mirror/dsa-puppet.git
7 years agoSetup /srv/mirrors/debian-security on security_mirror
Bastian Blank [Fri, 10 Feb 2017 20:10:11 +0000 (21:10 +0100)]
Setup /srv/mirrors/debian-security on security_mirror

7 years agoSetup /srv/mirrors on all (archvsync-based) mirrors
Bastian Blank [Fri, 10 Feb 2017 20:06:37 +0000 (21:06 +0100)]
Setup /srv/mirrors on all (archvsync-based) mirrors

7 years agoUse rsyncd via system on security_master
Bastian Blank [Fri, 10 Feb 2017 20:00:58 +0000 (21:00 +0100)]
Use rsyncd via system on security_master

7 years agoUse rsyncd via systemd on ftp_master
Bastian Blank [Fri, 10 Feb 2017 20:00:01 +0000 (21:00 +0100)]
Use rsyncd via systemd on ftp_master

7 years agoUse rsyncd via systemd on archive_master
Bastian Blank [Fri, 10 Feb 2017 19:59:32 +0000 (20:59 +0100)]
Use rsyncd via systemd on archive_master

7 years agoAdd cdn.debian.net server alias to deb.do
Peter Palfrader [Fri, 10 Feb 2017 12:57:11 +0000 (13:57 +0100)]
Add cdn.debian.net server alias to deb.do

7 years agoDo not add + for IndexOption in global context. It should still add to the existing...
Peter Palfrader [Thu, 9 Feb 2017 19:17:05 +0000 (20:17 +0100)]
Do not add + for IndexOption in global context.  It should still add to the existing options

7 years agoRemove redundant IndexOptions from all vhosts
Peter Palfrader [Thu, 9 Feb 2017 08:44:18 +0000 (09:44 +0100)]
Remove redundant IndexOptions from all vhosts

7 years agoDisable file descriptions in all apache indexes
Peter Palfrader [Thu, 9 Feb 2017 08:43:17 +0000 (09:43 +0100)]
Disable file descriptions in all apache indexes

7 years agoGet rid of incorrectly-specified (and therefore unused SuppressDescription IndexOptions
Peter Palfrader [Thu, 9 Feb 2017 08:18:49 +0000 (09:18 +0100)]
Get rid of incorrectly-specified (and therefore unused SuppressDescription IndexOptions

7 years agoAdd a couple aliases to the deb.d.o vhost
Julien Cristau [Thu, 9 Feb 2017 08:09:40 +0000 (09:09 +0100)]
Add a couple aliases to the deb.d.o vhost

Part of deprecating httpredir.

7 years agoMerge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa...
Martin Zobel-Helas [Wed, 8 Feb 2017 15:14:43 +0000 (16:14 +0100)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

* 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet:
  add sallinen
  Enable authentication for buildd-keyrings rsync module
  Use archvsync managed secrets files for rsyncd on syncproxy
  Cannot depend on Package[xinetd] without it being defined
  only pull in xinetd if we do not try to remove files
  Enable rsync-ssl on keyring.debian.org
  Unify rsyncd module comments
  Extract default rsyncd module parameter
  De-list all rsync shares on ftp/ports/security-master
  Enable rsync-ssl on keyring.debian.org
  setup-all-dchroots: use the 2017 key for debian-ports

7 years agoadd conova as bgp peer
Martin Zobel-Helas [Wed, 8 Feb 2017 15:14:19 +0000 (16:14 +0100)]
add conova as bgp peer

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoadd sallinen
Julien Cristau [Wed, 8 Feb 2017 08:59:49 +0000 (09:59 +0100)]
add sallinen

7 years agoMerge remote-tracking branch 'waldi/rsyncd-buildd-keyrings-auth'
Peter Palfrader [Tue, 7 Feb 2017 21:27:55 +0000 (22:27 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-buildd-keyrings-auth'

* waldi/rsyncd-buildd-keyrings-auth:
  Enable authentication for buildd-keyrings rsync module

7 years agoEnable authentication for buildd-keyrings rsync module
Bastian Blank [Tue, 7 Feb 2017 21:20:27 +0000 (22:20 +0100)]
Enable authentication for buildd-keyrings rsync module

7 years agoMerge remote-tracking branch 'waldi/managed-rsyncd-syncproxy'
Peter Palfrader [Tue, 7 Feb 2017 21:13:11 +0000 (22:13 +0100)]
Merge remote-tracking branch 'waldi/managed-rsyncd-syncproxy'

* waldi/managed-rsyncd-syncproxy:
  Use archvsync managed secrets files for rsyncd on syncproxy

