]> git.donarmstrong.com Git - dsa-puppet.git/log
dsa-puppet.git
9 years agoRetire backuphost
Peter Palfrader [Tue, 11 Nov 2014 20:15:21 +0000 (21:15 +0100)]
Retire backuphost

9 years agoremove backuphost volumes
Peter Palfrader [Tue, 11 Nov 2014 20:14:52 +0000 (21:14 +0100)]
remove backuphost volumes

9 years agoremove old portman-srv volume
Peter Palfrader [Tue, 11 Nov 2014 20:01:16 +0000 (21:01 +0100)]
remove old portman-srv volume

9 years agoAdd new temporary coccia-srv2, portman-srv2 devices
Peter Palfrader [Tue, 11 Nov 2014 18:59:54 +0000 (19:59 +0100)]
Add new temporary coccia-srv2, portman-srv2 devices

9 years agono masquerading on rautavaara
Peter Palfrader [Mon, 10 Nov 2014 15:00:51 +0000 (16:00 +0100)]
no masquerading on rautavaara

9 years agoNo more nfs on rautavaara
Peter Palfrader [Mon, 10 Nov 2014 15:00:41 +0000 (16:00 +0100)]
No more nfs on rautavaara

9 years agoRaise HSTS time
Peter Palfrader [Mon, 10 Nov 2014 13:23:27 +0000 (14:23 +0100)]
Raise HSTS time

9 years agoPrint less output when setting up one chroot fails and others succeed.
Paul Wise [Mon, 10 Nov 2014 02:16:49 +0000 (10:16 +0800)]
Print less output when setting up one chroot fails and others succeed.

9 years agofix typo: it's secretfile, not seccretfile
Evgeni Golov [Sun, 9 Nov 2014 14:56:10 +0000 (15:56 +0100)]
fix typo: it's secretfile, not seccretfile

Signed-off-by: Peter Palfrader <peter@palfrader.org>
9 years agoupdate-alternatives is now in usr/bin
Peter Palfrader [Fri, 7 Nov 2014 19:53:11 +0000 (20:53 +0100)]
update-alternatives is now in usr/bin

9 years agowant ruby-filesystem on jessie
Peter Palfrader [Fri, 7 Nov 2014 19:50:28 +0000 (20:50 +0100)]
want ruby-filesystem on jessie

9 years agoRevert "Make it work with jessie, II"
Peter Palfrader [Fri, 7 Nov 2014 19:49:13 +0000 (20:49 +0100)]
Revert "Make it work with jessie, II"

This reverts commit 2d2d25eb5b5c376c5f73551fa11f5acaf866a60d.

9 years agoRevert "Make it work with jessie, III"
Peter Palfrader [Fri, 7 Nov 2014 19:49:07 +0000 (20:49 +0100)]
Revert "Make it work with jessie, III"

This reverts commit 41c40c4a9c30480d08813b55fded8e147718f44f.

9 years agoAdd a second intermediate for gandi
Peter Palfrader [Fri, 7 Nov 2014 15:52:12 +0000 (16:52 +0100)]
Add a second intermediate for gandi

9 years agoAdd text for GANDI-2-CA
Peter Palfrader [Fri, 7 Nov 2014 15:44:47 +0000 (16:44 +0100)]
Add text for GANDI-2-CA

9 years agoAdd text for api.ftp-master.debian.org.crt
Peter Palfrader [Fri, 7 Nov 2014 15:44:17 +0000 (16:44 +0100)]
Add text for api.ftp-master.debian.org.crt

9 years agoreload bind9 from geodnssync using service
Helmut Grohne [Fri, 7 Nov 2014 14:38:28 +0000 (15:38 +0100)]
reload bind9 from geodnssync using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agorestart puppetmaster using service
Helmut Grohne [Fri, 7 Nov 2014 14:38:01 +0000 (15:38 +0100)]
restart puppetmaster using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agostart rc.local using service
Helmut Grohne [Fri, 7 Nov 2014 14:37:42 +0000 (15:37 +0100)]
start rc.local using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agostop monit using service
Helmut Grohne [Fri, 7 Nov 2014 14:36:23 +0000 (15:36 +0100)]
stop monit using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agoreload xinetd using service
Helmut Grohne [Fri, 7 Nov 2014 14:30:30 +0000 (15:30 +0100)]
reload xinetd using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agorestart cron from monit using service
Helmut Grohne [Fri, 7 Nov 2014 14:29:10 +0000 (15:29 +0100)]
restart cron from monit using service

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agoreload samhain using invoke-rc.d
Helmut Grohne [Fri, 7 Nov 2014 14:27:32 +0000 (15:27 +0100)]
reload samhain using invoke-rc.d

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agoreload ulogd using invoke-rc.d
Helmut Grohne [Fri, 7 Nov 2014 14:26:45 +0000 (15:26 +0100)]
reload ulogd using invoke-rc.d

Getting rid of explicit /etc/init.d/ invocations as those may disappear.

