Bastian Blank [Thu, 30 Nov 2017 19:58:53 +0000 (20:58 +0100)]
Allow sudo to runmirrors in the current location
Bastian Blank [Thu, 30 Nov 2017 19:56:06 +0000 (20:56 +0100)]
Make sudo set a special path for calls as archvsync user
This allows consumers (primarily dak) to call tools of the archvsync
user without path. This makes later switch to the packaged version
easier.
Julien Cristau [Thu, 30 Nov 2017 12:38:56 +0000 (13:38 +0100)]
Remove philp from experimental_apache
Upgraded to stretch.
Paul Wise [Wed, 29 Nov 2017 08:16:36 +0000 (16:16 +0800)]
Redirect old children-distros page to new derivatives page
Peter Palfrader [Sun, 26 Nov 2017 13:30:18 +0000 (14:30 +0100)]
include with the correct name
Peter Palfrader [Sun, 26 Nov 2017 13:29:17 +0000 (14:29 +0100)]
set vm dirty values
Peter Palfrader [Sun, 26 Nov 2017 13:27:32 +0000 (14:27 +0100)]
do extra grub for grnet-node01,grnet-node02
Peter Palfrader [Sun, 26 Nov 2017 13:24:22 +0000 (14:24 +0100)]
set elevator=deadline at grnet
Julien Cristau [Thu, 23 Nov 2017 18:06:30 +0000 (18:06 +0000)]
Add kantuser
Julien Cristau [Thu, 23 Nov 2017 17:10:17 +0000 (17:10 +0000)]
Add kantuser volume at ubc
Peter Palfrader [Thu, 23 Nov 2017 08:47:45 +0000 (09:47 +0100)]
set mode of /etc/default/locale to a+r
Julien Cristau [Thu, 23 Nov 2017 00:34:50 +0000 (00:34 +0000)]
Add extra netnod servers to ferm
Julien Cristau [Thu, 23 Nov 2017 00:08:27 +0000 (00:08 +0000)]
named: add more dnsnode server ACLs
Peter Palfrader [Wed, 22 Nov 2017 18:14:25 +0000 (19:14 +0100)]
Remove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)
Peter Palfrader [Wed, 22 Nov 2017 18:05:46 +0000 (19:05 +0100)]
give %list access to service {spamassassin,amavis} {reload,restart,stop,start}
Peter Palfrader [Wed, 22 Nov 2017 18:03:28 +0000 (19:03 +0100)]
sudo on listhosts: give list group access to postcat as postfix
Julien Cristau [Mon, 20 Nov 2017 10:10:15 +0000 (11:10 +0100)]
Once more with feeling
Julien Cristau [Mon, 20 Nov 2017 10:08:58 +0000 (11:08 +0100)]
Enable wsgi-py3 for tracker
Julien Cristau [Mon, 20 Nov 2017 10:03:21 +0000 (11:03 +0100)]
remove ticharich from experimental_apache group
It's now on stretch
Julien Cristau [Sun, 19 Nov 2017 11:51:05 +0000 (12:51 +0100)]
Reduce WAL retention from 21 to 14 days for bmdb1/debsources
Peter Palfrader [Tue, 14 Nov 2017 08:18:07 +0000 (09:18 +0100)]
Merge remote-tracking branch 'stapelberg/mimetype'
* stapelberg/mimetype:
manpages: force content-type to text/plain for non-html .gz files
Michael Stapelberg [Tue, 14 Nov 2017 08:15:23 +0000 (09:15 +0100)]
manpages: force content-type to text/plain for non-html .gz files
Julien Cristau [Fri, 10 Nov 2017 23:03:32 +0000 (00:03 +0100)]
Distinguish ssl/nossl access logs for planet-backend
Julien Cristau [Fri, 10 Nov 2017 22:51:35 +0000 (23:51 +0100)]
Revert "install newer version of devscripts"
devscripts was updated in stretch-backports and now the hardcoded
version doesn't exist.
This reverts commit
55e8d03c4d97a031237a43a1aec3830b0dab5fc7.
