mirror/dsa-puppet.git
7 years agoTurn apache2_security_mirror into a security_mirror role
Peter Palfrader [Fri, 29 Jul 2016 22:50:21 +0000 (22:50 +0000)]
Turn apache2_security_mirror into a security_mirror role

7 years agorebuild onion website if things change
Peter Palfrader [Fri, 29 Jul 2016 20:05:06 +0000 (20:05 +0000)]
rebuild onion website if things change

7 years agofix sort order
Peter Palfrader [Fri, 29 Jul 2016 19:56:46 +0000 (19:56 +0000)]
fix sort order

7 years agoadd onion.d.o
Peter Palfrader [Fri, 29 Jul 2016 19:56:21 +0000 (19:56 +0000)]
add onion.d.o

7 years agoexport onion list to dillon
Peter Palfrader [Fri, 29 Jul 2016 19:52:01 +0000 (19:52 +0000)]
export onion list to dillon

7 years agoonion for release
Peter Palfrader [Fri, 29 Jul 2016 18:17:55 +0000 (18:17 +0000)]
onion for release

7 years agomove metadata.ftp-master.debian.org to a default with extra
Peter Palfrader [Fri, 29 Jul 2016 18:14:02 +0000 (18:14 +0000)]
move metadata.ftp-debian.org to a default with extra

7 years agomove bits to a default with extra
Peter Palfrader [Fri, 29 Jul 2016 18:12:14 +0000 (18:12 +0000)]
move bits to a default with extra

7 years agoMake common-static-vhost-ssl-with-extra a thing
Peter Palfrader [Fri, 29 Jul 2016 18:12:04 +0000 (18:12 +0000)]
Make common-static-vhost-ssl-with-extra a thing

7 years agomore onion serivces
Peter Palfrader [Fri, 29 Jul 2016 18:05:32 +0000 (18:05 +0000)]
more onion serivces

7 years agoonion for www.ports.debian.org
Peter Palfrader [Fri, 29 Jul 2016 18:05:22 +0000 (18:05 +0000)]
onion for www.ports.debian.org

7 years agoonions for standard static vhosts
Peter Palfrader [Fri, 29 Jul 2016 17:49:38 +0000 (17:49 +0000)]
onions for standard static vhosts

7 years agore-write how static vhosts with extra config work
Peter Palfrader [Fri, 29 Jul 2016 17:35:46 +0000 (17:35 +0000)]
re-write how static vhosts with extra config work

7 years agoonion for lintian
Peter Palfrader [Fri, 29 Jul 2016 17:24:49 +0000 (17:24 +0000)]
onion for lintian

7 years agoadd planet.d.o onionbalance and web
Peter Palfrader [Fri, 29 Jul 2016 17:15:21 +0000 (17:15 +0000)]
add planet.d.o onionbalance and web

7 years agoadd planet.d.o onion
Peter Palfrader [Fri, 29 Jul 2016 17:03:32 +0000 (17:03 +0000)]
add planet.d.o onion

7 years agothe other vhost
Peter Palfrader [Fri, 29 Jul 2016 16:52:39 +0000 (16:52 +0000)]
the other vhost

7 years agoonion for www
Peter Palfrader [Fri, 29 Jul 2016 16:49:59 +0000 (16:49 +0000)]
onion for www

7 years agoMerge branch 'master' of file:///srv/puppet.debian.org/git/dsa-puppet
Peter Palfrader [Fri, 29 Jul 2016 16:09:07 +0000 (16:09 +0000)]
Merge branch 'master' of file:///srv/puppet.debian.org/git/dsa-puppet

* 'master' of file:///srv/puppet.debian.org/git/dsa-puppet:
  use busoni instead of mirror-anu for tor static

7 years agouse busoni instead of mirror-anu for tor static
Peter Palfrader [Fri, 29 Jul 2016 16:09:05 +0000 (18:09 +0200)]
use busoni instead of mirror-anu for tor static

7 years agoadd comments
Peter Palfrader [Fri, 29 Jul 2016 15:49:16 +0000 (15:49 +0000)]
add comments

7 years agofix ports
Peter Palfrader [Fri, 29 Jul 2016 15:49:06 +0000 (15:49 +0000)]
fix ports

