NetworkInfrastructure » History » Version 98
Denis 'GNUtoo' Carikli, 03/12/2019 05:03 PM
1 | 1 | Denis 'GNUtoo' Carikli | h1. NetworkInfrastructure |
---|---|---|---|
2 | |||
3 | 16 | Denis 'GNUtoo' Carikli | |_. What |_. Where |_. Access type | Who | comments | |
4 | 25 | Denis 'GNUtoo' Carikli | | "Redmine instance":https://redmine.replicant.us | OSUOSL | Redmine administrator | Several Replicant contributors including: |
5 | 37 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
6 | 38 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
7 | 57 | Joonas Kylmälä | * Joonas Kylmälä |
8 | 1 | Denis 'GNUtoo' Carikli | * Add your name here if you have access and want to be mentioned | | |
9 | 92 | Denis 'GNUtoo' Carikli | | "Mailing list":https://lists.osuosl.org/mailman/listinfo/replicant | OSUOSL | Mailing list administrator | Several Replicant contributors including: |
10 | 41 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
11 | 60 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
12 | 87 | Denis 'GNUtoo' Carikli | * Add your name here if you have access and want to be mentioned | | |
13 | 1 | Denis 'GNUtoo' Carikli | | "Wordpress instance":https://blog.replicant.us/ | OSUOSL | Wordpress administator | Several Replicant contributors including: |
14 | 37 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
15 | 38 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
16 | 1 | Denis 'GNUtoo' Carikli | * Add your name here if you have access and want to be mentioned | This instance is auto-updated automatically with the help of a plugin. | |
17 | 97 | Denis 'GNUtoo' Carikli | | "Releases":https://ftp-osl.osuosl.org/pub/replicant/ | OSUOSL | SSH?/SFTP | Only the following people have access to it: |
18 | 61 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
19 | 97 | Denis 'GNUtoo' Carikli | * [[People#Joonas-Kylmälä|Joonas Kylmälä]] | We should not use too much space | |
20 | 96 | Denis 'GNUtoo' Carikli | | A virtual machine hosted by the FSF that handles: |
21 | 98 | Denis 'GNUtoo' Carikli | * "Replicant Source code":https://git.replicant.us/ | FSF | SSH root access | Only the following people or machines have access to it |
22 | 37 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
23 | 57 | Joonas Kylmälä | * Joonas Kylmälä |
24 | 1 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
25 | 64 | Denis 'GNUtoo' Carikli | * Several FSF system administrators |
26 | 96 | Denis 'GNUtoo' Carikli | * FSF backup server | Resources kindly offered by the FSF | |
27 | 52 | Denis 'GNUtoo' Carikli | | [[PrivateContact|Private contact address]] | This is handled by [[People#Paul-Kocialkowski|Paul Kocialkowski]]'s mail servers: |
28 | 53 | Denis 'GNUtoo' Carikli | * armstrong.paulk.fr |
29 | 52 | Denis 'GNUtoo' Carikli | * gagarine.paulk.fr | SSH, physical access | [[People#Paul-Kocialkowski|Paul Kocialkowski]] only (it's his machines) | The contact address is redirected to several Replicant contributors including: |
30 | 42 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
31 | 38 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
32 | 1 | Denis 'GNUtoo' Carikli | * Add your name here if you receive mail from this address and want to be mentioned | |
33 | 33 | Denis 'GNUtoo' Carikli | | IRC channel | Freenode | Channel operator(s) | Several Replicant contributors including: |
34 | 38 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
35 | 37 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
36 | 58 | Kurtis Hanna | * [[People#Kurtis-Hanna|Kurtis Hanna]] |
37 | 88 | Denis 'GNUtoo' Carikli | * Add your name here if you have access and want to be mentioned | @MODE #Replicant +qe $~a *!*@gateway/web/*@ and @MODE #Replicant +qe $~a *!*@gateway/shell/matrix.org/*@ have been applied. Unless one connects via a web based irc client or via the Matrix.org IRC bridge one will need to register one's nick with Freenode in order to speak | |
38 | 43 | Denis 'GNUtoo' Carikli | | The replicant.us (mostly-static) front website | OSUOSL (hook) + FSF for the source code | * See the source code hosting line above. |
39 | * Probably none for the hook | See the source code hosting line above. | * "Source code":https://git.replicant.us/replicant/website/ |
||
40 | * Patches are to be sent to the Replicant mailing list |
||
41 | * There is a jenkins hook with a token to pull and deploy the website source code | |
||
42 | 45 | Denis 'GNUtoo' Carikli | | The replicant.us domain name | gandi.net | * Web inteface through gandi website |
43 | * The DNS entries are configured to use gandi's DNS server | Several Replicant contributors including: |
||
44 | 91 | Denis 'GNUtoo' Carikli | * [[People#Denis-GNUtoo-Carikli|GNUtoo]] |
45 | * [[People#Bradley-M-Kuhn|Bradley Kuhn]] |
||
46 | 44 | Denis 'GNUtoo' Carikli | * [[People#Paul-Kocialkowski|Paul Kocialkowski]] |
47 | * Add your name here if you have access and want to be mentioned | | |
||
48 | 32 | Denis 'GNUtoo' Carikli | | The replicant.us TLS certificate | Let's Encrypt | Access probably by controlling the respective domain name | * https://www.replicant.us: OSUOSL |
49 | 29 | Denis 'GNUtoo' Carikli | * https://blog.replicant.us: OSUOSL |
50 | * https://redmine.replicant.us: OSUOSL |
||
51 | 30 | Denis 'GNUtoo' Carikli | * https://git.replicant.us: ? | History: CA-cert -> GlobalSign -> LetsEncrypt | |
52 | 16 | Denis 'GNUtoo' Carikli | |
53 | 13 | Denis 'GNUtoo' Carikli | h2. OSUOSL |
54 | 7 | Denis 'GNUtoo' Carikli | |
55 | 16 | Denis 'GNUtoo' Carikli | The OSUOSL is the Oregon State University Open Source Lab. |
56 | 19 | Denis 'GNUtoo' Carikli | |
57 | 56 | Denis 'GNUtoo' Carikli | Contact: |
58 | * They can be contacted on #osuosl on the Freenode IRC network |
||
59 | 92 | Denis 'GNUtoo' Carikli | * They also have a 'support' mail address at osuosl.org |
60 | 56 | Denis 'GNUtoo' Carikli | |
61 | 66 | Denis 'GNUtoo' Carikli | h2. Virtual machine in FSF's office |
62 | 1 | Denis 'GNUtoo' Carikli | |
63 | * The virtual machine is hosted in a server that is in their office. |
||
64 | * Several FSF network administrator also have access to the virtual machine |
||
65 | 66 | Denis 'GNUtoo' Carikli | |
66 | 75 | Denis 'GNUtoo' Carikli | Contact: |
67 | 76 | Denis 'GNUtoo' Carikli | * The 'sysadmin' mail address at gnu.org |
68 | * The FSF system administrators can also be contacted on #fsfsys on the Freenode IRC network for more urgent matters |
||
69 | 75 | Denis 'GNUtoo' Carikli | |
70 | 66 | Denis 'GNUtoo' Carikli | h3. Virtual machine specifications |
71 | 67 | Denis 'GNUtoo' Carikli | |
72 | 69 | Denis 'GNUtoo' Carikli | The virtual machine runs on top of Xen and has: |
73 | 66 | Denis 'GNUtoo' Carikli | * About 3G of RAM |
74 | * 1 virtual core |
||
75 | * a 10G rootfs partition |
||
76 | * a 100G storage partition for Replicant git repositories |
||
77 | 1 | Denis 'GNUtoo' Carikli | * One IPv4 and one IPv6 |
78 | 69 | Denis 'GNUtoo' Carikli | |
79 | Software: |
||
80 | 93 | Denis 'GNUtoo' Carikli | * Trisquel 8.0 |
81 | 72 | Denis 'GNUtoo' Carikli | * The virtual machine may be using FAI and cfengine but it would need more investigation on that. |
82 | * The distribution seem to have the latest security updates applies. How it does it needs to be investigated by looking at cron jobs (it might use FAI for that). |
||
83 | 66 | Denis 'GNUtoo' Carikli | |
84 | h3. Virtual machine backup policies |
||
85 | 68 | Denis 'GNUtoo' Carikli | |
86 | 89 | Denis 'GNUtoo' Carikli | The virtual machine is backed up daily. The backup procedure excludes the following path at the time of writing: |
87 | 62 | Denis 'GNUtoo' Carikli | <pre> |
