Peter Palfrader [Fri, 9 Dec 2016 09:02:39 +0000 (09:02 +0000)]
move ntp munin checks to ntp module
Peter Palfrader [Fri, 9 Dec 2016 08:13:00 +0000 (08:13 +0000)]
Move ntp and ntpdate incldue into a time module
Peter Palfrader [Fri, 9 Dec 2016 08:10:58 +0000 (09:10 +0100)]
Let the puppet usergroup read puppet.conf
Aurelien Jarno [Thu, 8 Dec 2016 14:14:36 +0000 (15:14 +0100)]
decommission franck
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Thu, 8 Dec 2016 14:10:16 +0000 (15:10 +0100)]
Change /etc/puppet/puppet.conf mode to 0440
It contains a password on the master node.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Thu, 8 Dec 2016 09:59:43 +0000 (10:59 +0100)]
sudo from videoteam to sreview
Peter Palfrader [Sat, 3 Dec 2016 09:38:13 +0000 (10:38 +0100)]
raise HPKP timeout from 14 days to 60
Peter Palfrader [Thu, 1 Dec 2016 10:19:44 +0000 (10:19 +0000)]
install popcon
Peter Palfrader [Thu, 1 Dec 2016 10:18:48 +0000 (10:18 +0000)]
Use proper bacula port in bacula-idle-restart
Peter Palfrader [Wed, 30 Nov 2016 07:20:51 +0000 (08:20 +0100)]
Revert "Revert "move back to default bacula ports for ubc""
This reverts commit
24fc21e69a739a6465c51c4c7f950814bc656b5c.
Peter Palfrader [Tue, 29 Nov 2016 18:09:51 +0000 (19:09 +0100)]
Revert "move back to default bacula ports for ubc"
This reverts commit
9a3c9db00b1fe093ef39d584baf1d47b1c1fadb2.
Peter Palfrader [Tue, 29 Nov 2016 18:06:56 +0000 (19:06 +0100)]
move back to default bacula ports for ubc
Peter Palfrader [Sat, 26 Nov 2016 13:23:43 +0000 (14:23 +0100)]
kill munin-update jobs older than 2 hours
Peter Palfrader [Sat, 26 Nov 2016 11:43:14 +0000 (12:43 +0100)]
Merge ubcece (old IP address range) into ubc
Peter Palfrader [Sat, 26 Nov 2016 11:33:24 +0000 (11:33 +0000)]
Make bacula-idle-restart use ports defined in the manifest
Peter Palfrader [Sat, 26 Nov 2016 11:31:09 +0000 (11:31 +0000)]
Put client_port into the stored config
Peter Palfrader [Sat, 26 Nov 2016 11:30:42 +0000 (11:30 +0000)]
Set bacula_fd_port to 19102 for ubc
Peter Palfrader [Sat, 26 Nov 2016 11:30:26 +0000 (11:30 +0000)]
Allow hiera to override 9102 default for bacula client (fd) port
Peter Palfrader [Sat, 26 Nov 2016 11:29:57 +0000 (11:29 +0000)]
Use bacula_client_port variable in ferm rule instead of "bacula-fd" service port
Peter Palfrader [Fri, 25 Nov 2016 17:52:05 +0000 (18:52 +0100)]
give senfter a new apache
Peter Palfrader [Fri, 25 Nov 2016 14:26:27 +0000 (15:26 +0100)]
Do not return OCSP errors to clients
Peter Palfrader [Fri, 25 Nov 2016 14:22:29 +0000 (15:22 +0100)]
raise cache size
Peter Palfrader [Fri, 25 Nov 2016 14:11:54 +0000 (15:11 +0100)]
enable stapling on stretch apache2
Peter Palfrader [Fri, 25 Nov 2016 14:05:28 +0000 (15:05 +0100)]
syntax fix II
Peter Palfrader [Fri, 25 Nov 2016 14:05:03 +0000 (15:05 +0100)]
syntax fix I
Peter Palfrader [Fri, 25 Nov 2016 14:04:14 +0000 (15:04 +0100)]
Install new apache on draghi
Peter Palfrader [Fri, 25 Nov 2016 14:00:40 +0000 (15:00 +0100)]
package libapache2-mod-macro is obsolete
Peter Palfrader [Fri, 25 Nov 2016 14:00:11 +0000 (15:00 +0100)]
fix whitespace
Peter Palfrader [Fri, 25 Nov 2016 13:59:18 +0000 (13:59 +0000)]
Add an apache2 factoid for backported from stretch apache
Peter Palfrader [Sat, 19 Nov 2016 19:49:20 +0000 (20:49 +0100)]
backports static-master is now dillon, source on coccia
Martin Zobel-Helas [Thu, 17 Nov 2016 21:42:03 +0000 (22:42 +0100)]
Revert "massive amount of spam from that address"
This reverts commit
988ded1d84a750b2cb2fcd86a68869b77a7e1e37.
Martin Zobel-Helas [Thu, 17 Nov 2016 21:06:36 +0000 (22:06 +0100)]
massive amount of spam from that address
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Paul Wise [Sat, 12 Nov 2016 05:00:36 +0000 (13:00 +0800)]
Begin attempt at adding SSO for the Debian wiki
Peter Palfrader [Tue, 8 Nov 2016 20:18:53 +0000 (21:18 +0100)]
syntax fix
Peter Palfrader [Tue, 8 Nov 2016 20:18:02 +0000 (21:18 +0100)]
switch buildd repo to apt.buildd.debian.org
Peter Palfrader [Tue, 8 Nov 2016 19:47:21 +0000 (19:47 +0000)]
ship apt.buildd only to klecker and senfter
Peter Palfrader [Tue, 8 Nov 2016 19:47:12 +0000 (19:47 +0000)]
support shipping a component to just a few mirrors
Peter Palfrader [Tue, 8 Nov 2016 19:39:17 +0000 (19:39 +0000)]
Revert "refactor static-components.conf.erb a bit - no logic changes yet"
This reverts commit
6b4b367c4bad827e3917fc6622e01f847f49ce14.
Peter Palfrader [Tue, 8 Nov 2016 19:28:14 +0000 (20:28 +0100)]
refactor static-components.conf.erb a bit - no logic changes yet
Peter Palfrader [Tue, 8 Nov 2016 19:24:04 +0000 (20:24 +0100)]
Add apt.buildd.d.o
Peter Palfrader [Tue, 8 Nov 2016 19:00:56 +0000 (20:00 +0100)]
Make wuiet a static source
Peter Palfrader [Mon, 7 Nov 2016 10:18:48 +0000 (11:18 +0100)]
retire powell
Peter Palfrader [Mon, 7 Nov 2016 07:55:28 +0000 (08:55 +0100)]
Stop taking backups from franck
Aurelien Jarno [Sun, 6 Nov 2016 22:34:34 +0000 (23:34 +0100)]
setup-all-dchroots: powerpc/stretch is gone
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Fri, 4 Nov 2016 09:42:18 +0000 (10:42 +0100)]
do not set terminal type
Peter Palfrader [Fri, 4 Nov 2016 09:35:06 +0000 (10:35 +0100)]
ship a tmux.conf
Peter Palfrader [Thu, 3 Nov 2016 14:24:12 +0000 (15:24 +0100)]
Remove leap second config for debian <= 7
Peter Palfrader [Thu, 3 Nov 2016 13:37:56 +0000 (14:37 +0100)]
Comment out security linux -> cdn redirect
Aurelien Jarno [Tue, 1 Nov 2016 11:51:57 +0000 (12:51 +0100)]
weblogsync: Synchronize public logs in additions of debian.org logs
Commit
b8a50b04 has broken the synchronisation of non www.debian.org
public logs. Fix that.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sun, 30 Oct 2016 19:24:30 +0000 (20:24 +0100)]
Give projectb access to usper
Requested by Joerg Jaspert for the deferred queue overview.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 29 Oct 2016 21:11:41 +0000 (23:11 +0200)]
Move backports-debian.org redirection from fasolo to static
