Martin Zobel-Helas [Thu, 7 Aug 2014 11:15:20 +0000 (13:15 +0200)]
block nasty 404 spam that is sent to webmaster@debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Tollef Fog Heen [Sun, 27 Jul 2014 20:32:12 +0000 (22:32 +0200)]
Add delaycompress to munin-node logrotate file to reduce cron spam
Peter Palfrader [Sun, 27 Jul 2014 19:37:20 +0000 (21:37 +0200)]
make coccia an ftp upload host
Peter Palfrader [Sun, 27 Jul 2014 18:27:00 +0000 (20:27 +0200)]
Listen on all port 22s
Martin Zobel-Helas [Sun, 27 Jul 2014 12:06:53 +0000 (14:06 +0200)]
looks like SSH want it this way
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sun, 27 Jul 2014 12:00:22 +0000 (14:00 +0200)]
Add extra ports for ssh on paradis
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sun, 27 Jul 2014 11:12:11 +0000 (13:12 +0200)]
people ssl cert
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sun, 27 Jul 2014 11:12:11 +0000 (13:12 +0200)]
people ssl cert
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sun, 27 Jul 2014 09:57:52 +0000 (11:57 +0200)]
add cert for people.debian.org
Tollef Fog Heen [Thu, 24 Jul 2014 20:20:22 +0000 (22:20 +0200)]
Set Surrogate-Key to local host name to make purging obsolete content easier
Peter Palfrader [Thu, 24 Jul 2014 05:47:43 +0000 (07:47 +0200)]
perma redirect and HSTS for lintian
Peter Palfrader [Wed, 23 Jul 2014 20:34:49 +0000 (22:34 +0200)]
Add alioth certs to our cert tree
Peter Palfrader [Wed, 23 Jul 2014 09:42:20 +0000 (11:42 +0200)]
Add debian.org.tw
Peter Palfrader [Tue, 22 Jul 2014 20:35:49 +0000 (22:35 +0200)]
Kill extra space
Peter Palfrader [Tue, 22 Jul 2014 20:34:12 +0000 (22:34 +0200)]
Update the way we populate machine ssh keys for da-backup
Peter Palfrader [Tue, 22 Jul 2014 19:42:47 +0000 (21:42 +0200)]
Move lintian to https
Peter Palfrader [Tue, 22 Jul 2014 19:41:41 +0000 (21:41 +0200)]
Make a common-dsa-vhost-https-redirect macro
Peter Palfrader [Tue, 22 Jul 2014 19:32:47 +0000 (21:32 +0200)]
hsts for bits
Peter Palfrader [Tue, 22 Jul 2014 19:25:58 +0000 (21:25 +0200)]
bits.d.o: redirect everything but /feeds to https
Peter Palfrader [Tue, 22 Jul 2014 19:17:00 +0000 (21:17 +0200)]
More complex bits.debian.org config
Peter Palfrader [Tue, 22 Jul 2014 19:14:20 +0000 (21:14 +0200)]
Comment/reorganize static-vhosts-simple
Peter Palfrader [Tue, 22 Jul 2014 19:10:06 +0000 (21:10 +0200)]
use privacyssl as the log format in two places
Peter Palfrader [Tue, 22 Jul 2014 19:05:13 +0000 (21:05 +0200)]
Merge branch 'new-ssl'
* new-ssl:
ssl::service for bits and lintian
Add chains for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 19:05:08 +0000 (21:05 +0200)]
Add certs for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 17:54:42 +0000 (19:54 +0200)]
ssl::service for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 17:53:29 +0000 (19:53 +0200)]
Add chains for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 08:49:54 +0000 (10:49 +0200)]
Add lintian vhost
Peter Palfrader [Tue, 22 Jul 2014 06:59:45 +0000 (08:59 +0200)]
lintian can trigger static update component
Peter Palfrader [Tue, 22 Jul 2014 06:56:30 +0000 (08:56 +0200)]
lilburn is a static source
Peter Palfrader [Mon, 21 Jul 2014 18:39:41 +0000 (20:39 +0200)]
enable lintian static service (RT#5166)
Peter Palfrader [Mon, 21 Jul 2014 16:04:24 +0000 (18:04 +0200)]
Accept tftp from 192.168.43.0/24 on master
Peter Palfrader [Sun, 20 Jul 2014 10:19:12 +0000 (12:19 +0200)]
