X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Froles%2Ftemplates%2Fsecurity_mirror%2Fsecurity.debian.org.erb;h=80b6ee68ffabc2439395dcd07e02065fa770dd92;hb=2bcc93461324af3441263c3a21189664ee8b7446;hp=ee839cd3d538bc525a390073674bedbd6035848a;hpb=7d296b65a7dd50c5701b7e6a3acbbfbdc968615a;p=mirror%2Fdsa-puppet.git diff --git a/modules/roles/templates/security_mirror/security.debian.org.erb b/modules/roles/templates/security_mirror/security.debian.org.erb index ee839cd3d..80b6ee68f 100644 --- a/modules/roles/templates/security_mirror/security.debian.org.erb +++ b/modules/roles/templates/security_mirror/security.debian.org.erb @@ -5,7 +5,7 @@ ServerAdmin debian-admin@debian.org - DocumentRoot /srv/ftp.root/debian-security + DocumentRoot /srv/mirrors/debian-security ServerPath /debian-security ServerName security.debian.org ServerAlias security.ipv6.debian.org @@ -28,26 +28,28 @@ ExpiresActive On ExpiresDefault "access plus 2 minutes" - Alias /debian-security /srv/ftp.root/debian-security - Use ftp-archive /srv/ftp.root/debian-security + Alias /debian-security /srv/mirrors/debian-security + Use ftp-archive /srv/mirrors/debian-security + + Alias /_health /run/dsa-mirror-health-security/health + + Require all granted + RewriteEngine on - RewriteRule ^/$ http://www.debian.org/security/ - - #RewriteCond %{HTTP:Fastly-Client-IP} !. [NV] - #RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront" - #<% if scope.function_onion_global_service_hostname(['security.debian.org']) -%> - #RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>" - #<% end %> - #RewriteRule ^/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302] - #RewriteCond %{HTTP:Fastly-Client-IP} !. [NV] - #RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront" - #<% if scope.function_onion_global_service_hostname(['security.debian.org']) -%> - #RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>" - #<% end %> - #RewriteRule ^/debian-security/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302] - - CustomLog /var/log/apache2/security.debian.org-access.log privacy + RewriteRule ^/$ https://www.debian.org/security/ + + RewriteCond %{HTTP:Fastly-Client-IP} !. [NV] + RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront" + RewriteCond %{HTTP_USER_AGENT} "!check_http" + RewriteCond %{HTTP_USER_AGENT} "!dsa-check-mirrorsync" + <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%> + RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>" + <% end %> + RewriteCond %{REQUEST_URI} "!=/_health" + RewriteRule ^/(.*) http://security-cdn.debian.org/$1 [L,R=302] + + CustomLog /var/log/apache2/security.debian.org-access.log combined ServerSignature On