Commit graph

284 commits

Author SHA1 Message Date
Kevin Fenzi
e6a1139cec haproxy / staging: update openshift ca cert for haproxy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-31 11:31:12 -07:00
Kevin Fenzi
516d5e77e8 haproxy: fix conditional that was reversed for mbs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 10:06:47 -07:00
Kevin Fenzi
f19cb7f225 haproxy: adjust staging haproxy for things that should exist
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:56:35 -07:00
Kevin Fenzi
959fdaa00b haproxy: add a placeholder ca for openshift staging
Openshift doesn't exist in staging yet, but we want to finish mostly
building out proxy01 before doing that, so set a placeholder ca here
until we can update it with the real one.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-25 09:39:17 -07:00
Kevin Fenzi
16d012933c haproxy: add ipa stg cert for iad2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 21:52:12 -07:00
Stephen Smoogen
257a130bc8 remove zanata2fedmsg. the zanata roles are still there for the time being as they are tied into webstizes and such 2020-07-22 15:22:37 -04:00
Kevin Fenzi
506b41bb65 Add sundries02, wiki02 and datagrepper02
Add some more '02' instances to increase uptime/availibility.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-14 14:32:25 -07:00
Stephen Smoogen
857a3c623d this should remove a lot of things looking at phx2 systems 2020-06-10 09:18:11 -04:00
Kevin Fenzi
c7a0d2f3c4 also fix the ipa file
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-08 15:20:15 -07:00
Kevin Fenzi
162bb8bf5e iad2-move: there is only one active openshift, and it is the iad2 one, use its ssl cert
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-08 15:17:15 -07:00
Kevin Fenzi
83d76a8614 iad2: haproxy: fix up openshift certs so iad2 and phx2 are correct and both install. Just copy the phx2 ipa pem for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-28 10:46:48 -07:00
Kevin Fenzi
e92d630821 iad2: pkgs01 in iad2, not pkgs02
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-26 19:37:13 -07:00
Kevin Fenzi
5097e46eb0 iad2: haproxy: adjust haproxy for iad2, should make kojipkgs, src and rabbitmq reachable
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-26 18:34:27 -07:00
Pierre-Yves Chibon
cb93ea22a1 proxy: Fix a number of links in the 503 error template
See https://pagure.io/fedora-infrastructure/issue/8452 for
some more context about this change.

Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-04-24 21:34:20 +02:00
Rick Elrod
6208045041 fix tags
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Rick Elrod
0dded6b55c install libsemanage a few more times because twice is not enough
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Rick Elrod
ea96618bd4 Get rid of modernpaste everywhere, redirect it to paste.centos.org everywhere
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-04-24 21:34:18 +02:00
Kevin Fenzi
779fa01877 autocloud: fare well autocloud, you served long and well...
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:17 +02:00
Kevin Fenzi
e50fa5f3f2 freshmaker: remove everything
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:14 +02:00
Mikolaj Izdebski
28156f917d haproxy: Remove Koschei endpoints 2020-04-24 21:34:11 +02:00
Mikolaj Izdebski
7a50525e9b haproxy: Remove proxy for mdapi 2020-04-24 21:34:11 +02:00
Kevin Fenzi
6d54f56f5d happroxy: switch that and try uri balancing.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-07-21 18:43:08 +00:00
Kevin Fenzi
7d70382af9 haproxy: try and balance kojipkgs by source ip instead of appheader (which isn't even set here)?
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-07-21 18:28:38 +00:00
Kevin Fenzi
73dae59db8 elections: clean up some old stuff from the old site and add redirect to new.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-05-31 17:57:13 +00:00
Patrick Uiterwijk
c9cba10f70 Remove fas02 references from haproxy and varnish
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-24 20:59:36 +02:00
Stephen Smoogen
658a22035b remove fas03 from inventory and a LOT of config files where it was hard-coded 2019-05-23 22:53:51 +00:00
Patrick Uiterwijk
e4fbd6f88a haproxy: remove FAS
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:22:28 +02:00
Patrick Uiterwijk
766f34132e haproxy: remove ipsilon
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:22:03 +02:00
Patrick Uiterwijk
d1f6227a91 haproxy: remove koji entries
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-22 09:18:23 +02:00
Kevin Fenzi
bb3d49b94e haproxy / koji: add koji02 into load balancing in haproxy so we can reboot nodes.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-05-21 22:20:02 +00:00
Patrick Uiterwijk
f5e2a0eabc Add 8443 for totp to proxies
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-05-11 20:43:03 +02:00
Clement Verna
18048e10ed fedora-hubs: delete unused ansible role + config
Signed-off-by: Clement Verna <cverna@tutanota.com>
2019-04-24 10:37:06 +02:00
Stephen Smoogen
194b0058c6 remove retrace02 from inventory and files. Leave mgmt as it is still plugged in and may show up. 2019-04-05 19:19:58 +00:00
Patrick Uiterwijk
2476040c97 There are also three rabbitmq nodes in staging
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-25 22:09:35 +01:00
Patrick Uiterwijk
b4c94a8688 haproxy: add missing trailing quotes
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-14 21:37:45 +01:00
Patrick Uiterwijk
0f6a6db888 Add rabbitmq proxying to the proxies
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2019-03-12 19:28:47 +01:00
Stephen Smoogen
58a9e4d4e5 ok let us try and make proxy01/10 have 3 engines 2019-02-25 19:35:27 +00:00
Stephen Smoogen
b44f095866 haproxy: test mirrorlist in stg 2019-02-25 18:30:00 +00:00
Kevin Fenzi
8cd7031fa0 haproxy: fix haproxy config to listen for the fedmsgs that fedmsg-gateway emits.
Turns out that 'localhost' resolves to ::1 now, but we aren't using ipv6 here but
ipv4, so haproxy was listening in the wrong place for fedmsgs to appear.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-01-10 18:22:05 +00:00
Rick Elrod
daeaae624a make the dir here instead
Signed-off-by: Rick Elrod <relrod@redhat.com>
2018-12-17 18:46:44 +00:00
Kevin Fenzi
91948c4581 switch mirrorlist containers to podman 2018-12-12 20:06:59 +00:00
Kevin Fenzi
d57f891ade Fix staging oci-registry to point to 01 only since we don't have a 02 anymore.
This commit should make no changes to production and thus shouldn't need a freeze break.
2018-10-11 22:07:33 +00:00
David Shier
c0f45892ff Removed all traces i could fild of the tagger and statscache (and stats_cache for databases) in ansible, proxy configs, and the nagios config. Pursuant to request in pagzre issue https://pagure.io/fedora-infrastructure/issue/7267 . - Odin2016 2018-10-03 17:50:38 +00:00
Patrick Uiterwijk
fc7005848a Clear OpenShift from haproxy. It's using apache mod_proxy_balancer
Signed-off-by: Patrick Uiterwijk <patrick@puiterwijk.org>
2018-09-28 18:02:42 +02:00
Kevin Fenzi
ff74860db5 new ca cert for prod openshift 2018-09-27 22:27:51 +00:00
Kevin Fenzi
6ca94af4e4 Openshift redeploy to production.
Add 3 more nodes (we might use one later for staging)
move to latest openshift ansible
Change config to do multitenant, have logs and other config tweaks.
2018-09-27 21:04:49 +00:00
Mikolaj Izdebski
0a67a43d54 Clean up haproxy config for copr 2018-09-27 09:25:46 +00:00
Mikolaj Izdebski
ae45945a4b Revert "Configure haproxy for copr prod"
This reverts commit d6384fbba2.
2018-09-27 09:23:20 +00:00
Mikolaj Izdebski
d6384fbba2 Configure haproxy for copr prod 2018-09-27 09:19:23 +00:00
Kevin Fenzi
452b5f50a4 fix copr frontend in prod too 2018-09-22 20:51:21 +00:00