Different log rules for http vs. https
Peter Palfrader [Sat, 19 Jul 2014 11:14:22 +0000 (13:14 +0200)]
restrict security-master's rsync for the archive, II
Peter Palfrader [Sat, 19 Jul 2014 10:57:14 +0000 (12:57 +0200)]
restrict security-master's rsync for the archive
Peter Palfrader [Fri, 18 Jul 2014 08:30:42 +0000 (10:30 +0200)]
Default to 3.3 syslog-ng if version is not otherwise handled
Peter Palfrader [Sun, 13 Jul 2014 20:18:53 +0000 (22:18 +0200)]
retire lw05, lw06
Peter Palfrader [Sun, 13 Jul 2014 19:51:47 +0000 (21:51 +0200)]
ipv6 fw updates for lw
Peter Palfrader [Sun, 13 Jul 2014 19:21:29 +0000 (21:21 +0200)]
nat to varnish on lw07
Peter Palfrader [Sun, 13 Jul 2014 17:45:05 +0000 (19:45 +0200)]
allow lw07 access to sibelius postgres
Peter Palfrader [Sun, 13 Jul 2014 12:58:33 +0000 (14:58 +0200)]
Prepare to move postgres to lw07
Peter Palfrader [Sun, 13 Jul 2014 12:10:46 +0000 (14:10 +0200)]
Do not mount qa ro
Peter Palfrader [Sun, 13 Jul 2014 12:07:49 +0000 (14:07 +0200)]
Add qa.d.o
Peter Palfrader [Sun, 13 Jul 2014 07:46:48 +0000 (09:46 +0200)]
set debian mirror for csail
Peter Palfrader [Sat, 12 Jul 2014 22:21:04 +0000 (00:21 +0200)]
autofs on lw0[78]
Peter Palfrader [Sat, 12 Jul 2014 22:18:28 +0000 (00:18 +0200)]
Different srv/build-trees mount on the freebsds
Peter Palfrader [Sat, 12 Jul 2014 14:06:08 +0000 (16:06 +0200)]
Disable proposed-updates
Peter Palfrader [Sat, 12 Jul 2014 11:03:18 +0000 (13:03 +0200)]
set HISTCONTROL in root's bashrc. Only set stuff when running interactively
Peter Palfrader [Sat, 12 Jul 2014 10:35:29 +0000 (12:35 +0200)]
Deploy /etc/schroot/buildd/fstab via puppet
Peter Palfrader [Sat, 12 Jul 2014 10:32:16 +0000 (12:32 +0200)]
Remove /etc/schroot/mount-defaults
Peter Palfrader [Sat, 12 Jul 2014 09:56:32 +0000 (11:56 +0200)]
Move some of the porterbox schroot logic to the schroot module that is shared with buildd
Peter Palfrader [Sat, 12 Jul 2014 09:37:48 +0000 (11:37 +0200)]
Guard schroot setup scripts with PROFILE = dsa
Peter Palfrader [Sat, 12 Jul 2014 09:17:34 +0000 (11:17 +0200)]
Deploy initial ssh_known_hosts using puppet
Peter Palfrader [Sat, 12 Jul 2014 09:02:44 +0000 (09:02 +0000)]
Try to work if $::hoster is not yet defined
Peter Palfrader [Sat, 12 Jul 2014 08:56:22 +0000 (10:56 +0200)]
Do not backup mipsel-manda-*
Martin Zobel-Helas [Fri, 11 Jul 2014 20:55:58 +0000 (22:55 +0200)]
add ip for mfl
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 11 Jul 2014 20:51:26 +0000 (22:51 +0200)]
Revert "allow mfl to access adayevskaya via ssh"
This reverts commit
8e8a82b008d3b5845fb96f4e87d9417556b4cf7f.
Martin Zobel-Helas [Fri, 11 Jul 2014 20:42:58 +0000 (22:42 +0200)]
allow mfl to access adayevskaya via ssh
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Fri, 11 Jul 2014 19:25:47 +0000 (21:25 +0200)]
fix rule
Peter Palfrader [Fri, 11 Jul 2014 19:22:16 +0000 (21:22 +0200)]
firewall: restrict tftp on abel and jenkins to local networks
Peter Palfrader [Fri, 11 Jul 2014 19:21:12 +0000 (21:21 +0200)]
firewall: tftp on master, no more tftp on rietz
Héctor Orón Martínez [Wed, 9 Jul 2014 11:22:36 +0000 (13:22 +0200)]
portman: does not need ssh all buildd
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Peter Palfrader [Wed, 9 Jul 2014 06:12:05 +0000 (08:12 +0200)]
Revert "postgres: add wanna-build-ports in the base backups"
This reverts commit
fe22b3b8f19a26c1c1d698e17c048f402246d183.
