mirror/dsa-puppet.git
5 years agoUse ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganet...
Peter Palfrader [Sun, 18 Nov 2018 09:50:11 +0000 (10:50 +0100)]
Use ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganeti module

5 years agoAlso restrict "ganeti/kvm host" purpose
Peter Palfrader [Sun, 18 Nov 2018 09:47:57 +0000 (10:47 +0100)]
Also restrict "ganeti/kvm host" purpose

5 years agoTry to not limit ganeti firewall rules to v4
Peter Palfrader [Sun, 18 Nov 2018 09:25:51 +0000 (10:25 +0100)]
Try to not limit ganeti firewall rules to v4

5 years agosudo: add additional openmanage command line for nagios
Julien Cristau [Tue, 13 Nov 2018 14:24:37 +0000 (15:24 +0100)]
sudo: add additional openmanage command line for nagios

Lets us blacklist the battery probe on wieck and schumann.

5 years agoferm cleanup: sallinen
Peter Palfrader [Tue, 13 Nov 2018 12:58:00 +0000 (13:58 +0100)]
ferm cleanup: sallinen

5 years agoferm cleanup: bmdb1:debsources, fix
Peter Palfrader [Tue, 13 Nov 2018 12:55:38 +0000 (13:55 +0100)]
ferm cleanup: bmdb1:debsources, fix

5 years agoferm cleanup: bmdb1:debsources
Peter Palfrader [Tue, 13 Nov 2018 12:54:21 +0000 (13:54 +0100)]
ferm cleanup: bmdb1:debsources

5 years agoferm cleanup: bmdb1:dedup
Peter Palfrader [Tue, 13 Nov 2018 12:53:14 +0000 (13:53 +0100)]
ferm cleanup: bmdb1:dedup

5 years agoferm cleanup: bmdb1:bacula
Peter Palfrader [Tue, 13 Nov 2018 12:52:24 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:bacula

5 years agoferm cleanup: bmdb1:wannabuild, remove duplicate allow from backuphost
Peter Palfrader [Tue, 13 Nov 2018 12:52:01 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:wannabuild, remove duplicate allow from backuphost

5 years agoferm cleanup: bmdb1:wannabuild
Peter Palfrader [Tue, 13 Nov 2018 12:50:36 +0000 (13:50 +0100)]
ferm cleanup: bmdb1:wannabuild

5 years agoferm cleanup: bmdb1:dak, fix
Peter Palfrader [Tue, 13 Nov 2018 12:48:49 +0000 (13:48 +0100)]
ferm cleanup: bmdb1:dak, fix

5 years agoferm cleanup: bmdb1:dak
Peter Palfrader [Tue, 13 Nov 2018 12:46:53 +0000 (13:46 +0100)]
ferm cleanup: bmdb1:dak

5 years agoferm cleanup: bmdb1:main, fix
Peter Palfrader [Tue, 13 Nov 2018 12:41:42 +0000 (13:41 +0100)]
ferm cleanup: bmdb1:main, fix

5 years agoferm cleanup: bmdb1:main
Peter Palfrader [Tue, 13 Nov 2018 12:39:35 +0000 (13:39 +0100)]
ferm cleanup: bmdb1:main

also: no longer allow bmdb1:main access from bm-bl9

5 years agoferm cleanup: fasolo postgres
Peter Palfrader [Tue, 13 Nov 2018 12:12:15 +0000 (13:12 +0100)]
ferm cleanup: fasolo postgres

5 years agotest avoiding hardcoding addresses
Peter Palfrader [Tue, 13 Nov 2018 12:08:53 +0000 (13:08 +0100)]
test avoiding hardcoding addresses

5 years agono more varnish on sibelius
Peter Palfrader [Tue, 13 Nov 2018 09:40:32 +0000 (10:40 +0100)]
no more varnish on sibelius

5 years agobugs-search no longer runs on sonntag
Peter Palfrader [Tue, 13 Nov 2018 09:40:09 +0000 (10:40 +0100)]
bugs-search no longer runs on sonntag

5 years agobacklist 51.15.215.91 from snapshot
Peter Palfrader [Sun, 11 Nov 2018 17:35:33 +0000 (18:35 +0100)]
backlist 51.15.215.91 from snapshot

5 years agoRevert "99builddsourceslist: temporarily add stretch-proposed-updates to stretch...
Julien Cristau [Sun, 11 Nov 2018 00:44:50 +0000 (01:44 +0100)]
Revert "99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots"

Debian 9.6 is out, so the temporary workaround is no longer necessary.

