]> git.openstreetmap.org Git - chef.git/log
chef.git
2 hours agoBlackhole unreachable Amazon IPv6 block on equinix machines master
Tom Hughes [Sat, 27 Apr 2024 10:12:50 +0000 (11:12 +0100)]
Blackhole unreachable Amazon IPv6 block on equinix machines

47 hours agoblogs: fix build in test
Grant Slater [Thu, 25 Apr 2024 13:48:09 +0000 (14:48 +0100)]
blogs: fix build in test

2 days agootrs: Add otrs::debian for installing otrs via deb package
Grant Slater [Thu, 18 Apr 2024 15:22:17 +0000 (16:22 +0100)]
otrs: Add otrs::debian for installing otrs via deb package

2 days agoblogs: fix bundler install run as blogs user
Grant Slater [Thu, 25 Apr 2024 11:11:39 +0000 (12:11 +0100)]
blogs: fix bundler install run as blogs user

2 days agontp: fix undeclared prometheus dependency
Grant Slater [Thu, 25 Apr 2024 09:48:43 +0000 (10:48 +0100)]
ntp: fix undeclared prometheus dependency

2 days agosystemd-networkd-wait-online waiting for timeout in dokken
Grant Slater [Wed, 24 Apr 2024 16:21:26 +0000 (17:21 +0100)]
systemd-networkd-wait-online waiting for timeout in dokken

2 days agoUse fully resolved libeatmydata.so in ld.so.preload
Grant Slater [Wed, 24 Apr 2024 16:08:22 +0000 (17:08 +0100)]
Use fully resolved libeatmydata.so in ld.so.preload

3 days agoUpdate authorized_keys
Altilunium [Tue, 23 Apr 2024 22:10:56 +0000 (05:10 +0700)]
Update authorized_keys

3 days agoAllow wordpress themes to be installed from zip
Guillaume Rischard [Tue, 23 Apr 2024 21:06:10 +0000 (17:06 -0400)]
Allow wordpress themes to be installed from zip

3 days agoadd rtnf ssh key
Grant Slater [Tue, 23 Apr 2024 16:26:22 +0000 (17:26 +0100)]
add rtnf ssh key

3 days agoEnable rtnf on dev
Grant Slater [Tue, 23 Apr 2024 16:23:06 +0000 (17:23 +0100)]
Enable rtnf on dev

3 days agoStop zip theme being unpacked every time chef runs
Guillaume Rischard [Tue, 23 Apr 2024 15:55:10 +0000 (11:55 -0400)]
Stop zip theme being unpacked every time chef runs

3 days agodisable blog-staging recipe during dev
Grant Slater [Tue, 23 Apr 2024 15:10:11 +0000 (16:10 +0100)]
disable blog-staging recipe during dev

3 days agobless mikel as admin on fume
Grant Slater [Tue, 23 Apr 2024 15:06:35 +0000 (16:06 +0100)]
bless mikel as admin on fume

3 days agofix wordpress role membership on fume
Grant Slater [Tue, 23 Apr 2024 15:00:23 +0000 (16:00 +0100)]
fix wordpress role membership on fume

3 days agoenable mikel on fume
Grant Slater [Tue, 23 Apr 2024 14:54:16 +0000 (15:54 +0100)]
enable mikel on fume

4 days agodevices: add initramfs-tools dependency
Grant Slater [Mon, 22 Apr 2024 16:52:49 +0000 (17:52 +0100)]
devices: add initramfs-tools dependency

4 days agoAllow wordpress themes to be installed from zip
Guillaume Rischard [Mon, 22 Apr 2024 22:09:42 +0000 (18:09 -0400)]
Allow wordpress themes to be installed from zip

4 days agowordpress: add additional required packages
Grant Slater [Mon, 22 Apr 2024 14:09:40 +0000 (15:09 +0100)]
wordpress: add additional required packages

Requirements are listed here: https://make.wordpress.org/hosting/handbook/server-environment/

4 days agoblog: add staging clone
Grant Slater [Mon, 22 Apr 2024 13:42:09 +0000 (14:42 +0100)]
blog: add staging clone

5 days agodevices: fix style issue
Grant Slater [Mon, 22 Apr 2024 12:57:27 +0000 (13:57 +0100)]
devices: fix style issue

6 days agoDrop roundingPeriod from cloudwatch exporter configuration
Tom Hughes [Sun, 21 Apr 2024 06:39:52 +0000 (07:39 +0100)]
Drop roundingPeriod from cloudwatch exporter configuration

