mirror/dsa-puppet.git
7 years agono need for the ynic-special lldp module anymore - we put lldp everywhere
Peter Palfrader [Thu, 23 Feb 2017 18:05:06 +0000 (19:05 +0100)]
no need for the ynic-special lldp module anymore - we put lldp everywhere

7 years agofix debian mirror bind addr for ipv6 on klecker
Peter Palfrader [Thu, 23 Feb 2017 17:34:51 +0000 (17:34 +0000)]
fix debian mirror bind addr for ipv6 on klecker

7 years agodebian and security anycast-test addresses
Peter Palfrader [Thu, 23 Feb 2017 17:29:04 +0000 (18:29 +0100)]
debian and security anycast-test addresses

7 years agoadd security.anycast-test server alias, do away with having both testing-anycast...
Peter Palfrader [Thu, 23 Feb 2017 17:27:02 +0000 (18:27 +0100)]
add security.anycast-test server alias, do away with having both testing-anycast and anycast-test

7 years agoRetire poulenc: hardware died
Peter Palfrader [Thu, 23 Feb 2017 17:08:17 +0000 (18:08 +0100)]
Retire poulenc: hardware died

7 years agoadd klecker to debian_mirror_onion
Peter Palfrader [Thu, 23 Feb 2017 16:05:34 +0000 (17:05 +0100)]
add klecker to debian_mirror_onion

7 years agoAdd klecker to the ftp.d.o mirror group now that the fastly live check no longer...
Peter Palfrader [Thu, 23 Feb 2017 16:00:43 +0000 (17:00 +0100)]
Add klecker to the ftp.d.o mirror group now that the fastly live check no longer requires http 200 on GET / (we redirect into /debian/

7 years agoAdd server alias for $location.$archive.backend.mirrors.debian.org
Peter Palfrader [Thu, 23 Feb 2017 15:59:54 +0000 (16:59 +0100)]
Add server alias for $location.$archive.backend.mirrors.debian.org

7 years agotouch /srv/ftp.root/.nobackup
Peter Palfrader [Thu, 23 Feb 2017 15:42:56 +0000 (16:42 +0100)]
touch /srv/ftp.root/.nobackup

7 years agoadd a missing ,
Peter Palfrader [Thu, 23 Feb 2017 15:38:20 +0000 (16:38 +0100)]
add a missing ,

7 years agoconova to debug_mirror
Peter Palfrader [Thu, 23 Feb 2017 15:37:18 +0000 (16:37 +0100)]
conova to debug_mirror

7 years agobind address for security, debug and debian mirror on conova
Peter Palfrader [Thu, 23 Feb 2017 15:37:01 +0000 (16:37 +0100)]
bind address for security, debug and debian mirror on conova

7 years agoconova to security_mirror
Peter Palfrader [Thu, 23 Feb 2017 15:32:27 +0000 (16:32 +0100)]
conova to security_mirror

7 years agoFix a typo in my previous commit
Aurelien Jarno [Thu, 23 Feb 2017 13:46:18 +0000 (14:46 +0100)]
Fix a typo in my previous commit

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agobuildd: make sure the buildd service is disabled and not running
Aurelien Jarno [Thu, 23 Feb 2017 13:38:12 +0000 (14:38 +0100)]
buildd: make sure the buildd service is disabled and not running

This is a leftover init script from the official buildd package, our
setup uses cron to (re)start the build daemon.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoRedirect removed official mirror pages
Paul Wise [Wed, 22 Feb 2017 01:36:27 +0000 (09:36 +0800)]
Redirect removed official mirror pages

7 years agoMake conova be a debian mirror
Peter Palfrader [Tue, 21 Feb 2017 18:42:39 +0000 (19:42 +0100)]
Make conova be a debian mirror

7 years agoadd mirror-conova to the archvsync_base role
Peter Palfrader [Tue, 21 Feb 2017 15:17:22 +0000 (16:17 +0100)]
add mirror-conova to the archvsync_base role

