mirror/dsa-puppet.git
6 years agoset vm dirty values
Peter Palfrader [Sun, 26 Nov 2017 13:29:17 +0000 (14:29 +0100)]
set vm dirty values

6 years agodo extra grub for grnet-node01,grnet-node02
Peter Palfrader [Sun, 26 Nov 2017 13:27:32 +0000 (14:27 +0100)]
do extra grub for grnet-node01,grnet-node02

6 years agoset elevator=deadline at grnet
Peter Palfrader [Sun, 26 Nov 2017 13:24:22 +0000 (14:24 +0100)]
set elevator=deadline at grnet

6 years agoAdd kantuser
Julien Cristau [Thu, 23 Nov 2017 18:06:30 +0000 (18:06 +0000)]
Add kantuser

6 years agoAdd kantuser volume at ubc
Julien Cristau [Thu, 23 Nov 2017 17:10:17 +0000 (17:10 +0000)]
Add kantuser volume at ubc

6 years agoset mode of /etc/default/locale to a+r
Peter Palfrader [Thu, 23 Nov 2017 08:47:45 +0000 (09:47 +0100)]
set mode of /etc/default/locale to a+r

6 years agoAdd extra netnod servers to ferm
Julien Cristau [Thu, 23 Nov 2017 00:34:50 +0000 (00:34 +0000)]
Add extra netnod servers to ferm

6 years agonamed: add more dnsnode server ACLs
Julien Cristau [Thu, 23 Nov 2017 00:08:27 +0000 (00:08 +0000)]
named: add more dnsnode server ACLs

6 years agoRemove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)
Peter Palfrader [Wed, 22 Nov 2017 18:14:25 +0000 (19:14 +0100)]
Remove /etc/init.d sudo to spamassassin and amavis - listmaster can go via service(8)

6 years agogive %list access to service {spamassassin,amavis} {reload,restart,stop,start}
Peter Palfrader [Wed, 22 Nov 2017 18:05:46 +0000 (19:05 +0100)]
give %list access to service {spamassassin,amavis} {reload,restart,stop,start}

6 years agosudo on listhosts: give list group access to postcat as postfix
Peter Palfrader [Wed, 22 Nov 2017 18:03:28 +0000 (19:03 +0100)]
sudo on listhosts: give list group access to postcat as postfix

6 years agoOnce more with feeling
Julien Cristau [Mon, 20 Nov 2017 10:10:15 +0000 (11:10 +0100)]
Once more with feeling

6 years agoEnable wsgi-py3 for tracker
Julien Cristau [Mon, 20 Nov 2017 10:08:58 +0000 (11:08 +0100)]
Enable wsgi-py3 for tracker

6 years agoremove ticharich from experimental_apache group
Julien Cristau [Mon, 20 Nov 2017 10:03:21 +0000 (11:03 +0100)]
remove ticharich from experimental_apache group

It's now on stretch

6 years agoReduce WAL retention from 21 to 14 days for bmdb1/debsources
Julien Cristau [Sun, 19 Nov 2017 11:51:05 +0000 (12:51 +0100)]
Reduce WAL retention from 21 to 14 days for bmdb1/debsources

6 years agoMerge remote-tracking branch 'stapelberg/mimetype'
Peter Palfrader [Tue, 14 Nov 2017 08:18:07 +0000 (09:18 +0100)]
Merge remote-tracking branch 'stapelberg/mimetype'

* stapelberg/mimetype:
  manpages: force content-type to text/plain for non-html .gz files

6 years agomanpages: force content-type to text/plain for non-html .gz files
Michael Stapelberg [Tue, 14 Nov 2017 08:15:23 +0000 (09:15 +0100)]
manpages: force content-type to text/plain for non-html .gz files

6 years agoDistinguish ssl/nossl access logs for planet-backend
Julien Cristau [Fri, 10 Nov 2017 23:03:32 +0000 (00:03 +0100)]
Distinguish ssl/nossl access logs for planet-backend

6 years agoRevert "install newer version of devscripts"
Julien Cristau [Fri, 10 Nov 2017 22:51:35 +0000 (23:51 +0100)]
Revert "install newer version of devscripts"

devscripts was updated in stretch-backports and now the hardcoded
version doesn't exist.

This reverts commit 55e8d03c4d97a031237a43a1aec3830b0dab5fc7.

