mirror/dsa-puppet.git
7 years agoMove ntp and ntpdate incldue into a time module
Peter Palfrader [Fri, 9 Dec 2016 08:13:00 +0000 (08:13 +0000)]
Move ntp and ntpdate incldue into a time module

7 years agoLet the puppet usergroup read puppet.conf
Peter Palfrader [Fri, 9 Dec 2016 08:10:58 +0000 (09:10 +0100)]
Let the puppet usergroup read puppet.conf

7 years agodecommission franck
Aurelien Jarno [Thu, 8 Dec 2016 14:14:36 +0000 (15:14 +0100)]
decommission franck

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoChange /etc/puppet/puppet.conf mode to 0440
Aurelien Jarno [Thu, 8 Dec 2016 14:10:16 +0000 (15:10 +0100)]
Change /etc/puppet/puppet.conf mode to 0440

It contains a password on the master node.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agosudo from videoteam to sreview
Peter Palfrader [Thu, 8 Dec 2016 09:59:43 +0000 (10:59 +0100)]
sudo from videoteam to sreview

7 years agoraise HPKP timeout from 14 days to 60
Peter Palfrader [Sat, 3 Dec 2016 09:38:13 +0000 (10:38 +0100)]
raise HPKP timeout from 14 days to 60

7 years agoinstall popcon
Peter Palfrader [Thu, 1 Dec 2016 10:19:44 +0000 (10:19 +0000)]
install popcon

7 years agoUse proper bacula port in bacula-idle-restart
Peter Palfrader [Thu, 1 Dec 2016 10:18:48 +0000 (10:18 +0000)]
Use proper bacula port in bacula-idle-restart

7 years agoRevert "Revert "move back to default bacula ports for ubc""
Peter Palfrader [Wed, 30 Nov 2016 07:20:51 +0000 (08:20 +0100)]
Revert "Revert "move back to default bacula ports for ubc""

This reverts commit 24fc21e69a739a6465c51c4c7f950814bc656b5c.

7 years agoRevert "move back to default bacula ports for ubc"
Peter Palfrader [Tue, 29 Nov 2016 18:09:51 +0000 (19:09 +0100)]
Revert "move back to default bacula ports for ubc"

This reverts commit 9a3c9db00b1fe093ef39d584baf1d47b1c1fadb2.

7 years agomove back to default bacula ports for ubc
Peter Palfrader [Tue, 29 Nov 2016 18:06:56 +0000 (19:06 +0100)]
move back to default bacula ports for ubc

7 years agokill munin-update jobs older than 2 hours
Peter Palfrader [Sat, 26 Nov 2016 13:23:43 +0000 (14:23 +0100)]
kill munin-update jobs older than 2 hours

7 years agoMerge ubcece (old IP address range) into ubc
Peter Palfrader [Sat, 26 Nov 2016 11:43:14 +0000 (12:43 +0100)]
Merge ubcece (old IP address range) into ubc

7 years agoMake bacula-idle-restart use ports defined in the manifest
Peter Palfrader [Sat, 26 Nov 2016 11:33:24 +0000 (11:33 +0000)]
Make bacula-idle-restart use ports defined in the manifest

7 years agoPut client_port into the stored config
Peter Palfrader [Sat, 26 Nov 2016 11:31:09 +0000 (11:31 +0000)]
Put client_port into the stored config

7 years agoSet bacula_fd_port to 19102 for ubc
Peter Palfrader [Sat, 26 Nov 2016 11:30:42 +0000 (11:30 +0000)]
Set bacula_fd_port to 19102 for ubc

7 years agoAllow hiera to override 9102 default for bacula client (fd) port
Peter Palfrader [Sat, 26 Nov 2016 11:30:26 +0000 (11:30 +0000)]
Allow hiera to override 9102 default for bacula client (fd) port

7 years agoUse bacula_client_port variable in ferm rule instead of "bacula-fd" service port
Peter Palfrader [Sat, 26 Nov 2016 11:29:57 +0000 (11:29 +0000)]
Use bacula_client_port variable in ferm rule instead of "bacula-fd" service port

7 years agogive senfter a new apache
Peter Palfrader [Fri, 25 Nov 2016 17:52:05 +0000 (18:52 +0100)]
give senfter a new apache

