]> git.donarmstrong.com Git - dsa-puppet.git/log
dsa-puppet.git
10 years agofix typo
Luca Filipozzi [Fri, 3 Jan 2014 20:57:25 +0000 (20:57 +0000)]
fix typo

10 years agosigh, crucial one character
Stephen Gran [Fri, 3 Jan 2014 19:37:41 +0000 (19:37 +0000)]
sigh, crucial one character

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoclean up Makefile a bit
Stephen Gran [Fri, 3 Jan 2014 19:36:34 +0000 (19:36 +0000)]
clean up Makefile a bit

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoAdd some basic documentation
Stephen Gran [Fri, 3 Jan 2014 19:28:54 +0000 (19:28 +0000)]
Add some basic documentation

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agomanage /etc/ca-certificates.conf because gandi
Luca Filipozzi [Fri, 3 Jan 2014 16:36:56 +0000 (16:36 +0000)]
manage /etc/ca-certificates.conf because gandi

10 years agoRevert "Add a new puppet face"
Stephen Gran [Fri, 3 Jan 2014 15:01:53 +0000 (15:01 +0000)]
Revert "Add a new puppet face"

This reverts commit b75862abf9f8001f671f5fc603ffcfb981797231.

10 years agoAdd a new puppet face
Stephen Gran [Fri, 3 Jan 2014 14:56:14 +0000 (14:56 +0000)]
Add a new puppet face

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agowhitespace cleanup
Stephen Gran [Fri, 3 Jan 2014 12:11:53 +0000 (12:11 +0000)]
whitespace cleanup

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agouse a puppet builtin for this
Stephen Gran [Fri, 3 Jan 2014 12:10:21 +0000 (12:10 +0000)]
use a puppet builtin for this

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agofix regexp
Stephen Gran [Fri, 3 Jan 2014 09:07:32 +0000 (09:07 +0000)]
fix regexp

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agomove over dns_primary/seconday
Stephen Gran [Thu, 2 Jan 2014 22:40:04 +0000 (22:40 +0000)]
move over dns_primary/seconday

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoThis comes from LDAP
Stephen Gran [Thu, 2 Jan 2014 22:26:39 +0000 (22:26 +0000)]
This comes from LDAP

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoIn ruby, this must be an array
Stephen Gran [Thu, 2 Jan 2014 22:16:13 +0000 (22:16 +0000)]
In ruby, this must be an array

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agotry this on
Stephen Gran [Thu, 2 Jan 2014 21:58:52 +0000 (21:58 +0000)]
try this on

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agomove more to roles
Stephen Gran [Thu, 2 Jan 2014 21:37:23 +0000 (21:37 +0000)]
move more to roles

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agotemplate breakage
Stephen Gran [Thu, 2 Jan 2014 21:33:26 +0000 (21:33 +0000)]
template breakage

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agotry to fix nagios template
Stephen Gran [Thu, 2 Jan 2014 20:17:19 +0000 (20:17 +0000)]
try to fix nagios template

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agowe are passed a string
Stephen Gran [Thu, 2 Jan 2014 19:55:19 +0000 (19:55 +0000)]
we are passed a string

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agopuppet math is primitive
Stephen Gran [Thu, 2 Jan 2014 19:54:54 +0000 (19:54 +0000)]
puppet math is primitive

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agotry to fix errors
Stephen Gran [Thu, 2 Jan 2014 19:52:10 +0000 (19:52 +0000)]
try to fix errors

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoA chain for www
Peter Palfrader [Thu, 2 Jan 2014 18:12:01 +0000 (19:12 +0100)]
A chain for www

10 years agoMore workarounds
Tollef Fog Heen [Thu, 2 Jan 2014 18:07:39 +0000 (19:07 +0100)]
More workarounds

10 years agoMake denis an extra nrpe client
Peter Palfrader [Thu, 2 Jan 2014 17:57:26 +0000 (18:57 +0100)]
Make denis an extra nrpe client

10 years agoMore workarounds
Tollef Fog Heen [Thu, 2 Jan 2014 17:56:07 +0000 (18:56 +0100)]
More workarounds

10 years agoerr, not error. Maybe
Tollef Fog Heen [Thu, 2 Jan 2014 17:53:57 +0000 (18:53 +0100)]
err, not error.  Maybe

10 years agoMore workarounds
Tollef Fog Heen [Thu, 2 Jan 2014 17:49:34 +0000 (18:49 +0100)]
More workarounds

