mirror/dsa-puppet.git
8 years agoCommit local changes to fileserver.conf
Peter Palfrader [Sun, 7 Feb 2016 09:52:05 +0000 (09:52 +0000)]
Commit local changes to fileserver.conf

8 years agofix whitespace
Peter Palfrader [Sat, 6 Feb 2016 20:26:53 +0000 (21:26 +0100)]
fix whitespace

8 years agoShip ssl certs for i18n and l10n.d.o
Peter Palfrader [Sat, 6 Feb 2016 20:11:04 +0000 (21:11 +0100)]
Ship ssl certs for i18n and l10n.d.o

8 years agoremove www-master rsync
Peter Palfrader [Sat, 6 Feb 2016 16:46:32 +0000 (17:46 +0100)]
remove www-master rsync

8 years agoMake backups of santoro
Peter Palfrader [Sat, 6 Feb 2016 16:46:10 +0000 (17:46 +0100)]
Make backups of santoro

8 years agouninstall static service certs and keys from hosts that do not serve this service
Peter Palfrader [Sat, 6 Feb 2016 15:53:12 +0000 (15:53 +0000)]
uninstall static service certs and keys from hosts that do not serve this service

8 years agostatic: only install apache::site instances relevant for this mirror
Peter Palfrader [Sat, 6 Feb 2016 15:38:31 +0000 (16:38 +0100)]
static: only install apache::site instances relevant for this mirror

8 years agostatic: only install ssl::service instances relevant for this mirror
Peter Palfrader [Sat, 6 Feb 2016 15:32:16 +0000 (16:32 +0100)]
static: only install ssl::service instances relevant for this mirror

8 years agosantoro no longer is an old-style www mirror
Peter Palfrader [Sat, 6 Feb 2016 15:09:38 +0000 (16:09 +0100)]
santoro no longer is an old-style www mirror

8 years agosantoro to staticsync (for www)
Peter Palfrader [Sat, 6 Feb 2016 15:01:58 +0000 (16:01 +0100)]
santoro to staticsync (for www)

8 years agosort entries in hieradata
Peter Palfrader [Sat, 6 Feb 2016 15:01:28 +0000 (16:01 +0100)]
sort entries in hieradata

8 years agomove some of www.d.o's redirects to https
Julien Cristau [Fri, 5 Feb 2016 17:40:08 +0000 (18:40 +0100)]
move some of www.d.o's redirects to https

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agoswitch search.d.o to letsencrypt
Julien Cristau [Fri, 5 Feb 2016 17:16:22 +0000 (18:16 +0100)]
switch search.d.o to letsencrypt

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agoremove tlsa for search.debian.org
Julien Cristau [Fri, 5 Feb 2016 15:52:50 +0000 (16:52 +0100)]
remove tlsa for search.debian.org

Let's try to rotate keys without breaking stuff

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agoTry different FileSet config
Peter Palfrader [Thu, 4 Feb 2016 09:16:58 +0000 (10:16 +0100)]
Try different FileSet config

8 years agobacula: try ignoring /swapfile* instead of just /swapfile. Also set Ignore FileSet...
Peter Palfrader [Thu, 4 Feb 2016 09:04:58 +0000 (10:04 +0100)]
bacula: try ignoring /swapfile* instead of just /swapfile.  Also set Ignore FileSet Changes to avoid a full backup run everywhere.  And set Accurate = yes and enable acl and xattr support

8 years agoAdd certs for www-master and cgi.d.o
Peter Palfrader [Thu, 4 Feb 2016 08:00:39 +0000 (09:00 +0100)]
Add certs for www-master and cgi.d.o

8 years agoAdd planet-search key too
Peter Palfrader [Tue, 2 Feb 2016 21:19:19 +0000 (22:19 +0100)]
Add planet-search key too

8 years agoAdd planet-search role and cert
Peter Palfrader [Tue, 2 Feb 2016 21:13:04 +0000 (22:13 +0100)]
Add planet-search role and cert

