mirror/dsa-puppet.git
5 years agoDrop traffic from 220.243.135/24 220.243.136/24 on bugs.d.o
Julien Cristau [Wed, 3 Apr 2019 13:17:22 +0000 (15:17 +0200)]
Drop traffic from 220.243.135/24 220.243.136/24 on bugs.d.o

5 years agoUse the new local timeservers for timesyncd at manda
Aurelien Jarno [Wed, 3 Apr 2019 08:59:51 +0000 (10:59 +0200)]
Use the new local timeservers for timesyncd at manda

5 years agoUse modern cryptography for NTP keys
Aurelien Jarno [Wed, 3 Apr 2019 08:35:22 +0000 (10:35 +0200)]
Use modern cryptography for NTP keys

5 years agoAllow access to dak@bmdb1 from ullmann
Aurelien Jarno [Wed, 3 Apr 2019 08:13:31 +0000 (10:13 +0200)]
Allow access to dak@bmdb1 from ullmann

5 years agoAllow access to wanna-build@bmdb1 from respighi
Aurelien Jarno [Wed, 3 Apr 2019 08:06:54 +0000 (10:06 +0200)]
Allow access to wanna-build@bmdb1 from respighi

5 years agoAdd missing slash in redirectmatch
Tollef Fog Heen [Tue, 2 Apr 2019 18:33:51 +0000 (20:33 +0200)]
Add missing slash in redirectmatch

5 years agoRedirect /debian to /debian/ on ftp.d.o and friends
Julien Cristau [Tue, 2 Apr 2019 11:42:26 +0000 (13:42 +0200)]
Redirect /debian to /debian/ on ftp.d.o and friends

5 years agoAllow access to ullmann from wuiet
Aurelien Jarno [Tue, 2 Apr 2019 11:02:20 +0000 (13:02 +0200)]
Allow access to ullmann from wuiet

5 years agosyslog-ng.conf: add support for buster
Aurelien Jarno [Mon, 1 Apr 2019 16:04:22 +0000 (18:04 +0200)]
syslog-ng.conf: add support for buster

5 years agosyslog-ng.conf: drop support for versions older than jessie
Aurelien Jarno [Mon, 1 Apr 2019 16:03:09 +0000 (18:03 +0200)]
syslog-ng.conf: drop support for versions older than jessie

5 years agoFix syslogversion facter for 2 digits versions
Aurelien Jarno [Mon, 1 Apr 2019 15:57:36 +0000 (17:57 +0200)]
Fix syslogversion facter for 2 digits versions

5 years agoAdd missing new files from commit 131e09855e06
Aurelien Jarno [Mon, 1 Apr 2019 15:58:48 +0000 (17:58 +0200)]
Add missing new files from commit 131e09855e06

5 years agoAllow nagios to check the SSL CA cert
Aurelien Jarno [Mon, 1 Apr 2019 13:35:35 +0000 (15:35 +0200)]
Allow nagios to check the SSL CA cert

5 years agoNow -backports or -updates for jessie
Aurelien Jarno [Mon, 1 Apr 2019 13:23:25 +0000 (15:23 +0200)]
Now -backports or -updates for jessie

5 years agorsync-ssh-wrap: add allowed_rsyncs for buster
Aurelien Jarno [Mon, 1 Apr 2019 12:56:20 +0000 (14:56 +0200)]
rsync-ssh-wrap: add allowed_rsyncs for buster

5 years agoRemove kfreebsd left-over
Aurelien Jarno [Mon, 1 Apr 2019 10:53:58 +0000 (12:53 +0200)]
Remove kfreebsd left-over

5 years agoMore mirror-conova decomissioning
Aurelien Jarno [Mon, 1 Apr 2019 09:10:27 +0000 (11:10 +0200)]
More mirror-conova decomissioning

5 years agodecomission mirror-conova
Aurelien Jarno [Mon, 1 Apr 2019 09:05:15 +0000 (11:05 +0200)]
decomission mirror-conova

5 years agoUpdate puppetlabs/stdlib module
Aurelien Jarno [Sun, 31 Mar 2019 22:05:19 +0000 (00:05 +0200)]
Update puppetlabs/stdlib module

5 years agoNo backports for buster
Aurelien Jarno [Sun, 31 Mar 2019 20:25:31 +0000 (22:25 +0200)]
No backports for buster

5 years agoDrop squeeze support
Aurelien Jarno [Sun, 31 Mar 2019 20:11:57 +0000 (22:11 +0200)]
Drop squeeze support

5 years agoAdd the certregen::client class to all nodes
Aurelien Jarno [Sat, 30 Mar 2019 12:16:04 +0000 (13:16 +0100)]
Add the certregen::client class to all nodes

5 years agoAdd puppetlabs/certregen module
Aurelien Jarno [Sat, 30 Mar 2019 12:13:17 +0000 (13:13 +0100)]
Add puppetlabs/certregen module

5 years agoAdd trabaci
Aurelien Jarno [Sat, 23 Mar 2019 12:43:58 +0000 (13:43 +0100)]
Add trabaci

5 years agoAdd trabaci volumes
Aurelien Jarno [Sat, 23 Mar 2019 11:58:40 +0000 (12:58 +0100)]
Add trabaci volumes

5 years agoMove more hiera stuff from mirror-conova to schmelzer
Julien Cristau [Mon, 18 Mar 2019 15:16:40 +0000 (16:16 +0100)]
Move more hiera stuff from mirror-conova to schmelzer

5 years agoFix typo that caused missing debug mirror on schmelzer
Julien Cristau [Mon, 18 Mar 2019 15:14:11 +0000 (16:14 +0100)]
Fix typo that caused missing debug mirror on schmelzer

Also add the right parameters.

5 years agoschmelzer has /srv/mirrors/public-debian, use it
Julien Cristau [Mon, 18 Mar 2019 14:51:31 +0000 (15:51 +0100)]
schmelzer has /srv/mirrors/public-debian, use it

Helps keep things in sync with other mirrors that are its downstreams.

5 years agoganeti: add ganeti2-osuosl ip range
Julien Cristau [Sun, 17 Mar 2019 18:12:25 +0000 (19:12 +0100)]
ganeti: add ganeti2-osuosl ip range

No dedicated private network for now, just trying things out.

5 years agoFix rsync setup on schmelzer
Julien Cristau [Sun, 17 Mar 2019 16:01:39 +0000 (17:01 +0100)]
Fix rsync setup on schmelzer

5 years agoDecommission lully.d.o
Aurelien Jarno [Sun, 17 Mar 2019 12:36:15 +0000 (13:36 +0100)]
Decommission lully.d.o

Replaced by loghost-osuosl-01

5 years agoblacklist 211.13.205.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:20:07 +0000 (11:20 +0100)]
blacklist 211.13.205.0/24

5 years agoblacklist 84.204.194.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:19:35 +0000 (11:19 +0100)]
blacklist 84.204.194.0/24

5 years agosyslog: fix longstanding hostname typo
Julien Cristau [Fri, 15 Mar 2019 10:14:37 +0000 (11:14 +0100)]
syslog: fix longstanding hostname typo

Looks like this has been around since d6761ce0180c2b4ac9f90e744fa34416ee68ae48
in 2013.

5 years agoblacklist 159.226.95.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:14:46 +0000 (11:14 +0100)]
blacklist 159.226.95.0/24

5 years agoAdd cron script to compress and clean up logs on syslog hosts
Julien Cristau [Thu, 14 Mar 2019 13:16:02 +0000 (14:16 +0100)]
Add cron script to compress and clean up logs on syslog hosts

5 years agoremove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home
Peter Palfrader [Mon, 11 Mar 2019 08:59:43 +0000 (09:59 +0100)]
remove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home

5 years agoAdd lw08 to the snapshot_shell role and give ftp-master some infra there
Peter Palfrader [Mon, 11 Mar 2019 08:56:03 +0000 (09:56 +0100)]
Add lw08 to the snapshot_shell role and give ftp-master some infra there

5 years agoStop making nsswitch executable
Peter Palfrader [Sat, 9 Mar 2019 10:37:25 +0000 (11:37 +0100)]
Stop making nsswitch executable

5 years agolvm setup for pieta
Aurelien Jarno [Fri, 8 Mar 2019 20:16:38 +0000 (21:16 +0100)]
lvm setup for pieta

