Add sysadmin-veteran with shell anywhere that sysadmin-noc and/or fi-apprentice had access

This commit is contained in:
Nick Bebout 2016-05-17 00:18:04 +00:00
parent fdcad9a21d
commit e51aba3aeb
70 changed files with 70 additions and 70 deletions

View file

@ -13,7 +13,7 @@ tcp_ports: [ 80, 443,
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -13,7 +13,7 @@ tcp_ports: [ 80, 443,
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-ask,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -21,7 +21,7 @@ custom_rules: [
#
# allow a bunch of sysadmin groups here so they can access internal stuff
#
fas_client_groups: sysadmin-ask,sysadmin-web,sysadmin-main,sysadmin-cvs,sysadmin-build,sysadmin-noc,sysadmin-releng,sysadmin-dba,sysadmin-hosted,sysadmin-tools,sysadmin-spin,sysadmin-cloud,fi-apprentice,sysadmin-darkserver,sysadmin-badges,sysadmin-troubleshoot,sysadmin-qa,sysadmin-centos,sysadmin-ppc,sysadmin-koschei,sysadmin-secondary,sysadmin-fedimg
fas_client_groups: sysadmin-ask,sysadmin-web,sysadmin-main,sysadmin-cvs,sysadmin-build,sysadmin-noc,sysadmin-releng,sysadmin-dba,sysadmin-hosted,sysadmin-tools,sysadmin-spin,sysadmin-cloud,fi-apprentice,sysadmin-darkserver,sysadmin-badges,sysadmin-troubleshoot,sysadmin-qa,sysadmin-centos,sysadmin-ppc,sysadmin-koschei,sysadmin-secondary,sysadmin-fedimg,sysadmin-veteran
#
# This is a postfix gateway. This will pick up gateway postfix config in base

View file

@ -8,7 +8,7 @@ tcp_ports: [ 80, 443 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-ask,sysadmin-build,sysadmin-cvs,sysadmin-main,sysadmin-web,sysadmin-noc,sysadmin-hosted,sysadmin-releng,sysadmin-qa,sysadmin-tools,sysadmin-cloud,sysadmin-bot,sysadmin-centos,sysadmin-koschei,sysadmin-datanommer,sysadmin-fedimg,fi-apprentice,sysadmin-regcfp,sysadmin-badges
fas_client_groups: sysadmin-ask,sysadmin-build,sysadmin-cvs,sysadmin-main,sysadmin-web,sysadmin-noc,sysadmin-hosted,sysadmin-releng,sysadmin-qa,sysadmin-tools,sysadmin-cloud,sysadmin-bot,sysadmin-centos,sysadmin-koschei,sysadmin-datanommer,sysadmin-fedimg,fi-apprentice,sysadmin-regcfp,sysadmin-badges,sysadmin-veteran
ansible_base: /srv/web/infra
freezes: false

View file

@ -5,7 +5,7 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8000 ]
udp_ports: [ 69 ]
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice,sysadmin-noc,sysadmin-veteran
nrpe_procs_warn: 250
nrpe_procs_crit: 300

View file

@ -5,7 +5,7 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8000 ]
udp_ports: [ 69 ]
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice,sysadmin-noc,sysadmin-veteran
nrpe_procs_warn: 250
nrpe_procs_crit: 300

View file

@ -11,7 +11,7 @@ tcp_ports: [ 80, 443, 8888 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-qa
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-qa,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/qadevel-sudoers"
# This gets overridden by whichever node we want to run special cronjobs.

View file

@ -11,7 +11,7 @@ tcp_ports: [ 80, 443, 8888 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-qa
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-qa,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/qadevel-sudoers"
# This gets overridden by whichever node we want to run special cronjobs.

