Commit graph

39807 commits

Author SHA1 Message Date
Pedro Moura
680965df6f fix membership-map task lint
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2023-09-25 12:43:59 -03:00
Pedro Moura
9d1f56f39c add task to remove membership-map files in stg in proxies.yml
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2023-09-22 15:51:49 -03:00
Kevin Fenzi
498f213226 add another cmmunishift poc project
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-22 10:38:59 -07:00
Kevin Fenzi
605f282f7b rkhunter: adjust email for rkhunter
I don't think Patrick and Mark care about these emails anymore.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-22 10:23:07 -07:00
Kevin Fenzi
6fa4f6752e ipsilon: increase memory on ipsilon vm's
The ipsilon vm's have been swapping and using a lot of memory.
We have memory to spare on those virthosts, so just bump it up to 32.
Might be this will help some slowness / timeout issues some folks have
seen authenticating to matrix and bugzilla.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-22 09:54:56 -07:00
Aurélien Bompard
ba1c0bff89
Run Datanommer on Python 3.11
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-09-22 12:35:01 +02:00
Aurélien Bompard
1784fd2189
Fixup 6a1d210c
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-09-22 12:26:17 +02:00
Aurélien Bompard
6a1d210c8a
Activate Github webhook for Datanommer and Datagrepper
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-09-22 09:17:19 +02:00
Kevin Fenzi
ceec274e27 retrace: configure ipv6 address
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 17:06:05 -07:00
Kevin Fenzi
4baa78d8d1 inventory: comment out one of those hosts completely
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 16:28:54 -07:00
f5d034bc10 maubot: remove named supplmental group
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-22 09:10:08 +10:00
8cb4866fb2 maubot: try a named supplmental group
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-22 09:04:27 +10:00
Kevin Fenzi
638c0ff9a6 ipa03.stg: comment out for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 15:56:23 -07:00
Kevin Fenzi
20f56c51fe inventory: also comment those hosts in cloud inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 15:42:39 -07:00
Kevin Fenzi
bdb8ecadd0 inventory: disable some dev copr instances for now until they are ready to be deployed
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 15:09:19 -07:00
Kevin Fenzi
d8cfd2c93b virthost: drop some no longer used host groups
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 14:08:21 -07:00
Kevin Fenzi
f0e6442a27 noc: drop bodhi nagios alert group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 14:01:18 -07:00
Kevin Fenzi
2bb693daa1 noc: drop mod_wsgi for now it may no longer be needed
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 13:41:06 -07:00
ccd49cdcdd
languages: update scripts parameters 2023-09-21 22:29:02 +02:00
Kevin Fenzi
d55ae6a8fa noc02: fix network variables to new style
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 13:13:32 -07:00
Kevin Fenzi
baf6dbc0b0 noc02: move to rhel9 and ibiblio02
This is a rhel7 instance, move it to rhel9.
Also, ibiblio01 is old and going away, so move it to 02.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-21 13:10:46 -07:00
Pedro Moura
4b039f6d46 Add membership-map files to remove from mirrormanager
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2023-09-21 18:08:03 +00:00
Pedro Moura
b3a5e9de30 Add task to remove files from membership-map
Signed-off-by: Pedro Moura <pmoura@redhat.com>
2023-09-21 18:08:03 +00:00
Michal Konecny
17f02d725a [Pagure] Enable safe directories for production
See https://pagure.io/fedora-infrastructure/issue/11330 for more details.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-21 17:19:38 +02:00
Aurélien Bompard
71a0ae8a5b
Activate Github webhook for Noggin
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2023-09-21 14:04:16 +02:00
33293382fb
zabbix: change zabbix-agent service to restarted
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-09-21 10:48:17 +01:00
afe4e0b224
zabbix: change zabbix_server service to state restarted
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-09-21 10:42:28 +01:00
92bd0c9cd4
zabbix: modify startservices task to restart zabbix server
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-09-21 10:22:27 +01:00
0920e7ae47
zabbix: Update db creation task to continue when db exists
Signed-off-by: David Kirwan <davidkirwanirl@gmail.com>
2023-09-21 08:33:42 +01:00
Kevin Fenzi
197d53a9ba aliases: add hetznercloud alias ( ticket 11518 )
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 18:25:26 -07:00
Kevin Fenzi
ad7521f4b6 mirrors: update ip for rackspace mirror acl (ticket 11533)
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 18:11:59 -07:00
a65b78ca06 maubot: add gid 2 as a supplemental group
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-21 08:37:16 +10:00
Adam Williamson
5f56b3a370 Give myself more fedorapeople quota
I need to upload some ISOs...

