mirror/dsa-puppet.git
6 years agoMake dsa-puppet-stuff a concat
Peter Palfrader [Mon, 25 Dec 2017 10:44:47 +0000 (11:44 +0100)]
Make dsa-puppet-stuff a concat

6 years agobacula-unlink-removed-volumes: do not remove .nobackup files
Peter Palfrader [Sun, 24 Dec 2017 14:27:12 +0000 (15:27 +0100)]
bacula-unlink-removed-volumes: do not remove .nobackup files

6 years agoAfter rotating log files, sleep a few seconds
Tollef Fog Heen [Sat, 23 Dec 2017 08:02:26 +0000 (09:02 +0100)]
After rotating log files, sleep a few seconds

This allows syslog to actually reopen files, we're seeing problems
where it's (probably) ignoring the signal since it's in the middle of
rotating already.

Since this runs from logrotate there should be no admin irritation
over it.

6 years agodisable unprivileged BPF loading
Peter Palfrader [Fri, 22 Dec 2017 20:35:33 +0000 (21:35 +0100)]
disable unprivileged BPF loading

6 years agoUse ftp.uk.debian.org instead of mirror.bytemark.co.uk at ARM
Aurelien Jarno [Thu, 21 Dec 2017 21:56:43 +0000 (22:56 +0100)]
Use ftp.uk.debian.org instead of mirror.bytemark.co.uk at ARM

Hopefully that will fix the chroot creation at ARM.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoRetire planeta.debian.net ServerAlias for planet.d.o
Julien Cristau [Tue, 19 Dec 2017 11:04:20 +0000 (12:04 +0100)]
Retire planeta.debian.net ServerAlias for planet.d.o

The DNS entry was owned by damog, who retired in 2015 (RT#5923).

6 years agoUse https instead of http for some redirects
Paul Wise [Sun, 17 Dec 2017 03:01:41 +0000 (11:01 +0800)]
Use https instead of http for some redirects

6 years agoIgnore unhealthy hosts for deciding which mirrors are the newest
Tollef Fog Heen [Wed, 13 Dec 2017 19:46:36 +0000 (20:46 +0100)]
Ignore unhealthy hosts for deciding which mirrors are the newest

This prevents the case we saw in #877966 where bad timing of a mirror
push led to an outage.  The disadvantage is that time might be moving
backwards instead, but giving out older packages (or dists/) is better
than giving out no files at all.

6 years agoHandle ConnectTimeout the same as ReadTimeout for mirror-health
Tollef Fog Heen [Tue, 12 Dec 2017 21:25:14 +0000 (22:25 +0100)]
Handle ConnectTimeout the same as ReadTimeout for mirror-health

6 years agoAdd lower-case redirects for all the top-level upper-case URLs on www.d.o
Paul Wise [Sun, 10 Dec 2017 01:32:12 +0000 (09:32 +0800)]
Add lower-case redirects for all the top-level upper-case URLs on d.o

Upper-case URLs on www.d.o were a terrible idea.

6 years agoRedirect debian.org/bugs to /Bugs (Closes: #883946)
Paul Wise [Sun, 10 Dec 2017 00:10:17 +0000 (08:10 +0800)]
Redirect debian.org/bugs to /Bugs (Closes: #883946)

6 years agoThe TCP BBR module is only available on stretch and later
Aurelien Jarno [Sat, 9 Dec 2017 23:14:17 +0000 (00:14 +0100)]
The TCP BBR module is only available on stretch and later

6 years agoSet referrer-policy to same-origin on debtags.d.o
Julien Cristau [Fri, 8 Dec 2017 16:43:27 +0000 (17:43 +0100)]
Set referrer-policy to same-origin on debtags.d.o

Per Enrico, "django needs referrers for POST requests"