View file

@ -6,6 +6,6 @@ num_cpus: 8
tcp_ports: [ 80, 443 ]
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -6,6 +6,6 @@ num_cpus: 2
tcp_ports: []
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -6,6 +6,6 @@ num_cpus: 2
tcp_ports: [ 80, 443 ]
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-darkserver,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -14,6 +14,6 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-noc,sysadmin-datanommer,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-datanommer,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -11,6 +11,6 @@ tcp_ports: [ 80, 443, 6996 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-datanommer,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-datanommer,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -10,4 +10,4 @@ num_cpus: 1
tcp_ports: [ 68 ]
udp_ports: [ 69 ]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-veteran

View file

@ -13,7 +13,7 @@ tcp_ports: [ 80 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -13,7 +13,7 @@ tcp_ports: [ 80 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -13,7 +13,7 @@ tcp_ports: [
]
# TODO, restrict this down to just sysadmin-releng
fas_client_groups: sysadmin-datanommer,sysadmin-releng,sysadmin-fedimg,fi-apprentice
fas_client_groups: sysadmin-datanommer,sysadmin-releng,sysadmin-fedimg,fi-apprentice,sysadmin-noc,sysadmin-veteran
# These people get told when something goes wrong.
fedmsg_error_recipients:

View file

@ -15,7 +15,7 @@ custom_rules: [
tcp_ports: [443, 6523, 9418]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-veteran
freezes: false

View file

@ -12,7 +12,7 @@ tcp_ports: [ 80, 443, 111, 2049,
udp_ports: [ 111, 2049 ]
fas_client_groups: sysadmin-releng,fi-apprentice
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:

View file

@ -28,7 +28,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-koschei,fi-apprentice
fas_client_groups: sysadmin-koschei,fi-apprentice,sysadmin-noc,sysadmin-veteran
freezes: false

View file

@ -26,7 +26,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-koschei,fi-apprentice
fas_client_groups: sysadmin-koschei,fi-apprentice,sysadmin-noc,sysadmin-veteran
freezes: false

View file

@ -26,7 +26,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-koschei,fi-apprentice
fas_client_groups: sysadmin-koschei,fi-apprentice,sysadmin-noc,sysadmin-veteran
freezes: false

View file

@ -25,7 +25,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-koschei,fi-apprentice
fas_client_groups: sysadmin-koschei,fi-apprentice,sysadmin-noc,sysadmin-veteran
freezes: false

View file

@ -26,7 +26,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT',
]
fas_client_groups: sysadmin-koschei,fi-apprentice
fas_client_groups: sysadmin-koschei,fi-apprentice,sysadmin-noc,sysadmin-veteran
freezes: false

View file

@ -6,7 +6,7 @@ num_cpus: 2
tcp_ports: [ 443 ]
fas_client_groups: sysadmin-noc,sysadmin-qa,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-qa,fi-apprentice,sysadmin-veteran
# These are consumed by a task in roles/fedmsg/base/main.yml
# We don't really use the announce cert.. but it was supposed to be a way for

View file

@ -9,4 +9,4 @@ num_cpus: 1
tcp_ports: [ 11211 ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran

View file

@ -9,4 +9,4 @@ num_cpus: 1
tcp_ports: [ 11211 ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran

View file

@ -19,7 +19,7 @@ custom6_rules: [ '-A INPUT -p tcp -m tcp -s 2610:28:3090:3001:dead:beef:cafe:fed
'-A INPUT -p tcp -m tcp -s 2a00:d1a0:1::131 --dport 443 -j ACCEPT', ]
collectd_apache: true
fas_client_groups: sysadmin-web,sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-web,sysadmin-noc,fi-apprentice,sysadmin-veteran
nrpe_procs_warn: 1200
nrpe_procs_crit: 1400
# By default run 45 wsgi procs

View file

@ -10,7 +10,7 @@ custom_rules: [ '-A INPUT -p tcp -m tcp -s 192.168.0.0/16 --dport 80 -j ACCEPT',
'-A INPUT -p tcp -m tcp -s 10.5.126.0/24 --dport 443 -j ACCEPT' ]
collectd_apache: true
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
nrpe_procs_warn: 500
nrpe_procs_crit: 600
# By default run 45 wsgi procs

