4b8e397bd5a939200567ffa007875d9b98344148
[mirror/dsa-puppet.git] / modules / buildd / manifests / init.pp
1 class buildd ($ensure=present) {
2         # Do nothing until we get the buildd user from ldap
3         if $::buildd_user_exists {
4                 include schroot
5
6                 package { 'sbuild':
7                         ensure => installed,
8                         tag    => extra_repo,
9                 }
10                 package { 'libsbuild-perl':
11                         ensure => installed,
12                         tag    => extra_repo,
13                         before => Package['sbuild']
14                 }
15
16                 package { 'apt-transport-https':
17                         ensure => installed,
18                 }
19                 if $ensure == present {
20                         package { 'dupload':
21                                 ensure => installed,
22                         }
23                         file { '/etc/dupload.conf':
24                                 source  => 'puppet:///modules/buildd/dupload.conf',
25                                 require => Package['dupload'],
26                         }
27                         package { 'buildd':
28                                 ensure => installed,
29                         }
30                         file { '/etc/buildd/buildd.conf':
31                                 source  => 'puppet:///modules/buildd/buildd.conf',
32                                 require => Package['buildd'],
33                         }
34                         file { '/etc/sbuild/sbuild.conf':
35                                 source  => 'puppet:///modules/buildd/sbuild.conf',
36                                 require => Package['sbuild'],
37                         }
38                         include ferm::ftp_conntrack
39                 }
40
41                 site::aptrepo { 'buildd':
42                         ensure => absent,
43                 }
44
45                 $suite = $::lsbdistcodename ? {
46                         wheezy   => $::lsbdistcodename,
47                         jessie   => $::lsbdistcodename,
48                         stretch  => $::lsbdistcodename,
49                         undef   => 'wheezy',
50                         default => 'jessie'
51                 }
52
53                 if (versioncmp($::lsbmajdistrelease, '9') >= 0) {
54                         site::aptrepo { 'buildd.debian.org':
55                                 ensure => absent,
56                         }
57                 } else {
58                         site::aptrepo { 'buildd.debian.org':
59                                 key        => 'puppet:///modules/buildd/buildd.debian.org.gpg',
60                                 url        => 'https://apt.buildd.debian.org/',
61                                 suite      => $suite,
62                                 components => 'main',
63                                 require    => Package['apt-transport-https'],
64                         }
65                 }
66
67                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
68                         content => "Acquire::https::apt.buildd.debian.org::CaInfo \"/etc/ssl/ca-debian/ca-certificates.crt\";\n",
69                 }
70
71                 # 'bad' extension
72                 file { '/etc/apt/preferences.d/buildd.debian.org':
73                         ensure => absent,
74                 }
75                 file { '/etc/apt/preferences.d/buildd':
76                         ensure => absent,
77                 }
78                 file { '/etc/cron.d/dsa-buildd': ensure => absent, }
79                 concat::fragment { 'dsa-puppet-stuff--buildd':
80                         target => '/etc/cron.d/dsa-puppet-stuff',
81                         source  => 'puppet:///modules/buildd/cron.d-dsa-buildd',
82                         require => Package['debian.org']
83                 }
84
85                 package { 'python-psutil':
86                         ensure => installed,
87                 }
88                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
89                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill',
90                         mode    => '0555',
91                 }
92
93                 file { '/etc/cron.d/puppet-buildd-aptitude': ensure => absent }
94                 concat::fragment { 'dsa-puppet-stuff--buildd-aptitude-killer':
95                         target => '/etc/cron.d/dsa-puppet-stuff',
96                         content  => @(EOF)
97                                 */5 * * * * root /usr/local/sbin/buildd-schroot-aptitude-kill
98                                 | EOF
99                 }
100
101                 service { 'buildd':
102                         enable => false,
103                         ensure => 'stopped',
104                 }
105
106                 file { '/etc/cron.d/puppet-update-buildd-schroots': ensure => absent }
107                 if $has_srv_buildd {
108                         concat::fragment { 'dsa-puppet-stuff--buildd-update-schroots':
109                                 target => '/etc/cron.d/dsa-puppet-stuff',