6 years agoFix planet-backend.d.o
Julien Cristau [Fri, 10 Nov 2017 22:48:09 +0000 (23:48 +0100)]
Fix planet-backend.d.o

6 years agoadd ssl vhost for planet-backend
Julien Cristau [Fri, 10 Nov 2017 22:12:54 +0000 (23:12 +0100)]
add ssl vhost for planet-backend

6 years agoFix http://www.debian.org
Julien Cristau [Fri, 10 Nov 2017 13:00:51 +0000 (14:00 +0100)]
Fix http://www.debian.org

Thanks, paravoid

6 years agopicconi and pkgmirror-csail are on stretch, remove from experimental_apache
Julien Cristau [Wed, 8 Nov 2017 14:11:05 +0000 (15:11 +0100)]
picconi and pkgmirror-csail are on stretch, remove from experimental_apache

6 years agoFixup sources.d.o config
Julien Cristau [Mon, 6 Nov 2017 21:22:15 +0000 (22:22 +0100)]
Fixup sources.d.o config

6 years agoRotate fastly syslogs
Julien Cristau [Fri, 3 Nov 2017 15:20:06 +0000 (16:20 +0100)]
Rotate fastly syslogs

6 years agoReload syslog-ng after daemon.log rotation to prevent cron spam
Tollef Fog Heen [Wed, 1 Nov 2017 20:36:42 +0000 (21:36 +0100)]
Reload syslog-ng after daemon.log rotation to prevent cron spam

6 years agoseger's dak db is on postgresql 9.6
Julien Cristau [Wed, 1 Nov 2017 20:04:31 +0000 (21:04 +0100)]
seger's dak db is on postgresql 9.6

6 years agoDisable ftp:// on security-master
Julien Cristau [Wed, 1 Nov 2017 13:54:58 +0000 (14:54 +0100)]
Disable ftp:// on security-master

6 years agoTurn off ftp:// on ftp.debian.org
Julien Cristau [Wed, 1 Nov 2017 13:45:33 +0000 (14:45 +0100)]
Turn off ftp:// on ftp.debian.org

6 years agoTurn off ftp:// on security mirrors
Julien Cristau [Wed, 1 Nov 2017 13:41:47 +0000 (14:41 +0100)]
Turn off ftp:// on security mirrors

6 years agoAdd debsources role for sources.d.o
Julien Cristau [Wed, 1 Nov 2017 12:49:00 +0000 (13:49 +0100)]
Add debsources role for sources.d.o

6 years agoserial options that work on clementi hopefully will also work on czerny
Peter Palfrader [Tue, 31 Oct 2017 23:43:31 +0000 (00:43 +0100)]
serial options that work on clementi hopefully will also work on czerny

6 years agoDo not do serial on manda-hosts just yet
Peter Palfrader [Tue, 31 Oct 2017 23:23:03 +0000 (00:23 +0100)]
Do not do serial on manda-hosts just yet

6 years agopuppet managed grub on celemtni, czerny
Peter Palfrader [Tue, 31 Oct 2017 22:52:43 +0000 (23:52 +0100)]
puppet managed grub on celemtni, czerny

6 years agoDisable OCSP stapling on the default vhost
Julien Cristau [Mon, 30 Oct 2017 19:14:37 +0000 (20:14 +0100)]
Disable OCSP stapling on the default vhost

It can't work since we don't run an OCSP responder.

6 years agoFurther restrict access to cgi-bin on http://popcon.d.o
Julien Cristau [Sun, 29 Oct 2017 17:55:58 +0000 (18:55 +0100)]
Further restrict access to cgi-bin on popcon.d.o

6 years agoRemove unneeded bits from the http popcon vhost, and enable HSTS
Julien Cristau [Sun, 29 Oct 2017 17:52:26 +0000 (18:52 +0100)]
Remove unneeded bits from the http popcon vhost, and enable HSTS

6 years agoImport popcon.d.o apache vhost config
Julien Cristau [Sun, 29 Oct 2017 17:41:09 +0000 (18:41 +0100)]
Import popcon.d.o apache vhost config

6 years agoAdd ssl key/cert for popcon
Julien Cristau [Sun, 29 Oct 2017 08:37:28 +0000 (09:37 +0100)]
Add ssl key/cert for popcon

6 years agoredirect www.d.o to https
Peter Palfrader [Sat, 28 Oct 2017 08:45:39 +0000 (10:45 +0200)]
redirect www.d.o to https

6 years agowww: Split out onion hostname
Peter Palfrader [Sat, 28 Oct 2017 08:44:49 +0000 (10:44 +0200)]
www: Split out onion hostname