Julien Cristau [Fri, 10 Nov 2017 22:48:09 +0000 (23:48 +0100)]
Fix planet-backend.d.o
Julien Cristau [Fri, 10 Nov 2017 22:12:54 +0000 (23:12 +0100)]
add ssl vhost for planet-backend
Julien Cristau [Fri, 10 Nov 2017 13:00:51 +0000 (14:00 +0100)]
Fix http://www.debian.org
Thanks, paravoid
Julien Cristau [Wed, 8 Nov 2017 14:11:05 +0000 (15:11 +0100)]
picconi and pkgmirror-csail are on stretch, remove from experimental_apache
Julien Cristau [Mon, 6 Nov 2017 21:22:15 +0000 (22:22 +0100)]
Fixup sources.d.o config
Julien Cristau [Fri, 3 Nov 2017 15:20:06 +0000 (16:20 +0100)]
Rotate fastly syslogs
Tollef Fog Heen [Wed, 1 Nov 2017 20:36:42 +0000 (21:36 +0100)]
Reload syslog-ng after daemon.log rotation to prevent cron spam
Julien Cristau [Wed, 1 Nov 2017 20:04:31 +0000 (21:04 +0100)]
seger's dak db is on postgresql 9.6
Julien Cristau [Wed, 1 Nov 2017 13:54:58 +0000 (14:54 +0100)]
Disable ftp:// on security-master
Julien Cristau [Wed, 1 Nov 2017 13:45:33 +0000 (14:45 +0100)]
Turn off ftp:// on ftp.debian.org
Julien Cristau [Wed, 1 Nov 2017 13:41:47 +0000 (14:41 +0100)]
Turn off ftp:// on security mirrors
Julien Cristau [Wed, 1 Nov 2017 12:49:00 +0000 (13:49 +0100)]
Add debsources role for sources.d.o
Peter Palfrader [Tue, 31 Oct 2017 23:43:31 +0000 (00:43 +0100)]
serial options that work on clementi hopefully will also work on czerny
Peter Palfrader [Tue, 31 Oct 2017 23:23:03 +0000 (00:23 +0100)]
Do not do serial on manda-hosts just yet
Peter Palfrader [Tue, 31 Oct 2017 22:52:43 +0000 (23:52 +0100)]
puppet managed grub on celemtni, czerny
Julien Cristau [Mon, 30 Oct 2017 19:14:37 +0000 (20:14 +0100)]
Disable OCSP stapling on the default vhost
It can't work since we don't run an OCSP responder.
Julien Cristau [Sun, 29 Oct 2017 17:55:58 +0000 (18:55 +0100)]
Further restrict access to cgi-bin on popcon.d.o
Julien Cristau [Sun, 29 Oct 2017 17:52:26 +0000 (18:52 +0100)]
Remove unneeded bits from the http popcon vhost, and enable HSTS
Julien Cristau [Sun, 29 Oct 2017 17:41:09 +0000 (18:41 +0100)]
Import popcon.d.o apache vhost config
Julien Cristau [Sun, 29 Oct 2017 08:37:28 +0000 (09:37 +0100)]
Add ssl key/cert for popcon
Peter Palfrader [Sat, 28 Oct 2017 08:45:39 +0000 (10:45 +0200)]
redirect www.d.o to https
Peter Palfrader [Sat, 28 Oct 2017 08:44:49 +0000 (10:44 +0200)]
www: Split out onion hostname
Peter Palfrader [Sat, 28 Oct 2017 08:43:34 +0000 (10:43 +0200)]
Split common-d.o into common-www.d.o and -inner
Peter Palfrader [Sat, 28 Oct 2017 08:40:43 +0000 (10:40 +0200)]
Add a comment
Peter Palfrader [Sat, 28 Oct 2017 08:39:36 +0000 (10:39 +0200)]
remove obsolete ServerAlias entries for www-other
Peter Palfrader [Sat, 28 Oct 2017 08:37:29 +0000 (10:37 +0200)]
redirect www-other (i.e. debian.org, CC.d.o, www.d.CC) to https on www.debian.org now
Peter Palfrader [Mon, 23 Oct 2017 13:43:32 +0000 (15:43 +0200)]
reject package file names that could be used to install local files. Issue reported by Julian Andres Klode.