10 years agoAdd workaround for buildd not being a real role yet
Tollef Fog Heen [Thu, 2 Jan 2014 17:47:12 +0000 (18:47 +0100)]
Add workaround for buildd not being a real role yet

10 years agoLog error rather than exploding unhelpfully
Tollef Fog Heen [Thu, 2 Jan 2014 17:44:31 +0000 (18:44 +0100)]
Log error rather than exploding unhelpfully

10 years agoRuby is not python
Tollef Fog Heen [Thu, 2 Jan 2014 17:39:15 +0000 (18:39 +0100)]
Ruby is not python

10 years agoSimply exim config slightly by checking for roles in manifest
Tollef Fog Heen [Thu, 2 Jan 2014 17:22:58 +0000 (18:22 +0100)]
Simply exim config slightly by checking for roles in manifest

10 years agoMove all roles from local.yaml to hiera
Tollef Fog Heen [Wed, 1 Jan 2014 15:12:14 +0000 (16:12 +0100)]
Move all roles from local.yaml to hiera

Hopefully this won't break anything.

10 years agoAnd put the ssl cert out
Peter Palfrader [Wed, 1 Jan 2014 21:58:40 +0000 (22:58 +0100)]
And put the ssl cert out

10 years agoTry new www vhost config
Peter Palfrader [Wed, 1 Jan 2014 21:55:40 +0000 (22:55 +0100)]
Try new www vhost config

10 years agoMove volatile vhost from www to static
Peter Palfrader [Wed, 1 Jan 2014 21:53:42 +0000 (22:53 +0100)]
Move volatile vhost from www to static

10 years agoChecking for classes in templates is not reliable
Peter Palfrader [Wed, 1 Jan 2014 21:08:45 +0000 (21:08 +0000)]
Checking for classes in templates is not reliable

10 years agono RRL on the primary
Peter Palfrader [Wed, 1 Jan 2014 21:00:23 +0000 (22:00 +0100)]
no RRL on the primary

10 years agomaybe these firewall rules are better
Peter Palfrader [Wed, 1 Jan 2014 20:58:49 +0000 (21:58 +0100)]
maybe these firewall rules are better

10 years agoremove another hardcoding of hostnames
Peter Palfrader [Wed, 1 Jan 2014 20:45:52 +0000 (21:45 +0100)]
remove another hardcoding of hostnames

10 years agosyntax fix
Peter Palfrader [Wed, 1 Jan 2014 20:43:12 +0000 (20:43 +0000)]
syntax fix

10 years agotry to rolify dns
Peter Palfrader [Wed, 1 Jan 2014 20:41:15 +0000 (21:41 +0100)]
try to rolify dns

10 years agomaster is now denis
Peter Palfrader [Wed, 1 Jan 2014 20:29:32 +0000 (21:29 +0100)]
master is now denis

10 years agonew way to update zones
Peter Palfrader [Wed, 1 Jan 2014 20:29:26 +0000 (21:29 +0100)]
new way to update zones

10 years agoput release cert onto franck - we have no release service yet
Peter Palfrader [Wed, 1 Jan 2014 19:56:42 +0000 (20:56 +0100)]
put release cert onto franck - we have no release service yet

10 years agoput nagios cert onto nagios host by role
Peter Palfrader [Wed, 1 Jan 2014 19:55:08 +0000 (20:55 +0100)]
put nagios cert onto nagios host by role

10 years agoadd nagios.debian.org
Martin Zobel-Helas [Wed, 1 Jan 2014 19:51:18 +0000 (20:51 +0100)]
add nagios.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd nagios.debian.org and release.debian.org
Martin Zobel-Helas [Wed, 1 Jan 2014 19:45:12 +0000 (20:45 +0100)]
add nagios.debian.org and release.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd ftp-master.debian.org
Martin Zobel-Helas [Wed, 1 Jan 2014 19:41:26 +0000 (20:41 +0100)]
add ftp-master.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoremove zappa
Peter Palfrader [Wed, 1 Jan 2014 17:52:32 +0000 (18:52 +0100)]
remove zappa

10 years agoUse submission for mail to zani
Peter Palfrader [Wed, 1 Jan 2014 17:52:06 +0000 (18:52 +0100)]
Use submission for mail to zani

10 years agoAdd vhost_listen_443
Peter Palfrader [Wed, 1 Jan 2014 16:20:25 +0000 (17:20 +0100)]
Add vhost_listen_443