5 years agomove incoming smtp to port 2025 on smit.d.o
Aurelien Jarno [Fri, 8 Mar 2019 18:18:39 +0000 (19:18 +0100)]
move incoming smtp to port 2025 on smit.d.o

5 years agoAdd smit
Aurelien Jarno [Thu, 7 Mar 2019 20:48:05 +0000 (21:48 +0100)]
Add smit

5 years agoAdd debconf.org cert
Julien Cristau [Tue, 5 Mar 2019 19:36:49 +0000 (20:36 +0100)]
Add debconf.org cert

5 years agoTake over debconf.org with a redirect to www
Julien Cristau [Tue, 5 Mar 2019 19:33:24 +0000 (20:33 +0100)]
Take over debconf.org with a redirect to www

5 years agoAdd schmelzer to a couple more things
Julien Cristau [Fri, 1 Mar 2019 13:33:15 +0000 (14:33 +0100)]
Add schmelzer to a couple more things

5 years agoFix mirror-health-security by skipping the security to security-cdn redirect
Julien Cristau [Fri, 1 Mar 2019 13:25:05 +0000 (14:25 +0100)]
Fix mirror-health-security by skipping the security to security-cdn redirect

5 years agoadd some roles to schmelzer
Julien Cristau [Thu, 28 Feb 2019 13:12:34 +0000 (14:12 +0100)]
add some roles to schmelzer

5 years agomirror-umn console is on COM2
Julien Cristau [Thu, 21 Feb 2019 12:04:48 +0000 (13:04 +0100)]
mirror-umn console is on COM2

5 years agoAdd conova ip range
Julien Cristau [Wed, 20 Feb 2019 15:41:49 +0000 (16:41 +0100)]
Add conova ip range

5 years agoAdd schmelzer
Julien Cristau [Wed, 20 Feb 2019 15:37:11 +0000 (16:37 +0100)]
Add schmelzer

5 years agoDecommission kantuser (RT#7583)
Julien Cristau [Sun, 17 Feb 2019 18:53:59 +0000 (19:53 +0100)]
Decommission kantuser (RT#7583)

5 years agoadd default lvm conf for pijper
Aurelien Jarno [Sun, 17 Feb 2019 06:33:27 +0000 (07:33 +0100)]
add default lvm conf for pijper

5 years agocvs.d.o is gone, drop redirect
Tollef Fog Heen [Sat, 16 Feb 2019 21:07:49 +0000 (22:07 +0100)]
cvs.d.o is gone, drop redirect

5 years agoadd mekeel-srv (RT#7226)
Julien Cristau [Sat, 16 Feb 2019 17:04:31 +0000 (18:04 +0100)]
add mekeel-srv (RT#7226)

5 years agosyslog-ng: define fastly destination on all log hosts, not just lully
Julien Cristau [Fri, 8 Feb 2019 07:57:34 +0000 (08:57 +0100)]
syslog-ng: define fastly destination on all log hosts, not just lully

5 years agoRevert "99builddsourceslist: disable apt redirects in chroots"
Aurelien Jarno [Mon, 4 Feb 2019 21:00:07 +0000 (22:00 +0100)]
Revert "99builddsourceslist: disable apt redirects in chroots"

This reverts commit 840177adeb15e1a9f23cff136708eb60a10cd3a7.

All the chroots now have an updated apt.

5 years agoFix KVM detection for rng-tools
Aurelien Jarno [Sun, 3 Feb 2019 09:59:39 +0000 (10:59 +0100)]
Fix KVM detection for rng-tools

5 years agoDo not setup grub/kernel serial console on ppc64el VMs
Aurelien Jarno [Sun, 3 Feb 2019 00:22:02 +0000 (01:22 +0100)]
Do not setup grub/kernel serial console on ppc64el VMs

On ppc64el VMs, grub and the kernel automatically switch to the serial
console if there is no video card. OTOH the serial console is not called
ttyS0, so it's better to not try to setup it up manually.

5 years agoganeti2: remove qemu-system-ppc64 wrapper
Aurelien Jarno [Sun, 3 Feb 2019 00:09:55 +0000 (01:09 +0100)]
ganeti2: remove qemu-system-ppc64 wrapper

The wrapper ended-up simpler than on arm64, therefore kvm_extra can be
used instead.