7 years agoDo not return OCSP errors to clients
Peter Palfrader [Fri, 25 Nov 2016 14:26:27 +0000 (15:26 +0100)]
Do not return OCSP errors to clients

7 years agoraise cache size
Peter Palfrader [Fri, 25 Nov 2016 14:22:29 +0000 (15:22 +0100)]
raise cache size

7 years agoenable stapling on stretch apache2
Peter Palfrader [Fri, 25 Nov 2016 14:11:54 +0000 (15:11 +0100)]
enable stapling on stretch apache2

7 years agosyntax fix II
Peter Palfrader [Fri, 25 Nov 2016 14:05:28 +0000 (15:05 +0100)]
syntax fix II

7 years agosyntax fix I
Peter Palfrader [Fri, 25 Nov 2016 14:05:03 +0000 (15:05 +0100)]
syntax fix I

7 years agoInstall new apache on draghi
Peter Palfrader [Fri, 25 Nov 2016 14:04:14 +0000 (15:04 +0100)]
Install new apache on draghi

7 years agopackage libapache2-mod-macro is obsolete
Peter Palfrader [Fri, 25 Nov 2016 14:00:40 +0000 (15:00 +0100)]
package libapache2-mod-macro is obsolete

7 years agofix whitespace
Peter Palfrader [Fri, 25 Nov 2016 14:00:11 +0000 (15:00 +0100)]
fix whitespace

7 years agoAdd an apache2 factoid for backported from stretch apache
Peter Palfrader [Fri, 25 Nov 2016 13:59:18 +0000 (13:59 +0000)]
Add an apache2 factoid for backported from stretch apache

7 years agobackports static-master is now dillon, source on coccia
Peter Palfrader [Sat, 19 Nov 2016 19:49:20 +0000 (20:49 +0100)]
backports static-master is now dillon, source on coccia

7 years agoRevert "massive amount of spam from that address"
Martin Zobel-Helas [Thu, 17 Nov 2016 21:42:03 +0000 (22:42 +0100)]
Revert "massive amount of spam from that address"

This reverts commit 988ded1d84a750b2cb2fcd86a68869b77a7e1e37.

7 years agomassive amount of spam from that address
Martin Zobel-Helas [Thu, 17 Nov 2016 21:06:36 +0000 (22:06 +0100)]
massive amount of spam from that address

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
7 years agoBegin attempt at adding SSO for the Debian wiki
Paul Wise [Sat, 12 Nov 2016 05:00:36 +0000 (13:00 +0800)]
Begin attempt at adding SSO for the Debian wiki

7 years agosyntax fix
Peter Palfrader [Tue, 8 Nov 2016 20:18:53 +0000 (21:18 +0100)]
syntax fix

7 years agoswitch buildd repo to apt.buildd.debian.org
Peter Palfrader [Tue, 8 Nov 2016 20:18:02 +0000 (21:18 +0100)]
switch buildd repo to apt.buildd.debian.org

7 years agoship apt.buildd only to klecker and senfter
Peter Palfrader [Tue, 8 Nov 2016 19:47:21 +0000 (19:47 +0000)]
ship apt.buildd only to klecker and senfter

7 years agosupport shipping a component to just a few mirrors
Peter Palfrader [Tue, 8 Nov 2016 19:47:12 +0000 (19:47 +0000)]
support shipping a component to just a few mirrors

7 years agoRevert "refactor static-components.conf.erb a bit - no logic changes yet"
Peter Palfrader [Tue, 8 Nov 2016 19:39:17 +0000 (19:39 +0000)]
Revert "refactor static-components.conf.erb a bit - no logic changes yet"

This reverts commit 6b4b367c4bad827e3917fc6622e01f847f49ce14.

