mirror/dsa-puppet.git
6 years agoEnable TCP BBR on a bunch of hosts. Not all for now, but maybe we should. (re:...
Peter Palfrader [Fri, 8 Dec 2017 14:28:16 +0000 (15:28 +0100)]
Enable TCP BBR on a bunch of hosts.  Not all for now, but maybe we should.  (re: RT#6990)

6 years agoPut vhost for signup.salsa.debian.org on the salsa host (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:18:52 +0000 (23:18 +0100)]
Put vhost for signup.salsa.debian.org on the salsa host (re: RT#7008)

6 years agoPut cert for signup.salsa.debian.org on the salsa host (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:14:29 +0000 (23:14 +0100)]
Put cert for signup.salsa.debian.org on the salsa host (re: RT#7008)

6 years agoInstall packages for salsa registration app (re: RT#7008)
Peter Palfrader [Tue, 5 Dec 2017 22:06:58 +0000 (23:06 +0100)]
Install packages for salsa registration app (re: RT#7008)

6 years agoFixup sources.d.n setup
Julien Cristau [Tue, 5 Dec 2017 08:31:17 +0000 (09:31 +0100)]
Fixup sources.d.n setup

No static component means no vhost generated by the usual macros.

6 years agoAdd sources.d.n static vhost with redirect to sources.d.o
Julien Cristau [Tue, 5 Dec 2017 08:20:53 +0000 (09:20 +0100)]
Add sources.d.n static vhost with redirect to sources.d.o

6 years agoMake redirects from {volatile,women}.d.o to www.d.o use https
Julien Cristau [Mon, 4 Dec 2017 07:05:26 +0000 (08:05 +0100)]
Make redirects from {volatile,women}.d.o to d.o use https

6 years agoRemove dak's sudoers entry for code signing
Julien Cristau [Sun, 3 Dec 2017 16:33:40 +0000 (17:33 +0100)]
Remove dak's sudoers entry for code signing

6 years agoAdd planet_master role and planet-master.d.o vhost
Julien Cristau [Fri, 1 Dec 2017 20:53:05 +0000 (21:53 +0100)]
Add planet_master role and planet-master.d.o vhost

Access to the vhost is restricted to d.o hosts, the idea being it is
only to be used for testing.

6 years agoAnd fix a pronoun
Peter Palfrader [Thu, 30 Nov 2017 20:13:42 +0000 (21:13 +0100)]
And fix a pronoun

6 years agoMerge remote-tracking branch 'waldi/sudo-archvsync-runmirrors'
Peter Palfrader [Thu, 30 Nov 2017 20:13:25 +0000 (21:13 +0100)]
Merge remote-tracking branch 'waldi/sudo-archvsync-runmirrors'

* waldi/sudo-archvsync-runmirrors:
  Add comment to sudoers
  Allow sudo to runmirrors in the current location
  Make sudo set a special path for calls as archvsync user

6 years agoAdd comment to sudoers
Bastian Blank [Thu, 30 Nov 2017 20:10:50 +0000 (21:10 +0100)]
Add comment to sudoers

6 years agoAllow sudo to runmirrors in the current location
Bastian Blank [Thu, 30 Nov 2017 19:58:53 +0000 (20:58 +0100)]
Allow sudo to runmirrors in the current location

6 years agoMake sudo set a special path for calls as archvsync user
Bastian Blank [Thu, 30 Nov 2017 19:56:06 +0000 (20:56 +0100)]
Make sudo set a special path for calls as archvsync user

This allows consumers (primarily dak) to call tools of the archvsync
user without path.  This makes later switch to the packaged version
easier.

6 years agoRemove philp from experimental_apache
Julien Cristau [Thu, 30 Nov 2017 12:38:56 +0000 (13:38 +0100)]
Remove philp from experimental_apache

Upgraded to stretch.

