Julien Cristau [Mon, 18 Mar 2019 14:51:31 +0000 (15:51 +0100)]
schmelzer has /srv/mirrors/public-debian, use it
Helps keep things in sync with other mirrors that are its downstreams.
Julien Cristau [Sun, 17 Mar 2019 18:12:25 +0000 (19:12 +0100)]
ganeti: add ganeti2-osuosl ip range
No dedicated private network for now, just trying things out.
Julien Cristau [Sun, 17 Mar 2019 16:01:39 +0000 (17:01 +0100)]
Fix rsync setup on schmelzer
Aurelien Jarno [Sun, 17 Mar 2019 12:36:15 +0000 (13:36 +0100)]
Decommission lully.d.o
Replaced by loghost-osuosl-01
Peter Palfrader [Fri, 15 Mar 2019 10:20:07 +0000 (11:20 +0100)]
blacklist 211.13.205.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:19:35 +0000 (11:19 +0100)]
blacklist 84.204.194.0/24
Julien Cristau [Fri, 15 Mar 2019 10:14:37 +0000 (11:14 +0100)]
syslog: fix longstanding hostname typo
Looks like this has been around since
d6761ce0180c2b4ac9f90e744fa34416ee68ae48
in 2013.
Peter Palfrader [Fri, 15 Mar 2019 10:14:46 +0000 (11:14 +0100)]
blacklist 159.226.95.0/24
Julien Cristau [Thu, 14 Mar 2019 13:16:02 +0000 (14:16 +0100)]
Add cron script to compress and clean up logs on syslog hosts
Peter Palfrader [Mon, 11 Mar 2019 08:59:43 +0000 (09:59 +0100)]
remove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home
Peter Palfrader [Mon, 11 Mar 2019 08:56:03 +0000 (09:56 +0100)]
Add lw08 to the snapshot_shell role and give ftp-master some infra there
Peter Palfrader [Sat, 9 Mar 2019 10:37:25 +0000 (11:37 +0100)]
Stop making nsswitch executable
Aurelien Jarno [Fri, 8 Mar 2019 20:16:38 +0000 (21:16 +0100)]
lvm setup for pieta
Aurelien Jarno [Fri, 8 Mar 2019 18:18:39 +0000 (19:18 +0100)]
move incoming smtp to port 2025 on smit.d.o
Aurelien Jarno [Thu, 7 Mar 2019 20:48:05 +0000 (21:48 +0100)]
Add smit
Julien Cristau [Tue, 5 Mar 2019 19:36:49 +0000 (20:36 +0100)]
Add debconf.org cert
Julien Cristau [Tue, 5 Mar 2019 19:33:24 +0000 (20:33 +0100)]
Take over debconf.org with a redirect to www
Julien Cristau [Fri, 1 Mar 2019 13:33:15 +0000 (14:33 +0100)]
Add schmelzer to a couple more things
Julien Cristau [Fri, 1 Mar 2019 13:25:05 +0000 (14:25 +0100)]
Fix mirror-health-security by skipping the security to security-cdn redirect
Julien Cristau [Thu, 28 Feb 2019 13:12:34 +0000 (14:12 +0100)]
add some roles to schmelzer
Julien Cristau [Thu, 21 Feb 2019 12:04:48 +0000 (13:04 +0100)]
mirror-umn console is on COM2
Julien Cristau [Wed, 20 Feb 2019 15:41:49 +0000 (16:41 +0100)]
Add conova ip range
Julien Cristau [Wed, 20 Feb 2019 15:37:11 +0000 (16:37 +0100)]
Add schmelzer
Julien Cristau [Sun, 17 Feb 2019 18:53:59 +0000 (19:53 +0100)]
Decommission kantuser (RT#7583)
Aurelien Jarno [Sun, 17 Feb 2019 06:33:27 +0000 (07:33 +0100)]
add default lvm conf for pijper
Tollef Fog Heen [Sat, 16 Feb 2019 21:07:49 +0000 (22:07 +0100)]
cvs.d.o is gone, drop redirect
Julien Cristau [Sat, 16 Feb 2019 17:04:31 +0000 (18:04 +0100)]
add mekeel-srv (RT#7226)
Julien Cristau [Fri, 8 Feb 2019 07:57:34 +0000 (08:57 +0100)]
syslog-ng: define fastly destination on all log hosts, not just lully
Aurelien Jarno [Mon, 4 Feb 2019 21:00:07 +0000 (22:00 +0100)]
Revert "99builddsourceslist: disable apt redirects in chroots"
This reverts commit
840177adeb15e1a9f23cff136708eb60a10cd3a7.
