remove db-koji0[12].phx2, sign-bridge01.phx2, fedocal01.phx2, nuancier01.phx2, nuancier02.phx2

This commit is contained in:
Stephen Smoogen 2020-06-11 17:14:23 -04:00
parent 89dafdc841
commit 08f622be41
12 changed files with 23 additions and 39 deletions

View file

@ -9,7 +9,7 @@ num_cpus: 2
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source sign-bridge01.phx2.fedoraproject.org,secondary-bridge01.phx2.fedoraproject.org -j ACCEPT']
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
ansible_ifcfg_whitelist:
- eth0

View file

@ -1,6 +1,6 @@
---
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source sign-bridge01.phx2.fedoraproject.org,secondary-bridge01.phx2.fedoraproject.org -j ACCEPT']
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
host_group: autosign

View file

@ -12,7 +12,8 @@ testing: True
# Make connections from signing bridges stateless, they break sigul connections
# https://bugzilla.redhat.com/show_bug.cgi?id=1283364
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source sign-bridge01.phx2.fedoraproject.org -j ACCEPT']
# this is sign-bridge01.iad2 ip 10.3.169.120
custom_rules: ['-A INPUT --proto tcp --sport 44334 --source 10.3.169.120 -j ACCEPT']
# With 16 cpus, theres a bunch more kernel threads
nrpe_procs_warn: 900

View file

@ -123,7 +123,6 @@ datagrepper02.phx2.fedoraproject.org
# datagrepper01.stg.phx2.fedoraproject.org
[fedimg]
fedimg01.phx2.fedoraproject.org
fedimg01.iad2.fedoraproject.org
[fedimg_stg]
@ -137,8 +136,6 @@ busgateway01.iad2.fedoraproject.org
# busgateway01.stg.phx2.fedoraproject.org
[fedocal]
fedocal01.phx2.fedoraproject.org
fedocal02.phx2.fedoraproject.org
[fedocal_stg]
# fedocal01.stg.phx2.fedoraproject.org
@ -150,8 +147,6 @@ github2fedmsg01.iad2.fedoraproject.org
# github2fedmsg01.stg.phx2.fedoraproject.org
[mailman]
mailman01.phx2.fedoraproject.org
mailman02.phx2.fedoraproject.org
mailman01.iad2.fedoraproject.org
mailman02.iad2.fedoraproject.org
@ -191,7 +186,6 @@ bodhi-backend01.iad2.fedoraproject.org
# bodhi-backend01.stg.phx2.fedoraproject.org
[sign_bridge]
sign-bridge01.phx2.fedoraproject.org
sign-bridge01.iad2.fedoraproject.org
# sign-bridge01.stg.phx2.fedoraproject.org
#
@ -219,9 +213,7 @@ db-fas01.phx2.fedoraproject.org
db-fas01.iad2.fedoraproject.org
db-datanommer01.iad2.fedoraproject.org
db-datanommer02.phx2.fedoraproject.org
db-koji01.phx2.fedoraproject.org
db-koji01.iad2.fedoraproject.org
db-koji02.phx2.fedoraproject.org
db-qa01.qa.fedoraproject.org
db-qa02.qa.fedoraproject.org
db-qa03.qa.fedoraproject.org
@ -362,8 +354,6 @@ notifs-web02.iad2.fedoraproject.org
# notifs-web02.stg.phx2.fedoraproject.org
[nuancier]
nuancier01.phx2.fedoraproject.org
nuancier02.phx2.fedoraproject.org
[nuancier_stg]
# nuancier01.stg.phx2.fedoraproject.org
@ -1207,8 +1197,8 @@ bodhi-backend01.phx2.fedoraproject.org
mailman01.phx2.fedoraproject.org
people02.fedoraproject.org
db-datanommer02.phx2.fedoraproject.org
fedocal02.phx2.fedoraproject.org
nuancier01.phx2.fedoraproject.org
#nuancier01.phx2.fedoraproject.org
#fedocal02.phx2.fedoraproject.org
pagure01.fedoraproject.org
pkgs02.phx2.fedoraproject.org
notifs-web01.iad2.fedoraproject.org
@ -1605,8 +1595,6 @@ datagrepper01.phx2.fedoraproject.org
datagrepper02.phx2.fedoraproject.org
db-datanommer02.phx2.fedoraproject.org
db-fas01.phx2.fedoraproject.org
db-koji01.phx2.fedoraproject.org
db-koji02.phx2.fedoraproject.org
db-qa01.qa.fedoraproject.org
db-qa02.qa.fedoraproject.org
db-qa03.qa.fedoraproject.org
@ -1614,8 +1602,6 @@ db01.phx2.fedoraproject.org
db03.phx2.fedoraproject.org
fas01.phx2.fedoraproject.org
fedimg01.phx2.fedoraproject.org
fedocal01.phx2.fedoraproject.org
fedocal02.phx2.fedoraproject.org
gnome-backups01.phx2.fedoraproject.org
ipa01.phx2.fedoraproject.org
ipa02.phx2.fedoraproject.org
@ -1634,8 +1620,6 @@ memcached02.phx2.fedoraproject.org
noc01.phx2.fedoraproject.org
ns03.phx2.fedoraproject.org
ns04.phx2.fedoraproject.org
nuancier01.phx2.fedoraproject.org
nuancier02.phx2.fedoraproject.org
odcs-backend-releng01.phx2.fedoraproject.org
odcs-backend01.phx2.fedoraproject.org
odcs-frontend01.phx2.fedoraproject.org
@ -1687,7 +1671,6 @@ resultsdb-stg01.qa.fedoraproject.org
resultsdb01.qa.fedoraproject.org
retrace01.qa.fedoraproject.org
secondary01.phx2.fedoraproject.org
sign-bridge01.phx2.fedoraproject.org
tang01.phx2.fedoraproject.org
tang02.phx2.fedoraproject.org
virthost-comm01.qa.fedoraproject.org