7 years agoMake archvsync_base create the /etc/ssh/userkeys/archvsync symlink
Peter Palfrader [Tue, 21 Feb 2017 15:15:31 +0000 (16:15 +0100)]
Make archvsync_base create the /etc/ssh/userkeys/archvsync symlink

7 years agorestart instead of just start
Peter Palfrader [Sun, 19 Feb 2017 08:15:00 +0000 (09:15 +0100)]
restart instead of just start

7 years agolog requested hostname in www-other.debian.org-access.log
Peter Palfrader [Fri, 17 Feb 2017 12:31:59 +0000 (13:31 +0100)]
log requested hostname in www-other.debian.org-access.log

7 years agoNew inet4 for busoni
Peter Palfrader [Wed, 15 Feb 2017 07:23:31 +0000 (08:23 +0100)]
New inet4 for busoni

7 years agogive syncproxy3.wna a dedicated address
Peter Palfrader [Mon, 13 Feb 2017 19:44:34 +0000 (20:44 +0100)]
give syncproxy3.wna a dedicated address

7 years agoCall it syncproxy3.wna instead, our config does not like to re-use the server's hostn...
Peter Palfrader [Mon, 13 Feb 2017 19:19:51 +0000 (20:19 +0100)]
Call it syncproxy3.wna instead, our config does not like to re-use the server's hostname for a vhost easily

7 years agoremove no longer needed rsync access ferm role - glinka is history and gretchaninov...
Peter Palfrader [Mon, 13 Feb 2017 19:10:54 +0000 (20:10 +0100)]
remove no longer needed rsync access ferm role - glinka is history and gretchaninov is in the syncproxy role

7 years agogretchaninov as a syncproxy
Peter Palfrader [Mon, 13 Feb 2017 19:09:36 +0000 (20:09 +0100)]
gretchaninov as a syncproxy

7 years agoAdd manpages.d.n -> d.o redirect
Peter Palfrader [Mon, 13 Feb 2017 18:19:00 +0000 (19:19 +0100)]
Add manpages.d.n -> d.o redirect

7 years agofix syncproxy http -> https redirect on ipv6
Peter Palfrader [Sun, 12 Feb 2017 17:11:54 +0000 (17:11 +0000)]
fix syncproxy http -> https redirect on ipv6

7 years agofix syncproxy https bind on ipv6 address
Peter Palfrader [Sun, 12 Feb 2017 17:04:18 +0000 (17:04 +0000)]
fix syncproxy https bind on ipv6 address

7 years agosupport limit-mirrors in has_static_component
Peter Palfrader [Sun, 12 Feb 2017 16:36:50 +0000 (17:36 +0100)]
support limit-mirrors in has_static_component

7 years agorename archive-master rsyncd.conf
Peter Palfrader [Sun, 12 Feb 2017 08:39:18 +0000 (09:39 +0100)]
rename archive-master rsyncd.conf

7 years agoAdd lldpd via puppet
Peter Palfrader [Sat, 11 Feb 2017 16:12:02 +0000 (17:12 +0100)]
Add lldpd via puppet

7 years agoadd mirroradm static push sudo
Peter Palfrader [Sat, 11 Feb 2017 13:38:32 +0000 (14:38 +0100)]
add mirroradm static push sudo

7 years agomirror-master static component
Peter Palfrader [Sat, 11 Feb 2017 13:33:06 +0000 (14:33 +0100)]
mirror-master static component

7 years agojust move roles around to group things by service. should be no real changes
Peter Palfrader [Fri, 10 Feb 2017 20:54:51 +0000 (21:54 +0100)]
just move roles around to group things by service.  should be no real changes

7 years agorename archive_master to historical_master to match _mirror name
Peter Palfrader [Fri, 10 Feb 2017 20:52:32 +0000 (21:52 +0100)]
rename archive_master to historical_master to match _mirror name