8 years agossl for {10years,es,fr,miniconf10}.debconf.org
Peter Palfrader [Tue, 2 Feb 2016 17:34:23 +0000 (18:34 +0100)]
ssl for {10years,es,fr,miniconf10}.debconf.org

8 years agoclean out some buildd.debian-ports.org/portman stuff
Peter Palfrader [Tue, 2 Feb 2016 10:07:56 +0000 (11:07 +0100)]
clean out some buildd.debian-ports.org/portman stuff

8 years agossl for {news,debaday,timeline}.debian.net, debconf[4567].debconf.org
Peter Palfrader [Tue, 2 Feb 2016 07:59:53 +0000 (08:59 +0100)]
ssl for {news,debaday,timeline}.debian.net, debconf[4567].debconf.org

8 years agoAdd default SSL site
Peter Palfrader [Tue, 2 Feb 2016 06:46:50 +0000 (07:46 +0100)]
Add default SSL site

8 years agoThere is no spohr.debian.org anymore
Peter Palfrader [Tue, 2 Feb 2016 06:46:10 +0000 (07:46 +0100)]
There is no spohr.debian.org anymore

8 years agorsync ssl on ftp-master
Peter Palfrader [Mon, 1 Feb 2016 21:34:34 +0000 (22:34 +0100)]
rsync ssl on ftp-master

8 years agoMove rsync ssl setup into the rsync module
Peter Palfrader [Mon, 1 Feb 2016 21:31:42 +0000 (21:31 +0000)]
Move rsync ssl setup into the rsync module

8 years agoAdd "DST Root CA X3" to ca-debian
Julien Cristau [Mon, 1 Feb 2016 19:49:30 +0000 (20:49 +0100)]
Add "DST Root CA X3" to ca-debian

It signed Let's Encrypt's CA.

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agoAnd redirect .net to .org
Peter Palfrader [Mon, 1 Feb 2016 19:04:23 +0000 (20:04 +0100)]
And redirect .net to .org

8 years agoRevert "Set WSGIScriptReloading On"
Peter Palfrader [Mon, 1 Feb 2016 18:58:45 +0000 (19:58 +0100)]
Revert "Set WSGIScriptReloading On"

This reverts commit 73898a88dbf0245dc94c3f8decac8ccbb7546391.

8 years agoSet WSGIScriptReloading On
Peter Palfrader [Mon, 1 Feb 2016 18:57:37 +0000 (19:57 +0100)]
Set WSGIScriptReloading On

8 years agoUpdate debtags.d.o vhost
Peter Palfrader [Mon, 1 Feb 2016 18:23:08 +0000 (19:23 +0100)]
Update debtags.d.o vhost

8 years agogive tate access to the pg on bmdb1
Peter Palfrader [Mon, 1 Feb 2016 18:06:02 +0000 (19:06 +0100)]
give tate access to the pg on bmdb1

8 years agodsa-rsync-ssl ferm on v6 also
Peter Palfrader [Mon, 1 Feb 2016 08:19:46 +0000 (09:19 +0100)]
dsa-rsync-ssl ferm on v6 also

8 years agodsa rsync ssl ferm
Peter Palfrader [Sun, 31 Jan 2016 21:58:13 +0000 (22:58 +0100)]
dsa rsync ssl ferm

8 years agoadd template
Peter Palfrader [Sun, 31 Jan 2016 21:56:49 +0000 (22:56 +0100)]
add template

8 years agorsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:56:26 +0000 (22:56 +0100)]
rsync ssl service, more

8 years agorsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:54:49 +0000 (22:54 +0100)]
rsync ssl service, more

8 years agorsync ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 21:52:15 +0000 (22:52 +0100)]
rsync ssl on syncproxies

8 years agofermport for xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 21:47:15 +0000 (22:47 +0100)]
fermport for xinetd::service

8 years agotypo
Peter Palfrader [Sun, 31 Jan 2016 21:41:22 +0000 (22:41 +0100)]
typo

