010-security.debian.org.conf: explicitly bind to localhost
[mirror/dsa-puppet.git] / modules / roles / templates / security_mirror / security.debian.org.erb
index 5294a1f..9177327 100644 (file)
@@ -3,19 +3,9 @@
 ## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git
 ##
 
-<Directory /srv/ftp.root/debian-security>
-   IndexOptions NameWidth=* +SuppressDescription
-   Options +FollowSymLinks
-   Options +Indexes
-   FileETag MTime Size
-   <% if @lsbmajdistrelease > '7' -%>
-     Require all granted
-   <% end -%>
-</Directory>
-
-<VirtualHost *:80>
+<VirtualHost *:80 127.0.0.1:80 [::1]:80>
    ServerAdmin debian-admin@debian.org
-   DocumentRoot /srv/ftp.root/debian-security
+   DocumentRoot /srv/mirrors/debian-security
    ServerPath /debian-security
    ServerName security.debian.org
    ServerAlias security.ipv6.debian.org
    ServerAlias security-cdn1.debian.org
    ServerAlias security-cdn2.debian.org
    ServerAlias security-nagios.debian.org
+   <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+   ServerAlias <%= scope.function_onion_global_service_hostname(['security.debian.org']) %>
+   <% end %>
+   ServerAlias security.backend.mirrors.debian.org
+   ServerAlias *.security.backend.mirrors.debian.org
+   ServerAlias security.anycast-test.mirrors.debian.org
+
 
    ExpiresActive On
    ExpiresDefault "access plus 2 minutes"
 
-   Alias /debian-security /srv/ftp.root/debian-security
-   Use ftp-archive /srv/ftp.root/debian-security
-
-   RewriteEngine on
-   RewriteRule ^/$      http://www.debian.org/security/
+   Alias /debian-security /srv/mirrors/debian-security
+   Use ftp-archive /srv/mirrors/debian-security
 
-   # Possible values include: debug, info, notice, warn, error, crit,
-   # alert, emerg.
-   LogLevel warn
+   Alias /_health /run/dsa-mirror-health-security/health
+   <Directory /run/dsa-mirror-health-security/>
+      Require all granted
+   </Directory>
 
-   CustomLog /var/log/apache2/security.debian.org-access.log privacy
+   RewriteEngine on
+   RewriteRule ^/$      https://www.debian.org/security/
+
+   RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+   RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront"
+   RewriteCond %{HTTP_USER_AGENT} "!check_http"
+   RewriteCond %{HTTP_USER_AGENT} "!dsa-check-mirrorsync"
+   RewriteCond %{HTTP_USER_AGENT} "!mirror-health"
+   <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+   RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>"
+   <% end %>
+   RewriteCond %{REQUEST_URI} "!=/_health"
+   RewriteRule ^/(.*) http://security-cdn.debian.org/$1 [L,R=302]
+
+   CustomLog /var/log/apache2/security.debian.org-access.log combined
    ServerSignature On
 </VirtualHost>
 
-# vim: set ts=3 sw=3 et:
+# vim:set syn=apache: