mirror/dsa-puppet.git
8 years agonew function call to find hiera objects
Martin Zobel-Helas [Sat, 18 Mar 2017 12:43:09 +0000 (13:43 +0100)]
new function call to find hiera objects

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
8 years agono more use of Puppet::Parser::Parser
Martin Zobel-Helas [Sat, 18 Mar 2017 11:33:06 +0000 (12:33 +0100)]
no more use of Puppet::Parser::Parser

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
8 years agoadd environmentconf
Martin Zobel-Helas [Fri, 17 Mar 2017 21:49:35 +0000 (22:49 +0100)]
add environmentconf

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
8 years agobuildd.d.o: update archive key
Aurelien Jarno [Tue, 14 Mar 2017 21:23:05 +0000 (22:23 +0100)]
buildd.d.o: update archive key

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoadd dpl.d.o static component
Peter Palfrader [Sun, 12 Mar 2017 13:13:19 +0000 (14:13 +0100)]
add dpl.d.o static component

8 years agoadd dpl.d.o static component
Peter Palfrader [Sun, 12 Mar 2017 13:12:41 +0000 (14:12 +0100)]
add dpl.d.o static component

8 years agoretire glinka
Peter Palfrader [Sat, 11 Mar 2017 20:56:13 +0000 (21:56 +0100)]
retire glinka

8 years agospacing change (and vim modline) for debtags.d.o vhost config
Peter Palfrader [Sat, 11 Mar 2017 18:48:01 +0000 (19:48 +0100)]
spacing change (and vim modline) for debtags.d.o vhost config

8 years agoClean out old watcher pause files automatically
Peter Palfrader [Sat, 11 Mar 2017 09:45:46 +0000 (10:45 +0100)]
Clean out old watcher pause files automatically

8 years agoretire sompek, stadler
Peter Palfrader [Sat, 11 Mar 2017 09:35:30 +0000 (10:35 +0100)]
retire sompek, stadler

8 years agoignore local qemu-efi on acker, aagaard
Peter Palfrader [Sat, 11 Mar 2017 09:34:49 +0000 (10:34 +0100)]
ignore local qemu-efi on acker, aagaard

8 years agoadd missing sudo entry for debsources
Peter Palfrader [Fri, 10 Mar 2017 10:27:32 +0000 (11:27 +0100)]
add missing sudo entry for debsources

8 years agofirefox considers style in .svg things "unsafe-inline" settings, so we need a differe...
Peter Palfrader [Wed, 8 Mar 2017 18:00:44 +0000 (19:00 +0100)]
firefox considers style in .svg things "unsafe-inline" settings, so we need a different CSP for svg files

8 years agoamended policy
Peter Palfrader [Wed, 8 Mar 2017 17:15:59 +0000 (18:15 +0100)]
amended policy

8 years agoSet a CSP for lintian, acked by nthykier
Peter Palfrader [Wed, 8 Mar 2017 17:09:56 +0000 (18:09 +0100)]
Set a CSP for lintian, acked by nthykier

8 years agoSet a bunch of security related headers that might break stuff. We will found out
Peter Palfrader [Wed, 8 Mar 2017 12:26:37 +0000 (13:26 +0100)]
Set a bunch of security related headers that might break stuff.  We will found out

8 years agorename pratchett to headers
Peter Palfrader [Wed, 8 Mar 2017 12:24:17 +0000 (13:24 +0100)]
rename pratchett to headers

8 years agoAdd anycast mirror to sources.list
Peter Palfrader [Mon, 6 Mar 2017 09:21:55 +0000 (10:21 +0100)]
Add anycast mirror to sources.list

8 years agoSet ServerAliveInterval and BatchMode on ssh to backuphost
Peter Palfrader [Fri, 3 Mar 2017 16:12:39 +0000 (17:12 +0100)]
Set ServerAliveInterval and BatchMode on ssh to backuphost

8 years agoremove sudo access on acker for sledge and kibi
Peter Palfrader [Wed, 1 Mar 2017 17:36:27 +0000 (18:36 +0100)]
remove sudo access on acker for sledge and kibi

8 years agovsftp sites need an /srv/ftp, or else anon auth fails
Peter Palfrader [Wed, 1 Mar 2017 17:02:48 +0000 (18:02 +0100)]
vsftp sites need an /srv/ftp, or else anon auth fails

