Peter Palfrader [Wed, 12 Dec 2018 13:03:15 +0000 (14:03 +0100)]
Make a snapshot.debian.net vhost
Julien Cristau [Wed, 28 Nov 2018 10:37:13 +0000 (11:37 +0100)]
Drop references to long-gone db.d.o repos
Julien Cristau [Wed, 28 Nov 2018 10:36:28 +0000 (11:36 +0100)]
Use https for *-restricted db.d.o repo too
Julien Cristau [Wed, 28 Nov 2018 10:30:56 +0000 (11:30 +0100)]
Use https to access the db.d.o repo
Julien Cristau [Wed, 28 Nov 2018 09:38:30 +0000 (10:38 +0100)]
Fixup db.d.o archive key for apt consumption, it shouldn't be armored
Julien Cristau [Wed, 28 Nov 2018 08:51:14 +0000 (09:51 +0100)]
Extend lifetime of db.d.o archive key by a year
Julien Cristau [Wed, 28 Nov 2018 08:33:53 +0000 (09:33 +0100)]
Delete old logs on hosts using pybuildd
pybuildd keeps them indefinitely
(https://salsa.debian.org/wb-team/pybuildd/issues/11) so clean up ourselves to
avoid running into ENOSPC.
Julien Cristau [Fri, 23 Nov 2018 09:37:04 +0000 (10:37 +0100)]
Don't try to install obsolete postgresql client packages
Peter Palfrader [Thu, 22 Nov 2018 13:30:23 +0000 (14:30 +0100)]
postfix fail2ban -- ban quicker and longer
Julien Cristau [Thu, 22 Nov 2018 09:47:45 +0000 (10:47 +0100)]
Remove old stuff from obsolete package ignore list
- storace/backuphost don't need old pg anymore
- rainier/rapoport use stable rabbitmq-server
- conova-node* are on stretch
Peter Palfrader [Wed, 21 Nov 2018 09:27:38 +0000 (10:27 +0100)]
lvm ganeti.manda.debian.org: set global_filter
Julien Cristau [Tue, 20 Nov 2018 22:08:19 +0000 (23:08 +0100)]
Update rabbitmq module
Julien Cristau [Tue, 20 Nov 2018 22:07:26 +0000 (23:07 +0100)]
Add puppet/archive module, required for newer puppet/rabbitmq
Julien Cristau [Tue, 20 Nov 2018 20:49:05 +0000 (21:49 +0100)]
Revert "Update 3rdparty rabbitmq module"
This reverts commit
921e69100a563cf143f56a3905d8362336d939ff.
Julien Cristau [Tue, 20 Nov 2018 20:49:03 +0000 (21:49 +0100)]
Revert "Add systemd module, required by rabbitmq"
This reverts commit
1329adc9f34c3c87e353983ec9023a6cf6e93e67.
Julien Cristau [Tue, 20 Nov 2018 20:48:56 +0000 (21:48 +0100)]
Revert "Add puppet/archive module"
This reverts commit
ce70d6baf887ae03a2a6a7f5e73eb2e2c3dea208.
Julien Cristau [Tue, 20 Nov 2018 20:33:49 +0000 (21:33 +0100)]
Add puppet/archive module
Required by puppet/rabbitmq
Julien Cristau [Tue, 20 Nov 2018 20:28:40 +0000 (21:28 +0100)]
Rename our systemd module to dsa_systemd
Avoid conflict with 3rdparty.
Julien Cristau [Tue, 20 Nov 2018 20:09:44 +0000 (21:09 +0100)]
Add systemd module, required by rabbitmq
Julien Cristau [Tue, 20 Nov 2018 20:02:31 +0000 (21:02 +0100)]
pubsub: manage_repos -> repos_ensure
Julien Cristau [Tue, 20 Nov 2018 19:57:58 +0000 (20:57 +0100)]
Update 3rdparty rabbitmq module
Simon McVittie [Tue, 20 Nov 2018 16:18:50 +0000 (16:18 +0000)]
setup-dchroot: Request unmerged /usr
Merged /usr is known to cause multiple packages to be misbuilt. As long
as we support unmerged /usr for user systems, we should mitigate
this class of bugs by using unmerged-/usr chroots on official buildds,
resulting in binary packages that work equally well on merged- or
unmerged-/usr user systems.
