mirror/dsa-puppet.git
5 years agoAdd schmelzer
Julien Cristau [Wed, 20 Feb 2019 15:37:11 +0000 (16:37 +0100)]
Add schmelzer

5 years agoDecommission kantuser (RT#7583)
Julien Cristau [Sun, 17 Feb 2019 18:53:59 +0000 (19:53 +0100)]
Decommission kantuser (RT#7583)

5 years agoadd default lvm conf for pijper
Aurelien Jarno [Sun, 17 Feb 2019 06:33:27 +0000 (07:33 +0100)]
add default lvm conf for pijper

5 years agocvs.d.o is gone, drop redirect
Tollef Fog Heen [Sat, 16 Feb 2019 21:07:49 +0000 (22:07 +0100)]
cvs.d.o is gone, drop redirect

5 years agoadd mekeel-srv (RT#7226)
Julien Cristau [Sat, 16 Feb 2019 17:04:31 +0000 (18:04 +0100)]
add mekeel-srv (RT#7226)

5 years agosyslog-ng: define fastly destination on all log hosts, not just lully
Julien Cristau [Fri, 8 Feb 2019 07:57:34 +0000 (08:57 +0100)]
syslog-ng: define fastly destination on all log hosts, not just lully

5 years agoRevert "99builddsourceslist: disable apt redirects in chroots"
Aurelien Jarno [Mon, 4 Feb 2019 21:00:07 +0000 (22:00 +0100)]
Revert "99builddsourceslist: disable apt redirects in chroots"

This reverts commit 840177adeb15e1a9f23cff136708eb60a10cd3a7.

All the chroots now have an updated apt.

5 years agoFix KVM detection for rng-tools
Aurelien Jarno [Sun, 3 Feb 2019 09:59:39 +0000 (10:59 +0100)]
Fix KVM detection for rng-tools

5 years agoDo not setup grub/kernel serial console on ppc64el VMs
Aurelien Jarno [Sun, 3 Feb 2019 00:22:02 +0000 (01:22 +0100)]
Do not setup grub/kernel serial console on ppc64el VMs

On ppc64el VMs, grub and the kernel automatically switch to the serial
console if there is no video card. OTOH the serial console is not called
ttyS0, so it's better to not try to setup it up manually.

5 years agoganeti2: remove qemu-system-ppc64 wrapper
Aurelien Jarno [Sun, 3 Feb 2019 00:09:55 +0000 (01:09 +0100)]
ganeti2: remove qemu-system-ppc64 wrapper

The wrapper ended-up simpler than on arm64, therefore kvm_extra can be
used instead.

5 years agoadd loghost-osuosl-01
Julien Cristau [Mon, 28 Jan 2019 21:43:43 +0000 (22:43 +0100)]
add loghost-osuosl-01

5 years agoganeti2: add wrapper for qemu-system-ppc64
Julien Cristau [Sun, 27 Jan 2019 15:00:27 +0000 (16:00 +0100)]
ganeti2: add wrapper for qemu-system-ppc64

5 years agoempty slapd-ftmg.conf
Peter Palfrader [Thu, 24 Jan 2019 12:36:36 +0000 (13:36 +0100)]
empty slapd-ftmg.conf

5 years agoslapd: listen on localhost only
Peter Palfrader [Thu, 24 Jan 2019 12:35:21 +0000 (13:35 +0100)]
slapd: listen on localhost only

5 years agoAdd default /etc/default/slapd
Peter Palfrader [Thu, 24 Jan 2019 12:34:09 +0000 (13:34 +0100)]
Add default /etc/default/slapd

5 years agotypo fix
Peter Palfrader [Thu, 24 Jan 2019 12:32:29 +0000 (13:32 +0100)]
typo fix

5 years agossl slapd: load hbd backend module, disable db and backend specific config
Peter Palfrader [Thu, 24 Jan 2019 12:30:55 +0000 (13:30 +0100)]
ssl slapd: load hbd backend module, disable db and backend specific config

5 years agodefault slapd.conf
Peter Palfrader [Thu, 24 Jan 2019 12:27:40 +0000 (13:27 +0100)]
default slapd.conf

5 years agosso: install slapd (re: RT#7454)
Peter Palfrader [Thu, 24 Jan 2019 12:19:29 +0000 (13:19 +0100)]
sso: install slapd (re: RT#7454)

