205730ba64b3e71be6a78d7bec77abf136a7a5cf
[mirror/dsa-puppet.git] / modules / buildd / manifests / init.pp
1 class buildd ($ensure=present) {
2         # Do nothing until we get the buildd user from ldap
3         if $::buildd_user_exists {
4                 include schroot
5
6                 package { 'sbuild':
7                         ensure => installed,
8                         tag    => extra_repo,
9                 }
10                 package { 'libsbuild-perl':
11                         ensure => installed,
12                         tag    => extra_repo,
13                         before => Package['sbuild']
14                 }
15
16                 package { 'apt-transport-https':
17                         ensure => installed,
18                 }
19                 if $ensure == present {
20                         package { 'dupload':
21                                 ensure => installed,
22                         }
23                         file { '/etc/dupload.conf':
24                                 source  => 'puppet:///modules/buildd/dupload.conf',
25                                 require => Package['dupload'],
26                         }
27                         package { 'buildd':
28                                 ensure => installed,
29                         }
30                         file { '/etc/buildd/buildd.conf':
31                                 source  => 'puppet:///modules/buildd/buildd.conf',
32                                 require => Package['buildd'],
33                         }
34                         if ($::lsbmajdistrelease >= 8) {
35                                 file { '/etc/sbuild/sbuild.conf':
36                                         source  => 'puppet:///modules/buildd/sbuild.conf',
37                                         require => Package['sbuild'],
38                                 }
39                         } else {
40                                 file { '/etc/sbuild/sbuild.conf':
41                                         source  => 'puppet:///modules/buildd/sbuild.conf.wheezy',
42                                         require => Package['sbuild'],
43                                 }
44                         }
45                         include ferm::ftp_conntrack
46                 }
47
48                 site::aptrepo { 'buildd':
49                         ensure => absent,
50                 }
51
52                 $suite = $::lsbdistcodename ? {
53                         wheezy   => $::lsbdistcodename,
54                         jessie   => $::lsbdistcodename,
55                         stretch  => $::lsbdistcodename,
56                         undef   => 'wheezy',
57                         default => 'jessie'
58                 }
59
60                 site::aptrepo { 'buildd.debian.org':
61                         key        => 'puppet:///modules/buildd/buildd.debian.org.gpg',
62                         url        => 'https://apt.buildd.debian.org/',
63                         suite      => $suite,
64                         components => 'main',
65                         require    => Package['apt-transport-https'],
66                 }
67
68                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
69                         content => "Acquire::https::apt.buildd.debian.org::CaInfo \"/etc/ssl/ca-debian/ca-certificates.crt\";\n",
70                 }
71
72                 # 'bad' extension
73                 file { '/etc/apt/preferences.d/buildd.debian.org':
74                         ensure => absent,
75                 }
76                 file { '/etc/apt/preferences.d/buildd':
77                         ensure => absent,
78                 }
79                 file { '/etc/cron.d/dsa-buildd':
80                         source  => 'puppet:///modules/buildd/cron.d-dsa-buildd',
81                         require => Package['debian.org']
82                 }
83
84                 if ($::kernel == 'Linux') {
85                         package { 'python-psutil':
86                                 ensure => installed,
87                         }
88                         if ($::lsbmajdistrelease >= 8) {
89                                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
90                                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill',
91                                         mode    => '0555',
92                                 }
93                         } else {
94                                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
95                                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.wheezy',
96                                         mode    => '0555',
97                                 }
98                         }
99                 } else {
100                         file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
101                                 source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.squeeze',
102                                 mode    => '0555',
103                         }
104                 }
105                 file { '/etc/cron.d/puppet-buildd-aptitude':
106                         content => "*/5 * * * * root /usr/local/sbin/buildd-schroot-aptitude-kill\n",
107                 }
108
109                 service { 'buildd':
110                         enable => false,
111                         ensure => 'stopped',
112                 }
113
114                 if $has_srv_buildd {
115                         file { '/etc/cron.d/puppet-update-buildd-schroots':
116                                 content  => "13 21 * * 0,3 root PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin setup-all-dchroots buildd\n",
117                         }
118                 }
119
120                 file { '/home/buildd':
121                         ensure  => directory,
122                         mode    => '2755',
123                         group   => buildd,
124                         owner   => buildd,
125                 }
126                 file { '/home/buildd/build':
127                         ensure  => directory,
128                         mode    => '2750',
129                         group   => buildd,
130                         owner   => buildd,
131                 }
132                 file { '/home/buildd/logs':
133                         ensure  => directory,
134                         mode    => '2750',
135                         group   => buildd,
136                         owner   => buildd,
137                 }
138                 file { '/home/buildd/old-logs':
139                         ensure  => directory,
140                         mode    => '2750',
141                         group   => buildd,
142                         owner   => buildd,
143                 }
144                 file { '/home/buildd/upload-security':
145                         ensure  => directory,
146                         mode    => '2750',
147                         group   => buildd,
148                         owner   => buildd,
149                 }
150                 file { '/home/buildd/stats':
151                         ensure  => directory,
152                         mode    => '2755',
153                         group   => buildd,
154                         owner   => buildd,
155                 }
156                 file { '/home/buildd/stats/graphs':
157                         ensure  => directory,
158                         mode    => '2755',
159                         group   => buildd,
160                         owner   => buildd,
161                 }
162                 file { '/home/buildd/upload':
163                         ensure  => directory,
164                         mode    => '2755',
165                         group   => buildd,
166                         owner   => buildd,
167                 }
168                 file { '/home/buildd/.forward':
169                         content  => "|/usr/bin/buildd-mail\n",
170                         group   => buildd,
171                         owner   => buildd,
172                 }
173                 file { '/home/buildd/.gnupg':
174                         ensure  => directory,
175                         mode    => '700',
176                         group   => buildd,
177                         owner   => buildd,
178                 }
179                 file { '/home/buildd/.gnupg/gpg.conf':
180                         content  => "personal-digest-preferences SHA512\n",
181                         group   => buildd,
182                         owner   => buildd,
183                 }
184
185                 if ! $::buildd_key {
186                         exec { 'create-buildd-key':
187                                 command => '/bin/su - buildd -c \'mkdir -p -m 02700 .ssh && ssh-keygen -C "`whoami`@`hostname` (`date +%Y-%m-%d`)" -P "" -f .ssh/id_rsa -q\'',
188                                 onlyif  => '/usr/bin/getent passwd buildd > /dev/null && ! [ -e /home/buildd/.ssh/id_rsa ]'
189                         }
190                 }
191
192
193                 exec { 'add-buildd-user-to-sbuild':
194                         command => 'adduser buildd sbuild',
195                         onlyif  => "getent group sbuild > /dev/null && ! getent group sbuild | grep '\\<buildd\\>' > /dev/null"
196                 }
197         }
198 }