mirror/dsa-puppet.git
5 years agoRedirect old DevRef filenames to the new names
Paul Wise [Wed, 25 Jul 2018 06:31:11 +0000 (14:31 +0800)]
Redirect old DevRef filenames to the new names

Requested-by: Stuart Prescott <stuart@debian.org>
Mapping-by: Stuart Prescott <stuart@debian.org>
5 years agoAlso make setting timezone work on debian 9 (stretch)
Peter Palfrader [Wed, 25 Jul 2018 04:50:46 +0000 (06:50 +0200)]
Also make setting timezone work on debian 9 (stretch)

5 years agoDo not install the redirect vhosts on www-staging.d.o
Paul Wise [Wed, 25 Jul 2018 03:40:15 +0000 (11:40 +0800)]
Do not install the redirect vhosts on www-staging.d.o

5 years agoSet vhost_listen variables required by apache-www.debian.org template
Paul Wise [Wed, 25 Jul 2018 03:33:14 +0000 (11:33 +0800)]
Set vhost_listen variables required by apache-debian.org template

Fixes: commit e9c182207bf901dd7689986fc02e5c4e24c4553a

5 years agoAdd www-staging vhost
Paul Wise [Wed, 25 Jul 2018 03:26:34 +0000 (11:26 +0800)]
Add www-staging vhost

It was broken when the website moved to the static.d.o CDN

5 years agoDebian Policy is moving back to multi-page version, revert redirects
Paul Wise [Wed, 25 Jul 2018 02:00:06 +0000 (10:00 +0800)]
Debian Policy is moving back to multi-page version, revert redirects

Partially reverts commit da0b9ba9ce08cd6040aa84513d9f80b611ed8584

5 years agoonionbalance requires a restart whenever tor is retarted
Peter Palfrader [Mon, 23 Jul 2018 16:09:27 +0000 (18:09 +0200)]
onionbalance requires a restart whenever tor is retarted

This change causes onionbalance to get restarted when tor does,
and so onion services don't got stale.

5 years agoPass the Authorization header through to the WSGI app for the DebConf websites
Nicolas Dandrimont [Mon, 23 Jul 2018 14:30:19 +0000 (22:30 +0800)]
Pass the Authorization header through to the WSGI app for the DebConf websites

5 years agoallow snapshot to reload apache2
Peter Palfrader [Sun, 22 Jul 2018 11:01:44 +0000 (13:01 +0200)]
allow snapshot to reload apache2

5 years agoadd archive-master.debian.org to spec/octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:37:41 +0000 (17:37 +0200)]
add archive-debian.org to spec/octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoadd registry.salsa.debian.org to spec/octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:31:57 +0000 (17:31 +0200)]
add registry.salsa.debian.org to spec/octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoadd /etc/ssh/ssh_known_hosts to octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:19:40 +0000 (17:19 +0200)]
add /etc/ssh/ssh_known_hosts to octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoinstall rugged build dependencies in .gitlab-ci.yml
Martin Zobel-Helas [Fri, 20 Jul 2018 15:11:00 +0000 (17:11 +0200)]
install rugged build dependencies in .gitlab-ci.yml

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoAdd facts for sibelius.debian.org to octocatalog
Martin Zobel-Helas [Fri, 20 Jul 2018 14:09:24 +0000 (16:09 +0200)]
Add facts for sibelius.debian.org to octocatalog

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoAdd sallinen to blacklist_acpi_power_meter list
Julien Cristau [Wed, 18 Jul 2018 09:36:46 +0000 (11:36 +0200)]
Add sallinen to blacklist_acpi_power_meter list

5 years agoWe only have puppets >= 3.0 now
Peter Palfrader [Tue, 17 Jul 2018 15:34:34 +0000 (17:34 +0200)]
We only have puppets >= 3.0 now

5 years agorun puppet every 1.5 hrs instead of every 2
Peter Palfrader [Tue, 17 Jul 2018 15:34:08 +0000 (17:34 +0200)]
run puppet every 1.5 hrs instead of every 2

5 years agoRemove wheezy-supporting cruft
Julien Cristau [Tue, 17 Jul 2018 13:10:35 +0000 (15:10 +0200)]
Remove wheezy-supporting cruft

We're no longer running any wheezy hosts.

