]> git.donarmstrong.com Git - dsa-puppet.git/log
dsa-puppet.git
9 years agoadd memcache to open ports
Stephen Gran [Sun, 7 Sep 2014 15:27:20 +0000 (16:27 +0100)]
add memcache to open ports

Signed-off-by: Stephen Gran <steve@lobefin.net>
9 years agodrop these until it goes away
Stephen Gran [Wed, 3 Sep 2014 18:59:47 +0000 (19:59 +0100)]
drop these until it goes away

Signed-off-by: Stephen Gran <steve@lobefin.net>
9 years agostorace is new bacula storage host
Peter Palfrader [Wed, 3 Sep 2014 14:44:09 +0000 (16:44 +0200)]
storace is new bacula storage host

9 years agochange unicamp mirror
Aurelien Jarno [Fri, 29 Aug 2014 22:58:32 +0000 (00:58 +0200)]
change unicamp mirror

unicamp's mirror has stopped mirroring sources, switch to another close
mirror.

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoSet local_from_check to false to avoid adding Sender header
Tollef Fog Heen [Wed, 27 Aug 2014 02:02:42 +0000 (04:02 +0200)]
Set local_from_check to false to avoid adding Sender header

9 years agosyntax
Peter Palfrader [Sat, 23 Aug 2014 09:51:08 +0000 (11:51 +0200)]
syntax

9 years agoAllow bt ports between static hosts
Peter Palfrader [Sat, 23 Aug 2014 09:47:44 +0000 (11:47 +0200)]
Allow bt ports between static hosts

9 years agomultipath: x86-bm-01 update wwid
Héctor Orón Martínez [Fri, 22 Aug 2014 16:50:09 +0000 (18:50 +0200)]
multipath: x86-bm-01 update wwid

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoupdate arch all buildd hostname
Héctor Orón Martínez [Fri, 22 Aug 2014 16:33:50 +0000 (18:33 +0200)]
update arch all buildd hostname

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agomultipath: replace all-bm-01 by x86-bm-01
Héctor Orón Martínez [Fri, 22 Aug 2014 16:28:46 +0000 (18:28 +0200)]
multipath: replace all-bm-01 by x86-bm-01

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoall-bm-01: no backups
Héctor Orón Martínez [Tue, 19 Aug 2014 23:06:47 +0000 (01:06 +0200)]
all-bm-01: no backups

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoall-bm-01: add multipath for new buildd host for arch:all
Héctor Orón Martínez [Tue, 19 Aug 2014 21:39:49 +0000 (23:39 +0200)]
all-bm-01: add multipath for new buildd host for arch:all

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoSet a debian-mirror for arm
Peter Palfrader [Sun, 17 Aug 2014 08:36:19 +0000 (10:36 +0200)]
Set a debian-mirror for arm

9 years agossl cert: add chain for ports
Héctor Orón Martínez [Fri, 15 Aug 2014 21:25:22 +0000 (23:25 +0200)]
ssl cert: add chain for ports

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agossl cert: add buildd.debian-ports.org.crt
Héctor Orón Martínez [Fri, 15 Aug 2014 21:08:23 +0000 (23:08 +0200)]
ssl cert: add buildd.debian-ports.org.crt

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agod-ports: fixup typo in buildd_ports_master role class
Héctor Orón Martínez [Fri, 15 Aug 2014 18:31:54 +0000 (20:31 +0200)]
d-ports: fixup typo in buildd_ports_master role class

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agod-ports: set apache memlimit
Héctor Orón Martínez [Fri, 15 Aug 2014 18:27:03 +0000 (20:27 +0200)]
d-ports: set apache memlimit

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoFix mirror url
Peter Palfrader [Fri, 15 Aug 2014 17:16:25 +0000 (19:16 +0200)]
Fix mirror url

9 years agoAdd unicamp hoster
Peter Palfrader [Fri, 15 Aug 2014 16:49:02 +0000 (18:49 +0200)]
Add unicamp hoster

9 years agoAvoid backups of powerpc-unicamp-01
Peter Palfrader [Fri, 15 Aug 2014 16:38:43 +0000 (18:38 +0200)]
Avoid backups of powerpc-unicamp-01