This reverts commit 6817281d2e8f2d2a0991b7517d451e6c7e38734a.

5 years agosamhain: ignore /etc/schroot/dsa/default-mirror
Julien Cristau [Fri, 9 Nov 2018 14:25:50 +0000 (15:25 +0100)]
samhain: ignore /etc/schroot/dsa/default-mirror

It comes from puppet.

5 years agosamhain: deal with rename of db.d.o restricted sources.list entry
Julien Cristau [Thu, 8 Nov 2018 08:12:51 +0000 (09:12 +0100)]
samhain: deal with rename of db.d.o restricted sources.list entry

5 years agosudo: add manda-node0[34] to DELLHOSTS
Julien Cristau [Wed, 7 Nov 2018 22:20:50 +0000 (23:20 +0100)]
sudo: add manda-node0[34] to DELLHOSTS

Lets nagios monitor system and storage health.

5 years agoFix debian_org::apt_restricted
Julien Cristau [Wed, 7 Nov 2018 21:13:12 +0000 (22:13 +0100)]
Fix debian_org::apt_restricted

5 years agoInstall srvadmin foo on dell hosts, and move our restricted archive to debian_org...
Julien Cristau [Wed, 7 Nov 2018 21:07:37 +0000 (22:07 +0100)]
Install srvadmin foo on dell hosts, and move our restricted archive to debian_org::apt_restricted

5 years agoand symlink
Peter Palfrader [Wed, 7 Nov 2018 19:22:52 +0000 (20:22 +0100)]
and symlink

5 years agochange megaraid_sas test
Peter Palfrader [Wed, 7 Nov 2018 19:19:00 +0000 (20:19 +0100)]
change megaraid_sas test

5 years agoftp.de.debian.org appears to be unavailable -- switch man-da to ftp2
Peter Palfrader [Wed, 7 Nov 2018 19:09:24 +0000 (20:09 +0100)]
ftp.de.debian.org appears to be unavailable -- switch man-da to ftp2

5 years agodifferent name for aptrepo
Peter Palfrader [Wed, 7 Nov 2018 18:16:04 +0000 (19:16 +0100)]
different name for aptrepo

5 years agofix class
Peter Palfrader [Wed, 7 Nov 2018 18:13:02 +0000 (19:13 +0100)]
fix class

5 years agomegaraid_sas
Peter Palfrader [Wed, 7 Nov 2018 18:11:47 +0000 (19:11 +0100)]
megaraid_sas

5 years agoAdd megaraid_sas facter
Peter Palfrader [Wed, 7 Nov 2018 18:08:38 +0000 (19:08 +0100)]
Add megaraid_sas facter

5 years agoPut grub and kernel on ttyS0 on manda-node0[34]
Julien Cristau [Wed, 7 Nov 2018 09:01:25 +0000 (10:01 +0100)]
Put grub and kernel on ttyS0 on manda-node0[34]

5 years agosetup-dchroot: merge from tor (genname split into function, ubuntu updates)
Peter Palfrader [Tue, 6 Nov 2018 08:04:53 +0000 (09:04 +0100)]
setup-dchroot: merge from tor (genname split into function, ubuntu updates)

- split schroot base name generation into its own function
- if we build an ubuntu chroot, upgrade to the latest packages available
  in -updates and -security of their suite, since it seems they don't
  ever do point releases so you end up with a 4 year old openssl in your
  chroot.

5 years agoTemporarily switch off privacy logging for security.d.o
Julien Cristau [Mon, 5 Nov 2018 19:21:57 +0000 (20:21 +0100)]
Temporarily switch off privacy logging for security.d.o

I want to figure out what clients are still hitting it directly,
especially at specific times, so some insight into User-Agents and
timestamps would be useful.

5 years agoRedirect all of security.d.o to security-cdn
Julien Cristau [Sun, 4 Nov 2018 12:03:42 +0000 (13:03 +0100)]
Redirect all of security.d.o to security-cdn

Instead of just /pool/updates/main/l/linux/*, redirect everything except:
- if coming from fastly or aws
- if coming from nagios or mini-nag
- if using the onion service
- if doing a health check

Eventually we might point the security.d.o name directly at the CDN, but let's
see if this helps already.