Signed-off-by: Helmut Grohne <helmut@subdivi.de>
9 years agoAdd api.ftp-master role
Peter Palfrader [Fri, 7 Nov 2014 15:36:52 +0000 (16:36 +0100)]
Add api.ftp-master role

9 years agoAdd api.ftp-master.debian.org cert, and new gandi intermediate for it
Peter Palfrader [Fri, 7 Nov 2014 15:35:45 +0000 (16:35 +0100)]
Add api.ftp-master.debian.org cert, and new gandi intermediate for it

9 years agoMake it work with jessie, III
Peter Palfrader [Thu, 6 Nov 2014 18:51:36 +0000 (18:51 +0000)]
Make it work with jessie, III

9 years agoMake it work with jessie, II
Peter Palfrader [Thu, 6 Nov 2014 18:43:19 +0000 (18:43 +0000)]
Make it work with jessie, II

9 years agoMake it work with jessie, I
Peter Palfrader [Thu, 6 Nov 2014 17:53:39 +0000 (17:53 +0000)]
Make it work with jessie, I

9 years agofix function name
Peter Palfrader [Thu, 6 Nov 2014 17:00:21 +0000 (18:00 +0100)]
fix function name

9 years agoHandle hosts that are not in ldap yet
Peter Palfrader [Thu, 6 Nov 2014 16:59:33 +0000 (17:59 +0100)]
Handle hosts that are not in ldap yet

9 years agoAdd lindsay
Peter Palfrader [Thu, 6 Nov 2014 16:39:04 +0000 (17:39 +0100)]
Add lindsay

9 years agoAdd mips-aql-01
Peter Palfrader [Tue, 4 Nov 2014 19:25:05 +0000 (20:25 +0100)]
Add mips-aql-01

9 years agoNo backups of ia64-arm-01
Peter Palfrader [Tue, 4 Nov 2014 18:30:56 +0000 (19:30 +0100)]
No backups of ia64-arm-01

9 years agoDecommission rem
Peter Palfrader [Tue, 4 Nov 2014 16:48:06 +0000 (17:48 +0100)]
Decommission rem

9 years agoNo backups for mips-aql-02, please
Peter Palfrader [Tue, 4 Nov 2014 06:08:58 +0000 (07:08 +0100)]
No backups for mips-aql-02, please

9 years agoAdd aql
Peter Palfrader [Mon, 3 Nov 2014 19:55:01 +0000 (20:55 +0100)]
Add aql

9 years agosort broken rtc entries
Peter Palfrader [Mon, 3 Nov 2014 19:23:47 +0000 (20:23 +0100)]
sort broken rtc entries

9 years agomips-aql-02: no/broken RTC
Peter Palfrader [Mon, 3 Nov 2014 19:23:31 +0000 (20:23 +0100)]
mips-aql-02: no/broken RTC

9 years agoMake sure we do not have apt-listchanges
Peter Palfrader [Mon, 3 Nov 2014 07:26:26 +0000 (08:26 +0100)]
Make sure we do not have apt-listchanges

9 years agohowells/hummels: ynic armhf buildd decomission
Héctor Orón Martínez [Thu, 30 Oct 2014 23:53:15 +0000 (00:53 +0100)]
howells/hummels: ynic armhf buildd decomission

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoExclude some FreeBSD-specific filesystems for munin df* plugins
Paul Wise [Tue, 28 Oct 2014 23:21:12 +0000 (07:21 +0800)]
Exclude some FreeBSD-specific filesystems for munin df* plugins

Fixes all kFreeBSD hosts showing problems for the munin df* plugins

Workaround: https://bugs.debian.org/767102
Signed-off-by: Paul Wise <pabs@debian.org>
9 years agoadd more packages to local ignore
Martin Zobel-Helas [Tue, 28 Oct 2014 16:14:36 +0000 (16:14 +0000)]
add more packages to local ignore