View file

@ -9,7 +9,7 @@ num_cpus: 4
tcp_ports: [ 22, 25, 80, 443 ]
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-web,fi-apprentice,sysadmin-hosted,sysadmin-veteran
freezes: false
postfix_group: vpn

View file

@ -6,7 +6,7 @@ num_cpus: 2
tcp_ports: [ 80, 443, 8443]
fas_client_groups: sysadmin-releng,fi-apprentice
fas_client_groups: sysadmin-releng,fi-apprentice,sysadmin-noc,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
docker_cert_dir: "/etc/docker/certs.d/registry.stg.fedoraproject.org"

View file

@ -12,6 +12,6 @@ tcp_ports: [ 80, 443, 8888 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-paste,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-paste,fi-apprentice,sysadmin-veteran
# This host doesn't freeze
freezes: false

View file

@ -12,6 +12,6 @@ tcp_ports: [ 80, 443, 8888 ]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.5.126.13 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
fas_client_groups: sysadmin-noc,sysadmin-paste,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-paste,fi-apprentice,sysadmin-veteran
# This host doesn't freeze
freezes: false

View file

@ -65,7 +65,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.131.71 -j ACCEPT',
]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
collectd_apache: true

View file

@ -70,7 +70,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp --dport 9941 -s 10.5.131.72 -j ACCEPT',
]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
collectd_apache: true

View file

@ -7,7 +7,7 @@ num_cpus: 1
# for systems that do not match the above - specify the same parameter in
# the host_vars/$hostname file
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice,sysadmin-noc,sysadmin-veteran
# this enables infrastructure-testing repo

View file

@ -8,6 +8,6 @@ nrpe_procs_crit: 1000
# nfs mount options, overrides the all/default
nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,actimeo=600,nfsvers=4"
fas_client_groups: sysadmin-noc,alt-sugar,alt-k12linux,altvideos,hosted-content,mips-content,s390_content,fi-apprentice,qa-deltaisos
fas_client_groups: sysadmin-noc,alt-sugar,alt-k12linux,altvideos,hosted-content,mips-content,s390_content,fi-apprentice,qa-deltaisos,sysadmin-veteran
host_group: secondary

View file

@ -9,7 +9,7 @@ num_cpus: 2
tcp_ports: [ 25 ]
fas_client_groups: sysadmin-noc,sysadmin-tools,fi-apprentice
fas_client_groups: sysadmin-noc,sysadmin-tools,fi-apprentice,sysadmin-veteran
postfix_transport_filename: transports.mm-smtp
postfix_group: smtp-mm

View file

@ -8,7 +8,7 @@ num_cpus: 2
# the host_vars/$hostname file
tcp_ports: [ 80, 873 ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
# This gets overridden by whichever node we want to run special cronjobs.
master_sundries_node: False

View file

@ -8,7 +8,7 @@ num_cpus: 2
# the host_vars/$hostname file
tcp_ports: [ 80, 873 ]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
# This gets overridden by whichever node we want to run special cronjobs.
master_sundries_node: False

View file

@ -3,7 +3,7 @@
# general information
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice,sysadmin-noc,sysadmin-veteran
tcp_ports: [ 80, 443, "{{ buildslave_port }}" ]
freezes: false

View file

@ -7,7 +7,7 @@ num_cpus: 2
tcp_ports: [ 53, 80, 443, 873, "6881:6999" ]
udp_ports: [ 53 ]
fas_client_groups: sysadmin-web,torrentadmin,sysadmin-noc,torrent-cc,fi-apprentice
fas_client_groups: sysadmin-web,torrentadmin,sysadmin-noc,torrent-cc,fi-apprentice,sysadmin-veteran
nrpe_procs_warn: 300
nrpe_procs_crit: 500

