, servers and channels. +"> + +<helptopic key="userhost" title="/USERHOST <nick> [<nick>]+" value=" +Returns the hostname and nickname of a user, and some other +miscellaneous information. +"> + +<helptopic key="away" title="/AWAY [:<message>]" value=" +If a message is given, marks you as being away, otherwise +removes your away status and previous message. +"> + +<helptopic key="ison" title="/ISON <nick> [<nick>]+" value=" +Returns a subset of the nicks you give, showing only those +that are currently online. +"> + +<helptopic key="invite" title="/INVITE [<nick> <channel> [<time>]]" value=" +Invites a user to a channel. If the channel is NOT +A, only +channel halfoperators or above can invite people. If +A is set, +anyone can invite people to the channel, as long as the person +doing the invite is a member of the channel they wish to invite +the user to. + +Invited users may override bans, +k, and similar in addition to ++i, depending on configuration. + +If a time is provided, the invite expires after that time and the user +can no longer use it to enter the channel. The time can be specified +in the form of 1y2w3d4h5m6s - meaning one year, two weeks, three days, +four hours, five minutes and six seconds. All fields in this format +are optional. Alternatively, the time may just be specified as a number +of seconds. + +/INVITE without a parameter will list pending invitations for channels +you have been invited to. +"> + +<helptopic key="pass" title="/PASS <password>" value=" +This command is used by your client when setting up +your IRC session to submit a server password to the +server. + +You should not use it during an established connection. +"> + +<helptopic key="whowas" title="/WHOWAS <nick> [<count>]" value=" +Returns a list of times the user was seen recently on IRC along with +the time they were last seen and their server. + +If <count> is given, only return the <count> most recent entries. +"> + +<helptopic key="links" title="/LINKS" value=" +Shows all linked servers. +"> + +<helptopic key="map" title="/MAP" value=" +Shows a graphical representation of all users and servers on the +network, and the links between them, as a tree from the perspective +of your server. +"> + +<helptopic key="whois" title="/WHOIS [<servername>] <nick>[,<nick>]+" value=" +Returns the WHOIS information of a user, their channels, hostname, +etc. If a servername is provided, then a whois is performed from +the server where the user is actually located rather than locally, +showing idle and signon times. +"> + +<helptopic key="time" title="/TIME [<servername>]" value=" +Returns the local time of the server, or remote time of another +server. +"> + +<helptopic key="info" title="/INFO [<servername>]" value=" +Returns information on the developers and supporters who made this +IRC server possible. +"> + +<helptopic key="setname" title="/SETNAME :<realname>" value=" +Sets your real name to the specified real name. +"> + + +<helptopic key="coper" title="Oper Commands" value=" +ALLTIME CBAN CHECK CHGHOST CHGIDENT +CHGNAME CLEARCHAN CLOAK CONNECT DIE +ELINE FILTER GLINE GLOADMODULE GLOBOPS +GRELOADMODULE GUNLOADMODULE KILL KLINE LOADMODULE +NICKLOCK NICKUNLOCK OJOIN OPERMOTD QLINE +RCONNECT REHASH RELOADMODULE RESTART RLINE +RSQUIT SAJOIN SAKICK SAMODE SANICK +SAPART SAQUIT SATOPIC SETHOST SETIDENT +SETIDLE SHUN SQUIT SWHOIS TLINE +UNLOADMODULE WALLOPS ZLINE +"> + +<helptopic key="tline" title="/TLINE <mask>" value=" +This command returns the number of local and global clients matched, +and the percentage of clients matched, plus how they were matched +(by IP address or by hostname). Mask should be given as either +nick!user@host or user@IP (wildcards and CIDR blocks are accepted). +"> + +<helptopic key="filter" title="/FILTER <pattern> [<action> <flags> [<duration>] :<reason>]" value=" +This command will add a global filter when more than one parameter is +given, for messages of the types specified by the flags, with the given +filter pattern, action, duration (when the action is 'gline', 'zline' +or 'shun'), and reason. + +The filter will take effect when a message of any type specified by +the flags and matching the pattern is sent to the server, and +perform the specified action. + +Valid FILTER Actions +-------------------- + +None Does nothing +Warn Lets the message through and informs +s server operators + of the message and all relevant info +Block Blocks message and informs +s server operators of the blocked + message and all relevant info +Silent Blocks message, but does not notify server operators +Kill Kills the user +Gline G-lines the user for the specified duration +Zline Z-lines the user for the specified duration +Shun Shuns the user for the specified duration (requires the shun module) + +Valid FILTER Flags +------------------ + +p Block private and channel messages +n Block private and channel notices +P Block part messages +q Block quit messages +o Don't match against opers +r Don't match against registered users +c Strip all formatting codes from the message before matching +* Represents all of the above flags except r +- Does nothing, a non-op for when you do not want to specify any + flags + +The reason for the filter will be used as the reason for the action, +unless the action is 'none', and is sent to the user when their text is +blocked by 'block' and 'silent' actions. + +A G-line, Z-line or shun duration may be specified in seconds, or in the +format 1y2w3d4h5m6s - meaning one year, two weeks, three days, 4 hours, 5 +minutes and 6 seconds. All fields in this format are optional. + +When only one parameter is provided (the filter pattern) the provided +filter will be removed. Note that if you remove a +configuration-defined filter, it will reappear at next rehash unless +it is also removed from the config file. +"> + +<helptopic key="ojoin" title="/OJOIN <channel>" value=" +Force joins you to the specified channel, and gives you +Y and any other +configuration-defined modes on it, preventing you from being kicked. +Depending on configuration, may announce that you have joined the +channel on official network business. +"> + +<helptopic key="check" title="/CHECK <nick>|<ipmask>|<hostmask>|<channel> [<servername>]" value=" +Allows opers to look up advanced information on nicknames, IP addresses, +hostmasks or channels, in a similar way to WHO but in more detail, +displaying most information the server has stored on the target, +including all metadata. + +With the second parameter given, runs the command remotely on the +specified server, useful especially if used on a nickname that is +online on a remote server. +"> + +<helptopic key="alltime" title="/ALLTIME" value=" +Shows the date and time of all servers on the network. +"> + +<helptopic key="rconnect" title="/RCONNECT <remote-server-mask> <target-server-mask>" value=" +The server matching <remote-server-mask> will try to connect to the first +server in the config file matching <target-server-mask>. +"> + +<helptopic key="rsquit" title="/RSQUIT <target-server-mask> [:<reason>]" value=" +Causes a remote server matching <target-server-mask> to be disconnected from +the network. +"> + +<helptopic key="globops" title="/GLOBOPS :<message>" value=" +Sends a message to all users with the +g snomask. +"> + +<helptopic key="cban" title="/CBAN <channelmask> [<duration> [:<reason>]]" value=" +Sets or removes a global channel based ban. You must specify all three parameters +to add a ban, and one parameter to remove a ban (just the channelmask). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="sajoin" title="/SAJOIN [<nick>] <channel>[,<channel>]+" value=" +Forces the user to join the channel(s). +If no nick is given, it joins the oper doing the /SAJOIN. +"> + +<helptopic key="sapart" title="/SAPART <nick> <channel>[,<channel>]+ [:<reason>]" value=" +Forces the user to part the channel(s), with an optional reason. +"> + +<helptopic key="samode" title="/SAMODE <target> (+|-)<modes> [<mode-parameters>]" value=" +Applies the given mode change to the channel or nick specified. +"> + +<helptopic key="sanick" title="/SANICK <nick> <newnick>" value=" +Changes the user's nick to the new nick. +"> + +<helptopic key="sakick" title="/SAKICK <channel> <nick> [:<reason>]" value=" +Kicks the given user from the specified channel, with an optional reason. +"> + +<helptopic key="satopic" title="/SATOPIC <channel> :<topic>" value=" +Applies the given topic to the specified channel. +"> + +<helptopic key="saquit" title="/SAQUIT <nick> :<reason>" value=" +Forces user to quit with the specified reason. +"> + +<helptopic key="setidle" title="/SETIDLE <duration>" value=" +Sets your idle time to the specified value. + +The time can be specified in the form of 1y2w3d4h5m6s - meaning one year, +two weeks, three days, four hours, five minutes and six seconds. +All fields in this format are optional. Alternatively, the time may +just be specified as a number of seconds. +"> + +<helptopic key="sethost" title="/SETHOST <host>" value=" +Sets your host to the specified host. +"> + +<helptopic key="setident" title="/SETIDENT <username>" value=" +Sets your username to the specified value. +"> + +<helptopic key="swhois" title="/SWHOIS <nick> :<swhois>" value=" +Sets the user's swhois field to the given swhois message. +This will be visible in their /WHOIS. + +To remove this message again, use: +/SWHOIS <nick> : +"> + +<helptopic key="mkpasswd" title="/MKPASSWD <hashtype> <plaintext>" value=" +Encodes the plaintext to a hash of the given type and displays +the result. +"> + +<helptopic key="opermotd" title="/OPERMOTD [<servername>]" value=" +Displays the Oper MOTD. +"> + +<helptopic key="nicklock" title="/NICKLOCK <nick> <newnick>" value=" +Changes the user's nick to the new nick, and forces +it to remain as such for the remainder of the session. +"> + +<helptopic key="nickunlock" title="/NICKUNLOCK <nick>" value=" +Allows a previously locked user to change nicks again. +"> + +<helptopic key="chghost" title="/CHGHOST <nick> <host>" value=" +Changes the host of the user to the specified host. +"> + +<helptopic key="chgname" title="/CHGNAME <nick> :<realname>" value=" +Changes the real name of the user to the specified real name. +"> + +<helptopic key="chgident" title="/CHGIDENT <nick> <username>" value=" +Changes the username of the user to the specified value. +"> + +<helptopic key="shun" title="/SHUN <nick!user@host>[,<nick!user@host>]+ [<duration> :<reason>]" value=" +Sets or removes a shun (global server-side ignore) on a nick!user@host mask. +You must specify all three parameters to add a shun, and one parameter +to remove a shun (just the nick!user@host). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="die" title="/DIE <servername>" value=" +This command shuts down the local server. A single parameter is +required, which must match the name of the local server. +"> + +<helptopic key="restart" title="/RESTART <servername>" value=" +This command restarts the local server. A single parameter is +required, which must match the name of the local server. +"> + +<helptopic key="commands" title="/COMMANDS" value=" +Shows all currently available commands. +"> + +<helptopic key="kill" title="/KILL <nick>[,<nick>]+ :<reason>" value=" +This command will disconnect a user from IRC with the given reason. +"> + +<helptopic key="rehash" title="/REHASH [<servermask>]" value=" +This command will cause the server configuration file to be reread and +values reinitialized for all servers matching the server mask, or the +local server if one is not specified. +"> + +<helptopic key="connect" title="/CONNECT <servermask>" value=" +Add a connection to the server matching the given server mask. You must +have configured the server for linking in your configuration file +before trying to link them. +"> + +<helptopic key="squit" title="/SQUIT <servermask>" value=" +Disconnects the server matching the given server mask from this server. +"> + +<helptopic key="modules" title="/MODULES [<servername>]" value=" +Lists currently loaded modules, their memory offsets, version numbers, +and flags. If you are not an operator, you will see reduced detail. +"> + +<helptopic key="loadmodule" title="/LOADMODULE <modulename>" value=" +Loads the specified module into the local server. +"> + +<helptopic key="unloadmodule" title="/UNLOADMODULE <modulename>" value=" +Unloads a module from the local server. +"> + +<helptopic key="reloadmodule" title="/RELOADMODULE <modulename>" value=" +Unloads and reloads a module on the local server. +"> + +<helptopic key="gloadmodule" title="/GLOADMODULE <modulename> [<servermask>]" value=" +Loads the specified module on all linked servers. +"> + +<helptopic key="gunloadmodule" title="/GUNLOADMODULE <modulename> [<servermask>]" value=" +Unloads a module from all linked servers. +"> + +<helptopic key="greloadmodule" title="/GRELOADMODULE <modulename> [<servermask>]" value=" +Unloads and reloads a module on all linked servers. +"> + +<helptopic key="kline" title="/KLINE <user@host>[,<user@host>]+ [<duration> :<reason>]" value=" +Sets or removes a K-line (local user@host based ban) on a user@host mask. +You must specify all three parameters to add a ban, and one parameter +to remove a ban (just the user@host). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="zline" title="/ZLINE <ipmask>[,<ipmask>]+ [<duration> :<reason>]" value=" +Sets or removes a Z-line (global IP based ban) on an IP mask. +You must specify all three parameters to add a ban, and one parameter +to remove a ban (just the ipmask). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="qline" title="/QLINE <nickmask>[,<nickmask>]+ [<duration> :<reason>]" value=" +Sets or removes a Q-line (global nick based ban) on a nick mask. +You must specify all three parameters to add a ban, and one parameter +to remove a ban (just the nickmask). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="gline" title="/GLINE <user@host>[,<user@host>]+ [<duration> :<reason>]" value=" +Sets or removes a G-line (global user@host based ban) on a user@host mask. +You must specify all three parameters to add a ban, and one +parameter to remove a ban (just the user@host). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="eline" title="/ELINE <user@host>[,<user@host>]+ [<duration> :<reason>]" value=" +Sets or removes a E-line (global user@host ban exception) on a user@host mask. +You must specify at least 3 parameters to add an exception, and one +parameter to remove an exception (just the user@host). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. + +This command has a few important limitations. Bans on *@<ip> can only +be negated by an E-line on *@<ip>, bans on *@<host> can be negated by +E-lines on *@<ip>, or *@<host>, and bans on <user>@* or <user>@<host> +can be negated by any E-line that matches. +"> + +<helptopic key="wallops" title="/WALLOPS :<message>" value=" +Sends a message to all +w users. +"> + +<helptopic key="rline" title="/RLINE <regex> [<duration> :<reason>]" value=" +Sets or removes an R-line (global regex ban) on a n!u@h\srealname mask. You +must specify all three parameters to add an R-line, and one parameter +to remove an R-line (just the regex). + +The duration may be specified in seconds, or in the format +1y2w3d4h5m6s - meaning one year, two weeks, three days, four hours, +five minutes and six seconds. All fields in this format are optional. +"> + +<helptopic key="clearchan" title="/CLEARCHAN <channel> [KILL|KICK|G|Z] [:<reason>]" value=" +Quits or kicks all non-opers from a channel, optionally G/Z-lines them. +Useful for quickly nuking bot channels. + +The default method, KILL, simply disconnects the victims from the server, +while methods G and Z also add G/Z-lines for all the targets. + +When used, the victims won't see each other getting kicked or quitting. +"> + +<helptopic key="cloak" title="/CLOAK <host>" value=" +Generate the cloak of a host or IP. This is useful for example when +trying to get the cloak of a user from /WHOWAS and they were not +using their cloak when they quit. +"> + +<helptopic key="umodes" title="User Modes" value=" + c Blocks private messages and notices from users who do + not share a common channel with you (requires the + commonchans module). + d Deaf mode. User will not receive any messages or notices + from channels they are in (requires the deaf module). + g In combination with /ACCEPT, provides for server-side + ignore (requires the callerid module). + h Marks as 'available for help' in WHOIS (server operators + only, requires the helpmsg module). + i Makes invisible to /WHO if the user using /WHO is not in + a common channel. + k Prevents the user from being kicked from channels, or + having op modes removed from them (services only, + requires the services module). + o Marks as a server operator. + s <mask> Receives server notices specified by <mask> + (server operators only). + r Marks as a having a