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoRevert porterbox fiddlings
Héctor Orón Martínez [Mon, 27 Oct 2014 16:05:57 +0000 (17:05 +0100)]
Revert porterbox fiddlings

9 years agomotd: do not check porterbox class, always included now
Héctor Orón Martínez [Mon, 27 Oct 2014 15:50:43 +0000 (16:50 +0100)]
motd: do not check porterbox class, always included now

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoporterbox: only include schroot when module is present
Héctor Orón Martínez [Mon, 27 Oct 2014 13:13:50 +0000 (14:13 +0100)]
porterbox: only include schroot when module is present

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoroles: drop redundant configuration
Héctor Orón Martínez [Mon, 27 Oct 2014 12:35:48 +0000 (13:35 +0100)]
roles: drop redundant configuration

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoroles: make use of porterbox uninstall features
Héctor Orón Martínez [Mon, 27 Oct 2014 12:03:01 +0000 (13:03 +0100)]
roles: make use of porterbox uninstall features

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoporterbox: allow uninstallation
Héctor Orón Martínez [Mon, 27 Oct 2014 09:44:10 +0000 (10:44 +0100)]
porterbox: allow uninstallation

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoSet the correct syslog-ng version number on hosts with syslog-ng 3.5
Paul Wise [Sun, 26 Oct 2014 05:28:03 +0000 (13:28 +0800)]
Set the correct syslog-ng version number on hosts with syslog-ng 3.5

9 years agoPut da-backup authkeys onto storace
Peter Palfrader [Sat, 25 Oct 2014 21:54:31 +0000 (23:54 +0200)]
Put da-backup authkeys onto storace

9 years agoAllow pg connections from pgbackuphost
Peter Palfrader [Sat, 25 Oct 2014 21:14:26 +0000 (23:14 +0200)]
Allow pg connections from pgbackuphost

9 years agoRemove backuphost.d.o as pg backuphost
Peter Palfrader [Sat, 25 Oct 2014 21:09:18 +0000 (23:09 +0200)]
Remove backuphost.d.o as pg backuphost

9 years agoUse storace as pg backuphost
Peter Palfrader [Sat, 25 Oct 2014 21:05:42 +0000 (23:05 +0200)]
Use storace as pg backuphost

9 years agomake storace a pg backup server
Peter Palfrader [Sat, 25 Oct 2014 20:55:35 +0000 (22:55 +0200)]
make storace a pg backup server

9 years agoMake portforward fact not break due to no config
Peter Palfrader [Sat, 25 Oct 2014 14:33:59 +0000 (14:33 +0000)]
Make portforward fact not break due to no config

9 years agoDisable port forward between danzi and sibelius
Peter Palfrader [Sat, 25 Oct 2014 14:31:39 +0000 (16:31 +0200)]
Disable port forward between danzi and sibelius

9 years agoRT#5423 - give secretary group right to run partly update on vote/
Martin Zobel-Helas [Wed, 22 Oct 2014 12:13:30 +0000 (12:13 +0000)]
RT#5423 - give secretary group right to run partly update on vote/

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoReduce munin-html fork count to the minimum
Paul Wise [Wed, 22 Oct 2014 04:15:19 +0000 (12:15 +0800)]
Reduce munin-html fork count to the minimum

9 years agoarm64: ignore flash-kernel at gw-linaro
Héctor Orón Martínez [Tue, 21 Oct 2014 12:06:36 +0000 (14:06 +0200)]
arm64: ignore flash-kernel at gw-linaro

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoarm64: porterbox is asachi now
Héctor Orón Martínez [Sat, 18 Oct 2014 11:10:38 +0000 (13:10 +0200)]
arm64: porterbox is asachi now

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agono more stabile
Martin Zobel-Helas [Sat, 18 Oct 2014 09:41:06 +0000 (09:41 +0000)]
no more stabile

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoarm64: buildd and porterbox disable backups
Héctor Orón Martínez [Fri, 17 Oct 2014 18:07:26 +0000 (20:07 +0200)]
arm64: buildd and porterbox disable backups

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoporterbox: support arm64 setup
Héctor Orón Martínez [Fri, 17 Oct 2014 17:07:57 +0000 (19:07 +0200)]
porterbox: support arm64 setup

