mirror/dsa-puppet.git
5 years agoAdd puppet/archive module, required for newer puppet/rabbitmq
Julien Cristau [Tue, 20 Nov 2018 22:07:26 +0000 (23:07 +0100)]
Add puppet/archive module, required for newer puppet/rabbitmq

5 years agoRevert "Update 3rdparty rabbitmq module"
Julien Cristau [Tue, 20 Nov 2018 20:49:05 +0000 (21:49 +0100)]
Revert "Update 3rdparty rabbitmq module"

This reverts commit 921e69100a563cf143f56a3905d8362336d939ff.

5 years agoRevert "Add systemd module, required by rabbitmq"
Julien Cristau [Tue, 20 Nov 2018 20:49:03 +0000 (21:49 +0100)]
Revert "Add systemd module, required by rabbitmq"

This reverts commit 1329adc9f34c3c87e353983ec9023a6cf6e93e67.

5 years agoRevert "Add puppet/archive module"
Julien Cristau [Tue, 20 Nov 2018 20:48:56 +0000 (21:48 +0100)]
Revert "Add puppet/archive module"

This reverts commit ce70d6baf887ae03a2a6a7f5e73eb2e2c3dea208.

5 years agoAdd puppet/archive module
Julien Cristau [Tue, 20 Nov 2018 20:33:49 +0000 (21:33 +0100)]
Add puppet/archive module

Required by puppet/rabbitmq

5 years agoRename our systemd module to dsa_systemd
Julien Cristau [Tue, 20 Nov 2018 20:28:40 +0000 (21:28 +0100)]
Rename our systemd module to dsa_systemd

Avoid conflict with 3rdparty.

5 years agoAdd systemd module, required by rabbitmq
Julien Cristau [Tue, 20 Nov 2018 20:09:44 +0000 (21:09 +0100)]
Add systemd module, required by rabbitmq

5 years agopubsub: manage_repos -> repos_ensure
Julien Cristau [Tue, 20 Nov 2018 20:02:31 +0000 (21:02 +0100)]
pubsub: manage_repos -> repos_ensure

5 years agoUpdate 3rdparty rabbitmq module
Julien Cristau [Tue, 20 Nov 2018 19:57:58 +0000 (20:57 +0100)]
Update 3rdparty rabbitmq module

5 years agosetup-dchroot: Request unmerged /usr
Simon McVittie [Tue, 20 Nov 2018 16:18:50 +0000 (16:18 +0000)]
setup-dchroot: Request unmerged /usr

Merged /usr is known to cause multiple packages to be misbuilt. As long
as we support unmerged /usr for user systems, we should mitigate
this class of bugs by using unmerged-/usr chroots on official buildds,
resulting in binary packages that work equally well on merged- or
unmerged-/usr user systems.

See:

https://bugs.debian.org/913229
https://udd.debian.org/cgi-bin/bts-usertags.cgi?user=md@linux.it&tag=usrmerge
thread at https://lists.debian.org/debian-devel/2018/11/msg00299.html

Signed-off-by: Simon McVittie <smcv@debian.org>
Signed-off-by: Julien Cristau <jcristau@debian.org>
5 years agoAdd pijper
Julien Cristau [Mon, 19 Nov 2018 16:57:28 +0000 (17:57 +0100)]
Add pijper

5 years agoDon't install megacli if we're not amd64
Julien Cristau [Mon, 19 Nov 2018 16:47:12 +0000 (17:47 +0100)]
Don't install megacli if we're not amd64

5 years agomanda-node03, manda-node04: lvm: issue discards
Peter Palfrader [Mon, 19 Nov 2018 12:38:15 +0000 (13:38 +0100)]
manda-node03, manda-node04: lvm: issue discards

5 years agomanda-node03, manda-node04: lvm: set a device filter
Peter Palfrader [Mon, 19 Nov 2018 12:35:09 +0000 (13:35 +0100)]
manda-node03, manda-node04: lvm: set a device filter

5 years agoadd default lvm conf for new manda hosts
Peter Palfrader [Mon, 19 Nov 2018 12:33:15 +0000 (13:33 +0100)]
add default lvm conf for new manda hosts