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2023-09-20 14:49:49 -07:00
302084a1f1 maubot: put logging config back to normal
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-21 06:45:12 +10:00
Kevin Fenzi
1c43429266 ipa / client: just remove the sshd override file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 12:10:32 -07:00
Kevin Fenzi
308ff1a8ce Revert "ipa / client: pass --no-sshd to client enroll"
This reverts commit df1445a64b.

Turns out we do have to enable sshd on client enroll because it passes
'ssh' to services in sssd.conf, which we need to get ssh keys for users.
:( Instead will try another approach.
2023-09-20 12:07:06 -07:00
Kevin Fenzi
9d22463f7e zabbix / staging: enable ipa client here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 11:24:27 -07:00
Kevin Fenzi
df1445a64b ipa / client: pass --no-sshd to client enroll
In RHEL9, ipa-enroll-client by default adds a
/etc/ssh/sshd_config.d/04-ipa.conf file with some sshd configuration.
Almost all of these things are things we already set in our sshd_config,
but one of them causes sshd to enable password (and 2nd factor required)
auth. We don't want this, we only want to allow ssh keys.
So, pass --no-sshd to enrollment and that should prevent it from
messing with our sshd config.

I have also removed this file and reloaded sshd all around.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 10:52:17 -07:00
Kevin Fenzi
6f48779818 koji_builder: switch to 30s sleep time
Right now builders are checking in every 20s, but that puts a lot of
load on the db server. Having them check in every 30s should ease that
some. Might increase it higher as well.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 09:31:39 -07:00
Kevin Fenzi
2d8fe00180 sundries / staging / budget: move this sync to every hour instead of every 5 minutes to avoid cron noise
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 09:30:47 -07:00
Kevin Fenzi
255b4d87bb With the release of Fedora 39 Beta yesterday, infrastructure freeze is now over.
Our next freeze is for Fedora 39 final release, currently scheduled for 2023-10-03.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-09-20 09:15:08 -07:00
Michal Konecny
079a115f8f Disable ipa_initial on ipa03.stg
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-20 16:41:23 +02:00
Michal Konecny
8a6b5a7c65 [IPA-Server]Don't install pynag on RHEL9
pynag is not available on rhel9 yet.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-20 15:56:10 +02:00
Michal Konecny
dd6b5b1546 Set new ipa host ipa_initial variable to
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-20 15:36:48 +02:00
Michal Konecny
ab4b99a9e3 Fix the typo in ipa_stg inventory
Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-20 14:49:31 +02:00
Michal Konečný
9d4a47131d Add ipa03.stg to staging group in inventory
Signed-off-by: Michal Konečný <michal.konecny@pacse.eu>
2023-09-20 12:25:52 +00:00
Michal Konecny
2d088b91ca Add ipa03 host on staging
This is a test host to deploy ipa on RHEL9.

Signed-off-by: Michal Konecny <mkonecny@redhat.com>
2023-09-20 13:42:03 +02:00
64a6c0b011 maubot: update logging config
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-20 13:59:22 +10:00
Pavel Raiskup
48aa4e43bc copr-frontend: better "ps aux" output
It allows us to easily filter out all httpd processes in 'ps' or in
htop.
2023-09-18 14:03:46 +02:00
db612b10cd maubot: fix deps issue
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2023-09-18 15:02:56 +10:00