]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/apt/recipes/default.rb
Use https between tile caches and render servers
[chef.git] / cookbooks / apt / recipes / default.rb
index 2fcc6fa7871b3559a4b5827c2c6c45d5c063a376..508030bf2bde17d743004aba693cd58783d51255 100644 (file)
 # limitations under the License.
 #
 
 # limitations under the License.
 #
 
-package "apt"
-package "update-notifier-common"
+package %w[
+  apt
+  gnupg-curl
+  update-notifier-common
+]
 
 file "/etc/motd.tail" do
   action :delete
 
 file "/etc/motd.tail" do
   action :delete
@@ -29,105 +32,139 @@ execute "apt-update" do
   command "/usr/bin/apt-get update"
 end
 
   command "/usr/bin/apt-get update"
 end
 
+archive_host = if node[:country]
+                 "#{node[:country]}.archive.ubuntu.com"
+               else
+                 "archive.ubuntu.com"
+               end
+
 template "/etc/apt/sources.list" do
   source "sources.list.erb"
   owner "root"
   group "root"
 template "/etc/apt/sources.list" do
   source "sources.list.erb"
   owner "root"
   group "root"
-  mode 0644
+  mode 0o644
+  variables :archive_host => archive_host, :codename => node[:lsb][:codename]
   notifies :run, "execute[apt-update]", :immediately
 end
 
   notifies :run, "execute[apt-update]", :immediately
 end
 
-apt_source "brightbox-ruby-ng" do
-  url "http://ppa.launchpad.net/brightbox/ruby-ng/ubuntu"
-  key "C3173AA6"
+if node[:lsb][:release].to_f >= 16.04
+  apt_source "brightbox-ruby-ng" do
+    action :delete
+  end
+else
+  apt_source "brightbox-ruby-ng" do
+    url "http://ppa.launchpad.net/brightbox/ruby-ng/ubuntu"
+    key "F5DA5F09C3173AA6"
+  end
 end
 
 apt_source "ubuntugis-stable" do
   url "http://ppa.launchpad.net/ubuntugis/ppa/ubuntu"
 end
 
 apt_source "ubuntugis-stable" do
   url "http://ppa.launchpad.net/ubuntugis/ppa/ubuntu"
-  key "314DF160"
+  key "089EBE08314DF160"
 end
 
 apt_source "ubuntugis-unstable" do
   url "http://ppa.launchpad.net/ubuntugis/ubuntugis-unstable/ubuntu"
 end
 
 apt_source "ubuntugis-unstable" do
   url "http://ppa.launchpad.net/ubuntugis/ubuntugis-unstable/ubuntu"
-  key "314DF160"
+  key "089EBE08314DF160"
 end
 
 apt_source "openstreetmap" do
 end
 
 apt_source "openstreetmap" do
-  template "openstreetmap.list.erb"
   url "http://ppa.launchpad.net/osmadmins/ppa/ubuntu"
   url "http://ppa.launchpad.net/osmadmins/ppa/ubuntu"
-  key "0AC4F2CB"
+  key "D57F48750AC4F2CB"
+  update true
 end
 
 apt_source "management-component-pack" do
 end
 
 apt_source "management-component-pack" do
-  template "hp.list.erb"
-  url "http://downloads.linux.hp.com/SDR/downloads/ManagementComponentPack"
-  key "B1275EA3"
+  source_template "hp.list.erb"
+  url "http://downloads.linux.hpe.com/SDR/repo/mcp"
+  key "C208ADDE26C2B797"
+  key_url "https://downloads.linux.hpe.com/SDR/hpePublicKey2048_key1.pub"
 end
 
 apt_source "hwraid" do
 end
 
 apt_source "hwraid" do
-  template "hwraid.list.erb"
+  source_template "hwraid.list.erb"
   url "http://hwraid.le-vert.net/ubuntu"
   url "http://hwraid.le-vert.net/ubuntu"
-  key "23B3D3B4"
+  key "6005210E23B3D3B4"
 end
 
 apt_source "mapnik-v210" do
   url "http://ppa.launchpad.net/mapnik/v2.1.0/ubuntu"
 end
 
 apt_source "mapnik-v210" do
   url "http://ppa.launchpad.net/mapnik/v2.1.0/ubuntu"
-  key "5D50B6BA"
+  key "4F7B93595D50B6BA"
 end
 