5 years agorename lvm-manda-ganeti.conf -> lvm-manda-ganeti3.conf
Peter Palfrader [Mon, 19 Nov 2018 12:30:02 +0000 (13:30 +0100)]
rename lvm-manda-ganeti.conf -> lvm-manda-ganeti3.conf

5 years agotry to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 19:13:48 +0000 (20:13 +0100)]
try to sort pin files

5 years agoRevert "try to sort pin files"
Peter Palfrader [Sun, 18 Nov 2018 19:03:18 +0000 (20:03 +0100)]
Revert "try to sort pin files"

This reverts commit 839c8ea25d94aa887d71e46d150509ff4c339fac.

5 years agotry to sort pin files
Peter Palfrader [Sun, 18 Nov 2018 19:01:37 +0000 (20:01 +0100)]
try to sort pin files

5 years agoTry ganeti address definitions for new manda cluster
Peter Palfrader [Sun, 18 Nov 2018 09:51:28 +0000 (10:51 +0100)]
Try ganeti address definitions for new manda cluster

5 years agoUse ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganet...
Peter Palfrader [Sun, 18 Nov 2018 09:50:11 +0000 (10:50 +0100)]
Use ldap's purpose field (ganeti/kvm host) to decide which hosts get the puppet ganeti module

5 years agoAlso restrict "ganeti/kvm host" purpose
Peter Palfrader [Sun, 18 Nov 2018 09:47:57 +0000 (10:47 +0100)]
Also restrict "ganeti/kvm host" purpose

5 years agoTry to not limit ganeti firewall rules to v4
Peter Palfrader [Sun, 18 Nov 2018 09:25:51 +0000 (10:25 +0100)]
Try to not limit ganeti firewall rules to v4

5 years agosudo: add additional openmanage command line for nagios
Julien Cristau [Tue, 13 Nov 2018 14:24:37 +0000 (15:24 +0100)]
sudo: add additional openmanage command line for nagios

Lets us blacklist the battery probe on wieck and schumann.

5 years agoferm cleanup: sallinen
Peter Palfrader [Tue, 13 Nov 2018 12:58:00 +0000 (13:58 +0100)]
ferm cleanup: sallinen

5 years agoferm cleanup: bmdb1:debsources, fix
Peter Palfrader [Tue, 13 Nov 2018 12:55:38 +0000 (13:55 +0100)]
ferm cleanup: bmdb1:debsources, fix

5 years agoferm cleanup: bmdb1:debsources
Peter Palfrader [Tue, 13 Nov 2018 12:54:21 +0000 (13:54 +0100)]
ferm cleanup: bmdb1:debsources

5 years agoferm cleanup: bmdb1:dedup
Peter Palfrader [Tue, 13 Nov 2018 12:53:14 +0000 (13:53 +0100)]
ferm cleanup: bmdb1:dedup

5 years agoferm cleanup: bmdb1:bacula
Peter Palfrader [Tue, 13 Nov 2018 12:52:24 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:bacula

5 years agoferm cleanup: bmdb1:wannabuild, remove duplicate allow from backuphost
Peter Palfrader [Tue, 13 Nov 2018 12:52:01 +0000 (13:52 +0100)]
ferm cleanup: bmdb1:wannabuild, remove duplicate allow from backuphost

5 years agoferm cleanup: bmdb1:wannabuild
Peter Palfrader [Tue, 13 Nov 2018 12:50:36 +0000 (13:50 +0100)]
ferm cleanup: bmdb1:wannabuild

5 years agoferm cleanup: bmdb1:dak, fix
Peter Palfrader [Tue, 13 Nov 2018 12:48:49 +0000 (13:48 +0100)]
ferm cleanup: bmdb1:dak, fix

5 years agoferm cleanup: bmdb1:dak
Peter Palfrader [Tue, 13 Nov 2018 12:46:53 +0000 (13:46 +0100)]
ferm cleanup: bmdb1:dak

