mirror/dsa-puppet.git
5 years agoStart with removing some moszumanska entries (in particular about pg backups). re...
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups).  re: #7513)

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2

5 years agoDo not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls...
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt

5 years agorestart unbound after putting trust anchors in place
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place

5 years agoUse temporary redirects for ports redirects to the wiki
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki

The URLs could change to the website or elsewhere at some point.

Suggested-by: weasel
5 years agoRedirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages

5 years agoAdd workaround for new Tor configuration requirement
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement

See-also: https://trac.torproject.org/projects/tor/ticket/27849

5 years agowe send mail from nagios@. make it exist
Peter Palfrader [Fri, 14 Sep 2018 12:23:39 +0000 (14:23 +0200)]
we send mail from nagios@.  make it exist

5 years agoTry to samhain ignore /var/lib/puppet/clientbucket more
Peter Palfrader [Thu, 23 Aug 2018 07:46:56 +0000 (09:46 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket more

5 years agoand get dependency right
Peter Palfrader [Wed, 22 Aug 2018 09:14:56 +0000 (11:14 +0200)]
and get dependency right

5 years agoAdd munin-async service to the catalog
Peter Palfrader [Wed, 22 Aug 2018 09:14:37 +0000 (11:14 +0200)]
Add munin-async service to the catalog

5 years agoSet munin-async restart time to 10sec
Peter Palfrader [Wed, 22 Aug 2018 09:11:11 +0000 (11:11 +0200)]
Set munin-async restart time to 10sec

Sometimes munin-async fails to start, presumably because it cannot
connect to the running munind yet.  The service file tells it to
restart always, but with the default sleep time before a restart of
100ms we often run into
 systemd[1]: munin-async.service: Start request repeated too quickly.
after 5 fails attempts within a second or two.

Give munind more time to actually launch.

5 years agoStart repro only after we are online
Peter Palfrader [Wed, 22 Aug 2018 08:56:51 +0000 (10:56 +0200)]
Start repro only after we are online

It fails to bind to its IP addresses otherwise.

5 years agoTry to samhain ignore /var/lib/puppet/clientbucket
Peter Palfrader [Wed, 22 Aug 2018 08:15:29 +0000 (10:15 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket

5 years agoAlso ask our nagios check if drbd is fine
Peter Palfrader [Tue, 21 Aug 2018 20:48:10 +0000 (22:48 +0200)]
Also ask our nagios check if drbd is fine

5 years agoganeti-reboot-cluster: wait for drbd to have caught up
Peter Palfrader [Tue, 21 Aug 2018 20:46:34 +0000 (22:46 +0200)]
ganeti-reboot-cluster: wait for drbd to have caught up

5 years agoand a mirror
Peter Palfrader [Tue, 21 Aug 2018 14:04:04 +0000 (16:04 +0200)]
and a mirror

5 years agolarger net
Peter Palfrader [Tue, 21 Aug 2018 14:02:39 +0000 (16:02 +0200)]
larger net

5 years agoone more net
Peter Palfrader [Tue, 21 Aug 2018 14:00:02 +0000 (16:00 +0200)]
one more net

5 years agothe amazon crawlers change IP address as soon as they are blocked
Peter Palfrader [Tue, 21 Aug 2018 13:57:57 +0000 (15:57 +0200)]
the amazon crawlers change IP address as soon as they are blocked

5 years agoblacklist more amazon aws
Peter Palfrader [Tue, 21 Aug 2018 13:48:53 +0000 (15:48 +0200)]
blacklist more amazon aws

5 years agoblacklist 18.185.157.46 and 18.194.174.202
Peter Palfrader [Tue, 21 Aug 2018 10:09:44 +0000 (12:09 +0200)]
blacklist 18.185.157.46 and 18.194.174.202

5 years ago99builddsourceslist: remove jessie-kfreebsd hacks
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: remove jessie-kfreebsd hacks

5 years ago99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security...
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots

Temporarily add stretch-proposed-updates for stretch-security chroots as requested
by the security team to handle Thunderbird and Firefox ESR 60.x releases. This should
be removed with the release of the 9.5 point release.