7 days agodevices: enable nvme.poll_queues if supported
Grant Slater [Fri, 19 Apr 2024 14:11:41 +0000 (15:11 +0100)]
devices: enable nvme.poll_queues if supported

9 days agonominatim: UI forwarding should take precedence to blocking
Sarah Hoffmann [Thu, 18 Apr 2024 08:00:52 +0000 (10:00 +0200)]
nominatim: UI forwarding should take precedence to blocking

9 days agoremove fragments of old civicrm-staging
Grant Slater [Thu, 18 Apr 2024 03:40:41 +0000 (04:40 +0100)]
remove fragments of old civicrm-staging

9 days agoapt: enable backports on debian
Grant Slater [Thu, 18 Apr 2024 03:37:46 +0000 (04:37 +0100)]
apt: enable backports on debian

9 days agonominatim: update Python dependencies
Sarah Hoffmann [Wed, 17 Apr 2024 19:07:02 +0000 (21:07 +0200)]
nominatim: update Python dependencies

2 weeks agoosqa: remove search, replaced with duckduckgo iframe
Grant Slater [Wed, 10 Apr 2024 17:04:27 +0000 (18:04 +0100)]
osqa: remove search, replaced with duckduckgo iframe

2 weeks agoosqa: disable contact form
Grant Slater [Wed, 10 Apr 2024 16:07:45 +0000 (17:07 +0100)]
osqa: disable contact form

2 weeks agoMerge remote-tracking branch 'github/pull/656'
Tom Hughes [Tue, 9 Apr 2024 12:23:17 +0000 (13:23 +0100)]
Merge remote-tracking branch 'github/pull/656'

2 weeks agobuild(deps): bump kitchen-dokken from 2.20.3 to 2.20.4
dependabot[bot] [Tue, 9 Apr 2024 11:20:19 +0000 (11:20 +0000)]
build(deps): bump kitchen-dokken from 2.20.3 to 2.20.4

Bumps [kitchen-dokken](https://github.com/test-kitchen/kitchen-dokken) from 2.20.3 to 2.20.4.
- [Release notes](https://github.com/test-kitchen/kitchen-dokken/releases)
- [Changelog](https://github.com/test-kitchen/kitchen-dokken/blob/main/CHANGELOG.md)
- [Commits](https://github.com/test-kitchen/kitchen-dokken/compare/v2.20.3...v2.20.4)

---
updated-dependencies:
- dependency-name: kitchen-dokken
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2 weeks agoUpdate configuration of nodesource repo
Tom Hughes [Sun, 7 Apr 2024 14:17:03 +0000 (15:17 +0100)]
Update configuration of nodesource repo

2 weeks agoUpdate Node.js to the 20.x branch
Tom Hughes [Sun, 7 Apr 2024 13:38:43 +0000 (14:38 +0100)]
Update Node.js to the 20.x branch

3 weeks agoModernise mod_perl installation
Tom Hughes [Fri, 5 Apr 2024 15:43:53 +0000 (16:43 +0100)]
Modernise mod_perl installation

3 weeks agootrs: ensure SetPermissions.pl and daemon restart happen in correct order
Grant Slater [Fri, 5 Apr 2024 15:36:45 +0000 (16:36 +0100)]
otrs: ensure SetPermissions.pl and daemon restart happen in correct order

3 weeks agootrs: enable all required apache modules
Grant Slater [Fri, 5 Apr 2024 14:56:25 +0000 (15:56 +0100)]
otrs: enable all required apache modules

3 weeks agootrs: Add additional packages as required by deb
Grant Slater [Fri, 5 Apr 2024 14:55:12 +0000 (15:55 +0100)]
otrs: Add additional packages as required by deb

3 weeks agoDrop cleanup code
Tom Hughes [Thu, 4 Apr 2024 17:13:21 +0000 (18:13 +0100)]
Drop cleanup code

3 weeks agoMerge remote-tracking branch 'github/pull/655'
Tom Hughes [Thu, 4 Apr 2024 17:03:42 +0000 (18:03 +0100)]
Merge remote-tracking branch 'github/pull/655'

3 weeks agootrs: upgrade to latest znuny 6.0.x release
Grant Slater [Wed, 3 Apr 2024 21:27:38 +0000 (22:27 +0100)]
otrs: upgrade to latest znuny 6.0.x release

znuny only supports upgrading one minor version at a time.
Future upgrades will be 6.0.x -> 6.1.x -> 6.2.x etc

