From 7f429f3d13819107c31caaa1abe14497aedc4954 Mon Sep 17 00:00:00 2001 From: James Antill Date: Mon, 24 Mar 2025 16:18:48 -0400 Subject: [PATCH] Clean nftables var. for specific staging groups. Signed-off-by: James Antill --- inventory/group_vars/buildvm_stg | 2 -- inventory/group_vars/koji_stg | 1 - inventory/group_vars/pkgs_stg | 1 - inventory/group_vars/proxies_stg | 1 - inventory/group_vars/wiki_stg | 1 - 5 files changed, 6 deletions(-) diff --git a/inventory/group_vars/buildvm_stg b/inventory/group_vars/buildvm_stg index fc8171deb9..ac766b92bc 100644 --- a/inventory/group_vars/buildvm_stg +++ b/inventory/group_vars/buildvm_stg @@ -24,8 +24,6 @@ lvm_size: 150000 max_mem_size: "{{ mem_size }}" mem_size: 10240 nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=4" -# Do we want to use nftables instead of iptables -nftables: true num_cpus: 4 resolvconf: "resolv.conf/iad2" source_registry: "registry.fedoraproject.org" diff --git a/inventory/group_vars/koji_stg b/inventory/group_vars/koji_stg index 354edf27b1..eddc8f6d90 100644 --- a/inventory/group_vars/koji_stg +++ b/inventory/group_vars/koji_stg @@ -19,7 +19,6 @@ lvm_size: 250000 mem_size: 32768 # NOTE -- staging mounts read-only nfs_mount_opts: "ro,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3" -nftables: true num_cpus: 8 source_registry: "registry.stg.fedoraproject.org" # for systems that do not match the above - specify the same parameter in diff --git a/inventory/group_vars/pkgs_stg b/inventory/group_vars/pkgs_stg index a250dc466b..cb6d74b002 100644 --- a/inventory/group_vars/pkgs_stg +++ b/inventory/group_vars/pkgs_stg @@ -33,7 +33,6 @@ ipa_host_group: pkgs lvm_size: 500000 max_mem_size: 32768 mem_size: 16384 -nftables: true num_cpus: 8 pagure_static_uid: 600 # Configures ssh for git@ user diff --git a/inventory/group_vars/proxies_stg b/inventory/group_vars/proxies_stg index c0a742705a..33b33571df 100644 --- a/inventory/group_vars/proxies_stg +++ b/inventory/group_vars/proxies_stg @@ -29,7 +29,6 @@ nft_custom_rules: - 'add rule ip filter INPUT ip saddr 10.3.166.121 tcp dport 22623 counter accept' - 'add rule ip filter INPUT ip saddr 10.3.166.122 tcp dport 22623 counter accept' - 'add rule ip filter INPUT ip saddr 10.3.166.123 tcp dport 22623 counter accept' -nftables: true external: true ipa_client_shell_groups: - fi-apprentice diff --git a/inventory/group_vars/wiki_stg b/inventory/group_vars/wiki_stg index 2e4346b0f6..f87b60e28a 100644 --- a/inventory/group_vars/wiki_stg +++ b/inventory/group_vars/wiki_stg @@ -13,7 +13,6 @@ ipa_host_group_desc: Fedora Wiki lvm_size: 30000 mem_size: 4096 nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,sec=sys,nfsvers=3" -nftables: true num_cpus: 2 tcp_ports: [80] # mediawiki variables -- 2.50.0