6 years agoRedirect old children-distros page to new derivatives page
Paul Wise [Wed, 29 Nov 2017 08:16:36 +0000 (16:16 +0800)]
Redirect old children-distros page to new derivatives page

6 years agoinclude with the correct name
Peter Palfrader [Sun, 26 Nov 2017 13:30:18 +0000 (14:30 +0100)]
include with the correct name

6 years agoset vm dirty values
Peter Palfrader [Sun, 26 Nov 2017 13:29:17 +0000 (14:29 +0100)]
set vm dirty values

6 years agodo extra grub for grnet-node01,grnet-node02
Peter Palfrader [Sun, 26 Nov 2017 13:27:32 +0000 (14:27 +0100)]
do extra grub for grnet-node01,grnet-node02

6 years agoset elevator=deadline at grnet
Peter Palfrader [Sun, 26 Nov 2017 13:24:22 +0000 (14:24 +0100)]
set elevator=deadline at grnet

6 years agoAdd kantuser
Julien Cristau [Thu, 23 Nov 2017 18:06:30 +0000 (18:06 +0000)]
Add kantuser

6 years agoAdd kantuser volume at ubc
Julien Cristau [Thu, 23 Nov 2017 17:10:17 +0000 (17:10 +0000)]
Add kantuser volume at ubc

6 years agoset mode of /etc/default/locale to a+r
Peter Palfrader [Thu, 23 Nov 2017 08:47:45 +0000 (09:47 +0100)]
set mode of /etc/default/locale to a+r

6 years agoAdd extra netnod servers to ferm
Julien Cristau [Thu, 23 Nov 2017 00:34:50 +0000 (00:34 +0000)]
Add extra netnod servers to ferm

6 years agonamed: add more dnsnode server ACLs
Julien Cristau [Thu, 23 Nov 2017 00:08:27 +0000 (00:08 +0000)]
named: add more dnsnode server ACLs

6 years agoRemove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)
Peter Palfrader [Wed, 22 Nov 2017 18:14:25 +0000 (19:14 +0100)]
Remove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)

6 years agogive %list access to service {spamassassin,amavis} {reload,restart,stop,start}
Peter Palfrader [Wed, 22 Nov 2017 18:05:46 +0000 (19:05 +0100)]
give %list access to service {spamassassin,amavis} {reload,restart,stop,start}

6 years agosudo on listhosts: give list group access to postcat as postfix
Peter Palfrader [Wed, 22 Nov 2017 18:03:28 +0000 (19:03 +0100)]
sudo on listhosts: give list group access to postcat as postfix

6 years agoOnce more with feeling
Julien Cristau [Mon, 20 Nov 2017 10:10:15 +0000 (11:10 +0100)]
Once more with feeling

6 years agoEnable wsgi-py3 for tracker
Julien Cristau [Mon, 20 Nov 2017 10:08:58 +0000 (11:08 +0100)]
Enable wsgi-py3 for tracker

6 years agoremove ticharich from experimental_apache group
Julien Cristau [Mon, 20 Nov 2017 10:03:21 +0000 (11:03 +0100)]
remove ticharich from experimental_apache group

It's now on stretch

6 years agoReduce WAL retention from 21 to 14 days for bmdb1/debsources
Julien Cristau [Sun, 19 Nov 2017 11:51:05 +0000 (12:51 +0100)]
Reduce WAL retention from 21 to 14 days for bmdb1/debsources

6 years agoMerge remote-tracking branch 'stapelberg/mimetype'
Peter Palfrader [Tue, 14 Nov 2017 08:18:07 +0000 (09:18 +0100)]
Merge remote-tracking branch 'stapelberg/mimetype'

* stapelberg/mimetype:
  manpages: force content-type to text/plain for non-html .gz files

6 years agomanpages: force content-type to text/plain for non-html .gz files
Michael Stapelberg [Tue, 14 Nov 2017 08:15:23 +0000 (09:15 +0100)]
manpages: force content-type to text/plain for non-html .gz files

6 years agoDistinguish ssl/nossl access logs for planet-backend
Julien Cristau [Fri, 10 Nov 2017 23:03:32 +0000 (00:03 +0100)]
Distinguish ssl/nossl access logs for planet-backend

6 years agoRevert "install newer version of devscripts"
Julien Cristau [Fri, 10 Nov 2017 22:51:35 +0000 (23:51 +0100)]
Revert "install newer version of devscripts"

devscripts was updated in stretch-backports and now the hardcoded
version doesn't exist.

This reverts commit 55e8d03c4d97a031237a43a1aec3830b0dab5fc7.