6 years agoEnable TCP BBR on a bunch of hosts. Not all for now, but maybe we should. (re:...
Peter Palfrader [Fri, 8 Dec 2017 14:28:16 +0000 (15:28 +0100)]
Enable TCP BBR on a bunch of hosts.  Not all for now, but maybe we should.  (re: RT#6990)

6 years agoPut vhost for signup.salsa.debian.org on the salsa host (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:18:52 +0000 (23:18 +0100)]
Put vhost for signup.salsa.debian.org on the salsa host (re: RT#7008)

6 years agoPut cert for signup.salsa.debian.org on the salsa host (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:14:29 +0000 (23:14 +0100)]
Put cert for signup.salsa.debian.org on the salsa host (re: RT#7008)

6 years agoInstall packages for salsa registration app (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:06:58 +0000 (23:06 +0100)]
Install packages for salsa registration app (re: RT#7008)

6 years agoFixup sources.d.n setup
Julien Cristau [Tue, 5 Dec 2017 08:31:17 +0000 (09:31 +0100)]
Fixup sources.d.n setup

No static component means no vhost generated by the usual macros.

6 years agoAdd sources.d.n static vhost with redirect to sources.d.o
Julien Cristau [Tue, 5 Dec 2017 08:20:53 +0000 (09:20 +0100)]
Add sources.d.n static vhost with redirect to sources.d.o

6 years agoMake redirects from {volatile,women}.d.o to www.d.o use https
Julien Cristau [Mon, 4 Dec 2017 07:05:26 +0000 (08:05 +0100)]
Make redirects from {volatile,women}.d.o to d.o use https

6 years agoRemove dak's sudoers entry for code signing
Julien Cristau [Sun, 3 Dec 2017 16:33:40 +0000 (17:33 +0100)]
Remove dak's sudoers entry for code signing

6 years agoAdd planet_master role and planet-master.d.o vhost
Julien Cristau [Fri, 1 Dec 2017 20:53:05 +0000 (21:53 +0100)]
Add planet_master role and planet-master.d.o vhost

Access to the vhost is restricted to d.o hosts, the idea being it is
only to be used for testing.

6 years agoAnd fix a pronoun
Peter Palfrader [Thu, 30 Nov 2017 20:13:42 +0000 (21:13 +0100)]
And fix a pronoun

6 years agoMerge remote-tracking branch 'waldi/sudo-archvsync-runmirrors'
Peter Palfrader [Thu, 30 Nov 2017 20:13:25 +0000 (21:13 +0100)]
Merge remote-tracking branch 'waldi/sudo-archvsync-runmirrors'

* waldi/sudo-archvsync-runmirrors:
  Add comment to sudoers
  Allow sudo to runmirrors in the current location
  Make sudo set a special path for calls as archvsync user

6 years agoAdd comment to sudoers
Bastian Blank [Thu, 30 Nov 2017 20:10:50 +0000 (21:10 +0100)]
Add comment to sudoers

6 years agoAllow sudo to runmirrors in the current location
Bastian Blank [Thu, 30 Nov 2017 19:58:53 +0000 (20:58 +0100)]
Allow sudo to runmirrors in the current location

6 years agoMake sudo set a special path for calls as archvsync user
Bastian Blank [Thu, 30 Nov 2017 19:56:06 +0000 (20:56 +0100)]
Make sudo set a special path for calls as archvsync user

This allows consumers (primarily dak) to call tools of the archvsync
user without path.  This makes later switch to the packaged version
easier.

6 years agoRemove philp from experimental_apache
Julien Cristau [Thu, 30 Nov 2017 12:38:56 +0000 (13:38 +0100)]
Remove philp from experimental_apache

Upgraded to stretch.