9 years agoarm64: add buildds to broken-rtc
Héctor Orón Martínez [Fri, 15 Aug 2014 11:37:39 +0000 (13:37 +0200)]
arm64: add buildds to broken-rtc

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agobacula: exclude arm64 buildd backups
Héctor Orón Martínez [Thu, 14 Aug 2014 17:53:40 +0000 (19:53 +0200)]
bacula: exclude arm64 buildd backups

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoDisable weblog providers and destination as ravel is down and those logs being used...
Peter Palfrader [Thu, 14 Aug 2014 06:54:22 +0000 (06:54 +0000)]
Disable weblog providers and destination as ravel is down and those logs being used is uncertain

9 years agorsyncd-dakmaster.conf: use new location for buildd-debian-dists
Ansgar Burchardt [Wed, 13 Aug 2014 08:29:49 +0000 (10:29 +0200)]
rsyncd-dakmaster.conf: use new location for buildd-debian-dists

We refer to the current live copy in /srv/static.debian.org to avoid
having another (consistent) copy below /srv/ftp-master.debian.org.
Hopefully this doesn't break.

Signed-off-by: Peter Palfrader <peter@palfrader.org>
9 years agorsyncd-dakmaster.conf: drop exports referring to /srv/incoming.d.o/dists
Ansgar Burchardt [Wed, 13 Aug 2014 08:27:06 +0000 (10:27 +0200)]
rsyncd-dakmaster.conf: drop exports referring to /srv/incoming.d.o/dists

/srv/incoming.debian.org/dists did not exist even before the recent
changes to incoming.d.o.

Signed-off-by: Peter Palfrader <peter@palfrader.org>
9 years agonew source path for incoming
Peter Palfrader [Tue, 12 Aug 2014 19:38:21 +0000 (21:38 +0200)]
new source path for incoming

9 years agoSet a debian-mirror for ynic
Peter Palfrader [Tue, 12 Aug 2014 19:05:35 +0000 (21:05 +0200)]
Set a debian-mirror for ynic

9 years agonew source path for incoming
Peter Palfrader [Tue, 12 Aug 2014 18:43:54 +0000 (20:43 +0200)]
new source path for incoming

9 years agoPath for incoming.d.o
Peter Palfrader [Mon, 11 Aug 2014 20:34:50 +0000 (22:34 +0200)]
Path for incoming.d.o

9 years agosudo for dak to static-update-component incoming
Peter Palfrader [Mon, 11 Aug 2014 18:04:26 +0000 (20:04 +0200)]
sudo for dak to static-update-component incoming

9 years agoprepare incoming static-site
Peter Palfrader [Mon, 11 Aug 2014 18:02:57 +0000 (20:02 +0200)]
prepare incoming static-site

9 years agoCreate incoming.debian.org static vhost
Peter Palfrader [Mon, 11 Aug 2014 18:02:27 +0000 (20:02 +0200)]
Create incoming.debian.org static vhost

9 years agoblock nasty 404 spam that is sent to webmaster@debian.org
Martin Zobel-Helas [Thu, 7 Aug 2014 11:15:20 +0000 (13:15 +0200)]
block nasty 404 spam that is sent to webmaster@debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoAdd delaycompress to munin-node logrotate file to reduce cron spam
Tollef Fog Heen [Sun, 27 Jul 2014 20:32:12 +0000 (22:32 +0200)]
Add delaycompress to munin-node logrotate file to reduce cron spam

9 years agomake coccia an ftp upload host
Peter Palfrader [Sun, 27 Jul 2014 19:37:20 +0000 (21:37 +0200)]
make coccia an ftp upload host

9 years agoListen on all port 22s
Peter Palfrader [Sun, 27 Jul 2014 18:27:00 +0000 (20:27 +0200)]
Listen on all port 22s

9 years agolooks like SSH want it this way
Martin Zobel-Helas [Sun, 27 Jul 2014 12:06:53 +0000 (14:06 +0200)]
looks like SSH want it this way

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoAdd extra ports for ssh on paradis
Martin Zobel-Helas [Sun, 27 Jul 2014 12:00:22 +0000 (14:00 +0200)]
Add extra ports for ssh on paradis

