]> git.donarmstrong.com Git - dsa-puppet.git/blob - modules/buildd/manifests/init.pp
0390300482f189f655b0dcf8d42f55791c40f1bf
[dsa-puppet.git] / modules / buildd / manifests / init.pp
1 class buildd ($ensure=present) {
2
3         include schroot
4
5         package { 'sbuild':
6                 ensure => installed,
7                 tag    => extra_repo,
8         }
9         package { 'libsbuild-perl':
10                 ensure => installed,
11                 tag    => extra_repo,
12                 before => Package['sbuild']
13         }
14
15         package { 'apt-transport-https':
16                 ensure => installed,
17         }
18         if $ensure == present {
19                 package { 'dupload':
20                         ensure => installed,
21                 }
22                 file { '/etc/dupload.conf':
23                         source  => 'puppet:///modules/buildd/dupload.conf',
24                         require => Package['dupload'],
25                 }
26                 site::linux_module { 'dm_snapshot': }
27                 include ferm::ftp_conntrack
28         }
29
30         site::aptrepo { 'buildd':
31                 ensure => absent,
32         }
33
34         $suite = $::lsbdistcodename ? {
35                 squeeze => $::lsbdistcodename,
36                 wheezy  => $::lsbdistcodename,
37                 undef   => 'squeeze',
38                 default => 'wheezy'
39         }
40
41         site::aptrepo { 'buildd.debian.org':
42                 key        => 'puppet:///modules/buildd/buildd.debian.org.gpg',
43                 url        => 'https://buildd.debian.org/apt/',
44                 suite      => $suite,
45                 components => 'main',
46                 require    => Package['apt-transport-https'],
47         }
48
49         $buildd_prop_ensure = $::hostname ? {
50                 /^(alkman|brahms|porpora|zandonai)$/ => 'present',
51                 default => 'absent',
52         }
53
54         if ($::lsbmajdistrelease >= 8) {
55                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
56                         content => "Acquire::https::buildd.debian.org::CaInfo \"/etc/ssl/ca-debian/ca-certificates.crt\";\n",
57                 }
58         } else {
59                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
60                         content => "Acquire::https::buildd.debian.org::CaInfo \"/etc/ssl/servicecerts/buildd.debian.org.crt\";\n",
61                 }
62         }
63         site::aptrepo { 'buildd.debian.org-proposed':
64                 ensure     => $buildd_prop_ensure,
65                 url        => 'https://buildd.debian.org/apt/',
66                 suite      => "${suite}-proposed",
67                 components => 'main',
68                 require    => [ Package['apt-transport-https'],
69                                 File['/etc/apt/apt.conf.d/puppet-https-buildd'] ],
70         }
71
72         # 'bad' extension
73         file { '/etc/apt/preferences.d/buildd.debian.org':
74                 ensure => absent,
75         }
76         file { '/etc/apt/preferences.d/buildd':
77                 ensure => absent,
78         }
79         file { '/etc/cron.d/dsa-buildd':
80                 source  => 'puppet:///modules/buildd/cron.d-dsa-buildd',
81                 require => Package['debian.org']
82         }
83
84         if ($::lsbmajdistrelease >= 7 and $::kernel == 'Linux') {
85                 package { 'python-psutil':
86                         ensure => installed,
87                 }
88                 if ($::lsbmajdistrelease >= 8) {
89                         file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
90                                 source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill',
91                                 mode    => '0555',
92                         }
93                 } else {
94                         file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
95                                 source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.wheezy',
96                                 mode    => '0555',
97                         }
98                 }
99         } else {
100                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
101                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.squeeze',
102                         mode    => '0555',
103                 }
104         }
105         file { '/etc/cron.d/puppet-buildd-aptitude':
106                 content => "*/5 * * * * root /usr/local/sbin/buildd-schroot-aptitude-kill\n",
107         }
108
109         if $has_srv_buildd {
110                 file { '/etc/cron.d/puppet-update-buildd-schroots':
111                         content  => "13 21 * * 0 root PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin setup-all-dchroots buildd\n",
112                 }
113         }
114
115         file { '/home/buildd':
116                 ensure  => directory,
117                 mode    => '2755',
118                 group   => buildd,
119                 owner   => buildd,
120         }
121         file { '/home/buildd/build':
122                 ensure  => directory,
123                 mode    => '2750',
124                 group   => buildd,
125                 owner   => buildd,
126         }
127         file { '/home/buildd/logs':
128                 ensure  => directory,
129                 mode    => '2750',
130                 group   => buildd,
131                 owner   => buildd,
132         }
133         file { '/home/buildd/old-logs':
134                 ensure  => directory,
135                 mode    => '2750',
136                 group   => buildd,
137                 owner   => buildd,
138         }
139         file { '/home/buildd/upload-security':
140                 ensure  => directory,
141                 mode    => '2750',
142                 group   => buildd,
143                 owner   => buildd,
144         }
145         file { '/home/buildd/stats':
146                 ensure  => directory,
147                 mode    => '2755',
148                 group   => buildd,
149                 owner   => buildd,
150         }
151         file { '/home/buildd/stats/graphs':
152                 ensure  => directory,
153                 mode    => '2755',
154                 group   => buildd,
155                 owner   => buildd,
156         }
157         file { '/home/buildd/upload':
158                 ensure  => directory,
159                 mode    => '2755',
160                 group   => buildd,
161                 owner   => buildd,
162         }
163         file { '/home/buildd/.forward':
164                 content  => "|/usr/bin/buildd-mail\n",
165                 group   => buildd,
166                 owner   => buildd,
167         }
168
169         if ! $::buildd_key {
170                 exec { 'create-buildd-key':
171                         command => '/bin/su - buildd -c \'mkdir -p -m 02700 .ssh && ssh-keygen -C "`whoami`@`hostname` (`date +%Y-%m-%d`)" -P "" -f .ssh/id_rsa -q\'',
172                         onlyif  => '/usr/bin/getent passwd buildd > /dev/null && ! [ -e /home/buildd/.ssh/id_rsa ]'
173                 }
174         }
175
176
177         if $::buildd_user_exists {
178                 exec { 'add-buildd-user-to-sbuild':
179                         command => 'adduser buildd sbuild',
180                         onlyif  => "getent group sbuild > /dev/null && ! getent group sbuild | grep '\\<buildd\\>' > /dev/null"
181                 }
182         }
183 }