7 years agoAdd onion services for a bunch of static things
Peter Palfrader [Fri, 29 Jul 2016 15:38:35 +0000 (15:38 +0000)]
Add onion services for a bunch of static things

7 years agoTransfer onion hostname info to puppet master
Peter Palfrader [Fri, 29 Jul 2016 15:02:15 +0000 (15:02 +0000)]
Transfer onion hostname info to puppet master

7 years agorename onion facts
Peter Palfrader [Fri, 29 Jul 2016 14:00:24 +0000 (14:00 +0000)]
rename onion facts

7 years agoremove .onion from configured address for onionbalance
Peter Palfrader [Fri, 29 Jul 2016 07:18:11 +0000 (07:18 +0000)]
remove .onion from configured address for onionbalance

7 years agofix a typo in the onionbalance config file
Peter Palfrader [Fri, 29 Jul 2016 06:36:24 +0000 (08:36 +0200)]
fix a typo in the onionbalance config file

7 years agouse correct config filename for onionbalance
Peter Palfrader [Fri, 29 Jul 2016 06:33:01 +0000 (08:33 +0200)]
use correct config filename for onionbalance

7 years agouse fqdn in storedconf name
Peter Palfrader [Fri, 29 Jul 2016 06:30:30 +0000 (08:30 +0200)]
use fqdn in storedconf name

7 years agouse correct config filename for onionbalance
Peter Palfrader [Fri, 29 Jul 2016 06:24:40 +0000 (08:24 +0200)]
use correct config filename for onionbalance

7 years agoand onionbalance module
Peter Palfrader [Thu, 28 Jul 2016 21:29:58 +0000 (21:29 +0000)]
and onionbalance module

7 years agoAdd an onionbalance service names facter
Peter Palfrader [Thu, 28 Jul 2016 21:07:07 +0000 (21:07 +0000)]
Add an onionbalance service names facter

7 years agoput an onion instance into a storedconf for onionbalance
Peter Palfrader [Thu, 28 Jul 2016 20:32:47 +0000 (20:32 +0000)]
put an onion instance into a storedconf for onionbalance

7 years agomove to stringifying our facts again
Peter Palfrader [Thu, 28 Jul 2016 20:32:22 +0000 (20:32 +0000)]
move to stringifying our facts again

7 years agoAdd onion service facter to learn onion hostname
Peter Palfrader [Thu, 28 Jul 2016 19:45:51 +0000 (19:45 +0000)]
Add onion service facter to learn onion hostname

7 years agoStart an onion module
Peter Palfrader [Thu, 28 Jul 2016 19:34:38 +0000 (19:34 +0000)]
Start an onion module

7 years agoAll www and static mirrors run jessie
Julien Cristau [Wed, 27 Jul 2016 17:31:17 +0000 (19:31 +0200)]
All www and static mirrors run jessie

Remove no longer needed apache 2.4 conditionals

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAll security mirrors run jessie
Julien Cristau [Wed, 27 Jul 2016 17:26:54 +0000 (19:26 +0200)]
All security mirrors run jessie

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoUse the ftp-archive apache macro for security mirrors
Julien Cristau [Wed, 27 Jul 2016 17:20:55 +0000 (19:20 +0200)]
Use the ftp-archive apache macro for security mirrors

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoMove the Cache-Control setting for package archives to a macro
Julien Cristau [Wed, 27 Jul 2016 17:19:33 +0000 (19:19 +0200)]
Move the Cache-Control setting for package archives to a macro

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoSet Cache-Control header for debian-debug and debian-ports archives
Julien Cristau [Wed, 27 Jul 2016 16:39:48 +0000 (18:39 +0200)]
Set Cache-Control header for debian-debug and debian-ports archives

Set max-age to 2 minutes for dists, 30 days for by-hash and pool, to
match ftp.debian.org.

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAdd olin
Peter Palfrader [Wed, 27 Jul 2016 14:25:31 +0000 (16:25 +0200)]
Add olin

7 years agoAlso pin hp-health on blades
Julien Cristau [Wed, 27 Jul 2016 11:16:35 +0000 (13:16 +0200)]
Also pin hp-health on blades

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAlso pin hp-health on HP G6
Julien Cristau [Wed, 27 Jul 2016 11:14:17 +0000 (13:14 +0200)]
Also pin hp-health on HP G6

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoPin older hp-health on DL3*0 G5
Julien Cristau [Wed, 27 Jul 2016 11:07:08 +0000 (13:07 +0200)]
Pin older hp-health on DL3*0 G5

Latest hp-health doesn't seem to work on those boxes.

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoapt: do not download norwegian and french translations
Peter Palfrader [Tue, 26 Jul 2016 12:10:32 +0000 (14:10 +0200)]
apt: do not download norwegian and french translations

7 years agoAdd zprofile
Peter Palfrader [Tue, 26 Jul 2016 11:31:31 +0000 (13:31 +0200)]
Add zprofile

7 years agoSet TMOUT
Peter Palfrader [Tue, 26 Jul 2016 11:18:44 +0000 (13:18 +0200)]
Set TMOUT

7 years agoremove dc16 access to pg on vittoria (re: RT#6355)
Peter Palfrader [Mon, 25 Jul 2016 20:59:30 +0000 (22:59 +0200)]
remove dc16 access to pg on vittoria (re: RT#6355)

7 years agosetup-all-dchroots: create stretch chroots on mips64el
Aurelien Jarno [Sun, 24 Jul 2016 08:32:19 +0000 (10:32 +0200)]
setup-all-dchroots: create stretch chroots on mips64el

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agogive jenkins-adm access to the jenkins user and to service jenkins on the jenkins...
Peter Palfrader [Wed, 20 Jul 2016 17:07:22 +0000 (19:07 +0200)]
give jenkins-adm access to the jenkins user and to service jenkins on the jenkins host

7 years agosudoers: move voip stuff to other services
Peter Palfrader [Wed, 20 Jul 2016 17:06:31 +0000 (19:06 +0200)]
sudoers: move voip stuff to other services

7 years agocaballero is gone
Peter Palfrader [Sun, 17 Jul 2016 10:12:34 +0000 (12:12 +0200)]
caballero is gone

7 years agoftp.au.debian.org is very slow from mirror-anu
Peter Palfrader [Sat, 16 Jul 2016 07:07:48 +0000 (09:07 +0200)]
ftp.au.debian.org is very slow from mirror-anu

7 years agomirror.linux.org.au has been down for maintenance for several days, with no clear...
Peter Palfrader [Sat, 16 Jul 2016 06:59:58 +0000 (08:59 +0200)]
mirror.linux.org.au has been down for maintenance for several days, with no clear estimate for return of service announced afaict

7 years agoStop using SSLCertificateChainFile
Julien Cristau [Mon, 4 Jul 2016 19:33:22 +0000 (21:33 +0200)]
Stop using SSLCertificateChainFile

It's deprecated since apache 2.4, the chain now lives with the
certificate.

7 years agorelease.debian.org/proposed-updates/ wants the multiviews option
Julien Cristau [Mon, 4 Jul 2016 15:49:56 +0000 (17:49 +0200)]
release.debian.org/proposed-updates/ wants the multiviews option

7 years agoAdjust release.d.o vhost
Julien Cristau [Mon, 4 Jul 2016 15:23:22 +0000 (17:23 +0200)]
Adjust release.d.o vhost

7 years agoAdd coccia as static source
Julien Cristau [Mon, 4 Jul 2016 13:57:31 +0000 (15:57 +0200)]
Add coccia as static source

7 years agoAdd static component for release.debian.org/proposed-updates
Julien Cristau [Mon, 4 Jul 2016 13:48:48 +0000 (15:48 +0200)]
Add static component for release.debian.org/proposed-updates

7 years agoMove and conditionalize release.d.o vhost
Julien Cristau [Mon, 4 Jul 2016 12:42:36 +0000 (14:42 +0200)]
Move and conditionalize release.d.o vhost

7 years agoMove release.d.o to static and letsencrypt
Julien Cristau [Mon, 4 Jul 2016 12:15:01 +0000 (14:15 +0200)]
Move release.d.o to static and letsencrypt

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agolucatelli: decomission
Héctor Orón Martínez [Sat, 2 Jul 2016 18:56:14 +0000 (20:56 +0200)]
lucatelli: decomission