See:
https://bugs.debian.org/913229
https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=md@linux.it&tag=usrmerge
thread at https://lists.debian.org/debian-devel/2018/11/msg00299.html
Signed-off-by: Simon McVittie <smcv@debian.org>
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Mon, 19 Nov 2018 16:57:28 +0000 (17:57 +0100)]
Add pijper
Julien Cristau [Mon, 19 Nov 2018 16:47:12 +0000 (17:47 +0100)]
Don't install megacli if we're not amd64
Peter Palfrader [Mon, 19 Nov 2018 12:38:15 +0000 (13:38 +0100)]
manda-node03, manda-node04: lvm: issue discards
Peter Palfrader [Mon, 19 Nov 2018 12:35:09 +0000 (13:35 +0100)]
manda-node03, manda-node04: lvm: set a device filter
Peter Palfrader [Mon, 19 Nov 2018 12:33:15 +0000 (13:33 +0100)]
add default lvm conf for new manda hosts
Peter Palfrader [Mon, 19 Nov 2018 12:30:02 +0000 (13:30 +0100)]
rename lvm-manda-ganeti.conf -> lvm-manda-ganeti3.conf
Peter Palfrader [Sun, 18 Nov 2018 19:13:48 +0000 (20:13 +0100)]
try to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 19:03:18 +0000 (20:03 +0100)]
Revert "try to sort pin files"
This reverts commit
839c8ea25d94aa887d71e46d150509ff4c339fac.
Peter Palfrader [Sun, 18 Nov 2018 19:01:37 +0000 (20:01 +0100)]
try to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 09:51:28 +0000 (10:51 +0100)]
Try ganeti address definitions for new manda cluster
Peter Palfrader [Sun, 18 Nov 2018 09:50:11 +0000 (10:50 +0100)]
Use ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganeti module
Peter Palfrader [Sun, 18 Nov 2018 09:47:57 +0000 (10:47 +0100)]
Also restrict "ganeti/kvm host" purpose
Peter Palfrader [Sun, 18 Nov 2018 09:25:51 +0000 (10:25 +0100)]
Try to not limit ganeti firewall rules to v4
Julien Cristau [Tue, 13 Nov 2018 14:24:37 +0000 (15:24 +0100)]
sudo: add additional openmanage command line for nagios
Lets us blacklist the battery probe on wieck and schumann.
Peter Palfrader [Tue, 13 Nov 2018 12:58:00 +0000 (13:58 +0100)]
ferm cleanup: sallinen
Peter Palfrader [Tue, 13 Nov 2018 12:55:38 +0000 (13:55 +0100)]
ferm cleanup: bmdb1:debsources, fix
Peter Palfrader [Tue, 13 Nov 2018 12:54:21 +0000 (13:54 +0100)]
ferm cleanup: bmdb1:debsources
Peter Palfrader [Tue, 13 Nov 2018 12:53:14 +0000 (13:53 +0100)]
ferm cleanup: bmdb1:dedup
Peter Palfrader [Tue, 13 Nov 2018 12:52:24 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:bacula
Peter Palfrader [Tue, 13 Nov 2018 12:52:01 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:wannabuild, remove duplicate allow from backuphost
Peter Palfrader [Tue, 13 Nov 2018 12:50:36 +0000 (13:50 +0100)]
ferm cleanup: bmdb1:wannabuild
Peter Palfrader [Tue, 13 Nov 2018 12:48:49 +0000 (13:48 +0100)]
ferm cleanup: bmdb1:dak, fix
Peter Palfrader [Tue, 13 Nov 2018 12:46:53 +0000 (13:46 +0100)]
ferm cleanup: bmdb1:dak
Peter Palfrader [Tue, 13 Nov 2018 12:41:42 +0000 (13:41 +0100)]
ferm cleanup: bmdb1:main, fix
Peter Palfrader [Tue, 13 Nov 2018 12:39:35 +0000 (13:39 +0100)]
ferm cleanup: bmdb1:main
also: no longer allow bmdb1:main access from bm-bl9
Peter Palfrader [Tue, 13 Nov 2018 12:12:15 +0000 (13:12 +0100)]
ferm cleanup: fasolo postgres
Peter Palfrader [Tue, 13 Nov 2018 12:08:53 +0000 (13:08 +0100)]
test avoiding hardcoding addresses
Peter Palfrader [Tue, 13 Nov 2018 09:40:32 +0000 (10:40 +0100)]
no more varnish on sibelius
Peter Palfrader [Tue, 13 Nov 2018 09:40:09 +0000 (10:40 +0100)]
bugs-search no longer runs on sonntag
Peter Palfrader [Sun, 11 Nov 2018 17:35:33 +0000 (18:35 +0100)]
backlist 51.15.215.91 from snapshot
Julien Cristau [Sun, 11 Nov 2018 00:44:50 +0000 (01:44 +0100)]
Revert "99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots"
Debian 9.6 is out, so the temporary workaround is no longer necessary.