7 years agoUse archvsync managed secrets files for rsyncd on syncproxy
Bastian Blank [Tue, 7 Feb 2017 21:11:03 +0000 (22:11 +0100)]
Use archvsync managed secrets files for rsyncd on syncproxy

7 years agoMerge remote-tracking branch 'waldi/rsyncd-unify'
Peter Palfrader [Tue, 7 Feb 2017 20:58:38 +0000 (21:58 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-unify'

* waldi/rsyncd-unify:
  Unify rsyncd module comments
  Extract default rsyncd module parameter
  De-list all rsync shares on ftp/ports/security-master

7 years agoCannot depend on Package[xinetd] without it being defined
Peter Palfrader [Tue, 7 Feb 2017 20:47:16 +0000 (21:47 +0100)]
Cannot depend on Package[xinetd] without it being defined

7 years agoonly pull in xinetd if we do not try to remove files
Peter Palfrader [Tue, 7 Feb 2017 20:45:30 +0000 (21:45 +0100)]
only pull in xinetd if we do not try to remove files

7 years agoMerge remote-tracking branch 'waldi/keyring-ssl'
Peter Palfrader [Tue, 7 Feb 2017 20:41:49 +0000 (21:41 +0100)]
Merge remote-tracking branch 'waldi/keyring-ssl'

* waldi/keyring-ssl:
  Enable rsync-ssl on keyring.debian.org

Conflicts:
modules/roles/manifests/keyring.pp

7 years agoEnable rsync-ssl on keyring.debian.org
Bastian Blank [Fri, 3 Feb 2017 17:34:28 +0000 (18:34 +0100)]
Enable rsync-ssl on keyring.debian.org

7 years agoMerge remote-tracking branch 'waldi/keyring-ssl'
Peter Palfrader [Tue, 7 Feb 2017 20:37:19 +0000 (21:37 +0100)]
Merge remote-tracking branch 'waldi/keyring-ssl'

* waldi/keyring-ssl:
  Enable rsync-ssl on keyring.debian.org

7 years agoUnify rsyncd module comments
Bastian Blank [Fri, 3 Feb 2017 17:55:55 +0000 (18:55 +0100)]
Unify rsyncd module comments

7 years agoExtract default rsyncd module parameter
Bastian Blank [Fri, 3 Feb 2017 17:52:29 +0000 (18:52 +0100)]
Extract default rsyncd module parameter

7 years agoDe-list all rsync shares on ftp/ports/security-master
Bastian Blank [Fri, 3 Feb 2017 17:48:14 +0000 (18:48 +0100)]
De-list all rsync shares on ftp/ports/security-master

Remove all comments at the same time

7 years agoEnable rsync-ssl on keyring.debian.org
Bastian Blank [Fri, 3 Feb 2017 17:34:28 +0000 (18:34 +0100)]
Enable rsync-ssl on keyring.debian.org

7 years agosetup-all-dchroots: use the 2017 key for debian-ports
Aurelien Jarno [Tue, 7 Feb 2017 15:29:38 +0000 (16:29 +0100)]
setup-all-dchroots: use the 2017 key for debian-ports

7 years agoadd ServerAlias for debian.testing-anycast.mirrors.debian.org
Martin Zobel-Helas [Tue, 7 Feb 2017 10:42:33 +0000 (11:42 +0100)]
add ServerAlias for debian.testing-anycast.mirrors.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoAdd CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync
Peter Palfrader [Mon, 6 Feb 2017 22:04:41 +0000 (23:04 +0100)]
Add CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync

7 years agoubc-bl2 is powered off
Martin Zobel-Helas [Mon, 6 Feb 2017 20:03:15 +0000 (21:03 +0100)]
ubc-bl2 is powered off

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoMerge remote-tracking branch 'waldi/rsyncd-protect'
Peter Palfrader [Mon, 6 Feb 2017 11:52:42 +0000 (12:52 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-protect'

* waldi/rsyncd-protect:
  Allow rsyncd to access /home read-only

7 years agoAllow rsyncd to access /home read-only
Bastian Blank [Fri, 3 Feb 2017 17:24:42 +0000 (18:24 +0100)]
Allow rsyncd to access /home read-only

7 years agoMerge remote-tracking branch 'waldi/rsyncd-systemd'
Peter Palfrader [Fri, 3 Feb 2017 09:07:50 +0000 (10:07 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-systemd'

* waldi/rsyncd-systemd:
  Use rsync::site_systemd on ports_master
  Add systemd backed rsync service