7 years agorefactor static-components.conf.erb a bit - no logic changes yet
Peter Palfrader [Tue, 8 Nov 2016 19:28:14 +0000 (20:28 +0100)]
refactor static-components.conf.erb a bit - no logic changes yet

7 years agoAdd apt.buildd.d.o
Peter Palfrader [Tue, 8 Nov 2016 19:24:04 +0000 (20:24 +0100)]
Add apt.buildd.d.o

7 years agoMake wuiet a static source
Peter Palfrader [Tue, 8 Nov 2016 19:00:56 +0000 (20:00 +0100)]
Make wuiet a static source

7 years agoretire powell
Peter Palfrader [Mon, 7 Nov 2016 10:18:48 +0000 (11:18 +0100)]
retire powell

7 years agoStop taking backups from franck
Peter Palfrader [Mon, 7 Nov 2016 07:55:28 +0000 (08:55 +0100)]
Stop taking backups from franck

7 years agosetup-all-dchroots: powerpc/stretch is gone
Aurelien Jarno [Sun, 6 Nov 2016 22:34:34 +0000 (23:34 +0100)]
setup-all-dchroots: powerpc/stretch is gone

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agodo not set terminal type
Peter Palfrader [Fri, 4 Nov 2016 09:42:18 +0000 (10:42 +0100)]
do not set terminal type

7 years agoship a tmux.conf
Peter Palfrader [Fri, 4 Nov 2016 09:35:06 +0000 (10:35 +0100)]
ship a tmux.conf

7 years agoRemove leap second config for debian <= 7
Peter Palfrader [Thu, 3 Nov 2016 14:24:12 +0000 (15:24 +0100)]
Remove leap second config for debian <= 7

7 years agoComment out security linux -> cdn redirect
Peter Palfrader [Thu, 3 Nov 2016 13:37:56 +0000 (14:37 +0100)]
Comment out security linux -> cdn redirect

7 years agoweblogsync: Synchronize public logs in additions of www.debian.org logs
Aurelien Jarno [Tue, 1 Nov 2016 11:51:57 +0000 (12:51 +0100)]
weblogsync: Synchronize public logs in additions of debian.org logs

Commit b8a50b04 has broken the synchronisation of non www.debian.org
public logs. Fix that.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoGive projectb access to usper
Aurelien Jarno [Sun, 30 Oct 2016 19:24:30 +0000 (20:24 +0100)]
Give projectb access to usper

Requested by Joerg Jaspert for the deferred queue overview.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoMove backports-master.debian.org redirection from fasolo to static
Aurelien Jarno [Sat, 29 Oct 2016 21:11:41 +0000 (23:11 +0200)]
Move backports-debian.org redirection from fasolo to static

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agofasolo is a static master and source
Julien Cristau [Sat, 29 Oct 2016 13:38:48 +0000 (15:38 +0200)]
fasolo is a static master and source

7 years agofasolo is master for backports / incoming / metadata.ftp-master
Julien Cristau [Sat, 29 Oct 2016 13:36:42 +0000 (15:36 +0200)]
fasolo is master for backports / incoming / metadata.ftp-master

7 years agoremove dacs
Peter Palfrader [Sat, 29 Oct 2016 07:26:54 +0000 (09:26 +0200)]
remove dacs

7 years agoadd comment
Peter Palfrader [Thu, 27 Oct 2016 18:42:56 +0000 (20:42 +0200)]
add comment

7 years agoUpdate leap-seconds.list
Peter Palfrader [Thu, 27 Oct 2016 18:41:38 +0000 (20:41 +0200)]
Update leap-seconds.list

7 years agoraise max-age for HTTP Public Key Pins from 3 days to 2 weeks
Peter Palfrader [Tue, 25 Oct 2016 11:38:26 +0000 (13:38 +0200)]
raise max-age for HTTP Public Key Pins from 3 days to 2 weeks

7 years agorename ubc-enc2b9 to ubc-enc2bl09
Peter Palfrader [Tue, 25 Oct 2016 08:18:10 +0000 (10:18 +0200)]
rename ubc-enc2b9 to ubc-enc2bl09

7 years agorename ubc-enc2b2 to ubc-enc2bl02
Peter Palfrader [Tue, 25 Oct 2016 08:11:38 +0000 (10:11 +0200)]
rename ubc-enc2b2 to ubc-enc2bl02

7 years agorename ubc-enc2b1 to ubc-enc2bl01
Peter Palfrader [Tue, 25 Oct 2016 07:53:49 +0000 (09:53 +0200)]
rename ubc-enc2b1 to ubc-enc2bl01