6 years agoFix planet-backend.d.o
Julien Cristau [Fri, 10 Nov 2017 22:48:09 +0000 (23:48 +0100)]
Fix planet-backend.d.o

6 years agoadd ssl vhost for planet-backend
Julien Cristau [Fri, 10 Nov 2017 22:12:54 +0000 (23:12 +0100)]
add ssl vhost for planet-backend

6 years agoFix http://www.debian.org
Julien Cristau [Fri, 10 Nov 2017 13:00:51 +0000 (14:00 +0100)]
Fix http://www.debian.org

Thanks, paravoid

6 years agopicconi and pkgmirror-csail are on stretch, remove from experimental_apache
Julien Cristau [Wed, 8 Nov 2017 14:11:05 +0000 (15:11 +0100)]
picconi and pkgmirror-csail are on stretch, remove from experimental_apache

6 years agoFixup sources.d.o config
Julien Cristau [Mon, 6 Nov 2017 21:22:15 +0000 (22:22 +0100)]
Fixup sources.d.o config

6 years agoRotate fastly syslogs
Julien Cristau [Fri, 3 Nov 2017 15:20:06 +0000 (16:20 +0100)]
Rotate fastly syslogs

6 years agoReload syslog-ng after daemon.log rotation to prevent cron spam
Tollef Fog Heen [Wed, 1 Nov 2017 20:36:42 +0000 (21:36 +0100)]
Reload syslog-ng after daemon.log rotation to prevent cron spam

6 years agoseger's dak db is on postgresql 9.6
Julien Cristau [Wed, 1 Nov 2017 20:04:31 +0000 (21:04 +0100)]
seger's dak db is on postgresql 9.6

6 years agoDisable ftp:// on security-master
Julien Cristau [Wed, 1 Nov 2017 13:54:58 +0000 (14:54 +0100)]
Disable ftp:// on security-master

6 years agoTurn off ftp:// on ftp.debian.org
Julien Cristau [Wed, 1 Nov 2017 13:45:33 +0000 (14:45 +0100)]
Turn off ftp:// on ftp.debian.org

6 years agoTurn off ftp:// on security mirrors
Julien Cristau [Wed, 1 Nov 2017 13:41:47 +0000 (14:41 +0100)]
Turn off ftp:// on security mirrors

6 years agoAdd debsources role for sources.d.o
Julien Cristau [Wed, 1 Nov 2017 12:49:00 +0000 (13:49 +0100)]
Add debsources role for sources.d.o

6 years agoserial options that work on clementi hopefully will also work on czerny
Peter Palfrader [Tue, 31 Oct 2017 23:43:31 +0000 (00:43 +0100)]
serial options that work on clementi hopefully will also work on czerny

6 years agoDo not do serial on manda-hosts just yet
Peter Palfrader [Tue, 31 Oct 2017 23:23:03 +0000 (00:23 +0100)]
Do not do serial on manda-hosts just yet

6 years agopuppet managed grub on celemtni, czerny
Peter Palfrader [Tue, 31 Oct 2017 22:52:43 +0000 (23:52 +0100)]
puppet managed grub on celemtni, czerny

6 years agoDisable OCSP stapling on the default vhost
Julien Cristau [Mon, 30 Oct 2017 19:14:37 +0000 (20:14 +0100)]
Disable OCSP stapling on the default vhost

It can't work since we don't run an OCSP responder.

6 years agoFurther restrict access to cgi-bin on http://popcon.d.o
Julien Cristau [Sun, 29 Oct 2017 17:55:58 +0000 (18:55 +0100)]
Further restrict access to cgi-bin on popcon.d.o

6 years agoRemove unneeded bits from the http popcon vhost, and enable HSTS
Julien Cristau [Sun, 29 Oct 2017 17:52:26 +0000 (18:52 +0100)]
Remove unneeded bits from the http popcon vhost, and enable HSTS

6 years agoImport popcon.d.o apache vhost config
Julien Cristau [Sun, 29 Oct 2017 17:41:09 +0000 (18:41 +0100)]
Import popcon.d.o apache vhost config

6 years agoAdd ssl key/cert for popcon
Julien Cristau [Sun, 29 Oct 2017 08:37:28 +0000 (09:37 +0100)]
Add ssl key/cert for popcon

6 years agoredirect www.d.o to https
Peter Palfrader [Sat, 28 Oct 2017 08:45:39 +0000 (10:45 +0200)]
redirect www.d.o to https

6 years agowww: Split out onion hostname
Peter Palfrader [Sat, 28 Oct 2017 08:44:49 +0000 (10:44 +0200)]
www: Split out onion hostname

6 years agoSplit common-www.d.o into common-www.d.o and -inner
Peter Palfrader [Sat, 28 Oct 2017 08:43:34 +0000 (10:43 +0200)]
Split common-d.o into common-www.d.o and -inner

