mirror/dsa-puppet.git
6 years agoAllow sudo to runmirrors in the current location
Bastian Blank [Thu, 30 Nov 2017 19:58:53 +0000 (20:58 +0100)]
Allow sudo to runmirrors in the current location

6 years agoMake sudo set a special path for calls as archvsync user
Bastian Blank [Thu, 30 Nov 2017 19:56:06 +0000 (20:56 +0100)]
Make sudo set a special path for calls as archvsync user

This allows consumers (primarily dak) to call tools of the archvsync
user without path.  This makes later switch to the packaged version
easier.

6 years agoRemove philp from experimental_apache
Julien Cristau [Thu, 30 Nov 2017 12:38:56 +0000 (13:38 +0100)]
Remove philp from experimental_apache

Upgraded to stretch.

6 years agoRedirect old children-distros page to new derivatives page
Paul Wise [Wed, 29 Nov 2017 08:16:36 +0000 (16:16 +0800)]
Redirect old children-distros page to new derivatives page

6 years agoinclude with the correct name
Peter Palfrader [Sun, 26 Nov 2017 13:30:18 +0000 (14:30 +0100)]
include with the correct name

6 years agoset vm dirty values
Peter Palfrader [Sun, 26 Nov 2017 13:29:17 +0000 (14:29 +0100)]
set vm dirty values

6 years agodo extra grub for grnet-node01,grnet-node02
Peter Palfrader [Sun, 26 Nov 2017 13:27:32 +0000 (14:27 +0100)]
do extra grub for grnet-node01,grnet-node02

6 years agoset elevator=deadline at grnet
Peter Palfrader [Sun, 26 Nov 2017 13:24:22 +0000 (14:24 +0100)]
set elevator=deadline at grnet

6 years agoAdd kantuser
Julien Cristau [Thu, 23 Nov 2017 18:06:30 +0000 (18:06 +0000)]
Add kantuser

6 years agoAdd kantuser volume at ubc
Julien Cristau [Thu, 23 Nov 2017 17:10:17 +0000 (17:10 +0000)]
Add kantuser volume at ubc

6 years agoset mode of /etc/default/locale to a+r
Peter Palfrader [Thu, 23 Nov 2017 08:47:45 +0000 (09:47 +0100)]
set mode of /etc/default/locale to a+r

6 years agoAdd extra netnod servers to ferm
Julien Cristau [Thu, 23 Nov 2017 00:34:50 +0000 (00:34 +0000)]
Add extra netnod servers to ferm

6 years agonamed: add more dnsnode server ACLs
Julien Cristau [Thu, 23 Nov 2017 00:08:27 +0000 (00:08 +0000)]
named: add more dnsnode server ACLs

6 years agoRemove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)
Peter Palfrader [Wed, 22 Nov 2017 18:14:25 +0000 (19:14 +0100)]
Remove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)

6 years agogive %list access to service {spamassassin,amavis} {reload,restart,stop,start}
Peter Palfrader [Wed, 22 Nov 2017 18:05:46 +0000 (19:05 +0100)]
give %list access to service {spamassassin,amavis} {reload,restart,stop,start}

6 years agosudo on listhosts: give list group access to postcat as postfix
Peter Palfrader [Wed, 22 Nov 2017 18:03:28 +0000 (19:03 +0100)]
sudo on listhosts: give list group access to postcat as postfix

6 years agoOnce more with feeling
Julien Cristau [Mon, 20 Nov 2017 10:10:15 +0000 (11:10 +0100)]
Once more with feeling

6 years agoEnable wsgi-py3 for tracker
Julien Cristau [Mon, 20 Nov 2017 10:08:58 +0000 (11:08 +0100)]
Enable wsgi-py3 for tracker

6 years agoremove ticharich from experimental_apache group
Julien Cristau [Mon, 20 Nov 2017 10:03:21 +0000 (11:03 +0100)]
remove ticharich from experimental_apache group

It's now on stretch

6 years agoReduce WAL retention from 21 to 14 days for bmdb1/debsources
Julien Cristau [Sun, 19 Nov 2017 11:51:05 +0000 (12:51 +0100)]
Reduce WAL retention from 21 to 14 days for bmdb1/debsources

6 years agoMerge remote-tracking branch 'stapelberg/mimetype'
Peter Palfrader [Tue, 14 Nov 2017 08:18:07 +0000 (09:18 +0100)]
Merge remote-tracking branch 'stapelberg/mimetype'