5 years agoExclude dsa-check-mirrorsync nagios check from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:11:23 +0000 (16:11 +0100)]
Exclude dsa-check-mirrorsync nagios check from security to security-cdn redirect

5 years agoExclude nagios check_http from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:09:25 +0000 (16:09 +0100)]
Exclude nagios check_http from security to security-cdn redirect

Prep for making that redirect global

5 years agoDisable mod_disk_cache on security-tracker
Julien Cristau [Fri, 2 Nov 2018 12:19:18 +0000 (13:19 +0100)]
Disable mod_disk_cache on security-tracker

5 years agoDrop sibelius from postgres-make-base-backups
Julien Cristau [Thu, 1 Nov 2018 17:34:33 +0000 (18:34 +0100)]
Drop sibelius from postgres-make-base-backups

5 years agoDrop firewall rule for pg @ sibelius
Julien Cristau [Thu, 1 Nov 2018 17:32:53 +0000 (18:32 +0100)]
Drop firewall rule for pg @ sibelius

5 years agoRemove sibelius/snapshot from dsa-check-backuppg
Julien Cristau [Thu, 1 Nov 2018 17:31:31 +0000 (18:31 +0100)]
Remove sibelius/snapshot from dsa-check-backuppg

5 years agounique all ip addresses
Peter Palfrader [Wed, 31 Oct 2018 08:41:50 +0000 (09:41 +0100)]
unique all ip addresses

5 years agoTry a unique around v4addrs
Peter Palfrader [Wed, 31 Oct 2018 08:39:06 +0000 (09:39 +0100)]
Try a unique around v4addrs

5 years agoRevert "sibelius nfs on public net"
Peter Palfrader [Wed, 31 Oct 2018 08:34:17 +0000 (09:34 +0100)]
Revert "sibelius nfs on public net"

This reverts commits 613379c1d1814794d873352a4791c5556eac938f and
1f3cd8bea3ed396c5e1ab35d369e6b72bb27b3f2.

5 years agosibelius nfs on public net, 2
Peter Palfrader [Wed, 31 Oct 2018 08:05:47 +0000 (09:05 +0100)]
sibelius nfs on public net, 2

5 years agosibelius nfs on public net
Peter Palfrader [Wed, 31 Oct 2018 08:05:09 +0000 (09:05 +0100)]
sibelius nfs on public net

5 years agomake fail2ban cleanup job shut up
Peter Palfrader [Tue, 30 Oct 2018 10:18:15 +0000 (11:18 +0100)]
make fail2ban cleanup job shut up

5 years agomove DROP blacklists to ferm prio 005, after munin
Peter Palfrader [Tue, 30 Oct 2018 09:45:11 +0000 (10:45 +0100)]
move DROP blacklists to ferm prio 005, after munin

5 years agomanually create the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:38:18 +0000 (10:38 +0100)]
manually create the subchain

5 years agoprevent the trailing ; after the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:32:31 +0000 (10:32 +0100)]
prevent the trailing ; after the subchain

5 years agomove the fail2ban rules under the dsa-f2b chain
Peter Palfrader [Tue, 30 Oct 2018 09:28:01 +0000 (10:28 +0100)]
move the fail2ban rules under the dsa-f2b chain

5 years agoMove logging and related/established out of ferm.conf into a dsa.d rule
Peter Palfrader [Tue, 30 Oct 2018 09:23:42 +0000 (10:23 +0100)]
Move logging and related/established out of ferm.conf into a dsa.d rule

5 years agomove munin rules from conf.d to the rules dir, 2
Peter Palfrader [Tue, 30 Oct 2018 09:21:31 +0000 (10:21 +0100)]
move munin rules from conf.d to the rules dir, 2

5 years agomove munin rules from conf.d to the rules dir
Peter Palfrader [Tue, 30 Oct 2018 09:20:32 +0000 (10:20 +0100)]
move munin rules from conf.d to the rules dir

5 years agorename interfaces to 50-munin-interfaces
Peter Palfrader [Tue, 30 Oct 2018 09:17:50 +0000 (10:17 +0100)]
rename interfaces to  50-munin-interfaces

5 years agomerge munin_ip v4 and v6 into one rule
Peter Palfrader [Tue, 30 Oct 2018 09:15:25 +0000 (10:15 +0100)]
merge munin_ip v4 and v6 into one rule

5 years agochange default ferm rule priority to 10 from 00
Peter Palfrader [Tue, 30 Oct 2018 09:07:46 +0000 (10:07 +0100)]
change default ferm rule priority to 10 from 00