5 years agosetup-all-dchroots: fix architecture list generation
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
setup-all-dchroots: fix architecture list generation

5 years agoTry one fewer threads per snapshot process
Peter Palfrader [Sun, 19 Aug 2018 20:18:01 +0000 (22:18 +0200)]
Try one fewer threads per snapshot process

5 years agoremove old cleanup items
Peter Palfrader [Sun, 19 Aug 2018 09:44:29 +0000 (11:44 +0200)]
remove old cleanup items

5 years agoMove default webpage from apache to webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:43:10 +0000 (11:43 +0200)]
Move default webpage from apache to webserver module

5 years agoMove creation of /run/dsa/shutdown-marker to a new common webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:38:57 +0000 (11:38 +0200)]
Move creation of /run/dsa/shutdown-marker to a new common webserver module

5 years agosetup-all-dchroots: Support rebuilding just one arch/suite
Peter Palfrader [Thu, 16 Aug 2018 08:08:52 +0000 (10:08 +0200)]
setup-all-dchroots: Support rebuilding just one arch/suite

5 years agosetup-all-dchroots: move DPKGARCH to where it's used
Peter Palfrader [Thu, 16 Aug 2018 08:07:17 +0000 (10:07 +0200)]
setup-all-dchroots: move DPKGARCH to where it's used

5 years agosetup-all-dchroots: remove unused $UNAMEARCH
Peter Palfrader [Thu, 16 Aug 2018 08:05:03 +0000 (10:05 +0200)]
setup-all-dchroots: remove unused $UNAMEARCH

5 years agosetup-all-dchroots: documentation comments
Peter Palfrader [Thu, 16 Aug 2018 08:04:53 +0000 (10:04 +0200)]
setup-all-dchroots: documentation comments

5 years agosetup-all-dchroots: We use extraargs as a global variable, write it in caps
Peter Palfrader [Thu, 16 Aug 2018 08:02:23 +0000 (10:02 +0200)]
setup-all-dchroots: We use extraargs as a global variable, write it in caps

5 years agosetup-all-dchroots: get rid of obsolete variable "$extra" that is always the empty...
Peter Palfrader [Thu, 16 Aug 2018 08:01:54 +0000 (10:01 +0200)]
setup-all-dchroots: get rid of obsolete variable "$extra" that is always the empty string

5 years agosetup-all-dchroots: move all main code to after function declarations
Peter Palfrader [Thu, 16 Aug 2018 08:01:01 +0000 (10:01 +0200)]
setup-all-dchroots: move all main code to after function declarations

5 years agosetup-all-dchroots: copy from tor: -c support
Peter Palfrader [Thu, 16 Aug 2018 07:50:34 +0000 (09:50 +0200)]
setup-all-dchroots: copy from tor: -c support

Add option to just write config files.  Also revamps parameter parsing.

5 years agosetup-all-dchroots: tabs to spaces
Peter Palfrader [Thu, 16 Aug 2018 07:40:33 +0000 (09:40 +0200)]
setup-all-dchroots: tabs to spaces

5 years agoAdd bttracker alias to the cdimage maintenance vhost
Julien Cristau [Wed, 15 Aug 2018 17:08:49 +0000 (19:08 +0200)]
Add bttracker alias to the cdimage maintenance vhost

5 years agoCreate missing directory
Julien Cristau [Wed, 15 Aug 2018 06:36:40 +0000 (08:36 +0200)]
Create missing directory

5 years agoPrepare maintenance page for cdimage.d.o and friends
Julien Cristau [Wed, 15 Aug 2018 06:31:18 +0000 (08:31 +0200)]
Prepare maintenance page for cdimage.d.o and friends

5 years agoAdd diversity@d.o to various exim config bits
Héctor Orón Martínez [Tue, 14 Aug 2018 14:18:50 +0000 (16:18 +0200)]
Add diversity@d.o to various exim config bits

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
5 years agoporterbox: install dgit. rt#7366
Héctor Orón Martínez [Sun, 12 Aug 2018 16:03:35 +0000 (18:03 +0200)]
porterbox: install dgit. rt#7366

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
5 years agoDon't manage salsa's /run/redis
Julien Cristau [Tue, 7 Aug 2018 08:44:49 +0000 (10:44 +0200)]
Don't manage salsa's /run/redis

Permissions conflicts with the package's
/usr/lib/tmpfiles.d/redis-server.conf so we keep changing them and
restarting the service needlessly.

