mirror/dsa-puppet.git
5 years agoAdd the certregen::client class to all nodes
Aurelien Jarno [Sat, 30 Mar 2019 12:16:04 +0000 (13:16 +0100)]
Add the certregen::client class to all nodes

5 years agoAdd puppetlabs/certregen module
Aurelien Jarno [Sat, 30 Mar 2019 12:13:17 +0000 (13:13 +0100)]
Add puppetlabs/certregen module

5 years agoAdd trabaci
Aurelien Jarno [Sat, 23 Mar 2019 12:43:58 +0000 (13:43 +0100)]
Add trabaci

5 years agoAdd trabaci volumes
Aurelien Jarno [Sat, 23 Mar 2019 11:58:40 +0000 (12:58 +0100)]
Add trabaci volumes

5 years agoMove more hiera stuff from mirror-conova to schmelzer
Julien Cristau [Mon, 18 Mar 2019 15:16:40 +0000 (16:16 +0100)]
Move more hiera stuff from mirror-conova to schmelzer

5 years agoFix typo that caused missing debug mirror on schmelzer
Julien Cristau [Mon, 18 Mar 2019 15:14:11 +0000 (16:14 +0100)]
Fix typo that caused missing debug mirror on schmelzer

Also add the right parameters.

5 years agoschmelzer has /srv/mirrors/public-debian, use it
Julien Cristau [Mon, 18 Mar 2019 14:51:31 +0000 (15:51 +0100)]
schmelzer has /srv/mirrors/public-debian, use it

Helps keep things in sync with other mirrors that are its downstreams.

5 years agoganeti: add ganeti2-osuosl ip range
Julien Cristau [Sun, 17 Mar 2019 18:12:25 +0000 (19:12 +0100)]
ganeti: add ganeti2-osuosl ip range

No dedicated private network for now, just trying things out.

5 years agoFix rsync setup on schmelzer
Julien Cristau [Sun, 17 Mar 2019 16:01:39 +0000 (17:01 +0100)]
Fix rsync setup on schmelzer

5 years agoDecommission lully.d.o
Aurelien Jarno [Sun, 17 Mar 2019 12:36:15 +0000 (13:36 +0100)]
Decommission lully.d.o

Replaced by loghost-osuosl-01

5 years agoblacklist 211.13.205.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:20:07 +0000 (11:20 +0100)]
blacklist 211.13.205.0/24

5 years agoblacklist 84.204.194.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:19:35 +0000 (11:19 +0100)]
blacklist 84.204.194.0/24

5 years agosyslog: fix longstanding hostname typo
Julien Cristau [Fri, 15 Mar 2019 10:14:37 +0000 (11:14 +0100)]
syslog: fix longstanding hostname typo

Looks like this has been around since d6761ce0180c2b4ac9f90e744fa34416ee68ae48
in 2013.

5 years agoblacklist 159.226.95.0/24
Peter Palfrader [Fri, 15 Mar 2019 10:14:46 +0000 (11:14 +0100)]
blacklist 159.226.95.0/24

5 years agoAdd cron script to compress and clean up logs on syslog hosts
Julien Cristau [Thu, 14 Mar 2019 13:16:02 +0000 (14:16 +0100)]
Add cron script to compress and clean up logs on syslog hosts

5 years agoremove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home
Peter Palfrader [Mon, 11 Mar 2019 08:59:43 +0000 (09:59 +0100)]
remove duplicate /etc/ssh/userkeys/dak, add srv/ftp.../home

5 years agoAdd lw08 to the snapshot_shell role and give ftp-master some infra there
Peter Palfrader [Mon, 11 Mar 2019 08:56:03 +0000 (09:56 +0100)]
Add lw08 to the snapshot_shell role and give ftp-master some infra there

5 years agoStop making nsswitch executable
Peter Palfrader [Sat, 9 Mar 2019 10:37:25 +0000 (11:37 +0100)]
Stop making nsswitch executable

5 years agolvm setup for pieta
Aurelien Jarno [Fri, 8 Mar 2019 20:16:38 +0000 (21:16 +0100)]
lvm setup for pieta

5 years agomove incoming smtp to port 2025 on smit.d.o
Aurelien Jarno [Fri, 8 Mar 2019 18:18:39 +0000 (19:18 +0100)]
move incoming smtp to port 2025 on smit.d.o