8 years agoone place missed
Peter Palfrader [Sun, 31 Jan 2016 21:40:20 +0000 (22:40 +0100)]
one place missed

8 years agosplit service and port in xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 21:38:53 +0000 (22:38 +0100)]
split service and port in xinetd::service

8 years agotry it as a class
Peter Palfrader [Sun, 31 Jan 2016 19:12:10 +0000 (20:12 +0100)]
try it as a class

8 years agoCannot re-declare ssl
Peter Palfrader [Sun, 31 Jan 2016 19:10:29 +0000 (20:10 +0100)]
Cannot re-declare ssl

8 years agoenable ssl
Peter Palfrader [Sun, 31 Jan 2016 19:09:51 +0000 (20:09 +0100)]
enable ssl

8 years agotry ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 19:05:08 +0000 (20:05 +0100)]
try ssl on syncproxies

8 years agossl for debconf[23]
Peter Palfrader [Sun, 31 Jan 2016 17:58:06 +0000 (17:58 +0000)]
ssl for debconf[23]

8 years agoremove useless block
Peter Palfrader [Sun, 31 Jan 2016 17:48:02 +0000 (18:48 +0100)]
remove useless block

8 years agossl for debconf[01]
Peter Palfrader [Sun, 31 Jan 2016 17:45:26 +0000 (18:45 +0100)]
ssl for debconf[01]

8 years agoAdd tate to sso-rp
Peter Palfrader [Sun, 31 Jan 2016 17:22:19 +0000 (17:22 +0000)]
Add tate to sso-rp

8 years agoship debtags key
Peter Palfrader [Sun, 31 Jan 2016 17:21:45 +0000 (17:21 +0000)]
ship debtags key

8 years agofix paths
Peter Palfrader [Sun, 31 Jan 2016 17:16:02 +0000 (18:16 +0100)]
fix paths

8 years agoAdd debtags role
Peter Palfrader [Sun, 31 Jan 2016 17:13:39 +0000 (18:13 +0100)]
Add debtags role

8 years agofix TLSA records with multiple cert locations
Peter Palfrader [Sun, 31 Jan 2016 17:06:50 +0000 (17:06 +0000)]
fix TLSA records with multiple cert locations

8 years agoAppend chain if exists
Peter Palfrader [Sun, 31 Jan 2016 17:02:36 +0000 (17:02 +0000)]
Append chain if exists

8 years agoAppend chain if exists
Peter Palfrader [Sun, 31 Jan 2016 17:01:53 +0000 (17:01 +0000)]
Append chain if exists

8 years agohandle array of certfiles
Peter Palfrader [Sun, 31 Jan 2016 16:57:55 +0000 (17:57 +0100)]
handle array of certfiles

8 years agoGet certs from the LE dir also
Peter Palfrader [Sun, 31 Jan 2016 16:54:23 +0000 (17:54 +0100)]
Get certs from the LE dir also

8 years agoAdd tate
Peter Palfrader [Sun, 31 Jan 2016 16:20:28 +0000 (17:20 +0100)]
Add tate

8 years agoAdd tate
Peter Palfrader [Sun, 31 Jan 2016 15:56:09 +0000 (16:56 +0100)]
Add tate

8 years agoletsencrypt can trigger zone file update
Peter Palfrader [Sun, 31 Jan 2016 14:02:20 +0000 (15:02 +0100)]
letsencrypt can trigger zone file update

8 years agoretire unused rsync modules on ftp-master
Peter Palfrader [Tue, 26 Jan 2016 14:38:13 +0000 (15:38 +0100)]
retire unused rsync modules on ftp-master

8 years agoRedirects /doc/manuals/ to /doc/
Iain R. Learmonth [Sun, 24 Jan 2016 16:15:34 +0000 (16:15 +0000)]
Redirects /doc/manuals/ to /doc/

The /doc/manuals/ folder contains manuals that are built as part of the
webwml process, but does not contain an index file. /doc/ is the logical
index file for this, so redirect to that to avoid just providing an
Apache index listing. (Fixes: #694927)