10 years agoTry to enable ssl for dsa.d.o
Peter Palfrader [Wed, 1 Jan 2014 16:14:56 +0000 (17:14 +0100)]
Try to enable ssl for dsa.d.o

10 years agodsa.d.o cert on static mirrors
Peter Palfrader [Wed, 1 Jan 2014 16:07:06 +0000 (17:07 +0100)]
dsa.d.o cert on static mirrors

10 years agoMove dsa.d.o to static
Peter Palfrader [Wed, 1 Jan 2014 15:55:38 +0000 (16:55 +0100)]
Move dsa.d.o to static

10 years agoMove dsa.d.o to static
Peter Palfrader [Wed, 1 Jan 2014 15:55:06 +0000 (16:55 +0100)]
Move dsa.d.o to static

10 years agodeploy db.d.o cert
Peter Palfrader [Wed, 1 Jan 2014 15:26:07 +0000 (16:26 +0100)]
deploy db.d.o cert

10 years agoadd munin.debian.org
Martin Zobel-Helas [Wed, 1 Jan 2014 15:03:58 +0000 (16:03 +0100)]
add munin.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd dsa.debian.org
Martin Zobel-Helas [Wed, 1 Jan 2014 15:02:28 +0000 (16:02 +0100)]
add dsa.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd db.debian.oradd db.debian.orgg
Martin Zobel-Helas [Wed, 1 Jan 2014 15:00:11 +0000 (16:00 +0100)]
add db.debian.oradd db.debian.orgg

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoUse fqdn, not hostname
Tollef Fog Heen [Wed, 1 Jan 2014 14:51:11 +0000 (15:51 +0100)]
Use fqdn, not hostname

10 years agoHiera does not know how to look up anything but top-level values
Tollef Fog Heen [Wed, 1 Jan 2014 14:48:31 +0000 (15:48 +0100)]
Hiera does not know how to look up anything but top-level values

10 years agoStart moving bits from local.yaml to hiera
Tollef Fog Heen [Wed, 1 Jan 2014 14:27:33 +0000 (15:27 +0100)]
Start moving bits from local.yaml to hiera

10 years agodo not do backups of /var/log/apache2/
Martin Zobel-Helas [Wed, 1 Jan 2014 11:53:54 +0000 (12:53 +0100)]
do not do backups of /var/log/apache2/

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoonly set sts header if mod headers is loaded
Peter Palfrader [Wed, 1 Jan 2014 11:01:20 +0000 (12:01 +0100)]
only set sts header if mod headers is loaded

10 years agoenable mod headers everywhere
Peter Palfrader [Wed, 1 Jan 2014 10:59:35 +0000 (11:59 +0100)]
enable mod headers everywhere

10 years agoAdd SSL related apache macros
Peter Palfrader [Wed, 1 Jan 2014 10:54:40 +0000 (11:54 +0100)]
Add SSL related apache macros

10 years agoRemove sites-available/common-ssl.inc
Peter Palfrader [Wed, 1 Jan 2014 10:46:08 +0000 (11:46 +0100)]
Remove sites-available/common-ssl.inc

10 years agoinstall mod-macro everywhere
Peter Palfrader [Wed, 1 Jan 2014 10:44:10 +0000 (11:44 +0100)]
install mod-macro everywhere

10 years agoTell bad apt where to find its certificate
Peter Palfrader [Wed, 1 Jan 2014 10:23:45 +0000 (10:23 +0000)]
Tell bad apt where to find its certificate

10 years agoadd more servicecerts
Martin Zobel-Helas [Wed, 1 Jan 2014 10:02:32 +0000 (11:02 +0100)]
add more servicecerts

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd sso.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 22:27:25 +0000 (23:27 +0100)]
add sso.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd rt.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 21:59:17 +0000 (22:59 +0100)]
add rt.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agomake cron be quiet
Stephen Gran [Tue, 31 Dec 2013 16:32:50 +0000 (16:32 +0000)]
make cron be quiet

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoadd nm.debian.org and contributors.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 15:18:43 +0000 (16:18 +0100)]
add nm.debian.org and contributors.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agotry this
Martin Zobel-Helas [Tue, 31 Dec 2013 15:09:50 +0000 (16:09 +0100)]
try this