7 years agoMove archvsync_base from FTP to debian_mirror
Peter Palfrader [Fri, 10 Feb 2017 20:50:55 +0000 (21:50 +0100)]
Move archvsync_base from FTP to debian_mirror

7 years agowe already set the TLSA up in rsync::site_systemd.pp
Peter Palfrader [Fri, 10 Feb 2017 20:47:38 +0000 (21:47 +0100)]
we already set the TLSA up in rsync::site_systemd.pp

7 years agoMerge remote-tracking branch 'waldi/rsync-systemd-master'
Peter Palfrader [Fri, 10 Feb 2017 20:41:07 +0000 (21:41 +0100)]
Merge remote-tracking branch 'waldi/rsync-systemd-master'

* waldi/rsync-systemd-master:
  Use rsyncd via system on security_master
  Use rsyncd via systemd on ftp_master
  Use rsyncd via systemd on archive_master

7 years agolittle /srv/mirrors changes
Peter Palfrader [Fri, 10 Feb 2017 20:36:35 +0000 (21:36 +0100)]
little /srv/mirrors changes

7 years agoMerge remote-tracking branch 'waldi/srv-mirrors'
Peter Palfrader [Fri, 10 Feb 2017 20:35:31 +0000 (21:35 +0100)]
Merge remote-tracking branch 'waldi/srv-mirrors'

* waldi/srv-mirrors:
  Setup /srv/mirrors/debian-security on security_mirror
  Setup /srv/mirrors on all (archvsync-based) mirrors

Conflicts:
modules/roles/manifests/ftp.pp

7 years agoAdd a note to ftp.d.o role to point to debian_mirror
Peter Palfrader [Fri, 10 Feb 2017 20:31:35 +0000 (21:31 +0100)]
Add a note to ftp.d.o role to point to debian_mirror

7 years agoAdd a note to roles::ftp
Peter Palfrader [Fri, 10 Feb 2017 20:30:56 +0000 (21:30 +0100)]
Add a note to roles::ftp

7 years agoSetup /srv/mirrors/debian-security on security_mirror
Bastian Blank [Fri, 10 Feb 2017 20:10:11 +0000 (21:10 +0100)]
Setup /srv/mirrors/debian-security on security_mirror

7 years agoSetup /srv/mirrors on all (archvsync-based) mirrors
Bastian Blank [Fri, 10 Feb 2017 20:06:37 +0000 (21:06 +0100)]
Setup /srv/mirrors on all (archvsync-based) mirrors

7 years agoUse rsyncd via system on security_master
Bastian Blank [Fri, 10 Feb 2017 20:00:58 +0000 (21:00 +0100)]
Use rsyncd via system on security_master

7 years agoUse rsyncd via systemd on ftp_master
Bastian Blank [Fri, 10 Feb 2017 20:00:01 +0000 (21:00 +0100)]
Use rsyncd via systemd on ftp_master

7 years agoUse rsyncd via systemd on archive_master
Bastian Blank [Fri, 10 Feb 2017 19:59:32 +0000 (20:59 +0100)]
Use rsyncd via systemd on archive_master

7 years agoAdd cdn.debian.net server alias to deb.do
Peter Palfrader [Fri, 10 Feb 2017 12:57:11 +0000 (13:57 +0100)]
Add cdn.debian.net server alias to deb.do

7 years agoDo not add + for IndexOption in global context. It should still add to the existing...
Peter Palfrader [Thu, 9 Feb 2017 19:17:05 +0000 (20:17 +0100)]
Do not add + for IndexOption in global context.  It should still add to the existing options

7 years agoRemove redundant IndexOptions from all vhosts
Peter Palfrader [Thu, 9 Feb 2017 08:44:18 +0000 (09:44 +0100)]
Remove redundant IndexOptions from all vhosts

7 years agoDisable file descriptions in all apache indexes
Peter Palfrader [Thu, 9 Feb 2017 08:43:17 +0000 (09:43 +0100)]
Disable file descriptions in all apache indexes