88 | /dev |
||
89 | /proc |
||
90 | /tmp |
||
91 | /sys |
||
92 | /run |
||
93 | /mnt |
||
94 | /mnt0 |
||
95 | /mnt1 |
||
96 | /mnt2 |
||
97 | /mnt3 |
||
98 | /mnt4 |
||
99 | /mnt5 |
||
100 | /mnt6 |
||
101 | /mnt7 |
||
102 | /mnt8 |
||
103 | /mnt9 |
||
104 | /floppy/ |
||
105 | /cdrom/ |
||
106 | /media/ |
||
107 | /net/ |
||
108 | /var/spool/squid/ |
||
109 | /var/spool/squid3/ |
||
110 | /var/spool/squid3_bak/ |
||
111 | /var/spool/squid-tbd/ |
||
112 | /var/spool/squid*/ |
||
113 | /var/spool/django/ |
||
114 | /var/spool/exim/ |
||
115 | /var/cache/ |
||
116 | /srv/chroot/ |
||
117 | /t |
||
118 | /srv/to-tape |
||
119 | /var/lib/ceph/osd/ |
||
120 | /var/lib/apt/lists/ |
||
121 | /var/cache/apt/ |
||
122 | </pre> |
||
123 | 44 | Denis 'GNUtoo' Carikli | |
124 | 81 | Denis 'GNUtoo' Carikli | h3. git hosting infrastructure on this machine |
125 | 80 | Denis 'GNUtoo' Carikli | |
126 | The source code is in /srv/git/git-data/repositories and is divided in several groups: |
||
127 | ** Replicant source code |
||
128 | ** LineageOS mirror |
||
129 | ** Various developers repositories |
||
130 | |||
131 | 82 | Denis 'GNUtoo' Carikli | |_. function |_. software |_. comments | |
132 | | authorization | gitolite | | |
||
133 | 84 | Denis 'GNUtoo' Carikli | | read access | * git:// -> git daemon |
134 | * ssh:// -> ssh daemon |
||
135 | * https:// -> ? (TODO: document the software/configuration) |
||
136 | 83 | Denis 'GNUtoo' Carikli | | | |
137 | 82 | Denis 'GNUtoo' Carikli | | web | cgit | | |
138 | |||
139 | 79 | Denis 'GNUtoo' Carikli | h2. Gandi |
140 | 1 | Denis 'GNUtoo' Carikli | |
141 | * See https://en.wikipedia.org/wiki/Gandi for more details |
||
142 | 46 | Denis 'GNUtoo' Carikli | |
143 | 79 | Denis 'GNUtoo' Carikli | h2. Freenode |
144 | 46 | Denis 'GNUtoo' Carikli | |
145 | 79 | Denis 'GNUtoo' Carikli | h2. TODO: |
146 | 47 | Denis 'GNUtoo' Carikli | |
147 | 1 | Denis 'GNUtoo' Carikli | * Ask the OSUOSL about backup policies. |
148 | 47 | Denis 'GNUtoo' Carikli | * Document public spaces like Freenode IRC channel. |
149 | 1 | Denis 'GNUtoo' Carikli | * Do our own backup policies and do some backups ourselves. |
150 | 47 | Denis 'GNUtoo' Carikli | * Contact the people that have some control of the resources above and ask for permission to mention them here |
151 | 50 | Denis 'GNUtoo' Carikli | * Fill the gaps (mentioned with '?') in this page |
152 | 48 | Denis 'GNUtoo' Carikli | * Look what happens when an account is deleted |
153 | 55 | Denis 'GNUtoo' Carikli | * Fix the related issues in the "tracker":https://redmine.replicant.us/projects/replicant/issues?utf8=%E2%9C%93&set_filter=1&f%5B%5D=status_id&op%5Bstatus_id%5D=o&f%5B%5D=category_id&op%5Bcategory_id%5D=%3D&v%5Bcategory_id%5D%5B%5D=57&f%5B%5D=&c%5B%5D=tracker&c%5B%5D=status&c%5B%5D=priority&c%5B%5D=subject&c%5B%5D=assigned_to&c%5B%5D=updated_on&c%5B%5D=category&c%5B%5D=cf_21&group_by=&t%5B%5D= |
154 | 54 | Denis 'GNUtoo' Carikli | * Move the entries of this TODO list to the tracker when it makes sense |
155 | 77 | Denis 'GNUtoo' Carikli | |
156 | h1. Funding and legal entity |
||
157 | 78 | Denis 'GNUtoo' Carikli | |
158 | The FSF holds Replicant funds and acts like an umbrella Oragnisation. |
||
159 | |||
160 | 95 | Denis 'GNUtoo' Carikli | The person that is designed to be in contact with the FSF is Denis Carikli. |
161 | 78 | Denis 'GNUtoo' Carikli | |
162 | 95 | Denis 'GNUtoo' Carikli | The people responsible for fund usage decisions are Paul Kocialkowski and Denis Carikli |
163 | |||
164 | Our contact at the FSF is John Sullivan |
||
165 | 94 | Denis 'GNUtoo' Carikli | |
166 | h1. Legal advise |
||
167 | |||
168 | Contact John Sullivan at the FSF. |
||
169 | |||
170 | Note that John Sullivan is not a lawyer but the FSF has lawyers. |