Julien Cristau [Fri, 20 Oct 2017 06:12:39 +0000 (08:12 +0200)]
Cleanup experimental_apache role
Not needed on hosts running stretch
Luca Filipozzi [Thu, 19 Oct 2017 00:59:41 +0000 (00:59 +0000)]
Merge branch 'master' of ssh://handel.debian.org/~/dsa-puppet
Luca Filipozzi [Thu, 19 Oct 2017 00:58:44 +0000 (00:58 +0000)]
remove custom casulana rules
Martin Zobel-Helas [Wed, 18 Oct 2017 22:48:28 +0000 (18:48 -0400)]
RT#6923 - More users and groups
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Julien Cristau [Wed, 18 Oct 2017 19:41:19 +0000 (21:41 +0200)]
Add mail filters for some aliases (rt#6227)
- add sender callout for leader, patents, trademark
- add greylisting for patents, trademark
- add RBLs for patents, trademark
- add RHSBLs for leader, patents, treasurer, trademark
Luca Filipozzi [Wed, 18 Oct 2017 18:50:49 +0000 (18:50 +0000)]
always a typo
Luca Filipozzi [Wed, 18 Oct 2017 18:49:29 +0000 (18:49 +0000)]
prune ssh ACLs for luca
Luca Filipozzi [Wed, 18 Oct 2017 17:59:54 +0000 (17:59 +0000)]
add more casulana rules for br1
Luca Filipozzi [Wed, 18 Oct 2017 17:05:44 +0000 (17:05 +0000)]
add masquerade rules for casulana virtual machines
Luca Filipozzi [Wed, 18 Oct 2017 00:26:37 +0000 (00:26 +0000)]
undo casulana custom roles
Luca Filipozzi [Tue, 17 Oct 2017 23:13:57 +0000 (23:13 +0000)]
fix up the custom cloud-admins rule
Luca Filipozzi [Tue, 17 Oct 2017 23:11:59 +0000 (23:11 +0000)]
custom rule for cloud-builds on casaluna
Martin Zobel-Helas [Mon, 16 Oct 2017 20:46:14 +0000 (16:46 -0400)]
add sudo access to group cloud-builds
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Julien Cristau [Sun, 15 Oct 2017 10:22:30 +0000 (12:22 +0200)]
bmdb1 main cluster is back on timeline 1
Tollef Fog Heen [Sun, 8 Oct 2017 05:34:43 +0000 (07:34 +0200)]
Ensure mirror-health is restarted after the daemon-reload
Tollef Fog Heen [Sun, 8 Oct 2017 05:21:47 +0000 (07:21 +0200)]
Drop klecker from ftp.d.o mirror-health checking
klecker is not part of the set of backends that Fastly uses, so
checking against it has no value and might leave us unhealthy if
klecker is ahead.
Peter Palfrader [Fri, 6 Oct 2017 08:25:10 +0000 (10:25 +0200)]
mask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount
Peter Palfrader [Fri, 6 Oct 2017 08:23:48 +0000 (10:23 +0200)]
Add a systemd::mask
Peter Palfrader [Thu, 5 Oct 2017 09:43:36 +0000 (11:43 +0200)]
Fix octal number in python script to it compiles
Paul Wise [Thu, 5 Oct 2017 08:37:09 +0000 (16:37 +0800)]
Revert "Use RedirectPermanent instead of RewriteRule"
This reverts commit
abb8a9a1d0c72a616e297be5a1b091b6c9a74191.