6 years agoRedirect old children-distros page to new derivatives page
Paul Wise [Wed, 29 Nov 2017 08:16:36 +0000 (16:16 +0800)]
Redirect old children-distros page to new derivatives page

6 years agoinclude with the correct name
Peter Palfrader [Sun, 26 Nov 2017 13:30:18 +0000 (14:30 +0100)]
include with the correct name

6 years agoset vm dirty values
Peter Palfrader [Sun, 26 Nov 2017 13:29:17 +0000 (14:29 +0100)]
set vm dirty values

6 years agodo extra grub for grnet-node01,grnet-node02
Peter Palfrader [Sun, 26 Nov 2017 13:27:32 +0000 (14:27 +0100)]
do extra grub for grnet-node01,grnet-node02

6 years agoset elevator=deadline at grnet
Peter Palfrader [Sun, 26 Nov 2017 13:24:22 +0000 (14:24 +0100)]
set elevator=deadline at grnet

6 years agoAdd kantuser
Julien Cristau [Thu, 23 Nov 2017 18:06:30 +0000 (18:06 +0000)]
Add kantuser

6 years agoAdd kantuser volume at ubc
Julien Cristau [Thu, 23 Nov 2017 17:10:17 +0000 (17:10 +0000)]
Add kantuser volume at ubc

6 years agoset mode of /etc/default/locale to a+r
Peter Palfrader [Thu, 23 Nov 2017 08:47:45 +0000 (09:47 +0100)]
set mode of /etc/default/locale to a+r

6 years agoAdd extra netnod servers to ferm
Julien Cristau [Thu, 23 Nov 2017 00:34:50 +0000 (00:34 +0000)]
Add extra netnod servers to ferm

6 years agonamed: add more dnsnode server ACLs
Julien Cristau [Thu, 23 Nov 2017 00:08:27 +0000 (00:08 +0000)]
named: add more dnsnode server ACLs

6 years agoRemove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)
Peter Palfrader [Wed, 22 Nov 2017 18:14:25 +0000 (19:14 +0100)]
Remove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)

6 years agogive %list access to service {spamassassin,amavis} {reload,restart,stop,start}
Peter Palfrader [Wed, 22 Nov 2017 18:05:46 +0000 (19:05 +0100)]
give %list access to service {spamassassin,amavis} {reload,restart,stop,start}

6 years agosudo on listhosts: give list group access to postcat as postfix
Peter Palfrader [Wed, 22 Nov 2017 18:03:28 +0000 (19:03 +0100)]
sudo on listhosts: give list group access to postcat as postfix

6 years agoOnce more with feeling
Julien Cristau [Mon, 20 Nov 2017 10:10:15 +0000 (11:10 +0100)]
Once more with feeling

6 years agoEnable wsgi-py3 for tracker
Julien Cristau [Mon, 20 Nov 2017 10:08:58 +0000 (11:08 +0100)]
Enable wsgi-py3 for tracker

6 years agoremove ticharich from experimental_apache group
Julien Cristau [Mon, 20 Nov 2017 10:03:21 +0000 (11:03 +0100)]
remove ticharich from experimental_apache group

It's now on stretch

6 years agoReduce WAL retention from 21 to 14 days for bmdb1/debsources
Julien Cristau [Sun, 19 Nov 2017 11:51:05 +0000 (12:51 +0100)]
Reduce WAL retention from 21 to 14 days for bmdb1/debsources

6 years agoMerge remote-tracking branch 'stapelberg/mimetype'
Peter Palfrader [Tue, 14 Nov 2017 08:18:07 +0000 (09:18 +0100)]
Merge remote-tracking branch 'stapelberg/mimetype'

* stapelberg/mimetype:
  manpages: force content-type to text/plain for non-html .gz files

6 years agomanpages: force content-type to text/plain for non-html .gz files
Michael Stapelberg [Tue, 14 Nov 2017 08:15:23 +0000 (09:15 +0100)]
manpages: force content-type to text/plain for non-html .gz files

6 years agoDistinguish ssl/nossl access logs for planet-backend
Julien Cristau [Fri, 10 Nov 2017 23:03:32 +0000 (00:03 +0100)]
Distinguish ssl/nossl access logs for planet-backend

6 years agoRevert "install newer version of devscripts"
Julien Cristau [Fri, 10 Nov 2017 22:51:35 +0000 (23:51 +0100)]
Revert "install newer version of devscripts"

devscripts was updated in stretch-backports and now the hardcoded
version doesn't exist.