* stapelberg/mimetype:
  manpages: force content-type to text/plain for non-html .gz files

6 years agomanpages: force content-type to text/plain for non-html .gz files
Michael Stapelberg [Tue, 14 Nov 2017 08:15:23 +0000 (09:15 +0100)]
manpages: force content-type to text/plain for non-html .gz files

6 years agoDistinguish ssl/nossl access logs for planet-backend
Julien Cristau [Fri, 10 Nov 2017 23:03:32 +0000 (00:03 +0100)]
Distinguish ssl/nossl access logs for planet-backend

6 years agoRevert "install newer version of devscripts"
Julien Cristau [Fri, 10 Nov 2017 22:51:35 +0000 (23:51 +0100)]
Revert "install newer version of devscripts"

devscripts was updated in stretch-backports and now the hardcoded
version doesn't exist.

This reverts commit 55e8d03c4d97a031237a43a1aec3830b0dab5fc7.

6 years agoFix planet-backend.d.o
Julien Cristau [Fri, 10 Nov 2017 22:48:09 +0000 (23:48 +0100)]
Fix planet-backend.d.o

6 years agoadd ssl vhost for planet-backend
Julien Cristau [Fri, 10 Nov 2017 22:12:54 +0000 (23:12 +0100)]
add ssl vhost for planet-backend

6 years agoFix http://www.debian.org
Julien Cristau [Fri, 10 Nov 2017 13:00:51 +0000 (14:00 +0100)]
Fix http://www.debian.org

Thanks, paravoid

6 years agopicconi and pkgmirror-csail are on stretch, remove from experimental_apache
Julien Cristau [Wed, 8 Nov 2017 14:11:05 +0000 (15:11 +0100)]
picconi and pkgmirror-csail are on stretch, remove from experimental_apache

6 years agoFixup sources.d.o config
Julien Cristau [Mon, 6 Nov 2017 21:22:15 +0000 (22:22 +0100)]
Fixup sources.d.o config

6 years agoRotate fastly syslogs
Julien Cristau [Fri, 3 Nov 2017 15:20:06 +0000 (16:20 +0100)]
Rotate fastly syslogs

7 years agoReload syslog-ng after daemon.log rotation to prevent cron spam
Tollef Fog Heen [Wed, 1 Nov 2017 20:36:42 +0000 (21:36 +0100)]
Reload syslog-ng after daemon.log rotation to prevent cron spam

7 years agoseger's dak db is on postgresql 9.6
Julien Cristau [Wed, 1 Nov 2017 20:04:31 +0000 (21:04 +0100)]
seger's dak db is on postgresql 9.6

7 years agoDisable ftp:// on security-master
Julien Cristau [Wed, 1 Nov 2017 13:54:58 +0000 (14:54 +0100)]
Disable ftp:// on security-master

7 years agoTurn off ftp:// on ftp.debian.org
Julien Cristau [Wed, 1 Nov 2017 13:45:33 +0000 (14:45 +0100)]
Turn off ftp:// on ftp.debian.org

7 years agoTurn off ftp:// on security mirrors
Julien Cristau [Wed, 1 Nov 2017 13:41:47 +0000 (14:41 +0100)]
Turn off ftp:// on security mirrors

7 years agoAdd debsources role for sources.d.o
Julien Cristau [Wed, 1 Nov 2017 12:49:00 +0000 (13:49 +0100)]
Add debsources role for sources.d.o

7 years agoserial options that work on clementi hopefully will also work on czerny
Peter Palfrader [Tue, 31 Oct 2017 23:43:31 +0000 (00:43 +0100)]
serial options that work on clementi hopefully will also work on czerny

7 years agoDo not do serial on manda-hosts just yet
Peter Palfrader [Tue, 31 Oct 2017 23:23:03 +0000 (00:23 +0100)]
Do not do serial on manda-hosts just yet

7 years agopuppet managed grub on celemtni, czerny
Peter Palfrader [Tue, 31 Oct 2017 22:52:43 +0000 (23:52 +0100)]
puppet managed grub on celemtni, czerny

7 years agoDisable OCSP stapling on the default vhost
Julien Cristau [Mon, 30 Oct 2017 19:14:37 +0000 (20:14 +0100)]
Disable OCSP stapling on the default vhost

It can't work since we don't run an OCSP responder.