7 years agoUse rsync::site_systemd on ports_master
Bastian Blank [Sun, 29 Jan 2017 10:56:11 +0000 (11:56 +0100)]
Use rsync::site_systemd on ports_master

7 years agoAdd systemd backed rsync service
Bastian Blank [Sun, 29 Jan 2017 10:26:15 +0000 (11:26 +0100)]
Add systemd backed rsync service

7 years agoremove nfs/autofs from bilbao
Peter Palfrader [Fri, 3 Feb 2017 08:44:26 +0000 (09:44 +0100)]
remove nfs/autofs from bilbao

7 years agoadd bilbao-lvm
Peter Palfrader [Thu, 2 Feb 2017 14:28:46 +0000 (15:28 +0100)]
add bilbao-lvm

7 years agoretire debprivate-darmstadt.debian.org
Peter Palfrader [Thu, 2 Feb 2017 13:57:09 +0000 (14:57 +0100)]
retire debprivate-darmstadt.debian.org

7 years agofix ports-master rename
Peter Palfrader [Thu, 2 Feb 2017 10:27:14 +0000 (11:27 +0100)]
fix ports-master rename

7 years agoRemove unused parameter fname from rsync::site
Bastian Blank [Sun, 29 Jan 2017 09:13:48 +0000 (10:13 +0100)]
Remove unused parameter fname from rsync::site

Signed-off-by: Peter Palfrader <peter@palfrader.org>
7 years agoRename roles::ports-master to roles::ports_master
Bastian Blank [Sun, 29 Jan 2017 10:55:31 +0000 (11:55 +0100)]
Rename roles::ports-master to roles::ports_master

Signed-off-by: Peter Palfrader <peter@palfrader.org>
7 years agoremove extra stuff
Peter Palfrader [Wed, 1 Feb 2017 19:15:48 +0000 (20:15 +0100)]
remove extra stuff

7 years agodeploy network/interfaces stanza for anycast node
Peter Palfrader [Wed, 1 Feb 2017 19:14:21 +0000 (20:14 +0100)]
deploy network/interfaces stanza for anycast node

7 years agouse the puppet archive.d.o apache config on sibelius
Peter Palfrader [Wed, 1 Feb 2017 07:48:50 +0000 (08:48 +0100)]
use the puppet archive.d.o apache config on sibelius

7 years agoremove confusing apache::cache manifest
Peter Palfrader [Wed, 1 Feb 2017 07:46:22 +0000 (08:46 +0100)]
remove confusing apache::cache manifest

7 years agouse the puppet archive.d.o apache config on klecker
Peter Palfrader [Wed, 1 Feb 2017 07:42:58 +0000 (08:42 +0100)]
use the puppet archive.d.o apache config on klecker

7 years agoadd archive bind address for klecker
Peter Palfrader [Wed, 1 Feb 2017 07:42:06 +0000 (08:42 +0100)]
add archive bind address for klecker

7 years agoServe the archive on / and on /debian-archive/
Peter Palfrader [Wed, 1 Feb 2017 07:40:42 +0000 (08:40 +0100)]
Serve the archive on / and on /debian-archive/

7 years agouse expires on archive
Peter Palfrader [Wed, 1 Feb 2017 07:38:52 +0000 (08:38 +0100)]
use expires on archive

7 years agoarchive.d.o is not your standard archive layout
Peter Palfrader [Wed, 1 Feb 2017 07:37:39 +0000 (08:37 +0100)]
archive.d.o is not your standard archive layout

7 years agoMake gretchaninov an archive mirror
Peter Palfrader [Wed, 1 Feb 2017 07:31:06 +0000 (08:31 +0100)]
Make gretchaninov an archive mirror

7 years agoSet ServerAdmin properly on ftp.d.o vhost
Peter Palfrader [Wed, 1 Feb 2017 07:28:23 +0000 (08:28 +0100)]
Set ServerAdmin properly on ftp.d.o vhost

7 years agoDisable userdir on a bunch of vhosts
Peter Palfrader [Wed, 1 Feb 2017 07:27:38 +0000 (08:27 +0100)]
Disable userdir on a bunch of vhosts

7 years agowhitespace change
Peter Palfrader [Wed, 1 Feb 2017 07:25:40 +0000 (08:25 +0100)]
whitespace change

7 years agoadd dedication
Martin Zobel-Helas [Tue, 31 Jan 2017 22:08:08 +0000 (23:08 +0100)]
add dedication