5 years agoall our hosts still want stretch::network_online though
Peter Palfrader [Tue, 7 Aug 2018 08:18:02 +0000 (10:18 +0200)]
all our hosts still want stretch::network_online though

5 years agobacula-fd: se ipv6 address from ldap since DNS during boot is icky
Peter Palfrader [Tue, 7 Aug 2018 08:17:05 +0000 (10:17 +0200)]
bacula-fd: se ipv6 address from ldap since DNS during boot is icky

5 years agoget our ipv[46] ldap addresses
Peter Palfrader [Tue, 7 Aug 2018 08:12:31 +0000 (10:12 +0200)]
get our ipv[46] ldap addresses

5 years agobacula-fd: wait for unbound also
Peter Palfrader [Tue, 7 Aug 2018 07:35:08 +0000 (09:35 +0200)]
bacula-fd: wait for unbound also

5 years agoRevert "allow access to pg on vittoria for dc18"
Julien Cristau [Tue, 7 Aug 2018 07:11:57 +0000 (09:11 +0200)]
Revert "allow access to pg on vittoria for dc18"

This reverts commit 21edc51f3c8a84ec014b0f0bffc8ebd972b6b2f2.

5 years agoRevert "RT#7368: add additional IP"
Julien Cristau [Tue, 7 Aug 2018 07:11:53 +0000 (09:11 +0200)]
Revert "RT#7368: add additional IP"

This reverts commit e764ff0ec7eaccac713c15cb4c3fb284649b850b.

5 years agowait until after network-online.target for bacula-fd
Peter Palfrader [Tue, 7 Aug 2018 07:03:15 +0000 (09:03 +0200)]
wait until after network-online.target for bacula-fd

5 years agoDecommission powerpc-osuosl-01
Julien Cristau [Mon, 6 Aug 2018 16:27:22 +0000 (18:27 +0200)]
Decommission powerpc-osuosl-01

5 years agoDecommission powerpc-unicamp-01
Julien Cristau [Mon, 6 Aug 2018 16:03:50 +0000 (18:03 +0200)]
Decommission powerpc-unicamp-01

5 years agoadd 'do not modify' headers
Luca Filipozzi [Mon, 6 Aug 2018 07:48:00 +0000 (00:48 -0700)]
add 'do not modify' headers

Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Mon, 6 Aug 2018 07:20:52 +0000 (00:20 -0700)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <luca.filipozzi@gmail.com>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Fri, 3 Aug 2018 15:23:44 +0000 (15:23 +0000)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agocomplete RT#7389
Luca Filipozzi [Fri, 3 Aug 2018 10:22:24 +0000 (10:22 +0000)]
complete RT#7389

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agore-add vhost after x509 certificate issuance
Luca Filipozzi [Fri, 3 Aug 2018 10:07:14 +0000 (10:07 +0000)]
re-add vhost after x509 certificate issuance

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agorevert vhost until x509 cert deployed
Luca Filipozzi [Fri, 3 Aug 2018 09:43:22 +0000 (09:43 +0000)]
revert vhost until x509 cert deployed

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agoaction RT#7389 - debconf19.debconf.org setup
Luca Filipozzi [Fri, 3 Aug 2018 09:36:00 +0000 (09:36 +0000)]
action RT#7389 - debconf19.debconf.org setup

Signed-off-by: Luca Filipozzi <lfilipoz@emyr.net>
5 years agobacula-sd: listen on ipv6
Peter Palfrader [Fri, 3 Aug 2018 07:59:54 +0000 (09:59 +0200)]
bacula-sd: listen on ipv6

5 years agoallow ipv6 connections to all clients from the bacula director
Peter Palfrader [Fri, 3 Aug 2018 07:56:57 +0000 (09:56 +0200)]
allow ipv6 connections to all clients from the bacula director

5 years agobacula-ferm: we do not need to explicitly allow connections from localhost
Peter Palfrader [Fri, 3 Aug 2018 07:56:39 +0000 (09:56 +0200)]
bacula-ferm: we do not need to explicitly allow connections from localhost

