Peter Palfrader [Mon, 13 May 2019 15:37:46 +0000 (17:37 +0200)]
more amazon networks to blacklist
Peter Palfrader [Sun, 12 May 2019 18:55:49 +0000 (20:55 +0200)]
blacklist 95.115.66.23
Peter Palfrader [Sun, 12 May 2019 18:54:30 +0000 (20:54 +0200)]
blacklist 63.32.0.0/14
Peter Palfrader [Mon, 29 Apr 2019 07:05:12 +0000 (09:05 +0200)]
Order sometimes matters because ifupdown is ... ifupdown
Julien Cristau [Wed, 24 Apr 2019 20:21:02 +0000 (22:21 +0200)]
release.d.o: don't serve *.wml as text/vnd.wap.wml
Héctor Orón Martínez [Mon, 15 Apr 2019 09:10:45 +0000 (11:10 +0200)]
Add cloudaccounts@d.o to spam filters
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Tollef Fog Heen [Sat, 13 Apr 2019 20:39:14 +0000 (22:39 +0200)]
Comment out code again
Tollef Fog Heen [Sat, 13 Apr 2019 20:35:35 +0000 (22:35 +0200)]
A bit of debug information
Tollef Fog Heen [Sat, 13 Apr 2019 20:33:33 +0000 (22:33 +0200)]
Enable banner setting
Tollef Fog Heen [Sat, 13 Apr 2019 20:32:11 +0000 (22:32 +0200)]
A bit of formatting
Tollef Fog Heen [Sat, 13 Apr 2019 20:30:36 +0000 (22:30 +0200)]
Second attempt at split sshd settings
Tollef Fog Heen [Sat, 13 Apr 2019 20:17:01 +0000 (22:17 +0200)]
Remove exploratory code for now
Tollef Fog Heen [Sat, 13 Apr 2019 20:15:24 +0000 (22:15 +0200)]
Kinda-noop-change to fix up bits
Tollef Fog Heen [Sat, 13 Apr 2019 20:14:06 +0000 (22:14 +0200)]
Fix up commenting again
Tollef Fog Heen [Sat, 13 Apr 2019 20:13:24 +0000 (22:13 +0200)]
Ruby syntax fixups
Tollef Fog Heen [Sat, 13 Apr 2019 20:11:23 +0000 (22:11 +0200)]
More commenting out
Tollef Fog Heen [Sat, 13 Apr 2019 20:10:02 +0000 (22:10 +0200)]
Comment out code to not break stuff
Tollef Fog Heen [Sat, 13 Apr 2019 20:09:41 +0000 (22:09 +0200)]
More data structure wrangling
Tollef Fog Heen [Sat, 13 Apr 2019 20:06:31 +0000 (22:06 +0200)]
Add address masks
Tollef Fog Heen [Sat, 13 Apr 2019 20:02:19 +0000 (22:02 +0200)]
Initial work on splitting sshd settings between source = debian.org and not
Tollef Fog Heen [Sat, 13 Apr 2019 18:27:44 +0000 (20:27 +0200)]
Remove old cleanup rule
/etc/exim4/Git is unlikely to reappear and has been removed for almost six years, time to drop this
Tollef Fog Heen [Sat, 13 Apr 2019 10:02:00 +0000 (12:02 +0200)]
Revert "Temporarily expose /srv/mirrors/debian on archive through rsync"
No longer needed.
This reverts commit
77541134868bf310b24f78afe538b0bd526442f5.
Tollef Fog Heen [Sat, 13 Apr 2019 07:54:33 +0000 (09:54 +0200)]
Temporarily expose /srv/mirrors/debian on archive through rsync
Peter Palfrader [Fri, 12 Apr 2019 13:44:36 +0000 (15:44 +0200)]
modify 3rdparty/modules/certregen/manifests/client to set the user and group that puppet enforces anyhow
Peter Palfrader [Fri, 12 Apr 2019 13:01:24 +0000 (15:01 +0200)]
bacula: 'E' also indicates a failed job
Peter Palfrader [Fri, 12 Apr 2019 12:46:12 +0000 (14:46 +0200)]
ipsec: replace auto=start/closeaction=restart with just auto=route to avoid restart loops
Peter Palfrader [Thu, 11 Apr 2019 10:54:10 +0000 (12:54 +0200)]
new bacula 9 no longer does pg service=...