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agodann halt nich
Martin Zobel-Helas [Tue, 31 Jan 2017 21:50:08 +0000 (22:50 +0100)]
dann halt nich

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoadd no IP for now, we don't have any peer yet
Martin Zobel-Helas [Tue, 31 Jan 2017 21:46:39 +0000 (22:46 +0100)]
add no IP for now, we don't have any peer yet

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoadd boman to debian_mirror
Martin Zobel-Helas [Tue, 31 Jan 2017 21:43:14 +0000 (22:43 +0100)]
add boman to debian_mirror

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoadd boman
Martin Zobel-Helas [Tue, 31 Jan 2017 21:29:31 +0000 (22:29 +0100)]
add boman

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agolet new cdimage-search do https and onion
Peter Palfrader [Tue, 31 Jan 2017 20:43:44 +0000 (21:43 +0100)]
let new cdimage-search do https and onion

7 years agocdimage-search uses http proxy module
Peter Palfrader [Tue, 31 Jan 2017 20:36:16 +0000 (21:36 +0100)]
cdimage-search uses http proxy module

7 years agoadd cdimage-search role
Peter Palfrader [Tue, 31 Jan 2017 20:32:38 +0000 (21:32 +0100)]
add cdimage-search role

7 years agosamhain, stop obsessing over ports
Peter Palfrader [Tue, 31 Jan 2017 20:19:24 +0000 (21:19 +0100)]
samhain, stop obsessing over ports

7 years agofix rule
Peter Palfrader [Tue, 31 Jan 2017 08:27:04 +0000 (08:27 +0000)]
fix rule

7 years agotry to setup firewall rules for bgp on bilbao
Peter Palfrader [Tue, 31 Jan 2017 08:23:31 +0000 (09:23 +0100)]
try to setup firewall rules for bgp on bilbao

7 years agoadd priv.accumu.debian.org to searchpath
Peter Palfrader [Mon, 30 Jan 2017 20:40:38 +0000 (21:40 +0100)]
add priv.accumu.debian.org to searchpath

7 years agoRevert "put puppet config for ftp.d.o onto klecker"
Peter Palfrader [Mon, 30 Jan 2017 18:52:32 +0000 (19:52 +0100)]
Revert "put puppet config for ftp.d.o onto klecker"

This reverts commit 4afbb6552d3b4c54230f07fa57c4c781b3b9a9d7.

Our fastly config relies on / returning 200 OK (not a redirect).  So
disabling this for now.

7 years agoput puppet config for ftp.d.o onto klecker
Peter Palfrader [Mon, 30 Jan 2017 18:39:13 +0000 (19:39 +0100)]
put puppet config for ftp.d.o onto klecker

7 years agoadd mirror-isc to ftp.d.o onion rotation
Peter Palfrader [Mon, 30 Jan 2017 18:34:28 +0000 (19:34 +0100)]
add mirror-isc to ftp.d.o onion rotation

7 years agosyntax fix
Peter Palfrader [Mon, 30 Jan 2017 18:32:57 +0000 (19:32 +0100)]
syntax fix

7 years agosyntax fix
Peter Palfrader [Mon, 30 Jan 2017 18:31:39 +0000 (19:31 +0100)]
syntax fix

7 years agouse proper directory
Peter Palfrader [Mon, 30 Jan 2017 18:31:14 +0000 (19:31 +0100)]
use proper directory

7 years agosyntax fix
Peter Palfrader [Mon, 30 Jan 2017 18:24:31 +0000 (19:24 +0100)]
syntax fix

7 years agopuppetize ftp.d.o http
Peter Palfrader [Mon, 30 Jan 2017 18:22:28 +0000 (19:22 +0100)]
puppetize ftp.d.o http

7 years agologlevel warn is default
Peter Palfrader [Mon, 30 Jan 2017 18:13:03 +0000 (19:13 +0100)]
loglevel warn is default

7 years agomerge directory setup into ftp-archive macro
Peter Palfrader [Mon, 30 Jan 2017 18:08:11 +0000 (19:08 +0100)]
merge directory setup into ftp-archive macro

7 years agoRemove dak -> backports sudo entry that is apparently unused (because it used a wrong...
Peter Palfrader [Mon, 30 Jan 2017 14:59:35 +0000 (15:59 +0100)]
Remove dak -> backports sudo entry that is apparently unused (because it used a wrong host set)

7 years agogive kibi access to acker
Peter Palfrader [Mon, 30 Jan 2017 14:58:39 +0000 (15:58 +0100)]
give kibi access to acker

7 years agoRevert "setup-dchroot: create /srv/chroot"
Héctor Orón Martínez [Mon, 30 Jan 2017 10:55:57 +0000 (11:55 +0100)]
Revert "setup-dchroot: create /srv/chroot"

the point of the check is to make sure we have created /srv/chroot on a
suitable filesystem, as we don't want the scripts to run if we haven't
done all the filesystem setup yet

This reverts commit 47e806d785e3195f855584d0739abb0ee2682c27.

