mirror/dsa-puppet.git
5 years agoDrop ftp.ports.debian.org from klecker
Aurelien Jarno [Sat, 21 Sep 2019 16:32:31 +0000 (18:32 +0200)]
Drop ftp.ports.debian.org from klecker

also move roles::ports_mirror::onion_service to new-klecker

5 years agoautofs: pinel is now at ubc
Aurelien Jarno [Sat, 21 Sep 2019 16:30:05 +0000 (18:30 +0200)]
autofs: pinel is now at ubc

5 years agoeximconf.erb: spell smarthost_port better
Peter Palfrader [Sat, 21 Sep 2019 16:26:10 +0000 (18:26 +0200)]
eximconf.erb: spell smarthost_port better

5 years agoeximconf.erb: we want linebreaks after these variable includes
Peter Palfrader [Sat, 21 Sep 2019 16:24:24 +0000 (18:24 +0200)]
eximconf.erb: we want linebreaks after these variable includes

5 years agoAnd fix the smarthost template somewhat
Peter Palfrader [Sat, 21 Sep 2019 16:23:07 +0000 (18:23 +0200)]
And fix the smarthost template somewhat

5 years agoRemove smarthost_port from nodeinfo
Peter Palfrader [Sat, 21 Sep 2019 16:18:59 +0000 (18:18 +0200)]
Remove smarthost_port from nodeinfo

5 years agoAll these files that we ignore on heavy exim hosts have not changed in the last 4...
Peter Palfrader [Sat, 21 Sep 2019 15:58:45 +0000 (17:58 +0200)]
All these files that we ignore on heavy exim hosts have not changed in the last 4+ years on the hosts I checked; stop ignoring them

5 years agoHave the mailrelays store a firewall rule to allow incoming smtp on the other hosts
Peter Palfrader [Sat, 21 Sep 2019 15:34:24 +0000 (17:34 +0200)]
Have the mailrelays store a firewall rule to allow incoming smtp on the other hosts

5 years agoprefix dinis volumes at bm with OLD-
Julien Cristau [Sat, 21 Sep 2019 14:56:13 +0000 (16:56 +0200)]
prefix dinis volumes at bm with OLD-

5 years agodinis is now at manda
Julien Cristau [Sat, 21 Sep 2019 14:08:56 +0000 (16:08 +0200)]
dinis is now at manda

5 years agoprefix lindsay volumes with OLD-
Aurelien Jarno [Sat, 21 Sep 2019 13:44:12 +0000 (15:44 +0200)]
prefix lindsay volumes with OLD-

5 years agostatic: change lintian.debian.org master to static-master-ubc-01.d.o
Aurelien Jarno [Sat, 21 Sep 2019 13:25:07 +0000 (15:25 +0200)]
static: change lintian.debian.org master to static-master-ubc-01.d.o

5 years agoautofs: lindsay is now at ubc
Aurelien Jarno [Sat, 21 Sep 2019 12:36:50 +0000 (14:36 +0200)]
autofs: lindsay is now at ubc

5 years agoadd postgresql-manda-01
Julien Cristau [Sat, 21 Sep 2019 13:05:53 +0000 (15:05 +0200)]
add postgresql-manda-01

5 years agoremove old-style ssh firewalling setup for mirrors/syncproxies
Peter Palfrader [Sat, 21 Sep 2019 11:30:39 +0000 (13:30 +0200)]
remove old-style ssh firewalling setup for mirrors/syncproxies

5 years agoAdd lindsay and pinel volumes at ubc
Aurelien Jarno [Sat, 21 Sep 2019 11:32:57 +0000 (13:32 +0200)]
Add lindsay and pinel volumes at ubc

5 years agolet ports mirrors get triggered from syncproxies
Peter Palfrader [Sat, 21 Sep 2019 11:18:32 +0000 (13:18 +0200)]
let ports mirrors get triggered from syncproxies

5 years agomove syncproxy config into hiera
Peter Palfrader [Sat, 21 Sep 2019 11:15:51 +0000 (13:15 +0200)]
move syncproxy config into hiera

also, syncproxies ssh from their configured IP address.

Further, drop klecker from syncproxy role (that job is moving to smit).