This reverts commit 55e8d03c4d97a031237a43a1aec3830b0dab5fc7.

6 years agoFix planet-backend.d.o
Julien Cristau [Fri, 10 Nov 2017 22:48:09 +0000 (23:48 +0100)]
Fix planet-backend.d.o

6 years agoadd ssl vhost for planet-backend
Julien Cristau [Fri, 10 Nov 2017 22:12:54 +0000 (23:12 +0100)]
add ssl vhost for planet-backend

6 years agoFix http://www.debian.org
Julien Cristau [Fri, 10 Nov 2017 13:00:51 +0000 (14:00 +0100)]
Fix http://www.debian.org

Thanks, paravoid

6 years agopicconi and pkgmirror-csail are on stretch, remove from experimental_apache
Julien Cristau [Wed, 8 Nov 2017 14:11:05 +0000 (15:11 +0100)]
picconi and pkgmirror-csail are on stretch, remove from experimental_apache

6 years agoFixup sources.d.o config
Julien Cristau [Mon, 6 Nov 2017 21:22:15 +0000 (22:22 +0100)]
Fixup sources.d.o config

6 years agoRotate fastly syslogs
Julien Cristau [Fri, 3 Nov 2017 15:20:06 +0000 (16:20 +0100)]
Rotate fastly syslogs

6 years agoReload syslog-ng after daemon.log rotation to prevent cron spam
Tollef Fog Heen [Wed, 1 Nov 2017 20:36:42 +0000 (21:36 +0100)]
Reload syslog-ng after daemon.log rotation to prevent cron spam

6 years agoseger's dak db is on postgresql 9.6
Julien Cristau [Wed, 1 Nov 2017 20:04:31 +0000 (21:04 +0100)]
seger's dak db is on postgresql 9.6

6 years agoDisable ftp:// on security-master
Julien Cristau [Wed, 1 Nov 2017 13:54:58 +0000 (14:54 +0100)]
Disable ftp:// on security-master

6 years agoTurn off ftp:// on ftp.debian.org
Julien Cristau [Wed, 1 Nov 2017 13:45:33 +0000 (14:45 +0100)]
Turn off ftp:// on ftp.debian.org

6 years agoTurn off ftp:// on security mirrors
Julien Cristau [Wed, 1 Nov 2017 13:41:47 +0000 (14:41 +0100)]
Turn off ftp:// on security mirrors

6 years agoAdd debsources role for sources.d.o
Julien Cristau [Wed, 1 Nov 2017 12:49:00 +0000 (13:49 +0100)]
Add debsources role for sources.d.o

6 years agoserial options that work on clementi hopefully will also work on czerny
Peter Palfrader [Tue, 31 Oct 2017 23:43:31 +0000 (00:43 +0100)]
serial options that work on clementi hopefully will also work on czerny

6 years agoDo not do serial on manda-hosts just yet
Peter Palfrader [Tue, 31 Oct 2017 23:23:03 +0000 (00:23 +0100)]
Do not do serial on manda-hosts just yet

6 years agopuppet managed grub on celemtni, czerny
Peter Palfrader [Tue, 31 Oct 2017 22:52:43 +0000 (23:52 +0100)]
puppet managed grub on celemtni, czerny

6 years agoDisable OCSP stapling on the default vhost
Julien Cristau [Mon, 30 Oct 2017 19:14:37 +0000 (20:14 +0100)]
Disable OCSP stapling on the default vhost

It can't work since we don't run an OCSP responder.