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agosudo: add arm64 porterbox
Héctor Orón Martínez [Thu, 16 Oct 2014 13:31:29 +0000 (15:31 +0200)]
sudo: add arm64 porterbox

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoporterbox: add arm-linaro-01.debian.org to not do backups
Héctor Orón Martínez [Wed, 15 Oct 2014 23:25:20 +0000 (01:25 +0200)]
porterbox: add arm-linaro-01.debian.org to not do backups

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoSet ciphersuites
Peter Palfrader [Tue, 14 Oct 2014 20:58:02 +0000 (22:58 +0200)]
Set ciphersuites

9 years agoapache: disable SSLv3 support
Peter Palfrader [Tue, 14 Oct 2014 19:47:13 +0000 (21:47 +0200)]
apache: disable SSLv3 support

9 years agoUse a more future-proof hostname in git clone dsa-puppet.git.
Paul Wise [Tue, 14 Oct 2014 02:31:23 +0000 (10:31 +0800)]
Use a more future-proof hostname in git clone dsa-puppet.git.

9 years agoShow full error messages when there is a problem restarting stunnel.
Paul Wise [Tue, 14 Oct 2014 02:30:13 +0000 (10:30 +0800)]
Show full error messages when there is a problem restarting stunnel.

9 years agoInclude ftp_conntrack on security_mirror
Julien Cristau [Sun, 12 Oct 2014 16:29:04 +0000 (18:29 +0200)]
Include ftp_conntrack on security_mirror

Signed-off-by: Julien Cristau <jcristau@debian.org>
9 years agoallow traffic to syslog port
Martin Zobel-Helas [Sun, 12 Oct 2014 08:31:34 +0000 (08:31 +0000)]
allow traffic to syslog port

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agostatic push mirror-csail.debian.org
Peter Palfrader [Sun, 12 Oct 2014 07:36:13 +0000 (09:36 +0200)]
static push mirror-csail.debian.org

9 years agofix hostname
Martin Zobel-Helas [Sat, 11 Oct 2014 21:41:39 +0000 (21:41 +0000)]
fix hostname

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agonew loghost loghost-grnet-01
Martin Zobel-Helas [Sat, 11 Oct 2014 21:31:52 +0000 (21:31 +0000)]
new loghost loghost-grnet-01

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoAdd static_mirror_nopush concept
Peter Palfrader [Sat, 11 Oct 2014 10:07:31 +0000 (12:07 +0200)]
Add static_mirror_nopush concept

9 years agoAdd debaday.debian.net
Peter Palfrader [Sat, 11 Oct 2014 09:43:32 +0000 (11:43 +0200)]
Add debaday.debian.net

9 years agoinclude ganeti class on grnet nodes
Peter Palfrader [Fri, 10 Oct 2014 19:17:03 +0000 (21:17 +0200)]
include ganeti class on grnet nodes

9 years agoAdd modules/lvm/files/lvm-grnet-nodeX-ganeti.conf
Peter Palfrader [Fri, 10 Oct 2014 18:57:33 +0000 (20:57 +0200)]
Add modules/lvm/files/lvm-grnet-nodeX-ganeti.conf

9 years agogrnet ganeti hosts
Peter Palfrader [Fri, 10 Oct 2014 18:54:24 +0000 (20:54 +0200)]
grnet ganeti hosts

9 years agoSet debian mirror for grnet
Peter Palfrader [Fri, 10 Oct 2014 15:20:21 +0000 (17:20 +0200)]
Set debian mirror for grnet

9 years agoadd mirror for sanger
Peter Palfrader [Fri, 10 Oct 2014 11:38:23 +0000 (13:38 +0200)]
add mirror for sanger

9 years agoremove mirror-csail from not-bacula-client group
Julien Cristau [Fri, 10 Oct 2014 08:46:27 +0000 (10:46 +0200)]
remove mirror-csail from not-bacula-client group

With .nobackup files in place in the appropriate places, we can haz
backups.