5 years agoferm cleanup: bmdb1:main, fix
Peter Palfrader [Tue, 13 Nov 2018 12:41:42 +0000 (13:41 +0100)]
ferm cleanup: bmdb1:main, fix

5 years agoferm cleanup: bmdb1:main
Peter Palfrader [Tue, 13 Nov 2018 12:39:35 +0000 (13:39 +0100)]
ferm cleanup: bmdb1:main

also: no longer allow bmdb1:main access from bm-bl9

5 years agoferm cleanup: fasolo postgres
Peter Palfrader [Tue, 13 Nov 2018 12:12:15 +0000 (13:12 +0100)]
ferm cleanup: fasolo postgres

5 years agotest avoiding hardcoding addresses
Peter Palfrader [Tue, 13 Nov 2018 12:08:53 +0000 (13:08 +0100)]
test avoiding hardcoding addresses

5 years agono more varnish on sibelius
Peter Palfrader [Tue, 13 Nov 2018 09:40:32 +0000 (10:40 +0100)]
no more varnish on sibelius

5 years agobugs-search no longer runs on sonntag
Peter Palfrader [Tue, 13 Nov 2018 09:40:09 +0000 (10:40 +0100)]
bugs-search no longer runs on sonntag

5 years agobacklist 51.15.215.91 from snapshot
Peter Palfrader [Sun, 11 Nov 2018 17:35:33 +0000 (18:35 +0100)]
backlist 51.15.215.91 from snapshot

5 years agoRevert "99builddsourceslist: temporarily add stretch-proposed-updates to stretch...
Julien Cristau [Sun, 11 Nov 2018 00:44:50 +0000 (01:44 +0100)]
Revert "99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots"

Debian 9.6 is out, so the temporary workaround is no longer necessary.

This reverts commit 6817281d2e8f2d2a0991b7517d451e6c7e38734a.

5 years agosamhain: ignore /etc/schroot/dsa/default-mirror
Julien Cristau [Fri, 9 Nov 2018 14:25:50 +0000 (15:25 +0100)]
samhain: ignore /etc/schroot/dsa/default-mirror

It comes from puppet.

5 years agosamhain: deal with rename of db.d.o restricted sources.list entry
Julien Cristau [Thu, 8 Nov 2018 08:12:51 +0000 (09:12 +0100)]
samhain: deal with rename of db.d.o restricted sources.list entry

5 years agosudo: add manda-node0[34] to DELLHOSTS
Julien Cristau [Wed, 7 Nov 2018 22:20:50 +0000 (23:20 +0100)]
sudo: add manda-node0[34] to DELLHOSTS

Lets nagios monitor system and storage health.

5 years agoFix debian_org::apt_restricted
Julien Cristau [Wed, 7 Nov 2018 21:13:12 +0000 (22:13 +0100)]
Fix debian_org::apt_restricted

5 years agoInstall srvadmin foo on dell hosts, and move our restricted archive to debian_org...
Julien Cristau [Wed, 7 Nov 2018 21:07:37 +0000 (22:07 +0100)]
Install srvadmin foo on dell hosts, and move our restricted archive to debian_org::apt_restricted

5 years agoand symlink
Peter Palfrader [Wed, 7 Nov 2018 19:22:52 +0000 (20:22 +0100)]
and symlink

5 years agochange megaraid_sas test
Peter Palfrader [Wed, 7 Nov 2018 19:19:00 +0000 (20:19 +0100)]
change megaraid_sas test

5 years agoftp.de.debian.org appears to be unavailable -- switch man-da to ftp2
Peter Palfrader [Wed, 7 Nov 2018 19:09:24 +0000 (20:09 +0100)]
ftp.de.debian.org appears to be unavailable -- switch man-da to ftp2

5 years agodifferent name for aptrepo
Peter Palfrader [Wed, 7 Nov 2018 18:16:04 +0000 (19:16 +0100)]
different name for aptrepo

5 years agofix class
Peter Palfrader [Wed, 7 Nov 2018 18:13:02 +0000 (19:13 +0100)]
fix class

5 years agomegaraid_sas
Peter Palfrader [Wed, 7 Nov 2018 18:11:47 +0000 (19:11 +0100)]
megaraid_sas