110                                 content  => @(EOF)
111                                         13 22 * * 0,3 root PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin setup-all-dchroots buildd
112                                         | EOF
113                         }
114                 }
115
116                 file { '/home/buildd':
117                         ensure  => directory,
118                         mode    => '2755',
119                         group   => buildd,
120                         owner   => buildd,
121                 }
122                 file { '/home/buildd/build':
123                         ensure  => directory,
124                         mode    => '2750',
125                         group   => buildd,
126                         owner   => buildd,
127                 }
128                 file { '/home/buildd/logs':
129                         ensure  => directory,
130                         mode    => '2750',
131                         group   => buildd,
132                         owner   => buildd,
133                 }
134                 file { '/home/buildd/old-logs':
135                         ensure  => directory,
136                         mode    => '2750',
137                         group   => buildd,
138                         owner   => buildd,
139                 }
140                 file { '/home/buildd/upload-security':
141                         ensure  => directory,
142                         mode    => '2750',
143                         group   => buildd,
144                         owner   => buildd,
145                 }
146                 file { '/home/buildd/stats':
147                         ensure  => directory,
148                         mode    => '2755',
149                         group   => buildd,
150                         owner   => buildd,
151                 }
152                 file { '/home/buildd/stats/graphs':
153                         ensure  => directory,
154                         mode    => '2755',
155                         group   => buildd,
156                         owner   => buildd,
157                 }
158                 file { '/home/buildd/upload':
159                         ensure  => directory,
160                         mode    => '2755',
161                         group   => buildd,
162                         owner   => buildd,
163                 }
164                 file { '/home/buildd/.forward':
165                         content  => "|/usr/bin/buildd-mail\n",
166                         group   => buildd,
167                         owner   => buildd,
168                 }
169                 file { '/home/buildd/.gnupg':
170                         ensure  => directory,
171                         mode    => '700',
172                         group   => buildd,
173                         owner   => buildd,
174                 }
175                 file { '/home/buildd/.gnupg/gpg.conf':
176                         content  => "personal-digest-preferences SHA512\n",
177                         group   => buildd,
178                         owner   => buildd,
179                 }
180
181                 file { '/home/buildd/.profile':
182                         content  => @(EOT),
183                                 export XDG_RUNTIME_DIR="/run/user/$(id -u)"
184                                 export DBUS_SESSION_BUS_ADDRESS="unix:path=${XDG_RUNTIME_DIR}/bus"
185                                 | EOT
186                         group   => buildd,
187                         owner   => buildd,
188                 }
189
190                 if ! $::buildd_key {
191                         exec { 'create-buildd-key':
192                                 command => '/bin/su - buildd -c \'mkdir -p -m 02700 .ssh && ssh-keygen -C "`whoami`@`hostname` (`date +%Y-%m-%d`)" -P "" -f .ssh/id_rsa -q\'',
193                                 onlyif  => '/usr/bin/getent passwd buildd > /dev/null && ! [ -e /home/buildd/.ssh/id_rsa ]'
194                         }
195                 }
196
197
198                 exec { 'add-buildd-user-to-sbuild':
199                         command => 'adduser buildd sbuild',
200                         onlyif  => "getent group sbuild > /dev/null && ! getent group sbuild | grep '\\<buildd\\>' > /dev/null"
201                 }
202
203                 # Enable lingering for pybuildd
204                 file { '/var/lib/systemd/linger':
205                         ensure  => directory,
206                         mode    => '755',
207                 }
208                 file { "/var/lib/systemd/linger/buildd":
209                         ensure => present,
210                 }
211
212                 # And persistent journald storage
213                 exec {'mkdir -p /etc/systemd/journald.conf.d':
214                         unless => 'test -d /etc/systemd/journald.conf.d',
215                 }
216                 file { '/etc/systemd/journald.conf.d/persistency.conf':
217                         source => 'puppet:///modules/systemd/persistency.conf',
218                 }
219         }
220 }