registered nickname + (requires the account module). + w Receives wallops messages. + x Gives a cloaked hostname (requires the cloak module). + z Only allow private messages from TLS users (requires + the sslmodes module). + B Marks as a bot (requires the botmode module). + D Privdeaf mode. User will not receive any private messages + or notices from users (requires the deaf module). + H Hides an oper's oper status from WHOIS (requires the + hideoper module). + I Hides a user's entire channel list in WHOIS from + non-server operators (requires the hidechans module). + L Stops redirections done by the redirect module (requires + the redirect module). + N Allows users to opt-out of receiving channel history + (requires the chanhistory module). + O Allows server operators to opt-in to overriding + restrictions (requires the override module). + R Blocks private messages from unregistered users + (requires the account module). + S Strips formatting codes out of private messages + to the user (requires the stripcolor module). + W Receives notifications when a user uses WHOIS on them + (server operators only, requires the showwhois module). +"> + +<helptopic key="chmodes" title="Channel Modes" value=" + v <nickname> Gives voice to <nickname>, allowing them to speak + while the channel is +m. + h <nickname> Gives halfop status to <nickname> (requires the + customprefix module). + o <nickname> Gives op status to <nickname>. + a <nickname> Gives protected status to <nickname>, preventing + them from being kicked (+q only, requires the + customprefix module). + q <nickname> Gives owner status to <nickname>, preventing them + from being kicked (Services or +q only, requires + the customprefix module). + + b <hostmask> Bans <hostmask> from the channel. + e <hostmask> Excepts <hostmask> from bans (requires the + banexception module). + I <hostmask> Excepts <hostmask> from +i, allowing matching + users to join while the channel is invite-only + (requires the inviteexception module). + + c Blocks messages that contain formatting codes + (requires the blockcolor module). + d <time> Blocks messages to a channel from new users + until they have been in the channel for <time> + seconds (requires the delaymsg module). + f [*]<lines>:<sec> Kicks on text flood equal to or above the + specified rate. With *, the user is banned + (requires the messageflood module). + g <mask> Blocks messages matching the given glob mask + (requires the chanfilter module). + i Makes the channel invite-only. + Users can only join if an operator + uses /INVITE to invite them. + j <joins>:<sec> Limits joins to the specified rate (requires + the joinflood module). + k <key> Set the channel key (password) to <key>. + l <limit> Set the maximum allowed users to <limit>. + m Enable moderation. Only users with +v, +h, or +o + can speak. + n Blocks users who are not members of the channel + from messaging it. + p Hides the channel in /WHOIS from people who are not a member. + You probably want the s (secret) channel mode rather than this. + r Marks the channel as registered with Services + (requires the account module). + s Hides the channel in /WHOIS and /LIST from people who are not a member. + t Prevents users without +h or +o from changing the + topic. + u Makes the channel an auditorium; normal users only + see themselves or themselves and the operators, + while operators see all the users (requires the + auditorium module). + w <flag>:<banmask> Adds basic channel access controls of <flag> to + <banmask>, via the +w listmode. + For example, +w o:R:Brain will op anyone identified + to the account 'Brain' on join. + (requires the autoop module) + z Blocks non-TLS clients from joining the channel + (requires the sslmodes module). + + A Allows anyone to invite users to the channel + (normally only chanops can invite, requires + the allowinvite module). + B {ban|block|mute|kick|kickban}:<minlen>:<percent> + Blocks messages with too many capital letters, + as determined by the network configuration + (requires the anticaps module). + C Blocks any CTCPs to the channel (requires the + noctcp module). + D Delays join messages from users until they message + the channel (requires the delayjoin module). + E [~|*]<lines>:<sec>[:<difference>][:<backlog>] Allows blocking of + similar messages (requires the repeat module). + Kicks as default, blocks with ~ and bans with * + The last two parameters are optional. + F <changes>:<sec> Blocks nick changes when they equal or exceed the + specified rate (requires the nickflood module). + H <num>:<duration> Displays the last <num> lines of chat to joining + users. <duration> is the maximum time to keep + lines in the history buffer (requires the + chanhistory module). + J <seconds> Prevents rejoin after kick for the specified + number of seconds. This prevents auto-rejoin + (requires the kicknorejoin module). + K Blocks /KNOCK on the channel (requires the + knock module). + L <channel> If the channel reaches its limit set by +l, + redirect users to <channel> (requires the + redirect module). + M Blocks unregistered users from speaking (requires + the account module). + N Prevents users on the channel from changing nick + (requires the nonicks module). + O Channel is server operators only (can only be set + by server operators, requires the operchans module). + P Makes the channel permanent; Bans, invites, the + topic, modes, and such will not be lost when it + empties (can only be set by server operators, + requires the permchannels module). + Q Only services servers and their users can kick + (requires the nokicks module). + R Blocks unregistered users from joining (requires + the account module). + S Strips formatting codes from messages to the + channel (requires the stripcolor module). + T Blocks /NOTICEs to the channel from users who are + not at least halfop (requires the nonotice module). + X <type>:<status> Makes users of <status> or higher exempt to the + specified restriction <type>. For example: flood:h + (requires the exemptchanops module). + Possible restriction types to exempt with +X are: + + anticaps Channel mode +B + auditorium-see Permission required to see the full user list of + a +u channel (requires the auditorium module). + auditorium-vis Permission required to be visible in a +u channel + (requires the auditorium module). + blockcolor Channel mode +c + filter Channel mode +g + flood Channel mode +f + nickflood Channel mode +F + noctcp Channel mode +C + nonick Channel mode +N + nonotice Channel mode +T + regmoderated Channel mode +M + repeat Channel mode +E + stripcolor Channel mode +S + topiclock Channel mode +t + +NOTE: A large number of these modes are dependent upon server-side modules +being loaded by a server/network administrator. The actual modes available +on your network may be very different to this list. Please consult your +help channel if you have any questions. +"> + +<helptopic key="stats" title="/STATS <symbol> [<servername>]" value=" +Shows various server statistics. Depending on configuration, some +symbols may be only available to opers. + +Valid symbols are: + +e Show E-lines (global user@host ban exceptions) +g Show G-lines (global user@host bans) +k Show K-lines (local user@host bans) +q Show Q-lines (global nick bans) +R Show R-lines (global regular expression bans) +Z Show Z-lines (global IP mask bans) + +s Show filters (global) +C Show channel bans (global) +H Show shuns (global) + +c Show link blocks +d Show configured DNSBLs and related statistics +m Show command statistics, number of times commands have been used +o Show a list of all valid oper usernames and hostmasks +p Show open client ports, and the port type (tls, plaintext, etc) +u Show server uptime +z Show memory usage statistics +i Show connect class permissions +l Show all client connections with information (sendq, commands, bytes, time connected) +L Show all client connections with information and IP address +P Show online opers and their idle times +T Show bandwidth/socket statistics +U Show services servers +Y Show connection classes +O Show opertypes and the allowed user and channel modes it can set +E Show socket engine events +S Show currently held registered nicknames +G Show how many local users are connected from each country + +Note that all /STATS use is broadcast to online server operators. +"> + +<helptopic key="snomasks" title="Server Notice Masks" value=" + a Allows receipt of local announcement messages. + A Allows