5 years agoship ftmg.sso.debian.org key to sso host
Peter Palfrader [Thu, 24 Jan 2019 10:10:32 +0000 (11:10 +0100)]
ship ftmg.sso.debian.org key to sso host

5 years agoActually install apt https config
Julien Cristau [Wed, 23 Jan 2019 15:27:30 +0000 (16:27 +0100)]
Actually install apt https config

5 years agoTell apt to use cartel CAs for https mirrors
Julien Cristau [Wed, 23 Jan 2019 15:21:24 +0000 (16:21 +0100)]
Tell apt to use cartel CAs for https mirrors

5 years agoTry to support debootstrapping from https sources on debian.org infra
Peter Palfrader [Wed, 23 Jan 2019 12:47:42 +0000 (13:47 +0100)]
Try to support debootstrapping from https sources on debian.org infra

5 years agouse local mirrors less
Peter Palfrader [Wed, 23 Jan 2019 12:07:14 +0000 (13:07 +0100)]
use local mirrors less

5 years agoswitch default mirror to https://deb.debian.org/debian
Peter Palfrader [Wed, 23 Jan 2019 12:03:40 +0000 (13:03 +0100)]
switch default mirror to https://deb.debian.org/debian

5 years agoinstall ca-certificates in all chroots
Peter Palfrader [Wed, 23 Jan 2019 10:07:10 +0000 (11:07 +0100)]
install ca-certificates in all chroots

5 years agoinstall security (LTS) updates for jessie
Peter Palfrader [Wed, 23 Jan 2019 08:51:53 +0000 (09:51 +0100)]
install security (LTS) updates for jessie

5 years agouse https://deb.debian.org/debian as default mirror
Peter Palfrader [Wed, 23 Jan 2019 08:51:06 +0000 (09:51 +0100)]
use https://deb.debian.org/debian as default mirror

5 years agosetup-dchroot: do install of security and updates for ubuntu chroots earlier
Peter Palfrader [Wed, 23 Jan 2019 08:50:56 +0000 (09:50 +0100)]
setup-dchroot: do install of security and updates for ubuntu chroots earlier

5 years agoterminate case properly
Peter Palfrader [Wed, 23 Jan 2019 08:25:24 +0000 (09:25 +0100)]
terminate case properly

5 years agoInstall apt-transport-https during debootstrap
Peter Palfrader [Wed, 23 Jan 2019 08:22:53 +0000 (09:22 +0100)]
Install apt-transport-https during debootstrap

5 years ago99builddsourceslist: disable apt redirects in chroots
Aurelien Jarno [Tue, 22 Jan 2019 19:31:47 +0000 (20:31 +0100)]
99builddsourceslist: disable apt redirects in chroots

5 years agoRemove moszumanska-lvm and moszumanska from multipath config
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:54 +0000 (21:17 +0100)]
Remove moszumanska-lvm and moszumanska from multipath config

5 years agoAvoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:37 +0000 (21:17 +0100)]
Avoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd

5 years agoEnable SSILegacyExprParser on www.debconf.org
Julien Cristau [Thu, 17 Jan 2019 15:46:37 +0000 (16:46 +0100)]
Enable SSILegacyExprParser on www.debconf.org

The site would need updates for the new syntax

5 years agowww.debconf.org vhost update
Julien Cristau [Thu, 17 Jan 2019 15:37:04 +0000 (16:37 +0100)]
www.debconf.org vhost update

Add missing redirects from current config on kent.debconf.org

5 years agoAdd www.debconf.org vhost for real
Julien Cristau [Thu, 17 Jan 2019 15:26:08 +0000 (16:26 +0100)]
Add www.debconf.org vhost for real

5 years agoAdd www.debconf.org vhost on static
Julien Cristau [Thu, 17 Jan 2019 15:04:07 +0000 (16:04 +0100)]
Add www.debconf.org vhost on static

5 years agoAdd www.debconf.org static component
Julien Cristau [Thu, 17 Jan 2019 14:42:02 +0000 (15:42 +0100)]
Add www.debconf.org static component

5 years agoBump RLimitNPROC for bugs web hosts
Julien Cristau [Wed, 16 Jan 2019 07:08:07 +0000 (08:08 +0100)]
Bump RLimitNPROC for bugs web hosts

Bug#919316

5 years agoSet LogLevel VERBOSE in sshd
Peter Palfrader [Mon, 14 Jan 2019 09:40:02 +0000 (10:40 +0100)]
Set LogLevel VERBOSE in sshd