7 years agoFurther restrict access to cgi-bin on http://popcon.d.o
Julien Cristau [Sun, 29 Oct 2017 17:55:58 +0000 (18:55 +0100)]
Further restrict access to cgi-bin on popcon.d.o

7 years agoRemove unneeded bits from the http popcon vhost, and enable HSTS
Julien Cristau [Sun, 29 Oct 2017 17:52:26 +0000 (18:52 +0100)]
Remove unneeded bits from the http popcon vhost, and enable HSTS

7 years agoImport popcon.d.o apache vhost config
Julien Cristau [Sun, 29 Oct 2017 17:41:09 +0000 (18:41 +0100)]
Import popcon.d.o apache vhost config

7 years agoAdd ssl key/cert for popcon
Julien Cristau [Sun, 29 Oct 2017 08:37:28 +0000 (09:37 +0100)]
Add ssl key/cert for popcon

7 years agoredirect www.d.o to https
Peter Palfrader [Sat, 28 Oct 2017 08:45:39 +0000 (10:45 +0200)]
redirect www.d.o to https

7 years agowww: Split out onion hostname
Peter Palfrader [Sat, 28 Oct 2017 08:44:49 +0000 (10:44 +0200)]
www: Split out onion hostname

7 years agoSplit common-www.d.o into common-www.d.o and -inner
Peter Palfrader [Sat, 28 Oct 2017 08:43:34 +0000 (10:43 +0200)]
Split common-d.o into common-www.d.o and -inner

7 years agoAdd a comment
Peter Palfrader [Sat, 28 Oct 2017 08:40:43 +0000 (10:40 +0200)]
Add a comment

7 years agoremove obsolete ServerAlias entries for www-other
Peter Palfrader [Sat, 28 Oct 2017 08:39:36 +0000 (10:39 +0200)]
remove obsolete ServerAlias entries for www-other

7 years agoredirect www-other (i.e. debian.org, www.CC.d.o, www.d.CC) to https on www.debian...
Peter Palfrader [Sat, 28 Oct 2017 08:37:29 +0000 (10:37 +0200)]
redirect www-other (i.e. debian.org, CC.d.o, www.d.CC) to https on www.debian.org now

7 years agoreject package file names that could be used to install local files. Issue reported...
Peter Palfrader [Mon, 23 Oct 2017 13:43:32 +0000 (15:43 +0200)]
reject package file names that could be used to install local files.  Issue reported by Julian Andres Klode.

7 years agoCleanup experimental_apache role
Julien Cristau [Fri, 20 Oct 2017 06:12:39 +0000 (08:12 +0200)]
Cleanup experimental_apache role

Not needed on hosts running stretch

7 years agoMerge branch 'master' of ssh://handel.debian.org/~/dsa-puppet
Luca Filipozzi [Thu, 19 Oct 2017 00:59:41 +0000 (00:59 +0000)]
Merge branch 'master' of ssh://handel.debian.org/~/dsa-puppet

7 years agoremove custom casulana rules
Luca Filipozzi [Thu, 19 Oct 2017 00:58:44 +0000 (00:58 +0000)]
remove custom casulana rules

7 years agoRT#6923 - More users and groups
Martin Zobel-Helas [Wed, 18 Oct 2017 22:48:28 +0000 (18:48 -0400)]
RT#6923 - More users and groups

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoAdd mail filters for some aliases (rt#6227)
Julien Cristau [Wed, 18 Oct 2017 19:41:19 +0000 (21:41 +0200)]
Add mail filters for some aliases (rt#6227)

- add sender callout for leader, patents, trademark
- add greylisting for patents, trademark
- add RBLs for patents, trademark
- add RHSBLs for leader, patents, treasurer, trademark

7 years agoalways a typo
Luca Filipozzi [Wed, 18 Oct 2017 18:50:49 +0000 (18:50 +0000)]
always a typo

7 years agoprune ssh ACLs for luca
Luca Filipozzi [Wed, 18 Oct 2017 18:49:29 +0000 (18:49 +0000)]
prune ssh ACLs for luca

7 years agoadd more casulana rules for br1
Luca Filipozzi [Wed, 18 Oct 2017 17:59:54 +0000 (17:59 +0000)]
add more casulana rules for br1

7 years agoadd masquerade rules for casulana virtual machines
Luca Filipozzi [Wed, 18 Oct 2017 17:05:44 +0000 (17:05 +0000)]
add masquerade rules for casulana virtual machines