receipt of remote announcement messages. + c Allows receipt of local connect messages. + C Allows receipt of remote connect messages. + d Allows receipt of local DNSBL messages (requires the dnsbl module). + D Allows receipt of remote DNSBL messages (requires the dnsbl module). + f Allows receipt of local filter messages (requires the filter module). + F Allows receipt of remote filter messages (requires the filter module). + g Allows receipt of globops (requires the globops module). + j Allows receipt of channel creation notices (requires the chancreate module). + J Allows receipt of remote channel creation notices (requires the chancreate module). + k Allows receipt of local kill messages. + K Allows receipt of remote kill messages. + l Allows receipt of local linking related messages. + L Allows receipt of remote linking related messages. + n Allows receipt of local nickname changes (requires the seenicks module). + N Allows receipt of remote nickname changes (requires the seenicks modules). + o Allows receipt of oper-up, oper-down, and oper-failure messages. + O Allows receipt of remote oper-up, oper-down, and oper-failure messages. + q Allows receipt of local quit messages. + Q Allows receipt of remote quit messages. + t Allows receipt of attempts to use /STATS (local and remote). + v Allows receipt of oper override notices (requires the override module). + x Allows receipt of local X-line notices (G/Z/Q/K/E/R/SHUN/CBan). + X Allows receipt of remote X-line notices (G/Z/Q/K/E/R/SHUN/CBan). +"> + +<helptopic key="extbans" title="Extended Bans" value=" +Extbans are split into two types; matching extbans, which match on +users in additional ways, and acting extbans, which restrict users +in different ways to a standard ban. + +To use an extban, simply set +b <ban> or +e <ban> with it as the ban, +instead of a normal nick!user@host mask, to ban or exempt matching +users. Ban exceptions on acting extbans exempt that user from matching +an extban of that type, and from any channel mode corresponding to the +restriction. Matching extbans may also be used for invite exceptions by +setting +I <extban>. + +Matching extbans: + + a:<mask> Matches user with both a matching banmask and real name, + where <mask> is in the format nick!user@host+realname + (requires realnameban module). + j:<channel> Matches anyone in the given channel. Does not support + wildcards (requires the channelban module). + n:<class> Matches users in a matching connect class (requires + the classban module). + r:<realname> Matches users with a matching real name (requires the + realnameban module). + s:<server> Matches users on a matching server (requires the + serverban module). + z:<tlsfp> Matches users having the given TLS certificate + fingerprint (requires the sslmodes module). + w:<gateway> Matches users who are connecting via a WebIRC gateway that + matches <gateway>. + O:<opertype> Matches server operators of a matching type, mostly + useful as an invite exception (requires the + operchans module). + R:<account> Matches users logged into a matching account (requires + the account module). + U:<banmask> Matches unregistered users matching the given banmask. + (requires the account module). + +Acting extbans: + + c:<banmask> Blocks any messages that contain formatting codes from + matching users (requires the blockcolor module). + m:<banmask> Blocks messages from matching users (requires the muteban + module). Users with +v or above are not affected. + A:<banmask> Blocks invites by matching users even when +A is set + (requires the allowinvite module). + B:<banmask> Blocks all capital or nearly all capital messages from + matching users (requires the blockcaps module). + C:<banmask> Blocks CTCPs from matching users (requires the noctcp + module). + N:<banmask> Blocks nick changes from matching users (requires + the nonicks module). + Q:<banmask> Blocks kicks by matching users (requires the nokicks + module). + S:<banmask> Strips formatting codes from messages from matching + users (requires the stripcolor module). + T:<banmask> Blocks notices from matching users (requires the + nonotice module). + +A ban given to an Acting extban may either be a nick!user@host mask +(unless stated otherwise), matched against users as for a normal ban, +or a Matching extban. + +There is an additional special type of extended ban, a redirect ban: + + Redirect n!u@h#channel will redirect the banned user to #channel + when they try to join (requires the banredirect module). +"> diff --git a/ansible/roles/inspircd/templates/us.manero.org/help.txt b/ansible/roles/inspircd/templates/us.manero.org/help.txt new file mode 100644 index 0000000..1b31972 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/help.txt @@ -0,0 +1,20 @@ +Thanks for installing InspIRCd! + +In order to get your server running you need to create config files. Examples +can be found at `/usr/local/etc/inspircd/examples`. + +If you need any help with this then you can visit our support channel at +ircs://irc.teranova.net/inspircd, open a support discussion at +https://git.io/JIuYv, or refer to the the docs site: + + https://docs.inspircd.org/4/configuration + https://docs.inspircd.org/4/modules + +When you are done you can run the following command to start InspIRCd: + + /usr/local/bin/inspircd + +If you have installed from an official package you may need to prefix this +command with `sudo -g nobody -u nobody` to run as the correct group/user. + +You can also use one of the helper scripts in `/usr/local/libexec/inspircd`. diff --git a/ansible/roles/inspircd/templates/us.manero.org/inspircd.conf b/ansible/roles/inspircd/templates/us.manero.org/inspircd.conf new file mode 100644 index 0000000..03258a4 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/inspircd.conf @@ -0,0 +1,194 @@ +<define name="networkDomain" value="manero.org"> +<define name="networkName" value="ManeroNet"> +<define name="dir" value="/usr/local/etc/inspircd"> + +<server + name="us.&networkDomain;" + description="&networkName; IRC server" + network="&networkName;"> + +<admin + name="Graham McIntire" + description="Supreme Overlord" + nick="gmc" + email="graham@mcintire.me"> + +<bind + address="*" + port="6697" + type="Clients" + sslprofile="ssl" + defer="0" + free="no"> + +<include file="/usr/local/etc/inspircd/irccloud.conf"> + +<connect + name="main" + allow="*" + maxchans="100" + timeout="20" + pingfreq="2m" + hardsendq="1M" + softsendq="10240" + recvq="10K" + threshold="10" + commandrate="1000" + fakelag="yes" + localmax="3" + globalmax="3" + resolvehostnames="yes" + useident="no" + limit="5000" + modes="+cx"> + +<cidr + ipv4clone="32" + ipv6clone="128"> + +<include file="/usr/local/etc/inspircd/opers.conf"> +<files motd="/usr/local/etc/inspircd/motd.txt"> +<dns + timeout="5"> +<maxlist chan="*" limit="100"> +<options + prefixquit="Quit: " + suffixquit="" + prefixpart="&quot;" + suffixpart="&quot;" + syntaxhints="no" + cyclehostsfromuser="no" + announcets="yes" + allowmismatch="no" + defaultbind="auto" + maskinlist="yes" + maskintopic="yes" + pingwarning="15" + serverpingfreq="1m" + splitwhois="no" + defaultmodes="not" + xlinemessage="You're banned! Email irc@&networkDomain; with the ERROR line below for help." + xlinequit="%fulltype%: %reason%" + modesinlist="opers" + extbanformat="name" + exemptchanops="filter:o nickflood:o nonick:v regmoderated:o" + invitebypassmodes="yes" + nosnoticestack="no"> + +<performance + netbuffersize="10240" + somaxconn="128" + softlimit="12800" + clonesonconnect="yes" + timeskipwarn="2s" + quietbursts="yes"> + +<security + announceinvites="dynamic" + hideservices="no" + flatlinks="no" + hidekills="" + hideservicekills="yes" + hidesplits="no" + maxtargets="20" + customversion="" + restrictbannedusers="yes" + genericoper="no" + userstats="Pu"> + +<limits + maxaway="200" + maxchan="60" + maxhost="64" + maxuser="10" + maxkey="30" + maxkick="300" + maxmodes="20" + maxnick="30" + maxquit="300" + maxreal="130" + maxtopic="330"> + +<log method="file" +# level="normal" + level="debug" + type="* -USERINPUT -USEROUTPUT" + target="inspircd.log"> + +<whowas + groupsize="10" + maxgroups="10000" + maxkeep="7d" + nickupdate="yes"> + +<badhost host="root@*" reason="Don't IRC as root!"> +<badhost host="*@198.51.100.0/24" reason="This subnet is bad."