5 years agoAdd smit
Aurelien Jarno [Thu, 7 Mar 2019 20:48:05 +0000 (21:48 +0100)]
Add smit

5 years agoAdd debconf.org cert
Julien Cristau [Tue, 5 Mar 2019 19:36:49 +0000 (20:36 +0100)]
Add debconf.org cert

5 years agoTake over debconf.org with a redirect to www
Julien Cristau [Tue, 5 Mar 2019 19:33:24 +0000 (20:33 +0100)]
Take over debconf.org with a redirect to www

5 years agoAdd schmelzer to a couple more things
Julien Cristau [Fri, 1 Mar 2019 13:33:15 +0000 (14:33 +0100)]
Add schmelzer to a couple more things

5 years agoFix mirror-health-security by skipping the security to security-cdn redirect
Julien Cristau [Fri, 1 Mar 2019 13:25:05 +0000 (14:25 +0100)]
Fix mirror-health-security by skipping the security to security-cdn redirect

5 years agoadd some roles to schmelzer
Julien Cristau [Thu, 28 Feb 2019 13:12:34 +0000 (14:12 +0100)]
add some roles to schmelzer

5 years agomirror-umn console is on COM2
Julien Cristau [Thu, 21 Feb 2019 12:04:48 +0000 (13:04 +0100)]
mirror-umn console is on COM2

5 years agoAdd conova ip range
Julien Cristau [Wed, 20 Feb 2019 15:41:49 +0000 (16:41 +0100)]
Add conova ip range

5 years agoAdd schmelzer
Julien Cristau [Wed, 20 Feb 2019 15:37:11 +0000 (16:37 +0100)]
Add schmelzer

5 years agoDecommission kantuser (RT#7583)
Julien Cristau [Sun, 17 Feb 2019 18:53:59 +0000 (19:53 +0100)]
Decommission kantuser (RT#7583)

5 years agoadd default lvm conf for pijper
Aurelien Jarno [Sun, 17 Feb 2019 06:33:27 +0000 (07:33 +0100)]
add default lvm conf for pijper

5 years agocvs.d.o is gone, drop redirect
Tollef Fog Heen [Sat, 16 Feb 2019 21:07:49 +0000 (22:07 +0100)]
cvs.d.o is gone, drop redirect

5 years agoadd mekeel-srv (RT#7226)
Julien Cristau [Sat, 16 Feb 2019 17:04:31 +0000 (18:04 +0100)]
add mekeel-srv (RT#7226)

5 years agosyslog-ng: define fastly destination on all log hosts, not just lully
Julien Cristau [Fri, 8 Feb 2019 07:57:34 +0000 (08:57 +0100)]
syslog-ng: define fastly destination on all log hosts, not just lully

5 years agoRevert "99builddsourceslist: disable apt redirects in chroots"
Aurelien Jarno [Mon, 4 Feb 2019 21:00:07 +0000 (22:00 +0100)]
Revert "99builddsourceslist: disable apt redirects in chroots"

This reverts commit 840177adeb15e1a9f23cff136708eb60a10cd3a7.

All the chroots now have an updated apt.

5 years agoFix KVM detection for rng-tools
Aurelien Jarno [Sun, 3 Feb 2019 09:59:39 +0000 (10:59 +0100)]
Fix KVM detection for rng-tools

5 years agoDo not setup grub/kernel serial console on ppc64el VMs
Aurelien Jarno [Sun, 3 Feb 2019 00:22:02 +0000 (01:22 +0100)]
Do not setup grub/kernel serial console on ppc64el VMs

On ppc64el VMs, grub and the kernel automatically switch to the serial
console if there is no video card. OTOH the serial console is not called
ttyS0, so it's better to not try to setup it up manually.

5 years agoganeti2: remove qemu-system-ppc64 wrapper
Aurelien Jarno [Sun, 3 Feb 2019 00:09:55 +0000 (01:09 +0100)]
ganeti2: remove qemu-system-ppc64 wrapper

The wrapper ended-up simpler than on arm64, therefore kvm_extra can be
used instead.