Signed-off-by: Peter Palfrader <peter@palfrader.org>
8 years agofix ipv6 netrange for anu
Julien Cristau [Sun, 24 Jan 2016 16:09:01 +0000 (17:09 +0100)]
fix ipv6 netrange for anu

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agolocal mirror for .au servers
Peter Palfrader [Sat, 23 Jan 2016 17:51:53 +0000 (18:51 +0100)]
local mirror for .au servers

8 years agobytemark has debian-debug
Peter Palfrader [Fri, 22 Jan 2016 20:01:44 +0000 (21:01 +0100)]
bytemark has debian-debug

8 years agohttp-redir role with apache config
Peter Palfrader [Sun, 17 Jan 2016 20:58:58 +0000 (21:58 +0100)]
http-redir role with apache config

8 years agop-u for kfreebsd
Peter Palfrader [Sun, 17 Jan 2016 18:54:36 +0000 (19:54 +0100)]
p-u for kfreebsd

8 years agolvm.conf for clementi and czerny
Julien Cristau [Sun, 17 Jan 2016 15:42:23 +0000 (16:42 +0100)]
lvm.conf for clementi and czerny

Signed-off-by: Julien Cristau <jcristau@debian.org>
8 years agobuildds: force SHA512 signatures
Aurelien Jarno [Sat, 16 Jan 2016 17:25:48 +0000 (18:25 +0100)]
buildds: force SHA512 signatures

Provide a ~/.gnupg/gpg.conf on the buildds to force SHA512 signatures.
Otherwise gpg still uses to SHA1 by default...

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agognt on -14
Peter Palfrader [Sat, 16 Jan 2016 15:43:00 +0000 (16:43 +0100)]
gnt on -14

8 years agoblades update bm
Peter Palfrader [Fri, 15 Jan 2016 20:04:34 +0000 (21:04 +0100)]
blades update bm

8 years agoAdd bmdb1-lvm2 and dillon-lvm2 wwids
Peter Palfrader [Wed, 13 Jan 2016 09:28:47 +0000 (10:28 +0100)]
Add bmdb1-lvm2 and dillon-lvm2 wwids

8 years agoFix path name (etc/rsyncd instead of /etc/rsync)
Peter Palfrader [Tue, 12 Jan 2016 08:23:46 +0000 (09:23 +0100)]
Fix path name (etc/rsyncd instead of /etc/rsync)

8 years agoDo push -anu on static updates
Peter Palfrader [Tue, 12 Jan 2016 08:14:23 +0000 (09:14 +0100)]
Do push -anu on static updates

8 years ago-anu static address
Peter Palfrader [Tue, 12 Jan 2016 08:14:06 +0000 (09:14 +0100)]
-anu static address

8 years agoenable -anu security addresses
Peter Palfrader [Tue, 12 Jan 2016 08:07:18 +0000 (09:07 +0100)]
enable -anu security addresses

8 years agosamhain ignore: /etc/rsyncd/debian.secrets is handled by the mirror team
Peter Palfrader [Mon, 11 Jan 2016 17:28:34 +0000 (18:28 +0100)]
samhain ignore: /etc/rsyncd/debian.secrets is handled by the mirror team

8 years agofix syncproxy manifest site name
Peter Palfrader [Mon, 11 Jan 2016 11:54:31 +0000 (11:54 +0000)]
fix syncproxy manifest site name

8 years agohave security rsync bind to specific address
Peter Palfrader [Mon, 11 Jan 2016 11:51:31 +0000 (12:51 +0100)]
have security rsync bind to specific address

8 years agoAdd IP addresses for mirror-anu in its role as syncproxy.au
Peter Palfrader [Mon, 11 Jan 2016 11:46:02 +0000 (12:46 +0100)]
Add IP addresses for mirror-anu in its role as syncproxy.au