6 years agoFurther restrict access to cgi-bin on http://popcon.d.o
Julien Cristau [Sun, 29 Oct 2017 17:55:58 +0000 (18:55 +0100)]
Further restrict access to cgi-bin on popcon.d.o

6 years agoRemove unneeded bits from the http popcon vhost, and enable HSTS
Julien Cristau [Sun, 29 Oct 2017 17:52:26 +0000 (18:52 +0100)]
Remove unneeded bits from the http popcon vhost, and enable HSTS

6 years agoImport popcon.d.o apache vhost config
Julien Cristau [Sun, 29 Oct 2017 17:41:09 +0000 (18:41 +0100)]
Import popcon.d.o apache vhost config

6 years agoAdd ssl key/cert for popcon
Julien Cristau [Sun, 29 Oct 2017 08:37:28 +0000 (09:37 +0100)]
Add ssl key/cert for popcon

6 years agoredirect www.d.o to https
Peter Palfrader [Sat, 28 Oct 2017 08:45:39 +0000 (10:45 +0200)]
redirect www.d.o to https

6 years agowww: Split out onion hostname
Peter Palfrader [Sat, 28 Oct 2017 08:44:49 +0000 (10:44 +0200)]
www: Split out onion hostname

6 years agoSplit common-www.d.o into common-www.d.o and -inner
Peter Palfrader [Sat, 28 Oct 2017 08:43:34 +0000 (10:43 +0200)]
Split common-d.o into common-www.d.o and -inner

6 years agoAdd a comment
Peter Palfrader [Sat, 28 Oct 2017 08:40:43 +0000 (10:40 +0200)]
Add a comment

6 years agoremove obsolete ServerAlias entries for www-other
Peter Palfrader [Sat, 28 Oct 2017 08:39:36 +0000 (10:39 +0200)]
remove obsolete ServerAlias entries for www-other

6 years agoredirect www-other (i.e. debian.org, www.CC.d.o, www.d.CC) to https on www.debian...
Peter Palfrader [Sat, 28 Oct 2017 08:37:29 +0000 (10:37 +0200)]
redirect www-other (i.e. debian.org, CC.d.o, www.d.CC) to https on www.debian.org now

6 years agoreject package file names that could be used to install local files. Issue reported...
Peter Palfrader [Mon, 23 Oct 2017 13:43:32 +0000 (15:43 +0200)]
reject package file names that could be used to install local files.  Issue reported by Julian Andres Klode.

6 years agoCleanup experimental_apache role
Julien Cristau [Fri, 20 Oct 2017 06:12:39 +0000 (08:12 +0200)]
Cleanup experimental_apache role

Not needed on hosts running stretch

6 years agoMerge branch 'master' of ssh://handel.debian.org/~/dsa-puppet
Luca Filipozzi [Thu, 19 Oct 2017 00:59:41 +0000 (00:59 +0000)]
Merge branch 'master' of ssh://handel.debian.org/~/dsa-puppet

6 years agoremove custom casulana rules
Luca Filipozzi [Thu, 19 Oct 2017 00:58:44 +0000 (00:58 +0000)]
remove custom casulana rules

6 years agoRT#6923 - More users and groups
Martin Zobel-Helas [Wed, 18 Oct 2017 22:48:28 +0000 (18:48 -0400)]
RT#6923 - More users and groups

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoAdd mail filters for some aliases (rt#6227)
Julien Cristau [Wed, 18 Oct 2017 19:41:19 +0000 (21:41 +0200)]
Add mail filters for some aliases (rt#6227)

- add sender callout for leader, patents, trademark
- add greylisting for patents, trademark
- add RBLs for patents, trademark
- add RHSBLs for leader, patents, treasurer, trademark

6 years agoalways a typo
Luca Filipozzi [Wed, 18 Oct 2017 18:50:49 +0000 (18:50 +0000)]
always a typo

6 years agoprune ssh ACLs for luca
Luca Filipozzi [Wed, 18 Oct 2017 18:49:29 +0000 (18:49 +0000)]
prune ssh ACLs for luca