5 years agoAdd megaraid_sas facter
Peter Palfrader [Wed, 7 Nov 2018 18:08:38 +0000 (19:08 +0100)]
Add megaraid_sas facter

5 years agoPut grub and kernel on ttyS0 on manda-node0[34]
Julien Cristau [Wed, 7 Nov 2018 09:01:25 +0000 (10:01 +0100)]
Put grub and kernel on ttyS0 on manda-node0[34]

5 years agosetup-dchroot: merge from tor (genname split into function, ubuntu updates)
Peter Palfrader [Tue, 6 Nov 2018 08:04:53 +0000 (09:04 +0100)]
setup-dchroot: merge from tor (genname split into function, ubuntu updates)

- split schroot base name generation into its own function
- if we build an ubuntu chroot, upgrade to the latest packages available
  in -updates and -security of their suite, since it seems they don't
  ever do point releases so you end up with a 4 year old openssl in your
  chroot.

5 years agoTemporarily switch off privacy logging for security.d.o
Julien Cristau [Mon, 5 Nov 2018 19:21:57 +0000 (20:21 +0100)]
Temporarily switch off privacy logging for security.d.o

I want to figure out what clients are still hitting it directly,
especially at specific times, so some insight into User-Agents and
timestamps would be useful.

5 years agoRedirect all of security.d.o to security-cdn
Julien Cristau [Sun, 4 Nov 2018 12:03:42 +0000 (13:03 +0100)]
Redirect all of security.d.o to security-cdn

Instead of just /pool/updates/main/l/linux/*, redirect everything except:
- if coming from fastly or aws
- if coming from nagios or mini-nag
- if using the onion service
- if doing a health check

Eventually we might point the security.d.o name directly at the CDN, but let's
see if this helps already.

5 years agoExclude dsa-check-mirrorsync nagios check from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:11:23 +0000 (16:11 +0100)]
Exclude dsa-check-mirrorsync nagios check from security to security-cdn redirect

5 years agoExclude nagios check_http from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:09:25 +0000 (16:09 +0100)]
Exclude nagios check_http from security to security-cdn redirect

Prep for making that redirect global

5 years agoDisable mod_disk_cache on security-tracker
Julien Cristau [Fri, 2 Nov 2018 12:19:18 +0000 (13:19 +0100)]
Disable mod_disk_cache on security-tracker

5 years agoDrop sibelius from postgres-make-base-backups
Julien Cristau [Thu, 1 Nov 2018 17:34:33 +0000 (18:34 +0100)]
Drop sibelius from postgres-make-base-backups

5 years agoDrop firewall rule for pg @ sibelius
Julien Cristau [Thu, 1 Nov 2018 17:32:53 +0000 (18:32 +0100)]
Drop firewall rule for pg @ sibelius

5 years agoRemove sibelius/snapshot from dsa-check-backuppg
Julien Cristau [Thu, 1 Nov 2018 17:31:31 +0000 (18:31 +0100)]
Remove sibelius/snapshot from dsa-check-backuppg

5 years agounique all ip addresses
Peter Palfrader [Wed, 31 Oct 2018 08:41:50 +0000 (09:41 +0100)]
unique all ip addresses

5 years agoTry a unique around v4addrs
Peter Palfrader [Wed, 31 Oct 2018 08:39:06 +0000 (09:39 +0100)]
Try a unique around v4addrs

5 years agoRevert "sibelius nfs on public net"
Peter Palfrader [Wed, 31 Oct 2018 08:34:17 +0000 (09:34 +0100)]
Revert "sibelius nfs on public net"

This reverts commits 613379c1d1814794d873352a4791c5556eac938f and
1f3cd8bea3ed396c5e1ab35d369e6b72bb27b3f2.

