X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/dad206335d841720939ac97b6ea90307db2976e6..f71ac318c6866183a879adda1c7ecef007a74924:/cookbooks/tile/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/tile/recipes/default.rb b/cookbooks/tile/recipes/default.rb index d31b0bc3c..6aeedaae8 100644 --- a/cookbooks/tile/recipes/default.rb +++ b/cookbooks/tile/recipes/default.rb @@ -56,7 +56,6 @@ remote_file "#{Chef::Config[:file_cache_path]}/fastly-ip-list.json" do ignore_failure true end -tilecaches = search(:node, "roles:tilecache").sort_by { |n| n[:hostname] } fastlyips = JSON.parse(IO.read("#{Chef::Config[:file_cache_path]}/fastly-ip-list.json")) apache_site "default" do @@ -69,7 +68,7 @@ end apache_site "tile.openstreetmap.org" do template "apache.erb" - variables :caches => tilecaches, :fastly => fastlyips["addresses"] + variables :fastly => fastlyips["addresses"] end template "/etc/logrotate.d/apache2" do @@ -85,6 +84,18 @@ directory "/srv/tile.openstreetmap.org" do mode "755" end +directory "/srv/tile.openstreetmap.org/conf" do + owner "tile" + group "tile" + mode "755" +end + +file "/srv/tile.openstreetmap.org/conf/ip.map" do + owner "tile" + group "adm" + mode "644" +end + package "renderd" systemd_service "renderd" do @@ -448,6 +459,7 @@ if node[:tile][:database][:external_data_script] cwd "/srv/tile.openstreetmap.org" user "tile" group "tile" + ignore_failure true end end @@ -483,6 +495,10 @@ package %w[ python3-pyproj ] +gem_package "apachelogregex" +gem_package "file-tail" +gem_package "lru_redux" + remote_directory "/usr/local/bin" do source "bin" owner "root" @@ -493,6 +509,35 @@ remote_directory "/usr/local/bin" do files_mode "755" end +template "/usr/local/bin/tile-ratelimit" do + source "tile-ratelimit.erb" + owner "root" + group "root" + mode "755" +end + +systemd_service "tile-ratelimit" do + description "Monitor tile requests and enforce rate limits" + after "apache2.service" + user "tile" + group "adm" + exec_start "/usr/local/bin/tile-ratelimit" + private_tmp true + private_devices true + private_network true + protect_system "full" + protect_home true + read_write_paths "/srv/tile.openstreetmap.org/conf" + no_new_privileges true + restart "on-failure" +end + +service "tile-ratelimit" do + action [:enable, :start] + subscribes :restart, "file[/usr/local/bin/tile-ratelimit]" + subscribes :restart, "systemd_service[tile-ratelimit]" +end + template "/usr/local/bin/expire-tiles" do source "expire-tiles.erb" owner "root"