Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi
We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-
20171122
Peter Palfrader [Wed, 17 Oct 2018 13:11:27 +0000 (15:11 +0200)]
try to switch dnsnodeapi-ACL over to the TSIG key
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann
it's used to create the autoremoval hints
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu
everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.
Peter Palfrader [Fri, 12 Oct 2018 12:28:31 +0000 (14:28 +0200)]
fix onion_v4_addr in debug class
Peter Palfrader [Fri, 12 Oct 2018 12:26:37 +0000 (14:26 +0200)]
fix onion role for debug
Peter Palfrader [Fri, 12 Oct 2018 12:21:04 +0000 (14:21 +0200)]
put -debug webserver and onion config onto mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 09:11:52 +0000 (11:11 +0200)]
do fail2ban on postfix AUTH attempts on lists.d.o
Peter Palfrader [Thu, 11 Oct 2018 16:04:22 +0000 (18:04 +0200)]
retire old DNS root key
Peter Palfrader [Wed, 10 Oct 2018 09:19:35 +0000 (11:19 +0200)]
drop manual blacklist of smtp abusers
Peter Palfrader [Wed, 10 Oct 2018 09:19:12 +0000 (11:19 +0200)]
use fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)
Peter Palfrader [Wed, 10 Oct 2018 08:34:08 +0000 (10:34 +0200)]
Add smtp_protocol_error to log_selector
We want to learn when clients try to use AUTH LOGIN and friends so we
can block them more easily.
Peter Palfrader [Wed, 10 Oct 2018 08:24:14 +0000 (10:24 +0200)]
more
Peter Palfrader [Wed, 10 Oct 2018 08:19:14 +0000 (10:19 +0200)]
more
Peter Palfrader [Wed, 10 Oct 2018 08:15:41 +0000 (10:15 +0200)]
netfilter DROP traffic from some mail abusers
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups). re: #7513)
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki
The URLs could change to the website or elsewhere at some point.
Suggested-by: weasel
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement
See-also: https://trac.torproject.org/projects/tor/ticket/27849
Peter Palfrader [Fri, 14 Sep 2018 12:23:39 +0000 (14:23 +0200)]
we send mail from nagios@. make it exist
Peter Palfrader [Thu, 23 Aug 2018 07:46:56 +0000 (09:46 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket more
Peter Palfrader [Wed, 22 Aug 2018 09:14:56 +0000 (11:14 +0200)]
and get dependency right
Peter Palfrader [Wed, 22 Aug 2018 09:14:37 +0000 (11:14 +0200)]
Add munin-async service to the catalog
Peter Palfrader [Wed, 22 Aug 2018 09:11:11 +0000 (11:11 +0200)]
Set munin-async restart time to 10sec
Sometimes munin-async fails to start, presumably because it cannot
connect to the running munind yet. The service file tells it to
restart always, but with the default sleep time before a restart of
100ms we often run into
systemd[1]: munin-async.service: Start request repeated too quickly.
after 5 fails attempts within a second or two.
Give munind more time to actually launch.
Peter Palfrader [Wed, 22 Aug 2018 08:56:51 +0000 (10:56 +0200)]
Start repro only after we are online
It fails to bind to its IP addresses otherwise.
Peter Palfrader [Wed, 22 Aug 2018 08:15:29 +0000 (10:15 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket
Peter Palfrader [Tue, 21 Aug 2018 20:48:10 +0000 (22:48 +0200)]
Also ask our nagios check if drbd is fine
Peter Palfrader [Tue, 21 Aug 2018 20:46:34 +0000 (22:46 +0200)]
ganeti-reboot-cluster: wait for drbd to have caught up
Peter Palfrader [Tue, 21 Aug 2018 14:04:04 +0000 (16:04 +0200)]
and a mirror
Peter Palfrader [Tue, 21 Aug 2018 14:02:39 +0000 (16:02 +0200)]
larger net
Peter Palfrader [Tue, 21 Aug 2018 14:00:02 +0000 (16:00 +0200)]
one more net
Peter Palfrader [Tue, 21 Aug 2018 13:57:57 +0000 (15:57 +0200)]
the amazon crawlers change IP address as soon as they are blocked
Peter Palfrader [Tue, 21 Aug 2018 13:48:53 +0000 (15:48 +0200)]
blacklist more amazon aws
Peter Palfrader [Tue, 21 Aug 2018 10:09:44 +0000 (12:09 +0200)]
blacklist 18.185.157.46 and 18.194.174.202
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: remove jessie-kfreebsd hacks
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots
Temporarily add stretch-proposed-updates for stretch-security chroots as requested
by the security team to handle Thunderbird and Firefox ESR 60.x releases. This should
be removed with the release of the 9.5 point release.
