Peter Palfrader [Mon, 11 Jan 2016 11:54:31 +0000 (11:54 +0000)]
fix syncproxy manifest site name
Peter Palfrader [Mon, 11 Jan 2016 11:51:31 +0000 (12:51 +0100)]
have security rsync bind to specific address
Peter Palfrader [Mon, 11 Jan 2016 11:46:02 +0000 (12:46 +0100)]
Add IP addresses for mirror-anu in its role as syncproxy.au
Paul Wise [Sun, 10 Jan 2016 22:15:00 +0000 (06:15 +0800)]
Give d-i folks access to rebuild the d-i website
Aurelien Jarno [Sat, 9 Jan 2016 15:04:20 +0000 (16:04 +0100)]
rng-tools: yet another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:19:49 +0000 (15:19 +0100)]
rng-tools: another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:02:58 +0000 (15:02 +0100)]
Enable rng-tools module on linux
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 13:22:08 +0000 (14:22 +0100)]
Install rng-tools if there is a /dev/hwrng device
We can then provide entropy to the guests using virtio-rng.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Fri, 8 Jan 2016 21:12:57 +0000 (21:12 +0000)]
Make an apache site for syncproxies
Peter Palfrader [Fri, 8 Jan 2016 21:12:35 +0000 (21:12 +0000)]
use https in our default index page
Peter Palfrader [Fri, 8 Jan 2016 20:35:26 +0000 (21:35 +0100)]
vars need a $
Peter Palfrader [Fri, 8 Jan 2016 20:34:01 +0000 (21:34 +0100)]
move bind addresses to vars
Peter Palfrader [Fri, 8 Jan 2016 20:30:31 +0000 (21:30 +0100)]
klecker gets dsa-rsync from being a syncproxy
Peter Palfrader [Fri, 8 Jan 2016 20:29:17 +0000 (21:29 +0100)]
Add klecker to the syncproxy role
Peter Palfrader [Fri, 8 Jan 2016 08:35:54 +0000 (09:35 +0100)]
remove schein from security-mirror group
Aurelien Jarno [Thu, 7 Jan 2016 15:41:12 +0000 (16:41 +0100)]
debian.c3sl.ufpr.br is actually ftp.br.debian.org
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Thu, 7 Jan 2016 15:37:15 +0000 (16:37 +0100)]
update unicamp netrange
In addition, use the whole range allocated to unicamp instead of the
debian range to cope with (fortunately unlikely) future IP changes.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Wed, 6 Jan 2016 21:32:26 +0000 (22:32 +0100)]
Get rid of buildd-{lenny,squeeze,wheezy} shares on security-master rsync
Peter Palfrader [Wed, 6 Jan 2016 21:31:36 +0000 (22:31 +0100)]
log rsync for syncproxy and security to dedicated logs
Peter Palfrader [Wed, 6 Jan 2016 12:28:43 +0000 (13:28 +0100)]
No SRV support in jessie apt
Peter Palfrader [Wed, 6 Jan 2016 12:27:30 +0000 (13:27 +0100)]
Use deb.debian.org as the default mirror to test it
Peter Palfrader [Wed, 6 Jan 2016 12:26:46 +0000 (13:26 +0100)]
mirror.nl.leaseweb.nl is out of date
Peter Palfrader [Mon, 4 Jan 2016 20:40:37 +0000 (21:40 +0100)]
Add mirror-umn to syncproxy
Peter Palfrader [Mon, 4 Jan 2016 20:40:22 +0000 (21:40 +0100)]
set security IP address for mirror-umn
Julien Cristau [Sat, 2 Jan 2016 22:40:38 +0000 (23:40 +0100)]
Better if the static mirrors get the d-i.d.o cert
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:36:19 +0000 (23:36 +0100)]
HTTPS for d-i.debian.org (rt#6049)
Drop the ServerAlias, we're not using it and the ssl macro doesn't mix
with extra.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:28:21 +0000 (23:28 +0100)]
Revert "static-mirroring: add common-static-vhost-ssl-with-extra macro"
This reverts commit
8f4f534e4d36f406477077c09d113982014e49e9.
That's not going to work out.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:22:20 +0000 (23:22 +0100)]
static-mirroring: add common-static-vhost-ssl-with-extra macro
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:00:54 +0000 (23:00 +0100)]
add d-i.debian.org ssl cert
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 2 Jan 2016 20:21:21 +0000 (20:21 +0000)]
Attempt to configure an apache vhost for a static component only if it exists on this host, part 2
Julien Cristau [Sat, 2 Jan 2016 20:12:13 +0000 (21:12 +0100)]
switch my root ssh key to one stored on a yubikey
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 2 Jan 2016 19:58:00 +0000 (19:58 +0000)]
Attempt to configure an apache vhost for a static component only if it exists on this host, part 1
Aurelien Jarno [Sat, 2 Jan 2016 16:55:19 +0000 (17:55 +0100)]
Revert "cron.d/dsa-buildd: only look for .upload files"
This reverts commit
df6c4329e9b0395d76d7170581907c70116ecebf.