5 years agofix apache version
Peter Palfrader [Tue, 17 Jul 2018 05:47:23 +0000 (07:47 +0200)]
fix apache version

5 years agoour cipher suite is still the one recommended by mozilla
Peter Palfrader [Tue, 17 Jul 2018 05:46:48 +0000 (07:46 +0200)]
our cipher suite is still the one recommended by mozilla

5 years agoretire smetana
Peter Palfrader [Mon, 16 Jul 2018 15:14:04 +0000 (17:14 +0200)]
retire smetana

5 years agoApparently, no quoting
Peter Palfrader [Sun, 15 Jul 2018 08:58:47 +0000 (10:58 +0200)]
Apparently, no quoting

5 years agoand use template after setting var
Peter Palfrader [Sun, 15 Jul 2018 08:56:30 +0000 (10:56 +0200)]
and use template after setting var

5 years agofix template
Peter Palfrader [Sun, 15 Jul 2018 08:55:13 +0000 (10:55 +0200)]
fix template

5 years agoUse update-ca-certificates to update ca-global on stretch and later
Peter Palfrader [Sun, 15 Jul 2018 08:54:26 +0000 (10:54 +0200)]
Use update-ca-certificates to update ca-global on stretch and later

5 years agoGive us longer to notice degraded boot
Peter Palfrader [Sat, 14 Jul 2018 17:54:31 +0000 (19:54 +0200)]
Give us longer to notice degraded boot

5 years agoonly run /usr/local/sbin/update-ca-certificates-dsa if it exists
Peter Palfrader [Sat, 14 Jul 2018 13:00:33 +0000 (15:00 +0200)]
only run /usr/local/sbin/update-ca-certificates-dsa if it exists

5 years agoAllow debadmin to sudo to codesign
Tollef Fog Heen [Fri, 13 Jul 2018 20:25:50 +0000 (22:25 +0200)]
Allow debadmin to sudo to codesign

5 years agoMake salsa.d.o the default ssl vhost on godard so lame clients can get to it
Julien Cristau [Mon, 9 Jul 2018 18:06:59 +0000 (20:06 +0200)]
Make salsa.d.o the default ssl vhost on godard so lame clients can get to it

Apparently bzr still doesn't do SNI
(https://salsa.debian.org/salsa/support/issues/90)

5 years agoComment out rate-limiting of https traffic on security-tracker
Julien Cristau [Sun, 8 Jul 2018 10:39:29 +0000 (12:39 +0200)]
Comment out rate-limiting of https traffic on security-tracker

5 years agoIncrease https bandwidth for security-tracker
Julien Cristau [Sat, 7 Jul 2018 12:34:22 +0000 (14:34 +0200)]
Increase https bandwidth for security-tracker

5 years agoKeep things cached for at least 10min
Julien Cristau [Sat, 7 Jul 2018 08:00:59 +0000 (10:00 +0200)]
Keep things cached for at least 10min

5 years agoFix apache module name
Julien Cristau [Sat, 7 Jul 2018 07:47:11 +0000 (09:47 +0200)]
Fix apache module name

5 years agoUse mod_cache_disk on security-tracker
Julien Cristau [Sat, 7 Jul 2018 07:10:54 +0000 (09:10 +0200)]
Use mod_cache_disk on security-tracker

5 years agoFix typo in comment
Julien Cristau [Fri, 6 Jul 2018 13:10:28 +0000 (15:10 +0200)]
Fix typo in comment

5 years agodrop things from 66.170.99.[12]
Peter Palfrader [Fri, 6 Jul 2018 09:38:38 +0000 (11:38 +0200)]
drop things from 66.170.99.[12]

5 years agofix rule
Peter Palfrader [Fri, 6 Jul 2018 09:33:19 +0000 (11:33 +0200)]
fix rule

5 years agodisable deflate on security-tracker. we are cpu bound
Peter Palfrader [Fri, 6 Jul 2018 09:28:35 +0000 (11:28 +0200)]
disable deflate on security-tracker.  we are cpu bound

