redirect linux updates to fastly
[mirror/dsa-puppet.git] / modules / roles / templates / security_mirror / security.debian.org.erb
index 5299f36..d4be2a4 100644 (file)
@@ -8,6 +8,7 @@
    Options +FollowSymLinks
    Options +Indexes
    FileETag MTime Size
+   Require all granted
 </Directory>
 
 <VirtualHost *:80>
    ServerAlias security-cdn1.debian.org
    ServerAlias security-cdn2.debian.org
    ServerAlias security-nagios.debian.org
+   <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+   ServerAlias <%= scope.function_onion_global_service_hostname(['security.debian.org']) %>
+   <% end %>
+
 
    ExpiresActive On
    ExpiresDefault "access plus 2 minutes"
 
    Alias /debian-security /srv/ftp.root/debian-security
-
-   <Directory /srv/ftp.root/debian-security/pool>
-      <FilesMatch "\.(bz2|gz|deb|dsc|xz)$">
-         ExpiresDefault "access plus 1 month"
-         Header append Cache-Control "public"
-      </FilesMatch>
-   </Directory>
-
-   <Directory /srv/ftp.root/debian-security/dists>
-      ExpiresDefault "access plus 1 seconds"
-      Header append Cache-Control "public"
-   </Directory>
+   Use ftp-archive /srv/ftp.root/debian-security
 
    RewriteEngine on
    RewriteRule ^/$      http://www.debian.org/security/
 
+   RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+   RewriteRule ^/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
+   RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+   RewriteRule ^/debian-security/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
+
    # Possible values include: debug, info, notice, warn, error, crit,
    # alert, emerg.
    LogLevel warn