7fc00c568a79f4e80192c02c07551bd2e362d00c
[mirror/dsa-puppet.git] / modules / buildd / manifests / init.pp
1 class buildd ($ensure=present) {
2         # Do nothing until we get the buildd user from ldap
3         if $::buildd_user_exists {
4                 include schroot
5
6                 package { 'sbuild':
7                         ensure => installed,
8                         tag    => extra_repo,
9                 }
10                 package { 'libsbuild-perl':
11                         ensure => installed,
12                         tag    => extra_repo,
13                         before => Package['sbuild']
14                 }
15
16                 if $ensure == present {
17                         package { 'dupload':
18                                 ensure => installed,
19                         }
20                         file { '/etc/dupload.conf':
21                                 source  => 'puppet:///modules/buildd/dupload.conf',
22                                 require => Package['dupload'],
23                         }
24                         package { 'buildd':
25                                 ensure => installed,
26                         }
27                         file { '/etc/buildd/buildd.conf':
28                                 source  => 'puppet:///modules/buildd/buildd.conf',
29                                 require => Package['buildd'],
30                         }
31                         file { '/etc/sbuild/sbuild.conf':
32                                 source  => 'puppet:///modules/buildd/sbuild.conf',
33                                 require => Package['sbuild'],
34                         }
35                         include ferm::ftp_conntrack
36                 }
37
38                 if (versioncmp($::lsbmajdistrelease, '9') >= 0) {
39                         site::aptrepo { 'buildd.debian.org':
40                                 ensure => absent,
41                         }
42                         file { '/etc/apt/apt.conf.d/puppet-https-buildd':
43                                 ensure => absent,
44                         }
45                 } else {
46                         site::aptrepo { 'buildd.debian.org':
47                                 key        => 'puppet:///modules/buildd/buildd.debian.org.gpg',
48                                 url        => 'https://apt.buildd.debian.org/',
49                                 suite      => 'jessie',
50                                 components => 'main',
51                                 require    => Package['apt-transport-https'],
52                         }
53                         file { '/etc/apt/apt.conf.d/puppet-https-buildd':
54                                 content => "Acquire::https::apt.buildd.debian.org::CaInfo \"/etc/ssl/ca-debian/ca-certificates.crt\";\n",
55                         }
56                 }
57
58                 file { '/etc/cron.d/dsa-buildd': ensure => absent, }
59                 concat::fragment { 'dsa-puppet-stuff--buildd':
60                         target => '/etc/cron.d/dsa-puppet-stuff',
61                         source  => 'puppet:///modules/buildd/cron.d-dsa-buildd',
62                         require => Package['debian.org']
63                 }
64
65                 package { 'python-psutil':
66                         ensure => installed,
67                 }
68                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
69                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill',
70                         mode    => '0555',
71                 }
72
73                 file { '/etc/cron.d/puppet-buildd-aptitude': ensure => absent }
74                 concat::fragment { 'dsa-puppet-stuff--buildd-aptitude-killer':
75                         target => '/etc/cron.d/dsa-puppet-stuff',
76                         content  => @(EOF)
77                                 */5 * * * * root /usr/local/sbin/buildd-schroot-aptitude-kill
78                                 | EOF
79                 }
80
81                 service { 'buildd':
82                         enable => false,
83                         ensure => 'stopped',
84                 }
85
86                 file { '/etc/cron.d/puppet-update-buildd-schroots': ensure => absent }
87                 if $has_srv_buildd {
88                         concat::fragment { 'dsa-puppet-stuff--buildd-update-schroots':
89                                 target => '/etc/cron.d/dsa-puppet-stuff',
90                                 content  => @(EOF)
91                                         13 22 * * 0,3 root PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin setup-all-dchroots buildd
92                                         | EOF
93                         }
94                 }
95
96                 file { '/home/buildd':
97                         ensure  => directory,
98                         mode    => '2755',
99                         group   => buildd,
100                         owner   => buildd,
101                 }
102                 file { '/home/buildd/build':
103                         ensure  => directory,
104                         mode    => '2750',
105                         group   => buildd,
106                         owner   => buildd,
107                 }
108                 file { '/home/buildd/logs':
109                         ensure  => directory,
110                         mode    => '2750',
111                         group   => buildd,
112                         owner   => buildd,
113                 }
114                 file { '/home/buildd/old-logs':
115                         ensure  => directory,
116                         mode    => '2750',
117                         group   => buildd,
118                         owner   => buildd,
119                 }
120                 file { '/home/buildd/upload-security':
121                         ensure  => directory,
122                         mode    => '2750',
123                         group   => buildd,
124                         owner   => buildd,
125                 }
126                 file { '/home/buildd/stats':
127                         ensure  => directory,
128                         mode    => '2755',
129                         group   => buildd,
130                         owner   => buildd,
131                 }
132                 file { '/home/buildd/stats/graphs':
133                         ensure  => directory,
134                         mode    => '2755',
135                         group   => buildd,
136                         owner   => buildd,
137                 }
138                 file { '/home/buildd/upload':
139                         ensure  => directory,
140                         mode    => '2755',
141                         group   => buildd,
142                         owner   => buildd,
143                 }
144                 file { '/home/buildd/.forward':
145                         content  => "|/usr/bin/buildd-mail\n",
146                         group   => buildd,
147                         owner   => buildd,
148                 }
149                 file { '/home/buildd/.gnupg':
150                         ensure  => directory,
151                         mode    => '700',
152                         group   => buildd,
153                         owner   => buildd,
154                 }
155                 file { '/home/buildd/.gnupg/gpg.conf':
156                         content  => "personal-digest-preferences SHA512\n",
157                         group   => buildd,
158                         owner   => buildd,
159                 }
160
161                 file { '/home/buildd/.profile':
162                         content  => @(EOT),
163                                 export XDG_RUNTIME_DIR="/run/user/$(id -u)"
164                                 export DBUS_SESSION_BUS_ADDRESS="unix:path=${XDG_RUNTIME_DIR}/bus"
165                                 | EOT
166                         group   => buildd,
167                         owner   => buildd,
168                 }
169
170                 if ! $::buildd_key {
171                         exec { 'create-buildd-key':
172                                 command => '/bin/su - buildd -c \'mkdir -p -m 02700 .ssh && ssh-keygen -C "`whoami`@`hostname` (`date +%Y-%m-%d`)" -P "" -f .ssh/id_rsa -q\'',
173                                 onlyif  => '/usr/bin/getent passwd buildd > /dev/null && ! [ -e /home/buildd/.ssh/id_rsa ]'
174                         }
175                 }
176
177
178                 exec { 'add-buildd-user-to-sbuild':
179                         command => 'adduser buildd sbuild',
180                         onlyif  => "getent group sbuild > /dev/null && ! getent group sbuild | grep '\\<buildd\\>' > /dev/null"
181                 }
182
183                 # Enable lingering for pybuildd
184                 file { '/var/lib/systemd/linger':
185                         ensure  => directory,
186                         mode    => '755',
187                 }
188                 file { "/var/lib/systemd/linger/buildd":
189                         ensure => present,
190                 }
191
192                 # And persistent journald storage
193                 exec {'mkdir -p /etc/systemd/journald.conf.d':
194                         unless => 'test -d /etc/systemd/journald.conf.d',
195                 }
196                 file { '/etc/systemd/journald.conf.d/persistency.conf':
197                         source => 'puppet:///modules/systemd/persistency.conf',
198                 }
199         }
200 }