6 years agoSplit common-www.d.o into common-www.d.o and -inner
Peter Palfrader [Sat, 28 Oct 2017 08:43:34 +0000 (10:43 +0200)]
Split common-d.o into common-www.d.o and -inner

6 years agoAdd a comment
Peter Palfrader [Sat, 28 Oct 2017 08:40:43 +0000 (10:40 +0200)]
Add a comment

6 years agoremove obsolete ServerAlias entries for www-other
Peter Palfrader [Sat, 28 Oct 2017 08:39:36 +0000 (10:39 +0200)]
remove obsolete ServerAlias entries for www-other

6 years agoredirect www-other (i.e. debian.org, www.CC.d.o, www.d.CC) to https on www.debian...
Peter Palfrader [Sat, 28 Oct 2017 08:37:29 +0000 (10:37 +0200)]
redirect www-other (i.e. debian.org, CC.d.o, www.d.CC) to https on www.debian.org now

6 years agoreject package file names that could be used to install local files. Issue reported...
Peter Palfrader [Mon, 23 Oct 2017 13:43:32 +0000 (15:43 +0200)]
reject package file names that could be used to install local files.  Issue reported by Julian Andres Klode.

6 years agoCleanup experimental_apache role
Julien Cristau [Fri, 20 Oct 2017 06:12:39 +0000 (08:12 +0200)]
Cleanup experimental_apache role

Not needed on hosts running stretch

6 years agoMerge branch 'master' of ssh://handel.debian.org/~/dsa-puppet
Luca Filipozzi [Thu, 19 Oct 2017 00:59:41 +0000 (00:59 +0000)]
Merge branch 'master' of ssh://handel.debian.org/~/dsa-puppet

6 years agoremove custom casulana rules
Luca Filipozzi [Thu, 19 Oct 2017 00:58:44 +0000 (00:58 +0000)]
remove custom casulana rules

6 years agoRT#6923 - More users and groups
Martin Zobel-Helas [Wed, 18 Oct 2017 22:48:28 +0000 (18:48 -0400)]
RT#6923 - More users and groups

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agoAdd mail filters for some aliases (rt#6227)
Julien Cristau [Wed, 18 Oct 2017 19:41:19 +0000 (21:41 +0200)]
Add mail filters for some aliases (rt#6227)

- add sender callout for leader, patents, trademark
- add greylisting for patents, trademark
- add RBLs for patents, trademark
- add RHSBLs for leader, patents, treasurer, trademark

6 years agoalways a typo
Luca Filipozzi [Wed, 18 Oct 2017 18:50:49 +0000 (18:50 +0000)]
always a typo

6 years agoprune ssh ACLs for luca
Luca Filipozzi [Wed, 18 Oct 2017 18:49:29 +0000 (18:49 +0000)]
prune ssh ACLs for luca

6 years agoadd more casulana rules for br1
Luca Filipozzi [Wed, 18 Oct 2017 17:59:54 +0000 (17:59 +0000)]
add more casulana rules for br1

6 years agoadd masquerade rules for casulana virtual machines
Luca Filipozzi [Wed, 18 Oct 2017 17:05:44 +0000 (17:05 +0000)]
add masquerade rules for casulana virtual machines

6 years agoundo casulana custom roles
Luca Filipozzi [Wed, 18 Oct 2017 00:26:37 +0000 (00:26 +0000)]
undo casulana custom roles

6 years agofix up the custom cloud-admins rule
Luca Filipozzi [Tue, 17 Oct 2017 23:13:57 +0000 (23:13 +0000)]
fix up the custom cloud-admins rule

6 years agocustom rule for cloud-builds on casaluna
Luca Filipozzi [Tue, 17 Oct 2017 23:11:59 +0000 (23:11 +0000)]
custom rule for cloud-builds on casaluna

6 years agoadd sudo access to group cloud-builds
Martin Zobel-Helas [Mon, 16 Oct 2017 20:46:14 +0000 (16:46 -0400)]
add sudo access to group cloud-builds

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
6 years agobmdb1 main cluster is back on timeline 1
Julien Cristau [Sun, 15 Oct 2017 10:22:30 +0000 (12:22 +0200)]
bmdb1 main cluster is back on timeline 1

6 years agoEnsure mirror-health is restarted after the daemon-reload
Tollef Fog Heen [Sun, 8 Oct 2017 05:34:43 +0000 (07:34 +0200)]
Ensure mirror-health is restarted after the daemon-reload

6 years agoDrop klecker from ftp.d.o mirror-health checking
Tollef Fog Heen [Sun, 8 Oct 2017 05:21:47 +0000 (07:21 +0200)]
Drop klecker from ftp.d.o mirror-health checking

klecker is not part of the set of backends that Fastly uses, so
checking against it has no value and might leave us unhealthy if
klecker is ahead.