8 years agoFix cluster name for debbugs cluster
Peter Palfrader [Tue, 28 Feb 2017 07:29:25 +0000 (08:29 +0100)]
Fix cluster name for debbugs cluster

8 years agobackup hosts fetch from buxtehude
Peter Palfrader [Mon, 27 Feb 2017 20:49:32 +0000 (21:49 +0100)]
backup hosts fetch from buxtehude

8 years agobackup hosts to buxtehude
Peter Palfrader [Mon, 27 Feb 2017 20:47:08 +0000 (21:47 +0100)]
backup hosts to buxtehude

8 years agobuxtehude needs to pg backup tools
Peter Palfrader [Mon, 27 Feb 2017 20:39:59 +0000 (21:39 +0100)]
buxtehude needs to pg backup tools

8 years agobmdb1 ferm syntax fix
Peter Palfrader [Sun, 26 Feb 2017 21:43:33 +0000 (22:43 +0100)]
bmdb1 ferm syntax fix

8 years agofetch backups from bmdb1:debsources
Peter Palfrader [Sun, 26 Feb 2017 21:42:55 +0000 (22:42 +0100)]
fetch backups from bmdb1:debsources

8 years agofetch backups from melartin
Peter Palfrader [Sun, 26 Feb 2017 21:39:21 +0000 (22:39 +0100)]
fetch backups from melartin

8 years agossh-keygen on pg servers
Peter Palfrader [Sun, 26 Feb 2017 21:36:17 +0000 (22:36 +0100)]
ssh-keygen on pg servers

8 years agoPut the scripts we need for pg backups into puppet
Peter Palfrader [Sun, 26 Feb 2017 21:26:44 +0000 (22:26 +0100)]
Put the scripts we need for pg backups into puppet

8 years agoallow pg access to bmdb1 debsources from backup hosts
Peter Palfrader [Sun, 26 Feb 2017 21:12:12 +0000 (22:12 +0100)]
allow pg access to bmdb1 debsources from backup hosts

8 years agoallow pg access to melartin from backup hosts
Peter Palfrader [Sun, 26 Feb 2017 21:11:02 +0000 (22:11 +0100)]
allow pg access to melartin from backup hosts

8 years agoenable module reqtimeout everywhere
Peter Palfrader [Sun, 26 Feb 2017 18:36:17 +0000 (19:36 +0100)]
enable module reqtimeout everywhere

8 years agoMerge remote-tracking branch 'waldi/syncproxy-security-buildd-pool'
Peter Palfrader [Sun, 26 Feb 2017 17:00:38 +0000 (18:00 +0100)]
Merge remote-tracking branch 'waldi/syncproxy-security-buildd-pool'

* waldi/syncproxy-security-buildd-pool:
  Export debian-security-buildd-pool on syncproxy

8 years agoExport debian-security-buildd-pool on syncproxy
Bastian Blank [Sun, 26 Feb 2017 16:57:01 +0000 (17:57 +0100)]
Export debian-security-buildd-pool on syncproxy

8 years agoRevert "ignore old puppet-common on stretch hosts"
Peter Palfrader [Sun, 26 Feb 2017 08:50:21 +0000 (09:50 +0100)]
Revert "ignore old puppet-common on stretch hosts"

This reverts commit 2c07d5039e8884dfe0d869c5e39dfe2f44dc83c0.

The ignore only works for obsolete packages, not for out of date
packages.

8 years agoignore old puppet-common on stretch hosts
Peter Palfrader [Sun, 26 Feb 2017 08:39:40 +0000 (09:39 +0100)]
ignore old puppet-common on stretch hosts

8 years agofix class name
Peter Palfrader [Sat, 25 Feb 2017 19:54:28 +0000 (20:54 +0100)]
fix class name

8 years agoadd a piuparts slave role
Peter Palfrader [Sat, 25 Feb 2017 19:53:52 +0000 (20:53 +0100)]
add a piuparts slave role

8 years agosome hosts use mpm_prefork
Peter Palfrader [Sat, 25 Feb 2017 17:43:46 +0000 (18:43 +0100)]
some hosts use mpm_prefork

8 years agotimesyncd at ubc
Peter Palfrader [Sat, 25 Feb 2017 17:28:15 +0000 (18:28 +0100)]
timesyncd at ubc