5 years agoadd loghost-osuosl-01
Julien Cristau [Mon, 28 Jan 2019 21:43:43 +0000 (22:43 +0100)]
add loghost-osuosl-01

5 years agoganeti2: add wrapper for qemu-system-ppc64
Julien Cristau [Sun, 27 Jan 2019 15:00:27 +0000 (16:00 +0100)]
ganeti2: add wrapper for qemu-system-ppc64

5 years agoempty slapd-ftmg.conf
Peter Palfrader [Thu, 24 Jan 2019 12:36:36 +0000 (13:36 +0100)]
empty slapd-ftmg.conf

5 years agoslapd: listen on localhost only
Peter Palfrader [Thu, 24 Jan 2019 12:35:21 +0000 (13:35 +0100)]
slapd: listen on localhost only

5 years agoAdd default /etc/default/slapd
Peter Palfrader [Thu, 24 Jan 2019 12:34:09 +0000 (13:34 +0100)]
Add default /etc/default/slapd

5 years agotypo fix
Peter Palfrader [Thu, 24 Jan 2019 12:32:29 +0000 (13:32 +0100)]
typo fix

5 years agossl slapd: load hbd backend module, disable db and backend specific config
Peter Palfrader [Thu, 24 Jan 2019 12:30:55 +0000 (13:30 +0100)]
ssl slapd: load hbd backend module, disable db and backend specific config

5 years agodefault slapd.conf
Peter Palfrader [Thu, 24 Jan 2019 12:27:40 +0000 (13:27 +0100)]
default slapd.conf

5 years agosso: install slapd (re: RT#7454)
Peter Palfrader [Thu, 24 Jan 2019 12:19:29 +0000 (13:19 +0100)]
sso: install slapd (re: RT#7454)

5 years agoship ftmg.sso.debian.org key to sso host
Peter Palfrader [Thu, 24 Jan 2019 10:10:32 +0000 (11:10 +0100)]
ship ftmg.sso.debian.org key to sso host

5 years agoActually install apt https config
Julien Cristau [Wed, 23 Jan 2019 15:27:30 +0000 (16:27 +0100)]
Actually install apt https config

5 years agoTell apt to use cartel CAs for https mirrors
Julien Cristau [Wed, 23 Jan 2019 15:21:24 +0000 (16:21 +0100)]
Tell apt to use cartel CAs for https mirrors

5 years agoTry to support debootstrapping from https sources on debian.org infra
Peter Palfrader [Wed, 23 Jan 2019 12:47:42 +0000 (13:47 +0100)]
Try to support debootstrapping from https sources on debian.org infra

5 years agouse local mirrors less
Peter Palfrader [Wed, 23 Jan 2019 12:07:14 +0000 (13:07 +0100)]
use local mirrors less

5 years agoswitch default mirror to https://deb.debian.org/debian
Peter Palfrader [Wed, 23 Jan 2019 12:03:40 +0000 (13:03 +0100)]
switch default mirror to https://deb.debian.org/debian

5 years agoinstall ca-certificates in all chroots
Peter Palfrader [Wed, 23 Jan 2019 10:07:10 +0000 (11:07 +0100)]
install ca-certificates in all chroots

5 years agoinstall security (LTS) updates for jessie
Peter Palfrader [Wed, 23 Jan 2019 08:51:53 +0000 (09:51 +0100)]
install security (LTS) updates for jessie

5 years agouse https://deb.debian.org/debian as default mirror
Peter Palfrader [Wed, 23 Jan 2019 08:51:06 +0000 (09:51 +0100)]
use https://deb.debian.org/debian as default mirror

5 years agosetup-dchroot: do install of security and updates for ubuntu chroots earlier
Peter Palfrader [Wed, 23 Jan 2019 08:50:56 +0000 (09:50 +0100)]
setup-dchroot: do install of security and updates for ubuntu chroots earlier

5 years agoterminate case properly
Peter Palfrader [Wed, 23 Jan 2019 08:25:24 +0000 (09:25 +0100)]
terminate case properly

5 years agoInstall apt-transport-https during debootstrap
Peter Palfrader [Wed, 23 Jan 2019 08:22:53 +0000 (09:22 +0100)]
Install apt-transport-https during debootstrap

5 years ago99builddsourceslist: disable apt redirects in chroots
Aurelien Jarno [Tue, 22 Jan 2019 19:31:47 +0000 (20:31 +0100)]
99builddsourceslist: disable apt redirects in chroots

