Commit graph

718 commits

Author SHA1 Message Date
Kevin Fenzi
22ef05d3f2 proxies: stg.release-monitoring.org make this it's own site
Normally we can just define the site once with it's prod name and use
that in stg with an alias. This works because we have a wildcard ssl
cert for *.fedoraproject.org. So, stg.fedoraproject.org and
fedoraproject.org both work fine. We can't do this for
release-monitoring tho as we use letsencrypt certs and don't have a
wildcard. We could expand out letsencrypt role to get altnames, but just
making these seperate sites should fix it.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-12 11:13:23 -08:00
Kevin Fenzi
177465221c proxies / websites: we want release-monitoring.org in stg too.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-12 10:21:24 -08:00
Kevin Fenzi
030a0ddc40 proxies / websites: revert disabling some sites in stg now that it's back
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-11 19:36:32 -08:00
Kevin Fenzi
385acb276e proxies /redirects: don't use env here
The site is the prod name, with an alias for the stg host.
No need to try and install into a stg site when it doesn't exist.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-11 18:30:34 -08:00
Kevin Fenzi
bbfc222d25 proxies / websites: re-enable some hosts in stg
we disabled these when we didn't have stg in iad2 yet.
Now that we do, we can re-add them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-11 16:34:00 -08:00
Pierre-Yves Chibon
414a063625 Proxy-websites: create the testdays.fic.o
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:50:56 +01:00
Pierre-Yves Chibon
b1b0365f95 proxies: fix typo
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:48:26 +01:00
Pierre-Yves Chibon
439844863e Proxies: add a redirect from testdays.fic.o to testdays.fp.o
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 14:47:18 +01:00
Pierre-Yves Chibon
1390d242ef proxies: get testdays to redirect to openshift in stg and prod
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-11-05 13:56:44 +01:00
Kevin Fenzi
e0555ee173 proxies / reverseproxy: drop duplicate website var
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-03 15:24:45 -08:00
Kevin Fenzi
48e878b9fe testdays: fix up testdays proxying in staging
It was redirecting it to the old fedorainfracloud ip.
Then it wasn't proxying to openshift.

When moving to prod, the conditionals here should be removed.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-11-01 11:33:52 -08:00
Kevin Fenzi
511654cda5 proxies / redirects: Add a redirect for iot.fp.o -> getfedora/iot
Fixes ticket #9401

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-27 13:14:02 +00:00
Rick Elrod
ad55b9ddc8 Revert "Disable prerelease redirects"
This reverts commit 54c4089a70.
2020-10-27 07:28:53 -05:00
Aurélien Bompard
b219aad49f
Try to fix ipsilon's openid
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-15 16:45:20 +02:00
Kevin Fenzi
e59166aeac pkgs / staging: sort out staging certs and sites.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 16:20:32 -07:00
Kevin Fenzi
150f53ecb0 Freeze Break Request: Update openshift ssl certs
These certs are used for *.app.os.fedoraproject.org.
ie, things that don't also have/use a fedoraproject.org route.
THis includes the console and some apps that just never bothered to make
a fedoraproject route.