Peter Palfrader [Thu, 11 Apr 2019 10:36:38 +0000 (12:36 +0200)]
bacula: merge parts of the bacula 9 config
Laura Arjona Reina [Wed, 10 Apr 2019 08:32:03 +0000 (10:32 +0200)]
Add redirection for debian.org/misc/bsd.license RT#7733
Add redirection for bsd.license document, removed from
www.debian.org repository (Bug #924888).
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Aurelien Jarno [Mon, 8 Apr 2019 19:14:17 +0000 (21:14 +0200)]
Enable backports on buster
Peter Palfrader [Sat, 6 Apr 2019 12:52:15 +0000 (14:52 +0200)]
we do headers by default
Peter Palfrader [Sat, 6 Apr 2019 12:51:01 +0000 (14:51 +0200)]
add apache::headers
Peter Palfrader [Sat, 6 Apr 2019 12:50:26 +0000 (14:50 +0200)]
snapshot: follow redirects to /file/<hash> in varnish
Peter Palfrader [Sat, 6 Apr 2019 12:45:01 +0000 (14:45 +0200)]
Snapshot: do requests for /file/<hash> directly from the filesystem
Aurelien Jarno [Fri, 5 Apr 2019 20:39:21 +0000 (22:39 +0200)]
Fix thinko in previous commit
Aurelien Jarno [Fri, 5 Apr 2019 20:22:54 +0000 (22:22 +0200)]
/dev/hwrng on s390x appeared with buster but is not functional
Julien Cristau [Wed, 3 Apr 2019 13:17:22 +0000 (15:17 +0200)]
Drop traffic from 220.243.135/24 220.243.136/24 on bugs.d.o
Aurelien Jarno [Wed, 3 Apr 2019 08:59:51 +0000 (10:59 +0200)]
Use the new local timeservers for timesyncd at manda
Aurelien Jarno [Wed, 3 Apr 2019 08:35:22 +0000 (10:35 +0200)]
Use modern cryptography for NTP keys
Aurelien Jarno [Wed, 3 Apr 2019 08:13:31 +0000 (10:13 +0200)]
Allow access to dak@bmdb1 from ullmann
Aurelien Jarno [Wed, 3 Apr 2019 08:06:54 +0000 (10:06 +0200)]
Allow access to wanna-build@bmdb1 from respighi
Tollef Fog Heen [Tue, 2 Apr 2019 18:33:51 +0000 (20:33 +0200)]
Add missing slash in redirectmatch
Julien Cristau [Tue, 2 Apr 2019 11:42:26 +0000 (13:42 +0200)]
Redirect /debian to /debian/ on ftp.d.o and friends
Aurelien Jarno [Tue, 2 Apr 2019 11:02:20 +0000 (13:02 +0200)]
Allow access to ullmann from wuiet
Aurelien Jarno [Mon, 1 Apr 2019 16:04:22 +0000 (18:04 +0200)]
syslog-ng.conf: add support for buster
Aurelien Jarno [Mon, 1 Apr 2019 16:03:09 +0000 (18:03 +0200)]
syslog-ng.conf: drop support for versions older than jessie
Aurelien Jarno [Mon, 1 Apr 2019 15:57:36 +0000 (17:57 +0200)]
Fix syslogversion facter for 2 digits versions
Aurelien Jarno [Mon, 1 Apr 2019 15:58:48 +0000 (17:58 +0200)]
Add missing new files from commit
131e09855e06
