]> git.openstreetmap.org Git - chef.git/log
chef.git
8 months agoRelax evasive limits some more
Tom Hughes [Mon, 11 Mar 2024 21:27:37 +0000 (21:27 +0000)]
Relax evasive limits some more

8 months agoMake evasive configuration work
Tom Hughes [Mon, 11 Mar 2024 20:13:00 +0000 (20:13 +0000)]
Make evasive configuration work

8 months agoPass bantime and findtime to jail config correctly
Tom Hughes [Mon, 11 Mar 2024 19:18:32 +0000 (19:18 +0000)]
Pass bantime and findtime to jail config correctly

8 months agoReduce look back for forbidden request jail
Tom Hughes [Mon, 11 Mar 2024 19:12:03 +0000 (19:12 +0000)]
Reduce look back for forbidden request jail

8 months agoRelax site count limit for evasive
Tom Hughes [Mon, 11 Mar 2024 18:20:56 +0000 (18:20 +0000)]
Relax site count limit for evasive

8 months agoRelax page count limit for evasive
Tom Hughes [Mon, 11 Mar 2024 17:48:37 +0000 (17:48 +0000)]
Relax page count limit for evasive

8 months agoActively disable mod_evasive when necessary
Tom Hughes [Mon, 11 Mar 2024 17:41:32 +0000 (17:41 +0000)]
Actively disable mod_evasive when necessary

8 months agoDisable mod_evasive for prometheus
Tom Hughes [Mon, 11 Mar 2024 17:39:18 +0000 (17:39 +0000)]
Disable mod_evasive for prometheus

8 months agoUse fail2ban to block IPs getting repeated HTTP forbidden responses
Tom Hughes [Mon, 11 Mar 2024 17:30:03 +0000 (17:30 +0000)]
Use fail2ban to block IPs getting repeated HTTP forbidden responses

8 months agoEnable mod_evasive for all apache instances except render servers
Tom Hughes [Mon, 11 Mar 2024 17:15:10 +0000 (17:15 +0000)]
Enable mod_evasive for all apache instances except render servers

8 months agoDrop unused attribute
Tom Hughes [Mon, 11 Mar 2024 17:18:16 +0000 (17:18 +0000)]
Drop unused attribute

8 months agoAdd an alert for mysql connection errors
Tom Hughes [Mon, 11 Mar 2024 08:40:10 +0000 (08:40 +0000)]
Add an alert for mysql connection errors

8 months agoIncrease mysql connection limit for the wiki
Tom Hughes [Mon, 11 Mar 2024 08:27:44 +0000 (08:27 +0000)]
Increase mysql connection limit for the wiki

8 months agoRemove ifupdown to stop it trying to manage the network
Tom Hughes [Sun, 10 Mar 2024 21:06:38 +0000 (21:06 +0000)]
Remove ifupdown to stop it trying to manage the network

8 months agomailman: automate year match code
Grant Slater [Sun, 10 Mar 2024 20:20:20 +0000 (20:20 +0000)]
mailman: automate year match code

8 months agoapache: fix combined_extended compatibility with Ubuntu 20.04
Grant Slater [Sun, 10 Mar 2024 20:15:25 +0000 (20:15 +0000)]
apache: fix combined_extended compatibility with Ubuntu 20.04

8 months agoapache: use new combined_extended log format instead of combined
Grant Slater [Sun, 10 Mar 2024 19:49:49 +0000 (19:49 +0000)]
apache: use new combined_extended log format instead of combined

8 months agoRemove gorwen DNS and DHCP
Grant Slater [Sun, 10 Mar 2024 19:45:12 +0000 (19:45 +0000)]
Remove gorwen DNS and DHCP

8 months agowiki: Delay abusive scrapers
Grant Slater [Sun, 10 Mar 2024 15:37:16 +0000 (15:37 +0000)]
wiki: Delay abusive scrapers

8 months agoIncrease size of php-fpm pool for the main wiki
Tom Hughes [Sun, 10 Mar 2024 13:46:40 +0000 (13:46 +0000)]
Increase size of php-fpm pool for the main wiki

8 months agoDrop separate secure logs for mediawiki instances
Tom Hughes [Sun, 10 Mar 2024 13:44:45 +0000 (13:44 +0000)]
Drop separate secure logs for mediawiki instances

8 months agoDefine an extended log format for apachae requests
Tom Hughes [Sun, 10 Mar 2024 13:42:46 +0000 (13:42 +0000)]
Define an extended log format for apachae requests

Adds the request time and SSL details to the standard combined format.