5 years agomirror ssh firewalling setup from ferm/templates/me.conf.erb with roles
Peter Palfrader [Sat, 21 Sep 2019 10:43:31 +0000 (12:43 +0200)]
mirror ssh firewalling setup from ferm/templates/me.conf.erb with roles

In particular:
  debian mirrors can be accessed from syncproxies
  debug mirrors can be accessed from ftp-master
  historical mirrors can be accessed from historical-master
  security mirrors can be accessed from security-master

And from the previous commits:
  syncproxies can be accessed from syncproxies, ftp-master, ports-master, and security-master

5 years agoAdd a minimal historical_master (archive.debian.org-master) role.
Peter Palfrader [Sat, 21 Sep 2019 10:39:32 +0000 (12:39 +0200)]
Add a minimal historical_master (archive.debian.org-master) role.

The master does not have any special rsync config that is not also
preesnt on the mirrors (and currently the historical master also is a
historical mirror).

5 years agoSo now we have ssh::server::from and ssh::server::to, hopefully making it more clear
Peter Palfrader [Sat, 21 Sep 2019 10:35:09 +0000 (12:35 +0200)]
So now we have ssh::server::from and ssh::server::to, hopefully making it more clear

5 years agoI am still unsure how to do tags properly
Peter Palfrader [Sat, 21 Sep 2019 10:33:45 +0000 (12:33 +0200)]
I am still unsure how to do tags properly

5 years agowhitespace/quoting: modules/roles/manifests/*mirror (make lint happy)
Peter Palfrader [Sat, 21 Sep 2019 10:31:28 +0000 (12:31 +0200)]
whitespace/quoting: modules/roles/manifests/*mirror (make lint happy)

5 years agominor naming fixes
Peter Palfrader [Sat, 21 Sep 2019 10:26:20 +0000 (12:26 +0200)]
minor naming fixes

5 years agoon ftp, ports, and security-master: store ssh allows to be collected on the syncproxies
Peter Palfrader [Sat, 21 Sep 2019 10:24:22 +0000 (12:24 +0200)]
on ftp, ports, and security-master: store ssh allows to be collected on the syncproxies

5 years agowhitespace/quoting: modules/roles/manifests/{ftp_master,security_master} (make lint...
Peter Palfrader [Sat, 21 Sep 2019 10:22:50 +0000 (12:22 +0200)]
whitespace/quoting: modules/roles/manifests/{ftp_master,security_master} (make lint happy)

5 years agosyncproxy ssh firewalling
Peter Palfrader [Sat, 21 Sep 2019 10:21:37 +0000 (12:21 +0200)]
syncproxy ssh firewalling

5 years agoDrop OLD-picconi volumes from multipath-bm.conf
Aurelien Jarno [Sat, 21 Sep 2019 10:22:31 +0000 (12:22 +0200)]
Drop OLD-picconi volumes from multipath-bm.conf

They do not exist anymore on the MSA

5 years agoRename unused volume on the bytemark MSA
Aurelien Jarno [Sat, 21 Sep 2019 10:20:27 +0000 (12:20 +0200)]
Rename unused volume on the bytemark MSA

The name matches the one of the MSA. They need to be zeroed at some
point, but we want to postpone that once the VM have been moved out of
bytemark.

5 years agoMake ssh allow tag specific to the target (archvsync role in this case)
Peter Palfrader [Sat, 21 Sep 2019 10:18:54 +0000 (12:18 +0200)]
Make ssh allow tag specific to the target (archvsync role in this case)

5 years agowhitespace/quoting: modules/roles/manifests/syncproxy (make lint happy)
Peter Palfrader [Sat, 21 Sep 2019 10:15:49 +0000 (12:15 +0200)]
whitespace/quoting: modules/roles/manifests/syncproxy (make lint happy)

5 years agoDecommission rusca (RT#7949)
Aurelien Jarno [Sat, 21 Sep 2019 09:58:53 +0000 (11:58 +0200)]
Decommission rusca (RT#7949)