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agopeople ssl cert
Martin Zobel-Helas [Sun, 27 Jul 2014 11:12:11 +0000 (13:12 +0200)]
people ssl cert

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agopeople ssl cert
Martin Zobel-Helas [Sun, 27 Jul 2014 11:12:11 +0000 (13:12 +0200)]
people ssl cert

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoadd cert for people.debian.org
Martin Zobel-Helas [Sun, 27 Jul 2014 09:57:52 +0000 (11:57 +0200)]
add cert for people.debian.org

9 years agoSet Surrogate-Key to local host name to make purging obsolete content easier
Tollef Fog Heen [Thu, 24 Jul 2014 20:20:22 +0000 (22:20 +0200)]
Set Surrogate-Key to local host name to make purging obsolete content easier

9 years agoperma redirect and HSTS for lintian
Peter Palfrader [Thu, 24 Jul 2014 05:47:43 +0000 (07:47 +0200)]
perma redirect and HSTS for lintian

9 years agoAdd alioth certs to our cert tree
Peter Palfrader [Wed, 23 Jul 2014 20:34:49 +0000 (22:34 +0200)]
Add alioth certs to our cert tree

9 years agoAdd debian.org.tw
Peter Palfrader [Wed, 23 Jul 2014 09:42:20 +0000 (11:42 +0200)]
Add debian.org.tw

9 years agoKill extra space
Peter Palfrader [Tue, 22 Jul 2014 20:35:49 +0000 (22:35 +0200)]
Kill extra space

9 years agoUpdate the way we populate machine ssh keys for da-backup
Peter Palfrader [Tue, 22 Jul 2014 20:34:12 +0000 (22:34 +0200)]
Update the way we populate machine ssh keys for da-backup

9 years agoMove lintian to https
Peter Palfrader [Tue, 22 Jul 2014 19:42:47 +0000 (21:42 +0200)]
Move lintian to https

9 years agoMake a common-dsa-vhost-https-redirect macro
Peter Palfrader [Tue, 22 Jul 2014 19:41:41 +0000 (21:41 +0200)]
Make a common-dsa-vhost-https-redirect macro

9 years agohsts for bits
Peter Palfrader [Tue, 22 Jul 2014 19:32:47 +0000 (21:32 +0200)]
hsts for bits

9 years agobits.d.o: redirect everything but /feeds to https
Peter Palfrader [Tue, 22 Jul 2014 19:25:58 +0000 (21:25 +0200)]
bits.d.o: redirect everything but /feeds to https

9 years agoMore complex bits.debian.org config
Peter Palfrader [Tue, 22 Jul 2014 19:17:00 +0000 (21:17 +0200)]
More complex bits.debian.org config

9 years agoComment/reorganize static-vhosts-simple
Peter Palfrader [Tue, 22 Jul 2014 19:14:20 +0000 (21:14 +0200)]
Comment/reorganize static-vhosts-simple

9 years agouse privacyssl as the log format in two places
Peter Palfrader [Tue, 22 Jul 2014 19:10:06 +0000 (21:10 +0200)]
use privacyssl as the log format in two places

9 years agoMerge branch 'new-ssl'
Peter Palfrader [Tue, 22 Jul 2014 19:05:13 +0000 (21:05 +0200)]
Merge branch 'new-ssl'

* new-ssl:
  ssl::service for bits and lintian
  Add chains for bits and lintian

9 years agoAdd certs for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 19:05:08 +0000 (21:05 +0200)]
Add certs for bits and lintian

9 years agossl::service for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 17:54:42 +0000 (19:54 +0200)]
ssl::service for bits and lintian

9 years agoAdd chains for bits and lintian
Peter Palfrader [Tue, 22 Jul 2014 17:53:29 +0000 (19:53 +0200)]
Add chains for bits and lintian

9 years agoAdd lintian vhost
Peter Palfrader [Tue, 22 Jul 2014 08:49:54 +0000 (10:49 +0200)]
Add lintian vhost

9 years agolintian can trigger static update component
Peter Palfrader [Tue, 22 Jul 2014 06:59:45 +0000 (08:59 +0200)]
lintian can trigger static update component