10 years agoadd buildd.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 15:07:13 +0000 (16:07 +0100)]
add buildd.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd security-tracker.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 14:53:00 +0000 (15:53 +0100)]
add security-tracker.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd symlink
Martin Zobel-Helas [Tue, 31 Dec 2013 14:44:08 +0000 (15:44 +0100)]
add symlink

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoremove symlink
Martin Zobel-Helas [Tue, 31 Dec 2013 14:43:37 +0000 (15:43 +0100)]
remove symlink

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd buildd.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 14:33:32 +0000 (15:33 +0100)]
add buildd.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoclass documentation
Stephen Gran [Tue, 31 Dec 2013 09:14:16 +0000 (09:14 +0000)]
class documentation

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agowe do not want that check
Stephen Gran [Tue, 31 Dec 2013 09:12:30 +0000 (09:12 +0000)]
we do not want that check

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agorelax permissions for mxes
Stephen Gran [Tue, 31 Dec 2013 09:10:52 +0000 (09:10 +0000)]
relax permissions for mxes

Signed-off-by: Stephen Gran <steve@lobefin.net>
10 years agoadd new cert for udd.debian.org
Martin Zobel-Helas [Tue, 31 Dec 2013 07:58:33 +0000 (08:58 +0100)]
add new cert for udd.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agodo not run an authority on draghi
Peter Palfrader [Mon, 30 Dec 2013 22:56:00 +0000 (23:56 +0100)]
do not run an authority on draghi

10 years agoadayevskaya can ssh into denis
Peter Palfrader [Mon, 30 Dec 2013 22:43:39 +0000 (23:43 +0100)]
adayevskaya can ssh into denis

10 years agowe also want text version in that file
Martin Zobel-Helas [Mon, 30 Dec 2013 22:40:25 +0000 (23:40 +0100)]
we also want text version in that file

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd service lists.debian.org
Martin Zobel-Helas [Mon, 30 Dec 2013 22:35:21 +0000 (23:35 +0100)]
add service lists.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agoadd new cert for lists.debian.org
Martin Zobel-Helas [Mon, 30 Dec 2013 22:30:11 +0000 (23:30 +0100)]
add new cert for lists.debian.org

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
10 years agodenis is now the primary
Peter Palfrader [Mon, 30 Dec 2013 22:22:57 +0000 (23:22 +0100)]
denis is now the primary

10 years agoUse different tsig alg
Peter Palfrader [Mon, 30 Dec 2013 22:05:12 +0000 (22:05 +0000)]
Use different tsig alg

10 years agoNotify bind9 on puppet-shared-keys update
Peter Palfrader [Mon, 30 Dec 2013 21:58:43 +0000 (21:58 +0000)]
Notify bind9 on puppet-shared-keys update

10 years agoinclude named.conf.puppet-shared-keys
Peter Palfrader [Mon, 30 Dec 2013 21:51:16 +0000 (22:51 +0100)]
include named.conf.puppet-shared-keys

10 years agofix named.conf.puppet-shared-keys
Peter Palfrader [Mon, 30 Dec 2013 21:46:47 +0000 (21:46 +0000)]
fix named.conf.puppet-shared-keys

10 years agoTry to create shared keys using puppet
Peter Palfrader [Mon, 30 Dec 2013 21:34:43 +0000 (22:34 +0100)]
Try to create shared keys using puppet

10 years agoAllow ssh to adayevskaya from all debian.org hosts
Peter Palfrader [Mon, 30 Dec 2013 18:57:36 +0000 (19:57 +0100)]
Allow ssh to adayevskaya from all debian.org hosts

10 years agomoar ssh authorized-keys files
Peter Palfrader [Mon, 30 Dec 2013 18:55:15 +0000 (19:55 +0100)]
moar ssh authorized-keys files

10 years agoDo not backup zani
Peter Palfrader [Sun, 29 Dec 2013 22:04:56 +0000 (23:04 +0100)]
Do not backup zani

10 years agoCut down retention periods significantly
Peter Palfrader [Sun, 29 Dec 2013 21:51:27 +0000 (22:51 +0100)]
Cut down retention periods significantly

10 years agoAdd zani dedication
Peter Palfrader [Sun, 29 Dec 2013 21:38:32 +0000 (22:38 +0100)]
Add zani dedication

10 years agosigh, get the package right
Stephen Gran [Sun, 29 Dec 2013 18:46:34 +0000 (18:46 +0000)]
sigh, get the package right

Signed-off-by: Stephen Gran <steve@lobefin.net>