Commit graph

298 commits

Author SHA1 Message Date
Kevin Fenzi
e82d21eefd haproxy: decrease chances of marking ipsilon down
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-03-31 09:36:13 -07:00
Aurélien Bompard
b8e6754f97 Use a VM for Ipsilon in prod too
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-03-23 16:55:38 +00:00
Pierre-Yves Chibon
25ff2bea69 haproxy: let's assume zabbix is up for now
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-18 10:11:12 +01:00
Pierre-Yves Chibon
7d1fbba00d haproxy: be more flexible for zabbix
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 17:04:21 +01:00
Pierre-Yves Chibon
23c7ef8c20 haproxy: zabbix returns either 200 or 401 - maybe this way?
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 16:49:43 +01:00
Pierre-Yves Chibon
36de1196e1 haproxy: zabbix returns either 200 or 401
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 16:45:58 +01:00
Pierre-Yves Chibon
ea9d107ef8 haproxy: zabbix now returns 401
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 16:40:32 +01:00
Pierre-Yves Chibon
b3a0df510d haproxy: fix the path where haproxy check for zabbix
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 15:58:50 +01:00
Pierre-Yves Chibon
157e8029a8 haproxy: add support for zabbix in haproxy but stg only
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2021-03-17 10:34:30 +01:00
Aurélien Bompard
aace9bb2cc
New certificate for IPA in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-02-12 11:39:24 +01:00
Adrian Reber
cb4bb12298 mirrorlist: clean up unused definitions
Remove everything which is related to running the mirrorlist server
process as a container. This has not been used for the last few months.

Also remove the 3 mirrorlist process setup for IAD2 as it is no longer
necessary and removing it also simplifies the configuration.

Signed-off-by: Adrian Reber <adrian@lisas.de>
2020-11-17 07:32:01 +00:00
Aurélien Bompard
38cc67731b
Proxy: attempt to move ipsilon back to a VM in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-07 10:59:41 +02:00
Pierre-Yves Chibon
c0f7fa3e8c proxy: bring back pdc-backend, this one doesn't have anything to do with the pdc-backend hosts
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-10-06 15:49:06 +02:00
Pierre-Yves Chibon
f91a80046b Wipe everything that is to do with pdc-backend from our ansible repo
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-10-05 18:57:52 +00:00
Kevin Fenzi
e6a1139cec haproxy / staging: update openshift ca cert for haproxy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-31 11:31:12 -07:00
Kevin Fenzi
516d5e77e8 haproxy: fix conditional that was reversed for mbs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 10:06:47 -07:00
Kevin Fenzi
f19cb7f225 haproxy: adjust staging haproxy for things that should exist
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:56:35 -07:00
Kevin Fenzi
959fdaa00b haproxy: add a placeholder ca for openshift staging
Openshift doesn't exist in staging yet, but we want to finish mostly
building out proxy01 before doing that, so set a placeholder ca here
until we can update it with the real one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:39:17 -07:00
Kevin Fenzi
16d012933c haproxy: add ipa stg cert for iad2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 21:52:12 -07:00
Stephen Smoogen
257a130bc8 remove zanata2fedmsg. the zanata roles are still there for the time being as they are tied into webstizes and such 2020-07-22 15:22:37 -04:00
Kevin Fenzi
506b41bb65 Add sundries02, wiki02 and datagrepper02
Add some more '02' instances to increase uptime/availibility.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-14 14:32:25 -07:00
Stephen Smoogen
857a3c623d this should remove a lot of things looking at phx2 systems 2020-06-10 09:18:11 -04:00
Kevin Fenzi
c7a0d2f3c4 also fix the ipa file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-08 15:20:15 -07:00
Kevin Fenzi
162bb8bf5e iad2-move: there is only one active openshift, and it is the iad2 one, use its ssl cert
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-08 15:17:15 -07:00
Kevin Fenzi
83d76a8614 iad2: haproxy: fix up openshift certs so iad2 and phx2 are correct and both install. Just copy the phx2 ipa pem for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-28 10:46:48 -07:00
Kevin Fenzi
e92d630821 iad2: pkgs01 in iad2, not pkgs02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-26 19:37:13 -07:00
Kevin Fenzi
5097e46eb0 iad2: haproxy: adjust haproxy for iad2, should make kojipkgs, src and rabbitmq reachable
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-26 18:34:27 -07:00
Pierre-Yves Chibon
cb93ea22a1 proxy: Fix a number of links in the 503 error template
See https://pagure.io/fedora-infrastructure/issue/8452 for
some more context about this change.

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-04-24 21:34:20 +02:00
Rick Elrod
6208045041 fix tags
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Rick Elrod
0dded6b55c install libsemanage a few more times because twice is not enough
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Rick Elrod
ea96618bd4 Get rid of modernpaste everywhere, redirect it to paste.centos.org everywhere
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Kevin Fenzi
779fa01877 autocloud: fare well autocloud, you served long and well...
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:17 +02:00
Kevin Fenzi
e50fa5f3f2 freshmaker: remove everything
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:14 +02:00
Mikolaj Izdebski
28156f917d haproxy: Remove Koschei endpoints 2020-04-24 21:34:11 +02:00
Mikolaj Izdebski
7a50525e9b haproxy: Remove proxy for mdapi 2020-04-24 21:34:11 +02:00
Kevin Fenzi
6d54f56f5d happroxy: switch that and try uri balancing.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-07-21 18:43:08 +00:00
Kevin Fenzi
7d70382af9 haproxy: try and balance kojipkgs by source ip instead of appheader (which isn't even set here)?
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-07-21 18:28:38 +00:00
Kevin Fenzi
73dae59db8 elections: clean up some old stuff from the old site and add redirect to new.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-05-31 17:57:13 +00:00
Patrick Uiterwijk
c9cba10f70 Remove fas02 references from haproxy and varnish
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-24 20:59:36 +02:00
Stephen Smoogen
658a22035b remove fas03 from inventory and a LOT of config files where it was hard-coded 2019-05-23 22:53:51 +00:00
Patrick Uiterwijk
e4fbd6f88a haproxy: remove FAS
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:22:28 +02:00
Patrick Uiterwijk
766f34132e haproxy: remove ipsilon
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:22:03 +02:00
Patrick Uiterwijk
d1f6227a91 haproxy: remove koji entries
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:18:23 +02:00
Kevin Fenzi
bb3d49b94e haproxy / koji: add koji02 into load balancing in haproxy so we can reboot nodes.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-05-21 22:20:02 +00:00
Patrick Uiterwijk
f5e2a0eabc Add 8443 for totp to proxies
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-11 20:43:03 +02:00
Clement Verna
18048e10ed fedora-hubs: delete unused ansible role + config
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-24 10:37:06 +02:00
Stephen Smoogen
194b0058c6 remove retrace02 from inventory and files. Leave mgmt as it is still plugged in and may show up. 2019-04-05 19:19:58 +00:00
Patrick Uiterwijk
2476040c97 There are also three rabbitmq nodes in staging
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-25 22:09:35 +01:00
Patrick Uiterwijk
b4c94a8688 haproxy: add missing trailing quotes
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-14 21:37:45 +01:00
Patrick Uiterwijk
0f6a6db888 Add rabbitmq proxying to the proxies
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-12 19:28:47 +01:00