Instead change buildd to avoid the condition to happen.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 2 Jan 2016 15:37:08 +0000 (16:37 +0100)]
cron.d/dsa-buildd: only look for .upload files
Only look for .upload files, and use their contents to determine which
files to delete. This avoid triggering reuploads when the package has
been built before midnight, but uploaded after midnight.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Wed, 30 Dec 2015 20:04:28 +0000 (21:04 +0100)]
allow gitdoadm to sudo to git
Peter Palfrader [Tue, 29 Dec 2015 22:02:46 +0000 (23:02 +0100)]
retire delfin-srv
Peter Palfrader [Tue, 29 Dec 2015 21:51:52 +0000 (22:51 +0100)]
Add delfin-lvm
Peter Palfrader [Tue, 29 Dec 2015 21:39:30 +0000 (22:39 +0100)]
retire bmdb1-srv
Peter Palfrader [Tue, 29 Dec 2015 20:31:14 +0000 (21:31 +0100)]
Add bmdb1-lvm
Martin Zobel-Helas [Sat, 26 Dec 2015 12:39:13 +0000 (12:39 +0000)]
add vittoria to ferm rules
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sat, 26 Dec 2015 12:34:41 +0000 (12:34 +0000)]
add vittoria to postgres hosts
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 25 Dec 2015 10:32:22 +0000 (10:32 +0000)]
set different path for lintian, to avoid backup of autogenerated material every day.
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Julien Cristau [Fri, 25 Dec 2015 00:48:56 +0000 (01:48 +0100)]
ftpmaster changed archive layout on franck
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Thu, 24 Dec 2015 12:19:01 +0000 (13:19 +0100)]
rsyncd-dakmaster.conf update from Joerg
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Tue, 22 Dec 2015 05:57:03 +0000 (06:57 +0100)]
Point to https://debian.org/mirror/size for size
Peter Palfrader [Mon, 21 Dec 2015 19:26:28 +0000 (20:26 +0100)]
change order
Peter Palfrader [Mon, 21 Dec 2015 19:25:55 +0000 (20:25 +0100)]
also replace dashes
Peter Palfrader [Mon, 21 Dec 2015 19:25:47 +0000 (20:25 +0100)]
change order
Peter Palfrader [Mon, 21 Dec 2015 19:22:01 +0000 (20:22 +0100)]
fix syntax
Peter Palfrader [Mon, 21 Dec 2015 19:21:18 +0000 (20:21 +0100)]
make syncproxy rsync.conf a template
Peter Palfrader [Mon, 21 Dec 2015 19:18:14 +0000 (20:18 +0100)]
Add more paths
Peter Palfrader [Mon, 21 Dec 2015 19:18:07 +0000 (20:18 +0100)]
refactor debian-org/lib/facter/paths.rb facter
Peter Palfrader [Mon, 21 Dec 2015 19:09:10 +0000 (20:09 +0100)]
Add mirror-isc to syncproxy role, update conf
Peter Palfrader [Mon, 21 Dec 2015 18:44:58 +0000 (19:44 +0100)]
Add deb.d.o vhost
Peter Palfrader [Mon, 21 Dec 2015 18:36:00 +0000 (19:36 +0100)]
Add a deb.debian.org static component
Peter Palfrader [Mon, 21 Dec 2015 18:15:51 +0000 (19:15 +0100)]
syntax fix
Peter Palfrader [Mon, 21 Dec 2015 18:12:54 +0000 (19:12 +0100)]
Set bind address for security rsync
Peter Palfrader [Mon, 21 Dec 2015 18:08:59 +0000 (19:08 +0100)]
Set IP address for static mirror and debug for mirror-isc
Peter Palfrader [Mon, 21 Dec 2015 09:27:34 +0000 (10:27 +0100)]
debian.inode.at dropped sparc
Julien Cristau [Sun, 20 Dec 2015 15:28:34 +0000 (16:28 +0100)]
decommission bizet
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sun, 20 Dec 2015 11:57:37 +0000 (12:57 +0100)]
fix template
Peter Palfrader [Sun, 20 Dec 2015 11:56:09 +0000 (12:56 +0100)]
rename file
Peter Palfrader [Sun, 20 Dec 2015 11:55:01 +0000 (12:55 +0100)]
Add debug mirror
Peter Palfrader [Sat, 19 Dec 2015 11:45:27 +0000 (12:45 +0100)]
more debconf static stuff
Peter Palfrader [Sat, 19 Dec 2015 11:43:00 +0000 (12:43 +0100)]
Add static debconf pages
Aurelien Jarno [Thu, 17 Dec 2015 23:04:28 +0000 (00:04 +0100)]
Disable jessie-proposed-update repo for mips machines
The fix we need for the build daemons is now in the jessie-security
kernel.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Thu, 17 Dec 2015 15:53:27 +0000 (16:53 +0100)]
repro needs a restart to reload the cert
Peter Palfrader [Thu, 17 Dec 2015 15:49:18 +0000 (16:49 +0100)]
reload repro when www.debian.org cert changes
Peter Palfrader [Wed, 16 Dec 2015 20:19:30 +0000 (21:19 +0100)]
remove beach from nfs, add buxtehude instead
Peter Palfrader [Wed, 16 Dec 2015 07:27:33 +0000 (08:27 +0100)]
lw04 is now a ProLiant ML150 G5, and hp-health does not support that
Peter Palfrader [Sun, 13 Dec 2015 15:36:47 +0000 (16:36 +0100)]
Revert "Temporarily do not use mirror-ubc"
This reverts commit
7207fb5b8c2d19d5ee7f80c6e66e63c3351ed339.
