mirror/dsa-puppet.git
5 years agotry a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings

5 years agoallow respighi to access udd on ullmann
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann

it's used to create the autoremoval hints

5 years agomerge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule

5 years agoallow ssh from ftpmaster to debug_mirrors
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors

5 years agodebug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter

5 years agoMake hiera's debug_mirror look like debian_mirror
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror

5 years agofix a prefix len in dsa-postgres-udd6
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6

5 years agoRemove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses

5 years agoSet up grub with serial console at leaseweb
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb

5 years agoAdd health check on debian-debug archive backends
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends

5 years agoUsing *:80 as vhost on mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu

everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.

5 years agofix onion_v4_addr in debug class
Peter Palfrader [Fri, 12 Oct 2018 12:28:31 +0000 (14:28 +0200)]
fix onion_v4_addr in debug class

5 years agofix onion role for debug
Peter Palfrader [Fri, 12 Oct 2018 12:26:37 +0000 (14:26 +0200)]
fix onion role for debug

5 years agoput -debug webserver and onion config onto mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:21:04 +0000 (14:21 +0200)]
put -debug webserver and onion config onto mirror-accumu

5 years agodo fail2ban on postfix AUTH attempts on lists.d.o
Peter Palfrader [Fri, 12 Oct 2018 09:11:52 +0000 (11:11 +0200)]
do fail2ban on postfix AUTH attempts on lists.d.o

5 years agoretire old DNS root key
Peter Palfrader [Thu, 11 Oct 2018 16:04:22 +0000 (18:04 +0200)]
retire old DNS root key

5 years agodrop manual blacklist of smtp abusers
Peter Palfrader [Wed, 10 Oct 2018 09:19:35 +0000 (11:19 +0200)]
drop manual blacklist of smtp abusers

5 years agouse fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)
Peter Palfrader [Wed, 10 Oct 2018 09:19:12 +0000 (11:19 +0200)]
use fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)

5 years agoAdd smtp_protocol_error to log_selector
Peter Palfrader [Wed, 10 Oct 2018 08:34:08 +0000 (10:34 +0200)]
Add smtp_protocol_error to log_selector

We want to learn when clients try to use AUTH LOGIN and friends so we
can block them more easily.

5 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:24:14 +0000 (10:24 +0200)]
more

5 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:19:14 +0000 (10:19 +0200)]
more

5 years agonetfilter DROP traffic from some mail abusers
Peter Palfrader [Wed, 10 Oct 2018 08:15:41 +0000 (10:15 +0200)]
netfilter DROP traffic from some mail abusers

5 years agoStart with removing some moszumanska entries (in particular about pg backups). re...
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups).  re: #7513)

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls...
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt

5 years agorestart unbound after putting trust anchors in place
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place

5 years agoUse temporary redirects for ports redirects to the wiki
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki

The URLs could change to the website or elsewhere at some point.

Suggested-by: weasel
5 years agoRedirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages

5 years agoAdd workaround for new Tor configuration requirement
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement

See-also: https://trac.torproject.org/projects/tor/ticket/27849

5 years agowe send mail from nagios@. make it exist
Peter Palfrader [Fri, 14 Sep 2018 12:23:39 +0000 (14:23 +0200)]
we send mail from nagios@.  make it exist

5 years agoTry to samhain ignore /var/lib/puppet/clientbucket more
Peter Palfrader [Thu, 23 Aug 2018 07:46:56 +0000 (09:46 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket more

5 years agoand get dependency right
Peter Palfrader [Wed, 22 Aug 2018 09:14:56 +0000 (11:14 +0200)]
and get dependency right

5 years agoAdd munin-async service to the catalog
Peter Palfrader [Wed, 22 Aug 2018 09:14:37 +0000 (11:14 +0200)]
Add munin-async service to the catalog

5 years agoSet munin-async restart time to 10sec
Peter Palfrader [Wed, 22 Aug 2018 09:11:11 +0000 (11:11 +0200)]
Set munin-async restart time to 10sec

Sometimes munin-async fails to start, presumably because it cannot
connect to the running munind yet.  The service file tells it to
restart always, but with the default sleep time before a restart of
100ms we often run into
 systemd[1]: munin-async.service: Start request repeated too quickly.
after 5 fails attempts within a second or two.

Give munind more time to actually launch.