9 years agolilburn is a static source
Peter Palfrader [Tue, 22 Jul 2014 06:56:30 +0000 (08:56 +0200)]
lilburn is a static source

9 years agoenable lintian static service (RT#5166)
Peter Palfrader [Mon, 21 Jul 2014 18:39:41 +0000 (20:39 +0200)]
enable lintian static service (RT#5166)

9 years agoAccept tftp from 192.168.43.0/24 on master
Peter Palfrader [Mon, 21 Jul 2014 16:04:24 +0000 (18:04 +0200)]
Accept tftp from 192.168.43.0/24 on master

9 years agoDifferent log rules for http vs. https
Peter Palfrader [Sun, 20 Jul 2014 10:19:12 +0000 (12:19 +0200)]
Different log rules for http vs. https

9 years agorestrict security-master's rsync for the archive, II
Peter Palfrader [Sat, 19 Jul 2014 11:14:22 +0000 (13:14 +0200)]
restrict security-master's rsync for the archive, II

9 years agorestrict security-master's rsync for the archive
Peter Palfrader [Sat, 19 Jul 2014 10:57:14 +0000 (12:57 +0200)]
restrict security-master's rsync for the archive

9 years agoDefault to 3.3 syslog-ng if version is not otherwise handled
Peter Palfrader [Fri, 18 Jul 2014 08:30:42 +0000 (10:30 +0200)]
Default to 3.3 syslog-ng if version is not otherwise handled

9 years agoretire lw05, lw06
Peter Palfrader [Sun, 13 Jul 2014 20:18:53 +0000 (22:18 +0200)]
retire lw05, lw06

9 years agoipv6 fw updates for lw
Peter Palfrader [Sun, 13 Jul 2014 19:51:47 +0000 (21:51 +0200)]
ipv6 fw updates for lw

9 years agonat to varnish on lw07
Peter Palfrader [Sun, 13 Jul 2014 19:21:29 +0000 (21:21 +0200)]
nat to varnish on lw07

9 years agoallow lw07 access to sibelius postgres
Peter Palfrader [Sun, 13 Jul 2014 17:45:05 +0000 (19:45 +0200)]
allow lw07 access to sibelius postgres

9 years agoPrepare to move postgres to lw07
Peter Palfrader [Sun, 13 Jul 2014 12:58:33 +0000 (14:58 +0200)]
Prepare to move postgres to lw07

9 years agoDo not mount qa ro
Peter Palfrader [Sun, 13 Jul 2014 12:10:46 +0000 (14:10 +0200)]
Do not mount qa ro

9 years agoAdd qa.d.o
Peter Palfrader [Sun, 13 Jul 2014 12:07:49 +0000 (14:07 +0200)]
Add qa.d.o

9 years agoset debian mirror for csail
Peter Palfrader [Sun, 13 Jul 2014 07:46:48 +0000 (09:46 +0200)]
set debian mirror for csail

9 years agoautofs on lw0[78]
Peter Palfrader [Sat, 12 Jul 2014 22:21:04 +0000 (00:21 +0200)]
autofs on lw0[78]

9 years agoDifferent srv/build-trees mount on the freebsds
Peter Palfrader [Sat, 12 Jul 2014 22:18:28 +0000 (00:18 +0200)]
Different srv/build-trees mount on the freebsds

9 years agoDisable proposed-updates
Peter Palfrader [Sat, 12 Jul 2014 14:06:08 +0000 (16:06 +0200)]
Disable proposed-updates

9 years agoset HISTCONTROL in root's bashrc. Only set stuff when running interactively
Peter Palfrader [Sat, 12 Jul 2014 11:03:18 +0000 (13:03 +0200)]
set HISTCONTROL in root's bashrc.  Only set stuff when running interactively

9 years agoDeploy /etc/schroot/buildd/fstab via puppet
Peter Palfrader [Sat, 12 Jul 2014 10:35:29 +0000 (12:35 +0200)]
Deploy /etc/schroot/buildd/fstab via puppet

9 years agoRemove /etc/schroot/mount-defaults
Peter Palfrader [Sat, 12 Jul 2014 10:32:16 +0000 (12:32 +0200)]
Remove /etc/schroot/mount-defaults