 apt_source "nginx" do
 end
 
 apt_source "nginx" do
-  template "nginx.list.erb"
+  source_template "nginx.list.erb"
   url "http://nginx.org/packages/ubuntu"
   url "http://nginx.org/packages/ubuntu"
-  key "7BD9BF62"
+  key "ABF5BD827BD9BF62"
 end
 
 end
 
-apt_source "elasticsearch" do
-  template "elasticsearch.list.erb"
+apt_source "elasticsearch1.7" do
+  source_template "elasticsearch.list.erb"
   url "http://packages.elasticsearch.org/elasticsearch/1.7/debian"
   url "http://packages.elasticsearch.org/elasticsearch/1.7/debian"
-  key "D88E42B4"
+  key "D27D666CD88E42B4"
+end
+
+apt_source "elasticsearch2.x" do
+  source_template "elasticsearch.list.erb"
+  url "http://packages.elasticsearch.org/elasticsearch/2.x/debian"
+  key "D27D666CD88E42B4"
+end
+
+apt_source "elasticsearch5.x" do
+  source_template "elasticsearch.list.erb"
+  url "https://artifacts.elastic.co/packages/5.x/apt"
+  key "D27D666CD88E42B4"
 end
 
 apt_source "logstash" do
 end
 
 apt_source "logstash" do
-  template "elasticsearch.list.erb"
-  url "http://packages.elasticsearch.org/logstash/1.5/debian"
-  key "D88E42B4"
+  source_template "elasticsearch.list.erb"
+  url "http://packages.elasticsearch.org/logstash/2.3/debian"
+  key "D27D666CD88E42B4"
 end
 
 apt_source "logstash-forwarder" do
 end
 
 apt_source "logstash-forwarder" do
-  template "elasticsearch.list.erb"
+  source_template "elasticsearch.list.erb"
   url "http://packages.elasticsearch.org/logstashforwarder/debian"
   url "http://packages.elasticsearch.org/logstashforwarder/debian"
-  key "D88E42B4"
+  key "D27D666CD88E42B4"
 end
 
 apt_source "passenger" do
   url "https://oss-binaries.phusionpassenger.com/apt/passenger"
 end
 
 apt_source "passenger" do
   url "https://oss-binaries.phusionpassenger.com/apt/passenger"
-  key "AC40B2F7"
+  key "561F9B9CAC40B2F7"
 end
 
 apt_source "postgresql" do
 end
 
 apt_source "postgresql" do
-  template "postgresql.list.erb"
+  source_template "postgresql.list.erb"
   url "http://apt.postgresql.org/pub/repos/apt"
   url "http://apt.postgresql.org/pub/repos/apt"
-  key "ACCC4CF8"
+  key "7FCC7D46ACCC4CF8"
+end
+
+apt_source "mediawiki" do
+  source_template "mediawiki.list.erb"
+  url "https://releases.wikimedia.org/debian"
+  key "90E9F83F22250DD7"
 end
 
 package "unattended-upgrades"
 
 end
 
 package "unattended-upgrades"
 
-auto_upgrades = if node[:apt][:unattended_upgrades][:enable]
-                  IO.read("/usr/share/unattended-upgrades/20auto-upgrades")
-                else
-                  IO.read("/usr/share/unattended-upgrades/20auto-upgrades-disabled")
-                end
+if Dir.exist?("/usr/share/unattended-upgrades")
+  auto_upgrades = if node[:apt][:unattended_upgrades][:enable]
+                    IO.read("/usr/share/unattended-upgrades/20auto-upgrades")
+                  else
+                    IO.read("/usr/share/unattended-upgrades/20auto-upgrades-disabled")
+                  end
 
 
-file "/etc/apt/apt.conf.d/20auto-upgrades" do
-  user "root"
-  group "root"
-  mode 0644
-  content auto_upgrades
+  file "/etc/apt/apt.conf.d/20auto-upgrades" do
+    user "root"
+    group "root"
+    mode 0o644
+    content auto_upgrades
+  end
 end
 
 template "/etc/apt/apt.conf.d/60chef" do
   source "apt.conf.erb"
   owner "root"
   group "root"
 end
 
 template "/etc/apt/apt.conf.d/60chef" do
   source "apt.conf.erb"
   owner "root"
   group "root"
-  mode 0644
+  mode 0o644
 end
 end