8 months agomediawiki: add apache request duration logging
Grant Slater [Sun, 10 Mar 2024 13:07:01 +0000 (13:07 +0000)]
mediawiki: add apache request duration logging

8 months agowiki: remove outdated file
Grant Slater [Sun, 10 Mar 2024 13:06:25 +0000 (13:06 +0000)]
wiki: remove outdated file

8 months agoTry 307 redirect instead of 308
Guillaume RISCHARD [Fri, 8 Mar 2024 23:02:48 +0000 (18:02 -0500)]
Try 307 redirect instead of 308

8 months agoDrop cleanup code
Tom Hughes [Fri, 8 Mar 2024 09:31:49 +0000 (09:31 +0000)]
Drop cleanup code

8 months agoDelete mediawiki link refresh service and timer
Tom Hughes [Fri, 8 Mar 2024 09:26:07 +0000 (09:26 +0000)]
Delete mediawiki link refresh service and timer

8 months agoDisable mediawiki link refresh job on all wikis
Tom Hughes [Fri, 8 Mar 2024 09:16:05 +0000 (09:16 +0000)]
Disable mediawiki link refresh job on all wikis

8 months agoDrop role for gorwen
Tom Hughes [Thu, 7 Mar 2024 22:06:11 +0000 (22:06 +0000)]
Drop role for gorwen

8 months agoDrop user_tokens table
Tom Hughes [Thu, 7 Mar 2024 17:47:57 +0000 (17:47 +0000)]
Drop user_tokens table

8 months agoosqa: block login access and conditional posts
Grant Slater [Thu, 7 Mar 2024 11:45:54 +0000 (11:45 +0000)]
osqa: block login access and conditional posts

8 months agoplanet: always set cors header
Grant Slater [Thu, 7 Mar 2024 11:08:40 +0000 (11:08 +0000)]
planet: always set cors header

Always set CORS header to ensure the header is also set on redirects.

Fixes: https://github.com/openstreetmap/operations/issues/1038
Signed-off-by: Grant Slater <github@firefishy.com>
8 months agoUse 308 redirect to keep IDN POST parameters
Guillaume Rischard [Wed, 6 Mar 2024 23:53:42 +0000 (18:53 -0500)]
Use 308 redirect to keep IDN POST parameters

With many thanks to @MegaphoneJon for the precious help!

8 months agoEnable hardware watchdog support on more machines
Tom Hughes [Tue, 5 Mar 2024 10:35:44 +0000 (10:35 +0000)]
Enable hardware watchdog support on more machines

8 months agoEnable hardware watchdog on HP machines
Tom Hughes [Mon, 4 Mar 2024 19:18:27 +0000 (19:18 +0000)]
Enable hardware watchdog on HP machines

8 months agooverpass: update to newest version
Sarah Hoffmann [Mon, 4 Mar 2024 14:44:12 +0000 (15:44 +0100)]
overpass: update to newest version

Also avoid failing import script when systemd scripts not yet enabled.

8 months agoAdd overpass-query role to grisu
Tom Hughes [Mon, 4 Mar 2024 08:16:46 +0000 (08:16 +0000)]
Add overpass-query role to grisu

8 months agoDisable registration of OAuth 1 clients
Tom Hughes [Fri, 1 Mar 2024 08:15:58 +0000 (08:15 +0000)]
Disable registration of OAuth 1 clients

8 months agoAdd Yandex to imagery blacklist
Tom Hughes [Tue, 20 Feb 2024 20:46:34 +0000 (20:46 +0000)]
Add Yandex to imagery blacklist

8 months agonominatim: disable luajit
Sarah Hoffmann [Mon, 19 Feb 2024 09:35:43 +0000 (10:35 +0100)]
nominatim: disable luajit

Something is potentially buggy with luajit and causes data loss.