5 years agoalso govern submission port
Peter Palfrader [Tue, 30 Oct 2018 09:00:46 +0000 (10:00 +0100)]
also govern submission port

5 years agoClean up fail2ban database
Peter Palfrader [Tue, 30 Oct 2018 08:57:53 +0000 (09:57 +0100)]
Clean up fail2ban database

5 years agomore aggressive fail2ban on exim hosts
Peter Palfrader [Sun, 28 Oct 2018 12:05:41 +0000 (13:05 +0100)]
more aggressive fail2ban on exim hosts

5 years agoAdd a second easydns ipv4 address
Peter Palfrader [Tue, 23 Oct 2018 16:29:04 +0000 (18:29 +0200)]
Add a second easydns ipv4 address

5 years agomirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug

5 years agoMake mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug

5 years agoklecker no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug

5 years agoremove debian.fi
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi

We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.

5 years agonetnod call the key netnod-debian-20171122
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-20171122

5 years agotry to switch dnsnodeapi-ACL over to the TSIG key
Peter Palfrader [Wed, 17 Oct 2018 13:11:27 +0000 (15:11 +0200)]
try to switch dnsnodeapi-ACL over to the TSIG key

5 years agotry a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings

5 years agoallow respighi to access udd on ullmann
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann

it's used to create the autoremoval hints

5 years agomerge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule

5 years agoallow ssh from ftpmaster to debug_mirrors
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors

5 years agodebug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter

5 years agoMake hiera's debug_mirror look like debian_mirror
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror

5 years agofix a prefix len in dsa-postgres-udd6
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6

5 years agoRemove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses

5 years agoSet up grub with serial console at leaseweb
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb

5 years agoAdd health check on debian-debug archive backends
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends

5 years agoUsing *:80 as vhost on mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu

everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.

5 years agofix onion_v4_addr in debug class
Peter Palfrader [Fri, 12 Oct 2018 12:28:31 +0000 (14:28 +0200)]
fix onion_v4_addr in debug class

5 years agofix onion role for debug
Peter Palfrader [Fri, 12 Oct 2018 12:26:37 +0000 (14:26 +0200)]
fix onion role for debug

5 years agoput -debug webserver and onion config onto mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:21:04 +0000 (14:21 +0200)]
put -debug webserver and onion config onto mirror-accumu

5 years agodo fail2ban on postfix AUTH attempts on lists.d.o
Peter Palfrader [Fri, 12 Oct 2018 09:11:52 +0000 (11:11 +0200)]
do fail2ban on postfix AUTH attempts on lists.d.o

5 years agoretire old DNS root key
Peter Palfrader [Thu, 11 Oct 2018 16:04:22 +0000 (18:04 +0200)]
retire old DNS root key

5 years agodrop manual blacklist of smtp abusers
Peter Palfrader [Wed, 10 Oct 2018 09:19:35 +0000 (11:19 +0200)]
drop manual blacklist of smtp abusers

5 years agouse fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)
Peter Palfrader [Wed, 10 Oct 2018 09:19:12 +0000 (11:19 +0200)]
use fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)

5 years agoAdd smtp_protocol_error to log_selector
Peter Palfrader [Wed, 10 Oct 2018 08:34:08 +0000 (10:34 +0200)]
Add smtp_protocol_error to log_selector

We want to learn when clients try to use AUTH LOGIN and friends so we
can block them more easily.

5 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:24:14 +0000 (10:24 +0200)]
more

5 years agomore
Peter Palfrader [Wed, 10 Oct 2018 08:19:14 +0000 (10:19 +0200)]
more

5 years agonetfilter DROP traffic from some mail abusers
Peter Palfrader [Wed, 10 Oct 2018 08:15:41 +0000 (10:15 +0200)]
netfilter DROP traffic from some mail abusers

5 years agoStart with removing some moszumanska entries (in particular about pg backups). re...
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups).  re: #7513)

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls...
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt

5 years agorestart unbound after putting trust anchors in place
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place

5 years agoUse temporary redirects for ports redirects to the wiki
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki

The URLs could change to the website or elsewhere at some point.

Suggested-by: weasel
5 years agoRedirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages

5 years agoAdd workaround for new Tor configuration requirement
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement

See-also: https://trac.torproject.org/projects/tor/ticket/27849