7 years agoundo casulana custom roles
Luca Filipozzi [Wed, 18 Oct 2017 00:26:37 +0000 (00:26 +0000)]
undo casulana custom roles

7 years agofix up the custom cloud-admins rule
Luca Filipozzi [Tue, 17 Oct 2017 23:13:57 +0000 (23:13 +0000)]
fix up the custom cloud-admins rule

7 years agocustom rule for cloud-builds on casaluna
Luca Filipozzi [Tue, 17 Oct 2017 23:11:59 +0000 (23:11 +0000)]
custom rule for cloud-builds on casaluna

7 years agoadd sudo access to group cloud-builds
Martin Zobel-Helas [Mon, 16 Oct 2017 20:46:14 +0000 (16:46 -0400)]
add sudo access to group cloud-builds

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agobmdb1 main cluster is back on timeline 1
Julien Cristau [Sun, 15 Oct 2017 10:22:30 +0000 (12:22 +0200)]
bmdb1 main cluster is back on timeline 1

7 years agoEnsure mirror-health is restarted after the daemon-reload
Tollef Fog Heen [Sun, 8 Oct 2017 05:34:43 +0000 (07:34 +0200)]
Ensure mirror-health is restarted after the daemon-reload

7 years agoDrop klecker from ftp.d.o mirror-health checking
Tollef Fog Heen [Sun, 8 Oct 2017 05:21:47 +0000 (07:21 +0200)]
Drop klecker from ftp.d.o mirror-health checking

klecker is not part of the set of backends that Fastly uses, so
checking against it has no value and might leave us unhealthy if
klecker is ahead.

7 years agomask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount
Peter Palfrader [Fri, 6 Oct 2017 08:25:10 +0000 (10:25 +0200)]
mask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount

7 years agoAdd a systemd::mask
Peter Palfrader [Fri, 6 Oct 2017 08:23:48 +0000 (10:23 +0200)]
Add a systemd::mask

7 years agoFix octal number in python script to it compiles
Peter Palfrader [Thu, 5 Oct 2017 09:43:36 +0000 (11:43 +0200)]
Fix octal number in python script to it compiles

7 years agoRevert "Use RedirectPermanent instead of RewriteRule"
Paul Wise [Thu, 5 Oct 2017 08:37:09 +0000 (16:37 +0800)]
Revert "Use RedirectPermanent instead of RewriteRule"

This reverts commit abb8a9a1d0c72a616e297be5a1b091b6c9a74191.

7 years agoUse RedirectPermanent instead of RewriteRule
Paul Wise [Thu, 5 Oct 2017 08:21:32 +0000 (16:21 +0800)]
Use RedirectPermanent instead of RewriteRule

7 years agoBetter debian-ports.org/debian-cd redirection
Aurelien Jarno [Thu, 5 Oct 2017 08:21:22 +0000 (10:21 +0200)]
Better debian-ports.org/debian-cd redirection

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoDrop remaining debian-ports-cd code
Aurelien Jarno [Thu, 5 Oct 2017 07:57:42 +0000 (09:57 +0200)]
Drop remaining debian-ports-cd code

7 years agoRedirect ftp.ports.debian.org/debian-ports-cd to cdimage
Aurelien Jarno [Thu, 5 Oct 2017 07:54:57 +0000 (09:54 +0200)]
Redirect ftp.ports.debian.org/debian-ports-cd to cdimage

7 years agoUpdate debian-ports.org/debian-cd redirection to cdimage.d.do
Aurelien Jarno [Thu, 5 Oct 2017 07:41:20 +0000 (09:41 +0200)]
Update debian-ports.org/debian-cd redirection to cdimage.d.do

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoFormat weekly stunnel restart script nicer
Peter Palfrader [Tue, 3 Oct 2017 10:51:19 +0000 (12:51 +0200)]
Format weekly stunnel restart script nicer

7 years agoHave gobby reload its config when we change its ssl cert
Julien Cristau [Tue, 3 Oct 2017 10:42:35 +0000 (12:42 +0200)]
Have gobby reload its config when we change its ssl cert

7 years agoremove auto-cert and auto-clientcert symlinks from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:49:55 +0000 (10:49 +0200)]
remove auto-cert and auto-clientcert symlinks from fileserver path