5 years agosibelius nfs on public net, 2
Peter Palfrader [Wed, 31 Oct 2018 08:05:47 +0000 (09:05 +0100)]
sibelius nfs on public net, 2

5 years agosibelius nfs on public net
Peter Palfrader [Wed, 31 Oct 2018 08:05:09 +0000 (09:05 +0100)]
sibelius nfs on public net

5 years agomake fail2ban cleanup job shut up
Peter Palfrader [Tue, 30 Oct 2018 10:18:15 +0000 (11:18 +0100)]
make fail2ban cleanup job shut up

5 years agomove DROP blacklists to ferm prio 005, after munin
Peter Palfrader [Tue, 30 Oct 2018 09:45:11 +0000 (10:45 +0100)]
move DROP blacklists to ferm prio 005, after munin

5 years agomanually create the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:38:18 +0000 (10:38 +0100)]
manually create the subchain

5 years agoprevent the trailing ; after the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:32:31 +0000 (10:32 +0100)]
prevent the trailing ; after the subchain

5 years agomove the fail2ban rules under the dsa-f2b chain
Peter Palfrader [Tue, 30 Oct 2018 09:28:01 +0000 (10:28 +0100)]
move the fail2ban rules under the dsa-f2b chain

5 years agoMove logging and related/established out of ferm.conf into a dsa.d rule
Peter Palfrader [Tue, 30 Oct 2018 09:23:42 +0000 (10:23 +0100)]
Move logging and related/established out of ferm.conf into a dsa.d rule

5 years agomove munin rules from conf.d to the rules dir, 2
Peter Palfrader [Tue, 30 Oct 2018 09:21:31 +0000 (10:21 +0100)]
move munin rules from conf.d to the rules dir, 2

5 years agomove munin rules from conf.d to the rules dir
Peter Palfrader [Tue, 30 Oct 2018 09:20:32 +0000 (10:20 +0100)]
move munin rules from conf.d to the rules dir

5 years agorename interfaces to 50-munin-interfaces
Peter Palfrader [Tue, 30 Oct 2018 09:17:50 +0000 (10:17 +0100)]
rename interfaces to  50-munin-interfaces

5 years agomerge munin_ip v4 and v6 into one rule
Peter Palfrader [Tue, 30 Oct 2018 09:15:25 +0000 (10:15 +0100)]
merge munin_ip v4 and v6 into one rule

5 years agochange default ferm rule priority to 10 from 00
Peter Palfrader [Tue, 30 Oct 2018 09:07:46 +0000 (10:07 +0100)]
change default ferm rule priority to 10 from 00

5 years agoalso govern submission port
Peter Palfrader [Tue, 30 Oct 2018 09:00:46 +0000 (10:00 +0100)]
also govern submission port

5 years agoClean up fail2ban database
Peter Palfrader [Tue, 30 Oct 2018 08:57:53 +0000 (09:57 +0100)]
Clean up fail2ban database

5 years agomore aggressive fail2ban on exim hosts
Peter Palfrader [Sun, 28 Oct 2018 12:05:41 +0000 (13:05 +0100)]
more aggressive fail2ban on exim hosts

5 years agoAdd a second easydns ipv4 address
Peter Palfrader [Tue, 23 Oct 2018 16:29:04 +0000 (18:29 +0200)]
Add a second easydns ipv4 address

5 years agomirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug

5 years agoMake mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug

5 years agoklecker no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug

5 years agoremove debian.fi
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi

We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.

5 years agonetnod call the key netnod-debian-20171122
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-20171122

5 years agotry to switch dnsnodeapi-ACL over to the TSIG key
Peter Palfrader [Wed, 17 Oct 2018 13:11:27 +0000 (15:11 +0200)]
try to switch dnsnodeapi-ACL over to the TSIG key

5 years agotry a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings

5 years agoallow respighi to access udd on ullmann
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann

it's used to create the autoremoval hints

5 years agomerge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule

5 years agoallow ssh from ftpmaster to debug_mirrors
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors

5 years agodebug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter

5 years agoMake hiera's debug_mirror look like debian_mirror
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror

5 years agofix a prefix len in dsa-postgres-udd6
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6

5 years agoRemove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses

5 years agoSet up grub with serial console at leaseweb
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb

5 years agoAdd health check on debian-debug archive backends
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends

5 years agoUsing *:80 as vhost on mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu

everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.