Commit graph

32863 commits

Author SHA1 Message Date
Mark O'Brien
e16418f602 Merge branch 'master' of ssh://pagure.io/fedora-infra/ansible 2020-07-28 15:35:06 +01:00
Mark O'Brien
6994fef4f8 [proxies] new proxy33 in aws capetown 2020-07-28 15:34:59 +01:00
Silvie Chlupova
67b5f69f2d copr: add architecture s390x 2020-07-28 13:49:39 +02:00
Kevin Fenzi
74f76fb624 openshift / staging: adjust nfs mounts for iad2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 15:49:26 -07:00
Kevin Fenzi
7825d7664b base keytab: try and just use --force here
We made this change for other keytabs, so just do it here too.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 15:35:00 -07:00
Kevin Fenzi
461fbcf0aa Revert "base / keytab: Try and throttle task to 1"
Didn't help. ;(

This reverts commit 37db5af9f0.
2020-07-27 15:30:48 -07:00
Kevin Fenzi
37db5af9f0 base / keytab: Try and throttle task to 1
This task seems to fail with a nameserver failed to answer message when
you provision a bunch of hosts at once. Try running just one at a time
and see if it helps any.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 15:27:21 -07:00
Kevin Fenzi
6a5de33aa9 use correct dns server for os-control01.stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 15:12:43 -07:00
Kevin Fenzi
5142adfa02 use the correct network for os-nodeNN.stg instances.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 14:41:38 -07:00
Kevin Fenzi
c242ed601d bvmhost-x86-01.stg: use correct interface for bridge/clevis
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 13:07:44 -07:00
Kevin Fenzi
a0db3baae9 pdc-web01/02: double memory to 32gb
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 12:24:19 -07:00
Kevin Fenzi
f824fda069 inventory: add new virthosts in staging to staging group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 11:46:37 -07:00
Kevin Fenzi
d2851fdd07 Revert "inventory: use br_gw and gw both"
This reverts commit bb6499236e.
2020-07-27 11:34:45 -07:00
Kevin Fenzi
bb6499236e inventory: use br_gw and gw both
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 11:33:46 -07:00
Kevin Fenzi
33c605ae66 inventory: add in bvmhost-x86-01.stg and vmhost-x86-03.stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 11:31:27 -07:00
Kevin Fenzi
97de1470d3 os-cluster: fix syntax on including fas_client in stg.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 10:02:34 -07:00
Kevin Fenzi
42a840c053 inventory: add initial openshift cluster for staging into inventory
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-27 09:59:11 -07:00
Mohan Boddu
ad03d0ad88 Revert "Revert "Revert "inventory: re-add autosign01 to run ansible against it"""
We are disabling the autosign01.iad2.fp.o so that nagios wont complain
about it with ssh turned off and to disable someone running something
like 'ansible something all'

This reverts commit 91671f86cc.
2020-07-27 10:35:38 -04:00
Mohan Boddu
91671f86cc Revert "Revert "inventory: re-add autosign01 to run ansible against it""
This reverts commit a34a8e9430.
2020-07-27 10:28:04 -04:00
Mohan Boddu
0d9e49a7ec Setup for F33 Mass Rebuild
Adding f33-rebuild tag