9 months agoUpdate chef client to 18.4.2
Tom Hughes [Wed, 14 Feb 2024 21:43:05 +0000 (21:43 +0000)]
Update chef client to 18.4.2

9 months agoDisable OAuth 1.0 support
Tom Hughes [Thu, 8 Feb 2024 20:01:10 +0000 (20:01 +0000)]
Disable OAuth 1.0 support

9 months agoMerge remote-tracking branch 'github/pull/649'
Tom Hughes [Wed, 7 Feb 2024 11:43:45 +0000 (11:43 +0000)]
Merge remote-tracking branch 'github/pull/649'

9 months agobuild(deps): bump cookstyle from 7.32.2 to 7.32.8
dependabot[bot] [Wed, 7 Feb 2024 11:41:08 +0000 (11:41 +0000)]
build(deps): bump cookstyle from 7.32.2 to 7.32.8

Bumps [cookstyle](https://github.com/chef/cookstyle) from 7.32.2 to 7.32.8.
- [Release notes](https://github.com/chef/cookstyle/releases)
- [Changelog](https://github.com/chef/cookstyle/blob/main/CHANGELOG.md)
- [Commits](https://github.com/chef/cookstyle/compare/v7.32.2...v7.32.8)

---
updated-dependencies:
- dependency-name: cookstyle
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
9 months agoCivicrm extension update
Guillaume RISCHARD [Sat, 3 Feb 2024 15:36:25 +0000 (10:36 -0500)]
Civicrm extension update

9 months agoCivicrm core version bump
Guillaume RISCHARD [Sat, 3 Feb 2024 00:25:01 +0000 (19:25 -0500)]
Civicrm core version bump

9 months agoEnable rate limiting for dev cgimap instances
Tom Hughes [Wed, 31 Jan 2024 15:37:41 +0000 (15:37 +0000)]
Enable rate limiting for dev cgimap instances

9 months agoAdd a test instance for the login/signup rework
Tom Hughes [Fri, 26 Jan 2024 12:36:28 +0000 (12:36 +0000)]
Add a test instance for the login/signup rework

9 months agoExtend search period and ban time for trackpoint jail
Tom Hughes [Wed, 24 Jan 2024 09:33:10 +0000 (09:33 +0000)]
Extend search period and ban time for trackpoint jail

9 months agoAdd fail2ban block for repeated timeouts on the trackpoints API call
Tom Hughes [Wed, 24 Jan 2024 08:31:24 +0000 (08:31 +0000)]
Add fail2ban block for repeated timeouts on the trackpoints API call

9 months agoFix active query alerts
Tom Hughes [Wed, 24 Jan 2024 08:23:41 +0000 (08:23 +0000)]
Fix active query alerts

9 months agoDrop duplicate replication lag alert
Tom Hughes [Tue, 23 Jan 2024 09:10:10 +0000 (09:10 +0000)]
Drop duplicate replication lag alert

9 months agoAdd alerts for high numbers of active queries on the main database
Tom Hughes [Tue, 23 Jan 2024 09:09:38 +0000 (09:09 +0000)]
Add alerts for high numbers of active queries on the main database

9 months agoDrop redundant alert that does nothing
Tom Hughes [Tue, 23 Jan 2024 08:56:21 +0000 (08:56 +0000)]
Drop redundant alert that does nothing

9 months agoTighten timeouts and log request timeouts
Tom Hughes [Thu, 18 Jan 2024 12:21:35 +0000 (12:21 +0000)]
Tighten timeouts and log request timeouts

9 months agoimagery: workaround account issue in tests
Grant Slater [Mon, 15 Jan 2024 17:12:50 +0000 (17:12 +0000)]
imagery: workaround account issue in tests

10 months agoMove yearly reindex to start a day earlier
Tom Hughes [Mon, 15 Jan 2024 09:51:12 +0000 (09:51 +0000)]
Move yearly reindex to start a day earlier

10 months agoimagery: tiler env var tweaks
Grant Slater [Sat, 13 Jan 2024 21:30:07 +0000 (21:30 +0000)]
imagery: tiler env var tweaks

10 months agodns: upgrade dnscontrol to 4.8.1
Grant Slater [Thu, 11 Jan 2024 14:03:21 +0000 (14:03 +0000)]
dns: upgrade dnscontrol to 4.8.1

10 months agoRevert "Disable login with facebook"
Tom Hughes [Thu, 11 Jan 2024 09:27:24 +0000 (09:27 +0000)]
Revert "Disable login with facebook"

This reverts commit 31e786d715dbb4599a129f5e3bbfdda7c1c54cbb.

