Commit graph

35698 commits

Author SHA1 Message Date
Dusty Mabe
c2ceab0958 aws-iam-policies: fcos-upload-amis: group some policies with other similar ones
Move CreateSnapshot to be with ImportSnapshot. Move DescribeImageAttribute
to be with ModifyImageAttribute.
2021-08-30 20:24:36 +00:00
Stephen Smoogen
2272ab1f6f Add in a test to make that the nagios templates try to add in groups
with no vpn.

Signed-off-by: Stephen Smoogen <ssmoogen@redhat.com>
2021-08-27 11:05:40 -04:00
Pavel Raiskup
58c451d6ed copr-be: decrease the amount of AWS builders 2021-08-26 21:00:11 +02:00
Pavel Raiskup
288b487bf5 copr-be: use vmhost x86 02 again 2021-08-26 18:59:58 +02:00
Kevin Fenzi
bfb3e7f26d ocp_stg: no vpn here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-26 09:02:12 -07:00
Mark O Brien
5da8595200 os: add access to os control for sysadmin-openshift group
Signed-off-by: Mark O Brien <markobri@redhat.com>
2021-08-26 15:25:45 +00:00
Kevin Fenzi
0dade64ba2 ocp / staging: tell nagios not to check nrpe/swap/mails on ocp hosts
By default nagios assumes it can connect to everything in inventory via
nrpe and monitor things like swap and number of emails in the postfix
queue. For ocp hosts running CoreOS we don't want to have nagios
monitor any of that, we only want it to monitor ping (is the host up).
This change is only in vars here, but it needs a noc run to activate, so
it will need a freeze break to run the noc playbook (as noc is frozen).

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-26 15:06:12 +00:00
Pavel Raiskup
6574da16d4 copr-be: prefer ppc64le boxes over AWS non-SPOT for source builds 2021-08-26 13:38:39 +02:00
Pavel Raiskup
1e0279cfbb copr-be: deprioritize AWS (all builds) and ppc64le builders for source builds 2021-08-26 11:29:43 +02:00
Pavel Raiskup
35664cc9a3 copr-be-upgrade: upgrade also copr-cli
Which is needed nowadays for the copr-ping cronjob.
2021-08-26 09:37:49 +02:00
Kevin Fenzi
a64b1e8e4f value: make sure to only start zodbot on value02 now
We moved zodbot from value01 (rhel7/python2) to value02 (rhel8/python3).
Without this it starts zodbot on 2 hosts and caused problems.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-25 16:04:53 -07:00
Kevin Fenzi
bb62cec8f8 osbs-node01/02: moved to 240g space so 0ad flatpak can build
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-25 12:57:43 -07:00
Pavel Raiskup
d635907b4a copr-be: drain vmhost x86 02 2021-08-25 19:23:20 +02:00
Adam Williamson
beacd484a1 greenwave: leave fedora-35 out of the main policy
Tomas added f35 back to this policy yesterday, which would
usually be the right thing to do, but in fact we have a modified
policy for f35 because some tests are known failing - see
d19fd11 . We don't want f35 in the main policy till the bugs
affecting those tests are fixed, or else no update will ever
pass gating.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-25 09:01:56 -07:00
David Kirwan
03c6f77555 metrics-for-apps: no longer need pxe bios template for ocp nodes
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-25 13:52:16 +09:00
David Kirwan
fc3153dc91 metrics-for-apps: added noc01.iad2.fedoraproject.org to staging_friendly
group, to ensure it does not receive iptable rule banning access to
staging network 10.3.166.0/24

Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-25 13:44:05 +09:00
David Kirwan
e47f5bbe18 metrics-for-apps: synchronise rhcos files to noc01 for uefi boot
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-25 12:22:41 +09:00
David Kirwan
b5fd9a05b9 metrics-for-apps: Update ocp compute nodes to use uefi boot
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-25 11:58:40 +09:00
Brendan Early
0f18b26363 fedora-packages-static: add production os to hosts 2021-08-24 21:28:41 +00:00
Kevin Fenzi
2b0a7558e0 add vmhost-x86-09
This host is an old phx2 host thats been sitting there on this ip, but
we haven't moved any vm's to it (thus it shouldn't be affected by the
freeze). However, we should get in ansible so it's network is managed
and so we remember to reboot it for updates, etc.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-24 10:54:55 -07:00
4a52541da4 F35 bodhi activation point
Signed-off-by: Tomas Hrcka <thrcka@redhat.com>
2021-08-24 11:48:17 +02:00
petebuffon
5a97060249 Batch update of vmhost* Ansible host_vars files for linux-system-roles/network conversion. 2021-08-23 23:06:55 +00:00
f561217bdf Correct the database URLs for badges-backend in staging
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-08-23 23:04:40 +00:00
Kevin Fenzi
5c709e38e5 bvmhost-a64-10: use linux-system-roles/networking
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-23 15:10:55 -07:00
lrossett
97c9915b94
adds a check for the deployment_type var 2021-08-23 15:06:53 -03:00
lrossett
48b8957386
fixes ca sceret name 2021-08-23 15:06:27 -03:00
lrossett
7f79ed6880
removing linvess check 2021-08-23 14:38:17 -03:00
lrossett
3ba84f6b97
checks if deployment_type var is defined 2021-08-23 14:04:25 -03:00
lrossett
e56d0b6809
enabling both stg and prod servers 2021-08-23 13:42:23 -03:00
Frank Ch. Eigler
d835aba567 debuginfod proxies: preserve & pass %2F etc.
Apache httpd by default blocks URL-encoded / (%2F) characters in the
URL path, even though these are RFC-compliant.  Enable them and permit
their safe passage to the debuginfod servers.

See also https://stackoverflow.com/a/9933890/661150

Signed-off-by: Frank Ch. Eigler <fche@redhat.com>
2021-08-23 11:39:36 +00:00
9a32ce7912 ursabot: create pki/fedora-messaging directory
Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-08-23 19:52:20 +10:00
6b43caff64 set fedora-messaging certs for ursabot
Just doing this for staging right now, to check it works as expected

Signed-off-by: Ryan Lerch <rlerch@redhat.com>
2021-08-23 19:39:22 +10:00
Pavel Raiskup
35bb0977fb copr-be: tag x86 builders as arch_noarch
This will be used to avoid biulding source RPMs on ppc64le boxes.
2021-08-23 11:37:45 +02:00
Kevin Fenzi
ec0d18a8b8 nagios: adjust where zodbot announces alerts, zodbot is on value02 now
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-22 10:10:10 -07:00
Adam Williamson
d19fd11654 Greenwave policy: skip some known-broken F35 tests from policy
desktop_background tests are known to fail ATM because the F35
backgrounds don't exist yet, and desktop_update_graphical on
GNOME is known broken:
https://bugzilla.redhat.com/show_bug.cgi?id=1995817
so we add a copy of the policy with those tests left out, to
avoid all F35 updates failing gating because of these issues.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-20 15:50:17 -07:00
Adam Williamson
1bd94ce508 Greenwave: add KDE live ISO tests to openQA update gating rules
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-20 15:47:43 -07:00
Kevin Fenzi
ee1198e0cf value: port 5050 direct needs open for zodbot
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-20 14:03:25 -07:00
Kevin Fenzi
983d456072 wiki: update content license note
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-20 13:52:39 -07:00
Kevin Fenzi
da6b339229 batcave: change value01 to value02 for zodbot announcements.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-20 09:12:21 -07:00
Kevin Fenzi
918956204d value: rw for the meetbot meeting logs in /srv
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 17:00:47 -07:00
Kevin Fenzi
bfb32a9dfb zodbot: add env vars for fasjson
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 16:23:27 -07:00
Kevin Fenzi
5e6ab492a5 haproxy: tweak filename for ocp certs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 16:13:33 -07:00
Kevin Fenzi
b102f1f58a wiki: adjust wiki01 to new networking
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 15:59:32 -07:00
Kevin Fenzi
ba541c60f0 wiki: reinstall wiki02 with new os/wiki version
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 14:11:20 -07:00
Kevin Fenzi
ce5c8188d2 proxies: setup askbot redirect to ask (ticket 10140)
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-19 13:43:17 -07:00
Kevin Fenzi
7e523ddb61 badges/stg: use correct names
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-18 14:06:33 -07:00
Kevin Fenzi
1b7db35db4 badges/stg: convert ip config to new format
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-18 14:03:53 -07:00
Kevin Fenzi
8cd3227549 badges / staging: stand up staging badges to allow for testing
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-18 13:59:17 -07:00
Kevin Fenzi
00e37bd2f2 value: only install meeting to team linking script on value01
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-18 13:44:05 -07:00
Frank Ch. Eigler
1af312bdd3 debuginfod: support f36+, enlarge fdcache
Fix the debuginfod sysconfig file to not stop at f32..f35 but go at
least to eleven ^W f39 for RPM inclusion.  Bump up the fdcache size
to 1024 entries so more archive pieces are retained unpacked, given
that the VMs still have pretty generous unused storage.

These changes are already hand-applied to prod and stg.
2021-08-18 20:35:49 +00:00