7 years agoGet rid of incorrectly-specified (and therefore unused SuppressDescription IndexOptions
Peter Palfrader [Thu, 9 Feb 2017 08:18:49 +0000 (09:18 +0100)]
Get rid of incorrectly-specified (and therefore unused SuppressDescription IndexOptions

7 years agoAdd a couple aliases to the deb.d.o vhost
Julien Cristau [Thu, 9 Feb 2017 08:09:40 +0000 (09:09 +0100)]
Add a couple aliases to the deb.d.o vhost

Part of deprecating httpredir.

7 years agoMerge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa...
Martin Zobel-Helas [Wed, 8 Feb 2017 15:14:43 +0000 (16:14 +0100)]
Merge branch 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

* 'master' of git+ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet:
  add sallinen
  Enable authentication for buildd-keyrings rsync module
  Use archvsync managed secrets files for rsyncd on syncproxy
  Cannot depend on Package[xinetd] without it being defined
  only pull in xinetd if we do not try to remove files
  Enable rsync-ssl on keyring.debian.org
  Unify rsyncd module comments
  Extract default rsyncd module parameter
  De-list all rsync shares on ftp/ports/security-master
  Enable rsync-ssl on keyring.debian.org
  setup-all-dchroots: use the 2017 key for debian-ports

7 years agoadd conova as bgp peer
Martin Zobel-Helas [Wed, 8 Feb 2017 15:14:19 +0000 (16:14 +0100)]
add conova as bgp peer

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoadd sallinen
Julien Cristau [Wed, 8 Feb 2017 08:59:49 +0000 (09:59 +0100)]
add sallinen

7 years agoMerge remote-tracking branch 'waldi/rsyncd-buildd-keyrings-auth'
Peter Palfrader [Tue, 7 Feb 2017 21:27:55 +0000 (22:27 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-buildd-keyrings-auth'

* waldi/rsyncd-buildd-keyrings-auth:
  Enable authentication for buildd-keyrings rsync module

7 years agoEnable authentication for buildd-keyrings rsync module
Bastian Blank [Tue, 7 Feb 2017 21:20:27 +0000 (22:20 +0100)]
Enable authentication for buildd-keyrings rsync module

7 years agoMerge remote-tracking branch 'waldi/managed-rsyncd-syncproxy'
Peter Palfrader [Tue, 7 Feb 2017 21:13:11 +0000 (22:13 +0100)]
Merge remote-tracking branch 'waldi/managed-rsyncd-syncproxy'

* waldi/managed-rsyncd-syncproxy:
  Use archvsync managed secrets files for rsyncd on syncproxy

7 years agoUse archvsync managed secrets files for rsyncd on syncproxy
Bastian Blank [Tue, 7 Feb 2017 21:11:03 +0000 (22:11 +0100)]
Use archvsync managed secrets files for rsyncd on syncproxy

7 years agoMerge remote-tracking branch 'waldi/rsyncd-unify'
Peter Palfrader [Tue, 7 Feb 2017 20:58:38 +0000 (21:58 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-unify'

* waldi/rsyncd-unify:
  Unify rsyncd module comments
  Extract default rsyncd module parameter
  De-list all rsync shares on ftp/ports/security-master

7 years agoCannot depend on Package[xinetd] without it being defined
Peter Palfrader [Tue, 7 Feb 2017 20:47:16 +0000 (21:47 +0100)]
Cannot depend on Package[xinetd] without it being defined

7 years agoonly pull in xinetd if we do not try to remove files
Peter Palfrader [Tue, 7 Feb 2017 20:45:30 +0000 (21:45 +0100)]
only pull in xinetd if we do not try to remove files

7 years agoMerge remote-tracking branch 'waldi/keyring-ssl'
Peter Palfrader [Tue, 7 Feb 2017 20:41:49 +0000 (21:41 +0100)]
Merge remote-tracking branch 'waldi/keyring-ssl'