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Julien Cristau [Sat, 29 Oct 2016 13:38:48 +0000 (15:38 +0200)]
fasolo is a static master and source
Julien Cristau [Sat, 29 Oct 2016 13:36:42 +0000 (15:36 +0200)]
fasolo is master for backports / incoming / metadata.ftp-master
Peter Palfrader [Sat, 29 Oct 2016 07:26:54 +0000 (09:26 +0200)]
remove dacs
Peter Palfrader [Thu, 27 Oct 2016 18:42:56 +0000 (20:42 +0200)]
add comment
Peter Palfrader [Thu, 27 Oct 2016 18:41:38 +0000 (20:41 +0200)]
Update leap-seconds.list
Peter Palfrader [Tue, 25 Oct 2016 11:38:26 +0000 (13:38 +0200)]
raise max-age for HTTP Public Key Pins from 3 days to 2 weeks
Peter Palfrader [Tue, 25 Oct 2016 08:18:10 +0000 (10:18 +0200)]
rename ubc-enc2b9 to ubc-enc2bl09
Peter Palfrader [Tue, 25 Oct 2016 08:11:38 +0000 (10:11 +0200)]
rename ubc-enc2b2 to ubc-enc2bl02
Peter Palfrader [Tue, 25 Oct 2016 07:53:49 +0000 (09:53 +0200)]
rename ubc-enc2b1 to ubc-enc2bl01
Julien Cristau [Mon, 24 Oct 2016 16:46:24 +0000 (18:46 +0200)]
No more ftpd on franck
Aurelien Jarno [Sat, 22 Oct 2016 20:21:30 +0000 (22:21 +0200)]
Add ftp.upload and ssh.upload roles to usper.d.o
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 22 Oct 2016 16:44:35 +0000 (18:44 +0200)]
Add usper.d.o
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Julien Cristau [Sat, 22 Oct 2016 12:32:57 +0000 (14:32 +0200)]
Add fasolo as ftp-master
Julien Cristau [Sat, 22 Oct 2016 12:18:57 +0000 (14:18 +0200)]
Get rid of "release" role
The web bits moved to static.d.o.
Peter Palfrader [Fri, 21 Oct 2016 11:21:23 +0000 (11:21 +0000)]
split out apt config into own class. use multi-suite site::aptrepo
Peter Palfrader [Fri, 21 Oct 2016 11:12:30 +0000 (11:12 +0000)]
support an array of mirrors for site::aptrepo
Peter Palfrader [Fri, 21 Oct 2016 07:02:32 +0000 (09:02 +0200)]
let dak signal buildd pool update
Peter Palfrader [Fri, 21 Oct 2016 06:02:38 +0000 (08:02 +0200)]
Export debian-security-buildd-pool
Peter Palfrader [Fri, 21 Oct 2016 05:04:59 +0000 (07:04 +0200)]
get backports from fastly as well
Julien Cristau [Thu, 20 Oct 2016 18:29:48 +0000 (20:29 +0200)]
Force type for *.debdiff.html.gz on release.d.o
Serve them as html rather than gzip.
Julien Cristau [Thu, 20 Oct 2016 17:47:00 +0000 (19:47 +0200)]
Fixup apache config syntax error
Julien Cristau [Thu, 20 Oct 2016 17:43:54 +0000 (19:43 +0200)]
Don't redirect on security for cloudfront and tor hidden service
Redirecting from https or .onion to plain http is probably a bad plan.