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
setup-all-dchroots: fix architecture list generation
Peter Palfrader [Sun, 19 Aug 2018 20:18:01 +0000 (22:18 +0200)]
Try one fewer threads per snapshot process
Peter Palfrader [Sun, 19 Aug 2018 09:44:29 +0000 (11:44 +0200)]
remove old cleanup items
Peter Palfrader [Sun, 19 Aug 2018 09:43:10 +0000 (11:43 +0200)]
Move default webpage from apache to webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:38:57 +0000 (11:38 +0200)]
Move creation of /run/dsa/shutdown-marker to a new common webserver module
Peter Palfrader [Thu, 16 Aug 2018 08:08:52 +0000 (10:08 +0200)]
setup-all-dchroots: Support rebuilding just one arch/suite
Peter Palfrader [Thu, 16 Aug 2018 08:07:17 +0000 (10:07 +0200)]
setup-all-dchroots: move DPKGARCH to where it's used
Peter Palfrader [Thu, 16 Aug 2018 08:05:03 +0000 (10:05 +0200)]
setup-all-dchroots: remove unused $UNAMEARCH
Peter Palfrader [Thu, 16 Aug 2018 08:04:53 +0000 (10:04 +0200)]
setup-all-dchroots: documentation comments
Peter Palfrader [Thu, 16 Aug 2018 08:02:23 +0000 (10:02 +0200)]
setup-all-dchroots: We use extraargs as a global variable, write it in caps
Peter Palfrader [Thu, 16 Aug 2018 08:01:54 +0000 (10:01 +0200)]
setup-all-dchroots: get rid of obsolete variable "$extra" that is always the empty string
Peter Palfrader [Thu, 16 Aug 2018 08:01:01 +0000 (10:01 +0200)]
setup-all-dchroots: move all main code to after function declarations
Peter Palfrader [Thu, 16 Aug 2018 07:50:34 +0000 (09:50 +0200)]
setup-all-dchroots: copy from tor: -c support
Add option to just write config files. Also revamps parameter parsing.
Peter Palfrader [Thu, 16 Aug 2018 07:40:33 +0000 (09:40 +0200)]
setup-all-dchroots: tabs to spaces
Julien Cristau [Wed, 15 Aug 2018 17:08:49 +0000 (19:08 +0200)]
Add bttracker alias to the cdimage maintenance vhost
Julien Cristau [Wed, 15 Aug 2018 06:36:40 +0000 (08:36 +0200)]
Create missing directory
Julien Cristau [Wed, 15 Aug 2018 06:31:18 +0000 (08:31 +0200)]
Prepare maintenance page for cdimage.d.o and friends
Héctor Orón Martínez [Tue, 14 Aug 2018 14:18:50 +0000 (16:18 +0200)]
Add diversity@d.o to various exim config bits
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Héctor Orón Martínez [Sun, 12 Aug 2018 16:03:35 +0000 (18:03 +0200)]
porterbox: install dgit. rt#7366
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Julien Cristau [Tue, 7 Aug 2018 08:44:49 +0000 (10:44 +0200)]
Don't manage salsa's /run/redis
Permissions conflicts with the package's
/usr/lib/tmpfiles.d/redis-server.conf so we keep changing them and
restarting the service needlessly.