> + +<badnick nick="ChanServ" reason="Reserved For Services"> +<badnick nick="NickServ" reason="Reserved For Services"> +<badnick nick="OperServ" reason="Reserved For Services"> +<badnick nick="MemoServ" reason="Reserved For Services"> + +<exception + host="*@serverop.com" + reason="Oper's hostname"> + +<insane + hostmasks="no" + ipmasks="no" + nickmasks="no" + trigger="95.5"> + +<sslprofile name="ssl" + provider="openssl" + ca="/usr/local/etc/inspircd/ca.pem" + certfile="/usr/local/etc/inspircd/fullchain.cer" + keyfile="/usr/local/etc/inspircd/us.manero.org.key" + tlsv12="yes"> + +<customprefix name="founder" + letter="q" + prefix="~" + rank="50000" + ranktoset="50000" + ranktounset="50000" + depriv="yes"> + +<customprefix name="admin" + letter="a" + prefix="&amp;" + rank="40000" + ranktoset="50000" + ranktounset="50000" + depriv="yes"> + +<customprefix name="halfop" + letter="h" + prefix="%" + rank="20000" + ranktoset="30000" + ranktounset="30000" + depriv="yes"> + +<cloak method="nickname" + case="preserve" + class="" + invalidchar="strip" + prefix="" + suffix=".manero.org"> + +<class name="bots" + commands="PRIVMSG NOTICE JOIN PART QUIT NICK MODE TOPIC KICK BAN UNBAN WHO WHOIS LIST NAMES" + usermodes="iws" + chanmodes="ntis" + privs="users/flood/no-throttle users/flood/increased-buffers"> + +<type name="BotOper" + classes="bots" + host="204.110.191.210" + maxchans="9999999"> + +<include file="/usr/local/etc/inspircd/modules.conf"> +<include file="/usr/local/etc/inspircd/services/atheme.conf"> +<include file="/usr/local/etc/inspircd/links.conf"> + diff --git a/ansible/roles/inspircd/templates/us.manero.org/irccloud.conf b/ansible/roles/inspircd/templates/us.manero.org/irccloud.conf new file mode 100644 index 0000000..9cc6470 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/irccloud.conf @@ -0,0 +1,30 @@ +# This file contains connect classes which are used by IRCCloud users. +# See https://www.irccloud.com for more information on IRCCloud and +# https://www.irccloud.com/networks for more information on supporting +# IRCCloud on your network. + +<connect name="IRCCloud" + parent="main" + globalmax="100" + localmax="100" + useconnectban="no" + useconnflood="no" + usednsbl="no"> + +<connect name="IRCCloud (IPv4)" + parent="IRCCloud" + allow="5.254.36.56/29 5.254.36.104/29" + uniqueusername="yes"> + +# This is not typically needed as each user has their own IPv6 but if you have +# <cidr:ipv6clone> set to a value lower than 128 you will need to enable it. +#<connect name="IRCCloud (IPv6)" +# parent="IRCCloud" +# allow="2a03:5180:f::/62 2a03:5180:f:4::/63 2a03:5180:f:6::/64"> + +# IRCCloud IPv4 users use a shared IPv4 address which means that some clients +# may have trouble banning them. To work around this you can use the cloak_user +# module to copy the user identifier from the username to the hostname. +#<cloak method="username" +# class="IRCCloud (IPv4),IRCCloud (IPv6)" +# suffix=".irccloud.com"> diff --git a/ansible/roles/inspircd/templates/us.manero.org/iso-8859-1.conf b/ansible/roles/inspircd/templates/us.manero.org/iso-8859-1.conf new file mode 100644 index 0000000..4dfd058 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/iso-8859-1.conf @@ -0,0 +1,42 @@ +# This file contains ISO 8859-1 codepage rules for use with the codepage module. + +<codepage name="iso-8859-1" charset="iso-8859-1"> + +<cpchars begin="192" end="214" front="yes"> # ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ +<cpchars begin="216" end="246" front="yes"> # ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö +<cpchars begin="248" end="255" front="yes"> # øùúûüýþÿ + +<cpcase lower="83" upper="223"> # ß => S +<cpcase lower="192" upper="224"> # à => À +<cpcase lower="193" upper="225"> # á => Á +<cpcase lower="194" upper="226"> # â => Â +<cpcase lower="195" upper="227"> # ã => Ã +<cpcase lower="196" upper="228"> # ä => Ä +<cpcase lower="197" upper="229"> # å => Å +<cpcase lower="198" upper="230"> # æ => Æ +<cpcase lower="199" upper="231"> # ç => Ç +<cpcase lower="200" upper="232"> # è => È +<cpcase lower="201" upper="233"> # é => É +<cpcase lower="202" upper="234"> # ê => Ê +<cpcase lower="203" upper="235"> # ë => Ë +<cpcase lower="204" upper="236"> # ì => Ì +<cpcase lower="205" upper="237"> # í => Í +<cpcase lower="206" upper="238"> # î => Î +<cpcase lower="207" upper="239"> # ï => Ï +<cpcase lower="208" upper="240"> # ð => Ð +<cpcase lower="209" upper="241"> # ñ => Ñ +<cpcase lower="210" upper="242"> # ò => Ò +<cpcase lower="211" upper="243"> # ó => Ó +<cpcase lower="212" upper="244"> # ô => Ô +<cpcase lower="213" upper="245"> # õ => Õ +<cpcase lower="214" upper="246"> # ö => Ö +<cpcase lower="216" upper="248"> # ø => Ø +<cpcase lower="217" upper="249"> # ù => Ù +<cpcase lower="218" upper="250"> # ú => Ú +<cpcase lower="219" upper="251"> # û => Û +<cpcase lower="220" upper="252"> # ü => Ü +<cpcase lower="221" upper="253"> # ý => Ý +<cpcase lower="222" upper="254"> # þ => Þ + +# Include the ASCII rules to avoid duplication. +<include file="&dir.example;/codepages/ascii.example.conf"> diff --git a/ansible/roles/inspircd/templates/us.manero.org/iso-8859-2.conf b/ansible/roles/inspircd/templates/us.manero.org/iso-8859-2.conf new file mode 100644 index 0000000..49b77cd --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/iso-8859-2.conf @@ -0,0 +1,60 @@ +# This file contains ISO 8859-2 codepage rules for use with the codepage module. + +<codepage name="iso-8859-2" charset="iso-8859-2"> + +<cpchars index="161" front="yes"> # Ą +<cpchars index="163" front="yes"> # Ł +<cpchars begin="165" end="166" front="yes"> # ĽŚ +<cpchars begin="169" end="172" front="yes"> # ŠŞŤŹ +<cpchars begin="174" end="175" front="yes"> # ŽŻ +<cpchars index="177" front="yes"> # ą +<cpchars index="179" front="yes"> # ł +<cpchars begin="181" end="182" front="yes"> # ľś +<cpchars begin="185" end="188" front="yes"> # šşťź +<cpchars begin="190" end="214" front="yes"> # žżŔÁÂĂÄĹĆÇČÉĘËĚÍÎĎĐŃŇÓÔŐÖ +<cpchars begin="216" end="246" front="yes"> # ŘŮÚŰÜÝŢßŕáâăäĺćçčéęëěíîďđńňóôőö +<cpchars begin="248" end="254" front="yes"> # řůúűüýţ + +<cpcase lower="177" upper="161"> # ą => Ą +<cpcase lower="179" upper="163"> # ł => Ł +<cpcase lower="181" upper="165"> # ľ => Ľ +<cpcase lower="182" upper="166"> # ś => Ś +<cpcase lower="185" upper="169"> # š => Š +<cpcase lower="186" upper="170"> # ş => Ş +<cpcase lower="187" upper="171"> # ť => Ť +<cpcase lower="188" upper="172"> # ź => Ź +<cpcase lower="190" upper="174"> # ž => Ž +<cpcase lower="191" upper="175"> # ż => Ż +<cpcase lower="224" upper="192"> # ŕ => Ŕ +<cpcase lower="225" upper="193"> # á => Á +<cpcase lower="226" upper="194"> # â => Â +<cpcase lower="227" upper="195"> # ă => Ă +<cpcase lower="228" upper="196"> # ä => Ä +<cpcase lower="229" upper="197"> # ĺ => Ĺ +<cpcase lower="230" upper="198"> # ć => Ć +<cpcase lower="231" upper="199"> # ç => Ç +<cpcase lower="232" upper="200"> # č => Č +<cpcase lower="233" upper="201"> # é => É +<cpcase lower="234" upper="202"> # ę => Ę +<cpcase lower="235" upper="203"> # ë => Ë +<cpcase lower="236" upper="204"> # ě => Ě +<cpcase lower="237" upper="205"> # í => Í +<cpcase lower="238" upper="206"> # î => Î +<cpcase lower="239" upper="207"> # ď => Ď +<cpcase lower="240" upper="208"> # đ => Đ +<cpcase lower="241" upper="209"> # ń => Ń +<cpcase lower="242" upper="210"> # ň => Ň +<cpcase lower="243" upper="211"> # ó => Ó +<cpcase lower="244" upper="212"> # ô => Ô +<cpcase lower="245" upper="213"> # ő => Ő +<cpcase lower="246" upper="214"> # ö => Ö +<cpcase lower="248" upper="216"> # ř => Ř +<cpcase lower="249" upper="217"> # ů => Ů +<cpcase lower="250" upper="218"> # ú => Ú +<cpcase lower="251" upper="219"> # ű => Ű +<cpcase lower="252" upper="220"> # ü => Ü +<cpcase lower="253" upper="221"> # ý => Ý +<cpcase lower="254" upper="222"> # ţ => Ţ + +# Include the ASCII rules to avoid duplication. +<include file="&dir.example;/codepages/ascii.example.conf"> diff --git a/ansible/roles/inspircd/templates/us.manero.org/links.conf b/ansible/roles/inspircd/templates/us.manero.org/links.conf new file mode 100644 index 0000000..271ca9d --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/links.conf @@ -0,0 +1,46 @@ +<bind address="" port="7000" type="servers"> +#<bind address="" port="7001" type="servers" ssl="ssl"> + +<bind + address="*" + port="7001" + type="servers" + sslprofile="ssl"> + +<link + name="ca.manero.org" + ipaddr="100.82.143.128" + port="7001" + allowmask="100.82.143.128/32" + timeout="1m" + sslprofile="ssl" + bind="" + statshidden="no" + hidden="no" + sendpass="{{ vault_inspircd_us_link_ca_sendpass }}" + recvpass="{{ vault_inspircd_us_link_ca_recvpass }}"> + +#<link +# name="irc.nsnw.ca" +# ipaddr="167.114.169.143" +# port="7001" +# allowmask="167.114.169.143/32" +# timeout="1m" +# ssl="gnutls" +# sslprofile="gnutls" +# bind="" +# statshidden="no" +# hidden="no" +# sendpass="B0PMmTpYr1sw7qAXhbeycKGBkV3vCKDeWCCbo0KPdwIB33p8LI7CJHJaWrt80H1" +# recvpass="sc6JcwWz7CWCMXmAMtQIpPITarLHgSUsiF12TvG9bNwtDc4GMZXruMZitlwGPmx"> + +<link + name="services.manero.org" + ipaddr="127.0.0.1" + port="7000" + allowmask="127.0.0.0/8" + sendpass="{{ vault_inspircd_us_link_services_sendpass }}" + recvpass="{{ vault_inspircd_us_link_services_recvpass }}"> + +<uline server="services.manero.org" silent="yes"> +#<autoconnect period="1m" server="ca.manero.org"> diff --git a/ansible/roles/inspircd/templates/us.manero.org/modules.conf b/ansible/roles/inspircd/templates/us.manero.org/modules.conf new file mode 100644 index 0000000..56b1232 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/modules.conf @@ -0,0 +1,94 @@ +<module name="alias"> +<module name="allowinvite"> +<module name="chancreate"> +<module name="check"> +<module name="chghost"> +<module name="chgident"> +<module name="chgname"> +<module name="cloak"> +<module name="cloak_user"> +#<include file="&dir;/codepages/ascii.conf"> +#<include file="&dir;/codepages/iso-8859-1.conf"> +#<include file="&dir;/codepages/iso-8859-2.conf"> +#<include file="&dir;/codepages/rfc1459.conf"> +#<include file="&dir;/codepages/strict-rfc1459.conf"> +<module name="customprefix"> +<module name="hidechans"> +<module name="ircv3"> +<module name="monitor"> +<module name="cap"> +<module name="ircv3_accounttag"> +<module name="ircv3_batch"> +<module name="ircv3_capnotify"> +<module name="ircv3_chghost"> +<module name="ircv3_ctctags"> +<module name="ircv3_echomessage"> +<module name="ircv3_invitenotify"> +<module name="ircv3_labeledresponse"> +<module name="ircv3_msgid"> +<module name="ircv3_sts"> +<sts host="us.manero.org" port="6697" duration="1d"> +<module name="ircv3_servertime"> +<module name="messageflood"> +<monitor maxentries="30"> +<module name="multiprefix"> +<module name="nokicks"> +<passforward + + # nick: The nick of the service to forward passwords to. + nick="NickServ" + + # forwardmsg: Message to send to users when forwarding their + # password. You can use the following variables in this message: + # + # %nick% The nickname of the authenticating user. + # %nickrequired% The nickname of the service to forward to (see above). + # %pass% The password to forward to services. + # %user% The username of the authenticating user. + forwardmsg="NOTICE %nick% :*** Forwarding password to %nickrequired%" + + # cmd: The message to send to forward passwords to services. + cmd="SQUERY %nickrequired% :IDENTIFY %nick% %pass%"> +<module name="sajoin"> +<module name="samode"> +<module name="sanick"> +<module name="satopic"> +<module name="services"> +<servicesintegration accountoverrideshold="yes" + disablemodes="no"> +<module name="sethost"> +<module name="setident"> +<module name="setidle"> +<module name="setname"> +<setname notifyopers="yes"> +<module name="sha1"> +<module name="sha2"> +<module name="showfile"> +<module name="showwhois"> +<showwhois opersonly="yes"> +<module name="shun"> +<module name="spanningtree"> +<include file="&dir;/links.conf"> +<module name="ssl_openssl"> +<module name="stripcolor"> +<module name="vhost"> +<module name="services_account"> +<module name="bcrypt"> +<bcrypt rounds="10"> +<module name="password_hash"> +<mkpasswd operonly="no"> +<module name="knock"> +<knock notify="notice"> +<module name="swhois"> +<module name="sakick"> +<module name="autoop"> +<module name="sslmodes"> +<module name="sslinfo"> +<module name="override"> +<module name="sasl"> +<sasl requiressl="no" + target="services.manero.org"> +<module name="customprefix"> +<module name="hideoper"> +<hideoper mode="yes"> + diff --git a/ansible/roles/inspircd/templates/us.manero.org/motd.txt b/ansible/roles/inspircd/templates/us.manero.org/motd.txt new file mode 100644 index 0000000..97ce8a6 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/motd.txt @@ -0,0 +1,27 @@ + + ____ + ! + ! ! + ! `- _ _ _ + | ``` ! +_____! * ! +\, \ + l _ ; + \ _/ \. / + \ .’ + . ./’ + `. , + \ ; + ``’ + +This server is hosted in Princeton, Texas by gmc + + +███╗ ███╗ █████╗ ███╗ ██╗███████╗██████╗ ██████╗ +████╗ ████║██╔══██╗████╗ ██║██╔════╝██╔══██╗██╔═══██╗ +██╔████╔██║███████║██╔██╗ ██║█████╗ ██████╔╝██║ ██║ +██║╚██╔╝██║██╔══██║██║╚██╗██║██╔══╝ ██╔══██╗██║ ██║ +██║ ╚═╝ ██║██║ ██║██║ ╚████║███████╗██║ ██║╚██████╔╝ +╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚══════╝╚═╝ ╚═╝ ╚═════╝ + +Welcome to the manero memorial irc network diff --git a/ansible/roles/inspircd/templates/us.manero.org/opermotd.txt b/ansible/roles/inspircd/templates/us.manero.org/opermotd.txt new file mode 100644 index 0000000..b9360dc --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/opermotd.txt @@ -0,0 +1,37 @@ + _____ _____ _____ _____ _ +|_ _| |_ _| | __ \ / ____| | | + | | _ __ ___ _ __ | | | |__) || | __| | + | | | '_ \ / __| | '_ \ | | | _ / | | / _` | + _| |_ | | | | \__ \ | |_) | _| |_ | | \ \ | |____ | (_| | +|_____| |_| |_| |___/ | .__/ |_____| |_| \_\ \_____| \__,_| + _____________________| |__________________________________ +|_____________________|_|__________________________________| + + \iThe IRC server for the 31st century\x + + /\ /\ + { `---' } \bWELCOME TO AN \c13I\c04N\c07S\c08P\c03I\c10R\c12C\c06D\c99 NETWORK\x + { O O } + ~~> V <~~ If you see this, I'm probably new. + \ \|/ / If I'm not new, my owner is lazy. ;-) + `-----'____ + / \ \_ + { }\ )_\_ _ + | \_/ |/ / \_\_/ ) + \__/ /(_/ \__/ + (__/ + + +-- To change this see \bopermotd.example.txt\x --+ + | | + | * \bWeb:\x https://www.inspircd.org | + | * \bIRC:\x ircs://irc.teranova.net/inspircd | + | * \bDocs:\x https://docs.inspircd.org | + | * \bIssues:\x https://git.io/JIuYi | + | * \bDiscussions:\x https://git.io/JIuYv | + | | + | We hope you like this software. Please do | + | make sure to customise your configuration, | + | though, so you love it. Enjoy. | + | | + | -- The InspIRCd Team | + +---------------------------------------------+ diff --git a/ansible/roles/inspircd/templates/us.manero.org/opers.conf b/ansible/roles/inspircd/templates/us.manero.org/opers.conf new file mode 100644 index 0000000..821895a --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/opers.conf @@ -0,0 +1,46 @@ +<class name="SACommands" commands="SAJOIN SAPART SANICK SAQUIT SATOPIC SAKICK SAMODE OJOIN"> +<class name="ServerLink" commands="CONNECT SQUIT RCONNECT RSQUIT MKPASSWD ALLTIME SWHOIS LOCKSERV UNLOCKSERV" usermodes="*" chanmodes="*" privs="servers/auspex" snomasks="Cc"> +<class name="BanControl" commands="KILL GLINE KLINE ZLINE QLINE ELINE TLINE RLINE CHECK NICKLOCK NICKUNLOCK SHUN CLONES CBAN" usermodes="*" chanmodes="*" snomasks="Xx"> +<class name="OperChat" commands="WALLOPS GLOBOPS" usermodes="*" chanmodes="*" privs="users/mass-message" snomasks="Gg"> +<class name="HostCloak" commands="SETHOST SETIDENT SETIDLE CHGNAME CHGHOST CHGIDENT" usermodes="*" chanmodes="*" privs="users/auspex"> +<class + name="Shutdown" + commands="DIE RESTART REHASH LOADMODULE UNLOADMODULE RELOADMODULE GLOADMODULE GUNLOADMODULE GRELOADMODULE" + privs="users/auspex channels/auspex servers/auspex users/mass-message users/flood/no-throttle users/flood/increased-buffers" + usermodes="*" + chanmodes="*" + snomasks="*"> + +<type + # name: Name of the type. Used in actual server operator accounts below. + name="NetAdmin" + + # classes: Classes (blocks above) that this type belongs to. + classes="SACommands OperChat BanControl HostCloak Shutdown ServerLink" # vhost: Host that opers of this type get when they log in (oper up). This is optional. + vhost="netadmin.manero.org" + + # maxchans: Maximum number of channels opers of this type can be in at once. + maxchans="60" + + # modes: User modes besides +o that are set on an oper of this type # when they oper up. Used for snomasks and other things. + # Requires the opermodes module to be loaded. + modes="+s +cCqQ"> + +<oper + name="gmc" + hash="bcrypt" + password="{{ vault_inspircd_us_oper_graham_password }}" + host="*@*" + sslonly="yes" + type="NetAdmin"> + +<oper + name="andys" + hash="bcrypt" + password="{{ vault_inspircd_us_oper_andys_password }}" + host="*@*" + sslonly="yes" + type="NetAdmin"> + + + diff --git a/ansible/roles/inspircd/templates/us.manero.org/quotes.txt b/ansible/roles/inspircd/templates/us.manero.org/quotes.txt