8 years agoGive d-i folks access to rebuild the d-i website
Paul Wise [Sun, 10 Jan 2016 22:15:00 +0000 (06:15 +0800)]
Give d-i folks access to rebuild the d-i website

8 years agorng-tools: yet another try to fix it
Aurelien Jarno [Sat, 9 Jan 2016 15:04:20 +0000 (16:04 +0100)]
rng-tools: yet another try to fix it

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agorng-tools: another try to fix it
Aurelien Jarno [Sat, 9 Jan 2016 14:19:49 +0000 (15:19 +0100)]
rng-tools: another try to fix it

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoEnable rng-tools module on linux
Aurelien Jarno [Sat, 9 Jan 2016 14:02:58 +0000 (15:02 +0100)]
Enable rng-tools module on linux

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoInstall rng-tools if there is a /dev/hwrng device
Aurelien Jarno [Sat, 9 Jan 2016 13:22:08 +0000 (14:22 +0100)]
Install rng-tools if there is a /dev/hwrng device

We can then provide entropy to the guests using virtio-rng.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoMake an apache site for syncproxies
Peter Palfrader [Fri, 8 Jan 2016 21:12:57 +0000 (21:12 +0000)]
Make an apache site for syncproxies

8 years agouse https in our default index page
Peter Palfrader [Fri, 8 Jan 2016 21:12:35 +0000 (21:12 +0000)]
use https in our default index page

8 years agovars need a $
Peter Palfrader [Fri, 8 Jan 2016 20:35:26 +0000 (21:35 +0100)]
vars need a $

8 years agomove bind addresses to vars
Peter Palfrader [Fri, 8 Jan 2016 20:34:01 +0000 (21:34 +0100)]
move bind addresses to vars

8 years agoklecker gets dsa-rsync from being a syncproxy
Peter Palfrader [Fri, 8 Jan 2016 20:30:31 +0000 (21:30 +0100)]
klecker gets dsa-rsync from being a syncproxy

8 years agoAdd klecker to the syncproxy role
Peter Palfrader [Fri, 8 Jan 2016 20:29:17 +0000 (21:29 +0100)]
Add klecker to the syncproxy role

8 years agoremove schein from security-mirror group
Peter Palfrader [Fri, 8 Jan 2016 08:35:54 +0000 (09:35 +0100)]
remove schein from security-mirror group

8 years agodebian.c3sl.ufpr.br is actually ftp.br.debian.org
Aurelien Jarno [Thu, 7 Jan 2016 15:41:12 +0000 (16:41 +0100)]
debian.c3sl.ufpr.br is actually ftp.br.debian.org

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoupdate unicamp netrange
Aurelien Jarno [Thu, 7 Jan 2016 15:37:15 +0000 (16:37 +0100)]
update unicamp netrange

In addition, use the whole range allocated to unicamp instead of the
debian range to cope with (fortunately unlikely) future IP changes.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoGet rid of buildd-{lenny,squeeze,wheezy} shares on security-master rsync
Peter Palfrader [Wed, 6 Jan 2016 21:32:26 +0000 (22:32 +0100)]
Get rid of buildd-{lenny,squeeze,wheezy} shares on security-master rsync

8 years agolog rsync for syncproxy and security to dedicated logs
Peter Palfrader [Wed, 6 Jan 2016 21:31:36 +0000 (22:31 +0100)]
log rsync for syncproxy and security to dedicated logs

8 years agoNo SRV support in jessie apt
Peter Palfrader [Wed, 6 Jan 2016 12:28:43 +0000 (13:28 +0100)]
No SRV support in jessie apt

8 years agoUse deb.debian.org as the default mirror to test it
Peter Palfrader [Wed, 6 Jan 2016 12:27:30 +0000 (13:27 +0100)]
Use deb.debian.org as the default mirror to test it

8 years agomirror.nl.leaseweb.nl is out of date
Peter Palfrader [Wed, 6 Jan 2016 12:26:46 +0000 (13:26 +0100)]
mirror.nl.leaseweb.nl is out of date