Fixes 9162

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 19:38:24 +00:00
Kevin Fenzi
5c70045704 Update staging openshift ssl cert to new one.
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-10-14 09:32:07 -07:00
Aurélien Bompard
38cc67731b
Proxy: attempt to move ipsilon back to a VM in staging
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-10-07 10:59:41 +02:00
Pierre-Yves Chibon
721206902b proxy: add a server alias for testdays.stg
Signed-off-by: Pierre-Yves Chibon <pingou@pingoured.fr>
2020-10-02 12:18:44 +02:00
Rick Elrod
54c4089a70 Disable prerelease redirects
Signed-off-by: Rick Elrod <relrod@redhat.com>
2020-09-29 06:59:21 -05:00
Kevin Fenzi
0a4698b669 proxies / staging: fix the openqa-labs backend address
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-09-24 08:17:16 -07:00
Kevin Fenzi
51428eb99a proxies / staging: point openqa in stg to lab
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-09-21 15:21:47 -07:00
Mark O'Brien
94f47caeea [proxies] fasjson is only in stage for now 2020-09-02 17:05:07 +01:00
Kevin Fenzi
bfcf91830b proxies / staging: adjust fasjson website a bit
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-09-01 11:27:11 -07:00
Kevin Fenzi
69cec0c4f6 proxies / staging: add fasjson.stg website/reverseproxy
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-09-01 10:39:25 -07:00
Aurélien Bompard
8334489a75
FASJSON: fixup install
Signed-off-by: Aurélien Bompard <aurelien@bompard.org>
2020-09-01 15:36:36 +02:00
Aurélien Bompard
44734cabb1
Noggin: leave a space for FAS 2020-09-01 15:35:50 +02:00
Kevin Fenzi
2c50a9ac9b proxies / websites: drop stg.release-monitoring.org too
For the same reason as the last commit. We don't have staging back yet
and so we can't get certs for them.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-08-07 16:23:44 -07:00
Kevin Fenzi
a1f8337a38 fpaste.org: drop for now until ownership or at least resolves to new ips
We don't own fpaste.org, in the past the owners just pointed it to our
proxies and we got a cert for it. However, it's still pointing to the
old phx2 proxies right now. So, drop it until it's fixed to point to the
new ones, or given to us as a domain.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-08-07 16:05:56 -07:00
Kevin Fenzi
ae1f509177 proxies / websites: don't define stg.fedoracommunity.org in prod
Doing this makes letsencrypt try and get a cert for it, but it's not
setup to do that correctly. Wait until stg is back.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-08-07 15:56:40 -07:00
Mark O'Brien
cb22333aae [proxies] ensure all directories exists 2020-08-04 17:20:52 +01:00
Mark O'Brien
9b54e14d1c [proxies] ensure dir exists 2020-08-04 17:14:50 +01:00
Stephen Smoogen
8595ca9a61 put in a tag to make proxy playbook run for data-analysis much shorter 2020-07-31 13:08:11 -04:00
Stephen Smoogen
5f7864f24f put in web-data-analysis changes to get proxies to work 2020-07-31 11:08:44 -04:00
Kevin Fenzi
c5da244a17 websites: try and disable letsencrypt/certbot in stg
Right now we don't have a working certgetter, so disable these for now
until we can get certgetter01 able to go out and get certs.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-24 18:09:30 -07:00
Kevin Fenzi
fa50e284fd proxies: re-enable apps-fp-o role
Turns out this also deploys all the bootstrap and fonts that things use,
not just the apps viewer thing. So, re-enable it for now so things work
again.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-22 15:23:13 -07:00
Stephen Smoogen
257a130bc8 remove zanata2fedmsg. the zanata roles are still there for the time being as they are tied into webstizes and such 2020-07-22 15:22:37 -04:00
Kevin Fenzi
b01fd570a8 comment out stg.whatcanidoforfedora.org for now so we can renew the prod cert
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-07-10 15:26:24 -07:00
Kevin Fenzi
79198c0112 Revert "kojipkgs: switch http/2 on again"
This reverts commit 4b9e9a196d.
2020-06-23 14:18:18 -07:00
Kevin Fenzi
4b9e9a196d kojipkgs: switch http/2 on again
We had problems the last time we had this on, but that was a while back,
so lets try it again. If we notice weird build failures, we can revert
it back again.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-06-22 15:35:10 -07:00
Adam Williamson
ddbafa861a Explicitly declare tasks in proxies-website.yml
This might help, @smooge?

Signed-off-by: Adam Williamson <awilliam@redhat.com>
2020-06-16 10:43:14 -07:00
Stephen Smoogen
62c8dcccac Revert "fix selinux so it will run on proxy101/proxy110". Even explicitely calling out these two servers, the playbook is being skipped.
This reverts commit 7092e2180e.
2020-06-16 12:28:28 -04:00
Stephen Smoogen
7092e2180e fix selinux so it will run on proxy101/proxy110 2020-06-16 12:25:03 -04:00
Stephen Smoogen
fdee6622ce fix sundries rsync to allow vpn to get data 2020-06-12 13:16:21 -04:00
41f79ab8d2 dhcp/inventory: removing beaker and beaker-client
Removing references to beaker and the hosts that were part of that setup
2020-06-02 18:52:47 +00:00
Kevin Fenzi
7f6cdda0b2 iad2: adjust more proxy things for iad2: kojipkgs, nagios and certbot for pkgs
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-27 21:13:55 -07:00
Kevin Fenzi
fa38fe6191 iad2: proxies-reverseproxies: try and generalize datacenter for reverse proxies
Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-26 18:00:11 -07:00
Kevin Fenzi
03ccad12e1 proxies: comment out apps-fp-o for now.
apps-fp-o no longer works in Fedora 32.
It needs PyYAML which was dropped, and has 2 python2
yaml scripts that no longer will work. We need to either
replace it or drop it or fix it.

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
2020-05-25 08:32:09 -07:00
2c8040908d proxies: second attempt at fixing ansible-review 2020-05-21 20:52:28 +00:00
f758238830 proxies: fixing formatting mistake 2020-05-21 20:52:28 +00:00