View file

@ -75,8 +75,8 @@
- role: gluster/client
glusterservername: gluster
servers:
- nuancier01.stg.phx2.fedoraproject.org
- nuancier02.stg.phx2.fedoraproject.org
- nuancier01.stg.iad2.fedoraproject.org
- nuancier02.stg.iad2.fedoraproject.org
username: "{{ nuancier_gluster_username }}"
password: "{{ nuancier_gluster_password }}"
owner: apache
@ -105,8 +105,8 @@
- role: gluster/client
glusterservername: gluster
servers:
- nuancier01.phx2.fedoraproject.org
- nuancier02.phx2.fedoraproject.org
- nuancier01.iad2.fedoraproject.org
- nuancier02.iad2.fedoraproject.org
username: "{{ nuancier_gluster_username }}"
password: "{{ nuancier_gluster_password }}"
owner: apache

View file

@ -2,12 +2,12 @@
# NOTE: should be used with --limit most of the time
# NOTE: most of these vars_path come from group_vars/backup_server or from hostvars
- import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml myhosts=db-datanommer02.phx2.fedoraproject.org:db-qa01.qa.fedoraproject.org:db-koji01.phx2.fedoraproject.org:db-fas01.stg.phx2.fedoraproject.org:db-fas01.phx2.fedoraproject.org:db01.phx2.fedoraproject.org:db01.stg.phx2.fedoraproject.org:db-qa02.qa.fedoraproject.org:db-koji01.stg.phx2.fedoraproject.org:db-qa03.qa.fedoraproject.org:db-koji02.phx2.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-datanommer01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org"
- import_playbook: "/srv/web/infra/ansible/playbooks/include/virt-create.yml myhosts=db-datanommer02.phx2.fedoraproject.org:db-qa01.qa.fedoraproject.org:db-fas01.stg.phx2.fedoraproject.org:db-fas01.phx2.fedoraproject.org:db01.phx2.fedoraproject.org:db01.stg.phx2.fedoraproject.org:db-qa02.qa.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org:db-qa03.qa.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-datanommer01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org"
# Once the instance exists, configure it.
- name: configure postgresql server system
hosts: db-datanommer02.phx2.fedoraproject.org:db-qa01.qa.fedoraproject.org:db-koji01.phx2.fedoraproject.org:db-fas01.stg.phx2.fedoraproject.org:db-fas01.phx2.fedoraproject.org:db01.phx2.fedoraproject.org:db01.stg.phx2.fedoraproject.org:db-qa02.qa.fedoraproject.org:db-koji01.stg.phx2.fedoraproject.org:db-qa03.qa.fedoraproject.org:db-koji02.phx2.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-datanommer01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org
hosts: db-datanommer02.phx2.fedoraproject.org:db-qa01.qa.fedoraproject.org:db-fas01.stg.phx2.fedoraproject.org:db-fas01.phx2.fedoraproject.org:db01.phx2.fedoraproject.org:db01.stg.phx2.fedoraproject.org:db-qa02.qa.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org:db-qa03.qa.fedoraproject.org:db-fas01.iad2.fedoraproject.org:db01.iad2.fedoraproject.org:db-datanommer01.iad2.fedoraproject.org:db-koji01.iad2.fedoraproject.org:db-openqa01.iad2.fedoraproject.org
user: root
gather_facts: True