Peter Palfrader [Tue, 7 Aug 2018 08:18:02 +0000 (10:18 +0200)]
all our hosts still want stretch::network_online though
Peter Palfrader [Tue, 7 Aug 2018 08:17:05 +0000 (10:17 +0200)]
bacula-fd: se ipv6 address from ldap since DNS during boot is icky
Peter Palfrader [Tue, 7 Aug 2018 08:12:31 +0000 (10:12 +0200)]
get our ipv[46] ldap addresses
Peter Palfrader [Tue, 7 Aug 2018 07:35:08 +0000 (09:35 +0200)]
bacula-fd: wait for unbound also
Julien Cristau [Tue, 7 Aug 2018 07:11:57 +0000 (09:11 +0200)]
Revert "allow access to pg on vittoria for dc18"
This reverts commit
21edc51f3c8a84ec014b0f0bffc8ebd972b6b2f2.
Julien Cristau [Tue, 7 Aug 2018 07:11:53 +0000 (09:11 +0200)]
Revert "RT#7368: add additional IP"
This reverts commit
e764ff0ec7eaccac713c15cb4c3fb284649b850b.
Peter Palfrader [Tue, 7 Aug 2018 07:03:15 +0000 (09:03 +0200)]
wait until after network-online.target for bacula-fd
Julien Cristau [Mon, 6 Aug 2018 16:27:22 +0000 (18:27 +0200)]
Decommission powerpc-osuosl-01
Julien Cristau [Mon, 6 Aug 2018 16:03:50 +0000 (18:03 +0200)]
Decommission powerpc-unicamp-01
Luca Filipozzi [Mon, 6 Aug 2018 07:48:00 +0000 (00:48 -0700)]
add 'do not modify' headers
Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
Luca Filipozzi [Mon, 6 Aug 2018 07:20:52 +0000 (00:20 -0700)]
action RT#7389 - debconf19.debconf.org setup
Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
Luca Filipozzi [Fri, 3 Aug 2018 15:23:44 +0000 (15:23 +0000)]
action RT#7389 - debconf19.debconf.org setup
Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
Luca Filipozzi [Fri, 3 Aug 2018 10:22:24 +0000 (10:22 +0000)]
complete RT#7389
Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
Luca Filipozzi [Fri, 3 Aug 2018 10:07:14 +0000 (10:07 +0000)]
re-add vhost after x509 certificate issuance
Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
Luca Filipozzi [Fri, 3 Aug 2018 09:43:22 +0000 (09:43 +0000)]
revert vhost until x509 cert deployed
Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
Luca Filipozzi [Fri, 3 Aug 2018 09:36:00 +0000 (09:36 +0000)]
action RT#7389 - debconf19.debconf.org setup
Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
Peter Palfrader [Fri, 3 Aug 2018 07:59:54 +0000 (09:59 +0200)]
bacula-sd: listen on ipv6
Peter Palfrader [Fri, 3 Aug 2018 07:56:57 +0000 (09:56 +0200)]
allow ipv6 connections to all clients from the bacula director
Peter Palfrader [Fri, 3 Aug 2018 07:56:39 +0000 (09:56 +0200)]
bacula-ferm: we do not need to explicitly allow connections from localhost
Peter Palfrader [Fri, 3 Aug 2018 07:53:12 +0000 (09:53 +0200)]
whitespace fix
Peter Palfrader [Fri, 3 Aug 2018 07:53:05 +0000 (09:53 +0200)]
bacula: reorder a statement (should cause no effective change)
Peter Palfrader [Tue, 31 Jul 2018 11:15:05 +0000 (13:15 +0200)]
add Forwarded-For header
Peter Palfrader [Tue, 31 Jul 2018 11:14:51 +0000 (13:14 +0200)]
whitespace fixup
Peter Palfrader [Tue, 31 Jul 2018 08:30:10 +0000 (10:30 +0200)]
add a ,
Peter Palfrader [Tue, 31 Jul 2018 08:27:18 +0000 (10:27 +0200)]
bacula-fd: listen on both ipv4 and ipv6
Peter Palfrader [Tue, 31 Jul 2018 08:22:15 +0000 (10:22 +0200)]
Add has_v[46]_ldap key to nodeinfo['misc'] to say whether we have a v[46] address in ldap