10 months agoDisable login with facebook
Tom Hughes [Wed, 10 Jan 2024 14:14:05 +0000 (14:14 +0000)]
Disable login with facebook

10 months agoimagery: add forwarded header
Grant Slater [Wed, 10 Jan 2024 11:37:37 +0000 (11:37 +0000)]
imagery: add forwarded header

10 months agoimagery: fix proto headers
Grant Slater [Wed, 10 Jan 2024 11:35:22 +0000 (11:35 +0000)]
imagery: fix proto headers

10 months agoUpgrade the DeviceFeatureWebGL matomo plugin to 5.0.0
Tom Hughes [Wed, 10 Jan 2024 08:38:59 +0000 (08:38 +0000)]
Upgrade the DeviceFeatureWebGL matomo plugin to 5.0.0

10 months agoFix restarting of cgimap after updates on the dev server
Tom Hughes [Tue, 9 Jan 2024 19:05:18 +0000 (19:05 +0000)]
Fix restarting of cgimap after updates on the dev server

10 months agoUpdate matomo to 5.0.1
Tom Hughes [Tue, 9 Jan 2024 19:00:50 +0000 (19:00 +0000)]
Update matomo to 5.0.1

10 months agoimagery: increase threads for tiler
Grant Slater [Tue, 9 Jan 2024 18:59:25 +0000 (18:59 +0000)]
imagery: increase threads for tiler

10 months agoimagery: fix titiler API root
Grant Slater [Tue, 9 Jan 2024 18:43:16 +0000 (18:43 +0000)]
imagery: fix titiler API root

10 months agoimagery: tiler proxy_redirect off
Grant Slater [Tue, 9 Jan 2024 18:24:57 +0000 (18:24 +0000)]
imagery: tiler proxy_redirect off

10 months agoimagery: move tiler api url
Grant Slater [Tue, 9 Jan 2024 18:06:26 +0000 (18:06 +0000)]
imagery: move tiler api url

10 months agolint fix on ironbelly role
Grant Slater [Tue, 9 Jan 2024 18:06:08 +0000 (18:06 +0000)]
lint fix on ironbelly role

10 months agoimagery: fixes for host and https
Grant Slater [Tue, 9 Jan 2024 17:36:58 +0000 (17:36 +0000)]
imagery: fixes for host and https

10 months agoApply imagery::tiler to ironbelly
Grant Slater [Tue, 9 Jan 2024 16:55:38 +0000 (16:55 +0000)]
Apply imagery::tiler to ironbelly

10 months agoimager: add tiler cookbook
Grant Slater [Tue, 9 Jan 2024 16:54:30 +0000 (16:54 +0000)]
imager: add tiler cookbook

10 months agoAdd a connection rate limit to the web frontends
Tom Hughes [Tue, 9 Jan 2024 12:26:28 +0000 (12:26 +0000)]
Add a connection rate limit to the web frontends

10 months agocommunity: bump to 3.1.4 release
Grant Slater [Tue, 9 Jan 2024 07:47:20 +0000 (07:47 +0000)]
community: bump to 3.1.4 release

10 months agoUpdate matomo to 4.16.0
Tom Hughes [Mon, 8 Jan 2024 20:34:44 +0000 (20:34 +0000)]
Update matomo to 4.16.0

10 months agoUse cmake to build cgimap on the dev server
Tom Hughes [Sun, 7 Jan 2024 19:53:08 +0000 (19:53 +0000)]
Use cmake to build cgimap on the dev server

10 months agoUse all frontends for processing rails message mail
Tom Hughes [Sat, 6 Jan 2024 11:16:18 +0000 (11:16 +0000)]
Use all frontends for processing rails message mail