5 years agoStart repro only after we are online
Peter Palfrader [Wed, 22 Aug 2018 08:56:51 +0000 (10:56 +0200)]
Start repro only after we are online

It fails to bind to its IP addresses otherwise.

5 years agoTry to samhain ignore /var/lib/puppet/clientbucket
Peter Palfrader [Wed, 22 Aug 2018 08:15:29 +0000 (10:15 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket

5 years agoAlso ask our nagios check if drbd is fine
Peter Palfrader [Tue, 21 Aug 2018 20:48:10 +0000 (22:48 +0200)]
Also ask our nagios check if drbd is fine

5 years agoganeti-reboot-cluster: wait for drbd to have caught up
Peter Palfrader [Tue, 21 Aug 2018 20:46:34 +0000 (22:46 +0200)]
ganeti-reboot-cluster: wait for drbd to have caught up

5 years agoand a mirror
Peter Palfrader [Tue, 21 Aug 2018 14:04:04 +0000 (16:04 +0200)]
and a mirror

5 years agolarger net
Peter Palfrader [Tue, 21 Aug 2018 14:02:39 +0000 (16:02 +0200)]
larger net

5 years agoone more net
Peter Palfrader [Tue, 21 Aug 2018 14:00:02 +0000 (16:00 +0200)]
one more net

5 years agothe amazon crawlers change IP address as soon as they are blocked
Peter Palfrader [Tue, 21 Aug 2018 13:57:57 +0000 (15:57 +0200)]
the amazon crawlers change IP address as soon as they are blocked

5 years agoblacklist more amazon aws
Peter Palfrader [Tue, 21 Aug 2018 13:48:53 +0000 (15:48 +0200)]
blacklist more amazon aws

5 years agoblacklist 18.185.157.46 and 18.194.174.202
Peter Palfrader [Tue, 21 Aug 2018 10:09:44 +0000 (12:09 +0200)]
blacklist 18.185.157.46 and 18.194.174.202

5 years ago99builddsourceslist: remove jessie-kfreebsd hacks
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: remove jessie-kfreebsd hacks

5 years ago99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security...
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots

Temporarily add stretch-proposed-updates for stretch-security chroots as requested
by the security team to handle Thunderbird and Firefox ESR 60.x releases. This should
be removed with the release of the 9.5 point release.

5 years agosetup-all-dchroots: fix architecture list generation
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
setup-all-dchroots: fix architecture list generation

5 years agoTry one fewer threads per snapshot process
Peter Palfrader [Sun, 19 Aug 2018 20:18:01 +0000 (22:18 +0200)]
Try one fewer threads per snapshot process

5 years agoremove old cleanup items
Peter Palfrader [Sun, 19 Aug 2018 09:44:29 +0000 (11:44 +0200)]
remove old cleanup items

5 years agoMove default webpage from apache to webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:43:10 +0000 (11:43 +0200)]
Move default webpage from apache to webserver module

5 years agoMove creation of /run/dsa/shutdown-marker to a new common webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:38:57 +0000 (11:38 +0200)]
Move creation of /run/dsa/shutdown-marker to a new common webserver module

5 years agosetup-all-dchroots: Support rebuilding just one arch/suite
Peter Palfrader [Thu, 16 Aug 2018 08:08:52 +0000 (10:08 +0200)]
setup-all-dchroots: Support rebuilding just one arch/suite

5 years agosetup-all-dchroots: move DPKGARCH to where it's used
Peter Palfrader [Thu, 16 Aug 2018 08:07:17 +0000 (10:07 +0200)]
setup-all-dchroots: move DPKGARCH to where it's used

5 years agosetup-all-dchroots: remove unused $UNAMEARCH
Peter Palfrader [Thu, 16 Aug 2018 08:05:03 +0000 (10:05 +0200)]
setup-all-dchroots: remove unused $UNAMEARCH

5 years agosetup-all-dchroots: documentation comments
Peter Palfrader [Thu, 16 Aug 2018 08:04:53 +0000 (10:04 +0200)]
setup-all-dchroots: documentation comments

5 years agosetup-all-dchroots: We use extraargs as a global variable, write it in caps
Peter Palfrader [Thu, 16 Aug 2018 08:02:23 +0000 (10:02 +0200)]
setup-all-dchroots: We use extraargs as a global variable, write it in caps

5 years agosetup-all-dchroots: get rid of obsolete variable "$extra" that is always the empty...
Peter Palfrader [Thu, 16 Aug 2018 08:01:54 +0000 (10:01 +0200)]
setup-all-dchroots: get rid of obsolete variable "$extra" that is always the empty string

5 years agosetup-all-dchroots: move all main code to after function declarations
Peter Palfrader [Thu, 16 Aug 2018 08:01:01 +0000 (10:01 +0200)]
setup-all-dchroots: move all main code to after function declarations

5 years agosetup-all-dchroots: copy from tor: -c support
Peter Palfrader [Thu, 16 Aug 2018 07:50:34 +0000 (09:50 +0200)]
setup-all-dchroots: copy from tor: -c support

Add option to just write config files.  Also revamps parameter parsing.