new file mode 100644 index 0000000..18edecc --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/quotes.txt @@ -0,0 +1,203 @@ +Men are from Mars. Women are from Venus. Computers are from hell +Computer /nm./: a device designed to speed and automate errors +Hardware /nm./: the part of the computer that you can kick. +Maniac /n./ An early computer built by nuts. +RAM /abr./: Rarely Adequate Memory. +Programmer /n./ A red-eyed, mumbling mammal capable of conversing with inanimate objects +Multitasking /adj./ 3 PCs and a chair with wheels +Plonk /excl./: The sound a newbie makes as he falls to the bottom of a kill file +hURL /n./: a link to a web site that makes you want to puke +SUPERCOMPUTER: what it sounded like before you bought it. +If it's really a supercomputer, how come the bullets don't bounce off when I shoot it? . The Covert Comic. +A computer is like an Old Testament god, with a lot of rules and no mercy. . Joseph Campbell +I dropped my computer on my foot! That Megahurtz!! +A computer's attention span is as long as it's power cord +586: The average IQ needed to understand a PC +Memory is like an orgasm. It's a lot better if you don't have to fake it +If it jams, force it. If it breaks, it needed replacing anyway. +A bus station is where a bus stops. A train station is where a train stops. On my desk I have a workstation.. +Want to come see my HARD DRIVE ? I promise it isn't 3.5 inches and it ain't floppy. . Geek pick-up line. +If you torture the data enough, it will confess. . Ronald Coase +If you give someone a program, you will frustrate them for a day; if you teach them how to program, you will frustrate them for a lifetime +ASCII stupid question, get a stupid ANSI! +Use the source, Luke... +Programming is an art form that fights back +MacOS, Windows, BeOS: they're all just Xerox copies +Whenever you think you have a clever programming trick... forget it! +Managing senior programmers is like herding cats. . Dave Platt +Your program is sick ! Shoot it and put it out of its memory +/* You are not expected to understand this */ +To define recursion, we must first define recursion +ERROR: Computer possessed; Load EXOR.SYS ? [Y/N] +Linux is only free if your time is worthless +Linux: find out what you've been missing while you've been rebooting Windows NT +unzip; strip; touch; finger; mount; fsck; more; yes; unmount; sleep +Profanity is the one language all programmers know best +It's 5.50 a.m.... Do you know where your stack pointer is? +#define QUESTION ((bb) || !(bb)) . Shakespeare +The more I C, the less I see. +Confucius say: He who play in root, eventually kill tree. +Unix is the answer, but only if you phrase the question very carefully +C++: Hard to learn and built to stay that way +Java is, in many ways, C++-- . Michael Feldman. +They don't make bugs like Bunny anymore . Olav Mjelde +If debugging is the process of removing software bugs, then programming must be the process of putting them in +When the only tool you own is a hammer, every problem you encounter resembles a nail +System Error: press F13 to continue... +To err is human, but for a real disaster you need a computer +Computers make very fast, very accurate mistakes +Life would be so much easier if we only had the source code +Who is this 'General Failure' and why is he reading my disk? +hAS aNYONE sEEN MY cAPSLOCK kEY? +InspIRCd, now with excessive amounts of Cheeze +I'm in the computer business, I make Out-Of-Order signs +Kevorkian Virus: helps your computer shut down whenever it wants to. + [OUT OF QUOTES, PLEASE ORDER MORE] +Insert Something Funkeh.. err.. There! --> +Cannot delete tmp150---3.tmp: There is not enough free disk space. Delete one or more files to free disk space, and then try again +File not found. Should I fake it ? (Y/N) +The definition of an upgrade: Take old bugs out, put new ones in +If it's not on fire, it's a software problem +It's a little-known fact that the Y1K problem caused the Dark Ages +Artificial Intelligence usually beats natural stupidity +Making fun of AOL users is like making fun of the kid in the wheel chair +Daddy, why doesn't this magnet pick up this floppy disk? +Daddy, what does FORMATTING DRIVE C mean? +See daddy ? All the keys are in alphabetical order now. +Enter any 11-digit prime number to continue... +ASCII and ye shall receive. +The web is a dominatrix. Every where I turn, I see little buttons ordering me to Submit. +<FrostyCoolSlug> NO, You cannot dial 999, I'm downloading my mail ;/ +640K ought to be enough for anybody. . Bill Gates, 1981 +Windows not found, [P]arty, [C]elebrate, [D]rink? +English, the Microsoft of languages... +It's been said that Bill Gates named his company after his dick... +Ever notice how fast Windows runs ? -- Neither did I +If at first you don't succeed, work for Microsoft +We are Microsoft. Resistance Is Futile. You Will Be Assimilated +"Microsoft Works." . Oxymoron +Windows isn't a virus, viruses do something +PANIC! buffer = :NickServ WRITE_DB(3). <-- JUST KIDDING! +It just keeps going and going and going and going and goi <BANG> +All that I know is that nukes are coming from 127.0.0.1 +I know all about the irc and the mirc cops. +M re ink n ed d, ple s r fil +Please refrain from feeding the server operators. Thank you. +I know all about mirc stuff, hmm.. I think this channel is experiencing packet loss.. +MacDonalds claims Macintosh stole their next idea of the iMac +I can't hold her any longer, captain, she's gonna bl.. sorry, got caught up in the moment +I recommend purchasing a Cyrix CPU for testing nuclear meltdowns +Is it an international rule to have the worst picture possible on your driver license? +Have you hugged your services coder, today? +Ever wonder why they make the colon flash on alarm clocks? +Whats this?.. blue screen with a VXD error?!.. I'VE BEEN NUKED! +do-do-bop-doo-doo-do-do-doo.. For those of you who know that song, you have problems.. +be wery wery quiet... hunting wabbit... +I've been IRC Nuked"Great warrior? War does not make one great." - Yoda +"I find your lack of faith.....disturbing." - Darth Vader +"I have a bad feeling about this.."--All of the Star Wars characters. +Can I upgrade my Hard Drive to a WARP drive? +Canadian DOS prompt: EH?\> +Canadian DOS: "Yer sure, eh?" [y/n] +CONGRESS.SYS Corrupted: Re-boot Washington D.C (Y/n)? +I don't have a solution but I admire the problem. +Famous Last Words: Trust me. I know what I'm doing. +Hey Captain, I just created a black ho-p!%$ NO CARRIER +Access denied--nah nah na nah nah! +Bad command. Bad, bad command! Sit! Stay! Staaay.. +Error: Keyboard not attached. Press F1 to continue. +*grumble* "You're just supposed to sit here?" +"Hey, what's this button d..<BOOM>" -W. Crusher +"He has become One with Himself!" "He's passed out!" "That too."-B5 +For a funny quote, call back later. +Famous last words: 'You saw a WHAT around the corner?!' +I like work ... I can sit and watch it for hours. +Copywight 1994 Elmer Fudd. All wights wesewved. +Cannot find REALITY.SYS. Universe halted. +BUFFERS=20 FILES=15 2nd down, 4th quarter, 5 yards to go! +My software never has bugs. It just develops random features. +Why doesn't DOS ever say 'EXCELLENT command or filename!? +Shell to DOS... Come in DOS, do you copy? Shell to DOS... +Computing Definition - Network-Admin: Primary person who just got set up for the blame of the system crash. +An expert is a person who has made all the mistakes which can be made in a very narrow field. +Famous last words: This is the safe way to do it....... +Famous Last Words: Trust me. I know what I'm doing. +Clinton, "I didn't say that - er, well - yes, but I didn't mean..." +CLINTON LEGACY??...even Pharaoh had only ten plagues... +IBM I Bought McIntosh +IBM I Bring Manuals +IBM I've Been Moved +IBM Idolized By Management +IBM Impenetrable Brain Matter +IBM Imperialism By Marketing +IBM Incorrigible Boisterous Mammoth +IBM Inertia Breeds Mediocrity +IBM Ingenuity Becomes Mysterious +IBM Ingrained Batch Mentality +IBM Innovation By Management +IBM Insipid Belligerent Mossbacks +IBM Insipidly Bankrolling Millions +IBM Inspect Before Multiusing +IBM Install Bigger Memory +IBM Institution By Machiavelli +IBM Insultingly Boring Merchandisers +IBM Intellectuals Being Moronized +IBM Intelligence Belittling Meaning +IBM Intimidated, Buffaloed Management +IBM Into Building Money +IBM Intolerant of Beards & Moustaches +IBM Invest Before Multi-tasking +IBM Investigate