10 months agoPreserve case of local part for rails message delivery
Tom Hughes [Sat, 6 Jan 2024 11:15:06 +0000 (11:15 +0000)]
Preserve case of local part for rails message delivery

https://github.com/openstreetmap/operations/issues/1017

10 months agoMinor wordsmithing
Guillaume Rischard [Thu, 4 Jan 2024 00:01:01 +0000 (19:01 -0500)]
Minor wordsmithing

10 months agonominatim: need to fetch tags on source code update
Sarah Hoffmann [Tue, 2 Jan 2024 16:50:33 +0000 (17:50 +0100)]
nominatim: need to fetch tags on source code update

10 months agocivicrm: use correct donotsendreportemail extension to repo
Grant Slater [Fri, 29 Dec 2023 23:42:21 +0000 (23:42 +0000)]
civicrm: use correct donotsendreportemail extension to repo

10 months agoplanet: add notes S3 redirect
Grant Slater [Sat, 23 Dec 2023 15:53:49 +0000 (15:53 +0000)]
planet: add notes S3 redirect

10 months agonominatim: make deploy tag the default mode of checkout
Sarah Hoffmann [Sat, 23 Dec 2023 08:36:57 +0000 (09:36 +0100)]
nominatim: make deploy tag the default mode of checkout

10 months agonominatim: deploy code from a tag
Sarah Hoffmann [Fri, 22 Dec 2023 16:20:46 +0000 (17:20 +0100)]
nominatim: deploy code from a tag

10 months agoSpecify timezone for OSUOSL as US/Pacific
Tom Hughes [Fri, 22 Dec 2023 10:18:21 +0000 (10:18 +0000)]
Specify timezone for OSUOSL as US/Pacific

10 months agoSet timezone for servers in us-east-2
Tom Hughes [Fri, 22 Dec 2023 10:17:59 +0000 (10:17 +0000)]
Set timezone for servers in us-east-2

10 months agoRemove unused teraswitch role
Tom Hughes [Fri, 22 Dec 2023 10:17:21 +0000 (10:17 +0000)]
Remove unused teraswitch role

10 months agoDrop memory constraint on low zoom render threads
Tom Hughes [Thu, 21 Dec 2023 18:34:53 +0000 (18:34 +0000)]
Drop memory constraint on low zoom render threads

10 months agoSet a timeout for the DNS rebuild service
Tom Hughes [Thu, 21 Dec 2023 10:14:42 +0000 (10:14 +0000)]
Set a timeout for the DNS rebuild service

10 months agoRun the low zoom render every day
Tom Hughes [Wed, 20 Dec 2023 20:40:38 +0000 (20:40 +0000)]
Run the low zoom render every day

10 months agoAdd mincore to allowed system calls for renderd
Tom Hughes [Wed, 20 Dec 2023 20:15:30 +0000 (20:15 +0000)]
Add mincore to allowed system calls for renderd

10 months agoAdd user_mutes to monthly reindex
Tom Hughes [Wed, 20 Dec 2023 20:11:11 +0000 (20:11 +0000)]
Add user_mutes to monthly reindex

10 months agoGrant access to user_mutes table
Tom Hughes [Wed, 20 Dec 2023 19:47:17 +0000 (19:47 +0000)]
Grant access to user_mutes table

10 months agoRelax system call filter for renderd
Tom Hughes [Wed, 20 Dec 2023 19:45:05 +0000 (19:45 +0000)]
Relax system call filter for renderd

10 months agoPreload libtcmalloc for renderd
Tom Hughes [Wed, 20 Dec 2023 19:31:21 +0000 (19:31 +0000)]
Preload libtcmalloc for renderd

10 months agoimagery: add missing include_recipe
Grant Slater [Wed, 20 Dec 2023 01:24:33 +0000 (01:24 +0000)]
imagery: add missing include_recipe

10 months agopodman: add environment variable support
Grant Slater [Wed, 20 Dec 2023 01:22:41 +0000 (01:22 +0000)]
podman: add environment variable support

10 months agoRevert "render: Run lowzoom daily"
Grant Slater [Tue, 19 Dec 2023 00:10:57 +0000 (00:10 +0000)]
Revert "render: Run lowzoom daily"

This reverts commit c19f837a25a957d444db9e5946249a15e1caed5b.