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
7 years agoSwitch wiki.debian.org to letsencrypt
Aurelien Jarno [Fri, 1 Jul 2016 20:56:02 +0000 (22:56 +0200)]
Switch wiki.debian.org to letsencrypt

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoNo TLSA for wiki.debian.org for a while
Aurelien Jarno [Fri, 1 Jul 2016 18:14:42 +0000 (20:14 +0200)]
No TLSA for wiki.debian.org for a while

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoDecommission merulo
Julien Cristau [Wed, 29 Jun 2016 22:13:07 +0000 (00:13 +0200)]
Decommission merulo

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoSwitch bits.d.o and lintian.d.o to letsencrypt
Aurelien Jarno [Wed, 29 Jun 2016 21:24:42 +0000 (23:24 +0200)]
Switch bits.d.o and lintian.d.o to letsencrypt

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoNo TLSA for bits.d.o and lintian.d.o for a while
Aurelien Jarno [Wed, 29 Jun 2016 19:45:53 +0000 (21:45 +0200)]
No TLSA for bits.d.o and lintian.d.o for a while

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoSwitch people.debian.org to letsencrypt
Aurelien Jarno [Wed, 29 Jun 2016 19:25:47 +0000 (21:25 +0200)]
Switch people.debian.org to letsencrypt

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoNot TLSA for people.debian.org for a while
Aurelien Jarno [Wed, 29 Jun 2016 15:51:35 +0000 (17:51 +0200)]
Not TLSA for people.debian.org for a while

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoReplace self-signed veyepar.d.o cert with LE
Julien Cristau [Wed, 29 Jun 2016 14:46:36 +0000 (16:46 +0200)]
Replace self-signed veyepar.d.o cert with LE

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoHelps if I open the right port
Julien Cristau [Wed, 29 Jun 2016 13:30:18 +0000 (15:30 +0200)]
Helps if I open the right port

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAllow dc16 hosts to access postgres on vittoria
Julien Cristau [Wed, 29 Jun 2016 13:26:46 +0000 (15:26 +0200)]
Allow dc16 hosts to access postgres on vittoria

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAdd topinambour.cristau.org to DSA_IPS
Julien Cristau [Tue, 28 Jun 2016 20:40:59 +0000 (22:40 +0200)]
Add topinambour.cristau.org to DSA_IPS

7 years agoAdd people.do to DSA_IPs
Peter Palfrader [Tue, 28 Jun 2016 20:08:40 +0000 (22:08 +0200)]
Add people.do to DSA_IPs

7 years agoAdd mips-manda-01 and mipsel-manda-03
Aurelien Jarno [Tue, 28 Jun 2016 19:09:44 +0000 (21:09 +0200)]
Add mips-manda-01 and mipsel-manda-03

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoschroot: add the new dbgsym mirrors
Maximiliano Curia [Fri, 24 Jun 2016 08:35:51 +0000 (10:35 +0200)]
schroot: add the new dbgsym mirrors

This allows the installation of the autogenerated dbgsym packages in the porterbox images.

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agosudo: remove smetana and merulo from porterbox list
Julien Cristau [Sun, 26 Jun 2016 15:48:08 +0000 (17:48 +0200)]
sudo: remove smetana and merulo from porterbox list

7 years agonielsen has been decommissioned for a lot of time already
Aurelien Jarno [Sat, 25 Jun 2016 18:13:37 +0000 (20:13 +0200)]
nielsen has been decommissioned for a lot of time already

Also drop code that was only used by it.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agomundy has been decommissioned for a lot of time already
Aurelien Jarno [Sat, 25 Jun 2016 18:12:49 +0000 (20:12 +0200)]
mundy has been decommissioned for a lot of time already

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agobeethoven has been decommissioned for a lot of time already
Aurelien Jarno [Sat, 25 Jun 2016 18:05:34 +0000 (20:05 +0200)]
beethoven has been decommissioned for a lot of time already

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoRemove more decommissioned hosts
Aurelien Jarno [Sat, 25 Jun 2016 17:57:06 +0000 (19:57 +0200)]
Remove more decommissioned hosts

allegri.debian.org
berlioz.debian.org
escher.debian.org
lamb.debian.org
lafayette.debian.org
locke.debian.org
malo.debian.org
samosa.debian.org