5 years agoRemove moszumanska-lvm and moszumanska from multipath config
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:54 +0000 (21:17 +0100)]
Remove moszumanska-lvm and moszumanska from multipath config

5 years agoAvoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd
Tollef Fog Heen [Sat, 19 Jan 2019 20:17:37 +0000 (21:17 +0100)]
Avoid restarting ud-replicated too quickly, to avoid being rate-limited by systemd

5 years agoEnable SSILegacyExprParser on www.debconf.org
Julien Cristau [Thu, 17 Jan 2019 15:46:37 +0000 (16:46 +0100)]
Enable SSILegacyExprParser on www.debconf.org

The site would need updates for the new syntax

5 years agowww.debconf.org vhost update
Julien Cristau [Thu, 17 Jan 2019 15:37:04 +0000 (16:37 +0100)]
www.debconf.org vhost update

Add missing redirects from current config on kent.debconf.org

5 years agoAdd www.debconf.org vhost for real
Julien Cristau [Thu, 17 Jan 2019 15:26:08 +0000 (16:26 +0100)]
Add www.debconf.org vhost for real

5 years agoAdd www.debconf.org vhost on static
Julien Cristau [Thu, 17 Jan 2019 15:04:07 +0000 (16:04 +0100)]
Add www.debconf.org vhost on static

5 years agoAdd www.debconf.org static component
Julien Cristau [Thu, 17 Jan 2019 14:42:02 +0000 (15:42 +0100)]
Add www.debconf.org static component

5 years agoBump RLimitNPROC for bugs web hosts
Julien Cristau [Wed, 16 Jan 2019 07:08:07 +0000 (08:08 +0100)]
Bump RLimitNPROC for bugs web hosts

Bug#919316

5 years agoSet LogLevel VERBOSE in sshd
Peter Palfrader [Mon, 14 Jan 2019 09:40:02 +0000 (10:40 +0100)]
Set LogLevel VERBOSE in sshd

5 years agoAdd wiki.debconf.org static vhost (RT#7595)
Julien Cristau [Sun, 13 Jan 2019 22:51:35 +0000 (23:51 +0100)]
Add wiki.debconf.org static vhost (RT#7595)

5 years agodebconfstatic can update wiki.debconf.org
Julien Cristau [Sun, 13 Jan 2019 22:44:15 +0000 (23:44 +0100)]
debconfstatic can update wiki.debconf.org

5 years agoUpdate DMUP url in motd
Julien Cristau [Sun, 13 Jan 2019 22:42:05 +0000 (23:42 +0100)]
Update DMUP url in motd

5 years agoAdd wiki.debconf.org static component
Julien Cristau [Sun, 13 Jan 2019 22:35:21 +0000 (23:35 +0100)]
Add wiki.debconf.org static component

5 years agoFix sudoers syntax
Julien Cristau [Thu, 10 Jan 2019 21:20:21 +0000 (22:20 +0100)]
Fix sudoers syntax

5 years agosudo: add an extra entry for dsa-check-openmanage
Julien Cristau [Thu, 10 Jan 2019 21:08:20 +0000 (22:08 +0100)]
sudo: add an extra entry for dsa-check-openmanage

Add ability to ignore "Cache Battery 0 in controller 0 is Degraded
(Non-Critical) [probably harmless]" warning.

5 years agopostgres-make-base-backups.erb: fix limited info log
Peter Palfrader [Tue, 8 Jan 2019 13:49:08 +0000 (14:49 +0100)]
postgres-make-base-backups.erb: fix limited info log

5 years agoRT#7513 Get rid of most traces of moszumanska
Tollef Fog Heen [Mon, 7 Jan 2019 20:59:04 +0000 (21:59 +0100)]
RT#7513 Get rid of most traces of moszumanska

5 years agoAdd an adm key for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 19:39:06 +0000 (20:39 +0100)]
Add an adm key for tfheen

5 years agoOpen up some IPs for tfheen
Tollef Fog Heen [Wed, 2 Jan 2019 18:47:11 +0000 (19:47 +0100)]
Open up some IPs for tfheen

5 years agoremove duplicate entry for sallinen in postgresql_server
Peter Palfrader [Wed, 2 Jan 2019 17:29:38 +0000 (18:29 +0100)]
remove duplicate entry for sallinen in postgresql_server