This reverts commit
6817281d2e8f2d2a0991b7517d451e6c7e38734a.
Julien Cristau [Fri, 9 Nov 2018 14:25:50 +0000 (15:25 +0100)]
samhain: ignore /etc/schroot/dsa/default-mirror
It comes from puppet.
Julien Cristau [Thu, 8 Nov 2018 08:12:51 +0000 (09:12 +0100)]
samhain: deal with rename of db.d.o restricted sources.list entry
Julien Cristau [Wed, 7 Nov 2018 22:20:50 +0000 (23:20 +0100)]
sudo: add manda-node0[34] to DELLHOSTS
Lets nagios monitor system and storage health.
Julien Cristau [Wed, 7 Nov 2018 21:13:12 +0000 (22:13 +0100)]
Fix debian_org::apt_restricted
Julien Cristau [Wed, 7 Nov 2018 21:07:37 +0000 (22:07 +0100)]
Install srvadmin foo on dell hosts, and move our restricted archive to debian_org::apt_restricted
Peter Palfrader [Wed, 7 Nov 2018 19:22:52 +0000 (20:22 +0100)]
and symlink
Peter Palfrader [Wed, 7 Nov 2018 19:19:00 +0000 (20:19 +0100)]
change megaraid_sas test
Peter Palfrader [Wed, 7 Nov 2018 19:09:24 +0000 (20:09 +0100)]
ftp.de.debian.org appears to be unavailable -- switch man-da to ftp2
Peter Palfrader [Wed, 7 Nov 2018 18:16:04 +0000 (19:16 +0100)]
different name for aptrepo
Peter Palfrader [Wed, 7 Nov 2018 18:13:02 +0000 (19:13 +0100)]
fix class
Peter Palfrader [Wed, 7 Nov 2018 18:11:47 +0000 (19:11 +0100)]
megaraid_sas
Peter Palfrader [Wed, 7 Nov 2018 18:08:38 +0000 (19:08 +0100)]
Add megaraid_sas facter
Julien Cristau [Wed, 7 Nov 2018 09:01:25 +0000 (10:01 +0100)]
Put grub and kernel on ttyS0 on manda-node0[34]
Peter Palfrader [Tue, 6 Nov 2018 08:04:53 +0000 (09:04 +0100)]
setup-dchroot: merge from tor (genname split into function, ubuntu updates)
- split schroot base name generation into its own function
- if we build an ubuntu chroot, upgrade to the latest packages available
in -updates and -security of their suite, since it seems they don't
ever do point releases so you end up with a 4 year old openssl in your
chroot.
Julien Cristau [Mon, 5 Nov 2018 19:21:57 +0000 (20:21 +0100)]
Temporarily switch off privacy logging for security.d.o
I want to figure out what clients are still hitting it directly,
especially at specific times, so some insight into User-Agents and
timestamps would be useful.