5 years agodo some basic traffic shaping on soriano
Peter Palfrader [Fri, 6 Jul 2018 09:21:18 +0000 (11:21 +0200)]
do some basic traffic shaping on soriano

5 years agoenable expires module for security-tracker
Peter Palfrader [Fri, 6 Jul 2018 08:56:22 +0000 (10:56 +0200)]
enable expires module for security-tracker

5 years agomove apache config for security-tracker.debian.org.conf to puppet
Peter Palfrader [Fri, 6 Jul 2018 08:53:32 +0000 (10:53 +0200)]
move apache config for security-tracker.debian.org.conf to puppet

5 years agoKill planet.debian.net (RT#7019)
Julien Cristau [Thu, 5 Jul 2018 12:41:38 +0000 (14:41 +0200)]
Kill planet.debian.net (RT#7019)

5 years agoThe git user's sudo entries should be NOPASSWD (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 12:10:21 +0000 (14:10 +0200)]
The git user's sudo entries should be NOPASSWD (RT#7316)

5 years agofix rule name
Peter Palfrader [Thu, 5 Jul 2018 11:22:46 +0000 (13:22 +0200)]
fix rule name

5 years agosnapshot - drop traffic from 61.69.254.110
Peter Palfrader [Thu, 5 Jul 2018 11:09:42 +0000 (13:09 +0200)]
snapshot - drop traffic from 61.69.254.110

5 years agoAlso give the git user sudo access to salsa-* on godard (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 11:11:46 +0000 (13:11 +0200)]
Also give the git user sudo access to salsa-* on godard (RT#7316)

5 years agoMore users for salsa (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 10:31:21 +0000 (12:31 +0200)]
More users for salsa (RT#7316)

5 years agoAdd registry.salsa.debian.org vhost config (RT#7316)
Julien Cristau [Thu, 5 Jul 2018 10:02:37 +0000 (12:02 +0200)]
Add registry.salsa.debian.org vhost config (RT#7316)

5 years agounicamp renumbering
Julien Cristau [Fri, 29 Jun 2018 14:43:57 +0000 (16:43 +0200)]
unicamp renumbering

5 years agoremove parth, re: RT#7334
Peter Palfrader [Sun, 24 Jun 2018 21:22:47 +0000 (23:22 +0200)]
remove parth, re: RT#7334

5 years agosetup-all-dchroots: wheezy is gone, jessie is limited to LTS architectures
Aurelien Jarno [Sun, 24 Jun 2018 21:15:05 +0000 (23:15 +0200)]
setup-all-dchroots: wheezy is gone, jessie is limited to LTS architectures

5 years agoget arm-arm-01 out of broken_rtc set
Julien Cristau [Thu, 21 Jun 2018 06:44:44 +0000 (08:44 +0200)]
get arm-arm-01 out of broken_rtc set

HW's been replaced

5 years agoInstall ganeti-reboot-cluster
Peter Palfrader [Tue, 19 Jun 2018 15:19:20 +0000 (17:19 +0200)]
Install ganeti-reboot-cluster

5 years agoUpdate my home ip ranges yet again
Julien Cristau [Mon, 18 Jun 2018 18:45:45 +0000 (20:45 +0200)]
Update my home ip ranges yet again

5 years agoset Expires to 1 week also for .gz files
Peter Palfrader [Thu, 7 Jun 2018 19:43:34 +0000 (21:43 +0200)]
set Expires to 1 week also for .gz files

5 years agoEnable HTTP/2 on sources.d.o
Julien Cristau [Fri, 1 Jun 2018 19:13:26 +0000 (21:13 +0200)]
Enable HTTP/2 on sources.d.o

5 years agohttp rate limiting for dynamic hosts also on v6
Peter Palfrader [Fri, 1 Jun 2018 18:24:15 +0000 (20:24 +0200)]
http rate limiting for dynamic hosts also on v6

5 years agosnapshot: allow 6 requests per minute even to clients that we think are excessive
Peter Palfrader [Fri, 1 Jun 2018 18:12:06 +0000 (20:12 +0200)]
snapshot: allow 6 requests per minute even to clients that we think are excessive