8 years agoAdd piu-slave-ubc-01
Peter Palfrader [Sat, 25 Feb 2017 17:10:09 +0000 (18:10 +0100)]
Add piu-slave-ubc-01

8 years agoAdd storage for piu-slave-ubc-01
Peter Palfrader [Sat, 25 Feb 2017 15:10:06 +0000 (16:10 +0100)]
Add storage for piu-slave-ubc-01

8 years agoUse mpm_worker over mpm_event
Peter Palfrader [Sat, 25 Feb 2017 14:44:54 +0000 (15:44 +0100)]
Use mpm_worker over mpm_event

8 years agonew apache on mirror-conova
Peter Palfrader [Fri, 24 Feb 2017 09:22:08 +0000 (10:22 +0100)]
new apache on mirror-conova

8 years agobackend server aliases for archive, debug, debian, and security
Peter Palfrader [Fri, 24 Feb 2017 09:14:56 +0000 (10:14 +0100)]
backend server aliases for archive, debug, debian, and security

8 years agoAdd mirror-conova to historical_mirror
Peter Palfrader [Fri, 24 Feb 2017 09:09:26 +0000 (10:09 +0100)]
Add mirror-conova to historical_mirror

8 years agofix archive mirror bind magic
Peter Palfrader [Fri, 24 Feb 2017 09:05:00 +0000 (09:05 +0000)]
fix archive mirror bind magic

8 years agoAdd archive rsync to historical_mirror role
Peter Palfrader [Fri, 24 Feb 2017 08:37:43 +0000 (09:37 +0100)]
Add archive rsync to historical_mirror role

8 years agorename boman to mirror-accumu
Peter Palfrader [Thu, 23 Feb 2017 20:04:57 +0000 (21:04 +0100)]
rename boman to mirror-accumu

8 years agomake bytemark a security mirror (for anycast)
Peter Palfrader [Thu, 23 Feb 2017 19:00:54 +0000 (20:00 +0100)]
make bytemark a security mirror (for anycast)

8 years agolisten on anycast address with apache on debian mirrors that are in the bgp group
Peter Palfrader [Thu, 23 Feb 2017 18:38:12 +0000 (18:38 +0000)]
listen on anycast address with apache on debian mirrors that are in the bgp group

8 years agorename bilbao to mirror-bytemark
Peter Palfrader [Thu, 23 Feb 2017 18:31:43 +0000 (19:31 +0100)]
rename bilbao to mirror-bytemark

8 years agolimit ftp to the security address
Peter Palfrader [Thu, 23 Feb 2017 18:12:28 +0000 (19:12 +0100)]
limit ftp to the security address

8 years agono need for the ynic-special lldp module anymore - we put lldp everywhere
Peter Palfrader [Thu, 23 Feb 2017 18:05:06 +0000 (19:05 +0100)]
no need for the ynic-special lldp module anymore - we put lldp everywhere

8 years agofix debian mirror bind addr for ipv6 on klecker
Peter Palfrader [Thu, 23 Feb 2017 17:34:51 +0000 (17:34 +0000)]
fix debian mirror bind addr for ipv6 on klecker

8 years agodebian and security anycast-test addresses
Peter Palfrader [Thu, 23 Feb 2017 17:29:04 +0000 (18:29 +0100)]
debian and security anycast-test addresses

8 years agoadd security.anycast-test server alias, do away with having both testing-anycast...
Peter Palfrader [Thu, 23 Feb 2017 17:27:02 +0000 (18:27 +0100)]
add security.anycast-test server alias, do away with having both testing-anycast and anycast-test

8 years agoRetire poulenc: hardware died
Peter Palfrader [Thu, 23 Feb 2017 17:08:17 +0000 (18:08 +0100)]
Retire poulenc: hardware died

8 years agoadd klecker to debian_mirror_onion
Peter Palfrader [Thu, 23 Feb 2017 16:05:34 +0000 (17:05 +0100)]
add klecker to debian_mirror_onion

8 years agoAdd klecker to the ftp.d.o mirror group now that the fastly live check no longer...
Peter Palfrader [Thu, 23 Feb 2017 16:00:43 +0000 (17:00 +0100)]
Add klecker to the ftp.d.o mirror group now that the fastly live check no longer requires http 200 on GET / (we redirect into /debian/