Héctor Orón Martínez [Tue, 8 Jul 2014 23:03:05 +0000 (01:03 +0200)]
sudo: add wbadm-ports
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Héctor Orón Martínez [Tue, 8 Jul 2014 23:01:01 +0000 (01:01 +0200)]
postgres: add wanna-build-ports in the base backups
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Héctor Orón Martínez [Tue, 8 Jul 2014 22:58:09 +0000 (00:58 +0200)]
ferm: update -ports rules
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Martin Zobel-Helas [Tue, 8 Jul 2014 22:12:47 +0000 (00:12 +0200)]
new wiki.debian.org cert
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Tue, 8 Jul 2014 18:08:27 +0000 (20:08 +0200)]
only wheezy and squeeze on ia64
Héctor Orón Martínez [Tue, 8 Jul 2014 00:46:37 +0000 (02:46 +0200)]
portman: allow postgress access
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Peter Palfrader [Mon, 7 Jul 2014 12:33:40 +0000 (14:33 +0200)]
w-p-u at brown
Peter Palfrader [Mon, 7 Jul 2014 12:33:01 +0000 (14:33 +0200)]
Add "brown's" debian mirror URL
Peter Palfrader [Mon, 7 Jul 2014 10:06:30 +0000 (12:06 +0200)]
Except that doesn't work
Peter Palfrader [Mon, 7 Jul 2014 10:05:14 +0000 (12:05 +0200)]
cluster_nodes is now an array
Peter Palfrader [Mon, 7 Jul 2014 10:02:29 +0000 (12:02 +0200)]
Try new factor that also works on non-master-candiate nodes
Peter Palfrader [Mon, 7 Jul 2014 06:40:54 +0000 (08:40 +0200)]
Make sure we get rid of os-prober everywhere
Peter Palfrader [Sat, 5 Jul 2014 10:55:14 +0000 (12:55 +0200)]
p-u at man-da
Peter Palfrader [Sat, 5 Jul 2014 07:58:08 +0000 (09:58 +0200)]
Try to enable p-u at bm
Peter Palfrader [Sat, 5 Jul 2014 07:53:54 +0000 (09:53 +0200)]
Clear proposed-updates repo from hosts that do not have it now according to puppet
Peter Palfrader [Fri, 4 Jul 2014 20:26:20 +0000 (22:26 +0200)]
Pass --directory=/ to schroot
Peter Palfrader [Thu, 3 Jul 2014 09:16:18 +0000 (11:16 +0200)]
Deploy qa.d.o cert on qamaster
Peter Palfrader [Thu, 3 Jul 2014 09:15:34 +0000 (11:15 +0200)]
Add cert for qa.d.o
Peter Palfrader [Thu, 3 Jul 2014 06:45:15 +0000 (08:45 +0200)]
Fix two chains
Peter Palfrader [Thu, 3 Jul 2014 06:39:12 +0000 (08:39 +0200)]
Add chain for qa.d.o
Peter Palfrader [Thu, 3 Jul 2014 06:25:06 +0000 (08:25 +0200)]
Deploy packages.qa.d.o cert on packagesqamaster
Peter Palfrader [Thu, 3 Jul 2014 06:23:55 +0000 (08:23 +0200)]
Add packages.qa.d.o cert
Peter Palfrader [Wed, 2 Jul 2014 20:01:10 +0000 (22:01 +0200)]
Add chain for packages.qa.d.o
Peter Palfrader [Mon, 30 Jun 2014 15:41:31 +0000 (17:41 +0200)]
Revert "change from debian.netcologne.de to mirror.unitedcolo.de"
This reverts commit
2a93a38ee61beb5ffdab93659d32a387f95a18d1.
mirror.unitedcolo.de is unreachable.
Peter Palfrader [Mon, 30 Jun 2014 15:40:43 +0000 (17:40 +0200)]
pettersson gets proposed-updates for now
Peter Palfrader [Mon, 30 Jun 2014 12:13:31 +0000 (14:13 +0200)]
Fix Alias for /debian-security
Peter Palfrader [Sun, 29 Jun 2014 12:22:38 +0000 (12:22 +0000)]
Fix tracker chain
Stephen Gran [Sun, 29 Jun 2014 12:10:07 +0000 (13:10 +0100)]
add manualroute tracker -> ticharich
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 29 Jun 2014 11:59:10 +0000 (12:59 +0100)]
tracker.d.o mail vhost
Signed-off-by: Stephen Gran <steve@lobefin.net>
Luca Filipozzi [Sat, 28 Jun 2014 19:17:19 +0000 (19:17 +0000)]
remove LANG and LANGUAGE from profile
Luca Filipozzi [Sat, 28 Jun 2014 18:59:26 +0000 (18:59 +0000)]
put /root/.profile under puppet control, too
Martin Zobel-Helas [Fri, 27 Jun 2014 21:19:00 +0000 (23:19 +0200)]
add hiera for tracker
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 27 Jun 2014 20:33:48 +0000 (22:33 +0200)]
add ssl cert for tracker.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Thu, 26 Jun 2014 20:34:45 +0000 (22:34 +0200)]
Merge branch 'merge'
* merge:
security_mirror: use /srv/ instead of deprecated /org/
Simon Paillard [Thu, 26 Jun 2014 17:30:31 +0000 (19:30 +0200)]
security_mirror: use /srv/ instead of deprecated /org/
Signed-off-by: Peter Palfrader <peter@palfrader.org>
Peter Palfrader [Thu, 26 Jun 2014 20:30:06 +0000 (22:30 +0200)]
Change /org to /srv in security rsync.conf
Martin Zobel-Helas [Wed, 25 Jun 2014 20:51:37 +0000 (22:51 +0200)]
add paradis.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 25 Jun 2014 20:10:00 +0000 (22:10 +0200)]
add paradis LUN information
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>