5 years agosnapshot_web dynamic rules
Peter Palfrader [Fri, 1 Jun 2018 16:38:35 +0000 (18:38 +0200)]
snapshot_web dynamic rules

5 years agosnapshot_web dynamic rules
Peter Palfrader [Fri, 1 Jun 2018 16:02:36 +0000 (18:02 +0200)]
snapshot_web dynamic rules

5 years agoDrop apache2deb9 variable
Julien Cristau [Fri, 1 Jun 2018 15:50:02 +0000 (17:50 +0200)]
Drop apache2deb9 variable

All our apaches are stretch at this point.

5 years agoAdd data-protection@d.o to various exim config bits
Julien Cristau [Fri, 1 Jun 2018 15:49:35 +0000 (17:49 +0200)]
Add data-protection@d.o to various exim config bits

5 years agoport 6081 should be allowed via snapshot
Peter Palfrader [Fri, 1 Jun 2018 15:46:34 +0000 (17:46 +0200)]
port 6081 should be allowed via snapshot

5 years agotry apache rate limiting on snapshot hosts, 2
Peter Palfrader [Fri, 1 Jun 2018 15:05:55 +0000 (17:05 +0200)]
try apache rate limiting on snapshot hosts, 2

5 years agotry apache rate limiting on snapshot hosts
Peter Palfrader [Fri, 1 Jun 2018 15:02:38 +0000 (17:02 +0200)]
try apache rate limiting on snapshot hosts

5 years agoadd template
Peter Palfrader [Fri, 1 Jun 2018 09:11:27 +0000 (11:11 +0200)]
add template

5 years agoparts of the nagios setup
Peter Palfrader [Fri, 1 Jun 2018 09:10:45 +0000 (11:10 +0200)]
parts of the nagios setup

5 years agonagios: install some packages and define service
Peter Palfrader [Fri, 1 Jun 2018 09:03:41 +0000 (11:03 +0200)]
nagios: install some packages and define service

5 years agodebian nagios service does not use digest auth
Peter Palfrader [Fri, 1 Jun 2018 09:02:33 +0000 (11:02 +0200)]
debian nagios service does not use digest auth

5 years agonagios: we do not need proxy_http
Peter Palfrader [Fri, 1 Jun 2018 09:00:50 +0000 (11:00 +0200)]
nagios: we do not need proxy_http

5 years agoadd apache::authn_anon and apache::auth_digest
Peter Palfrader [Fri, 1 Jun 2018 09:00:10 +0000 (11:00 +0200)]
add apache::authn_anon and apache::auth_digest

5 years agonagios master: apache vhost
Peter Palfrader [Fri, 1 Jun 2018 08:58:43 +0000 (10:58 +0200)]
nagios master: apache vhost

5 years agostart using nagios::server again, move cert setup there
Peter Palfrader [Fri, 1 Jun 2018 08:56:10 +0000 (10:56 +0200)]
start using nagios::server again, move cert setup there

5 years agoremove obsolete stuff from nagios::server
Peter Palfrader [Fri, 1 Jun 2018 08:55:41 +0000 (10:55 +0200)]
remove obsolete stuff from nagios::server

5 years agorestart stale icinga automatically
Peter Palfrader [Fri, 1 Jun 2018 08:51:02 +0000 (10:51 +0200)]
restart stale icinga automatically

5 years agowider regex for clearing failed rsyncd service to catch rsyncd-snapshot-farm@
Peter Palfrader [Fri, 1 Jun 2018 07:46:12 +0000 (09:46 +0200)]
wider regex for clearing failed rsyncd service to catch rsyncd-snapshot-farm@

5 years agoignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts
Peter Palfrader [Fri, 1 Jun 2018 07:06:03 +0000 (09:06 +0200)]
ignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts

5 years agoignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts
Peter Palfrader [Fri, 1 Jun 2018 07:05:14 +0000 (09:05 +0200)]
ignore ruby-dbi ruby-deprecated ruby-dbd-pg on snapshot hosts