All the chroots now have an updated apt.
Aurelien Jarno [Sun, 3 Feb 2019 09:59:39 +0000 (10:59 +0100)]
Fix KVM detection for rng-tools
Aurelien Jarno [Sun, 3 Feb 2019 00:22:02 +0000 (01:22 +0100)]
Do not setup grub/kernel serial console on ppc64el VMs
On ppc64el VMs, grub and the kernel automatically switch to the serial
console if there is no video card. OTOH the serial console is not called
ttyS0, so it's better to not try to setup it up manually.
Aurelien Jarno [Sun, 3 Feb 2019 00:09:55 +0000 (01:09 +0100)]
ganeti2: remove qemu-system-ppc64 wrapper
The wrapper ended-up simpler than on arm64, therefore kvm_extra can be
used instead.
Julien Cristau [Mon, 28 Jan 2019 21:43:43 +0000 (22:43 +0100)]
add loghost-osuosl-01
Julien Cristau [Sun, 27 Jan 2019 15:00:27 +0000 (16:00 +0100)]
ganeti2: add wrapper for qemu-system-ppc64
Peter Palfrader [Thu, 24 Jan 2019 12:36:36 +0000 (13:36 +0100)]
empty slapd-ftmg.conf
Peter Palfrader [Thu, 24 Jan 2019 12:35:21 +0000 (13:35 +0100)]
slapd: listen on localhost only
Peter Palfrader [Thu, 24 Jan 2019 12:34:09 +0000 (13:34 +0100)]
Add default /etc/default/slapd
Peter Palfrader [Thu, 24 Jan 2019 12:32:29 +0000 (13:32 +0100)]
typo fix
Peter Palfrader [Thu, 24 Jan 2019 12:30:55 +0000 (13:30 +0100)]
ssl slapd: load hbd backend module, disable db and backend specific config
Peter Palfrader [Thu, 24 Jan 2019 12:27:40 +0000 (13:27 +0100)]
default slapd.conf
Peter Palfrader [Thu, 24 Jan 2019 12:19:29 +0000 (13:19 +0100)]
sso: install slapd (re: RT#7454)
Peter Palfrader [Thu, 24 Jan 2019 10:10:32 +0000 (11:10 +0100)]
ship ftmg.sso.debian.org key to sso host
Julien Cristau [Wed, 23 Jan 2019 15:27:30 +0000 (16:27 +0100)]
Actually install apt https config
Julien Cristau [Wed, 23 Jan 2019 15:21:24 +0000 (16:21 +0100)]
Tell apt to use cartel CAs for https mirrors
Peter Palfrader [Wed, 23 Jan 2019 12:47:42 +0000 (13:47 +0100)]
Try to support debootstrapping from https sources on debian.org infra
Peter Palfrader [Wed, 23 Jan 2019 12:07:14 +0000 (13:07 +0100)]
use local mirrors less
Peter Palfrader [Wed, 23 Jan 2019 12:03:40 +0000 (13:03 +0100)]
switch default mirror to https://deb.debian.org/debian
Peter Palfrader [Wed, 23 Jan 2019 10:07:10 +0000 (11:07 +0100)]
install ca-certificates in all chroots
Peter Palfrader [Wed, 23 Jan 2019 08:51:53 +0000 (09:51 +0100)]
install security (LTS) updates for jessie