Signed-off-by: Julien Cristau <jcristau@debian.org>
9 years agomirror-csail is a security mirror and doesn't need bacula
Julien Cristau [Thu, 9 Oct 2014 20:32:37 +0000 (22:32 +0200)]
mirror-csail is a security mirror and doesn't need bacula

Signed-off-by: Julien Cristau <jcristau@debian.org>
9 years agoremove rautavaara from entropy_key
Martin Zobel-Helas [Thu, 9 Oct 2014 19:10:41 +0000 (19:10 +0000)]
remove rautavaara from entropy_key

Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
9 years agoMake sure puppet does not mess up our ganeti
Peter Palfrader [Wed, 8 Oct 2014 19:38:59 +0000 (21:38 +0200)]
Make sure puppet does not mess up our ganeti

9 years agoferm: add networks for jcristau
Julien Cristau [Mon, 6 Oct 2014 19:52:08 +0000 (21:52 +0200)]
ferm: add networks for jcristau

Signed-off-by: Julien Cristau <jcristau@debian.org>
9 years agoDebian GNU/Hurd does not support unshare
Paul Wise [Wed, 1 Oct 2014 22:32:04 +0000 (06:32 +0800)]
Debian GNU/Hurd does not support unshare

Requested-in: <CABcaWC3NRq2Wq-RKux62mEYnXu2G01ARz7cTXOx4whjq1V0GcQ@mail.gmail.com>

9 years agoancina: decommision rt#5316
Héctor Orón Martínez [Tue, 30 Sep 2014 10:27:42 +0000 (12:27 +0200)]
ancina: decommision rt#5316

Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
9 years agoReduce munin-html fork count more
Paul Wise [Tue, 30 Sep 2014 06:06:01 +0000 (14:06 +0800)]
Reduce munin-html fork count more

9 years agoHalve the number of munin-html jobs, to prevent OOM errors due to fork count.
Paul Wise [Mon, 29 Sep 2014 04:32:28 +0000 (12:32 +0800)]
Halve the number of munin-html jobs, to prevent OOM errors due to fork count.

Should prevent mails like these:

Cron <munin@menotti> nice /usr/share/munin/munin-html
Killed

Cron <munin@menotti> nice /usr/share/munin/munin-html
fork failed: Cannot allocate memory at /usr/share/perl5/Munin/Master/HTMLOld.pm line 776.

9 years agoPort LastlogTimes object to platforms with a 64-bit lastlog.ll_time
Paul Wise [Mon, 29 Sep 2014 02:50:19 +0000 (10:50 +0800)]
Port LastlogTimes object to platforms with a 64-bit lastlog.ll_time

Fixes this error from merulo, an ia64 machine:

Traceback (most recent call last):
  File "/etc/cron.weekly/puppet-mail-big-homedirs", line 256, in <module>
    HomedirReminder().run()
  File "/etc/cron.weekly/puppet-mail-big-homedirs", line 166, in __init__
    self.lastlog_times = LastlogTimes()
  File "/etc/cron.weekly/puppet-mail-big-homedirs", line 125, in __init__
    lastlog_time, _, _ = list(struct.unpack(self.LASTLOG_STRUCT, record))
struct.error: unpack requires a string argument of length 292

9 years agoSwitch away from ftp.uk
Peter Palfrader [Sun, 28 Sep 2014 17:06:08 +0000 (19:06 +0200)]
Switch away from ftp.uk

9 years agoretire ratelimit bind repo
Peter Palfrader [Thu, 25 Sep 2014 16:44:19 +0000 (18:44 +0200)]
retire ratelimit bind repo

9 years agoAdd a per-suite apt repo from db.do
Peter Palfrader [Thu, 25 Sep 2014 16:30:44 +0000 (18:30 +0200)]
Add a per-suite apt repo from db.do

9 years agoEnable httredir to run everything as httpredir-app
Peter Palfrader [Sun, 21 Sep 2014 20:58:53 +0000 (22:58 +0200)]
Enable httredir to run everything as httpredir-app

9 years agoAllow httpredir role to run some things as httpredir-app
Peter Palfrader [Sun, 21 Sep 2014 17:06:33 +0000 (19:06 +0200)]
Allow httpredir role to run some things as httpredir-app

9 years agoAdd httpredir sudo
Peter Palfrader [Sat, 20 Sep 2014 16:46:17 +0000 (18:46 +0200)]
Add httpredir sudo

9 years agoAdd httpredir-bm-01
Peter Palfrader [Sat, 20 Sep 2014 16:32:54 +0000 (18:32 +0200)]
Add httpredir-bm-01

9 years agoIgnore ganeti-os-noop on powell and bm-bl1 also
Peter Palfrader [Sat, 20 Sep 2014 07:27:28 +0000 (09:27 +0200)]
Ignore ganeti-os-noop on powell and bm-bl1 also