5 years agowhitespace fix
Peter Palfrader [Fri, 3 Aug 2018 07:53:12 +0000 (09:53 +0200)]
whitespace fix

5 years agobacula: reorder a statement (should cause no effective change)
Peter Palfrader [Fri, 3 Aug 2018 07:53:05 +0000 (09:53 +0200)]
bacula: reorder a statement (should cause no effective change)

5 years agoadd Forwarded-For header
Peter Palfrader [Tue, 31 Jul 2018 11:15:05 +0000 (13:15 +0200)]
add Forwarded-For header

5 years agowhitespace fixup
Peter Palfrader [Tue, 31 Jul 2018 11:14:51 +0000 (13:14 +0200)]
whitespace fixup

5 years agoadd a ,
Peter Palfrader [Tue, 31 Jul 2018 08:30:10 +0000 (10:30 +0200)]
add a ,

5 years agobacula-fd: listen on both ipv4 and ipv6
Peter Palfrader [Tue, 31 Jul 2018 08:27:18 +0000 (10:27 +0200)]
bacula-fd: listen on both ipv4 and ipv6

5 years agoAdd has_v[46]_ldap key to nodeinfo['misc'] to say whether we have a v[46] address...
Peter Palfrader [Tue, 31 Jul 2018 08:22:15 +0000 (10:22 +0200)]
Add has_v[46]_ldap key to nodeinfo['misc'] to say whether we have a v[46] address in ldap

5 years agoretire old cleanup job for ip6_ munin plugins
Peter Palfrader [Tue, 31 Jul 2018 08:21:18 +0000 (10:21 +0200)]
retire old cleanup job for ip6_ munin plugins

5 years agoMake sure nodeinfo['misc']['v[46]addrs'] always exists, possibly empty.
Peter Palfrader [Tue, 31 Jul 2018 08:19:37 +0000 (10:19 +0200)]
Make sure nodeinfo['misc']['v[46]addrs'] always exists, possibly empty.

5 years agoferm/munin: use already split v[46]addrs for munin addresses
Peter Palfrader [Tue, 31 Jul 2018 08:10:59 +0000 (10:10 +0200)]
ferm/munin: use already split v[46]addrs for munin addresses

5 years agoFix metadata-backend.ftp-master.d.o redirects
Julien Cristau [Tue, 31 Jul 2018 06:34:54 +0000 (08:34 +0200)]
Fix metadata-backend.ftp-master.d.o redirects

5 years agodsa-bacula-scheduler: one more backup slot
Peter Palfrader [Tue, 31 Jul 2018 06:04:18 +0000 (08:04 +0200)]
dsa-bacula-scheduler: one more backup slot

5 years agoMake metadata-backend.ftp-master hopefully work
Julien Cristau [Tue, 31 Jul 2018 05:34:50 +0000 (07:34 +0200)]
Make metadata-backend.ftp-master hopefully work

5 years agoMake metadata-backend its own vhost and move ssl setup there
Julien Cristau [Tue, 31 Jul 2018 05:22:48 +0000 (07:22 +0200)]
Make metadata-backend its own vhost and move ssl setup there

5 years agoAdd metadata-backend.ftp-master.d.o
Julien Cristau [Tue, 31 Jul 2018 05:10:48 +0000 (07:10 +0200)]
Add metadata-backend.ftp-master.d.o

5 years agoAdd ssl to metadata.ftp-master.d.o
Julien Cristau [Tue, 31 Jul 2018 04:39:58 +0000 (06:39 +0200)]
Add ssl to metadata.ftp-master.d.o

5 years agoRevert "Add ssl to metadata.ftp-master.d.o"
Julien Cristau [Tue, 31 Jul 2018 04:45:48 +0000 (06:45 +0200)]
Revert "Add ssl to metadata.ftp-master.d.o"

I'll try again while actually shipping the key/cert.

This reverts commit 5fc26dc04d384d4d6fd687efc9c1b82cdbbb7602.