5 years agoAdd wiki.debconf.org static vhost (RT#7595)
Julien Cristau [Sun, 13 Jan 2019 22:51:35 +0000 (23:51 +0100)]
Add wiki.debconf.org static vhost (RT#7595)

5 years agodebconfstatic can update wiki.debconf.org
Julien Cristau [Sun, 13 Jan 2019 22:44:15 +0000 (23:44 +0100)]
debconfstatic can update wiki.debconf.org

5 years agoUpdate DMUP url in motd
Julien Cristau [Sun, 13 Jan 2019 22:42:05 +0000 (23:42 +0100)]
Update DMUP url in motd

5 years agoAdd wiki.debconf.org static component
Julien Cristau [Sun, 13 Jan 2019 22:35:21 +0000 (23:35 +0100)]
Add wiki.debconf.org static component

5 years agoFix sudoers syntax
Julien Cristau [Thu, 10 Jan 2019 21:20:21 +0000 (22:20 +0100)]
Fix sudoers syntax

5 years agosudo: add an extra entry for dsa-check-openmanage
Julien Cristau [Thu, 10 Jan 2019 21:08:20 +0000 (22:08 +0100)]
sudo: add an extra entry for dsa-check-openmanage

Add ability to ignore "Cache Battery 0 in controller 0 is Degraded
(Non-Critical) [probably harmless]" warning.

5 years agopostgres-make-base-backups.erb: fix limited info log
Peter Palfrader [Tue, 8 Jan 2019 13:49:08 +0000 (14:49 +0100)]
postgres-make-base-backups.erb: fix limited info log

5 years agoRT#7513 Get rid of most traces of moszumanska
Tollef Fog Heen [Mon, 7 Jan 2019 20:59:04 +0000 (21:59 +0100)]
RT#7513 Get rid of most traces of moszumanska

5 years agoAdd an adm key for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 19:39:06 +0000 (20:39 +0100)]
Add an adm key for tfheen

5 years agoOpen up some IPs for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 18:47:11 +0000 (19:47 +0100)]
Open up some IPs for tfheen

5 years agoremove duplicate entry for sallinen in postgresql_server
Peter Palfrader [Wed, 2 Jan 2019 17:29:38 +0000 (18:29 +0100)]
remove duplicate entry for sallinen in postgresql_server

5 years agoRemove disfunct combined.njabl.org RBL from rbllist for all the roles that had it
Peter Palfrader [Wed, 2 Jan 2019 13:22:38 +0000 (14:22 +0100)]
Remove disfunct combined.njabl.org RBL from rbllist for all the roles that had it

5 years agodo not rate limit on the loopback interface
Peter Palfrader [Mon, 31 Dec 2018 09:02:27 +0000 (10:02 +0100)]
do not rate limit on the loopback interface

5 years agoalso close http connections after each request via haproxy
Peter Palfrader [Sun, 23 Dec 2018 09:33:01 +0000 (10:33 +0100)]
also close http connections after each request via haproxy

5 years agofor snapshot, disable keep-alive so we can rate-limit better
Peter Palfrader [Sun, 23 Dec 2018 09:25:19 +0000 (10:25 +0100)]
for snapshot, disable keep-alive so we can rate-limit better

5 years agoblacklist 198.11.128.0/18
Peter Palfrader [Sat, 22 Dec 2018 18:05:09 +0000 (19:05 +0100)]
blacklist 198.11.128.0/18

5 years agoActually drop drom 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 17:57:56 +0000 (18:57 +0100)]
Actually drop drom 208.91.68.213

5 years agoblacklist 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 15:43:30 +0000 (16:43 +0100)]
blacklist 208.91.68.213

5 years agoone ; too many
Peter Palfrader [Sat, 22 Dec 2018 15:35:53 +0000 (16:35 +0100)]
one ; too many

5 years agoport 6081 is redirected
Peter Palfrader [Sat, 22 Dec 2018 15:35:01 +0000 (16:35 +0100)]
port 6081 is redirected

5 years agosnapshot: try to put a bound on connections per client
Peter Palfrader [Sat, 22 Dec 2018 15:29:12 +0000 (16:29 +0100)]
snapshot: try to put a bound on connections per client

5 years agosnapshot: set QS_LocRequestLimitDefault if mod_qos is loaded
Peter Palfrader [Thu, 20 Dec 2018 11:37:04 +0000 (12:37 +0100)]
snapshot: set QS_LocRequestLimitDefault if mod_qos is loaded

