Commit graph

15 commits

Author SHA1 Message Date
Kevin Fenzi
463439136b inventory /group_vars: clean up a bunch of old phx2 networks for iad2
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2022-06-08 10:34:01 -07:00
Kevin Fenzi
580cd252c5 Inventory group/host variables: Sort yaml
This was done using yq (
https://mikefarah.gitbook.io/yq/operators/sort-keys )

Doing things this way makes it much easier to see if a variable is set
in a file or if two hosts differ in what variables they set. Hopefully
we can keep things sorted moving forward.

Basically this means just sort a-z anything you add to any host or group
vaiable and it will be in the right place.

Additionally, this enforces 'normal' intent rules for all the variable
files which we should also try and obey. 2 spaces for first level, 3 for
next, etc. When in doubt you can run yq on it.

This should cause NO actual vairable changes, it's all just readability
fixing for humans, ansible parses it exactly the same.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-11-16 13:27:57 -08:00
Kevin Fenzi
3c12ef6aa9 Killed trailing spaces in group/host vars with fire.
Normally it's just a nitpick to not have trailing spaces on variables.
However, for some things like mac address, it really matters.
Bunches of buildhw's were failing ansibile because they were passing
"mac address " to linux-system-roles networking and ansible was going
'huh, nope, I can't find that mac address here at all'.
So, just blow all the tailing spaces away to avoid any other variables
that hit this.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-05-04 08:52:52 -07:00
Nils Philippsen
dbbf94a411 ipa/client: configure global shell access and sudo
Almost global anyway, i.e. inside the VPN.

The ipa/client-based shell access and sudo rules are only effective for
staging right now, the respective playbook bits are masked out for prod.

- Assign Ansible host groups to IPA host groups, the latter don't care
  about 'stg' in the name and use dashes rather than underscores.
- Distill shell access groups from fas_client_groups in group and host
  vars.
- Let all `sysadmin-*` groups in the previous list run anything via sudo
  in the host group (except bastion & batcave).
- Remove `fas_client_groups` from staging host and group vars.
- Remove sudoers from staging host and group vars if only `sysadmin-*`
  groups have shell access.
- Set up `ipa_client_shell_groups` on bastion to be a super set of the
  same on batcave.

Newly created IPA host groups:
- autosign
- badges
- basset
- bastion
- batcave
- blockerbugs
- bodhi
- bugzilla2fedmsg
- busgateway
- datagrepper
- dbserver
- dns
- fedimg
- github2fedmsg
- ipa
- kernel-qa
- kerneltest
- kojibuilder
- kojihub
- kojipkgs
- logging
- mailman
- memcached
- mirrormanager
- nagios
- notifs
- oci-registry
- odcs
- openqa
- openqa-workers
- osbs
- packages
- pdc-web
- pkgs
- proxies
- rabbitmq
- releng-compose
- resultsdb
- secondary
- sign-bridge
- sundries
- value
- wiki

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-02-01 22:23:41 +00:00
Pierre-Yves Chibon
22662d79b5 Clean up inventory files for odcs and pkgs for the fedmsg-related variables and comments
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-07-23 13:11:50 +02:00
Pierre-Yves Chibon
d0452479ed Revert "remove fedmsg variables which define endpoints on other fedmsg systems"
We need to keep these variables defined as they are used in the .wsgi files
to set the number of procs and threads for apache.

This reverts commit 6e92ba25a7.
2020-07-23 13:09:24 +02:00
Stephen Smoogen
6e92ba25a7 remove fedmsg variables which define endpoints on other fedmsg systems 2020-07-22 12:28:44 -04:00
Jan Kaluža
000c46402c ODCS: Set the same allowed_clients for both prod and staging. 2020-04-24 21:34:29 +02:00
Jan Kaluža
af92d2582a ODCS: Add extra compose target directory for private composes. 2020-04-24 21:34:26 +02:00
Jan Kaluža
7ef7b3c7e5 ODCS: Allow humaton, mohanboddu and jkaluza to run any type of compose. 2020-04-24 21:34:26 +02:00
Kevin Fenzi
db9e25330b inventory: try removing all the calls to ansible_python_interpreter and rely on the auto detection.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-04-24 21:34:15 +02:00
Jan Kaluža
280ce5b533 Do not install fedmsg-hub certs. 2020-04-24 21:34:13 +02:00
Mikolaj Izdebski
f4ebcc677a ODCS: Use dedicated sysadmin-odcs group 2020-04-24 21:34:13 +02:00
Mikolaj Izdebski
98eb4b1c0f odcs stg: Set ansible_python_interpreter to python3 2020-04-24 21:34:12 +02:00
Kevin Fenzi
4b31ac5152 ansible: Change all our group names from foo-bar to foo_bar or foo-bar-baz to foo_bar_baz
In ansible 2.8 the - character isn't supposed to be valid in group names.
While we could override this, might has well just bite the bullet and change it.
So, just switch all group names to use _ instead of -

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2019-05-20 17:38:09 +00:00
Renamed from inventory/group_vars/odcs-frontend-stg (Browse further)