Julien Cristau [Sun, 4 Nov 2018 12:03:42 +0000 (13:03 +0100)]
Redirect all of security.d.o to security-cdn
Instead of just /pool/updates/main/l/linux/*, redirect everything except:
- if coming from fastly or aws
- if coming from nagios or mini-nag
- if using the onion service
- if doing a health check
Eventually we might point the security.d.o name directly at the CDN, but let's
see if this helps already.
Julien Cristau [Sat, 3 Nov 2018 15:11:23 +0000 (16:11 +0100)]
Exclude dsa-check-mirrorsync nagios check from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:09:25 +0000 (16:09 +0100)]
Exclude nagios check_http from security to security-cdn redirect
Prep for making that redirect global
Julien Cristau [Fri, 2 Nov 2018 12:19:18 +0000 (13:19 +0100)]
Disable mod_disk_cache on security-tracker
Julien Cristau [Thu, 1 Nov 2018 17:34:33 +0000 (18:34 +0100)]
Drop sibelius from postgres-make-base-backups
Julien Cristau [Thu, 1 Nov 2018 17:32:53 +0000 (18:32 +0100)]
Drop firewall rule for pg @ sibelius
Julien Cristau [Thu, 1 Nov 2018 17:31:31 +0000 (18:31 +0100)]
Remove sibelius/snapshot from dsa-check-backuppg
Peter Palfrader [Wed, 31 Oct 2018 08:41:50 +0000 (09:41 +0100)]
unique all ip addresses
Peter Palfrader [Wed, 31 Oct 2018 08:39:06 +0000 (09:39 +0100)]
Try a unique around v4addrs
Peter Palfrader [Wed, 31 Oct 2018 08:34:17 +0000 (09:34 +0100)]
Peter Palfrader [Wed, 31 Oct 2018 08:05:47 +0000 (09:05 +0100)]
sibelius nfs on public net, 2
Peter Palfrader [Wed, 31 Oct 2018 08:05:09 +0000 (09:05 +0100)]
sibelius nfs on public net
Peter Palfrader [Tue, 30 Oct 2018 10:18:15 +0000 (11:18 +0100)]
make fail2ban cleanup job shut up
Peter Palfrader [Tue, 30 Oct 2018 09:45:11 +0000 (10:45 +0100)]
move DROP blacklists to ferm prio 005, after munin
Peter Palfrader [Tue, 30 Oct 2018 09:38:18 +0000 (10:38 +0100)]
manually create the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:32:31 +0000 (10:32 +0100)]
prevent the trailing ; after the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:28:01 +0000 (10:28 +0100)]
move the fail2ban rules under the dsa-f2b chain
Peter Palfrader [Tue, 30 Oct 2018 09:23:42 +0000 (10:23 +0100)]
Move logging and related/established out of ferm.conf into a dsa.d rule
Peter Palfrader [Tue, 30 Oct 2018 09:21:31 +0000 (10:21 +0100)]
move munin rules from conf.d to the rules dir, 2
Peter Palfrader [Tue, 30 Oct 2018 09:20:32 +0000 (10:20 +0100)]
move munin rules from conf.d to the rules dir
Peter Palfrader [Tue, 30 Oct 2018 09:17:50 +0000 (10:17 +0100)]
rename interfaces to 50-munin-interfaces
Peter Palfrader [Tue, 30 Oct 2018 09:15:25 +0000 (10:15 +0100)]
merge munin_ip v4 and v6 into one rule
Peter Palfrader [Tue, 30 Oct 2018 09:07:46 +0000 (10:07 +0100)]
change default ferm rule priority to 10 from 00
Peter Palfrader [Tue, 30 Oct 2018 09:00:46 +0000 (10:00 +0100)]
also govern submission port
Peter Palfrader [Tue, 30 Oct 2018 08:57:53 +0000 (09:57 +0100)]
Clean up fail2ban database
Peter Palfrader [Sun, 28 Oct 2018 12:05:41 +0000 (13:05 +0100)]
more aggressive fail2ban on exim hosts
Peter Palfrader [Tue, 23 Oct 2018 16:29:04 +0000 (18:29 +0200)]
Add a second easydns ipv4 address
Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi
We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-
20171122