6 years agoAdd a comment
Peter Palfrader [Sat, 28 Oct 2017 08:40:43 +0000 (10:40 +0200)]
Add a comment

6 years agoremove obsolete ServerAlias entries for www-other
Peter Palfrader [Sat, 28 Oct 2017 08:39:36 +0000 (10:39 +0200)]
remove obsolete ServerAlias entries for www-other

6 years agoredirect www-other (i.e. debian.org, www.CC.d.o, www.d.CC) to https on www.debian...
Peter Palfrader [Sat, 28 Oct 2017 08:37:29 +0000 (10:37 +0200)]
redirect www-other (i.e. debian.org, CC.d.o, www.d.CC) to https on www.debian.org now

6 years agoreject package file names that could be used to install local files. Issue reported...
Peter Palfrader [Mon, 23 Oct 2017 13:43:32 +0000 (15:43 +0200)]
reject package file names that could be used to install local files.  Issue reported by Julian Andres Klode.

6 years agoCleanup experimental_apache role
Julien Cristau [Fri, 20 Oct 2017 06:12:39 +0000 (08:12 +0200)]
Cleanup experimental_apache role

Not needed on hosts running stretch

6 years agoMerge branch 'master' of ssh://handel.debian.org/~/dsa-puppet
Luca Filipozzi [Thu, 19 Oct 2017 00:59:41 +0000 (00:59 +0000)]
Merge branch 'master' of ssh://handel.debian.org/~/dsa-puppet

6 years agoremove custom casulana rules
Luca Filipozzi [Thu, 19 Oct 2017 00:58:44 +0000 (00:58 +0000)]
remove custom casulana rules

6 years agoRT#6923 - More users and groups
Martin Zobel-Helas [Wed, 18 Oct 2017 22:48:28 +0000 (18:48 -0400)]
RT#6923 - More users and groups

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoAdd mail filters for some aliases (rt#6227)
Julien Cristau [Wed, 18 Oct 2017 19:41:19 +0000 (21:41 +0200)]
Add mail filters for some aliases (rt#6227)

- add sender callout for leader, patents, trademark
- add greylisting for patents, trademark
- add RBLs for patents, trademark
- add RHSBLs for leader, patents, treasurer, trademark

6 years agoalways a typo
Luca Filipozzi [Wed, 18 Oct 2017 18:50:49 +0000 (18:50 +0000)]
always a typo

6 years agoprune ssh ACLs for luca
Luca Filipozzi [Wed, 18 Oct 2017 18:49:29 +0000 (18:49 +0000)]
prune ssh ACLs for luca

6 years agoadd more casulana rules for br1
Luca Filipozzi [Wed, 18 Oct 2017 17:59:54 +0000 (17:59 +0000)]
add more casulana rules for br1

6 years agoadd masquerade rules for casulana virtual machines
Luca Filipozzi [Wed, 18 Oct 2017 17:05:44 +0000 (17:05 +0000)]
add masquerade rules for casulana virtual machines

6 years agoundo casulana custom roles
Luca Filipozzi [Wed, 18 Oct 2017 00:26:37 +0000 (00:26 +0000)]
undo casulana custom roles

6 years agofix up the custom cloud-admins rule
Luca Filipozzi [Tue, 17 Oct 2017 23:13:57 +0000 (23:13 +0000)]
fix up the custom cloud-admins rule

6 years agocustom rule for cloud-builds on casaluna
Luca Filipozzi [Tue, 17 Oct 2017 23:11:59 +0000 (23:11 +0000)]
custom rule for cloud-builds on casaluna

6 years agoadd sudo access to group cloud-builds
Martin Zobel-Helas [Mon, 16 Oct 2017 20:46:14 +0000 (16:46 -0400)]
add sudo access to group cloud-builds

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agobmdb1 main cluster is back on timeline 1
Julien Cristau [Sun, 15 Oct 2017 10:22:30 +0000 (12:22 +0200)]
bmdb1 main cluster is back on timeline 1

6 years agoEnsure mirror-health is restarted after the daemon-reload
Tollef Fog Heen [Sun, 8 Oct 2017 05:34:43 +0000 (07:34 +0200)]
Ensure mirror-health is restarted after the daemon-reload

6 years agoDrop klecker from ftp.d.o mirror-health checking
Tollef Fog Heen [Sun, 8 Oct 2017 05:21:47 +0000 (07:21 +0200)]
Drop klecker from ftp.d.o mirror-health checking

klecker is not part of the set of backends that Fastly uses, so
checking against it has no value and might leave us unhealthy if
klecker is ahead.