Peter Palfrader [Sun, 13 Dec 2015 14:00:50 +0000 (15:00 +0100)]
Remove multipath defaults section
Peter Palfrader [Sun, 13 Dec 2015 12:05:08 +0000 (13:05 +0100)]
Temporarily do not use mirror-ubc
Tollef Fog Heen [Sat, 12 Dec 2015 12:17:40 +0000 (13:17 +0100)]
Use security-cdn.d.o instead of security.d.o
Peter Palfrader [Fri, 11 Dec 2015 18:46:09 +0000 (19:46 +0100)]
bunch of updated certs
Peter Palfrader [Fri, 11 Dec 2015 11:54:18 +0000 (12:54 +0100)]
move network-test master to dillon
Peter Palfrader [Fri, 11 Dec 2015 11:49:07 +0000 (12:49 +0100)]
Move planet, bits and network-test also from bizet since the sources are all in europe
Peter Palfrader [Fri, 11 Dec 2015 11:25:42 +0000 (12:25 +0100)]
move static-master for www to dillon
Peter Palfrader [Fri, 11 Dec 2015 08:55:54 +0000 (09:55 +0100)]
Update several certs
Peter Palfrader [Wed, 9 Dec 2015 22:21:42 +0000 (23:21 +0100)]
munin cleanup cronjob
Peter Palfrader [Mon, 7 Dec 2015 09:32:49 +0000 (10:32 +0100)]
remove comment
Aurelien Jarno [Tue, 8 Dec 2015 14:12:12 +0000 (15:12 +0100)]
cron.d/dsa-buildd: cleanup upload queues
The security upload queue is not cleaned after packages are accepted as
mails are not sent for security reasons. The standard upload queue is not
also not always cleaned as packages can be rejected (new version, out-of
date chroot with Built-Using, etc.)
Automatically cleanup upload queues by removing files older than 60
days. After this time it's probably better to rebuild the package with
an up-to-date chroot.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Mon, 7 Dec 2015 20:14:48 +0000 (21:14 +0100)]
Push to -isc
Peter Palfrader [Mon, 7 Dec 2015 19:56:19 +0000 (19:56 +0000)]
create static-components.conf from a yaml file, re-add -anu, but let it mirror only www
Julien Cristau [Mon, 7 Dec 2015 14:02:39 +0000 (15:02 +0100)]
nagios can run hpssacli via sudo
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Mon, 7 Dec 2015 09:27:52 +0000 (10:27 +0100)]
Not convinced mirror-anu should be a static mirror
Julien Cristau [Mon, 7 Dec 2015 08:46:12 +0000 (09:46 +0100)]
install hpssacli on HP servers
Replaces hpacucli.
Peter Palfrader [Mon, 7 Dec 2015 08:45:20 +0000 (09:45 +0100)]
Also add static_mirror_nopush hosts to static_mirror
Peter Palfrader [Mon, 7 Dec 2015 08:39:46 +0000 (09:39 +0100)]
Add mirror-isc to static_mirror_nopush
Julien Cristau [Sun, 6 Dec 2015 23:31:09 +0000 (00:31 +0100)]
move mirror-csail back to static_mirror
Signed-off-by: Julien Cristau <jcristau@debian.org>
Paul Wise [Sun, 6 Dec 2015 02:21:03 +0000 (10:21 +0800)]
Set the right permissions for Apache logs on weblog_providers
Peter Palfrader [Sat, 5 Dec 2015 18:16:58 +0000 (19:16 +0100)]
we do want backups of mirror-{anu,isc,umn}
Peter Palfrader [Sat, 5 Dec 2015 18:16:47 +0000 (19:16 +0100)]
mirror-anu must not be in apache2_www_mirror if it is in static
Peter Palfrader [Sat, 5 Dec 2015 18:16:29 +0000 (19:16 +0100)]
We do not want to block static syncs on mirror-* yet
Aurelien Jarno [Sat, 5 Dec 2015 13:36:40 +0000 (14:36 +0100)]
update unicamp netrange
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Martin Zobel-Helas [Fri, 4 Dec 2015 16:39:41 +0000 (16:39 +0000)]
remove for now again
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 4 Dec 2015 16:26:27 +0000 (16:26 +0000)]
add mirror-isc and mirror-umn
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 4 Dec 2015 14:14:16 +0000 (14:14 +0000)]
add mirror-anu.debian.org
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Wed, 2 Dec 2015 21:45:51 +0000 (22:45 +0100)]
Allow rusca to access the main cluster on bmdb1
Peter Palfrader [Wed, 2 Dec 2015 18:25:46 +0000 (19:25 +0100)]
sudo for %debian-r