Baffling Malodor +IBM Irresponsible Behave Multinational +IBM It Beats Mattel +IBM It's a Big Mess +IBM It's Better Manually +IBM Itty Bitty Machine +IBM Institute for Black Magic +100,000 lemmings can't be wrong. +Murphy's Eighth Law: If everything seems to be going well, you have obviously overlooked something. +Rules of the game: Do not believe in miracles - rely on them. +Rules of the game: Any given program, once running, is obsolete. +Computing Definition - Error: What someone else has made when they disagree with your computer output. +Backup not found: (A)bort (R)etry (P)anic +WinErr 653: Multitasking attempted - system confused. +Cannot join #real_life (invite only) +"Unfortunately, no one can be told what the Matrix is. You have to see it for yourself." - Matrix +"Reality is a thing of the past" - Matrix +"The future will not be user friendly" - Matrix +"The general idea in chat is to make yourself understandable... ..." - Peer +"heh i am talkin to someone...she's not dead...yet anyways" - Stinky +"He who must die, must die in the dark, even though he sells candles" +"If at first you don't succeed, skydiving is not for you." +"Friendship is like peeing on yourself: everyone can see it, but only you get the warm feeling that it brings." +"France sucks, but Paris swallows" +"A computer once beat me at chess, but it was no match for me at kick boxing. +"Ever wonder why the SAME PEOPLE make up ALL the conspiracy theories? +"Don't think of it as being outnumbered. Think of it as having a wide target selection." +"Sysadmins can't be sued for malpractice, but surgeons don't have to deal with patients who install new versions of their own innards." +"FACE!" +"Dirka Dirka Mohammed JIHAD!" +We can learn much from wise words, little from wisecracks, and less from wise guys. +"Blessed are the young, for they shall inherit the national debt." - Herbert Hoover +If you have five dollars and Chuck Norris has five dollars, Chuck Norris has more money than you. +Apple pays Chuck Norris 99 cents every time he listens to a song. +If Chuck Norris and InspIRCd met in a dark alley, Chuck Norris would get his first black eye. Ever. +Chuck Norris can sneeze with his eyes open. +Chuck Norris can kill two stones with one bird. +There is no theory of evolution. Just a list of animals Chuck Norris allows to live. +The Great Wall of China was originally created to keep Chuck Norris out. It failed miserably. +Chuck Norris can win a game of Connect Four in only three moves. +Chuck Norris is not hung like a horse... horses are hung like Chuck Norris. +Chuck Norris is currently suing NBC, claiming Law and Order are trademarked names for his left and right legs. +Chuck Norris CAN believe it's not butter. +Chuck Norris is so fast, he can run around the world and punch himself in the back of the head. +When the Boogeyman goes to sleep every night, he checks his closet for Chuck Norris. +Outer space exists because it's afraid to be on the same planet with Chuck Norris. +Chuck Norris counted to infinity - twice. +Chuck Norris only fears one thing in this world, and that is InspIRCd. +InspIRCd's core is ran by donated Chuck Norris DNA. +Chuck Norris exists because InspIRCd allows him to. +Chuck Norris CAN punch you in the face over the internet. +When Chuck Norris uses InspIRCd, he doesn't use the /kill command, he uses the /ROUND-HOUSE-TO-THE-FACE command. +A developer only classifies oneself as such if they consider themselves as such. +"While hunting in Africa, I shot an elephant in my pajamas. How an elephant got into my pajamas I'll never know." -- Groucho Marx diff --git a/ansible/roles/inspircd/templates/us.manero.org/services-atheme.conf b/ansible/roles/inspircd/templates/us.manero.org/services-atheme.conf new file mode 100644 index 0000000..fbf3e89 --- /dev/null +++ b/ansible/roles/inspircd/templates/us.manero.org/services-atheme.conf @@ -0,0 +1,50 @@ +# This file contains aliases and nickname reservations which are used +# by Atheme. See https://atheme.github.io/atheme.html for more +# information on Atheme. + +<include file="/usr/local/etc/inspircd/services/generic.conf"> + +# Long hand aliases for services pseudoclients. +<alias text="ALIS" replace="PRIVMSG $requirement :$2-" requires="ALIS" service="yes"> +<alias text="CHANFIX" replace="PRIVMSG $requirement :$2-" requires="ChanFix" service="yes"> +<alias text="GAMESERV" replace="PRIVMSG $requirement :$2-" requires="GameServ" service="yes"> +<alias text="GROUPSERV" replace="PRIVMSG $requirement :$2-" requires="GroupServ" service="yes"> +<alias text="HELPSERV" replace="PRIVMSG $requirement :$2-" requires="HelpServ" service="yes"> +<alias text="INFOSERV" replace="PRIVMSG $requirement :$2-" requires="InfoServ" service="yes"> +<alias text="PROXYSCAN" replace="PRIVMSG $requirement :$2-" requires="Proxyscan" service="yes" operonly="yes"> +<alias text="RPGSERV" replace="PRIVMSG $requirement :$2-" requires="RPGServ" service="yes"> + +# Short hand aliases for services pseudoclients. +<alias text="CF" replace="PRIVMSG $requirement :$2-" requires="ChanFix" service="yes"> +<alias text="GS" replace="PRIVMSG $requirement :$2-" requires="GroupServ" service="yes"> +<alias text="IS" replace="PRIVMSG $requirement :$2-" requires="InfoServ" service="yes"> +<alias text="LS" replace="PRIVMSG $requirement :$2-" requires="ALIS" service="yes"> +<alias text="PS" replace="PRIVMSG $requirement :$2-" requires="Proxyscan" service="yes" operonly="yes"> +<alias text="RS" replace="PRIVMSG $requirement :$2-" requires="RPGServ" service="yes"> + +# These short hand aliases conflict with other pseudoclients. You can enable +# them but you will need to comment out the uncommented ones above first, +#<alias text="GS" replace="PRIVMSG $requirement :$2-" requires="GameServ" service="yes"> +#<alias text="HS" replace="PRIVMSG $requirement :$2-" requires="HelpServ" service="yes"> + +# Prevent clients from using the nicknames of services pseudoclients. +<badnick nick="ALIS" reason="Reserved for a network service"> +<badnick nick="ChanFix" reason="Reserved for a network service"> +<badnick nick="GameServ" reason="Reserved for a network service"> +<badnick nick="GroupServ" reason="Reserved for a network service"> +<badnick nick="HelpServ" reason="Reserved for a network service"> +<badnick nick="InfoServ" reason="Reserved for a network service"> +<badnick nick="Proxyscan" reason="Reserved for a network service"> +<badnick nick="RPGServ" reason="Reserved for a network service"> +<badnick nick="SaslServ" reason="Reserved for a network service"> + +# Exempt services pseudoclients from filters. +<exemptfromfilter target="ALIS"> +<exemptfromfilter target="ChanFix"> +<exemptfromfilter target="GameServ"> +<exemptfromfilter target="GroupServ"> +<exemptfromfilter target="HelpServ"> +<exemptfromfilter target="InfoServ"> +<exemptfromfilter target="Proxyscan"> +<exemptfromfilter target="RPGServ"> +<exemptfromfilter target="SaslServ"> diff --git a/ansible/roles/netbox/tasks/main.yml b/ansible/roles/netbox/tasks/main.yml index 10e9be5..b774f9c 100644 --- a/ansible/roles/netbox/tasks/main.yml +++ b/ansible/roles/netbox/tasks/main.yml @@ -38,6 +38,15 @@ state: started enabled: true +- name: Stop netbox services before user/group changes + ansible.builtin.systemd: + name: "{{ item }}" + state: stopped + loop: + - netbox + - netbox-rq + failed_when: false + - name: Create netbox group ansible.builtin.group: name: "{{ netbox_group }}" diff --git a/ansible/roles/uisp/tasks/main.yml b/ansible/roles/uisp/tasks/main.yml index efe3b3a..2c5730e 100644 --- a/ansible/roles/uisp/tasks/main.yml +++ b/ansible/roles/uisp/tasks/main.yml @@ -103,6 +103,30 @@ group: root mode: '0700' +- name: Download UISP installer script + ansible.builtin.get_url: + url: https://getuisp.com/install.sh + dest: "{{ uisp_app_dir }}/update.sh" + owner: "{{ uisp_user }}" + group: root + mode: "0755" + register: uisp_installer + +- name: Check if UISP containers are already running + community.docker.docker_container_info: + name: unms-postgres + register: uisp_postgres_container + failed_when: false + +- name: Run UISP installer (first install only — skips existing) + ansible.builtin.command: "{{ uisp_app_dir }}/update.sh" + become: true + become_user: "{{ uisp_user }}" + when: + - not uisp_postgres_container.exists | default(false) + register: uisp_install + changed_when: uisp_install.rc == 0 + - name: Deploy UISP auto-update cron job ansible.builtin.copy: dest: /etc/cron.d/unms-update