5 years agosetup-all-dchroots: tabs to spaces
Peter Palfrader [Thu, 16 Aug 2018 07:40:33 +0000 (09:40 +0200)]
setup-all-dchroots: tabs to spaces

5 years agoAdd bttracker alias to the cdimage maintenance vhost
Julien Cristau [Wed, 15 Aug 2018 17:08:49 +0000 (19:08 +0200)]
Add bttracker alias to the cdimage maintenance vhost

5 years agoCreate missing directory
Julien Cristau [Wed, 15 Aug 2018 06:36:40 +0000 (08:36 +0200)]
Create missing directory

5 years agoPrepare maintenance page for cdimage.d.o and friends
Julien Cristau [Wed, 15 Aug 2018 06:31:18 +0000 (08:31 +0200)]
Prepare maintenance page for cdimage.d.o and friends

5 years agoAdd diversity@d.o to various exim config bits
Héctor Orón Martínez [Tue, 14 Aug 2018 14:18:50 +0000 (16:18 +0200)]
Add diversity@d.o to various exim config bits

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
5 years agoporterbox: install dgit. rt#7366
Héctor Orón Martínez [Sun, 12 Aug 2018 16:03:35 +0000 (18:03 +0200)]
porterbox: install dgit. rt#7366

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
5 years agoDon't manage salsa's /run/redis
Julien Cristau [Tue, 7 Aug 2018 08:44:49 +0000 (10:44 +0200)]
Don't manage salsa's /run/redis

Permissions conflicts with the package's
/usr/lib/tmpfiles.d/redis-server.conf so we keep changing them and
restarting the service needlessly.

5 years agoall our hosts still want stretch::network_online though
Peter Palfrader [Tue, 7 Aug 2018 08:18:02 +0000 (10:18 +0200)]
all our hosts still want stretch::network_online though

5 years agobacula-fd: se ipv6 address from ldap since DNS during boot is icky
Peter Palfrader [Tue, 7 Aug 2018 08:17:05 +0000 (10:17 +0200)]
bacula-fd: se ipv6 address from ldap since DNS during boot is icky

5 years agoget our ipv[46] ldap addresses
Peter Palfrader [Tue, 7 Aug 2018 08:12:31 +0000 (10:12 +0200)]
get our ipv[46] ldap addresses

5 years agobacula-fd: wait for unbound also
Peter Palfrader [Tue, 7 Aug 2018 07:35:08 +0000 (09:35 +0200)]
bacula-fd: wait for unbound also

5 years agoRevert "allow access to pg on vittoria for dc18"
Julien Cristau [Tue, 7 Aug 2018 07:11:57 +0000 (09:11 +0200)]
Revert "allow access to pg on vittoria for dc18"

This reverts commit 21edc51f3c8a84ec014b0f0bffc8ebd972b6b2f2.

5 years agoRevert "RT#7368: add additional IP"
Julien Cristau [Tue, 7 Aug 2018 07:11:53 +0000 (09:11 +0200)]
Revert "RT#7368: add additional IP"

This reverts commit e764ff0ec7eaccac713c15cb4c3fb284649b850b.

5 years agowait until after network-online.target for bacula-fd
Peter Palfrader [Tue, 7 Aug 2018 07:03:15 +0000 (09:03 +0200)]
wait until after network-online.target for bacula-fd

5 years agoDecommission powerpc-osuosl-01
Julien Cristau [Mon, 6 Aug 2018 16:27:22 +0000 (18:27 +0200)]
Decommission powerpc-osuosl-01

5 years agoDecommission powerpc-unicamp-01
Julien Cristau [Mon, 6 Aug 2018 16:03:50 +0000 (18:03 +0200)]
Decommission powerpc-unicamp-01

5 years agoadd 'do not modify' headers
Luca Filipozzi [Mon, 6 Aug 2018 07:48:00 +0000 (00:48 -0700)]
add 'do not modify' headers

Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Mon, 6 Aug 2018 07:20:52 +0000 (00:20 -0700)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Fri, 3 Aug 2018 15:23:44 +0000 (15:23 +0000)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agocomplete RT#7389
Luca Filipozzi [Fri, 3 Aug 2018 10:22:24 +0000 (10:22 +0000)]
complete RT#7389

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agore-add vhost after x509 certificate issuance
Luca Filipozzi [Fri, 3 Aug 2018 10:07:14 +0000 (10:07 +0000)]
re-add vhost after x509 certificate issuance

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agorevert vhost until x509 cert deployed
Luca Filipozzi [Fri, 3 Aug 2018 09:43:22 +0000 (09:43 +0000)]
revert vhost until x509 cert deployed

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Fri, 3 Aug 2018 09:36:00 +0000 (09:36 +0000)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agobacula-sd: listen on ipv6
Peter Palfrader [Fri, 3 Aug 2018 07:59:54 +0000 (09:59 +0200)]
bacula-sd: listen on ipv6

5 years agoallow ipv6 connections to all clients from the bacula director
Peter Palfrader [Fri, 3 Aug 2018 07:56:57 +0000 (09:56 +0200)]
allow ipv6 connections to all clients from the bacula director

5 years agobacula-ferm: we do not need to explicitly allow connections from localhost
Peter Palfrader [Fri, 3 Aug 2018 07:56:39 +0000 (09:56 +0200)]
bacula-ferm: we do not need to explicitly allow connections from localhost

5 years agowhitespace fix
Peter Palfrader [Fri, 3 Aug 2018 07:53:12 +0000 (09:53 +0200)]
whitespace fix

5 years agobacula: reorder a statement (should cause no effective change)
Peter Palfrader [Fri, 3 Aug 2018 07:53:05 +0000 (09:53 +0200)]
bacula: reorder a statement (should cause no effective change)

5 years agoadd Forwarded-For header
Peter Palfrader [Tue, 31 Jul 2018 11:15:05 +0000 (13:15 +0200)]
add Forwarded-For header

5 years agowhitespace fixup
Peter Palfrader [Tue, 31 Jul 2018 11:14:51 +0000 (13:14 +0200)]
whitespace fixup

5 years agoadd a ,
Peter Palfrader [Tue, 31 Jul 2018 08:30:10 +0000 (10:30 +0200)]
add a ,

5 years agobacula-fd: listen on both ipv4 and ipv6
Peter Palfrader [Tue, 31 Jul 2018 08:27:18 +0000 (10:27 +0200)]
bacula-fd: listen on both ipv4 and ipv6

5 years agoAdd has_v[46]_ldap key to nodeinfo['misc'] to say whether we have a v[46] address...
Peter Palfrader [Tue, 31 Jul 2018 08:22:15 +0000 (10:22 +0200)]
Add has_v[46]_ldap key to nodeinfo['misc'] to say whether we have a v[46] address in ldap

5 years agoretire old cleanup job for ip6_ munin plugins
Peter Palfrader [Tue, 31 Jul 2018 08:21:18 +0000 (10:21 +0200)]
retire old cleanup job for ip6_ munin plugins

5 years agoMake sure nodeinfo['misc']['v[46]addrs'] always exists, possibly empty.
Peter Palfrader [Tue, 31 Jul 2018 08:19:37 +0000 (10:19 +0200)]
Make sure nodeinfo['misc']['v[46]addrs'] always exists, possibly empty.

5 years agoferm/munin: use already split v[46]addrs for munin addresses
Peter Palfrader [Tue, 31 Jul 2018 08:10:59 +0000 (10:10 +0200)]
ferm/munin: use already split v[46]addrs for munin addresses

5 years agoFix metadata-backend.ftp-master.d.o redirects
Julien Cristau [Tue, 31 Jul 2018 06:34:54 +0000 (08:34 +0200)]
Fix metadata-backend.ftp-master.d.o redirects

5 years agodsa-bacula-scheduler: one more backup slot
Peter Palfrader [Tue, 31 Jul 2018 06:04:18 +0000 (08:04 +0200)]
dsa-bacula-scheduler: one more backup slot

5 years agoMake metadata-backend.ftp-master hopefully work
Julien Cristau [Tue, 31 Jul 2018 05:34:50 +0000 (07:34 +0200)]
Make metadata-backend.ftp-master hopefully work