Signed-off-by: Grant Slater <github@firefishy.com>
3 weeks agoimagery: retry proxy errors
Grant Slater [Wed, 3 Apr 2024 16:08:49 +0000 (17:08 +0100)]
imagery: retry proxy errors

3 weeks agoimagery: fix url typo
Grant Slater [Wed, 3 Apr 2024 15:45:07 +0000 (16:45 +0100)]
imagery: fix url typo

3 weeks agoimagery: switch to file:// based mosaic for ZA
Grant Slater [Wed, 3 Apr 2024 15:44:05 +0000 (16:44 +0100)]
imagery: switch to file:// based mosaic for ZA

3 weeks agoimagery: increase nginx keepalive again
Grant Slater [Tue, 2 Apr 2024 16:57:35 +0000 (17:57 +0100)]
imagery: increase nginx keepalive again

3 weeks agoimagery: switch to volume mount for imagery
Grant Slater [Tue, 2 Apr 2024 16:55:41 +0000 (17:55 +0100)]
imagery: switch to volume mount for imagery

3 weeks agopodman: add volume support
Grant Slater [Tue, 2 Apr 2024 16:54:01 +0000 (17:54 +0100)]
podman: add volume support

3 weeks agoimagery: use gz mosaic directly
Grant Slater [Tue, 2 Apr 2024 13:36:20 +0000 (14:36 +0100)]
imagery: use gz mosaic directly

3 weeks agoimager: tune timeout and lower titiler workers
Grant Slater [Tue, 2 Apr 2024 13:31:52 +0000 (14:31 +0100)]
imager: tune timeout and lower titiler workers

3 weeks agoimagery: attempt to make tile serving more resilient to errors
Grant Slater [Tue, 2 Apr 2024 13:12:20 +0000 (14:12 +0100)]
imagery: attempt to make tile serving more resilient to errors

3 weeks agoRevert "nominatim: improve IP query block expression"
Sarah Hoffmann [Tue, 2 Apr 2024 09:59:43 +0000 (11:59 +0200)]
Revert "nominatim: improve IP query block expression"

This reverts commit 6beb17e095d006393405d9882fb762837df78588.

3 weeks agonominatim: improve IP query block expression
Sarah Hoffmann [Tue, 2 Apr 2024 09:52:04 +0000 (11:52 +0200)]
nominatim: improve IP query block expression

3 weeks agonominatim: update taginfo description
Sarah Hoffmann [Mon, 1 Apr 2024 13:10:52 +0000 (15:10 +0200)]
nominatim: update taginfo description

4 weeks agoDon't look for md arrays if the driver isn't loaded
Tom Hughes [Fri, 29 Mar 2024 00:05:16 +0000 (00:05 +0000)]
Don't look for md arrays if the driver isn't loaded

4 weeks agoremove ftp role from angor
Grant Slater [Thu, 28 Mar 2024 22:11:20 +0000 (22:11 +0000)]
remove ftp role from angor

4 weeks agoremove draco
Grant Slater [Thu, 28 Mar 2024 12:27:24 +0000 (12:27 +0000)]
remove draco

4 weeks agoimagery: increase http2 max concurrent streams
Grant Slater [Wed, 27 Mar 2024 19:34:25 +0000 (19:34 +0000)]
imagery: increase http2 max concurrent streams

4 weeks agoimagery: fix regex to only match os_sv png formats
Grant Slater [Wed, 27 Mar 2024 17:58:19 +0000 (17:58 +0000)]
imagery: fix regex to only match os_sv png formats

4 weeks agoRevert "imagery: workaround OS imagery custom formats"
Grant Slater [Wed, 27 Mar 2024 17:50:10 +0000 (17:50 +0000)]
Revert "imagery: workaround OS imagery custom formats"

This reverts commit b0bf79fd8052f90360efd8e093c83cc03c38696a.