* waldi/keyring-ssl:
  Enable rsync-ssl on keyring.debian.org

Conflicts:
modules/roles/manifests/keyring.pp

7 years agoEnable rsync-ssl on keyring.debian.org
Bastian Blank [Fri, 3 Feb 2017 17:34:28 +0000 (18:34 +0100)]
Enable rsync-ssl on keyring.debian.org

7 years agoMerge remote-tracking branch 'waldi/keyring-ssl'
Peter Palfrader [Tue, 7 Feb 2017 20:37:19 +0000 (21:37 +0100)]
Merge remote-tracking branch 'waldi/keyring-ssl'

* waldi/keyring-ssl:
  Enable rsync-ssl on keyring.debian.org

7 years agoUnify rsyncd module comments
Bastian Blank [Fri, 3 Feb 2017 17:55:55 +0000 (18:55 +0100)]
Unify rsyncd module comments

7 years agoExtract default rsyncd module parameter
Bastian Blank [Fri, 3 Feb 2017 17:52:29 +0000 (18:52 +0100)]
Extract default rsyncd module parameter

7 years agoDe-list all rsync shares on ftp/ports/security-master
Bastian Blank [Fri, 3 Feb 2017 17:48:14 +0000 (18:48 +0100)]
De-list all rsync shares on ftp/ports/security-master

Remove all comments at the same time

7 years agoEnable rsync-ssl on keyring.debian.org
Bastian Blank [Fri, 3 Feb 2017 17:34:28 +0000 (18:34 +0100)]
Enable rsync-ssl on keyring.debian.org

7 years agosetup-all-dchroots: use the 2017 key for debian-ports
Aurelien Jarno [Tue, 7 Feb 2017 15:29:38 +0000 (16:29 +0100)]
setup-all-dchroots: use the 2017 key for debian-ports

7 years agoadd ServerAlias for debian.testing-anycast.mirrors.debian.org
Martin Zobel-Helas [Tue, 7 Feb 2017 10:42:33 +0000 (11:42 +0100)]
add ServerAlias for debian.testing-anycast.mirrors.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoAdd CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync
Peter Palfrader [Mon, 6 Feb 2017 22:04:41 +0000 (23:04 +0100)]
Add CAP_DAC_READ_SEARCH to CapabilityBoundingSet for rsync

7 years agoubc-bl2 is powered off
Martin Zobel-Helas [Mon, 6 Feb 2017 20:03:15 +0000 (21:03 +0100)]
ubc-bl2 is powered off

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoMerge remote-tracking branch 'waldi/rsyncd-protect'
Peter Palfrader [Mon, 6 Feb 2017 11:52:42 +0000 (12:52 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-protect'

* waldi/rsyncd-protect:
  Allow rsyncd to access /home read-only

7 years agoAllow rsyncd to access /home read-only
Bastian Blank [Fri, 3 Feb 2017 17:24:42 +0000 (18:24 +0100)]
Allow rsyncd to access /home read-only

7 years agoMerge remote-tracking branch 'waldi/rsyncd-systemd'
Peter Palfrader [Fri, 3 Feb 2017 09:07:50 +0000 (10:07 +0100)]
Merge remote-tracking branch 'waldi/rsyncd-systemd'

* waldi/rsyncd-systemd:
  Use rsync::site_systemd on ports_master
  Add systemd backed rsync service

7 years agoUse rsync::site_systemd on ports_master
Bastian Blank [Sun, 29 Jan 2017 10:56:11 +0000 (11:56 +0100)]
Use rsync::site_systemd on ports_master

7 years agoAdd systemd backed rsync service
Bastian Blank [Sun, 29 Jan 2017 10:26:15 +0000 (11:26 +0100)]
Add systemd backed rsync service

7 years agoremove nfs/autofs from bilbao
Peter Palfrader [Fri, 3 Feb 2017 08:44:26 +0000 (09:44 +0100)]
remove nfs/autofs from bilbao