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoalkman has been decommissioned for a lot of time already
Aurelien Jarno [Sat, 25 Jun 2016 15:13:02 +0000 (17:13 +0200)]
alkman has been decommissioned for a lot of time already

Also drop code that was only used by it.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoFix a typo in powerpc-osuosl-01 host name
Aurelien Jarno [Sat, 25 Jun 2016 09:47:31 +0000 (11:47 +0200)]
Fix a typo in powerpc-osuosl-01 host name

powerpc-ousosl-01 => powerpc-osuosl-01

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agomayr.debian.org has been decommissioned for a lot of time
Aurelien Jarno [Fri, 24 Jun 2016 22:26:59 +0000 (00:26 +0200)]
mayr.debian.org has been decommissioned for a lot of time

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoAdd mips-sil-01 and mipsel-sil-01
Aurelien Jarno [Fri, 24 Jun 2016 22:26:07 +0000 (00:26 +0200)]
Add mips-sil-01 and mipsel-sil-01

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agodo not do anything with the buildd module until we have the buildd user from ldap
Peter Palfrader [Fri, 24 Jun 2016 16:36:29 +0000 (18:36 +0200)]
do not do anything with the buildd module until we have the buildd user from ldap

7 years agoretire ia64-arm-01
Peter Palfrader [Fri, 24 Jun 2016 16:18:38 +0000 (18:18 +0200)]
retire ia64-arm-01

7 years agono backups of arm-arm-04
Peter Palfrader [Fri, 24 Jun 2016 16:18:28 +0000 (18:18 +0200)]
no backups of arm-arm-04

7 years agoSwitch appstream, qa, *.dgit to letsencrypt
Julien Cristau [Mon, 20 Jun 2016 10:58:40 +0000 (12:58 +0200)]
Switch appstream, qa, *.dgit to letsencrypt

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoAlso temporarily remove TLSA records for *.dgit and appstream
Julien Cristau [Mon, 20 Jun 2016 07:53:50 +0000 (09:53 +0200)]
Also temporarily remove TLSA records for *.dgit and appstream

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoNo TLSA for qa.debian.org for a while
Julien Cristau [Mon, 20 Jun 2016 07:51:08 +0000 (09:51 +0200)]
No TLSA for qa.debian.org for a while

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoDeploy certs for blends, release, security-team and wnpp-by-tags
Peter Palfrader [Sun, 19 Jun 2016 22:03:18 +0000 (00:03 +0200)]
Deploy certs for blends, release, security-team and wnpp-by-tags

7 years agoadd more space
Peter Palfrader [Sun, 19 Jun 2016 22:02:52 +0000 (00:02 +0200)]
add more space

7 years agoadd comments
Peter Palfrader [Sun, 19 Jun 2016 22:02:34 +0000 (00:02 +0200)]
add comments

7 years agoDo ssl for blends, security-team, and wnpp-by-tags
Peter Palfrader [Sun, 19 Jun 2016 22:38:07 +0000 (00:38 +0200)]
Do ssl for blends, security-team, and wnpp-by-tags

7 years agoStop trusting the SPI CA for debian.org services.
Paul Wise [Sun, 19 Jun 2016 03:04:33 +0000 (11:04 +0800)]
Stop trusting the SPI CA for debian.org services.

The SPI CA certificate is no longer used by debian.org services.

See-also: 5125ae620e16738e841813dd2f4135cb1eadb00e

7 years agoSync update-ca-certificates-dsa with stretch update-ca-certificates
Paul Wise [Sun, 19 Jun 2016 03:02:58 +0000 (11:02 +0800)]
Sync update-ca-certificates-dsa with stretch update-ca-certificates

7 years agoDelete openstack.bm.d.o ssl cert
Julien Cristau [Sat, 18 Jun 2016 16:55:41 +0000 (18:55 +0200)]
Delete openstack.bm.d.o ssl cert

It's not in use, and about to expire.  And since this was the last user
of DEBIAN-CA, delete that too.

7 years agoupdate (unused, commented-out) man-da upstream nameservers, re: RT#6279
Peter Palfrader [Fri, 17 Jun 2016 19:40:37 +0000 (21:40 +0200)]
update (unused, commented-out) man-da upstream nameservers, re: RT#6279