9 years agoMove some of the porterbox schroot logic to the schroot module that is shared with...
Peter Palfrader [Sat, 12 Jul 2014 09:56:32 +0000 (11:56 +0200)]
Move some of the porterbox schroot logic to the schroot module that is shared with buildd

9 years agoGuard schroot setup scripts with PROFILE = dsa
Peter Palfrader [Sat, 12 Jul 2014 09:37:48 +0000 (11:37 +0200)]
Guard schroot setup scripts with PROFILE = dsa

9 years agoDeploy initial ssh_known_hosts using puppet
Peter Palfrader [Sat, 12 Jul 2014 09:17:34 +0000 (11:17 +0200)]
Deploy initial ssh_known_hosts using puppet

9 years agoTry to work if $::hoster is not yet defined
Peter Palfrader [Sat, 12 Jul 2014 09:02:44 +0000 (09:02 +0000)]
Try to work if $::hoster is not yet defined

9 years agoDo not backup mipsel-manda-*
Peter Palfrader [Sat, 12 Jul 2014 08:56:22 +0000 (10:56 +0200)]
Do not backup mipsel-manda-*

9 years agoadd ip for mfl
Martin Zobel-Helas [Fri, 11 Jul 2014 20:55:58 +0000 (22:55 +0200)]
add ip for mfl

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoRevert "allow mfl to access adayevskaya via ssh"
Martin Zobel-Helas [Fri, 11 Jul 2014 20:51:26 +0000 (22:51 +0200)]
Revert "allow mfl to access adayevskaya via ssh"

This reverts commit 8e8a82b008d3b5845fb96f4e87d9417556b4cf7f.

9 years agoallow mfl to access adayevskaya via ssh
Martin Zobel-Helas [Fri, 11 Jul 2014 20:42:58 +0000 (22:42 +0200)]
allow mfl to access adayevskaya via ssh

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agofix rule
Peter Palfrader [Fri, 11 Jul 2014 19:25:47 +0000 (21:25 +0200)]
fix rule

9 years agofirewall: restrict tftp on abel and jenkins to local networks
Peter Palfrader [Fri, 11 Jul 2014 19:22:16 +0000 (21:22 +0200)]
firewall: restrict tftp on abel and jenkins to local networks

9 years agofirewall: tftp on master, no more tftp on rietz
Peter Palfrader [Fri, 11 Jul 2014 19:21:12 +0000 (21:21 +0200)]
firewall: tftp on master, no more tftp on rietz

9 years agoportman: does not need ssh all buildd
Héctor Orón Martínez [Wed, 9 Jul 2014 11:22:36 +0000 (13:22 +0200)]
portman: does not need ssh all buildd

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoRevert "postgres: add wanna-build-ports in the base backups"
Peter Palfrader [Wed, 9 Jul 2014 06:12:05 +0000 (08:12 +0200)]
Revert "postgres: add wanna-build-ports in the base backups"

This reverts commit fe22b3b8f19a26c1c1d698e17c048f402246d183.

9 years agosudo: add wbadm-ports
Héctor Orón Martínez [Tue, 8 Jul 2014 23:03:05 +0000 (01:03 +0200)]
sudo: add wbadm-ports

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agopostgres: add wanna-build-ports in the base backups
Héctor Orón Martínez [Tue, 8 Jul 2014 23:01:01 +0000 (01:01 +0200)]
postgres: add wanna-build-ports in the base backups

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoferm: update -ports rules
Héctor Orón Martínez [Tue, 8 Jul 2014 22:58:09 +0000 (00:58 +0200)]
ferm: update -ports rules

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agonew wiki.debian.org cert
Martin Zobel-Helas [Tue, 8 Jul 2014 22:12:47 +0000 (00:12 +0200)]
new wiki.debian.org cert

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoonly wheezy and squeeze on ia64
Peter Palfrader [Tue, 8 Jul 2014 18:08:27 +0000 (20:08 +0200)]
only wheezy and squeeze on ia64

9 years agoportman: allow postgress access
Héctor Orón Martínez [Tue, 8 Jul 2014 00:46:37 +0000 (02:46 +0200)]
portman: allow postgress access

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>