5 years agoretire old-style firewalling for mirrormaster sshing to the mirror nodes
Peter Palfrader [Sat, 21 Sep 2019 10:02:14 +0000 (12:02 +0200)]
retire old-style firewalling for mirrormaster sshing to the mirror nodes

5 years agoAttempt to enable melartin(mirrormaster) to ssh to all the mirrors/syncproxies
Peter Palfrader [Sat, 21 Sep 2019 09:58:58 +0000 (11:58 +0200)]
Attempt to enable melartin(mirrormaster) to ssh to all the mirrors/syncproxies

5 years agoarchvsync_base: use group name rather than gid number
Peter Palfrader [Sat, 21 Sep 2019 09:57:54 +0000 (11:57 +0200)]
archvsync_base: use group name rather than gid number

5 years agowhitespace/quoting: modules/roles/manifests/archvsync_base (make lint happy)
Peter Palfrader [Sat, 21 Sep 2019 09:56:23 +0000 (11:56 +0200)]
whitespace/quoting: modules/roles/manifests/archvsync_base (make lint happy)

5 years agoAttempt to fix new-klecker as debian mirror
Julien Cristau [Sat, 21 Sep 2019 09:41:45 +0000 (11:41 +0200)]
Attempt to fix new-klecker as debian mirror

5 years agonew-klecker as debian mirror
Julien Cristau [Sat, 21 Sep 2019 09:37:59 +0000 (11:37 +0200)]
new-klecker as debian mirror

5 years agoRevert "ferm: open ssh from mirror-master to ports mirror"
Julien Cristau [Sat, 21 Sep 2019 09:33:18 +0000 (11:33 +0200)]
Revert "ferm: open ssh from mirror-master to ports mirror"

This reverts commit 2cdec8fac4eb9511d0e7d1a01523066cbd9d13f6.

5 years agoferm: open ssh from mirror-master to ports mirror
Julien Cristau [Sat, 21 Sep 2019 09:29:33 +0000 (11:29 +0200)]
ferm: open ssh from mirror-master to ports mirror

5 years agonew-klecker as ports mirror
Julien Cristau [Sat, 21 Sep 2019 09:25:14 +0000 (11:25 +0200)]
new-klecker as ports mirror

5 years agoAdd a new volume on a not so broken vdisk for backuphost
Aurelien Jarno [Sat, 21 Sep 2019 08:47:13 +0000 (10:47 +0200)]
Add a new volume on a not so broken vdisk for backuphost

5 years agoRetire unused extranrpeclient role -- the mini-nag host now pushes a storedconf to...
Peter Palfrader [Fri, 20 Sep 2019 18:52:47 +0000 (20:52 +0200)]
Retire unused extranrpeclient role -- the mini-nag host now pushes a storedconf to get nrpe access

5 years agoAnd allow nrpe from the dns master
Peter Palfrader [Fri, 20 Sep 2019 18:49:15 +0000 (20:49 +0200)]
And allow nrpe from the dns master

5 years agouse correct class for concat fragment
Peter Palfrader [Fri, 20 Sep 2019 18:47:41 +0000 (20:47 +0200)]
use correct class for concat fragment

5 years agouse correct class for concat fragment
Peter Palfrader [Fri, 20 Sep 2019 18:46:07 +0000 (20:46 +0200)]
use correct class for concat fragment

5 years agoSwitch nrpe allow-config to store/collect
Peter Palfrader [Fri, 20 Sep 2019 18:44:39 +0000 (20:44 +0200)]
Switch nrpe allow-config to store/collect

5 years agoSwitch nrpe firewalling to store/collect
Peter Palfrader [Fri, 20 Sep 2019 18:33:19 +0000 (20:33 +0200)]
Switch nrpe firewalling to store/collect

5 years agoThe da-backup on lw03 has not been useful in a long time, remove it
Peter Palfrader [Fri, 20 Sep 2019 18:24:46 +0000 (20:24 +0200)]
The da-backup on lw03 has not been useful in a long time, remove it

It was useful for backing up the morgue to storace, but since
lw03 ran out of disk space for morgue probably years ago, we should
not keep this around anymore.