7 years agofix one path
Peter Palfrader [Tue, 3 Oct 2017 08:48:55 +0000 (10:48 +0200)]
fix one path

7 years agoTry to replace file access to auto-ca things with templates
Peter Palfrader [Tue, 3 Oct 2017 08:47:51 +0000 (10:47 +0200)]
Try to replace file access to auto-ca things with templates

7 years agoAdd syncproxy addresses to ssh whitelist
Julien Cristau [Tue, 3 Oct 2017 08:34:40 +0000 (10:34 +0200)]
Add syncproxy addresses to ssh whitelist

7 years agoAnd more move things
Peter Palfrader [Tue, 3 Oct 2017 08:34:37 +0000 (10:34 +0200)]
And more move things

7 years agomove ssl/clientcerts to ssl/auto-clientcerts
Peter Palfrader [Tue, 3 Oct 2017 08:33:04 +0000 (10:33 +0200)]
move ssl/clientcerts to ssl/auto-clientcerts

7 years agomove exim/certs to ssl/auto-certs
Peter Palfrader [Tue, 3 Oct 2017 08:31:19 +0000 (10:31 +0200)]
move exim/certs to ssl/auto-certs

7 years agoStop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place
Peter Palfrader [Tue, 3 Oct 2017 08:28:08 +0000 (08:28 +0000)]
Stop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place

7 years agoremove from-letsencrypt symlink from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:16:23 +0000 (10:16 +0200)]
remove from-letsencrypt symlink from fileserver path

7 years agoMake db key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:15:17 +0000 (10:15 +0200)]
Make db key loaded from a template

7 years agoMake gobby key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:14:36 +0000 (08:14 +0000)]
Make gobby key loaded from a template

7 years agoAdd tls key for gobby server
Julien Cristau [Tue, 3 Oct 2017 07:51:00 +0000 (09:51 +0200)]
Add tls key for gobby server

This should remove the need to rotate it manually.

7 years agoUse restrict authorized_keys option for geodns
Julien Cristau [Tue, 3 Oct 2017 07:07:07 +0000 (09:07 +0200)]
Use restrict authorized_keys option for geodns

no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty,no-user
is a mouthful, and geo[123] are all on stretch.

7 years agoremove unused modules/ssl/files/chains with the GANDI chains
Peter Palfrader [Tue, 3 Oct 2017 07:07:20 +0000 (09:07 +0200)]
remove unused modules/ssl/files/chains with the GANDI chains

7 years agoUse a template to get more of the from-letsencrypt certs and keys, and no longer...
Peter Palfrader [Tue, 3 Oct 2017 07:06:52 +0000 (09:06 +0200)]
Use a template to get more of the from-letsencrypt certs and keys, and no longer support getting certs and chains from files/{servicecerts,chains} (which no longer holds any DSA certs)

7 years agoRestrict ssh to mirrors
Julien Cristau [Tue, 3 Oct 2017 07:00:09 +0000 (09:00 +0200)]
Restrict ssh to mirrors

7 years agoFix ssl key template
Julien Cristau [Tue, 3 Oct 2017 06:59:30 +0000 (08:59 +0200)]
Fix ssl key template

7 years agoUse a template to get from-letsencrypt cert key, and no longer support getting keys...
Peter Palfrader [Tue, 3 Oct 2017 06:55:52 +0000 (08:55 +0200)]
Use a template to get from-letsencrypt cert key, and no longer support getting keys from files/keys (which no longer exists anyhow)

7 years agobmdb1/main on postgresql 9.6
Julien Cristau [Mon, 2 Oct 2017 16:26:45 +0000 (18:26 +0200)]
bmdb1/main on postgresql 9.6

7 years agodon't spawn a shell in create-onionbalance-config
Julien Cristau [Mon, 2 Oct 2017 12:48:50 +0000 (14:48 +0200)]
don't spawn a shell in create-onionbalance-config

python can do these things.

7 years agoMake sure onionbalance private keys are group-readable
Julien Cristau [Mon, 2 Oct 2017 12:27:26 +0000 (14:27 +0200)]
Make sure onionbalance private keys are group-readable

Seems umask is no longer sufficient and they end up 0600.

7 years agobmdb1's debsources cluster is on 9.6
Julien Cristau [Sun, 1 Oct 2017 21:41:39 +0000 (23:41 +0200)]
bmdb1's debsources cluster is on 9.6