5 years agoadd loghost-osuosl-01
Julien Cristau [Mon, 28 Jan 2019 21:43:43 +0000 (22:43 +0100)]
add loghost-osuosl-01

5 years agoganeti2: add wrapper for qemu-system-ppc64
Julien Cristau [Sun, 27 Jan 2019 15:00:27 +0000 (16:00 +0100)]
ganeti2: add wrapper for qemu-system-ppc64

5 years agoempty slapd-ftmg.conf
Peter Palfrader [Thu, 24 Jan 2019 12:36:36 +0000 (13:36 +0100)]
empty slapd-ftmg.conf

5 years agoslapd: listen on localhost only
Peter Palfrader [Thu, 24 Jan 2019 12:35:21 +0000 (13:35 +0100)]
slapd: listen on localhost only

5 years agoAdd default /etc/default/slapd
Peter Palfrader [Thu, 24 Jan 2019 12:34:09 +0000 (13:34 +0100)]
Add default /etc/default/slapd

5 years agotypo fix
Peter Palfrader [Thu, 24 Jan 2019 12:32:29 +0000 (13:32 +0100)]
typo fix

5 years agossl slapd: load hbd backend module, disable db and backend specific config
Peter Palfrader [Thu, 24 Jan 2019 12:30:55 +0000 (13:30 +0100)]
ssl slapd: load hbd backend module, disable db and backend specific config

5 years agodefault slapd.conf
Peter Palfrader [Thu, 24 Jan 2019 12:27:40 +0000 (13:27 +0100)]
default slapd.conf

5 years agosso: install slapd (re: RT#7454)
Peter Palfrader [Thu, 24 Jan 2019 12:19:29 +0000 (13:19 +0100)]
sso: install slapd (re: RT#7454)

5 years agoship ftmg.sso.debian.org key to sso host
Peter Palfrader [Thu, 24 Jan 2019 10:10:32 +0000 (11:10 +0100)]
ship ftmg.sso.debian.org key to sso host

5 years agoActually install apt https config
Julien Cristau [Wed, 23 Jan 2019 15:27:30 +0000 (16:27 +0100)]
Actually install apt https config

5 years agoTell apt to use cartel CAs for https mirrors
Julien Cristau [Wed, 23 Jan 2019 15:21:24 +0000 (16:21 +0100)]
Tell apt to use cartel CAs for https mirrors

5 years agoTry to support debootstrapping from https sources on debian.org infra
Peter Palfrader [Wed, 23 Jan 2019 12:47:42 +0000 (13:47 +0100)]
Try to support debootstrapping from https sources on debian.org infra

5 years agouse local mirrors less
Peter Palfrader [Wed, 23 Jan 2019 12:07:14 +0000 (13:07 +0100)]
use local mirrors less

5 years agoswitch default mirror to https://deb.debian.org/debian
Peter Palfrader [Wed, 23 Jan 2019 12:03:40 +0000 (13:03 +0100)]
switch default mirror to https://deb.debian.org/debian

5 years agoinstall ca-certificates in all chroots
Peter Palfrader [Wed, 23 Jan 2019 10:07:10 +0000 (11:07 +0100)]
install ca-certificates in all chroots

5 years agoinstall security (LTS) updates for jessie
Peter Palfrader [Wed, 23 Jan 2019 08:51:53 +0000 (09:51 +0100)]
install security (LTS) updates for jessie

5 years agouse https://deb.debian.org/debian as default mirror
Peter Palfrader [Wed, 23 Jan 2019 08:51:06 +0000 (09:51 +0100)]
use https://deb.debian.org/debian as default mirror

5 years agosetup-dchroot: do install of security and updates for ubuntu chroots earlier
Peter Palfrader [Wed, 23 Jan 2019 08:50:56 +0000 (09:50 +0100)]
setup-dchroot: do install of security and updates for ubuntu chroots earlier

5 years agoterminate case properly
Peter Palfrader [Wed, 23 Jan 2019 08:25:24 +0000 (09:25 +0100)]
terminate case properly