Peter Palfrader [Wed, 23 Jan 2019 08:51:06 +0000 (09:51 +0100)]
use https://deb.debian.org/debian as default mirror
Peter Palfrader [Wed, 23 Jan 2019 08:50:56 +0000 (09:50 +0100)]
setup-dchroot: do install of security and updates for ubuntu chroots earlier
Peter Palfrader [Wed, 23 Jan 2019 08:25:24 +0000 (09:25 +0100)]
terminate case properly
Peter Palfrader [Wed, 23 Jan 2019 08:22:53 +0000 (09:22 +0100)]
Install apt-transport-https during debootstrap
Aurelien Jarno [Tue, 22 Jan 2019 19:31:47 +0000 (20:31 +0100)]
99builddsourceslist: disable apt redirects in chroots
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:54 +0000 (21:17 +0100)]
Remove moszumanska-lvm and moszumanska from multipath config
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:37 +0000 (21:17 +0100)]
Avoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd
Julien Cristau [Thu, 17 Jan 2019 15:46:37 +0000 (16:46 +0100)]
Enable SSILegacyExprParser on www.debconf.org
The site would need updates for the new syntax
Julien Cristau [Thu, 17 Jan 2019 15:37:04 +0000 (16:37 +0100)]
www.debconf.org vhost update
Add missing redirects from current config on kent.debconf.org
Julien Cristau [Thu, 17 Jan 2019 15:26:08 +0000 (16:26 +0100)]
Add www.debconf.org vhost for real
Julien Cristau [Thu, 17 Jan 2019 15:04:07 +0000 (16:04 +0100)]
Add www.debconf.org vhost on static
Julien Cristau [Thu, 17 Jan 2019 14:42:02 +0000 (15:42 +0100)]
Add www.debconf.org static component
Julien Cristau [Wed, 16 Jan 2019 07:08:07 +0000 (08:08 +0100)]
Bump RLimitNPROC for bugs web hosts
Bug#919316
Peter Palfrader [Mon, 14 Jan 2019 09:40:02 +0000 (10:40 +0100)]
Set LogLevel VERBOSE in sshd
Julien Cristau [Sun, 13 Jan 2019 22:51:35 +0000 (23:51 +0100)]
Add wiki.debconf.org static vhost (RT#7595)
Julien Cristau [Sun, 13 Jan 2019 22:44:15 +0000 (23:44 +0100)]
debconfstatic can update wiki.debconf.org
Julien Cristau [Sun, 13 Jan 2019 22:42:05 +0000 (23:42 +0100)]
Update DMUP url in motd
Julien Cristau [Sun, 13 Jan 2019 22:35:21 +0000 (23:35 +0100)]
Add wiki.debconf.org static component
Julien Cristau [Thu, 10 Jan 2019 21:20:21 +0000 (22:20 +0100)]
Fix sudoers syntax
Julien Cristau [Thu, 10 Jan 2019 21:08:20 +0000 (22:08 +0100)]
sudo: add an extra entry for dsa-check-openmanage
Add ability to ignore "Cache Battery 0 in controller 0 is Degraded
(Non-Critical) [probably harmless]" warning.
