Commit graph

38658 commits

Author SHA1 Message Date
Stephen Smoogen
0863d2c8a9 Fix item in sshd_config that Kevin found in review 2023-01-17 15:43:33 -05:00
Stephen Smoogen
1618137592 retry to make a branch with just the sshd config change. 2023-01-17 20:37:34 +00:00
Kevin Fenzi
721d018ad6 pagure-dist-git: stop spewing INFO/DEBUG on https pushes
Right now when someone does a https push they get about 100 lines of
INFO and DEBUG from pagure. Everything from acls to messaging to pika to
everything. There's no need for all this debug/info spew.
Lets disable it and go back to just WARNINGS

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-17 12:33:45 -08:00
Kevin Fenzi
152fa064ad bodhi: set the correct bodhi version
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-16 15:35:08 -08:00
Kevin Fenzi
a7abb71efd bodhi: move to f37
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-16 15:21:23 -08:00
Kevin Fenzi
3574e037a3 wiki / staging: make sure to mount attachments dir in staging
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-16 14:20:31 -08:00
Michal Konečný
b7e5056a4e [notifs-backend] Fix YAML syntax
Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-16 16:09:56 +01:00
Michal Konečný
00bb6a3634 [notifs-backend] Update FMN playbook
Remove redis from playbook, it's no longer used. We are using memcached instead.
Start the services automatically after deployment.

Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-16 15:58:59 +01:00
Kevin Fenzi
c3cfb0e140 koji-hub: upstream has moved/renamed the wsgi script
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-13 13:53:27 -08:00
Dusty Mabe
7b63158eab
Revert "openshift-apps: put the pruner to sleep again"
Now that the holidays are over let's prune!

This reverts commit edf56b5611.
2023-01-13 15:44:02 -05:00
Kevin Fenzi
00e7d2a28c typo: use the correct seperator
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-13 12:01:46 -08:00
Kevin Fenzi
120c29b533 buildvm-s390x-01.stg: do not use linux-system-roles on s390x builder in staging either
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-13 11:25:58 -08:00
Kevin Fenzi
4b2e6f8fe4 builders: exclude updating koji-containerbuild for now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-13 10:30:51 -08:00
Kevin Fenzi
4bec2d3255 buildvm_s390x: attempt to rebalance kvm lpar to allow for heavybuilders
We have been having issues with webkitgtk not being able to build due to
memory constraints on the existing builders. Also, we are overcomitted
on memory on the kvm lpar. So, to hopefully fix this:

* remove 3 existing builders.
* just leave the 3 cpus and 17gb memory from one free for the host
* make 2 of the other builders double the size in memory, cpu and disk.
* Will add these 2 to the heavybuilder channel and hopefully webkitgtk
  will be happy again.

I'm a bit concerned that this might slow the mass rebuild down, but we
will see. :)

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-12 14:36:11 -08:00
Frank Ch. Eigler
873fed608d debuginfod: tweak caching, stop retaining f32 data
Signed-off-by: Frank Ch. Eigler <fche@redhat.com>
2023-01-12 21:20:34 +00:00
Matej Focko
5b838955a4 bodhi: add bots to admin packager groups
Signed-off-by: Matej Focko <mfocko@redhat.com>
2023-01-12 20:16:43 +00:00
Kevin Fenzi
639fb415e9 pagure: try and put fedora-websites back to normal
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-11 11:22:25 -08:00
Kevin Fenzi
3328386f51 fix more vim syntax fun
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-11 09:26:48 -08:00
Kevin Fenzi
4d7c02510f more vim spew fixing
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-11 08:57:04 -08:00
Kevin Fenzi
c652719988 vim did something weird here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-11 08:53:49 -08:00
Kevin Fenzi
47cf07184e wildcard-2023.fedoraproject.org: new wildcard ssl cert
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-11 08:48:40 -08:00
Nick Bebout
6987b8bc1e Add aws-fpl group to ipsilon per mattdm's request 2023-01-10 20:12:27 -06:00
Kevin Fenzi
0aeb60adea collectd: add to selinux policy to prevent denied read for proc/net
Should fix up these messages from all machines:
audit[865]: AVC avc:  denied  { read } for  pid=865 comm="reader#2" name="net" dev="proc" ino=4026531845 scontext=system_u:system_r:collectd_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=lnk_file permissive=0
audit[865]: AVC avc:  denied  { read } for  pid=865 comm="reader#2" name="net" dev="proc" ino=4026531845 scontext=system_u:system_r:collectd_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=lnk_file permissive=0

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-10 14:35:18 -08:00
Kevin Fenzi
584d9e6406 koji-gc: don't untag/gc things in *pending tags
We hit a case with an old update that was almost ready to be untagged,
but then was submitted as an update and _then_ untagged.
See https://pagure.io/fedora-infrastructure/issue/11058
Telling koji-gc to keep anything in pending tags should avoid this small
window for problems.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-10 12:47:45 -08:00
Michal Konečný
f8a250f89b [toddlers] Set the log level back to INFO for production
Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-10 17:27:42 +01:00
Michal Konečný
1cc16e1750 [toddlers] Set log level to debug for toddlers
Partial setting to debug doesn't seems to work, let's set the whole toddlers to debug.

Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-10 16:32:19 +01:00
Michal Konečný
c08475fbcb [toddlers] Set the log level for correct class
Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-10 16:25:59 +01:00
Michal Konečný
127a770619 [toddlers] Add debug output to scm_request_processor
To help fix the issue with creating branch change the log level to DEBUG temporarily.

Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2023-01-10 16:13:45 +01:00
Kevin Fenzi
0d08f15f41 ip6tables: allow dhcp6d from aws
While we actually use SLAAC in aws, there's a dhcp6d sending out the
router advertisements, so without that the instance doesn't get an ipv6
ip and just doesn't work. With this it does.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-09 19:06:27 -08:00
Jakub Kadlcik
98410c9b7b copr: mask the systemd-oomd service 2023-01-09 11:40:08 +01:00
Kevin Fenzi
4b262d7ada apps.ocp.stg new certs for 2023
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-08 18:26:33 -08:00
Kevin Fenzi
31f11df469 koschei: increase timeout from 30s to 180s to allow loading larger queries
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2023-01-08 11:12:00 -08:00
Stephen Smoogen
9b82c517f4 put back in copy of people.conf so that we can get correct config on webserver 2023-01-05 13:38:33 -05:00
Stephen Smoogen
69ba9efed8 Move to using new certs for fedorapeople
Get new certs per instructions
Put new certs in ansible_private from letsencrypt
Change the cert name in configs to 2023 to show different from 2017 one.

Signed-off-by: Stephen Smoogen <ssmoogen@redhat.com>
2023-01-05 12:50:34 -05:00
Pavel Raiskup
5e75fa84c6 copr-dist-git: rebuilding cgit data takes one hour 2023-01-03 13:20:07 +01:00
Pavel Raiskup
bf8d23bbfd copr-fe: re-enable automatic PyPI rebuilds
Relates: https://github.com/fedora-copr/copr/issues/2289
2023-01-03 13:19:52 +01:00
Jakub Kadlcik
6a386738d7 copr: make sure rpmlint package is up-to-date on builders
https://pagure.io/FedoraReview/issue/461
2022-12-21 23:46:12 +01:00
David Kirwan
b33aa64cde fas2discourse: Create playbook/role
Create task to generate keytab
2022-12-21 10:09:54 +09:00
David Kirwan
f78802897b mdapi: set correct path to mdapi client inside cronjob
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-20 18:00:51 +09:00
David Kirwan
01c03085ed mdapi: fix configmap file name
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-20 17:49:53 +09:00
David Kirwan
15ec523d15 mdapi: add myconfig.py configmap
add volumemount to deploymentconfig
       add volumemount to cronjob

Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-20 17:34:49 +09:00
David Kirwan
ab250d7a87 mdapi: change cronjob entrypoint command
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-20 16:13:35 +09:00
David Kirwan
d59ca4e29f mdapi: point s2i git uri at new repo
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-20 15:47:55 +09:00
Adam Williamson
d23bfae035 Update one more fedora-36 entry in greenwave config
Whoops, forgot this one.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2022-12-19 19:04:50 -08:00
Adam Williamson
de979123fa openQA: don't install the fedoraupdaterestart plugin any more
We don't need it, we use upstream RETRY now.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2022-12-19 16:16:11 -08:00
Adam Williamson
55c7450311 Update greenwave rules for F35 EOL
Thanks to @jforbes for reminding me of this - now F35 is EOL,
we don't run the openQA upgrade tests on F36, so we have to
upgrade the gating policy or no F35 updates can be pushed.
Also drop other fedora-35 references in openQA-related rules.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2022-12-19 16:11:07 -08:00
Kevin Fenzi
5ca2b2eb36 os.fedoraproject.org / app.os.fedoraproject.org: remove more old openshift 3.11 cluster stuff
It may be that having this on some of the proxies is causing problems
because it's trying to ping the old openshift 3.11 cluster and filling
up apache slots with it. We do not need this stuff anymore, so remove
it.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2022-12-16 10:15:27 -08:00
Dusty Mabe
edf56b5611
openshift-apps: put the pruner to sleep again
Now that we've pruned 1.2T from the repo let's put the pruner back
to sleep over the holidays. It's a brand new service and if anything
goes awry we want to be around to investigate.

Will re-enabled in January.
2022-12-15 11:18:38 -05:00
David Kirwan
e4b47ff35c communishift: testing venv workaround for dependency issues
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-15 15:36:35 +09:00
David Kirwan
2378c9cf35 communishift: testing venv workaround for dependency issues
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2022-12-15 15:21:59 +09:00