]> git.donarmstrong.com Git - dsa-puppet.git/blob - modules/buildd/manifests/init.pp
e168abc33354cf6d6e07e768d6458361ca5857fc
[dsa-puppet.git] / modules / buildd / manifests / init.pp
1 class buildd ($ensure=present) {
2
3         include schroot
4
5         package { 'sbuild':
6                 ensure => installed,
7                 tag    => extra_repo,
8         }
9         package { 'libsbuild-perl':
10                 ensure => installed,
11                 tag    => extra_repo,
12                 before => Package['sbuild']
13         }
14
15         package { 'apt-transport-https':
16                 ensure => installed,
17         }
18         if $ensure == present {
19                 package { 'dupload':
20                         ensure => installed,
21                 }
22                 file { '/etc/dupload.conf':
23                         source  => 'puppet:///modules/buildd/dupload.conf',
24                         require => Package['dupload'],
25                 }
26                 site::linux_module { 'dm_snapshot': }
27                 include ferm::ftp_conntrack
28         }
29
30         site::aptrepo { 'buildd':
31                 ensure => absent,
32         }
33
34         $suite = $::lsbdistcodename ? {
35                 squeeze  => $::lsbdistcodename,
36                 wheezy   => $::lsbdistcodename,
37                 jessie   => $::lsbdistcodename,
38                 stretch  => $::lsbdistcodename,
39                 undef   => 'squeeze',
40                 default => 'wheezy'
41         }
42
43         $buildd_apt_main_ensure = $::hostname ? {
44                 /^(schroeder|sompek|stadler)$/ => 'absent',
45                 default => 'present',
46         }
47
48         site::aptrepo { 'buildd.debian.org':
49                 ensure     => $buildd_apt_main_ensure,
50                 key        => 'puppet:///modules/buildd/buildd.debian.org.gpg',
51                 url        => 'https://buildd.debian.org/apt/',
52                 suite      => $suite,
53                 components => 'main',
54                 require    => Package['apt-transport-https'],
55         }
56
57         $buildd_prop_ensure = $::hostname ? {
58                 /^(alkman|zandonai)$/ => 'present',
59                 default => 'absent',
60         }
61
62         if ($::lsbmajdistrelease >= 8) {
63                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
64                         content => "Acquire::https::buildd.debian.org::CaInfo \"/etc/ssl/ca-debian/ca-certificates.crt\";\n",
65                 }
66         } else {
67                 file { '/etc/apt/apt.conf.d/puppet-https-buildd':
68                         content => "Acquire::https::buildd.debian.org::CaInfo \"/etc/ssl/servicecerts/buildd.debian.org.crt\";\n",
69                 }
70         }
71         site::aptrepo { 'buildd.debian.org-proposed':
72                 ensure     => $buildd_prop_ensure,
73                 url        => 'https://buildd.debian.org/apt/',
74                 suite      => "${suite}-proposed",
75                 components => 'main',
76                 require    => [ Package['apt-transport-https'],
77                                 File['/etc/apt/apt.conf.d/puppet-https-buildd'] ],
78         }
79
80         # 'bad' extension
81         file { '/etc/apt/preferences.d/buildd.debian.org':
82                 ensure => absent,
83         }
84         file { '/etc/apt/preferences.d/buildd':
85                 ensure => absent,
86         }
87         file { '/etc/cron.d/dsa-buildd':
88                 source  => 'puppet:///modules/buildd/cron.d-dsa-buildd',
89                 require => Package['debian.org']
90         }
91
92         if ($::lsbmajdistrelease >= 7 and $::kernel == 'Linux') {
93                 package { 'python-psutil':
94                         ensure => installed,
95                 }
96                 if ($::lsbmajdistrelease >= 8) {
97                         file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
98                                 source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill',
99                                 mode    => '0555',
100                         }
101                 } else {
102                         file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
103                                 source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.wheezy',
104                                 mode    => '0555',
105                         }
106                 }
107         } else {
108                 file { '/usr/local/sbin/buildd-schroot-aptitude-kill':
109                         source  => 'puppet:///modules/buildd/buildd-schroot-aptitude-kill.squeeze',
110                         mode    => '0555',
111                 }
112         }
113         file { '/etc/cron.d/puppet-buildd-aptitude':
114                 content => "*/5 * * * * root /usr/local/sbin/buildd-schroot-aptitude-kill\n",
115         }
116
117         if $has_srv_buildd {
118                 file { '/etc/cron.d/puppet-update-buildd-schroots':
119                         content  => "13 21 * * 0 root PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/sbin:/usr/local/bin setup-all-dchroots buildd\n",
120                 }
121         }
122
123         file { '/home/buildd':
124                 ensure  => directory,
125                 mode    => '2755',
126                 group   => buildd,
127                 owner   => buildd,
128         }
129         file { '/home/buildd/build':
130                 ensure  => directory,
131                 mode    => '2750',
132                 group   => buildd,
133                 owner   => buildd,
134         }
135         file { '/home/buildd/logs':
136                 ensure  => directory,
137                 mode    => '2750',
138                 group   => buildd,
139                 owner   => buildd,
140         }
141         file { '/home/buildd/old-logs':
142                 ensure  => directory,
143                 mode    => '2750',
144                 group   => buildd,
145                 owner   => buildd,
146         }
147         file { '/home/buildd/upload-security':
148                 ensure  => directory,
149                 mode    => '2750',
150                 group   => buildd,
151                 owner   => buildd,
152         }
153         file { '/home/buildd/stats':
154                 ensure  => directory,
155                 mode    => '2755',
156                 group   => buildd,
157                 owner   => buildd,
158         }
159         file { '/home/buildd/stats/graphs':
160                 ensure  => directory,
161                 mode    => '2755',
162                 group   => buildd,
163                 owner   => buildd,
164         }
165         file { '/home/buildd/upload':
166                 ensure  => directory,
167                 mode    => '2755',
168                 group   => buildd,
169                 owner   => buildd,
170         }
171         file { '/home/buildd/.forward':
172                 content  => "|/usr/bin/buildd-mail\n",
173                 group   => buildd,
174                 owner   => buildd,
175         }
176
177         if ! $::buildd_key {
178                 exec { 'create-buildd-key':
179                         command => '/bin/su - buildd -c \'mkdir -p -m 02700 .ssh && ssh-keygen -C "`whoami`@`hostname` (`date +%Y-%m-%d`)" -P "" -f .ssh/id_rsa -q\'',
180                         onlyif  => '/usr/bin/getent passwd buildd > /dev/null && ! [ -e /home/buildd/.ssh/id_rsa ]'
181                 }
182         }
183
184
185         if $::buildd_user_exists {
186                 exec { 'add-buildd-user-to-sbuild':
187                         command => 'adduser buildd sbuild',
188                         onlyif  => "getent group sbuild > /dev/null && ! getent group sbuild | grep '\\<buildd\\>' > /dev/null"
189                 }
190         }
191 }