6 years agomask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount
Peter Palfrader [Fri, 6 Oct 2017 08:25:10 +0000 (10:25 +0200)]
mask sys-kernel-debug-tracing.mount and sys-kernel-debug.mount

6 years agoAdd a systemd::mask
Peter Palfrader [Fri, 6 Oct 2017 08:23:48 +0000 (10:23 +0200)]
Add a systemd::mask

6 years agoFix octal number in python script to it compiles
Peter Palfrader [Thu, 5 Oct 2017 09:43:36 +0000 (11:43 +0200)]
Fix octal number in python script to it compiles

6 years agoRevert "Use RedirectPermanent instead of RewriteRule"
Paul Wise [Thu, 5 Oct 2017 08:37:09 +0000 (16:37 +0800)]
Revert "Use RedirectPermanent instead of RewriteRule"

This reverts commit abb8a9a1d0c72a616e297be5a1b091b6c9a74191.

6 years agoUse RedirectPermanent instead of RewriteRule
Paul Wise [Thu, 5 Oct 2017 08:21:32 +0000 (16:21 +0800)]
Use RedirectPermanent instead of RewriteRule

6 years agoBetter debian-ports.org/debian-cd redirection
Aurelien Jarno [Thu, 5 Oct 2017 08:21:22 +0000 (10:21 +0200)]
Better debian-ports.org/debian-cd redirection

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoDrop remaining debian-ports-cd code
Aurelien Jarno [Thu, 5 Oct 2017 07:57:42 +0000 (09:57 +0200)]
Drop remaining debian-ports-cd code

6 years agoRedirect ftp.ports.debian.org/debian-ports-cd to cdimage
Aurelien Jarno [Thu, 5 Oct 2017 07:54:57 +0000 (09:54 +0200)]
Redirect ftp.ports.debian.org/debian-ports-cd to cdimage

6 years agoUpdate debian-ports.org/debian-cd redirection to cdimage.d.do
Aurelien Jarno [Thu, 5 Oct 2017 07:41:20 +0000 (09:41 +0200)]
Update debian-ports.org/debian-cd redirection to cdimage.d.do

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
6 years agoFormat weekly stunnel restart script nicer
Peter Palfrader [Tue, 3 Oct 2017 10:51:19 +0000 (12:51 +0200)]
Format weekly stunnel restart script nicer

6 years agoHave gobby reload its config when we change its ssl cert
Julien Cristau [Tue, 3 Oct 2017 10:42:35 +0000 (12:42 +0200)]
Have gobby reload its config when we change its ssl cert

6 years agoremove auto-cert and auto-clientcert symlinks from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:49:55 +0000 (10:49 +0200)]
remove auto-cert and auto-clientcert symlinks from fileserver path

6 years agofix one path
Peter Palfrader [Tue, 3 Oct 2017 08:48:55 +0000 (10:48 +0200)]
fix one path

6 years agoTry to replace file access to auto-ca things with templates
Peter Palfrader [Tue, 3 Oct 2017 08:47:51 +0000 (10:47 +0200)]
Try to replace file access to auto-ca things with templates

6 years agoAdd syncproxy addresses to ssh whitelist
Julien Cristau [Tue, 3 Oct 2017 08:34:40 +0000 (10:34 +0200)]
Add syncproxy addresses to ssh whitelist

6 years agoAnd more move things
Peter Palfrader [Tue, 3 Oct 2017 08:34:37 +0000 (10:34 +0200)]
And more move things

6 years agomove ssl/clientcerts to ssl/auto-clientcerts
Peter Palfrader [Tue, 3 Oct 2017 08:33:04 +0000 (10:33 +0200)]
move ssl/clientcerts to ssl/auto-clientcerts

6 years agomove exim/certs to ssl/auto-certs
Peter Palfrader [Tue, 3 Oct 2017 08:31:19 +0000 (10:31 +0200)]
move exim/certs to ssl/auto-certs

6 years agoStop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place
Peter Palfrader [Tue, 3 Oct 2017 08:28:08 +0000 (08:28 +0000)]
Stop hardcoding /srv/puppet.debian.org/from-letsencrypt/ all over the place