View file

@ -55,7 +55,7 @@
# Note that the hosts are used explicitly here to choose only the "primary".
# We don't want to run upgrades on both pgbdr nodes at the same time.
# ... is anything special needed to upgrade pgbdr nodes?
hosts: db-koji01.phx2.fedoraproject.org:db-koji01.stg.phx2.fedoraproject.org
hosts: db-koji01.iad2.fedoraproject.org:db-koji01.stg.iad2.fedoraproject.org
user: root
vars_files:
- /srv/web/infra/ansible/vars/global.yml

View file

@ -178,9 +178,9 @@ Alias /pub /pub
Require all granted
</Directory>
# This IP is sign-bridge01.phx2.fedoraproject.org.
# This IP is sign-bridge01.iad2.fedoraproject.org.
# It needs to be able to sign openh264 packages.
RewriteCond %{HTTP:X-Forwarded-For} !10.5.125.71
RewriteCond %{HTTP:X-Forwarded-For} !10.3.169.120
RewriteRule ".*/.*openh264.*.(x86_64|armv7hl|i686|ppc64|ppc64le|aarch64|s390x).rpm$" "https://fedoraproject.org/wiki/non-distributable-rpms" [R=302,L]
# Set HSTS header via HTTP since it cannot be easily set in squid, which terminates HTTPS

View file

@ -13,9 +13,9 @@ script_location = /opt/app-root/src/alembic
#sqlalchemy.url = postgresql://<%= fedocal_app %>:<%= fedocal_appPassword %>@db-fedocal/fedocal
{% if env == 'staging' %}
sqlalchemy.url = postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.stg.phx2.fedoraproject.org/{{ fedocal_db_name }}
sqlalchemy.url = postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.stg.iad2.fedoraproject.org/{{ fedocal_db_name }}
{% else %}
sqlalchemy.url = postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.phx2.fedoraproject.org/{{ fedocal_db_name }}
sqlalchemy.url = postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.iad2.fedoraproject.org/{{ fedocal_db_name }}
{% endif %}

View file

@ -8,9 +8,9 @@ SECRET_KEY='{{ fedocal_secret_key }}'
#DB_URL=postgres://user:pass@host/db_name
#DB_URL="postgresql://<%= fedocal_app %>:<%= fedocal_appPassword %>@db-fedocal/fedocal"
{% if env == 'staging' %}
DB_URL='postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.stg.phx2.fedoraproject.org/{{ fedocal_db_name }}'
DB_URL='postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.stg.iad2.fedoraproject.org/{{ fedocal_db_name }}'
{% else %}
DB_URL='postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.phx2.fedoraproject.org/{{ fedocal_db_name }}'
DB_URL='postgresql://{{ fedocal_db_user }}:{{ fedocal_db_pass }}@db01.iad2.fedoraproject.org/{{ fedocal_db_name }}'
{% endif %}

View file

@ -12,9 +12,9 @@ script_location = /opt/app-root/src/nuancier/alembic
# revision_environment = false
{% if env == 'staging' %}
sqlalchemy.url = postgresql://{{ nuancier_db_admin_user }}:{{ nuancier_db_admin_pass }}@db01.stg.phx2.fedoraproject.org/{{ nuancier_db_name }}
sqlalchemy.url = postgresql://{{ nuancier_db_admin_user }}:{{ nuancier_db_admin_pass }}@db01.stg.iad2.fedoraproject.org/{{ nuancier_db_name }}
{% else %}
sqlalchemy.url = postgresql://{{ nuancier_db_admin_user }}:{{ nuancier_db_admin_pass }}@db01.phx2.fedoraproject.org/{{ nuancier_db_name }}
sqlalchemy.url = postgresql://{{ nuancier_db_admin_user }}:{{ nuancier_db_admin_pass }}@db01.iad2.fedoraproject.org/{{ nuancier_db_name }}
{% endif %}

View file

@ -7,9 +7,9 @@ SECRET_KEY='{{ nuancier_secret_key }}'
### url to the database server:
{% if env == 'staging' %}
DB_URL='postgresql://{{ nuancier_db_user }}:{{ nuancier_db_pass }}@db01.stg.phx2.fedoraproject.org/{{ nuancier_db_name }}'
DB_URL='postgresql://{{ nuancier_db_user }}:{{ nuancier_db_pass }}@db01.stg.iad2.fedoraproject.org/{{ nuancier_db_name }}'
{% else %}
DB_URL='postgresql://{{ nuancier_db_user }}:{{ nuancier_db_pass }}@db01.phx2.fedoraproject.org/{{ nuancier_db_name }}'
DB_URL='postgresql://{{ nuancier_db_user }}:{{ nuancier_db_pass }}@db01.iad2.fedoraproject.org/{{ nuancier_db_name }}'
{% endif %}
### The FAS groups in which the admin of nuancier are