4 weeks agoimagery: workaround OS imagery custom formats
Grant Slater [Wed, 27 Mar 2024 17:44:39 +0000 (17:44 +0000)]
imagery: workaround OS imagery custom formats

4 weeks agoDrop role for draco
Tom Hughes [Wed, 27 Mar 2024 17:38:18 +0000 (17:38 +0000)]
Drop role for draco

4 weeks agoimagery: escape layer name in js
Grant Slater [Wed, 27 Mar 2024 17:25:09 +0000 (17:25 +0000)]
imagery: escape layer name in js

4 weeks agoimagery: enable nginx cache correctly
Grant Slater [Wed, 27 Mar 2024 17:13:06 +0000 (17:13 +0000)]
imagery: enable nginx cache correctly

4 weeks agoimager: fix string quote
Grant Slater [Wed, 27 Mar 2024 17:06:21 +0000 (17:06 +0000)]
imager: fix string quote

4 weeks agoimagery: add za_ngi_aerial using tiler
Grant Slater [Wed, 27 Mar 2024 16:17:30 +0000 (16:17 +0000)]
imagery: add za_ngi_aerial using tiler

4 weeks agonominatim: remove referer block on details again
Sarah Hoffmann [Wed, 27 Mar 2024 13:13:25 +0000 (14:13 +0100)]
nominatim: remove referer block on details again

4 weeks agonominatim: refuse to geocode IP addresses
Sarah Hoffmann [Wed, 27 Mar 2024 10:32:23 +0000 (11:32 +0100)]
nominatim: refuse to geocode IP addresses

4 weeks agoaccount: update ligfietser ssh key
Grant Slater [Wed, 27 Mar 2024 12:47:01 +0000 (12:47 +0000)]
account: update ligfietser ssh key

Close: https://github.com/openstreetmap/operations/issues/1044

Signed-off-by: Grant Slater <github@firefishy.com>
4 weeks agoimagery: improve tiler caching and keepalive
Grant Slater [Tue, 26 Mar 2024 20:56:17 +0000 (20:56 +0000)]
imagery: improve tiler caching and keepalive

4 weeks agopodman: revert to using default slirp4netns mtu
Grant Slater [Tue, 26 Mar 2024 20:48:04 +0000 (20:48 +0000)]
podman: revert to using default slirp4netns mtu

4 weeks agotests: move imagery-tiler to only test on debian
Grant Slater [Tue, 26 Mar 2024 20:40:11 +0000 (20:40 +0000)]
tests: move imagery-tiler to only test on debian

podman on ubuntu 22.04 unresolved race condition start up bugs.
The version in debian 12 is reliable. In production the container starts
up successfully after a few tries, but this behaviour breaks tests.

Signed-off-by: Grant Slater <github@firefishy.com>
4 weeks agodev: sort users list
Grant Slater [Tue, 26 Mar 2024 20:24:24 +0000 (20:24 +0000)]
dev: sort users list

4 weeks agodev: activate ligfietser
Grant Slater [Tue, 26 Mar 2024 20:22:17 +0000 (20:22 +0000)]
dev: activate ligfietser

4 weeks agonominatim: disallow details requests without referer
Sarah Hoffmann [Tue, 26 Mar 2024 19:47:44 +0000 (20:47 +0100)]
nominatim: disallow details requests without referer

4 weeks agoInstall libbrotli-dev on the dev server
Tom Hughes [Mon, 25 Mar 2024 21:47:40 +0000 (21:47 +0000)]
Install libbrotli-dev on the dev server

5 weeks agoUpdate bundle
Tom Hughes [Wed, 20 Mar 2024 18:36:20 +0000 (18:36 +0000)]
Update bundle

5 weeks agoTry and detaint messages.openstreetmap.org deliveries
Tom Hughes [Wed, 20 Mar 2024 17:43:10 +0000 (17:43 +0000)]
Try and detaint messages.openstreetmap.org deliveries

5 weeks agoValidate local parts for messages.openstreetmap.org to untaint them
Tom Hughes [Wed, 20 Mar 2024 12:45:49 +0000 (12:45 +0000)]
Validate local parts for messages.openstreetmap.org to untaint them

5 weeks agonetworking: ensure nftables script checks input
Grant Slater [Wed, 20 Mar 2024 10:32:54 +0000 (10:32 +0000)]
networking: ensure nftables script checks input

Ensure the nftables script does not prematurely exit on any invalid input.
eg: If unblocking a set of IPs skip any not currently blocked instead of premature exit.

