diff --git a/inventory/host_vars/arm-koji01.qa.fedoraproject.org b/inventory/host_vars/arm-koji01.qa.fedoraproject.org index 6f59f0939f..40d8bcf9a5 100644 --- a/inventory/host_vars/arm-koji01.qa.fedoraproject.org +++ b/inventory/host_vars/arm-koji01.qa.fedoraproject.org @@ -12,16 +12,10 @@ nrpe_procs_warn: 900 nrpe_procs_crit: 1000 fas_client_groups: sysadmin-releng,sysadmin-secondary +sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" fedmsg_fqdn: arm-koji01.qa.fedoraproject.org -custom_rules: [ - # Need for rsync from secondary01 for content. - '-A INPUT -p tcp -m tcp -s 10.5.126.27 --dport 873 -j ACCEPT', -] - -sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" - # # define this here because arm koji only needs eth0, not eth1 also # @@ -35,41 +29,3 @@ fedmsg_koji_instance: arm # Set this to use the qa domain resolv.conf to make sure it can talk to it's db resolvconf: resolv.conf/qa - -# Overload the fedmsg_certs definition from the ansible koji group, since the -# arm hub *also* does compose stuff, not just koji stuff. -fedmsg_certs: -- service: shell - owner: root - group: sysadmin -- service: koji - owner: root - group: apache - can_send: - - buildsys.build.state.change - - buildsys.package.list.change - - buildsys.repo.done - - buildsys.repo.init - - buildsys.rpm.sign - - buildsys.tag - - buildsys.task.state.change - - buildsys.untag -- service: bodhi - owner: root - group: localreleng - can_send: - - compose.branched.complete - - compose.branched.mash.complete - - compose.branched.mash.start - - compose.branched.pungify.complete - - compose.branched.pungify.start - - compose.branched.rsync.complete - - compose.branched.rsync.start - - compose.branched.start - - compose.epelbeta.complete - - compose.rawhide.complete - - compose.rawhide.mash.complete - - compose.rawhide.mash.start - - compose.rawhide.rsync.complete - - compose.rawhide.rsync.start - - compose.rawhide.start diff --git a/inventory/host_vars/ppc-koji01.ppc.fedoraproject.org b/inventory/host_vars/ppc-koji01.ppc.fedoraproject.org index d4c080968d..f08be04bae 100644 --- a/inventory/host_vars/ppc-koji01.ppc.fedoraproject.org +++ b/inventory/host_vars/ppc-koji01.ppc.fedoraproject.org @@ -2,18 +2,19 @@ nm: 255.255.255.0 gw: 10.5.129.254 dns: 10.5.126.21 +ks_url: http://10.5.126.23/repo/rhel/ks/kvm-rhel-7-ppc64le +ks_repo: http://10.5.126.23/repo/rhel/RHEL7-ppc64le/ volgroup: /dev/vg_guests eth0_ip: 10.5.129.240 main_bridge: br1 vmhost: ppc8-01.ppc.fedoraproject.org datacenter: phx2 - -ks_url: http://10.5.126.23/repo/rhel/ks/kvm-rhel-7-ppc64le -ks_repo: http://10.5.126.23/repo/rhel/RHEL7-ppc64le/ - nrpe_procs_warn: 900 nrpe_procs_crit: 1000 +fas_client_groups: sysadmin-releng,sysadmin-secondary +sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" + fedmsg_fqdn: ppc-koji01.qa.fedoraproject.org # diff --git a/inventory/host_vars/s390-koji01.qa.fedoraproject.org b/inventory/host_vars/s390-koji01.qa.fedoraproject.org index 237875aea6..c54e5aa7df 100644 --- a/inventory/host_vars/s390-koji01.qa.fedoraproject.org +++ b/inventory/host_vars/s390-koji01.qa.fedoraproject.org @@ -13,16 +13,10 @@ nrpe_procs_warn: 900 nrpe_procs_crit: 1000 fas_client_groups: sysadmin-releng,sysadmin-secondary +sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" fedmsg_fqdn: s390-koji01.qa.fedoraproject.org -custom_rules: [ - # Need for rsync from secondary01 for content. - '-A INPUT -p tcp -m tcp -s 209.132.181.8 --dport 873 -j ACCEPT', -] - -sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers" - # # define this here because s390 koji only needs eth0, not eth1 also # @@ -36,41 +30,3 @@ fedmsg_koji_instance: s390 # Set this to use the qa domain resolv.conf to make sure it can talk to it's db resolvconf: resolv.conf/qa - -# Overload the fedmsg_certs definition from the ansible koji group, since the -# s390 hub *also* does compose stuff, not just koji stuff. -fedmsg_certs: -- service: shell - owner: root - group: sysadmin -- service: koji - owner: root - group: apache - can_send: - - buildsys.build.state.change - - buildsys.package.list.change - - buildsys.repo.done - - buildsys.repo.init - - buildsys.rpm.sign - - buildsys.tag - - buildsys.task.state.change - - buildsys.untag -- service: bodhi - owner: root - group: localreleng - can_send: - - compose.branched.complete - - compose.branched.mash.complete - - compose.branched.mash.start - - compose.branched.pungify.complete - - compose.branched.pungify.start - - compose.branched.rsync.complete - - compose.branched.rsync.start - - compose.branched.start - - compose.epelbeta.complete - - compose.rawhide.complete - - compose.rawhide.mash.complete - - compose.rawhide.mash.start - - compose.rawhide.rsync.complete - - compose.rawhide.rsync.start - - compose.rawhide.start