7 years agoNo more ftpd on franck
Julien Cristau [Mon, 24 Oct 2016 16:46:24 +0000 (18:46 +0200)]
No more ftpd on franck

7 years agoAdd ftp.upload and ssh.upload roles to usper.d.o
Aurelien Jarno [Sat, 22 Oct 2016 20:21:30 +0000 (22:21 +0200)]
Add ftp.upload and ssh.upload roles to usper.d.o

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoAdd usper.d.o
Aurelien Jarno [Sat, 22 Oct 2016 16:44:35 +0000 (18:44 +0200)]
Add usper.d.o

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoAdd fasolo as ftp-master
Julien Cristau [Sat, 22 Oct 2016 12:32:57 +0000 (14:32 +0200)]
Add fasolo as ftp-master

7 years agoGet rid of "release" role
Julien Cristau [Sat, 22 Oct 2016 12:18:57 +0000 (14:18 +0200)]
Get rid of "release" role

The web bits moved to static.d.o.

7 years agosplit out apt config into own class. use multi-suite site::aptrepo
Peter Palfrader [Fri, 21 Oct 2016 11:21:23 +0000 (11:21 +0000)]
split out apt config into own class.  use multi-suite site::aptrepo

7 years agosupport an array of mirrors for site::aptrepo
Peter Palfrader [Fri, 21 Oct 2016 11:12:30 +0000 (11:12 +0000)]
support an array of mirrors for site::aptrepo

7 years agolet dak signal buildd pool update
Peter Palfrader [Fri, 21 Oct 2016 07:02:32 +0000 (09:02 +0200)]
let dak signal buildd pool update

7 years agoExport debian-security-buildd-pool
Peter Palfrader [Fri, 21 Oct 2016 06:02:38 +0000 (08:02 +0200)]
Export debian-security-buildd-pool

7 years agoget backports from fastly as well
Peter Palfrader [Fri, 21 Oct 2016 05:04:59 +0000 (07:04 +0200)]
get backports from fastly as well

7 years agoForce type for *.debdiff.html.gz on release.d.o
Julien Cristau [Thu, 20 Oct 2016 18:29:48 +0000 (20:29 +0200)]
Force type for *.debdiff.html.gz on release.d.o

Serve them as html rather than gzip.

7 years agoFixup apache config syntax error
Julien Cristau [Thu, 20 Oct 2016 17:47:00 +0000 (19:47 +0200)]
Fixup apache config syntax error

7 years agoDon't redirect on security for cloudfront and tor hidden service
Julien Cristau [Thu, 20 Oct 2016 17:43:54 +0000 (19:43 +0200)]
Don't redirect on security for cloudfront and tor hidden service

Redirecting from https or .onion to plain http is probably a bad plan.

7 years agoredirect linux updates to fastly
Peter Palfrader [Thu, 20 Oct 2016 07:41:41 +0000 (09:41 +0200)]
redirect linux updates to fastly

7 years agopush ~/.selected_editor
Peter Palfrader [Tue, 18 Oct 2016 19:13:10 +0000 (21:13 +0200)]
push ~/.selected_editor

7 years agoAdd deb.debian.org https vhost
Julien Cristau [Tue, 18 Oct 2016 17:40:52 +0000 (19:40 +0200)]
Add deb.debian.org https vhost

A bit special: no HPKP, and redirects are currently different from the
HTTP vhost.

7 years agomove deprecated modulepath so it is only set on the master
Peter Palfrader [Sun, 16 Oct 2016 07:22:40 +0000 (09:22 +0200)]
move deprecated modulepath so it is only set on the master

7 years agoDo not have production and staging section in puppet.conf on all clients
Peter Palfrader [Sun, 16 Oct 2016 07:20:39 +0000 (09:20 +0200)]
Do not have production and staging section in puppet.conf on all clients

7 years agoDecommission jenko
Aurelien Jarno [Sat, 15 Oct 2016 12:54:11 +0000 (14:54 +0200)]
Decommission jenko

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
7 years agoadd acker
Peter Palfrader [Sat, 15 Oct 2016 08:38:29 +0000 (10:38 +0200)]
add acker

7 years agoadd aagaard
Peter Palfrader [Fri, 14 Oct 2016 18:36:48 +0000 (20:36 +0200)]
add aagaard