Signed-off-by: Mohan Boddu <mboddu@bhujji.com>
2020-07-27 09:05:05 -04:00
Pierre-Yves Chibon
4ceb0b2c1c distgit/pagure: Drop old code dealing with phx2 and py2 and rhel7
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-07-27 09:46:58 +02:00
Pierre-Yves Chibon
84f046eaba distgit/pagure: Drop 1755 in favor of spelled out permissions on /var/log/pagure
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-07-27 09:44:44 +02:00
Kevin Fenzi
6b89c6277d db-koji01: Try adjusting effective cache size to what postgresql suggests
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-26 11:50:14 -07:00
Kevin Fenzi
516d5e77e8 haproxy: fix conditional that was reversed for mbs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 10:06:47 -07:00
Dusty Mabe
64322971e0 koji_hub: allow update/remove for sidetag owners
https://pagure.io/releng/issue/9229#comment-667272
2020-07-25 16:58:55 +00:00
Kevin Fenzi
f19cb7f225 haproxy: adjust staging haproxy for things that should exist
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:56:35 -07:00
Kevin Fenzi
959fdaa00b haproxy: add a placeholder ca for openshift staging
Openshift doesn't exist in staging yet, but we want to finish mostly
building out proxy01 before doing that, so set a placeholder ca here
until we can update it with the real one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:39:17 -07:00
Kevin Fenzi
16d012933c haproxy: add ipa stg cert for iad2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 21:52:12 -07:00
Kevin Fenzi
a47fccbf0a staging: fix the intermediate cert for wildcard
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 19:09:49 -07:00
Kevin Fenzi
c5da244a17 websites: try and disable letsencrypt/certbot in stg
Right now we don't have a working certgetter, so disable these for now
until we can get certgetter01 able to go out and get certs.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 18:09:30 -07:00
Kevin Fenzi
2d95e93d1d certgetter: do not include fas_client or 2fa in stg for now.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 15:48:47 -07:00
Kevin Fenzi
410c81e91c inventory: also add certgetter01.stg to staging group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 15:10:12 -07:00
Kevin Fenzi
2d8bf791cd inventory: create a certgetter01.stg instance and use it in stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 15:07:56 -07:00
Kevin Fenzi
14f05eb02f openshift-apps / message-tagging-service: MTS_CONFIG_VERSION has to be a string
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 14:57:52 -07:00
Adam Williamson
a2bef634cf openqa/worker: use include_tasks not import_tasks
Using `when` with `import_tasks` doesn't actually skip the import
entirely, it just imports the tasks and skips them one by one.
Which reads oddly. `include_tasks` is properly dynamic so seems
better here.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2020-07-24 14:11:21 -07:00
Patrick Uiterwijk
97234b1c83 Also add DNS check override for host check
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-07-24 22:42:55 +02:00
Kevin Fenzi
665964a79f ipa / server: fix files to have correct suffix
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 13:23:05 -07:00
Patrick Uiterwijk
7cdcbb5880 Make all ldif files apply on all IPA boxes. Not everything gets synced
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-07-24 22:09:18 +02:00
Patrick Uiterwijk
7db1377081 Do not require hosts to be in the IPA DNS zone
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2020-07-24 22:05:55 +02:00
Stephen Smoogen
5908e7b681 turns out even if fedmsg is not actually listening on the ports it is supposed to do so it is still supposed to do fedmsg 2020-07-24 14:11:27 -04:00
Mark O'Brien
c82df0f30b [maintainer-test] dont need this anymore fedora user has been removed 2020-07-24 13:16:03 +01:00
Mark O'Brien
d95a26b3e7 [maintainer-test] lets try update without creating the file 2020-07-24 11:21:44 +01:00
Pierre-Yves Chibon
e6c0433e19 distgit/pagure: set the sticky bit on /var/log/pagure so the group membership remains
The owner itself does not really matter, especially when considering the
section above where the pagure user is created in the packager group.

Fixes https://pagure.io/releng/issue/9623

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-07-24 11:24:28 +02:00
Adam Williamson
d9f5530046 openqa/worker: configure to use 172. IP range not 10.
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2020-07-23 17:27:19 -07:00
Stephen Smoogen
aa6dc95c84 try and make buildhw-a64 ip address work on eth1 versus eth0 2020-07-23 16:53:42 -04:00
Stephen Smoogen
9246a167db make sure endpoints no longer used are removed 2020-07-23 16:04:45 -04:00
Kevin Fenzi
0eb6dae00e playbooks: ipa/proxies: 2fa also only in prod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-23 12:30:44 -07:00
Kevin Fenzi
7d4333cda3 inventory: add ipa01.stg to iad2 group
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-23 12:24:22 -07:00
Kevin Fenzi
2ee56651b0 playbooks: ipa/proxies: make fasClient only prod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-23 12:24:22 -07:00
Stephen Smoogen
93ea8c9830 do not copy a file which no longer exists 2020-07-23 15:11:05 -04:00