5 years agoInstall apt-transport-https during debootstrap
Peter Palfrader [Wed, 23 Jan 2019 08:22:53 +0000 (09:22 +0100)]
Install apt-transport-https during debootstrap

5 years ago99builddsourceslist: disable apt redirects in chroots
Aurelien Jarno [Tue, 22 Jan 2019 19:31:47 +0000 (20:31 +0100)]
99builddsourceslist: disable apt redirects in chroots

5 years agoRemove moszumanska-lvm and moszumanska from multipath config
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:54 +0000 (21:17 +0100)]
Remove moszumanska-lvm and moszumanska from multipath config

5 years agoAvoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:37 +0000 (21:17 +0100)]
Avoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd

5 years agoEnable SSILegacyExprParser on www.debconf.org
Julien Cristau [Thu, 17 Jan 2019 15:46:37 +0000 (16:46 +0100)]
Enable SSILegacyExprParser on www.debconf.org

The site would need updates for the new syntax

5 years agowww.debconf.org vhost update
Julien Cristau [Thu, 17 Jan 2019 15:37:04 +0000 (16:37 +0100)]
www.debconf.org vhost update

Add missing redirects from current config on kent.debconf.org

5 years agoAdd www.debconf.org vhost for real
Julien Cristau [Thu, 17 Jan 2019 15:26:08 +0000 (16:26 +0100)]
Add www.debconf.org vhost for real

5 years agoAdd www.debconf.org vhost on static
Julien Cristau [Thu, 17 Jan 2019 15:04:07 +0000 (16:04 +0100)]
Add www.debconf.org vhost on static

5 years agoAdd www.debconf.org static component
Julien Cristau [Thu, 17 Jan 2019 14:42:02 +0000 (15:42 +0100)]
Add www.debconf.org static component

5 years agoBump RLimitNPROC for bugs web hosts
Julien Cristau [Wed, 16 Jan 2019 07:08:07 +0000 (08:08 +0100)]
Bump RLimitNPROC for bugs web hosts

Bug#919316

5 years agoSet LogLevel VERBOSE in sshd
Peter Palfrader [Mon, 14 Jan 2019 09:40:02 +0000 (10:40 +0100)]
Set LogLevel VERBOSE in sshd

5 years agoAdd wiki.debconf.org static vhost (RT#7595)
Julien Cristau [Sun, 13 Jan 2019 22:51:35 +0000 (23:51 +0100)]
Add wiki.debconf.org static vhost (RT#7595)

5 years agodebconfstatic can update wiki.debconf.org
Julien Cristau [Sun, 13 Jan 2019 22:44:15 +0000 (23:44 +0100)]
debconfstatic can update wiki.debconf.org

5 years agoUpdate DMUP url in motd
Julien Cristau [Sun, 13 Jan 2019 22:42:05 +0000 (23:42 +0100)]
Update DMUP url in motd

5 years agoAdd wiki.debconf.org static component
Julien Cristau [Sun, 13 Jan 2019 22:35:21 +0000 (23:35 +0100)]
Add wiki.debconf.org static component

5 years agoFix sudoers syntax
Julien Cristau [Thu, 10 Jan 2019 21:20:21 +0000 (22:20 +0100)]
Fix sudoers syntax

5 years agosudo: add an extra entry for dsa-check-openmanage
Julien Cristau [Thu, 10 Jan 2019 21:08:20 +0000 (22:08 +0100)]
sudo: add an extra entry for dsa-check-openmanage

Add ability to ignore "Cache Battery 0 in controller 0 is Degraded
(Non-Critical) [probably harmless]" warning.

5 years agopostgres-make-base-backups.erb: fix limited info log
Peter Palfrader [Tue, 8 Jan 2019 13:49:08 +0000 (14:49 +0100)]
postgres-make-base-backups.erb: fix limited info log

5 years agoRT#7513 Get rid of most traces of moszumanska
Tollef Fog Heen [Mon, 7 Jan 2019 20:59:04 +0000 (21:59 +0100)]
RT#7513 Get rid of most traces of moszumanska

5 years agoAdd an adm key for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 19:39:06 +0000 (20:39 +0100)]
Add an adm key for tfheen

5 years agoOpen up some IPs for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 18:47:11 +0000 (19:47 +0100)]
Open up some IPs for tfheen