Commit graph

35547 commits

Author SHA1 Message Date
Kevin Fenzi
338a7fe1be value: set sebool to use nfs on value01/mote
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 12:41:26 -07:00
Kevin Fenzi
5fafaafec3 value: add a keytab for zodbot on value02 in prod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 12:34:40 -07:00
Kevin Fenzi
f9b76c707e value: Adjust playbook for installing value02 in prod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 12:25:05 -07:00
Kevin Fenzi
8a363ce123 value: add nfs volume for meeting logs
This allows us to share these between value01 and value02

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 12:25:05 -07:00
Adam Williamson
6398e5eb9b Add Fedora 35 to greenwave config for openQA update gating
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-17 12:05:11 -07:00
Kevin Fenzi
54637ddf02 value02: adjust network params
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 12:03:11 -07:00
Kevin Fenzi
b537d651f4 Don't forget some nice host variables.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 11:59:29 -07:00
Kevin Fenzi
01043987b7 value02: Install rhel8 based value02.
This host will run zodbot with python3.
mote will stay on value01 until it can be moved/upgraded/re-written.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-17 11:58:36 -07:00
František Zatloukal
f0a83d86ef Blockerbugs: Update variables to have different stg/prod keys 2021-08-17 12:01:21 +02:00
David Kirwan
1868c951a7 metrics-for-apps: Ensure the playbook copies environment specific files
to control nodes

Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-17 12:26:54 +09:00
David Kirwan
773bb63e35 metrics-for-apps: CA cert for the ocp4 staging cluster
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-17 10:26:56 +09:00
cc88b49dd2 websites: enable ssl redirect for fedoracommunity 2021-08-16 22:29:43 +00:00
e963526654 noggin: remove Nest banner 2021-08-16 22:23:38 +00:00
5772bd7f24 mailman: remove Nest banner 2021-08-16 22:23:38 +00:00
Kevin Fenzi
0ece41d731 mirrormanager / frontend: also set db host for prod
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-16 15:07:53 -07:00
Kevin Fenzi
a1c775b1b2 mirrormanager / frontend: in staging we cannot use the prod db server, specify stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-16 14:29:52 -07:00
Michal Konečný
27b1cc5423 monitor-gating: Fix end tag after branching
The branching happened few days ago and till then the monitor-gating
script is failing. Let's update the end tag to `f36` to fix the issue.

Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2021-08-16 14:27:56 +02:00
Nils Philippsen
501988bba8 Make FM key file readable for countme user
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-08-16 10:07:51 +02:00
Nils Philippsen
5e09dce82d Import fedora-messaging-utils role
Importing the role rather than listing it in the playbook lets its tasks
have the tags used in the importing role, i.e. should ensure they are
run when the things that need simple_message_to_bus are installed.

Additionally, don't attempt to install it manually from
web-data-analysis (it isn't found because it lives in a different role).

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-08-16 06:02:37 +00:00
Nils Philippsen
cce1067c31 Add tasks in fedora-messaging-utils role
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-08-16 06:02:37 +00:00
David Kirwan
ef700c72a2 metrics-for-apps: ocp compute nodes run the console
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-16 13:38:06 +09:00
David Kirwan
6de8b73b9a metrics-for-apps: hotfix rename ocp4 staging CA cert
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-16 11:04:59 +09:00
David Kirwan
63b493fe31 metrics-for-apps: hotfix rename ocp4 staging ca certificate
Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-16 10:51:33 +09:00
Kevin Fenzi
771160176a default ocp4 var to false
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-13 20:01:41 -07:00
Kevin Fenzi
a2c4323f84 add ocp4 var
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-13 19:10:43 -07:00
Kevin Fenzi
ffe6484549 haproxy: use env_short here
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-13 16:39:02 -07:00
Kevin Fenzi
73bb20bb13 Revert "haproxy: adjust names on files to use .stg"
This reverts commit 8b1f44206d.
2021-08-13 16:37:13 -07:00
Kevin Fenzi
8b1f44206d haproxy: adjust names on files to use .stg
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-13 13:25:25 -07:00
David Kirwan
55185861c8 metrics-for-apps:
- Updating apache proxy config to handle ocp4 CA cert
- place ocp4 CA cert on proxies
- add ocp4 stg ca cert to haproxy/files