8 years agoAdd server alias for $location.$archive.backend.mirrors.debian.org
Peter Palfrader [Thu, 23 Feb 2017 15:59:54 +0000 (16:59 +0100)]
Add server alias for $location.$archive.backend.mirrors.debian.org

8 years agotouch /srv/ftp.root/.nobackup
Peter Palfrader [Thu, 23 Feb 2017 15:42:56 +0000 (16:42 +0100)]
touch /srv/ftp.root/.nobackup

8 years agoadd a missing ,
Peter Palfrader [Thu, 23 Feb 2017 15:38:20 +0000 (16:38 +0100)]
add a missing ,

8 years agoconova to debug_mirror
Peter Palfrader [Thu, 23 Feb 2017 15:37:18 +0000 (16:37 +0100)]
conova to debug_mirror

8 years agobind address for security, debug and debian mirror on conova
Peter Palfrader [Thu, 23 Feb 2017 15:37:01 +0000 (16:37 +0100)]
bind address for security, debug and debian mirror on conova

8 years agoconova to security_mirror
Peter Palfrader [Thu, 23 Feb 2017 15:32:27 +0000 (16:32 +0100)]
conova to security_mirror

8 years agoFix a typo in my previous commit
Aurelien Jarno [Thu, 23 Feb 2017 13:46:18 +0000 (14:46 +0100)]
Fix a typo in my previous commit

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agobuildd: make sure the buildd service is disabled and not running
Aurelien Jarno [Thu, 23 Feb 2017 13:38:12 +0000 (14:38 +0100)]
buildd: make sure the buildd service is disabled and not running

This is a leftover init script from the official buildd package, our
setup uses cron to (re)start the build daemon.

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
8 years agoRedirect removed official mirror pages
Paul Wise [Wed, 22 Feb 2017 01:36:27 +0000 (09:36 +0800)]
Redirect removed official mirror pages

8 years agoMake conova be a debian mirror
Peter Palfrader [Tue, 21 Feb 2017 18:42:39 +0000 (19:42 +0100)]
Make conova be a debian mirror

8 years agoadd mirror-conova to the archvsync_base role
Peter Palfrader [Tue, 21 Feb 2017 15:17:22 +0000 (16:17 +0100)]
add mirror-conova to the archvsync_base role

8 years agoMake archvsync_base create the /etc/ssh/userkeys/archvsync symlink
Peter Palfrader [Tue, 21 Feb 2017 15:15:31 +0000 (16:15 +0100)]
Make archvsync_base create the /etc/ssh/userkeys/archvsync symlink

8 years agorestart instead of just start
Peter Palfrader [Sun, 19 Feb 2017 08:15:00 +0000 (09:15 +0100)]
restart instead of just start

8 years agolog requested hostname in www-other.debian.org-access.log
Peter Palfrader [Fri, 17 Feb 2017 12:31:59 +0000 (13:31 +0100)]
log requested hostname in www-other.debian.org-access.log

8 years agoNew inet4 for busoni
Peter Palfrader [Wed, 15 Feb 2017 07:23:31 +0000 (08:23 +0100)]
New inet4 for busoni

8 years agogive syncproxy3.wna a dedicated address
Peter Palfrader [Mon, 13 Feb 2017 19:44:34 +0000 (20:44 +0100)]
give syncproxy3.wna a dedicated address

8 years agoCall it syncproxy3.wna instead, our config does not like to re-use the server's hostn...
Peter Palfrader [Mon, 13 Feb 2017 19:19:51 +0000 (20:19 +0100)]
Call it syncproxy3.wna instead, our config does not like to re-use the server's hostname for a vhost easily

8 years agoremove no longer needed rsync access ferm role - glinka is history and gretchaninov...
Peter Palfrader [Mon, 13 Feb 2017 19:10:54 +0000 (20:10 +0100)]
remove no longer needed rsync access ferm role - glinka is history and gretchaninov is in the syncproxy role

8 years agogretchaninov as a syncproxy
Peter Palfrader [Mon, 13 Feb 2017 19:09:36 +0000 (20:09 +0100)]
gretchaninov as a syncproxy

8 years agoAdd manpages.d.n -> d.o redirect
Peter Palfrader [Mon, 13 Feb 2017 18:19:00 +0000 (19:19 +0100)]
Add manpages.d.n -> d.o redirect

8 years agofix syncproxy http -> https redirect on ipv6
Peter Palfrader [Sun, 12 Feb 2017 17:11:54 +0000 (17:11 +0000)]
fix syncproxy http -> https redirect on ipv6