5 years agoreload ferm on changes instead of restart
Peter Palfrader [Mon, 17 Dec 2018 09:19:44 +0000 (10:19 +0100)]
reload ferm on changes instead of restart

5 years agoMake a snapshot.debian.net vhost, 2
Peter Palfrader [Wed, 12 Dec 2018 13:05:22 +0000 (14:05 +0100)]
Make a snapshot.debian.net vhost, 2

5 years agoMake a snapshot.debian.net vhost
Peter Palfrader [Wed, 12 Dec 2018 13:03:15 +0000 (14:03 +0100)]
Make a snapshot.debian.net vhost

5 years agoDrop references to long-gone db.d.o repos
Julien Cristau [Wed, 28 Nov 2018 10:37:13 +0000 (11:37 +0100)]
Drop references to long-gone db.d.o repos

5 years agoUse https for *-restricted db.d.o repo too
Julien Cristau [Wed, 28 Nov 2018 10:36:28 +0000 (11:36 +0100)]
Use https for *-restricted db.d.o repo too

5 years agoUse https to access the db.d.o repo
Julien Cristau [Wed, 28 Nov 2018 10:30:56 +0000 (11:30 +0100)]
Use https to access the db.d.o repo

5 years agoFixup db.d.o archive key for apt consumption, it shouldn't be armored
Julien Cristau [Wed, 28 Nov 2018 09:38:30 +0000 (10:38 +0100)]
Fixup db.d.o archive key for apt consumption, it shouldn't be armored

5 years agoExtend lifetime of db.d.o archive key by a year
Julien Cristau [Wed, 28 Nov 2018 08:51:14 +0000 (09:51 +0100)]
Extend lifetime of db.d.o archive key by a year

5 years agoDelete old logs on hosts using pybuildd
Julien Cristau [Wed, 28 Nov 2018 08:33:53 +0000 (09:33 +0100)]
Delete old logs on hosts using pybuildd

pybuildd keeps them indefinitely
(https://salsa.debian.org/wb-team/pybuildd/issues/11) so clean up ourselves to
avoid running into ENOSPC.

5 years agoDon't try to install obsolete postgresql client packages
Julien Cristau [Fri, 23 Nov 2018 09:37:04 +0000 (10:37 +0100)]
Don't try to install obsolete postgresql client packages

5 years agopostfix fail2ban -- ban quicker and longer
Peter Palfrader [Thu, 22 Nov 2018 13:30:23 +0000 (14:30 +0100)]
postfix fail2ban -- ban quicker and longer

5 years agoRemove old stuff from obsolete package ignore list
Julien Cristau [Thu, 22 Nov 2018 09:47:45 +0000 (10:47 +0100)]
Remove old stuff from obsolete package ignore list

- storace/backuphost don't need old pg anymore
- rainier/rapoport use stable rabbitmq-server
- conova-node* are on stretch

5 years agolvm ganeti.manda.debian.org: set global_filter
Peter Palfrader [Wed, 21 Nov 2018 09:27:38 +0000 (10:27 +0100)]
lvm ganeti.manda.debian.org: set global_filter

5 years agoUpdate rabbitmq module
Julien Cristau [Tue, 20 Nov 2018 22:08:19 +0000 (23:08 +0100)]
Update rabbitmq module

5 years agoAdd puppet/archive module, required for newer puppet/rabbitmq
Julien Cristau [Tue, 20 Nov 2018 22:07:26 +0000 (23:07 +0100)]
Add puppet/archive module, required for newer puppet/rabbitmq

5 years agoRevert "Update 3rdparty rabbitmq module"
Julien Cristau [Tue, 20 Nov 2018 20:49:05 +0000 (21:49 +0100)]
Revert "Update 3rdparty rabbitmq module"

This reverts commit 921e69100a563cf143f56a3905d8362336d939ff.

5 years agoRevert "Add systemd module, required by rabbitmq"
Julien Cristau [Tue, 20 Nov 2018 20:49:03 +0000 (21:49 +0100)]
Revert "Add systemd module, required by rabbitmq"

This reverts commit 1329adc9f34c3c87e353983ec9023a6cf6e93e67.

5 years agoRevert "Add puppet/archive module"
Julien Cristau [Tue, 20 Nov 2018 20:48:56 +0000 (21:48 +0100)]
Revert "Add puppet/archive module"

This reverts commit ce70d6baf887ae03a2a6a7f5e73eb2e2c3dea208.