Signed-off-by: Grant Slater <github@firefishy.com>
5 weeks agoapache: increase mod_evasive page_count to reduce iD false positives
Grant Slater [Tue, 19 Mar 2024 23:41:02 +0000 (23:41 +0000)]
apache: increase mod_evasive page_count to reduce iD false positives

5 weeks agoFix fail2ban evasive filter
Tom Hughes [Tue, 19 Mar 2024 21:20:03 +0000 (21:20 +0000)]
Fix fail2ban evasive filter

5 weeks agonetworking: add flush command to nftables script
Grant Slater [Tue, 19 Mar 2024 11:15:05 +0000 (11:15 +0000)]
networking: add flush command to nftables script

5 weeks agopodman: fix typo in param
Grant Slater [Mon, 18 Mar 2024 17:50:31 +0000 (17:50 +0000)]
podman: fix typo in param

5 weeks agopodman: increase default pid limit.
Grant Slater [Mon, 18 Mar 2024 17:33:01 +0000 (17:33 +0000)]
podman: increase default pid limit.

Workaround 2048 pid limit. Extremely low, causing issues with titiler.
Ideally should be set using a paramater.

Signed-off-by: Grant Slater <github@firefishy.com>
5 weeks agoAdd alert for node exporter text file scrape errors
Tom Hughes [Mon, 18 Mar 2024 17:28:05 +0000 (17:28 +0000)]
Add alert for node exporter text file scrape errors

5 weeks agoimagery: use https for tiler
Grant Slater [Mon, 18 Mar 2024 14:49:38 +0000 (14:49 +0000)]
imagery: use https for tiler

5 weeks agoimagery: add ngi-aerial code
Grant Slater [Mon, 18 Mar 2024 14:08:27 +0000 (14:08 +0000)]
imagery: add ngi-aerial code

6 weeks agoRevet accidental commit
Tom Hughes [Fri, 15 Mar 2024 15:56:57 +0000 (15:56 +0000)]
Revet accidental commit

6 weeks agocommunity: security bump version
Grant Slater [Fri, 15 Mar 2024 12:18:39 +0000 (12:18 +0000)]
community: security bump version

6 weeks agoDisable exim paniclog watcher
Tom Hughes [Fri, 15 Mar 2024 10:02:27 +0000 (10:02 +0000)]
Disable exim paniclog watcher

6 weeks agoFix exim daemon options for Ubuntu
Tom Hughes [Fri, 15 Mar 2024 10:01:26 +0000 (10:01 +0000)]
Fix exim daemon options for Ubuntu

6 weeks agoDrop attempt at SPF checking
Tom Hughes [Thu, 14 Mar 2024 11:19:04 +0000 (11:19 +0000)]
Drop attempt at SPF checking

6 weeks agoAccept any mail that passes an osmfoundation.org SPF check
Tom Hughes [Thu, 14 Mar 2024 10:52:05 +0000 (10:52 +0000)]
Accept any mail that passes an osmfoundation.org SPF check

6 weeks agoReject incoming mail which fails SPF checks
Tom Hughes [Thu, 14 Mar 2024 09:42:26 +0000 (09:42 +0000)]
Reject incoming mail which fails SPF checks

6 weeks agoAdd munin web redirects to prometheus
Grant Slater [Wed, 13 Mar 2024 14:48:11 +0000 (14:48 +0000)]
Add munin web redirects to prometheus

6 weeks agoScrub last munin traces
Grant Slater [Wed, 13 Mar 2024 14:39:59 +0000 (14:39 +0000)]
Scrub last munin traces

Signed-off-by: Grant Slater <github@firefishy.com>
6 weeks agoRemove munin-server GHA test
Grant Slater [Wed, 13 Mar 2024 14:31:29 +0000 (14:31 +0000)]
Remove munin-server GHA test

6 weeks agoRemove munin server role
Grant Slater [Wed, 13 Mar 2024 14:29:13 +0000 (14:29 +0000)]
Remove munin server role

6 weeks agoRemove munin
Grant Slater [Tue, 12 Mar 2024 20:45:46 +0000 (20:45 +0000)]
Remove munin

Fixed: https://github.com/openstreetmap/operations/issues/501
Signed-off-by: Grant Slater <github@firefishy.com>
6 weeks agohardware: do not fail if node[:hardware][:pci] is undefined (tests)
Grant Slater [Tue, 12 Mar 2024 21:15:16 +0000 (21:15 +0000)]
hardware: do not fail if node[:hardware][:pci] is undefined (tests)

6 weeks agogit: use extended combined_extended
Grant Slater [Tue, 12 Mar 2024 14:05:05 +0000 (14:05 +0000)]
git: use extended combined_extended