8 years agofix syncproxy https bind on ipv6 address
Peter Palfrader [Sun, 12 Feb 2017 17:04:18 +0000 (17:04 +0000)]
fix syncproxy https bind on ipv6 address

8 years agosupport limit-mirrors in has_static_component
Peter Palfrader [Sun, 12 Feb 2017 16:36:50 +0000 (17:36 +0100)]
support limit-mirrors in has_static_component

8 years agorename archive-master rsyncd.conf
Peter Palfrader [Sun, 12 Feb 2017 08:39:18 +0000 (09:39 +0100)]
rename archive-master rsyncd.conf

8 years agoAdd lldpd via puppet
Peter Palfrader [Sat, 11 Feb 2017 16:12:02 +0000 (17:12 +0100)]
Add lldpd via puppet

8 years agoadd mirroradm static push sudo
Peter Palfrader [Sat, 11 Feb 2017 13:38:32 +0000 (14:38 +0100)]
add mirroradm static push sudo

8 years agomirror-master static component
Peter Palfrader [Sat, 11 Feb 2017 13:33:06 +0000 (14:33 +0100)]
mirror-master static component

8 years agojust move roles around to group things by service. should be no real changes
Peter Palfrader [Fri, 10 Feb 2017 20:54:51 +0000 (21:54 +0100)]
just move roles around to group things by service.  should be no real changes

8 years agorename archive_master to historical_master to match _mirror name
Peter Palfrader [Fri, 10 Feb 2017 20:52:32 +0000 (21:52 +0100)]
rename archive_master to historical_master to match _mirror name

8 years agoMove archvsync_base from FTP to debian_mirror
Peter Palfrader [Fri, 10 Feb 2017 20:50:55 +0000 (21:50 +0100)]
Move archvsync_base from FTP to debian_mirror

8 years agowe already set the TLSA up in rsync::site_systemd.pp
Peter Palfrader [Fri, 10 Feb 2017 20:47:38 +0000 (21:47 +0100)]
we already set the TLSA up in rsync::site_systemd.pp

8 years agoMerge remote-tracking branch 'waldi/rsync-systemd-master'
Peter Palfrader [Fri, 10 Feb 2017 20:41:07 +0000 (21:41 +0100)]
Merge remote-tracking branch 'waldi/rsync-systemd-master'

* waldi/rsync-systemd-master:
  Use rsyncd via system on security_master
  Use rsyncd via systemd on ftp_master
  Use rsyncd via systemd on archive_master

8 years agolittle /srv/mirrors changes
Peter Palfrader [Fri, 10 Feb 2017 20:36:35 +0000 (21:36 +0100)]
little /srv/mirrors changes

8 years agoMerge remote-tracking branch 'waldi/srv-mirrors'
Peter Palfrader [Fri, 10 Feb 2017 20:35:31 +0000 (21:35 +0100)]
Merge remote-tracking branch 'waldi/srv-mirrors'

* waldi/srv-mirrors:
  Setup /srv/mirrors/debian-security on security_mirror
  Setup /srv/mirrors on all (archvsync-based) mirrors

Conflicts:
modules/roles/manifests/ftp.pp

8 years agoAdd a note to ftp.d.o role to point to debian_mirror
Peter Palfrader [Fri, 10 Feb 2017 20:31:35 +0000 (21:31 +0100)]
Add a note to ftp.d.o role to point to debian_mirror

8 years agoAdd a note to roles::ftp
Peter Palfrader [Fri, 10 Feb 2017 20:30:56 +0000 (21:30 +0100)]
Add a note to roles::ftp

8 years agoSetup /srv/mirrors/debian-security on security_mirror
Bastian Blank [Fri, 10 Feb 2017 20:10:11 +0000 (21:10 +0100)]
Setup /srv/mirrors/debian-security on security_mirror

8 years agoSetup /srv/mirrors on all (archvsync-based) mirrors
Bastian Blank [Fri, 10 Feb 2017 20:06:37 +0000 (21:06 +0100)]
Setup /srv/mirrors on all (archvsync-based) mirrors

8 years agoUse rsyncd via system on security_master
Bastian Blank [Fri, 10 Feb 2017 20:00:58 +0000 (21:00 +0100)]
Use rsyncd via system on security_master