6 years agoremove from-letsencrypt symlink from fileserver path
Peter Palfrader [Tue, 3 Oct 2017 08:16:23 +0000 (10:16 +0200)]
remove from-letsencrypt symlink from fileserver path

6 years agoMake db key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:15:17 +0000 (10:15 +0200)]
Make db key loaded from a template

6 years agoMake gobby key loaded from a template
Peter Palfrader [Tue, 3 Oct 2017 08:14:36 +0000 (08:14 +0000)]
Make gobby key loaded from a template

6 years agoAdd tls key for gobby server
Julien Cristau [Tue, 3 Oct 2017 07:51:00 +0000 (09:51 +0200)]
Add tls key for gobby server

This should remove the need to rotate it manually.

6 years agoUse restrict authorized_keys option for geodns
Julien Cristau [Tue, 3 Oct 2017 07:07:07 +0000 (09:07 +0200)]
Use restrict authorized_keys option for geodns

no-port-forwarding,no-X11-forwarding,no-agent-forwarding,no-pty,no-user
is a mouthful, and geo[123] are all on stretch.

6 years agoremove unused modules/ssl/files/chains with the GANDI chains
Peter Palfrader [Tue, 3 Oct 2017 07:07:20 +0000 (09:07 +0200)]
remove unused modules/ssl/files/chains with the GANDI chains

6 years agoUse a template to get more of the from-letsencrypt certs and keys, and no longer...
Peter Palfrader [Tue, 3 Oct 2017 07:06:52 +0000 (09:06 +0200)]
Use a template to get more of the from-letsencrypt certs and keys, and no longer support getting certs and chains from files/{servicecerts,chains} (which no longer holds any DSA certs)

6 years agoRestrict ssh to mirrors
Julien Cristau [Tue, 3 Oct 2017 07:00:09 +0000 (09:00 +0200)]
Restrict ssh to mirrors

6 years agoFix ssl key template
Julien Cristau [Tue, 3 Oct 2017 06:59:30 +0000 (08:59 +0200)]
Fix ssl key template

6 years agoUse a template to get from-letsencrypt cert key, and no longer support getting keys...
Peter Palfrader [Tue, 3 Oct 2017 06:55:52 +0000 (08:55 +0200)]
Use a template to get from-letsencrypt cert key, and no longer support getting keys from files/keys (which no longer exists anyhow)

6 years agobmdb1/main on postgresql 9.6
Julien Cristau [Mon, 2 Oct 2017 16:26:45 +0000 (18:26 +0200)]
bmdb1/main on postgresql 9.6

6 years agodon't spawn a shell in create-onionbalance-config
Julien Cristau [Mon, 2 Oct 2017 12:48:50 +0000 (14:48 +0200)]
don't spawn a shell in create-onionbalance-config

python can do these things.

6 years agoMake sure onionbalance private keys are group-readable
Julien Cristau [Mon, 2 Oct 2017 12:27:26 +0000 (14:27 +0200)]
Make sure onionbalance private keys are group-readable

Seems umask is no longer sufficient and they end up 0600.

6 years agobmdb1's debsources cluster is on 9.6
Julien Cristau [Sun, 1 Oct 2017 21:41:39 +0000 (23:41 +0200)]
bmdb1's debsources cluster is on 9.6

6 years agoAdd debconf17.dc.o static component
Julien Cristau [Sun, 1 Oct 2017 19:34:54 +0000 (21:34 +0200)]
Add debconf17.dc.o static component

6 years agoConsider ourselves unhealthy if fetching from localhost fails
Tollef Fog Heen [Sun, 1 Oct 2017 18:27:30 +0000 (20:27 +0200)]
Consider ourselves unhealthy if fetching from localhost fails

6 years agoUse max instead of if to get biggest timestamp
Tollef Fog Heen [Sun, 1 Oct 2017 18:27:08 +0000 (20:27 +0200)]
Use max instead of if to get biggest timestamp

6 years agostop hardcoding danzi in postgres-make-base-backup
Julien Cristau [Sun, 1 Oct 2017 18:27:15 +0000 (20:27 +0200)]
stop hardcoding danzi in postgres-make-base-backup

It's now added in a concat fragment.

6 years agoUse postgres::backup_source for danzi's main pg cluster
Julien Cristau [Sun, 1 Oct 2017 18:20:15 +0000 (20:20 +0200)]
Use postgres::backup_source for danzi's main pg cluster