6 years agoadd more casulana rules for br1
Luca Filipozzi [Wed, 18 Oct 2017 17:59:54 +0000 (17:59 +0000)]
add more casulana rules for br1

6 years agoadd masquerade rules for casulana virtual machines
Luca Filipozzi [Wed, 18 Oct 2017 17:05:44 +0000 (17:05 +0000)]
add masquerade rules for casulana virtual machines

6 years agoundo casulana custom roles
Luca Filipozzi [Wed, 18 Oct 2017 00:26:37 +0000 (00:26 +0000)]
undo casulana custom roles

6 years agofix up the custom cloud-admins rule
Luca Filipozzi [Tue, 17 Oct 2017 23:13:57 +0000 (23:13 +0000)]
fix up the custom cloud-admins rule

6 years agocustom rule for cloud-builds on casaluna
Luca Filipozzi [Tue, 17 Oct 2017 23:11:59 +0000 (23:11 +0000)]
custom rule for cloud-builds on casaluna

6 years agoadd sudo access to group cloud-builds
Martin Zobel-Helas [Mon, 16 Oct 2017 20:46:14 +0000 (16:46 -0400)]
add sudo access to group cloud-builds

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agobmdb1 main cluster is back on timeline 1
Julien Cristau [Sun, 15 Oct 2017 10:22:30 +0000 (12:22 +0200)]
bmdb1 main cluster is back on timeline 1

6 years agoEnsure mirror-health is restarted after the daemon-reload
Tollef Fog Heen [Sun, 8 Oct 2017 05:34:43 +0000 (07:34 +0200)]
Ensure mirror-health is restarted after the daemon-reload

6 years agoDrop klecker from ftp.d.o mirror-health checking
Tollef Fog Heen [Sun, 8 Oct 2017 05:21:47 +0000 (07:21 +0200)]
Drop klecker from ftp.d.o mirror-health checking

klecker is not part of the set of backends that Fastly uses, so
checking against it has no value and might leave us unhealthy if
klecker is ahead.

6 years agomask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount
Peter Palfrader [Fri, 6 Oct 2017 08:25:10 +0000 (10:25 +0200)]
mask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount

6 years agoAdd a systemd::mask
Peter Palfrader [Fri, 6 Oct 2017 08:23:48 +0000 (10:23 +0200)]
Add a systemd::mask

6 years agoFix octal number in python script to it compiles
Peter Palfrader [Thu, 5 Oct 2017 09:43:36 +0000 (11:43 +0200)]
Fix octal number in python script to it compiles

6 years agoRevert "Use RedirectPermanent instead of RewriteRule"
Paul Wise [Thu, 5 Oct 2017 08:37:09 +0000 (16:37 +0800)]
Revert "Use RedirectPermanent instead of RewriteRule"

This reverts commit abb8a9a1d0c72a616e297be5a1b091b6c9a74191.

6 years agoUse RedirectPermanent instead of RewriteRule
Paul Wise [Thu, 5 Oct 2017 08:21:32 +0000 (16:21 +0800)]
Use RedirectPermanent instead of RewriteRule

6 years agoBetter debian-ports.org/debian-cd redirection
Aurelien Jarno [Thu, 5 Oct 2017 08:21:22 +0000 (10:21 +0200)]
Better debian-ports.org/debian-cd redirection

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoDrop remaining debian-ports-cd code
Aurelien Jarno [Thu, 5 Oct 2017 07:57:42 +0000 (09:57 +0200)]
Drop remaining debian-ports-cd code

6 years agoRedirect ftp.ports.debian.org/debian-ports-cd to cdimage
Aurelien Jarno [Thu, 5 Oct 2017 07:54:57 +0000 (09:54 +0200)]
Redirect ftp.ports.debian.org/debian-ports-cd to cdimage