Peter Palfrader [Thu, 20 Oct 2016 07:41:41 +0000 (09:41 +0200)]
redirect linux updates to fastly
Peter Palfrader [Tue, 18 Oct 2016 19:13:10 +0000 (21:13 +0200)]
push ~/.selected_editor
Julien Cristau [Tue, 18 Oct 2016 17:40:52 +0000 (19:40 +0200)]
Add deb.debian.org https vhost
A bit special: no HPKP, and redirects are currently different from the
HTTP vhost.
Peter Palfrader [Sun, 16 Oct 2016 07:22:40 +0000 (09:22 +0200)]
move deprecated modulepath so it is only set on the master
Peter Palfrader [Sun, 16 Oct 2016 07:20:39 +0000 (09:20 +0200)]
Do not have production and staging section in puppet.conf on all clients
Aurelien Jarno [Sat, 15 Oct 2016 12:54:11 +0000 (14:54 +0200)]
Decommission jenko
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Sat, 15 Oct 2016 08:38:29 +0000 (10:38 +0200)]
add acker
Peter Palfrader [Fri, 14 Oct 2016 18:36:48 +0000 (20:36 +0200)]
add aagaard
Peter Palfrader [Fri, 14 Oct 2016 06:14:50 +0000 (08:14 +0200)]
raise pin age to 3d
Luca Filipozzi [Thu, 13 Oct 2016 17:38:29 +0000 (17:38 +0000)]
add new host for luca
Peter Palfrader [Thu, 13 Oct 2016 07:06:39 +0000 (09:06 +0200)]
remove double slashes on metadata.ftp-debian.org
Peter Palfrader [Thu, 13 Oct 2016 06:58:53 +0000 (08:58 +0200)]
Revert "remove double slashes on metadata.ftp-debian.org"
This reverts commit
5d598f2a486bfb7619f294eeb606aa114f183349.
Peter Palfrader [Thu, 13 Oct 2016 06:56:39 +0000 (08:56 +0200)]
remove double slashes on metadata.ftp-debian.org
Peter Palfrader [Wed, 12 Oct 2016 13:04:30 +0000 (15:04 +0200)]
raise pin age to 1d
Peter Palfrader [Wed, 12 Oct 2016 13:01:57 +0000 (15:01 +0200)]
LE cert for buildd
Peter Palfrader [Wed, 12 Oct 2016 13:00:20 +0000 (15:00 +0200)]
LE cert for ftp-master
Peter Palfrader [Wed, 12 Oct 2016 12:43:29 +0000 (14:43 +0200)]
LE cert for munin
Peter Palfrader [Wed, 12 Oct 2016 12:41:01 +0000 (14:41 +0200)]
LE cert for nagios
Peter Palfrader [Wed, 12 Oct 2016 12:37:14 +0000 (14:37 +0200)]
LE cert for nm, contributors
Peter Palfrader [Wed, 12 Oct 2016 12:29:49 +0000 (14:29 +0200)]
LE cert for rt
Peter Palfrader [Wed, 12 Oct 2016 12:28:03 +0000 (14:28 +0200)]
LE cert for security-tracker
Peter Palfrader [Wed, 12 Oct 2016 12:24:31 +0000 (14:24 +0200)]
LE cert for sso
Peter Palfrader [Wed, 12 Oct 2016 12:23:35 +0000 (14:23 +0200)]
LE cert for vote
Peter Palfrader [Wed, 12 Oct 2016 07:23:48 +0000 (09:23 +0200)]
set TLSA port to 0 in preparation of cert roll for buildd, contributors, ftp-master, munin, nagios, nm, rt, security-tracker, sso, vote
Julien Cristau [Sun, 9 Oct 2016 16:14:27 +0000 (18:14 +0200)]
Move udd.d.o cert to letsencrypt
Julien Cristau [Sun, 9 Oct 2016 16:07:43 +0000 (18:07 +0200)]
Switch lists.d.o to letsencrypt
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sun, 9 Oct 2016 15:43:55 +0000 (17:43 +0200)]
Switch to letsencrypt for api.ftp-master.d.o