View file

@ -23,7 +23,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 10.5.126.23 --dport 5050 -j ACCEPT',
]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-mote
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-mote,sysadmin-veteran
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:

View file

@ -23,7 +23,7 @@ custom_rules: [
'-A INPUT -p tcp -m tcp -s 10.5.126.23 --dport 5050 -j ACCEPT',
]
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-mote
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-mote,sysadmin-veteran
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:

View file

@ -9,7 +9,7 @@ num_cpus: 4
virt_install_command: "{{ virt_install_command_rhel6 }}"
tcp_ports: [ 80 ]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
# mediawiki variables
wikiname: "fp"

View file

@ -9,7 +9,7 @@ num_cpus: 2
virt_install_command: "{{ virt_install_command_rhel6 }}"
tcp_ports: [ 80 ]
fas_client_groups: sysadmin-noc,fi-apprentice
fas_client_groups: sysadmin-noc,fi-apprentice,sysadmin-web,sysadmin-veteran
# mediawiki variables
wikiname: "fp"

View file

@ -1,4 +1,4 @@
fas_client_groups: sysadmin-noc,sysadmin-releng
fas_client_groups: sysadmin-noc,sysadmin-releng,sysadmin-veteran
kojipkgs_url: armpkgs.fedoraproject.org
kojihub_url: arm.koji.fedoraproject.org/kojihub

View file

@ -11,7 +11,7 @@ datacenter: phx2
nrpe_procs_warn: 900
nrpe_procs_crit: 1000
fas_client_groups: sysadmin-noc,sysadmin-secondary
fas_client_groups: sysadmin-noc,sysadmin-secondary,sysadmin-veteran
fedmsg_fqdn: arm-koji01.qa.fedoraproject.org

View file

@ -12,4 +12,4 @@ eth0_nm: 255.255.255.128
vmhost: virthost-comm03.qa.fedoraproject.org
datacenter: phx2
fas_client_groups: sysadmin-main,sysadmin-noc,sysadmin-qa,fi-apprentice,sysadmin-releng,sysadmin-kernel,arm-qa,sysadmin-centos,qa-automation-shell,sysadmin-troubleshoot,sysadmin-atomic,sysadmin-ppc
fas_client_groups: sysadmin-main,sysadmin-noc,sysadmin-qa,fi-apprentice,sysadmin-veteran,sysadmin-releng,sysadmin-kernel,arm-qa,sysadmin-centos,qa-automation-shell,sysadmin-troubleshoot,sysadmin-atomic,sysadmin-ppc

View file

@ -22,7 +22,7 @@ eth1_gw: 10.5.127.254
vmhost: bvirthost10.phx2.fedoraproject.org
datacenter: phx2
fas_client_groups: sysadmin-noc,sysadmin-releng
fas_client_groups: sysadmin-noc,sysadmin-releng,sysadmin-veteran
koji_hub_nfs: "fedora_koji"

View file

@ -22,7 +22,7 @@ dbs_to_backup:
lvm_size: 500000
mem_size: 8192
num_cpus: 12
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-secondary
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-secondary,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers"
# kernel SHMMAX value

View file

@ -22,7 +22,7 @@ lvm_size: 500000
mem_size: 16384
num_cpus: 8
tcp_ports: [ 5432, 443 ]
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
# kernel SHMMAX value
kernel_shmmax: 68719476736

View file

@ -22,7 +22,7 @@ dbs_to_backup:
lvm_size: 100000
mem_size: 8192
num_cpus: 4
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
#
# Only allow postgresql access from the frontend nodes and hosted.