Aurelien Jarno [Mon, 1 Apr 2019 13:35:35 +0000 (15:35 +0200)]
Allow nagios to check the SSL CA cert
Aurelien Jarno [Mon, 1 Apr 2019 13:23:25 +0000 (15:23 +0200)]
Now -backports or -updates for jessie
Aurelien Jarno [Mon, 1 Apr 2019 12:56:20 +0000 (14:56 +0200)]
rsync-ssh-wrap: add allowed_rsyncs for buster
Aurelien Jarno [Mon, 1 Apr 2019 10:53:58 +0000 (12:53 +0200)]
Remove kfreebsd left-over
Aurelien Jarno [Mon, 1 Apr 2019 09:10:27 +0000 (11:10 +0200)]
More mirror-conova decomissioning
Aurelien Jarno [Mon, 1 Apr 2019 09:05:15 +0000 (11:05 +0200)]
decomission mirror-conova
Aurelien Jarno [Sun, 31 Mar 2019 22:05:19 +0000 (00:05 +0200)]
Update puppetlabs/stdlib module
Aurelien Jarno [Sun, 31 Mar 2019 20:25:31 +0000 (22:25 +0200)]
No backports for buster
Aurelien Jarno [Sun, 31 Mar 2019 20:11:57 +0000 (22:11 +0200)]
Drop squeeze support
Aurelien Jarno [Sat, 30 Mar 2019 12:16:04 +0000 (13:16 +0100)]
Add the certregen::client class to all nodes
Aurelien Jarno [Sat, 30 Mar 2019 12:13:17 +0000 (13:13 +0100)]
Add puppetlabs/certregen module
Aurelien Jarno [Sat, 23 Mar 2019 12:43:58 +0000 (13:43 +0100)]
Add trabaci
Aurelien Jarno [Sat, 23 Mar 2019 11:58:40 +0000 (12:58 +0100)]
Add trabaci volumes
Julien Cristau [Mon, 18 Mar 2019 15:16:40 +0000 (16:16 +0100)]
Move more hiera stuff from mirror-conova to schmelzer
Julien Cristau [Mon, 18 Mar 2019 15:14:11 +0000 (16:14 +0100)]
Fix typo that caused missing debug mirror on schmelzer
Also add the right parameters.
Julien Cristau [Mon, 18 Mar 2019 14:51:31 +0000 (15:51 +0100)]
schmelzer has /srv/mirrors/public-debian, use it
Helps keep things in sync with other mirrors that are its downstreams.
Julien Cristau [Sun, 17 Mar 2019 18:12:25 +0000 (19:12 +0100)]
ganeti: add ganeti2-osuosl ip range
No dedicated private network for now, just trying things out.
Julien Cristau [Sun, 17 Mar 2019 16:01:39 +0000 (17:01 +0100)]
Fix rsync setup on schmelzer
Aurelien Jarno [Sun, 17 Mar 2019 12:36:15 +0000 (13:36 +0100)]
Decommission lully.d.o
Replaced by loghost-osuosl-01
Peter Palfrader [Fri, 15 Mar 2019 10:20:07 +0000 (11:20 +0100)]
blacklist 211.13.205.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:19:35 +0000 (11:19 +0100)]
blacklist 84.204.194.0/24
Julien Cristau [Fri, 15 Mar 2019 10:14:37 +0000 (11:14 +0100)]
syslog: fix longstanding hostname typo
Looks like this has been around since
d6761ce0180c2b4ac9f90e744fa34416ee68ae48
in 2013.
Peter Palfrader [Fri, 15 Mar 2019 10:14:46 +0000 (11:14 +0100)]
blacklist 159.226.95.0/24
Julien Cristau [Thu, 14 Mar 2019 13:16:02 +0000 (14:16 +0100)]
Add cron script to compress and clean up logs on syslog hosts
Peter Palfrader [Mon, 11 Mar 2019 08:59:43 +0000 (09:59 +0100)]
remove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home
Peter Palfrader [Mon, 11 Mar 2019 08:56:03 +0000 (09:56 +0100)]
Add lw08 to the snapshot_shell role and give ftp-master some infra there
Peter Palfrader [Sat, 9 Mar 2019 10:37:25 +0000 (11:37 +0100)]
Stop making nsswitch executable
Aurelien Jarno [Fri, 8 Mar 2019 20:16:38 +0000 (21:16 +0100)]
lvm setup for pieta
Aurelien Jarno [Fri, 8 Mar 2019 18:18:39 +0000 (19:18 +0100)]
move incoming smtp to port 2025 on smit.d.o
Aurelien Jarno [Thu, 7 Mar 2019 20:48:05 +0000 (21:48 +0100)]
Add smit
Julien Cristau [Tue, 5 Mar 2019 19:36:49 +0000 (20:36 +0100)]
Add debconf.org cert
Julien Cristau [Tue, 5 Mar 2019 19:33:24 +0000 (20:33 +0100)]
Take over debconf.org with a redirect to www
Julien Cristau [Fri, 1 Mar 2019 13:33:15 +0000 (14:33 +0100)]
Add schmelzer to a couple more things
Julien Cristau [Fri, 1 Mar 2019 13:25:05 +0000 (14:25 +0100)]
Fix mirror-health-security by skipping the security to security-cdn redirect
Julien Cristau [Thu, 28 Feb 2019 13:12:34 +0000 (14:12 +0100)]
add some roles to schmelzer
Julien Cristau [Thu, 21 Feb 2019 12:04:48 +0000 (13:04 +0100)]
mirror-umn console is on COM2
Julien Cristau [Wed, 20 Feb 2019 15:41:49 +0000 (16:41 +0100)]
Add conova ip range
Julien Cristau [Wed, 20 Feb 2019 15:37:11 +0000 (16:37 +0100)]
Add schmelzer
Julien Cristau [Sun, 17 Feb 2019 18:53:59 +0000 (19:53 +0100)]
Decommission kantuser (RT#7583)
Aurelien Jarno [Sun, 17 Feb 2019 06:33:27 +0000 (07:33 +0100)]
add default lvm conf for pijper
Tollef Fog Heen [Sat, 16 Feb 2019 21:07:49 +0000 (22:07 +0100)]
cvs.d.o is gone, drop redirect
Julien Cristau [Sat, 16 Feb 2019 17:04:31 +0000 (18:04 +0100)]
add mekeel-srv (RT#7226)
Julien Cristau [Fri, 8 Feb 2019 07:57:34 +0000 (08:57 +0100)]
syslog-ng: define fastly destination on all log hosts, not just lully
Aurelien Jarno [Mon, 4 Feb 2019 21:00:07 +0000 (22:00 +0100)]
Revert "99builddsourceslist: disable apt redirects in chroots"
This reverts commit
840177adeb15e1a9f23cff136708eb60a10cd3a7.
All the chroots now have an updated apt.
Aurelien Jarno [Sun, 3 Feb 2019 09:59:39 +0000 (10:59 +0100)]
Fix KVM detection for rng-tools
Aurelien Jarno [Sun, 3 Feb 2019 00:22:02 +0000 (01:22 +0100)]
Do not setup grub/kernel serial console on ppc64el VMs
On ppc64el VMs, grub and the kernel automatically switch to the serial
console if there is no video card. OTOH the serial console is not called
ttyS0, so it's better to not try to setup it up manually.
Aurelien Jarno [Sun, 3 Feb 2019 00:09:55 +0000 (01:09 +0100)]
ganeti2: remove qemu-system-ppc64 wrapper
The wrapper ended-up simpler than on arm64, therefore kvm_extra can be
used instead.
Julien Cristau [Mon, 28 Jan 2019 21:43:43 +0000 (22:43 +0100)]
add loghost-osuosl-01
Julien Cristau [Sun, 27 Jan 2019 15:00:27 +0000 (16:00 +0100)]
ganeti2: add wrapper for qemu-system-ppc64
Peter Palfrader [Thu, 24 Jan 2019 12:36:36 +0000 (13:36 +0100)]
empty slapd-ftmg.conf
Peter Palfrader [Thu, 24 Jan 2019 12:35:21 +0000 (13:35 +0100)]
slapd: listen on localhost only
Peter Palfrader [Thu, 24 Jan 2019 12:34:09 +0000 (13:34 +0100)]
Add default /etc/default/slapd