5 years agoRemove spec/octocatalog: its very out of date, and thus probably not as useful. ...
Peter Palfrader [Fri, 20 Sep 2019 18:23:01 +0000 (20:23 +0200)]
Remove spec/octocatalog: its very out of date, and thus probably not as useful.  If we want something like this again, we should find a way that keeps things current and do not interfere with us maintaining this config base

5 years agoonionbalance -> hiera role
Peter Palfrader [Fri, 20 Sep 2019 18:21:45 +0000 (20:21 +0200)]
onionbalance -> hiera role

5 years agoTor#27849 is fixed, remove workaround
Peter Palfrader [Fri, 20 Sep 2019 18:19:12 +0000 (20:19 +0200)]
Tor#27849 is fixed, remove workaround

5 years agomultipath: remove manziarly* and wuiet* (moved to ubc)
Aurelien Jarno [Thu, 19 Sep 2019 19:50:11 +0000 (21:50 +0200)]
multipath: remove manziarly* and wuiet* (moved to ubc)

5 years agoplanet static master is now ubc
Julien Cristau [Wed, 18 Sep 2019 14:47:48 +0000 (16:47 +0200)]
planet static master is now ubc

5 years agoadd philp volume at ubc
Julien Cristau [Wed, 18 Sep 2019 13:41:17 +0000 (15:41 +0200)]
add philp volume at ubc

5 years agoRevert "Use static-master-grnet-01 for incoming.ports.d.o"
Aurelien Jarno [Wed, 18 Sep 2019 11:25:24 +0000 (13:25 +0200)]
Revert "Use static-master-grnet-01 for incoming.ports.d.o"

This reverts commit 7f82f7567d9685920a00a2ac0e888e891b966b7b.

We use /srv/static.debian.org as the source for rsync

5 years agoUse static-master-grnet-01 for incoming.ports.d.o
Aurelien Jarno [Wed, 18 Sep 2019 07:01:35 +0000 (09:01 +0200)]
Use static-master-grnet-01 for incoming.ports.d.o

And drop static_master role from porta

5 years agouse static-master-grnet-01 for bootstrap.debian.net
Aurelien Jarno [Wed, 18 Sep 2019 06:53:06 +0000 (08:53 +0200)]
use static-master-grnet-01 for bootstrap.debian.net

It is located on the same ganeti cluster as boott and is less I/O
starved than dillon.

5 years agostatic: use static-master-ubc-01.d.o as a master for manpages.d.o
Aurelien Jarno [Tue, 17 Sep 2019 19:39:04 +0000 (21:39 +0200)]
static: use static-master-ubc-01.d.o as a master for manpages.d.o

5 years agodebconf19 is not static just yet
Julien Cristau [Tue, 17 Sep 2019 18:00:20 +0000 (20:00 +0200)]
debconf19 is not static just yet

5 years agonew-klecker: enable the static trigger and provide onion services
Aurelien Jarno [Tue, 17 Sep 2019 17:56:40 +0000 (19:56 +0200)]
new-klecker: enable the static trigger and provide onion services

5 years agoEnable more static components for new-klecker
Aurelien Jarno [Tue, 17 Sep 2019 13:48:27 +0000 (15:48 +0200)]
Enable more static components for new-klecker

5 years agoDrop klecker from static_mirror_web
Aurelien Jarno [Tue, 17 Sep 2019 13:48:27 +0000 (15:48 +0200)]
Drop klecker from static_mirror_web

It will be replaced by new-klecker

5 years agoAs we are removing klecker from the static rotation, stop providing (static) onion...
Peter Palfrader [Tue, 17 Sep 2019 13:40:07 +0000 (15:40 +0200)]
As we are removing klecker from the static rotation, stop providing (static) onion services from it

5 years agoAdd new-klecker as a static mirror
Aurelien Jarno [Tue, 17 Sep 2019 12:13:09 +0000 (14:13 +0200)]
Add new-klecker as a static mirror

(not yet triggered)

5 years agopuppet still created /var/lib/misc/thishost/pkglist. remove that
Peter Palfrader [Tue, 17 Sep 2019 09:35:07 +0000 (11:35 +0200)]
puppet still created /var/lib/misc/thishost/pkglist.  remove that