6 years agomask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount
Peter Palfrader [Fri, 6 Oct 2017 08:25:10 +0000 (10:25 +0200)]
mask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount

6 years agoAdd a systemd::mask
Peter Palfrader [Fri, 6 Oct 2017 08:23:48 +0000 (10:23 +0200)]
Add a systemd::mask

6 years agoFix octal number in python script to it compiles
Peter Palfrader [Thu, 5 Oct 2017 09:43:36 +0000 (11:43 +0200)]
Fix octal number in python script to it compiles

6 years agoRevert "Use RedirectPermanent instead of RewriteRule"
Paul Wise [Thu, 5 Oct 2017 08:37:09 +0000 (16:37 +0800)]
Revert "Use RedirectPermanent instead of RewriteRule"

This reverts commit abb8a9a1d0c72a616e297be5a1b091b6c9a74191.

6 years agoUse RedirectPermanent instead of RewriteRule
Paul Wise [Thu, 5 Oct 2017 08:21:32 +0000 (16:21 +0800)]
Use RedirectPermanent instead of RewriteRule

6 years agoBetter debian-ports.org/debian-cd redirection
Aurelien Jarno [Thu, 5 Oct 2017 08:21:22 +0000 (10:21 +0200)]
Better debian-ports.org/debian-cd redirection

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoDrop remaining debian-ports-cd code
Aurelien Jarno [Thu, 5 Oct 2017 07:57:42 +0000 (09:57 +0200)]
Drop remaining debian-ports-cd code

6 years agoRedirect ftp.ports.debian.org/debian-ports-cd to cdimage
Aurelien Jarno [Thu, 5 Oct 2017 07:54:57 +0000 (09:54 +0200)]
Redirect ftp.ports.debian.org/debian-ports-cd to cdimage

6 years agoUpdate debian-ports.org/debian-cd redirection to cdimage.d.do
Aurelien Jarno [Thu, 5 Oct 2017 07:41:20 +0000 (09:41 +0200)]
Update debian-ports.org/debian-cd redirection to cdimage.d.do

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoFormat weekly stunnel restart script nicer
Peter Palfrader [Tue, 3 Oct 2017 10:51:19 +0000 (12:51 +0200)]
Format weekly stunnel restart script nicer

6 years agoHave gobby reload its config when we change its ssl cert
Julien Cristau [Tue, 3 Oct 2017 10:42:35 +0000 (12:42 +0200)]
Have gobby reload its config when we change its ssl cert

6 years agoremove auto-cert and auto-clientcert symlinks from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:49:55 +0000 (10:49 +0200)]
remove auto-cert and auto-clientcert symlinks from fileserver path

6 years agofix one path
Peter Palfrader [Tue, 3 Oct 2017 08:48:55 +0000 (10:48 +0200)]
fix one path

6 years agoTry to replace file access to auto-ca things with templates
Peter Palfrader [Tue, 3 Oct 2017 08:47:51 +0000 (10:47 +0200)]
Try to replace file access to auto-ca things with templates

6 years agoAdd syncproxy addresses to ssh whitelist
Julien Cristau [Tue, 3 Oct 2017 08:34:40 +0000 (10:34 +0200)]
Add syncproxy addresses to ssh whitelist

6 years agoAnd more move things
Peter Palfrader [Tue, 3 Oct 2017 08:34:37 +0000 (10:34 +0200)]
And more move things

6 years agomove ssl/clientcerts to ssl/auto-clientcerts
Peter Palfrader [Tue, 3 Oct 2017 08:33:04 +0000 (10:33 +0200)]
move ssl/clientcerts to ssl/auto-clientcerts

6 years agomove exim/certs to ssl/auto-certs
Peter Palfrader [Tue, 3 Oct 2017 08:31:19 +0000 (10:31 +0200)]
move exim/certs to ssl/auto-certs

6 years agoStop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place
Peter Palfrader [Tue, 3 Oct 2017 08:28:08 +0000 (08:28 +0000)]
Stop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place

6 years agoremove from-letsencrypt symlink from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:16:23 +0000 (10:16 +0200)]
remove from-letsencrypt symlink from fileserver path

6 years agoMake db key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:15:17 +0000 (10:15 +0200)]
Make db key loaded from a template