Signed-off-by: David Kirwan <dkirwan@redhat.com>
2021-08-13 20:02:38 +00:00
Adam Williamson
bd0683a453 openQA: drop scratch builds, git branches etc.
We don't need the scratch builds any more, they're in u-t. We
also don't need to use a side branch on lab createhdds any more,
or deploy from u-t on prod.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-12 15:48:54 -07:00
Adam Williamson
e12714e662 Add host_vars for openqa-p09-worker02
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-12 13:48:23 -07:00
Adam Williamson
db8e162fee openQA: re-enable openqa-p09-worker02
Kevin says it should be fixed, let's see.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-12 11:07:25 -07:00
Kevin Fenzi
049a0a604c koji hub / gc: update for f35 and f36 koji garbage collection
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-12 10:45:01 -07:00
Adam Williamson
b2f88d916b openQA: trim Fedora group asset size to 500G
600G kinda pushes the limits on prod, and I think 500 should be
enough, let's see how it goes.

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2021-08-12 09:22:19 -07:00
Aurélien Bompard
61d33dc0cf
So many places.
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 17:20:57 +02:00
Aurélien Bompard
70c435d41f
Adjust self-referencing URL again
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 17:17:51 +02:00
Aurélien Bompard
0ee9fe41bd
Adjust self-referencing URL
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 17:15:07 +02:00
Aurélien Bompard
fd58efe5b8
Make Datagrepper 2 available in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 17:06:07 +02:00
Aurélien Bompard
13ebc4e684
Add the staging openshift config for datagrepper
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 16:29:19 +02:00
Stephen Coady
137cd7ee7c add scoady to datanommer appowners
Signed-off-by: Stephen Coady <scoady@redhat.com>
2021-08-12 15:17:56 +01:00
Aurélien Bompard
e90e3db279
Fix TOML syntax on staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 15:41:10 +02:00
Aurélien Bompard
499ff17f5e
Add the queue for datanommer
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 15:33:30 +02:00
Aurélien Bompard
d685f6da09
Typo
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-12 14:58:44 +02:00
Nils Philippsen
6e62fcbe69 Don't drop temporary files all over the place
When renaming a file over another which is the same hard link, the
rename is a no-op. This left many temporary files in /var/log/hosts
because a file is attempted to be synced (and thus hard-linked between
dated and undated file names) over a couple of days. The solution to
this is how the `ln` command does it: rename, then unlink the temporary
file.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-08-12 09:45:49 +00:00
Pavel Raiskup
f8e3bdee6b copr-be: copr-ping: faster recovery
When the last build succeeds, the nrpe service should recover
immediately. Also refine some of the log messages.
2021-08-12 09:06:47 +02:00
Kevin Fenzi
4faf14ea89 Re-add fedora-35 processing now that we have a branched.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-11 19:45:10 -07:00
Kevin Fenzi
3e167e43ed branched compose cron job: this should be f35
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2021-08-11 11:22:06 -07:00
Nils Philippsen
51a4fa8639 logging: Make FM config be owned by countme user
This is so the various scripts running under the countme user actually
can read it and send messages on the bus.

Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-08-11 15:11:24 +00:00
Aurélien Bompard
56440ef994
Build the new datanommer on python 3.9
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2021-08-11 15:28:38 +02:00
Michal Konečný
98ea6b11fc distgit: Add pull_request_close ACL
Currently it's not possible to create token with pull_request_close ACL
for user (see https://pagure.io/pagure-dist-git/issue/144).

This commit will allow users to add pull_request_close ACL to their
token. The user is still validated if it has the permission, so adding
this ACL to user token doesn't allow user to use API to close any PR
currently opened in dist-git.

Thanks @pingou for helping me with this.

Signed-off-by: Michal Konečný <mkonecny@redhat.com>
2021-08-11 15:22:42 +02:00