5 years agoset expires: headers on alioth-archive
Peter Palfrader [Thu, 31 May 2018 19:20:44 +0000 (21:20 +0200)]
set expires: headers on alioth-archive

5 years agoAdd a few pointers on the anonscm index page
Julien Cristau [Thu, 31 May 2018 15:56:31 +0000 (17:56 +0200)]
Add a few pointers on the anonscm index page

5 years agoindex page for anonscm, 2
Peter Palfrader [Thu, 31 May 2018 15:46:27 +0000 (17:46 +0200)]
index page for anonscm, 2

5 years agoindex page for anonscm
Peter Palfrader [Thu, 31 May 2018 15:45:20 +0000 (17:45 +0200)]
index page for anonscm

5 years agoput an /srv/anonscm.debian.org/htdocs in place
Peter Palfrader [Thu, 31 May 2018 15:44:08 +0000 (17:44 +0200)]
put an /srv/anonscm.debian.org/htdocs in place

5 years agovhost cleanup
Peter Palfrader [Thu, 31 May 2018 15:38:22 +0000 (17:38 +0200)]
vhost cleanup

5 years agovhost update
Peter Palfrader [Thu, 31 May 2018 15:33:19 +0000 (17:33 +0200)]
vhost update

5 years agonon-SSL is on 80
Peter Palfrader [Thu, 31 May 2018 15:28:50 +0000 (17:28 +0200)]
non-SSL is on 80

5 years agoUse anonscm.map
Peter Palfrader [Thu, 31 May 2018 15:25:05 +0000 (17:25 +0200)]
Use anonscm.map

5 years agotry to put anonscm.map onto host, 3
Peter Palfrader [Thu, 31 May 2018 15:24:19 +0000 (17:24 +0200)]
try to put anonscm.map onto host, 3

5 years agotry to put anonscm.map onto host, 2
Peter Palfrader [Thu, 31 May 2018 15:23:32 +0000 (17:23 +0200)]
try to put anonscm.map onto host, 2

5 years agotry to put anonscm.map onto host
Peter Palfrader [Thu, 31 May 2018 15:22:07 +0000 (17:22 +0200)]
try to put anonscm.map onto host

5 years agoprepare anonscm vhost
Peter Palfrader [Thu, 31 May 2018 15:15:38 +0000 (17:15 +0200)]
prepare anonscm vhost

5 years agoset hsts on snapshot
Peter Palfrader [Wed, 30 May 2018 12:16:25 +0000 (14:16 +0200)]
set hsts on snapshot

5 years agoTry to put haproxy on snapshot hosts
Peter Palfrader [Wed, 30 May 2018 08:24:46 +0000 (10:24 +0200)]
Try to put haproxy on snapshot hosts

5 years agoAdd a logging device for haproxy
Peter Palfrader [Wed, 30 May 2018 08:18:57 +0000 (10:18 +0200)]
Add a logging device for haproxy

5 years agoAdd haproxy module from tor
Peter Palfrader [Wed, 30 May 2018 08:17:08 +0000 (10:17 +0200)]
Add haproxy module from tor

5 years agoa haproxy facter
Peter Palfrader [Wed, 30 May 2018 08:16:25 +0000 (10:16 +0200)]
a haproxy facter

5 years agoMore verbose setup-all-dchroots when run in a terminal
Peter Palfrader [Wed, 30 May 2018 08:00:54 +0000 (10:00 +0200)]
More verbose setup-all-dchroots when run in a terminal

5 years agoinstall snapshot cert
Peter Palfrader [Tue, 29 May 2018 14:24:02 +0000 (16:24 +0200)]
install snapshot cert

5 years agosallinen: retire 443->5473 dnat
Peter Palfrader [Tue, 29 May 2018 12:37:24 +0000 (14:37 +0200)]
sallinen: retire 443->5473 dnat

5 years agoFetch sallinen.debian.org snapshot backups from port 5473
Peter Palfrader [Tue, 29 May 2018 09:37:43 +0000 (11:37 +0200)]
Fetch sallinen.debian.org snapshot backups from port 5473