Peter Palfrader [Tue, 8 Jan 2019 13:49:08 +0000 (14:49 +0100)]
postgres-make-base-backups.erb: fix limited info log
Tollef Fog Heen [Mon, 7 Jan 2019 20:59:04 +0000 (21:59 +0100)]
RT#7513 Get rid of most traces of moszumanska
Tollef Fog Heen [Wed, 2 Jan 2019 19:39:06 +0000 (20:39 +0100)]
Add an adm key for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 18:47:11 +0000 (19:47 +0100)]
Open up some IPs for tfheen
Peter Palfrader [Wed, 2 Jan 2019 17:29:38 +0000 (18:29 +0100)]
remove duplicate entry for sallinen in postgresql_server
Peter Palfrader [Wed, 2 Jan 2019 13:22:38 +0000 (14:22 +0100)]
Remove disfunct combined.njabl.org RBL from rbllist for all the roles that had it
Peter Palfrader [Mon, 31 Dec 2018 09:02:27 +0000 (10:02 +0100)]
do not rate limit on the loopback interface
Peter Palfrader [Sun, 23 Dec 2018 09:33:01 +0000 (10:33 +0100)]
also close http connections after each request via haproxy
Peter Palfrader [Sun, 23 Dec 2018 09:25:19 +0000 (10:25 +0100)]
for snapshot, disable keep-alive so we can rate-limit better
Peter Palfrader [Sat, 22 Dec 2018 18:05:09 +0000 (19:05 +0100)]
blacklist 198.11.128.0/18
Peter Palfrader [Sat, 22 Dec 2018 17:57:56 +0000 (18:57 +0100)]
Actually drop drom 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 15:43:30 +0000 (16:43 +0100)]
blacklist 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 15:35:53 +0000 (16:35 +0100)]
one ; too many
Peter Palfrader [Sat, 22 Dec 2018 15:35:01 +0000 (16:35 +0100)]
port 6081 is redirected
Peter Palfrader [Sat, 22 Dec 2018 15:29:12 +0000 (16:29 +0100)]
snapshot: try to put a bound on connections per client
Peter Palfrader [Thu, 20 Dec 2018 11:37:04 +0000 (12:37 +0100)]
snapshot: set QS_LocRequestLimitDefault if mod_qos is loaded
Peter Palfrader [Mon, 17 Dec 2018 09:19:44 +0000 (10:19 +0100)]
reload ferm on changes instead of restart
Peter Palfrader [Wed, 12 Dec 2018 13:05:22 +0000 (14:05 +0100)]
Make a snapshot.debian.net vhost, 2
Peter Palfrader [Wed, 12 Dec 2018 13:03:15 +0000 (14:03 +0100)]
Make a snapshot.debian.net vhost
Julien Cristau [Wed, 28 Nov 2018 10:37:13 +0000 (11:37 +0100)]
Drop references to long-gone db.d.o repos
Julien Cristau [Wed, 28 Nov 2018 10:36:28 +0000 (11:36 +0100)]
Use https for *-restricted db.d.o repo too
Julien Cristau [Wed, 28 Nov 2018 10:30:56 +0000 (11:30 +0100)]
Use https to access the db.d.o repo
Julien Cristau [Wed, 28 Nov 2018 09:38:30 +0000 (10:38 +0100)]
Fixup db.d.o archive key for apt consumption, it shouldn't be armored
Julien Cristau [Wed, 28 Nov 2018 08:51:14 +0000 (09:51 +0100)]
Extend lifetime of db.d.o archive key by a year
Julien Cristau [Wed, 28 Nov 2018 08:33:53 +0000 (09:33 +0100)]
Delete old logs on hosts using pybuildd
pybuildd keeps them indefinitely
(https://salsa.debian.org/wb-team/pybuildd/issues/11) so clean up ourselves to
avoid running into ENOSPC.
Julien Cristau [Fri, 23 Nov 2018 09:37:04 +0000 (10:37 +0100)]
Don't try to install obsolete postgresql client packages
Peter Palfrader [Thu, 22 Nov 2018 13:30:23 +0000 (14:30 +0100)]
postfix fail2ban -- ban quicker and longer
Julien Cristau [Thu, 22 Nov 2018 09:47:45 +0000 (10:47 +0100)]
Remove old stuff from obsolete package ignore list
- storace/backuphost don't need old pg anymore
- rainier/rapoport use stable rabbitmq-server
- conova-node* are on stretch
Peter Palfrader [Wed, 21 Nov 2018 09:27:38 +0000 (10:27 +0100)]
lvm ganeti.manda.debian.org: set global_filter
Julien Cristau [Tue, 20 Nov 2018 22:08:19 +0000 (23:08 +0100)]
Update rabbitmq module
Julien Cristau [Tue, 20 Nov 2018 22:07:26 +0000 (23:07 +0100)]
Add puppet/archive module, required for newer puppet/rabbitmq