5 years agoRemove disfunct combined.njabl.org RBL from rbllist for all the roles that had it
Peter Palfrader [Wed, 2 Jan 2019 13:22:38 +0000 (14:22 +0100)]
Remove disfunct combined.njabl.org RBL from rbllist for all the roles that had it

5 years agodo not rate limit on the loopback interface
Peter Palfrader [Mon, 31 Dec 2018 09:02:27 +0000 (10:02 +0100)]
do not rate limit on the loopback interface

5 years agoalso close http connections after each request via haproxy
Peter Palfrader [Sun, 23 Dec 2018 09:33:01 +0000 (10:33 +0100)]
also close http connections after each request via haproxy

5 years agofor snapshot, disable keep-alive so we can rate-limit better
Peter Palfrader [Sun, 23 Dec 2018 09:25:19 +0000 (10:25 +0100)]
for snapshot, disable keep-alive so we can rate-limit better

5 years agoblacklist 198.11.128.0/18
Peter Palfrader [Sat, 22 Dec 2018 18:05:09 +0000 (19:05 +0100)]
blacklist 198.11.128.0/18

5 years agoActually drop drom 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 17:57:56 +0000 (18:57 +0100)]
Actually drop drom 208.91.68.213

5 years agoblacklist 208.91.68.213
Peter Palfrader [Sat, 22 Dec 2018 15:43:30 +0000 (16:43 +0100)]
blacklist 208.91.68.213

5 years agoone ; too many
Peter Palfrader [Sat, 22 Dec 2018 15:35:53 +0000 (16:35 +0100)]
one ; too many

5 years agoport 6081 is redirected
Peter Palfrader [Sat, 22 Dec 2018 15:35:01 +0000 (16:35 +0100)]
port 6081 is redirected

5 years agosnapshot: try to put a bound on connections per client
Peter Palfrader [Sat, 22 Dec 2018 15:29:12 +0000 (16:29 +0100)]
snapshot: try to put a bound on connections per client

5 years agosnapshot: set QS_LocRequestLimitDefault if mod_qos is loaded
Peter Palfrader [Thu, 20 Dec 2018 11:37:04 +0000 (12:37 +0100)]
snapshot: set QS_LocRequestLimitDefault if mod_qos is loaded

5 years agoreload ferm on changes instead of restart
Peter Palfrader [Mon, 17 Dec 2018 09:19:44 +0000 (10:19 +0100)]
reload ferm on changes instead of restart

5 years agoMake a snapshot.debian.net vhost, 2
Peter Palfrader [Wed, 12 Dec 2018 13:05:22 +0000 (14:05 +0100)]
Make a snapshot.debian.net vhost, 2

5 years agoMake a snapshot.debian.net vhost
Peter Palfrader [Wed, 12 Dec 2018 13:03:15 +0000 (14:03 +0100)]
Make a snapshot.debian.net vhost

5 years agoDrop references to long-gone db.d.o repos
Julien Cristau [Wed, 28 Nov 2018 10:37:13 +0000 (11:37 +0100)]
Drop references to long-gone db.d.o repos

5 years agoUse https for *-restricted db.d.o repo too
Julien Cristau [Wed, 28 Nov 2018 10:36:28 +0000 (11:36 +0100)]
Use https for *-restricted db.d.o repo too

5 years agoUse https to access the db.d.o repo
Julien Cristau [Wed, 28 Nov 2018 10:30:56 +0000 (11:30 +0100)]
Use https to access the db.d.o repo

5 years agoFixup db.d.o archive key for apt consumption, it shouldn't be armored
Julien Cristau [Wed, 28 Nov 2018 09:38:30 +0000 (10:38 +0100)]
Fixup db.d.o archive key for apt consumption, it shouldn't be armored

5 years agoExtend lifetime of db.d.o archive key by a year
Julien Cristau [Wed, 28 Nov 2018 08:51:14 +0000 (09:51 +0100)]
Extend lifetime of db.d.o archive key by a year

5 years agoDelete old logs on hosts using pybuildd
Julien Cristau [Wed, 28 Nov 2018 08:33:53 +0000 (09:33 +0100)]
Delete old logs on hosts using pybuildd

pybuildd keeps them indefinitely
(https://salsa.debian.org/wb-team/pybuildd/issues/11) so clean up ourselves to
avoid running into ENOSPC.