5 years agopush debdeltas only to csail, isc, senfter; dropping klecker
Peter Palfrader [Tue, 17 Sep 2019 09:30:16 +0000 (11:30 +0200)]
push debdeltas only to csail, isc, senfter; dropping klecker

5 years agowuiet is no longer a static_source. apt.buildd.debian.org was retired months ago
Peter Palfrader [Tue, 17 Sep 2019 08:10:26 +0000 (10:10 +0200)]
wuiet is no longer a static_source.  apt.buildd.debian.org was retired months ago

5 years agoports/static mirror: if listen_addr are not explicitly set, use the host's public...
Peter Palfrader [Tue, 17 Sep 2019 08:04:16 +0000 (10:04 +0200)]
ports/static mirror: if listen_addr are not explicitly set, use the host's public IPv4 address for onion purposes

5 years agoUpdate wuiet IP address
Aurelien Jarno [Mon, 16 Sep 2019 23:12:30 +0000 (01:12 +0200)]
Update wuiet IP address

5 years agowannabuild has been moved from bmdb1 to danzi
Aurelien Jarno [Mon, 16 Sep 2019 22:41:32 +0000 (00:41 +0200)]
wannabuild has been moved from bmdb1 to danzi

5 years agowhitespace/quoting: modules/staticsync/manifests/static_mirror.pp (make lint happy)
Peter Palfrader [Mon, 16 Sep 2019 17:05:02 +0000 (19:05 +0200)]
whitespace/quoting: modules/staticsync/manifests/static_mirror.pp (make lint happy)

5 years agoRemove setting env vars in the static_mirror part of puppet-cron
Peter Palfrader [Mon, 16 Sep 2019 17:03:42 +0000 (19:03 +0200)]
Remove setting env vars in the static_mirror part of puppet-cron

This was re-setting MAILTO=root, which is already set at the top level,
and it was also setting PATH to only a subset of what it was before
(dropped the sbins).

5 years agoslapd-ftmg.conf has credentials, lock down modes
Peter Palfrader [Mon, 16 Sep 2019 11:57:24 +0000 (13:57 +0200)]
slapd-ftmg.conf has credentials, lock down modes

5 years agodisable root access to DB
Peter Palfrader [Mon, 16 Sep 2019 11:55:54 +0000 (13:55 +0200)]
disable root access to DB

5 years agoDocument initial database contents
Peter Palfrader [Mon, 16 Sep 2019 11:55:37 +0000 (13:55 +0200)]
Document initial database contents

5 years agoShip an initial ftmg slapd config
Peter Palfrader [Mon, 16 Sep 2019 11:39:59 +0000 (13:39 +0200)]
Ship an initial ftmg slapd config

5 years agosso: add openssh-ldap.schema, re: RT#7454
Peter Palfrader [Mon, 16 Sep 2019 10:28:42 +0000 (12:28 +0200)]
sso: add openssh-ldap.schema, re: RT#7454

5 years agowhitespace/quoting: modules/roles/manifests/static_mirror_web (make lint happy)
Peter Palfrader [Mon, 16 Sep 2019 09:52:46 +0000 (11:52 +0200)]
whitespace/quoting: modules/roles/manifests/static_mirror_web (make lint happy)

5 years agostatic_mirror_web: replace the vhost_listen string with an Array of IP addresses
Peter Palfrader [Mon, 16 Sep 2019 09:50:45 +0000 (11:50 +0200)]
static_mirror_web: replace the vhost_listen string with an Array of IP addresses

5 years agoports_mirror: replace the vhost_listen string with an Array of IP addresses
Peter Palfrader [Mon, 16 Sep 2019 09:38:49 +0000 (11:38 +0200)]
ports_mirror: replace the vhost_listen string with an Array of IP addresses

5 years agowhitespace cleanup
Peter Palfrader [Mon, 16 Sep 2019 09:22:45 +0000 (11:22 +0200)]
whitespace cleanup

5 years agomake dns primary export and keyring host collect firewall rules for the openpgpkey...
Peter Palfrader [Mon, 16 Sep 2019 09:11:50 +0000 (11:11 +0200)]
make dns primary export and keyring host collect firewall rules for the openpgpkey zone transfer; retire old-style dns_primary role