7 years agoadd bilbao-lvm
Peter Palfrader [Thu, 2 Feb 2017 14:28:46 +0000 (15:28 +0100)]
add bilbao-lvm

7 years agoretire debprivate-darmstadt.debian.org
Peter Palfrader [Thu, 2 Feb 2017 13:57:09 +0000 (14:57 +0100)]
retire debprivate-darmstadt.debian.org

7 years agofix ports-master rename
Peter Palfrader [Thu, 2 Feb 2017 10:27:14 +0000 (11:27 +0100)]
fix ports-master rename

7 years agoRemove unused parameter fname from rsync::site
Bastian Blank [Sun, 29 Jan 2017 09:13:48 +0000 (10:13 +0100)]
Remove unused parameter fname from rsync::site

Signed-off-by: Peter Palfrader <peter@palfrader.org>
7 years agoRename roles::ports-master to roles::ports_master
Bastian Blank [Sun, 29 Jan 2017 10:55:31 +0000 (11:55 +0100)]
Rename roles::ports-master to roles::ports_master

Signed-off-by: Peter Palfrader <peter@palfrader.org>
7 years agoremove extra stuff
Peter Palfrader [Wed, 1 Feb 2017 19:15:48 +0000 (20:15 +0100)]
remove extra stuff

7 years agodeploy network/interfaces stanza for anycast node
Peter Palfrader [Wed, 1 Feb 2017 19:14:21 +0000 (20:14 +0100)]
deploy network/interfaces stanza for anycast node

7 years agouse the puppet archive.d.o apache config on sibelius
Peter Palfrader [Wed, 1 Feb 2017 07:48:50 +0000 (08:48 +0100)]
use the puppet archive.d.o apache config on sibelius

7 years agoremove confusing apache::cache manifest
Peter Palfrader [Wed, 1 Feb 2017 07:46:22 +0000 (08:46 +0100)]
remove confusing apache::cache manifest

7 years agouse the puppet archive.d.o apache config on klecker
Peter Palfrader [Wed, 1 Feb 2017 07:42:58 +0000 (08:42 +0100)]
use the puppet archive.d.o apache config on klecker

7 years agoadd archive bind address for klecker
Peter Palfrader [Wed, 1 Feb 2017 07:42:06 +0000 (08:42 +0100)]
add archive bind address for klecker

7 years agoServe the archive on / and on /debian-archive/
Peter Palfrader [Wed, 1 Feb 2017 07:40:42 +0000 (08:40 +0100)]
Serve the archive on / and on /debian-archive/

7 years agouse expires on archive
Peter Palfrader [Wed, 1 Feb 2017 07:38:52 +0000 (08:38 +0100)]
use expires on archive

7 years agoarchive.d.o is not your standard archive layout
Peter Palfrader [Wed, 1 Feb 2017 07:37:39 +0000 (08:37 +0100)]
archive.d.o is not your standard archive layout

7 years agoMake gretchaninov an archive mirror
Peter Palfrader [Wed, 1 Feb 2017 07:31:06 +0000 (08:31 +0100)]
Make gretchaninov an archive mirror

7 years agoSet ServerAdmin properly on ftp.d.o vhost
Peter Palfrader [Wed, 1 Feb 2017 07:28:23 +0000 (08:28 +0100)]
Set ServerAdmin properly on ftp.d.o vhost

7 years agoDisable userdir on a bunch of vhosts
Peter Palfrader [Wed, 1 Feb 2017 07:27:38 +0000 (08:27 +0100)]
Disable userdir on a bunch of vhosts

7 years agowhitespace change
Peter Palfrader [Wed, 1 Feb 2017 07:25:40 +0000 (08:25 +0100)]
whitespace change

7 years agoadd dedication
Martin Zobel-Helas [Tue, 31 Jan 2017 22:08:08 +0000 (23:08 +0100)]
add dedication

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>