View file

@ -22,7 +22,7 @@ dbs_to_backup:
lvm_size: 30000
mem_size: 4096
num_cpus: 2
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
#
# Only allow postgresql access from the frontend node and ipsilon01.stg

View file

@ -22,7 +22,7 @@ dbs_to_backup:
lvm_size: 300000
mem_size: 32768
num_cpus: 16
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
# kernel SHMMAX value
kernel_shmmax: 68719476736

View file

@ -21,7 +21,7 @@ databases:
dbs_to_backup:
- koji
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-releng
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-releng,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/00releng-sudoers"
# These are normally group variables, but in this case db servers are often different

View file

@ -42,7 +42,7 @@ lvm_size: 300000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 5432, 443, 3306 ]
fas_client_groups: sysadmin-qa,sysadmin-noc
fas_client_groups: sysadmin-qa,sysadmin-noc,sysadmin-veteran
# kernel SHMMAX value
kernel_shmmax: 68719476736

View file

@ -22,7 +22,7 @@ dbs_to_backup:
lvm_size: 500000
mem_size: 25165
num_cpus: 12
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-secondary
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-secondary,sysadmin-veteran
sudoers: "{{ private }}/files/sudo/sysadmin-secondary-sudoers"
# kernel SHMMAX value

View file

@ -62,7 +62,7 @@ dbs_to_backup:
lvm_size: 300000
mem_size: 16384
num_cpus: 10
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
#
# We should narrow this down at some point

View file

@ -31,7 +31,7 @@ databases:
lvm_size: 300000
mem_size: 16384
num_cpus: 4
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
#
# We should narrow this down at some point

View file

@ -29,7 +29,7 @@ lvm_size: 300000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 5432, 443, 3306 ]
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
# kernel SHMMAX value
kernel_shmmax: 68719476736

View file

@ -23,7 +23,7 @@ lvm_size: 300000
mem_size: 8192
num_cpus: 2
tcp_ports: [ 5432, 443, 3306 ]
fas_client_groups: sysadmin-dba,sysadmin-noc
fas_client_groups: sysadmin-dba,sysadmin-noc,sysadmin-veteran
# kernel SHMMAX value
kernel_shmmax: 68719476736

View file

@ -20,6 +20,6 @@ lvm_size: 32768
mem_size: 16384
num_cpus: 16
fas_client_groups: fi-apprentice,sysadmin-logs,sysadmin-noc
fas_client_groups: fi-apprentice,sysadmin-veteran,sysadmin-logs,sysadmin-noc
host_backup_targets: ['/var/log']

View file

@ -22,7 +22,7 @@ datacenter: phx2
# virtual machine
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
lvm_size: 768000
mem_size: 4096

View file

@ -22,7 +22,7 @@ datacenter: phx2
# virtual machine
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
lvm_size: 768000
mem_size: 4096

View file

@ -24,7 +24,7 @@ datacenter: phx2
# virtual machine
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
lvm_size: 50000
mem_size: 4096
num_cpus: 4

View file

@ -28,7 +28,7 @@ datacenter: phx2
# virtual machine
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
lvm_size: 50000
mem_size: 4096

View file

@ -28,7 +28,7 @@ vmhost: virthost-comm03.qa.fedoraproject.org
# virtual machine
############################################################
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
lvm_size: 50000
mem_size: 4096
num_cpus: 4

View file

@ -12,7 +12,7 @@ datacenter: phx2
nrpe_procs_warn: 900
nrpe_procs_crit: 1000
fas_client_groups: sysadmin-noc,sysadmin-secondary
fas_client_groups: sysadmin-noc,sysadmin-secondary,sysadmin-veteran
fedmsg_fqdn: s390-koji01.qa.fedoraproject.org

View file

@ -18,7 +18,7 @@ volgroup: /dev/vg_guests
vmhost: virthost-comm04.qa.fedoraproject.org
datacenter: phx2
fas_client_groups: sysadmin-qa,sysadmin-main,fi-apprentice
fas_client_groups: sysadmin-qa,sysadmin-main,sysadmin-noc,fi-apprentice,sysadmin-veteran
############################################################
# virtual machine