5 years agoAdd puppet/archive module
Julien Cristau [Tue, 20 Nov 2018 20:33:49 +0000 (21:33 +0100)]
Add puppet/archive module

Required by puppet/rabbitmq

5 years agoRename our systemd module to dsa_systemd
Julien Cristau [Tue, 20 Nov 2018 20:28:40 +0000 (21:28 +0100)]
Rename our systemd module to dsa_systemd

Avoid conflict with 3rdparty.

5 years agoAdd systemd module, required by rabbitmq
Julien Cristau [Tue, 20 Nov 2018 20:09:44 +0000 (21:09 +0100)]
Add systemd module, required by rabbitmq

5 years agopubsub: manage_repos -> repos_ensure
Julien Cristau [Tue, 20 Nov 2018 20:02:31 +0000 (21:02 +0100)]
pubsub: manage_repos -> repos_ensure

5 years agoUpdate 3rdparty rabbitmq module
Julien Cristau [Tue, 20 Nov 2018 19:57:58 +0000 (20:57 +0100)]
Update 3rdparty rabbitmq module

5 years agosetup-dchroot: Request unmerged /usr
Simon McVittie [Tue, 20 Nov 2018 16:18:50 +0000 (16:18 +0000)]
setup-dchroot: Request unmerged /usr

Merged /usr is known to cause multiple packages to be misbuilt. As long
as we support unmerged /usr for user systems, we should mitigate
this class of bugs by using unmerged-/usr chroots on official buildds,
resulting in binary packages that work equally well on merged- or
unmerged-/usr user systems.

See:

https://bugs.debian.org/913229
https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=md@linux.it&tag=usrmerge
thread at https://lists.debian.org/debian-devel/2018/11/msg00299.html

Signed-off-by: Simon McVittie <smcv@debian.org>
Signed-off-by: Julien Cristau <jcristau@debian.org>
5 years agoAdd pijper
Julien Cristau [Mon, 19 Nov 2018 16:57:28 +0000 (17:57 +0100)]
Add pijper

5 years agoDon't install megacli if we're not amd64
Julien Cristau [Mon, 19 Nov 2018 16:47:12 +0000 (17:47 +0100)]
Don't install megacli if we're not amd64

5 years agomanda-node03, manda-node04: lvm: issue discards
Peter Palfrader [Mon, 19 Nov 2018 12:38:15 +0000 (13:38 +0100)]
manda-node03, manda-node04: lvm: issue discards

5 years agomanda-node03, manda-node04: lvm: set a device filter
Peter Palfrader [Mon, 19 Nov 2018 12:35:09 +0000 (13:35 +0100)]
manda-node03, manda-node04: lvm: set a device filter

5 years agoadd default lvm conf for new manda hosts
Peter Palfrader [Mon, 19 Nov 2018 12:33:15 +0000 (13:33 +0100)]
add default lvm conf for new manda hosts

5 years agorename lvm-manda-ganeti.conf -> lvm-manda-ganeti3.conf
Peter Palfrader [Mon, 19 Nov 2018 12:30:02 +0000 (13:30 +0100)]
rename lvm-manda-ganeti.conf -> lvm-manda-ganeti3.conf

5 years agotry to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 19:13:48 +0000 (20:13 +0100)]
try to sort pin files

5 years agoRevert "try to sort pin files"
Peter Palfrader [Sun, 18 Nov 2018 19:03:18 +0000 (20:03 +0100)]
Revert "try to sort pin files"

This reverts commit 839c8ea25d94aa887d71e46d150509ff4c339fac.

5 years agotry to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 19:01:37 +0000 (20:01 +0100)]
try to sort pin files

5 years agoTry ganeti address definitions for new manda cluster
Peter Palfrader [Sun, 18 Nov 2018 09:51:28 +0000 (10:51 +0100)]
Try ganeti address definitions for new manda cluster

5 years agoUse ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganet...
Peter Palfrader [Sun, 18 Nov 2018 09:50:11 +0000 (10:50 +0100)]
Use ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganeti module

5 years agoAlso restrict "ganeti/kvm host" purpose
Peter Palfrader [Sun, 18 Nov 2018 09:47:57 +0000 (10:47 +0100)]
Also restrict "ganeti/kvm host" purpose

5 years agoTry to not limit ganeti firewall rules to v4
Peter Palfrader [Sun, 18 Nov 2018 09:25:51 +0000 (10:25 +0100)]
Try to not limit ganeti firewall rules to v4