X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Froles%2Ftemplates%2Fsecurity_mirror%2Fsecurity.debian.org.erb;h=ec73f2cae71e4cabb9584cceecc297f340285700;hb=9b60934e7a658e3485fd9ce057c4252796e537c9;hp=d4be2a44094868276cd1124c5e2c91da0999923a;hpb=a245784ed5c12aedc4ac3e19bac9b216daee2571;p=mirror%2Fdsa-puppet.git
diff --git a/modules/roles/templates/security_mirror/security.debian.org.erb b/modules/roles/templates/security_mirror/security.debian.org.erb
index d4be2a440..ec73f2cae 100644
--- a/modules/roles/templates/security_mirror/security.debian.org.erb
+++ b/modules/roles/templates/security_mirror/security.debian.org.erb
@@ -3,14 +3,6 @@
## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git
##
-
- IndexOptions NameWidth=* +SuppressDescription
- Options +FollowSymLinks
- Options +Indexes
- FileETag MTime Size
- Require all granted
-
-
ServerAdmin debian-admin@debian.org
DocumentRoot /srv/ftp.root/debian-security
@@ -28,6 +20,9 @@
<% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
ServerAlias <%= scope.function_onion_global_service_hostname(['security.debian.org']) %>
<% end %>
+ ServerAlias security.backend.mirrors.debian.org
+ ServerAlias *.security.backend.mirrors.debian.org
+ ServerAlias security.anycast-test.mirrors.debian.org
ExpiresActive On
@@ -36,20 +31,29 @@
Alias /debian-security /srv/ftp.root/debian-security
Use ftp-archive /srv/ftp.root/debian-security
+ Alias /_health /run/dsa-mirror-health-ftp/health
+
+ Require all granted
+
+
RewriteEngine on
- RewriteRule ^/$ http://www.debian.org/security/
+ RewriteRule ^/$ https://www.debian.org/security/
RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+ RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront"
+ <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+ RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>"
+ <% end %>
RewriteRule ^/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
RewriteCond %{HTTP:Fastly-Client-IP} !. [NV]
+ RewriteCond %{HTTP_USER_AGENT} "!Amazon CloudFront"
+ <% if scope.function_onion_global_service_hostname(['security.debian.org']) -%>
+ RewriteCond %{HTTP_HOST} "!=<%= scope.function_onion_global_service_hostname(['security.debian.org']) %>"
+ <% end %>
RewriteRule ^/debian-security/(pool/updates/main/l/linux/.*) http://security-cdn.debian.org/$1 [L,R=302]
- # Possible values include: debug, info, notice, warn, error, crit,
- # alert, emerg.
- LogLevel warn
-
CustomLog /var/log/apache2/security.debian.org-access.log privacy
ServerSignature On
-# vim: set ts=3 sw=3 et:
+# vim:set syn=apache: