mirror/dsa-puppet.git
5 years agoInstall srvadmin foo on dell hosts, and move our restricted archive to debian_org...
Julien Cristau [Wed, 7 Nov 2018 21:07:37 +0000 (22:07 +0100)]
Install srvadmin foo on dell hosts, and move our restricted archive to debian_org::apt_restricted

5 years agoand symlink
Peter Palfrader [Wed, 7 Nov 2018 19:22:52 +0000 (20:22 +0100)]
and symlink

5 years agochange megaraid_sas test
Peter Palfrader [Wed, 7 Nov 2018 19:19:00 +0000 (20:19 +0100)]
change megaraid_sas test

5 years agoftp.de.debian.org appears to be unavailable -- switch man-da to ftp2
Peter Palfrader [Wed, 7 Nov 2018 19:09:24 +0000 (20:09 +0100)]
ftp.de.debian.org appears to be unavailable -- switch man-da to ftp2

5 years agodifferent name for aptrepo
Peter Palfrader [Wed, 7 Nov 2018 18:16:04 +0000 (19:16 +0100)]
different name for aptrepo

5 years agofix class
Peter Palfrader [Wed, 7 Nov 2018 18:13:02 +0000 (19:13 +0100)]
fix class

5 years agomegaraid_sas
Peter Palfrader [Wed, 7 Nov 2018 18:11:47 +0000 (19:11 +0100)]
megaraid_sas

5 years agoAdd megaraid_sas facter
Peter Palfrader [Wed, 7 Nov 2018 18:08:38 +0000 (19:08 +0100)]
Add megaraid_sas facter

5 years agoPut grub and kernel on ttyS0 on manda-node0[34]
Julien Cristau [Wed, 7 Nov 2018 09:01:25 +0000 (10:01 +0100)]
Put grub and kernel on ttyS0 on manda-node0[34]

5 years agosetup-dchroot: merge from tor (genname split into function, ubuntu updates)
Peter Palfrader [Tue, 6 Nov 2018 08:04:53 +0000 (09:04 +0100)]
setup-dchroot: merge from tor (genname split into function, ubuntu updates)

- split schroot base name generation into its own function
- if we build an ubuntu chroot, upgrade to the latest packages available
  in -updates and -security of their suite, since it seems they don't
  ever do point releases so you end up with a 4 year old openssl in your
  chroot.

5 years agoTemporarily switch off privacy logging for security.d.o
Julien Cristau [Mon, 5 Nov 2018 19:21:57 +0000 (20:21 +0100)]
Temporarily switch off privacy logging for security.d.o

I want to figure out what clients are still hitting it directly,
especially at specific times, so some insight into User-Agents and
timestamps would be useful.

5 years agoRedirect all of security.d.o to security-cdn
Julien Cristau [Sun, 4 Nov 2018 12:03:42 +0000 (13:03 +0100)]
Redirect all of security.d.o to security-cdn

Instead of just /pool/updates/main/l/linux/*, redirect everything except:
- if coming from fastly or aws
- if coming from nagios or mini-nag
- if using the onion service
- if doing a health check

Eventually we might point the security.d.o name directly at the CDN, but let's
see if this helps already.

5 years agoExclude dsa-check-mirrorsync nagios check from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:11:23 +0000 (16:11 +0100)]
Exclude dsa-check-mirrorsync nagios check from security to security-cdn redirect

5 years agoExclude nagios check_http from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:09:25 +0000 (16:09 +0100)]
Exclude nagios check_http from security to security-cdn redirect

Prep for making that redirect global

6 years agoDisable mod_disk_cache on security-tracker
Julien Cristau [Fri, 2 Nov 2018 12:19:18 +0000 (13:19 +0100)]
Disable mod_disk_cache on security-tracker

6 years agoDrop sibelius from postgres-make-base-backups
Julien Cristau [Thu, 1 Nov 2018 17:34:33 +0000 (18:34 +0100)]
Drop sibelius from postgres-make-base-backups

6 years agoDrop firewall rule for pg @ sibelius
Julien Cristau [Thu, 1 Nov 2018 17:32:53 +0000 (18:32 +0100)]
Drop firewall rule for pg @ sibelius

6 years agoRemove sibelius/snapshot from dsa-check-backuppg
Julien Cristau [Thu, 1 Nov 2018 17:31:31 +0000 (18:31 +0100)]
Remove sibelius/snapshot from dsa-check-backuppg

6 years agounique all ip addresses
Peter Palfrader [Wed, 31 Oct 2018 08:41:50 +0000 (09:41 +0100)]
unique all ip addresses

6 years agoTry a unique around v4addrs
Peter Palfrader [Wed, 31 Oct 2018 08:39:06 +0000 (09:39 +0100)]
Try a unique around v4addrs

6 years agoRevert "sibelius nfs on public net"
Peter Palfrader [Wed, 31 Oct 2018 08:34:17 +0000 (09:34 +0100)]
Revert "sibelius nfs on public net"

This reverts commits 613379c1d1814794d873352a4791c5556eac938f and
1f3cd8bea3ed396c5e1ab35d369e6b72bb27b3f2.

6 years agosibelius nfs on public net, 2
Peter Palfrader [Wed, 31 Oct 2018 08:05:47 +0000 (09:05 +0100)]
sibelius nfs on public net, 2

6 years agosibelius nfs on public net
Peter Palfrader [Wed, 31 Oct 2018 08:05:09 +0000 (09:05 +0100)]
sibelius nfs on public net

6 years agomake fail2ban cleanup job shut up
Peter Palfrader [Tue, 30 Oct 2018 10:18:15 +0000 (11:18 +0100)]
make fail2ban cleanup job shut up

6 years agomove DROP blacklists to ferm prio 005, after munin
Peter Palfrader [Tue, 30 Oct 2018 09:45:11 +0000 (10:45 +0100)]
move DROP blacklists to ferm prio 005, after munin

6 years agomanually create the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:38:18 +0000 (10:38 +0100)]
manually create the subchain

6 years agoprevent the trailing ; after the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:32:31 +0000 (10:32 +0100)]
prevent the trailing ; after the subchain

6 years agomove the fail2ban rules under the dsa-f2b chain
Peter Palfrader [Tue, 30 Oct 2018 09:28:01 +0000 (10:28 +0100)]
move the fail2ban rules under the dsa-f2b chain

6 years agoMove logging and related/established out of ferm.conf into a dsa.d rule
Peter Palfrader [Tue, 30 Oct 2018 09:23:42 +0000 (10:23 +0100)]
Move logging and related/established out of ferm.conf into a dsa.d rule

6 years agomove munin rules from conf.d to the rules dir, 2
Peter Palfrader [Tue, 30 Oct 2018 09:21:31 +0000 (10:21 +0100)]
move munin rules from conf.d to the rules dir, 2

6 years agomove munin rules from conf.d to the rules dir
Peter Palfrader [Tue, 30 Oct 2018 09:20:32 +0000 (10:20 +0100)]
move munin rules from conf.d to the rules dir

6 years agorename interfaces to 50-munin-interfaces
Peter Palfrader [Tue, 30 Oct 2018 09:17:50 +0000 (10:17 +0100)]
rename interfaces to  50-munin-interfaces

6 years agomerge munin_ip v4 and v6 into one rule
Peter Palfrader [Tue, 30 Oct 2018 09:15:25 +0000 (10:15 +0100)]
merge munin_ip v4 and v6 into one rule

6 years agochange default ferm rule priority to 10 from 00
Peter Palfrader [Tue, 30 Oct 2018 09:07:46 +0000 (10:07 +0100)]
change default ferm rule priority to 10 from 00

6 years agoalso govern submission port
Peter Palfrader [Tue, 30 Oct 2018 09:00:46 +0000 (10:00 +0100)]
also govern submission port

6 years agoClean up fail2ban database
Peter Palfrader [Tue, 30 Oct 2018 08:57:53 +0000 (09:57 +0100)]
Clean up fail2ban database

6 years agomore aggressive fail2ban on exim hosts
Peter Palfrader [Sun, 28 Oct 2018 12:05:41 +0000 (13:05 +0100)]
more aggressive fail2ban on exim hosts

6 years agoAdd a second easydns ipv4 address
Peter Palfrader [Tue, 23 Oct 2018 16:29:04 +0000 (18:29 +0200)]
Add a second easydns ipv4 address

6 years agomirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug

6 years agoMake mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug

6 years agoklecker no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug

6 years agoremove debian.fi
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi

We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.

6 years agonetnod call the key netnod-debian-20171122
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-20171122

6 years agotry to switch dnsnodeapi-ACL over to the TSIG key
Peter Palfrader [Wed, 17 Oct 2018 13:11:27 +0000 (15:11 +0200)]
try to switch dnsnodeapi-ACL over to the TSIG key

6 years agotry a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings

6 years agoallow respighi to access udd on ullmann
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann

it's used to create the autoremoval hints

6 years agomerge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule

6 years agoallow ssh from ftpmaster to debug_mirrors
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors

6 years agodebug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter

6 years agoMake hiera's debug_mirror look like debian_mirror
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror

6 years agofix a prefix len in dsa-postgres-udd6
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6

6 years agoRemove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses

6 years agoSet up grub with serial console at leaseweb
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb

6 years agoAdd health check on debian-debug archive backends
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends

6 years agoUsing *:80 as vhost on mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu

everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.

6 years agofix onion_v4_addr in debug class
Peter Palfrader [Fri, 12 Oct 2018 12:28:31 +0000 (14:28 +0200)]
fix onion_v4_addr in debug class

6 years agofix onion role for debug
Peter Palfrader [Fri, 12 Oct 2018 12:26:37 +0000 (14:26 +0200)]
fix onion role for debug

6 years agoput -debug webserver and onion config onto mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:21:04 +0000 (14:21 +0200)]
put -debug webserver and onion config onto mirror-accumu

6 years agodo fail2ban on postfix AUTH attempts on lists.d.o
Peter Palfrader [Fri, 12 Oct 2018 09:11:52 +0000 (11:11 +0200)]
do fail2ban on postfix AUTH attempts on lists.d.o

6 years agoretire old DNS root key
Peter Palfrader [Thu, 11 Oct 2018 16:04:22 +0000 (18:04 +0200)]
retire old DNS root key

6 years agodrop manual blacklist of smtp abusers
Peter Palfrader [Wed, 10 Oct 2018 09:19:35 +0000 (11:19 +0200)]
drop manual blacklist of smtp abusers

6 years agouse fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)
Peter Palfrader [Wed, 10 Oct 2018 09:19:12 +0000 (11:19 +0200)]
use fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)

6 years agoAdd smtp_protocol_error to log_selector
Peter Palfrader [Wed, 10 Oct 2018 08:34:08 +0000 (10:34 +0200)]
Add smtp_protocol_error to log_selector

We want to learn when clients try to use AUTH LOGIN and friends so we
can block them more easily.

6 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:24:14 +0000 (10:24 +0200)]
more

6 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:19:14 +0000 (10:19 +0200)]
more

6 years agonetfilter DROP traffic from some mail abusers
Peter Palfrader [Wed, 10 Oct 2018 08:15:41 +0000 (10:15 +0200)]
netfilter DROP traffic from some mail abusers

6 years agoStart with removing some moszumanska entries (in particular about pg backups). re...
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups).  re: #7513)

6 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4

6 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3

6 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2

6 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls...
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt

6 years agorestart unbound after putting trust anchors in place
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place

6 years agoUse temporary redirects for ports redirects to the wiki
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki

The URLs could change to the website or elsewhere at some point.

Suggested-by: weasel
6 years agoRedirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages

6 years agoAdd workaround for new Tor configuration requirement
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement

See-also: https://trac.torproject.org/projects/tor/ticket/27849

6 years agowe send mail from nagios@. make it exist
Peter Palfrader [Fri, 14 Sep 2018 12:23:39 +0000 (14:23 +0200)]
we send mail from nagios@.  make it exist

6 years agoTry to samhain ignore /var/lib/puppet/clientbucket more
Peter Palfrader [Thu, 23 Aug 2018 07:46:56 +0000 (09:46 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket more

6 years agoand get dependency right
Peter Palfrader [Wed, 22 Aug 2018 09:14:56 +0000 (11:14 +0200)]
and get dependency right

6 years agoAdd munin-async service to the catalog
Peter Palfrader [Wed, 22 Aug 2018 09:14:37 +0000 (11:14 +0200)]
Add munin-async service to the catalog

6 years agoSet munin-async restart time to 10sec
Peter Palfrader [Wed, 22 Aug 2018 09:11:11 +0000 (11:11 +0200)]
Set munin-async restart time to 10sec

Sometimes munin-async fails to start, presumably because it cannot
connect to the running munind yet.  The service file tells it to
restart always, but with the default sleep time before a restart of
100ms we often run into
 systemd[1]: munin-async.service: Start request repeated too quickly.
after 5 fails attempts within a second or two.

Give munind more time to actually launch.

6 years agoStart repro only after we are online
Peter Palfrader [Wed, 22 Aug 2018 08:56:51 +0000 (10:56 +0200)]
Start repro only after we are online

It fails to bind to its IP addresses otherwise.

6 years agoTry to samhain ignore /var/lib/puppet/clientbucket
Peter Palfrader [Wed, 22 Aug 2018 08:15:29 +0000 (10:15 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket

6 years agoAlso ask our nagios check if drbd is fine
Peter Palfrader [Tue, 21 Aug 2018 20:48:10 +0000 (22:48 +0200)]
Also ask our nagios check if drbd is fine

6 years agoganeti-reboot-cluster: wait for drbd to have caught up
Peter Palfrader [Tue, 21 Aug 2018 20:46:34 +0000 (22:46 +0200)]
ganeti-reboot-cluster: wait for drbd to have caught up

6 years agoand a mirror
Peter Palfrader [Tue, 21 Aug 2018 14:04:04 +0000 (16:04 +0200)]
and a mirror

6 years agolarger net
Peter Palfrader [Tue, 21 Aug 2018 14:02:39 +0000 (16:02 +0200)]
larger net

6 years agoone more net
Peter Palfrader [Tue, 21 Aug 2018 14:00:02 +0000 (16:00 +0200)]
one more net

6 years agothe amazon crawlers change IP address as soon as they are blocked
Peter Palfrader [Tue, 21 Aug 2018 13:57:57 +0000 (15:57 +0200)]
the amazon crawlers change IP address as soon as they are blocked

6 years agoblacklist more amazon aws
Peter Palfrader [Tue, 21 Aug 2018 13:48:53 +0000 (15:48 +0200)]
blacklist more amazon aws

6 years agoblacklist 18.185.157.46 and 18.194.174.202
Peter Palfrader [Tue, 21 Aug 2018 10:09:44 +0000 (12:09 +0200)]
blacklist 18.185.157.46 and 18.194.174.202

6 years ago99builddsourceslist: remove jessie-kfreebsd hacks
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: remove jessie-kfreebsd hacks

6 years ago99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security...
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots

Temporarily add stretch-proposed-updates for stretch-security chroots as requested
by the security team to handle Thunderbird and Firefox ESR 60.x releases. This should
be removed with the release of the 9.5 point release.

6 years agosetup-all-dchroots: fix architecture list generation
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
setup-all-dchroots: fix architecture list generation

6 years agoTry one fewer threads per snapshot process
Peter Palfrader [Sun, 19 Aug 2018 20:18:01 +0000 (22:18 +0200)]
Try one fewer threads per snapshot process

6 years agoremove old cleanup items
Peter Palfrader [Sun, 19 Aug 2018 09:44:29 +0000 (11:44 +0200)]
remove old cleanup items

6 years agoMove default webpage from apache to webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:43:10 +0000 (11:43 +0200)]
Move default webpage from apache to webserver module

6 years agoMove creation of /run/dsa/shutdown-marker to a new common webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:38:57 +0000 (11:38 +0200)]
Move creation of /run/dsa/shutdown-marker to a new common webserver module

6 years agosetup-all-dchroots: Support rebuilding just one arch/suite
Peter Palfrader [Thu, 16 Aug 2018 08:08:52 +0000 (10:08 +0200)]
setup-all-dchroots: Support rebuilding just one arch/suite

6 years agosetup-all-dchroots: move DPKGARCH to where it's used
Peter Palfrader [Thu, 16 Aug 2018 08:07:17 +0000 (10:07 +0200)]
setup-all-dchroots: move DPKGARCH to where it's used

6 years agosetup-all-dchroots: remove unused $UNAMEARCH
Peter Palfrader [Thu, 16 Aug 2018 08:05:03 +0000 (10:05 +0200)]
setup-all-dchroots: remove unused $UNAMEARCH