For review - what do we think? Maybe a bit more intrusive than we wanted.
To be thrashed out:
(1) must eliminate wildcard aliases for everything that needs a cert
(2) somewhat more radical .conf file changes (see _common.conf)
(3) the grants navs' confs files
(4) move 'servername', 'serveralias' and 'https' definitions to pillar (possibly refactor pillars to make subdomain definition more consistent), note that we can't test real targets on tmp2 without doing this and setting up proper dns subdomains like tmp2.grantnav.threesixtygiving.org
For review - what do we think? Maybe a bit more intrusive than we wanted. To be thrashed out: (1) must eliminate wildcard aliases for everything that needs a cert (2) somewhat more radical .conf file changes (see _common.conf) (3) the grants navs' confs files (4) move 'servername', 'serveralias' and 'https' definitions to pillar (possibly refactor pillars to make subdomain definition more consistent), note that we can't test real targets on tmp2 without doing this and setting up proper dns subdomains like tmp2.grantnav.threesixtygiving.org