5 years agoshorter rule name
Peter Palfrader [Mon, 16 Sep 2019 09:03:49 +0000 (11:03 +0200)]
shorter rule name

5 years agoIf the name is too long for netfilter, hash it
Peter Palfrader [Mon, 16 Sep 2019 09:02:30 +0000 (11:02 +0200)]
If the name is too long for netfilter, hash it

5 years agomove 3rd party nameserver info from the ferm template to hiera, retire geodns old...
Peter Palfrader [Mon, 16 Sep 2019 08:53:30 +0000 (10:53 +0200)]
move 3rd party nameserver info from the ferm template to hiera, retire geodns old-style role

5 years agore-arrange hieradata/common slightly
Peter Palfrader [Mon, 16 Sep 2019 08:37:25 +0000 (10:37 +0200)]
re-arrange hieradata/common slightly

5 years agopublish, store and collect ferm rules for dns primary access
Peter Palfrader [Mon, 16 Sep 2019 08:30:27 +0000 (10:30 +0200)]
publish, store and collect ferm rules for dns primary access

5 years agowhitespace/quoting: modules/nagiosmanifests/ (make lint happy)
Peter Palfrader [Mon, 16 Sep 2019 08:28:46 +0000 (10:28 +0200)]
whitespace/quoting: modules/nagiosmanifests/ (make lint happy)

5 years agoTry a new ferm rule class
Peter Palfrader [Mon, 16 Sep 2019 08:07:18 +0000 (10:07 +0200)]
Try a new ferm rule class

5 years agowhitespace/quoting: modules/ferm/manifests/ (make lint happy)
Peter Palfrader [Mon, 16 Sep 2019 06:12:22 +0000 (08:12 +0200)]
whitespace/quoting: modules/ferm/manifests/ (make lint happy)

5 years agowhitespace/quoting: modules/named/manifests/ (make lint happy)
Peter Palfrader [Mon, 16 Sep 2019 05:59:35 +0000 (07:59 +0200)]
whitespace/quoting: modules/named/manifests/ (make lint happy)

5 years agothis from setting is the default. no need to pass it on explicitly
Peter Palfrader [Sun, 15 Sep 2019 20:31:37 +0000 (22:31 +0200)]
this from setting is the default.  no need to pass it on explicitly

5 years agoMake ssh puppetkeys mode 0444 (instead of 0644)
Peter Palfrader [Sun, 15 Sep 2019 20:27:59 +0000 (22:27 +0200)]
Make ssh puppetkeys mode 0444 (instead of 0644)

5 years agohandle sync ssh keys for dgit
Peter Palfrader [Sun, 15 Sep 2019 20:21:28 +0000 (22:21 +0200)]
handle sync ssh keys for dgit

The dgit master host (gideon) is available only via ssh to DDs.
it syncs its data to a publicly accessible host (cgi-grnet-01) over
ssh.  Until now the authkeys file was maintained by hand, but
Ian Jackson asked if we could do that in puppet so updates in IP
addresses etc. get automatically handled.

5 years agomigrate packagesmaster and packagesqamaster role
Peter Palfrader [Sun, 15 Sep 2019 19:58:51 +0000 (21:58 +0200)]
migrate packagesmaster and packagesqamaster role

5 years agowhitespace/quoting: modules/exim/manifests/* (make lint happy)
Peter Palfrader [Sun, 15 Sep 2019 19:53:59 +0000 (21:53 +0200)]
whitespace/quoting: modules/exim/manifests/* (make lint happy)

5 years agoPartially migrate the mailrelay role. ferm still needs the old style.
Peter Palfrader [Sun, 15 Sep 2019 19:51:18 +0000 (21:51 +0200)]
Partially migrate the mailrelay role.  ferm still needs the old style.

5 years agoretire bugsmx role
Peter Palfrader [Sun, 15 Sep 2019 19:41:22 +0000 (21:41 +0200)]
retire bugsmx role

5 years agomake sure exim on reger does the rtmaster stuff
Peter Palfrader [Sun, 15 Sep 2019 19:39:02 +0000 (21:39 +0200)]
make sure exim on reger does the rtmaster stuff