Paul Wise [Thu, 5 Oct 2017 08:21:32 +0000 (16:21 +0800)]
Use RedirectPermanent instead of RewriteRule
Aurelien Jarno [Thu, 5 Oct 2017 08:21:22 +0000 (10:21 +0200)]
Better debian-ports.org/debian-cd redirection
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Thu, 5 Oct 2017 07:57:42 +0000 (09:57 +0200)]
Drop remaining debian-ports-cd code
Aurelien Jarno [Thu, 5 Oct 2017 07:54:57 +0000 (09:54 +0200)]
Redirect ftp.ports.debian.org/debian-ports-cd to cdimage
Aurelien Jarno [Thu, 5 Oct 2017 07:41:20 +0000 (09:41 +0200)]
Update debian-ports.org/debian-cd redirection to cdimage.d.do
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Tue, 3 Oct 2017 10:51:19 +0000 (12:51 +0200)]
Format weekly stunnel restart script nicer
Julien Cristau [Tue, 3 Oct 2017 10:42:35 +0000 (12:42 +0200)]
Have gobby reload its config when we change its ssl cert
Peter Palfrader [Tue, 3 Oct 2017 08:49:55 +0000 (10:49 +0200)]
remove auto-cert and auto-clientcert symlinks from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:48:55 +0000 (10:48 +0200)]
fix one path
Peter Palfrader [Tue, 3 Oct 2017 08:47:51 +0000 (10:47 +0200)]
Try to replace file access to auto-ca things with templates
Julien Cristau [Tue, 3 Oct 2017 08:34:40 +0000 (10:34 +0200)]
Add syncproxy addresses to ssh whitelist
Peter Palfrader [Tue, 3 Oct 2017 08:34:37 +0000 (10:34 +0200)]
And more move things
Peter Palfrader [Tue, 3 Oct 2017 08:33:04 +0000 (10:33 +0200)]
move ssl/clientcerts to ssl/auto-clientcerts
Peter Palfrader [Tue, 3 Oct 2017 08:31:19 +0000 (10:31 +0200)]
move exim/certs to ssl/auto-certs
Peter Palfrader [Tue, 3 Oct 2017 08:28:08 +0000 (08:28 +0000)]
Stop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place
Peter Palfrader [Tue, 3 Oct 2017 08:16:23 +0000 (10:16 +0200)]
remove from-letsencrypt symlink from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:15:17 +0000 (10:15 +0200)]
Make db key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:14:36 +0000 (08:14 +0000)]
Make gobby key loaded from a template
Julien Cristau [Tue, 3 Oct 2017 07:51:00 +0000 (09:51 +0200)]
Add tls key for gobby server
This should remove the need to rotate it manually.
Julien Cristau [Tue, 3 Oct 2017 07:07:07 +0000 (09:07 +0200)]
Use restrict authorized_keys option for geodns
no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty,no-user
is a mouthful, and geo[123] are all on stretch.
Peter Palfrader [Tue, 3 Oct 2017 07:07:20 +0000 (09:07 +0200)]
remove unused modules/ssl/files/chains with the GANDI chains
Peter Palfrader [Tue, 3 Oct 2017 07:06:52 +0000 (09:06 +0200)]
Use a template to get more of the from-letsencrypt certs and keys, and no longer support getting certs and chains from files/{servicecerts,chains} (which no longer holds any DSA certs)
Julien Cristau [Tue, 3 Oct 2017 07:00:09 +0000 (09:00 +0200)]
Restrict ssh to mirrors
Julien Cristau [Tue, 3 Oct 2017 06:59:30 +0000 (08:59 +0200)]
Fix ssl key template
Peter Palfrader [Tue, 3 Oct 2017 06:55:52 +0000 (08:55 +0200)]
Use a template to get from-letsencrypt cert key, and no longer support getting keys from files/keys (which no longer exists anyhow)
Julien Cristau [Mon, 2 Oct 2017 16:26:45 +0000 (18:26 +0200)]
bmdb1/main on postgresql 9.6
Julien Cristau [Mon, 2 Oct 2017 12:48:50 +0000 (14:48 +0200)]
don't spawn a shell in create-onionbalance-config
python can do these things.
Julien Cristau [Mon, 2 Oct 2017 12:27:26 +0000 (14:27 +0200)]
Make sure onionbalance private keys are group-readable
Seems umask is no longer sufficient and they end up 0600.
Julien Cristau [Sun, 1 Oct 2017 21:41:39 +0000 (23:41 +0200)]
bmdb1's debsources cluster is on 9.6