Ricky Elrod
dcb984c6d2
add python2-mock here
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2016-09-06 20:15:05 +00:00
Patrick Uiterwijk
f1dd7a7432
Unify all ssl cipher suite configurations
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-08-31 19:28:26 +00:00
Patrick Uiterwijk
b6dda2c8b3
Create candidate registry at proxy
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-08-29 19:09:38 +00:00
Ricky Elrod
f1e82e00ca
set https so styles work
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2016-08-03 09:30:02 +00:00
Ricky Elrod
ff9c55e1e8
set ProxyPreserveHost
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2016-08-03 09:16:38 +00:00
Patrick Uiterwijk
46629ba55c
Route all xmlrpc requests to mm-frontend-checkin01
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-06-17 20:33:44 +00:00
Ricky Elrod
1463224098
Nuke fedora-mobile website reverse proxy
...
Signed-off-by: Ricky Elrod <codeblock@fedoraproject.org >
2016-06-05 21:22:11 +00:00
Kevin Fenzi
2209cb5efa
drop bodhost01 and proxy07
2016-05-31 16:48:17 +00:00
Kevin Fenzi
3b40f60873
Try moving this to defaults instead of vars.
2016-05-26 16:22:55 +00:00
Patrick Uiterwijk
e34d1ff891
Remove temporary download.fp.o to dl.fp.o 24 Beta redirect
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-05-10 16:56:25 +00:00
Patrick Uiterwijk
80b8e5f6f5
Fix redirects for all images for F24 beta
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-05-10 15:36:12 +00:00
Patrick Uiterwijk
7d6d10e7e5
ProxyPass and redirect don't collaborate nicely
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-05-10 15:24:17 +00:00
Kevin Fenzi
26868b53bc
Remove $
2016-05-10 15:10:50 +00:00
Kevin Fenzi
e24c3cc5f8
Redirect workstation beta to dl for now.
2016-05-10 14:52:44 +00:00
Patrick Uiterwijk
d99cc31de5
Well, maybe you can register at a registry?
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-04-12 17:43:02 +00:00
Patrick Uiterwijk
b14a7b3b1b
This needs to be under Location
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-04-12 16:21:25 +00:00
Patrick Uiterwijk
5888a3c32b
Only allow containerbuild to push to the registry
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-04-12 16:12:50 +00:00
Patrick Uiterwijk
98a1619e01
Let's use the existing pki path
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-04-12 14:16:56 +00:00
Patrick Uiterwijk
97b00e90ab
Use Fedora proxies as only proxy for Docker Registry
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-04-12 13:56:26 +00:00
Patrick Uiterwijk
c0b7382df2
Allow to keep the host header through a setting
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-03-10 22:07:34 +00:00
Patrick Uiterwijk
ac83211407
Indexing /datagrepper is useless
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-02-11 13:19:26 +00:00
Patrick Uiterwijk
69aa7513b0
Also match api_2
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-01-22 02:23:59 +00:00
Patrick Uiterwijk
b69187c61c
COPR API goes over SSL
2016-01-22 01:04:50 +00:00
Patrick Uiterwijk
ff3c5dcdf6
Proxy copr api
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-01-22 00:44:27 +00:00
Patrick Uiterwijk
d0f8126a9a
This is called file
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-01-22 00:41:38 +00:00
Patrick Uiterwijk
6f990c34dd
Do not forward COPR /api requests
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-01-22 00:40:47 +00:00
Patrick Uiterwijk
62a0372a38
Add the de-facto x-forwarded-proto
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2016-01-15 09:34:32 +00:00
Patrick Uiterwijk
7d179ed9dc
Merge patch to enable HSTS on id.fp.o. #4991
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-12-01 21:34:46 +00:00
Patrick Uiterwijk
a0cf3666ce
Cherrypy wants -Proto. Lets make it happy
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-12-01 21:15:03 +00:00
Patrick Uiterwijk
08568865fe
Replace all restart httpd with reload httpd
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-11-04 23:40:01 +00:00
Patrick Uiterwijk
2f3988868c
Set requesttimeout on headers
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-10-15 17:34:08 +00:00
Kevin Fenzi
7b8f1624bf
Gte another reload place
2015-10-11 19:53:20 +00:00
Ralph Bean
b0d3350791
Revert "robots.txt for bodhi.fp.o."
...
This reverts commit dd76e91f2f .
2015-10-11 19:14:42 +00:00
Ralph Bean
dd76e91f2f
robots.txt for bodhi.fp.o.
2015-10-11 19:09:17 +00:00
Kevin Fenzi
17b4748e4e
Switch proxies to use the mpm event module instead of prefork.
2015-10-09 15:34:17 +00:00
Patrick Uiterwijk
fcc019136a
Also start haveged
2015-10-08 00:07:03 +00:00
Patrick Uiterwijk
6d8f8f3641
Var files are also useful
2015-10-08 00:01:30 +00:00
Patrick Uiterwijk
62b853b51e
Create both prod and stg ticket keys
2015-10-07 23:42:44 +00:00
Kevin Fenzi
b34edf77a7
Move the haveged install to the mod_ssl role
2015-10-07 23:24:41 +00:00
Patrick Uiterwijk
4fa59b5ce8
Enable ticket keys
2015-10-07 23:04:25 +00:00
Kevin Fenzi
dac2988255
Add connect time random to use 1024 byes of /dev/random
2015-10-07 23:00:17 +00:00
Patrick Uiterwijk
7106486ce3
Add haveged to proxies for entropy
2015-10-07 20:12:14 +00:00
Patrick Uiterwijk
25f71933ab
Robots have no use in fedoracommunity as its just an aggregator
...
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-09-16 11:50:59 +00:00
Stephen Smoogen
b74a402571
and we remove proxy09
2015-09-01 22:13:09 +00:00
Stephen Smoogen
1bc2c83952
change various ips to new ipv6 address
2015-08-21 19:41:43 +00:00
Patrick Uiterwijk
a4a3080f86
Make all redirects be 302
...
This will allow us more flexibility for moving redirects around.
It will result in less cached redirect entries, and as such more
requests to the proxies, but since those requests are handled by
the reverse proxies themselves, and within apache, those should
not take that much extra processing.
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com >
2015-08-17 13:37:02 +00:00
Adrian Reber
0c710e5d60
The crawler logs are now on mm-frontend01.
...
ProxyPass to the crawler is no longer required.
2015-06-23 07:39:18 +00:00
Adrian Reber
4d80aff5f1
The crawler logs are now on mm-crawler01
2015-06-12 16:11:00 +00:00
Till Maas
e3606ba68e
Use more https URLs where possible
2015-06-04 17:20:06 +02:00
Adrian Reber
74c772f99f
Fix redirect from publiclist to mirrormanager.
...
There have been reports that the old links pointing to the mirrorlist
are no longer working:
$ curl -I http://mirrors.fedoraproject.org/publiclist/
Location: https://admin.fedoraproject.org/mirrormanager///
This redirect still works but trying to access a specific mirrorlist
fails:
$ curl -I http://mirrors.fedoraproject.org/publiclist/EPEL/7/
Location: https://admin.fedoraproject.org/mirrormanager///EPEL/7/
$ curl -I https://admin.fedoraproject.org/mirrormanager///EPEL/7/
HTTP/1.1 404 NOT FOUND
At different places there are just too many slashes added. Removing the
slashes seems to help.
2015-05-15 19:06:05 +00:00