7 years agoraise pin age to 3d
Peter Palfrader [Fri, 14 Oct 2016 06:14:50 +0000 (08:14 +0200)]
raise pin age to 3d

7 years agoadd new host for luca
Luca Filipozzi [Thu, 13 Oct 2016 17:38:29 +0000 (17:38 +0000)]
add new host for luca

7 years agoremove double slashes on metadata.ftp-master.debian.org
Peter Palfrader [Thu, 13 Oct 2016 07:06:39 +0000 (09:06 +0200)]
remove double slashes on metadata.ftp-debian.org

7 years agoRevert "remove double slashes on metadata.ftp-master.debian.org"
Peter Palfrader [Thu, 13 Oct 2016 06:58:53 +0000 (08:58 +0200)]
Revert "remove double slashes on metadata.ftp-debian.org"

This reverts commit 5d598f2a486bfb7619f294eeb606aa114f183349.

7 years agoremove double slashes on metadata.ftp-master.debian.org
Peter Palfrader [Thu, 13 Oct 2016 06:56:39 +0000 (08:56 +0200)]
remove double slashes on metadata.ftp-debian.org

7 years agoraise pin age to 1d
Peter Palfrader [Wed, 12 Oct 2016 13:04:30 +0000 (15:04 +0200)]
raise pin age to 1d

7 years agoLE cert for buildd
Peter Palfrader [Wed, 12 Oct 2016 13:01:57 +0000 (15:01 +0200)]
LE cert for buildd

7 years agoLE cert for ftp-master
Peter Palfrader [Wed, 12 Oct 2016 13:00:20 +0000 (15:00 +0200)]
LE cert for ftp-master

7 years agoLE cert for munin
Peter Palfrader [Wed, 12 Oct 2016 12:43:29 +0000 (14:43 +0200)]
LE cert for munin

7 years agoLE cert for nagios
Peter Palfrader [Wed, 12 Oct 2016 12:41:01 +0000 (14:41 +0200)]
LE cert for nagios

7 years agoLE cert for nm, contributors
Peter Palfrader [Wed, 12 Oct 2016 12:37:14 +0000 (14:37 +0200)]
LE cert for nm, contributors

7 years agoLE cert for rt
Peter Palfrader [Wed, 12 Oct 2016 12:29:49 +0000 (14:29 +0200)]
LE cert for rt

7 years agoLE cert for security-tracker
Peter Palfrader [Wed, 12 Oct 2016 12:28:03 +0000 (14:28 +0200)]
LE cert for security-tracker

7 years agoLE cert for sso
Peter Palfrader [Wed, 12 Oct 2016 12:24:31 +0000 (14:24 +0200)]
LE cert for sso

7 years agoLE cert for vote
Peter Palfrader [Wed, 12 Oct 2016 12:23:35 +0000 (14:23 +0200)]
LE cert for vote

7 years agoset TLSA port to 0 in preparation of cert roll for buildd, contributors, ftp-master...
Peter Palfrader [Wed, 12 Oct 2016 07:23:48 +0000 (09:23 +0200)]
set TLSA port to 0 in preparation of cert roll for buildd, contributors, ftp-master, munin, nagios, nm, rt, security-tracker, sso, vote

7 years agoMove udd.d.o cert to letsencrypt
Julien Cristau [Sun, 9 Oct 2016 16:14:27 +0000 (18:14 +0200)]
Move udd.d.o cert to letsencrypt

7 years agoSwitch lists.d.o to letsencrypt
Julien Cristau [Sun, 9 Oct 2016 16:07:43 +0000 (18:07 +0200)]
Switch lists.d.o to letsencrypt

Signed-off-by: Julien Cristau <jcristau@debian.org>
7 years agoSwitch to letsencrypt for api.ftp-master.d.o
Julien Cristau [Sun, 9 Oct 2016 15:43:55 +0000 (17:43 +0200)]
Switch to letsencrypt for api.ftp-master.d.o

7 years agodisable TLSA for api.ftp-master, lists, and udd
Peter Palfrader [Sun, 9 Oct 2016 11:31:21 +0000 (13:31 +0200)]
disable TLSA for api.ftp-master, lists, and udd