7 years agosetup-dchroot: create /srv/chroot
Héctor Orón Martínez [Mon, 30 Jan 2017 10:51:07 +0000 (11:51 +0100)]
setup-dchroot: create /srv/chroot

Usually when new buildd is setup it does not have a basedir (/srv/chroot)
which causes script setting up build chroots to fail.
This change creates basedir if directory does not exist, instead to error out.

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
7 years agodo systemd stuff only on systemd systems
Peter Palfrader [Sun, 29 Jan 2017 20:54:00 +0000 (21:54 +0100)]
do systemd stuff only on systemd systems

7 years agonew apache on cgi-grnet-01
Peter Palfrader [Sun, 29 Jan 2017 20:14:33 +0000 (21:14 +0100)]
new apache on cgi-grnet-01

7 years agomanpages uses mod expires
Peter Palfrader [Sun, 29 Jan 2017 20:07:14 +0000 (21:07 +0100)]
manpages uses mod expires

7 years agoorder allow,deny is legacy sytax
Peter Palfrader [Sun, 29 Jan 2017 20:05:27 +0000 (21:05 +0100)]
order allow,deny is legacy sytax

7 years agoMerge remote-tracking branch 'stapelberg/dyn'
Peter Palfrader [Sun, 29 Jan 2017 20:04:24 +0000 (21:04 +0100)]
Merge remote-tracking branch 'stapelberg/dyn'

* stapelberg/dyn:
  dyn.manpages.d.o: let auxserver handle redirects, serve static assets

7 years agodyn.manpages.d.o: let auxserver handle redirects, serve static assets
Michael Stapelberg [Sun, 29 Jan 2017 20:00:22 +0000 (21:00 +0100)]
dyn.manpages.d.o: let auxserver handle redirects, serve static assets

7 years agorestore lost apache2::ssl file
Peter Palfrader [Sun, 29 Jan 2017 18:34:54 +0000 (19:34 +0100)]
restore lost apache2::ssl file

7 years agoadd missing file
Peter Palfrader [Sun, 29 Jan 2017 18:32:16 +0000 (19:32 +0100)]
add missing file

7 years agoenable proxy_http module
Peter Palfrader [Sun, 29 Jan 2017 18:31:23 +0000 (19:31 +0100)]
enable proxy_http module

7 years agomanpages role has no config left - most is in static now
Peter Palfrader [Sun, 29 Jan 2017 18:28:04 +0000 (19:28 +0100)]
manpages role has no config left - most is in static now

7 years agoadd dyn.manpages role and vhost
Peter Palfrader [Sun, 29 Jan 2017 18:27:48 +0000 (19:27 +0100)]
add dyn.manpages role and vhost

7 years agoman manpages-dyn role
Peter Palfrader [Sun, 29 Jan 2017 18:21:39 +0000 (19:21 +0100)]
man manpages-dyn role

7 years agoglinka is not a manpages host anymore
Peter Palfrader [Sun, 29 Jan 2017 18:21:30 +0000 (19:21 +0100)]
glinka is not a manpages host anymore

7 years agono more manpages key on manpages hosts
Peter Palfrader [Sun, 29 Jan 2017 18:20:53 +0000 (19:20 +0100)]
no more manpages key on manpages hosts

7 years agoOnly set ExecStart command for bacula-fd on stretch
Julien Cristau [Sun, 29 Jan 2017 17:45:45 +0000 (18:45 +0100)]
Only set ExecStart command for bacula-fd on stretch

On jessie let the init script + /etc/default file handle things.

7 years agoUpdate stretch bacula-fd cmdline once more
Julien Cristau [Sun, 29 Jan 2017 15:11:00 +0000 (16:11 +0100)]
Update stretch bacula-fd cmdline once more

Make it look like the jessie one so a single nagios check is happy with
both.

7 years agoFixup stretch bacula some more
Julien Cristau [Sun, 29 Jan 2017 14:52:49 +0000 (15:52 +0100)]
Fixup stretch bacula some more

7 years agoMake systemd happier
Julien Cristau [Sun, 29 Jan 2017 14:29:53 +0000 (15:29 +0100)]
Make systemd happier