5 years agoAdd ssl to metadata.ftp-master.d.o
Julien Cristau [Tue, 31 Jul 2018 04:39:58 +0000 (06:39 +0200)]
Add ssl to metadata.ftp-master.d.o

5 years agoAllow codesign on ftphosts to update metadata.ftp-master.debian.org
Tollef Fog Heen [Tue, 31 Jul 2018 04:09:20 +0000 (06:09 +0200)]
Allow codesign on ftphosts to update metadata.ftp-debian.org

5 years agoRT#7368: add additional IP
Martin Zobel-Helas [Sun, 29 Jul 2018 02:40:23 +0000 (04:40 +0200)]
RT#7368: add additional IP

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoallow access to pg on vittoria for dc18
Julien Cristau [Fri, 27 Jul 2018 10:04:24 +0000 (12:04 +0200)]
allow access to pg on vittoria for dc18

RT#7368

5 years agoRedirect old DevRef filenames to the new names
Paul Wise [Wed, 25 Jul 2018 06:31:11 +0000 (14:31 +0800)]
Redirect old DevRef filenames to the new names

Requested-by: Stuart Prescott <stuart@debian.org>
Mapping-by: Stuart Prescott <stuart@debian.org>
5 years agoAlso make setting timezone work on debian 9 (stretch)
Peter Palfrader [Wed, 25 Jul 2018 04:50:46 +0000 (06:50 +0200)]
Also make setting timezone work on debian 9 (stretch)

5 years agoDo not install the redirect vhosts on www-staging.d.o
Paul Wise [Wed, 25 Jul 2018 03:40:15 +0000 (11:40 +0800)]
Do not install the redirect vhosts on www-staging.d.o

5 years agoSet vhost_listen variables required by apache-www.debian.org template
Paul Wise [Wed, 25 Jul 2018 03:33:14 +0000 (11:33 +0800)]
Set vhost_listen variables required by apache-debian.org template

Fixes: commit e9c182207bf901dd7689986fc02e5c4e24c4553a

5 years agoAdd www-staging vhost
Paul Wise [Wed, 25 Jul 2018 03:26:34 +0000 (11:26 +0800)]
Add www-staging vhost

It was broken when the website moved to the static.d.o CDN

5 years agoDebian Policy is moving back to multi-page version, revert redirects
Paul Wise [Wed, 25 Jul 2018 02:00:06 +0000 (10:00 +0800)]
Debian Policy is moving back to multi-page version, revert redirects

Partially reverts commit da0b9ba9ce08cd6040aa84513d9f80b611ed8584

5 years agoonionbalance requires a restart whenever tor is retarted
Peter Palfrader [Mon, 23 Jul 2018 16:09:27 +0000 (18:09 +0200)]
onionbalance requires a restart whenever tor is retarted

This change causes onionbalance to get restarted when tor does,
and so onion services don't got stale.

5 years agoPass the Authorization header through to the WSGI app for the DebConf websites
Nicolas Dandrimont [Mon, 23 Jul 2018 14:30:19 +0000 (22:30 +0800)]
Pass the Authorization header through to the WSGI app for the DebConf websites

5 years agoallow snapshot to reload apache2
Peter Palfrader [Sun, 22 Jul 2018 11:01:44 +0000 (13:01 +0200)]
allow snapshot to reload apache2

5 years agoadd archive-master.debian.org to spec/octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:37:41 +0000 (17:37 +0200)]
add archive-debian.org to spec/octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoadd registry.salsa.debian.org to spec/octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:31:57 +0000 (17:31 +0200)]
add registry.salsa.debian.org to spec/octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoadd /etc/ssh/ssh_known_hosts to octocatalog/init-system
Martin Zobel-Helas [Fri, 20 Jul 2018 15:19:40 +0000 (17:19 +0200)]
add /etc/ssh/ssh_known_hosts to octocatalog/init-system

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoinstall rugged build dependencies in .gitlab-ci.yml
Martin Zobel-Helas [Fri, 20 Jul 2018 15:11:00 +0000 (17:11 +0200)]
install rugged build dependencies in .gitlab-ci.yml

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
5 years agoAdd facts for sibelius.debian.org to octocatalog
Martin Zobel-Helas [Fri, 20 Jul 2018 14:09:24 +0000 (16:09 +0200)]
Add facts for sibelius.debian.org to octocatalog

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>